Observed behavior: The stats and pool diagnostic route handlers call backendDiagnosticFailure(error) for unexpected errors other than StatsUnavailableError. That defaults to backend unavailable, even when the handler was supplied a known authenticated storage factory. The sanitized fallback loses the selected-backend fact that the status handler already preserves.
Expected behavior: Unexpected failure snapshots should retain the known selected backend where it remains authenticated, while preserving fixed error classification, no raw exception output, and outer publication admission. When no factory is available, keep the honest unavailable fallback.
Root cause: src/daemon/routes/stats.ts and src/daemon/routes/pool-stats.ts omit the optional backend argument in their generic error branches; src/daemon/routes/status.ts already passes its known configured backend.
How to reproduce: Instantiate either route with an authenticated SQLite or PostgreSQL factory, inject an unexpected non-StatsUnavailableError collection failure through the existing public test seam, and inspect its JSON response. The backend becomes unavailable instead of the known backend. Test both backends, missing-factory behavior, exception canaries, and outer publication-witness rejection.
Review provenance and scope: Accepted P2 combining the same defect from PR #1103 comment 3945663155 and comment 3945663170, candidate 801f79f27e449bffa1db60c8ec3de18016ebd47b, originating Feature #619. Filed after all three initial candidate review rounds were spent under the approved deferral policy. Separate native Bug outside the fixed Epic #224 delivery inventory; this does not alter the successful or classified StatsUnavailableError responses.
Environment:
- Agent: Codex, Astra delivery owner; Copilot PR review findings
- Connector: CLI/repository source review
- OS: Fedora Linux
Observed behavior: The stats and pool diagnostic route handlers call
backendDiagnosticFailure(error)for unexpected errors other thanStatsUnavailableError. That defaults to backendunavailable, even when the handler was supplied a known authenticated storage factory. The sanitized fallback loses the selected-backend fact that the status handler already preserves.Expected behavior: Unexpected failure snapshots should retain the known selected backend where it remains authenticated, while preserving fixed error classification, no raw exception output, and outer publication admission. When no factory is available, keep the honest unavailable fallback.
Root cause:
src/daemon/routes/stats.tsandsrc/daemon/routes/pool-stats.tsomit the optional backend argument in their generic error branches;src/daemon/routes/status.tsalready passes its known configured backend.How to reproduce: Instantiate either route with an authenticated SQLite or PostgreSQL factory, inject an unexpected non-StatsUnavailableError collection failure through the existing public test seam, and inspect its JSON response. The backend becomes unavailable instead of the known backend. Test both backends, missing-factory behavior, exception canaries, and outer publication-witness rejection.
Review provenance and scope: Accepted P2 combining the same defect from PR #1103 comment 3945663155 and comment 3945663170, candidate
801f79f27e449bffa1db60c8ec3de18016ebd47b, originating Feature #619. Filed after all three initial candidate review rounds were spent under the approved deferral policy. Separate native Bug outside the fixed Epic #224 delivery inventory; this does not alter the successful or classified StatsUnavailableError responses.Environment: