Repository navigation
Build(deps): Bump cap-std from 4.0.2 to 4.0.3 - #93
dependabot[bot] wants to merge 9 commits into
Conversation
Bumps [cap-std](https://github.com/bytecodealliance/cap-std) from 4.0.2 to 4.0.3. - [Commits](sunfishcode/cap-std@cap-std-v4.0.2...cap-std-v4.0.3) --- updated-dependencies: - dependency-name: cap-std dependency-version: 4.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rustix](https://github.com/bytecodealliance/rustix) from 1.1.4 to 1.1.5. - [Release notes](https://github.com/bytecodealliance/rustix/releases) - [Changelog](https://github.com/bytecodealliance/rustix/blob/main/CHANGES.md) - [Commits](bytecodealliance/rustix@v1.1.4...v1.1.5) --- updated-dependencies: - dependency-name: rustix dependency-version: 1.1.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
…102-rustix # Conflicts: # CHANGELOG.md
…#93) # Conflicts: # Cargo.toml
Code Lawyer — capability dependency admissionChange kind: deliberate dependency upgrade. The integration preserves cap-std 4.0.3 and Rustix 1.1.5 when resolving their adjacent manifest conflict. #93 is prepared against #102/#179, independently of #94; the BLAKE3 upgrade is not a correctness prerequisite for this capability update.
Published cap-std runtime source is unchanged. The cap-primitives runtime delta removes re-appending a trailing slash before the guarded component open, retaining directory-required and no-follow handling; this needs source and existing public-contract validation, not checksum-only acceptance. No runtime defect in Keep or new regression test is claimed from this inspection. @codex Please review the finite dependency/admission scope. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Independent review: Keep PR #93Reviewed exact clean head Findings and acceptanceNo new demonstrated P0–P5 implementation defect in the finite dependency, admission and merge-integration scope. The root and separately locked fuzz graph agree on cap-std/cap-primitives 4.0.3; cap-fs-ext 4.0.2, Rustix 1.1.5, selected features and the exact winx exception remain. The published cap-std runtime source is byte-identical, and the cap-primitives manual resolver correction retains directory requirements, bounded explicit symlink handling, capability confinement and original error propagation. Keep's caller checks were inspected rather than inferred from package checksums. Source-review outcome supports approval; overall acceptance remains blocked by inherited policy and prerequisite gates. Verification ChecklistComplete finite diff and every merge
Every changed upstream path and selected production routing
Keep runtime and tooling caller checklistThe following finite capability consumer families converge on the inspected upstream entry points. No unjustified parallel-rule divergence was found; deliberate production/test authority differences are recorded.
Constants, every changed number and binding evidence
Repository standards, state transitions and evidence subjects
Executed, inspected, skipped and pendingExecuted by this reviewer: read-only exact Git status/head/tree/full diff/parent/combined-resolution/byte-preservation/whitespace inspection; complete supplied published old/new package comparisons; caller/source/standard/evidence inspection; lock-coordinate extraction; live paginated GitHub metadata/comment/review/thread/check queries. No host builds, tests or lints were run. The authorized Codex fallback was used directly; agy was not independently re-invoked and no subagent was spawned. Inspected, not independently executed: exact copied-Docker full chain
Pending landing checks at inspection: exact-head hosted run37167906610 documentation/workflow and dependency policy SUCCESS; Rust quality and runtime fuzz IN_PROGRESS. Independent source review does not replace required protections, advisory output or terminal hosted results. #179's unapproved policy disposition and #179/#102 actual integration remain separate gates; coordinator owns final state/protection/head checks. Explicit limitations: static fallback/platform tracing does not establish execution of every upstream OS or forced Linux manual route; no all-platform equivalence, upstream unsafe-code certification, physical power-loss experiment, exhaustive concurrency/fault state space, new performance distribution, resource-policy compliance or universal absence-of-Busy is claimed. Existing finite exact-byte/refusal/model/crash laws are evidence, not absence proof. No mandatory changed-source-path static-review area remains blocked within the finite scope. Overall acceptance remains blocked by inherited policy/prerequisite/final-hosted gates rather than a newly demonstrated capability implementation defect. REQUEST CHANGES |
Code Lawyer activity — prepared candidateExact local and pushed head:
No Keep source, expected runtime outcome, identity, format or recovery protocol is changed by this dependency upgrade. No product RED, universal platform equivalence, physical power-loss proof or performance improvement is claimed. #94 is not a correctness prerequisite for this change. |
Problem and outcome
Change kind: deliberate dependency upgrade. Update cap-std and resolved cap-primitives from 4.0.2 to 4.0.3 across the library, repository tasks and separately locked fuzz workspace. Keep cap-fs-ext 4.0.2 and existing features. Renew the capability dependency admission and exact winx exception's explanatory coordinate without broadening policy.
Candidate
44c736c251ad121f69f217452540c98fa989cb33, treef5faff4dfa253c4e8e6b704ddcab9463e4dfddb3, follows integrationf50666f4f29871d48389fef060e8f5ba47ccb3f6: original Dependabote4ec66796522e85a59bcfedc02f25c3895528817merged #102's11bc72c41cc379944766adbdef60f046e786b820. The sole conflict was adjacent root dependency lines; the resolution retains both cap-std 4.0.3 and Rustix 1.1.5. #179 and #102 must clear their separate gates and land before this prepared stack. #94 is independent and is not a prerequisite.Contract and scope
Published cap-std runtime source is unchanged. The cap-primitives manual resolver no longer re-appends a trailing slash before the guarded component open; directory-required and explicit symlink handling remain. Existing public filesystem profile, no-follow, identity, exact-byte, namespace and typed-corruption rules remain required. No Keep source, test expectation, public API, on-disk format, identity or recovery protocol changes.
The supported mutation model remains cooperating writers under Keep authority. An open handle or metadata check does not make pathname unlink/rename conditional on inode identity against arbitrary concurrent raw mutation. Pre-effect refusal remains distinct from execution failure after namespace effects or uncertain synchronization; the dependency upgrade does not promise rollback or automatic disposal of incomplete retention stages.
Alternatives rejected: stale fuzz resolution, relaxed pins, broader features/license exceptions and checksum-only acceptance. The risk is changed OS path resolution; review must trace actual selected paths and caller checks. No performance improvement or new all-platform isolation guarantee is claimed. Historical crash and benchmark receipts retain their recorded builds.
Evidence and acceptance
Owner: @flyingrobots. Oracles: existing specified public storage, no-follow and typed-refusal laws, generated conformance/model checks, and reopened-state crash campaigns. Small in-memory and medium filesystem/subprocess classifications retain their current resource-enforcement limitations in docs/testing/enforcement.md; Docker alone does not supply per-test memory/egress ceilings. No test or assertion is changed, so no fabricated product RED or new resource waiver is claimed. The inherited #179 execution-profile decision remains a separate required gate.
The published old/new cap-std and cap-primitives package source is available for independent review. Cargo updated the fuzz lock with only the two capability version/checksum changes. Exact archived source and synthetic Docker tree are checked before full validation. The complete required local chain completed with exit 0 at this exact tree: Golden, both crash campaigns, conformance, format/structure, both feature checks/Clippy, debug/release workspace tests, doctests/docs, pinned compiler and separately locked fuzz checks. Pinned Markdown validation passes. An expired documentation container initially ran no check; it was restarted and that original setup failure remains recorded. Independent exact-head review found no new implementation defect, and all four final hosted jobs pass in run 37167906610. Overall acceptance still requires #179's separate policy disposition, prerequisite landing and final actual-main/head confirmation. No host tests, physical power-loss proof, rollback claim or broad filesystem audit is substituted.