Skip to content

Fix: preserve platform admission for catalog publisher authority (#150) - #157

Merged
flyingrobots merged 5 commits into
mainfrom
fix/150-catalog-platform-admission
Oct 3, 2026
Merged

flyingrobots merged 5 commits into
mainfrom
fix/150-catalog-platform-admission

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Problem

With repository-tasks enabled, a caller could acquire a writer lock on a filesystem that production initialization refuses, then obtain a real FilesystemCatalogPublisher through open_unchecked_for_repository_tasks. Lock ownership was being converted into production platform authority without admission, violating KEEP-CATALOG-007 and T-12.2.

Change and invariant

Change kind: bug fix. The legacy constructor now checks the production profile on its retained root, including existing protocol directories, and requires strict root identity before creating admission. It reopens the pinned capability readably because profile ioctls cannot operate on an O_PATH descriptor. Unsupported platforms return the original io::Error before publisher construction. The existing public signature remains; its corrected behavior is explicitly documented.

The catalog crash harness now opens its publisher through ordinary initialization and admission. Publication crash runs require actual admitted ext4 scratch storage; they retain their fault decorators, phase ordering and restart oracles. No separate unchecked production publisher or caller-provided proof flag is introduced. Other public migration, version-two and recovery admission boundaries are explicitly outside this finite publisher inventory.

RED → GREEN evidence

  • Parent: 6051abb25a9fd33ae7ee0de5614514b709a4d82a; regression commit: 1ffdf5a. A real tmpfs root produces exact AdmitPlatform/Unsupported, but the old alternate route returns a publisher and fails refused platform acquired public publisher authority.
  • Fix: f7956c0. The same negative law passes in debug/release. The positive law opens the alternate route on genuinely admitted ext4, writes a stage and checks exact retained bytes.
  • A separate production write-dropping mutation fails the positive persisted-byte assertion. Initial EBADF diagnostics from probing an O_PATH descriptor were retained and corrected through capability-relative reopening, not a weakened expectation.
  • Complete debug and optimized crash campaigns, full workspace debug/release tests, doctests, all-feature/minimal-feature warnings-denied Clippy, formatting, source structure and focused debug/release laws pass in copied Docker source. Markdown lint also passes after a documentation-only formatting commit. All four required jobs in hosted run 37054126009 passed on final pushed head fa06adfde89b70be5aaf7356206b7d8c1fbce169. CodeRabbit is rate limited and has supplied no approval.

The source-text architecture test stayed green during the demonstrated bypass. It is removed under the failed-calibration deletion criterion and replaced by the public runtime laws. Existing namespace/no-follow, writer exclusion, publication, corruption and restart evidence remains. See the evidence record and the admission rationale.

Final landing validation

Normal integration 657593fe50c824dd31dc328bf9e696183ef20767 passed the full copied-Docker validation chain and all four hosted checks. Independent Codex review identified one inaccurate constructor-consumer sentence; rustdoc-only successor 3626f6e2677a1d6d3af08b88245584800596ff55 corrects it without changing runtime code or test expectations. Fresh copied-Docker documentation, doctests, formatting, source structure and all-feature Clippy pass on the successor. The complete independent review and exact-successor APPROVE include the mandatory verification checklist. Final-head hosted run 37147862754 completed with all four required jobs successful on the final head; older green runs were not substituted for it. CodeRabbit remains rate-limited.

Compatibility and limits

No durable format, identity, publication order or dependency changes. A formerly accepted unsupported repository-task platform now refuses intentionally. The pinned-root route validates that capability, not the historical spelling or alias history of the earlier lock-acquisition path. No arbitrary raw namespace isolation or power-loss guarantee is added. No performance improvement is claimed; profile inspection adds bounded filesystem metadata work during construction.

This branch started from origin/main at 6051abb and incorporated main 182e49520f98c6035828a739dcf3c224df535b84 through normal merge 657593fe50c824dd31dc328bf9e696183ef20767. Both documentation conflicts retain the platform-admission, sealed-stage observation (#158) and partial-seal recovery (#172) contracts. It does not depend on PR #156. Original roadmap checkboxes are unchanged.

Closes #150. Refs #131, #132.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 32 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 72ed856f-aa45-4ed1-8b57-532d04202e7f
📥 Commits

Reviewing files that changed from the base of the PR and between 182e495 and 3626f6e.

📒 Files selected for processing (12)
  • CHANGELOG.md
  • docs/formats/segment-store-v1/publication.md
  • docs/formats/segment-store-v1/rationale.md
  • docs/formats/segment-store-v1/requirements.md
  • docs/testing-evidence/catalog-platform-admission.md
  • src/adapters/filesystem_catalog_publisher.rs
  • src/adapters/filesystem_platform_admission.rs
  • src/adapters/filesystem_platform_profile.rs
  • tests/catalog_filesystem_publication/directory_laws.rs
  • tests/catalog_platform_admission.rs
  • tests/catalog_platform_admission/unsupported_directory.rs
  • xtask/src/durability_crash_matrix/production_protocol/initialization.rs
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Validation receipt for final pushed head fa06adfde89b70be5aaf7356206b7d8c1fbce169:

Evidence Result
Parent 6051abb public unsupported-platform law, committed as 1ffdf5a Observed runtime RED: refused platform acquired public publisher authority.
Fixed public negative and positive laws GREEN in debug and release on actual tmpfs/ext4 respectively.
Separate production write-dropping calibration Positive assertion failed with observed [] versus the supplied retained evidence bytes; negative law remained green.
Complete production crash matrix GREEN debug and optimized, with ext4 scratch and unchanged fault schedule.
Full workspace tests and doctests GREEN debug/release, copied exact source f7956c0405141cda7c4e93d257ace897b272e082.
Formatting, source structure, all-feature/minimal-feature Clippy GREEN with warnings denied.
Markdown Initial overlong paragraph refused; final changed documents GREEN after formatting-only fa06adf.

The final commit changes only paragraph formatting in the publication contract. No runtime source, test or dependency changed after the complete local campaign. Earlier descriptor-probe EBADF diagnostics are retained; they exposed the need for a readable capability-relative descriptor and were corrected without weakening the production admission rule or expected refusal.

Hosted run 37054126009 is queued for the final SHA. The earlier run was cancelled by normal concurrency handling after the final push and is not an acceptance receipt. CodeRabbit reports a rate limit; its green status is not approval. No merge has been performed.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer finding — current consumer documentation

Candidate: 657593fe50c824dd31dc328bf9e696183ef20767.

Severity File/lines Issue Evidence Acceptance check
P4 src/adapters/filesystem_catalog_publisher.rs:80–81 Rustdoc still says repository process-death tests call the legacy locked-root constructor. Current crash publisher calls ordinary FilesystemPlatformAdmission::initialize and FilesystemCatalogPublisher::open at xtask/src/durability_crash_matrix/production_protocol/initialization.rs:45–47; current alternate-route callers are the public admission regression laws. Describe the supported already-locked caller route and explicitly identify ordinary initialization as the crash campaign route; documentation build and exact-head delta review pass.

This is a verified documentation mismatch, not a runtime failure. @codex: second-opinion input is welcome; a hosted review quota is not approval. The authorized independent Codex review is in progress and its full report will be posted.

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create an environment for this repo.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent review of Keep PR #157

Reviewer: independent Codex review agent /root/landing157_review, GPT-6 family; the precise deployed model variant is not exposed in this session. This is the user-authorized independent Codex fallback applying the complete agy-review mandatory protocol, not an agy subprocess or CodeRabbit approval. Reviewed 2026-10-03. No source edits, tests, commits, pushes, comments, merge, configuration changes, or subagents were performed by this reviewer. Only this report was written.

Repository: flyingrobots/keep. Branch: fix/150-catalog-platform-admission. Exact reviewed head: 657593fe50c824dd31dc328bf9e696183ef20767; tree: 1e041554cfce1e5d4112e827c5ee3033ea1abfc5. Target: main, exact base 182e49520f98c6035828a739dcf3c224df535b84. Local HEAD/tree and live PR metadata agree. The worktree was clean at inspection. The verdict applies only to this head.

Findings

P4 — Update the constructor's actual consumer description. src/adapters/filesystem_catalog_publisher.rs:80-81 says repository process-death tests use open_unchecked_for_repository_tasks after executing initialization through RepositoryInitializationStorage. This PR deliberately removes that usage: xtask/src/durability_crash_matrix/production_protocol/initialization.rs:45-47 now calls FilesystemPlatformAdmission::initialize and ordinary FilesystemCatalogPublisher::open. A repository-wide caller search finds only the alternate-route integration laws at tests/catalog_platform_admission.rs:44,63. A reader following the public rustdoc therefore receives a false description of the present crash campaign and its admission boundary. Describe the already-locked caller route as the supported legacy entry point, and identify ordinary initialization as the current crash campaign route. Validation: inspect the resulting wording against both call sites, build documentation, and review the documentation-only successor. No runtime change or new runtime regression is required for this correction.

No demonstrated runtime correctness, durability, identity, authority, or integration defect was found in the scoped candidate. The P4 documentation correction is the only requested change; its low severity should not be inflated into a runtime failure.

Verification Checklist: runtime paths

Path traced Exact source coordinates and result
Ordinary initialization authority filesystem_store_initializer.rs:32-36 → filesystem_initialization_storage.rs:25-30 → filesystem_platform_profile.rs:42-56,114-128 → initializer 79-96. Production profile precedes namespace initialization; typed phase/source survives. Strict root identity is required before a proof is returned.
Published-store reopen authority filesystem_store_initializer.rs:52-55,99-121 → profile 42-56 → writer acquisition and published namespace admission → profile 201-204. Existing production checks remain unchanged.
Alternate repository catalog authority filesystem_catalog_publisher.rs:93-100 → filesystem_platform_admission.rs:33-39 → retained-lock clone → sync_capable_directory.rs:10-24 opening . readably → profile 61-64,114-128,201-204 → ordinary publisher 55-75. No external proof or boolean switch can bypass the checks.
Linux profile parity Both ordinary and alternate routes invoke the same admit_linux_profile with the same three PROTOCOL_DIRECTORIES at profile 11,55,62. Root and present children must satisfy ext4/writable/non-casefolded constraints (276-295); children must share device and mount (297-309); statx must report required identity (145-164,217-238). Missing directories are allowed during profile checking, but publisher construction subsequently opens every required directory (62-64) and refuses absence/non-directory/link state.
Other operating systems Profile 66-72 refuses the alternate route with Unsupported; ordinary open 97-103 also refuses. No external catalog bypass remains on these configurations. This was statically inspected; this reviewer did not run another-OS target.
Private test route Admission 27-30,50-58 and publisher 103-112 are cfg(test) and restricted to the adapter module. The repository feature no longer enables this catalog bypass. Lenient probes still exist for separate migration boundaries and are not falsely classified as catalog constructors.
Publisher lifetime and failure Publisher 31-43,55-75, writer lock 72-119,123-149: all clone/profile/directory errors return before publisher success; consumed lock drops on error. The successful publisher retains lock after directory/stage fields. No protocol artifact is created or repaired by alternate admission. Existing profile root synchronization is preserved; it is not namespace rollback.
Writable positive outcome Integration law catalog_platform_admission.rs:54-73 → ordinary initialize/drop → writer reacquisition → alternate constructor → publisher 124-127 → filesystem_segment_stage.rs:31-40,55-67. The supplied exact bytes are read from the retained stage after handles close. This establishes staging capability, not completed catalog publication or power-loss durability.
Unsupported negative outcome Integration law catalog_platform_admission.rs:24-50 → owned /dev/shm fixture (unsupported_directory.rs:13-29) → exact ordinary AdmitPlatform/Unsupported → real writer lock → alternate route → exact Unsupported. Unconditional refusal cannot satisfy the positive companion law.
Publication crash campaign production_protocol.rs:36-43 → production_protocol/publication.rs:23 → initialization 42-48 → ordinary production initialization/open → actual segment stage publication.rs:28-35. Failure now honestly stops unsupported scratch before publisher authority.
Indirect harness consumers Recovery segment/head preparation production_protocol/recovery.rs:52-89 both use initialization publisher; migration production_protocol/migration.rs:24 invokes publication first. These paths inherit ordinary catalog admission. Generic initialization initialization.rs:17-39, migration/version-two admission, and recovery discard authority retain their distinct fault boundaries.
Sealed-stage merged integration Publication 35-44 → ObservedSegmentStage 25-70 → real stage/write/flush/sync → without_observer 73-84 → original publisher selection filesystem_catalog_publisher.rs:141-155. Private stage and metadata remain together; selection closes the same stage and verifies original publisher authority. SealedSegment 24-32,69-90 has no public arbitrary stage conversion.
Observer errors and interruption Observer 26-50: excessive limit refuses before effects; successful underlying writes are checked; after-write Interrupted retains its original error under non-retryable Other, preventing replay of completed effects. Flush/sync 54-70 still perform underlying operations and propagate before/after failures. No callback receives a stage.
Crash observer state transitions production_protocol/segment_stage.rs:30-64,69-125 preserves before/during/after byte boundaries with checked subtraction/addition, and distinguishes prefix/sealed flush/sync lengths. control.rs:28-70 uses an explicit readiness socket and blocking death gate, without synchronization sleeps. Process death releases kernel writer ownership; retained bytes remain recovery evidence.
Partial-seal merged classification recovery_segment_classifier.rs:24-46,65-83 → recovery_segment_seal_framing.rs:9-66. Recognized incomplete seals validate available fixed fields before truncation. Complete seals still use full admission. Temporary expected-field completion does not admit absent bytes or claim feasibility for unchecked variable coordinates.
Assessment, discard, and restart integration recovery_stage_assessor.rs:19-28 preserves classifier refusal → recovery_segment_stage_error.rs:32-35,66-79 preserves exact seal cause. recovery_stage_discard_planner.rs:16-54 needs successful truncation assessment, so corrupted seals cannot become requests. Harness recovery 92-114 uses fingerprint/admit/assess/plan; restart restart/semantic.rs:50-73 invokes the same classifier on actual reopened bytes.
Fuzz/replay merged integration fuzz_targets/segment_format.rs:12-23,70-110 routes selector 5 to the production classifier and independent fixed-byte table; seed producer segment_seeds.rs:38-62 emits the retained counterexample; tests/materialization.rs:49-54,143-164 requires the named emitted input, correct selector, and exact runtime cause. The corpus count is not the runtime oracle.

All abbreviated adapter filenames in the table are under src/adapters/; recovery filenames are under src/adapters/recovery/; production/restart harness filenames are under xtask/src/durability_crash_matrix/. New laws are under tests/; fuzz paths are under fuzz/ and seed paths under xtask/src/fuzz_seed_corpus/.

Verification Checklist: history and every merge

The original common main is 6051abb25a9fd33ae7ee0de5614514b709a4d82a. 1ffdf5a adds only the exact negative regression/fixture; f7956c0 contains the focused fix, positive law, harness route, replacement of the ineffective spelling test, and records. fa06adfde89b70be5aaf7356206b7d8c1fbce169 changes only paragraph formatting in publication documentation. The current net diff against target is twelve files, 200 additions and 37 deletions; those are diff coordinates, not correctness evidence.

Merge audited against both parents Integration verification
657593fe50c824dd31dc328bf9e696183ef20767, parents fa06adf / 182e495 First-parent diff imports #172 recovery and #158 observer code; second-parent diff is exactly this finite #150 change. Imported runtime, tests, fuzz, and observer caller code remain byte-for-byte equal to current main. The combined changelog retains #150, #146, #171 and prior #99 entries. Rationale retains both admission and observation decisions. Requirements retain corrected catalog authority, sealed receipt, and partial seal evidence rows. Publication admission wording and incoming recovery/fuzz documentation are preserved.
182e49520f98c6035828a739dcf3c224df535b84, parents d0cff10 / e781c0b #158 integration removes arbitrary sealed conversion, introduces private observer, preserves underlying effects/error sources and swaps crash caller to without_observer; second parent is the branch tree (empty tree diff). #172 classifier/error paths are retained.
e781c0b276ec4d1f66a76668bd31893261a2e6dd, parents 15aa976 / d0cff10 First-parent diff imports partial-seal correction and raw receipts; second-parent diff carries observer changes. Subsystems coexist without rerouting assessment or weakening sealing. Combined rationale/requirements/changelog retain both contracts.
d0cff10d7c911d33d615c3aa2246ae2b4497432a, parents 6051abb / 07e6cc4 #172 integration adds incomplete-seal validator, typed cause, permanent counterexample/fuzz selector and runtime materialization evidence; second parent is the branch tree (empty tree diff).

The prior #99 narrower contract is already in the common base: preserve/refuse incomplete retention stages before effects, cooperating writer assumptions, fresh retries, and explicit uncertainty instead of rollback. #150 does not alter its code or documentation. This review does not reinterpret that accepted contract as arbitrary out-of-band namespace isolation, inode-conditional unlink, or rollback after effects.

Verification Checklist: constants, numbers, and documentation

Constant or claim Checked evidence and conclusion
Three v1 directories; nine separate v2 directories Profile 11,18-28 explicitly lists them. Alternate catalog route uses the three-directory profile; no claim of v2 certification is made.
ext4 magic 0x0000_ef53, casefold 0x4000_0000, mount/device checks Existing profile 285-306 is shared verbatim by ordinary and alternate paths; platform requirements at recovery.md:368-387 match. Actual positive/negative admission laws reject unconditional acceptance/refusal. No new numeric filesystem threshold is introduced.
Strict versus lenient root identity Profile 201-214,223-238 and admission 38,56 show production alternate is strict, private tests remain lenient; migration retains its separately declared bypass. Older kernel/lenient comments are not interpreted as a production catalog exception.
Restart byte limit 1_048_576 New laws 41,61 use the unchanged harness bound initialization.rs:15,51-54, admitted by the checked newtype. Neither receipt nor PR promises this as a latency/memory measurement. No changed performance budget or timed limit is hidden by the fix.
Header/record/seal ends 64/209/337; interruptions 32/136/273 Crash observer 10-15 matches the old decorator diff exactly. Independently decoding one-zero golden hex gives 337 bytes; empty golden gives 192 = 64 + 128. Canonical seal/header lengths and recovery fixtures agree. Existing campaign schedule is retained.
Observer generated lengths 1 through 64 and seven-byte writes byte_equivalence.rs:15-35 and observer test 110-116 match the evidence table. This is a finite repeating-pattern family, not arbitrary payload equivalence. The independently supplied empty golden checks a separate specified case.
errno 5, non-retryable post-effect interruption, exact bytes Fault-port tests, raw individual mutation diagnostics, and original interruption-chain assertions agree; the observations do not claim actual failing disk or rollback.
Partial-seal fixed offsets/widths and format version 1 versus corrupt version 2 Validator 9-66, canonical seal 5-10, independent contradiction table framing_laws.rs:61-202, and fuzz byte table 92-110 agree. Every recognized incomplete end in 16..128 is visited; absent mutations retain exact truncation. This is fixed framing, not complete future seal feasibility.
Fuzz seed 17101, campaign 15 seconds, per-input timeout 5, RSS 1024 MiB, maximum input 1048576 partial-seal-corruption.md replay commands match raw fuzz-green.txt:17-19. Receipt ends at line 708 with 3,110,375 runs in 16 seconds: 15 is the requested libFuzzer campaign bound, not a measured exact-duration claim. Single-input replay is explicitly separate from fuzz exploration.
Rust 1.96.0, edition 2024, Linux aarch64 Toolchain/Cargo declarations match the fresh companion manifest and historical build profile output. Pinned nightly/cargo-fuzz settings are historical fuzz coordinates, not a change to the stable product toolchain.
#150 changelog, publication, rationale, requirements and evidence claims Read the entire net diff and finite inventory. No format, identity, dependency or publication-order changes occur. Ordinary init is now the harness publisher route; retained-root admission does not claim ambient spelling history. The sole stale current consumer description is finding P4.
#172/#158 incoming documentation and historical figures Evidence records, recovery/fuzz docs, rationale and requirements retained their scoped claims. Generated family limits, interrupted coordinates, calibrated failures and debug/release receipts agree. Historical full-suite test totals are not restated as current totals or proofs.
README and unrelated durable-format/retention numbers README is unchanged; these numbers are outside the finite PR delta. No repository-wide numerical or recovery audit is claimed.

No new timing, throughput, recovery-time, power-loss, buffer-performance, percentile, allocation optimization, or measurable speedup claim is introduced. Missing ordinary per-test ceilings and sandbox controls remain disclosed enforcement gaps; none is fabricated from green execution.

Raw RED/GREEN and calibration inspection

Read individual failures and restored results, not merely mutation labels or case counts. External receipts below use relative coordinates in the retained review evidence archive; source-attestation limitations are stated separately.

Claim / assertion Raw coordinates inspected
#150 parent actually mints refused authority keep-audit/150/parent-red.log:44-56, error refused platform acquired public publisher authority, after successful compilation. Parent SHA and unchanged expectation verified from test/fix history.
Descriptor attempt was not GREEN 150/focused-green.log:9-24 actually contains RED; 150/crash-validation.log:10-29 contains exact EBADF and both failing laws. Filenames were not trusted as verdicts.
#150 restored laws 150/crash-validation-readable.log:1-9,48-56: negative and positive execute successfully in debug/release. Fresh head repeats them at 157-validation.log:517-524,2522-2529.
#150 exact persisted-byte calibration 150/write-calibration.log:45-63: negative passes; positive exact assertion fails with [] against literal retained evidence bytes. Dedicated mutation/source/output paths distinguish builds.
#150 full/static/document attempts 150/full-validation.log, clippy.log, markdown.log, markdown-final.log: historical suite/profile evidence indexed; original line-length failure retained and subsequent formatting GREEN inspected. Fresh-head checks supersede historical acceptance, not calibration.
#146 compiler capability RED and restored restriction keep-audit/146/capability-red.log: compile-fail law incorrectly compiles on parent, then fails for that exact reason; focused and final-head logs show it refuses on fix. This is static/API calibration.
#146 original individual runtime mutations keep-landing/158-cal-retry.log:48-58, 158-cal-flush.log:48-63, 158-cal-sync.log:48-58, 158-cal-clamp.log:48-58, 158-cal-bytes.log:48-71. Read original script 158-original-calibrate.sh; each separate production mutation compiles and fails its named outcome. Skipped flush reports wrong failure boundary; skipped sync produces forbidden sealing; clamp admits excessive limit; retry repeats effects into success; zeroing fails exact golden bytes.
#146 differential calibration/restoration 146/equivalence-calibration.log fails exact output at generated length 1; equivalence-validation.log, final-focused.log, final-head-validation.log restore runtime laws. Intermediate Clippy doc-markdown failure remains in focused receipts, followed by corrected warnings-denied results.
#171 original/reduced runtime RED Committed partial-seal-corruption/parent-red.txt:45-61 and reduced-parent-runtime-red.txt:9-29: classifier/assessment failure, plus first finite-sweep witness offset=16, observed=17.
#171 diagnostic/source/coordinate calibration Read all three committed patches and full wrong-diagnostic-red.txt, dropped-source-red.txt, wrong-coordinate-red.txt; each named assertion executes after compilation and fails for wrong observed value, missing typed cause, or wrong exact truncation length.
#171 materialized-input calibration Read patches and full materialized-selector-red.txt:11-25, materialized-absent-red.txt:9-19, materialized-diagnostic-red.txt:11-25; correct named input/selector/runtime error are separate witnesses. Restored materialized-green.txt:1-23 executes debug/release and Clippy.
#171 restored adjacent boundaries Read framing-green.txt, recovery-green.txt, calibration-green.txt: new law and classification/assessment/discard neighbors execute debug/release with expected result.
#171 semantic fuzz RED and restored exploration Read fuzz-parent-red.txt assertion at 48-50, exit 77 at 88; reviewed fuzz-green.txt replay, explicit seeded bounded launch and completion at 708. Compilation/setup/zero-selected-test attempts are not credited as calibration.

Historical external raw logs do not themselves embed full source SHA and launch commands. Their SHAs come from versioned evidence/commit separation and PR receipts; this reviewer does not represent them as independently source-attested reruns. Committed normalized #171 receipts deliberately replace container prefixes while preserving diagnostics. Fresh candidate execution is bound through an exact copied-tree manifest, separate from those historical attestations.

Standards, queue, execution, and limits

Read applicable project AGENTS.md, the supplied global atomic-work agreement, all binding Testing Standards, and the enforcement profile. The bug-fix declaration, owner, named oracles, medium filesystem laws, small/static calibration subjects, retained failures, finite exploration, fixture ownership, deletion criterion and retirement conditions are present. No new parser, durable format, dependency, optimization, unsafe code, unbounded content allocation, public boolean parameter, lossy cast or changed protocol arithmetic is introduced by #150. Existing reviewed modules over the target size are not misrepresented as newly created policy compliance. Markdown physical-line wrapping rules from another repository were not imposed; the actual local lint profile applies.

The removed source-string test is inspected at its old revision: it freezes one signature and public declarations and misses the feature-gated producer. Public runtime refusal and positive staging laws replace its actual claimed promise. This is the documented failed-calibration deletion criterion, not deletion of a failing product regression. No test result/count substitutes for runtime authority evidence.

GitHub inspection: supplied fully paginated queue read; live REST comments/reviews refreshed with pagination; live GraphQL reviewThreads returned no nodes and hasNextPage=false. There are no submitted reviews or review threads. CodeRabbit explicitly reports rate limitation; its passing check is not approval. Quota/setup bot comments and historical receipt are not correctness or acceptance evidence. The newly posted P4 report matches the verified issue; this reviewer did not publish it.

Executed by this reviewer: read-only Git diff/history/blob/identity/status checks, whole finite #150 diff, source searches/reads, raw evidence inspection, independent golden byte-length decoding, git diff --check, live GitHub identity/queue/check reads. No Rust commands or host tests were executed by this reviewer.

Inspected only: parent executor's full fresh Docker campaign, keep-landing/157-validation.log and 157-validation-manifest.md. Exact copied tree agrees with reviewed head. Manifest records Linux aarch64, pinned stable Rust, separate build output, ext4 scratch and tmpfs negative fixture. Parent executor reports terminal EXIT 0. Commands cover debug/release process-death matrices, golden/conformance/source-structure gates, format, both feature checks and warnings-denied Clippy, full workspace debug/release tests, doctests/docs/MSRV and fuzz format/check/Clippy. Direct current-head raw law results are inspected at the coordinates above, with observer/recovery laws and sealed compile-fail example also present. This inspection is not a reviewer-owned test execution or physical power-loss experiment.

Live hosted checks at reviewed head all pass: Rust quality gates, documentation/workflow integrity, dependency policy and runtime fuzz smoke, run 37147249947. Their statuses were independently queried; this reviewer did not inspect every hosted job's complete log, rerun dependency audits, or execute live fuzz independently. Current-head checks must be queried again if the branch changes.

Coverage boundaries: scoped runtime paths and incoming merge integration were audited; this is not an exhaustive audit of the entire Keep repository, every historical #99 fault transition, another OS, arbitrary remount/out-of-band namespace attacks, physical power loss, every possible input/schedule, or per-test enforcement. The repository's disclosed ordinary ceiling/isolation gaps are not approved waivers or new compliance claims. No performance benchmark was run because no optimization or numeric performance promise is changed. Future documentation-only correction should retain runtime tree and receive exact-successor delta review plus relevant doc/static and hosted checks.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent exact-successor review: Keep PR #157

Reviewer: independent Codex agent /root/landing157_review, GPT-6 family (precise deployed model variant not exposed). User-authorized independent fallback under the complete agy-review protocol. Reviewed 2026-10-03. Read-only source/remote inspection; no Rust execution, host tests, source changes, publication, configuration changes or subagents. Only this report was written.

Repository flyingrobots/keep, branch fix/150-catalog-platform-admission, target main at 182e49520f98c6035828a739dcf3c224df535b84. Exact successor head 3626f6e2677a1d6d3af08b88245584800596ff55, exact tree a7d9f55173f9b7a2c3511077cefe784c9902f8c9; local identity and live PR metadata agree. Worktree is clean. Previous fully reviewed head 657593fe50c824dd31dc328bf9e696183ef20767, tree 1e041554cfce1e5d4112e827c5ee3033ea1abfc5.

Findings

No remaining actionable findings in the finite successor. Prior P4 is closed. The public rustdoc now accurately describes the legacy route as accepting an already retained writer lock and the catalog crash campaign as using ordinary platform initialization and Self::open.

Verification Checklist: successor delta and adoption

Verification Evidence and result
Complete successor diff Exact predecessor-to-successor diff changes only src/adapters/filesystem_catalog_publisher.rs, with three rustdoc lines replacing two at lines 80-82. No runtime tokens, test expectations, dependencies, constants, formats, identity, publication ordering, authority paths, merged runtime code or evidence records change.
Closed documentation scenario Successor rustdoc filesystem_catalog_publisher.rs:80-82 matches xtask/src/durability_crash_matrix/production_protocol/initialization.rs:45-47: ordinary FilesystemPlatformAdmission::initialize then FilesystemCatalogPublisher::open. It no longer claims that the process-death campaign invokes the alternate route.
Alternate current consumer Public integration law callers remain tests/catalog_platform_admission.rs:44,63; actual constructor is now at publisher 94-101, accepting the same writer lock and policy, still checking FilesystemPlatformAdmission::from_repository_writer_lock.
Platform/refusal/capability paths All prior ordinary initialize/reopen, alternate Linux/non-Linux, private unit-test, precise refusal and positive staging checks remain unchanged. Only source line coordinates in this one publisher file shift below the edited paragraph.
Every prior merge and integration invariant The successor is a non-merge documentation correction. The full prior audits of merges 657593f, 182e495, e781c0b, d0cff10, including #172 partial seal, #158 sealed observer and accepted #99 boundaries, apply unchanged.
Constants and every scoped document figure No numeric claim or constant changes. The corrected consumer description is consistent with prior publication/rationale/evidence prose. The prior constant, format-byte, finite generated-family, campaign limit and historical-figure inventory applies unchanged.
Complete prior Verification Checklist adopted at successor Adopt every runtime path, parent/merge integration check, constant/claim/document check, raw RED/GREEN calibration inspection and repository-standard result in 157-independent-review.md for this successor, subject to the coverage limits already stated there. This is explicit adoption of the entire checklist, not just its conclusion. Finding P4 and the predecessor REQUEST CHANGES verdict are superseded by the inspected correction and this verdict. Prior hosted results remain predecessor results, not successor results.
File/line translation In src/adapters/filesystem_catalog_publisher.rs, unchanged coordinates before line 80 retain their prior meaning; replace old lines 80-81 with new 80-82; old line 82 and every later line map to old line + 1. Thus prior alternate 93-100 is 94-101, private test route 103-112 is 104-113, stage creation 124-127 is 125-128, and selection 141-155 is 142-156. All other files retain their exact coordinates.
Review-before-correction traceability Full predecessor report was posted at https://github.com/flyingrobots/keep/pull/157#issuecomment-5972688527 before this correction. This successor addresses only its finite documentation finding.
Static diff validity Reviewer executed read-only complete git diff, diff stat, git diff --check, identity/status, exact current rustdoc/caller reads and live PR/check queries. Diff has no whitespace errors.

Validation and remaining gate

The complete predecessor Docker runtime campaign ended successfully on its exact copied runtime tree. Since this successor changes only comments, its product code, regression laws, raw calibrations and merged implementations are identical; those runtime receipts remain relevant evidence with their original source coordinates. No repeated full campaign is represented as having run on the successor.

Inspected the fresh 157-doc-delta-validation.log, whose first line records successor tree a7d9f55173f9b7a2c3511077cefe784c9902f8c9. It contains successful documentation generation, all workspace doctests (including the sealed-stage compile-fail law), and warnings-denied Clippy completion in the copied Docker source. This reviewer did not launch those commands. The log itself does not contain a terminal exit marker or command tracing; the parent executor separately confirmed terminal EXIT 0 for session 51856 and completion of the full listed doc/static sequence. Terminal success is therefore executor-attested, not a fresh command executed by this reviewer.

At this review's live query, all four successor hosted jobs in run 37147862754 were pending: Rust quality gates, documentation/workflow integrity, dependency policy and runtime fuzz smoke. CodeRabbit's rate-limited passing status is not a review approval. Do not substitute predecessor hosted run 37147249947 for successor CI. The independent review is approved and local doc/static completion is executor-confirmed; merge eligibility still requires all required exact-successor hosted checks green, unchanged head/base and authorized repository protections.

All prior scope limits remain: static review plus inspected execution is not reviewer-owned runtime execution, process death is not physical power loss, finite paths/input families do not prove all schedules or inputs, and this is not a repository-wide or speculative namespace-hardening audit. No mandatory changed area remains unreviewed in this finite documentation delta.

APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer closure — platform admission

Final candidate: 3626f6e2677a1d6d3af08b88245584800596ff55; target main 182e49520f98c6035828a739dcf3c224df535b84.

Item Severity/source File Commit / evidence Outcome
Retained writer lock bypassed production filesystem admission P1 / issue #150 Catalog publisher/admission/profile adapters Runtime parent RED at regression 1ffdf5aa22bc1c0b4e77c472e5cc552d0dfb4fae; original fix f7956c0405141cda7c4e93d257ace897b272e082 Exact tmpfs refusal and real admitted ext4 staging pass debug/release; exact-byte assertion fails under write-dropping mutation.
Preserve incoming sealed-stage observation and partial-seal diagnostics Integration review Crash publication, recovery classifier, requirements/rationale/changelog Normal merge 657593fe50c824dd31dc328bf9e696183ef20767; both documentation conflict sides retained Full copied-Docker campaign passes, including both crash profiles and adjacent runtime laws; incoming code remains intact.
Outdated constructor consumer description P4 / Code Lawyer and independent Codex src/adapters/filesystem_catalog_publisher.rs 3626f6e2677a1d6d3af08b88245584800596ff55; finding Corrected to distinguish already-locked legacy callers from current ordinary crash initialization. Documentation-only change; no fabricated runtime RED.
Historic provider limits and receipts Review reconciliation Complete conversation/review/thread queue Original CodeRabbit quota and Codex review quota comments, prior validation receipt, posted complete independent review Provider quotas are not approval. Historical evidence supports calibration; final-head checks and authorized independent review determine landing.

Full candidate validation at 657593f used a clean copied Docker tree 1e041554cfce1e5d4112e827c5ee3033ea1abfc5, separate build output, Linux aarch64 Rust 1.96.0, actual admitted ext4 scratch, and actual tmpfs for the negative law. The sequential chain exited 0: golden/conformance/source-structure checks, debug/release process-death matrices, formatting, all-feature/minimal-feature compilation and warnings-denied Clippy, debug/release workspace tests, doctests/docs/MSRV, and fuzz-target formatting/compilation/Clippy.

The final successor changes rustdoc only. Its copied tree a7d9f55173f9b7a2c3511077cefe784c9902f8c9 was verified, and its fresh format/source-structure/documentation/all-feature doctest/Clippy chain exited 0. The preceding full runtime campaign applies to unchanged implementation and test expectations; it is not presented as a second full run at another SHA. Fresh hosted run 37147862754 completed with all four required jobs successful and supplies final-head acceptance, including runtime fuzz, documentation/workflow integrity and dependency policy.

The authorized independent reviewer was configured as GPT-6.1-sol with high reasoning. The full initial report contains every traced path, merge-parent comparison, constant/claim verification and raw calibration coordinates. The final delta report confirms the resulting exact head and closes its only requested change.

Limits remain explicit: no arbitrary out-of-band namespace isolation, ambient alias-history attestation, physical power-loss evidence, unrelated adapter certification, new performance claim, or universally enforced test resource sandbox is asserted. The ineffective source-spelling test was replaced with public runtime laws under its recorded failed-calibration deletion criterion. No changes-requested review or actionable inline thread remains. No repository protection bypass is authorized or used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Preserve platform admission across public catalog publisher routes (T-12.2)

1 participant