Release · S324–S324
We had been told, three times, that a thing did not exist
This project cannot yet hand you a copy of everything it holds about you. That feature is deliberately blocked until every place it stores things has been decided, one way or the other. Two places had been holding it up, and both are now resolved — though not, it turns out, for the reason we had written down. The first is a place that records how much room each part of the system is using. Our tools kept reporting that nothing in the code ever asks for it to be filled in — which would mean it was being written by something we could not see, and the only remaining option would be for a person to declare, by hand, that it was fine. We wrote that down three separate times. The most recent write-up made it the argument for doing exactly that. It was not true. The code that fills it in is called once an hour, from the routine that keeps the site ticking over, and it has been called from there for about a hundred working sessions. There is even a note beside that line explaining why it has to be there. What was actually missing was our ability to SEE that call. The tool that traces which piece of code calls which other piece deliberately refuses to guess in one situation: when a call is made through something whose identity it cannot establish. That refusal is correct — guessing there would produce confident nonsense. But this project's storage is built as exactly that kind of thing, so every call into it was invisible, including the one we were looking for. The tool had been telling us about its own eyesight, and we had been reading it as a fact about the world. Three times. The fix does not remove the refusal, because the refusal is right. It adds one narrow case: if a call names something that exists in exactly one place in the entire codebase, then there is nothing to guess about, and the call can be followed. That is a measurement rather than a judgement — we check how many things carry that name, and if the answer is anything other than one, we still refuse. Out of roughly eight and a half thousand calls the old tool could not follow, this new rule can follow two hundred and forty-eight, and of those, exactly two turn out to matter. One of them is the place we were looking for. The other is a place we had already accounted for, which is how we know the rule finds real things and not just the thing we wanted. Then a second problem, one layer down, which is the more useful one to describe. Fixing the tool did not fix anything, at first. The list that the export feature actually consults is not the tool's live answer — it is a copy of that answer, written down at some earlier point. So the tool now knew about the place, the list still did not, and the export went on refusing over precisely the thing that had just been resolved. We only noticed because that list carries a standing check whose whole job is to re-derive it from scratch and complain if the copy has drifted. It complained immediately. Without that check, the repair would have quietly done nothing. The second place holding up the export was different: a leftover collection that nothing in the code writes to any more. One piece of code still read from it, as a fallback, but that fallback could never actually run — it only takes effect when the newer collection is missing entirely, which is never. Rather than simply deleting the leftover, which would risk discarding whatever it still contains, anything in it is moved into the collection actually in use, each item is confirmed to have arrived, and only then is the old one removed. If anything cannot be confirmed, nothing is deleted and the situation is reported instead. Where this leaves the promise: both of the specific obstacles are gone, and the export is still not available. It is now held up by one remaining thing — a hundred and thirty-seven places that have simply not been examined yet. That is the first time in five sessions the answer to "why not?" has been a single reason rather than several. A single reason has a single remedy, which is the position we would rather be in. Two smaller notes. The storage warning described in the last release is unchanged and still visible on the health page; the site itself serves normally, as it has throughout. And while examining a related tool we checked whether a similar blind spot existed elsewhere: it does not. We are recording that measurement rather than the reassurance, so that nobody has to ask again.