writeonce/database/src
shoney.arickathil 7b39da7eb6 fix(db2-keys): a logged delete must replay on a keys-resident table
- wo_row_remove's keys arm borrows the row from the log to find its
  index entries, and a borrow reads through db->rt->wal. At boot that
  pointer is not wired yet: main.c replays first (main.c:226) and
  assigns rt.wal afterwards (main.c:268)
- so the borrow found no log, the remove failed, and replay reported a
  valid tombstone as CORRUPTION. An UPDATE record would have failed the
  same way, since replay applies it as remove-then-recreate
- replay now lends the runtime a read-only view over the fd it already
  has open, for the replay's duration only, and restores what was there
- broken by the delete fix in 76b8fd9 — deletes worked in-process but
  their tombstones broke the next boot. Unreachable in production only
  because the loader still refuses the annotation
- pinned by test_keys_resident_delete_then_replay, verified failing
  against the unfixed code (2 failures) and clean with it
- found by asking whether the read-modify-append plan was ready, not by
  a gate

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit dc25462461b9f79d70c803f7174adc90fa16c90e)
2026-08-30 20:37:27 +02:00
..
CODE-LOGIC.md Merge master into db-residency-doctrine — and close the two half-exposed features 2026-08-29 10:14:25 +02:00
db.c feat(db2-keys): the query paths read through the iterator and borrow 2026-08-30 20:36:31 +02:00
db.h feat: arc stage 3 T7 — transparent DB actor (WO_T_DB hole closed) 2026-08-21 13:10:26 +02:00
table.c fix(db2-keys): delete on a keys-resident table was memory corruption 2026-08-30 20:37:27 +02:00
table.h feat(db2-keys): rewire remaining readers, survive compaction 2026-08-30 20:36:31 +02:00
wal.c fix(db2-keys): a logged delete must replay on a keys-resident table 2026-08-30 20:37:27 +02:00
wal.h feat(db2-keys): inserts and boot — payload dropped after the barrier 2026-08-30 20:36:31 +02:00