Confirmed undisclosed partial durability
Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2.
After chunks/index replacement, ingest calls _record_version but ignores its failure result. It returns stored although the full source snapshot/version needed by safe re-ingestion is unavailable. A same-content retry returns unchanged and does not repair the missing snapshot.
Sources: ignored version acknowledgment, version failure return, safe snapshot requirement.
Isolated reproduction with real SQLite fault
In a temporary store, ingest an original document. Add a SQLite trigger that aborts inserts into that source's version history, then ingest replacement text. Remove the test trigger and retry the identical replacement.
replacement result: stored, 1 chunk
current indexed content: replacement snapshot
version history: original version only
get_source_snapshot: None
same-content retry: unchanged
snapshot after retry: None
Independently reproduced; initial reviewer used a failed return and confirmation used an actual aborted SQLite insert. The index replacement succeeded, so this issue does not falsely call it total ingest failure. Existing safe-snapshot refusal is correct and must remain.
Acceptance criteria
- Either include version persistence in verified publication or report an explicit partial/degraded result with repair guidance.
- Permit a safe retry to repair missing current snapshot/version metadata rather than treating it as fully unchanged.
- Preserve old durable history and do not fabricate full content from incomplete chunk text.
- Test version-write failure after successful indexing and subsequent repair.
No source changes were made.
Confirmed undisclosed partial durability
Reviewed
masterat886c36d8ebe861aa987059a1744d45b78797baae(v4.7.0). Suggested priority: P2.After chunks/index replacement, ingest calls
_record_versionbut ignores its failure result. It returnsstoredalthough the full source snapshot/version needed by safe re-ingestion is unavailable. A same-content retry returnsunchangedand does not repair the missing snapshot.Sources: ignored version acknowledgment, version failure return, safe snapshot requirement.
Isolated reproduction with real SQLite fault
In a temporary store, ingest an original document. Add a SQLite trigger that aborts inserts into that source's version history, then ingest replacement text. Remove the test trigger and retry the identical replacement.
Independently reproduced; initial reviewer used a failed return and confirmation used an actual aborted SQLite insert. The index replacement succeeded, so this issue does not falsely call it total ingest failure. Existing safe-snapshot refusal is correct and must remain.
Acceptance criteria
No source changes were made.