Skip to content

Fix: isolate locator subprocesses from golden writer handoffs - #179

Open
flyingrobots wants to merge 2 commits into
mainfrom
fix/178-durable-locator-isolation
Open

flyingrobots wants to merge 2 commits into
mainfrom
fix/178-durable-locator-isolation

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Problem and outcome

Change kind: test-isolation bug fix. Release CI on main 7a21faebdbed38c386db14873966d433754c6eb4 returned WriterLock { source: Busy } while preparing the durable layout-binding law. The golden executable mixed writer-authority handoffs with two locator laws that spawned children. A controlled public-API experiment demonstrates that an unrelated child held before exec retains inherited lock authority after the parent's guard drops.

Move those two unchanged locator laws to their own integration-test executable. The parent of that executable creates no store; its children run one law each. A locator child can no longer inherit descriptors from golden storage tests running in another process. No test is ignored, deleted, retried or globally serialized; runtime assertions and child selectors remain byte-identical. Shared unused fixture operations have local, explained dead-code allowances rather than production API changes.

Invariant, alternatives and limits

Keep must return exact named bytes or refuse; this change preserves the existing layout, output-sentinel, relative-store binding and original-I/O-cause assertions. Production source, locks, typed Busy refusals, API, format, recovery protocol and performance behavior do not change. No benchmark improvement is claimed.

Rejected: retrying Busy into success, sleeps, weakening assertions, serializing the whole suite, or changing production unlock behavior. The original CI log lacks the failing handoff and syscall trace. The pipe-controlled experiment demonstrates the interference mechanism, not the exact original schedule. A strace diagnostic run passed and is explicitly not treated as proof of absence. A subsequent mainline run also passed; that does not resolve the recorded failure. The narrower guarantee here is structural process isolation plus preserved runtime laws.

Evidence and review gates

Owner: @flyingrobots. Evidence, original RED and controlled mechanism record exact coordinates, public typed outcome, source and coverage limits. The observed RED was a runtime fixture-acquisition failure before the law’s product assertions; it does not calibrate those unchanged assertions. No artificial harness-count regression is added. Original production/test source is byte-identical between the failed main and parent 3165890e9291cfb5fe10e81a9d7cd151f3e59464.

Candidate f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a, tree 408d9c1491e782cee3971680c998c2335153b7a7, passes copied-Docker debug/release golden and locator suites, all-feature strict Clippy, formatting, and pinned Markdown checks. Initial candidate's focused runtime checks passed but Clippy rejected the root-level fixture import visibility and unused cleanup method; successor retains the original nested scope and documents narrowly unused fixture operations. That lint failure remains recorded, not called product RED.

The unchanged medium laws use owned ext4 scratch in Linux Docker. Locator children retain their 20-second watchdog. Existing ordinary-Cargo per-test memory/resource/egress and suite-budget enforcement gaps are disclosed; this change neither implements them nor extends #106's unrelated waiver. Full required stable-candidate validation, independent exact-head review, final hosted CI and policy-gap disposition remain acceptance gates.

Addresses #178. Close only after final acceptance and bounded disposition of the recorded failure; no universal absence-of-Busy claim is made.

The missing resource-profile controls are tracked by #180. Independent review found no implementation defect but requires an explicitly approved, expiring scoped waiver or implemented controls; no waiver is yet approved. The full local chain was interrupted during compilation when the Docker container exited 255 (OOMKilled=false). The exact source tree and ext4 mounts were reverified, and only the remaining validation commands resumed with a separate log. That environment failure remains preserved.

Final validation status

All four hosted jobs in run 37165745204 pass at unchanged head f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a, including release validation. The resumed local chain completed exit0; the interruption and first-candidate lint failure remain recorded. CodeRabbit approves this exact head. Independent review's sole remaining disposition is the resource-policy gap. A maintainer waiver through 2026-10-17, limited to these moved laws and tracked by #180, has been requested but is not yet approved. Merge awaits that explicit decision and independent confirmation.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 95706482-a132-48a2-aeff-616899bfbc4a
📥 Commits

Reviewing files that changed from the base of the PR and between 3165890 and f9a9c2e.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • docs/testing-evidence/durable-locator-isolation.md
  • docs/testing-evidence/durable-locator-isolation/controlled-inheritance.txt
  • docs/testing-evidence/durable-locator-isolation/hosted-red.txt
  • docs/testing-evidence/durable-locator-isolation/probe-source.txt
  • tests/durable_locator.rs
  • tests/durable_locator/suite.rs
  • tests/golden_file_worldline/suite.rs
💤 Files with no reviewable changes (1)
  • tests/golden_file_worldline/suite.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: Documentation and workflow integrity
  • GitHub Check: Runtime fuzz smoke
  • GitHub Check: Rust quality gates
  • GitHub Check: Dependency policy
🧰 Additional context used
🪛 LanguageTool
docs/testing-evidence/durable-locator-isolation/probe-source.txt

[style] ~48-~48: Using many exclamation marks might seem excessive (in this case: 11 exclamation marks for a text that’s 2614 characters long)
Context: ...iagnostic reaps its child. assert_eq!(rustix::io::write(&release_write, &[1])?, 1); let status = child.join().map_err(|_| "spawn thread panicked")??; assert!(status.success()); assert!(matches!(during, Err(WriterLockAcquireError::Busy)), "a child before exec must retain inherited writer authority"); let after = FilesystemWriterLock::try_acquire(root)?; drop(after); println!("controlled pre-exec child: parent drop...

(EN_EXCESSIVE_EXCLAMATION)

🔇 Additional comments (7)
docs/testing-evidence/durable-locator-isolation.md (1)

1-29: LGTM!

docs/testing-evidence/durable-locator-isolation/hosted-red.txt (1)

1-8: LGTM!

docs/testing-evidence/durable-locator-isolation/probe-source.txt (1)

1-57: LGTM!

docs/testing-evidence/durable-locator-isolation/controlled-inheritance.txt (1)

1-29: LGTM!

tests/durable_locator/suite.rs (1)

1-8: LGTM!

Also applies to: 11-16

CHANGELOG.md (1)

11-11: LGTM!

tests/durable_locator.rs (1)

10-11: 🎯 Functional Correctness

The selectors already include the required suite::durable_locator_laws:: prefix. Both names match the two #[test] functions, so --exact selects one child test instead of an empty set.


Summary by CodeRabbit

  • Tests
    • Durable-locator tests now run serially in a separate test executable, isolated from golden-store test processes. This prevents lock handles from being shared across those test runs.
  • Documentation
    • Added testing evidence describing the observed lock contention, a controlled process-inheritance experiment, and the limits of the available CI results.
    • Recorded that product assertions, APIs, and protocols remain unchanged.

Walkthrough

Durable locator laws now run in a separate Linux-gated test executable. The golden worldline suite no longer includes those laws. Supporting records document the observed writer-lock failure and a controlled inherited-descriptor experiment.

Changes

Durable Locator Test Isolation

Layer / File(s) Summary
Record lock inheritance evidence
docs/testing-evidence/durable-locator-isolation.md, docs/testing-evidence/durable-locator-isolation/hosted-red.txt, docs/testing-evidence/durable-locator-isolation/probe-source.txt, docs/testing-evidence/durable-locator-isolation/controlled-inheritance.txt
The records describe the hosted WriterLock { source: Busy } failure and a controlled experiment. In the experiment, inherited descriptors keep the lock busy until the child exits. The records distinguish the experiment from the unobserved hosted failure schedule.
Run locator laws in a separate executable
tests/durable_locator.rs, tests/durable_locator/suite.rs, tests/golden_file_worldline/suite.rs, docs/testing-evidence/durable-locator-isolation.md, CHANGELOG.md
A Linux-gated executable includes the durable locator suite, and the golden worldline suite no longer includes those laws. The evidence record describes the separation, retained assertions, and validation profile. The changelog records the isolation change.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to f9a9c

The locator laws remain selected in their separate executable, with no identified merge-blocking issue from this change. Complete the stated validation and CI gates before merging.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main change: isolating locator subprocesses from golden writer handoffs.
Description check ✅ Passed The description gives substantial detail on the problem, invariant, approach, alternatives, evidence, validation, and known limits. It does not use several template headings, including Security implic…
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A lock stays busy through the fork,
Until the child has left its mark.
The locator laws take their own flight,
While golden tests keep their scope tight.
The record notes what logs can show,
And what the test runs do not know.

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent review: Keep PR #179

Reviewed exact head f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a, tree 408d9c1491e782cee3971680c998c2335153b7a7, against main 3165890e9291cfb5fe10e81a9d7cd151f3e59464. Local Git and live PR metadata agree. The isolated review checkout was clean. This is the explicitly authorized independent Codex fallback using the supplied agy-review protocol; no additional agent or agy invocation was made.

Findings

No verified P0–P5 implementation defect in the reviewed diff. The correction removes the identified descriptor-sharing boundary without changing Keep production code, product expectations, assertion bodies, child selectors, lock semantics, formats or public APIs.

Mandatory acceptance gap, separate from correctness

Testing-profile risk disposition is missing. docs/testing/enforcement.md:11 explicitly covers new or changed tests and rejects blanket grandfathering. Moving these laws changes their execution profile even though assertion bodies are unchanged. The record at docs/testing-evidence/durable-locator-isolation.md:27-29 correctly discloses ordinary-Cargo enforcement gaps, but disclosure is not approval. docs/testing/enforcement.md:21, :49-51 require per-test deadlines/memory ceilings, admitted resources, egress isolation and measured suite-budget admission. The existing 20-second child watchdog provides only one deadline; Docker plus owned ext4 scratch does not establish the missing controls. :7 and :61 require the approving maintainer, exact unmet requirement and scope, consequence, attempted evidence, compensating verification, linked issue and expiry. docs/Testing Standards.md:88-90, :170, :189 are consistent with that requirement.

The existing #106 waiver explicitly covers only that PR's documentation-test version/banner changes and cannot cover #179. No maintainer-approved #179 waiver was present in the supplied artifacts or PR body/comments inspected. Resolve the controls or obtain an explicitly approved, expiring waiver confined to these moved medium laws and their disclosed execution gaps. The author must not self-approve it. This is an acceptance blocker, not evidence that the process-isolation implementation is incorrect and not a request to introduce unrelated storage hardening.

The risk record should preserve the remaining causal uncertainty: the exact hosted handoff/schedule is unobserved. The correction guarantees this process boundary; it does not establish universal absence of Busy. Do not turn #178's eventual landing disposition into a claim of an identified original syscall trace or substitute retries for recurrence diagnosis.

Verification Checklist

Runtime paths and retained boundaries

  • Cargo integration target tests/durable_locator.rs:8-11 is Linux-only and imports tests/durable_locator/suite.rs:3-16. The former Linux-only import at parent tests/golden_file_worldline/suite.rs:33-35 is absent at the head; head :30-35 imports layout and namespace laws without locator laws. The original golden entry tests/golden_file_worldline.rs:5-6 still loads its suite. The tests/ entry file creates a distinct executable under Cargo's existing auto-discovery; no Cargo target override or disabled auto-tests exists.
  • Both new-target parent paths are the unchanged tests/golden_file_worldline/durable_locator_laws.rs:23-34 → :37-59. Parent paths create no TestDirectory, store or writer authority. They launch timeout 20s with the current executable, exact law selector, --nocapture, --test-threads=1, and the matching CHILD environment value. The nested suite::durable_locator_laws namespace matches both byte-identical selectors at :21 and :32.
  • Admitted child route durable_locator_laws.rs:38-45 requires both the matching environment value and exact complete argument sequence. Each exact child executes one operation serially. The child does not launch another child: this admission branch calls the operation directly. Other invocations follow the parent launcher. No assertion is ignored, retried or globally serialized.
  • Relative-store route durable_locator_laws.rs:91-121 → shared durable_fixture.rs:66-75 creates both real stores in the child before opening the relative DurableStore. Product path src/adapters/durable/store.rs:80-91 resolves the locator once; :106-116 and :125-136 use that stored locator for fresh snapshots/read output. Child assertions at durable_locator_laws.rs:99-119 retain original-store membership, exclusion of the second store and exact original bytes after cwd changes.
  • Deleted-cwd route durable_locator_laws.rs:62-88 → src/adapters/durable/store.rs:85-86 → src/adapters/durable/error.rs:19-22,64-73 retains exact Locator, NotFound, Linux NOENT and downcast original Error::source. WorkingDirectory restoration at durable_locator_laws.rs:124-138 remains explicit on success and best-effort on early return/unwind inside the isolated child.
  • Golden layout-binding law tests/golden_file_worldline/durable_layout_laws.rs:79-118 remains in the golden process. Its fixture call at :83 precedes the exact LayoutMissing assertions at :101-115, and the sentinel [0xAB] at :116 is unchanged. Both ingress routes remain src/adapters/durable/layout_reads.rs:84-100 and :112-125; canonical record decoding routes to the same semantic range path. No production path is rerouted by this PR.
  • Shared fixture authority sequence durable_fixture.rs:66-75 → :122-168 catalog publication → :110-119 migration → :171-202 retention publication still drops/reacquires authority between calls. No retry, explicit unlock or altered handoff was introduced. Production writer boundary src/adapters/filesystem_writer_lock.rs:72-94,113-129,136-170 retains nonblocking Busy refusal and owned handles; root CLOEXEC at :140 closes on exec, not at fork. The guard retains both lock descriptions at :52-56.
  • Locator-parent descriptor tables contain no golden writer guard. The golden process no longer has the only subprocess-creation module in its suite. Source scan of the golden module tree identified Command/output spawning only in the now separately imported locator module. Parallel executions of distinct integration binaries therefore cannot fork each other's live golden lock descriptions. Both locator children can run concurrently, but each owns its own PID-qualified scratch and performs store construction after exec.
  • tests/segment_filesystem_stage/sandbox.rs:19-32 uses process-ID-qualified, law-specific names, preventing cross-child scratch collisions; :49-57 retains explicit removal and Drop cleanup. No scratch naming or cleanup code changed.
  • The two local dead_code allowances in tests/durable_locator/suite.rs:4-8,12-16 name one lint and explain this executable's subset import. They do not change shared fixture visibility or relax other suites. Partial-record constructors remain used by golden laws; explicit cleanup remains called by tests/golden_file_worldline/durable_assertions.rs:48,94. Import-site scope keeps shared API/source unchanged.

History and merge audit

  • PR history consists of 01988bc4f07257dd8fdf1fb19675257cc5e9ad56 and f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a, each with one parent. There are no merge commits in the PR range, so no merge-parent/conflict-resolution diff is outstanding.
  • Audited both commits and the complete base-to-head diff. Initial target import and selector namespace adjustments were repaired by the second commit. At final head, durable_locator_laws.rs, durable_fixture.rs, durable_layout_laws.rs, and sandbox source have zero base-to-head diff. Final selectors and assertions are byte-identical, rather than merely semantically similar.
  • Verified the historical RED-to-parent comparison: git diff --name-only 7a21faebdbed38c386db14873966d433754c6eb4 3165890e9291cfb5fe10e81a9d7cd151f3e59464 -- src tests Cargo.toml Cargo.lock rust-toolchain.toml reports only Cargo.lock. The changed lock graph is the subsequent repository YAML-tool update; production source and failing assertions did not change. No claim that all repository bytes are identical is made.
  • Earlier Keep collector authority continuous in reader-fence process laws #174 evidence docs/testing-evidence/reader-fence-process.md:39-47 remains historical continuous-authority evidence for that different fixture. Its RED/Busy observation is not proof that Fix unexpected writer contention in durable-layout validation #178 has the same causal trace; the current correction preserves the limits rather than importing that conclusion.

Constants, claims and numerical evidence

  • Existing 20-second watchdog: durable_locator_laws.rs:5,46-47 matches docs/testing-evidence/durable-locator-isolation.md:27. No timeout changed. It is a hang ceiling, not a measured latency promise or memory budget. There is no new p95/SLO figure; the document explicitly disclaims suite measurements.
  • Two moved laws: verified the two test entry functions at durable_locator_laws.rs:23-34, one shared source import in the new suite, no import in golden. Historical hosted count 51 passed + 1 failed = 52 matches hosted-red.txt:8. Focused candidate counts 2 locator + 50 golden = 52 in both profiles. Counts check preservation only; they are not an oracle for storage correctness.
  • Unchanged fixture limits at durable_fixture.rs:62,183: catalog restart 16,777,216 bytes; retention closure parameters 4096, 8, 16,777,216, 67,108,864. They are existing admitted policy caps, not new measurements or claims that total test RSS is bounded. Product MAXIMUM and ReaderAttemptLimit::DEFAULT uses are unchanged. Exact range coordinates, differing same-length blob inputs and sentinel are unchanged at durable_layout_laws.rs:82-116.
  • Historical hosted coordinates: live GitHub run 37164344603 reports failed push head 7a21faebdbed38c386db14873966d433754c6eb4 and failed release step. Live failed log matches docs/testing-evidence/durable-locator-isolation/hosted-red.txt:1-8, including timestamps, named law, typed Busy, counts and 0.67-second historical duration. Its separate dependency download failure occurred in the documentation job and does not explain the observed layout law failure.
  • Controlled probe probe-source.txt:24-54 takes public Keep authority, signals readiness from a pre-exec hook, drops the parent guard, observes Busy, releases/reaps, then reacquires. Each pipe transfer is one byte and both ends are CLOEXEC. Receipt controlled-inheritance.txt:26-29 identifies the external crate and the expected observation. The package/version lines and 3.14-second build duration in :1-28 are historical compiler output, not product limits. Rust 1.96.0/edition 2024/rustix =1.1.4 agree with the probe declaration and pinned product toolchain/dependency. Diagnostic 0.0.0 versions are package metadata, not release claims.
  • The probe's unsafe hook and printing exist only in a plaintext replay artifact, outside the Cargo workspace/product/suite; no unsafe executable source was admitted by this PR. The hook's successful path only performs pipe I/O and returns. Its controlled schedule demonstrates inherited-descriptor lifetime and exact public contention, not the original hosted schedule. No probabilistic sleep or strace pass is upgraded to causal proof.
  • Focused receipt 178-stable-focused.log:1-2,48,104,106,152,208,210-265 records formatting, debug/release suites and strict all-feature Clippy. Historical elapsed durations 0.31/9.35 and 0.30/1.15 seconds are output, not acceptance thresholds. 178-markdown.log:1-4 records pinned markdownlint-cli2 0.23.3 and zero issues for the two changed Markdown files.
  • Full-chain receipt 178-full-validation.log:1-10 pins candidate tree, rustc 1.96.0, Linux aarch64 and actual ext4 scratch; it separately identifies tmpfs. Subsequent commands reflect the candidate's validation chain. It was still live at inspection: no terminal completion or full-success assertion is made.
  • Every changed Markdown paragraph reviewed: durable-locator-isolation.md:3-29 and CHANGELOG.md:11 describe test isolation, historical mechanism evidence and limits; they introduce no storage throughput, durability, recovery or universal race-free measurement. Paragraphs are single physical lines in the new evidence page. Documentation Standards requires coherent paragraphs, not an unrelated universal physical-line rule; no imported rule was used.
  • Scope-specific numerical references Fix unexpected writer contention in durable-layout validation #178/Build(deps): update and admit the documentation tool graph #106 and named SHAs/run IDs reconcile with PR intent and the supplied prior waiver. The Build(deps): update and admit the documentation tool graph #106 waiver's expiry/candidate are historical and explicitly excluded from Fix: isolate locator subprocesses from golden writer handoffs #179. Unchanged README and other CHANGELOG entries were not re-audited as unrelated numeric claims; this review checks changed/current claims and their binding evidence, not every prior repository measurement.

Evidence subjects, failures and limitations

  • Original hosted result is an actual failing runtime law on unfixed source, with fixture acquisition failure before its range-refusal assertions. It is not calibration showing those product assertion bodies fired. The record at durable-locator-isolation.md:9 makes that distinction. No new or materially changed load-bearing assertion was introduced, so Rule 4 does not require a fabricated assertion mutation solely for the move.
  • Controlled probe is external diagnostic kernel/public-adapter evidence, not a permanent new CI law or assertion-count gate. Retained locator/layout checks are product verification. Formatting, Clippy, Markdown and source-structure checks are tool/static evidence and cannot prove exact-byte behavior.
  • Initial candidate runtime success and Clippy failure remain distinct. The final head repairs module scope and documents unused imported operations. A compiler/lint failure is not represented as product RED.
  • Error/unwind and child exit paths remain unchanged: spawn/current-executable errors propagate; non-success/timeout child status fails the parent assertion with captured stdout/stderr; exact Locator original sources remain available; cwd cleanup attempts restoration. No new cancellation, durability, recovery or restart state machine is introduced. Existing timeout/cleanup limits are not silently promoted into new guarantees.
  • No new parser, identity preimage, durable format, dependency, unsafe product operation, feature, performance optimization or product write protocol exists in the diff. New fuzzing, physical power-loss experiments and benchmarks therefore do not establish an additional changed claim here. Existing broader runtime checks remain required for final acceptance.
  • Explicit gaps: original failing handoff/syscall schedule unknown; controlled probe is one deterministic diagnostic schedule; no exhaustive scheduling, universal absence of Busy, physical power-loss, complete global lock audit, per-test memory/egress enforcement, measured suite budget or flake-rate evidence. Original strace-delayed parent suite passed (178-parent-schedule.log:56); that is a diagnostic outcome, not absence proof.

Execution status and review coverage

Executed by this reviewer: read-only Git status/head/tree/history/diffs including whitespace check; static source/evidence review; live GitHub PR metadata, comments/reviews and review-thread pagination; historical failed-run metadata and log comparison. Review threads had zero nodes and hasNextPage: false; both inspected PR comments were automated status/usage messages, with no unresolved code finding at that inspection.

Inspected, not independently executed: copied-Docker focused debug/release validation, strict all-feature Clippy and formatting receipt; Markdown receipt; controlled public-API diagnostic receipt/source; strace parent receipt; live full-chain partial log. Parent owns full-chain completion and hosted gates. No host Rust tests were run. A Docker discovery attempt found my default socket unavailable at that moment; no configuration was changed and the parent confirmed its existing Docker execution route. Independent test duplication was not required or claimed.

Pending at review inspection: hosted run 37165745204 still had Rust quality and fuzz smoke in progress; documentation/workflow integrity and dependency policy had succeeded. CodeRabbit was still processing; Codex hosted review reported usage limit. Pending checks are not green. Recheck exact head, final full-chain terminal status, all required hosted checks and any arriving actionable review feedback before integration.

There is no mandatory source path left unreviewed within this eight-file correction. This review does not certify unrelated storage subsystems or establish all testing-policy controls. Correctness review supports the bounded isolation change; final acceptance is blocked by the unapproved scoped testing-profile disposition and outstanding final validation.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer activity — candidate f9a9c2e

Exact pushed head f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a, tree 408d9c1491e782cee3971680c998c2335153b7a7, targets main 3165890e9291cfb5fe10e81a9d7cd151f3e59464.

Obligation Evidence / result
Recorded runtime failure Original release golden-law Busy from main7a21fae is preserved. Failure occurred during real fixture acquisition before product assertions, not assertion calibration.
Concrete mechanism External pipe-handshake experiment demonstrates inherited writer authority before exec and successful acquisition after exec/reap. Exact historical CI handoff remains unknown.
Bounded correction Existing locator laws, child selectors and assertions remain byte-identical in a distinct executable. Golden process no longer spawns locator children. No production source, API, protocol, assertion deletion, retry or global serialization change.
Focused validation Final copied-tree formatting, debug/release golden and locator laws, strict all-feature Clippy and pinned Markdown checks pass. Initial root-level import Clippy failure is preserved and corrected by nested module scope.
Full local chain Golden/conformance, debug/release crash campaigns, source structure, fmt, both feature-matrix checks/Clippy passed before container exit255 interrupted test compilation; OOMKilled=false. After restart, unchanged tree and both ext4 scratch mounts were reverified. Remaining debug/release workspace tests, doctests/docs, pinned compiler check and locked fuzz fmt/build/Clippy completed exit0. No product failure was retried into green and the environment interruption remains recorded.
Review CodeRabbit approval is for this exact head. Independent full-checklist review reports no implementation defect but requires scoped policy disposition and final checks. No unresolved inline thread or implementation finding.
Remaining policy gate Binding testing-profile controls for the moved laws remain incomplete. #180 owns enforcement. #106's waiver does not apply; no #179 waiver is approved.
Remaining hosted gate Run37165745204 passes documentation, dependency and fuzz jobs; Rust quality remains running at this observation. Pending is not green.

No new speculative hardening is proposed. Merge remains gated on the current exact head's final hosted success, explicit scoped policy approval and resulting independent-review confirmation. Recurrence of Busy remains actionable; this is not universal lock-schedule certification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant