Skip to content

Test: verify migration compatibility and fuzz recovery transitions (#112) - #162

Merged
flyingrobots merged 3 commits into
mainfrom
test/112-migration-compatibility-fuzz
Oct 3, 2026
Merged

flyingrobots merged 3 commits into
mainfrom
test/112-migration-compatibility-fuzz

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Missing evidence and outcome

The migration compatibility ledger lacked a runtime v1-authority refusal witness at every forward prefix, comprehensive migration-record version/flag cases, and recovery-planner fuzz inputs. This PR adds those checks while preserving production behavior.

A fresh filesystem store executes each migration prefix. The untouched store reopens as v1; every nonempty prefix refuses v1 authority at the existing Namespace/InvalidData boundary, and original HEAD/catalog/segment names and bytes remain unchanged. Public record decoders refuse unsupported versions and every single mandatory flag bit with exact coordinates. The existing migration_format fuzz target now explores bounded recovery residue with valid and contradictory seeds and specified admission properties.

Change kind: missing verification and stronger fuzz exploration. Current candidate normally integrates main 80d23f51897085bac34bb5c4db067d0627748e13, including the reviewed #161 completion fix and #175 continuous reader-fixture authority. CHANGELOG preserves both parents; the corpus-test conflict preserves mainline #172’s stronger emitted-counterexample runtime witness. No product code behavior, format, API, dependency, recovery-policy or benchmark changes.

Evidence

Focused filesystem and public-decoder laws pass in debug/release. Separately copied mutations go RED: accepting migrating namespaces as v1; damaging HEAD after the final migration phase; bypassing marker version/flag checks; forcing v1 planner success with a retained intent stage. These calibrate missing evidence, not a claimed production bug on main. An initial endian mistake in the test patch and lint corrections are retained as authoring failures, not product RED.

A fixed starting corpus is archived before a successful 20,000-execution libFuzzer run using seed 112, 4,096-byte input cap, five-second per-input timeout and 1,024 MiB RSS limit. The pinned nightly/cargo-fuzz binary exports AddressSanitizer initialization and the release mutation proves active assertions. Recipes for valid and malformed record/transition seeds are checked in and picked up by existing smoke/scheduled workflows. No real product crash was found in this bounded run.

Full required copied-Docker validation passes at integrated source 6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37, tree 437bc1971fc8a98f2d039e446b3f5008979974f9, and all four hosted jobs pass in run 37155153324. Fresh independent review found one finite calibration gap: earlier Marker/VersionOne controls did not reach later distinct assertions. Evidence-only successor 1c886fdb3ab17c62d0b935f22dd3d7818709245c records six intended runtime controls for Intent/Receipt headers and precise pre-intent/Complete properties, followed by unchanged decoder debug/release GREEN and a new archived-corpus 20,000-run fuzz GREEN. No production defect is inferred. All four final-successor hosted jobs pass in run 37155679287. Independent exact-head APPROVE verifies the six controls, raw receipts and unchanged runtime scope, closing the sole P2 finding. Evidence maps contracts, replay, calibration, resource limits and exclusions. KEEP-MIGRATION-008 and fuzz documentation now cite the expanded evidence.

Scope and limitations

Recovery fuzzing invokes public parser/planner runtime. Complete-success checks reuse product decoders and prove planner/admission agreement; other result classes receive robustness exploration rather than a full independent reference model. The fuzz-only envelope is bounded and is not an on-disk format. Filesystem fixtures bypass platform eligibility checks to isolate migration compatibility; this is not new platform, physical power-loss or arbitrary-concurrency evidence. Existing crash and recovery owners remain.

The materialization tool test no longer freezes incidental global/per-target seed counts. After integration it retains mainline’s exact typed refusal from the real recovery classifier over an emitted counterexample, plus deterministic repeated materialization; the weaker nonempty-output assertion is subsumed. Product confidence comes from the runtime laws and fuzz oracles. No count was merely increased to accommodate more cases.

Original roadmap checkboxes are unchanged. Merge remains necessary before claiming mainline delivery.

Closes #112. Refs #131, #132.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 01ee4023-f392-489c-862d-301a1a2893fa
📥 Commits

Reviewing files that changed from the base of the PR and between 80d23f5 and 1c886fd.

📒 Files selected for processing (26)
  • CHANGELOG.md
  • docs/formats/segment-store-v2/requirements.md
  • docs/testing-evidence/migration-compatibility-fuzz.md
  • docs/testing-evidence/migration-compatibility-fuzz/intent-red.txt
  • docs/testing-evidence/migration-compatibility-fuzz/intent.patch
  • docs/testing-evidence/migration-compatibility-fuzz/namespace-red.txt
  • docs/testing-evidence/migration-compatibility-fuzz/namespace.patch
  • docs/testing-evidence/migration-compatibility-fuzz/pre-intent-red.txt
  • docs/testing-evidence/migration-compatibility-fuzz/pre-intent.patch
  • docs/testing-evidence/migration-compatibility-fuzz/receipt-red.txt
  • docs/testing-evidence/migration-compatibility-fuzz/receipt.patch
  • docs/testing-evidence/migration-compatibility-fuzz/records-red.txt
  • docs/testing-evidence/migration-compatibility-fuzz/records.patch
  • docs/testing-evidence/migration-compatibility-fuzz/restored-fuzz-green.txt
  • docs/testing-evidence/migration-compatibility-fuzz/restored-headers-green.txt
  • docs/testing-evidence/migration-compatibility-fuzz/stage-red.txt
  • docs/testing-evidence/migration-compatibility-fuzz/stage.patch
  • fuzz/README.md
  • fuzz/fuzz_targets/migration_format.rs
  • fuzz/fuzz_targets/migration_format/recovery.rs
  • src/adapters/store_migration.rs
  • src/adapters/store_migration/filesystem_migration_compatibility_tests.rs
  • tests/store_migration_compatibility.rs
  • xtask/src/fuzz_seed_corpus.rs
  • xtask/src/fuzz_seed_corpus/migration_recovery_seeds.rs
  • xtask/src/fuzz_seed_corpus/migration_seeds.rs
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Exact-head receipt: 85919fb1cab1d5757c49fe7707f470bd581d7568. Local and pushed heads match; worktree clean.

The copied-source validation chain completed with exit 0: workspace/fuzz formatting; source structure; all-feature and minimal-feature workspace warnings-denied Clippy; fuzz-target Clippy; full all-feature workspace tests and doctests in debug and release; cargo xtask durability-crash-matrix; and cargo run --quiet --release --locked --package xtask -- durability-crash-matrix. Markdown lint also passes.

A fresh named starting corpus was archived before the 20,000-execution seed-112 migration fuzz run. That run completed successfully with the documented input/timeout/RSS bounds. Separate candidate-excluded mutations were observed RED for v1 authority admission, byte preservation, precise version/flag diagnostics and the recovery-planner oracle. Initial test-authoring and lint failures remain recorded and are excluded from calibration claims.

Raw author evidence is retained under the issue-112 scratch directory, including full-validation.log, fuzz-initial-corpus.tar, fuzz-fixed-corpus.log and the separate mutation logs. The checked-in evidence record supplies replay, contract mapping and limits.

Hosted documentation and dependency checks are green; Rust quality gates and runtime fuzz smoke remain in progress on this exact SHA. This receipt does not claim independent review approval or mainline integration.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer finding — finite calibration gap

Severity Boundary Verified gap Acceptance
P2 tests/store_migration_compatibility.rs:29-51,70-89; fuzz/fuzz_targets/migration_format/recovery.rs:70-115 Historical header mutation fails at Marker assertions first, so it cannot establish that the later independent Intent/Receipt version/flag assertions fail. Historical planner mutation reaches only the VersionOne property, leaving the distinct precise EffectBeforeIntent and Complete namespace/stage/admitted-record assertions without witnessed RED. This is missing falsification evidence, not a demonstrated production defect. One bounded batch preserving earlier checks to reach Intent and Receipt refusals, plus controls reaching the precise pre-intent and three Complete checks. Record intended assertion failures and restored GREEN; no per-bit, per-coordinate or full-campaign repetition.

The original filesystem authority/byte-preservation and Marker/VersionOne calibration remains valid for its actual scope. @codex No runtime bug is inferred from this evidence gap. The candidate stays unchanged while isolated calibration copies run.

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create an environment for this repo.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent review of PR #162

Candidate: 6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37, tree 437bc1971fc8a98f2d039e446b3f5008979974f9, branch test/112-migration-compatibility-fuzz, against main 80d23f51897085bac34bb5c4db067d0627748e13. Read-only isolated checkout the isolated candidate checkout; no tests, source changes, commits, publishing, or configuration changes performed by this reviewer. Review uses the authorized independent Codex fallback and the agy-review protocol. AGENTS.md, both review skills, Testing Standards and enforcement profile were read.

Findings

No product defect or semantic merge regression was demonstrated. The following is a verified proof gap, not evidence that the existing product decoders or planner are incorrect.

P2 — Complete the missing calibration for distinct new load-bearing assertions. Coordinates: tests/store_migration_compatibility.rs:36, :43, :74, :78; fuzz/fuzz_targets/migration_format/recovery.rs:83, :91, :95, :111; evidence summary docs/testing-evidence/migration-compatibility-fuzz.md:23. Binding Testing Standards Rule 4 requires the named assertion to execute and fail for the intended reason. The header mutation receipt fails at the earlier Marker assertions, tests/store_migration_compatibility.rs:29 and :70, with checksum errors instead of the specified version/flag errors (keep-audit/112/header-mutation-red.log:50-61). It therefore never reaches the Intent or Receipt assertions in either test. These assertions guard separate decoder implementations: migration_intent_decoder.rs:46-69 and migration_receipt_decoder.rs:45-68; the Marker receipt does not establish their falsifiability. The planner mutation receipt fails only at assert_version_one, recovery fuzz line 62 (planner-fuzz-mutation-red.log:39-51), before assert_pre_intent_effects or assert_complete can establish a RED. Consequently the precise EffectBeforeIntent coordinate and Complete namespace, stage-absence and joint-record assertions lack the required recorded calibration. A green bounded campaign does not replace that evidence. Fix with a finite isolated calibration batch preserving earlier assertions: reach Intent then Receipt version/flag failures, and separately violate the precise pre-intent result plus the three Complete properties. Preserve the first actual failure and subsequent unmutated GREEN; record source/build coordinates and replay seeds. No per-bit or per-version mutation campaign is requested, and this finding does not require a production patch.

Verification Checklist

Changed runtime paths and parallel rules

Path Traced implementation and conclusion
v1 compatibility at each completed forward-phase prefix filesystem_migration_compatibility_tests.rs:16-24 creates fresh v1 golden storage through filesystem_migration_test_fixture.rs:20-35, observes and verifies authority, then invokes the real phase executor. migration_resumption.rs:59-93 dispatches all phases to filesystem_migration_storage.rs:19-120. Compared phase order and effect calls with normal forward execution migration_execution.rs:19-32, :35-131 and migration_phase.rs:57-79; both cover intent write/sync/link/root-sync/cleanup, reader fence and namespace, marker, receipt, final root sync. No unjustified order difference found. The test intentionally checks completed prefixes, not interruption inside a phase.
v1 authority reopening New law filesystem_migration_compatibility_tests.rs:27-47 reaches filesystem_store_initializer.rs:70-75, then shared :99-121. Public reopen at :52-55 uses the same writer locking and namespace admission after the production platform probe. filesystem_initialization_namespace.rs:67-73 admits exactly the five v1 published names; membership rejects the first retained migration stage and every later migration artifact. Count zero verifies the unchanged intent; positive prefixes require Namespace/InvalidData. Test platform bypass is accurately disclosed and does not establish production eligibility.
exact preserved v1 names and bytes filesystem_migration_compatibility_tests.rs:19, :49-53 uses filesystem_migration_recovery_tests.rs:148-158: reads HEAD and every catalog/segment, sorts name/byte tuples, and compares the complete witness. No file-existence or inventory-count substitute. The same fixture provides actual published v1 golden bytes.
public unsupported-version and mandatory-flag refusal tests/store_migration_compatibility.rs:22-55, :62-87 reaches public admitted Marker admitted_format_marker.rs:27-28, Intent admitted_migration_intent.rs:46-47, Receipt admitted_migration_receipt.rs:42-47. All three owning decoders require exact length, validate fixed version/flags, then checksum: format_marker_decoder.rs:20-22, :45-72; migration_intent_decoder.rs:18-20, :46-69; migration_receipt_decoder.rs:21-23, :45-68. Version/flags are big endian at 16 and 20; each decoder independently preserves expected/observed typed refusal. Four version examples and every single flag bit are controlled examples, not exhaustive arbitrary malformed-record equivalence.
fuzz record paths retained migration_format.rs:16-27 dispatches Marker (0), Intent (1), Recovery (3), and otherwise Receipt; :30-57 preserves exact encode/decode byte invariants for admitted records. Receipt framing still uses exact admitted 96-byte marker and 256-byte intent before its receipt. Selector 3 changes only a fuzz envelope, not a public/durable discriminator.
fuzz recovery envelope migration_format/recovery.rs:12-33 admits expected intent, parses six bounded record slices and flags, calls the public planner, then evaluates three property families. :36-49 bounds copied records and uses checked slice splits and fallible conversion. Too-short, overlong-envelope-record or invalid expected-intent inputs receive no semantic property evaluation; trailing input and unused high presence bits are ignored. These are declared exploration limitations, not silent product repair.
planner success/refusal oracle Fuzz :53-67 independently enumerates absence of all migration evidence; :69-87 independently orders Namespace, Marker and Receipt effects before intent. Compared against production migration_recovery_planner.rs:29-68, :71-115. Complete assertions :90-115 require full namespace, no stages and joint decoder admission; compared migration_recovery_planner.rs:119-239. Its reuse of product decoders and lack of an oracle for all other plans are accurately disclosed. No complete reference-model or filesystem recovery claim inferred. Calibration gap remains as above.
recovery execution after incoming #161 Fuzz calls the storage-independent planner, not recover_store_migration. Actual recovery migration_recovery_execution.rs:129-150 verifies current storage, observes, plans, then calls new verify_complete for Complete. filesystem_migration_recovery.rs:86-88 routes to filesystem_initialization_namespace.rs:100-135 before success. Resumption/adoption/discard and exact typed error boundaries remain at migration_recovery_execution.rs:166-189. Thus a planner Complete in fuzz is not represented as proof of actual namespace eligibility or recovery durability.
deterministic seed materialization and campaign admission fuzz_seed_corpus.rs:70-81 calls changed migration_seeds.rs:17-47, which preserves parser records, adds explicit malformed records at :76-109, and calls migration_recovery_seeds.rs:9-43. Framing migration_recovery_seeds.rs:46-65 validates lengths before canonical little-endian u16 framing and prefixes selector 3. Both CI and scheduled workflows prepare seeds and execute registered runtime fuzz targets (ci.yml:150-156, fuzz-scheduled.yml:67-78). Scheduled evolving corpora are disposable, separately bounded/minimized state. No corpus count establishes product correctness.
stronger incoming materialization witness xtask/src/fuzz_seed_corpus/tests/materialization.rs:49-54, :142-164 looks up the named emitted partial-seal counterexample, verifies selector 5, calls the actual recovery classifier, checks exact UnsupportedVersion { expected: 1, observed: 2 }, and compares repeated output. Byte-identical to main parent; topic's weaker nonempty assertion was not restored. Mainline calibration receipts remain untouched under docs/testing-evidence/partial-seal-corruption/.

Merge audit

The PR-range history contains one merge, 6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37, with first parent 85919fb1cab1d5757c49fe7707f470bd581d7568 and second parent 80d23f51897085bac34bb5c4db067d0627748e13. Inspected the combined merge diff, first-parent incoming file diff, and complete second-parent topic diff. The final topic delta is 12 files; production modification is only a cfg(test) module registration. Incoming mainline source is otherwise preserved exactly. The incoming #172 segment recovery framing, #158 sealed observation API, #157 catalog platform admission, #156 stage tests, #159 retention model, #160/#175 reader-fence fixtures, and #161 namespace recovery checks have no new topic edits or rerouted callers. This is semantic integration review of their interaction with #112, not a claim to repeat those earlier full PR audits.

The CHANGELOG keeps both topic and incoming entries, including the incoming historical retention-model correction. The requirements merge retains incoming complete-namespace/restart declarations and replaces only #112's status/evidence row. The fuzz README keeps #172's recovery selector and counterexample text alongside the #112 migration paragraph. Materialization is exactly the second-parent stronger runtime witness. The evidence paragraph at migration compatibility line 29 explicitly describes that resolution. Incoming removal of the weaker corrupt-intent directory-count law is preserved, with stronger typed-refusal/whole-witness laws in the incoming restart matrix; the topic does not restore the removed weaker assertion.

Constants and figures

Constant or claim Verification
21 ordered phases / every complete prefix migration_phase.rs:57-79; new loop uses ALL.len() directly. The preservation mutation fails at prefix 21, admission mutation at prefix 1. No phase-count assertion is used as evidence.
Version 2; fields 16..18 and 20..24; 32 mandatory bits Three independent decoders read BE u16 at 16 and BE u32 at 20 and reject nonzero flags. Tests use checked shift and explicit incompatible version examples.
Marker 96, Intent 256 format_marker_decoder.rs:9-13; intent format and public admitted decoder; retained fuzz split agrees with product records.
Six recovery record payloads; bound 513; copied payload bound 3,078; total envelope bound 3,349 recovery.rs:9-10, :17-25, :36-49. Six times 513 = 3,078; selector + 256 expected + two presence bytes + twelve length bytes + 3,078 = 3,349. This fuzz-only cap permits overlong embedded records and does not change product storage limits.
namespace bit masks and recipe presence masks Mapped six namespace bits plus reader fence to production migration_recovery_residue.rs:6-15, :26-42. Recipe masks map VersionOne, staged/durable intent, contiguous/holed namespace, marker/receipt stages, Complete and contradictory evidence to the corresponding semantic residue.
Local seed 112; 20,000 executions; 4,096 input bytes; timeout 5; RSS 1,024 MiB keep-audit/112/fuzz-fixed-corpus.log:3-10 records actual command and starting corpus; terminal Done 20000 runs confirms bounded completion. Inputs were archived as named recipes in fuzz-initial-corpus.tar; tar inventory inspected. These are historical local-run coordinates, not current-head validation.
Pinned nightly and cargo-fuzz 0.13.2; ASan symbol and active assertions fuzz/campaign.env pins nightly-2026-07-24 and 0.13.2. Read-only Docker metadata/tool queries confirmed installed nightly and cargo-fuzz version. nm on retained /build/keep112/.../migration_format found __asan_init; planner mutation raw receipt demonstrates a running optimized fuzz assertion. This retained binary is historical evidence, not a current-tree fuzz execution.
Stable Rust 1.96.0; Linux aarch64 copied-source runtime rust-toolchain.toml and new 162-validation.log:1-10 show exact candidate tree, rustc, aarch64, ext4 crash root and tmpfs alternative. Docker containers inspected read-only.
Smoke/scheduled runner bounds Unchanged fuzz/campaign.env owns one-MiB campaign inputs, 5-second input timeout, 1,024 MiB RSS, 600-second build timeout, 15/600-second exploration, 120-second minimization, 60-second process grace and finite corpus/artifact bounds. Local 4,096-byte campaign is separately and honestly identified; no changed product time/buffer/rate limit. No new latency/RSS performance measurements claimed.
Changed CHANGELOG/requirements/README/evidence numeric claims Topic CHANGELOG contains issue identifiers and v1/v2 labels, not measurements. Requirements row marks the added laws implemented; proof admission is still incomplete because of finding above. Evidence envelope arithmetic and local campaign figures verified as above. Mainline's imported historical figures/receipts retain exact second-parent bytes, including the 343-sequence model correction; no topic parameter invalidates them and no earlier SHA's green result is treated as a current-head result.

Evidence, standards and execution status

  • Executed by reviewer: read-only Git identity/status/diffs/history, text/source/evidence reads, archived-corpus inventory, Docker process/toolchain queries and historical fuzz-binary symbol inspection. git diff --check passes and checkout remains clean. No host or container tests executed by reviewer.
  • Inspected historical product evidence: keep-audit/112/full-validation.log, focused logs and the successful fixed-corpus fuzz log. Original authoring/lint failures remain recorded and are not counted as behavioral RED. Existing crash/recovery owners remain responsible for interruptions within phases, restart and process death; these tests establish completed prefixes, not power loss.
  • Inspected valid calibration: v1-mutation-red.log:43-56 reports forbidden prefix-1 admission; bytes-mutation-red.log:49-50 reports altered HEAD witness at prefix 21; header-mutation-red.log:50-61 reports both Marker diagnostic changes; planner-fuzz-mutation-red.log:39-51 reports VersionOne oracle failure on the named intent-stage seed. Each is an actual assertion/outcome failure, not compiler/setup failure. Candidate mutations are absent from the reviewed topic diff.
  • Current candidate validation: parent-owned copied-Docker 162-validation.log records exact tree 437bc197...; at review completion it has reached warnings-denied fuzz Clippy, but the complete chain has no terminal success supplied. Pending validation is not claimed passed. The parent must separately finish current-head required validation and live hosted gates.
  • Review queue inspected: supplied fully paginated snapshot contains three global comments, zero reviews and zero threads; rate limits and historical receipts confer no approval. Parent owns final live refresh. No unresolved actionable thread was concealed in this snapshot.
  • Repository standards: declared missing verification/stronger exploration with no production behavior change; small decoder and medium filesystem laws carry oracle/size/deletion notes, whole-byte/type outcomes are asserted, arithmetic and input allocation are bounded, and changed prose paragraphs use one physical line. No dependency/format/API change, benchmark regression or new production write protocol requires additional acceptance. Calibration is mandatory and remains incomplete. Ordinary-test per-test budget/sandbox and measured latency gaps are explicitly disclosed; this review does not fabricate enforcement or expand this finite finding into the repository-wide backlog.
  • Limits: static path comparison is not runtime proof; retained historical Docker receipts do not transfer to this merge head; planner fuzzing does not execute filesystem recovery, arbitrary interleavings, shutdown schedules or physical power loss; no exhaustive grammar/reference-model claim is admitted. Current-hosted review/check/protection state is delegated to the parent's final refresh, not inferred from this snapshot.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner Author

PR #162 exact-successor evidence review

Reviewed head 1c886fdb3ab17c62d0b935f22dd3d7818709245c, tree 5eeafd1381f5a6c8251ac4cde573eb3035627e28, against main 80d23f51897085bac34bb5c4db067d0627748e13, in clean isolated checkout the isolated candidate checkout. This review adopts the complete previously verified runtime, merge, constant, format, compatibility and failure-model checklist in 162-independent-review.md for predecessor 6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37, tree 437bc1971fc8a98f2d039e446b3f5008979974f9. The successor adds only one evidence section, six patches and eight receipts: 15 documentation/evidence files. Runtime code, tests, fuzz targets, corpus recipes, dependencies and formats are unchanged; there is no additional merge to audit.

The sole P2 finding is closed. No new verified finding remains. The added controls establish the previously missing assertions' falsifiability without changing candidate expectations. They calibrate oracles; they do not demonstrate a new product defect or real on-disk counterexample.

Verification Checklist

Control Source alignment and actual RED
Intent version/flags intent.patch bypasses only the two checks in migration_intent_decoder.rs; Marker remains unchanged. Raw and committed intent-red receipts reach tests/store_migration_compatibility.rs:36 and :74, yielding ChecksumMismatch against UnsupportedVersion { expected: 2, observed: 0 } and UnsupportedFlags { observed: 1 }. The earlier Marker assertions execute successfully.
Receipt version/flags receipt.patch bypasses only Receipt checks. Raw and committed receipt-red receipts reach tests/store_migration_compatibility.rs:43 and :78 with the intended diagnostic mismatch. Earlier Marker and Intent assertions pass.
Precise pre-intent coordinate pre-intent.patch calls the real planner, then replaces Namespace with Marker in its returned EffectBeforeIntent error. The named effect-before-intent seed reaches the unchanged precise effect assertion at original recovery.rs:83, shifted to line 86 in the control. Actual output: an effect before durable intent must retain its precise refusal: Err(EffectBeforeIntent { effect: Marker }). VersionOne assertion passes first.
Complete namespace namespace.patch calls the real planner, then removes observed reader_fence only for Complete. The Complete seed reaches original line 91, shifted to 94, and fails complete migration needs the entire namespace.
Complete stage absence stage.patch calls the real planner, then inserts an empty intent stage for Complete. Prior namespace/property assertions pass; original line 95, shifted to 98, fails complete migration must not leave staged evidence.
Complete joint-record admission records.patch calls the real planner, then replaces the observed receipt with a one-byte invalid record for Complete. Namespace and stage assertions pass; original line 111, shifted to 114, fails complete migration needs jointly admitted records.

For every control, inspected the complete raw log, exact source variant, committed patch and copied Docker source. Read-only comparison confirms the six actual Docker files equal their corresponding retained variants. Reconstructed each patch from candidate source versus exact variant and compared bytes to the committed patch; all six match and pass git apply --check --unidiff-zero. These are actual running assertion failures, not compiler/setup failures. Independent copied source/target directories prevent cross-control cache reuse.

All eight committed receipts exactly equal their raw logs after the declared normalization: isolated /build/keep162...-source and ...-target prefixes plus line-end/trailing-empty whitespace. No diagnostic, command, seed, assertion coordinate, expected/observed value or exit-result content was removed. The original launcher stops after the valid pre-intent assertion because its grep expects fuzz/fuzz_targets instead of the compiler's fuzz_targets; inspected original and corrected launchers and execution traces confirm that only the remaining namespace, stage and records controls were subsequently launched. The document correctly excludes that launcher mismatch from runtime RED.

Inspected unchanged-source restoration directly in Docker: Intent decoder, Receipt decoder, fuzz recovery module and public compatibility tests equal the successor candidate bytes. The restored header receipt pins predecessor tree 437bc197... and shows both laws GREEN in debug and release. The restored fuzz receipt pins that same tree and records seed 112, 20,000 executions, 4,096-byte maximum input, timeout 5 and RSS 1,024 MiB, ending in Done 20000 runs. Named starting-corpus archive and recipe inventory were inspected; it retains the effect-before-intent and Complete replay seeds. These are historical runtime-tree receipts for the unchanged runtime, not a claim that successor CI has already passed.

The original full copied-Docker validation log now contains all required stages through terminal fuzz Clippy, including debug/release workspace tests, doctests, both crash campaigns, source structure, conformance, feature checks, formatting and warnings-denied Clippy. The parent supplied the completed process's exit 0. Live read-only inspection of hosted run 37155153324 independently confirms head 6e7e2d6..., completed success, and all four hosted jobs successful. Numeric statements in the new evidence section match those receipts; no new runtime bound or performance figure is introduced.

Repository evidence declarations remain accurate: docs/testing-evidence/migration-compatibility-fuzz.md:33-50 names each control, source coordinates, reproduction command, normalized/raw provenance and limitations. The four post-planning controls calibrate unchanged oracles using deliberately inconsistent observations, as expressly disclosed. They are not a substitute for runtime storage recovery acceptance, and this closure asserts no additional exploration, arbitrary interleaving, resource enforcement or power-loss coverage. Changed prose uses one physical line per paragraph. git diff --check passes.

Executed by this reviewer: read-only Git/diff/source queries, raw-to-normalized receipt comparisons, patch reconstruction and apply checks, Docker file reads and hosted-run/check queries. Inspected, not rerun: product tests, mutations, full Docker validation and fuzz campaigns. No host/container tests, production edits, commits, comments or configuration mutations were performed.

At the final check, successor run 37155679287 has Documentation and Dependency policy successful, with Rust quality gates and Runtime fuzz smoke still in progress. This approval covers the exact successor code/evidence review. It does not authorize a merge while required successor checks remain pending, and a CodeRabbit success status alone is not treated as an approving review. The parent owns final head, review queue, hosted gates and protection refresh.

APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer closure — candidate 1c886fd

Obligation Source / severity Evidence and outcome
Compatibility and bounded recovery fuzz acceptance #112 / KEEP-MIGRATION-008 Runtime laws preserve every original v1 HEAD/catalog/segment name and byte through complete forward prefixes, require precise v1 authority refusal after migration starts, and require exact public unsupported-version/flag errors. Named valid/malformed recipes drive bounded parser/planner fuzzing; no full storage-recovery or independent grammar-model claim.
Merge compatibility Both-parent review of 6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37 Mainline #161 completion admission and #175 fixture authority survive. CHANGELOG preserves both parents. Materialization retains mainline #172's actual emitted-counterexample classifier refusal instead of restoring the weaker nonempty assertion.
Missing distinct assertion calibration Independent and self review / P2 1c886fdb3ab17c62d0b935f22dd3d7818709245c records two independent decoder controls and four fuzz-property controls. Each reaches its intended runtime assertion without changing expected values. Restored debug/release public tests and archived-corpus 20,000-execution fuzz run pass. The initial launcher path-match failure is preserved and excluded from runtime RED. Closed by exact-successor independent review.
Full validation Required Full copied-Docker chain exits zero at runtime tree 437bc1971fc8a98f2d039e446b3f5008979974f9, including both crash campaigns and debug/release suites. Successor changes only evidence/docs. Final successor whitespace/Markdown checks and all four hosted jobs in run 37155679287 pass.
Review queue and eligibility Complete paginated review bodies/comments/threads No unresolved actionable inline findings or active changes-requested reviews. CodeRabbit rate limit and hosted Codex notices are not approvals. Authorized independent exact-head review supplies the mandatory verification checklist. No branch-protection bypass.

No product behavior, format, public API, dependency, recovery policy or benchmark guarantee changes. Existing platform, physical-power-loss, fixed-schedule and ordinary resource-enforcement limits remain explicit. The record distinguishes tool output, oracle calibration and product runtime evidence. Historical measurements remain attributed to their original source; final validation is tied to this exact head.

MERGE GATE: OPEN under the maintainer's existing authorization. Recheck head/base and required checks immediately before the normal signed merge.

@flyingrobots
flyingrobots merged commit 5179ed7 into main Oct 3, 2026
5 checks passed
@flyingrobots
flyingrobots deleted the test/112-migration-compatibility-fuzz branch October 3, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Complete migration compatibility and fuzz evidence

1 participant