--- id: BB-ISSUE-BB276B0D type: issue title: Luci runtime safety defects specs: - BB-SPEC-251EC85B --- # Luci runtime safety defects These defects block deployment of `45db070`. ## History - Monthly history is appended directly as zstd frames; interruption can corrupt the canonical archive and block history, recovery, web, and CLI reads. - The reader uses the default `bufio.Scanner` token limit, while the writer accepts larger events. - Idempotent append scans all retained history, so cost grows without bound. Required closure: failure-atomic persistence, size-safe reads and writes, interrupted-write regression coverage, and bounded lookup behavior. ## Workspaces and secrets Child workspaces are never removed. Injected file secrets, source, and outputs therefore persist indefinitely. Observed production held 28 GiB and 865,635 workspace files. Required closure: cleanup after every terminal outcome, secret removal tests, capacity handling, and separately approved cleanup of existing production data. ## Publishing and Podman - Registry publish reads the service user's host image store, but job-built images have no path into that store. - Package and site replacement remove the canonical target before exposing the replacement, leaving interruption and reader-visible gaps. - Image and registry destination values can be parsed as Podman options and return false success. - Staging cleanup errors are discarded and can leak old trees. - File publishers ignore cancellation while registry publishers share the shrinking job deadline. Required closure: current-job image identity, interruption-safe replacement, explicit operand boundaries, cleanup error handling, and consistent cancellation tests. ## Queue, state, and logs - A failed ref-state save after inbox creation can execute the same push repeatedly. - Nanosecond-only inbox IDs can collide across concurrent writers. - Final log output-close failure can be ignored before deleting the live copy. - Manual annotated tags can record the tag object rather than the built commit. - Invalid `serve` arguments perform recovery before usage validation. Each root cause requires a focused regression test before closure.