Follow-up to the spoke-namespace tiering registration fix (see #686 review notes and the PR that closes this gap).
Spoke-namespace files now register with tiering but are gated out of hot-to-cold migration in FindCandidates. Reason: legacy spoke-side compacted files sync once by design (#610) and carry sync_received receipts. Migrating one deletes its hot copy; confirmPresent's existence check then forgets the receipt (the row is not marked compacted_at, since hub compaction never consumed the file), the spoke re-offers it, and the hub re-accepts a duplicate next to the cold copy. This is the #611 hazard class, for migration instead of compaction.
What shipping spoke cold migration needs
- A migrated-receipt marking analogous to
compacted_at (e.g. migrated_at on sync_received, or reuse of the compacted marking) applied to receipts of files the migrator deletes from hot, so confirmPresent treats them as present without an existence check and re-delivery of the same path+sha stays a no-op.
- The migrator learning to mark receipts through the hub index for spoke-namespaced paths (spoke ID = first path segment).
- Query-side verification that multi-tier assembly unions cold spoke data correctly under the (spoke, spoke-db) naming, including partition pruning at the spoke depth (today spoke queries run unpruned by design; pruning them is optional but would need namespace-aware path generation).
- Lift the
FindCandidates gate and cover the two-cycle lifecycle (migrate, re-offer, no duplicate) in an integration test with sync_received rows.
Follow-up to the spoke-namespace tiering registration fix (see #686 review notes and the PR that closes this gap).
Spoke-namespace files now register with tiering but are gated out of hot-to-cold migration in
FindCandidates. Reason: legacy spoke-side compacted files sync once by design (#610) and carrysync_receivedreceipts. Migrating one deletes its hot copy;confirmPresent's existence check then forgets the receipt (the row is not markedcompacted_at, since hub compaction never consumed the file), the spoke re-offers it, and the hub re-accepts a duplicate next to the cold copy. This is the #611 hazard class, for migration instead of compaction.What shipping spoke cold migration needs
compacted_at(e.g.migrated_atonsync_received, or reuse of the compacted marking) applied to receipts of files the migrator deletes from hot, soconfirmPresenttreats them as present without an existence check and re-delivery of the same path+sha stays a no-op.FindCandidatesgate and cover the two-cycle lifecycle (migrate, re-offer, no duplicate) in an integration test withsync_receivedrows.