Skip to content

Fix: preserve typed refusals across storage boundaries - #133

Open
flyingrobots wants to merge 1 commit into
feature/roadmap-m4-tasksfrom
fix/110-typed-storage-refusals
Open

flyingrobots wants to merge 1 commit into
feature/roadmap-m4-tasksfrom
fix/110-typed-storage-refusals

Conversation

@flyingrobots

Copy link
Copy Markdown
Owner

Errors from durable storage adapters lost concrete causes when wrappers converted them to strings or replaced them with generic refusals. This change preserves typed payloads, original operational failures, and expected/observed coordinates across storage, recovery, retention, migration, GC, and transfer boundaries.

This PR is stacked on the roadmap branch in #107. Its prerequisite is that branch's storage and transfer APIs, including the earlier exact-record source-preservation fix. Review and merge this coherent outcome into that branch; mainline delivery remains pending #107's integration.

Invariant and approach

Keep returns exactly the named bytes or refuses with precise evidence. Shared exact-record conversion preserves OS failures unchanged and wraps semantic refusals as typed payloads. Boundary-owned error enums replace textual failures; predecessor decoding retains its concrete source. ADR-0010 documents the diagnostic API decision.

String parsing and a generic message wrapper were rejected because they erase classifications and causes. Replacing every I/O port signature was unnecessary.

Failure modes and validation

Downcast regressions cover corrupt chunks, byte-equal inode substitutions, malformed GC residue, nonempty reader fences, selected-root bounds and selection mismatches, and corrupt predecessor roots. Assertions failed before fixes; a selected-root stringification mutation also failed and was restored. A targeted source contract guards explicit textual I/O constructors without claiming a general proof of error flows.

Passed with pinned Rust 1.96.0:

  • Formatting and workspace/all-target/all-feature Clippy with warnings denied.
  • Native debug and release workspace suites.
  • Linux ext4 storage suite: 305 tests; Linux cross-build.
  • All 266 killed-writer crash cases in both debug and release.
  • Source structure, documentation integrity, stable fuzz-target compilation, dependency audit, and dependency policy checks.

Compatibility, recovery, performance, and security

Public refusal types and variants are additive; diagnostic wording and classifications become more precise. No identity, format, publication order, synchronization, or recovery protocol changes. No optimization, new dependency, or benchmark claim. Diagnostics retain bounded coordinates rather than content or secrets.

The roadmap and audit ledger record implementation evidence while leaving delivery open until mainline integration. Broader audit findings remain separately tracked.

Refs #110.

Retain concrete causes and expected/observed evidence in storage, recovery, retention, migration, GC, and transfer errors. Add downcast regressions and a production source contract; document the diagnostic API decision and pending integration.

Validation: pinned Rust fmt and Clippy; debug/release workspace tests; Linux ext4 storage laws and 266-case crash matrices in both profiles; source/documentation integrity; dependency audit and policy checks.

Refs #110
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0d67b290-c35e-47c0-abee-867ffd9cd52c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer — integration findings

Reviewing #133 at 66c0e4653424cd36e55a868c24d94898a40aca59 against the current local #107 candidate 92aafcd12ea5ad45e05356865dbc8218092e502d (which includes main 3165890e9291cfb5fe10e81a9d7cd151f3e59464). The normal merge is still local; compilation passes, runtime integration validation is pending.

Severity Location Verified issue Acceptance / disposition
P3 tests/typed_refusal_source_contract.rs:9-73 This assertion searches source spellings and filenames rather than invoking a storage boundary. Aliasing io::Error or moving a literal through a helper evades it; source comments can trip it. It does not establish the runtime typed-source promise, and conflicts with the maintainer's direction to remove brittle source detectors. Retire this detector under Testing Standards rule 18, remove its evidence claims, preserve runtime downcast/refusal laws and explicitly disclose that they are not an exhaustive proof of every error flow.
P4 ROADMAP.md:80 Incoming changes uncheck the existing F-01 checkbox despite the maintainer's instruction to leave previously completed tasks checked during the audit. Preserve the checkbox while retaining the explicit integration-pending audit note.

The merge must preserve main's incomplete-stage disposition-required refusal, original-handle stage identity, effect/durability reporting, bounded reads, namespace guards, and private reader fence. Main's existing RetentionSelectedRootRefusal supersedes the incoming duplicate selected-root enum; retain the incoming runtime scenarios against that existing public contract. Older parallel routines will not replace the current owning paths merely to avoid conflicts.

@codex Please review these concrete integration dispositions; provider unavailability will not be counted as approval.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer — verified integration regression (P2)

src/adapters/retention/filesystem_retention_current.rs::read_exact_optional now preserves ExactRecordError as the I/O payload. src/adapters/retention/verification_observation_error.rs::refusal still recognizes only the old RetentionCurrentStateRefusal wrapper. Consequently a truncated published retention/HEAD is reported by FilesystemRetentionSnapshot::load_for_verification as VerificationError::Operational, although it is demonstrated record corruption.

A deterministic filesystem regression has now executed RED on the unresolved integration candidate: a_truncated_retention_head_remains_corruption_after_typed_error_conversion reports Operational { source: View(Io { source: ... Refused(KindOrLength) }) }. This is a product-boundary assertion failure, not compilation or setup failure. The earlier short-name invocation with --exact selected zero tests and is excluded from evidence.

Acceptance: preserve Corrupt { subject: PublishedView, expected: Canonical, observed: Refused } for exact-record structural contradictions, preserve the typed underlying cause, leave operational failures operational, and leave every retained byte unchanged. Update the consumer classifier rather than reverting #133's source preservation.

The retention run also exposed six older-wrapper expectations. Three predecessor tests must now assert the decoder-bearing PredecessorRootRefused; the substituted-stage test must keep main's RetentionStorageError boundary/effects wrapper; two live-closure tests must inspect the current ClosureMemberRefused payload before its original catalog cause. These adaptations preserve the existing runtime refusal and unchanged-evidence promises.

@codex

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Activity Summary — local #133/#107 integration

The preserved normal merge is 43eaeb3ce850158faa619fc8813c2f98351720b9, with parents 92aafcd12ea5ad45e05356865dbc8218092e502d and #133 head 66c0e4653424cd36e55a868c24d94898a40aca59. The local candidate after the focused classifier fix is 34db5712329612e8306f088116b2c5db063a49cb. These commits are not pushed or merged to main yet.

Item Severity / source Disposition and evidence
Semantic integration Merge review Preserve current incomplete-stage refusal, stage identity, bounded reads, namespace guards and effect reporting. Existing selected-root diagnostics replace the incoming duplicate enum; reader fence remains private. Both-parent conflict decisions are consolidated in docs/testing-evidence/m4-integration.md.
Source-spelling detector P3 / Code Lawyer Retired in 43eaeb3 under the maintainer's testing direction; runtime error/refusal laws remain, with no exhaustive error-flow proof claimed.
Roadmap checkbox P4 / Code Lawyer F-01 remains checked; integration-pending status stays explicit.
Wrong verification classification P2 / Code Lawyer Public truncated-head law is observed RED at exact 43eaeb3. Fix 34db571 preserves Corrupt classification, original exact-record cause and retained evidence. A separate source-erasure mutation fails the intended cause assertion.
Validation Docker execution Debug and release all-feature library runs each pass 494 laws. Final focused debug includes the added exact-source assertion. All-target/all-feature Clippy, format, source structure and changed Markdown pass. Initial compile/lint/test failures and the excluded zero-test invocation are retained.
Independent review Pending Independent Codex is tracing the complete incoming #133 change and merge resolutions at exact 34db571, using the agy-review protocol. No approval is claimed yet.
Remaining gates Open Whole-#107 GC/disposition obligations, per-test resource-policy disposition, full stable-candidate validation and exact pushed-head CI remain required. Earlier #133 hosted checks do not certify the local integrated candidate.

The existing worker and target were reused; no new image/container/volume/target was created. Compiler target is about 905 MiB; host/Docker backing free space remains approximately 712/677 GiB. Historical source/compiler/evidence archives are preserved and explicitly accounted for; they were not pruned speculatively. The focused monitor now stops the owned worker on monitoring failure as well as limit/deadline failure. Aggregate operational guards are not per-test sandbox or suite-SLO compliance.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent scoped review: #133 integrated into #107

Reviewed head: 34db5712329612e8306f088116b2c5db063a49cb, clean in the isolated review checkout. The author checkout was independently checked clean at that same SHA before runtime verification. The full incoming #133 typed-error change, both-parent merge integration and classifier fix are in scope; whole-#107 acceptance and testing-policy approval are excluded.

Baseline: 92aafcd12ea5ad45e05356865dbc8218092e502d. Incoming head: 66c0e4653424cd36e55a868c24d94898a40aca59. Actual merge base: 4b9c38930f988911ab020b7c42e9221b721933af. Normal merge: 43eaeb3ce850158faa619fc8813c2f98351720b9. The reviewed successor fixes the public verification classification regression.

Live Git advertisement confirms main 3165890e9291cfb5fe10e81a9d7cd151f3e59464, remote #107 7cdc2cfbef59407f3c38881b39a290cb85501f9b, and remote #133 66c0e4653424cd36e55a868c24d94898a40aca59. The integrated candidate is local; earlier #107 PR base metadata is not current main. This is the explicitly authorized independent Codex fallback using the complete agy-review protocol. Quota replies and CodeRabbit's skipped review provide no substantive approval.

Findings

No verified P0–P5 defect remains in this declared slice at the reviewed head. Previously posted source-spelling, checkbox and classification findings are closed by the current implementation. Separate inherited obligations and evidence limitations are recorded below, not relabeled as new implementation findings.

Verification Checklist

Every runtime path and parallel implementation

All changed production files were inspected in the baseline-to-candidate diff, with incoming changes separately inspected from their actual merge base. Current owners and surrounding callers were checked wherever integration reroutes behavior. These coordinates refer to the reviewed tree.

Behavior Traced production path and result
Shared exact records src/adapters/filesystem_exact_record.rs:79 preserves original Io unchanged and typed Refused inside InvalidData. Exact read at :161, named verification at :178, absence check at :198, bounded residue read at :233 and no-follow/nonblocking open at :260 retain existing guards. Identity coordinates at :26 expose the recorded device/inode for diagnostics. No stringification is introduced. I/O custom payloads require get_ref(); traversing only Error::source() is insufficient.
Normal snapshot and verification snapshot src/adapters/retention/filesystem_retention_snapshot.rs:131 and filesystem_retention_verification.rs:34 share load_with at filesystem_retention_snapshot.rs:143, the admitted root, fence, source coordinates at :72 and source load at :95. Both observe retention through filesystem_retention_current.rs:113 and exact reading at :296. Verification uses verification_view_collector.rs:27; classifier at :60 consults verification_observation_error.rs:11 and forwards the original view source at verification_view_collector.rs:69. Normal collection preserves the cause; verification adds classification. Moving-view ambiguity and operational failure remain separate.
Classification src/adapters/retention/verification_observation_error.rs:21 recognizes ExactRecordError. At :27, kind/length, identity, byte, trailing-byte and remained-visible contradictions become structural PublishedView corruption; LengthOverflow remains operational. Old current-state mappings at :40 remain. New transition-only NamespaceRead/PredecessorRootRefused variants do not add a coordinate-observation route to those checks. The classifier preserves the producer's original error.
Current retention publication and predecessor src/adapters/retention/filesystem_retention_storage.rs:26 recovers, admits namespace/current state and rechecks closure; predecessor call at :78 reaches filesystem_retention_current.rs:238, committed retry reaches :199. Namespace conversion at :20 retains the actual OS cause, maps demonstrated missing selected namespace to InvalidData, and keeps other original kinds. Decode at :265 retains RetentionRootDecodeError; decoded selection disagreement remains distinct. filesystem_retention_refusal.rs:313 exposes retained sources.
Publication attempt/state src/adapters/retention/filesystem_retention_attempt.rs:31, :36, :76 through :163 retain attempt/namespace/pool/stage refusal conditions and ownership. Only semantic payloads change to FilesystemRetentionStageRefusal, defined at filesystem_retention_stage_refusal.rs:10; filesystem_retention_stage.rs:221 adapts them to I/O. Namespace-coordinate disagreement still uses the existing precise contract.
Retention recovery and stage effects src/adapters/retention/filesystem_retention_recovery.rs:145 checks pinned directories, observes, plans and admits root/closure evidence before reopening at :172 or execution at :176. filesystem_retention_recovery_observation.rs:122 retains regular-file, checked bound-plus-witness observation. Stage create/reopen/sync/link/remove/replace at filesystem_retention_stage.rs:48, :70, :87, :98, :125, :153 retain original handles, exact bytes and identities, mutation uncertainty and applied/unconfirmed effect boundaries. Conversion at :203 keeps main's typed RetentionStorageError mapping. Recovery context failures at filesystem_retention_recovery.rs:183, :190, :229, :282, :322 become typed state payloads. Incomplete stages still require disposition before effects.
Retention disposition src/adapters/retention/filesystem_retention_disposition.rs:162 routes through coordinates at :333, context and resume selection at :398. filesystem_retention_disposition_evidence.rs:29, :114, :126, :147 preserve artifact/decoder/checksum and exact absence causes. filesystem_retention_disposition_storage.rs:20 verifies bytes before unlink; stage operations at :35 through :99 use retained stage authority; pool removal at :118 keeps existing synchronization order. Broader disposition authority/effect completeness remains separately open.
Selected roots and durable anchors src/adapters/retention/filesystem_retention_snapshot.rs:246 checks selected namespace at :340, regular kind and format length at :264, exact read at :293, decoded generation/digest at :309, namespace at :320. Main's RetentionSelectedRootRefusal remains. src/adapters/durable/snapshot.rs:108 calls retained_anchors::verify; retained_anchors.rs:9, :32, :57 read one bounded root at a time and retain typed RootMissing, Snapshot, RootDecode and Closure failures. Incoming inline anchors and duplicate selected-root enum are superseded, not restored.
GC src/adapters/gc/filesystem_gc_authority.rs:138, :199, :241 recover/prepare/execute through existing residue and storage. Intent/receipt absence at :162/:304 becomes typed. filesystem_gc_residue.rs:34 retains bounded observation; :85 preserves exact absence error after discard. filesystem_gc_storage.rs:18, :155, :220 retain context, candidate admission/unlink, exact receipt dependency and intent removal. Semantic payloads are in filesystem_gc_refusal.rs:10. No ordering or admission weakening; broader GC effects/authority acceptance stays open.
Migration authority/fixed records src/adapters/store_migration/filesystem_migration_authority.rs:59, :96, :129, :165 retain authority/observation/current-state/version-one-stage refusal. filesystem_migration_storage.rs:15 through :118 implement intent/fence/namespace/marker/receipt phases; state checks at :131, :161, :189, :206 use typed FilesystemMigrationRefusal. A taken wrong-artifact stage is restored before refusal. filesystem_migration_fixed_artifact.rs:145 retains identity/record checks; conversion at :202 preserves original OS and shared exact-record errors.
Migration namespace/fence src/adapters/store_migration/filesystem_migration_namespace.rs:80, :102, :121, :236, :288 retain fence admission and full/partial ordered prefix checks. filesystem_migration_namespace_directory.rs:21, :42, :66, :88, :100, :108, :121, :132, :143, :169 retain pinned identity, filesystem/mount, kind/length, emptiness and membership. filesystem_migration_reader_fence.rs:22 retains zero-length regular inode/device checks. Error payloads change; mutation order does not.
Migration recovery/residue src/adapters/store_migration/filesystem_migration_recovery.rs:124 permits only incomplete regular pre-effect disposal, preserving exact absence and checked conversion/sync causes; adoption at :157 binds reopened handles. filesystem_migration_residue.rs:22, :35, :42, :79 retains bounded no-follow observations and current precise FilesystemMigrationRecoveryRefusal coordinates. These current owners supersede older incoming variants. migration_resumption.rs:157 reports the exact wrong-section phase through a typed payload.
Shared/exclusive reader fences src/adapters/retention/reader_fence.rs:36 and :60 both open no-follow and verify before/after flock. :74 splits the same predicate into kind, exact zero-length and identity diagnostics from reader_fence_refusal.rs:10/:20. Shared wait/exclusive nonblocking behavior and lifetime remain. ReaderFence stays adapter-private at reader_fence.rs:26 and retention.rs:300; diagnostic types alone become public. GC/disposition retain existing exclusive authority.
Initialization/publication prefixes src/adapters/filesystem_initialization_storage.rs:25, :52, :61, :80, :105 preserve namespace admission and retained writer authority before mutation. Main's filesystem_initialization_namespace.rs:233 remains the precise namespace refusal. filesystem_catalog_catalog.rs:30 and filesystem_catalog_head.rs:30 retain checked slices and now carry artifact/maximum/requested prefix coordinates. Exclusive creation/flush/sync/publication ordering is unchanged.
Platform/lock/inventory/materialization src/adapters/filesystem_platform_profile.rs:42/:80 open no-symlink roots; nested directory at :132, statx at :149/:228, profile at :301 and mount at :322 retain exact masks/flags/device/mount observations. Ordinary non-Linux paths still refuse Unsupported. filesystem_writer_lock.rs:173 and filesystem_recovery_namespace.rs:40 preserve pinned identity. Census at filesystem_recovery_inventory_scan.rs:9/:36 uses checked count/conversion/capacity and one drift witness. filesystem_recovery_stage_materialization.rs:43 retains exact short-read counts. sync_capable_directory.rs:10 still refuses non-directories. New semantic payloads are in filesystem_operation_refusal.rs:10, with the carried conversion source.
Compaction/ingestion recovery src/adapters/compaction/recovery.rs:82 and shared recover_with at :113 retain split preflight/observation/execution. recovery_preflight.rs:43, :166, :204, :232 admit all stages, derivable/unpublished records and successor coordinates with the new recovery_refusal.rs:10 payloads. recovery_execution.rs:24, :45, :79, :122 retain queue ordering, original stage observations, first-error stop, prior completions and failing-action effects. Complete/truncated stages and both HEAD outcomes remain under current guards. Old incoming stage-absence/change routines do not replace current observations/lower executors.
Authenticated reads/transfer src/authenticated_read/chunk_verification.rs:23 keeps immutable-source authentication; Error at :100 retains hashing cause. chunk_reader.rs:52 latches the original refusal, :109 uses it as InvalidData payload, and :74 projects missing/hash/identity into transfer vocabulary. Both reference/durable consumers use this current shared owner. src/adapters/pipeline/transfer.rs:133 returns original sink/read/cancellation/accounting errors; :228 stores the real failure and emits private typed TransferStop; :238 retains cancellation/accounting/window behavior. No formatted string replaces the chunk cause or original sink cause.
Registration/API/conformance Inspected src/adapters/compaction/mod.rs, gc/mod.rs, mod.rs, exports.rs, retention.rs, store_migration.rs, src/lib.rs:80/:187 and src/store/port_laws.rs. Additive diagnostic exports/tests are registered, existing wrappers retained, no duplicate selected-root type or ReaderFence export, no dependency added. Conformance functions now forward typed errors with ?. Public diagnostic wording/variant matching intentionally changes; no wire format changes.

Merges and prior findings

  • Audited merge 43eaeb3ce850158faa619fc8813c2f98351720b9 against BOTH full parents stated above. The incoming diff is 4b9c389..66c0e46; the declared baseline-to-head slice contains exactly one merge. Older implementations did not overwrite active owners to avoid conflicts.
  • Reconciled the compaction, durable, exact-record/initialization/platform, GC, retention, selected-root, migration and public-export conflict groups against actual current code. Confirmed baseline-to-candidate byte identity for superseding durable snapshot/retained-anchor, initialization namespace, retention selected-root, migration recovery and migration residue owners.
  • Inspected relevant inherited main integration 864f804816ba5b201902143dd7b160ff6ff4b3c9, parents 7cdc2cfbef59407f3c38881b39a290cb85501f9b and 3165890e9291cfb5fe10e81a9d7cd151f3e59464, including retained incomplete-stage refusal before execution. Current main namespace, no-follow, exact-byte/source-stage-identity, bounded materialization and effect/durability contracts remain. This is preservation review of relevant invariants, not whole inherited-merge acceptance.
  • Rechecked prior stage-identity, sync-outcome, recovery-progress and compaction-bound fixes where incoming integration touches their owners. No new evidence reopens closed findings. Failed synchronization remains unconfirmed durability, never rollback; a fresh idle observation does not certify a prior failed sync. Raw adversarial namespace mutation outside cooperating writer isolation gets no invented atomic guarantee.
  • Incoming source-spelling detector and duplicate retention_snapshot_refusal.rs are absent. Runtime laws remain registered. F-01 at ROADMAP.md:80 stays checked, with a partial/integration-pending audit note. These close the posted P3/P4 dispositions.

Tests, exact sources and oracle changes

  • src/authenticated_read/chunk_reader.rs:237: corrupt later chunk asserts the actual typed identity mismatch and expected/observed identities.
  • retention/retention_snapshot_refusal_tests.rs:16/:52: sparse over-bound root asserts exact Length; valid canonical successor under the selected filename asserts exact generation/digest Coordinate. Both check unchanged retention HEAD against main's existing enum. These are not new allocation benchmarks or atomic namespace proofs.
  • filesystem_retention_snapshot_tests.rs:134: nonempty fence asserts exact zero/9/9 lengths through ReaderFenceRefusal.
  • filesystem_retention_expectation_tests.rs:136 and filesystem_retention_recovery_predecessor_tests.rs:99: corrupt predecessor requires decoder-bearing ChecksumMismatch; valid substituted selection remains a distinct disagreement. Existing preservation checks remain.
  • filesystem_retention_storage_tests.rs:110: substituted root requires RetentionStorageError::Operation, PoolVerification and inner KindLengthOrIdentity, preserving main's progress wrapper.
  • filesystem_retention_publication_closure_tests.rs:58: two closure laws traverse ClosureMemberRefused before exact missing/corrupt catalog causes; retained-byte assertions remain.
  • store_migration/filesystem_migration_storage_tests.rs:63: substituted intent downcasts exact KindLengthOrIdentity. gc/filesystem_gc_residue.rs:105: a real non-regular record requires InvalidData and typed KindOrLength. filesystem_platform_profile_tests.rs:59 asserts typed profile/mount refusal categories.
  • retention/verification_record_refusal_tests.rs:16: public loader receives canonical HEAD shortened by one byte; exact Corrupt/PublishedView/Canonical/Refused, original ExactRecordError::Refused(KindOrLength), and unchanged retained-evidence witness are asserted. Medium filesystem product law, deterministic input, owned scratch, deletion criterion; no random seed/reducer applies.
  • 133-retention-initial.txt:298 preserves six older-wrapper failures, 241 passes, 245 filtered. The six expectation adaptations above retain the actual old storage outcomes; those failed wrapper expectations are not six new production defects.
  • 133-verification-red-43eaeb3.txt:7/:14/:21 executes one failing law on exact merge checkpoint: required corruption is Operational with retained KindOrLength. Earlier 133-verification-red.txt is additional observed RED; 133-zero-selection-excluded.txt:6 executes zero laws and is excluded.
  • 133-source-control.patch changes only the returned cause while retaining Corrupt classification. 133-source-control.txt:14 fails the intended exact-source assertion. The candidate collector forwards the original source, confirming restoration. This calibrates source independently of classification.
  • 133-verification-final-debug.txt:9, 133-library-debug.txt:502, 133-library-release.txt:502: final focused debug passes; all-feature library debug/release each pass 494 laws. Full debug precedes the added exact-source assertion; final focused debug and full release include it. Test count reports selection, not a proof of correctness.
  • Historical incoming calibration/workspace/crash claims are explicitly historical in the integrated audit. Original selected-root stringification control was not reproduced by this reviewer. No fresh exhaustive calibration of inherited assertions is claimed. Source spelling is not a product oracle and its deletion does not imply universal source preservation.

Constants, numeric claims and documents

No protocol timing/rate/buffer/size limit changes in this slice. New numeric diagnostic fields report the limits and observations already used by guards.

Constant / claim Source / evidence checked Result and limit
Exact lengths, one corruption/drift witness filesystem_exact_record.rs:161/:233; checked retention/migration/GC observation bounds. Checked conversions and bounded reads remain; error conversion introduces no enlarged-record allocation.
Inventory maximum 2,097,152 src/adapters/recovery/recovery_inventory_limit.rs:14, census owner filesystem_recovery_inventory_scan.rs:9/:36. Unchanged protocol ceiling, checked increments/conversion/capacity; new payloads retain maximum/observed and conversion source.
Root format bound retention/root_header_decoder.rs:9–:17: 192-byte header + 255 namespace bytes + 65,536 × 119-byte anchors + 64-byte trailer; new law grows by checked one beyond that maximum. Unchanged limit; exact maximum/observed asserted with unchanged HEAD. No peak-memory or throughput measurement inferred.
GC 65,536 candidates, 320-byte receipt gc/intent.rs:20, filesystem_gc_residue.rs:25, filesystem_gc_storage.rs:221. Unchanged format/protocol values; focused success does not satisfy separately missing stress/benchmark acceptance.
Migration six directories, canonical lengths, zero-length fence filesystem_migration_namespace.rs:100, format-marker/intent/receipt decoder constants, fixed-artifact/residue/namespace owners, reader_fence.rs:84. Existing prefix order, fixed lengths and zero bound retained.
ext4 magic/casefold and statx masks filesystem_platform_profile.rs:157, :234, :304: magic 0x0000_ef53, casefold 0x4000_0000, actual requested/observed masks and device/mount coordinates. Non-lossy diagnostic widening; no new platform support or changed admission threshold.
Six wrapper failures 133-retention-initial.txt:298 and six named failed laws; changed assertion sites. Exactly six retained original failures; later successes do not erase them.
One classifier RED, one source-control RED, zero-test exclusion RED/control receipts and patch listed above. Actual executed assertion failures; setup/compilation/zero-selection excluded.
494 debug and 494 release laws 133-library-debug.txt:502, 133-library-release.txt:502, current feature registrations. Consistent all-feature counts. Reviewer default-feature selection ran one law with 492 filtered, out of 493; one repository-task feature-gated law accounts for the difference.
Initial/final build and Clippy 133-build-initial.txt, 133-build-pass.txt; 133-clippy-initial.txt, 133-clippy-final.txt. Initial compilation failures retained, not RED. Three Clippy diagnostics are duplicate source arms and two missing-const suggestions. Current merged arms/const helpers and final success match the receipt; declaration-only changes do not alter source forwarding.
Formatting, structure, six Markdown files 133-format-check.txt, 133-structure.txt, 133-markdown.txt. Successful exits inspected; Markdown lists six changed files and no issues. Static/tool evidence does not certify storage behavior.
58-file source identity 133-source-sha256.txt, reviewer SHA-256 verification. All 58 changed Rust entries match the exact candidate. Manifest identifies source; alone it does not cryptographically attest every earlier command's input.
Rust 1.96.0, four CPUs, 8 GiB, two jobs, incremental off, offline deps Supplied pinned runner/worker configuration, Docker inspection and reviewer receipt. Existing worker/cache reused; no host Rust test or new target.
20 GiB build, 4 GiB runtime, 128 MiB logs, 50 GiB free, 900-second deadline Inspected bounded wrapper and before/after actual measurements. Conservative aggregate accounting; monitors refuse/stop owned workload on failure. These are not per-test memory/time ceilings, egress isolation or measured suite SLO.
Historical 905 MiB target, 712/677 GiB free, 7.9/3.5 GiB archives Independent after-run target 905 MiB, source 14 MiB, quota filesystem 921 MiB used, host 711 GiB free, backing 677 GiB free; archives still 7.9/3.5 GiB. Historical rounded 712 GiB is not presented as current host free. Separate raw historical disk measurement attestation is absent; current substantial headroom and preserved archives are verified.

Changed prose inspected: CHANGELOG.md, ROADMAP.md, docs/adr/0010-preserve-typed-storage-refusals.md, docs/adr/README.md, docs/audits/completed-roadmap-2026-09-30.md, docs/testing-evidence/m4-integration.md; adjacent 133-* receipts/control/manifest were reconciled. No changed README numeric claim exists. Dates, issue/ADR numbers and source SHAs identify historical/local coordinates, not performance measurements.

ADR-0010 matches current custom I/O payload access, typed operational/decoder sources, selected-root replacement, private authority, source-detector retirement, additive diagnostic API and classifier correction. Changelog claims are supported by current paths/laws without format, performance or power-loss claims. F-01 remains checked while audit/delivery remains partial. The dated audit's older matrix and PR-body figures, including 305 Linux storage tests and 266 killed-writer cases, are historical author evidence claims, not independently reproduced measurements of this candidate. They are explicitly excluded from this approval's runtime basis; the integrated documentation caveats them. No unsupported historical figure is used to discharge current acceptance.

Standards, discussion and limitations

  • Applied repository AGENTS.md, binding docs/Testing Standards.md and docs/testing/enforcement.md. Relevant contracts are exact bytes or explicit refusal, checked influenced arithmetic, typed boundaries, inward dependencies, deterministic identity/selection, bounded/no-follow admission, retained authority and truthful uncertainty/durability.
  • Checked semantic module ownership, Error/Display/source implementations, private capability versus public diagnostics, exact matching and mutation order. No unsafe code, dependency, format encoder/parser or optimization is added. Source structure/fmt/Clippy evidence is separate from product evidence. This repository does not impose another project's single-physical-line-per-paragraph convention.
  • New classification law declares medium size, deterministic oracle, deletion criterion and actual RED plus source-control falsification. Other new/adapted laws retain documented runtime oracles. Scratch ownership is not resource isolation. Per-test size admission, deadline/memory enforcement, network/egress restriction, complete recalibration of inherited assertions and measured suite budgets remain policy gaps; this review grants no waiver or whole-PR compliance claim.
  • Refreshed and read the entire live Fix: preserve typed refusals across storage boundaries #133 discussion: seven top-level comments, zero reviews, zero review threads; all three connections have hasNextPage: false. There are no nested review-comment pages. Read the body, quota/skipped-provider notices, P3/P4 integration dispositions, P2 classifier finding and activity summary. The activity summary adds no new implementation defect. Prior Roadmap: M4 tasks — retention, GC, compaction, verification, durable reads and ingestion, transfer pipeline #107 ledger/scope limitations remain constraints rather than renewed whole-PR approval.
  • No mandatory production-path, merge or classification area in the declared slice was left uninspected. Execution does not cover every error arm, platform or interruption. Historical evidence/measurement limits above remain explicit and are not invented successful checks.

Executed versus inspected checks

Executed independently:

Inspected only: initial/final all-target build, first six retention wrapper failures, exact-merge classifier RED, source-erasure control, author all-feature 494-law debug/release library runs, author final focused debug, initial/final Clippy, fmt, structure, changed Markdown, earlier scope evidence and incoming historical claims. Compilation/setup/zero-test results are excluded from runtime RED.

Not performed: a new full workspace campaign, optimized reviewer repetition, crash/process-death/fuzz/dependency campaign, hosted/pushed-head CI, cross-platform execution, physical power-loss testing, arbitrary concurrent raw namespace isolation, performance measurement or testing-policy approval. Inspected success is not execution by this reviewer and does not imply these missing checks. Full stable-candidate validation remains required separately.

Only the sole shared worker/target was used. No image/container/volume/builder/cache/target was created; no source/configuration changed or unknown archive deleted. After the focused run: target 905 MiB; 20 GiB ext4 source/cache filesystem 921 MiB used; host 711 GiB free; Docker backing 677 GiB free; retained historical build/source/evidence archives 7.9 GiB and 3.5 GiB. The conservative wrapper counted retained artifacts and current runtime/log usage; no guard fired. Worker was idle and explicitly released to the parent; no reviewer workload remains. Aggregate controls do not prove per-test sandbox/SLO compliance or every archive's provenance.

Scoped verdict

Approve the complete incoming #133 typed-error integration and classifier repair at exact 34db5712329612e8306f088116b2c5db063a49cb. Whole-#107 GC/disposition/authority obligations, per-test resource-policy disposition, full final validation and exact pushed-head CI remain open. This verdict authorizes no publication, merge or policy waiver.

APPROVE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant