feat(core): close R-15 Gate 3 with its evidence matrix and residual owners (#445) - #949
Conversation
…wners (#445) Gate 3's definition (file sync, atomic replacement, directory sync, generation reconciliation, fault injection) is met headless for ordinary records; contract 20 records the evidence per requirement and assigns every residual: asset-pair marker body to Gate 5, the key-epoch crash window and reclamation to Gate 4, power loss to Gate 6, deletion transitions to #948, and #357's legacy TypeScript path to Gate 7. The protected path now refuses a non-ordinary record before writing. R15_GATE3=IMPLEMENTED_HEADLESS.
|
@codex review |
🤖 CodeAnt AI — Review Status
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Reviewer's GuideThis PR closes R-15 Gate 3 for ordinary records in the headless secure-storage core, backed by cross-platform CI fault-injection evidence for synchronization, atomic promotion, directory durability, and generation recovery. It also fails closed for non-ordinary record classes before writing, records the remaining gate-owned work, and explicitly leaves production TypeScript/Tauri authority unchanged. Sequence diagram for Gate 3 durable protected writesequenceDiagram
participant Caller
participant protected_write
participant reconcile_protected
participant stage_and_promote
participant RootCommit
participant DurableFs
Caller->>protected_write: protected_write
protected_write->>protected_write: ensure_ordinary
alt non-ordinary record
protected_write-->>Caller: NotAnOrdinaryRecord
else ordinary record
protected_write->>reconcile_protected: reconcile_protected
reconcile_protected->>DurableFs: sync directories and recover generations
protected_write->>stage_and_promote: stage_and_promote
stage_and_promote->>DurableFs: sync staged files
stage_and_promote->>DurableFs: atomic generation promotion
protected_write->>RootCommit: commit marker transitions
RootCommit->>DurableFs: write-sync-rename-sync root pointer
DurableFs-->>protected_write: DURABLE_COMMIT_SUCCESS or COMMITTED_NOT_CONFIRMED_DURABLE
protected_write-->>Caller: ProtectedCommitted
end
Flow diagram for ordinary-record admission and residual ownershipflowchart LR
Request[Protected read write or reconciliation] --> Ordinary{Ordinary record?}
Ordinary -->|No| Refuse[NotAnOrdinaryRecord before writing]
Ordinary -->|Yes| Gate3[Gate 3 headless durable path]
Gate3 --> Evidence[CI fault-injection evidence]
Evidence --> Available[Available for ordinary records]
Gate3 --> Residuals[Remaining work has explicit owners]
Residuals --> Gate4[Gate 4 concurrency and reclamation]
Residuals --> Gate5[Gate 5 asset-pair commits]
Residuals --> Gate6[Gate 6 physical power-loss qualification]
Residuals --> Delete948[#948 deletion transitions]
Residuals --> Gate7[Gate 7 authority switch]
Gate7 --> Legacy[TypeScript/Tauri remains production authority]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Oct 2, 2026 7:38a.m. | Review ↗ | |
| Python | Oct 2, 2026 7:38a.m. | Review ↗ | |
| Rust | Oct 2, 2026 7:38a.m. | Review ↗ | |
| Shell | Oct 2, 2026 7:38a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 48 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughProtected write, reconciliation, and read paths now reject non-ordinary records before proceeding. The changelog and migration documents mark Gate 3 implemented headlessly and describe its evidence and remaining work. ChangesGate 3 protected storage
Priority: ⬇️ Low Merge Risk: 🔵 Low · up to The protected implementation currently rejects non-ordinary records, and production authority has not switched. Add direct reconciliation coverage and narrow the fault-injection claim before relying on the stated Gate 3 evidence.
Comment |
There was a problem hiding this comment.
All reported issues were addressed across 5 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
crates/worldscript-secure-storage/tests/gate3c_protected_test.rs (1)
455-467: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winAdd a direct reconciliation assertion for asset-pair records.
The asset-pair test exercises
protected_writeandread_protected, which each reject non-ordinary records before callingreconcile_protected. Removing onlyreconcile_protected’s guard would therefore leave this test passing. Add a direct assertion throughfixture.try_reconcile().Suggested fix
let mut fixture = Fixture::new(); fixture.record = RecordIdentity::new(RecordClass::Asset, &["p1", "a1"]).unwrap(); + assert_eq!( + fixture.try_reconcile(), + Err(ProtectedError::NotAnOrdinaryRecord) + ); assert_eq!( fixture.write_with(&mut StdFs, b"bytes"), Err(ProtectedError::NotAnOrdinaryRecord)
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
Review profile: CHILL
Plan: Essentials
Run ID: b1b0e62a-e102-40d9-aaf1-09133035fc75
📒 Files selected for processing (5)
CHANGELOG.mdcrates/worldscript-secure-storage/src/protected.rscrates/worldscript-secure-storage/tests/gate3c_protected_test.rsdocs/native/CORE-MIGRATION-LEDGER.mddocs/native/R15-SECURE-STORAGE-CONTRACT.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
Review wave on #949: the closure evidence names the injected boundaries per suite instead of claiming every step, the CHANGELOG qualifies directory sync on Windows, and the asset-pair refusal test also covers reconcile_protected and an untouched record directory.
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
|
@CodeAnt-AI review |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
User description
Part of #445; this is the Gate 3 closure for #921. No production authority switch:
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Evidence (contract §20 Gate 3 definition: "file sync, atomic replacement, directory sync, generation reconciliation, and fault-injection tests for one record class")
The evidence is headless and
CI_ONLY, on Linux, macOS and Windows runners. The faults are injected; this is not a power-loss test.stage_and_promotesyncs every staged file before promotiongate3_durable_testgate3_durable_test,gate3c_root_commit_testCOMMITTED_NOT_CONFIRMED_DURABLEgate3_durable_test,gate3b_commit_test,gate3c_protected_testgate3b_commit_test,gate3c_root_commit_test,gate3c_authority_test,gate3c_protected_testCode
protected_write,reconcile_protectedandread_protectednow refuse a non-ordinary record (control-plane, retained-authority, or an asset-pair member) withNotAnOrdinaryRecord, before anything is written. Test:an_asset_pair_member_is_refused_before_anything_is_written.Residuals, each with an owner (recorded in contract §20 and ledger row 10)
asset-pairmarker body and member commit (§8.4.1) belong to Gate 5, before any asset pair migrates.root_commit_mutex, exclusive admission, reader pins and generation reclamation.DELETE_PENDING/TOMBSTONED, §8.5), before Gate 7.R15_GATE3=IMPLEMENTED_HEADLESSis set in the block and in ledger row 10, and the status prose and CHANGELOG are updated. After this merges and the resulting main is proven, #357 and #921 will be closed with this evidence.CodeAnt-AI Description
Complete crash-durable protected storage for ordinary records
What Changed
Impact
✅ Crash-resilient ordinary-record updates✅ No partial files for unsupported record types✅ Clearer durability status on platforms without confirmed directory sync💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.