Skip to content

feat(core): persist the record catalog and commit catalog changes through the root (#445) - #946

Merged
qnbs merged 4 commits into
mainfrom
feat/445-gate3c-catalog-commit
Oct 2, 2026
Merged

qnbs merged 4 commits into
mainfrom
feat/445-gate3c-catalog-commit

Conversation

@qnbs

@qnbs qnbs commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #445 / #921 (Gate 3, slice 3C, part 3c-2a). No production authority switch: PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

What lands (authority)

  • Catalog page persistence
    • Pages live at <root_dir>/catalog/<shard>/generation-<n>.wsr1.
    • They are sealed under the root key route with the root's active_key_epoch, as control records of the root.
    • A page's catalog_generation is the root_generation of the root that publishes it. This is the one stated exception to the consecutive-counter rule, now written into contract §5.5.1. It is what tells a leftover page from an interrupted change (newer than the committed root) apart from a committed page.
  • load_catalog / list_records
    • Both start from the trusted cold start and take each shard's newest page that is at or below the committed root generation.
    • The pages must hash to the root's catalog_set_digest, and their descriptors' markers must hash to its marker_set_digest (via the new MarkerSetEntry::from_descriptor).
    • An unopenable, missing or replayed page, a non-canonical shard name or any other unexpected entry is RECOVERY_REQUIRED.
  • commit_catalog_change
    • Applies upserts and removals. Each record may appear at most once, and removing an uncatalogued record is refused before any write.
    • Relocates (never deletes) the leftover pages of an uncommitted change.
    • Writes one page per affected shard in a durably created directory.
    • Commits the root naming the new catalog, marker and key-epoch sets through commit_root.
  • Empty pages
    • An emptied shard now keeps a zero-descriptor page and stays in catalog_set_digest. An absent shard could not be told apart from a replayed older page.
    • The codec admits 0..=MAX descriptors, and contract §5.5.1 is amended to match.
  • Doc fix: removed a pre-existing rustdoc link to a private item (CatalogDescriptor::new_unverified), which failed cargo doc with -D warnings.

Proof

tests/gate3c_authority_test.rs has 12 tests, and they run on all three OS runners. They cover:

  • the first commit;
  • a change that leaves other shards' pages in place;
  • a replacement descriptor;
  • an emptied shard;
  • refused changes writing nothing;
  • an interrupted change's pages being ignored, then relocated;
  • a tampered page, a replayed older page and a removed shard;
  • unexpected catalog entries;
  • a root whose marker set disagrees with the catalog.

Locally, clippy is clean, the full crate suite passes, cargo doc with -D warnings passes, and pnpm docs:check passes.

Docs

  • Contract §5.5.1 now covers page generations, the physical locator and the sealing key.
  • Contract §20 has a new 3c-2a entry.
  • R15_GATE3=SLICE_3C_CATALOG_COMMIT is set in the block and in ledger row 10. The CHANGELOG is updated.

Known open item, tracked

A key-epoch record whose root never commits is still read as its epoch's newest generation. This fails closed with RECOVERY_REQUIRED. Resolving that crash window belongs to the Gate 4 journal that admits key-epoch changes, as recorded in §20.

Next: 3c-2b, which wires commit_write through catalog and root commits at each marker transition (dropping a rolled-back first write), plus retention. Then Gate 3 closure with #357 and the asset-pair boundary.

Summary by Sourcery

Persist and root-verify the record catalog so catalog changes become authoritative only through committed roots.

New Features:

  • Persist the record catalog under the authority root and expose verified catalog loading and record listing.
  • Commit catalog upserts and removals together with roots, including handling for empty shards and interrupted changes.

Bug Fixes:

  • Reject tampered, missing, replayed, mismatched, or unexpected catalog pages as recovery-required instead of trusting them.
  • Prevent refused catalog changes from writing partial filesystem state.
  • Fix the private rustdoc link that caused warning-denied documentation builds.

Enhancements:

  • Bind catalog pages and marker sets to the committed root, scope, key route, and active key epoch.
  • Retain and relocate uncommitted catalog pages rather than deleting them, while preserving unchanged shard pages.

CI:

  • Run the authority and catalog integration tests on macOS and Windows CI runners.

Documentation:

  • Update the secure-storage contract, migration ledger, and changelog for persisted root-verified catalog commits and empty-page semantics.

Tests:

  • Add cross-platform coverage for catalog commits, replacements, removals, recovery failures, interrupted changes, preflight refusals, and key-epoch mismatches.

Chores:

  • Advance the Gate 3 status to the catalog-commit slice while keeping the production authority switch disabled.

Summary by cubic

Persists the record catalog under the authority root and commits catalog changes through the root, so list_records only returns records from pages the committed root names.

  • commit_catalog_change preflights the operation ID, the active key epoch's route binding, and refuses a change that would rotate the key route or epoch (KeyRotationNotAdmitted) before relocating leftovers or writing any page; the commit inputs move into a CatalogCommit struct.
  • load_catalog opens pages under the scope and key route from the same anchor read that selects the root, refuses a page sealed under another key epoch, and treats a missing committed page or a file named as a shard as RECOVERY_REQUIRED.
  • A page's catalog_generation is the root generation that publishes it; pages live at <root_dir>/catalog/<shard>/generation-<n>.wsr1.
  • Pages and markers must hash to the root's catalog_set_digest and marker_set_digest; an emptied shard keeps a zero-descriptor page, and leftover pages of an uncommitted change are relocated, never deleted.
  • CatalogPage::new refuses an oversized descriptor list before sorting.
  • Fixes a rustdoc link to a private item that broke cargo doc with -D warnings.
  • A key-epoch record whose root never commits is still read as that epoch's newest generation and fails closed with RECOVERY_REQUIRED; closing that window is tracked for Gate 4. The change assumes one writer until Gate 4's root_commit_mutex and exclusive admission. No production authority switch; nothing reads or writes user data through it yet.

12 new tests in tests/gate3c_authority_test.rs cover the first commit, unchanged shards, replacement, emptied shards, refused changes, interrupted-change relocation, tampered/replayed/removed pages, pages under another epoch, unexpected entries, preflighted refusals, key-epoch rotation refusal, and marker-set mismatch; they run on all three OS runners. Contract, ledger and CHANGELOG are updated.

Written for commit 98e6ca3. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Secure storage now maintains a record catalog tied to the committed root. Record listings include only verified catalog entries.
    • Catalog changes are committed with a new root. Tampered, missing, replayed, or unexpected catalog data requires recovery; pages left by interrupted changes are set aside.
    • Empty catalog pages are supported when a shard has no remaining records. This functionality does not yet read or write user data.

CodeAnt-AI Description

Persist and verify the protected record catalog through the authority root

What Changed

  • Catalog pages are stored under the root, sealed with the root’s active key epoch, and published together with catalog, marker, and key-epoch digests in a new root.
  • list_records and catalog loading use only pages named by the committed root; tampered, missing, replayed, incorrectly sealed, or unexpected catalog entries require recovery instead of being trusted.
  • Catalog changes support descriptor additions, replacements, and removals, preserve empty shard pages, reject invalid changes before writing, and move pages from interrupted commits aside without deleting them.
  • Added coverage for persistence, interrupted changes, tampering, replay detection, key-epoch mismatches, invalid entries, empty shards, and cross-platform catalog behavior.

Impact

✅ Verified record listings
✅ Fewer silent catalog corruption risks
✅ Safer recovery after interrupted catalog changes

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

qnbs added 2 commits October 2, 2026 06:32
…ough the root (#445)

Gate 3 slice 3C part 3c-2a: catalog pages are stored under the root
directory, sealed under the root key route, with a page's generation
equal to the root generation that publishes it. load_catalog and
list_records trust only pages that hash to the committed root's catalog
and marker set digests; commit_catalog_change applies descriptor
changes, relocates leftover pages of an uncommitted change, writes the
affected shard pages (an emptied shard keeps a zero-descriptor page) and
commits the next root through commit_root.
@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 98e6ca3 Oct 02, 2026 · 05:07 05:09
✅ Reviewed your PR faf9982 Oct 02, 2026 · 04:58 05:00
✅ Reviewed your PR 2484dd0 Oct 02, 2026 · 04:36 04:39

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 22 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 2, 2026 5:08am UTC

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai

codeant-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@sourcery-ai

sourcery-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Reviewer's Guide

Adds headless persistence for the record catalog: catalog pages are durably sealed under the root authority, verified against the committed root’s catalog and marker digests, and changed through an atomic catalog-plus-root commit flow with interrupted writes quarantined. Empty-shard semantics, contract/status documentation, and cross-platform recovery tests are included; production authority and record write integration remain out of scope.

Sequence diagram for root-verified catalog loading

sequenceDiagram
    participant Caller
    participant load_catalog
    participant load_committed_root
    participant CatalogPages
    participant verify_catalog

    Caller->>load_catalog: load_catalog()
    load_catalog->>load_committed_root: load_committed_root()
    load_committed_root-->>load_catalog: committed root
    load_catalog->>CatalogPages: scan_catalog()
    CatalogPages-->>load_catalog: newest page at or below root_generation
    load_catalog->>CatalogPages: open_page()
    CatalogPages-->>load_catalog: verified catalog pages
    load_catalog->>verify_catalog: verify_catalog(root, pages)
    alt digests match
        verify_catalog-->>load_catalog: verified catalog
        load_catalog-->>Caller: LoadedCatalog
    else page or marker mismatch
        verify_catalog-->>load_catalog: RECOVERY_REQUIRED
        load_catalog-->>Caller: AuthorityError
    end
Loading

Sequence diagram for catalog change and root commit

sequenceDiagram
    participant Caller
    participant commit_catalog_change
    participant load_catalog
    participant CatalogPages
    participant DurableFs
    participant commit_root

    Caller->>commit_catalog_change: commit_catalog_change(change, commit)
    commit_catalog_change->>load_catalog: load_catalog()
    load_catalog-->>commit_catalog_change: current catalog
    commit_catalog_change->>CatalogPages: apply_change()
    alt invalid or duplicate change
        CatalogPages-->>commit_catalog_change: refusal
        commit_catalog_change-->>Caller: AuthorityError
    else valid change
        commit_catalog_change->>CatalogPages: scan_catalog()
        CatalogPages-->>commit_catalog_change: interrupted pages
        commit_catalog_change->>DurableFs: relocate(leftover pages)
        commit_catalog_change->>DurableFs: stage_and_promote(page)
        DurableFs-->>commit_catalog_change: promoted pages
        commit_catalog_change->>commit_root: commit_root(new catalog and marker digests)
        commit_root-->>commit_catalog_change: RootCommitted
        commit_catalog_change-->>Caller: RootCommitted
    end
Loading

File-Level Changes

Change Details Files
Persist and verify catalog pages as root-authorized control records.
  • Added catalog page discovery under shard/generation paths, selecting the newest page not newer than the committed root.
  • Opened pages using the committed root key route and validated catalog and marker-set digests against the root.
  • Classified malformed, missing, replayed, tampered, or unexpected catalog contents as recovery-required.
crates/worldscript-secure-storage/src/authority.rs
crates/worldscript-secure-storage/src/root.rs
crates/worldscript-secure-storage/src/root_store.rs
crates/worldscript-secure-storage/src/lib.rs
Implement atomic catalog changes through the root commit protocol.
  • Added upsert/removal validation, including duplicate-change and uncatalogued-removal refusal before writes.
  • Relocated pages left by uncommitted changes, durably created shard directories, and wrote affected pages at the next root generation.
  • Computed catalog, marker, and key-epoch sets and committed them through commit_root so the prior catalog remains authoritative until root commit.
crates/worldscript-secure-storage/src/authority.rs
Support durable empty-shard pages and document the catalog authority contract.
  • Allowed zero-descriptor pages while retaining emptied shards in the catalog set digest.
  • Specified page generations, physical locators, sealing keys, recovery behavior, and the new Gate 3 status in the secure-storage contract and migration ledger.
  • Updated changelog and corrected rustdoc visibility/linkage issues.
crates/worldscript-secure-storage/src/catalog.rs
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/CORE-MIGRATION-LEDGER.md
CHANGELOG.md
Add end-to-end authority and cross-platform test coverage.
  • Added tests for initial commits, shard preservation, replacement, empty pages, refused writes, interrupted commits, tampering, replay, removal, unexpected entries, and marker-set mismatches.
  • Enabled the authority test suite on macOS and Windows CI runners and updated catalog codec expectations.
crates/worldscript-secure-storage/tests/gate3c_authority_test.rs
crates/worldscript-secure-storage/tests/gate3c_catalog_test.rs
.github/workflows/ci.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepsource-io

deepsource-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in f43c91a...98e6ca3 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 2, 2026 5:07a.m. Review ↗
Python Oct 2, 2026 5:07a.m. Review ↗
Rust Oct 2, 2026 5:07a.m. Review ↗
Shell Oct 2, 2026 5:07a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@codeant-ai codeant-ai Bot added the size:XXL This PR changes 1000+ lines, ignoring generated files label Oct 2, 2026
@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 98e6ca3a
Scan Time: 2026-10-02 05:09:50 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

codescene-access[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the hard tier (normal profile): 12 files, 1325 meaningful lines, 4 commits — limit ≤20 files / ≤1200 lines / ≤10 commits. Consider splitting into smaller, independently reviewable PRs.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 29 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 82 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: e84580f8-e39e-47a1-8472-1183cc1d50ca

📥 Commits

Reviewing files that changed from the base of the PR and between 2484dd0 and 98e6ca3.

📒 Files selected for processing (8)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/anchor.rs
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/catalog.rs
  • crates/worldscript-secure-storage/src/root_store.rs
  • crates/worldscript-secure-storage/tests/gate3c_authority_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
📝 Walkthrough

Walkthrough

The secure-storage crate adds persisted record-catalog loading, listing, and commit operations tied to the committed root. Catalog pages and marker digests are verified. Empty shard pages are supported, and tests cover catalog changes and recovery cases.

Changes

Record Catalog Authority

Layer / File(s) Summary
Catalog page and authority contracts
crates/worldscript-secure-storage/src/catalog.rs, crates/worldscript-secure-storage/src/root.rs, crates/worldscript-secure-storage/src/authority.rs, crates/worldscript-secure-storage/src/lib.rs, crates/worldscript-secure-storage/tests/gate3c_catalog_test.rs, docs/native/R15-SECURE-STORAGE-CONTRACT.md
Catalog pages can contain zero descriptors when a shard is emptied. The crate adds authority types and marker entries derived from catalog descriptors, and exposes the catalog operations.
Load and verify catalog
crates/worldscript-secure-storage/src/authority.rs, crates/worldscript-secure-storage/tests/gate3c_authority_test.rs
Loading selects pages at or below the committed root generation and verifies catalog and marker digests. Tests cover listing and recovery errors for tampered, missing, replayed, or unexpected catalog state.
Commit catalog changes
crates/worldscript-secure-storage/src/authority.rs, crates/worldscript-secure-storage/src/root_store.rs, crates/worldscript-secure-storage/tests/gate3c_authority_test.rs, .github/workflows/ci.yml, CHANGELOG.md, docs/native/CORE-MIGRATION-LEDGER.md, docs/native/R15-SECURE-STORAGE-CONTRACT.md
Catalog changes write affected pages and commit a root with their digests. Uncommitted pages are relocated. Tests cover upserts, removals, refused changes, and interrupted commits. The ledger records catalog commit support while write-protocol integration and retention remain outstanding.

Priority: ➖ Normal

Merge Risk: 🔵 Low · up to 2484d

Catalog loading still needs to report a missing committed page as requiring recovery. This narrow error-handling gap should be fixed, but does not otherwise block the headless catalog workflow.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/ci.yml Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 2155d4cd-e964-4450-8df5-e3f7c412962a

📥 Commits

Reviewing files that changed from the base of the PR and between f43c91a and 2484dd0.

📒 Files selected for processing (11)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/catalog.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/root.rs
  • crates/worldscript-secure-storage/src/root_store.rs
  • crates/worldscript-secure-storage/tests/gate3c_authority_test.rs
  • crates/worldscript-secure-storage/tests/gate3c_catalog_test.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread CHANGELOG.md Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
Comment thread .github/workflows/ci.yml Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

…mmitted root's epoch (#445)

Review wave on #946: commit_catalog_change checks the operation ID and
the active epoch's binding before relocating leftovers or writing a
page; load_catalog opens pages under the scope and route from the same
anchor read that selected the root, refuses a page under another key
epoch, and treats a missing committed page or a file named as a shard
as RECOVERY_REQUIRED. The commit inputs move into CatalogCommit, the
catalog codec tests also run on macOS and Windows, and the contract
status enumerations name part 3c-2a.
Comment thread crates/worldscript-secure-storage/src/authority.rs
Comment thread crates/worldscript-secure-storage/src/authority.rs
Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Comment thread crates/worldscript-secure-storage/src/authority.rs
@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

CodeAnt Nitpicks

No threshold-suppressed suggestions found in the latest review.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread crates/worldscript-secure-storage/src/authority.rs
Comment thread crates/worldscript-secure-storage/src/authority.rs
#445)

Pages a change does not touch stay sealed under the committed epoch, so
commit_catalog_change now refuses a different route or active_key_epoch
(KeyRotationNotAdmitted); a rotation that rewrites every page is Gate 5.
CatalogPage::new refuses an oversized input before sorting, and the
contract states the one-writer assumption until Gate 4.
@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs
qnbs merged commit cfefa18 into main Oct 2, 2026
54 checks passed
@qnbs
qnbs deleted the feat/445-gate3c-catalog-commit branch October 2, 2026 05:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL This PR changes 1000+ lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant