Skip to content

feat(core): add the Gate 3 slice 3C root slot, pointer and key-epoch record encodings (#445) - #943

Merged
qnbs merged 6 commits into
mainfrom
feat/445-gate3c-root-records
Oct 2, 2026
Merged

qnbs merged 6 commits into
mainfrom
feat/445-gate3c-root-records

Conversation

@qnbs

@qnbs qnbs commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #445 / #921 (Gate 3, slice 3C, part 3a). No production authority switch: PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Why a contract amendment

§5.3/§5.3.1 fix the two-phase root commit's state machine, and §5.4 fixes its digests. The contract did not specify the three byte formats that commit persists, though: the root slot payload, the active-slot pointer, and the key-epoch control record (§8.3 gives only its statuses). This PR fixes them in a new §5.3.4, as version-1 constants, before any code persists them.

  • Root slot:
    • stored as authority-root:<scope> at record_generation = root_generation;
    • the payload is u32be(1) + canonical_root_body_bytes, which is exactly §5.4's root_digest input after the domain;
    • decoding is strict, and the envelope generation must equal the body's.
  • Active-slot pointer:
    • 81 unencrypted bytes: "WSRP", version, slot code, generation, root_digest, pointer_digest;
    • it holds no project content or key material;
    • it is recoverable state only, and the anchor always wins a disagreement.
  • Key-epoch control record:
    • stored as key-epoch:<scope>:<epoch> at record_generation = registry_generation;
    • the payload is version, epoch, §8.3 status (1–4) and the opaque key route (1–256 bytes), with no key material;
    • its set entry is (epoch, registry_generation, content_digest(envelope)).

What lands

  • root.rs:
    • new encode_root_body and strict decode_root_body;
    • root_digest now hashes the explicit canonical body. This is byte-identical: the pinned 3C1 vectors are unchanged and pass.
  • root_record.rs:
    • seal_root_slot / open_root_slot (open_root_slot returns the body plus its recomputed digest);
    • RootPointer::encode / decode;
    • KeyEpochRecord encode/decode/seal/open, where open yields its KeyEpochEntry.

Proof

tests/gate3c_root_record_test.rs has 9 tests:

  • root-slot round trip to the pinned 3C1 root_digest;
  • scope and generation binding;
  • strict body decoding: every truncation, trailing bytes, non-canonical state and live codes, invalid counters;
  • pointer layout against the pinned 3C1 pointer_digest vector, and refusal of every malformed or unbound pointer;
  • key-epoch layout, unknown statuses and route bounds;
  • seal/open yielding the set entry, bound to epoch and generation.

Locally, clippy is clean and pnpm docs:check passes.

Docs

  • Contract §5.3.4 is new, there is a new §20 slice 3C part 3a entry, and the status sentences are updated.
  • R15_GATE3=SLICE_3C_ROOT_RECORDS is set in the block and in ledger row 10.

Next: 3C part 3b, the §5.3.1 A–G root commit with its crash-recovery table and trusted cold start, wired into the write protocol with list_records, retention and the tracked acceptance items.

Summary by Sourcery

Define and validate the persisted Gate 3 root and key-epoch record formats without enabling production authority switching.

New Features:

  • Add versioned encoding, strict decoding, sealing, and opening for authority root slots, active-slot pointers, and key-epoch control records.

Bug Fixes:

  • Reject malformed, non-canonical, unbound, cross-scope, cross-generation, and cross-epoch root records instead of accepting them as authority.

Enhancements:

  • Refactor root digest computation around an explicit canonical root-body encoding while preserving existing digest vectors.

Documentation:

  • Document the version-1 root slot, pointer, and key-epoch formats and advance the Gate 3 implementation status to the root-record slice.

Tests:

  • Add coverage for record round trips, pinned layouts and digests, identity and generation binding, counter validation, and malformed-input rejection.

Chores:

  • Keep the implementation headless with no production authority switch or root commit flow enabled.

Summary by cubic

Adds the Gate 3 slice 3C root slot, active-slot pointer, and key-epoch record encodings, fixing the three byte formats the two-phase root commit persists before any code writes them. No production authority switch; this is headless implementation only.

  • New root_record module seals, opens, and strictly decodes the three records per the new contract §5.3.4.
  • Root slots are bound to their own active_key_epoch; key-epoch records validate both their epoch and registry generation counters via a KeyEpochAddress before any comparison, so unassigned counters are refused as InvalidCounter.
  • root_digest now hashes an explicit canonical root body instead of inline fields; output is byte-identical and the pinned 3C1 vectors still pass.
  • Decoding is strict: truncation, trailing bytes, non-canonical state/status codes, and invalid counters are all refused.
  • The pointer is recoverable state only and holds no project content or key material; the anchor always wins a disagreement.
  • Contract §5.3.4, the migration ledger, and the changelog document the new formats and advance R15_GATE3=SLICE_3C_ROOT_RECORDS.
  • 12 tests cover round trips, scope/generation binding on both key-epoch address counters, layout against pinned digests, and refusal of malformed input.

Written for commit 9cdfef2. Summary will update on new commits.

Review in cubic


CodeAnt-AI Description

Define and validate persisted root and key-epoch record formats

What Changed

  • Protected storage can now seal and open authority-root records tied to their scope and generation, returning the verified root digest.
  • Added strict encoding and decoding for the 81-byte active-slot pointer, rejecting invalid formats, slot values, generations, and tampered digests.
  • Added sealed key-epoch records containing the epoch status and opaque key route, with invalid statuses, routes, identities, and generations refused.
  • Root-body decoding now rejects truncated, trailing, non-canonical, or invalid values while preserving the existing root-digest vectors.
  • Added contract documentation and tests for valid round trips and malformed-record refusal; no production authority switch or commit flow is enabled.

Impact

✅ Fewer invalid authority records accepted
✅ Tampered root pointers are refused
✅ Clearer key-epoch and root-record compatibility

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • New Features
    • Added versioned, authenticated storage records for authority roots and key epochs, plus a strictly validated pointer format. Root records can be sealed and opened; key-epoch records can be encoded, sealed, validated, and opened.
    • Added strict decoding that rejects malformed, noncanonical, or mismatched records.
  • Documentation
    • Documented the record formats and their validation rules. These records are not yet used for commits; commit sequencing and crash recovery remain outstanding, and production authority is unchanged.

…record encodings (#445)

Contract §5.3.4 fixes the three byte formats the two-phase root commit persists, which the
contract left open: the root slot (format version + canonical root body, sealed as
authority-root:<scope> at root_generation), the 81-byte active-slot pointer bound by
pointer_digest, and the key-epoch control record (epoch, §8.3 status, opaque key route). The
root_record module seals/opens and strictly decodes them; root_digest now hashes the explicit
canonical root body (byte-identical, pinned vectors unchanged).
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 2, 2026 12:11am UTC

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 33 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: aa10d90b-005b-4cba-a08d-40f59351b2ff

📥 Commits

Reviewing files that changed from the base of the PR and between da6a232 and 9cdfef2.

📒 Files selected for processing (3)
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/root_record.rs
  • crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: d84cfb62-84e6-41e3-80dc-53cc97e7b018

📥 Commits

Reviewing files that changed from the base of the PR and between d1d49a5 and da6a232.

📒 Files selected for processing (7)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/root.rs
  • crates/worldscript-secure-storage/src/root_record.rs
  • crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The change adds canonical root-body encoding and decoding, plus version-1 codecs for root slots, active-slot pointers, and key-epoch records. It exposes these APIs and adds tests and contract updates. The records are not yet used for commits.

Changes

Secure-storage record formats

Layer / File(s) Summary
Canonical root-body codec
crates/worldscript-secure-storage/src/root.rs
Adds public root-body encoding and strict decoding. root_digest hashes the root domain with the canonical encoded body.
Root slots and active-slot pointers
crates/worldscript-secure-storage/src/root_record.rs, crates/worldscript-secure-storage/src/lib.rs, crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs, docs/native/R15-SECURE-STORAGE-CONTRACT.md
Adds root-slot sealing and opening with schema, generation, and epoch checks. Adds a digest-bound pointer codec with strict format validation. Exposes the record APIs and tests the root and pointer formats.
Key-epoch records and admission status
crates/worldscript-secure-storage/src/root_record.rs, crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs, CHANGELOG.md, docs/native/CORE-MIGRATION-LEDGER.md, docs/native/R15-SECURE-STORAGE-CONTRACT.md
Adds key-epoch encoding, sealing, opening, and validation for status, route, identity, schema, and registry generation. Tests these behaviors and updates the changelog and Gate 3 status. Root-commit wiring, list_records, retention, and production authority switching remain outstanding.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to da6a2

No concrete merge-blocking issue remains identified. This change adds record formats without enabling production commits or authority switching; it is mergeable subject to normal checks.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR adds the contract-defined, version-1 codecs and authenticated sealing/opening helpers for root slots, active-slot pointers, and key-epoch records, refactors root hashing around an explicit canonical body encoding, and validates the layouts with pinned vectors and strict malformed-input tests. It is headless only: no commit protocol, I/O, or production authority switch is introduced.

Sequence diagram for strict root slot sealing and opening

sequenceDiagram
    participant Caller
    participant RootRecord as root_record
    participant RecordCodec as seal_record_open_record
    participant Root as root

    Caller->>RootRecord: seal_root_slot(key, scope, root, key_epoch)
    RootRecord->>Root: encode_root_body(root)
    RootRecord->>RecordCodec: seal_record(..., root_generation, payload)
    RecordCodec-->>RootRecord: sealed envelope
    RootRecord-->>Caller: root slot envelope

    Caller->>RootRecord: open_root_slot(key, scope, root_generation, envelope)
    RootRecord->>RecordCodec: open_record(key, authority-root, envelope)
    RecordCodec-->>RootRecord: authenticated payload and header
    RootRecord->>Root: decode_root_body(body)
    RootRecord->>Root: root_digest(root)
    RootRecord-->>Caller: RootBody and recomputed digest
Loading

File-Level Changes

Change Details Files
Defines and implements version-1 persisted encodings for authority-root slots, active-slot pointers, and key-epoch control records.
  • Adds the §5.3.4 format constants and documents field layouts, identity bindings, generation rules, and digest behavior.
  • Adds root-slot sealing/opening with strict body decoding and envelope/body generation consistency checks.
  • Adds the fixed 81-byte pointer codec with magic, version, slot, generation, root digest, and self-binding pointer digest.
  • Adds key-epoch status and opaque key-route encoding, sealing/opening, route bounds, and set-entry derivation from envelope content digests.
crates/worldscript-secure-storage/src/root_record.rs
crates/worldscript-secure-storage/src/lib.rs
docs/native/R15-SECURE-STORAGE-CONTRACT.md
Makes root-body serialization explicit and canonical while preserving the existing root-digest vectors.
  • Splits canonical root-body encoding from domain-separated SHA-256 digest computation.
  • Adds strict big-endian decoding with truncation, trailing-byte, non-canonical flag/state, UTF-8, operation, counter, and live-migration validation.
  • Exports the encoding and decoding APIs and the root commit-state code mapping.
crates/worldscript-secure-storage/src/root.rs
crates/worldscript-secure-storage/src/lib.rs
Adds contract-vector and adversarial coverage for all three record formats.
  • Covers root-slot round trips, pinned root digests, scope binding, generation binding, and strict body rejection cases.
  • Covers pointer layout, pinned pointer digest, malformed inputs, unsupported versions, invalid slots, and altered bindings.
  • Covers key-epoch layout, status and route validation, sealing/opening, identity and generation binding, and content-digest set entries.
crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs
Updates Gate 3 documentation and implementation status without enabling production authority.
  • Records slice 3C part 3a as implemented headlessly and updates the migration ledger and contract status markers.
  • Explicitly keeps the production authority switch disabled and defers the two-phase commit, recovery, list-records, and retention work to part 3b.
docs/native/CORE-MIGRATION-LEDGER.md
docs/native/R15-SECURE-STORAGE-CONTRACT.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 9cdfef28
Scan Time: 2026-10-02 00:30:58 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found, 2 false positive secrets suppressed
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED No IAC issues

View Full Results

@deepsource-io

deepsource-io Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in d1d49a5...9cdfef2 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 2, 2026 12:10a.m. Review ↗
Python Oct 2, 2026 12:10a.m. Review ↗
Rust Oct 2, 2026 12:10a.m. Review ↗
Shell Oct 2, 2026 12:10a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@qnbs
qnbs marked this pull request as ready for review October 1, 2026 23:20
@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 6 days and 3 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR b8092f3 Oct 01, 2026 · 23:20 23:23

@codeant-ai

codeant-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

codescene-access[bot]

This comment was marked as outdated.

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Oct 1, 2026
codescene-access[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 7 files, 918 meaningful lines, 6 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated
Comment thread crates/worldscript-secure-storage/src/root_record.rs
Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread CHANGELOG.md Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated
Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated
Comment thread crates/worldscript-secure-storage/src/root_record.rs
Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

…s and reconcile the §5.3 journal-revision wording (#445)

Review wave on PR #943: a root slot is sealed under and checked against its own active_key_epoch;
key-epoch records validate registry_generation through a KeyEpochAddress; the duplicate key-route
bound is gone in favour of the provider's; §5.3.4 reconciles §5.3's journal-revision wording with
§5.4's encoding and reserves the extra key-epoch fields for a later format version.
Comment thread crates/worldscript-secure-storage/src/root_record.rs Outdated
codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/src/root_record.rs
codescene-access[bot]

This comment was marked as outdated.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs Outdated
Comment thread crates/worldscript-secure-storage/tests/gate3c_root_record_test.rs
codescene-access[bot]

This comment was marked as outdated.

#445)

d504504 pushed a new lifecycle test that failed: seal compared the address epoch with the record
before validating the address counters, so an epoch-0 address reported 'another epoch' instead of
InvalidCounter. The address is now validated first.

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs
qnbs enabled auto-merge (squash) October 2, 2026 00:30
@qnbs
qnbs merged commit 238e56c into main Oct 2, 2026
51 checks passed
@qnbs
qnbs deleted the feat/445-gate3c-root-records branch October 2, 2026 00:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL This PR changes 500-999 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant