Repository navigation
Pin that the raw-purge seam probe stops at the successor's first bucket (#4406) - #4443
Merged
erikdarlingdata merged 1 commit intoSep 26, 2026
Merged
Conversation
…he legacy's end (#4406)
erikdarlingdata
marked this pull request as ready for review
September 26, 2026 19:22
erikdarlingdata
deleted the
test/4406-seam-probe-stops-at-successor-floor
branch
September 26, 2026 19:22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #4406.
Why
The raw-purge coverage check for a legacy/successor pair stitches the two together so an
upgrading store's empty successor doesn't hold the purge forever. The stitch only probes the
seam between the legacy's last bucket and the successor's own first bucket above it — buckets
above that point belong to the successor's own span, which the ordinary repair walk covers, so
the coverage gate leaves them out on purpose.
No existing test seeded a NON-empty successor that has a hole inside its OWN span (above its
first bucket past the legacy). That left an untested edge: if the seam probe's upper bound ever
stopped tracking the successor's own floor and instead always fell back to a fixed offset from
now, the probe would start walking past the successor's floor and could either miss real holes
above it or wrongly flag buckets the ordinary repair path already owns.
What changes
Test-only. Adds one live pin to
FrozenRollupLiveTests:Upgrade_NonEmptySuccessor_HoleInItsOwnSpan_SeamProbeStopsAtItsFirstBucket_RawPurgeStaysCovered.It seeds a legacy frozen a few days back, a successor whose first bucket immediately above the
legacy is materialized (a gap-free seam), a later successor bucket materialized as well, and a
real hole in between — inside the successor's own span, above its first bucket. It asserts the
hole genuinely exists (raw admits a row for that hour; neither the legacy nor the successor
materialized it) and then asserts the raw-purge coverage check still reports Covered for
procedure_stats, proving the seam probe stops at the successor's first bucket and never reachesinto the successor's own span.
Test plan
FrozenRollupLiveTests(whole class): GREEN, 29/29, against a local TimescaleDB container.DocCommentHygieneTests: GREEN, 77/77.Darling.TestsandLite.Testsbuild 0 errors withEnableWindowsTargeting=true.toExpr(dropping theCOALESCE's first argument, so the upper bound always falls back totime_bucket('1 hour', now() - HourlyRefreshStartOffset) - INTERVAL '1 hour'instead of thesuccessor's own first bucket above the legacy) and reran the new pin alone: it failed
(
Assert.True() Failureon the finalIsRawTierDropSafeAsyncassertion — the fallback boundsits far below the deliberately unmaterialized hour in this test's setup, so the seam probe
walked into the successor's own span and found the hole, reporting the slot Short). Restored
the original line, rebuilt, and reran: GREEN again, confirming the mutation is what the pin
catches. No runtime RED against unmodified dev is possible for a pin of correct code; the
mutation is the proof.
CHANGELOG entry
SECTION: None
ENTRY: None: test-only change, no user-visible effect.