Skip to content

feat(email): add dedicated system email graph - #1162

Merged
kentcdodds merged 6 commits into
mainfrom
cursor/mailbox-step4-system-email-split
Aug 2, 2026
Merged

kentcdodds merged 6 commits into
mainfrom
cursor/mailbox-step4-system-email-split

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Aug 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adds the non-destructive step-4a deploy boundary for operator-owned email:

  • dedicated system_email_threads/messages/attachments/delivery_events tables
  • FK-safe copy of legacy system:email rows; no legacy mutation/deletion
  • forced, audited, atomic system_email_graph_reconcile catch-up action
  • no-content graph/reference/provider parity on maintenance status
  • ownership fences for shared inbox/sender references
  • complete column/schema/FK/CHECK drift guards

Live reads/writes remain on legacy tables until step 4b after production copy verification.

System recap — extends D1 operator email placement (medium risk)

Mode: recap · Base: main @ 61874c4e · Head: a3897236

Classification: extends — adds a dedicated D1 home and reconciliation gate for the existing operator-email primitive; no new top-level primitive.

Primitives touched

Primitive Group Impact
d1-app-db storage extends — four operator-only graph tables and indexes
email assistant extends — copy/reconcile/parity contracts
rbac auth composes — forced admin reconciliation action

System map

Legacy system-email authority is copied and atomically reconciled into a dedicated operator graph before step-4b routing.

Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).

flowchart LR
  legacy["d1-app-db<br/>Legacy system:email rows"]:::extended
  graph["d1-app-db<br/>Dedicated system_email_* graph"]:::extended
  admin["rbac<br/>Admin maintenance"]:::touched
  index["email<br/>Provider reverse index"]:::untouched
  legacy -->|"migration copy + forced atomic reconcile"| graph
  admin -->|"status parity / force:true repair"| graph
  index -->|"legacy authority disposition until 4b"| legacy
  classDef touched fill:#1a7f37,color:#fff
  classDef extended fill:#9a6700,color:#fff
  classDef added fill:#cf222e,color:#fff
  classDef untouched fill:#57606a,color:#fff
Loading

Invariants

  • No legacy rows are deleted or modified.
  • USER rows never enter dedicated operator tables.
  • Cross-owner inbox/sender references make parity fail and are not copied.
  • Reconcile is explicit force:true, audited, atomic, and followed by parity.
  • Step 4b requires quiesced writes or active dual-write plus forced reconcile and zero mismatch.

Verification

  • CI at a3897236: all required jobs pass; Bugbot passes
  • Dedicated graph retention finding fixed: scheduled legacy retention now atomically reconciles the dedicated copy; expired/over-cap/orphan integration coverage passes
  • Reconcile-error suggestion refuted: dedicated catch-up is part of the retention lane contract; throwing activates scheduled-lane failure logging/Sentry and retry instead of falsely reporting a complete successful lane. Legacy retention commits remain idempotent, so the next run safely retries graph reconciliation.
  • 23 focused migration/reconcile/parity/provider/admin tests pass
  • Full column metadata, FK actions, and required CHECK enums are drift-guarded
  • Typecheck, format, lint, migration ledger, docs, MCP, and E2E checks pass locally (parallel-only unrelated timeout flakes passed isolated)
  • Two independent reviews: catch-up/ownership/schema/provider/bind findings addressed; no remaining blocker

Conductor report

  • STATUS: done
  • Sequence step: 4a additive system-email schema/backfill/parity
  • Risk: medium, non-destructive; legacy remains authority
  • Backup gate: verified sha256 7787f8c9… remains recorded
  • Merged/deployed: pending self-merge — PR #1162
  • Next: self-merge/deploy, production forced reconcile + parity, then fresh step-4b authority branch

Cursor ManagePullRequest is pinned to the original run branch; this fresh-branch PR uses the authenticated Kent helper.


Note

Medium Risk
Non-destructive additive schema and copy-only path, but it touches operator mail storage, atomic reconcile batches, and retention ordering; legacy authority is unchanged until 4b, with explicit parity gates before cutover.

Overview
Introduces migration 0130 and four operator-only D1 tables (system_email_threads, system_email_messages, system_email_attachments, system_email_delivery_events) that mirror legacy system:email graph rows without user_id. The migration copies valid legacy rows in FK order; legacy tables remain live read/write and retention authority until step 4b.

Reconciliation and parity: reconcileSystemEmailGraphFromLegacy runs one atomic D1 batch (child-first deletes, parent-first upserts) with fences so cross-owner inbox/sender/thread references are skipped and keep parity false. Aggregate-only parity reports (counts and mismatch classes, no message content) cover the graph plus outbound provider index disposition legacy-email-messages-until-4b-routing.

Operations: Admin mailbox maintenance status now includes systemEmailGraph; a new audited action system_email_graph_reconcile requires force: true. Scheduled system-email retention still prunes legacy first; on success it reconciles the dedicated copy and skips reconcile when legacy blob deletes fail.

Account lifecycle: accountOperatorOwnedD1Surfaces and export exclusions document the dedicated tables alongside existing system:email exclusions; retention dispositions mark the four tables as alternate_cleanup in step 4a.

Reviewed by Cursor Bugbot for commit a389723. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added dedicated storage for operator system email threads, messages, attachments, and delivery events.
    • Added administrator reporting to compare system email data and identify synchronization mismatches.
    • Added a controlled administrator reconciliation action to repair discrepancies and report results.
  • Data Management

    • System email records remain protected by ownership and relationship validation.
    • Account exports and deletion workflows exclude operator-owned system email data.
    • Added retention synchronization and warnings for dedicated system email records.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented Aug 2, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This change adds dedicated operator-owned system-email graph tables, copies valid legacy records, reports parity, and supports atomic reconciliation. It also updates account export, retention, migration tracking, and admin mailbox maintenance interfaces.

Changes

System email graph expansion

Layer / File(s) Summary
Graph schema and migration contract
packages/worker/migrations/0130-system-email-graph-expand.sql, packages/worker/src/email/system-email-graph-columns.ts, packages/worker/src/email/system-email-graph-sql.ts, packages/worker/src/email/system-email-graph-migration.node.test.ts, packages/worker/src/email/test-schema.ts, tools/migration-ledger.json, docs/contributing/architecture/data-storage.md
Adds four dedicated graph tables and indexes. Copies valid system-owned legacy records idempotently. Defines shared column contracts, validation SQL, constraints, and migration coverage.
Parity reporting and reconciliation
packages/worker/src/email/system-email-graph-repo.ts, packages/worker/src/email/system-email-graph-repo.node.test.ts, packages/worker/src/email/outbound-provider-index.ts, packages/worker/src/email/outbound-provider-index.node.test.ts
Adds graph and provider-index parity reports. Reconciliation deletes drift in dependency order, upserts valid legacy data, and returns mutation and ownership metrics.
Account and retention boundaries
packages/worker/src/account/data-targets.ts, packages/worker/src/account/data-targets.node.test.ts, packages/worker/src/app/account-retention-dispositions.ts, packages/worker/src/app/account-retention-dispositions.node.test.ts, packages/worker/src/email/system-email.ts, packages/worker/src/email/system-email.workers.test.ts, packages/worker/src/email/system-email-retention-graph.workers.test.ts, docs/contributing/architecture/data-storage.md
Marks dedicated system-email tables as operator-owned account export and deletion exclusions. Adds alternate-cleanup retention dispositions and synchronizes the dedicated graph after legacy retention.
Admin status and reconciliation action
packages/worker/src/admin/mailbox-maintenance.ts, packages/worker/src/admin/mailbox-maintenance.node.test.ts, packages/worker/src/mcp/capabilities/admin/admin-mailbox-maintenance.ts, packages/worker/src/mcp/capabilities/admin/admin-mailbox-maintenance.node.test.ts
Adds graph parity to mailbox maintenance status. Adds a forced, audited system_email_graph_reconcile action with reconciliation metrics and post-reconciliation parity.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Admin as Admin MCP action
  participant Maintenance as Mailbox maintenance
  participant Repo as System email graph repository
  participant Legacy as Legacy email tables
  participant Dedicated as Dedicated system email tables

  Admin->>Maintenance: submit system_email_graph_reconcile with force=true
  Maintenance->>Repo: reconcile graph from legacy
  Repo->>Legacy: read validated authoritative records
  Repo->>Dedicated: delete drift and upsert records
  Repo->>Repo: reload parity report
  Repo-->>Maintenance: return metrics and parity
  Maintenance-->>Admin: return audited reconciliation result
Loading

Possibly related PRs

  • kentcdodds/kody#1124: Shares the system-email graph tables and delivery-event/provider-index data.
  • kentcdodds/kody#1139: Shares the admin mailbox maintenance service and MCP capability.
  • kentcdodds/kody#1152: Shares system-email graph parity, reconciliation, retention, and mailbox migration infrastructure.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 11.43% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the primary change: adding a dedicated system email graph.
Description check ✅ Passed The description explains the intent, changes, system impact, risks, and testing through equivalent sections, despite using Verification instead of Testing.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/mailbox-step4-system-email-split

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

cursoragent and others added 2 commits August 2, 2026 22:49
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds marked this pull request as ready for review August 2, 2026 22:54
@github-actions

github-actions Bot commented Aug 2, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-1162.kody-a99.workers.dev

Worker: kody-pr-1162
D1: kody-pr-1162-db
KV: kody-pr-1162-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (2)
packages/worker/src/email/system-email-graph-repo.ts (1)

301-322: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Derive the batch result offsets from the contract list.

mutationCounts and deletedMutationCounts both encode the statement layout as literal indices, and the caller passes the literal offset 4 at line 361. The mapping is correct today because systemEmailGraphColumnContracts has exactly four entries in threads → messages → attachments → deliveryEvents order. If a fifth table joins the contract, all three sites break silently and report metrics against the wrong table. Key the counts off the contract array instead.

♻️ Proposed refactor to key metrics by contract
-function mutationCounts(
-	results: ReadonlyArray<D1Result<unknown>>,
-	offset: number,
-): SystemEmailGraphMutationCounts {
-	return {
-		threads: Number(results[offset]?.meta.changes ?? 0),
-		messages: Number(results[offset + 1]?.meta.changes ?? 0),
-		attachments: Number(results[offset + 2]?.meta.changes ?? 0),
-		deliveryEvents: Number(results[offset + 3]?.meta.changes ?? 0),
-	}
-}
-
-function deletedMutationCounts(
-	results: ReadonlyArray<D1Result<unknown>>,
-): SystemEmailGraphMutationCounts {
-	return {
-		threads: Number(results[3]?.meta.changes ?? 0),
-		messages: Number(results[2]?.meta.changes ?? 0),
-		attachments: Number(results[1]?.meta.changes ?? 0),
-		deliveryEvents: Number(results[0]?.meta.changes ?? 0),
-	}
-}
+function mutationCounts(
+	results: ReadonlyArray<D1Result<unknown>>,
+	order: ReadonlyArray<SystemEmailGraphColumnContract>,
+	offset: number,
+): SystemEmailGraphMutationCounts {
+	const counts: SystemEmailGraphMutationCounts = {
+		threads: 0,
+		messages: 0,
+		attachments: 0,
+		deliveryEvents: 0,
+	}
+	for (const [index, contract] of order.entries()) {
+		counts[contract.key] = Number(results[offset + index]?.meta.changes ?? 0)
+	}
+	return counts
+}

Then update the caller:

 	const results = await input.db.batch<unknown>(statements)
 	const postReport = await loadSystemEmailGraphParityReport({ db: input.db })
 	return {
 		metrics: {
-			deleted: deletedMutationCounts(results),
-			upserted: mutationCounts(results, 4),
+			deleted: mutationCounts(results, childFirst, 0),
+			upserted: mutationCounts(
+				results,
+				systemEmailGraphColumnContracts,
+				childFirst.length,
+			),
 			referencedOwnerMismatchCount: referencedOwnerMismatchCount(postReport),
 		},
 		postReport,
 	}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/email/system-email-graph-repo.ts` around lines 301 - 322,
Update mutationCounts, deletedMutationCounts, and their caller to derive result
positions from systemEmailGraphColumnContracts instead of literal indices and
the hard-coded offset 4. Preserve the existing threads, messages, attachments,
and deliveryEvents mapping while making it automatically follow the contract
list order and length when additional tables are added.
packages/worker/src/email/system-email-graph-repo.node.test.ts (1)

255-285: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick win

Add coverage for the message-delete cascade into attachments.

The drift scenario deletes a thread row and an attachment row, but never a system_email_messages row. system_email_attachments.message_id declares ON DELETE CASCADE in packages/worker/migrations/0130-system-email-graph-expand.sql at lines 102-103. When delete-drift removes a dedicated message, SQLite cascades into system_email_attachments, and those cascaded rows are not counted in the statement changes value that deletedMutationCounts reads. The reported deleted.attachments metric then under-reports, and that metric reaches operators through admin_mailbox_maintenance.

Seed a legacy message that becomes invalid while it still has a dedicated attachment, then assert both the resulting row state and the reported metric. This pins the intended metric semantics before step 4b.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/email/system-email-graph-repo.node.test.ts` around lines
255 - 285, Extend the reconcileSystemEmailGraphFromLegacy test scenario to seed
a legacy message that becomes invalid while retaining a dedicated attachment,
causing message deletion to cascade to system_email_attachments. Assert the
cascaded attachment is absent from the final database state and that
repaired.metrics.deleted.attachments includes the cascaded deletion, alongside
the existing row-state and metric assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/app/account-retention-dispositions.ts`:
- Around line 34-57: Update the step 4a retention flow and its account-retention
disposition handling to actively clean dedicated system-email tables instead of
marking them only as alternate_cleanup. Apply the existing 90-day and
5,000-message retention rules to system_email_messages and
system_email_delivery_events, and remove orphaned system_email_attachments and
system_email_threads using the established cleanup helpers. Add an integration
test that inserts dedicated records and verifies the cleanup executes before
step 4b.

---

Nitpick comments:
In `@packages/worker/src/email/system-email-graph-repo.node.test.ts`:
- Around line 255-285: Extend the reconcileSystemEmailGraphFromLegacy test
scenario to seed a legacy message that becomes invalid while retaining a
dedicated attachment, causing message deletion to cascade to
system_email_attachments. Assert the cascaded attachment is absent from the
final database state and that repaired.metrics.deleted.attachments includes the
cascaded deletion, alongside the existing row-state and metric assertions.

In `@packages/worker/src/email/system-email-graph-repo.ts`:
- Around line 301-322: Update mutationCounts, deletedMutationCounts, and their
caller to derive result positions from systemEmailGraphColumnContracts instead
of literal indices and the hard-coded offset 4. Preserve the existing threads,
messages, attachments, and deliveryEvents mapping while making it automatically
follow the contract list order and length when additional tables are added.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: d9567dc5-838c-4df5-9110-22fb8421bf13

📥 Commits

Reviewing files that changed from the base of the PR and between 61874c4 and 7c271a3.

📒 Files selected for processing (18)
  • docs/contributing/architecture/data-storage.md
  • packages/worker/migrations/0130-system-email-graph-expand.sql
  • packages/worker/src/account/data-targets.node.test.ts
  • packages/worker/src/account/data-targets.ts
  • packages/worker/src/admin/mailbox-maintenance.node.test.ts
  • packages/worker/src/admin/mailbox-maintenance.ts
  • packages/worker/src/app/account-retention-dispositions.node.test.ts
  • packages/worker/src/app/account-retention-dispositions.ts
  • packages/worker/src/email/outbound-provider-index.node.test.ts
  • packages/worker/src/email/outbound-provider-index.ts
  • packages/worker/src/email/system-email-graph-columns.ts
  • packages/worker/src/email/system-email-graph-migration.node.test.ts
  • packages/worker/src/email/system-email-graph-repo.node.test.ts
  • packages/worker/src/email/system-email-graph-repo.ts
  • packages/worker/src/email/system-email-graph-sql.ts
  • packages/worker/src/mcp/capabilities/admin/admin-mailbox-maintenance.node.test.ts
  • packages/worker/src/mcp/capabilities/admin/admin-mailbox-maintenance.ts
  • tools/migration-ledger.json

Comment on lines +34 to +57
{
table: 'system_email_delivery_events',
kind: 'alternate_cleanup',
reason:
'Operator-owned D1 delivery events are excluded from account retention; step 4b will route the existing 90-day system-email retention policy to this dedicated table.',
},
{
table: 'system_email_messages',
kind: 'alternate_cleanup',
reason:
'Operator-owned D1 messages are excluded from account retention; step 4b will route the existing 90-day age and 5,000-message system cap to this dedicated table.',
},
{
table: 'system_email_attachments',
kind: 'alternate_cleanup',
reason:
'Operator-owned D1 attachment metadata follows dedicated system messages; step 4b will delete it through the routed system-email retention path.',
},
{
table: 'system_email_threads',
kind: 'alternate_cleanup',
reason:
'Operator-owned D1 threads are pruned when orphaned by dedicated system-message retention; routing begins in step 4b.',
},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Add active cleanup before using alternate_cleanup.

Lines 38, 44, 50, and 56 state that cleanup routing starts in step 4b. Step 4a copies legacy records into separate dedicated tables. Legacy retention deletes cannot remove these dedicated copies. The copied messages and attachment metadata can exceed the 90-day and 5,000-message limits if step 4b is delayed.

Run equivalent retention and orphan cleanup for the dedicated tables during step 4a. Add an integration test that executes the cleanup against dedicated records.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/app/account-retention-dispositions.ts` around lines 34 -
57, Update the step 4a retention flow and its account-retention disposition
handling to actively clean dedicated system-email tables instead of marking them
only as alternate_cleanup. Apply the existing 90-day and 5,000-message retention
rules to system_email_messages and system_email_delivery_events, and remove
orphaned system_email_attachments and system_email_threads using the established
cleanup helpers. Add an integration test that inserts dedicated records and
verifies the cleanup executes before step 4b.

cursoragent and others added 2 commits August 2, 2026 23:06
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/email/system-email.ts`:
- Around line 491-523: Guard the reconcileSystemEmailGraphFromLegacy call in
pruneSystemEmailRetention with try/catch so unexpected reconciliation failures
do not reject the already-completed retention work; record dedicatedGraphSync as
skipped with the thrown error’s reason, push a dedicated reconciliation-failure
warning, log the failure, and return the result. Extend the
SystemEmailRetentionResult skipped-reason union to include this new failure
reason, preserving the existing blob-delete-errors handling.

In `@packages/worker/src/email/test-schema.ts`:
- Around line 271-327: Update the test schema for system_email_delivery_events
to create the same unique partial provider_event_id index as the legacy table,
preserving the condition that excludes NULL values. Check migration
0130-system-email-graph-expand.sql for the canonical index name and definition,
then add the equivalent index alongside the CREATE TABLE statement in the test
schema.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 530dbe4a-5511-45b9-92ae-9aa3c70e2020

📥 Commits

Reviewing files that changed from the base of the PR and between 7c271a3 and e54d694.

📒 Files selected for processing (8)
  • docs/contributing/architecture/data-storage.md
  • packages/worker/src/app/account-retention-dispositions.node.test.ts
  • packages/worker/src/app/account-retention-dispositions.ts
  • packages/worker/src/email/system-email-graph-repo.node.test.ts
  • packages/worker/src/email/system-email-retention-graph.workers.test.ts
  • packages/worker/src/email/system-email.ts
  • packages/worker/src/email/system-email.workers.test.ts
  • packages/worker/src/email/test-schema.ts
🚧 Files skipped from review as they are similar to previous changes (4)
  • packages/worker/src/app/account-retention-dispositions.node.test.ts
  • packages/worker/src/app/account-retention-dispositions.ts
  • packages/worker/src/email/system-email-graph-repo.node.test.ts
  • docs/contributing/architecture/data-storage.md

Comment on lines +491 to +523
if (result.blobDeleteErrors > 0) {
result.dedicatedGraphSync = {
status: 'skipped',
reason: 'legacy-blob-delete-errors',
blobDeleteErrors: result.blobDeleteErrors,
}
result.warnings.push('dedicated-graph-sync-skipped')
console.warn('system-email-dedicated-graph-sync-skipped', {
reason: 'legacy-blob-delete-errors',
blobDeleteErrors: result.blobDeleteErrors,
})
return result
}

const graphSync = await reconcileSystemEmailGraphFromLegacy({ db: input.db })
result.dedicatedGraphSync = {
status: 'reconciled',
upserted: graphSync.metrics.upserted,
deleted: graphSync.metrics.deleted,
referencedOwnerMismatchCount:
graphSync.metrics.referencedOwnerMismatchCount,
parity: graphSync.postReport.parity,
}
if (!graphSync.postReport.parity) {
result.warnings.push('dedicated-graph-post-reconcile-mismatch')
console.warn('system-email-dedicated-graph-post-reconcile-mismatch', {
referencedOwnerMismatchCount:
graphSync.metrics.referencedOwnerMismatchCount,
upserted: graphSync.metrics.upserted,
deleted: graphSync.metrics.deleted,
})
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Guard reconcileSystemEmailGraphFromLegacy against unexpected failures.

Line 505 calls reconcileSystemEmailGraphFromLegacy with no try/catch. If this call throws (D1 batch failure, constraint violation, transient error), the entire pruneSystemEmailRetention promise rejects. All legacy retention work already committed above (age-based deletes, over-cap deletes, delivery-event deletes, thread cleanup) is lost from the caller's view, and no warnings entry or dedicatedGraphSync status records the failure.

This differs from the blobDeleteErrors > 0 branch, which explicitly records a skipped status, pushes a warning, and returns instead of throwing. An unhandled reconciliation error causes a harder failure than the exact case this function was written to tolerate gracefully.

Wrap the reconciliation call the same way, and extend the skipped reason union in SystemEmailRetentionResult (Lines 358-362) to cover this case.

🛡️ Proposed fix to guard the reconciliation call
 	dedicatedGraphSync:
 		| {
 				status: 'reconciled'
 				upserted: SystemEmailGraphMutationCounts
 				deleted: SystemEmailGraphMutationCounts
 				referencedOwnerMismatchCount: number
 				parity: boolean
 		  }
 		| {
 				status: 'skipped'
-				reason: 'legacy-blob-delete-errors'
+				reason: 'legacy-blob-delete-errors' | 'reconcile-error'
 				blobDeleteErrors: number
 		  }
-	const graphSync = await reconcileSystemEmailGraphFromLegacy({ db: input.db })
-	result.dedicatedGraphSync = {
-		status: 'reconciled',
-		upserted: graphSync.metrics.upserted,
-		deleted: graphSync.metrics.deleted,
-		referencedOwnerMismatchCount:
-			graphSync.metrics.referencedOwnerMismatchCount,
-		parity: graphSync.postReport.parity,
-	}
-	if (!graphSync.postReport.parity) {
-		result.warnings.push('dedicated-graph-post-reconcile-mismatch')
-		console.warn('system-email-dedicated-graph-post-reconcile-mismatch', {
-			referencedOwnerMismatchCount:
-				graphSync.metrics.referencedOwnerMismatchCount,
-			upserted: graphSync.metrics.upserted,
-			deleted: graphSync.metrics.deleted,
-		})
-	}
+	try {
+		const graphSync = await reconcileSystemEmailGraphFromLegacy({
+			db: input.db,
+		})
+		result.dedicatedGraphSync = {
+			status: 'reconciled',
+			upserted: graphSync.metrics.upserted,
+			deleted: graphSync.metrics.deleted,
+			referencedOwnerMismatchCount:
+				graphSync.metrics.referencedOwnerMismatchCount,
+			parity: graphSync.postReport.parity,
+		}
+		if (!graphSync.postReport.parity) {
+			result.warnings.push('dedicated-graph-post-reconcile-mismatch')
+			console.warn('system-email-dedicated-graph-post-reconcile-mismatch', {
+				referencedOwnerMismatchCount:
+					graphSync.metrics.referencedOwnerMismatchCount,
+				upserted: graphSync.metrics.upserted,
+				deleted: graphSync.metrics.deleted,
+			})
+		}
+	} catch (error) {
+		result.dedicatedGraphSync = {
+			status: 'skipped',
+			reason: 'reconcile-error',
+			blobDeleteErrors: 0,
+		}
+		result.warnings.push('dedicated-graph-sync-skipped')
+		console.warn('system-email-dedicated-graph-sync-skipped', {
+			reason: 'reconcile-error',
+			error,
+		})
+	}

Do you want me to open an issue to track this and add a corresponding test case that simulates a reconciliation failure?

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
if (result.blobDeleteErrors > 0) {
result.dedicatedGraphSync = {
status: 'skipped',
reason: 'legacy-blob-delete-errors',
blobDeleteErrors: result.blobDeleteErrors,
}
result.warnings.push('dedicated-graph-sync-skipped')
console.warn('system-email-dedicated-graph-sync-skipped', {
reason: 'legacy-blob-delete-errors',
blobDeleteErrors: result.blobDeleteErrors,
})
return result
}
const graphSync = await reconcileSystemEmailGraphFromLegacy({ db: input.db })
result.dedicatedGraphSync = {
status: 'reconciled',
upserted: graphSync.metrics.upserted,
deleted: graphSync.metrics.deleted,
referencedOwnerMismatchCount:
graphSync.metrics.referencedOwnerMismatchCount,
parity: graphSync.postReport.parity,
}
if (!graphSync.postReport.parity) {
result.warnings.push('dedicated-graph-post-reconcile-mismatch')
console.warn('system-email-dedicated-graph-post-reconcile-mismatch', {
referencedOwnerMismatchCount:
graphSync.metrics.referencedOwnerMismatchCount,
upserted: graphSync.metrics.upserted,
deleted: graphSync.metrics.deleted,
})
}
if (result.blobDeleteErrors > 0) {
result.dedicatedGraphSync = {
status: 'skipped',
reason: 'legacy-blob-delete-errors',
blobDeleteErrors: result.blobDeleteErrors,
}
result.warnings.push('dedicated-graph-sync-skipped')
console.warn('system-email-dedicated-graph-sync-skipped', {
reason: 'legacy-blob-delete-errors',
blobDeleteErrors: result.blobDeleteErrors,
})
return result
}
try {
const graphSync = await reconcileSystemEmailGraphFromLegacy({
db: input.db,
})
result.dedicatedGraphSync = {
status: 'reconciled',
upserted: graphSync.metrics.upserted,
deleted: graphSync.metrics.deleted,
referencedOwnerMismatchCount:
graphSync.metrics.referencedOwnerMismatchCount,
parity: graphSync.postReport.parity,
}
if (!graphSync.postReport.parity) {
result.warnings.push('dedicated-graph-post-reconcile-mismatch')
console.warn('system-email-dedicated-graph-post-reconcile-mismatch', {
referencedOwnerMismatchCount:
graphSync.metrics.referencedOwnerMismatchCount,
upserted: graphSync.metrics.upserted,
deleted: graphSync.metrics.deleted,
})
}
} catch (error) {
result.dedicatedGraphSync = {
status: 'skipped',
reason: 'reconcile-error',
blobDeleteErrors: 0,
}
result.warnings.push('dedicated-graph-sync-skipped')
console.warn('system-email-dedicated-graph-sync-skipped', {
reason: 'reconcile-error',
error,
})
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/email/system-email.ts` around lines 491 - 523, Guard the
reconcileSystemEmailGraphFromLegacy call in pruneSystemEmailRetention with
try/catch so unexpected reconciliation failures do not reject the
already-completed retention work; record dedicatedGraphSync as skipped with the
thrown error’s reason, push a dedicated reconciliation-failure warning, log the
failure, and return the result. Extend the SystemEmailRetentionResult
skipped-reason union to include this new failure reason, preserving the existing
blob-delete-errors handling.

Comment thread packages/worker/src/email/test-schema.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds merged commit 802e658 into main Aug 2, 2026
10 checks passed
@kentcdodds
kentcdodds deleted the cursor/mailbox-step4-system-email-split branch August 2, 2026 23:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants