feat(core): add the Gate 3 slice 3C root slot, pointer and key-epoch record encodings (#445) - #943
Conversation
…record encodings (#445) Contract §5.3.4 fixes the three byte formats the two-phase root commit persists, which the contract left open: the root slot (format version + canonical root body, sealed as authority-root:<scope> at root_generation), the 81-byte active-slot pointer bound by pointer_digest, and the key-epoch control record (epoch, §8.3 status, opaque key route). The root_record module seals/opens and strictly decodes them; root_digest now hashes the explicit canonical root body (byte-identical, pinned vectors unchanged).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 33 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (3)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (7)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe change adds canonical root-body encoding and decoding, plus version-1 codecs for root slots, active-slot pointers, and key-epoch records. It exposes these APIs and adds tests and contract updates. The records are not yet used for commits. ChangesSecure-storage record formats
Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to No concrete merge-blocking issue remains identified. This change adds record formats without enabling production commits or authority switching; it is mergeable subject to normal checks.
Comment |
Reviewer's GuideThis PR adds the contract-defined, version-1 codecs and authenticated sealing/opening helpers for root slots, active-slot pointers, and key-epoch records, refactors root hashing around an explicit canonical body encoding, and validates the layouts with pinned vectors and strict malformed-input tests. It is headless only: no commit protocol, I/O, or production authority switch is introduced. Sequence diagram for strict root slot sealing and openingsequenceDiagram
participant Caller
participant RootRecord as root_record
participant RecordCodec as seal_record_open_record
participant Root as root
Caller->>RootRecord: seal_root_slot(key, scope, root, key_epoch)
RootRecord->>Root: encode_root_body(root)
RootRecord->>RecordCodec: seal_record(..., root_generation, payload)
RecordCodec-->>RootRecord: sealed envelope
RootRecord-->>Caller: root slot envelope
Caller->>RootRecord: open_root_slot(key, scope, root_generation, envelope)
RootRecord->>RecordCodec: open_record(key, authority-root, envelope)
RecordCodec-->>RootRecord: authenticated payload and header
RootRecord->>Root: decode_root_body(body)
RootRecord->>Root: root_digest(root)
RootRecord-->>Caller: RootBody and recomputed digest
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Oct 2, 2026 12:10a.m. | Review ↗ | |
| Python | Oct 2, 2026 12:10a.m. | Review ↗ | |
| Rust | Oct 2, 2026 12:10a.m. | Review ↗ | |
| Shell | Oct 2, 2026 12:10a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
@codex review |
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
[check-pr-size] PR size is over the target tier (normal profile): 7 files, 918 meaningful lines, 6 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 7 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
…s and reconcile the §5.3 journal-revision wording (#445) Review wave on PR #943: a root slot is sealed under and checked against its own active_key_epoch; key-epoch records validate registry_generation through a KeyEpochAddress; the duplicate key-route bound is gone in favour of the provider's; §5.3.4 reconciles §5.3's journal-revision wording with §5.4's encoding and reserves the extra key-epoch fields for a later format version.
There was a problem hiding this comment.
All reported issues were addressed across 5 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
User description
Part of #445 / #921 (Gate 3, slice 3C, part 3a). No production authority switch:
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Why a contract amendment
§5.3/§5.3.1 fix the two-phase root commit's state machine, and §5.4 fixes its digests. The contract did not specify the three byte formats that commit persists, though: the root slot payload, the active-slot pointer, and the key-epoch control record (§8.3 gives only its statuses). This PR fixes them in a new §5.3.4, as version-1 constants, before any code persists them.
authority-root:<scope>atrecord_generation = root_generation;u32be(1)+canonical_root_body_bytes, which is exactly §5.4'sroot_digestinput after the domain;"WSRP", version, slot code, generation,root_digest,pointer_digest;key-epoch:<scope>:<epoch>atrecord_generation = registry_generation;(epoch, registry_generation, content_digest(envelope)).What lands
root.rs:encode_root_bodyand strictdecode_root_body;root_digestnow hashes the explicit canonical body. This is byte-identical: the pinned 3C1 vectors are unchanged and pass.root_record.rs:seal_root_slot/open_root_slot(open_root_slotreturns the body plus its recomputed digest);RootPointer::encode/decode;KeyEpochRecordencode/decode/seal/open, whereopenyields itsKeyEpochEntry.Proof
tests/gate3c_root_record_test.rshas 9 tests:root_digest;pointer_digestvector, and refusal of every malformed or unbound pointer;Locally, clippy is clean and
pnpm docs:checkpasses.Docs
R15_GATE3=SLICE_3C_ROOT_RECORDSis set in the block and in ledger row 10.Next: 3C part 3b, the §5.3.1 A–G root commit with its crash-recovery table and trusted cold start, wired into the write protocol with
list_records, retention and the tracked acceptance items.Summary by Sourcery
Define and validate the persisted Gate 3 root and key-epoch record formats without enabling production authority switching.
New Features:
Bug Fixes:
Enhancements:
Documentation:
Tests:
Chores:
Summary by cubic
Adds the Gate 3 slice 3C root slot, active-slot pointer, and key-epoch record encodings, fixing the three byte formats the two-phase root commit persists before any code writes them. No production authority switch; this is headless implementation only.
root_recordmodule seals, opens, and strictly decodes the three records per the new contract §5.3.4.active_key_epoch; key-epoch records validate both their epoch and registry generation counters via aKeyEpochAddressbefore any comparison, so unassigned counters are refused asInvalidCounter.root_digestnow hashes an explicit canonical root body instead of inline fields; output is byte-identical and the pinned 3C1 vectors still pass.R15_GATE3=SLICE_3C_ROOT_RECORDS.Written for commit 9cdfef2. Summary will update on new commits.
CodeAnt-AI Description
Define and validate persisted root and key-epoch record formats
What Changed
Impact
✅ Fewer invalid authority records accepted✅ Tampered root pointers are refused✅ Clearer key-epoch and root-record compatibility💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
Summary by CodeRabbit