mirror of
https://github.com/euzu/tuliprox.git
synced 2026-10-03 14:32:08 +02:00
The write-ahead log makes a single commit atomic but cannot rebuild a database whose value type has changed, because its cells hold positional MessagePack. Add a second, independent history of field-named JSON records so a database can be reconstructed from any schema version the application still knows how to migrate. BPlusTreeRecoveryJournal owns the only mutation path: it appends and syncs a journal record before touching the B+Tree, so a crash can only leave recovery ahead - which open() repairs by rebuilding through staged publication - and never leave the database ahead of its own history. - recovery/format.rs: bounded frames (magic, length, BLAKE3) around JSON payloads, with a hash chain and torn-tail tolerance. - recovery/schema.rs: RecoverySchema, plus the one-step-at-a-time migration loop; a record is only ever decoded at the current version. - recovery/generation.rs: immutable manifests, the CURRENT pointer, crash-safe generation selection, verified checkpoint publication and bounded pruning. - v3: BPlusTreeMetadata::Recovery carries database id, schema fingerprint, schema version and applied revision in the database header. Existing metadata encoding is unchanged. The schema fingerprint deliberately excludes the version, so raising CURRENT_VERSION migrates an existing database instead of rejecting it.