Skip to content

Build(deps): Bump cap-std from 4.0.2 to 4.0.3 - #93

Open
dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/cargo/cap-std-4.0.3
Open

dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/cargo/cap-std-4.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem and outcome

Change kind: deliberate dependency upgrade. Update cap-std and resolved cap-primitives from 4.0.2 to 4.0.3 across the library, repository tasks and separately locked fuzz workspace. Keep cap-fs-ext 4.0.2 and existing features. Renew the capability dependency admission and exact winx exception's explanatory coordinate without broadening policy.

Candidate 44c736c251ad121f69f217452540c98fa989cb33, tree f5faff4dfa253c4e8e6b704ddcab9463e4dfddb3, follows integration f50666f4f29871d48389fef060e8f5ba47ccb3f6: original Dependabot e4ec66796522e85a59bcfedc02f25c3895528817 merged #102's 11bc72c41cc379944766adbdef60f046e786b820. The sole conflict was adjacent root dependency lines; the resolution retains both cap-std 4.0.3 and Rustix 1.1.5. #179 and #102 must clear their separate gates and land before this prepared stack. #94 is independent and is not a prerequisite.

Contract and scope

Published cap-std runtime source is unchanged. The cap-primitives manual resolver no longer re-appends a trailing slash before the guarded component open; directory-required and explicit symlink handling remain. Existing public filesystem profile, no-follow, identity, exact-byte, namespace and typed-corruption rules remain required. No Keep source, test expectation, public API, on-disk format, identity or recovery protocol changes.

The supported mutation model remains cooperating writers under Keep authority. An open handle or metadata check does not make pathname unlink/rename conditional on inode identity against arbitrary concurrent raw mutation. Pre-effect refusal remains distinct from execution failure after namespace effects or uncertain synchronization; the dependency upgrade does not promise rollback or automatic disposal of incomplete retention stages.

Alternatives rejected: stale fuzz resolution, relaxed pins, broader features/license exceptions and checksum-only acceptance. The risk is changed OS path resolution; review must trace actual selected paths and caller checks. No performance improvement or new all-platform isolation guarantee is claimed. Historical crash and benchmark receipts retain their recorded builds.

Evidence and acceptance

Owner: @flyingrobots. Oracles: existing specified public storage, no-follow and typed-refusal laws, generated conformance/model checks, and reopened-state crash campaigns. Small in-memory and medium filesystem/subprocess classifications retain their current resource-enforcement limitations in docs/testing/enforcement.md; Docker alone does not supply per-test memory/egress ceilings. No test or assertion is changed, so no fabricated product RED or new resource waiver is claimed. The inherited #179 execution-profile decision remains a separate required gate.

The published old/new cap-std and cap-primitives package source is available for independent review. Cargo updated the fuzz lock with only the two capability version/checksum changes. Exact archived source and synthetic Docker tree are checked before full validation. The complete required local chain completed with exit 0 at this exact tree: Golden, both crash campaigns, conformance, format/structure, both feature checks/Clippy, debug/release workspace tests, doctests/docs, pinned compiler and separately locked fuzz checks. Pinned Markdown validation passes. An expired documentation container initially ran no check; it was restarted and that original setup failure remains recorded. Independent exact-head review found no new implementation defect, and all four final hosted jobs pass in run 37167906610. Overall acceptance still requires #179's separate policy disposition, prerequisite landing and final actual-main/head confirmation. No host tests, physical power-loss proof, rollback claim or broad filesystem audit is substituted.

Bumps [cap-std](https://github.com/bytecodealliance/cap-std) from 4.0.2 to 4.0.3.
- [Commits](sunfishcode/cap-std@cap-std-v4.0.2...cap-std-v4.0.3)

---
updated-dependencies:
- dependency-name: cap-std
  dependency-version: 4.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Dependency and supply-chain maintenance label Aug 30, 2026
@dependabot
dependabot Bot requested a review from flyingrobots as a code owner August 30, 2026 04:22
@dependabot dependabot Bot added the dependencies Dependency and supply-chain maintenance label Aug 30, 2026
@flyingrobots

Copy link
Copy Markdown
Owner

Code Lawyer — capability dependency admission

Change kind: deliberate dependency upgrade. The integration preserves cap-std 4.0.3 and Rustix 1.1.5 when resolving their adjacent manifest conflict. #93 is prepared against #102/#179, independently of #94; the BLAKE3 upgrade is not a correctness prerequisite for this capability update.

Severity Location Verified issue Acceptance
P2 fuzz/Cargo.lock The separately locked fuzz workspace still selects cap-std/cap-primitives 4.0.2 while root/xtask pins require cap-std 4.0.3. Cargo-generated lock update selects both 4.0.3 packages with matching root checksums and passes locked fuzz checks.
P3 docs/dependencies/cap-std-and-cap-fs-ext-4.0.2.md Current admission describes the old cap-std/cap-primitives versions. Renew admission for cap-std/cap-primitives 4.0.3, unchanged cap-fs-ext 4.0.2 and reviewed Rustix 1.1.5; verify no-follow path semantics and retain existing error/effect boundaries.
P4 deny.toml winx comment The explanatory comment names cap-primitives 4.0.2 after the graph updates. Correct the coordinate without broadening the existing exact-package license exception.

Published cap-std runtime source is unchanged. The cap-primitives runtime delta removes re-appending a trailing slash before the guarded component open, retaining directory-required and no-follow handling; this needs source and existing public-contract validation, not checksum-only acceptance. No runtime defect in Keep or new regression test is claimed from this inspection.

@codex Please review the finite dependency/admission scope.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1fbf4fa7-c5dd-4844-a1ed-2973fe203fa5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner

Independent review: Keep PR #93

Reviewed exact clean head 44c736c251ad121f69f217452540c98fa989cb33, tree f5faff4dfa253c4e8e6b704ddcab9463e4dfddb3, targeting main 3165890e9291cfb5fe10e81a9d7cd151f3e59464. Live GitHub agrees. This is the explicitly authorized independent Codex fallback applying the complete supplied agy-review protocol. No source edits, host tests, duplicate Docker test runs, subagents, configuration changes, publication or Git mutations occurred. Only this report was written.

Findings and acceptance

No new demonstrated P0–P5 implementation defect in the finite dependency, admission and merge-integration scope. The root and separately locked fuzz graph agree on cap-std/cap-primitives 4.0.3; cap-fs-ext 4.0.2, Rustix 1.1.5, selected features and the exact winx exception remain. The published cap-std runtime source is byte-identical, and the cap-primitives manual resolver correction retains directory requirements, bounded explicit symlink handling, capability confinement and original error propagation. Keep's caller checks were inspected rather than inferred from package checksums.

Source-review outcome supports approval; overall acceptance remains blocked by inherited policy and prerequisite gates. docs/testing/enforcement.md:11,21,49-51,61 still requires disposition of #179's changed medium-test execution profile. Its missing per-test memory/egress/resource/suite-measurement controls are disclosed, but no scoped approving-maintainer waiver is recorded. #106's unrelated waiver cannot discharge that requirement. #179 and #102 remain prerequisite landing gates, and #93's final hosted Rust/fuzz checks remain pending at inspection. These are not new defects caused by cap-std 4.0.3 and do not justify unrelated storage hardening. The coordinator must confirm exact-head final checks and the actual merged prerequisite tree before landing.

Verification Checklist

Complete finite diff and every merge

  • Read the complete actual-main delta: 16 files, including the inherited Rustix pins/admission, locator-test executable and mechanism evidence. The Build(deps): Bump cap-std from 4.0.2 to 4.0.3 #93 delta against reviewed prerequisite 11bc72c41cc379944766adbdef60f046e786b820 contains only root/xtask cap-std pins, two capability versions/checksums in each lockfile, admission rename/rewrite, winx explanatory comment and changelog. src/, tests/, xtask/src/ and repository-process-spawn/src/ have zero Build(deps): Bump cap-std from 4.0.2 to 4.0.3 #93 delta against that prerequisite. Existing assertions and production protocols remain byte-identical. Whitespace diff check passes.
  • Audited merge f50666f4f29871d48389fef060e8f5ba47ccb3f6, parents original capability candidate e4ec66796522e85a59bcfedc02f25c3895528817 and 11bc72c41cc379944766adbdef60f046e786b820. Against second parent, exactly Cargo.toml, Cargo.lock and xtask/Cargo.toml carry the original capability update. Against first parent, the newer target and reviewed Rustix/locator changes are inherited. The sole combined conflict resolution is Cargo.toml's adjacent pins: cap-std =4.0.3 and rustix =1.1.5 both survive with their original feature flags. No Keep implementation is uniquely rewritten. BLAKE3 remains 1.8.5; Build(deps): Bump blake3 from 1.8.5 to 1.8.7 #94 is not inherited or a correctness prerequisite.
  • Audited inherited merge 11bc72c41cc379944766adbdef60f046e786b820, parents afb5f000c2803c9226d7678ce0905d676723e474 and f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a. Against first parent, exactly Fix: isolate locator subprocesses from golden writer handoffs #179's eight files are inherited; against second, exactly Build(deps): admit rustix 1.1.5 across runtime and tooling #102's seven files differ. Combined CHANGELOG resolution preserves both entries. Locator law bodies, shared fixture, layout assertions, selectors, scratch and production locks are unchanged. Read the complete 102-integration-review.md and 179-independent-review.md; their resource-policy and causality limits remain binding.
  • Audited inherited merge 9842616a5f12e7920f6737fb63c7b5710f27f0fc, parents original Rustix candidate ece94b7bb9d318ea8629195cc5626328c2acfa58 and newer target fa3c2b56991e0ff5ceff909c959afdafef4815ca. Against target parent, only three direct Rustix pins and root lock version/checksum differ; no unique combined-resolution hunk exists. Main 3165890 has the reviewed target tree. Read the complete 102-independent-review.md, including its upstream/cfg, older target-merge and process-path checklist. The imported target's hundreds of historical changes are not recertified by this finite upgrade; parent preservation proves no extra semantic resolution was introduced.
  • Final successor 44c736c repairs the separately locked fuzz mismatch, renews admission and updates the exact winx coordinate without implementation/assertion changes. Earlier P2/P3/P4 obligations in 93-findings.md and the live author comment are closed in source. Locked fuzz checks completed in the exact-tree validation receipt. Their completion is not represented as a bug-regression RED or new assertion calibration.

Every changed upstream path and selected production routing

  • Compared complete published old/new package trees and normalized/original manifests, not just the supplied src diff. cap-std changes are package/VCS/lock metadata and its compatible cap-primitives requirement ^4.0.2 → ^4.0.3; all src bytes are unchanged. cap-primitives changes are package/VCS metadata, manual normal path handling, and two cfg-preserving reexport ordering edits in src/fs/mod.rs:64-80. No dependency/feature addition exists in those manifests.
  • cap-std 4.0.3 src/fs/dir.rs:89-104 → cap-primitives src/fs/open.rs:14-21 → Linux src/rustix/linux/fs/open_impl.rs:27-49,56-131. Linux first attempts openat2 with BENEATH/NO_MAGICLINKS. Unavailable/blocked/exhausted retry cases retain the existing manual fallback; other errors retain their sources and XDEV becomes an escape refusal. Four EAGAIN attempts at :84 are unchanged upstream policy, explicitly an arbitrary guess in its source, not a Keep-measured latency threshold.
  • Manual src/fs/manually/open.rs:23-26,69-128,210-295: trailing slash still sets dir_required; intermediate components use directory options; final options retain the required-directory bit. The changed call at :228-234 sends the component without an appended slash, with FollowSymlinks::No and dir_required. src/rustix/fs/oflags.rs:5-55 translates these to CLOEXEC/NOFOLLOW/DIRECTORY and preserves NONBLOCK. src/rustix/fs/open_unchecked.rs:12-58 preserves ELOOP/EMLINK/EFTYPE, NOTDIR symlink classification, NOENT and other original I/O causes.
  • Explicit symlink traversal remains manually/open.rs:239-255,267-280,298-382 → bounded read_link_one → component admission at :413-419. Absolute destinations refuse at PrefixOrRootDir; ParentDir cannot escape the retained directory stack at :184-205. For a final ordinary component, FollowSymlinks::No refuses at :376-379. A trailing slash intentionally still permits explicit symlink resolution at :376-382; no universal NO_SYMLINKS guarantee is inferred from that flag. Keep's protocol directory/file names do not carry trailing slashes, and regular-file callers independently refuse directory results. Keep's strict production root admission uses its own NO_SYMLINKS path, not this permissive fallback.
  • Directory API path: cap-fs-ext 4.0.2 src/dir_ext.rs:319-323 → cap-primitives src/fs/open_dir.rs:33-36 → the same open resolver with dir_options/FollowSymlinks::No. Its manifest's compatible 4.0.2 capability requirements admit locked 4.0.3. The published extension package and its features are unchanged. Ambient root opening at cap-std dir.rs:703-708 uses the separate unsandboxed ambient directory path; that unchanged entry does not itself prove strict production eligibility.
  • Parallel upstream selection: Linux/Android fallback at rustix/linux/fs/open_impl.rs:37-49; FreeBSD capability-support fallback at rustix/freebsd/fs/open_impl.rs:8-30; Windows device-name refusal then manual route at windows/fs/open_impl.rs:7-29; other Unix manual route through rustix/fs/mod.rs. Windows unchecked directory/reparse admission at windows/fs/open_unchecked.rs:161-204 and manual directory/file symlink handling at manually/open.rs:270-280 retain platform-specific rules. These are inspected source paths, not claims that all upstream platforms or forced Linux fallback were executed.

Keep runtime and tooling caller checklist

The following finite capability consumer families converge on the inspected upstream entry points. No unjustified parallel-rule divergence was found; deliberate production/test authority differences are recorded.

Behavior and caller path Checked boundary and retained rule
Production initialization/reopen: filesystem_initialization_storage.rs:25-26, filesystem_store_initializer.rs:32-54 → filesystem_platform_profile.rs:42-56,114-166 Keep's safe Rustix root path requires no symlinks, readable directory, writable non-casefolded Linux ext4, protocol-directory device/mount identity; cap handles are retained. Unsupported production platforms refuse. Test/repository-only ambient roots remain separately gated.
Version-two writer/reader: filesystem_version_two_admission.rs:51-54,81-110 and retention/filesystem_retention_snapshot.rs:148-176 Both use production v2 profile and namespace/marker/intent/receipt/root identity admission; writer obtains authority, reader obtains persistent shared fence. open_dir_nofollow pins retention/roots/manifests. Restart-stable device/inode and same-process mount identity remain distinct.
Writer acquisition: filesystem_writer_lock.rs:72-93,107-129 → :136-170 → :173-220 Retains root and lock handles, root-then-file nonblocking locks, regular-file admission, re-opened lock identity. Only would-block becomes Busy; other exact phases retain sources. Initialization exclusive-create/sync and reopen non-creation remain separate.
Sync-capable namespace opens: sync_capable_directory.rs:10-24 → caller filesystem_catalog_publisher.rs:59-78, initialization_storage :58-71 and recovery_namespace :21-56 Explicit no-follow/nonblocking, post-open directory kind, retained descriptors and namespace identity. Opening readable . from an O_PATH root does not reopen an ambient pathname. The legacy repository publisher still performs production eligibility admission.
Catalog/head/segment publication: filesystem_catalog_artifact.rs:17-30,33-103 and publisher :59-78 → catalog_restart_io.rs:17-34 Exclusive no-follow/nonblocking stages; regular, length-bounded verified artifacts; explicit file/directory sync and unchanged publication ordering. Restart loader catalog_restart_loader.rs:33-86 and segment loader catalog_restart_segments.rs:61 use the same file rules and no-follow pools.
Shared exact records: filesystem_exact_record.rs:132-166,173-189,220-258 → v2 records :75, retention current :283-292 and catalog :34-76 No-follow/nonblocking opens, exact regular kind/length/EOF, checked length conversion, retained device/inode and before/after bytes where required. Optional absence admits only NotFound; other original failures remain available.
Recovery inventory/discard: filesystem_recovery_inventory_reader.rs:48-90, filesystem_recovery_stage_discarder.rs:38,79-90 → recovery namespace :21-56 and recovery stage :165-250 Production profile, retained writer authority, canonical namespaces, streamed fingerprint and reopened stage identity/length. filesystem_recovery_stage_discard_storage.rs:97-127 reverifies evidence before pathname unlink; this does not make unlink inode-conditional against raw concurrent mutation.
Migration inventory/recovery: store_migration/filesystem_migration_recovery.rs:42-73, filesystem_inventory_directory.rs:26-60, filesystem_inventory_file.rs:82,115 → shared directory/record APIs Production profile and authority, namespace device/mount/inode, regular bounded exact artifact reads and pre-effect refusal. Repository-only root entry remains separately gated. Existing failed-effect uncertainty and restart observation remain.
Migration/reader fences: store_migration/filesystem_migration_reader_fence.rs:12-46 and retention/reader_fence.rs:35-69 Create/open use no-follow/nonblocking and require matching regular zero-length entry/handle identity. Snapshot flock waits deliberately for collection, then reverifies; migration's read-write handle has a different purpose, not weaker identity admission.
Retention pool/namespace readers: retention/filesystem_retention_snapshot.rs:158-176,237-265,320, current :203-251, storage :130,274-294, recovery observation :62,123 Validated pool names and no-follow directory APIs converge on shared exact records. Existing namespace identity/regular-kind/bounds checks remain; no automatic incomplete-stage disposition was introduced.
Repository inventory/source/docs: xtask/src/repository_file.rs:95-143,170-183 → callers source_structure and documentation_integrity Retained root identity versus fresh configured-path identity, explicit no-follow/nonblocking and post-open regular kind. Descriptor duplication :116-118,152-155 → repository-process-spawn/src/lib.rs:23-32 retains exact child cwd; parent cwd never changes.
Protocol conformance corpus: xtask/src/protocol_conformance/corpus.rs:45-95,107-168 Retained corpus root, validated relative paths, no-follow/nonblocking regular files, checked maximum+1 and observed exact length. Source and table routes use the same policy.
Golden corpus: xtask/src/golden_file_worldline/corpus_protocol.rs:43-109,133-157,226-258 Same no-follow/nonblocking regular-file policy for tables and sources, validated relative paths, bounded reads and exact observed length; no renamed alternative path weakens the source open.
Fuzz corpus source/publication: xtask/src/fuzz_seed_corpus/filesystem.rs:40-74,100-205,231-258 No-follow/nonblocking regular source reads with checked bounds; no-follow target directories; exclusive regular stage creation, write/sync/rename, explicitly partial batch and best-effort failure cleanup. Derived corpus has no claimed containing-directory power-loss sync.
Bounded process effects/errors: xtask/src/bounded_process/capture.rs:69-79,172-229 → input :25-84 and cleanup :14-42 → process_group :18-33 Existing retained cwd and Rustix 1.1.5 process paths, nonblocking partial writes, complete deadline/interruption, process-group cleanup and typed additional cleanup failures remain. Cap upgrade adds no cancellation/shutdown state machine or retry policy.
Inherited locator correction: tests/durable_locator.rs:8-11 → new suite :3-16 → unchanged durable_locator_laws.rs:23-59 Parent holds no store/authority, exact CHILD plus argument admission executes one serial law per child, shared source and selectors unchanged. Golden suite :30-35 excludes locator child creation. Exact Locator/NOENT Error::source, original-store bytes and layout refusal/sentinel remain. The original hosted handoff trace is unobserved.

Constants, every changed number and binding evidence

  • Both lockfiles contain the same unique capability records: cap-primitives 4.0.3 checksum 8b5f74729fd2f44701d1a8eb47e906cdb3ccd9ec0f02baad85a744b791940b18; cap-std 4.0.3 checksum c1ec78e242cfa2cfe276807ac2ecc00315a6c97786977414bcd1c3963b6c91b8. Root/xtask exact pins disable defaults; cap-fs-ext remains 4.0.2 with std; Rustix remains 1.1.5 with existing direct fs/std and xtask process features. No opportunistic lock drift against Build(deps): admit rustix 1.1.5 across runtime and tooling #102 exists. Original old checksums match supplied published-package lock metadata; new package checksum authentication was not independently re-downloaded by this reviewer. Actual locked builds inspect the selected graph rather than merely matching prose.
  • Every number in renewed admission docs/dependencies/cap-std-4.0.3-and-cap-fs-ext-4.0.2.md:1-82 checked: original 2026-07-26 admission date, 2026-10-03 renewal dates/Build(deps): admit rustix 1.1.5 across runtime and tooling #102/Build(deps): Bump cap-std from 4.0.2 to 4.0.3 #93, direct versions, and ambient-authority 0.0.2, bitflags 2.13.1, errno 0.3.14, fs-set-times 0.20.3, io-extras 0.19.0, io-lifetimes 2.0.4/3.0.1, ipnet 2.12.0, libc 0.2.186, linux-raw-sys 0.12.1, maybe-owned 0.3.4, once_cell 1.21.4 and rustix-linux-procfs 0.1.1 agree with both lockfiles. Winx 0.36.4 and its exact LLVM license exception remain unchanged at deny.toml:21-22. Published Rustix old/new floors 1.63/1.65 remain the previously inspected metadata; Keep is pinned 1.96.0. Neither capability manifest declares a floor. These are coordinates/compatibility metadata, not current measurements.
  • Changelog :11-15 preserves all three distinct capability/Rustix/locator entries and their issue linkage. No benchmark, throughput, allocation, all-platform equivalence or new latency claim was added. Admission :70,82 explicitly keeps old recovery/crash/benchmark receipts attached to their recorded builds. README and other existing historical measurement pages have zero Build(deps): Bump cap-std from 4.0.2 to 4.0.3 #93 diff; their unrelated figures are not freshly re-audited as current-release measurements.
  • Four upstream EAGAIN attempts and existing symlink traversal bound are unchanged; no recorded Keep performance receipt makes them a measured threshold. Directory/no-follow/CLOEXEC/NONBLOCK values are protocol/OS semantics, not empirical tuning. The changed resolver adds no timing/buffer/resource constant. No absent distribution was invented to justify a parameter change.
  • Relevant inherited process constants remain ten-millisecond poll, two-second cleanup grace, 1 MiB default per-stream capture, 4096-byte output scratch, one worker result, two-minute Git/doc deadlines, 16 MiB Git path stream and 64 KiB diagnostics. Source at bounded_process capture :15-16, input :12, reader :12, cleanup :11-12, git_inventory/process :15-18 and documentation_integrity/execution :20 agrees with ADR-0007:29-35 and ADR-0008:29-46. These are fixed contractual ceilings, not new measured overhead/SLO claims; no bound changed.
  • Existing profile constants are three v1/nine v2 protocol directories and ext4/casefold UAPI values (filesystem_platform_profile.rs:11,18-28,287-288), with strict production mount identity at :203-239. Existing exact EOF scratch is one byte and reader-fence length is zero. Public-stage historical evidence :14 gives 64-byte header + 128-byte seal =192 minimum and observed64; :35's 1 GiB/30-second experiment is historical additional resource evidence, not current per-test enforcement. Catalog-platform evidence binds actual readable ext4 descriptors and refusal of tmpfs authority. No format size or storage threshold changed.
  • Locator evidence durable-locator-isolation.md:7-29 remains historical: hosted 51 passed +1 failed=52; exactly two locator laws move, leaving50 golden laws. Existing20-second watchdog at locator source :46-47 matches evidence :27. The controlled probe's historical rustix1.1.4/Rust1.96.0 graph and3.14-second build output are not relabeled as measurements of this upgraded graph. The receipt demonstrates an inherited descriptor schedule, not the exact hosted trace, universal race freedom or assertion calibration for an unchanged layout oracle. Read all three imported plaintext artifacts; unsafe/printing remain outside executable Cargo source.
  • Current debug receipt 93-validation.log:515,696-758 reports402 library laws and2 locator/50 golden laws. These counts inventory execution and cannot prove storage correctness. Printed elapsed times are observed durations, not acceptance ceilings. Historical reader-fence process evidence retains its two fixed schedules, exact EWOULDBLOCK, SIGKILL/reap, inode/zero-length and20-second watchdog; no dependency change expands that schedule or power-loss coverage.

Repository standards, state transitions and evidence subjects

  • Read applicable AGENTS.md, Testing Standards, enforcement profile, documentation standards and relevant process/recovery decisions. PR body declares deliberate dependency upgrade, owner @flyingrobots, specified storage/no-follow/typed-refusal oracles, existing generated/model and reopened-state crash evidence, debug/release and honest resource classes. No new assertion or expected product behavior is edited; fabricated regression RED/mutation would misstate this change. New parser campaigns or performance benchmarks are not needed to support a new claim because no parser/format/performance claim changes here.
  • Dependency justification, disabled defaults, committed locks and original exact license policy are preserved. Dependencies remain confined to filesystem/process adapters and tools; no public dependency-owned type, identity preimage, canonical codec, durable format, sync protocol or recovery decision changes. The renewed admission is the appropriate local rationale; no unrelated cross-subsystem ADR is introduced.
  • Original I/O causes remain carried by typed open/inspect/verify/fingerprint/lock/process phases. Existing nested io::Error wrappers are not falsely claimed absent, but no new stringify/swallow/re-wrap path is introduced by this graph change. Checked read ceilings and regular/identity admission remain. Init interruption, publication death, restart recovery and migration uncertainty follow existing explicit commit/recovery protocols; a read handle never certifies complete content by existence alone.
  • Recovery admission :78-80 agrees with docs/adr/retention-bounded-recovery-landing.md:5-13: cooperating writers only; checked retained handles are not inode-conditional unlink/rename; incomplete retained stages preserved; pre-effect refusal distinct from execution error after effects/uncertain sync; no rollback or automatic disposal promise. Failing effects stop further execution and later attempts observe again. No stronger arbitrary-raw-mutation guarantee is smuggled into dependency admission.
  • Changed admission paragraphs use one physical line per coherent paragraph; no stale old admission link remains in a whole-tree search. Reformatting preserves existing admission obligations while adding the semantic correction and limits. Markdown/static validation is tooling evidence, never a product oracle. No file/function structure restriction is newly exceeded by runtime source because no runtime source changes.
  • Read complete initial queue, published author findings and PR body. Live Build(deps): Bump cap-std from 4.0.2 to 4.0.3 #93 has three comments (author's finite closure obligations, Codex quota notice, CodeRabbit skip), zero reviews and zero threads; every GraphQL connection has hasNextPage=false. There are no nested thread pages to omit. Neither skipped automation nor review quota is approval. Recheck feedback that arrives after this observation.

Executed, inspected, skipped and pending

Executed by this reviewer: read-only exact Git status/head/tree/full diff/parent/combined-resolution/byte-preservation/whitespace inspection; complete supplied published old/new package comparisons; caller/source/standard/evidence inspection; lock-coordinate extraction; live paginated GitHub metadata/comment/review/thread/check queries. No host builds, tests or lints were run. The authorized Codex fallback was used directly; agy was not independently re-invoked and no subagent was spawned.

Inspected, not independently executed: exact copied-Docker full chain 93-validation.log:1-4575 and 93-copy-attestation.log. Header pins tree f5faff4, Rust1.96.0, Linux aarch64 and real ext4 scratch; separate source/Cargo scratch bindings are attested. Traced chain includes golden, debug/release process-death crash matrix, conformance, source structure, formatting, workspace feature checks and strict feature-matrix Clippy, debug/release workspace tests, doctests/docs, pinned compiler and locked fuzz formatting/build/Clippy. Final fuzz Clippy finishes at :4573-4575; coordinator confirmed owned session50965 terminated exit0 on the unchanged exact tree. This receipt is current-candidate validation; earlier #102 successes remain historical evidence for their own SHA.

93-markdown-live.log:1-4 records real pinned markdownlint-cli2 0.23.3/markdownlint0.41.1,169 Markdown files and zero issues. Preserved 93-markdown.log only reports that the previous owned container had expired; no checker ran in that attempt. It is neither lint RED nor product RED. No failure was replaced by a success artifact.

Pending landing checks at inspection: exact-head hosted run37167906610 documentation/workflow and dependency policy SUCCESS; Rust quality and runtime fuzz IN_PROGRESS. Independent source review does not replace required protections, advisory output or terminal hosted results. #179's unapproved policy disposition and #179/#102 actual integration remain separate gates; coordinator owns final state/protection/head checks.

Explicit limitations: static fallback/platform tracing does not establish execution of every upstream OS or forced Linux manual route; no all-platform equivalence, upstream unsafe-code certification, physical power-loss experiment, exhaustive concurrency/fault state space, new performance distribution, resource-policy compliance or universal absence-of-Busy is claimed. Existing finite exact-byte/refusal/model/crash laws are evidence, not absence proof. No mandatory changed-source-path static-review area remains blocked within the finite scope. Overall acceptance remains blocked by inherited policy/prerequisite/final-hosted gates rather than a newly demonstrated capability implementation defect.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner

Code Lawyer activity — prepared candidate

Exact local and pushed head: 44c736c251ad121f69f217452540c98fa989cb33; tree f5faff4dfa253c4e8e6b704ddcab9463e4dfddb3.

Item Source Disposition and evidence
P2 stale fuzz graph Code Lawyer Corrected by 44c736c; Cargo updates only cap-std/cap-primitives versions/checksums, and locked fuzz build/Clippy plus hosted dependency policy pass.
P3 old capability admission Code Lawyer Renewed at 44c736c against published package source and actual callers, preserving selected features and bounded recovery/concurrency limits.
P4 winx explanatory coordinate Code Lawyer Corrected at 44c736c; exact license exception unchanged.
Adjacent manifest conflict Integration f50666f Both cap-std 4.0.3 and reviewed Rustix 1.1.5 pins/features retained; complete parent diff inspected.
Independent review Full exact-head report No new demonstrated implementation defect; complete path, merge, constant and evidence checklist supports source approval. Overall acceptance retains the distinct prerequisite/policy gates.
Local validation Exact copied tree Full required Docker chain exited 0, including both crash campaigns, conformance, feature-matrix Clippy, debug/release workspace tests, docs/MSRV and locked fuzz checks. Pinned Markdown passes. Original expired-container setup refusal remains recorded.
Hosted validation Run 37167906610 All four required jobs pass at this exact head. CodeRabbit bot-skip is not independent approval.
Landing gate #179 and #102 #179's separate resource-policy disposition remains unapproved; #106's waiver is not extended. Prerequisites must land and actual-main integration must retain the reviewed result with final review/protection checks before merge.

No Keep source, expected runtime outcome, identity, format or recovery protocol is changed by this dependency upgrade. No product RED, universal platform equivalence, physical power-loss proof or performance improvement is claimed. #94 is not a correctness prerequisite for this change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency and supply-chain maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant