Leave remote info orphan figures unknown when a manifest is unreadable (closes #228)
check / check (push) Canceled after 0s

When a manifest could not be read, remote info skipped it, counted that
snapshot's blobs as orphaned and advised running prune. The orphan
figures are now unknown in that case: the report says how many
manifests could not be read and gives no prune advice, and --json gives
orphaned_blob_count and orphaned_blob_size as null and lists the remote
keys in unreadable_manifests.

Directory names under metadata/ were used unchecked and printed raw, so
control characters in one reached the terminal. A name that is not a
remote key (64 lowercase hex characters) is now skipped with a warning,
as the snapshot listing already does.

The closing log line of remote info now carries the unreadable manifest
count in place of the orphan count.

Model: opus-5-5
This commit is contained in:
2026-10-07 04:36:04 +00:00
parent 8496404d8b
commit c113e120d6
4 changed files with 165 additions and 17 deletions
+12
View File
@@ -22,6 +22,18 @@ the tag exists and is exercised; what is left is merging `next` to
# Completed Steps
- 2026-10-07: Made `remote info` stop reporting a snapshot's blobs as
orphaned when its manifest cannot be read, and stop printing raw
names from under `metadata/`
([issue #228](https://git.eeqj.de/sneak/vaultik/issues/228)). A
manifest it failed to read was skipped, so that snapshot's blobs were
counted as orphaned and the report advised running `vaultik prune`.
The orphan figures are now unknown in that case, with no prune
advice, and `--json` gives them as `null` with the unreadable remote
keys in `unreadable_manifests`. A name under `metadata/` that is not
64 lowercase hex characters is now skipped with a warning instead of
being printed, control characters included.
- 2026-10-07: Made taking the process-wide lock atomic
([issue #227](https://git.eeqj.de/sneak/vaultik/issues/227)). The lock
read `vaultik.pid`, checked whether that PID was alive and then wrote