Skip to content

feat(core): add the Gate 3 slice 3C two-phase root commit, crash recovery and trusted cold start (#445) - #944

Merged
qnbs merged 4 commits into
mainfrom
feat/445-gate3c-root-commit
Oct 2, 2026
Merged

qnbs merged 4 commits into
mainfrom
feat/445-gate3c-root-commit

Conversation

@qnbs

@qnbs qnbs commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #445 / #921 (Gate 3, slice 3C, part 3b). No production authority switch: PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

What lands (crates/worldscript-secure-storage/src/root_store.rs)

This module runs contract §5.3.1 against the KeyProvider secure anchor from Gate 1b. The anchor holds the rollback floor and committed_root, and is the sole publication authority.

commit_root, steps A–G

  1. Pre-write checks, before anything durable: the generation is exactly committed_floor + 1, the evidence is COMMITTED, and root_key_ref_digest equals the route's digest.
  2. C: prepare the anchor.
  3. D+E1: write the target slot (the one the committed root does not occupy) directly in its COMMITTED form through 3A's staging, as §5.3.1 admits, then re-authenticate it to exactly target_final_root_digest.
  4. E2: replace the pointer by write → sync → rename_replace → directory sync, then read it back.
  5. F: commit the anchor.

recover_root, the §5.3.1 crash table

  • Completes forward only when the target slot authenticates to exactly the prepared digest, writing the pointer if E2 never happened.
  • Otherwise discards the preparation and relocates a non-matching target slot (never deleting it), so a retry can reuse the generation name.
  • A read failure decides nothing.

load_committed_root, the trusted cold start (steps 0–4)

  • The scope, slot, generation, digest and key route come only from the anchor.
  • The slot must authenticate to exactly the committed digest and bind the committed route.
  • A pending preparation must be recovered first.
  • A stale or missing pointer is repaired to the committed root, because the anchor always wins.

DurableFs::rename_replace

  • Used only for the recoverable pointer, never for a generation file.

Proof

tests/gate3c_root_commit_test.rs has 9 tests, run with the fault-injecting MemoryKeyProvider plus filesystem faults:

  • alternating slots and the cold start;
  • refusals before any durable write;
  • every §5.3.1 crash window:
    • after C, with no slot written → discarded;
    • after E1, before E2 → completed forward;
    • after E2, before F → completed forward;
    • an ambiguous F that landed → nothing pending;
  • a tampered target slot (relocated, then the retry succeeds);
  • a tampered or missing committed slot (RECOVERY_REQUIRED);
  • a stale or missing pointer (repaired).

The 3-OS CI step now also runs these tests on macOS and Windows (CI_ONLY, not power-loss evidence). Locally, clippy is clean, the full crate suite passes, and pnpm docs:check passes.

Not in this part (the rest of slice 3C)

  • Cold-start step 5, verifying the root's key-epoch set. This needs persisted key-epoch records.
  • Write-protocol integration: catalog plus root per marker transition, including dropping a rolled-back first write.
  • list_records and retention.
  • Gate 4 owns root_commit_mutex and exclusive admission.

Docs

  • Contract §20 has a new slice 3C part 3b entry, and the status sentences are updated.
  • R15_GATE3=SLICE_3C_ROOT_COMMIT is set in the block and in ledger row 10.

Summary by Sourcery

Implement crash-safe authority-root publication with secure-anchor recovery and trusted startup validation without enabling production authority switching.

New Features:

  • Add headless two-phase authority-root commits backed by the secure anchor and durable filesystem root slots.
  • Add crash recovery and trusted cold-start loading that fail closed on untrusted roots and repair stale pointers.

Bug Fixes:

  • Prevent interrupted, tampered, missing, or unproven root states from being treated as authoritative.

Enhancements:

  • Add atomic replacement support for the recoverable root pointer and expose root-store operations through the secure-storage crate.

CI:

  • Run root-commit recovery tests on macOS and Windows CI in addition to Linux.

Documentation:

  • Update the R-15 contract, migration ledger, changelog, and status markers for Gate 3 slice 3C part 3b.

Tests:

  • Add fault-injection coverage for root commit crash windows, recovery outcomes, tampered roots, pointer repair, scope validation, and failed pointer replacement.

Summary by cubic

Implements Gate 3 slice 3C part 3b in worldscript-secure-storage: the two-phase authority-root commit, crash recovery, and trusted cold start (contract §5.3.1), still headless — no production authority switch (PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO).

  • commit_root runs §5.3.1 A–G: pre-write checks (generation exactly floor+1, COMMITTED evidence, key-route digest, anchor scope), anchor prepare, target slot written directly in COMMITTED form and re-authenticated, pointer replaced by write-sync-rename-sync, then the anchor commit.
  • recover_root completes forward only when the target slot authenticates to exactly the prepared digest with COMMITTED evidence, re-syncing its directory first; a pointer that already names a target the anchor cannot prove it authorized fails closed with RECOVERY_REQUIRED and touches nothing; only while the pointer names the prior root does it discard the preparation, relocate the non-matching slot (never deleting), and repair the pointer to the committed root.
  • load_committed_root is the trusted cold start: scope, slot, generation, digest, evidence, and key route come only from the secure anchor, and a stale or missing pointer is repaired to the committed root.
  • DurableFs gains rename_replace, used only for the recoverable pointer, never for generation files.
  • Thirteen tests drive every §5.3.1 crash window plus tampered roots, an unproven pointer target, a foreign scope, and failed renames, against the fault-injecting in-memory provider; the 3-OS CI step runs them on macOS and Windows.
  • The contract ledger, changelog, and surface docs record this part 3b milestone and R15_GATE3=SLICE_3C_ROOT_COMMIT.

The rest of slice 3C (cold-start step 5 key-epoch verification, write-protocol integration, list_records and retention) and Gate 4's root_commit_mutex remain future work.

Written for commit b8b2e0f. Summary will update on new commits.

Review in cubic


CodeAnt-AI Description

Add crash-safe authority-root commits and trusted startup recovery

What Changed

  • New authority roots are committed through a two-phase process that validates the next generation, writes and verifies the root slot, updates the pointer durably, and publishes the secure anchor only after all prior steps succeed.
  • Interrupted commits can complete forward when the prepared root is authentic, or be safely abandoned while preserving invalid files for inspection and retry.
  • Startup now trusts the secure anchor over the filesystem pointer, rejects missing or tampered committed roots, and repairs stale or missing pointers automatically.
  • Added fault-injection coverage for commit failures, recovery paths, tampered roots, and pointer repair across supported filesystem CI environments.

Impact

✅ Crash-safe root publication
✅ Fail-closed startup on tampered or missing roots
✅ Automatic recovery from stale pointers

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • New Features

    • Added secure root commits with two-phase updates, recovery of interrupted commits, and trusted loading on startup. If a saved pointer is stale, it can be repaired from the committed root.
    • Commits reject invalid generations, key routes, or evidence before writing. Recovery fails closed when a committed root is missing or does not match.
    • This functionality does not yet read or write user data.
  • Tests

    • Added coverage for commit failures, recovery scenarios, and startup loading and repair.

…very and trusted cold start (#445)

commit_root runs contract §5.3.1 A-G against the KeyProvider's secure anchor: pre-write checks,
anchor prepare, the target slot written directly in COMMITTED form through slice 3A's staging and
re-authenticated to the prepared digest, the pointer replaced by write-sync-rename-sync, then the
anchor commit. recover_root completes forward only on an exactly authenticating target slot and
otherwise discards the preparation, relocating a non-matching slot. load_committed_root is the
trusted cold start (steps 0-4) and repairs a stale pointer to the anchor root. DurableFs gains
rename_replace for the pointer; the 3-OS CI step runs the new tests.
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 2, 2026 2:02am UTC

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 82 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 5d76c0cf-e5ca-45ad-ae84-a48d25111430

📥 Commits

Reviewing files that changed from the base of the PR and between 7fbce92 and b8b2e0f.

📒 Files selected for processing (5)
  • .github/workflows/ci.yml
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/root_store.rs
  • crates/worldscript-secure-storage/tests/gate3c_root_commit_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
📝 Walkthrough

Walkthrough

The secure-storage crate adds two-phase root commits, recovery of interrupted commits, and trusted cold-start loading. Cold start validates the committed slot against secure-anchor state and repairs a stale or missing pointer. Integration tests cover commit failure windows and altered or missing stored state.

Changes

Secure Root Commit

Layer / File(s) Summary
Root contracts and durable storage primitives
crates/worldscript-secure-storage/src/durable.rs, crates/worldscript-secure-storage/src/root_record.rs, crates/worldscript-secure-storage/src/commit.rs, crates/worldscript-secure-storage/src/root_store.rs, crates/worldscript-secure-storage/src/lib.rs
Adds root-store public types and exports, root-record helpers, and a durable filesystem operation for replacing the root pointer.
Commit, recovery, and trusted loading
crates/worldscript-secure-storage/src/root_store.rs
Adds root preparation and commit, recovery that checks the prepared digest, anchor-trusted cold-start loading, and durable pointer repair.
Crash-window tests and implementation records
crates/worldscript-secure-storage/tests/*, .github/workflows/ci.yml, CHANGELOG.md, docs/native/CORE-MIGRATION-LEDGER.md, docs/native/R15-SECURE-STORAGE-CONTRACT.md
Adds integration tests for commit failures, recovery, tampered or missing slots, and pointer repair. CI runs the new test. The changelog and secure-storage records describe the implemented slice and remaining work.

Priority: ⬇️ Low

Merge Risk: 🟡 Moderate · up to 7fbce

Interrupted commits followed by target-slot tampering can be silently discarded instead of requiring recovery. Fix this contract violation before merging; production authority remains disabled.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR adds a headless two-phase authority-root commit implementation backed by the secure anchor, including durable alternating-slot publication, atomic pointer replacement, crash recovery, trusted cold start, fault-injected cross-platform tests, and corresponding R-15 status documentation; production authority remains unchanged.

Sequence diagram for two-phase authority-root commit

sequenceDiagram
    participant Caller
    participant RootStore
    participant KeyProvider
    participant DurableFs

    Caller->>RootStore: commit_root()
    RootStore->>KeyProvider: read_root_anchor_state()
    RootStore->>RootStore: pre-write validation
    RootStore->>KeyProvider: prepare_root_anchor()
    RootStore->>DurableFs: stage_and_promote() target slot
    RootStore->>DurableFs: read target slot
    RootStore->>KeyProvider: resolve_ref()
    RootStore->>DurableFs: create_new() pointer temporary
    RootStore->>DurableFs: sync_file()
    RootStore->>DurableFs: rename_replace() pointer
    RootStore->>DurableFs: sync_dir()
    RootStore->>DurableFs: read pointer
    RootStore->>KeyProvider: commit_root_anchor()
    RootStore-->>Caller: RootCommitted
Loading

State diagram for root commit crash recovery

stateDiagram-v2
    [*] --> NoPreparation
    NoPreparation --> Prepared: prepare_root_anchor()
    Prepared --> TargetReady: target slot authenticates to prepared digest
    Prepared --> Discarded: target missing or mismatched
    TargetReady --> PointerWritten: ensure_pointer()
    PointerWritten --> Committed: commit_root_anchor()
    Discarded --> NoPreparation: abort_or_recover_root_anchor()
    Committed --> NoPreparation
    Prepared --> Prepared: read failure
    TargetReady --> TargetReady: read failure
Loading

File-Level Changes

Change Details Files
Implements the §5.3.1 two-phase authority-root commit protocol with the secure anchor as the sole publication authority.
  • Validates generation, commit evidence, and key-route digest before durable writes.
  • Prepares the anchor, writes and re-authenticates the alternating target slot through durable staging, atomically replaces and verifies the pointer, then commits the anchor.
  • Exposes the root-store API and factors root-slot plaintext generation for staged writes.
crates/worldscript-secure-storage/src/root_store.rs
crates/worldscript-secure-storage/src/root_record.rs
crates/worldscript-secure-storage/src/lib.rs
Adds crash recovery and trusted cold-start validation for authority roots.
  • Resolves pending preparations forward only when the target slot matches the prepared digest; otherwise aborts preparation and relocates conflicting bytes without deleting them.
  • Loads scope, slot, generation, digest, and key route from the anchor; fails closed on missing or tampered committed slots and repairs stale or missing pointers.
  • Adds atomic pointer replacement support to the durable filesystem abstraction and reuses relocation for rejected target slots.
crates/worldscript-secure-storage/src/root_store.rs
crates/worldscript-secure-storage/src/durable.rs
crates/worldscript-secure-storage/src/commit.rs
crates/worldscript-secure-storage/tests/gate3_durable_test.rs
crates/worldscript-secure-storage/tests/support/mod.rs
Adds comprehensive fault-injection coverage for commit, recovery, and cold-start behavior.
  • Covers alternating slots, pre-write refusals, every crash-table window, ambiguous anchor commits, tampered targets, invalid committed slots, and pointer repair.
  • Runs the root-commit integration test on macOS and Windows in addition to Linux CI.
crates/worldscript-secure-storage/tests/gate3c_root_commit_test.rs
.github/workflows/ci.yml
Updates R-15 documentation and implementation status to record slice 3C part 3b.
  • Documents the A–G commit flow, crash table, cold-start steps 0–4, and explicit exclusions such as key-epoch verification and Gate 4 serialization.
  • Advances the ledger, contract status, and Gate 3 marker to the root-commit slice while retaining the no-production-authority-switch constraint.
docs/native/CORE-MIGRATION-LEDGER.md
docs/native/R15-SECURE-STORAGE-CONTRACT.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepsource-io

deepsource-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 238e56c...b8b2e0f on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 2, 2026 2:01a.m. Review ↗
Python Oct 2, 2026 2:01a.m. Review ↗
Rust Oct 2, 2026 2:01a.m. Review ↗
Shell Oct 2, 2026 2:01a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: b8b2e0f6
Scan Time: 2026-10-02 02:21:36 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

codescene-access[bot]

This comment was marked as outdated.

@qnbs
qnbs marked this pull request as ready for review October 2, 2026 01:12
@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 6 days and 2 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR a01ab5f Oct 02, 2026 · 01:12 01:15

@codeant-ai

codeant-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 12 files, 1141 meaningful lines, 4 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Oct 2, 2026
codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
@codeant-ai

codeant-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

CodeAnt Nitpicks

1 code suggestion

1. FaultFs bypasses its fault injector for rename_replace, so tests cannot simulate failures during the new atomic pointer replacement step.

Incomplete implementation · crates/worldscript-secure-storage/tests/support/mod.rs:233-235

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 16fc5786-54bd-4627-851f-9dde44e7dec0

📥 Commits

Reviewing files that changed from the base of the PR and between 238e56c and 7fbce92.

📒 Files selected for processing (12)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/commit.rs
  • crates/worldscript-secure-storage/src/durable.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/root_record.rs
  • crates/worldscript-secure-storage/src/root_store.rs
  • crates/worldscript-secure-storage/tests/gate3_durable_test.rs
  • crates/worldscript-secure-storage/tests/gate3c_root_commit_test.rs
  • crates/worldscript-secure-storage/tests/support/mod.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread crates/worldscript-secure-storage/src/root_store.rs

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed against the latest diff

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
Comment thread crates/worldscript-secure-storage/src/root_store.rs
Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
Comment thread crates/worldscript-secure-storage/tests/gate3_durable_test.rs

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 12 files

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="crates/worldscript-secure-storage/src/lib.rs">

<violation number="1" location="crates/worldscript-secure-storage/src/lib.rs:11">
P3: The module list sentence lost its conjunction: it now reads "record catalog ([`catalog`]) persisted root records" without a separator between the two list items. Restore the "and" so the enumeration reads cleanly.</violation>
</file>

Requires human review: Auto-approval blocked because this review re-detected 2 unresolved issues already reported by Cubic.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/root_store.rs
Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread crates/worldscript-secure-storage/src/root_store.rs
Comment thread crates/worldscript-secure-storage/src/lib.rs
Comment thread .github/workflows/ci.yml
Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

… and harden root recovery (#445)

Review wave on PR #944: recovery returns RECOVERY_REQUIRED, touching nothing, when the pointer
already names a prepared target that does not authenticate (§5.3.1 after E2, before F); it discards
and relocates only while the pointer names the prior root, then repairs the pointer to the committed
root; it re-syncs the target slot directory before committing the anchor; loaded and completed
roots must carry COMMITTED evidence; a request scope other than the anchor's is refused; the
relocation error kind is preserved. Tests add the unproven-target, scope, failed-rename and
discard-repair cases.
Comment thread crates/worldscript-secure-storage/src/root_store.rs
Comment thread crates/worldscript-secure-storage/src/root_store.rs Outdated
codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/tests/gate3c_root_commit_test.rs Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/root_store.rs

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs
qnbs enabled auto-merge (squash) October 2, 2026 02:21
@qnbs
qnbs merged commit 065b221 into main Oct 2, 2026
51 checks passed
@qnbs
qnbs deleted the feat/445-gate3c-root-commit branch October 2, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL This PR changes 500-999 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant