feat: add exact owner-directed thread purges - #227
Conversation
Adapt the ownership and exclusion design from #217 into a bounded native-local command with content-bound plan identities and atomic apply. Prepare 0.15.0 notes; release remains gated on Apple's notarization agreement. Co-authored-by: Hannes Rudolph <49103247+hannesrudolph@users.noreply.github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed October 1, 2026, 9:32 AM ET / 13:32 UTC. ClawSweeper reviewWhat this changesAdds a preview-and-apply command that permanently removes selected conversations from Gitcrawl’s local archive and prevents later collection from restoring them. Regression provenancePossible regression — suspected (reviewed change). No predecessor PR is attributed. Merge readiness⛔ Blocked before merge - 4 items remain This remains useful work absent from current main, but the new export refusal can consume the active archive without producing an artifact. The narrower replacement retains that blocking defect from the related proposal. Priority: P0 Review scores
Verification
How this fits togetherGitcrawl collects GitHub conversations into a local SQLite archive used for search, analytics, and clustering. The purge command changes that archive and its collection policy, which portable export also consumes. flowchart LR
A[Selected conversations] --> B[Preview exact removal]
B --> C[Validate and apply transaction]
C --> D[Archive and durable exclusions]
E[GitHub collection] --> F[Check exclusions]
F --> D
D --> G[Portable export or refusal]
Before merge
Findings
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Copy recommended automerge instructionTechnical reviewBest possible solution: Reject excluded archives under the consume-source lock before moving them, while preserving the existing post-handoff failure contract. Do we have a high-confidence way to reproduce the issue? Yes, from source: export a closed, rollback-journal archive containing an owner exclusion with --consume-source; the new guard fails after rename and cleanup deletes staging. This review did not execute that path. Is this the best way to solve the issue? No. The bounded native purge is useful, but its publication refusal must occur before consuming the source; a locked preflight is a focused repair. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against db5f6bc22908. LabelsLabel changes:
Label justifications:
EvidenceAcceptance criteria:
What I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Owner-directed removal needs to delete archived content and retry work while keeping later crawls from restoring it. This replaces the stacked proposal in #217 with a bounded native-local
purge-threadscommand, retaining Hannes Rudolph's ownership and exclusion design.Preview
purge-threads owner/repo --numbers 123,456 --json, then pass the returnedplan_idto--apply. The ID binds the archive, exact selected identities, and selected stored rows. Apply revalidates that plan inside the same transaction that removes content/history/derived records and retry work and installs durable exclusions. Shared actor profiles and unrelated conversations remain intact. Owner removal stays separate from provider deletion and successful recovery.Size: +1,467/-22 across 21 files versus the stacked #217 at +7,431/-99 across 49 files (80% fewer added lines). The original removal-only commit was +1,509/-16; this candidate also adds content-bound plan identity and stronger rollback/collection tests.
Scope cuts: no portable runtime-mirror mutation or refresh ownership path, no arbitrary request-ID option, no idempotent reapply mode, no speculative blob cleanup, and one concise documentation section. Unsafe blob, shared cluster/workflow, ambiguous-identity and reusable-native-ID targets are refused. Portable publication with local exclusions is refused. Existing REST, GraphQL, analytics discovery/recovery, identity enrichment and store write paths respect the exclusions.
Credits: adapted from #217 by @hannesrudolph (Hannes Rudolph); his contribution is retained in the squash attribution and changelog.
Validation: synthetic archive regression tests cover exact selection, stable/stale plans, second-target failure rollback, content/revision/retry removal, shared actor and peer preservation, collection suppression, late receipts, unsafe targets, migrations, and CLI ownership locking.
make checkpassed on one AWS Crabbox lease after all 412 source-file hashes were verified; isolated Codex autoreview is clean through P2. Exact-head CI passed ford4c395d822f4e2baba853748a53334ac237d8c3f: Linux/macOS Go, Windows and Docs, Docker, secret scanning, Socket and CodeQL. Full gate coverage: 85.6%.Also prepares 0.15.0 release notes with an empty Unreleased section. Release dispatch is held while Apple's notarization preflight returns HTTP 403; no tag is created by this PR.