Skip to content

Test: verify public admitted filesystem stages (#147) - #156

Merged
flyingrobots merged 2 commits into
mainfrom
test/147-public-filesystem-stage
Oct 3, 2026
Merged

flyingrobots merged 2 commits into
mainfrom
test/147-public-filesystem-stage

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Problem and approach

Completed roadmap task T-11.3 promised tests/segment_filesystem_stage.rs, but only private adapter laws and a sandbox module existed. This PR adds that public integration target through real FilesystemPlatformAdmission::initialize and the ordinary catalog publisher constructor. It started from main 6051abb after #99 and now includes main 64fafe3ddcc92bcc45a461a0161030b87559070d through normal merge 05658799fb259a445f68c8bd434135483d491e40. The changelog resolution retains every incoming entry; production code equals the integrated mainline.

Change kind: correction of missing verification; no production behavior change. The laws assert exact refusal and preserved bytes for existing/competing stages, canonical sealed bytes against an independent golden, and an unsealed header retained without a published head or complete-segment admission. A private-suite include or unchecked publisher would not meet this contract, so neither is used.

Invariants and evidence

The oracle is the public exclusive-creation/sealing contract plus independently specified v1 format vectors. Six production mutations demonstrate detection of truncating admission, overwritten refusal evidence, wrong error kind, corrupted header, premature head publication and wrong complete-length refusal. The missing-target RED on parent is explicitly static delivery evidence, not a runtime regression. Runtime laws pass against unchanged production code.

Debug/release focused target, full workspace suites, related segment/writer/recovery-resume suites, formatting, all-feature/minimal-feature warnings-denied Clippy, source structure and Markdown lint pass in copied Docker source on genuine ext4. Serial/parallel runtime checks also pass with isolated networking, a 1 GiB address-space cap and 30-second suite deadline. Validation details preserve the initial setup failures and their corrections separately from runtime calibration. All four required jobs in hosted run 37052604124 passed on exact head 5f90f22bde1582ecaa7215d85e7ce9db62975d25. CodeRabbit approved that head with no inline findings.

See the evidence record for claims, mutations, commands, sizes, execution limits and deletion criteria. Ordinary CI per-test enforcement gaps remain disclosed in the binding enforcement profile.

Current landing evidence

Candidate 05658799fb259a445f68c8bd434135483d491e40 passes the full fresh copied-Docker validation chain, including both crash campaigns, debug/release workspace tests, feature compilation/Clippy, formatting, golden/conformance/source structure, docs/doctests/MSRV, and fuzz-target compilation/lint. The copied tracked tree was verified as 5a4daed57bf895dad218cee883cde6c91d64feff before execution. Fresh debug/release focused serial and simultaneous-process runs also pass under explicitly recorded unshare -n, 1 GiB virtual-address-space limit and 30-second per-process suite deadline. Those are bounded focused runs, not a p95 or universal CI isolation claim.

Hosted final-head run 37148378148 passes all four required jobs, and the fresh independent Codex review approves this exact head with the complete verification checklist. The old CodeRabbit approval does not transfer to a changed head; its current status is rate-limited.

Compatibility and limits

No source API, durable format, dependencies, publication ordering or recovery policy changes. No performance improvement is claimed. These medium-size Linux tests require admitted ext4 scratch space and do not silently bypass unsupported-platform refusal. Other platforms retain their existing refusal coverage. The ordered creation schedule and explicit drop are not a new process-death/power-loss campaign. Existing phase injection and private laws remain intact. The original roadmap checkbox is unchanged; completion requires mainline integration.

Closes #147. Refs #131, #132. Excludes the separately tracked #146 sealed-capability escape and #150 platform-admission bypass.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 5bc04b1a-2746-4125-b8d4-301ff1e0f449

📥 Commits

Reviewing files that changed from the base of the PR and between 6051abb and 5f90f22.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • docs/formats/segment-store-v1/requirements.md
  • docs/testing-evidence/public-filesystem-stage.md
  • tests/segment_filesystem_stage.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: Dependency policy
  • GitHub Check: Documentation and workflow integrity
  • GitHub Check: Rust quality gates
  • GitHub Check: Runtime fuzz smoke
🧰 Additional context used
🪛 LanguageTool
docs/testing-evidence/public-filesystem-stage.md

[style] ~12-~12: This phrase is redundant. Consider writing “same”.
Context: ...e competing public creation returns the same exact typed refusal and leaves those bytes un...

(SAME_EXACT)

🔇 Additional comments (4)
tests/segment_filesystem_stage.rs (1)

46-47: 📐 Maintainability & Code Quality

The cleanup concern is refuted. TestDirectory implements Drop, which removes the sandbox when assertions or ? return early. The explicit sandbox.remove() remains a checked success-path cleanup.

docs/testing-evidence/public-filesystem-stage.md (1)

1-43: LGTM!

docs/formats/segment-store-v1/requirements.md (1)

53-54: LGTM!

CHANGELOG.md (1)

11-12: LGTM!


Summary by CodeRabbit

  • Tests
    • Added Linux ext4 integration coverage for stage creation, including refusal to overwrite existing files, exclusive stage ownership, expected sealed data, and rejection of incomplete stages without publishing them.
  • Documentation
    • Added evidence notes describing the filesystem-stage checks, their limits, and how they relate to the segment-store requirements.

Walkthrough

The change adds Linux-only public filesystem-stage integration tests for exclusive creation, canonical sealed bytes, and dropped unsealed stages. It also updates the segment-store evidence records, adds test evidence documentation, and records the integration target in the changelog.

Changes

Public filesystem-stage integration

Layer / File(s) Summary
Admission and exclusive creation laws
tests/segment_filesystem_stage.rs
Tests check that stage creation refuses an existing file without changing its contents, and that a second creation is refused without changing the first stage file.
Sealed and unsealed stage results
tests/segment_filesystem_stage.rs
A sealing test compares file bytes with the one-zero-segment fixture. A drop test checks the remaining header bytes, the WrongLength result, and the absence of HEAD.
Evidence scope and execution records
docs/testing-evidence/public-filesystem-stage.md, docs/formats/segment-store-v1/requirements.md, CHANGELOG.md
The documentation records test scope, limits, and execution details. The requirements ledger updates evidence references, and the changelog records the integration target.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 5f90f

This PR adds filesystem-stage test evidence and documentation without changing production behavior. The reviewed assertion intentionally checks independent format lengths, leaving no concrete merge-blocking risk identified.

🚥 Pre-merge checks | ✅ 3 | ❌ 1 | ❓ 1

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (3 skipped: 3… Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive The new tests/segment_filesystem_stage.rs target exists and uses FilesystemPlatformAdmission::initialize, FilesystemCatalogPublisher::open, and public stage APIs. The four tests cover exact `Alr… Provide the full-workspace validation result and exact-head hosted CI result before treating #147 as fully satisfied.
✅ Passed checks (3 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The changed test, evidence, format-requirement references, and changelog entries directly support #147. The evidence record states that production behavior, format, dependencies, accessors, bypasses, …
Title check ✅ Passed The title clearly identifies the public filesystem-stage tests, which are the main change.
Description check ✅ Passed The description gives substantial context on the problem, invariants, test evidence, execution limits, compatibility, and scope. It does not use all template headings or explicitly address benchmark i…
Full details: Linked Issues check

Explanation

The new tests/segment_filesystem_stage.rs target exists and uses FilesystemPlatformAdmission::initialize, FilesystemCatalogPublisher::open, and public stage APIs. The four tests cover exact AlreadyExists refusal, byte preservation, independent golden bytes, and dropped unsealed-prefix behavior without HEAD or complete-segment admission. The evidence record states that existing writer, corruption, golden, and recovery laws remain separate and that the roadmap checkbox remains unchanged. Full-workspace validation and exact-head hosted CI are still reported as incomplete, so all #147 acceptance checks are not established.

Full details: Docstring Coverage

Explanation

Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A stage begins on ext4 ground
Existing bytes stay safe and sound
One writer claims the open file
Sealed bytes match the fixture’s style
An unsealed header waits, not HEAD
Tests record each path instead

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Validation update for exact candidate 5f90f22bde1582ecaa7215d85e7ce9db62975d25, based on main 6051abb25a9fd33ae7ee0de5614514b709a4d82a:

  • Public stage target passed debug and release through genuine ext4 production admission. Exact refusals and persisted-byte oracles executed; no unchecked publisher was used.
  • All six calibration mutations produced the intended runtime RED assertions. Dedicated mutant build directories prevented source/artifact reuse. The first calibration postprocessor lacked rg; its runtime RED was retained and remaining processing used available grep.
  • Full workspace debug and release tests, related segment/writer/recovery-resume tests, all-feature and minimal-feature warnings-denied Clippy, formatting, source structure and Markdown lint passed in copied Docker source.
  • Serial and parallel direct runtime checks passed with network isolation, 1 GiB address-space cap and 30-second suite deadline.
  • The first broad run failed two repository-tool tests because the copied source had no committed Git snapshot and /tools/bin was absent from PATH. Importing the exact candidate through a Git bundle and admitting the already-installed pinned b3sum corrected those concrete setup omissions. The original failures remain in local evidence; they are neither product regressions nor assertion-calibration receipts. No product/test expectation was changed to make that run pass.

No source implementation changes, format change, new crash campaign, or power-loss claim. The public target's missing-parent RED is static delivery evidence. Runtime calibration supplies separate evidence that its behavioral assertions detect broken outcomes. Hosted run 37052604124 remains the final exact-head CI receipt; pending checks are not yet reported green.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent ULTRA STRICT review — Keep PR #156

Reviewed flyingrobots/keep, branch test/147-public-filesystem-stage, exact head 05658799fb259a445f68c8bd434135483d491e40, tracked tree 5a4daed57bf895dad218cee883cde6c91d64feff, targeting main at 64fafe3ddcc92bcc45a461a0161030b87559070d. The isolated checkout remained clean and fixed at these coordinates through review.

This is the user-authorized independent Codex fallback applying the full agy-review mandatory protocol. It is not an agy-process result or the stale CodeRabbit approval. Review was read-only: no source edits, host Rust tests, commits, publishing, merges, configuration changes, or subagents. Only this report was written.

Findings

No verified P0–P5 defect in the scoped PR change or its integration with incoming main. No speculative hardening finding is asserted.

The four-file target-relative diff supplies the promised public integration target without changing production source, dependencies, format bytes, or durability policy. Existing/competing creation checks observe exact typed refusal and unchanged bytes; the successful stage observes independent canonical bytes; the dropped stage observes the canonical header, exact complete-segment refusal, and absent HEAD. The existing private tests remain distinct evidence, not a substitute for production admission.

Approval concerns the reviewed code and evidence at this exact head. Final independent live verification confirms all four required hosted jobs passed in run 37148378148: Rust quality gates, Documentation and workflow integrity, Runtime fuzz smoke, and Dependency policy. PR head/base and local head/tree remain the reviewed coordinates. CodeRabbit's current SUCCESS check is accompanied by a rate-limit comment and does not establish an independent current-head approval. Its actual APPROVED review is pinned to the older 5f90f22bde1582ecaa7215d85e7ce9db62975d25.

Verification Checklist

Scope, intent, and review queue

  • Read the applicable AGENTS.md, binding docs/Testing Standards.md, docs/testing/enforcement.md, and PR template. Applied Keep's exact-bytes-or-refuse law and its product/tool/calibration/static evidence distinction.
  • Independently queried live GitHub GraphQL for PR identity/body, issue Deliver promised public filesystem-stage integration target (T-11.3) #147, global comments, reviews, and review threads. All three connections returned hasNextPage: false; there were three global comments, one older approval, and zero review threads. Nested thread pagination has no entries to inspect. Read all supplied queue content and the updated live rate-limit comment; did not treat bot summaries as proof.
  • Checked the original roadmap at 1a586d83d5750083172d440f90e7b786d540ff0e: T-11.3 explicitly named tests/segment_filesystem_stage.rs. The test target is absent from parent 6051abb25a9fd33ae7ee0de5614514b709a4d82a. keep-audit/147/missing-target-red.log:1 records Cargo's missing-target refusal. This is static delivery RED, not a runtime bug regression.
  • Current target-relative diff is exactly CHANGELOG.md, docs/formats/segment-store-v1/requirements.md, docs/testing-evidence/public-filesystem-stage.md, and tests/segment_filesystem_stage.rs. Checked the whole diff and surrounding owners. No roadmap checkbox was changed and no integration commit was fabricated.
  • Production, xtask, fuzz, corpus, Cargo manifest and lockfile trees equal the target main version. The new test, sandbox and every production file affected by the Deliver promised public filesystem-stage integration target (T-11.3) #147 calibrations equal the calibrated pre-merge 5f90f22bde1582ecaa7215d85e7ce9db62975d25 version. Thus the older mutation observations still apply to these unchanged assertion/implementation pairs; fresh exact-tree GREEN supplements them.

Every runtime path delivering the new evidence

Promise/path Public test entry and production path Checked outcome and parallel paths
Genuine admitted filesystem authority tests/segment_filesystem_stage.rs:136 → src/adapters/filesystem_store_initializer.rs:32 → src/adapters/filesystem_initialization_storage.rs:25 → src/adapters/filesystem_platform_profile.rs:42 and :114 → src/adapters/store_initialization.rs:26 → initializer :79 → src/adapters/filesystem_catalog_publisher.rs:55 Profile requires no symlinks, writable case-sensitive ext4, compatible protocol-directory device/mount identities, retained writer authority, and synchronized initialized namespace. Failure propagates through typed initialization phase; the new test has no unchecked fallback.
Alternate admitted construction and unsupported platforms src/adapters/filesystem_store_initializer.rs:52 → platform :42 and initializer :105; repository route src/adapters/filesystem_catalog_publisher.rs:94 → src/adapters/filesystem_platform_admission.rs:33 → profile :61 → ordinary publisher :55 Reopen requires the published namespace. Legacy locked-root construction opens the same retained capability readably, performs strict profile/root identity, and then uses the same publisher. Non-Linux profile routes :67 and :98 explicitly refuse. tests/store_initialization.rs:63 owns non-Linux refusal; it was inspected, not executed on this Linux profile. New target :5 compiles out on non-Linux without claiming successful admission there.
Existing stage exact refusal/preservation Test :29 → publisher :125 → src/adapters/filesystem_segment_stage.rs:31 → src/adapters/filesystem_catalog_artifact.rs:17 Atomic create_new, no-follow and nonblocking open; Create { source } preserves AlreadyExists. Test :40 checks typed refusal and :45 compares independent preexisting bytes. No pathname enumeration is used by this creation path. The requirements explicitly exclude claiming an independent whole-enumeration audit.
Active first-owner preservation Test :52 → same create path → src/adapters/staged_segment.rs:43 → src/adapters/segment_stage_write.rs:7 → filesystem stage :55 First authority writes an actual canonical header before the second request. Test :64 checks exact refusal and :69 checks the entire saved first-owner bytes. This is the explicitly ordered first-owner/second-request schedule, not general concurrency exploration.
Canonical sealed storage Test :77 → create → staged begin :43 → src/adapters/admitted_segment_record.rs:29 → staged append :92 → staged seal :114 → filesystem write/flush/sync :55, :60, :66 Full frozen one-zero vector compared at test :92. Prefix flush/sync precedes seal append, followed by sealed flush/sync; consuming errors cannot retain a usable staged state. Dropping the sealed receipt closes its private stage; it does not publish it.
Dropped unsealed prefix, exact incomplete refusal, and no publication Test :99 → staged begin :43 → ordinary field destruction of staged and filesystem stage → actual read :115 → src/adapters/admitted_segment.rs:32 → src/adapters/segment_reader.rs:13 Test :116 requires all header bytes; :117 requires WrongLength { minimum: 192, observed: 64 }; :127 requires absent HEAD using fallible try_exists. No implicit Drop seal, repair, removal, or publication exists in the traversed production types. This observes normal explicit drop, not process death or power loss.
Existing recovery semantics of that prefix src/adapters/recovery/recovery_segment_classifier.rs:24 → canonical header admission :44 → empty tail :65 → bounded reusable admission :103 The exact canonical header is a zero-record reusable prefix, while the complete-segment parser refuses it. New law checks the bytes and complete-admission refusal; it does not itself perform recovery/resume. Existing recovery_segment_resume and related laws remain owners and execute in the full debug/release receipts. No automatic discard claim is introduced.
Existing private stage evidence src/adapters/filesystem_segment_stage_tests.rs:21, :44, :67, :89 → private setup :111 → publisher open_unchecked_for_tests at :105 Same creation/writer code but an explicitly different private admission seam. Existing private laws do not certify production admission; new public laws avoid this seam and strengthen active-owner/drop observations. The duplicate sizes have distinct admitted-boundary purposes.
Observed writer and production crash consumer imported by the merge xtask/src/durability_crash_matrix/production_protocol/initialization.rs:42 → ordinary initialize/open; publication.rs:28 → ObservedSegmentStage::new at :35 → staged writer at :38 → without_observer at :44 → selection at :55 src/adapters/observed_segment_stage.rs:25, :54, :63 call the underlying write/flush/sync; :79 preserves the original private stage and metadata. src/adapters/filesystem_catalog_publisher.rs:142 still checks publisher authority and admitted coordinates. New direct laws neither require nor expose a writable sealed conversion.

Every merge audited against both parents

The only merge in the PR's target-exclusive history is the final merge below. To validate its incoming invariants, the five merge commits carried by the incoming main since the original branch point were also inspected against both parents. Incoming implementation correctness is reviewed at the interaction boundary here, not presented as a renewed whole-repository audit.

Merge SHA Parents Integration verification
05658799fb259a445f68c8bd434135483d491e40 5f90f22bde1582ecaa7215d85e7ce9db62975d25, 64fafe3ddcc92bcc45a461a0161030b87559070d First-parent diff imports #172/#158/#157. Second-parent diff is exactly the four #147 files. All imported implementation, tests, corpus and receipts match incoming main. Changelog retains all four independent entries. Requirements preserve sealed capability, platform admission and partial-seal corrections alongside public-stage ownership.
64fafe3ddcc92bcc45a461a0161030b87559070d 182e49520f98c6035828a739dcf3c224df535b84, 3626f6e2677a1d6d3af08b88245584800596ff55 #157 integration is identical to its second parent's tree. Strict locked-root admission and ordinary crash-publisher initialization survive; previously merged sealed-stage/recovery corrections remain.
657593fe50c824dd31dc328bf9e696183ef20767 fa06adfde89b70be5aaf7356206b7d8c1fbce169, 182e49520f98c6035828a739dcf3c224df535b84 First side imports observation and partial-seal work; second side contains platform correction. Production constructors and crash observation compose through the same admitted publisher without reintroducing unchecked public authority or sealed-stage extraction. Shared prose/ledger/changelog retains both contracts.
182e49520f98c6035828a739dcf3c224df535b84 d0cff10d7c911d33d615c3aa2246ae2b4497432a, e781c0b276ec4d1f66a76668bd31893261a2e6dd #158 integration is identical to its second parent's tree. Private observer wrapper, specialized sealed conversion, compiler refusal and existing precise recovery framing remain together.
e781c0b276ec4d1f66a76668bd31893261a2e6dd 15aa976a77d5b65a4b6e8f8a2f9e01d2ba3b0d58, d0cff10d7c911d33d615c3aa2246ae2b4497432a Both parent diffs preserve the independent observation and recovery changes. recovery_segment_classifier.rs:69 validates recognized partial seal framing before returning truncation; observed_segment_stage.rs:79 cannot hand storage to callbacks. Crash harness uses the resulting wrapper without altering the recovery diagnostic rule.
d0cff10d7c911d33d615c3aa2246ae2b4497432a 6051abb25a9fd33ae7ee0de5614514b709a4d82a, 07e6cc4875c05592b71bb1f8b9c80631a31bcda5 #172 integration is identical to its second parent's tree. Precise partial-seal refusal, finite available-field tests, permanent counterexample and fuzz selector survive. The #147 header-only drop is unaffected: it contains no seal candidate.

Assertions, constants, every changed document figure, and raw evidence

Local evidence coordinates below are relative to the retained review evidence archive. They identify inspected artifacts, not newly committed repository receipts. Production/test file coordinates are relative to the reviewed repository.

New load-bearing outcome Named assertion Inspected runtime falsification
Existing and active-stage authority cannot be replaced Test :37 and :60 success guards keep-landing/156-cal-truncate.log:40–63: successful compilation, both intended authority guards fail, other two laws pass. The earlier postprocessor's missing rg is retained in keep-audit/147/calibration.log:1; that tool error is not the runtime RED.
Correct refusal cannot conceal byte loss Test :45 and :69 keep-landing/156-cal-refusal-bytes.log:52–70: exact refusal passes far enough to reach both byte comparisons; observed bytes are lost evidence, independent expected bytes differ.
Wrong refusal kind is detected Test :40 and :64 keep-landing/156-cal-wrong-kind.log:52–68: both exact Create/AlreadyExists assertions fail after compilation.
Noncanonical bytes cannot satisfy sealing/prefix promises Test :92 and :116 keep-landing/156-cal-header.log:52–70: both full golden and header comparison fail with zeroed header bytes.
Premature publication is detected Test :127 keep-landing/156-cal-head.log:52–60: the named no-HEAD assertion fails; other three laws pass.
Complete-segment refusal retains exact coordinates Test :117 keep-landing/156-cal-length.log:52–60: the exact WrongLength check fails when minimum is zero; other three laws pass.

The copied mutation script keep-landing/156-original-calibrate.sh identifies the exact production substitutions and dedicated source/build roots. Its remaining-mutations loop omits truncate because the first truncate runtime RED had already been captured; the separate truncate log provides that actual execution. These are six distinct outcome calibrations, not a mutation percentage. No compile/setup/zero-execution failure is used as calibration.

  • New fixed format numbers: header 64, seal 128, minimum complete segment 192, one zero payload byte, and sealed one-zero length 337 agree across src/adapters/segment_header.rs:8–15, segment_seal.rs:8–10, segment_reader.rs:9–20, normative docs/formats/segment-store-v1/segment.md:44–59 and :144–163, conformance/segment-store/v1/artifacts.tsv:3–4, and the actual hex widths. 192 = 64 + 128; 337 = 64 + 112 + 1 + 32 + 128. The test's literal expected 192/64 is independent of the production error formatting, and the WrongLength calibration detects its falsification.
  • Golden provenance: read conformance/segment-store/v1/ORIGIN.md and xtask/tests/segment_store_protocol_contract/fixture_oracle/encoding.rs. The oracle reconstructs specified headers/records/seals and named domain-separated digests without calling the production segment codecs; the new tests only decode hex transport through tests/support/mod.rs:155. Neither expected vector is regenerated from the runtime writer. No golden bytes changed.
  • Resource constants in the changed target: restart byte policy 1,048,576 at test :138 is a positive caller bound (catalog_restart_byte_limit.rs:17), with no throughput/latency measurement claim; it is not reached by restart loading in these stage-only laws. Record and layout policy maxima are 1,048,576 (segment_record_limit.rs, src/layout/entry_limit.rs:6–17). Header's inherited payload/segment bounds 67,108,864 and 1,073,741,824 agree with the normative tables and independent header vector. No limits were raised, and no empirical sizing evidence is invented.
  • Execution figures in public-filesystem-stage.md:37–41: Rust 1.96.0 is pinned in rust-toolchain.toml; edition 2024 and MSRV 1.96 are in Cargo. keep-landing/156-validation.log:1–10 prints exact tracked tree, Rust 1.96.0, aarch64, actual ext4 /dev/loop0, and tmpfs negative-fixture storage. Docker inspection shows its sole host bind is read-only /input; source/build copies are separate container paths. The container itself uses bridge networking; denied network is only claimed for the additional unshare -n runs.
  • 1 GiB and 30-second figures: keep-landing/156-isolation.sh and 156-isolation.log:24–50, :81–107 record unshare -n, ulimit -v 1048576 KiB, printed admitted limit and timeout 30s. These bound each test-binary process/suite, not per-test resource admission or denied filesystem observation. One serial run and two simultaneously running four-thread binary processes execute in both profiles; all complete successfully. Runtime observations are 0.01–0.03 seconds for these exact-head isolated runs; ordinary debug/release target observations are 0.02/0.01 seconds at validation :1130–1138 / :3146–3154. The below-one-second prose is supported as an observation, not a p95 or performance guarantee.
  • Imported Prevent post-seal writable stage escape through receipt mapping #146 constants/figures: the historical finite family 1 through 64 and seven-byte short-write cap agree with tests/observed_segment_stage/byte_equivalence.rs:15 and tests/observed_segment_stage.rs:111. Crash header/record/seal ends 64/209/337 and interior offsets 32/136/273 in xtask/.../production_protocol/segment_stage.rs:10–15 agree with the golden framing and lie inside their respective phases. Old capability RED at keep-audit/146/capability-red.log:50–62 witnesses an unexpectedly compiling compile-fail example, not an I/O failure. Incoming byte/flush/sync/excessive-limit/interruption calibrations were inspected in keep-landing/158-cal-*.log; no fault simulation is promoted to physical durability proof.
  • Imported Preserve platform admission across public catalog publisher routes (T-12.2) #150 claims: catalog-platform-admission.md's refusal and successful-write claims match the public laws and strict readable-capability implementation. keep-audit/150/parent-red.log executes the exact refused-platform law and observes unlawful publisher authority; write-calibration.log reaches the positive byte assertion with empty actual bytes. Raw commands are bounded Linux ext4/tmpfs observations, not certification of all filesystem authority routes. Incoming platform code is unchanged from main.
  • Imported Refuse corrupt partial segment seals before recovery discard #171 figures: partial-seal-corruption.md's version-2 counterexample, selector 5, fixed field positions and exact diagnostics match the retained fixture, classifier :69–83, validator :9–66, finite sweep tests/recovery_partial_seal/framing_laws.rs:16–55, and fuzz/fuzz_targets/segment_format.rs:21, :70–110. Read linked parent/reduced-parent/diagnostic/source/coordinate/materialized-input RED and GREEN receipts; named runtime failures match their claimed assertions. Raw fuzz-green.txt:17 records seed 17101, max_total_time 15, timeout 5, RSS 1024 MiB, max_len 1048576; :664 / :708 records the historical 3,110,375-run, 16-second completion. Those are historical pinned-run measurements/flags, not a guaranteed current rate or exact 15-second elapsed-time promise. Existing smoke execution is a separate current hosted gate.
  • Every changed prose claim: CHANGELOG.md:11's production ext4/exclusive/golden/unsealed statement matches the four public laws. Requirements KEEP-SEGMENT-008/009 distinguish exclusive-create coverage from enumeration and keep phase injection with its existing owner. Imported publication/rationale/recovery/requirements/fuzz paragraphs agree with the retained strict admission, private sealed authority, precise partial-seal diagnostic, and seed replay paths. Issue numbers and historical parent SHAs were checked as provenance coordinates, not test counts. No new rate, timeout, allocation benchmark, power-loss, p95, flake-rate or full-platform claim appears.

Errors, state transitions, determinism, and repository standards

  • Creation error retains the actual I/O source in SegmentStageCreateError::Create; the tests check the owning variant and exact source kind before comparing preserved bytes. Setup failures remain visible through ? and do not skip or fabricate admission.
  • Stage begin/append/seal consume state. Header/record/length/count admission uses checked arithmetic and bounds; write completion preserves exact phase and prior completed bytes, retries Interrupted only before a successful write result, and rejects zero or invalid counts (segment_stage_write.rs:17–43). Prefix and seal flush/sync boundaries remain explicit. Ambiguous failures consume the stage and preserve filesystem evidence rather than permitting accidental continuation.
  • Incoming observation after-write Interrupted is intentionally retained as the source of a non-retryable outer I/O error (observed_segment_stage.rs:41–50); it is not silently swallowed or retried after effects. The specialized sealed conversion exposes no callback/storage accessor. sealed_segment.rs:14 compiler restriction runs successfully in fresh all-feature doctests. New direct tests avoid conversion entirely.
  • Normal drop before seal leaves bytes/name and no HEAD; it makes no directory durability promise. Complete parsing refuses the header before indexing. Recovery classification distinguishes this reusable prefix from complete bytes and contradictory partial seals. No process interruption, shutdown-hold, async cancellation, device/config transition or restart protocol is changed by the PR; existing synchronous/crash/recovery boundaries were inspected for composition, and relevant existing suites/campaigns ran.
  • New tests have one owned actor/sandbox and a short explicit protocol schedule. PID-qualified distinct names and independent process execution isolate scratch; no wall-clock oracle, sleeps, random seed, filesystem-order oracle, shared mutable fixture, or production serializer-derived expectation is added. The immutable snapshots are specified format vectors, not unlabeled class-5 snapshots. Tests admit actual medium-size filesystem resources and state their retirement condition.
  • New source is 144 lines; functions are below hard limits, ownership is explicit, and there are no new public boolean parameters, unchecked indexing, lossy casts, unsafe, unwrap/expect/panic/todo/debug printing, dependency changes, or adapter imports into core. pub mod sandbox matches the existing integration-module visibility pattern and makes no library API addition. Existing support/test allocation is bounded by tiny fixed vectors; no hidden product whole-blob allocation is introduced.
  • Change kind is correction of missing verification, as permitted separately by Testing Standards rule 3; there is no invented product bug or changed production expectation. The static missing-target RED and runtime mutation RED are labeled correctly. Owner, named independent oracle, fixed schedule, medium size, admitted environment, execution limits, evidence scope and deletion criterion are recorded.
  • Existing test-budget/ordinary CI sandbox/p95/flake/inventory gaps remain explicitly disclosed in enforcement and the receipt. This approval does not certify repository-wide Testing Standards compliance or waive those gaps. The new focused execution supplies actual process deadline/address-space/network bounds and concurrency observations, but no inaccessible-filesystem sandbox or per-test resource monitor. No unrelated repository's one-physical-line prose policy or coverage percentage was invented as a binding Keep requirement.

Checks executed versus inspected/skipped

The independent reviewer executed read-only Git/source/diff/fixture-width checks, live GitHub queue/check queries, and Docker mount inspection. All Rust tests, mutation experiments and quality checks below were executed by the parent/copy-isolated Docker harness; this reviewer inspected their raw command and diagnostic receipts rather than rerunning host tests or changing the fixed checkout.

  • Inspected fresh exact-tree keep-landing/156-validation.log:1–4184 with traced commands and no recorded test failure/error/warning: golden-file-worldline check; debug and optimized process-death matrices; conformance; source structure; fmt; all-feature and no-default-feature workspace/all-target check and warnings-denied Clippy; full debug/release workspace tests; all-feature doctests; docs; pinned MSRV check; fuzz fmt/build/Clippy. The parent observed terminal EXIT 0. The new laws and related segment/writer/recovery/admission/observation laws execute in both full profiles.
  • Inspected fresh exact-head keep-landing/156-isolation.log:1–126: serial and simultaneous parallel public target binary runs in both profiles under recorded network/address-space/deadline controls, with successful outcomes. Parent observed terminal EXIT 0.
  • Inspected the six original Deliver promised public filesystem-stage integration target (T-11.3) #147 runtime RED logs, static missing-target RED, and focused source identity against their unchanged current-head assertion/implementation pairs. Earlier symlink/Git/PATH/Clippy/postprocessor setup failures are separately retained and excluded from product regression or calibration claims.
  • Independently inspected final hosted check state: all four required jobs are SUCCESS in run 37148378148 for the unchanged reviewed current head. The earlier in-progress state was preserved as an observation during review, then superseded by this fresh live result. Head/base/tree were revalidated at completion. Approval remains separate from permission to merge.
  • Skipped host Rust execution by explicit task restriction. Non-Linux refusal was inspected only. No new parser, performance optimization or process-death/power-loss claim is introduced. The existing process-death campaigns establish their admitted process-failure model; they do not establish physical power-loss persistence. No benchmark experiment, arbitrary payload equivalence, exhaustive concurrency exploration, independent whole-enumeration audit, full storage/recovery audit, global test-policy compliance, or universal absence of regressions is claimed.

No mandatory scoped code/evidence area remains inaccessible. The current-head required checks pass; the independent review verdict remains separate from authorization to integrate.

APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer closure — public filesystem-stage evidence

Reviewed candidate: 05658799fb259a445f68c8bd434135483d491e40, based on main 64fafe3ddcc92bcc45a461a0161030b87559070d.

Obligation Source Evidence Disposition
Deliver the promised public target #147 / original T-11.3 tests/segment_filesystem_stage.rs uses actual FilesystemPlatformAdmission::initialize, ordinary publisher and public stage/writer operations Named target executes in debug/release; no unchecked admission or included private test shim.
Exact refusal and preserved bytes #147 / testing standards Public existing-stage and active-stage laws; raw truncate, overwrite-before-refusal and wrong-error-kind mutations Named runtime assertions fail under each mutation and pass on unchanged production behavior.
Canonical seal and incomplete-prefix evidence #147 / independent v1 format oracle Golden sealed-byte comparison; header prefix, exact WrongLength { minimum: 192, observed: 64 }, absent HEAD; header/head/length mutations Distinct assertions calibrated; no automatic cleanup or physical power-loss claim.
Existing protocol and recovery contracts preserved Merge integration Both-parent review of 0565879; production, harness, fuzz and conformance source equals target main; all changelog entries retained #172 partial-seal, #158 sealed-observer and #157 platform-admission changes preserved; full local integration chain passes.
Full validation and current issue acceptance CodeRabbit top-level inconclusive check Fresh copied-Docker full chain plus exact-head hosted run Original incomplete-validation note is superseded by current receipts before landing.
Fixture cleanup concern CodeRabbit top-level detail, already refuted Existing sandbox implements Drop and checked explicit success cleanup No change required; assertion or ? early exit still drops owned fixture.
Docstring percentage / redundant phrase Optional CodeRabbit warning / style suggestion Test target documents scope, size, oracle and retirement; no new public product API No repository percentage gate exists; warning is not substituted for actual documentation review.
Calibration budget provenance Independent reviewer evidence request Fresh 156-isolation.sh and traced raw log execute both profile binaries serially and as simultaneous independent processes, each with unshare -n, ulimit -v 1048576, timeout 30s Completed successfully; enforcing commands and observed outcomes now recorded together.

The full fresh local validation script and log record copied tracked tree 5a4daed57bf895dad218cee883cde6c91d64feff, Rust 1.96.0, Linux aarch64, actual ext4 scratch and the complete sequential commands. Terminal exit was 0. It covers debug/release process-death crash matrices and workspace suites, golden/conformance/source structure, formatting, all-feature/minimal-feature compilation and warnings-denied Clippy, doctests/docs/MSRV, and fuzz-target formatting/compilation/lint. All runtime tests ran inside Docker with copied source and dedicated build output, without a writable host checkout mount. Focused isolated serial/parallel runs also exit 0.

The missing-parent target RED is static delivery evidence, not a demonstrated production bug. Six distinct production mutations provide runtime assertion calibration. Original setup failures and raw mutation diagnostics were retained and inspected, not replaced with green totals. No test-count assertion is used as a storage oracle.

The fresh independent review, assigned to GPT-6.1-sol with high reasoning using the complete agy-review protocol, approves this exact head with no findings. Complete feedback reconciliation includes global comments and review bodies, not only the empty inline-thread list. The prior CodeRabbit approval is historical; current provider rate limiting supplies no approval. No changes-requested review or actionable inline thread remains.

Current-head hosted run: 37148378148. All four required hosted jobs passed on the exact head, which the independent reviewer approves; base and head were revalidated before normal merge. Resource ceilings stated above apply only to those focused runs; ordinary per-test CI enforcement gaps remain documented. This change adds verification only and does not claim new production behavior, format, performance, parser fuzzing or power-loss coverage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deliver promised public filesystem-stage integration target (T-11.3)

1 participant