fix(sync): skip records that fail to decrypt or decode instead of failing the whole store - #3569
Conversation
…ling the whole store build
|
@greptile-apps plz sir may i have one review 🙏 |
Greptile SummaryReviewed PR #3569 which converts hard decrypt/decode failures across all record stores into skip-and-warn behavior. Found one P1 issue: Confidence Score: 4/5Safe to merge; the only concern is that build-level failures in sync.rs still use eprintln! and can surface in interactive sessions. The store-level changes are correct and well-tested. The one gap is sync.rs, which uses eprintln! for build failures while the same function is called from interactive history sessions. crates/atuin/src/sync.rs — eprintln! should be tracing::warn! to match the rest of the PR and avoid terminal pollution in interactive sessions. Important Files Changed
Reviews (2): Last reviewed commit: "review fixes" | Re-trigger Greptile |
BinaryMuse
left a comment
There was a problem hiding this comment.
This seems reasonable. Do we have a good way to surface to the user that something went wrong other than them looking in the logs?
### Bug Fixes - *(ai)* Dispatch skills registered in the slash command registry ([#3593](#3593)) - *(ci)* Fossier install in scan workflow ([#3485](#3485)) - *(i18n)* Fix typos in Russian localization ([#3575](#3575)) - *(nu)* Use `char -u 1b` for ESC in OSC 133 sequences ([#3530](#3530)) - *(nu)* Suppress error when `ATUIN_HISTORY_ID` is missing in `pre_prompt` hook ([#3587](#3587)) - *(pi)* Observe tool events instead of registering a bash tool ([#3557](#3557)) - *(pty-proxy)* Set `$SHELL` to the spawned shell ([#3548](#3548)) - *(search)* Fix terminal clearing with latest Ratatui ([#3578](#3578)) - *(sync)* Skip records that fail to decrypt or decode instead of failing the whole store ([#3569](#3569)) - Atuin hangs when attempting to spawn daemon from Ctrl+R invocation ([#3502](#3502)) - Capture session ID from stream headers rather than final event ([#3531](#3531)) - Doctor resiliency fo runknown platforms + openbsd warning ([#3551](#3551)) - Double input on arrow keys in AI setup prompt on Windows ([#3552](#3552)) - Exclude AI agent commands from zsh-autosuggestions ([#3567](#3567)) - Silence shellcheck SC2016 on literal `$all-user` author filter - Respect `store_failed` when using daemon ([#3571](#3571)) ### Documentation - Highlight `Ctrl-r` keybinding on docs page ([#3489](#3489)) - Document store purge workflow ([#3544](#3544)) - Fix command example typo in documentation ([#3536](#3536)) - Make commented-out lines in `config.toml` match real defaults ([#3583](#3583)) - Add fish shell cleanup step to uninstall instructions ([#3582](#3582)) ### Features - *(doctor)* Add whether daemon is enabled to `doctor` output ([#3572](#3572)) - *(pty-proxy)* Add `--shell` flag to override the spawned shell ([#3327](#3327)) - Setup fossier to stop bot slop prs ([#3482](#3482)) - Capture command output + expose to new `atuin_output` tool ([#3510](#3510)) - Cache user contexts on load until `/reload` ([#3525](#3525)) - Create database integration tests for atuin-server ([#3514](#3514)) - Add `/model` slash command for changing models ([#3576](#3576)) - Add mcp server for history tools and expand search filters ([#3581](#3581)) - Add status bar with model and usage information ([#3591](#3591)) ### Miscellaneous Tasks - *(rustdoc)* Fix Rustdoc warnings ([#3585](#3585)) - *(warnings)* Fix compile warnings with latest dependencies ([#3586](#3586)) - Vouch for all existing contributors ([#3486](#3486)) - Update GitHub app token format - Update to Rust 1.96.1 ([#3568](#3568)) - Adopt `derive_more` to reduce boilerplate across the codebase ([#3573](#3573)) ### Performance - *(search)* Scan history by recency until N unique ([#3553](#3553)) - Add `synchronous(Normal)` + `optimize_on_close` to record store SQLite ([#3577](#3577)) - Remove unnecessary clones in a hot path ([#3580](#3580)) ### Refactor - Implement `From<sqlx::Error>` and clean up `fix_error` ([#3484](#3484)) - Pull `fn into_utc` into `atuin-server-database` crate ([#3487](#3487))
@ellie: I have a solution for this in #3429, which adds |
Previously, we chose to fail loudly when there was a key mismatch in a users store. However, in the past, we did not check the key at login, so users could easily end up in a state where they inserted an invalid key, and then broke their store.
This PR ensures that even with a partially invalid store, the user can still sync their data.
This does not mean that users will be able to introduce new invalid keys, and simply makes things better for older users (pre key-checking). We still need to figure out a more straightforward way for a user to repair their entire record store if they have somehow mixed up keys, other than the
purge+push/pull --forcesteps.Checks