Repository navigation
Build(deps): Bump blake3 from 1.8.5 to 1.8.7 - #94
dependabot[bot] wants to merge 12 commits into
Conversation
Bumps [blake3](https://github.com/BLAKE3-team/BLAKE3) from 1.8.5 to 1.8.7. - [Release notes](https://github.com/BLAKE3-team/BLAKE3/releases) - [Commits](BLAKE3-team/BLAKE3@1.8.5...1.8.7) --- updated-dependencies: - dependency-name: blake3 dependency-version: 1.8.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rustix](https://github.com/bytecodealliance/rustix) from 1.1.4 to 1.1.5. - [Release notes](https://github.com/bytecodealliance/rustix/releases) - [Changelog](https://github.com/bytecodealliance/rustix/blob/main/CHANGES.md) - [Commits](bytecodealliance/rustix@v1.1.4...v1.1.5) --- updated-dependencies: - dependency-name: rustix dependency-version: 1.1.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
…102-rustix # Conflicts: # CHANGELOG.md
Code Lawyer — dependency admission findingsChange kind: deliberate dependency upgrade. The integrated candidate includes #102 and #179; their independent landing gates remain prerequisites.
These are graph/admission corrections, not a reproduced Keep runtime defect. Existing identity vectors, generated corpus cross-checks, typed refusals and streaming tests supply runtime evidence; no test-count or source-shape assertion will stand in for identity compatibility. The upstream 1.8.7 release cites an arrayref owner compromise as its removal rationale; this does not establish that Keep's previously locked arrayref 0.3.9 bytes were compromised. @codex Please review this finite admission scope. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Independent review findings — admission correctionsIndependent Codex review of
Coordinator independently verified both findings. These are admission-document inaccuracies, not observed runtime failures. Before/after source-to-document comparison and Markdown validation are the appropriate evidence. Full local runtime validation already passes on The benchmark is separately blocked: after clearing a forbidden inherited CARGO_TARGET_DIR, the runner precisely refuses this Docker host's missing CPU-model metadata. No measurement was produced and no performance gate is claimed satisfied. #179/#102 prerequisite landing and #179's separate policy decision also remain open. |
Independent review: Keep PR #94Reviewed exact head FindingsP3 — Supported-target dependency admission omits x86 CPU dispatchLocation: The renewed admission describes its list as the admitted normal graph “for supported targets,” but omits The omitted package declares Rust 1.85 and Suggested fix: add the exact target-specific P4 — Renewed admission incorrectly limits production and tool caller inventoryLocation: The page says Keep uses the incremental API only, and production calls use only Repository tasks also call Suggested fix: distinguish streaming BlobId/ChunkId calculation from adapter framing/checksums and fixed-domain one-shot migration initial-state digests; record the tool byte-admission calls and incremental state cloning. Preserve all domain strings, expected digests and current APIs. This is documentation reconciliation, not a reason to refactor sound callers or invent product RED evidence. Acceptance gates, separate from demonstrated defectsThe inherited #179 resource-policy disposition is still unapproved, and #179 and #102 remain open/unmerged at this observation. The coordinator reports the full local chain completed with exit 0 for source tree Benchmark validation remains unavailable on the admitted container profile. Verification ChecklistExact scope, findings and review queue
Every merge is a first-class change
Production runtime paths and parallel hashing pathsAll paths below ultimately select upstream ordinary unkeyed BLAKE3 through
Tool/oracle paths and retained process isolation
Published upstream source, dispatch, lengths and partitions
Constants, every changed claim and documentation figures
Executed, inspected, pending and unavailable checks
The finite source review found no demonstrated runtime BLAKE3 output/refusal defect. Two renewed-admission inaccuracies require focused documentation correction and a fresh exact-head review. Prerequisite and missing benchmark/hosted evidence remain separately identified acceptance gates; this verdict does not waive them. REQUEST CHANGES |
Independent delta review: Keep PR #94Reviewed exact final head Findings and source verdictBoth original findings are closed at this exact head. No new verified P0–P5 defect was found in the bounded delta. Exact-head source review: APPROVE, read together with the full Verification Checklist in
Verification Checklist
Unsatisfied acceptance gates#179 disposition and prerequisites: live #179 ( Benchmark evidence: the container attempts remain refusals of ambient Cargo target configuration and unsupported CPU metadata. No source-bound optimized performance measurement is available. A supported admitted Docker profile or explicit scoped disposition remains necessary; neither host execution nor invented metadata was used. Historical benchmark receipts and unconfigured thresholds remain historical, and no speedup/regression conclusion is claimed. Final hosted/integration gates: at direct inspection, all four required hosted jobs for exact 9a7a46e—Rust quality, documentation/workflow, runtime fuzz and dependency policy—were IN_PROGRESS. Earlier-head success is not final-head success. Confirm their terminal results, actual prerequisite landing, unchanged exact head and required integration/protection checks before acceptance. No missing source path within this finite correction remains; these are pending policy/evidence gates. Overall acceptance remains blocked despite source approval of the corrected delta. REQUEST CHANGES |
Review closure and remaining benchmark evidenceExact product head remains The local ARM Docker CPU-metadata refusal is preserved. A separate, unmerged validation branch now runs the unchanged repository benchmark on hosted x86 Docker: run 37168090008, workflow commit Raw protocol TSVs, original failure logs, image identity, actual CPU metadata and Docker resource/network configuration are retained as artifacts. Existing benchmark settings and thresholds remain unchanged. This supplies a same-host comparison with explicit coordinates, not a cross-machine speedup claim or a retroactively chosen performance threshold. The run is currently in progress; no benchmark result is claimed yet. |
Independent benchmark receipt review: Keep PR #94Product head remains Result and findingsNo verified P0–P5 defect in the receipt, comparison, or its bounded claims. The successful actual Docker execution supplies the previously missing benchmark execution/comparison evidence. Exact unchanged product source review remains APPROVE under the earlier full checklist plus delta review; this receipt introduces no product source change or new performance gate. The benchmark run 37168090008 completed SUCCESS on orchestration commit Verification Checklist
Remaining acceptance gatesThe benchmark and final-head hosted CI evidence gaps from the earlier delta review are now satisfied for their stated finite scope. This does not resolve #179's unapproved testing-profile risk disposition. Live #179 ( Benchmark receipt acceptance: APPROVE. Overall PR landing acceptance remains blocked by the separate policy/prerequisite disposition. REQUEST CHANGES |
Problem and outcome
Change kind: deliberate dependency upgrade. Update in-process BLAKE3 1.8.5 to 1.8.7 across the library, xtask and separately locked fuzz workspace, remove the now-unused arrayref license exception, and renew the exact dependency admission. The external b3sum oracle remains pinned at 1.8.5 and committed identity expectations are unchanged.
Candidate
9a7a46ec6d5043f61222c2f75fc7c49a16002cd3, tree9de5045171b4a779456a66ebc9b7cc96125c372b, merges original Dependabot head6ba2c1f389d64df570bbea1c81f196bb7f298796with #102's integrated11bc72c41cc379944766adbdef60f046e786b820inf9b75f45da022a1eeb9a9d1c83c9525aea08fa3c. Admission/fuzz corrections are6ee556532d68db6bb5ab6e97f6af2da6d6059cd7; subsequent documentation commits fix one trailing blank line and the independent review's caller/target-graph admission findings. This temporary stack waits for #179 and #102 to clear their independent gates and land. Their unmerged changes are not claimed as #94 work.Invariant, scope and alternatives
Version-one blob/chunk identities must continue to name exactly the same bytes; any identity mismatch remains a refusal. Existing streaming bounds, typed errors, durable encodings, writer/recovery protocols and public APIs retain their contracts. The admitted features remain exactly std and pure. Upstream's arrayref replacements require review of fixed lengths and mutable partitions; the mmap behavior changes are outside admitted features and calls. No faster implementation path is enabled.
Alternatives rejected: stale fuzz resolution, changing golden expectations, updating the external oracle merely to agree, adding features or accepting a dependency solely from a checksum. No performance improvement is claimed. Existing benchmark results are historical; current benchmark execution and compatibility checks remain required. Upstream cites an arrayref owner compromise as its removal rationale; no claim is made that previously locked 0.3.9 bytes were compromised.
Evidence and limitations
Owner: @flyingrobots. Product oracles are the existing specified identity vectors, generated preimage/digest comparisons with external b3sum, streaming/property laws, typed corruption refusals and reopened-state crash campaigns. These assert runtime outcomes; dependency policy and document checks are separate tooling/static evidence. Existing small in-memory and medium filesystem/subprocess test classifications do not imply automated per-test resource enforcement; gaps remain recorded in docs/testing/enforcement.md. This PR claims no new assertion calibration, exhaustive platform coverage or physical power-loss evidence.
The existing process-policy static test changes only its include_str path to follow the renamed admission document; its assertions and execution profile are unchanged. It remains static document-policy evidence, not proof of storage behavior. No user waiver is generalized to this PR.
The copied Docker source for
6ee5565has treedeaaa8ba81318296516310b49d81f12f0ca7f546, verified against the synthetic Git source copy. The full required local chain completed with exit 0: Golden Worldline, debug/release crash campaigns, conformance, structure, formatting, all/minimal checks and Clippy, debug/release workspace tests, doctests/docs, pinned compiler and locked fuzz checks. Final candidate changes since that run affect only admission prose; no runtime byte or assertion changes. Initial MD012 and its corrected repository-wide Markdown success are retained.Full independent review found no demonstrated runtime defect and identified two admission-document inaccuracies. They are corrected in
6c4019band9a7a46e: the conditional cpufeatures graph/dispatch/compiler/license metadata and the actual streaming, cloned-state, production one-shot and tool-provenance callers. Exact-head delta confirmation closes both findings and approves the source. All four final-head required CI jobs pass in run 37167535271; earlier-head results were not transferred.Local benchmark refusals remain preserved: first inherited CARGO_TARGET_DIR, then missing CPU-model metadata. The existing benchmark has now completed in a separate hosted Docker experiment at run 37168090008, comparing exact baseline 11bc72c with unchanged candidate 9a7a46e in baseline/candidate/candidate/baseline order on one runner. Raw results are retained in the audit branch under docs/audits/pr-landing-evidence/94. All workload allocation totals/peak heap agree; timings include increases and no new threshold, speedup or blanket no-regression claim is made. Independent benchmark receipt review approves this evidence after verifying artifact provenance, exact source trees and every comparison row; source approval remains unchanged. This closes the benchmark evidence gap without changing the product head. #179's separate policy decision and #179/#102 landing remain required. No waiver is assumed.