Skip to content

medium(iceberg): version-hint.text is updated even when the v<N>.metadata.json copy failed — breaks working directory readers #636

Description

@xe-nvdk

Found during the 2026-08-20 adversarial audit of the Iceberg export subsystem.

Problem

writeVersionHint (internal/iceberg/exporter.go:611-631): when the metadata read (line ~614) or the v<N>.metadata.json copy (line ~619) fails, okAll is set false but execution falls through and writes version-hint.text anyway (lines ~627-631). The hint then says N while vN.metadata.json doesn't exist — the exact "metadata file for version N missing" failure the function's own doc-comment says was empirically verified to break both DuckDB and Spark directory readers.

Failure scenario

Before the pass, readers had a stale-but-working N-1 hint/metadata pair. One transient failure — ENOSPC is the realistic one: the tiny hint write succeeds where the metadata-sized write fails — flips them to a broken pair for a full reconcile interval. The retry machinery (hintOK=false → fingerprint uncached → next-pass retry) bounds the damage but doesn't prevent it.

Fix shape

Skip the hint update when the metadata copy failed — the publishing order exists precisely so the pair stays consistent. Keep okAll=false so the pass retries.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions