feat(core): add the Gate 3 slice 3C two-phase root commit, crash recovery and trusted cold start (#445) - #944
Conversation
…very and trusted cold start (#445) commit_root runs contract §5.3.1 A-G against the KeyProvider's secure anchor: pre-write checks, anchor prepare, the target slot written directly in COMMITTED form through slice 3A's staging and re-authenticated to the prepared digest, the pointer replaced by write-sync-rename-sync, then the anchor commit. recover_root completes forward only on an exactly authenticating target slot and otherwise discards the preparation, relocating a non-matching slot. load_committed_root is the trusted cold start (steps 0-4) and repairs a stale pointer to the anchor root. DurableFs gains rename_replace for the pointer; the 3-OS CI step runs the new tests.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 11 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 82 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (5)
📝 WalkthroughWalkthroughThe secure-storage crate adds two-phase root commits, recovery of interrupted commits, and trusted cold-start loading. Cold start validates the committed slot against secure-anchor state and repairs a stale or missing pointer. Integration tests cover commit failure windows and altered or missing stored state. ChangesSecure Root Commit
Priority: ⬇️ Low Merge Risk: 🟡 Moderate · up to Interrupted commits followed by target-slot tampering can be silently discarded instead of requiring recovery. Fix this contract violation before merging; production authority remains disabled.
Comment |
Reviewer's GuideThis PR adds a headless two-phase authority-root commit implementation backed by the secure anchor, including durable alternating-slot publication, atomic pointer replacement, crash recovery, trusted cold start, fault-injected cross-platform tests, and corresponding R-15 status documentation; production authority remains unchanged. Sequence diagram for two-phase authority-root commitsequenceDiagram
participant Caller
participant RootStore
participant KeyProvider
participant DurableFs
Caller->>RootStore: commit_root()
RootStore->>KeyProvider: read_root_anchor_state()
RootStore->>RootStore: pre-write validation
RootStore->>KeyProvider: prepare_root_anchor()
RootStore->>DurableFs: stage_and_promote() target slot
RootStore->>DurableFs: read target slot
RootStore->>KeyProvider: resolve_ref()
RootStore->>DurableFs: create_new() pointer temporary
RootStore->>DurableFs: sync_file()
RootStore->>DurableFs: rename_replace() pointer
RootStore->>DurableFs: sync_dir()
RootStore->>DurableFs: read pointer
RootStore->>KeyProvider: commit_root_anchor()
RootStore-->>Caller: RootCommitted
State diagram for root commit crash recoverystateDiagram-v2
[*] --> NoPreparation
NoPreparation --> Prepared: prepare_root_anchor()
Prepared --> TargetReady: target slot authenticates to prepared digest
Prepared --> Discarded: target missing or mismatched
TargetReady --> PointerWritten: ensure_pointer()
PointerWritten --> Committed: commit_root_anchor()
Discarded --> NoPreparation: abort_or_recover_root_anchor()
Committed --> NoPreparation
Prepared --> Prepared: read failure
TargetReady --> TargetReady: read failure
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Oct 2, 2026 2:01a.m. | Review ↗ | |
| Python | Oct 2, 2026 2:01a.m. | Review ↗ | |
| Rust | Oct 2, 2026 2:01a.m. | Review ↗ | |
| Shell | Oct 2, 2026 2:01a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
@codex review |
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
[check-pr-size] PR size is over the target tier (normal profile): 12 files, 1141 meaningful lines, 4 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
CodeAnt Nitpicks1 code suggestion1.
|
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
Review profile: CHILL
Plan: Essentials
Run ID: 16fc5786-54bd-4627-851f-9dde44e7dec0
📒 Files selected for processing (12)
.github/workflows/ci.ymlCHANGELOG.mdcrates/worldscript-secure-storage/src/commit.rscrates/worldscript-secure-storage/src/durable.rscrates/worldscript-secure-storage/src/lib.rscrates/worldscript-secure-storage/src/root_record.rscrates/worldscript-secure-storage/src/root_store.rscrates/worldscript-secure-storage/tests/gate3_durable_test.rscrates/worldscript-secure-storage/tests/gate3c_root_commit_test.rscrates/worldscript-secure-storage/tests/support/mod.rsdocs/native/CORE-MIGRATION-LEDGER.mddocs/native/R15-SECURE-STORAGE-CONTRACT.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
There was a problem hiding this comment.
Review completed against the latest diff
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
1 issue found across 12 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="crates/worldscript-secure-storage/src/lib.rs">
<violation number="1" location="crates/worldscript-secure-storage/src/lib.rs:11">
P3: The module list sentence lost its conjunction: it now reads "record catalog ([`catalog`]) persisted root records" without a separator between the two list items. Restore the "and" so the enumeration reads cleanly.</violation>
</file>
Requires human review: Auto-approval blocked because this review re-detected 2 unresolved issues already reported by Cubic.
Re-trigger cubic
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
… and harden root recovery (#445) Review wave on PR #944: recovery returns RECOVERY_REQUIRED, touching nothing, when the pointer already names a prepared target that does not authenticate (§5.3.1 after E2, before F); it discards and relocates only while the pointer names the prior root, then repairs the pointer to the committed root; it re-syncs the target slot directory before committing the anchor; loaded and completed roots must carry COMMITTED evidence; a request scope other than the anchor's is refused; the relocation error kind is preserved. Tests add the unproven-target, scope, failed-rename and discard-repair cases.
There was a problem hiding this comment.
All reported issues were addressed across 5 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
…! in the fault filesystem (#445)
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
User description
Part of #445 / #921 (Gate 3, slice 3C, part 3b). No production authority switch:
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.What lands (
crates/worldscript-secure-storage/src/root_store.rs)This module runs contract §5.3.1 against the
KeyProvidersecure anchor from Gate 1b. The anchor holds the rollback floor andcommitted_root, and is the sole publication authority.commit_root, steps A–Gcommitted_floor + 1, the evidence isCOMMITTED, androot_key_ref_digestequals the route's digest.COMMITTEDform through 3A's staging, as §5.3.1 admits, then re-authenticate it to exactlytarget_final_root_digest.rename_replace→ directory sync, then read it back.recover_root, the §5.3.1 crash tableload_committed_root, the trusted cold start (steps 0–4)DurableFs::rename_replaceProof
tests/gate3c_root_commit_test.rshas 9 tests, run with the fault-injectingMemoryKeyProviderplus filesystem faults:RECOVERY_REQUIRED);The 3-OS CI step now also runs these tests on macOS and Windows (
CI_ONLY, not power-loss evidence). Locally, clippy is clean, the full crate suite passes, andpnpm docs:checkpasses.Not in this part (the rest of slice 3C)
list_recordsand retention.root_commit_mutexand exclusive admission.Docs
R15_GATE3=SLICE_3C_ROOT_COMMITis set in the block and in ledger row 10.Summary by Sourcery
Implement crash-safe authority-root publication with secure-anchor recovery and trusted startup validation without enabling production authority switching.
New Features:
Bug Fixes:
Enhancements:
CI:
Documentation:
Tests:
Summary by cubic
Implements Gate 3 slice 3C part 3b in
worldscript-secure-storage: the two-phase authority-root commit, crash recovery, and trusted cold start (contract §5.3.1), still headless — no production authority switch (PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO).commit_rootruns §5.3.1 A–G: pre-write checks (generation exactly floor+1,COMMITTEDevidence, key-route digest, anchor scope), anchor prepare, target slot written directly inCOMMITTEDform and re-authenticated, pointer replaced by write-sync-rename-sync, then the anchor commit.recover_rootcompletes forward only when the target slot authenticates to exactly the prepared digest withCOMMITTEDevidence, re-syncing its directory first; a pointer that already names a target the anchor cannot prove it authorized fails closed withRECOVERY_REQUIREDand touches nothing; only while the pointer names the prior root does it discard the preparation, relocate the non-matching slot (never deleting), and repair the pointer to the committed root.load_committed_rootis the trusted cold start: scope, slot, generation, digest, evidence, and key route come only from the secure anchor, and a stale or missing pointer is repaired to the committed root.DurableFsgainsrename_replace, used only for the recoverable pointer, never for generation files.R15_GATE3=SLICE_3C_ROOT_COMMIT.The rest of slice 3C (cold-start step 5 key-epoch verification, write-protocol integration,
list_recordsand retention) and Gate 4'sroot_commit_mutexremain future work.Written for commit b8b2e0f. Summary will update on new commits.
CodeAnt-AI Description
Add crash-safe authority-root commits and trusted startup recovery
What Changed
Impact
✅ Crash-safe root publication✅ Fail-closed startup on tampered or missing roots✅ Automatic recovery from stale pointers💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
Summary by CodeRabbit
New Features
Tests