Commit Graph
8 Commits
Author SHA1 Message Date
Wez Furlong d9851e3e02 update dev -> 2026.09.22-a276d4a8
Update docs for new stable tag

```
./assets/find-since-dev.sh 2026.09.22-a276d4a8
./docs/build.sh
```
2026-09-23 15:26:24 +01:00
Wez Furlong 3a88e3c883 spool: fix rocksdb load-shedding gate never reopening after a single-signal error
The gate could latch permanently when only one of the two error signals
(foreground or background) ever moved, requiring an operator restart. It now
auto-reopens for a retry after `error_unlatch_duration`, regardless of which
signal latched it.

Also serializes foreground error reporting with gate transitions so a
concurrent fatal error cannot be undone by a reopen, and rejects a zero
`error_unlatch_duration` when automatic reopening is enabled. The underlying
cause is always logged. Adds a reusable LD_PRELOAD fault-injection crate and
integration tests that reproduce a full disk and a slow disk to drive the
latch-and-reopen cycle end to end.

Fixes #597
2026-09-21 20:16:32 +01:00
Wez Furlong 9987248313 spool: surface and handle rocksdb background errors
We recently investigated an issue where a rocksdb had been damaged by
corrupting/removing SST files (it sounded like this was accidentally
self-inflicted by some backup/orchestration infrastructure) leaving the
system in a silently-broken state: writes just wouldn't make progress
and there were no error messages.

Inspecting the `/var/spool/kumomta/data/LOG` log file (which is a
readable text file) revealed messages like:

```
2026/06/12-14:55:31.884227 2875746 [ERROR] [db/compaction/compaction.cc:262] Unable to load table properties for file 29704 --- IO error: No such file or directory: While open a file for random read: /var/spool/kumomta/data/029704.sst: No such file or directory
2026/06/12-14:55:31.884311 2875746 [ERROR] [db/db_impl/db_impl_compaction_flush.cc:3385] Waiting after background compaction error: IO error: No such file or directory: While open a file for random read: /var/spool/kumomta/data/029704.sst: No such file or directory, Accumulated background error counts: 6363
```

This commit improves the observability in this situation by proactively
checking for error conditions:

1. The store() and remove() operations now use our own polling within
   a deadline loop rather than spawning a blocking task and delegating
   to rocksdb's blocking interface.  This allows us to inspect the
   background error count and be cancellable, safely respecting and
   caller provided smtp max transaction duration.

2. All read and write operations check for IO and Corruption errors
   and immediately latch an error state

3. The metrics monitoring task inspects and track background error
   counts and latch us into an unhealthy state when the background
   error state appears unhealthy and persistent.

4. Additional metrics are exposed to help monitoring and alerting

While adding integration test coverage for this, I found a typo that
meant that spool errors were ignored in the message crate; they got
silently converted to `true` in all cases rather than just mapping
the success case to a `true`.

Integration tests handle the case where an SST file is corrupted
(truncated) during runtime, as well as starting up when an SST file
is missing.   These excercise both the foreground and background
error detection paths.
2026-06-23 09:11:48 +01:00
Wez Furlong d6eb5176ad docs: remove rapidoc HTTP explorer
It has been replaced by our own static generation.
2026-01-30 16:37:12 +00:00
Wez Furlong 42bf5c5e61 docs: adjust reference to improve search terms
We've been hoping that mkdocs-material will ship the much anticipated
search enhancements for some time, but it's time to recognize that
we need to do something to improve the search results with how
things work right now.

This is a big commit that changes the titles of the various pages
from the code-annotated synopsis to just the name of the function.

This makes it much easier now to match things like `kumo.reject`
directly, but `reject` remains awkward to find.

I think this is the best that we can do at this time.

A few functions have been annotated with the `status: deprecated` to
show as deprecated in the toc/nav (shows with a little trash can next
to the name).
2025-05-16 14:02:19 -07:00
Wez Furlong 337b4e33a8 docs: update for stable 2025.03.19-1d3f1f67 release 2025-03-20 07:28:32 -07:00
Wez Furlong c5014f9594 docs: add some rocksdb tuning options to the docs 2025-03-04 16:23:14 -07:00
Wez Furlong df8aa10ad1 docs: split define_spool docs into separate pages 2025-03-04 16:23:14 -07:00