Skip to content

fix: gate the snapshot-seed signers pass on the versions we already hold - #446

Closed
karolko9 wants to merge 1 commit into
developfrom
fix/0521_snapshot-seed-signers-version-gate
Closed

karolko9 wants to merge 1 commit into
developfrom
fix/0521_snapshot-seed-signers-version-gate

Conversation

@karolko9

@karolko9 karolko9 commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator

What

snapshot-seed's signers pass (account_entry_state) emitted the full live-account set on every run — no comparison against what the database already holds. Right when written (the live signers writer did not exist yet), wrong since that writer deployed: on the second production pass every other correction collapsed to churn while this one re-emitted 10.9M identical rows, so its summary line was a constant that could not carry a signal.

The pass now reads max(last_updated_ledger) per account (sliced on the key like every other read here, RMT-deduplicated) and emits only accounts the snapshot holds newer. The summary reports written and skipped-as-unchanged, and the two sum to the snapshot's live-account count.

Verified

Production dry-run at checkpoint 64,237,951 (read-only): 0 written, 10,909,433 unchanged, sum equal to the snapshot's live accounts to the row. A later pass that writes millions again now means the live signers writer stopped stamping — which is the point.

Deliberately out of scope

  • No floor on the version read — the one input here that fails toward re-emitting (harmless under ReplacingMergeTree) rather than toward manufacturing rows; a floor would also refuse the legitimate first-seed/empty-table case. Explained in place.
  • No content diff at equal versions — that is the 0503 audit's job, and a heavier read (three arrays per account for 10.9M accounts).

Checks

  • gate regression test (4 cases), cargo clippy --all-targets -D warnings clean
  • docs: docs/backfills.md gains the signers-gate paragraph
  • API types: N/A — nothing under crates/api/**

Pass 4 emitted the full live-account set on every run — right before the
live signers writer existed, wrong since it deployed. The second production
pass measured it: every other correction collapsed to churn while this one
re-emitted 10.9M identical rows, so the summary line was a constant.

The pass now reads max(last_updated_ledger) per account (sliced, RMT-deduped)
and emits only what the snapshot holds newer. The summary reports written and
unchanged, summing to the live-account count. Verified on production: 0
written, 10,909,433 unchanged at checkpoint 64,237,951.

Deliberately no floor on the version read (fails toward re-emitting, which
RMT absorbs) and no content diff at equal versions (0503's audit).
@karolko9

Copy link
Copy Markdown
Collaborator Author

Superseded by #568: task 0210 split the seed passes into modules, so the same gate is rebuilt there (snapshot/entry_state.rs).

@karolko9 karolko9 closed this Sep 30, 2026
@karolko9
karolko9 deleted the fix/0521_snapshot-seed-signers-version-gate branch September 30, 2026 15:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant