Skip to content

fix(store): retain tombstone project on repeated sparse delete - #1514

Merged
dnlrsls merged 1 commit into
Gentleman-Programming:feat/prompt-inbox-foundation-trackerfrom
dnlrsls:fix/prompt-sparse-delete-owner
Sep 28, 2026
Merged

dnlrsls merged 1 commit into
Gentleman-Programming:feat/prompt-inbox-foundation-trackerfrom
dnlrsls:fix/prompt-sparse-delete-owner

Conversation

@dnlrsls

@dnlrsls dnlrsls commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

🔗 Linked Issue

Closes #1458

🏷️ PR Type

  • type:bug — Bug fix

📝 Summary

  • Retain the established prompt tombstone project on repeated sparse pulled deletes when the live prompt is gone but its session remains.
  • Clarify that pulled deletes claiming a foreign live inbox pair are quarantined even if their sync ID resolves.

📂 Changes

File Change
internal/store/store.go Prefer the same-sync-ID tombstone project before session fallback.
internal/store/store_test.go Regression for repeat under a live cross-project session and scoped export.
docs/ARCHITECTURE.md Align ownership and conflict behavior.

🧪 Test Plan

  • Focused regression: go test ./internal/store -run ^TestPulledSparsePromptDeleteRetainsOwnTombstoneProjectWhileSessionLives$ -count=1 — RED before fix (seq 3 dead letter), GREEN after.
  • Affected packages: CODEX_HOME= go test ./internal/store ./internal/cloud/autosync -count=1 — passed.
  • Additional: CODEX_HOME= go test ./... -count=1; golangci-lint run --new-from-rev=HEAD before commit; git diff --check — passed; existing full-package lint debt not resolved.

🤖 Automated Checks

Pending on this PR head: issue/label policy, unit, E2E, plugin, lint, Windows and cloud wrapper.

✅ Contributor Checklist

💬 Notes for Reviewers

Feature branch chain: main ← tracker #1464 ← 📍 this correction. Only this 43-line unit belongs here; #1240 and inferred no-live tombstone provenance policy are out of scope. Normal merge into tracker only after exact-head CI and full review. Native review-dbd647c6eed7bef7 approved and acknowledged.

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where repeated sparse deletions could change which project a deleted prompt belongs to. Deleted prompts now retain their established project assignment, keeping project exports consistent.
    • Improved handling of deletions associated with another active prompt, preventing the wrong prompt or session from being affected.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: cbefdb76-995d-4d01-aa6d-5ccb8d15d46a

📥 Commits

Reviewing files that changed from the base of the PR and between 890b96c and 379b870.

📒 Files selected for processing (3)
  • docs/ARCHITECTURE.md
  • internal/store/store.go
  • internal/store/store_test.go

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 5 remain after this review.


📝 Walkthrough

Walkthrough

Sparse prompt deletes now check an existing prompt tombstone for project ownership before using session-based data. A regression test checks repeated deletes, pull cursor advancement, dead-letter entries, and project exports. The architecture documentation describes the related delete quarantine and ownership rules.

Changes

Sparse delete ownership

Layer / File(s) Summary
Resolve and verify sparse delete ownership
internal/store/store.go, internal/store/store_test.go, docs/ARCHITECTURE.md
When a delete omits a nonblank project, the store checks the existing prompt row, then the matching prompt tombstone, before session-based fallbacks. The test verifies that a repeated sparse delete preserves the tombstone’s beta project and checks cursor, dead-letter, and export results. The architecture documentation describes the quarantine and ownership rules.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Suggested reviewers: alan-thegentleman

Merge Risk: ⚪ Minimal · up to 379b8

No actionable merge-blocking risk is identified for the sparse-delete ownership change; proceed with normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to 379b8

The change affects 2 systems.

Changed systems: internal, docs

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — internal (service) was modified; 2 changed files map to changed impact.
  • observed — docs (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in docs/ARCHITECTURE.md: Pulled deletes claiming a session-and-inbox pair held by another live prompt are now quarantined even when the payload’s sync ID resolves to a live prompt; previously, this rule applied only to unknown sync IDs. Sparse pulled deletes now resolve project ownership from the prompt’s established tombstone before falling back to the live session or active deleted-session tombstone.
  • observed — Modified behavior in internal/store/store.go: When the delete payload lacks a nonblank project, the fallback now checks the matching prompt tombstone for an owner after the existing prompt row and before the session-based fallback.
  • observed — Modified behavior in internal/store/store_test.go: Adds coverage that a repeated sparse prompt delete does not replace an existing tombstone’s beta project with project information inferred from the live alpha session. It also verifies the pull cursor advances to 3 without dead letters and that project exports include the tombstone only for beta.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: preserving the tombstone project during repeated sparse deletes.
Linked Issues check ✅ Passed Issue [#1458] requires preservation of admitted prompt identity during deletion, including retention of project ownership and protection against replay. This PR updates applyPromptDeleteTx to prefer…
Out of Scope Changes check ✅ Passed The changes stay within prompt deletion identity and ownership handling. The foreign live inbox-pair quarantine change supports deletion safety under the same issue objective. The regression test veri…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dnlrsls dnlrsls added the type:bug Bug fix label Sep 28, 2026
@dnlrsls

dnlrsls commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@dnlrsls
dnlrsls merged commit 313f526 into Gentleman-Programming:feat/prompt-inbox-foundation-tracker Sep 28, 2026
19 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant