refactor(state): one read-only URI builder; probe a held store via snapshot only

read_only_db_uri() replaces four inline mode=ro URI sites (two of which
still used the raw f-string that truncates on ?/# in the home path:
state_db_has_structural_damage and collect_state_db_stats). The doctor
write probe now applies the live-holder gate in both modes: a quiet store
is probed in place as on main, a held store is probed through a read-only
snapshot, and a held store over 1 GB is skipped with an info line unless
--fix is given (the unconditional copy cost one full DB write per plain
doctor run). Connect/backup failures propagate to the existing
classification instead of being reported as FTS write-health failures.
Observational sessions commands print a migration hint instead of a raw
traceback when a read-only opener meets an older schema.

Co-authored-by: Ahmett101 <Ahmett101@users.noreply.github.com>
This commit is contained in:
kshitijk4poor
2026-09-15 12:20:19 +05:30
committed by kshitij
parent e30c4ed50d
commit 55d9a49c1d
7 changed files with 64 additions and 24 deletions
+2 -1
View File
@@ -26,6 +26,7 @@ from typing import Any, Callable, Dict, List, Optional, Tuple
from hermes_state_holders import canonical_sqlite_path
from hermes_state_common import (
read_only_db_uri,
FTS_REBUILD_DEFERRAL_KEY, stat_db_file_identity as _stat_db_file_identity
)
@@ -716,7 +717,7 @@ def collect_state_db_stats(db_path: Path) -> Dict[str, Any]:
try:
# A short timeout keeps doctor snappy when a writer holds the lock. The tracked connect
# lets byte-probe helpers see this connection and refuse raw opens that would cancel locks.
conn = _connect_tracked_db(f"file:{Path(db_path)}?mode=ro", tracking_path=Path(db_path),
conn = _connect_tracked_db(read_only_db_uri(db_path), tracking_path=Path(db_path),
uri=True, timeout=2.0)
except Exception as exc:
logger.debug("collect_state_db_stats: cannot open %s read-only: %s", db_path, exc)