Protect digest-pinned packages and refuse partial-inventory pruning
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 16:00:51 +02:00
parent 3f834b0556
commit 743def17be
5 changed files with 174 additions and 11 deletions

View file

@ -131,3 +131,19 @@ counts (`deleted_count`, `candidate_count`, `skipped_protected_count`, `errors`)
- `railiance-apps/docs/forgejo-package-registry.md`
- `docs/forgejo-backup.md`
- `docs/workload-kv-access-lanes.md`
## Digest-pinned packages
Live/exported references with a valid sha256 digest (including tag@digest) protect
**every container version of that package**. The reason is
`protected_digest_package`. This conservative policy covers aliases and child
manifests without assuming the package API supplies a complete digest mapping.
Other packages retain normal depth-based cleanup. Additive inventory also retains
rollback references; removal requires the existing owner review. Storage use may
grow for digest-pinned packages until a reviewed registry-aware mapping replaces
this conservative protection.
Malformed Forgejo references stop apply. Incomplete requested cluster inventories
or failed package listings stop apply before any deletion, even when other package
lists succeed. Dry-run remains available for inspection. No manual prune execution
is needed to verify the protection logic.