4.3 KiB
4.3 KiB
Evidence Task 5C report
Delivered
- Added
vector.retain_published_generations(default3, validation minimum1). - Retention runs only after publication. It keeps ACTIVE, the newest configured generations, and generations referenced by running or resumable failed job checkpoints.
- Cleanup deletes the exact Evidence generation from the vector store before removing its immutable filesystem directory. Vector failures retain filesystem metadata for retry and produce credential-free partial reports.
- Added idempotent
tht preprocess evidence gc [--dry-run] --jsonreconciliation with pristine JSON output. - Materialized document reads now open generation/documents components with directory file
descriptors and
O_NOFOLLOW, require a regular file owned by the process with one link, and hash the bytes read from the same descriptor against the canonical manifest. - HTTP generation deletion is pinned to
delete_vector_generationwith exact table/kind/generation arguments. Legacy 404 responses fail closed with an actionable, sanitized migration message.
Evidence
- Focused retention, safe-read, CLI, and HTTP contract tests:
51 passed(Docker-backed direct parametrizations excluded from that focused invocation). - Real Docker pgvector adapter suites:
33 passed. - Full harness suite, including Docker-backed tests:
668 passed, 5 deselected. - Changed-file Ruff: clean.
git diff --check: clean.
The five deselected tests are the repository's opt-in l2 tests requiring external services;
they are not local pgvector tests. Test output retains pre-existing Pydantic serialization and
legacy-config deprecation warnings.
Review fix wave
- Publication is now explicit and durable (
PUBLISHEDmarker). Retention candidates require a valid generation manifest and publication marker (ACTIVE remains backward-compatible), so staged and malformed directories neither consume retention slots nor become deletion targets. - The policy retains ACTIVE plus exactly
N-1newest rollback publications, ordered by durable publication time and generation id. Running and failed-resumable JobRunner checkpoints protect every referenced plan generation. VectorStorenow exposes exact Evidence generation inventory. Direct pgvector uses a constrainedSELECT DISTINCToverkind='evidence'andmetadata.vector_generation; HTTP uses the allowlistedlist_evidence_generationsRPC and fails closed on legacy 404. The writer RPC SQL, revokes, and grants are packaged increate_vector_writer_rpc.sql.- Explicit GC reconciles the union of published filesystem generations and vector-only orphans, preserving vector-before-filesystem deletion and retry semantics.
run_as_jobholds the same corpus writer lock across checkpoint recovery, staging, publish, and retention. Explicit GC already uses this lock, serializing candidate snapshots with publishers.- Session artifact consumers no longer receive the corpus source path after validation. They get an owned, read-only copy atomically written from the bytes read and hash-validated on the same descriptor.
Fresh verification after the fix wave: full harness 672 passed, 5 deselected; Docker pgvector,
HTTP parity, and migration suites 43 passed; exact direct inventory/delete integration 1 passed;
changed-file Ruff and git diff --check clean.
Final hardening verification
- Canonical generation validation is exact (
^gen:[0-9a-f]{32}$) before HTTP/direct deletion; malformed HTTP inventory rows fail closed rather than entering the GC candidate set. - Added explicit protection coverage for running and failed-resumable JobRunner checkpoints, plus a second-GC idempotence assertion for vector-only orphan reconciliation.
- Added deterministic concurrent locking coverage: a job paused after discovery retains the corpus writer lock, explicit GC blocks, then completes after publication without deleting the active run.
- Added a descriptor-race regression: replacing the corpus pathname immediately after
read(2)leaves the atomically materialized session-owned copy byte-for-byte equal to the validated ACTIVE document and its manifest hash.
Final fresh evidence: Docker pgvector/HTTP/migration suites 48 passed; full harness 680 passed, 5 external L2 deselected; changed-file Ruff and git diff --check clean.