remote nuke reports the destination store empty while a leftover .partial upload remains #281

Open
opened 2026-10-08 08:12:28 +02:00 by clawbot · 1 comment
Collaborator

NukeRemote (internal/vaultik/prune.go:32-54) deletes through RemoveAllSnapshots and PruneBlobs. Both are fed by ListStream, which skips every name ending in .partial (internal/storage/file.go:223, internal/storage/rclone.go:198), and nothing else ever deletes such an object. The command then prints Backup destination store is now empty. (prune.go:52). The README calls remote nuke the single supported way to wipe the entire destination store.

Trigger: kill snapshot create during a blob upload to a file:// destination, or to an rclone remote with a server-side move, then run remote nuke --force. The leftover object, up to blob_size_limit in size, survives.

Found by the third audit pass on next at c06c4d2, by code trace.

Definition of done

  1. remote nuke also deletes the leftover .partial objects under the destination prefix, so its "now empty" message is true.
  2. A test plants a .partial object on a file:// destination and asserts that the prefix is empty after remote nuke.
  3. make check passes.

Model: fable-5-1 (audit); opus-5-5 (issue)

`NukeRemote` (`internal/vaultik/prune.go:32-54`) deletes through `RemoveAllSnapshots` and `PruneBlobs`. Both are fed by `ListStream`, which skips every name ending in `.partial` (`internal/storage/file.go:223`, `internal/storage/rclone.go:198`), and nothing else ever deletes such an object. The command then prints `Backup destination store is now empty.` (`prune.go:52`). The README calls `remote nuke` the single supported way to wipe the entire destination store. Trigger: kill `snapshot create` during a blob upload to a `file://` destination, or to an rclone remote with a server-side move, then run `remote nuke --force`. The leftover object, up to `blob_size_limit` in size, survives. Found by the third audit pass on `next` at `c06c4d2`, by code trace. ## Definition of done 1. `remote nuke` also deletes the leftover `.partial` objects under the destination prefix, so its "now empty" message is true. 2. A test plants a `.partial` object on a `file://` destination and asserts that the prefix is empty after `remote nuke`. 3. `make check` passes. Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot self-assigned this 2026-10-08 08:12:28 +02:00
Author
Collaborator

#283 makes remote nuke also delete the .partial objects under metadata/ and blobs/, through a new storage method the file and rclone backends implement; S3 has none to delete. The defect reproduced on current next before the fix. Empty directories under a file:// destination are still left behind.

Model: opus-5-5

https://git.eeqj.de/sneak/vaultik/pulls/283 makes `remote nuke` also delete the `.partial` objects under `metadata/` and `blobs/`, through a new storage method the file and rclone backends implement; S3 has none to delete. The defect reproduced on current `next` before the fix. Empty directories under a `file://` destination are still left behind. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/vaultik#281