Confirmed split-index success misreport
Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2.
SessionVectorStore._write_session_sync ignores the boolean acknowledgment from FTS indexing, commits current metadata/vector state and reports success even when FTS rejected the write. Backfill checks missing IDs rather than stale content, so an existing stale FTS row does not recover.
Temporary-store reproduction
Index an archive with old text; make only FTS index_session return its documented failure value False; replace the archive with new text; restore the FTS method and run backfill.
replacement index return: True
metadata: new replacementphrase
FTS old text found: True
FTS new text found: False
backfill new count: 0
Independently reproduced by three reviewers using disposable SQLite stores. The fault is injected at the FTS acknowledgment boundary, modeling a split-store write failure, not a observed live incident.
Acceptance criteria
- Honor failed FTS acknowledgments and do not report the multi-index update fully successful.
- Coordinate rollback/repair across the separate stores without losing previously searchable data.
- Detect stale content/version mismatches, not only missing document IDs, during repair/backfill.
- Test FTS failure with successful metadata DB writes and successful retry repair.
No source changes were made.
Confirmed split-index success misreport
Reviewed
masterat886c36d8ebe861aa987059a1744d45b78797baae(v4.7.0). Suggested priority: P2.SessionVectorStore._write_session_syncignores the boolean acknowledgment from FTS indexing, commits current metadata/vector state and reports success even when FTS rejected the write. Backfill checks missing IDs rather than stale content, so an existing stale FTS row does not recover.Temporary-store reproduction
Index an archive with old text; make only FTS
index_sessionreturn its documented failure valueFalse; replace the archive with new text; restore the FTS method and run backfill.Independently reproduced by three reviewers using disposable SQLite stores. The fault is injected at the FTS acknowledgment boundary, modeling a split-store write failure, not a observed live incident.
Acceptance criteria
No source changes were made.