NEC-15: Checkpoint writer: stop discarding edit history #145

Merged
nectenda-agent merged 2 commits from worktree-nec-15-checkpoint-writer-stop-discarding-edit-hi into main 2026-09-24 16:04:38 +01:00
Collaborator

Task: NEC-15 — https://projectron.nerchure.com/tasks/15

Compaction overwrote a document's one snapshot and deleted the log beneath it, so every document past 500 updates lost every earlier state. putSnapshot now moves the superseded snapshot byte-for-byte into a new doc_checkpoints table in the same transaction, and thins that document's checkpoints (all under 48 h, newest per UTC day to 90 days, newest per week beyond, never expired, newest always kept). Server-side rather than the client-written MessageType 19 the card proposed, by the user's decision: it needs no plugin release or wire change and protects every installed client from the deploy on. Deletion, account export/import/purge and usage metering carry the new table; STORE-003/025/026/050/051 and the security model are updated. Mutation-checked in both directions, including the WebSocket path through the threaded writer.

Spec: docs/changes/NEC-15-checkpoint-writer/spec.md

Changelog

The server now keeps earlier versions of each note when it compacts edit history, instead of discarding them.

Task: NEC-15 — https://projectron.nerchure.com/tasks/15 Compaction overwrote a document's one snapshot and deleted the log beneath it, so every document past 500 updates lost every earlier state. putSnapshot now moves the superseded snapshot byte-for-byte into a new doc_checkpoints table in the same transaction, and thins that document's checkpoints (all under 48 h, newest per UTC day to 90 days, newest per week beyond, never expired, newest always kept). Server-side rather than the client-written MessageType 19 the card proposed, by the user's decision: it needs no plugin release or wire change and protects every installed client from the deploy on. Deletion, account export/import/purge and usage metering carry the new table; STORE-003/025/026/050/051 and the security model are updated. Mutation-checked in both directions, including the WebSocket path through the threaded writer. Spec: `docs/changes/NEC-15-checkpoint-writer/spec.md` ## Changelog The server now keeps earlier versions of each note when it compacts edit history, instead of discarding them.
putSnapshot overwrote a document's one snapshot and deleted the log beneath
it, so every document past 500 updates lost every earlier state it had. The
superseded snapshot now moves byte-for-byte into doc_checkpoints in the same
transaction, and the document's checkpoints are thinned there: all under 48
hours, newest per UTC day to 90 days, newest per week beyond, never expired,
and the newest never thinned.

Server-side rather than the client-written MessageType 19 the card proposed,
by decision: compaction is the only destructive step, and keeping what it
replaces protects every installed plugin from the server deploy on, with no
wire change. Deletion, account transfer and usage metering all carry the new
table; an export from a server that predates it still verifies if empty.

Task: NEC-15
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BvEXWt7DiuAsJUpwwZDTDF
Make the checkpoint tests able to fail where review found they could not
All checks were successful
Release note / release-note (pull_request) Successful in 14s
CI / build (pull_request) Successful in 4m25s
CI / e2e (pull_request) Successful in 4m50s
CI / promote (pull_request) Has been skipped
81d2d138d4
The WebSocket test ran on an in-memory database, which gets the inline writer,
so the threaded worker's batch path was never exercised; it now uses a file.
The boundary test sat beside both boundaries rather than on them, and the purge
assertion read zero through shared_folders whether or not the rows went. Each
now fails when its rule is inverted. The security model also names account
purge as a way retained versions are deleted.

Task: NEC-15
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BvEXWt7DiuAsJUpwwZDTDF
cruelacid force-pushed worktree-nec-15-checkpoint-writer-stop-discarding-edit-hi from 81d2d138d4
All checks were successful
Release note / release-note (pull_request) Successful in 14s
CI / build (pull_request) Successful in 4m25s
CI / e2e (pull_request) Successful in 4m50s
CI / promote (pull_request) Has been skipped
to b7e32716eb
Some checks failed
Release note / release-note (pull_request) Successful in 13s
CI / e2e (pull_request) Successful in 4m56s
CI / build (pull_request) Successful in 5m30s
CI / promote (pull_request) Has been skipped
Deploy site / deploy (push) Successful in 53s
CI / build (push) Failing after 1m21s
CI / e2e (push) Successful in 4m54s
CI / promote (push) Has been skipped
2026-09-24 15:58:37 +01:00
Compare
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda!145
No description provided.