2 months ago
509762aAdd a local-only SQLite control database at <app-data>/remote-state.db that
serves as the authoritative local control plane for remote repository state.
This database is never uploaded to cloud providers and stays outside every
portable library.
Schema (4 tables, verbatim from issue #151):
- remote_repository_state: library cleanliness and expected remote generation
- remote_operations: durable operation/outbox state with a 10-state lifecycle
(prepared, pending, running, retry_wait, committing, verifying, completed,
failed, conflicted, cancelled)
- remote_transfer_parts: resumable upload/download offsets (schema only;
PR#5 populates rows)
- remote_cache_entries: verified cache catalog (schema only; PR#6 populates)
Key changes:
- control_db.rs: connection management with WAL mode, idempotent migrations,
typed enums (LocalState, OperationKind, OperationState, TransferDirection),
CRUD for all 4 tables, SHA-256 file digest helper
- recovery.rs: startup recovery pass that transitions interrupted operations
(running/committing/verifying -> retry_wait, prepared -> cancelled/pending/
conflicted based on DB digest comparison) without re-executing them
- upload_status.rs: mark_upload_status now persists to remote_operations
(durable source of truth) in addition to the in-memory projection;
get_all_upload_statuses reads from the durable table so statuses survive
restart (defect #8)
- mutation.rs: every local mutation now records a durable prepared operation
row before the mutation commits, then transitions it to pending and marks
the repository dirty after. The existing sync_backend mock interface and
11 call-sequence tests remain passing.
- RemoteState: holds a control_db handle and a per-library commit lock map
for serializing concurrent commit attempts
- app_runtime.rs: opens the control DB and runs recovery on startup
payload_json shape for publish operations:
{"song_ids": ["hash-a"], "percent": 42, "detail": "..."}
Seams left for later PRs:
- TODO(PR#4): drive retry via operation executor; replace revision-based
conflict check with manifest generation CAS
- TODO(PR#5): resumable uploads/downloads from verified offsets
- TODO(PR#6): persistent cache catalog populationParent92e5060