Skip to content

feat(core): close R-15 Gate 3 with its evidence matrix and residual owners (#445) - #949

Merged
qnbs merged 2 commits into
mainfrom
feat/445-gate3-closure
Oct 2, 2026
Merged

qnbs merged 2 commits into
mainfrom
feat/445-gate3-closure

Conversation

@qnbs

@qnbs qnbs commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #445; this is the Gate 3 closure for #921. No production authority switch: PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Evidence (contract §20 Gate 3 definition: "file sync, atomic replacement, directory sync, generation reconciliation, and fault-injection tests for one record class")

The evidence is headless and CI_ONLY, on Linux, macOS and Windows runners. The faults are injected; this is not a power-loss test.

Requirement Where Tests
File sync stage_and_promote syncs every staged file before promotion gate3_durable_test
Atomic replacement Immutable, generation-addressed promotion for records, markers, catalog pages and root slots; the root pointer is replaced by write-sync-rename-sync gate3_durable_test, gate3c_root_commit_test
Directory sync Record, marker, catalog-shard, catalog, root, slot and pointer directories are synced; an unconfirmed sync yields COMMITTED_NOT_CONFIRMED_DURABLE gate3_durable_test, gate3b_commit_test, gate3c_protected_test
Generation reconciliation Marker-chain reconciliation, root crash recovery and cold start, catalog leftovers, per-record protected startup resolution gate3b_commit_test, gate3c_root_commit_test, gate3c_authority_test, gate3c_protected_test
Fault injection Selected boundaries named per suite (create, partial write, file sync, read-back, link, remove, directory sync, slot create, pointer rename, record-dir create); secure-anchor faults at the prepare and commit windows see contract §20

Code

protected_write, reconcile_protected and read_protected now refuse a non-ordinary record (control-plane, retained-authority, or an asset-pair member) with NotAnOrdinaryRecord, before anything is written. Test: an_asset_pair_member_is_refused_before_anything_is_written.

Residuals, each with an owner (recorded in contract §20 and ledger row 10)

R15_GATE3=IMPLEMENTED_HEADLESS is set in the block and in ledger row 10, and the status prose and CHANGELOG are updated. After this merges and the resulting main is proven, #357 and #921 will be closed with this evidence.


CodeAnt-AI Description

Complete crash-durable protected storage for ordinary records

What Changed

  • Protected storage now completes Gate 3 for ordinary records, including synced files, atomic generation replacement, directory-sync reporting, startup recovery, and fault-injection coverage across Linux, macOS, and Windows.
  • Protected reads, writes, and reconciliation now reject control-plane, retained-authority, and asset-pair records before creating or changing any files.
  • Documentation records the Gate 3 evidence, remaining owners, and the fact that production authority remains unchanged.

Impact

✅ Crash-resilient ordinary-record updates
✅ No partial files for unsupported record types
✅ Clearer durability status on platforms without confirmed directory sync

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

…wners (#445)

Gate 3's definition (file sync, atomic replacement, directory sync,
generation reconciliation, fault injection) is met headless for ordinary
records; contract 20 records the evidence per requirement and assigns
every residual: asset-pair marker body to Gate 5, the key-epoch crash
window and reclamation to Gate 4, power loss to Gate 6, deletion
transitions to #948, and #357's legacy TypeScript path to Gate 7. The
protected path now refuses a non-ordinary record before writing.
R15_GATE3=IMPLEMENTED_HEADLESS.
@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR d813427 Oct 02, 2026 · 07:39 07:40
✅ Reviewed your PR d278e45 Oct 02, 2026 · 07:27 07:29

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 2, 2026 7:39am UTC

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 7 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@sourcery-ai

sourcery-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR closes R-15 Gate 3 for ordinary records in the headless secure-storage core, backed by cross-platform CI fault-injection evidence for synchronization, atomic promotion, directory durability, and generation recovery. It also fails closed for non-ordinary record classes before writing, records the remaining gate-owned work, and explicitly leaves production TypeScript/Tauri authority unchanged.

Sequence diagram for Gate 3 durable protected write

sequenceDiagram
    participant Caller
    participant protected_write
    participant reconcile_protected
    participant stage_and_promote
    participant RootCommit
    participant DurableFs

    Caller->>protected_write: protected_write
    protected_write->>protected_write: ensure_ordinary
    alt non-ordinary record
        protected_write-->>Caller: NotAnOrdinaryRecord
    else ordinary record
        protected_write->>reconcile_protected: reconcile_protected
        reconcile_protected->>DurableFs: sync directories and recover generations
        protected_write->>stage_and_promote: stage_and_promote
        stage_and_promote->>DurableFs: sync staged files
        stage_and_promote->>DurableFs: atomic generation promotion
        protected_write->>RootCommit: commit marker transitions
        RootCommit->>DurableFs: write-sync-rename-sync root pointer
        DurableFs-->>protected_write: DURABLE_COMMIT_SUCCESS or COMMITTED_NOT_CONFIRMED_DURABLE
        protected_write-->>Caller: ProtectedCommitted
    end
Loading

Flow diagram for ordinary-record admission and residual ownership

flowchart LR
    Request[Protected read write or reconciliation] --> Ordinary{Ordinary record?}
    Ordinary -->|No| Refuse[NotAnOrdinaryRecord before writing]
    Ordinary -->|Yes| Gate3[Gate 3 headless durable path]
    Gate3 --> Evidence[CI fault-injection evidence]
    Evidence --> Available[Available for ordinary records]
    Gate3 --> Residuals[Remaining work has explicit owners]
    Residuals --> Gate4[Gate 4 concurrency and reclamation]
    Residuals --> Gate5[Gate 5 asset-pair commits]
    Residuals --> Gate6[Gate 6 physical power-loss qualification]
    Residuals --> Delete948[#948 deletion transitions]
    Residuals --> Gate7[Gate 7 authority switch]
    Gate7 --> Legacy[TypeScript/Tauri remains production authority]
Loading

File-Level Changes

Change Details Files
Closes Gate 3 for ordinary protected records with headless durability evidence and explicit residual ownership.
  • Documents file, directory, atomic replacement, generation-reconciliation, and injected-fault evidence across Linux, macOS, and Windows CI.
  • Records deferred asset-pair, Gate 4, Gate 6, deletion, and legacy-authority work with owners and constraints.
  • Updates Gate 3 status to IMPLEMENTED_HEADLESS while retaining PRODUCTION_AUTHORITY_SWITCH_ALLOWED=NO.
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/CORE-MIGRATION-LEDGER.md
CHANGELOG.md
Restricts protected operations to ordinary records before any storage mutation.
  • Adds NotAnOrdinaryRecord and validates record class in protected write, reconciliation, and read entry points.
  • Rejects control-plane, retained-authority, and asset-pair members before catalog, marker, or root creation.
  • Adds regression coverage proving asset-pair refusal leaves storage untouched.
crates/worldscript-secure-storage/src/protected.rs
crates/worldscript-secure-storage/tests/gate3c_protected_test.rs

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: d813427e
Scan Time: 2026-10-02 07:40:52 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED No IAC issues

View Full Results

@codeant-ai codeant-ai Bot added the size:M This PR changes 30-99 lines, ignoring generated files label Oct 2, 2026
@deepsource-io

deepsource-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 173bc14...d813427 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 2, 2026 7:38a.m. Review ↗
Python Oct 2, 2026 7:38a.m. Review ↗
Rust Oct 2, 2026 7:38a.m. Review ↗
Shell Oct 2, 2026 7:38a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

codescene-access[bot]

This comment was marked as outdated.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 48 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: b0c185f8-0325-43c3-aabf-9fe3ba005b4d

📥 Commits

Reviewing files that changed from the base of the PR and between d278e45 and d813427.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
📝 Walkthrough

Walkthrough

Protected write, reconciliation, and read paths now reject non-ordinary records before proceeding. The changelog and migration documents mark Gate 3 implemented headlessly and describe its evidence and remaining work.

Changes

Gate 3 protected storage

Layer / File(s) Summary
Reject non-ordinary records at protected API boundaries
crates/worldscript-secure-storage/src/protected.rs, crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
Protected writes, reconciliation, and reads return NotAnOrdinaryRecord for disallowed record classes. A test verifies that an asset-pair identity creates no marker files or catalog.
Record Gate 3 status and remaining scope
CHANGELOG.md, docs/native/CORE-MIGRATION-LEDGER.md, docs/native/R15-SECURE-STORAGE-CONTRACT.md
The changelog and migration documents mark Gate 3 implemented headlessly and describe its evidence, remaining work, and production-authority status.

Priority: ⬇️ Low

Merge Risk: 🔵 Low · up to d278e

The protected implementation currently rejects non-ordinary records, and production authority has not switched. Add direct reconciliation coverage and narrow the fault-injection claim before relying on the stated Gate 3 evidence.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
Comment thread CHANGELOG.md Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
crates/worldscript-secure-storage/tests/gate3c_protected_test.rs (1)

455-467: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Add a direct reconciliation assertion for asset-pair records.

The asset-pair test exercises protected_write and read_protected, which each reject non-ordinary records before calling reconcile_protected. Removing only reconcile_protected’s guard would therefore leave this test passing. Add a direct assertion through fixture.try_reconcile().

Suggested fix
     let mut fixture = Fixture::new();
     fixture.record = RecordIdentity::new(RecordClass::Asset, &["p1", "a1"]).unwrap();
+    assert_eq!(
+        fixture.try_reconcile(),
+        Err(ProtectedError::NotAnOrdinaryRecord)
+    );
     assert_eq!(
         fixture.write_with(&mut StdFs, b"bytes"),
         Err(ProtectedError::NotAnOrdinaryRecord)

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: b1b0e62a-e102-40d9-aaf1-09133035fc75

📥 Commits

Reviewing files that changed from the base of the PR and between 173bc14 and d278e45.

📒 Files selected for processing (5)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/protected.rs
  • crates/worldscript-secure-storage/tests/gate3c_protected_test.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Review wave on #949: the closure evidence names the injected boundaries
per suite instead of claiming every step, the CHANGELOG qualifies
directory sync on Windows, and the asset-pair refusal test also covers
reconcile_protected and an untouched record directory.

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs

qnbs commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant