mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
The mint orchestrator leaves a durable orphan row whenever a crash lands before the atomic step-4 commit; nothing reclaimed the dangling keyring secret. Add reap_unreferenced_orphans: for each orphan with no live binding, delete its keyring entry THEN drop its journal row, persisting the trimmed document once. Delete-before-drop and drop-only-on-success make the sweep idempotent across recovery points, and a backend delete failure keeps that row for a later retry. store_all only merges, so a new KeyStore::delete seam (delegating to SecretStore::delete, absent-entry = Ok) is required; the fakes mirror that contract. Also folds in Paul's read-back-miss mint crash point: load returning None after a verified write yields Err, no binding, and a surviving orphan row for the reap. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>