Leave remote info orphan figures unknown when a manifest is unreadable (closes #228)
check / check (push) Waiting to run

When a manifest could not be read, remote info skipped it, counted that
snapshot's blobs as orphaned and advised running prune. The orphan
figures are now unknown in that case: the report says how many
manifests could not be read and gives no prune advice, and --json gives
orphaned_blob_count and orphaned_blob_size as null and lists the remote
keys in unreadable_manifests.

Directory names under metadata/ were used unchecked and printed raw, so
control characters in one reached the terminal. A name that is not a
remote key (64 lowercase hex characters) is now skipped with a warning,
as the snapshot listing already does.

The closing log line of remote info now carries the unreadable manifest
count in place of the orphan count.

Model: opus-5-5
This commit is contained in:
2026-10-07 04:36:04 +00:00
parent 8496404d8b
commit c113e120d6
4 changed files with 165 additions and 17 deletions
+3 -1
View File
@@ -390,7 +390,9 @@ recipients, and local database statistics.
**`remote info`**: Show storage backend type and location plus detailed
remote storage inventory: per-snapshot metadata sizes, blob counts, and
orphaned blob detection.
orphaned blob detection. If a manifest cannot be read, the orphaned blob
figures are reported as unknown; `--json` gives them as `null` and lists
the remote key of each unreadable manifest in `unreadable_manifests`.
* `--json`: Output as JSON
**`remote nuke`**: Delete every snapshot's metadata and every blob from the