Skip to content

Pin that the raw-purge seam probe stops at the successor's first bucket (#4406) - #4443

Merged
erikdarlingdata merged 1 commit into
devfrom
test/4406-seam-probe-stops-at-successor-floor
Sep 26, 2026
Merged

erikdarlingdata merged 1 commit into
devfrom
test/4406-seam-probe-stops-at-successor-floor

Conversation

@erikdarlingdata

Copy link
Copy Markdown
Owner

Refs #4406.

Why

The raw-purge coverage check for a legacy/successor pair stitches the two together so an
upgrading store's empty successor doesn't hold the purge forever. The stitch only probes the
seam between the legacy's last bucket and the successor's own first bucket above it — buckets
above that point belong to the successor's own span, which the ordinary repair walk covers, so
the coverage gate leaves them out on purpose.

No existing test seeded a NON-empty successor that has a hole inside its OWN span (above its
first bucket past the legacy). That left an untested edge: if the seam probe's upper bound ever
stopped tracking the successor's own floor and instead always fell back to a fixed offset from
now, the probe would start walking past the successor's floor and could either miss real holes
above it or wrongly flag buckets the ordinary repair path already owns.

What changes

Test-only. Adds one live pin to FrozenRollupLiveTests:
Upgrade_NonEmptySuccessor_HoleInItsOwnSpan_SeamProbeStopsAtItsFirstBucket_RawPurgeStaysCovered.

It seeds a legacy frozen a few days back, a successor whose first bucket immediately above the
legacy is materialized (a gap-free seam), a later successor bucket materialized as well, and a
real hole in between — inside the successor's own span, above its first bucket. It asserts the
hole genuinely exists (raw admits a row for that hour; neither the legacy nor the successor
materialized it) and then asserts the raw-purge coverage check still reports Covered for
procedure_stats, proving the seam probe stops at the successor's first bucket and never reaches
into the successor's own span.

Test plan

  • FrozenRollupLiveTests (whole class): GREEN, 29/29, against a local TimescaleDB container.
  • DocCommentHygieneTests: GREEN, 77/77.
  • Both Darling.Tests and Lite.Tests build 0 errors with EnableWindowsTargeting=true.
  • Mutation proof: temporarily changed the coverage stitch's toExpr (dropping the
    COALESCE's first argument, so the upper bound always falls back to
    time_bucket('1 hour', now() - HourlyRefreshStartOffset) - INTERVAL '1 hour' instead of the
    successor's own first bucket above the legacy) and reran the new pin alone: it failed
    (Assert.True() Failure on the final IsRawTierDropSafeAsync assertion — the fallback bound
    sits far below the deliberately unmaterialized hour in this test's setup, so the seam probe
    walked into the successor's own span and found the hole, reporting the slot Short). Restored
    the original line, rebuilt, and reran: GREEN again, confirming the mutation is what the pin
    catches. No runtime RED against unmodified dev is possible for a pin of correct code; the
    mutation is the proof.

CHANGELOG entry

SECTION: None
ENTRY: None: test-only change, no user-visible effect.

@erikdarlingdata
erikdarlingdata marked this pull request as ready for review September 26, 2026 19:22
@erikdarlingdata
erikdarlingdata merged commit 49761f9 into dev Sep 26, 2026
15 of 16 checks passed
@erikdarlingdata
erikdarlingdata deleted the test/4406-seam-probe-stops-at-successor-floor branch September 26, 2026 19:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant