Test: prove reader-fence process death and collector exclusion (#113) - #160
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 41 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (13)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-head validation receipt: Copied-source Docker with pinned Rust 1.96.0, Linux aarch64, owned scratch and real kernel flocks passes:
The separate mutation replacing shared acquisition with unlock fails both runtime laws at the intended checks: Raw author receipts are retained under the issue-113 scratch directory, including the initial Clippy feedback and copied-checkout Git ownership setup failure. Those setup failures are not calibration evidence. The corrected full validation completed successfully without altering product code or weakening checks. Hosted CI: documentation and dependency jobs are green; Rust and fuzz jobs are still running at this receipt. CodeRabbit and hosted Codex report usage limits; neither provided independent approval. This comment does not claim merge readiness or mainline integration. |
Bounded Code Lawyer calibration findingCandidate
The SIGKILL status and channel protocol markers attest the injected schedule; they are not separate product promises requiring artificial expectation mutations. The extra shared-lock control calibrates detection at the real filesystem boundary and is not presented as an existing Keep defect or a production subprocess path. No new product behavior, expanded scheduler, broad hardening pass or mutation score is requested. @codex — second opinion welcome; the finite experiments follow from the observed evidence gap. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Independent review: Keep PR #160Reviewed head: This is the explicitly authorized independent Codex fallback using the agy-review protocol. It is a read-only review, with no host Rust execution, source modifications, commits, publication, configuration changes, or delegation. The only written artifact is this report. The checkout was clean and the reviewed head/tree were reconfirmed at completion. Review approval would not authorize merging. FindingsNo demonstrated product defect was found in the six-file PR delta or its integration with the current target. The production reader implementation is unchanged relative to target main. There is one binding evidence-admission gap below. It concerns demonstrated falsification, not an allegation that the unchanged product mishandles reader death. E1 — P2: Complete calibration of the distinct release and preservation outcomesLocations: The retained Concrete consequence: removing or accidentally bypassing a newly introduced release/preservation observation has no recorded negative control demonstrating that the remaining test fails for that violation. This is a missing evidence requirement, not a verified assertion bypass in the candidate. Suggested finite fix: one bounded batch of isolated calibration experiments covering the three distinct outcomes, followed by restored GREEN, with source/tree, command, separate build directory, named failure and limitations recorded. An extra controlled shared holder can keep the real filesystem fence unavailable after the reader dies; this is OS-boundary oracle calibration, not a production bug claim. A copied production acquisition mutation that preserves its flock but corrupts the persistent file after the last guard can reach the preservation observation. A copied production snapshot refusal after shared acquisition can preserve the kernel-queued schedule and falsify post-release admission. Demonstrate that each intended check is reached, rather than counting earlier setup or exclusion failures. Equivalent alternatives are acceptable. No separate mutations are requested for PID, protocol bytes, generation fixture, signal number, watchdog branches, or individual device/inode/length coordinates. In particular, SIGKILL status is attestation that the injected fault occurred, not a separate Keep behavior needing an invented production subprocess path. No automatic-discard change, additional GC implementation, unrelated hardening, field-by-field mutation campaign, or alteration to production behavior is requested. Verification ChecklistScope, review surfaces, and standards
Runtime paths and state/error transitions
The parallel preexisting same-process law at Merge audit
Constants, numeric claims, raw evidence and calibration
Executed, inspected, skipped and unavailable
The finite blocker is E1. Supply its bounded outcome-calibration receipts and obtain a fresh exact-head review; final merge admission remains separate. Reviewed SHA: REQUEST CHANGES |
Independent bounded delta review: Keep PR #160Reviewed head: This is the expressly requested read-only Codex fallback under the agy-review protocol. It reviews only the evidence successor and closure of E1. No host Rust tests, new experiments, source modifications, publishing, configuration changes or delegation were performed. Only this report was written. Findings and E1 dispositionNo actionable findings remain. E1 is closed by a finite batch covering the three distinct outcomes named in the original independent review. The added documentation accurately distinguishes actual outcome falsification, OS-boundary negative controls, fault attestation and unchanged production behavior. It preserves the partially interleaved child error instead of inventing a reconstructed diagnostic. Verification ChecklistAdoption of the full review
New calibration: actual checks reached
All three named experiments compiled, ran one selected law and exited 101. The traced launcher records each result and dedicated source/target directories. The source variants contain only the documented additions; no checker or expected-value edit is hidden in these receipts. Original missing-shared-lock RED continues to supply the two exclusion calibrations from the adopted review. Together, these close the complete finite E1 gap. Signal status, channel markers and fixture generation remain experiment attestations, not targets for a separate field-by-field mutation campaign. Evidence provenance and byte fidelity
New prose, numbers and bounds
Execution and remaining limitsExecuted by this reviewer: read-only Git status/tree/diff/history checks; independent byte-normalization and patch-reconstruction comparisons; nonmutating patch application checks; read-only Docker source hashes and environment inspection. Inspected only: author's experiment execution and restored GREEN logs, scripts, and the full prior verification record. No Rust or calibration was rerun by this reviewer. The parent reported calibration session 11621 terminal exit zero; its trace shows each expected failing Cargo run exits 101. The report accepts the actual named runtime failures, not exit-code checking alone. No measurement or diagnostic was invented. Physical power loss, arbitrary interleavings, a complete GC, hostile raw writers and full resource-sandbox compliance remain outside the claims, exactly as in the original checklist. E1 is closed durably in the reviewed tree. No new or unresolved verified issue remains within the authorized delta. This is exact-head independent review approval; merging still requires the separately handled current-head hosted/protection and authorization gates. Reviewed SHA: APPROVE |
Code Lawyer activity summaryFinal candidate
The tests use repository-only initialization/migration admission, not platform certification. Kernel process death is not physical power loss; fixed schedules are not arbitrary interleaving exploration. Resource-sandbox gaps remain explicitly disclosed. Signal and protocol markers attest the experiment and are not used to manufacture unrelated calibration requirements. No API/format/security/durability behavior or performance claim changes. The original full review is published here; the bounded E1 finding is published here. Exact-successor approval, final-head hosted checks and the final feedback/protection recheck remain separate merge gates. Exact-successor independent APPROVE closes E1 at Final feedback pagination is exhausted: seven global comments, zero reviews and zero threads. Historical validation remains historical, duplicate quota notices provide no approval, E1 is closed, and no actionable finding remains. CodeRabbit is rate-limited; the maintainer-authorized independent Codex review satisfies the review fallback, without treating its status as CodeRabbit approval. Mainline rules retain signature, deletion and non-fast-forward protections; no bypass is requested. Normal merge follows the immediate head/base recheck under existing maintainer authorization. |
Missing evidence and outcome
The reader fence had same-process sharing tests but lacked permanent evidence for process death and for a new public snapshot waiting behind collection. This PR adds two Linux process laws through
FilesystemRetentionSnapshot::load. Change kind: missing verification; no production behavior change.A live child snapshot makes collection's exclusive acquisition return exactly
EWOULDBLOCK. After SIGKILL and reap, the same collector descriptor acquires the lock, and the persistent pathname retains its device/inode and zero length. In the opposite schedule, collection owns writer authority and the exclusive fence first; Linux's kernel lock queue must show the child's pending shared flock before the parent releases collection and observes successful snapshot admission.Validation and oracle
The oracle is KEEP-RETENTION-008 and the documented cooperating collector protocol. Readiness comes from Unix-domain channels; blocking is witnessed by the kernel, not by a delay without output. No sleeps establish ordering, and process spawning remains outside
src. Watchdogs only fail stuck tests.In a separate copied build, replacing shared acquisition with unlock makes both laws RED at their runtime checks: live collection incorrectly succeeds, and a new snapshot escapes the collector fence. Unmodified production passes in debug and release. All-feature warnings-denied Clippy passes. Full workspace debug/release tests and doctests, formatting, source structure, both Clippy feature profiles and Markdown lint pass at
8e436b2db7e8afe2a1942df19bd4c7473e414eaf. Two concurrent copies of the new test target also pass. All four required hosted checks are green on this exact head (run 37058881633). Automated reviewers reported usage limits, not approval. Evidence and replay include scope, failure output, environment limitations and deletion criteria.Current landing evidence
Integrated candidate
ee21b01d7b7740eaa56116809630534ea7caa05bpasses the full fresh copied-Docker validation chain and all four hosted jobs. Both process laws also pass alone, serially, in reversed standalone order and in simultaneous isolated binary runs. The independent review found no product defect and one finite calibration-evidence gap for post-death acquisition, persistent-fence preservation and post-release admission.One isolated batch demonstrates all three intended runtime failures, followed by restored debug/release GREEN. The existing evidence document now links replay patches and normalized raw receipts, explicitly distinguishing the retained-lock OS-boundary negative control from two production-output mutations. Final successor
c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3changes eight documentation/receipt files only; product code and test expectations remain unchanged. Whitespace, copied-Docker Markdown lint and patch applicability pass. Exact-successor independent APPROVE closes E1. All four jobs in final hosted run 37151013484 pass on this exact head. CodeRabbit remains rate-limited; the authorized independent review supplies the review gate, not its nominal green status.Scope and compatibility
No public API, format, identity, dependency, durability or recovery changes; no benchmark impact. The tests use repository-only initialization/migration admission and do not prove platform eligibility. They exercise actual kernel process death and filesystem lock identity, not physical power loss, arbitrary interleavings or a complete GC implementation. The collector follows the existing protocol with writer authority and the exclusive kernel lock.
Existing snapshot, corruption and substitution tests remain. A sleep-based negative assertion and source-string inspection were rejected because neither proves runtime exclusion. Child cleanup kills/reaps on failure, and each law owns its storage and channel. Linux
/proc/locksvisibility and therepository-tasksfeature are explicit execution requirements; other platforms supply no evidence from this target.Original branch base is main
6051abb25a9fd33ae7ee0de5614514b709a4d82a, including prerequisite #99. Normal mergeee21b01d7b7740eaa56116809630534ea7caa05bintegrates current maind08fafb2280a480a3c7d9460d13d53bbed4ae46b; the only conflict was CHANGELOG, with all entries retained. Original roadmap checkboxes remain unchanged; mainline integration remains a separate completion requirement.Closes #113. Refs #131, #132.
Security implications: production admission, identity, lock and corruption checks are unchanged. The evidence targets cooperating reader/collector behavior and grants no guarantee against arbitrary out-of-band namespace mutation.