feat(core): close Gate 2 with the §10.4.1 record-class disposition (#445) - #929
Conversation
) Gate 2 closure for #920. `disposition()` mirrors §10.4.1's exhaustive registry class by class: 31 MIGRATE_TO_R15 tokens, 7 native control-plane tokens (authority-root, record-catalog, key-epoch, record-commit, asset-pair, migration, migration-page) and 3 RETAIN_APPROVED_SEPARATE_PROTECTED_AUTHORITY tokens (credential, idb-kdf-salt, idb-passphrase-sentinel), with unit tests that every class appears exactly once and that the counts match the contract. `seal_record`/`open_record` now accept only MIGRATE_TO_R15 and control-plane classes. A retained-authority class, or a class without an admitted disposition, is refused before any parsing or cryptography (SealError/OpenError::NotAnR15RecordClass), so no R-15 ciphertext is ever created for credentials or the B-1 IDB salt/sentinel, as §10.4.1 requires. Contract §20 records the closure and assigns legacy locator-to-identity mapping to Gate 5 (§15.3), where the contract already puts per-class migration adapters. The status statements now record Gate 1b as implemented and Gate 2 as implemented headless. The #361 row notes that its Core evidence is complete while the shipped-helper gap persists until the Gate 7 switch (#925). The ledger and crate doc are updated to match.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 26 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 79 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (10)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (8)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe secure-storage crate now maps record classes to dispositions and rejects classes outside the R-15 set before schema validation or envelope parsing. Tests cover retained classes and accepted native control-plane records. The changelog and migration documents record Gate 2 as implemented headlessly; the production authority switch remains off. ChangesSecure-storage record-class disposition
Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The change restricts the headless codec to admitted R-15 classes without switching application storage authority. No concrete merge-blocking risk is established; merge after normal checks.
Comment |
Reviewer's GuideCloses Gate 2 headlessly by implementing the exhaustive §10.4.1 record-class disposition registry and enforcing it in the record codec, while explicitly refusing separately protected classes before parsing or cryptography. Contract and ledger documentation now assign legacy locator adapters to Gate 5, preserve the current TS/Tauri authority, and clarify that #361 remains open until the Gate 7 authority switch. Sequence diagram for record-class admission and R-15 codec enforcementsequenceDiagram
participant Caller
participant Codec
participant Disposition
participant Envelope
participant Crypto
Caller->>Codec: seal_record(key, identity, meta, plaintext)
Codec->>Disposition: is_r15_record_class(identity.class())
alt MIGRATE_TO_R15 or NativeControlPlane
Disposition-->>Codec: true
Codec->>Envelope: build WSR1 envelope
Codec->>Crypto: encrypt payload with canonical AAD
Crypto-->>Codec: ciphertext
Codec-->>Caller: Ok(record)
else RetainSeparateAuthority or no disposition
Disposition-->>Codec: false
Codec-->>Caller: Err(NotAnR15RecordClass)
end
Caller->>Codec: open_record(key, identity, bytes)
Codec->>Disposition: is_r15_record_class(identity.class())
alt admitted R-15 class
Disposition-->>Codec: true
Codec->>Envelope: parse_envelope(bytes)
Codec->>Crypto: decrypt and authenticate
Crypto-->>Codec: plaintext
Codec-->>Caller: Ok(OpenedRecord)
else refused class
Disposition-->>Codec: false
Codec-->>Caller: Err(NotAnR15RecordClass)
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Oct 1, 2026 7:33a.m. | Review ↗ | |
| Python | Oct 1, 2026 7:33a.m. | Review ↗ | |
| Rust | Oct 1, 2026 7:33a.m. | Review ↗ | |
| Shell | Oct 1, 2026 7:33a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
CodeAnt Nitpicks1 code suggestion1. Adding variants to these public exhaustive enums breaks downstream Rust callers that match
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4288e63ade
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
All reported issues were addressed across 8 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
…point (#445) Correction wave for the first epoch on 4288e63 (cubic P1 + 6 P3, Codex 3 P2): - The raw `seal`/`open` primitives, which take a public RecordContext, did not check the disposition, so retained-authority classes could still become WSR1 envelopes through them. They now refuse those classes with NotAnR15RecordClass. `open_record` keeps its pre-parse check, and the test now also presents truncated bytes to prove that ordering. - `commit_marker` accepted credential and IDB salt/sentinel identities and produced sealable control-plane markers. Ordinary markers now exist only for MIGRATE_TO_R15 classes other than the two asset-pair members. - Contract: the header no longer says 1b-platform is in progress, and §20 explains how its 31/7/3 token counts relate to §10.4.1's 28/5/3 class rows. The disposition table's comments now state that mapping correctly, and the ledger owner cell records the headless implementation. - The Gate 2 identity tests now pin the 29 ordinary-marker classes and run the all-pairs substitution proof over every R-15 identity.
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
|
[check-pr-size] PR size is over the target tier (normal profile): 13 files, 313 meaningful lines, 3 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
|
@codex review |
|
Codex Review: Didn't find any major issues. Delightful! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
All reported issues were addressed across 10 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
User description
Summary
Gate 2 closure for #920 (R-15 #445), after slice 1 (#917) and slice A (#928).
disposition()(src/disposition.rs) mirrors contract §10.4.1's exhaustive registry class by class. No class defaults toMIGRATE_TO_R15by omission.MIGRATE_TO_R15authority-root,record-catalog,key-epoch,record-commit,asset-pair,migration,migration-pageRETAIN_APPROVED_SEPARATE_PROTECTED_AUTHORITYcredential,idb-kdf-salt,idb-passphrase-sentinelCodec gate:
seal_record/open_recordaccept only the first two groups. A retained-authority class, or one without an admitted disposition, is refused before any parsing or cryptography (NotAnR15RecordClass). Credentials and the B-1 IDB salt and sentinel therefore never become R-15 ciphertext, which §10.4.1 requires ("no R-15 ciphertext is created"). Before this PR, the codec would have sealed them.Scope decision, from the contract
#920's admission planned a "Slice B — legacy source-locator adapters". On re-reading §20, the contract assigns per-class legacy migration adapters, discovery and inventory to Gate 5 ("each needs a Core or WebView adapter migration/refusal result"; §15.3
MigrationSourceAdapter). Building them here would pull Gate 5 forward, so §20 now records that assignment, and this PR is the Gate 2 closure.#361
Core evidence is complete across #917, #928 and this PR: registry, canonical AAD, identity-bound codec, substitution, modified-AAD and relocation tests. The defect #361 describes, however, is in the shipped filesystem helper, and that stays unchanged until the Gate 7 authority switch. #361 therefore stays open, and its contract row now says it closes with #925.
Also corrected
The contract status statements described Gate 1b as "in progress", but it is implemented (#850, #854, #855, #914, #915, #916); they now also record Gate 2 as implemented headless. The ledger token is updated as well.
Local proof
cargo fmt --check,clippy --all-targets -D warnings, 179 crate tests (4 new),cargo +1.77.2 check --all-targets,RUSTDOCFLAGS=-D warnings cargo doc,pnpm run ci:prepush: all pass.Headless only; no I/O, migration, app wiring or authority change.
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Part of #920
Part of #445
Summary by Sourcery
Close the R-15 Gate 2 record-class admission gap by explicitly classifying every record type and refusing non-R-15 classes before parsing or cryptographic processing.
New Features:
Bug Fixes:
Enhancements:
Documentation:
Tests:
Chores:
Summary by cubic
Closes Gate 2 by adding the §10.4.1 record-class disposition, so every codec entry point —
seal_record/open_recordand the rawseal/openprimitives — now refuses retained-authority and unrelated classes before any parsing or cryptography, andcommit_markerno longer produces ordinary markers for them, instead of sealing them as R-15 ciphertext.disposition()mirrors the contract's exhaustive registry: 31MIGRATE_TO_R15tokens, 7 native control-plane tokens, and 3RETAIN_APPROVED_SEPARATE_PROTECTED_AUTHORITYtokens.SealError/OpenError::NotAnR15RecordClassfires for refused classes; credentials, the IDB KDF salt, and the passphrase sentinel never become R-15 ciphertext or get ordinary commit markers.MIGRATE_TO_R15classes (excluding the two asset-pair members) have ordinary markers.Scope and doc updates
§15.3), matching where the contract already places per-class migration adapters.#361stays open because the shipped filesystem helper is unchanged until the Gate 7 authority switch.Written for commit d32ec4f. Summary will update on new commits.
CodeAnt-AI Description
Enforce which record classes may use R-15 protected envelopes
What Changed
Impact
✅ Credentials and browser key material stay out of ordinary R-15 records✅ Unapproved record classes fail closed before parsing or decryption✅ Clearer Gate 2 implementation status💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
Summary by CodeRabbit