Collectors record the result of every source (schema v3, table
source_status); /health reports failing sources (failures in a row >=
source_failure_threshold) and turns degraded; GET /sources shows the full
state; runs end with a summary log line instead of "data saved".
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Restoring a backup with no data while sources are configured now sets the
db_recreated.json marker (503 until data is collected), and the backup job
skips copying an empty database in that state. Adds finding 11 to the review.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
/addresses reads the cursor and data in one session and one snapshot,
/health exposes only time and backup file name of the last restore,
get_changes checks presence in batches instead of per value (6.8 s -> 88 ms
on a 12k-entry journal). Adds the plan for review fixes 5-10.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
When ripe.db is corrupted and no valid backup exists, a new empty database
is created with a db_recreated.json marker; /addresses and /addresses/diff
answer 503 until the collector gathers data again, /health reports
db_recreated. Tests now isolate all state files via conftest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Daemon job "backup" (online copy, quick_check, rotation), restore of the
newest valid copy when the database cannot be opened, change journal reset
after restore, last_restore in /health, docs and tests.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>