Test: verify public admitted filesystem stages (#147) - #156
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (4)
🧰 Additional context used🪛 LanguageTooldocs/testing-evidence/public-filesystem-stage.md[style] ~12-~12: This phrase is redundant. Consider writing “same”. (SAME_EXACT) 🔇 Additional comments (4)
Summary by CodeRabbit
WalkthroughThe change adds Linux-only public filesystem-stage integration tests for exclusive creation, canonical sealed bytes, and dropped unsealed stages. It also updates the segment-store evidence records, adds test evidence documentation, and records the integration target in the changelog. ChangesPublic filesystem-stage integration
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~12 minutes Change: Other Merge Risk: ⚪ Minimal · up to This PR adds filesystem-stage test evidence and documentation without changing production behavior. The reviewed assertion intentionally checks independent format lengths, leaving no concrete merge-blocking risk identified. 🚥 Pre-merge checks | ✅ 3 | ❌ 1 | ❓ 1❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
Full details: Linked Issues checkExplanation The new Full details: Docstring CoverageExplanation Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (3 skipped: 3 unsupported.)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A stage begins on ext4 ground Comment |
|
Validation update for exact candidate
No source implementation changes, format change, new crash campaign, or power-loss claim. The public target's missing-parent RED is static delivery evidence. Runtime calibration supplies separate evidence that its behavioral assertions detect broken outcomes. Hosted run 37052604124 remains the final exact-head CI receipt; pending checks are not yet reported green. |
Independent ULTRA STRICT review — Keep PR #156Reviewed This is the user-authorized independent Codex fallback applying the full agy-review mandatory protocol. It is not an agy-process result or the stale CodeRabbit approval. Review was read-only: no source edits, host Rust tests, commits, publishing, merges, configuration changes, or subagents. Only this report was written. FindingsNo verified P0–P5 defect in the scoped PR change or its integration with incoming main. No speculative hardening finding is asserted. The four-file target-relative diff supplies the promised public integration target without changing production source, dependencies, format bytes, or durability policy. Existing/competing creation checks observe exact typed refusal and unchanged bytes; the successful stage observes independent canonical bytes; the dropped stage observes the canonical header, exact complete-segment refusal, and absent Approval concerns the reviewed code and evidence at this exact head. Final independent live verification confirms all four required hosted jobs passed in run Verification ChecklistScope, intent, and review queue
Every runtime path delivering the new evidence
Every merge audited against both parentsThe only merge in the PR's target-exclusive history is the final merge below. To validate its incoming invariants, the five merge commits carried by the incoming main since the original branch point were also inspected against both parents. Incoming implementation correctness is reviewed at the interaction boundary here, not presented as a renewed whole-repository audit.
Assertions, constants, every changed document figure, and raw evidenceLocal evidence coordinates below are relative to the retained review evidence archive. They identify inspected artifacts, not newly committed repository receipts. Production/test file coordinates are relative to the reviewed repository.
The copied mutation script
Errors, state transitions, determinism, and repository standards
Checks executed versus inspected/skippedThe independent reviewer executed read-only Git/source/diff/fixture-width checks, live GitHub queue/check queries, and Docker mount inspection. All Rust tests, mutation experiments and quality checks below were executed by the parent/copy-isolated Docker harness; this reviewer inspected their raw command and diagnostic receipts rather than rerunning host tests or changing the fixed checkout.
No mandatory scoped code/evidence area remains inaccessible. The current-head required checks pass; the independent review verdict remains separate from authorization to integrate. APPROVE |
Code Lawyer closure — public filesystem-stage evidenceReviewed candidate:
The full fresh local validation script and log record copied tracked tree The missing-parent target RED is static delivery evidence, not a demonstrated production bug. Six distinct production mutations provide runtime assertion calibration. Original setup failures and raw mutation diagnostics were retained and inspected, not replaced with green totals. No test-count assertion is used as a storage oracle. The fresh independent review, assigned to GPT-6.1-sol with high reasoning using the complete agy-review protocol, approves this exact head with no findings. Complete feedback reconciliation includes global comments and review bodies, not only the empty inline-thread list. The prior CodeRabbit approval is historical; current provider rate limiting supplies no approval. No changes-requested review or actionable inline thread remains. Current-head hosted run: 37148378148. All four required hosted jobs passed on the exact head, which the independent reviewer approves; base and head were revalidated before normal merge. Resource ceilings stated above apply only to those focused runs; ordinary per-test CI enforcement gaps remain documented. This change adds verification only and does not claim new production behavior, format, performance, parser fuzzing or power-loss coverage. |
Problem and approach
Completed roadmap task T-11.3 promised
tests/segment_filesystem_stage.rs, but only private adapter laws and a sandbox module existed. This PR adds that public integration target through realFilesystemPlatformAdmission::initializeand the ordinary catalog publisher constructor. It started from main6051abbafter #99 and now includes main64fafe3ddcc92bcc45a461a0161030b87559070dthrough normal merge05658799fb259a445f68c8bd434135483d491e40. The changelog resolution retains every incoming entry; production code equals the integrated mainline.Change kind: correction of missing verification; no production behavior change. The laws assert exact refusal and preserved bytes for existing/competing stages, canonical sealed bytes against an independent golden, and an unsealed header retained without a published head or complete-segment admission. A private-suite include or unchecked publisher would not meet this contract, so neither is used.
Invariants and evidence
The oracle is the public exclusive-creation/sealing contract plus independently specified v1 format vectors. Six production mutations demonstrate detection of truncating admission, overwritten refusal evidence, wrong error kind, corrupted header, premature head publication and wrong complete-length refusal. The missing-target RED on parent is explicitly static delivery evidence, not a runtime regression. Runtime laws pass against unchanged production code.
Debug/release focused target, full workspace suites, related segment/writer/recovery-resume suites, formatting, all-feature/minimal-feature warnings-denied Clippy, source structure and Markdown lint pass in copied Docker source on genuine ext4. Serial/parallel runtime checks also pass with isolated networking, a 1 GiB address-space cap and 30-second suite deadline. Validation details preserve the initial setup failures and their corrections separately from runtime calibration. All four required jobs in hosted run 37052604124 passed on exact head
5f90f22bde1582ecaa7215d85e7ce9db62975d25. CodeRabbit approved that head with no inline findings.See the evidence record for claims, mutations, commands, sizes, execution limits and deletion criteria. Ordinary CI per-test enforcement gaps remain disclosed in the binding enforcement profile.
Current landing evidence
Candidate
05658799fb259a445f68c8bd434135483d491e40passes the full fresh copied-Docker validation chain, including both crash campaigns, debug/release workspace tests, feature compilation/Clippy, formatting, golden/conformance/source structure, docs/doctests/MSRV, and fuzz-target compilation/lint. The copied tracked tree was verified as5a4daed57bf895dad218cee883cde6c91d64feffbefore execution. Fresh debug/release focused serial and simultaneous-process runs also pass under explicitly recordedunshare -n, 1 GiB virtual-address-space limit and 30-second per-process suite deadline. Those are bounded focused runs, not a p95 or universal CI isolation claim.Hosted final-head run 37148378148 passes all four required jobs, and the fresh independent Codex review approves this exact head with the complete verification checklist. The old CodeRabbit approval does not transfer to a changed head; its current status is rate-limited.
Compatibility and limits
No source API, durable format, dependencies, publication ordering or recovery policy changes. No performance improvement is claimed. These medium-size Linux tests require admitted ext4 scratch space and do not silently bypass unsupported-platform refusal. Other platforms retain their existing refusal coverage. The ordered creation schedule and explicit drop are not a new process-death/power-loss campaign. Existing phase injection and private laws remain intact. The original roadmap checkbox is unchanged; completion requires mainline integration.
Closes #147. Refs #131, #132. Excludes the separately tracked #146 sealed-capability escape and #150 platform-admission bypass.