Skip to content

feat(core): commit every protected write transition through the authority root (#445) - #947

Merged
qnbs merged 3 commits into
mainfrom
feat/445-gate3c-protected-write
Oct 2, 2026
Merged

qnbs merged 3 commits into
mainfrom
feat/445-gate3c-protected-write

Conversation

@qnbs

@qnbs qnbs commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #445 / #921 (Gate 3, slice 3C, part 3c-2b). No production authority switch: PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

What lands (protected)

  • protected_write, following contract §9:
    1. Verifies the root-named marker.
    2. Reconciles the record and commits the catalog to the reconciled chain.
    3. Records PENDING(old -> new) and commits it through the root (step 2, §5.5 ordinary-write coherence).
    4. Stages and promotes the candidate, then records ACTIVE(new) (steps 3–8).
    5. Commits that through the root (step 9).
    • Only the second root transfers authority. The result is DURABLE_COMMIT_SUCCESS only when every directory sync was confirmed, otherwise COMMITTED_NOT_CONFIRMED_DURABLE (§9.1).
  • reconcile_protected, the per-record startup resolution:
    • the root-named marker must still be in the chain with its exact entry digest;
    • the record's pending write is completed or rolled back from authenticated evidence;
    • the catalog is then committed to the result.
    • A rolled-back first write is dropped from its shard, because version 1 has no ABSENT marker body. This closes the tracked feat(core): add the Gate 3 slice 3C record-catalog descriptors and pages (#445) #942 acceptance item.
  • read_protected serves only the generation the root-named descriptor makes readable. It returns NotCatalogued, NotYetReadable or the verified record. A newer marker on disk is a pending transition and is never read.
  • commit_write is split into begin_write and finish_write, with unchanged behaviour, so the two root commits can sit between them.
  • Retention (§5.5): nothing deletes a marker, catalog page, root slot or record generation. Garbage collection needs reader pins (§5.3.3) and exclusive admission, both Gate 4.

Contract

§9 step 9 gains an admitted variant: the marker generation and the page generation may be written before the anchor prepare (a), because neither is authority until the commit (c).

  • A page newer than the committed root is never selected (§5.5.1).
  • A marker chain ahead of the root is resolved only from authenticated evidence, as described above.

§20 has a new 3c-2b entry. R15_GATE3=SLICE_3C_PROTECTED_WRITE is set in the block and in ledger row 10, and the status enumerations and CHANGELOG are updated.

Proof

tests/gate3c_protected_test.rs has 8 tests, and they run on all three OS runners. They cover:

  • a first write and a replacement, with one root per marker transition;
  • an interrupted first write: enumerable but not readable, then dropped;
  • an interrupted replacement: the old generation is served, then ACTIVE(old) is re-committed;
  • a PENDING marker whose root never committed;
  • a chain ahead of the root, which is not read until reconciled;
  • a missing or replaced root-named marker.

Locally, clippy is clean, the full crate suite passes (22 test binaries), cargo doc with -D warnings passes, and pnpm docs:check passes.

Next: Gate 3 closure, with #357 reconciliation and the asset-pair marker boundary.

Summary by Sourcery

Route protected record transitions through the authority root and fail closed until the committed root authenticates the readable generation.

New Features:

  • Add protected record write, read, and startup reconciliation paths that commit marker transitions through the authority root.
  • Expose protected-write durability outcomes based on confirmed synchronization of all participating storage directories.

Bug Fixes:

  • Prevent reads from serving pending, unrooted, missing, replaced, or unverifiable record generations.
  • Recover interrupted writes from authenticated evidence while preserving prior generations and dropping rolled-back first writes from the catalog.

Enhancements:

  • Enforce root-named marker and catalog authority when selecting readable record generations.
  • Retain markers, catalog pages, root slots, and record generations for future pin-aware garbage collection.

CI:

  • Run the protected-write integration tests on macOS and Windows CI runners.

Documentation:

  • Update the secure-storage contract, migration ledger, status flags, and changelog for protected root-committed writes.

Tests:

  • Add cross-platform coverage for successful writes, replacements, interrupted transitions, unrooted chains, tampered markers and generations, and recovery behavior.

Summary by CodeRabbit

  • New Features
    • Added protected record reads and writes tied to a trusted authority root. Reads serve only the version confirmed by that root, and write success reflects whether durable storage was confirmed.
    • Startup recovery can complete or roll back interrupted writes using authenticated evidence, removing an interrupted first write from the protected record list.
    • These paths do not yet read or write user data.

CodeAnt-AI Description

Route protected record writes and reads through the trusted authority root

What Changed

  • Protected writes now commit both the pending transition and the completed generation through the authority root before reporting success.
  • Reads serve only the generation named by the committed root; interrupted writes remain unreadable or continue serving the previous generation until authenticated recovery completes.
  • Startup recovery verifies the complete marker chain, rejects missing, replaced, unverifiable, or never-rooted chains, and removes rolled-back first writes from the record list.
  • Durability results now include directory sync confirmation for catalog pages as well as records, markers, and root data.
  • Added coverage for successful writes, replacements, crashes, rollback, stale chains, tampering, and cross-platform CI execution.

Impact

✅ Root-authorized protected writes
✅ Old data remains readable during interrupted replacements
✅ Fail-closed recovery for missing or tampered markers

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

…rity root (#445)

Gate 3 slice 3C part 3c-2b: protected_write records PENDING and commits
it through the root (contract 9 step 2), stages the candidate and
records ACTIVE, then commits that root (step 9); only then is the write
DURABLE_COMMIT_SUCCESS (or COMMITTED_NOT_CONFIRMED_DURABLE). Reads serve
only the root-named descriptor's generation, and reconcile_protected
resolves a chain left ahead of the root from authenticated evidence,
dropping a rolled-back first write from its shard. commit_write is split
into begin_write and finish_write for the two root commits.
@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 71ef212 Oct 02, 2026 · 06:29 06:32
✅ Reviewed your PR 604ec1f Oct 02, 2026 · 06:23 06:26
✅ Reviewed your PR 29d395a Oct 02, 2026 · 06:08 06:10

@codeant-ai

codeant-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 2, 2026 6:30am UTC

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 21 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@sourcery-ai

sourcery-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Reviewer's Guide

Implements headless protected record writes through two authority-root commits—one for the pending transition and one for the active generation—with root-gated reads, authenticated startup reconciliation, durability reporting, cross-platform tests, and corresponding R-15 contract/status updates; production storage authority remains unchanged.

Sequence diagram for protected write through the authority root

sequenceDiagram
    participant Caller
    participant Protected as protected_write
    participant Root as AuthorityRoot
    participant Record as RecordStore
    participant FS as DurableFS

    Caller->>Protected: reconcile_protected()
    Protected->>Root: load_catalog()
    Protected->>Record: verify_named_marker()
    Protected->>Record: reconcile()
    Protected->>Root: commit_catalog_change()
    Protected->>Record: begin_write()
    Record->>FS: write_marker(PENDING)
    Protected->>Root: commit_catalog_change()
    Protected->>Record: finish_write()
    Record->>FS: stage and promote candidate
    Record->>FS: write_marker(ACTIVE)
    Protected->>Root: commit_catalog_change()
    Root-->>Caller: ProtectedCommitted
Loading

File-Level Changes

Change Details Files
Adds the protected record write, read, and startup-reconciliation path around the authority root.
  • Introduces protected_write with separate root commits for PENDING and ACTIVE marker transitions.
  • Adds authenticated reconciliation for pending or root-ahead marker chains, including dropping rolled-back first writes.
  • Restricts reads to the root-named catalog descriptor and verifies marker entry digests and committed record contents.
  • Preserves retention by avoiding deletion of markers, catalog pages, root slots, and generations.
crates/worldscript-secure-storage/src/protected.rs
crates/worldscript-secure-storage/src/lib.rs
crates/worldscript-secure-storage/src/authority.rs
Refactors the existing commit protocol to expose the boundaries required by the two authority-root commits.
  • Splits commit_write into begin_write and finish_write without changing the standalone behavior.
  • Exposes marker and committed-generation verification helpers to the protected path.
  • Propagates directory durability from both marker transitions and root commits into the protected write result.
crates/worldscript-secure-storage/src/commit.rs
Adds end-to-end coverage for protected authority transitions and recovery behavior.
  • Tests first writes, replacements, interrupted writes, uncommitted pending markers, root-ahead chains, and missing or substituted root-named markers.
  • Runs the protected test binary on macOS and Windows CI in addition to existing Linux coverage.
crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
.github/workflows/ci.yml
Updates the R-15 contract and project status to record the admitted protected-write slice.
  • Documents the admitted write ordering, root authority rules, read semantics, reconciliation behavior, and retention constraints.
  • Advances Gate 3 status to SLICE_3C_PROTECTED_WRITE while keeping production authority switching disabled.
  • Updates the changelog and migration ledger.
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/CORE-MIGRATION-LEDGER.md
CHANGELOG.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepsource-io

deepsource-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in cfefa18...71ef212 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 2, 2026 6:29a.m. Review ↗
Python Oct 2, 2026 6:29a.m. Review ↗
Rust Oct 2, 2026 6:29a.m. Review ↗
Shell Oct 2, 2026 6:29a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Oct 2, 2026
@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 71ef212f
Scan Time: 2026-10-02 06:32:27 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

codescene-access[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 9 files, 974 meaningful lines, 3 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

Comment thread crates/worldscript-secure-storage/tests/gate3c_protected_test.rs Outdated
Comment thread crates/worldscript-secure-storage/tests/gate3c_protected_test.rs Outdated
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 38 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 82 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 9787930b-38e4-428f-8055-24dd567e4c47

📥 Commits

Reviewing files that changed from the base of the PR and between 29d395a and 71ef212.

📒 Files selected for processing (6)
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/commit.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/protected.rs
  • crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 4dc90eca-9ee9-4da3-b27e-3934bb4689b0

📥 Commits

Reviewing files that changed from the base of the PR and between cfefa18 and 29d395a.

📒 Files selected for processing (9)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/commit.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/protected.rs
  • crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The secure-storage crate adds protected write, read, and reconciliation paths tied to the authority root. Writes commit pending and active marker transitions through the root. Reads serve the root-named committed record. Integration tests and documentation cover interruption recovery and marker mismatch behavior.

Changes

Protected Secure Storage

Layer / File(s) Summary
Record write phases
crates/worldscript-secure-storage/src/commit.rs, crates/worldscript-secure-storage/src/authority.rs
The record commit flow separates PENDING marker creation from record promotion and ACTIVE marker creation. Its durability result combines directory sync results from those steps.
Protected write API
crates/worldscript-secure-storage/src/protected.rs, crates/worldscript-secure-storage/src/lib.rs
The crate exposes protected storage types and functions. Protected writes reconcile existing state, commit pending catalog state, finish the record write, then commit the active state through the authority root.
Protected reads, recovery, and validation
crates/worldscript-secure-storage/src/protected.rs, crates/worldscript-secure-storage/tests/gate3c_protected_test.rs, .github/workflows/ci.yml, CHANGELOG.md, docs/native/*
Reads verify the root-named marker and serve the committed record. Reconciliation resolves interrupted writes and updates or removes catalog entries. Integration tests cover write, recovery, and marker mismatch cases; documentation records the implementation status and remaining boundaries.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 29d39

The change adds protected write, read and reconciliation paths in the secure-storage crate, with tests and documentation. It does not switch production authority. No concrete merge-blocking risk was identified in the supplied evidence.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

Comment thread crates/worldscript-secure-storage/src/protected.rs
Comment thread crates/worldscript-secure-storage/src/protected.rs

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 9 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/protected.rs
Comment thread crates/worldscript-secure-storage/src/protected.rs
Comment thread crates/worldscript-secure-storage/src/protected.rs
Comment thread crates/worldscript-secure-storage/src/protected.rs
Comment thread crates/worldscript-secure-storage/src/lib.rs
@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

Review wave on #947: the root-named marker is checked against the
complete verified chain, so a deleted earlier marker is refused;
reconcile_protected refuses to publish a chain for an uncatalogued
record unless it is a rolled-back first write (UnrootedChain); a
generation becomes readable only after its file verifies; and the
reported durability includes every catalog page directory sync.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

CodeAnt Nitpicks

No threshold-suppressed suggestions found in the latest review.

Comment thread crates/worldscript-secure-storage/src/protected.rs Outdated
@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs
qnbs merged commit 173bc14 into main Oct 2, 2026
51 checks passed
@qnbs
qnbs deleted the feat/445-gate3c-protected-write branch October 2, 2026 06:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL This PR changes 500-999 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant