Reconcile blob metadata after a crash during deletion
A process dies after file removal but before metadata commit. Recovery must distinguish absent bytes from an untouched blob.
- Focused work estimate
- 3h + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Crash consistency · Reconciliation
Estimated field mix
- Storage systems60%
- Database engineering40%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
Fictional archive Moss deduplicates generated attachments across documents within each organization. Use local files and transactional metadata stubs.
Setup prerequisites
- Generate duplicate and unique local byte fixtures.
- Create synthetic document references across two organizations.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- CBLOB-101 · Separate attachment display names from blob identities
- CBLOB-102 · Scope blob deduplication to the owning organization
- CBLOB-103 · Reject references to incomplete synthetic blobs
- CBLOB-104 · Tombstone unreferenced blobs before physical deletion
- CBLOB-105 · Prevent a new blob reference racing with reclamation
- CBLOB-106 · Record physical blob deletion failures without claiming completion
Acceptance criteria
- Missing claimed blob completes metadata
- Existing claimed blob retries safely
- Unclaimed blob is never deleted
Implementation constraints
- Recovery requires durable deletion claim identity.
Verification to include
- Crash after file removal
- Restart with stale unrelated claim
Deliverables
- Deletion reconciliation and restart cases
Rollout and recovery
Stop automatic recovery if claims cannot be verified.
Value of the work
For the engineer: Practice reclamation races and explicit data-lifecycle guarantees.
For the team: Inspect whether storage cleanup avoids broken references and hidden retention.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.