feat(core): commit every protected write transition through the authority root (#445) - #947
Conversation
…rity root (#445) Gate 3 slice 3C part 3c-2b: protected_write records PENDING and commits it through the root (contract 9 step 2), stages the candidate and records ACTIVE, then commits that root (step 9); only then is the write DURABLE_COMMIT_SUCCESS (or COMMITTED_NOT_CONFIRMED_DURABLE). Reads serve only the root-named descriptor's generation, and reconcile_protected resolves a chain left ahead of the root from authenticated evidence, dropping a rolled-back first write from its shard. commit_write is split into begin_write and finish_write for the two root commits.
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
@codex review |
Reviewer's GuideImplements headless protected record writes through two authority-root commits—one for the pending transition and one for the active generation—with root-gated reads, authenticated startup reconciliation, durability reporting, cross-platform tests, and corresponding R-15 contract/status updates; production storage authority remains unchanged. Sequence diagram for protected write through the authority rootsequenceDiagram
participant Caller
participant Protected as protected_write
participant Root as AuthorityRoot
participant Record as RecordStore
participant FS as DurableFS
Caller->>Protected: reconcile_protected()
Protected->>Root: load_catalog()
Protected->>Record: verify_named_marker()
Protected->>Record: reconcile()
Protected->>Root: commit_catalog_change()
Protected->>Record: begin_write()
Record->>FS: write_marker(PENDING)
Protected->>Root: commit_catalog_change()
Protected->>Record: finish_write()
Record->>FS: stage and promote candidate
Record->>FS: write_marker(ACTIVE)
Protected->>Root: commit_catalog_change()
Root-->>Caller: ProtectedCommitted
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Oct 2, 2026 6:29a.m. | Review ↗ | |
| Python | Oct 2, 2026 6:29a.m. | Review ↗ | |
| Rust | Oct 2, 2026 6:29a.m. | Review ↗ | |
| Shell | Oct 2, 2026 6:29a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
[check-pr-size] PR size is over the target tier (normal profile): 9 files, 974 meaningful lines, 3 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 38 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 82 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (6)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (9)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe secure-storage crate adds protected write, read, and reconciliation paths tied to the authority root. Writes commit pending and active marker transitions through the root. Reads serve the root-named committed record. Integration tests and documentation cover interruption recovery and marker mismatch behavior. ChangesProtected Secure Storage
Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The change adds protected write, read and reconciliation paths in the secure-storage crate, with tests and documentation. It does not switch production authority. No concrete merge-blocking risk was identified in the supplied evidence.
Comment |
There was a problem hiding this comment.
All reported issues were addressed across 9 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Review wave on #947: the root-named marker is checked against the complete verified chain, so a deleted earlier marker is refused; reconcile_protected refuses to publish a chain for an uncatalogued record unless it is a rolled-back first write (UnrootedChain); a generation becomes readable only after its file verifies; and the reported durability includes every catalog page directory sync.
|
@CodeAnt-AI review |
|
@codex review |
CodeAnt NitpicksNo threshold-suppressed suggestions found in the latest review. |
|
@CodeAnt-AI review |
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
User description
Part of #445 / #921 (Gate 3, slice 3C, part 3c-2b). No production authority switch:
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.What lands (
protected)protected_write, following contract §9:PENDING(old -> new)and commits it through the root (step 2, §5.5 ordinary-write coherence).ACTIVE(new)(steps 3–8).DURABLE_COMMIT_SUCCESSonly when every directory sync was confirmed, otherwiseCOMMITTED_NOT_CONFIRMED_DURABLE(§9.1).reconcile_protected, the per-record startup resolution:ABSENTmarker body. This closes the tracked feat(core): add the Gate 3 slice 3C record-catalog descriptors and pages (#445) #942 acceptance item.read_protectedserves only the generation the root-named descriptor makes readable. It returnsNotCatalogued,NotYetReadableor the verified record. A newer marker on disk is a pending transition and is never read.commit_writeis split intobegin_writeandfinish_write, with unchanged behaviour, so the two root commits can sit between them.Contract
§9 step 9 gains an admitted variant: the marker generation and the page generation may be written before the anchor prepare (a), because neither is authority until the commit (c).
§20 has a new 3c-2b entry.
R15_GATE3=SLICE_3C_PROTECTED_WRITEis set in the block and in ledger row 10, and the status enumerations and CHANGELOG are updated.Proof
tests/gate3c_protected_test.rshas 8 tests, and they run on all three OS runners. They cover:ACTIVE(old)is re-committed;PENDINGmarker whose root never committed;Locally, clippy is clean, the full crate suite passes (22 test binaries),
cargo docwith-D warningspasses, andpnpm docs:checkpasses.Next: Gate 3 closure, with #357 reconciliation and the asset-pair marker boundary.
Summary by Sourcery
Route protected record transitions through the authority root and fail closed until the committed root authenticates the readable generation.
New Features:
Bug Fixes:
Enhancements:
CI:
Documentation:
Tests:
Summary by CodeRabbit
CodeAnt-AI Description
Route protected record writes and reads through the trusted authority root
What Changed
Impact
✅ Root-authorized protected writes✅ Old data remains readable during interrupted replacements✅ Fail-closed recovery for missing or tampered markers💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.