Skip to content

Build(deps): Bump blake3 from 1.8.5 to 1.8.7 - #94

Open
dependabot[bot] wants to merge 12 commits into
mainfrom
dependabot/cargo/blake3-1.8.7
Open

dependabot[bot] wants to merge 12 commits into
mainfrom
dependabot/cargo/blake3-1.8.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem and outcome

Change kind: deliberate dependency upgrade. Update in-process BLAKE3 1.8.5 to 1.8.7 across the library, xtask and separately locked fuzz workspace, remove the now-unused arrayref license exception, and renew the exact dependency admission. The external b3sum oracle remains pinned at 1.8.5 and committed identity expectations are unchanged.

Candidate 9a7a46ec6d5043f61222c2f75fc7c49a16002cd3, tree 9de5045171b4a779456a66ebc9b7cc96125c372b, merges original Dependabot head 6ba2c1f389d64df570bbea1c81f196bb7f298796 with #102's integrated 11bc72c41cc379944766adbdef60f046e786b820 in f9b75f45da022a1eeb9a9d1c83c9525aea08fa3c. Admission/fuzz corrections are 6ee556532d68db6bb5ab6e97f6af2da6d6059cd7; subsequent documentation commits fix one trailing blank line and the independent review's caller/target-graph admission findings. This temporary stack waits for #179 and #102 to clear their independent gates and land. Their unmerged changes are not claimed as #94 work.

Invariant, scope and alternatives

Version-one blob/chunk identities must continue to name exactly the same bytes; any identity mismatch remains a refusal. Existing streaming bounds, typed errors, durable encodings, writer/recovery protocols and public APIs retain their contracts. The admitted features remain exactly std and pure. Upstream's arrayref replacements require review of fixed lengths and mutable partitions; the mmap behavior changes are outside admitted features and calls. No faster implementation path is enabled.

Alternatives rejected: stale fuzz resolution, changing golden expectations, updating the external oracle merely to agree, adding features or accepting a dependency solely from a checksum. No performance improvement is claimed. Existing benchmark results are historical; current benchmark execution and compatibility checks remain required. Upstream cites an arrayref owner compromise as its removal rationale; no claim is made that previously locked 0.3.9 bytes were compromised.

Evidence and limitations

Owner: @flyingrobots. Product oracles are the existing specified identity vectors, generated preimage/digest comparisons with external b3sum, streaming/property laws, typed corruption refusals and reopened-state crash campaigns. These assert runtime outcomes; dependency policy and document checks are separate tooling/static evidence. Existing small in-memory and medium filesystem/subprocess test classifications do not imply automated per-test resource enforcement; gaps remain recorded in docs/testing/enforcement.md. This PR claims no new assertion calibration, exhaustive platform coverage or physical power-loss evidence.

The existing process-policy static test changes only its include_str path to follow the renamed admission document; its assertions and execution profile are unchanged. It remains static document-policy evidence, not proof of storage behavior. No user waiver is generalized to this PR.

The copied Docker source for 6ee5565 has tree deaaa8ba81318296516310b49d81f12f0ca7f546, verified against the synthetic Git source copy. The full required local chain completed with exit 0: Golden Worldline, debug/release crash campaigns, conformance, structure, formatting, all/minimal checks and Clippy, debug/release workspace tests, doctests/docs, pinned compiler and locked fuzz checks. Final candidate changes since that run affect only admission prose; no runtime byte or assertion changes. Initial MD012 and its corrected repository-wide Markdown success are retained.

Full independent review found no demonstrated runtime defect and identified two admission-document inaccuracies. They are corrected in 6c4019b and 9a7a46e: the conditional cpufeatures graph/dispatch/compiler/license metadata and the actual streaming, cloned-state, production one-shot and tool-provenance callers. Exact-head delta confirmation closes both findings and approves the source. All four final-head required CI jobs pass in run 37167535271; earlier-head results were not transferred.

Local benchmark refusals remain preserved: first inherited CARGO_TARGET_DIR, then missing CPU-model metadata. The existing benchmark has now completed in a separate hosted Docker experiment at run 37168090008, comparing exact baseline 11bc72c with unchanged candidate 9a7a46e in baseline/candidate/candidate/baseline order on one runner. Raw results are retained in the audit branch under docs/audits/pr-landing-evidence/94. All workload allocation totals/peak heap agree; timings include increases and no new threshold, speedup or blanket no-regression claim is made. Independent benchmark receipt review approves this evidence after verifying artifact provenance, exact source trees and every comparison row; source approval remains unchanged. This closes the benchmark evidence gap without changing the product head. #179's separate policy decision and #179/#102 landing remain required. No waiver is assumed.

Bumps [blake3](https://github.com/BLAKE3-team/BLAKE3) from 1.8.5 to 1.8.7.
- [Release notes](https://github.com/BLAKE3-team/BLAKE3/releases)
- [Commits](BLAKE3-team/BLAKE3@1.8.5...1.8.7)

---
updated-dependencies:
- dependency-name: blake3
  dependency-version: 1.8.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Dependency and supply-chain maintenance label Aug 30, 2026
@dependabot
dependabot Bot requested a review from flyingrobots as a code owner August 30, 2026 04:22
@dependabot dependabot Bot added the dependencies Dependency and supply-chain maintenance label Aug 30, 2026
@flyingrobots

Copy link
Copy Markdown
Owner

Code Lawyer — dependency admission findings

Change kind: deliberate dependency upgrade. The integrated candidate includes #102 and #179; their independent landing gates remain prerequisites.

Severity Location Verified issue Acceptance check
P2 fuzz/Cargo.lock BLAKE3 entry The separately locked fuzz graph remains at 1.8.5 while the root and xtask exact pins require 1.8.7. Cargo updates the fuzz lock; both locked graphs admit 1.8.7 and pass their required checks.
P3 docs/dependencies/blake3-1.8.5.md, ADR-0001 Current admission and its caller still describe 1.8.5 and its transitive arrayref dependency. Renew admission against published 1.8.7 source and exact features; preserve historical evidence and the separately pinned external b3sum oracle.
P4 deny.toml:15 A crate-specific arrayref license exception remains after the updated graph removes arrayref. Remove the unused exception; run dependency policy for both locked workspaces.

These are graph/admission corrections, not a reproduced Keep runtime defect. Existing identity vectors, generated corpus cross-checks, typed refusals and streaming tests supply runtime evidence; no test-count or source-shape assertion will stand in for identity compatibility. The upstream 1.8.7 release cites an arrayref owner compromise as its removal rationale; this does not establish that Keep's previously locked arrayref 0.3.9 bytes were compromised.

@codex Please review this finite admission scope.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: e88e0fff-f79d-4153-a371-3bc80441aca2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner

Independent review findings — admission corrections

Independent Codex review of e0752efdcfa97f41fc1da473fed21cc212af0274 identified the following verified documentation findings. The complete review checklist will follow; this interim comment preserves the feedback before remediation.

Severity Location Concrete discrepancy Fix and acceptance
P3 docs/dependencies/blake3-1.8.7.md:70-81 The supported-target normal graph omits cpufeatures 0.3.0, selected by upstream BLAKE3 on x86/x86_64. Its lockfile libc metadata must be distinguished from active target dependencies. Name the conditional dependency and distinguish resolution from activation against published Cargo manifests.
P4 docs/dependencies/blake3-1.8.7.md:13,24 The claimed incremental-only production call inventory excludes the one-shot blake3::hash used by src/adapters/store_migration/migration_receipt_initial_state.rs:62-75 for durable initial-state digests. Document both production call paths and the broader existing durable hashing surface; do not change code or expected digests.

Coordinator independently verified both findings. These are admission-document inaccuracies, not observed runtime failures. Before/after source-to-document comparison and Markdown validation are the appropriate evidence. Full local runtime validation already passes on 6ee5565; existing runtime bytes and assertions remain unchanged by these corrections.

The benchmark is separately blocked: after clearing a forbidden inherited CARGO_TARGET_DIR, the runner precisely refuses this Docker host's missing CPU-model metadata. No measurement was produced and no performance gate is claimed satisfied. #179/#102 prerequisite landing and #179's separate policy decision also remain open.

@flyingrobots

Copy link
Copy Markdown
Owner

Independent review: Keep PR #94

Reviewed exact head e0752efdcfa97f41fc1da473fed21cc212af0274, tree 142c00ece21316303c5de28780747a02d9deb973, targeting main 3165890e9291cfb5fe10e81a9d7cd151f3e59464. Local checkout and live GitHub agree; checkout is clean. This is the expressly authorized independent Codex fallback using the complete agy-review protocol. No source, test, configuration, Git state, hosted discussion or tracker was changed. No host tests or additional agents were used. Only this report was written.

Findings

P3 — Supported-target dependency admission omits x86 CPU dispatch

Location: docs/dependencies/blake3-1.8.7.md:70-81.

The renewed admission describes its list as the admitted normal graph “for supported targets,” but omits cpufeatures 0.3.0. Published BLAKE3 1.8.7 Cargo.toml:134-135 makes that dependency unconditional on x86/x86_64, independently of pure; src/platform.rs:424-472 uses it for AVX2/SSE4.1/SSE2 detection. Both Keep lockfiles retain the exact package (Cargo.lock:169-175, fuzz/Cargo.lock:109-115). An x86 build therefore executes a dispatch dependency outside the page's purported complete admission inventory. This matters specifically when reviewing the selected unsafe/target boundary, not because the version change demonstrates an exploit or wrong digest.

The omitted package declares Rust 1.85 and MIT OR Apache-2.0 in its published manifest. Its libc dependency is target-conditioned to aarch64 Android/Linux/Apple and loongarch64 Linux (cpufeatures manifest:57-71); it is resolved in the lockfiles but does not become an active x86 BLAKE3 dependency. Do not describe every lockfile edge as simultaneously active. The old admission had a similar incomplete list, but this PR replaces that document with a renewed supported-target admission and must state the actual graph it admits.

Suggested fix: add the exact target-specific cpufeatures version, dispatch purpose, licensing/compiler metadata and target qualifications to the renewed admission. Distinguish resolved lockfile membership from active target edges; retain the pure exclusion of C/assembly without implying exclusion of CPU detection. Static source/manifest verification is sufficient for this document correction; it is not a request to change dependency features or add a runtime regression.

P4 — Renewed admission incorrectly limits production and tool caller inventory

Location: docs/dependencies/blake3-1.8.7.md:13,24 (related incomplete tool inventory at :15).

The page says Keep uses the incremental API only, and production calls use only Hasher::new, update, and finalize. Production src/adapters/store_migration/migration_receipt_initial_state.rs:62-75 calls blake3::hash for the initial retention, initial GC and empty-disposition digests. These digests are written into durable migration receipts and checked on admission: migration_receipt_decoder.rs:27-29 calls the corresponding readers at migration_receipt_initial_state.rs:10-59. In particular, reopening/admitting a migration receipt exercises a real production one-shot hash path outside the documented review boundary.

Repository tasks also call blake3::hash to admit the reviewed Node installer and lock bytes (xtask/src/documentation_integrity/node_toolchain.rs:108-124), beyond the seed naming described at :24. The incremental segment digest builder uses Hasher::clone (src/adapters/segment_digest_builder.rs:25-29). The document should describe the actual small API surface rather than an incorrect exhaustive list. No failure of these callers was demonstrated; the defect is an inaccurate renewed compatibility/admission boundary.

Suggested fix: distinguish streaming BlobId/ChunkId calculation from adapter framing/checksums and fixed-domain one-shot migration initial-state digests; record the tool byte-admission calls and incremental state cloning. Preserve all domain strings, expected digests and current APIs. This is documentation reconciliation, not a reason to refactor sound callers or invent product RED evidence.

Acceptance gates, separate from demonstrated defects

The inherited #179 resource-policy disposition is still unapproved, and #179 and #102 remain open/unmerged at this observation. docs/testing/enforcement.md:11,21,49-51,61 applies to #179's changed medium-test execution profile; its disclosed missing per-test memory/egress/suite-budget controls require resolution or an explicit, expiring maintainer-approved disposition. The incoming approval expressly concerned #106, not #179. This prerequisite blocker is not a #94 hashing defect or a new request to repair unrelated storage code. Prior 179-independent-review.md and 102-integration-review.md record the exact scope and limitation; current live #179 activity still states no approved waiver.

The coordinator reports the full local chain completed with exit 0 for source tree deaaa8ba81318296516310b49d81f12f0ca7f546 (6ee5565). I inspected the complete command list and final successful output in 94-validation.log. e0752ef differs solely by one trailing Markdown blank-line removal; this is runtime evidence for the recorded copied tree, not a fabricated execution of a different SHA. 94-copy-attestation.log agrees on the copied tree and ext4 source/Cargo scratch. The final Markdown receipt passes all 169 files. Live pushed-head documentation/workflow and dependency-policy checks succeed; Rust quality and runtime fuzz smoke are still in progress. CodeRabbit's successful status is accompanied by a skipped-review comment, and hosted Codex reports its usage limit; neither substitutes for a substantive independent review.

Benchmark validation remains unavailable on the admitted container profile. 94-benchmark.log preserves the initial refusal of ambient CARGO_TARGET_DIR; 94-benchmark-controlled.log preserves the corrected attempt's cpu-model refusal. The existing Linux metadata parser at xtask/src/benchmark_baseline/host_environment.rs:84-112 admits model name, Hardware, or Processor; the coordinator reports this ARM container lacks those fields. Neither attempt measured throughput or is a demonstrated BLAKE3 regression. No host benchmark, fabricated CPU metadata or unrelated benchmark-tool fix is authorized here. Complete the required benchmark gate on a supported source-bound Docker profile or obtain a task-specific disposition; pending evidence cannot be called green.

Verification Checklist

Exact scope, findings and review queue

  • Read checkout AGENTS.md, binding docs/Testing Standards.md, docs/testing/enforcement.md, and applicable documentation rules. Read the supplied complete protocol and agy-review skill. Declaration is a deliberate dependency upgrade with unchanged observable identity/API contracts; no product bug fix, new assertion or artificial runtime RED is claimed.
  • Compared main-to-head and integrated prerequisite 11bc72c-to-head. The full stack changes 19 files; Build(deps): Bump blake3 from 1.8.5 to 1.8.7 #94-specific delta is ten files. There is no Build(deps): Bump blake3 from 1.8.5 to 1.8.7 #94-specific runtime source, fixture, benchmark expectation, fuzz-target implementation or product assertion change. The one existing static process-policy test changes only include_str! at xtask/tests/process_policy_contract.rs:14; assertion bodies and execution profile remain unchanged. It proves written-policy shape, not exact storage bytes. Rule 4 applies to new/materially changed load-bearing assertions, not a spelling-only include path.
  • Rechecked all three published self-findings from comment 5975227006: both BLAKE3 lock entries are 1.8.7 with matching checksum; old document is replaced and ADR link updated; arrayref package and exact license exception are removed. No remaining reference to the deleted admission was found in the reviewed callers. The new findings above concern the replacement's actual content.
  • Read initial 94-queue-initial.json, PR body, subsequent live issue comments and reviews using paginated REST calls. Live GraphQL review-thread connection has zero nodes and hasNextPage: false; no nested comment pagination is needed for zero threads. The self-findings, usage-limit message and CodeRabbit skipped-review message are accounted for. No actionable inline thread was concealed by a status check.
  • Exact-head/tree/status and whitespace checks were executed read-only. No user checkout was used for changes. Final head remained e0752ef at the last check.

Every merge is a first-class change

  • 9842616a5f12e7920f6737fb63c7b5710f27f0fc, parents ece94b7bb9d318ea8629195cc5626328c2acfa58 and fa3c2b56991e0ff5ceff909c959afdafef4815ca: inspected both-parent diff identities and combined diff. Incoming fa3c2b5 has the actual-main tree already assessed in 102-independent-review.md; its broad historical source changes are not new Build(deps): Bump blake3 from 1.8.5 to 1.8.7 #94 edits. Against the incoming-main parent, the merge retains only the original four-file Rustix exact-pin/lock update, without runtime source conflict resolution. Subsequent afb5f00 reconciles the admission and separate fuzz graph. At current head, root/xtask/process-spawn exact pins and both lockfiles are 1.1.5; BLAKE3 admission edits do not undo the Rustix invariant. Earlier Rustix MSRV/fuzz findings remain corrected.
  • 11bc72c41cc379944766adbdef60f046e786b820, parents afb5f000c2803c9226d7678ce0905d676723e474 and f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a: inspected both-parent/combined diffs. Conflict is CHANGELOG; both dependency and locator-isolation entries survive. Against afb5f00 the only runtime-related delta is Fix: isolate locator subprocesses from golden writer handoffs #179's test import move; against f9a9c2e the only remaining delta is the seven-file Rustix admission/graph change. Prior exact integration report is reused with its validation and waiver limitations; relevant source facts are rechecked below.
  • f9b75f45da022a1eeb9a9d1c83c9525aea08fa3c, parents 6ba2c1f389d64df570bbea1c81f196bb7f298796 and 11bc72c41cc379944766adbdef60f046e786b820: inspected both-parent and combined diff. Combined root manifest preserves BLAKE3 1.8.7 and Rustix 1.1.5, exact pins/default-feature posture; against 11bc72c only three BLAKE3 manifest/root-lock files change. All incoming test isolation remains present. 6ee556532d68db6bb5ab6e97f6af2da6d6059cd7 adds fuzz/admission/license reconciliation; final e0752ef removes only the final admission blank line. No source conflict repair or identity re-baseline is hidden in these commits.

Production runtime paths and parallel hashing paths

All paths below ultimately select upstream ordinary unkeyed BLAKE3 through lib.rs:1089 → :1204 → :1398, or one-shot :920 → hash_all_at_once:879. Keep preimages/encodings are byte-identical to the integrated prerequisite. The relevant adapter/core route list was obtained from all blake3::/Hasher call sites, not only BlobId.

  • Public slice blob identity src/blob/id.rs:75-78 and public reader identity :101-105 → src/blob/hasher.rs:27-35,48-70,73-94. Both use identical magic/version/algorithm/content/trailing checked length. Reader uses 8192 bytes, retries Interrupted, refuses over-reported count, and preserves original read source. Length refusal precedes hash-state mutation. Streaming updates and finalization retain the same framing.
  • Public chunk identity src/chunk/id.rs:40-52 → src/chunk/hasher.rs:15-30; FastCdc src/chunk/detector.rs:74,101-102 reuses the same chunk hasher. Empty public chunks refuse; typed length admission remains before hashing. Reference ingestion src/reference/ingestion.rs:178,192,246-251, authenticated reconstruction src/authenticated_read/reconstruction.rs:44-55, adapter blob verification src/adapters/blob_verification.rs:112-132, and retention closure verification src/adapters/retention/closure_verifier.rs:93-112 all route through the same BlobHasher rather than a divergent hash implementation.
  • Framed adapter primitive src/adapters/framed_blake3.rs:8-35 is used by segment-record checksums (segment_record_checksum.rs:18-27), segment seal checksum/digest (segment_seal_hash.rs:20-47), catalog checksum/digest (catalog_integrity.rs:42-47), publication head checksum (publication_head_decoder.rs:97-98), and recovery fingerprint (recovery/recovery_stage_fingerprinter.rs:45,125-131). Domain/version/algorithm/trailing length remain identical. Streaming segment builder segment_digest_builder.rs:13-29 has matching framing and clone-on-finish; partial data is not silently published.
  • Layout checksum and identity src/adapters/layout_record_format.rs:29-49 use named domains/version/algorithm or codec/declared length with ordinary Hasher. These are representation-bound identities, distinct from logical BlobId. No new serializer output or encoding is introduced.
  • Retention namespace digest src/retention/namespace.rs:38-44 binds domain/fixed-width length/exact bytes. Closure digest src/adapters/retention/closure_digest.rs:23-38 hashes specified fields and BTreeMap-ordered members. Root encoder retention/root_encoder.rs:57-65,122-126 matches root decoder integrity root_integrity.rs:19,35,45-60,78-110; manifest encoder manifest_encoder.rs:56-65,106-110 matches manifest_integrity.rs:19,35,44-58,77-110. Count framing, ordered entries, distinct checksum/digest domains and partial-prefix refusal are retained. Head checksum head_decoder.rs:81-85 is shared by admission/egress.
  • Migration inventory src/adapters/store_migration/migration_inventory_hasher.rs:25-88 validates count/order before state mutation and refuses incomplete finalization. Intent hash migration_intent_format.rs:54-60, format-marker hash format_marker_decoder.rs:92-100, and receipt checksum migration_receipt_format.rs:10-14 retain exact domain/field order. Receipt initial-state digests migration_receipt_initial_state.rs:62-75 → upstream one-shot path also remain unchanged; this is the production path omitted from admission, not a new malformed digest. Receipt admission migration_receipt_decoder.rs:21-30,71-80 refuses mismatches with expected/observed fields before trusted admission.
  • No changed production API, write publication/sync ordering, writer lock, sealed-segment mutation, recovery transition, async cancellation contract or device/config switching state machine is present. Hash state remains synchronous, bounded by ordinary Hasher state, and is dropped on an aborted operation; explicit higher-level commit protocols are unchanged. Existing interruption/read errors remain typed; no new swallowing, nested source replacement, approximate repair or ambiguous continuation was found in the changed boundary.

Tool/oracle paths and retained process isolation

  • Golden internal oracle xtask/src/golden_file_worldline/identity_oracle.rs:114-124 independently frames blob preimages; :127-143 compares each digest with the external port. External blob framing golden_file_worldline/b3sum_oracle.rs:15-29 matches production magic/version/algorithm/payload/length without importing production identity types. Protocol chunk oracle protocol_conformance/chunk_identity.rs:39-49 constructs its independent witness; protocol_conformance/external_digest.rs:7-8 and Golden both route to xtask/src/external_digest.rs:64-110. b3sum uses raw/no-mmap/one-thread flags, cleared environment, C locale, exact 32-byte stdout, bounded diagnostics and a ten-second deadline. Width/status/diagnostic/source errors refuse; output is not substituted. CI remains .github/workflows/ci.yml:37 b3sum@1.8.5.
  • CDC seed bytes xtask/src/fuzz_seed_corpus/cdc_seeds.rs:48-59 use one-shot hash and exact unchanged witnesses. Documentation installer/lock admission documentation_integrity/node_toolchain.rs:108-124 also hashes reviewed bytes and refuses mismatch. These are tool/static provenance paths, not independent storage correctness evidence. Both now resolve the same admitted 1.8.7 graph.
  • Integration-only locator entry tests/durable_locator.rs:8-11 → tests/durable_locator/suite.rs:3-16 remains separate from golden tests/golden_file_worldline/suite.rs:30-35. Exact selectors at durable_locator_laws.rs:21,32 match the nested import namespace. Child admission :37-45 executes one law; parent :46-59 owns no writer/store and propagates spawn/status failure. Relative-store law :91-121 and deleted-cwd law :62-88 retain exact bytes/membership/typed original I/O source; restoration :124-138 remains explicit/best-effort on unwind. Fixture, locator source, golden layout law and sandbox are byte-identical to main. Golden process no longer spawns these locator children, so their separate executable cannot inherit a golden writer guard. The original hosted syscall schedule remains unknown; this is a bounded process-boundary guarantee, not universal absence of Busy.
  • Reused prior Fix: isolate locator subprocesses from golden writer handoffs #179/Build(deps): admit rustix 1.1.5 across runtime and tooling #102 source/evidence reports only for their bounded reviewed areas; did not promote their incomplete original receipts into current-head execution. Writer lifetime/CLOEXEC/fork boundaries and unchanged shared fixture handoffs remain as recorded. BLAKE3 changes none of those invariants; new hashes cannot silently redefine scratch/store ownership.

Published upstream source, dispatch, lengths and partitions

  • Inspected the provided published 1.8.5 and 1.8.7 package source and source diff, plus actual manifests/build-script diff. Manifest delta is version plus arrayref removal; selected features remain std,pure. build.rs:335-374 retains Rust SSE2/SSE4.1/AVX2 for x86 under pure, excludes AVX512 C/assembly and automatic aarch64 NEON, and enables WASM SIMD only for its unselected feature. Build-output cargo:: syntax is accepted by pinned Rust/Cargo 1.96.0. Build script's existing unsafe environment update remains upstream, not Keep core code. No new mmap/rayon feature is admitted.
  • Portable calls src/portable.rs:134-174: full-block loop guarantees at least 64 bytes; chunks_exact_mut supplies exactly 32 output bytes. Replacement conversions have identical extents to old arrayref macros. Empty/final-block paths retain flags and padding.
  • Upstream src/lib.rs:544-575: ChunkState compresses 64-byte leading slices only when input exceeds a block. :674-712: chunk references are exactly 1024 bytes from chunks_exact, and remainder output still occupies exactly one 32-byte slot. :721-755: parent references are 64 bytes from chunks_exact and odd child passthrough retains one 32-byte slot. :778-875: recursive bounded buffers and MAX_SIMD_DEGREE_OR_2 supply the 64-byte parent pair. :1304-1312: left/right CVs remain [0,32) and [32,64). No offset/order/length differs from old macro expansion.
  • src/platform.rs:477-546: every 4-byte little-endian read/write of fixed 32/64-byte arrays retains offset i*4 and extent four; word order and endianness unchanged. Runtime dispatch :66-118,424-472 retains Portable/SSE2/SSE4.1/AVX2 rules; added deprecated-lint allowances do not alter dispatch. cpufeatures omission in admission is finding one.
  • Rust AVX2 rust_avx2.rs:254-280,402-430: the 16-lane array splits into two disjoint degree-eight squares, and guarded output is 8*32 bytes. SSE2 rust_sse2.rs:550-560,657-661,682-752 and SSE4.1 rust_sse41.rs:539-546,645-649,671-741: degree-four 16-lane input splits into four ordered squares and eight-lane state into two; full-block/output slices retain 64/128/32-byte extents and length guards. No aliases or changed lane order result. WASM replacement is analogous but excluded by selected features; C/FFI implementation paths are excluded by pure and not asserted as executed.
  • Other upstream changes inspected: hazmat documentation fixes, OutputReader u64 constant spelling, std io module placement, mmap seek/fallback behavior and upstream test changes. Keep never calls update_reader/update_mmap/update_rayon, keyed/derive-key/hazmat or XOF interfaces. Mmap's 16 KiB threshold, seek/reset and swallowed-map fallback therefore do not change Keep behavior. No claim is made that an unselected mmap algorithm satisfies Keep's refusal law.

Constants, every changed claim and documentation figures

  • Changed admission/ADR/changelog numbers: BLAKE3 1.8.7/root+fuzz exact pins; prior 1.8.5; 32-byte output; version-one identity; external b3sum 1.8.5; selected features; arrayref 0.3.9 removal; transitive arrayvec 0.7.8/cfg-if 1.0.4/constant_time_eq 0.4.2 and build cc 1.3.0/find-msvc-tools 0.1.9/shlex 2.0.1 reconcile with actual manifests/locks. Missing target-dependent cpufeatures 0.3.0 is reported rather than assumed absent. Upstream BLAKE3 manifest has no rust-version; Keep pinned Rust is 1.96.0. The “far beyond 50 auditable lines” discussion is a maintainability rationale, not a claimed measured implementation size or repository hard limit.
  • Independently checked official upstream release metadata: BLAKE3 1.8.7 release, published 2026-08-20T09:06:20Z, reports arrayref removal after owner compromise. This corroborates the rationale/date only; no evidence establishes compromised bytes in Keep's previously locked arrayref package.
  • Inherited Rustix admission numbers: 1.1.5 root/xtask/process-spawn/fuzz; 1.65 declared compiler floor vs historical 1.63; capability graph versions remain as the prior admission review recorded. Current BLAKE3 changes do not overwrite them. This report does not claim an independent new all-platform Rustix execution.
  • Selected hashing constants 32-byte digest, 64-byte compression block, 1024-byte BLAKE3 chunk, degrees 1/4/8, and bounded static CV buffers reconcile with published upstream type sizes; they are algorithm/storage constants, not benchmark promises. Blob/recovery 8192-byte buffers and canonical version/algorithm coordinates remain unchanged. External 32-byte/65536-byte output limits and ten-second deadline are unchanged ceilings; no p95/throughput evidence is asserted. Locator timeout remains 20 seconds, matching its evidence page; fixture retention/catalog limits remain unchanged policy bounds, not a claim of total RSS enforcement.
  • Inherited locator numerical claims: two moved laws still have two entry functions and exact namespace selectors; 51 passed + one failed equals historical 52; focused two locator plus 50 golden equals preserved 52 in both profiles. docs/testing-evidence/durable-locator-isolation/hosted-red.txt:1-8 retains runtime Busy and 0.67-second historical output; controlled-inheritance.txt:1-29 retains original Rustix/BLAKE3/arrayref versions and 3.14-second build duration. They explicitly concern recorded parent builds, not the new 1.8.7 graph. Controlled mechanism evidence does not identify the original hosted handoff. No new measurement supersedes these failures.
  • Runtime evidence is existing specified blob/chunk vectors, public streaming/property/generated partition laws, format/refusal oracles and reopened crash-state campaigns. Expectations remain byte-identical to prerequisite. Existing identity and tool expected digests are not derived anew from the changed dependency to manufacture agreement. Product laws, static policy, tooling and calibration are recorded separately; no test count is promoted to an exact-byte oracle.
  • Changed Markdown paragraphs/links reviewed, admission document renamed with caller links corrected. Current graph/caller errors are findings, not lint complaints. New admission prose mostly uses single physical paragraphs; existing ADR/prior inherited wrapped paragraphs are not a newly invented formatting prohibition. Repository Documentation Standards asks for coherent paragraphs and treats physical/source-line length as advisory. Actual required Markdown/links/whitespace gates remain required.
  • Historical benchmark context checked in docs/benchmarks/streaming-cas-baseline-v1/README.md:10-35 against both linked TSV metadata: c529c07/30ffe90 source commits, Rust 1.96.0, aarch64-apple-darwin, Apple M1 Pro/M5 Pro, 100 samples/five warmups and scenario/profile counts are historical coordinates. The page explicitly refuses a before/after speedup claim and states thresholds remain unconfigured. These untouched artifacts are not new measurements of this upgrade; no performance claim is made. Unrelated historical README/changelog metrics and all raw timings were not globally re-audited; this finite review covers changed/current claims and inherited integration evidence, not certification of every old repository number.

Executed, inspected, pending and unavailable checks

  • Executed by this reviewer: read-only Git exact coordinates/status/history/complete scoped diffs, parent/combined merge diffs, unchanged-source comparisons, whitespace check; source/admission/upstream/receipt inspection; paginated live PR comments/reviews and complete review-thread connection; official upstream release metadata verification. No host tests or duplicate Docker suites were run.
  • Inspected, not independently executed: 94-validation.log:1-16,17-92,93-2296,2297-4505,4506-4574 records exact copied tree/rustc/aarch64/ext4 profile, Golden/conformance and debug/release crash campaigns, source-structure, format, both feature checks/strict Clippy, all-feature debug/release workspace tests, doctests/docs, pinned compiler check and separately locked fuzz format/build/strict Clippy. Coordinator observed terminal exit 0 for the live session. 94-copy-attestation.log and final one-blank-line diff reconcile source scope. 94-markdown.log retains initial MD012; 94-markdown-final.log records pinned markdownlint-cli2 0.23.3, 169 files, zero issues. A lint/setup failure is not product assertion RED.
  • Hosted at last direct observation: e0752ef documentation/workflow and dependency-policy SUCCESS; Rust quality/runtime fuzz IN_PROGRESS. The dependency-policy success establishes configured exact locked/advisory/license tool gates; it does not establish absence of cryptographic defects. Fix: isolate locator subprocesses from golden writer handoffs #179/Build(deps): admit rustix 1.1.5 across runtime and tooling #102 remain unmerged. Parent owns final hosted/protection/exact-main confirmation, incoming feedback and required pending checks; a later green result must preserve this report's observed status rather than retroactively claim it was executed here.
  • Unavailable/pending: source-bound benchmark on supported Docker metadata; scoped Fix: isolate locator subprocesses from golden writer handoffs #179 policy approval; actual prerequisite landing and final integration validation. No x86-specific independently forced SSE2/SSE4.1/AVX2 execution by this reviewer, exhaustive platform/schedule proof, physical power-loss evidence, per-test ordinary-Cargo memory/egress enforcement, measured suite distribution or new performance result is claimed. Existing aarch64 Docker results exercise the portable selection; hosted x86 pending results cannot be counted as completed here.

The finite source review found no demonstrated runtime BLAKE3 output/refusal defect. Two renewed-admission inaccuracies require focused documentation correction and a fresh exact-head review. Prerequisite and missing benchmark/hosted evidence remain separately identified acceptance gates; this verdict does not waive them.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner

Independent delta review: Keep PR #94

Reviewed exact final head 9a7a46ec6d5043f61222c2f75fc7c49a16002cd3, tree 9de5045171b4a779456a66ebc9b7cc96125c372b, against previously reviewed e0752efdcfa97f41fc1da473fed21cc212af0274. Clean local checkout and live GitHub agree. Base remains 3165890e9291cfb5fe10e81a9d7cd151f3e59464. This is the authorized read-only follow-up under the same mandatory review protocol, scoped to the two published findings and their documentation correction. Only this report was written.

Findings and source verdict

Both original findings are closed at this exact head. No new verified P0–P5 defect was found in the bounded delta. Exact-head source review: APPROVE, read together with the full Verification Checklist in 94-independent-review.md. That earlier report remains evidence for its recorded e0752ef head; this delta confirms the unchanged implementation and corrected documentation at 9a7a46e, without rewriting historical results.

  • P3 incomplete dependency admission: corrected at docs/dependencies/blake3-1.8.7.md:75-80. The document now names x86/x86_64 cpufeatures 0.3.0, selected runtime SSE2/SSE4.1/AVX2 detection under pure, Rust 1.85 and the MIT/Apache-2.0 license alternatives. These match published upstream BLAKE3 Cargo.toml:134-135, src/platform.rs:424-472, and cpufeatures' manifest. The locked libc 0.2.186 edge is explicitly distinguished from an active x86 BLAKE3 dependency; cpufeatures' libc declarations apply to certain aarch64/loongarch targets, while BLAKE3 selects cpufeatures only on x86/x86_64. No extra feature or implementation path was admitted.
  • P4 false caller inventory: corrected at admission :13,24. Streaming identities are distinguished from existing segment/catalog/layout/retention/migration hashes. The page records fixed-domain one-shot migration receipt hashes, bounded state cloning before segment seal suffixes, deterministic seed hashing and Node installer/lock byte admission. These match src/adapters/store_migration/migration_receipt_initial_state.rs:62-75, src/adapters/segment_digest_builder.rs:25-29, xtask/src/fuzz_seed_corpus/cdc_seeds.rs:48-59, and xtask/src/documentation_integrity/node_toolchain.rs:108-124. The inaccurate streaming-only/exhaustive API claims are removed without changing callers or expected bytes.

Verification Checklist

  • Inspected the complete e0752ef-to-9a7a46e delta: exactly one admission Markdown file, seven additions/two removals. Correction commits are 6c4019b1426456a4a2d30a737978da89e9c9f68a and final 9a7a46e; both are ordinary single-parent commits, with no new merge or conflict resolution. Runtime source, test source, fixtures, manifests, both lockfiles, dependency policy and workflows have zero delta. The earlier three-merge/runtime/upstream audit therefore remains applicable; no new runtime route or state machine needs a separate campaign.
  • Rechecked changed caller/graph/metadata statements against current production/tool source and published manifests rather than accepting commit/PR claims. New version/compiler/license/target numbers are corroborated. The clarification preserves fixed domains, exact digests, feature selection, immutable format/identity contracts and the inactive-libc distinction.
  • Executed read-only exact head/tree/status, full scoped diff, unchanged-source comparison, history and git diff --check; all agree. No host tests, mutation, source change, publishing or duplicate Docker execution occurred.
  • Inspected 94-review-doc-final-markdown.log: markdownlint-cli2 0.23.3, 169 selected files, zero issues. This is documentation/tool evidence, not storage execution. The existing static include_str! fixture loads this document, but its assertions and execution profile are unchanged; final hosted checks will rebuild it at the new SHA. No new load-bearing assertion or runtime bug fix was introduced, so artificial product RED or a full prose-triggered runtime rerun is unwarranted.
  • Read paginated current comment identities: original finite findings and both subsequent publication comments are present; live review-thread connection has zero nodes and hasNextPage: false. Feedback was published before correction according to the supplied comment coordinates; no unresolved inline finding appeared. Coordinator owns any later arriving review feedback.
  • Original completed Docker runtime evidence remains for 6ee5565, copied tree deaaa8ba81318296516310b49d81f12f0ca7f546, as recorded in 94-validation.log and 94-copy-attestation.log. Only Markdown changed after that execution. This review does not claim the full runtime chain executed on 9a7a46e or claim static confirmation is execution.

Unsatisfied acceptance gates

#179 disposition and prerequisites: live #179 (f9a9c2e) and #102 (11bc72c) remain open/unmerged. The inherited medium-test resource-policy disposition is still not approved; #106's waiver cannot cover it. Binding docs/testing/enforcement.md:11,21,49-51,61 and the prior #179/#102 reports retain that independent acceptance blocker. It is not a defect in the corrected #94 admission.

Benchmark evidence: the container attempts remain refusals of ambient Cargo target configuration and unsupported CPU metadata. No source-bound optimized performance measurement is available. A supported admitted Docker profile or explicit scoped disposition remains necessary; neither host execution nor invented metadata was used. Historical benchmark receipts and unconfigured thresholds remain historical, and no speedup/regression conclusion is claimed.

Final hosted/integration gates: at direct inspection, all four required hosted jobs for exact 9a7a46e—Rust quality, documentation/workflow, runtime fuzz and dependency policy—were IN_PROGRESS. Earlier-head success is not final-head success. Confirm their terminal results, actual prerequisite landing, unchanged exact head and required integration/protection checks before acceptance. No missing source path within this finite correction remains; these are pending policy/evidence gates.

Overall acceptance remains blocked despite source approval of the corrected delta.

REQUEST CHANGES

@flyingrobots

Copy link
Copy Markdown
Owner

Review closure and remaining benchmark evidence

Exact product head remains 9a7a46ec6d5043f61222c2f75fc7c49a16002cd3. The independent delta review closes both admission findings and approves the source; its overall acceptance remains gated by final CI, prerequisite landing and benchmark evidence.

The local ARM Docker CPU-metadata refusal is preserved. A separate, unmerged validation branch now runs the unchanged repository benchmark on hosted x86 Docker: run 37168090008, workflow commit 0a194bfd0b6e27acfa02ccdb007564804947fc2a. This workflow does not change this PR's source or main. It copies bundled source history into a digest-pinned Rust 1.96.0 container and checks out exact baseline 11bc72c41cc379944766adbdef60f046e786b820 and candidate 9a7a46e as clean trees. Each uses its own build directory, with the same container/runner CPU and memory limits. Dependencies and optimized binaries are prepared before network disconnection; measurement order is baseline, candidate, candidate, baseline.

Raw protocol TSVs, original failure logs, image identity, actual CPU metadata and Docker resource/network configuration are retained as artifacts. Existing benchmark settings and thresholds remain unchanged. This supplies a same-host comparison with explicit coordinates, not a cross-machine speedup claim or a retroactively chosen performance threshold. The run is currently in progress; no benchmark result is claimed yet.

@flyingrobots

Copy link
Copy Markdown
Owner

Independent benchmark receipt review: Keep PR #94

Product head remains 9a7a46ec6d5043f61222c2f75fc7c49a16002cd3, tree 9de5045171b4a779456a66ebc9b7cc96125c372b; clean local checkout and live PR metadata agree. This is a bounded, read-only follow-up to 94-independent-review.md and 94-delta-review.md, reviewing the newly supplied hosted benchmark receipt rather than repeating source or runtime campaigns. Only this report was written.

Result and findings

No verified P0–P5 defect in the receipt, comparison, or its bounded claims. The successful actual Docker execution supplies the previously missing benchmark execution/comparison evidence. Exact unchanged product source review remains APPROVE under the earlier full checklist plus delta review; this receipt introduces no product source change or new performance gate.

The benchmark run 37168090008 completed SUCCESS on orchestration commit 0a194bfd0b6e27acfa02ccdb007564804947fc2a, branch validation/94-hosted-benchmark. It checks out original immutable product history separately inside Docker, not the orchestration SHA as product. The final product CI run 37167535271 also completed SUCCESS, with all four jobs reporting exact head 9a7a46e. These directly refreshed results supersede the earlier reports' pending benchmark/hosted observations; those earlier observations remain historical, not erroneous promises of success.

Verification Checklist

  • Exact source and orchestration: read-only Git status/head/tree and live PR head confirm unchanged clean 9a7a46e. The orchestration checkout is exact 0a194bf. Its workflow Git blob 16db05548f98fd6d50439173eaf839148d6bd9b8 matches the live GitHub contents at that SHA. Workflow pr94-benchmark-evidence.yml:33-46 separately clones bundled history, checks out baseline 11bc72c41cc379944766adbdef60f046e786b820 and candidate 9a7a46e, prints original commit/tree and refuses dirty sources. Preparation and all four run logs confirm baseline tree 01c712f41fac391e14bde02cd84be3150596fd85 and candidate tree 9de5045171b4a779456a66ebc9b7cc96125c372b. Run commands also refuse dirtiness after measurement. No synthetic source commit, source repair or modified benchmark expectation is involved.
  • Artifact provenance and byte identity: independently fetched GitHub artifact 11290617044 for successful run 37168090008 directly into memory; independently computed archive SHA-256 54e80aa93c2d52223f932c8c480ab6949cac6cd4475d94d75eac23ff5885d664, exactly matching GitHub's artifact digest. Parsed the ZIP in memory and compared all twelve retained members byte-for-byte with the supplied raw artifact directory: four TSVs, four per-run logs, preparation log, image JSON, container-profile JSON and container log all match. No extra filesystem artifact was created by this review.
  • Durable audit copy identity: independently compared each raw TSV with docs/audits/pr-landing-evidence/94/ audit copy; all four match byte-for-byte. Independently computed SHA-256 values match README's table: baseline-1 7ea622ee433cd029dea14d2aef6b9b2574bd3de165efeb3ebc76754168fc9908; candidate-1 f178cab9e8e258f9f15e57ab8af3aab51fbe8283acd2d2161de0ae8da2b25eca; candidate-2 07982178b974968e85b53c5f092cfd96f1111eeb9cc17fe806db3056e5181fca; baseline-2 1e6018d2db7419b2e966f406ad84e65199374ea57107c9dab8f23b62d6fb9c83. These audit files are separate evidence, not changes to the reviewed product PR.
  • Same image/host/toolchain and bounds: image.json records digest rust@sha256:58fe97504a0e4cbba5d85599619a589923d3e779472a6fb0840d58d1c4ba99d7; the container's actual Image ID equals that inspected image. container-profile.json records NanoCpus 2000000000 and Memory 6442450944: exactly a two-CPU quota and 6 GiB container memory cap. It has no mounted host directory and NetworkSettings.Networks is empty. Workflow :27-30,40-53 admits online preparation/build first, then disconnects the bridge before measurement; it does not claim all preparation was offline. All four report metadata blocks :2-17 agree on optimized release, Rust 1.96.0/ac68faa20, x86_64-unknown-linux-gnu, Linux 6.17.0-1022-azure, actual AMD EPYC 7763 CPU model, admitted logical CPU count two, mandatory verification, process CPU clock and incremental-live-heap accounting. Full preparation log records actual CPU metadata rather than invented model labels. A CPU quota is not exclusive physical-core ownership or a dedicated-runner claim.
  • Separate builds and order: /baseline and /candidate have separate default target trees; preparation prebuilds both existing optimized benchmark executables with locked Cargo and the same host target. Workflow :54-64 runs exactly baseline-1, candidate-1, candidate-2, baseline-2 sequentially in the same container after network disconnection, with inherited CARGO_TARGET_DIR cleared. The successful set -euo pipefail step, raw per-run coordinate logs and four retained outputs corroborate completion. ABBA is an order control, not a long-term noise model or statistical significance guarantee.
  • Existing protocol and every row: all four raw reports use keep.streaming-cas-baseline/v1, have thirteen scenarios and five profiles, contain 100 timed samples for every row and five warmups in metadata, and state mandatory verification. Their existing final threshold rows say all-performance-metrics, unconfigured, requires-controlled-baseline-history. Report names/order agree across all four; comparison includes all eighteen rows. This is execution of the previously reviewed benchmark protocol, not new calibration, a newly invented threshold or proof of universal identity equivalence.
  • Independent ratio recomputation: read each row by its named header, independently calculated (candidate-1 statistic + candidate-2 statistic) / (baseline-1 statistic + baseline-2 statistic) for p50/p99 wall time, and compared all eighteen rows at six decimal places to comparison.tsv. Every cell agrees. These are ratios of averages of per-run quantiles; no raw pooled percentile, confidence interval or significance result can be inferred from them.
  • Extrema and unfavorable results: recomputed scenario p50 extrema 0.982335798704871 and 1.0309268469764412, rounding to 0.982336–1.030927; scenario p99 extrema 0.7648190299677068 and 1.0650631752237005, rounding to 0.764819–1.065063. Many-tiny-blobs has the largest scenario p50 increase, approximately 3.1%; early-deletion has the largest scenario p99 increase, approximately 6.5%. Profile keep-fastcdc-64-256-1024 has maximal profile p99 ratio 1.0836620343548993, rounded 1.083662. README's figures and names agree with raw/comparison rows. Observed increases are retained, not rewritten as “no regression”; the finite experiment supports no blanket speedup or no-regression claim.
  • Allocation equality: independently checked total-allocation-count, total-allocated-bytes and peak-live-heap-bytes for every scenario/profile across all four reports. All three fields agree in all eighteen rows, and comparison's equality flags match. This is the existing benchmark's incremental allocation/heap accounting, not process RSS, total host memory or an ordinary-test memory compliance claim.
  • Failures and evidence subjects: original local CARGO_TARGET_DIR refusal and ARM CPU-model refusal remain retained and acknowledged. Successful supported hosted execution does not reclassify them as BLAKE3 regressions or erase attempts. Benchmark measurements with mandatory behavioral verification, static digest/copy checks, hosted CI outcomes and source review remain distinct evidence. No performance percentage is used as a correctness oracle or an unconfigured acceptance ceiling.
  • Executed by this reviewer: read-only Git/live run/job/artifact/workflow metadata queries; downloaded-artifact digest/member comparisons in memory; TSV audit-copy SHA-256/byte comparison; independent header-based row/cardinality/sample/allocation checks; complete comparison ratio/extrema recomputation; source/workflow/profile/log/README inspection. Inspected, not executed by this reviewer: actual hosted Docker preparation and four measurement runs, full final product CI. No host benchmark/test or additional runtime suite was executed; no global configuration, product source or hosted state was modified.
  • Limits: one shared-host, order-controlled experiment with two runs per subject; no pooled raw sample distribution, confidence interval, long-term variance history, all-platform measurement, new harness calibration, physical power-loss experiment or ordinary-test resource-policy compliance is claimed. Existing performance thresholds remain unconfigured. No mandatory area of this bounded receipt review remains unreviewed.

Remaining acceptance gates

The benchmark and final-head hosted CI evidence gaps from the earlier delta review are now satisfied for their stated finite scope. This does not resolve #179's unapproved testing-profile risk disposition. Live #179 (f9a9c2e) and #102 (11bc72c) remain open/unmerged, and the recorded approval for #106 cannot waive #179. The binding disposition requirements at docs/testing/enforcement.md:11,21,49-51,61, prerequisite landing, and actual integration/protection checks remain independent gates. No product or evidence defect is invented to stand in for that missing approval.

Benchmark receipt acceptance: APPROVE. Overall PR landing acceptance remains blocked by the separate policy/prerequisite disposition.

REQUEST CHANGES

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency and supply-chain maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant