Repository navigation
Remove access-frequency pool tiering and reconcile version DELETE - #188
Merged
Merged
Conversation
Reverse the first-parent diff of a3df317, including the feature branch compatibility and mover follow-up fixes. Retain the independent multi-pool correctness fixes from #178 and migrate their shared test fixture away from access-tier code. Tolerate retired ILM keys and XML, read old v9 statistics while writing v8, and document migration without moving objects or rewriting their metadata. Include regression coverage using a historical scanner/writer v9 fixture. Signed-off-by: Feng Ruohang <rh@vonng.com>
Delete every copy of an explicitly addressed UUID, null version or delete marker under the pool lock. Preserve retention and replication callbacks, report unreadable pools and cleanup failures, and keep movement, incoming replication, expiration and free-version cleanup on their existing paths. Retain the separately developed general DELETE repair and replace its access-mover-only coverage with a real interrupted rebalance copy followed by HTTP deletion. Cover unqualified directory-marker DELETE and document the existing pool-order-dependent 503 behavior that this makes consistent. Signed-off-by: Feng Ruohang <rh@vonng.com>
Signed-off-by: Feng Ruohang <rh@vonng.com>
Signed-off-by: Feng Ruohang <rh@vonng.com>
Signed-off-by: Feng Ruohang <rh@vonng.com>
Signed-off-by: Feng Ruohang <rh@vonng.com>
Signed-off-by: Feng Ruohang <rh@vonng.com>
Vonng
marked this pull request as ready for review
September 15, 2026 07:09
This was referenced Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remove the default-off GET-frequency pool-tiering feature and its dedicated fixes. Ordinary addressed-version DELETE now reconciles resolved copies across pools, preventing a successful deletion from leaving another readable pool copy under the supported quorum conditions. Preserve the independent #178 Object Lock, conditional-delete, metadata, rebalance/decommission, replication-write and shared remote-tier protections.
Qualification
Production code is
41aa84609754769cfb1861d7fd060c2e84182b98, based on89637554d60c27cfc51d2281d0a4fe15e415f06d. Final delivery head4d0693cb8c560e88e85d78094c73d208fe9180b6changes only the history and migration documents relative to that tested code; every other tracked blob is identical. The unrelated local IAM/deadline commitebc9937d9is excluded and preserved.28e1339d630a22fa5a0e4659b6182224e81f6cd7cd4079856534390e40a697b1). Runs:8eb016db(90.20s),2a2b7b64(80.83s),371e7b9f(96.28s).40a59b3bpassed: offline DELETE503 SlowDownRead preserved the version on all four source drives; recovered DELETE204, three-node HEAD/GET404, all-eight-drive absence and other-version readback passed.Claude Code Opus5/max independently verified the final evidence and gave conditional MERGE GO. All four prerequisites are now satisfied: final CI is green, source equivalence is verified, the prior ledger/harness/all three run checksums were recomputed, and the five old main-worktree files were restored only after matching their archived hashes. Their complete snapshot remains recoverable through
refs/archive/access-tiering-main-five-files-20260915; the independent IAM commit is preserved. This approves merging, with release and deployment remaining separate deliverables.Merged on 2026-09-15 as
9df0f4aba. The fetched main merge tree is byte-for-byte identical to the qualified PR tree; no additional production changes entered during merge. The merge commit also passed all seven automatically triggered checks in Go CI and VulnCheck.Why the initially blocked run was not overwritten
R1 remains three attempts: pre-candidate fixture failure
83f88c59, effective PASSea58d0c5, and effective FAIL2059bc6b(DELETE204 followed by one node's HEAD503/GET503). The later all-disk snapshot and successful retries cannot reconstruct that failed request's disk state. Both2059bc6band historical83676ca2remain OPEN; neither is described as fixed, reproduced exactly or retrospectively passed.The previous readiness rule (404 samples plus admin disk summaries) admitted incomplete coordinator disk views. A later diagnostic directly recorded DELETE204 with
[nil,nil,nil,drive not found]in each pool, and one physical copy retained per pool. That satisfies existing 3-of-4 write quorum, but does not establish every-drive removal. Unique per-coordinator GetObjectTagging probes plus existing storage trace now verify actual ReadVersion responses from every drive; no production error handling was changed.A matching-write control used identical stopped real-rebalance fixtures: the baseline's existing conditional DELETE and the candidate's ordinary version DELETE both deleted across both pools. Each arm had 96 HEAD/GET observations, all404, with eight-drive absence. It is one matched pair, not proof that all possible mechanisms are excluded. Its 0.60s/17.08s readiness difference did not recur consistently in R2 (17.04s/0.62s/0.60s); no candidate-specific startup slowdown is claimed.
A separate controlled fixture positively reproduced the mechanism: stop destination disk7, DELETE204 at write quorum, verify its residual version, reconnect it, then make two already-cleared destination drives unavailable while retaining namespace quorum in pool0. The deleted version returned503 while a never-written version returned404; the same failed request recorded
[drive not found, drive not found, file version not found, nil]. This establishes a causal mechanism class, not the exact cause of the historical instance. This fixture used explicitly manufactured duplicate shards; real rebalance is covered separately. Partial-node restart did not recover every path within35s, so that experiment retains its FAIL. A separately recorded coordinated restart restored all40 paths and five-node HEAD/GET404.R2 is explicitly a new qualification round under corrected preparation conditions. R1 records and their checksums remain unchanged. Diagnostic logging stayed outside the PR; all disposable runtime resources were archived and cleaned.
Compatibility and operational boundaries
Tests use one Linux Docker VM and tmpfs. Cross-host, persistent-disk, pressure, all distinct duplicate UUIDs, full runtime statistics conservation, formal releases and production deployment are separate evidence boundaries, not claims supplied by these results.
Full introduction, subsequent fixes, preservation audit, review corrections, failed experiments and the qualified new round: history. Operations: migration guide.
Contribution licensing
Code is contributed under AGPL-3.0-or-later; docs retain CC BY4.0. Original attribution and license notices remain. All seven commits carry author-matching DCO sign-offs. No CLA or separate license grant is introduced.