You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Close two edges left by the re-review: unloaded cache files, sortless ordering
1. reload() only loads countsfile and statsfile under stats.saving, but
stats_fresh was read off the filenames alone. So on a table without
saving, both files were accepted, neither was loaded or swapped, and
meta_tables.stats_valid was still set true -- leaving the live cache rows,
which describe the data being replaced, eligible to be served. Reachable
by toggling saving off before a reload, or simply by reloading from a
process using the base saving=False setting after counts were recorded.
Freshness now asks whether both companions are in the swap as well as
whether both files were named, which is what actually decides what goes
live. The partial-file and manual reload_final_swap cases stay
conservative as before. A reload handed cache files it will not load now
says so rather than dropping them silently; it is left as a warning rather
than an error, since rejecting outright would change an accepted call into
a failure mid-release-candidate.
2. _metafile_order_state maps a SQL-null sort to None, and _generate_sorted_ids
reads sort=None as "use the configured sort". A metafile with
id_ordered=true, out_of_order=false and sort=NULL therefore numbered the
_tmp relation by the sort it was replacing, after which reload_meta
installed no sort and _set_ordered recorded an ordered table: exactly the
id_ordered-with-no-sort state the audit reports as an error.
reload now refuses that combination, with a message saying what to do
instead, before anything is rebuilt or swapped -- so the live table is
untouched and no _tmp or _resort relation is left behind. The check reads
the metafile whether or not this reload renumbers, since the non-resorting
path installs the same impossible row through reload_meta. Only the
incoherent combination is refused: a metafile that drops the sort and the
id_ordered claim together still loads.
Regression tests for both, plus the positive controls (a partial cache pair
is still not trusted; a sortless metafile that also clears id_ordered still
loads). Each new test was checked to fail against a39070f. Full suite green
(1405 passed) over three clean-database runs, ruff clean, docs clean under -W.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0 commit comments