Skip to content

fix(ingest): recover WAL segments shipped at shutdown - #1213

Merged
Makisuo merged 2 commits into
mainfrom
fix/ingest-wal-shutdown-recovery
Oct 2, 2026
Merged

Makisuo merged 2 commits into
mainfrom
fix/ingest-wal-shutdown-recovery

fix(ingest): keep a WAL owner claimable while recovery leaves segment…

ea5f8ef
Select commit
Loading
Failed to load commit list.
Maple Review Bot / Maple / review succeeded Oct 2, 2026 in 8m 12s

Confidence 4/5 · No issues found

🟢 Confidence 4/5 · likely safe to merge
quality 100/100 · no findings · tests covered · risk high

Adds a retired/ owner marker so shutdown-shipped WAL segments are claimable at any age, makes a sealed segment count as exported when the cursor sits at its end, and keeps an owner claimable while recovery leaves segments behind. The logic reads correctly and is covered by new tests.

  • retire() writes retired/<owner> before dropping the heartbeat; stale_owners lists it
  • WalLane::is_behind lets a cursor parked at a sealed segment's end count as exported
  • recover_orphans keeps the owner claimable when segments are left behind
What was checked
  • is_behind cannot skip unexported data: the parked case requires cursor.offset >= file_len and seq < active_seq, which seal() publishes only after the outgoing segment is final (`telemetry.rs:1…
  • No data loss on recovery: at boot cursor.seq < active_seq or the appended segment is sealed then shipped, so recovered frames are always in a segment is_behind reports as owed
  • Keeping the owner leaves the claim marker, so a second retry waits out CLAIM_LEASE (30 min) and the lifecycle rule ends the retry loop for permanently unplaceable lanes

ea5f8ef · Updated on every push. Reply "won't fix" to dismiss a finding, or mention @maple-review-bot to ask about one.