Stop a clean migration reporting domains it never lost

The post-migration comparison had the two versions counting domains
differently, and yesterday's wiring turned that into a gate: `run` would have
failed a migration that lost nothing.

The 0.15 side added every domain appearing in any account's address on top of
the domain principals - the fallback's own comment says "if the instance has
no explicit domain principals", but the loop ran unconditionally. The 0.16
side did the reverse, listing only domains some account calls its primary,
discarding the full Domain list it had already fetched. An instance with
three declared domains and accounts aliased across nine reported nine before
and three after. INBUXA is exactly that shape, and this was the account/domain
over-count noted as undiagnosed.

Both sides now mean "the domains this server holds". A domain that still goes
missing is reported as a warning rather than failing the run: what the two
versions call a domain differs across this boundary in ways we have now been
caught by once, and a missing account - which is compared with a local-part
fallback and is what actually matters - still fails.

Narrowing OK() also made String() return before printing the domain lines,
so the new warning would have been silent. Caught by its own test.
This commit is contained in:
2026-08-24 13:26:15 -07:00
parent 28128633ef
commit 3adaee3bc6
9 changed files with 156 additions and 24 deletions
+22 -5
View File
@@ -43,11 +43,25 @@ type ContentIntegrityResult struct {
MessageCountsCompared bool // false when the source version could not report counts
}
// OK reports whether everything this comparison was able to check matched.
// Read it together with MessageCountsCompared: OK with that false means
// "the directory survived", not "no mail was lost".
// OK reports whether everything that must match did: no account and no mail
// went missing. Read it together with MessageCountsCompared: OK with that
// false means "the directory survived", not "no mail was lost".
//
// Domains are deliberately not part of this. What the two versions call a
// domain differs across the 0.15/0.16 boundary — principals on one side,
// Domain objects on the other, with aliases and account-less domains
// counted differently — and we have already been caught once reporting a
// migration that lost nothing as having lost domains. A disagreement there
// is worth showing an operator; it is not worth failing a migration over,
// where a missing account is.
func (r ContentIntegrityResult) OK() bool {
return len(r.MissingAccounts) == 0 && len(r.MessageCountMismatches) == 0 && len(r.MissingDomains) == 0
return len(r.MissingAccounts) == 0 && len(r.MessageCountMismatches) == 0
}
// DomainsOK reports whether every domain seen before the migration is still
// listed after it.
func (r ContentIntegrityResult) DomainsOK() bool {
return len(r.MissingDomains) == 0
}
func (r ContentIntegrityResult) String() string {
@@ -59,7 +73,10 @@ func (r ContentIntegrityResult) String() string {
"(this migration's source version reports no per-mailbox counts, so no-data-loss is NOT verified here - "+
"only that every account and domain survived)", r.AccountsChecked)
}
if r.OK() {
// Everything below is a finding, so return early only when there is
// nothing at all to report - domains included, even though they no
// longer fail the run. A warning nobody can read is not a warning.
if r.OK() && r.DomainsOK() {
if r.MessageCountsCompared {
b.WriteString(", all message counts match")
}
+10 -2
View File
@@ -71,11 +71,16 @@ func RunLive(ctx context.Context, store *checkpoint.Store, rs *checkpoint.RunSta
if err != nil {
return checkpoint.StepOutcome{}, err
}
if !r.OK() {
switch {
case !r.OK():
// Recorded as a completed step with a failing verdict rather
// than an error: the comparison ran, and its answer is the
// finding. An error here would read as "we could not look".
return checkpoint.StepOutcome{Verdict: string(StatusFail), Detail: r.String()}, nil
case !r.DomainsOK():
// The two versions disagree about what counts as a domain, so
// this is reported rather than treated as data loss.
return checkpoint.StepOutcome{Verdict: string(StatusWarn), Detail: r.String()}, nil
}
return checkpoint.StepOutcome{Detail: r.String()}, nil
})
@@ -88,8 +93,11 @@ func RunLive(ctx context.Context, store *checkpoint.Store, rs *checkpoint.RunSta
}
status := StatusOK
if outcome.Verdict == string(StatusFail) {
switch outcome.Verdict {
case string(StatusFail):
status = StatusFail
case string(StatusWarn):
status = StatusWarn
}
report.Results = append(report.Results, CheckResult{Name: "content-integrity", Status: status, Detail: outcome.Detail})
return report, nil
+37 -7
View File
@@ -101,7 +101,40 @@ func TestRunLiveFailsWhenAnAccountIsMissing(t *testing.T) {
}
}
func TestRunLiveFailsWhenADomainIsMissing(t *testing.T) {
func TestRunLiveWarnsButDoesNotBlockWhenADomainIsMissing(t *testing.T) {
// What the two versions call a domain differs across the 0.15/0.16
// boundary - principals on one side, Domain objects on the other, with
// aliases counted differently - and INBUXA's own before-list was
// inflated with alias domains that the after-list structurally cannot
// contain. Failing the migration on that would abort a run that lost
// nothing, so it is reported and not treated as data loss.
srv := fakeInstance(t, []string{"example.org"}, map[string]float64{"[email protected]": 10})
defer srv.Close()
store, rs := newRun(t)
report, err := RunLive(context.Background(), store, rs, LiveOptions{
AdminURL: srv.URL, AdminUser: "admin", AdminPassword: "pw", HTTPClient: srv.Client(),
Before: &checkpoint.PreflightSnapshot{
Domains: []string{"example.org", "alias.example"},
UsedQuota: map[string]int64{"[email protected]": 1},
},
})
if err != nil {
t.Fatalf("RunLive: %v", err)
}
if report.Blocking() {
t.Fatalf("a domain-only difference must not abort the migration, got: %s", report.String())
}
if got := report.Results[0].Status; got != StatusWarn {
t.Fatalf("status = %q, want %q", got, StatusWarn)
}
if !strings.Contains(report.Results[0].Detail, "alias.example") {
t.Fatalf("the operator still needs to be told which domain, got %q", report.Results[0].Detail)
}
}
func TestRunLiveStillBlocksWhenAnAccountAndADomainAreMissing(t *testing.T) {
// A lost account is a lost account, whatever the domain list says.
srv := fakeInstance(t, []string{"example.org"}, map[string]float64{"[email protected]": 10})
defer srv.Close()
@@ -109,15 +142,12 @@ func TestRunLiveFailsWhenADomainIsMissing(t *testing.T) {
report, _ := RunLive(context.Background(), store, rs, LiveOptions{
AdminURL: srv.URL, AdminUser: "admin", AdminPassword: "pw", HTTPClient: srv.Client(),
Before: &checkpoint.PreflightSnapshot{
Domains: []string{"example.org", "vanished.example"},
UsedQuota: map[string]int64{"[email protected]": 1},
Domains: []string{"example.org", "alias.example"},
UsedQuota: map[string]int64{"[email protected]": 1, "[email protected]": 2},
},
})
if !report.Blocking() {
t.Fatalf("a missing domain must block, got: %s", report.String())
}
if !strings.Contains(report.Results[0].Detail, "vanished.example") {
t.Fatalf("the report should name the missing domain, got %q", report.Results[0].Detail)
t.Fatalf("a missing account must still block, got: %s", report.String())
}
}
+3
View File
@@ -18,6 +18,9 @@ const (
// are different answers, and reporting the second as the first is the
// failure mode ARCHITECTURE.md §4.7 warns about.
StatusSkip Status = "skip"
// StatusWarn is a finding worth an operator's attention that is not
// worth failing a migration over.
StatusWarn Status = "warn"
)
type CheckResult struct {