Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/issues/BB-ISSUE-BB276B0D-luci-runtime-safety-defects/index.md

Raw
Rendered preview

id: BB-ISSUE-BB276B0D type: issue title: Luci runtime safety defects specs:

  • BB-SPEC-251EC85B

Luci runtime safety defects

These defects block deployment of 45db070.

History

  • Monthly history is appended directly as zstd frames; interruption can corrupt the canonical archive and block history, recovery, web, and CLI reads.
  • The reader uses the default bufio.Scanner token limit, while the writer accepts larger events.
  • Idempotent append scans all retained history, so cost grows without bound.

Required closure: failure-atomic persistence, size-safe reads and writes, interrupted-write regression coverage, and bounded lookup behavior.

Workspaces and secrets

Child workspaces are never removed. Injected file secrets, source, and outputs therefore persist indefinitely. Observed production held 28 GiB and 865,635 workspace files.

Required closure: cleanup after every terminal outcome, secret removal tests, capacity handling, and separately approved cleanup of existing production data.

Publishing and Podman

  • Registry publish reads the service user's host image store, but job-built images have no path into that store.
  • Package and site replacement remove the canonical target before exposing the replacement, leaving interruption and reader-visible gaps.
  • Image and registry destination values can be parsed as Podman options and return false success.
  • Staging cleanup errors are discarded and can leak old trees.
  • File publishers ignore cancellation while registry publishers share the shrinking job deadline.

Required closure: current-job image identity, interruption-safe replacement, explicit operand boundaries, cleanup error handling, and consistent cancellation tests.

Queue, state, and logs

  • A failed ref-state save after inbox creation can execute the same push repeatedly.
  • Nanosecond-only inbox IDs can collide across concurrent writers.
  • Final log output-close failure can be ignored before deleting the live copy.
  • Manual annotated tags can record the tag object rather than the built commit.
  • Invalid serve arguments perform recovery before usage validation.

Each root cause requires a focused regression test before closure.

---
id: BB-ISSUE-BB276B0D
type: issue
title: Luci runtime safety defects
specs:
  - BB-SPEC-251EC85B
---

# Luci runtime safety defects

These defects block deployment of `45db070`.

## History

- Monthly history is appended directly as zstd frames; interruption can corrupt the canonical archive and block history, recovery, web, and CLI reads.
- The reader uses the default `bufio.Scanner` token limit, while the writer accepts larger events.
- Idempotent append scans all retained history, so cost grows without bound.

Required closure: failure-atomic persistence, size-safe reads and writes, interrupted-write regression coverage, and bounded lookup behavior.

## Workspaces and secrets

Child workspaces are never removed.
Injected file secrets, source, and outputs therefore persist indefinitely.
Observed production held 28 GiB and 865,635 workspace files.

Required closure: cleanup after every terminal outcome, secret removal tests, capacity handling, and separately approved cleanup of existing production data.

## Publishing and Podman

- Registry publish reads the service user's host image store, but job-built images have no path into that store.
- Package and site replacement remove the canonical target before exposing the replacement, leaving interruption and reader-visible gaps.
- Image and registry destination values can be parsed as Podman options and return false success.
- Staging cleanup errors are discarded and can leak old trees.
- File publishers ignore cancellation while registry publishers share the shrinking job deadline.

Required closure: current-job image identity, interruption-safe replacement, explicit operand boundaries, cleanup error handling, and consistent cancellation tests.

## Queue, state, and logs

- A failed ref-state save after inbox creation can execute the same push repeatedly.
- Nanosecond-only inbox IDs can collide across concurrent writers.
- Final log output-close failure can be ignored before deleting the live copy.
- Manual annotated tags can record the tag object rather than the built commit.
- Invalid `serve` arguments perform recovery before usage validation.

Each root cause requires a focused regression test before closure.