Skip to content

Type 2 column-default rewrite gate should use commit deltas, not main-only #693

Description

@cbb330

Problem

ReadBridgeStripProtection.isRewrite treats a commit as a rewrite only if the main-branch snapshot (or a replace/RTAS flag) is overwrite/replace.

The snapshots PUT sends the table's full snapshot list and ref map. Main-only is how we avoid treating a historical overwrite still in that list as "this commit." Side effect: a WAP / named-branch overwrite leaves main on an old append, so Type 2 does not fire. An unaware client can overwrite a stamped table on a branch without sending initial-default.

Do not

Do not infer the written ref by diffing existing vs incoming snapshot-ref maps. That re-derives what the commit already knew and fails on create-branch-at-same-snapshot, tags, and multi-ref PUTs.

Do

#669 adds optional jsonMetadataUpdates on IcebergSnapshotsRequestBody: Iceberg REST TableUpdate deltas (add-snapshot, set-snapshot-ref) from TableMetadata.changes().

After #669 (or equivalent) lands:

  1. Plumb those deltas to the write path that calls ReadBridgeStripProtection.prepare (today they are audit-only).
  2. Type 2: if an add-snapshot in this commit is overwrite/replace, require a matching initial-default handshake. Use set-snapshot-ref for which branch was written (main, WAP, …).
  3. CREATE BRANCH with only set-snapshot-ref and no new snapshot is not a rewrite.
  4. Clients that omit jsonMetadataUpdates keep the current main-only fallback.

Depends on #669. Blocks closing the WAP gap called out on #678.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions