Fix #457: provenance maintenance #468

Merged
crueber merged 2 commits from fix/issue-457 into main 2026-09-13 16:20:22 +00:00
Owner

Child of #449 (F3 + F8). (1) Child delete sweeps its parent meta/forks.json row (pulls.UnlistFork, CAS, Version++ only on removal) + decrements the social counter exactly then (social.DecForks, CAS, floor 0, absent stays absent); hooked post-linearization in serving RepoRegistry.Delete via buildCollab (wal core untouched, law 8); GC-safe by order (row goes second: 404-skip or never-probed) — existing #451 parent-delete e2e still passes. (2) merged_upstream_at: WRITE — stamped on cross-fork merges next to the merged event (same instant as pr merged_at), same-repo merges pay zero trips; no reader added (N-trip cost). Tests: table-driven unlist/dec/sweep/stamp suites + e2e child-delete sweep (row gone, counter 1→0), all -race; pulls 95.9% / social 99.5% coverage; gofmt/vet clean; docs 03 §7+decisions, 07 §6 (law 12); no new deps; no browser (backend-only change).

Child of #449 (F3 + F8). (1) Child delete sweeps its parent meta/forks.json row (pulls.UnlistFork, CAS, Version++ only on removal) + decrements the social counter exactly then (social.DecForks, CAS, floor 0, absent stays absent); hooked post-linearization in serving RepoRegistry.Delete via buildCollab (wal core untouched, law 8); GC-safe by order (row goes second: 404-skip or never-probed) — existing #451 parent-delete e2e still passes. (2) merged_upstream_at: WRITE — stamped on cross-fork merges next to the merged event (same instant as pr merged_at), same-repo merges pay zero trips; no reader added (N-trip cost). Tests: table-driven unlist/dec/sweep/stamp suites + e2e child-delete sweep (row gone, counter 1→0), all -race; pulls 95.9% / social 99.5% coverage; gofmt/vet clean; docs 03 §7+decisions, 07 §6 (law 12); no new deps; no browser (backend-only change).
Child of #449 (F3 + F8). (1) Deleting a fork child now sweeps its parent
meta/forks.json row (pulls.UnlistFork, CAS row-removal, Version++ only on
actual removal) and decrements the social forks counter exactly then
(social.DecForks via the ForksCounter seam, CAS loop floored at zero).
Hook order is GC-load-bearing: parent captured pre-wipe, row removed
post-linearization (a maintain pass either 404-skips or never probes).
Wired in composition (repoRegistry.Delete + buildCollab) — wal core
untouched (law 8); repoimport rollback owes no sweep. (2) merged_upstream_at:
WRITE (one conditional PUT on cross-fork merges, next to the merged event;
same-repo merges pay zero trips) — the 03 §2 table row is now true; no
reader added (per-child reads would cost N trips). Docs 03 §7 + decisions
and 07 §6 updated in the same change (law 12). No new deps.
A losing CAS attempt that found the row (412, row gone on re-read) must
not report removed — concurrent double-deletes of the same child both
reach the sweep (Registry.Delete is idempotent-success), and the stale
flag double-decremented the social counter for one row removal. Reset
the flag per attempt; add a concurrent double-sweep regression test
(exactly one DecForks, deterministic — fails without the fix).
Sign in to join this conversation.
No description provided.