Skip to content

feat: publish records and provenance checkpoints atomically - #231

Closed
vinceblock99 wants to merge 4 commits into
devfrom
feat/atomic-redb-publication
Closed

vinceblock99 wants to merge 4 commits into
devfrom
feat/atomic-redb-publication

Conversation

@vinceblock99

Copy link
Copy Markdown
Contributor

Separate commits can leave change objects, graph state, and provenance out of sync after a crash. This PR makes each record and each provenance checkpoint commit its related state together, and recovers interrupted agent turns.

  • Store canonical change/provenance objects in atomic.redb and publish them with the corresponding graph or session updates.
  • Commit durable ID allocation and outbox entries with the operation.
  • Recover committed agent work without losing change references, duplicating completed checkpoints, or consuming newer working edits.

Validation of this source tree: 9,139 tests passed (243 ignored), Clippy, rustdoc and formatting checks; real go-uuid migration and Codex hook workflows, including eight crash-recovery points. The branch source tree is identical to the tested version.

Draft follow-up to #230. Targets feat/atomic-redb to isolate this work; retarget to dev after #230 merges. Protobuf/RPC contracts are unchanged.

Repositories kept graph state in .atomic/pristine.redb and the provenance
journal in .atomic/changes.redb. Both now live in one .atomic/atomic.redb.

- atomic-core: a registry of every table (pristine/schema.rs) with a schema
  version in the new atomic_meta table. LegacyDatabases::merge_into copies
  each table through its typed definition into a fresh file, verifies a
  per-table digest against the source, refuses unknown non-empty tables, and
  leaves retired tables (stacks, channels, file_mtimes) behind.
- atomic-repository: ensure_database merges a legacy layout on first open
  (atomic.redb.merging -> atomic.redb; old files kept in .atomic/legacy/<ts>/)
  and finishes an interrupted retirement. Concurrent openers serialize on the
  legacy file lock. open/open_existing/open_readonly wait up to 5s for a
  busy database. The change store can share the repository's redb handle
  (Repository::redb_change_store) or open an existing file without creating
  it.
- atomic agent database-owner: opens atomic.redb only while serving a store
  request. Startup, Ping and Shutdown never touch it, so the owner no longer
  locks other atomic processes out of the repository.
- hooks: close the repository before acknowledging a checkpoint, since the
  owner now opens the same file.
Base automatically changed from feat/atomic-redb to dev October 6, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant