Test: verify migration compatibility and fuzz recovery transitions (#112) - #162
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 40 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (26)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-head receipt: The copied-source validation chain completed with exit 0: workspace/fuzz formatting; source structure; all-feature and minimal-feature workspace warnings-denied Clippy; fuzz-target Clippy; full all-feature workspace tests and doctests in debug and release; A fresh named starting corpus was archived before the 20,000-execution seed-112 migration fuzz run. That run completed successfully with the documented input/timeout/RSS bounds. Separate candidate-excluded mutations were observed RED for v1 authority admission, byte preservation, precise version/flag diagnostics and the recovery-planner oracle. Initial test-authoring and lint failures remain recorded and are excluded from calibration claims. Raw author evidence is retained under the issue-112 scratch directory, including Hosted documentation and dependency checks are green; Rust quality gates and runtime fuzz smoke remain in progress on this exact SHA. This receipt does not claim independent review approval or mainline integration. |
Code Lawyer finding — finite calibration gap
The original filesystem authority/byte-preservation and Marker/VersionOne calibration remains valid for its actual scope. @codex No runtime bug is inferred from this evidence gap. The candidate stays unchanged while isolated calibration copies run. |
|
To use Codex here, create an environment for this repo. |
Independent review of PR #162Candidate: FindingsNo product defect or semantic merge regression was demonstrated. The following is a verified proof gap, not evidence that the existing product decoders or planner are incorrect. P2 — Complete the missing calibration for distinct new load-bearing assertions. Coordinates: Verification ChecklistChanged runtime paths and parallel rules
Merge auditThe PR-range history contains one merge, The CHANGELOG keeps both topic and incoming entries, including the incoming historical retention-model correction. The requirements merge retains incoming complete-namespace/restart declarations and replaces only #112's status/evidence row. The fuzz README keeps #172's recovery selector and counterexample text alongside the #112 migration paragraph. Materialization is exactly the second-parent stronger runtime witness. The evidence paragraph at migration compatibility line 29 explicitly describes that resolution. Incoming removal of the weaker corrupt-intent directory-count law is preserved, with stronger typed-refusal/whole-witness laws in the incoming restart matrix; the topic does not restore the removed weaker assertion. Constants and figures
Evidence, standards and execution status
REQUEST CHANGES |
PR #162 exact-successor evidence reviewReviewed head The sole P2 finding is closed. No new verified finding remains. The added controls establish the previously missing assertions' falsifiability without changing candidate expectations. They calibrate oracles; they do not demonstrate a new product defect or real on-disk counterexample. Verification Checklist
For every control, inspected the complete raw log, exact source variant, committed patch and copied Docker source. Read-only comparison confirms the six actual Docker files equal their corresponding retained variants. Reconstructed each patch from candidate source versus exact variant and compared bytes to the committed patch; all six match and pass All eight committed receipts exactly equal their raw logs after the declared normalization: isolated Inspected unchanged-source restoration directly in Docker: Intent decoder, Receipt decoder, fuzz recovery module and public compatibility tests equal the successor candidate bytes. The restored header receipt pins predecessor tree The original full copied-Docker validation log now contains all required stages through terminal fuzz Clippy, including debug/release workspace tests, doctests, both crash campaigns, source structure, conformance, feature checks, formatting and warnings-denied Clippy. The parent supplied the completed process's exit 0. Live read-only inspection of hosted run Repository evidence declarations remain accurate: Executed by this reviewer: read-only Git/diff/source queries, raw-to-normalized receipt comparisons, patch reconstruction and apply checks, Docker file reads and hosted-run/check queries. Inspected, not rerun: product tests, mutations, full Docker validation and fuzz campaigns. No host/container tests, production edits, commits, comments or configuration mutations were performed. At the final check, successor run APPROVE |
Code Lawyer closure — candidate 1c886fd
No product behavior, format, public API, dependency, recovery policy or benchmark guarantee changes. Existing platform, physical-power-loss, fixed-schedule and ordinary resource-enforcement limits remain explicit. The record distinguishes tool output, oracle calibration and product runtime evidence. Historical measurements remain attributed to their original source; final validation is tied to this exact head. MERGE GATE: OPEN under the maintainer's existing authorization. Recheck head/base and required checks immediately before the normal signed merge. |
Missing evidence and outcome
The migration compatibility ledger lacked a runtime v1-authority refusal witness at every forward prefix, comprehensive migration-record version/flag cases, and recovery-planner fuzz inputs. This PR adds those checks while preserving production behavior.
A fresh filesystem store executes each migration prefix. The untouched store reopens as v1; every nonempty prefix refuses v1 authority at the existing Namespace/InvalidData boundary, and original HEAD/catalog/segment names and bytes remain unchanged. Public record decoders refuse unsupported versions and every single mandatory flag bit with exact coordinates. The existing
migration_formatfuzz target now explores bounded recovery residue with valid and contradictory seeds and specified admission properties.Change kind: missing verification and stronger fuzz exploration. Current candidate normally integrates main
80d23f51897085bac34bb5c4db067d0627748e13, including the reviewed #161 completion fix and #175 continuous reader-fixture authority. CHANGELOG preserves both parents; the corpus-test conflict preserves mainline #172’s stronger emitted-counterexample runtime witness. No product code behavior, format, API, dependency, recovery-policy or benchmark changes.Evidence
Focused filesystem and public-decoder laws pass in debug/release. Separately copied mutations go RED: accepting migrating namespaces as v1; damaging HEAD after the final migration phase; bypassing marker version/flag checks; forcing v1 planner success with a retained intent stage. These calibrate missing evidence, not a claimed production bug on main. An initial endian mistake in the test patch and lint corrections are retained as authoring failures, not product RED.
A fixed starting corpus is archived before a successful 20,000-execution libFuzzer run using seed 112, 4,096-byte input cap, five-second per-input timeout and 1,024 MiB RSS limit. The pinned nightly/cargo-fuzz binary exports AddressSanitizer initialization and the release mutation proves active assertions. Recipes for valid and malformed record/transition seeds are checked in and picked up by existing smoke/scheduled workflows. No real product crash was found in this bounded run.
Full required copied-Docker validation passes at integrated source
6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37, tree437bc1971fc8a98f2d039e446b3f5008979974f9, and all four hosted jobs pass in run 37155153324. Fresh independent review found one finite calibration gap: earlier Marker/VersionOne controls did not reach later distinct assertions. Evidence-only successor1c886fdb3ab17c62d0b935f22dd3d7818709245crecords six intended runtime controls for Intent/Receipt headers and precise pre-intent/Complete properties, followed by unchanged decoder debug/release GREEN and a new archived-corpus 20,000-run fuzz GREEN. No production defect is inferred. All four final-successor hosted jobs pass in run 37155679287. Independent exact-head APPROVE verifies the six controls, raw receipts and unchanged runtime scope, closing the sole P2 finding. Evidence maps contracts, replay, calibration, resource limits and exclusions. KEEP-MIGRATION-008 and fuzz documentation now cite the expanded evidence.Scope and limitations
Recovery fuzzing invokes public parser/planner runtime. Complete-success checks reuse product decoders and prove planner/admission agreement; other result classes receive robustness exploration rather than a full independent reference model. The fuzz-only envelope is bounded and is not an on-disk format. Filesystem fixtures bypass platform eligibility checks to isolate migration compatibility; this is not new platform, physical power-loss or arbitrary-concurrency evidence. Existing crash and recovery owners remain.
The materialization tool test no longer freezes incidental global/per-target seed counts. After integration it retains mainline’s exact typed refusal from the real recovery classifier over an emitted counterexample, plus deterministic repeated materialization; the weaker nonempty-output assertion is subsumed. Product confidence comes from the runtime laws and fuzz oracles. No count was merely increased to accommodate more cases.
Original roadmap checkboxes are unchanged. Merge remains necessary before claiming mainline delivery.
Closes #112. Refs #131, #132.