Skip to content

Test: prove reader-fence process death and collector exclusion (#113) - #160

Merged
flyingrobots merged 3 commits into
mainfrom
test/113-reader-fence-process-death
Oct 3, 2026
Merged

flyingrobots merged 3 commits into
mainfrom
test/113-reader-fence-process-death

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Missing evidence and outcome

The reader fence had same-process sharing tests but lacked permanent evidence for process death and for a new public snapshot waiting behind collection. This PR adds two Linux process laws through FilesystemRetentionSnapshot::load. Change kind: missing verification; no production behavior change.

A live child snapshot makes collection's exclusive acquisition return exactly EWOULDBLOCK. After SIGKILL and reap, the same collector descriptor acquires the lock, and the persistent pathname retains its device/inode and zero length. In the opposite schedule, collection owns writer authority and the exclusive fence first; Linux's kernel lock queue must show the child's pending shared flock before the parent releases collection and observes successful snapshot admission.

Validation and oracle

The oracle is KEEP-RETENTION-008 and the documented cooperating collector protocol. Readiness comes from Unix-domain channels; blocking is witnessed by the kernel, not by a delay without output. No sleeps establish ordering, and process spawning remains outside src. Watchdogs only fail stuck tests.

In a separate copied build, replacing shared acquisition with unlock makes both laws RED at their runtime checks: live collection incorrectly succeeds, and a new snapshot escapes the collector fence. Unmodified production passes in debug and release. All-feature warnings-denied Clippy passes. Full workspace debug/release tests and doctests, formatting, source structure, both Clippy feature profiles and Markdown lint pass at 8e436b2db7e8afe2a1942df19bd4c7473e414eaf. Two concurrent copies of the new test target also pass. All four required hosted checks are green on this exact head (run 37058881633). Automated reviewers reported usage limits, not approval. Evidence and replay include scope, failure output, environment limitations and deletion criteria.

Current landing evidence

Integrated candidate ee21b01d7b7740eaa56116809630534ea7caa05b passes the full fresh copied-Docker validation chain and all four hosted jobs. Both process laws also pass alone, serially, in reversed standalone order and in simultaneous isolated binary runs. The independent review found no product defect and one finite calibration-evidence gap for post-death acquisition, persistent-fence preservation and post-release admission.

One isolated batch demonstrates all three intended runtime failures, followed by restored debug/release GREEN. The existing evidence document now links replay patches and normalized raw receipts, explicitly distinguishing the retained-lock OS-boundary negative control from two production-output mutations. Final successor c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3 changes eight documentation/receipt files only; product code and test expectations remain unchanged. Whitespace, copied-Docker Markdown lint and patch applicability pass. Exact-successor independent APPROVE closes E1. All four jobs in final hosted run 37151013484 pass on this exact head. CodeRabbit remains rate-limited; the authorized independent review supplies the review gate, not its nominal green status.

Scope and compatibility

No public API, format, identity, dependency, durability or recovery changes; no benchmark impact. The tests use repository-only initialization/migration admission and do not prove platform eligibility. They exercise actual kernel process death and filesystem lock identity, not physical power loss, arbitrary interleavings or a complete GC implementation. The collector follows the existing protocol with writer authority and the exclusive kernel lock.

Existing snapshot, corruption and substitution tests remain. A sleep-based negative assertion and source-string inspection were rejected because neither proves runtime exclusion. Child cleanup kills/reaps on failure, and each law owns its storage and channel. Linux /proc/locks visibility and the repository-tasks feature are explicit execution requirements; other platforms supply no evidence from this target.

Original branch base is main 6051abb25a9fd33ae7ee0de5614514b709a4d82a, including prerequisite #99. Normal merge ee21b01d7b7740eaa56116809630534ea7caa05b integrates current main d08fafb2280a480a3c7d9460d13d53bbed4ae46b; the only conflict was CHANGELOG, with all entries retained. Original roadmap checkboxes remain unchanged; mainline integration remains a separate completion requirement.

Closes #113. Refs #131, #132.

Security implications: production admission, identity, lock and corruption checks are unchanged. The evidence targets cooperating reader/collector behavior and grants no guarantee against arbitrary out-of-band namespace mutation.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 41 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 4b0b431f-e885-4679-9544-b050ac8054d2
📥 Commits

Reviewing files that changed from the base of the PR and between d08fafb and c51e231.

📒 Files selected for processing (13)
  • CHANGELOG.md
  • docs/formats/segment-store-v2/requirements.md
  • docs/testing-evidence/reader-fence-process.md
  • docs/testing-evidence/reader-fence-process/persistent-fence-red.txt
  • docs/testing-evidence/reader-fence-process/persistent-fence.patch
  • docs/testing-evidence/reader-fence-process/post-release-admission-red.txt
  • docs/testing-evidence/reader-fence-process/post-release-admission.patch
  • docs/testing-evidence/reader-fence-process/restored-green.txt
  • docs/testing-evidence/reader-fence-process/retained-authority-red.txt
  • docs/testing-evidence/reader-fence-process/retained-authority.patch
  • tests/reader_fence_process.rs
  • tests/reader_fence_process/fixture.rs
  • tests/reader_fence_process/reader.rs
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Exact-head validation receipt: 8e436b2db7e8afe2a1942df19bd4c7473e414eaf, based directly on main 6051abb25a9fd33ae7ee0de5614514b709a4d82a. Local/pushed heads match and the worktree is clean.

Copied-source Docker with pinned Rust 1.96.0, Linux aarch64, owned scratch and real kernel flocks passes:

  • New process laws in debug and release; two simultaneous copies also pass with separate process-owned stores/channels.
  • Full workspace all-feature debug/release tests and doctests.
  • Formatting, source structure, all-feature/minimal-feature warnings-denied Clippy, and Markdown lint.

The separate mutation replacing shared acquisition with unlock fails both runtime laws at the intended checks: Ok(()) instead of exact EWOULDBLOCK, and snapshot escaped the exclusive collector fence. No mutation is present in this head. Existing product behavior was correct; this is missing runtime verification, not a claimed bug fix with fabricated parent RED.

Raw author receipts are retained under the issue-113 scratch directory, including the initial Clippy feedback and copied-checkout Git ownership setup failure. Those setup failures are not calibration evidence. The corrected full validation completed successfully without altering product code or weakening checks.

Hosted CI: documentation and dependency jobs are green; Rust and fuzz jobs are still running at this receipt. CodeRabbit and hosted Codex report usage limits; neither provided independent approval. This comment does not claim merge readiness or mainline integration.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Bounded Code Lawyer calibration finding

Candidate ee21b01d7b7740eaa56116809630534ea7caa05b. Full local validation and all four hosted checks pass; no production defect has been found. The independent reviewer and author identified one finite evidence obligation under Testing Standards rule 4.

Severity File / assertion Verified gap Closure check
P3 verification evidence tests/reader_fence_process.rs:43,45-49,75-76 The retained shared-lock-removal mutation fails at live-reader exclusion and premature admission, before reaching post-death exclusive acquisition, persistent-fence preservation or post-release admission. Those distinct runtime observations currently lack targeted falsification receipts. Run one isolated batch: retain an additional real shared lock as an explicitly labeled OS-boundary negative control, change actual persistent fence length after production admission checks, and force a typed production admission failure after the real shared-lock wait. Preserve expectations, demonstrate each intended RED, restore GREEN, and consolidate receipts.

The SIGKILL status and channel protocol markers attest the injected schedule; they are not separate product promises requiring artificial expectation mutations. The extra shared-lock control calibrates detection at the real filesystem boundary and is not presented as an existing Keep defect or a production subprocess path. No new product behavior, expanded scheduler, broad hardening pass or mutation score is requested.

@codex — second opinion welcome; the finite experiments follow from the observed evidence gap.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent review: Keep PR #160

Reviewed head: ee21b01d7b7740eaa56116809630534ea7caa05b. Tracked tree: b2a9420cf78b4196c75747d5db16d099dfb18937. Branch: test/113-reader-fence-process-death. Target: main d08fafb2280a480a3c7d9460d13d53bbed4ae46b. Original change: 8e436b2db7e8afe2a1942df19bd4c7473e414eaf on 6051abb25a9fd33ae7ee0de5614514b709a4d82a.

This is the explicitly authorized independent Codex fallback using the agy-review protocol. It is a read-only review, with no host Rust execution, source modifications, commits, publication, configuration changes, or delegation. The only written artifact is this report. The checkout was clean and the reviewed head/tree were reconfirmed at completion. Review approval would not authorize merging.

Findings

No demonstrated product defect was found in the six-file PR delta or its integration with the current target. The production reader implementation is unchanged relative to target main. There is one binding evidence-admission gap below. It concerns demonstrated falsification, not an allegation that the unchanged product mishandles reader death.

E1 — P2: Complete calibration of the distinct release and preservation outcomes

Locations: docs/testing-evidence/reader-fence-process.md:17; tests/reader_fence_process.rs:43, tests/reader_fence_process.rs:45, tests/reader_fence_process.rs:75. Binding requirement: docs/Testing Standards.md:48 requires every new load-bearing assertion to execute and fail under a witnessed regression or a targeted outcome violation.

The retained no-shared-lock-red.log:40–66 is genuine runtime RED. It falsifies live-reader exclusion at tests/reader_fence_process.rs:37 and early snapshot exclusion at tests/reader_fence_process/reader.rs:106. Both failures happen before the new laws reach their remaining distinct outcomes: exclusive acquisition after SIGKILL/reap, preservation of the original empty persistent fence, and successful public snapshot admission after a real queued lock wait is released. GREEN executions establish that these observations occur in the passing implementation, but do not satisfy the explicit falsification requirement for them. The existing retention-reader-fence-coverage.md calibration covers acquisition-time replacement and live contention, and explicitly excludes process death; it does not close this gap.

Concrete consequence: removing or accidentally bypassing a newly introduced release/preservation observation has no recorded negative control demonstrating that the remaining test fails for that violation. This is a missing evidence requirement, not a verified assertion bypass in the candidate.

Suggested finite fix: one bounded batch of isolated calibration experiments covering the three distinct outcomes, followed by restored GREEN, with source/tree, command, separate build directory, named failure and limitations recorded. An extra controlled shared holder can keep the real filesystem fence unavailable after the reader dies; this is OS-boundary oracle calibration, not a production bug claim. A copied production acquisition mutation that preserves its flock but corrupts the persistent file after the last guard can reach the preservation observation. A copied production snapshot refusal after shared acquisition can preserve the kernel-queued schedule and falsify post-release admission. Demonstrate that each intended check is reached, rather than counting earlier setup or exclusion failures. Equivalent alternatives are acceptable. No separate mutations are requested for PID, protocol bytes, generation fixture, signal number, watchdog branches, or individual device/inode/length coordinates. In particular, SIGKILL status is attestation that the injected fault occurred, not a separate Keep behavior needing an invented production subprocess path.

No automatic-discard change, additional GC implementation, unrelated hardening, field-by-field mutation campaign, or alteration to production behavior is requested.

Verification Checklist

Scope, review surfaces, and standards

  • Entire target-relative diff reviewed: CHANGELOG.md, version-two requirements, the new evidence document, the integration target, fixture and reader harness; 340 additions and one removal across six files. No src, dependency, lockfile, public format or production API delta relative to target main.
  • Applicable AGENTS.md, binding docs/Testing Standards.md and docs/testing/enforcement.md read. Medium-size declarations, named KEEP-RETENTION-008 oracles, observable outcomes, deletion criteria and missing-verification change kind are present. Neither test is presented as a reproduced production bug requiring fabricated parent runtime RED.
  • PR body and all retained review surfaces read. 160-queue.json contains three top-level comments, zero reviews and zero threads; pagination was exhausted by the parent's supplied queue collector. Hosted Codex and CodeRabbit usage-limit comments provide no approval. The validation comment is explicitly pinned to the original head. The body identifies that original SHA for its full validation; those historical receipts are not current-head CI evidence.
  • New Markdown prose uses one physical line per paragraph. Numeric and environment claims are bounded to Linux, the repository feature, owned scratch, actual process death and cooperating locks. No platform certification, arbitrary-interleaving, complete GC or physical-power-loss claim is made.
  • Existing ordinary-test sandbox/memory/suite-budget gaps are explicitly disclosed at evidence document line 21 and in the enforcement profile. This review does not certify resource-policy compliance or silently treat that gap ledger as an approved waiver. The tests add no claim of implementing those controls.

Runtime paths and state/error transitions

Behavior Traced path and observation Assessment
Fresh fixture and persistent fence fixture.rs:10–37 → RepositoryInitializationStorage::admit_unchecked at src/adapters/repository_initialization_storage.rs:26–28 → production initialization; writer lock passed into migration at fixture.rs:30–35 → filesystem_migration_repository_tasks.rs:35–51 → production migration. Fence creation/admission is in filesystem_migration_reader_fence.rs:12–36. Real production protocols with an explicit repository-only platform bypass. Private immutable vectors are written into a fresh owned store; migrated root identity is bound to that store. Catalog generation one is fixture-derived. No platform-admission parity claim.
Public reader acquisition reader.rs:26–40 → FilesystemRetentionSnapshot::load at filesystem_retention_snapshot.rs:122–161 → namespace/record/root-identity admission at 127–136 → ReaderFence::acquire at 137 → reader_fence.rs:35–50. Shared flock on an opened no-follow regular empty file; entry/handle identity verified before and after lock. Readiness is sent only after successful admission and the snapshot remains live while waiting for release.
Stable public view filesystem_retention_snapshot.rs:66–103 → retention_view_collector.rs:99–117 → retained fenced result at snapshot lines 156–160. Both catalog and retention head coordinates are read around view loading; mismatch retries, absence/refusal/exhaustion refuses. Selected roots remain independently checked at snapshot lines 194–249. The new child only requires the migrated catalog, and does not pretend to add root-corruption or concurrent-publication evidence.
Writer authority and live-reader exclusion reader_fence_process.rs:34–41 → FilesystemWriterLock::try_acquire at filesystem_writer_lock.rs:72–83, root and writer-file authority at 96–115/123–150 → actual exclusive nonblocking flock on reader.lock. Exact Errno::WOULDBLOCK, rather than generic failure. Writer authority precedes collector action and remains held through collection. The tests follow the documented collector protocol at reader_fence.rs:19–23; no complete production collector currently claimed.
Actual reader death, release and persistence reader_fence_process.rs:42–49 → reader.rs:119–127: kill, wait, verify signal nine; same collector descriptor reacquires; pathname metadata checked against original device/inode and zero length. Correct runtime observations. SIGKILL bypasses Rust destructors; no descriptor is transferred to the parent. Product ReaderFence owns a file, with no unlinking destructor. GREEN inspected; distinct falsification missing under E1.
Collector excludes a new public snapshot reader_fence_process.rs:64–76 → exclusive fence before child spawn → reader.rs:92–116 → queued_reader at 180–189 → release → admitted snapshot and successful child completion at 85–89/130–145. Positive kernel scheduling witness must identify pending FLOCK/ADVISORY/READ for the owned child PID and inode; early readiness fails. In this child production path there is only the one shared fence acquisition, so the inode-suffix match is not an observed ambiguous-witness defect. Readable PID-namespace /proc/locks is explicit. Post-release outcome calibration missing under E1.
Child protocol and cleanup reader.rs:55–82, 85–116, 119–155, 157–177; sandbox at tests/segment_filesystem_stage/sandbox.rs:19–32/49–58. Per-process, per-law paths and socket names isolate parallel executions. Startup/accept/channel errors propagate. Reader is constructed before timeout setup so errors invoke kill/reap cleanup. Polling yields; no sleeps establish correctness. Early EOF, child failure, wrong protocol or timeout refuses. Explicit normal shutdown and kill/reap occur before store removal. Best-effort Drop cleanup does not imply durability.
Typed production errors filesystem_retention_snapshot_error.rs:13–38/53–61; snapshot load mappings at 127–155; reader_fence.rs:54–69; view collector at 103–117. Boundary categories and sources preserved; no new swallowed production error or nested wrapping introduced by this PR. Harness failures are test failures, not public refusal APIs. Child death before readiness, unusable kernel visibility and stuck execution fail instead of counting as passing exclusion.

The parallel preexisting same-process law at filesystem_retention_snapshot_tests.rs:113–130 still acquires two shared fences, checks exact contention and positively checks release. Acquisition substitution and nonempty-file tests remain. They implement the same shared-lock contract; none is relabeled as process-death or new-reader schedule evidence.

Merge audit

Constants, numeric claims, raw evidence and calibration

Constant or claim Check and evidence Limit
Two laws Both named tests in the 79-line integration target; historical focused.log:40–46 and concurrent-replay.log:1–13; fresh debug 160-validation.log:761–767, release 2787–2793. Count identifies executed laws, not proof of correctness.
Twenty-second watchdog reader.rs:20, socket timeouts 29/80–81, readiness/finish ceilings 141–175; evidence document line 13 agrees. Fresh focused target took 0.07 seconds debug and 0.03 seconds release; historical focused/concurrent receipts report 0.04/0.05 seconds. No measured per-test/suite latency distribution or approved SLO is supplied. This is a conservative fail-only harness ceiling, not a passing exclusion oracle or resource-compliance claim.
1,048,576 catalog-read byte bound reader.rs:30–33; immutable catalog fixture decodes far below that bound. Existing typed CatalogRestartByteLimit admission remains in use. Policy ceiling, not a performance measurement; no change to production default policy.
Catalog generation one, zero-length fence, SIGKILL nine Golden catalog and child assertion at reader.rs:35–38; migration fence verify at 25–29; signal attestation at 122–125; persistence comparison at integration lines 45–49. Independent fixture/protocol values. Signal and message assertions attest experiment execution; E1 concerns distinct product/OS outcome observations.
Reader default three attempts reader_attempt_limit.rs:11–13, view collector lines 104–116. Existing refusal bound; new schedule has no moving heads or claim of arbitrary retry/interleaving coverage.
Shared-acquire-to-unlock mutation Inspected retained Docker sources /audit/keep113-source and /audit/keep113-no-shared-lock. Production diff is reader_fence.rs:48 LockShared → Unlock. no-shared-lock-red.log:49 gives early-ready failure and 53–56 gives actual success versus exact expected contention. Dedicated build directory /build/keep113-no-shared-lock appears at log 40. Mutant harness also predates module-visibility and Reader-construction cleanup refinements. These do not alter the two executed assertions or outcome paths; receipt is historical calibration, not claimed byte-identical exact-head source. No mutation present at current head. E1 identifies the uncalibrated outcome remainder.
Existing identity/calibration receipts retention-reader-fence-coverage.md supplies acquisition-time replacement, exact refusal and contention calibration, explicitly excluding process-death and post-final-verification interference. Not substituted for new lifetime/persistence/post-release assertion calibration.
Imported 343 histories Seven operations at model lines 54–62, three nested schedule coordinates and seven entry laws; 7³ = 343. CHANGELOG and requirements/evidence agree; precondition no-ops are explicitly disclosed. Exploration bound, not all sequences or a correctness metric. Historical #99's smaller alphabet remains historical.
Imported observer offsets/format counts Crash observer constants 64/32/209/136/337/273 remain unchanged across the observer conversion; delegation preserves underlying write lengths and before/after events. Partial-seal framing uses format constants with independent fuzz expected fixed bytes and 128-byte seal length. No altered benchmark, buffer, rate or durability threshold introduced by #113. Existing raw mainline calibration receipts retain their pinned coordinates.
No production behavior/format/API change Exact second-parent diff changes only tests and prose; no production path is modified. This is directly established by tree comparison, not an empirical universal-equivalence claim. Incoming target corrections retain their own scopes.

Executed, inspected, skipped and unavailable

  • Executed by this reviewer: read-only Git head/tree/status/diffs/history checks, source/document inspection, read-only Docker retained-source comparisons, raw-log inspection, and live GitHub PR-body/head/base retrieval. No Rust tests or mutations were run by this reviewer.
  • Inspected current candidate execution: 160-validate.sh, 160-validation-manifest.md, and full-chain trace 160-validation.log, beginning with exact tracked tree b2a9420..., Rust 1.96.0, Linux aarch64 and actual ext4 /dev/loop0 plus tmpfs negative fixture. The parent supplied terminal session 69810 exit zero; log independently shows final fuzz Clippy completion. This receipt covers golden/conformance/structure checks, debug and optimized process-death campaigns, full debug/release tests, both feature configurations for checks/Clippy, formatting, docs/doctests/MSRV, and fuzz target compilation/Clippy.
  • Inspected historical evidence: focused/runtime mutation/concurrent replay logs, corrected full validation log, Clippy diagnostics and correction, Markdown log, and original validation comment. Setup/ownership/Clippy failures were not counted as assertion calibration. Historical passes do not replace current-head checks.
  • Inspected current-head isolation evidence: 160-isolation.sh and 160-isolation.log record the same exact tracked tree, each law alone, the serial pair, reversed standalone order and two simultaneous binary invocations with owned PID-scoped stores/channels. All pass without retries. This provides bounded isolation/reordering evidence, not arbitrary schedule exploration.
  • Independently retrieved completed hosted run 37150385511: head ee21b01d7b7740eaa56116809630534ea7caa05b, conclusion success; Documentation and workflow integrity, Rust quality gates, Runtime fuzz smoke and Dependency policy each completed successfully. Runtime fuzzing, dependency audit/policy and hosted documentation/workflow checks are separate from the local compiler-only fuzz evidence. Branch-protection and final merge admission remain the parent's separate responsibility.
  • Not exercised or claimed: physical power loss, arbitrary interleavings, full GC execution, unsupported platforms, malicious noncooperating namespace writers, exhaustive resource sandbox compliance, or new benchmark improvements. Those are disclosed limits, not additional requested scope.

The finite blocker is E1. Supply its bounded outcome-calibration receipts and obtain a fresh exact-head review; final merge admission remains separate.

Reviewed SHA: ee21b01d7b7740eaa56116809630534ea7caa05b.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent bounded delta review: Keep PR #160

Reviewed head: c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3. Tracked tree: 5a568255e985da8ae43629fd8c7888b02c1312dc. Parent: previously reviewed ee21b01d7b7740eaa56116809630534ea7caa05b, tree b2a9420cf78b4196c75747d5db16d099dfb18937. Target remains main d08fafb2280a480a3c7d9460d13d53bbed4ae46b.

This is the expressly requested read-only Codex fallback under the agy-review protocol. It reviews only the evidence successor and closure of E1. No host Rust tests, new experiments, source modifications, publishing, configuration changes or delegation were performed. Only this report was written.

Findings and E1 disposition

No actionable findings remain. E1 is closed by a finite batch covering the three distinct outcomes named in the original independent review. The added documentation accurately distinguishes actual outcome falsification, OS-boundary negative controls, fault attestation and unchanged production behavior. It preserves the partially interleaved child error instead of inventing a reconstructed diagnostic.

Verification Checklist

Adoption of the full review

  • Clean checkout and exact head/tree verified before and after inspection. The successor is one ordinary commit with parent ee21b01...; there is no new merge requiring another integration audit.
  • Entire successor diff inspected: eight evidence files, 217 added lines. These are 14 lines in docs/testing-evidence/reader-fence-process.md, three zero-context mutation patches, three RED receipts and one restored GREEN receipt.
  • Empty production/test semantic delta independently established with git diff --exit-code ee21b01... HEAD -- src tests Cargo.toml Cargo.lock AGENTS.md xtask fuzz rust-toolchain.toml. No runtime code, expected values, test names, policy constants, dependencies or feature gates changed.
  • The original full Verification Checklist is explicitly adopted for this exact successor because those code paths and integration invariants are unchanged. This includes initialization/migration fixture admission; public FilesystemRetentionSnapshot::load → ReaderFence::acquire → shared kernel flock; double collection and typed failures; writer/collector authority; SIGKILL/reap and persistent fence observations; kernel-queued reader exclusion and post-release admission; channel/error/cleanup paths; same-process parallel law parity; merge ee21b01... against both parents; incoming Fix: refuse corrupt partial segment seals during recovery (#171) #172/Fix: keep sealed stage authority private during crash observation (#146) #158/Fix: preserve platform admission for catalog publisher authority (#150) #157/Test: verify public admitted filesystem stages (#147) #156/Test: verify retention release and restore against independent model (#128) #159 integration; and binding Retention recovery, crash-matrix evidence, reader fence, and model-based transitions (item 6) #99 incomplete-stage preservation, cooperating concurrency and failure-reporting contracts.
  • The adopted full review's constants and numeric/documentation checks remain applicable: two laws, 20-second fail-only watchdog, 1,048,576-byte catalog limit, fixture generation one, empty persistent fence, signal nine, default three reader attempts and imported 343-history model exploration. Its executed/inspected/skipped distinctions and limits remain unchanged.
  • Existing full-tree local validation, isolation/reordering evidence and completed original-head hosted run remain pinned historical execution evidence. A documentation successor does not convert that older hosted run into exact-current-head CI. Final current-head hosted and branch-protection admission are the parent's separate gate, not a condition this report claims already completed.

New calibration: actual checks reached

E1 outcome Patch and unchanged path Observed RED and why it reaches the intended check
Exclusive acquisition after reader death retained-authority.patch:4–6 inserts a separate actual shared holder after the original live-reader refusal and before reader.kill(). Expected values and the subsequent exclusive probe remain unchanged. Original path: tests/reader_fence_process.rs:37–43 → reader.rs:119–127 kill/wait/signal attestation → same descriptor's nonblocking exclusive acquisition. retained-authority-red.txt:43–51 records errno 11/WouldBlock and one executed failed law. The inserted shared operation blocks rather than returning nonblocking contention; the original first assertion accepts contention; kill/wait use SIGKILL. The remaining real holder therefore makes the unchanged post-kill exclusive probe fail. This is valid filesystem/OS oracle calibration, explicitly not a Keep production defect.
Original empty persistent fence survives persistent-fence.patch:4–5 writes actual file length one after ReaderFence::acquire_with's final verification at src/adapters/retention/reader_fence.rs:49, preserving the real shared flock. persistent-fence-red.txt:44–47 pins failure to unchanged tests/reader_fence_process.rs:45: observed (1792, 130331, 1) versus expected (1792, 130331, 0). Source order establishes that live contention, SIGKILL/reap and post-death exclusive acquisition all succeeded before this assertion. It calibrates the combined persisted-state observation, without claiming separate coordinate mutations.
Public snapshot admitted after queued wait and collector release post-release-admission.patch:4–7 inserts a typed Error::Fence refusal after ReaderFence::acquire at filesystem_retention_snapshot.rs:137. The actual blocking shared acquisition and parent checker are preserved. Parent path remains tests/reader_fence_process.rs:72–75: kernel-wait witness → drop collector/writer → await_snapshot; child path is reader.rs:34–40. post-release-admission-red.txt:43–51 preserves a partial child Fence diagnostic interleaved with parent's UnexpectedEof, and the named law fails after actual execution. Crucially, EOF observed while seeking the queue would produce the harness's separate reader failed before its kernel lock wait error at reader.rs:108–111; it cannot produce the raw read_exact UnexpectedEof shown here. The observed error therefore reaches unchanged post-release await_snapshot at lines 85–89 after successful await_kernel_wait. No setup failure, timer-only result or fabricated complete child error is counted.

All three named experiments compiled, ran one selected law and exited 101. The traced launcher records each result and dedicated source/target directories. The source variants contain only the documented additions; no checker or expected-value edit is hidden in these receipts. Original missing-shared-lock RED continues to supply the two exclusion calibrations from the adopted review. Together, these close the complete finite E1 gap. Signal status, channel markers and fixture generation remain experiment attestations, not targets for a separate field-by-field mutation campaign.

Evidence provenance and byte fidelity

  • Read 160-prepare-calibration.rb, 160-run-calibration.sh, 160-record-calibration.rb, the complete 160-calibration/execution.log, all three raw RED logs, all three full source variants, their destination-path files and the raw restored GREEN log.
  • Independently reconstructed each complete variant from the exact ee21b01... Git blob plus the committed zero-context patch. Byte comparison matches each retained full .rs variant exactly. git apply --check --unidiff-zero succeeds for all three patches without modifying the checkout.
  • Independently compared SHA-256 of the retained host variants with the corresponding actual Docker experiment source files. Matches: retained authority 604378f55132de78b66cc7e6df68ced30613aeb1b3fe3e93b81040e1a138d3ed; persistent fence 7ac20abb22a0e067410448aabbeb2aa7825bdf5b2161a69a94440b62ce0401f1; post-release admission 429d53b81a703ac5bf5eebcf2e663e133ff998068dd2ee5358514d93308f76b7.
  • Independently normalized each raw log by replacing only its named container source/build path prefixes and trimming the trailing whitespace/empty tail as the recording script does. Every committed RED receipt is byte-equal to that result. The restored GREEN receipt is likewise byte-equal to its raw log with the single target-prefix replacement. In particular the interleaved errorError fragment is faithfully retained.
  • Read the restored GREEN receipt: exact unmodified tracked tree b2a9420... at restored-green.txt:1–2; both unchanged laws pass debug at 3–11 and release at 13–21. The restoration uses the separate unmodified source/output pair, rather than a mutated source with potentially stale artifacts. Parent reports the restoration command exited zero; the inspected raw log shows both successful runs.
  • Independently queried the retained Docker environment: unmodified source tree b2a9420..., Rust 1.96.0, aarch64 and actual ext4 /dev/loop0. Experiment launcher explicitly copies the archived source, installs one variant per copy, uses a distinct target directory and binds ext4 scratch into both Cargo scratch routes.

New prose, numbers and bounds

  • reader-fence-process.md:27 accurately names three experiments, immutable source/tree, toolchain, platform and ext4 profile. Exit 101 is shown three times in the traced launcher; it is not a correctness score.
  • Lines 29/31/33 describe exactly the added mutations and observed distinct failures. Length one versus zero is raw data from the preserved assertion diagnostic; the unchanged device/inode pair is visible rather than inferred from a count. The third diagnostic is explicitly incomplete/interleaved and the schedule conclusion is justified by source ordering.
  • Line 35 supplies the exact first-law replay command, the second-law substitution and zero-context application requirement. Independent git apply --check validates that mechanism. Debug/release GREEN evidence is linked and correctly pinned to the unmodified source, not to a synthetic commit identity.
  • Line 37 accurately limits committed log normalization and retains scope: two fixed schedules, existing platforms/resource gaps, no power-loss evidence. No new durability, GC, benchmark or platform-eligibility promise is introduced.
  • Paragraphs use one physical line; link targets exist; git diff --check passes. The parent supplied passing copied-container Markdown lint. No runtime tests are needed for this prose-only delivery; the substantive evidence is the inspected prior experiments.

Execution and remaining limits

Executed by this reviewer: read-only Git status/tree/diff/history checks; independent byte-normalization and patch-reconstruction comparisons; nonmutating patch application checks; read-only Docker source hashes and environment inspection. Inspected only: author's experiment execution and restored GREEN logs, scripts, and the full prior verification record. No Rust or calibration was rerun by this reviewer.

The parent reported calibration session 11621 terminal exit zero; its trace shows each expected failing Cargo run exits 101. The report accepts the actual named runtime failures, not exit-code checking alone. No measurement or diagnostic was invented. Physical power loss, arbitrary interleavings, a complete GC, hostile raw writers and full resource-sandbox compliance remain outside the claims, exactly as in the original checklist.

E1 is closed durably in the reviewed tree. No new or unresolved verified issue remains within the authorized delta. This is exact-head independent review approval; merging still requires the separately handled current-head hosted/protection and authorization gates.

Reviewed SHA: c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3.

APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer activity summary

Final candidate c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3, tracked tree 5a568255e985da8ae43629fd8c7888b02c1312dc, targets main d08fafb2280a480a3c7d9460d13d53bbed4ae46b. Missing runtime verification is the change kind; production behavior is unchanged.

Item Source / severity Commit and files Validation and disposition
Reader-death and collector-exclusion contracts #113 Process laws and existing evidence document; integrated ee21b01 Actual public snapshots, writer authority and kernel locks establish the two fixed schedules. Full fresh copied-Docker validation passes in both profiles, including process-death campaigns, feature/Clippy profiles, docs and fuzz compilation. Each law alone, reversed standalone order, serial pair and simultaneous isolated binaries pass without retries.
E1 outcome calibration Independent review P2 evidence gap; parent initially classified P3 c51e231, existing evidence document and seven replay/receipt artifacts One bounded batch calibrates post-death exclusive acquisition using retained real shared authority, persistent fence preservation using a production file-length mutation, and post-release admission using a production typed refusal after the real lock wait. Each compiles and fails at the intended runtime observation with exit 101. Restored unmodified laws pass debug/release. No product bug is claimed.
Merge integration Code Lawyer ee21b01 normal merge of main Only changelog conflict; all incoming and original entries preserved. The process tests are unchanged from their original branch head. #99 retention scope/effect contracts and incoming production fixes remain intact.
Documentation and receipt admission Code Lawyer c51e231 documentation-only successor Whitespace, copied-Docker Markdown lint and independent zero-context patch applicability pass. Normalized raw logs retain original errors, including interleaved stderr. No runtime/test expectation/configuration change after the full local validation.

The tests use repository-only initialization/migration admission, not platform certification. Kernel process death is not physical power loss; fixed schedules are not arbitrary interleaving exploration. Resource-sandbox gaps remain explicitly disclosed. Signal and protocol markers attest the experiment and are not used to manufacture unrelated calibration requirements. No API/format/security/durability behavior or performance claim changes.

The original full review is published here; the bounded E1 finding is published here. Exact-successor approval, final-head hosted checks and the final feedback/protection recheck remain separate merge gates.

Exact-successor independent APPROVE closes E1 at c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3, adopting the full path/merge/evidence checklist through the verified evidence-only delta. Final hosted run 37151013484 completes successfully on that exact head: Rust quality gates, runtime fuzz smoke, documentation/workflow integrity and dependency policy all pass.

Final feedback pagination is exhausted: seven global comments, zero reviews and zero threads. Historical validation remains historical, duplicate quota notices provide no approval, E1 is closed, and no actionable finding remains. CodeRabbit is rate-limited; the maintainer-authorized independent Codex review satisfies the review fallback, without treating its status as CodeRabbit approval. Mainline rules retain signature, deletion and non-fast-forward protections; no bypass is requested. Normal merge follows the immediate head/base recheck under existing maintainer authorization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prove reader-fence process death and collector exclusion in external harness

1 participant