Require durable R2 storage for inbound MIME - #853
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (12)
📝 WalkthroughWalkthroughInbound email persistence now requires R2-first MIME storage and typed retryable failures. Daily receive quotas are refunded for pre-commit storage failures using the original UTC day, while post-commit bookkeeping failures do not trigger retries or refunds. Tests and documentation cover these contracts. ChangesInbound storage and quota handling
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant EmailRouting
participant handleInboundEmail
participant parseAndStoreInboundEmail
participant EMAIL_BLOBS
participant D1
EmailRouting->>handleInboundEmail: deliver inbound email
handleInboundEmail->>parseAndStoreInboundEmail: consume daily receive quota
parseAndStoreInboundEmail->>EMAIL_BLOBS: store raw MIME
parseAndStoreInboundEmail->>D1: insert message and attachments
D1-->>parseAndStoreInboundEmail: commit result
parseAndStoreInboundEmail-->>handleInboundEmail: return or throw storage error
handleInboundEmail->>handleInboundEmail: refund quota for retryable pre-commit failure
handleInboundEmail-->>EmailRouting: rethrow for retry
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
51d8fa9 to
a5e1f9c
Compare
|
🔎 Preview deployed: https://kody-pr-853.kody-a99.workers.dev Worker: Mocks:
|
Summary
EMAIL_BLOBSbefore inserting its D1 message rowraw_mimewrites; R2 failures propagate for Email Routing retryDurability policy
R2 is required for inbound MIME. A transient pre-commit R2/D1 failure is retried and does not consume receive quota. Once message+attachment rows are durable, bookkeeping failures are logged/acknowledged rather than retried, preventing duplicate mail.
Validation
System recap — extends existing primitives (medium risk)
Mode: recap · Base:
main@1689cd0c· Head:81899dbcClassification: extends — makes R2 the required durability boundary for inbound email MIME.
Primitives touched
emailemail-blobs-r2entitlementsInvariants
email_messages.raw_mimewrites.Summary by CodeRabbit
Improvements
Documentation