Purge the edge after a repair, or verify answers per PoP (#89) #90

Merged
archvillainette merged 1 commits from docs/repair-then-purge into main 2026-07-31 23:13:56 +00:00
2 changed files with 14 additions and 0 deletions
Showing only changes of commit 53cd6a79fb - Show all commits
+12
View File
@@ -97,6 +97,18 @@ broken — is skipped by every later run forever and no backfill repairs it. Wit
and replaced when it does not match. It costs a full GET per existing blob, so and replaced when it does not match. It costs a full GET per existing blob, so
it is a repair pass, not the default. it is a repair pass, not the default.
**After a repair, purge the pull zone before believing `verify`.** A repair is
the one thing that makes a key serve different bytes than it did before, and the
edge caches these objects for 30 days precisely because that normally cannot
happen. The two commands therefore look at different copies on purpose: `emit
--verify` repairs the **origin**, `verify` reads the **edge**, and in between a
warm PoP still answers with the old bytes while a cold one answers with the new.
Until the zone is purged `verify`'s verdict is per-PoP and settles nothing — a
pass is not proof, and a failure is not the repair having failed. The purge is
one call against the pull zone; it belongs in the repair procedure rather than
in `emit`, which holds a storage credential and no CDN one (sow-tools#89, and
the procedure itself is in sow-platform's NWSync runbook).
`emit` uploads blobs first and the index last, so the presence of an index is `emit` uploads blobs first and the index last, so the presence of an index is
the publication marker: an artifact whose emit died halfway leaves real blobs in the publication marker: an artifact whose emit died halfway leaves real blobs in
the zone and no index. Blob names are content hashes, so re-running skips the zone and no index. Blob names are content hashes, so re-running skips
+2
View File
@@ -67,6 +67,8 @@ check on a published blob upstream of a player's client.
--verify makes emit hash what it would otherwise skip. emit normally treats a --verify makes emit hash what it would otherwise skip. emit normally treats a
blob's presence as proof of its contents, so without this an object written blob's presence as proof of its contents, so without this an object written
truncated, or written by an emitter since found broken, is skipped forever. truncated, or written by an emitter since found broken, is skipped forever.
--verify repairs the storage zone, while verify reads the edge in front of it,
so purge the pull zone after a repair or verify answers differently per PoP.
--out DIR writes to a local repository tree instead of uploading, which is the --out DIR writes to a local repository tree instead of uploading, which is the
conformance path against upstream nwn_nwsync_write. Without it, the zone comes conformance path against upstream nwn_nwsync_write. Without it, the zone comes