diff --git a/docs/audits/completed-roadmap-criteria/README.md b/docs/audits/completed-roadmap-criteria/README.md new file mode 100644 index 00000000..5380f773 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/README.md @@ -0,0 +1,96 @@ +# Completed-roadmap audit scope + +This directory continues issue #131. The criterion-by-criterion audit is in +progress; the scope manifest is not a completion verdict. + +The original roadmap at commit +`1a586d83d5750083172d440f90e7b786d540ff0e` has 83 checked task entries. +The first-pass roadmap at commit +`4b9c38930f988911ab020b7c42e9221b721933af` leaves 64 checked and reopens 19. +`scope.tsv` records every original task, its original line, and its first-pass +state. Originally unchecked tasks and feature-level checkboxes are excluded. + +The [foundation verdicts](foundations.md), +[identity-layer and chunking verdicts](identity-layers-and-chunking.md), and +[flat-layout verdicts](flat-layout.md), and +[reference-store and read verdicts](reference-store-and-reads.md), and +[conformance-oracle verdicts](conformance-oracles.md), and +[benchmark-baseline verdict](benchmark-baseline.md), and +[architecture verdicts](architecture.md), and +[immutable-segment verdicts](immutable-segments.md) cover the +first 33 remaining checked tasks. Each separates acceptance and mainline +delivery and names inspected evidence and limits. The individual verdicts +retain their inspected historical coordinates. T-06.3 has unresolved +acceptance scope. T-09.1's canonical report-admission gap was owned by +issue #142 and has since been delivered as recorded below. The historical T-10.2 +forbidden-filename gap was owned by issue #144. +T-11.2 exposes writable stage authority after sealing; issue #146 owns that +correction. T-11.3 still lacks its originally named integration-test artifact; +the living-documentation correction in #69 does not fulfill that requirement. + +The [catalog publication verdict](catalog-publication.md) adds T-12.2 at +main `b50dbd4cb4cee286aea1aa0352152a232197dda1`: a public repository-task +constructor bypasses production platform admission, reproduced independently +and owned by #150. T-12.3 now has a separate verdict at main `6051abb25a9fd33ae7ee0de5614514b709a4d82a`: restart examples pass, but generated independent catalog-model evidence is missing; issue #166 owns that correction. T-12.1 now has a separate functional/codecs verdict on the same main revision, with its source-text scan-cost evidence gap owned by #168. The [store initialization verdict](store-initialization.md) adds T-13.1 on that same main revision: the authority-producing path correctly propagates lock identity refusal, but its cited runtime evidence survives ignoring that refusal; issue #169 owns the acquisition-boundary evidence repair. Thirty-seven remaining checked tasks now have recorded verdicts; twenty-seven other checked tasks and nineteen reopened entries still need full accounting. + +## Mainline delivery after the inspected snapshot + +PR #143 delivered canonical benchmark report admission as +`b50dbd4cb4cee286aea1aa0352152a232197dda1`. The +[issue #142 receipt](https://github.com/flyingrobots/keep/issues/142#issuecomment-5946020879) +records exact-head validation, bounded parser fuzzing and forty-five +mainline task/library laws in each build mode. This resolves the identified +admission gap; it does not assert a fresh performance measurement or replace +the historical T-09.1 baseline evidence. + +PR #149 delivered the two catalog evidence-anchor corrections as +`82374a995df095106aefe52f87ab3cb26184639d`. The +[current-head merge gate](https://github.com/flyingrobots/keep/pull/149#issuecomment-5946195690) +records the corrected independent review, green required hosted checks and +fresh Docker execution of the two ordering and sixteen publication fixture +laws in both modes on the byte-identical target runtime. Issue #148 is +closed. These documentation corrections neither resolve T-12.2's platform +admission bypass nor close #150. + +PR #135 delivered the T-06.4 capacity-bounded reference-store memory contract +as `07bf0b8f4315305e248e1628b339243e5e59ee0b`. The +[issue #74 receipt](https://github.com/flyingrobots/keep/issues/74#issuecomment-5945001183) +records exact-head validation and debug/release mainline allocation laws. +This does not claim constant total memory or a successful four-GiB ingestion. + +PR #145 delivered forbidden Rust source-filename enforcement as +`88f35c417abeb62ef72c65b3a1904151cc2e3ee9`. The +[issue #144 receipt](https://github.com/flyingrobots/keep/issues/144#issuecomment-5944930436) +records mainline debug/release policy laws and exact-head validation. + +PR #134 delivered single authentication per selected layout occurrence as +`8d902516e682361882bc5c9902de296ce5c9de85`. The +[issue #71 receipt](https://github.com/flyingrobots/keep/issues/71#issuecomment-5945833591) +records debug/release mainline authentication and accounting laws. T-06.3's +immediate-output criterion remains unmet; issue #71 stays open. No original +criterion or checkbox has been changed. + +PR #136 delivered current v1 format documentation as +`99551ece786d47ef62ecff785a2e24261a911e85`. Its corrected ledger names the +actual filesystem unit laws. T-11.3's original named +`tests/segment_filesystem_stage.rs` integration target remains absent, so +closing #69 does not close this remaining audit gap. Executable +[issue #147](https://github.com/flyingrobots/keep/issues/147) owns the named +public integration target and its mainline evidence under the #131 audit. + +Validation now uses separate Docker build directories per source clone. +A shared target directory reused a stale test binary across clones; those +earlier runs do not establish source-specific validation. Fresh isolated +debug/release keep suites, formatting, workspace Clippy, and source policy +passed for main and the inspected PR #134/#135 implementations. + +Task identifiers can have an alphabetic suffix: `T-22.1a` is a distinct +originally completed task. Counting only numeric identifiers incorrectly +produces 82 original and 63 remaining entries. + +Original acceptance criteria and definitions of done remain binding. The +reviewed implementation and its integration into `main` require separate +verdicts. Existing follow-ups for reopened entries remain owned by the +[tracking container](https://github.com/flyingrobots/keep/issues/132). + +The [recovery findings in progress](recovery-findings.md) record a reproduced T-13.2 partial-seal contradiction that reaches a discard plan, owned by #171. This does not complete T-13.2's remaining criterion review or change the recorded verdict totals. diff --git a/docs/audits/completed-roadmap-criteria/architecture.md b/docs/audits/completed-roadmap-criteria/architecture.md new file mode 100644 index 00000000..8b9737f9 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/architecture.md @@ -0,0 +1,75 @@ +# Architecture decision and structural-enforcement audit + +This page owns T-10.1 and T-10.2 from the originally checked roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 496–513. Inspected main is +`f49cff732cf7a6e1b472decba9e4c4130990559e`. T-10.3's durable-port/fake inventory is evaluated below. + +## T-10.1 — Decide the architecture + +**Acceptance and delivery: met on main.** ADR-0004 is accepted and defines +inward dependency flow, semantic ports, codecs at boundaries, canonical +JSON/CBOR profiles and justified substitution boundaries. It records the +codec relocation, alternatives, invariants and compatibility consequences. +The task is the architecture decision; this verdict does not prove universal +implementation conformity or substitute for T-10.3's review. + +## T-10.2 — Enforce structurally + +**Acceptance/definition of done: not met.** The roadmap explicitly names +module size, forbidden filenames, no Python and denied unreachable public +visibility. Size and Python admission exist in `xtask/src/source_structure/`; +`Cargo.toml` denies `unreachable_pub`. The collector/classifier has no admission +for the nine Rust filenames prohibited by AGENTS.md. + +A copy-isolated Docker main-equivalent clone with its own build directory +received one new inventoried `src/utils.rs` containing a module-ownership +comment. `cargo xtask source-structure-check` exited successfully. This is +observed acceptance of a prohibited name, not a compile error or zero-test +result. The temporary file and its index entry were removed afterward; the +clone returned to a clean state. No host worktree was mutated by the probe. + +Correction owner: [issue #144](https://github.com/flyingrobots/keep/issues/144). +Its coherent scope is the existing literal basename prohibitions, with exact +refusals and preservation of current source/path/Python/size checks. It does +not introduce a new dependency-analysis requirement or substring naming ban. + +## T-10.3 — Durable protocol ports and fault-injecting fakes + +**Named acceptance and delivery: met on main.** The implemented durable write +protocols expose storage capabilities and deterministic fakes. The inventory +below checks the port and failure laws rather than relying on filenames alone. + +| Protocol | Port | Executed failure evidence | +| --- | --- | --- | +| Immutable segment writing | `SegmentStage` | Scripted short/interrupted/zero/overreported writes and synchronization refusals; no receipt after failed durability | +| Store initialization | `StoreInitializationStorage` | Failure at each of six initialization phases; exact phase/source and attempted prefix | +| Catalog generation publication | `CatalogPublicationStorage` | Recording storage with exact phase failures and stopping later writes | +| Recovery stage discard | `RecoveryStageDiscardStorage` | Exact expected-state and directory-sync refusals; retained stage on refusal | +| Recovery stage completion | `RecoveryStageCompletionStorage` | Stage/pool/staging synchronization failures, pool conflict and operation-prefix assertions | +| Recovery next-head finalization | `RecoveryNextHeadFinalizationStorage` | Verification, candidate sync, replacement and root-sync failure laws | +| Recovery segment resume | `RecoverySegmentResumeStorage` | Injected storage failure returns no resumable stage; stale fingerprint refuses | +| Retention publication | `RetentionPublicationStorage` | All 17 publication phase failures preserve exact attempted prefix; authority failure precedes mutation | +| Store migration | `StoreMigrationStorage` | All 21 phase failures preserve exact attempted prefix; current-state verification failure precedes mutation | + +The immutable segment port is exercised by the scripted `stage_double`; +catalog, recovery, retention and migration suites carry their recording or +in-memory storage doubles. These are substitution boundaries with observable +failures, not placeholder traits. Inspection of existing domain directories +found no adapter/filesystem/network/Serde imports, but this targeted review is +not an exhaustive architectural analysis of every boundary module. + +Copy-isolated Docker with pinned Rust 1.96.0 and the dedicated main-equivalent +source build directory ran all eleven listed public integration targets: 72 +laws passed in debug and 72 in release, with zero filtered or ignored tests. +The source clone has unchanged main Rust/corpus content; no new production +implementation or native test was introduced for this evidence. + +This verdict establishes ports and fakes for implemented protocols. It does +not assert that passing mocks proves filesystem durability, that partial +migration recovery is delivered, or that retention production admission is +complete; those require their own later-task and correction-owner evidence. +T-10.2 remains unmerged on main, with its correction in PR #145. + +Thirty remaining checked tasks now have verdicts. Thirty-four other checked +tasks and nineteen reopened entries still need full accounting. No checkbox +changed, and neither issue #131 nor its tracking parent is closed. diff --git a/docs/audits/completed-roadmap-criteria/benchmark-baseline.md b/docs/audits/completed-roadmap-criteria/benchmark-baseline.md new file mode 100644 index 00000000..0e63b9b8 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/benchmark-baseline.md @@ -0,0 +1,74 @@ +# Benchmark-baseline acceptance audit + +This page owns the originally completed T-09.1 verdict for issue #131. +Binding text is the original roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 440–450. +Inspected main is `f49cff732cf7a6e1b472decba9e4c4130990559e`. +Originally unchecked T-09.2 and T-09.3 are excluded. + +## T-09.1 — Corpus, scenarios, metrics and one baseline + +**Named artifacts: present on main. Definition of done: not met.** + +The roadmap delegates evidence to the benchmark README and supplies no +separate task-specific DoD block. The repository's parse/validate/admit and +canonical-format standards remain binding at the report publication boundary. +Correction owner: [issue #142](https://github.com/flyingrobots/keep/issues/142). + +| Obligation | Inspected and executed evidence | Verdict | +| --- | --- | --- | +| Generated bounded corpus | `benchmark/src/corpus.rs`, generators and corpus tests: deterministic members, exact edit coordinates and identities, total byte limit 16,777,216 | Pass | +| Thirteen reproducible scenarios | Scenario catalog and scenario tests: frozen order, every scenario executes, deterministic semantic counters | Pass | +| Five profile comparisons | Profile tests: exact parameters and pinned provenance, exact partition coverage, edit reuse and production registered-profile identities | Pass | +| Required reference metrics | Measurement/report modules: wall/process-CPU time, nearest-rank percentiles, allocation/live-heap counters, bytes, operations and exact ratio fields | Pass for this reference scope | +| Verification mandatory; diagnostics distinguished from optimized evidence | Verification posture has no disabled state; build-profile law refuses debug publication; report metadata records posture | Pass | +| One source-bound committed baseline | `benchmark/baselines/c529c07-aarch64-apple-darwin.tsv`: existing Git commit c529c07, clean source, Rust 1.96.0, Darwin 25.3.0/M1 Pro, 100 samples/five warmups, 13 scenario and five profile rows | Artifact present; fields verified | +| Threshold policy explicit | Artifact and README mark all performance thresholds unconfigured; controlled-history work is originally unfinished T-09.2 | Pass | +| Bound captured source/compiler/host without ambiguity | Artifact validator accepts expected metadata plus a conflicting second git-commit coordinate | Fail | +| Admit complete canonical metric rows before publication | Existing accepted unit fixture contains bare scenario/index and profile/index rows, without headers or metric fields; validator checks counts only | Fail | +| Delivery | Existing implementation and historical artifact are on main; strict admission correction has not landed | Correction required | + +The original artifact is a historical measurement witness, not proof that +current code has identical throughput. PR #134 has separately source-bound +single-pass evidence; cross-host timings cannot establish a speedup. This +audit neither repeats the historical timings nor invents hardware coordinates +for a new optimized baseline. Durable scenarios remain outside T-09.1. + +## Reproduced failure + +The production ingress is +`xtask/src/benchmark_baseline/artifact.rs::validate`. It checks that expected +metadata lines occur and that 13 scenario/five profile rows occur. It does +not exclude a conflicting metadata line or validate the complete row grammar. + +In the accepted existing fixture, append: + +```text +metadatagit-commitffffffffffffffffffffffffffffffffffffffff +``` + +The expected captured commit remains present as well. A Docker probe asserting +refusal failed at `conflicting source coordinates were admitted`: validation +returned success. No bad artifact was published. The probe was restored and +the source clone is clean. The first probe had a function-qualification compile +error and is not RED evidence; only the corrected running assertion is counted. + +Issue #142 owns one coherent complete-report admission boundary, including +permanent typed mutation/fuzz evidence and protection of prior artifact state. +Existing positive tests and green builds do not discharge this missing law. + +## Executed evidence and accounting + +Copy-isolated Docker, pinned Rust 1.96.0, main-equivalent source clone +`7981988`, dedicated target directory: + +- keep-benchmark: 19 unit laws and one public integration law passed in + debug and release. +- Two actual benchmark report-admission laws passed in debug and release. +- Conflicting-source probe: one executed law failed at the intended assertion. +- An earlier `benchmark_report` filter selected zero tests and is not evidence. + +No native tests, fresh optimized baseline, full-workspace validation or +performance threshold claim is made. Twenty-seven checked tasks now have +verdicts; 37 other checked tasks and 19 reopened entries still need accounting. +T-06.3, T-06.4 and T-09.1 retain acceptance/DoD/delivery gaps. No checkbox changes. diff --git a/docs/audits/completed-roadmap-criteria/catalog-publication.md b/docs/audits/completed-roadmap-criteria/catalog-publication.md new file mode 100644 index 00000000..8979f4b6 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/catalog-publication.md @@ -0,0 +1,88 @@ +# Catalog publication admission audit + +This page owns the T-12.1, T-12.2 and T-12.3 verdicts from the originally checked roadmap at `1a586d83d5750083172d440f90e7b786d540ff0e`, lines 544–550. The T-12.2 finding inspects main `b50dbd4cb4cee286aea1aa0352152a232197dda1`; the later T-12.1 and T-12.3 verdicts name their inspected revision below. + +## T-12.2 — Writer exclusion and platform-admitted publication + +**Acceptance/definition of done: not met across supported features.** The +ordinary publisher constructor consumes a private-field +`FilesystemPlatformAdmission`. Writer locking and the publication state +machine have executable exclusion, ordering, refusal and recovery evidence. +However, `repository-tasks` exposes a public alternate constructor accepting +only `FilesystemWriterLock`. Its admission producer performs lenient root +identity observation without enforcing the production platform profile. + +The path is +`src/adapters/filesystem_catalog_publisher.rs::open_unchecked_for_repository_tasks` +through +`src/adapters/filesystem_platform_admission.rs::unchecked_for_repository_tasks` +to the lenient identity probe in `filesystem_platform_profile.rs`. The +existing architecture law checks the ordinary constructor and admission type +text, so it does not cover this alternate public route. The production crash +harness consumes that route after unchecked repository initialization. + +A temporary public API probe on an actually unsupported Linux Docker +filesystem first verified production initialization's exact +`AdmitPlatform/Unsupported` refusal. It then created the canonical namespace, +acquired the writer lock, and called the public repository-task constructor. +The constructor returned a publisher. The refusal law failed with +`refused platform acquired public publisher authority` on the exact inspected +main source, using a dedicated build directory. No admission flags were +forged, no bad artifact was published, and no host test was run. + +This demonstrates a platform-admission capability bypass, not corruption or +physical power-loss failure. The original platform-admitted publication +criterion and the feature-invariant rule remain binding. Executable +[issue #150](https://github.com/flyingrobots/keep/issues/150) owns the public +boundary regression, correction and affected crash-harness adaptation as one +independently mergeable outcome. Shared harness files alone do not establish +a prerequisite on the separate sealed-stage escape in #146. + +## Executed evidence and remaining limits + +Eleven catalog integration targets passed 59 laws in Docker debug and 59 in +release on `8d902516e682361882bc5c9902de296ce5c9de85`. The two ordering laws +and sixteen filesystem publisher fixture laws also passed in each mode. +These fixtures use an unchecked test publisher and do not prove production +platform admission. The failure probe ran separately on the inspected newer +main source; passing existing fixture laws does not negate that failure. + +The catalog ledger's absent ordering and filesystem publication evidence +owners were corrected by +[PR #149](https://github.com/flyingrobots/keep/pull/149) for #148, integrated +as `82374a995df095106aefe52f87ab3cb26184639d`. The two ordering and sixteen +publisher fixture laws were freshly rerun in Docker debug and release on +its exact target `b50dbd4cb4cee286aea1aa0352152a232197dda1`; the documentation +PR changes no runtime or test code. Those reference corrections do not +resolve T-12.2 or close #150. No fresh crash campaign or host-power-loss +evidence is claimed here. + +## T-12.3 — Restart snapshot and model agreement + +**Acceptance: restart examples supported; model-agreement evidence incomplete under the binding testing standard.** This verdict inspects main `6051abb25a9fd33ae7ee0de5614514b709a4d82a`. `KEEP-CATALOG-009` and `KEEP-CATALOG-010` are separate promises; passing restart examples does not establish generated model agreement. + +`src/adapters/catalog_restart_loader.rs::load_from_directory` reads and admits the selected head, admits its named catalog, checks generation/length/digest, loads the referenced segments and constructs an admitted filesystem snapshot. `tests/catalog_restart.rs` exercises exact frozen payload reconstruction. Its `catalog_restart/refusal_laws.rs` exercises corrupt and unsupported heads, noncanonical catalogs, missing catalog/segment files and conflicting physical-name contents through `FilesystemCatalogSnapshot::load`. These are actual filesystem-backed public outcomes, not harness enumeration. They do not establish arbitrary concurrent out-of-band namespace isolation or physical power-loss recovery. + +`tests/catalog_model.rs::generation_transitions_and_lookups_match_a_btree_map` checks only one hand-written sequence: bundle, one chunk, empty. Its `model()` obtains expected identities and payloads through the same production `AdmittedSegment::records()` boundary consumed by catalog construction. The example can detect some lookup defects, but shared decoding errors can agree on both sides. It has no generated history space, independent input-derived map, absent-lookup checks or generated invalid transitions. The separate transition examples establish specified stale/predecessor refusals at their chosen points; they do not close this model-evidence gap. + +Testing Standards rules 5 and 6 require generated evidence for agreement claims and an independently grounded oracle. Existing tests have no blanket exemption under `docs/testing/enforcement.md`. Therefore the complete definition of done is not established, even though the historical requirement ledger says implemented and its existing example passes. [Issue #166](https://github.com/flyingrobots/keep/issues/166) owns generated independent model histories, exact runtime assertions, replay/reduction and assertion calibration as one independently mergeable correction. No production catalog defect is alleged by this finding. + +Fresh source-specific Docker runs on `6051abb25a9fd33ae7ee0de5614514b709a4d82a` passed `cargo test --locked` and `cargo test --release --locked`, each selecting `catalog_generation`, `catalog`, `publication_head`, `catalog_encoding`, `catalog_locations`, `catalog_transition`, `catalog_snapshot`, `catalog_restart` and `catalog_model` with `--test`. Source and build directories were separate from other candidate branches, and filesystem scratch used the container's owned ext4 mount. This receipt establishes those existing runtime examples only; no new mutation, generated campaign, full crash campaign or resource-ceiling enforcement is claimed. The separate T-12.1 verdict follows below. + +## T-12.1 — Catalog/head codecs, ordering and successor proofs + +**Acceptance: implemented functional paths have evidence; the complete definition of done is not met by the claimed scan-cost test.** This verdict inspects main `6051abb25a9fd33ae7ee0de5614514b709a4d82a` against `KEEP-CATALOG-001` through `-006` and `-011`. It does not certify the separate writer-platform or model requirements. + +| Criterion | Inspected implementation and evidence | Verdict and limit | +| --- | --- | --- | +| `001` positive generation, canonical ordering, checked exhaustion | `src/catalog/generation.rs`; `tests/catalog_generation.rs` checks zero, ordering and maximum successor refusal. | Supported by typed boundary examples and checked arithmetic. | +| `002` frozen canonical catalog/head codecs and integrity-before-entry semantics | `catalog_decoder.rs` validates header/length, then integrity, then entry sequence; `tests/catalog.rs`, its integrity laws and `tests/publication_head.rs` exercise frozen bytes and mutations. | Supported by independent golden/mutation examples; not inferred from round trips alone. | +| `003` strict logical identity order and duplicate refusal | Decoder entry-sequence validation and encoder sorting; `tests/catalog/ordering_laws.rs` reseals independently mutated duplicate/reversed entries before checking exact refusal coordinates. | Supported by the specified ordering examples and inspected production admission. | +| `004` exact top-level named-segment binding and grouped scan cost | `catalog_admission.rs` and `catalog_entry_plan.rs` bind exact segment digest, offset, length, identity and checksum; public location/encoding examples exercise invalid spans, missing/extra segments and duplicate records. | Functional binding evidence exists. The separately claimed single-scan test never calls admission and is not runtime cost evidence; #168 owns this gap. | +| `005` exact successor generation and predecessor | `catalog_transition.rs`; `tests/catalog_transition.rs` checks successful successor, stale generation, wrong predecessor and exhaustion. | Supported at the specified examples. Generated independent model evidence remains separately owned by #166. | +| `006` one immutable snapshot generation | `CatalogSnapshot` privately owns the admitted head/catalog proofs and exposes borrowed immutable records; `tests/catalog_snapshot.rs` checks pinned records after a later head and exact generation/length/digest mismatches. | Supports the immutable snapshot contract; not arbitrary concurrent raw filesystem mutation isolation. | +| `011` public catalog/head parser fuzzing | `fuzz/fuzz_targets/catalog_format.rs` dispatches to catalog/head decoding from deterministic canonical seeds prepared by `catalog_seeds.rs`; catalog decoding already validates the complete entry sequence. | Actual bounded execution confirmed in the mainline CI receipt below; no exhaustive malformed-input proof claimed. | + +`tests/catalog_locations.rs::catalog_admission_does_not_rescan_segment_records_per_entry` reads source strings, counts `.record_cursor()` and requires the spelling `entries.chunk_by_mut`. Calling `bind_segment(group)?` twice inside the existing group loop would preserve all those strings and their counts while repeating the runtime scan. The test therefore cannot establish its named promise. Inspection of the current algorithm shows one grouped scan; the finding is inadequate evidence, not an allegation that the current implementation already double-scans. [Issue #168](https://github.com/flyingrobots/keep/issues/168) owns replacement with calibrated runtime cost evidence and explicit deletion criteria for the change detector. + +The fresh Docker debug/release command recorded in the T-12.3 section includes the functional catalog targets above. The source-text assertion also passed, but that result is not admitted as runtime evidence. Mainline [CI run 37051028800](https://github.com/flyingrobots/keep/actions/runs/37051028800), on the inspected SHA, records `catalog_format` running from its canonical corpus with a 15-second campaign budget and completing normally; this is a bounded parser smoke campaign. The checked roadmap entry remains checked as instructed, with the unmet evidence obligation recorded explicitly. diff --git a/docs/audits/completed-roadmap-criteria/conformance-oracles.md b/docs/audits/completed-roadmap-criteria/conformance-oracles.md new file mode 100644 index 00000000..1c7112a7 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/conformance-oracles.md @@ -0,0 +1,89 @@ +# Conformance-oracle acceptance audit + +This page owns the four originally completed F-08 task verdicts for +issue #131. Binding task text is the original roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 423–430. +Inspected main is `f49cff732cf7a6e1b472decba9e4c4130990559e`. +These completed entries have no separate task-specific definition-of-done +block: the named artifact, implementation and evidence must be on main. + +## T-08.1 — Worldline scenario and reference model + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected and executed evidence | Verdict | +| --- | --- | --- | +| State eight semantic laws and ordered A/B scenario | `docs/conformance/golden-file-worldline.md`: Scope, ordered worldline, canonical corpus grammar and Reference model | Pass | +| Independent identity and scenario oracle | `xtask/src/golden_file_worldline/`: typed preimage construction, external b3sum identity witness, canonical coordinate/mutation checks and ordered scenario model | Pass | +| Admit B without changing A; reject B claimed as A with no side effect | Scenario oracle checks exact identity/input fixture relations and ordered admitted-set membership through the required step sequence; public Worldline laws separately execute the production reference store | Pass | +| Malformed, unsupported, absent and mismatched outcomes stay distinct | Invalid-text and mutation oracles; corpus steps; typed checker errors and canonical table admission | Pass | +| Executable checker and delivery | `cargo xtask golden-file-worldline-check` passed; documentation, corpus and checker exist on main | Pass | + +The independent model is corpus-bounded logical evidence, not physical +storage or crash evidence. Required capability rows and declared-future rows +remain distinct; a future row is not an executable witness. Oracle modules +do not import Keep production identity/store types. The separate xtask +workspace crate does depend on Keep for other repository tasks. + +## T-08.2 — Rust CDC and ChunkId oracles + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected and executed evidence | Verdict | +| --- | --- | --- | +| Rust independent CDC recipe and scalar boundary oracle | `xtask/src/protocol_conformance/cdc_profile/`: regenerates Gear table and 96-byte profile record; reconstructs sources/mutations and scalar boundary expectations | Pass | +| Independent ChunkId preimages | `xtask/src/protocol_conformance/chunk_identity.rs` builds typed domain/version/algorithm/content/length recipes and checks external b3sum results | Pass | +| Canonical bounded fixture admission | Corpus capability-relative no-follow reads; table byte/row limits; canonical decimal/hex/path profiles; final-LF/CR/blank-line refusal | Pass | +| Executable command and delivery | Isolated `cargo xtask conformance-check` passed; both corpora and checker modules exist on main | Pass | + +Independent means independent of production Keep codecs/detectors. Hash +witnesses still rely on BLAKE3 implementations; no collision-freedom or +second-language implementation claim follows. + +## T-08.3 — Segment-store v1 and v2 fixture oracles + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected and executed evidence | Verdict | +| --- | --- | --- | +| Construct frozen v1 bytes independently | `xtask/tests/segment_store_protocol_contract/fixture_oracle/`: segment, bundle, catalog and head field encodings, checksums, identity and artifact comparisons | Pass | +| Construct frozen v2 bytes independently | `xtask/tests/retention_store_v2_format_oracle/`: registered definitions, inventory, intent, receipt, retention roots/manifests/head and exact v1 predecessor artifacts | Pass | +| Oracles avoid production codec imports | Both oracle directories use their own field/encoding/preimage construction; no Keep production imports | Pass | +| Executable exact fixture evidence | Both integration targets passed in debug/release: 25 v1 protocol laws and four v2 format laws | Pass | +| Delivery | Named directories, integration roots and v1/v2 frozen corpora exist on main | Pass | + +Matching fixtures does not prove every durable write/recovery crash state. +Those obligations remain with their owning recovery and migration tasks. + +## T-08.4 — Bounded external digest execution + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected and executed evidence | Verdict | +| --- | --- | --- | +| Written failure/retirement decision | Accepted ADR-0008 specifies process-group termination, direct-child reaping, bounded reader retirement and typed cleanup evidence | Pass | +| Bound input/execution/output work | `xtask/src/external_digest.rs`: streamed input parts, admitted PATH/C locale, raw single-thread b3sum, ten-second deadline and separate stdout/stderr caps | Pass | +| Preserve primary and cleanup failures | Bounded-process capture/reader modules retain original failure and additional retirement failure; detaching an already-failed reader never yields success | Pass | +| Executable failure and resource laws | Bounded-process tests cover output limits, process deadlines, input/reader failures, signaling and retirement; passed in debug/release | Pass | +| Delivery | ADR, process boundary, external witness and executable laws exist on main | Pass | + +The deadline starts before synchronous spawn and governs remaining work +after spawn returns; it is not an OS guarantee that spawn itself cannot +block. Failed-reader retirement bounds caller waiting, not proof that an +arbitrarily blocked injected worker has stopped. These documented limits +are preserved, and uncertain cleanup remains failure. + +## Executed evidence + +On 2026-10-01, pinned Rust 1.96.0 in copy-isolated Docker used the +main-equivalent clone `7981988` with its dedicated target directory. + +- Worldline command passed; 31 Worldline unit laws passed in debug/release. +- CDC/ChunkId conformance command passed with b3sum 1.8.5. +- v1 protocol and v2 format targets: 25 and four laws passed per profile. +- 22 bounded-process unit laws passed in debug/release; the filtered + integration laws also passed. Targets selecting zero tests are not counted. + +Twenty-six of 64 remaining checked tasks have verdicts. The two reference +corrections retain their acceptance/delivery limitations; 37 other checked +tasks and full accounting of 19 reopened entries remain. No checkbox changes. diff --git a/docs/audits/completed-roadmap-criteria/flat-layout.md b/docs/audits/completed-roadmap-criteria/flat-layout.md new file mode 100644 index 00000000..f3990ba7 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/flat-layout.md @@ -0,0 +1,120 @@ +# Flat-layout acceptance audit + +This page owns the four originally completed F-05 task verdicts for +issue #131. It uses the source and delivery rules in [foundations.md](foundations.md). +Binding task text is the roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 287–294. +Inspected main is `f49cff732cf7a6e1b472decba9e4c4130990559e`. +These completed entries have no separate task-specific definition-of-done +block. Delivery requires the named specification, implementation and evidence +on main. Originally unchecked T-05.5 is excluded. + +## T-05.1 — Specify the format + +**Acceptance: pass. Delivery: pass. Leave checked.** + +The binding scope is KEEP-LAYOUT-001 through -012. Every row below is an +inspection of the frozen specification in +`docs/formats/flat-chunk-layout-v1/README.md`, not an implementation verdict. + +| Requirement | Exact specification evidence | Verdict | +| --- | --- | --- | +| 001: versioned fixed-width grammar | Canonical plan record: magic, version, codec, big-endian header and 44-byte entry tables | Pass | +| 002: domain and exact plan length | Canonical LayoutId: ADR-0002 envelope, domain prefix and trailing checked length | Pass | +| 003: target identity and length | Fixed header: embedded canonical 59-byte BlobId; Structural laws: final aggregate equals embedded logical length | Pass | +| 004: one registered profile | Fixed header binds a typed profile coordinate; admission recognizes registered identities only | Pass | +| 005: typed chunk coordinates | Header fixes chunk version and algorithm; Entry binds positive length and exact digest | Pass | +| 006: ordered contiguous spans | Structural laws: offset zero, exact predecessor end, no gaps or overlaps | Pass | +| 007: checked arithmetic | Record/entry formulas, Bounds, and Structural laws require checked arithmetic before allocation or cursor movement | Pass | +| 008: exact empty/nonempty cardinality | Structural laws distinguish zero entries from required positive count | Pass | +| 009: depth and allocation bounds | Bounds: depth one, 1,048,576 entries, 46,137,520-byte record maximum, configured admission cap before materialization | Pass | +| 010: unsupported mandatory fields | Header zero flags/reserved bytes; deterministic refusal order rejects unsupported coordinates | Pass | +| 011: canonical framing | Positional fields exclude duplicate fields; declared/calculated/actual length equality rejects extra or missing bytes | Pass | +| 012: typed domain-separated checksum | Record checksum defines exact BLAKE3 preimage and separates checksum from identity, authority and retention | Pass | +| Delivery | Frozen specification, rationale, requirement ledger and golden/mutation corpus are on inspected main | Pass | + +The specification also distinguishes parsing, admission and verified +reconstruction, and documents compatibility/security limits. Its future +hierarchical codec is not permission to reinterpret flat codec 1. + +## T-05.2 — Implement codec, admission and fuzz target + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected implementation and executed evidence | Verdict | +| --- | --- | --- | +| Admitted semantic state | `src/layout/admitted.rs` and `validation.rs`: private fields, registered profile, contiguous checked spans, cardinality and configured cap | Pass | +| Canonical record and explicit policy | `src/adapters/layout_record.rs`, `layout_decode_policy.rs`, encoder, decoder and framing modules; trusted types follow bounded raw-header parsing | Pass | +| Bounds before allocation | Decoder framing checks protocol/configured counts, checked lengths and exact input length before entry materialization; configured-cap and mutation laws exercise refusals | Pass | +| Checksum and expected identity | Decoder verifies checksum before nested semantic admission, then expected LayoutId; mutation laws pin first-failure precedence | Pass | +| Exact independent golden bytes | `tests/layout_record.rs`, `layout_decode.rs`, and `layout_oracle.rs`: compare semantic encoding, admitted decoding and independent field/checksum/identity oracle against frozen records | Pass | +| Generated canonicality and corruption | `tests/layout_properties.rs` and `layout_mutations.rs`: generated canonical records and every frozen mutation's typed first-failure class | Pass | +| Supply bounded fuzz target | `fuzz/fuzz_targets/layout_record.rs`: protocol-capped decoding, exact canonical reencoding and expected-identity readmission for accepted input | Pass | +| Delivery | Implementation, public tests, fuzz target and `conformance/layout/v1/` are on inspected main | Pass | + +The record oracle uses independently assembled field/preimage calculations +and the BLAKE3 library; it is not an independent hash implementation. +Decoding materializes bounded entry metadata, as documented, and does not +claim constant memory. This audit inspects the fuzz target but does not +claim a locally executed fuzz campaign or a maximum-entry allocation soak. + +## T-05.3 — Verified reconstruction replays the profile + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected implementation and executed evidence | Verdict | +| --- | --- | --- | +| KEEP-LAYOUT-016: reproduce declared spans | `src/profile/verification.rs` replays the registered detector and compares each emitted span with layout entries, including EOF completion | Pass | +| Apply replay to the exact reconstructed bytes | `src/reference/reconstruction.rs::verify_complete_blob` authenticates each chunk, feeds profile verifier and blob hasher, finishes both before output | Pass | +| Refuse false boundaries despite correct chunk bytes | `content_correct_false_profile_boundaries_are_refused_before_output`: exact first index and expected/observed span lengths, with no emitted bytes | Pass | +| Preserve complete-object identity scope | Whole-blob mismatch and committed reconstruction laws in `tests/streaming_cas/` verify complete identity before output | Pass | +| Delivery | Domain verifier, reference mapping and named public laws are on inspected main; requirement ledger marks -016 implemented | Pass | + +This does not certify a durable reconstruction API. The extra verification +pass on main is the separate performance defect owned by #71/PR #134; +it does not remove profile replay or weaken this task's acceptance law. + +## T-05.4 — Exact range planning + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected implementation and executed evidence | Verdict | +| --- | --- | --- | +| KEEP-LAYOUT-017: minimal ordered overlap | `src/layout/range_plan.rs`: checks bounds; skips entries ending at/before start; stops at entries starting at/after end; returns the first/end interval with checked arithmetic | Pass | +| Empty ranges select no entries | Planner returns no first entry and zero count; public zero-length laws cover coordinates through EOF with no output | Pass | +| Exact boundary and generated range bytes | `tests/range_read.rs` and `range_read_properties.rs`: boundary slices, every short valid range and generated multichunk ranges match reference slices | Pass | +| Instrumented lookup scope | `an_interior_range_loads_only_its_single_overlapping_chunk`: removes every unselected chunk, succeeds on an interior range, and observes only the selected identity | Pass | +| Precise absent/out-of-bounds/malformed failures | Public range entrypoint/failure laws refuse before output; admitted and canonical entrypoints agree | Pass | +| Delivery | Public planner, range APIs and instrumented laws are on inspected main; ledger marks -017 implemented | Pass | + +The instrumented law observes two reads of the same selected chunk on main; +it proves minimal selected identities, not a single authentication pass. +An exact range does not authenticate the whole BlobId or replay all profile +boundaries; the public range receipt documents that narrower scope. + +## Executed evidence and limitations + +The earlier targeted runs below used a shared target directory. Fresh +source-isolated full keep debug/release suites now replace them as +source-specific evidence; see the [validation correction](README.md). + +On 2026-10-01, copy-isolated Docker and pinned Rust 1.96.0 used the +main-equivalent source clone identified in [foundations.md](foundations.md). +The following twelve public targets passed in debug and release, totaling +52 laws in each profile: + +- `adapters_layout_contract`, `layout_decode`, `layout_mutations`; +- `layout_oracle`, `layout_properties`, `layout_record`; +- `range_read`, `range_read_contract`, `range_read_entrypoints`; +- `range_read_failures`, `range_read_properties`, `streaming_cas`. + +The exact private interior-range law passed once in each profile. An initial +module filter selected zero tests and supplies no evidence. A subsequent +test-list command failed because ripgrep was absent inside the container; +the corrected exact-name execution ran and passed the intended law. + +No durable crash, benchmark execution, full-workspace or fuzz-campaign +claim follows from these checks. The subsequent +[reference-store audit](reference-store-and-reads.md) brings accounting to +22 verdicts, followed by four [conformance verdicts](conformance-oracles.md). +The other 37 and full accounting of 19 reopened tasks remain. diff --git a/docs/audits/completed-roadmap-criteria/foundations.md b/docs/audits/completed-roadmap-criteria/foundations.md new file mode 100644 index 00000000..7c7b8d60 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/foundations.md @@ -0,0 +1,126 @@ +# Foundation acceptance audit + + + +This page owns criterion-level verdicts for the first remaining checked +tasks in issue #131. It does not certify the repository or close that issue. + +## Basis and verdict rules + +The binding task text is `ROADMAP.md` at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 202–230. The inspected +main implementation is `f49cff732cf7a6e1b472decba9e4c4130990559e`. +The task text delegates detailed evidence to its named documents; these +completed entries have no separate task-specific definition-of-done block. +Their delivery condition is the roadmap's definition of Done: shipped on +main, with evidence named in a ledger, changelog, or test file. + +Pass below applies to the stated task, not every future operation governed +by its contract. A contract document can be complete while implementations +that it governs remain incomplete. Originally reopened T-01.2 belongs to +issue #110 and is excluded from these remaining-task verdicts. + +## T-01.1 — State the law and its limits + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| State exact named bytes or refusal | `README.md` opening law; ADR-0001 Context and Verification | Pass | +| State identity's limits | ADR-0001 Consequences: identity proves neither retention, durability, location, nor semantic type | Pass | +| State authentication and output scope | `docs/invariants/authenticated-reconstruction/README.md`: Meaning of authenticated, Complete-object reconstruction, Exact-range reconstruction, Output visibility, and Receipt posture | Pass | +| Distinguish implemented reference behavior from future durable reads | Same contract's Durable reconstruction requirement and Current public evidence | Pass | +| Deliver the named documentation on main | All three named documents exist at the inspected main commit | Pass | + +This verdict does not claim durable logical reconstruction is implemented; +that explicit gap is owned by #109. The mount-comparison documentation +correction in #137 is also separate from stating the logical-byte law. + +## T-01.3 — Keep application semantics out of the core + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| No Echo, Git, Graft, WARP, or CLI types in `src/` | Reviewed crate dependency declarations and source imports; no application crates or named application types occur in `src/` | Pass | +| Protocol owns physical storage, not application policy | ADR-0005; `docs/formats/segment-store-v1/requirements.md` KEEP-STORE-016; record/catalog/head coordinate declarations and codec boundaries | Pass | +| Ship the application-free protocol | Domain modules, port declarations, and adapters are present on inspected main; `xtask` is a separate workspace crate | Pass | + +KEEP-STORE-016 is marked Specified in the format's design ledger. That row +alone is not implementation evidence; this verdict also inspects the +implemented types and dependencies. This is a source audit, not an +automated guarantee that every future change will preserve the boundary. + +## T-02.1 — Decide the identity contract + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Accepted identity decision | ADR-0001 Status: Accepted; exact logical bytes and explicit version/algorithm coordinates | Pass | +| Canonical preimage and representations | ADR-0001 byte tables: domain-separated prefix, payload, trailing big-endian length; strict text and 59-byte binary forms | Pass | +| Limits, failures, and alternatives | ADR-0001 Verification, Allocation and performance implications, Compatibility law, Alternatives considered, and Consequences | Pass | +| Deliver decision and independent fixtures | ADR and `conformance/golden-file-worldline/v1/identities.tsv` exist on main; ADR records independent b3sum fixture generation | Pass | + +An accepted contract is not proof of every planned transformation. The +compatibility law remains binding on future encryption and compaction. + +## T-02.2 — Implement identity types and codecs + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| `BlobId`, `BlobHasher`, `BlobLength` | `src/blob/id.rs`, `hasher.rs`, `length.rs`: private validated identity fields, checked accumulation, typed length | Pass | +| Both strict codecs with typed failures | `src/adapters/blob_id_binary.rs`, `blob_id_text.rs`, and their error enums; length/framing/version/algorithm/canonical text admission precedes trusted construction | Pass | +| Match independent corpus, not merely round trips | `public_blob_id_matches_every_golden_vector`: computed identity, exact text and exact binary compared to frozen corpus | Pass | +| Refuse malformed encodings and preserve operational sources | Worldline laws for noncanonical text, exact maximum text bounds, binary mutation classes, and reader failures | Pass | +| Deliver implementation and evidence | Named implementation, corpus, and public integration laws are on inspected main | Pass | + +Text refusals are typed variants. This task does not assert every variant +carries expected/observed fields; that stronger reopened obligation belongs +to T-01.2/#110. Parser fuzz targets exist for text, binary, and hashing; +they were inspected but not executed in this audit run. + +## T-02.3 — One-pass unknown-length streaming identity + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Unknown length needs no pre-scan or seek | `BlobHasher::hash_reader` consumes `Read` until EOF; no `Seek` bound or preliminary read; finish appends checked total length | Pass | +| Constant state, no content-sized spool | `BlobHasher` owns one BLAKE3 state and `BlobLength`; reader uses a fixed 8,192-byte stack buffer | Pass | +| Partition changes do not move identity | `input_partitioning_does_not_move_blob_identity` and `generated_bytes_and_partitions_preserve_identity`, including partitioned public readers | Pass | +| Overflow refuses before mutation | `length_overflow_refuses_before_mutating_identity_state`: exact typed failure, unchanged count and hash state | Pass | +| Deliver implementation and public laws | Named code and laws are on inspected main | Pass | + +Bounded state follows the inspected implementation; this run does not claim +an allocation benchmark or multi-GiB soak measurement for blob hashing. + +## Executed evidence + +The earlier targeted runs below used a shared target directory. Fresh +source-isolated full keep debug/release suites now replace them as +source-specific evidence; see the [validation correction](README.md). + +On 2026-10-01, a Git-bundle clone of audit commit `7981988` ran in Docker +with pinned Rust 1.96.0. Its Rust source and conformance corpus are unchanged +from inspected main; the extra commit adds only the audit scope documents. + +- `cargo test -p keep --test golden_file_worldline`: 14 laws passed. +- The same integration target with `--release`: 14 laws passed. +- `cargo test -p keep --lib length_overflow_refuses_before_mutating_identity_state`: + one law passed, in debug and release. +- `cargo fmt --check` and workspace/all-target/all-feature Clippy with + `-D warnings`: passed. +- `cargo xtask source-structure-check`: passed. An initial invocation used + the nonexistent `source-structure` command and failed before checking; + the corrected command succeeded. + +No full-workspace, reboot, power-loss, benchmark, or fuzz-run claim follows +from these targeted results. The next five verdicts are in +[identity layers and chunking](identity-layers-and-chunking.md). The other +37 checked tasks and 19 reopened tasks still need complete accounting +before issue #131 can close. + + diff --git a/docs/audits/completed-roadmap-criteria/identity-layers-and-chunking.md b/docs/audits/completed-roadmap-criteria/identity-layers-and-chunking.md new file mode 100644 index 00000000..1845ff28 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/identity-layers-and-chunking.md @@ -0,0 +1,111 @@ +# Identity layers and chunking acceptance audit + +This page owns the next five remaining-task verdicts for issue #131. +It uses the source and delivery rules in [foundations.md](foundations.md). +Binding task text is the original roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 246–274; +inspected main is `f49cff732cf7a6e1b472decba9e4c4130990559e`. +These entries have no separate task-specific definition-of-done block; +delivery means the named decision or implementation and evidence are on main. + +## T-03.1 — Decide identity layers and transition laws + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Distinguish the five concepts | ADR-0002 Decision separately owns BlobId, LayoutId, RepresentationId, physical location, and retention reference | Pass | +| Specify permitted identity changes | ADR-0002 Transition laws table covers rechunking, repacking, key changes, tier copy, both compaction postures, catalog rebuild, and logical-byte changes | Pass | +| Preserve refusal and evidence boundaries | ADR-0002 Required refusal behavior and adversarial examples distinguish stale coordinates, representation substitution, and publication authority | Pass | +| Deliver accepted decision | ADR-0002 is Accepted and present on main | Pass | + +The feature explicitly says Done **as a model**. This verdict does not +claim an implemented representation codec, encryption, or compaction. +Originally unchecked T-03.3 remains excluded. ADR-0002's unassigned-codec +statement describes what that decision assigned; the later layout format +makes its own assignment. + +## T-03.2 — Assign layout codec 1 + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Assign codec 1 to keep.flat-chunks/v1 | `docs/formats/flat-chunk-layout-v1/README.md`: header and Canonical LayoutId define coordinate and assignment | Pass | +| Preserve ADR-0002's typed envelope | Same specification: KEEP:LAYOUT:ID domain, envelope version, codec, exact plan bytes and trailing checked length | Pass | +| Bound canonical plan and admission | Same specification supplies grammar, bounds, unsupported-coordinate refusals and fixtures; `src/adapters/layout_id_binary.rs` admits codec 1 only | Pass | +| Deliver exact canonical coordinate evidence | `conformance/layout/v1/` and `tests/layout_id.rs` exist on main; golden text/binary and malformed-coordinate laws executed | Pass | + +Assignment does not certify all F-05 behavior. Those four completed tasks +receive separate verdicts later in the original task order. + +## T-04.1 — Decide algorithm and profile record + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Accepted deterministic boundary decision | ADR-0003 freezes Gear64/FastCDC, masks, probe-byte handling, NC2 normalization and seed zero | Pass | +| Exact first registered profile | ADR-0003: minimum 16,384, target 65,536, maximum 262,144 bytes; canonical 96-byte big-endian record | Pass | +| StorageProfileId and admission policy | ADR-0003 hashes exact profile bytes; `RegisteredStorageProfile` admits only the registered identity; `tests/storage_profile_identity.rs` verifies exact coordinate and typed unsupported-profile refusal | Pass | +| Deliver decision and independent record evidence | Accepted ADR, `conformance/cdc-profile/v1/profile-record.bin`, and independent conformance checker are on main | Pass | + +The independent checker reconstructs the 96-byte field encoding and hashes +it using external b3sum; this is stronger than a codec round trip. + +## T-04.2 — Implement FastCdc and ChunkId + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Deterministic registered detector | `src/chunk/detector.rs` and `detector_feed.rs`; frozen minimum/target/maximum, masks, checked offsets, and explicit EOF | Pass | +| Exact nonempty chunk identity | `src/chunk/id.rs` and `hasher.rs`; golden identity checks and exact empty-input refusal law | Pass | +| Source-partition invariant boundaries and identities | `tests/streaming_cdc/suite.rs`: golden sources, boundary-adjacent feeds, one-byte carry, and generated partition/reconstruction/bounds laws | Pass | +| At most 4 KiB retained state and no detector heap allocation | Inline-size law and isolated allocation measurement at 16 KiB, 1 MiB, and 4 MiB; both profiles pass | Pass | +| Supply fuzz and benchmark surfaces | `fuzz/fuzz_targets/fast_cdc.rs` compares whole, bytewise and input-derived schedules plus exact coverage; `benches/streaming_cdc.rs` benchmarks whole/bytewise feeds; benchmark builds in Docker | Pass | +| Deliver implementation and evidence on main | All named files exist at inspected main | Pass | + +The allocation measurement excludes caller-owned input creation and sink +allocation, matching the documented detector boundary. It measures total, +current, and peak allocation through `AllocationInfo::default()`. +The benchmark build proves the benchmark is executable, not a throughput +result. No performance change or speed claim is made. The fuzz target was +inspected; this local run did not execute a fuzz campaign. + +## T-04.3 — Language-neutral corpora + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Inspected evidence | Verdict | +| --- | --- | --- | +| Freeze reproducible CDC corpus | `conformance/cdc-profile/v1/`: language-neutral profile, sources, mutations, boundaries, binary Gear table and profile record, with origin and grammar | Pass | +| Freeze reproducible ChunkId corpus | `conformance/chunk-id/v1/`: exact identity manifest, domain/preimage recipe, and origin | Pass | +| Executable independent checking | `cargo xtask conformance-check` regenerates Gear table/profile and validates sources, mutations, boundaries and ChunkId digests using external b3sum; executed successfully | Pass | +| Compare production detector with frozen evidence | `every_golden_source_has_exact_boundaries_and_chunk_identities` compares the case sets and exact boundaries, then verifies each span's bytes and identity | Pass | +| Deliver both corpora and checker | Both directories and `xtask/src/protocol_conformance/` exist on main | Pass | + +Language-neutral describes the fixture grammar. It does not claim a second +language implementation or certify arbitrary third-party readers. + +## Executed evidence + +The earlier targeted runs below used a shared target directory. Fresh +source-isolated full keep debug/release suites now replace them as +source-specific evidence; see the [validation correction](README.md). + +On 2026-10-01, copy-isolated Docker used the same pinned Rust 1.96.0 +main-equivalent source clone identified in [foundations.md](foundations.md). + +- `streaming_cdc`: seven laws passed in debug and release. +- `streaming_cdc_memory`: one allocation law passed in debug and release. +- `storage_profile_identity`: five laws passed in debug and release. +- `layout_id`: four laws passed in debug and release. +- `cargo xtask conformance-check`: passed with b3sum 1.8.5. +- `cargo bench -p keep --bench streaming_cdc --no-run`: passed. + +The next four verdicts are in [flat layout](flat-layout.md). Fourteen of +the 64 remaining checked entries had verdicts at that stage. The subsequent +[reference-store audit](reference-store-and-reads.md) brings accounting to +22 verdicts, followed by four [conformance verdicts](conformance-oracles.md). +The other 37 and 19 reopened entries remain open. diff --git a/docs/audits/completed-roadmap-criteria/immutable-segments.md b/docs/audits/completed-roadmap-criteria/immutable-segments.md new file mode 100644 index 00000000..07f00cbd --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/immutable-segments.md @@ -0,0 +1,74 @@ +# Immutable-segment protocol and verified I/O audit + +This page owns T-11.1 through T-11.3 from the originally checked roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 527–533. Inspected main is +`f49cff732cf7a6e1b472decba9e4c4130990559e`. + +## T-11.1 — Specify bytes, crash states, and recovery together + +**Named acceptance and delivery: met on main.** Accepted ADR-0005 and the +segment-store format directory describe framing, canonical checksums, +publication ordering, incomplete-stage states, and recovery decisions as one +protocol. The specification separates logical identity from physical segment +layout. This verdict concerns the specification; it does not prove every +implementation transition conforms to it. + +## T-11.2 — Implement codecs, writer, and reader + +**Acceptance/definition of done: not met.** The header, record, seal, complete +reader, golden fixtures, corruption refusals, and bounded-memory laws exist. +The segment-format fuzz target exercises five decoding boundaries, but no new +fuzz campaign is claimed by this audit. + +KEEP-SEGMENT-005 requires a public sealed receipt to expose no mutable stage +handle. With `repository-tasks` enabled, public `SealedSegment::map_stage` +gives an arbitrary caller closure the owned writable stage and preserves the +original receipt metadata. A temporary public API regression sealed an empty +segment, wrote one additional byte through that closure, and observed 193 +bytes while the returned sealed receipt still reported 192. The exact length +assertion failed. The probe was removed after recording the result. + +This demonstrates writable capability escape and stale sealed evidence. It +does not establish that the filesystem publisher admits corrupted bytes: +publication has separate verification and authority checks. The production +crash harness uses this mapper to remove its storage decorator, so the fix +must preserve that harness without keeping arbitrary post-seal mutation. + +Correction owner: [issue #146](https://github.com/flyingrobots/keep/issues/146). +The correction must land capability restrictions, harness adaptation, and +regression evidence together without changing format or content identity. + +## T-11.3 — Deterministic fault injection at every write phase + +**Behavioral evidence: met; named evidence path needs correction.** The +scripted writer suite covers header, record-header, payload, checksum, seal, +short/interrupted/zero/overreported writes, and both flush/synchronization +boundaries. Failures preserve the exact phase, source, and accepted prefix; +failed durability produces no sealed receipt. + +The roadmap's `tests/segment_filesystem_stage.rs` does not exist. The actual +four filesystem laws live in +`src/adapters/filesystem_segment_stage_tests.rs`, covering exclusive creation, +one owner, exact sealed bytes, and retained unsealed prefixes. This is an +outdated evidence reference, not evidence that those laws are missing. +At this inspected snapshot, documentation correction was assigned to #69. +PR #136 subsequently corrected the living v1 ledger and closed #69, but did +not add the originally named integration target. The literal artifact +requirement remains undelivered; executable +[issue #147](https://github.com/flyingrobots/keep/issues/147) now owns it under +the #131 audit. Existing unit laws do not substitute for the named public API +integration artifact. + +## Executed evidence and limits + +Copy-isolated Linux Docker with pinned Rust 1.96.0 and its source-specific +build directory ran nine public segment integration targets: 67 laws passed +in debug and 67 in release. Four actual filesystem unit laws passed in each +build mode. The failing mapper probe ran with `repository-tasks` enabled and +was restored afterward. These runs establish observed behavior under the +specified checks, not absence of all crash or corruption failures. + +Thirty-three remaining checked tasks now have recorded verdicts. Thirty-one +other checked tasks and nineteen reopened entries still need full accounting. +No original checkbox changed, and no correction is declared integrated merely +because a PR exists. diff --git a/docs/audits/completed-roadmap-criteria/recovery-duplicate-tail-red.txt b/docs/audits/completed-roadmap-criteria/recovery-duplicate-tail-red.txt new file mode 100644 index 00000000..a54402fd --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/recovery-duplicate-tail-red.txt @@ -0,0 +1,24 @@ + Compiling keep v0.0.0 () + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.37s + Running tests/recovery_duplicate_tail_probe.rs (/debug/deps/recovery_duplicate_tail_probe-ec09477950ce7801) + +running 1 test +test incomplete_tail_does_not_erase_proven_duplicate_corruption ... FAILED + +failures: + +---- incomplete_tail_does_not_erase_proven_duplicate_corruption stdout ---- + +thread 'incomplete_tail_does_not_erase_proven_duplicate_corruption' (1822723) panicked at tests/recovery_duplicate_tail_probe.rs:33:5: +assertion `left == right` failed: known duplicate corruption escaped as discard plans + left: ["record-header: Segment(TailHeader { record_index: 2, offset: 354, required: 112, observed: 1 })", "record-payload: Segment(Record { record_index: 2, offset: 354, expected: 145, observed: 120 })", "seal: Segment(Seal { offset: 354, required: 128, observed: 16 })"] + right: [] +note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace + + +failures: + incomplete_tail_does_not_erase_proven_duplicate_corruption + +test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + +error: test failed, to rerun pass `--test recovery_duplicate_tail_probe` diff --git a/docs/audits/completed-roadmap-criteria/recovery-findings.md b/docs/audits/completed-roadmap-criteria/recovery-findings.md new file mode 100644 index 00000000..95b81d4b --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/recovery-findings.md @@ -0,0 +1,23 @@ +# Recovery audit findings in progress + +This page records verified findings while auditing originally checked T-13.2 at main `6051abb25a9fd33ae7ee0de5614514b709a4d82a`. It is not a completed verdict for `KEEP-RECOVERY-005` through `-012`. The remaining inventory, classification, fingerprint and assessment criteria still require their complete accounting; the audit's completed-verdict count is unchanged. + +## Corrupt partial seal can authorize discard + +`KEEP-RECOVERY-010` requires every available fixed-framing byte to remain canonical before classifying a partial segment as truncation, with demonstrated corruption remaining a typed refusal. `recovery_segment_classifier.rs::classify_tail` recognizes complete seal magic and returns `RecoverySegmentTruncation::Seal` for a short seal without checking its available version, flags or other fixed fields. + +A copied-Docker public API probe starts from the canonical `one-zero-segment.hex` fixture, changes the seal version's low byte from one to two, then retains only the segment through both version bytes. The complete records end at offset 209; the retained seal has 18 bytes. The classifier accepts it as seal truncation even though its available version contradicts the format. The regression compiles and fails with `unsupported seal version admitted as discardable truncation` on the inspected main revision. + +A second probe fingerprints those exact contradictory bytes, admits their evidence, calls `assess_recovery_stage`, and obtains a successful `plan_recovery_stage_discard` with reason `Segment(Seal { offset: 209, required: 128, observed: 18 })`. Its failure output records that executable plan. This verifies propagation through public assessment/planning; no filesystem discard was executed and no actual evidence deletion is claimed by the experiment. + +[Issue #171](https://github.com/flyingrobots/keep/issues/171) owns one bounded correction for partial-seal fixed framing, precise refusal, downstream discard prevention, canonical-prefix compatibility and parser corpus coverage. A coherent boundary/mutation sweep must cover the fixed-framing family; the fix must not become an open-ended investigation of every possible future completion. The version-one segment protocol is distinct from #99's approved preservation policy for incomplete version-two retention stages. + +The existing complete-seal corruption and canonical short-seal examples do not exercise this contradictory short-seal branch. This finding is a runtime correctness defect, unlike #169's acquisition-test evidence gap. The original roadmap checkbox is preserved. + +## Incomplete tails bypass known duplicate refusal + +`KEEP-RECOVERY-010` also requires duplicate identities to remain typed refusals. On the same main revision, a canonical header followed by two copies of the one-zero record correctly refuses `DuplicateRecordIdentity` at indexes 0/1 and offsets 64/209 when no tail follows. Appending incomplete bytes bypasses `segment_identity_index::validate`: the partial-seal branch returns directly, while truncated record/header errors return through `classify_cursor_error` before the reusable-prefix identity check. + +A copied-Docker public runtime probe preserves that no-tail control, then fingerprints, admits, assesses and plans discard for each of three tails after the same duplicate records. All three incorrectly yield executable discard plans at offset 354: a one-byte record header, a 120-byte partial record, and the 16-byte seal magic. The [actual parent RED](recovery-duplicate-tail-red.txt) records each exact plan reason. No filesystem removal was executed, so this evidence establishes erroneous authorization rather than observed deletion. + +[Issue #173](https://github.com/flyingrobots/keep/issues/173) owns the bounded correction across all truncation-return paths and the corresponding runtime/generated regressions. It is independent of #171/#172's fixed-seal-framing correction: canonical incomplete seal magic is enough to reproduce this distinct duplicate invariant violation. Integration must preserve both corrections, but shared source alone does not establish a prerequisite. T-13.2 remains in progress and its checkbox and completed-verdict accounting remain unchanged. diff --git a/docs/audits/completed-roadmap-criteria/reference-store-and-reads.md b/docs/audits/completed-roadmap-criteria/reference-store-and-reads.md new file mode 100644 index 00000000..70453500 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/reference-store-and-reads.md @@ -0,0 +1,151 @@ +# Reference-store and authenticated-read acceptance audit + +This page owns eight originally completed task verdicts for issue #131. +Binding text is the roadmap at +`1a586d83d5750083172d440f90e7b786d540ff0e`, lines 317–412. +Inspected main is `f49cff732cf7a6e1b472decba9e4c4130990559e`. +PR implementations and mainline delivery are separate observations. + +## T-06.1 — Bounded ingestion and reconstruction + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Evidence on inspected main | Verdict | +| --- | --- | --- | +| Bounded streaming input | `src/reference/ingestion.rs`: fixed read/chunk buffers, checked input accounting, entry limit; `chunk_staging.rs`: committed plus pending plus incoming payload capacity checked before copy | Pass | +| Invisible staging and explicit commit | `tests/streaming_cas/ingestion_laws.rs`: staged absence, dropped stage, capacity refusal, cross-store deduplication and commit laws | Pass | +| Exact bounded reconstruction | Committed reconstruction/range allocation laws; complete identity and profile verification before output; writer belongs to caller | Pass | +| 216 exhaustive three-step model sequences | `tests/streaming_cas/model_laws.rs`: six operations in three nested loops; after every step each of three blob cases is compared with a BTreeMap model | Pass | +| Delivery | Implementation and named public/model/allocation laws are on main | Pass | + +Bounded does not mean constant total staging memory: unique pending payload +may grow to capacity and metadata to the configured entry limit. T-06.4 +has its own stronger measurement/documentation obligation below. + +## T-06.2 — Chunk deduplication is a storage fact + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Evidence on inspected main | Verdict | +| --- | --- | --- | +| Deduplicate by exact ChunkId | `ReferenceChunkStaging::stage_chunk` checks committed and pending ordered maps by ChunkId and compares actual bytes before reuse | Pass | +| Refuse conflicting bytes | `conflicting_existing_chunk_bytes_are_never_repaired` and ingestion conflict mapping preserve refusal rather than replacing content | Pass | +| Do not confer retention | Reference-store README Contract and Ingestion explicitly distinguish process-memory presence/deduplication from retention and durability | Pass | +| Observable reuse | `identical_chunks_are_deduplicated_without_a_retention_claim`: first stage owns payload, committed repeat has zero pending payload; cross-store commit checks missing deduplicated content | Pass | +| Delivery | Named architecture documentation, implementation and tests are on main | Pass | + +## T-06.3 — Single-pass authenticated emit + +**Acceptance: fail/pending reconciliation. Delivery: blocked.** + +Current correction owner is #71 / PR #134 at `fbb3813`. The checked roadmap +entry is historical scope, not proof that this correction has landed. + +| Original field / obligation | Evidence | Verdict | +| --- | --- | --- | +| One chunk authentication per selected entry | Main calls verified_chunk during verification and emission; PR #134 counts one ChunkId hash per selected entry | Fail on main; pass in PR | +| Complete BlobId/profile verification and range accounting | Existing refusal/receipt/property laws retained; PR's exact range counter regression covers one-byte, whole and empty requests | Pass in PR | +| Preserve failure surfaces and untrusted prefix posture | Typed failures and writer-prefix laws retained; no successful receipt after sink failure | Pass in PR | +| Counting adapter and no new public type | Private test-only observed hashes; exact whole/range counting laws; only private emission helper added | Pass in PR | +| Immediate output by default; strict proof only through an explicit new API | Original scope and issue expected behavior request immediate output. PR deliberately retains normative complete-proof-before-output behavior with no new mode | Unsatisfied; contract-owner clarification pending | +| Existing golden/refusal laws and boundary range | Full keep suite and exact selected-chunk counting laws in PR; main's selected-range law still observes two reads | Pass for preserved laws; optimization not on main | +| Stress / read amplification becomes 1 | Source-bound optimized TSV at 30ffe90 records whole-blob authenticated-byte accounting 1/1; range accounting counts complete selected chunks once | Pass in PR; no cross-host CPU speedup claim | +| Benchmark baseline regenerated | `benchmark/baselines/30ffe90-aarch64-apple-darwin.tsv`: clean source, compiler/host, 100 samples, five warmups; historical baseline retained | Pass in PR | +| CHANGELOG and rewritten two-pass rationale | PR updates both; fbb3813 also corrects the stale current metric definition | Pass in PR | +| Regression merged; unchanged interfaces; no prerequisites | Interfaces unchanged and branch based on main; regression remains unmerged | Delivery blocked | + +Literal output-order scope conflicts with the current reconstruction +contract. One-hash evidence cannot resolve that conflict. PR #134 now refs +instead of closes #71, and its Code Lawyer report records the unresolved +requirement. Do not declare this task complete or silently alter its scope. + +## T-06.4 — Bounded-memory staging + +**Acceptance: pass in PR implementation. Delivery: blocked.** + +Correction owner is #74 / PR #135 at `b5def4a`. + +| Original field / obligation | Evidence in PR #135 | Verdict | +| --- | --- | --- | +| Bounded missing-chunk window, or explicit unavoidable-materialization rationale with enforced capacity refusal | Colocated rationale explains invisible unique chunks must remain owned by an in-memory stage; capacity is checked before copies | Permitted rationale alternative met | +| Explicit bound, checked accounting and invisible staged value | Named fixed scratch constant; payload capacity and independent entry/metadata cap documented; repeated-content stage remains absent until commit | Pass | +| Source larger than ceiling | Deterministic one-million-byte source refuses at 200,000-byte capacity within measured scratch/payload/empirical metadata allowance | Pass | +| Exactly at capacity and one byte over | Public ingestion laws assert admission at the configured payload capacity and exact attempted total on overflow | Pass | +| All chunks present and none present | Deduplicated stage owns no payload; over-capacity and repeated-content fixtures exercise new unique payload | Pass | +| Terminal source failure after partial staging | b5def4a consumes 300,000 bytes, including a staged full chunk and partial successor; exact source error, zero retained staging heap and original committed content preserved | Pass | +| Memory ceiling law and large-source behavior | Seven allocation laws; synthetic 4 GiB input refuses after first 256 KiB chunk; successful synthetic 4 MiB repeat stores one unique chunk | Pass; not successful 4 GiB ingestion | +| API scope and documentation | Stage parameters unchanged; additive scratch constant, README memory section, rationale and CHANGELOG; no durable spill or async fallback | Pass | +| Memory law merged; README example unchanged | Root README and existing examples unchanged by PR; law remains unmerged | Delivery blocked | + +The metadata allowance is empirical fixture slack, not a universal allocator +bound. The source error is preconstructed outside measurement to preserve +its allocation without attributing it to staging. A cleanup-leak mutant +fails with 262,368 retained bytes; real code passes. No production leak is +claimed. Review gates remain; source/fixture evidence is not integration. + +## T-07.1 — State the authenticated reconstruction contract + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Evidence on inspected main | Verdict | +| --- | --- | --- | +| Define complete and range proof scopes | Authenticated-reconstruction README: Complete-object reconstruction, Exact-range reconstruction, Receipt posture and Output visibility | Pass | +| State success/refusal/operational failure separately | Contract and Decisions, refusals, and operation failures; requirement ledger -005 and -006 | Pass | +| Bind coordinates, limits and future durable obligations | Coordinates and evidence; receipt types; durable requirement ledger -009/-010 remains Planned | Pass | +| Delivery | Contract, rationale and requirement ledger exist on main | Pass | + +## T-07.2 — Complete-object and exact-layout reads + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Evidence on inspected main | Verdict | +| --- | --- | --- | +| Complete-object exact bytes and receipt | Committed reconstruction law verifies bytes, target, exact layout and byte count; mismatch/missing/profile refusal laws emit nothing | Pass | +| Exact requested committed layout, no fallback | `reconstruct_layout` looks up only its requested LayoutId; absent layout returns LayoutMissing; ordered automatic selection is a separate path | Pass | +| Receipt is complete-object scope | Private construction after complete verification and exact written length; ReconstructionReceipt differs from RangeReadReceipt | Pass | +| Delivery | Public API, implementation, receipt and named laws are on main | Pass | + +## T-07.3 — Exact range reads select overlapping chunks only + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Evidence on inspected main | Verdict | +| --- | --- | --- | +| Load only minimal overlap | Flat-layout planner and instrumented private selected-chunk law; unselected chunks removed without failing the read | Pass | +| Exact range and admitted target binding | Boundary/property laws, admitted/canonical entrypoint equivalence, forged same-length target-layout refusal | Pass | +| Keep receipt scope narrow | RangeReadReceipt explicitly excludes whole blob, unselected chunks and profile-boundary verification | Pass | +| Delivery | Named public tests and private instrumented law are on main | Pass | + +## T-07.4 — Distinct success, evidenced refusal and operational failure + +**Acceptance: pass. Delivery: pass. Leave checked.** + +| Obligation | Evidence on inspected main | Verdict | +| --- | --- | --- | +| Content failures and operational failures differ | Boundary error variants distinguish missing/identity/profile evidence from source/sink I/O errors with preserved sources | Pass | +| Exact writer diagnostics and accepted prefix | `broken_range_writers_preserve_exact_failure_boundaries` and `range_failure_reports_the_prefix_already_accepted`: exact counts, layout, source kind and source chain | Pass | +| No success receipt on failure | Result Err paths cannot construct a success receipt; prefix failure remains explicitly untrusted | Pass | +| Delivery | Failure laws, receipt construction and contract evidence are on main | Pass | + +## Validation and remaining accounting + +Docker uses pinned Rust 1.96.0 and separate target directories per source +clone. Main, PR #134 and PR #135 source identities are distinct. Previous +shared-target executions could reuse stale binaries across clones and are +not used as evidence for these verdicts; isolated reruns replace them. + +Full `cargo test -p keep` passed in debug/release for all three clones, +including public, unit, property, corruption, memory and doctest targets. +The isolated main memory target has two laws; PR #135 has seven. Each clone +also passed fmt, workspace/all-target/all-feature Clippy with warnings +denied, and source-structure policy. Main uses the unchanged Rust/corpus +source at audit clone `7981988`. The PR #134 clone uses `6a95b5f`; its later +fbb3813 change is documentation-only and was linted separately. PR #135 +uses `e43ad0e` plus the final b5def4a test/documentation patches. No +full-workspace or dependency-policy rerun is claimed here. + +Twenty-two of 64 remaining checked tasks have verdicts. Two reference-store +corrections have unmet mainline delivery, and #71 additionally has unresolved +acceptance scope. Four further verdicts are in +[conformance oracles](conformance-oracles.md). Thirty-eight tasks and the +19 reopened entries still need complete accounting. No checkbox changes. diff --git a/docs/audits/completed-roadmap-criteria/scope.tsv b/docs/audits/completed-roadmap-criteria/scope.tsv new file mode 100644 index 00000000..082367a5 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/scope.tsv @@ -0,0 +1,84 @@ +task original_line first_pass_state +T-01.1 202 remaining +T-01.2 205 reopened +T-01.3 209 remaining +T-02.1 223 remaining +T-02.2 224 remaining +T-02.3 227 remaining +T-03.1 246 remaining +T-03.2 247 remaining +T-04.1 265 remaining +T-04.2 267 remaining +T-04.3 270 remaining +T-05.1 287 remaining +T-05.2 289 remaining +T-05.3 292 remaining +T-05.4 293 remaining +T-06.1 317 remaining +T-06.2 319 remaining +T-06.3 321 remaining +T-06.4 356 remaining +T-07.1 402 remaining +T-07.2 404 remaining +T-07.3 406 remaining +T-07.4 409 remaining +T-08.1 423 remaining +T-08.2 426 remaining +T-08.3 427 remaining +T-08.4 430 remaining +T-09.1 449 remaining +T-10.1 509 remaining +T-10.2 510 remaining +T-10.3 512 remaining +T-11.1 527 remaining +T-11.2 529 remaining +T-11.3 531 remaining +T-12.1 544 remaining +T-12.2 546 remaining +T-12.3 549 remaining +T-13.1 565 remaining +T-13.2 567 remaining +T-13.3 569 remaining +T-13.4 571 remaining +T-14.1 590 reopened +T-15.1 632 remaining +T-15.2 634 remaining +T-16.1 655 remaining +T-16.2 658 remaining +T-16.3 662 remaining +T-16.4 664 remaining +T-16.5 665 remaining +T-17.0 710 remaining +T-17.1 715 reopened +T-17.2 760 reopened +T-17.3 807 reopened +T-18.0 860 remaining +T-18.1 864 reopened +T-18.2 898 reopened +T-18.3 918 remaining +T-19.1 959 reopened +T-20.1 1006 reopened +T-21.1 1046 reopened +T-21.2 1095 reopened +T-21.3 1127 remaining +T-22.1 1188 remaining +T-22.1a 1193 remaining +T-22.2 1247 remaining +T-22.3 1284 reopened +T-22.4 1327 reopened +T-22.5 1367 reopened +T-23.1 1413 reopened +T-24.1 1477 reopened +T-24.2 1509 reopened +T-24.3 1566 reopened +T-25.1 1620 remaining +T-25.2 1622 reopened +T-37.1 2127 remaining +T-37.2 2128 remaining +T-37.3 2129 remaining +T-37.4 2130 remaining +T-37.5 2131 remaining +T-37.6 2132 remaining +T-38.1 2147 remaining +T-38.2 2164 remaining +T-38.3 2174 remaining diff --git a/docs/audits/completed-roadmap-criteria/store-initialization.md b/docs/audits/completed-roadmap-criteria/store-initialization.md new file mode 100644 index 00000000..51fe1a60 --- /dev/null +++ b/docs/audits/completed-roadmap-criteria/store-initialization.md @@ -0,0 +1,29 @@ +# Store initialization audit + +This page owns the T-13.1 verdict from the originally checked roadmap at `1a586d83d5750083172d440f90e7b786d540ff0e`, lines 565–566. It inspects main `6051abb25a9fd33ae7ee0de5614514b709a4d82a`. T-13.2 through T-13.4 require separate verdicts; this page does not close recovery or the process-death matrix. + +## T-13.1 — Ordered, idempotent, writer-locked initialization + +**Acceptance/definition of done: not fully evidenced.** The original task names `initialize_store` and `KEEP-RECOVERY-002` through `-004`; it has no additional per-task definition-of-done fields. The implementation performs the named transitions and preserves the identity refusal, but the cited replacement experiment does not demonstrate that the authority-producing path respects that refusal. No current production bug is alleged. + +| Criterion | Inspected implementation and evidence | Verdict and limits | +| --- | --- | --- | +| `KEEP-RECOVERY-002`: platform, writer lock, ordered directories, synchronization receipt, precise first failure | `store_initialization.rs` calls the semantic port in the prescribed order and returns only after root sync. `tests/store_initialization.rs` injects each phase failure and checks its exact phase and absence of later transitions. | Runtime protocol evidence passes debug/release. These are contract-boundary port interactions, not test-harness case counts or actual syscall-failure injection. | +| `KEEP-RECOVERY-003`: admitted platform, canonical partial namespace, no evidence replacement, exclusion and published reopen | `filesystem_store_initializer.rs`, `filesystem_initialization_storage.rs` and `filesystem_initialization_namespace.rs` retain authority through sync, require canonical types/membership and distinguish initialization from published reopen. `filesystem_platform_profile.rs` checks existing child device/mount identity and writable non-casefolded ext4 properties before initialization. | Filesystem initializer and platform-policy laws pass debug/release. Initializer fixtures deliberately bypass production platform probing; policy-property tests are simulated observations, not mounted-filesystem experiments. Public writer tests separately confirm exclusion, preserved bytes and no-follow behavior. | +| `KEEP-RECOVERY-004`: do not return authority after opened/selected lock identity disagreement | `FilesystemWriterLock::acquire` locks the opened file, calls `verify_current_identity`, propagates its failure and only then constructs the guard. The cited unit law calls the checker directly; the public replacement law substitutes after a first guard already exists and proves root-lock exclusion. | The current code is correct by inspection, but the cited runtime suite survives ignoring the production identity refusal. [Issue #169](https://github.com/flyingrobots/keep/issues/169) owns the missing acquisition-boundary experiment and its calibration. | + +The separate feature-gated publisher-admission bypass remains owned by [#150](https://github.com/flyingrobots/keep/issues/150). It is not relabeled as a new initialization defect or duplicated here. Production platform admission, observer helpers, repository-task fixtures and returned writer authority are distinct boundaries. + +## Surviving mutation and required correction + +In an isolated Docker copy of the inspected main source, replacing only `verify_current_identity(&directory, expected_identity)?;` with `let _ = verify_current_identity(&directory, expected_identity);` leaves the private replacement checker law, public catalog writer-lock laws, initialization port laws and filesystem initializer laws GREEN. The mutation still performs the observation but allows writer authority to escape after a mismatch. A checker-only assertion cannot detect its caller discarding the refusal. + +An earlier mutant removed the call entirely and encountered dead-code lint during public integration compilation. That attempt is retained separately and is not runtime calibration evidence. The ignored-result mutant compiled and executed the cited tests successfully. Original source was restored with timestamps invalidated, and public lock laws passed again in debug/release. + +The correction must exercise deterministic entry replacement between opening the file and the post-acquisition guard through the actual authority-producing boundary, assert exact refusal and retained evidence, and reject the surviving mutant. It need not invent a production fix or freeze helper structure. Deletion or replacement of the old checker-only test must name the stronger law and its limits. + +## Execution and scope + +Copied source and a dedicated build directory were used for main `6051abb`. Debug/release runs passed `store_initialization`, `filesystem_store_initializer_tests`, `filesystem_writer_lock`, `filesystem_platform_profile` and the public `catalog_writer_lock` target. No host Rust execution, ambient sleeps or source-string assertion was used as runtime evidence. The mutation receipt is limited to the named debug suites; it is not a claim that every repository test would survive. + +These experiments do not prove physical power-loss persistence, arbitrary out-of-band namespace isolation or every platform's syscall behavior. The roadmap checkbox remains unchanged; integration of #169 and a reviewed replacement receipt are still needed to close this evidence gap. diff --git a/docs/audits/pr-landing-2026-10-03.md b/docs/audits/pr-landing-2026-10-03.md new file mode 100644 index 00000000..d9336e65 --- /dev/null +++ b/docs/audits/pr-landing-2026-10-03.md @@ -0,0 +1,79 @@ +# Open pull request landing pass + +This ledger records the maintainer-authorized landing pass following the completed-roadmap audit (#131/#132). Each candidate receives a fresh Code Lawyer review, complete feedback reconciliation, current-head validation and an effective independent approval before a normal merge. The maintainer explicitly authorized independent Codex review using the agy-review protocol and appropriately sized models. No force push, history rewrite or repository-rule bypass is authorized. + +The starting mainline is `6051abb25a9fd33ae7ee0de5614514b709a4d82a`. Open correction PRs at the start are #133, #156, #157, #158, #159, #160, #161, #162, #163, #164, #165, #167, #170 and #172. Current state and final evidence are recorded below; green earlier heads are not transferable to changed candidates. + +## Candidates + +| Candidate | Current disposition | Evidence and next action | +| --- | --- | --- | +| #172 / #171 | Merged as `d0cff10d7c911d33d615c3aa2246ae2b4497432a` | [Fresh independent GPT-6.1 high-reasoning APPROVE](https://github.com/flyingrobots/keep/pull/172#issuecomment-5972433501) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/172#issuecomment-5972433684) cover candidate `07e6cc4875c05592b71bb1f8b9c80631a31bcda5`. Required candidate checks passed. Signed normal merge has exactly the reviewed tree. [Mainline run 37146130023](https://github.com/flyingrobots/keep/actions/runs/37146130023) completed with all four jobs successful. | +| #158 / #146 | Merged as `182e49520f98c6035828a739dcf3c224df535b84` | [Fresh independent GPT-6.1 high-reasoning APPROVE](https://github.com/flyingrobots/keep/pull/158#issuecomment-5972567368) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/158#issuecomment-5972567648) cover `e781c0b276ec4d1f66a76668bd31893261a2e6dd`. Full copied-Docker validation and all four candidate jobs passed; CodeRabbit approved. Signed normal merge preserves the reviewed tree. [Mainline run 37146917789](https://github.com/flyingrobots/keep/actions/runs/37146917789) passes all four jobs. | +| #157 / #150 | Merged as `64fafe3ddcc92bcc45a461a0161030b87559070d` | [Full independent review](https://github.com/flyingrobots/keep/pull/157#issuecomment-5972688527) found one P4 current-consumer documentation mismatch, fixed in final candidate `3626f6e2677a1d6d3af08b88245584800596ff55`. [Exact-successor APPROVE](https://github.com/flyingrobots/keep/pull/157#issuecomment-5972712031) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/157#issuecomment-5972742138) reconcile all feedback. Full copied-Docker runtime validation passes at the integration parent; fresh doc/static checks pass on the rustdoc-only successor. [Final-head run 37147862754](https://github.com/flyingrobots/keep/actions/runs/37147862754) passes all four jobs. CodeRabbit was rate-limited, not an approval. Signed merge preserves the candidate tree; [mainline run 37148264987](https://github.com/flyingrobots/keep/actions/runs/37148264987) passes all four jobs. | +| #133 / #110 | Stacked on unfinished #107, not a direct-main candidate | Live PR base is `feature/roadmap-m4-tasks`; its body explicitly requires that branch’s storage and transfer APIs. Preserve the branch and evaluate that dependency before choosing a safe mainline integration boundary. Earlier validation claims are historical, not current landing acceptance. | +| #156 / #147 | Merged as `1325841cbcd27f4c504870728e3ca87d87a2c4cc` | [Fresh independent APPROVE](https://github.com/flyingrobots/keep/pull/156#issuecomment-5972840605) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/156#issuecomment-5972844070) cover candidate `05658799fb259a445f68c8bd434135483d491e40`. Full copied-Docker validation, explicitly bounded isolated serial/parallel runs and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37148378148) pass. Signed merge preserves the reviewed tree; [post-merge run 37149079743](https://github.com/flyingrobots/keep/actions/runs/37149079743) passes all four jobs. | +| #159 / #128 | Merged as `d08fafb2280a480a3c7d9460d13d53bbed4ae46b` | [Full independent review](https://github.com/flyingrobots/keep/pull/159#issuecomment-5972935118) identified a finite oracle-calibration gap, closed by durable receipts and [exact-head APPROVE](https://github.com/flyingrobots/keep/pull/159#issuecomment-5972986655) at `e768c8fcf769f25c422762cf67fa93384363ea68`. [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/159#issuecomment-5972997508) records the full copied-Docker chain, three intended mutation failures, restored debug/release GREEN and corrected receipt formatting. All four [final candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37149868953) pass; CodeRabbit approves. Signed normal merge has the exact reviewed tree. [Mainline run 37150330954](https://github.com/flyingrobots/keep/actions/runs/37150330954) passes all four jobs. | +| #160 / #113 | Merged as `34d70909b0cd93f6b020a59d4d40f43b07971cd8` | [Full independent review](https://github.com/flyingrobots/keep/pull/160#issuecomment-5973082033) found a finite calibration gap. One isolated batch demonstrates post-death lock acquisition, persisted fence preservation and post-release admission failures; restored debug/release laws pass. [Exact-head APPROVE](https://github.com/flyingrobots/keep/pull/160#issuecomment-5973131205) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/160#issuecomment-5973158803) cover final `c51e231e4ab456fbc8fa84f0fc2ca9609bb19ae3`. Full copied-Docker validation, bounded isolation checks and all four [final candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37151013484) pass. CodeRabbit is rate-limited, not approval. Signed normal merge preserves the reviewed tree; all four [mainline jobs](https://github.com/flyingrobots/keep/actions/runs/37151421847) pass. | +| #161 / #111 | Merged as `80d23f51897085bac34bb5c4db067d0627748e13` | The completed-namespace bug and finite diagnostic calibration findings close with actual baseline RED, fix `a3ea6c3`, and preserved receipts. Current candidate `2f22d0d9097820503d2a81085bb748273de9f56d` integrates #175, with both CHANGELOG entries preserved. [Exact integration APPROVE](https://github.com/flyingrobots/keep/pull/161#issuecomment-5973635915) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/161#issuecomment-5973636542) confirm both P2s remain closed. Full exact-tree copied-Docker validation and all four [final jobs](https://github.com/flyingrobots/keep/actions/runs/37154563204) pass. Signed normal merge has exactly the reviewed tree. [Mainline run 37155035000](https://github.com/flyingrobots/keep/actions/runs/37155035000) passes all four jobs. | +| #175 / #174 | Merged as `1c2b9d788fd4029d2469d2651faf0f8db2e0869e` | [Independent APPROVE](https://github.com/flyingrobots/keep/pull/175#issuecomment-5973505523) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/175#issuecomment-5973562719) cover final `e1300cf4a866bd34cba4ebf7dd50233ca264dada`. Deterministic fixture-contract RED, full copied-Docker validation and all four [final jobs](https://github.com/flyingrobots/keep/actions/runs/37153901813) pass. Initial receipt-whitespace and dependency-download failures remain recorded; the latter occurred before tests and its same-SHA execution succeeded. Signed normal merge preserves the reviewed tree. [Mainline run 37154541889](https://github.com/flyingrobots/keep/actions/runs/37154541889) passes all four jobs. | +| #162 / #112 | Merged as `5179ed78a74d19a3c24f300acbc5228144e6628a` | Integration preserves both changelog histories and mainline's stronger emitted-corpus runtime witness. [Full independent review](https://github.com/flyingrobots/keep/pull/162#issuecomment-5973702502) found one finite P2 calibration proof gap, closed by six intended runtime controls and restored decoder/fuzz GREEN in `1c886fdb3ab17c62d0b935f22dd3d7818709245c`. [Exact-head APPROVE](https://github.com/flyingrobots/keep/pull/162#issuecomment-5973741739) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/162#issuecomment-5973768453) confirm closure. Full copied-Docker validation and all four [final hosted jobs](https://github.com/flyingrobots/keep/actions/runs/37155679287) pass. Signed normal merge preserves the reviewed tree. [Mainline run 37156099123](https://github.com/flyingrobots/keep/actions/runs/37156099123) passes all four jobs. | +| #167 / #166 | Merged as `eb506dfb3830a32b0aec6a963c69da4f87012161` | [Fresh independent APPROVE](https://github.com/flyingrobots/keep/pull/167#issuecomment-5973842608) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/167#issuecomment-5973846145) cover `239bd19553449f8e509cc7752f142f7e2c4e46ff`. Full exact-tree copied-Docker validation and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37156173106) pass. The signed normal merge preserves the approved tree. [Mainline run 37156675889](https://github.com/flyingrobots/keep/actions/runs/37156675889) passes all four jobs. GraphQL refresh failed; complete REST discussion/review/inline retrieval confirmed no new findings. A failed description-read briefly cleared the PR body; it was restored and verified with source unchanged. | +| #170 / #169 | Merged as `d7c761e5cad8c4ba3a1ebb56c0e171ef6036910d` | [Fresh independent APPROVE](https://github.com/flyingrobots/keep/pull/170#issuecomment-5973931267) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/170#issuecomment-5973938907) cover candidate `e5b176a2e3a0c15d686b98685417067947d15520`. All three hosted findings and the prior receipt-whitespace finding remain closed; six mutation controls and eleven portable raw outputs were verified. Full exact-tree copied-Docker validation and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37156717967) pass. The signed normal merge preserves the approved tree and both CHANGELOG histories. [Mainline run 37157196665](https://github.com/flyingrobots/keep/actions/runs/37157196665) passes all four jobs. | +| #164 / #109 | Merged as `1079551bc6b331eb9847823e7d22b22ea4c47b62` | Fresh review fixed the allocation-documentation mismatch and two late public diagnostic defects: caller-input decoding and repeated source rendering. [Final independent APPROVE](https://github.com/flyingrobots/keep/pull/164#issuecomment-5974246110) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/164#issuecomment-5974261856) cover `9d19e2e0c3184efd5bc08c1f8cc12edd15421a93`. Actual runtime RED, debug/release GREEN, full final copied-Docker validation and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37158962636) pass. CodeRabbit accepted the late dispositions and withdrew optional fixture extraction; obsolete changes-requested reviews were explicitly reconciled. The signed normal merge has exactly the approved tree. [Mainline run 37159373928](https://github.com/flyingrobots/keep/actions/runs/37159373928) passes all four jobs. | +| #165 / #114 | Merged as `2efc131e8466b458088eaf5de0a5981e636d8f85` | [Fresh independent GPT-6.1 high-reasoning APPROVE](https://github.com/flyingrobots/keep/pull/165#issuecomment-5974504658) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/165#issuecomment-5974510981) cover `1f3991f86fa66783d88b9ac8dbb79ecd0d9a9554`. All late namespace/segment diagnostic findings are fixed with observed runtime RED, debug/release GREEN and distinct diagnostic calibration; shared expectations explicitly adopt the enriched error variant. Full isolated Git-archive Docker validation and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37160522753) pass. Prior assertion and copy/cache setup failures remain historical failures. No unresolved thread or effective changes request remains. Signed normal merge has the approved tree; [mainline run 37161239415](https://github.com/flyingrobots/keep/actions/runs/37161239415) passes all four jobs. | +| #163 / #130 | Merged as `2c0f0893b854bbc9989adcabc2f3f950d90e8c84` | Candidate `26c32d05038c7a3a38eda7cb2d259177013f5bf8` integrates main `2efc131` without runtime changes. Linked read/verification delivery labels and the migration ledger now agree with merged evidence. [Full independent review](https://github.com/flyingrobots/keep/pull/163#issuecomment-5974602999), [final exact-head APPROVE](https://github.com/flyingrobots/keep/pull/163#issuecomment-5974673177) and [CodeRabbit correction confirmation](https://github.com/flyingrobots/keep/pull/163#discussion_r4175406473) close both documentary findings. The obsolete changes-requested review is dismissed as addressed. Copied-Docker Rust/rustdoc checks pass at the unchanged-source integration; pinned Markdown passes on the final successor. Final-head [run 37162157015](https://github.com/flyingrobots/keep/actions/runs/37162157015) passes all four jobs. [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/163#issuecomment-5974690454) records final acceptance. Signed normal merge preserves the exact reviewed tree; all four [mainline jobs](https://github.com/flyingrobots/keep/actions/runs/37162628706) pass. | +| #107 and #141 | Eight original #107 inline findings closed; broader integration/audit unfinished | Pushed candidate `7cdc2cfbef59407f3c38881b39a290cb85501f9b` retains the independently reviewed fuzz, reader-lock, provenance and fixed-layout repairs recorded below. The four remaining original inline findings now have public runtime oracle corrections or a behavior-preserving readability correction. [Exact-successor independent delta approval](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976316751) and [Code Lawyer activity](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976316891) verify those changes and the consolidated `docs/testing-evidence/gc-retention-oracles.md` receipts, including the corrected retention evidence claim. Focused debug/release, both Clippy configurations, source structure, Markdown and whole-tree whitespace pass; rejected calibration setup/cache attempts are preserved. A fresh read-only integration preview at `e8ae339` still has 88 conflict paths against actual main `3165890`; its successors change only documentation. Required hosted jobs are absent for the conflicted candidate. Integration, original scope and review-body reconciliation, test-resource policy, full final validation and whole-PR approval remain gates. #133 stays stacked on #107; #141 remains the unfinished audit. | +| #106 and #105 | #106 merged as `4623b1621ed286fa21cb4a97367dedc3500bad05`; #105 closed as superseded | [Independent APPROVE](https://github.com/flyingrobots/keep/pull/106#issuecomment-5974779684) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/106#issuecomment-5974818774) cover candidate `1dc8440b4a938c83e6e0f8fa13e7d1533fba33a4`. Observed old-policy RED, exact-tree focused debug/release GREEN, real valid/malformed Markdown and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37162965032) pass. Signed merge preserves the reviewed tree; all four [mainline jobs](https://github.com/flyingrobots/keep/actions/runs/37163664544) pass. The [explicit maintainer waiver](https://github.com/flyingrobots/keep/pull/106#issuecomment-5974764492) covers only existing test-resource gaps for these version expectations, expires 2026-10-17 and is tracked by #177. Both npm graphs retain the separate braces advisory tracked by #176. #105 package bytes were verified identical to merged main before closing it; it is not counted as merged. | +| #104 | Merged as `7a21faebdbed38c386db14873966d433754c6eb4` | [Independent APPROVE](https://github.com/flyingrobots/keep/pull/104#issuecomment-5974823144), [actual-main confirmation](https://github.com/flyingrobots/keep/pull/104#issuecomment-5974848817) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/104#issuecomment-5974901930) cover `97edb3c4a0bf43ddd4691714bd2578d65fa52be1`. Copied-Docker policy/CLI checks and all four [candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37163553224) pass. Actual hosted logs verify the checksummed cargo-binstall fallback, signature-verified b3sum package resolution and successful consumers, plus pinned deny/audit installation and use. The missing-b3sum local setup failure remains recorded. Signed normal merge preserves the exact reviewed tree; [mainline run 37164344603](https://github.com/flyingrobots/keep/actions/runs/37164344603) subsequently failed one release durable-layout law with `WriterLock { source: Busy }`, plus a separate documentation dependency download; #178 tracks diagnosis and further merges are paused. | +| #103 | Merged as `3165890e9291cfb5fe10e81a9d7cd151f3e59464` | [Full independent APPROVE](https://github.com/flyingrobots/keep/pull/103#issuecomment-5974934777), [actual-main confirmation](https://github.com/flyingrobots/keep/pull/103#issuecomment-5974939191) and [Code Lawyer closure](https://github.com/flyingrobots/keep/pull/103#issuecomment-5974973864) cover `fa3c2b56991e0ff5ceff909c959afdafef4815ca`. Debug/release tool-policy and CLI laws, both Clippy configurations and final Markdown checks pass. All four [final candidate jobs](https://github.com/flyingrobots/keep/actions/runs/37164128210) pass. The signed normal merge preserves the reviewed tree. All four [post-merge jobs](https://github.com/flyingrobots/keep/actions/runs/37164907909) pass; that success does not erase the preceding #104 contention failure. | +| #102 | Integrated candidate validated locally; prerequisite/policy gates pending | Pushed `11bc72c41cc379944766adbdef60f046e786b820` combines approved rustix parent `afb5f000` and #179's `f9a9c2e`; the sole CHANGELOG conflict preserves both entries. [Independent delta review](https://github.com/flyingrobots/keep/pull/102#issuecomment-5975250540) finds no new implementation defect and confirms copied tree `01c712f41fac391e14bde02cd84be3150596fd85`. Focused locator/golden laws pass in both profiles, both Clippy configurations, format and structure pass; prior complete graph validation retains its original SHA and setup failures. Current [hosted run 37166512607](https://github.com/flyingrobots/keep/actions/runs/37166512607) passes all four required jobs. #179's distinct waiver and landing, final CI and exact-head approval remain required; #106 approval is not extended. | +| #179 / #178 | Corrective candidate in final validation; explicit policy disposition required | Pushed `f9a9c2ec8614ce9f905ef97aeb2163b5acc5982a` isolates the unchanged locator laws in their own executable. Original hosted Busy, a pipe-controlled inherited-lock experiment and honest causal limits are preserved in the PR. Focused debug/release and Clippy pass; [CodeRabbit approves](https://github.com/flyingrobots/keep/pull/179#pullrequestreview-5403640148). [Independent review](https://github.com/flyingrobots/keep/pull/179#issuecomment-5975125402) found no code defect but requires a scoped resource-profile waiver or enforcement, tracked by #180. The full local chain was interrupted by container exit 255 during compilation (not OOM), then resumed at the same tree after ext4 mounts were reverified. The resumed remaining chain completed successfully on the unchanged tree; all four [hosted jobs](https://github.com/flyingrobots/keep/actions/runs/37165745204) pass. A scoped waiver through 2026-10-17 was requested from the maintainer; approval and resulting independent-review confirmation remain gates. | +| #94 | Source and benchmark evidence approved; hosted CI green; prerequisites pending | Pushed `9a7a46ec6d5043f61222c2f75fc7c49a16002cd3` updates both BLAKE3 graphs and admission without changing expected identities or external b3sum. Full copied-Docker chain passes at `6ee5565`, tree `deaaa8ba81318296516310b49d81f12f0ca7f546`; subsequent changes affect admission prose only. [Full review](https://github.com/flyingrobots/keep/pull/94#issuecomment-5975317528) and [exact-head delta confirmation](https://github.com/flyingrobots/keep/pull/94#issuecomment-5975331547) close both documentation findings with source APPROVE. All four [final hosted jobs](https://github.com/flyingrobots/keep/actions/runs/37167535271) pass. Original lint and local benchmark refusals remain preserved. Separate [hosted Docker benchmark run](https://github.com/flyingrobots/keep/actions/runs/37168090008) completed successfully; [raw results and bounded comparison](pr-landing-evidence/94/README.md) preserve all timing increases and equal allocation measures. [Independent receipt approval](https://github.com/flyingrobots/keep/pull/94#issuecomment-5975495566) verifies artifact provenance, exact source trees, every comparison row and bounded claims; it finds no receipt defect and closes the benchmark evidence gap without changing the product head. #179's separate policy decision and #179/#102 landing remain prerequisites. | +| #93 | Integrated capability candidate pushed; full local validation passed | Candidate `44c736c251ad121f69f217452540c98fa989cb33`, tree `f5faff4dfa253c4e8e6b704ddcab9463e4dfddb3`, combines original cap-std upgrade with #102 in `f50666f`; adjacent-pin conflict preserves cap-std 4.0.3/Rustix 1.1.5. [Code Lawyer findings](https://github.com/flyingrobots/keep/pull/93#issuecomment-5975345761) address the separate fuzz graph, admission and license-comment coordinate. Full exact-tree copied-Docker validation and pinned Markdown pass; initial expired documentation container ran no test and is retained as setup evidence. [Independent source review](https://github.com/flyingrobots/keep/pull/93#issuecomment-5975421287) found no new implementation defect and preserves the separate policy/prerequisite gates; all four final [hosted jobs](https://github.com/flyingrobots/keep/actions/runs/37167906610) pass. #179/#102 are landing prerequisites; #94 is not a correctness prerequisite. | + +The separate duplicate-record/incomplete-tail defect #173 remains unresolved. Landing #172 corrects observed partial-seal fixed framing; it does not certify all recovery invariants or reopen #99's approved incomplete-retention-stage disposition deferral (#155). The broader completed-task audit remains unfinished. + +## Original #107 review queue and remaining acceptance + +The original queue contained eight unresolved inline threads, one changes-requested review body and two top-level comments. All eight original inline findings are now resolved with the evidence below. The latest complete paginated pre-closure refresh retained 17 discussion comments, nine review bodies and eight threads; later closure comments add evidence without erasing that history. Independent delta review found one remaining overstatement in the retention requirements evidence cell, corrected in `7cdc2cf`. CodeRabbit status, skipped incremental reviews and hosted Codex quota responses are not full acceptance. Original scope, complete review-body obligations and current-main integration remain open; thread resolution is not whole-PR approval. + +| Obligation | Current evidence and disposition | Exit condition | +| --- | --- | --- | +| Canonical GC fuzz relation, [thread 4146802713](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802713) | Implemented in `fb9f129`, including the same defect in the disposition selector. Runtime negative controls and restored checks pass. [Independent approval](https://github.com/flyingrobots/keep/pull/107#issuecomment-5975649040) verifies successor `05b804b`, original receipt preservation and current whitespace success. | Closed: full review published and thread resolved against the pushed successor; no whole-PR approval implied. | +| GC fixture provenance, [thread 4146802698](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802698) | Corrected in `65c0707`: historical unverified 1.98 entry and missing Cargo hash remain explicit; pinned 1.96 reconstruction, full tool commits, fixture hashes and external b3sum commands/results support current unchanged bytes. Raw receipts are in `docs/testing-evidence/gc-fixture-provenance/`. | Closed: [independent review](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976122184) recomputes all six displayed GC/profile/definition hashes and approves exact successor `f00e780`; thread resolved. | +| Reader-lock coordinate types, [thread 4146802719](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802719) | Implemented in `b1eaa59`: distinct device, mount and file roles, all observation/codec callers adapted. Static/API controls and separate runtime preservation evidence are recorded in `docs/testing-evidence/reader-lock-coordinates.md`. Independent review found an archive-replay defect; `7af834a` corrects it with direct extracted-project evidence and `9a5fb8f` fixes receipt spacing. | Closed: [exact-successor scoped APPROVE](https://github.com/flyingrobots/keep/pull/107#issuecomment-5975921727), [activity and limits](https://github.com/flyingrobots/keep/pull/107#issuecomment-5975922095), and resolved thread. No source/API defect remained; whole-PR integration, validation and policy gates remain separate. | +| Receipt encoder layout, [thread 4146802728](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802728) | `f00e780` binds each emitted array width and their aggregate to the fixed record at compile time; iterator writes replace the panicking slices. No admitted input supplied a width, so the proposed allocating/fallible API is declined with a source-supported fixed-array proof. | Closed: four static controls, generated public byte equality, runtime corruption/restoration and reduced witness are recorded in `docs/testing-evidence/receipt-layout.md`; [independent exact-head approval](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976122184) verifies the proof and evidence. Thread resolved; full integration and policy gates remain. | +| Opaque intent coordinates, [thread 4146802740](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802740) | `a62bfb8` adds public decoder laws for retained manifest/catalog/proof/pool/disposition, reader-lock and candidate coordinates and distinct intent identity; `5b533b0` corrects the universal-refusal claim and `4158001` links the evidence from KEEP-GC-001. | Closed: runtime mutation controls, restored debug/release GREEN and [exact-successor independent approval](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976316751); original thread resolved. | +| Exact GC refusals, [thread 4146802752](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802752) | `5b533b0` pins generation/profile causes, observed magic, receipt mount/file values and both digest mismatch coordinates. Expected values come from the public contract and frozen input fixtures. | Closed: distinct wrong-diagnostic controls fail the named public assertions; restored focused validation and [independent approval](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976316751) pass; thread resolved. | +| Head mutation resealing terminology, [thread 4146802756](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802756) | `6a84324` replaces the private boolean with named checksum/no-seal alternatives. It changes neither mutation input nor expected outcome and is not classified as a public API or product defect. | Closed: focused head laws pass in debug/release and [independent review](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976316751) confirms the unchanged behavior; thread resolved. | +| Exact retention refusals, [thread 4146802763](https://github.com/flyingrobots/keep/pull/107#discussion_r4146802763) | `b5ecd97` pins profile, closure-resource, generation and manifest-length diagnostics. The separate [P4 evidence overstatement](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976286720) is corrected in `7cdc2cf` without expanding the field campaign. | Closed: targeted runtime controls, restored debug/release GREEN, focused static gates and [exact-successor approval](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976316751); thread resolved. Consolidated evidence retains failed attempts and the still-open execution-profile policy gate. | +| Out-of-diff restart-identity statement | Current `docs/formats/segment-store-v2/README.md:106-108` already names restart-stable device/inode, matching the intended reopen contract. The review body's historical line reference is no longer current. | Verify the integrated production path retains that rule and explicitly reconcile the review-body finding; it is not an inline thread to resolve. | +| Top-level scope and completion claims | The original description claims completed M4 work and old numeric evidence; many surfaces now overlap newer merged corrections. The docstring percentage is optional provider policy, not repository acceptance. | Reconcile the remaining deliverables and dependencies with actual integrated source and current evidence, then rewrite the description; no wholesale acceptance or silent scope deletion. | + +## #107 integration closure ledger + +The active integration combines exact PR head `7cdc2cfbef59407f3c38881b39a290cb85501f9b` with main `3165890e9291cfb5fe10e81a9d7cd151f3e59464`. The work is preserved in an unfinished local merge; the pushed PR remains at `7cdc2cf`. No integrated candidate commit or merge approval exists yet. The [focused integration checkpoint](pr-landing-evidence/107-integration/README.md) records actual parent RED and copied-Docker debug/release evidence; it is not final acceptance. The original eight inline closures above remain scoped and valid; the following obligations concern the combined behavior and independently identified defects. + +| Obligation and invariant | Current evidence and disposition | Concrete exit condition | +| --- | --- | --- | +| Durable reads preserve truthful absence and authenticated domain ownership | Local source retains main's fallible locator and snapshot lookup, shared read core, full retention coordinates and bounded-memory documentation. The new content-read port propagates lookup failure instead of converting it to absence. Integrated durable read, ingestion, transfer, port and reader-fence laws now pass in debug/release; original transfer/staging features remain in scope. Full final acceptance remains open. | Integrated compile and reference/durable port, read, transfer and error-source laws pass without weakening main's exact typed refusals. | +| Recovery retains observed source identity, complete preflight and effect accounting | Local source retains main's exact-record, retained-stage, snapshot, incomplete-stage refusal and recovery error contracts. New GC/disposition callers now retain opened stage observations and pass their original identity when reopening. Existing GC interrupted-prefix laws pass in both profiles; complete effect propagation and direct caller substitution coverage remain open. | Direct/publication-triggered incomplete stages remain preserved; complete stages recover; substitution and post-effect synchronization failures retain precise causes, effects and evidence. Existing regression suites plus focused new caller regressions pass. | +| Migration remains admitted and restart-safe | Local source selects main's current/complete recovery gates, namespace preflight, linked-record identity checks, internal-only resumption and calibrated restart laws. Narrow digest exports remain available to new GC consumers. The completed-v2 namespace retains the PR's owned GC/disposition vocabulary with typed kind checks. These edits are not runtime validation. | Final extended definition and immutable fixture identities agree; migration prefix/restart and completed-namespace laws pass without reopening public resumption or admitting downstream residue during incomplete migration. | +| Verification claims remain subject-specific and provenance-bound | Main's Eq-only depths, exact supported sets, subjects, report provenance and typed source errors are retained locally. Reference verification now uses admitted operation context and a checked frozen-v1 projection. Exact supported-set and frozen-byte laws pass; arbitrary durable stamping is refused. [Published source finding](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976512518) identifies caller-selected receipt provenance; the parent probe fails both intended assertions and integrated projection regressions pass in debug/release. Whole-PR review remains pending. | Adapt reference verification through admitted operation evidence and checked v1 projection; reject mismatched provenance and unrepresentable subjects/depths/sets. Preserve main laws and all frozen receipt bytes with runtime regressions. | +| GC/compaction proof and mutation refer to the same authority | [P1 source finding](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976373285) confirms GC observes a separate pathname while unlinking through admission. The parallel compaction path has the same independent observation locator. Both public different-store regressions fail on the parent and pass after capability-bound observation in debug/release. Nested-directory binding and final independent review remain open; this is not a claim of arbitrary concurrent namespace isolation. | Deterministic different-store regression fails on the unfixed code, passes with capability-bound proof/observation/mutation, and retains identity and namespace checks. | +| Compaction recovery preflights before effects and preserves typed failure | [Source findings](https://github.com/flyingrobots/keep/pull/107#issuecomment-5976512518) identify early stage deletion before later head inspection, arbitrary current-catalog errors treated as absence, unbounded rereads and missing observed-identity binding in derivable-stage cleanup. Open blockers. | Contradictory later-stage, corrupt-head, size-limit and byte-identical substitution regressions establish precise non-success outcomes and preserved evidence. Post-effect failures accurately report their effects; restart laws pass. | +| Original GC, migration and fuzz coverage survives integration | Crash routing, transition-ledger and documentation conflicts remain. Main's semantic posture checks and calibrated emitted-input regression must coexist with PR GC boundaries and format grammar; suite cardinality is not runtime evidence. | Reconcile semantic routes and immutable identity fixtures; run the required stable-candidate debug/release, crash and fuzz validation with original acceptance scope intact. | +| Policy, full discussion and exact-head acceptance remain explicit | Independent migration, retention/GC and verification reviews are preparatory read-only findings, not integrated approval. Initial copied-Docker compilation failures are preserved; the library and unit executable now build, and library/test Clippy with all features passes. Full workspace tooling still has merge conflicts. #106's explicitly approved waiver expires 2026-10-17 and applies only to that dependency update; it does not cover #107 or #179. | Close this finite queue, reconcile all review bodies/discussion and current docs, obtain required test-resource policy disposition and exact-candidate independent approval, and verify required checks on the final pushed SHA before merging. | + +Initial compiler failures and overlay-filesystem setup failures are preserved as diagnostic evidence, not runtime RED. The checkpoint distinguishes those attempts from real parent regressions and subsequent focused runtime passes. The merge still has unresolved documentation and tooling files, so its implementation cannot yet be committed without completing resolution and required checks; no hook has been bypassed. The clean audit branch records this checkpoint separately so the uncommitted integration is neither lost nor represented as landed work. + +## Validation boundaries + +The fresh #172 focused run used the existing clean copied Docker tree whose tracked tree hash `af00023bb50da6b5f390fc8f2e4b070bf15ceb52` equals the candidate's tree. Its synthetic copy commit differs from the source commit; tree identity was checked before execution. An initial command named a nonexistent test target and ran no tests; that setup failure is retained separately and is not runtime RED. The corrected command executed the intended named laws in both profiles and returned success. + +The complete prior local validation and exact-head hosted run `37097418652` remain attributable to the same unchanged source. The fresh focused run supplements those results; it does not claim another full crash/fuzz campaign, physical power-loss evidence, or universally enforced test resource isolation. The landing review also distinguishes CodeRabbit's optional docstring percentage warning from repository-required public documentation and successful documentation CI. + +The audit branch's run 37163865768 failed before documentation tests because Cargo's shlex download encountered an HTTP/2 framing error; its other three jobs passed. This transport failure is preserved and is not attributed to the accepted product candidates. + +Mainline reliability issue #178 owns the newly observed durable-layout writer contention. The fork/exec inheritance schedule is a hypothesis drawn from current fixture handoffs and earlier #174 evidence, not a demonstrated cause of this failure. No retry-to-green, assertion suppression or further merge is justified before disposition. diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-debug-2.txt b/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-debug-2.txt new file mode 100644 index 00000000..82f7238d --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-debug-2.txt @@ -0,0 +1,58 @@ + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.02s + Running unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) + +running 1 test +test reference::verification::tests::tampered_stored_chunk_is_corrupt_at_the_chunk_identity_stage ... ok + +test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 473 filtered out; finished in 0.00s + + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) + +running 17 tests +test adapters::durable::ingestion_bound_tests::a_grown_sealed_stage_refuses_before_payload_allocation_or_publication ... ok +test adapters::durable::refusal_source_tests::a_non_regular_selected_root_keeps_the_exact_record_refusal ... ok +test adapters::durable::writer_tests::limit_and_identity_refusals_leave_nothing_visible ... ok +test adapters::durable::refusal_source_tests::a_corrupt_retained_root_keeps_its_typed_cause_through_durable_admission ... ok +test adapters::durable::tests::absence_is_evidence_against_the_pinned_view ... ok +test adapters::durable::tests::a_failing_writer_returns_no_receipt_and_the_exact_accepted_prefix ... ok +test adapters::durable::tests::identical_views_yield_identical_receipts_across_reopen ... ok +test adapters::durable::tests::a_pinned_snapshot_keeps_its_view_beside_a_successor_and_blocks_collection ... ok +test adapters::durable::writer_tests::an_interrupted_source_leaves_a_stage_that_recovery_discards ... ok +test adapters::durable::transfer_tests::a_reference_store_copies_into_a_durable_writer ... ok +test adapters::durable::writer_tests::one_pass_commits_a_blob_readable_by_layout_then_by_anchor ... ok +test adapters::durable::writer_tests::an_anchored_ingest_satisfies_the_port_laws_beside_the_fixture_store ... ok +test adapters::durable::tests::ranges_across_chunk_boundaries_emit_exactly_the_requested_bytes ... ok +test adapters::durable::transfer_tests::a_durable_snapshot_copies_into_a_reference_store_and_transfers_to_a_sink ... ok +test adapters::durable::tests::every_anchored_blob_reconstructs_exactly_with_a_receipt_naming_the_view ... ok +test adapters::durable::port_tests::durable_backend_satisfies_the_read_laws_through_the_port ... ok +test adapters::durable::writer_tests::nearby_content_reuses_every_unchanged_chunk_and_an_exact_re_ingest_publishes_nothing ... ok + +test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 457 filtered out; finished in 1.56s + + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) + +running 9 tests +test adapters::gc::filesystem_gc_tests::admission_refuses_a_foreign_gc_entry_or_a_directory_in_place_of_a_record ... ok +test adapters::gc::filesystem_gc_tests::nothing_to_retire_and_a_stale_plan_refuse_before_any_intent ... ok +test adapters::gc::filesystem_gc_tests::an_absent_candidate_after_a_present_one_is_ambiguous_and_touches_nothing ... ok +test adapters::gc::filesystem_gc_tests::a_reader_holding_the_fence_refuses_retirement_without_waiting ... ok +test adapters::gc::filesystem_gc_tests::retiring_the_disposed_orphan_leaves_the_receipt_and_the_live_segment ... ok +test adapters::gc::filesystem_gc_tests::a_durable_intent_excludes_retention_publication_and_another_retirement ... ok +test adapters::gc::filesystem_gc_tests::a_second_retirement_succeeds_the_first_receipts_generation ... ok +test adapters::gc::filesystem_gc_tests::a_truncated_stage_is_discarded_and_the_retirement_then_completes ... ok +test adapters::gc::filesystem_gc_tests::every_interrupted_prefix_recovers_to_the_same_complete_state ... ok + +test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 465 filtered out; finished in 2.07s + + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) + +running 4 tests +test adapters::compaction::filesystem_tests::recovery_over_an_untouched_store_is_idle ... ok +test adapters::compaction::filesystem_tests::a_mixed_segment_plans_its_live_records_for_copy_and_the_rest_for_omission ... ok +test adapters::compaction::filesystem_tests::compaction_preserves_every_identity_and_closure_and_frees_the_mixed_segment ... ok +test adapters::compaction::filesystem_tests::refusals_happen_before_any_stage_is_written ... ok + +test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 470 filtered out; finished in 0.32s diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-debug.txt b/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-debug.txt new file mode 100644 index 00000000..ba2914b3 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-debug.txt @@ -0,0 +1,103 @@ + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) + +running 1 test +test reference::verification::tests::tampered_stored_chunk_is_corrupt_at_the_chunk_identity_stage ... ok + +test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 473 filtered out; finished in 0.00s + + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) + +running 17 tests +test adapters::durable::ingestion_bound_tests::a_grown_sealed_stage_refuses_before_payload_allocation_or_publication ... ok +test adapters::durable::refusal_source_tests::a_corrupt_retained_root_keeps_its_typed_cause_through_durable_admission ... FAILED +test adapters::durable::refusal_source_tests::a_non_regular_selected_root_keeps_the_exact_record_refusal ... FAILED +test adapters::durable::writer_tests::limit_and_identity_refusals_leave_nothing_visible ... FAILED +test adapters::durable::tests::a_failing_writer_returns_no_receipt_and_the_exact_accepted_prefix ... FAILED +test adapters::durable::tests::a_pinned_snapshot_keeps_its_view_beside_a_successor_and_blocks_collection ... FAILED +test adapters::durable::tests::absence_is_evidence_against_the_pinned_view ... FAILED +test adapters::durable::tests::identical_views_yield_identical_receipts_across_reopen ... FAILED +test adapters::durable::writer_tests::one_pass_commits_a_blob_readable_by_layout_then_by_anchor ... FAILED +test adapters::durable::transfer_tests::a_reference_store_copies_into_a_durable_writer ... FAILED +test adapters::durable::writer_tests::an_anchored_ingest_satisfies_the_port_laws_beside_the_fixture_store ... FAILED +test adapters::durable::writer_tests::an_interrupted_source_leaves_a_stage_that_recovery_discards ... ok +test adapters::durable::port_tests::durable_backend_satisfies_the_read_laws_through_the_port ... FAILED +test adapters::durable::tests::ranges_across_chunk_boundaries_emit_exactly_the_requested_bytes ... FAILED +test adapters::durable::tests::every_anchored_blob_reconstructs_exactly_with_a_receipt_naming_the_view ... FAILED +test adapters::durable::transfer_tests::a_durable_snapshot_copies_into_a_reference_store_and_transfers_to_a_sink ... FAILED +test adapters::durable::writer_tests::nearby_content_reuses_every_unchanged_chunk_and_an_exact_re_ingest_publishes_nothing ... FAILED + +failures: + +---- adapters::durable::refusal_source_tests::a_corrupt_retained_root_keeps_its_typed_cause_through_durable_admission stdout ---- + +thread 'adapters::durable::refusal_source_tests::a_corrupt_retained_root_keeps_its_typed_cause_through_durable_admission' (1389) panicked at src/adapters/durable/refusal_source_tests.rs:33:5: +assertion failed: matches!(&error, DurableStoreError::Snapshot(source) if + matches!(source.as_ref(), crate::FilesystemRetentionSnapshotError::Root + { .. })) +note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace + +---- adapters::durable::refusal_source_tests::a_non_regular_selected_root_keeps_the_exact_record_refusal stdout ---- +Error: Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } } + +---- adapters::durable::writer_tests::limit_and_identity_refusals_leave_nothing_visible stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::tests::a_failing_writer_returns_no_receipt_and_the_exact_accepted_prefix stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::tests::a_pinned_snapshot_keeps_its_view_beside_a_successor_and_blocks_collection stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::tests::absence_is_evidence_against_the_pinned_view stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::tests::identical_views_yield_identical_receipts_across_reopen stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::writer_tests::one_pass_commits_a_blob_readable_by_layout_then_by_anchor stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::transfer_tests::a_reference_store_copies_into_a_durable_writer stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::writer_tests::an_anchored_ingest_satisfies_the_port_laws_beside_the_fixture_store stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::port_tests::durable_backend_satisfies_the_read_laws_through_the_port stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::tests::ranges_across_chunk_boundaries_emit_exactly_the_requested_bytes stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::tests::every_anchored_blob_reconstructs_exactly_with_a_receipt_naming_the_view stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::transfer_tests::a_durable_snapshot_copies_into_a_reference_store_and_transfers_to_a_sink stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + +---- adapters::durable::writer_tests::nearby_content_reuses_every_unchanged_chunk_and_an_exact_re_ingest_publishes_nothing stdout ---- +Error: Snapshot(Admission { source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } }) + + +failures: + adapters::durable::port_tests::durable_backend_satisfies_the_read_laws_through_the_port + adapters::durable::refusal_source_tests::a_corrupt_retained_root_keeps_its_typed_cause_through_durable_admission + adapters::durable::refusal_source_tests::a_non_regular_selected_root_keeps_the_exact_record_refusal + adapters::durable::tests::a_failing_writer_returns_no_receipt_and_the_exact_accepted_prefix + adapters::durable::tests::a_pinned_snapshot_keeps_its_view_beside_a_successor_and_blocks_collection + adapters::durable::tests::absence_is_evidence_against_the_pinned_view + adapters::durable::tests::every_anchored_blob_reconstructs_exactly_with_a_receipt_naming_the_view + adapters::durable::tests::identical_views_yield_identical_receipts_across_reopen + adapters::durable::tests::ranges_across_chunk_boundaries_emit_exactly_the_requested_bytes + adapters::durable::transfer_tests::a_durable_snapshot_copies_into_a_reference_store_and_transfers_to_a_sink + adapters::durable::transfer_tests::a_reference_store_copies_into_a_durable_writer + adapters::durable::writer_tests::an_anchored_ingest_satisfies_the_port_laws_beside_the_fixture_store + adapters::durable::writer_tests::limit_and_identity_refusals_leave_nothing_visible + adapters::durable::writer_tests::nearby_content_reuses_every_unchanged_chunk_and_an_exact_re_ingest_publishes_nothing + adapters::durable::writer_tests::one_pass_commits_a_blob_readable_by_layout_then_by_anchor + +test result: FAILED. 2 passed; 15 failed; 0 ignored; 0 measured; 457 filtered out; finished in 1.08s + +error: test failed, to rerun pass `--lib` diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-release.txt b/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-release.txt new file mode 100644 index 00000000..30e01660 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integrated-runtime-release.txt @@ -0,0 +1,118 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `release` profile [optimized] target(s) in 5.40s + Running unittests src/lib.rs (/build/keep107-coordinate-target/release/deps/keep-8ca1b588e6dfe3ea) + +running 1 test +test reference::verification::tests::tampered_stored_chunk_is_corrupt_at_the_chunk_identity_stage ... ok + +test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 473 filtered out; finished in 0.00s + + Finished `release` profile [optimized] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/release/deps/keep-8ca1b588e6dfe3ea) + +running 17 tests +test adapters::durable::ingestion_bound_tests::a_grown_sealed_stage_refuses_before_payload_allocation_or_publication ... ok +test adapters::durable::writer_tests::limit_and_identity_refusals_leave_nothing_visible ... ok +test adapters::durable::writer_tests::an_interrupted_source_leaves_a_stage_that_recovery_discards ... ok +test adapters::durable::refusal_source_tests::a_non_regular_selected_root_keeps_the_exact_record_refusal ... ok +test adapters::durable::writer_tests::one_pass_commits_a_blob_readable_by_layout_then_by_anchor ... ok +test adapters::durable::refusal_source_tests::a_corrupt_retained_root_keeps_its_typed_cause_through_durable_admission ... ok +test adapters::durable::transfer_tests::a_reference_store_copies_into_a_durable_writer ... ok +test adapters::durable::tests::absence_is_evidence_against_the_pinned_view ... ok +test adapters::durable::tests::a_failing_writer_returns_no_receipt_and_the_exact_accepted_prefix ... ok +test adapters::durable::tests::identical_views_yield_identical_receipts_across_reopen ... ok +test adapters::durable::tests::ranges_across_chunk_boundaries_emit_exactly_the_requested_bytes ... ok +test adapters::durable::tests::every_anchored_blob_reconstructs_exactly_with_a_receipt_naming_the_view ... ok +test adapters::durable::transfer_tests::a_durable_snapshot_copies_into_a_reference_store_and_transfers_to_a_sink ... ok +test adapters::durable::writer_tests::nearby_content_reuses_every_unchanged_chunk_and_an_exact_re_ingest_publishes_nothing ... ok +test adapters::durable::port_tests::durable_backend_satisfies_the_read_laws_through_the_port ... ok +test adapters::durable::writer_tests::an_anchored_ingest_satisfies_the_port_laws_beside_the_fixture_store ... ok +test adapters::durable::tests::a_pinned_snapshot_keeps_its_view_beside_a_successor_and_blocks_collection ... ok + +test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 457 filtered out; finished in 0.47s + + Finished `release` profile [optimized] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/release/deps/keep-8ca1b588e6dfe3ea) + +running 9 tests +test adapters::gc::filesystem_gc_tests::admission_refuses_a_foreign_gc_entry_or_a_directory_in_place_of_a_record ... ok +test adapters::gc::filesystem_gc_tests::nothing_to_retire_and_a_stale_plan_refuse_before_any_intent ... ok +test adapters::gc::filesystem_gc_tests::an_absent_candidate_after_a_present_one_is_ambiguous_and_touches_nothing ... ok +test adapters::gc::filesystem_gc_tests::a_reader_holding_the_fence_refuses_retirement_without_waiting ... ok +test adapters::gc::filesystem_gc_tests::retiring_the_disposed_orphan_leaves_the_receipt_and_the_live_segment ... ok +test adapters::gc::filesystem_gc_tests::a_durable_intent_excludes_retention_publication_and_another_retirement ... ok +test adapters::gc::filesystem_gc_tests::a_second_retirement_succeeds_the_first_receipts_generation ... ok +test adapters::gc::filesystem_gc_tests::a_truncated_stage_is_discarded_and_the_retirement_then_completes ... ok +test adapters::gc::filesystem_gc_tests::every_interrupted_prefix_recovers_to_the_same_complete_state ... ok + +test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 465 filtered out; finished in 1.53s + + Finished `release` profile [optimized] target(s) in 0.01s + Running unittests src/lib.rs (/build/keep107-coordinate-target/release/deps/keep-8ca1b588e6dfe3ea) + +running 4 tests +test adapters::compaction::filesystem_tests::recovery_over_an_untouched_store_is_idle ... ok +test adapters::compaction::filesystem_tests::a_mixed_segment_plans_its_live_records_for_copy_and_the_rest_for_omission ... ok +test adapters::compaction::filesystem_tests::compaction_preserves_every_identity_and_closure_and_frees_the_mixed_segment ... ok +test adapters::compaction::filesystem_tests::refusals_happen_before_any_stage_is_written ... ok + +test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 470 filtered out; finished in 0.15s + + Checking keep v0.0.0 (/build/keep107-integration-round2) +error: this argument (320 byte) is passed by value, but might be more efficient if passed by reference (limit: 256 byte) + --> tests/segment_verification/record_laws.rs:94:13 + | +94 | report: VerificationReport, + | ^^^^^^^^^^^^^^^^^^ help: consider passing by reference instead: `&VerificationReport` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#large_types_passed_by_value + = note: requested on the command line with `-D clippy::large-types-passed-by-value` + +error[E0369]: binary operation `<` cannot be applied to type `keep::VerificationDepth` + --> tests/segment_store_mutations.rs:151:40 + | +151 | assert!(VerificationDepth::Framing < VerificationDepth::Checksum); + | -------------------------- ^ --------------------------- keep::VerificationDepth + | | + | keep::VerificationDepth + | +note: `keep::VerificationDepth` does not implement `std::cmp::PartialOrd` + --> src/verification/depth.rs:18:1 + | + 18 | pub enum VerificationDepth { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ `keep::VerificationDepth` is defined in another crate + +error[E0369]: binary operation `<` cannot be applied to type `keep::VerificationDepth` + --> tests/segment_store_mutations.rs:152:41 + | +152 | assert!(VerificationDepth::Checksum < VerificationDepth::ChunkIdentity); + | --------------------------- ^ -------------------------------- keep::VerificationDepth + | | + | keep::VerificationDepth + | +note: `keep::VerificationDepth` does not implement `std::cmp::PartialOrd` + --> src/verification/depth.rs:18:1 + | + 18 | pub enum VerificationDepth { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ `keep::VerificationDepth` is defined in another crate + +error: could not compile `keep` (test "segment_verification") due to 1 previous error +warning: build failed, waiting for other jobs to finish... +For more information about this error, try `rustc --explain E0369`. +error: could not compile `keep` (test "segment_store_mutations") due to 2 previous errors +error: item in documentation is missing backticks + --> tests/verification_receipt.rs:308:72 + | +308 | /// Size: small. Oracle: v1 registers exactly depth codes 1 through 7; SnapshotBinding has no slot. + | ^^^^^^^^^^^^^^^ + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#doc_markdown + = note: `-D clippy::doc-markdown` implied by `-D clippy::pedantic` + = help: to override `-D clippy::pedantic` add `#[allow(clippy::doc_markdown)]` +help: try + | +308 - /// Size: small. Oracle: v1 registers exactly depth codes 1 through 7; SnapshotBinding has no slot. +308 + /// Size: small. Oracle: v1 registers exactly depth codes 1 through 7; `SnapshotBinding` has no slot. + | + +error: could not compile `keep` (test "verification_receipt") due to 1 previous error diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-2.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-2.txt new file mode 100644 index 00000000..9b5a27a8 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-2.txt @@ -0,0 +1,82 @@ + Checking keep v0.0.0 (/build/keep107-integration-round2) +error: couldn't read `tests/../src/reference/chunk_reader.rs`: No such file or directory (os error 2) + --> tests/transfer_port_architecture.rs:6:9 + | +6 | include_str!("../src/reference/chunk_reader.rs"), + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +error: pub(crate) struct inside private module + --> tests/golden_file_worldline/durable_fixture.rs:32:1 + | +32 | pub(super) struct Identified { + | ----------^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + = note: `-D clippy::redundant-pub-crate` implied by `-D clippy::nursery` + = help: to override `-D clippy::nursery` add `#[allow(clippy::redundant_pub_crate)]` + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:38:1 + | +38 | pub(super) fn identify(bytes: &[u8]) -> TestResult { + | ----------^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:59:1 + | +59 | pub(super) fn policy() -> TestResult { + | ----------^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:66:1 + | +66 | pub(super) fn build(name: &str, contents: &[&[u8]]) -> TestResult { + | ----------^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:78:1 + | +78 | pub(super) fn build_missing_chunk(name: &str, content: &[u8]) -> TestResult { + | ----------^^^^^^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:86:1 + | +86 | pub(super) fn build_selected_chunk( + | ----------^^^^^^^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: could not compile `keep` (test "transfer_port_architecture") due to 1 previous error +warning: build failed, waiting for other jobs to finish... +error: pub(crate) struct inside private module + --> tests/segment_filesystem_stage/sandbox.rs:8:1 + | +8 | pub(super) struct TestDirectory { + | ----------^^^^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: could not compile `keep` (test "gc_authority_root") due to 7 previous errors diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-3.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-3.txt new file mode 100644 index 00000000..cf71c3a7 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-3.txt @@ -0,0 +1,75 @@ + Checking keep v0.0.0 (/build/keep107-integration-round2) +error: pub(crate) struct inside private module + --> tests/golden_file_worldline/durable_fixture.rs:32:1 + | +32 | pub(super) struct Identified { + | ----------^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + = note: `-D clippy::redundant-pub-crate` implied by `-D clippy::nursery` + = help: to override `-D clippy::nursery` add `#[allow(clippy::redundant_pub_crate)]` + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:38:1 + | +38 | pub(super) fn identify(bytes: &[u8]) -> TestResult { + | ----------^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:59:1 + | +59 | pub(super) fn policy() -> TestResult { + | ----------^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:66:1 + | +66 | pub(super) fn build(name: &str, contents: &[&[u8]]) -> TestResult { + | ----------^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:78:1 + | +78 | pub(super) fn build_missing_chunk(name: &str, content: &[u8]) -> TestResult { + | ----------^^^^^^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) function inside private module + --> tests/golden_file_worldline/durable_fixture.rs:86:1 + | +86 | pub(super) fn build_selected_chunk( + | ----------^^^^^^^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: pub(crate) struct inside private module + --> tests/segment_filesystem_stage/sandbox.rs:8:1 + | +8 | pub(super) struct TestDirectory { + | ----------^^^^^^^^^^^^^^^^^^^^^ + | | + | help: consider using: `pub` + | + = help: for further information visit https://rust-lang.github.io/rust-clippy/rust-1.96.0/index.html#redundant_pub_crate + +error: could not compile `keep` (test "gc_authority_root") due to 7 previous errors +warning: build failed, waiting for other jobs to finish... diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-4.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-4.txt new file mode 100644 index 00000000..4d0d3a2c --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-clippy-tests-4.txt @@ -0,0 +1,23 @@ + Checking keep v0.0.0 (/build/keep107-integration-round2) + Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.08s + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `test` profile [unoptimized + debuginfo] target(s) in 2.39s + Running tests/segment_store_mutations.rs (/build/keep107-coordinate-target/debug/deps/segment_store_mutations-8c770183f2ee95e0) + +running 2 tests +test every_durable_record_has_a_ledger_and_every_row_cites_a_requirement ... ok +test every_frozen_mutation_reaches_its_exact_first_refusal ... ok + +test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s + + Running tests/segment_verification.rs (/build/keep107-coordinate-target/debug/deps/segment_verification-dc611717318782ba) + +running 6 tests +test record_laws::reporting_logical_record_evidence_allocates_no_heap_memory ... ok +test record_laws::a_layout_prepared_without_its_chunks_cannot_report_complete_blob_verification ... ok +test physical_segment_reports_refuse_logical_or_store_claims ... ok +test reporting_segment_evidence_allocates_no_heap_memory ... ok +test record_laws::admitted_record_reports_preserve_each_logical_subjects_exact_proof_scope ... ok +test segment_reports_bind_only_supported_evidence_to_the_exact_physical_bytes ... ok + +test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-focused-debug.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-focused-debug.txt new file mode 100644 index 00000000..fc15dafc --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-focused-debug.txt @@ -0,0 +1,104 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `test` profile [unoptimized + debuginfo] target(s) in 2.52s + Running tests/blob_verification.rs (/build/keep107-coordinate-target/debug/deps/blob_verification-b7fe4f140a2a8b59) + +running 12 tests +test root_laws::shallow_root_reports_do_not_claim_an_unconsulted_catalog ... ok +test refusal_laws::incomplete_blob_refuses_the_exact_missing_chunk ... ok +test root_laws::a_closure_budget_failure_is_operational_with_its_original_limit ... ok +test refusal_laws::complete_blob_verification_preserves_expected_and_observed_identities ... ok +test shallow_blob_evidence_does_not_require_unclaimed_chunk_closure ... ok +test refusal_laws::an_absent_blob_is_not_reported_as_corruption ... ok +test blob_reports_certify_only_the_requested_evidence_in_one_catalog ... ok +test refusal_laws::blob_verification_refuses_unrelated_depths_before_discovery ... ok +test root_laws::a_root_report_requires_complete_closure_in_its_named_catalog ... ok +test root_laws::root_reports_refuse_unrelated_depths ... ok +test root_laws::canonical_root_bytes_do_not_certify_an_absent_layout ... ok +test profile_law::correct_blob_bytes_do_not_certify_false_profile_boundaries ... ok + +test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s + + Running tests/catalog_verification.rs (/build/keep107-coordinate-target/debug/deps/catalog_verification-fd525b3070a6e0c7) + +running 4 tests +test reporting_catalog_evidence_requires_no_additional_allocation ... ok +test catalog_reports_bind_the_requested_evidence_to_the_selected_generation ... ok +test catalog_requests_outside_its_evidence_refuse_without_downgrading ... ok +test catalog_reachability_does_not_certify_an_incomplete_blob ... ok + +test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + + Running tests/catalog_verification_ceiling.rs (/build/keep107-coordinate-target/debug/deps/catalog_verification_ceiling-de60a4108b87b22f) + +running 1 test +test the_catalog_entry_ceiling_verifies_within_its_declared_memory_bound ... ok + +test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 42.27s + + +running 4 tests +test an_expected_identity_that_does_not_match_refuses_with_both ... ok + Running tests/content_store_port.rs (/build/keep107-coordinate-target/debug/deps/content_store_port-684d307c7de48177) +test staging_refuses_the_entry_limit_through_the_port ... ok +test staging_refuses_the_byte_limit_before_anything_is_visible ... ok +test the_reference_backend_round_trips_through_the_port ... ok + +test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s + + Running tests/gc_authority_root.rs (/build/keep107-coordinate-target/debug/deps/gc_authority_root-63af85d2401e170e) + +running 2 tests +test gc_refuses_an_observation_locator_for_another_store ... ok +test compaction_refuses_an_observation_locator_for_another_store ... ok + +test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.17s + + Running tests/segment_verification.rs (/build/keep107-coordinate-target/debug/deps/segment_verification-dc611717318782ba) + +running 6 tests +test reporting_segment_evidence_allocates_no_heap_memory ... ok +test record_laws::reporting_logical_record_evidence_allocates_no_heap_memory ... ok +test physical_segment_reports_refuse_logical_or_store_claims ... ok +test segment_reports_bind_only_supported_evidence_to_the_exact_physical_bytes ... ok +test record_laws::admitted_record_reports_preserve_each_logical_subjects_exact_proof_scope ... ok +test record_laws::a_layout_prepared_without_its_chunks_cannot_report_complete_blob_verification ... ok + +test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + + Running tests/verification_ingress.rs (/build/keep107-coordinate-target/debug/deps/verification_ingress-739e54411aaaaf0c) + +running 4 tests +test segment_version_refusal_preserves_both_protocol_coordinates ... ok +test a_segment_policy_limit_remains_an_operational_failure ... ok +test segment_checksum_refusal_preserves_expected_and_observed_bytes ... ok +test raw_segment_reports_are_only_issued_after_complete_admission ... ok + +test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + + Running tests/verification_receipt.rs (/build/keep107-coordinate-target/debug/deps/verification_receipt-443fd900bf0a4d6d) + +running 10 tests +test a_refusal_never_decodes_as_a_report_and_a_report_never_as_a_refusal ... ok +test a_reference_refusal_cannot_be_relabeled_as_durable ... ok +test live_reference_verification_reproduces_the_frozen_report ... ok +test the_golden_report_and_refusals_state_exactly_their_frozen_coordinates ... ok +test golden_receipts_match_the_oracle_and_decode_from_another_process ... ok +test snapshot_binding_is_refused_instead_of_encoded_as_another_depth ... ok +test live_reference_refusal_reproduces_the_frozen_supported_interval ... ok +test a_reference_report_cannot_be_relabeled_as_durable ... ok +test every_reference_store_outcome_projects_and_round_trips ... ok +test every_structural_field_has_one_exact_first_refusal ... ok + +test result: ok. 10 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + + Running tests/verification_view.rs (/build/keep107-coordinate-target/debug/deps/verification_view-fa08b03b608dd88d) + +running 6 tests +test an_observation_failure_preserves_its_operational_cause ... ok +test changing_catalogs_discard_the_superseded_view ... ok +test retention_head_changes_are_not_hidden_by_a_stable_catalog ... ok +test exhausted_collection_reports_exact_conflicting_candidates ... ok +test malformed_publication_observations_preserve_the_decoder_contradiction ... ok +test no_published_catalog_is_missing_evidence ... ok + +test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-focused-release.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-focused-release.txt new file mode 100644 index 00000000..75a92e6e --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-focused-release.txt @@ -0,0 +1,36 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `release` profile [optimized] target(s) in 3.24s + Running tests/gc_authority_root.rs (/build/keep107-coordinate-target/release/deps/gc_authority_root-4629d17b0491d874) + +running 2 tests +test compaction_refuses_an_observation_locator_for_another_store ... ok +test gc_refuses_an_observation_locator_for_another_store ... ok + +test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.56s + + Running tests/verification_receipt.rs (/build/keep107-coordinate-target/release/deps/verification_receipt-88c876b73b3390ba) + +running 10 tests +test a_reference_refusal_cannot_be_relabeled_as_durable ... ok +test a_reference_report_cannot_be_relabeled_as_durable ... ok +test every_reference_store_outcome_projects_and_round_trips ... ok +test a_refusal_never_decodes_as_a_report_and_a_report_never_as_a_refusal ... ok +test golden_receipts_match_the_oracle_and_decode_from_another_process ... ok +test live_reference_refusal_reproduces_the_frozen_supported_interval ... ok +test snapshot_binding_is_refused_instead_of_encoded_as_another_depth ... ok +test every_structural_field_has_one_exact_first_refusal ... ok +test live_reference_verification_reproduces_the_frozen_report ... ok +test the_golden_report_and_refusals_state_exactly_their_frozen_coordinates ... ok + +test result: ok. 10 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + + Running tests/verification_report.rs (/build/keep107-coordinate-target/release/deps/verification_report-1a3ff18e8a176872) + +running 5 tests +test a_wrong_target_passes_chunk_identity_and_fails_only_the_complete_blob ... ok +test unsupported_depths_refuse_with_the_exact_supported_set ... ok +test absent_subjects_are_missing_evidence_against_the_complete_view ... ok +test a_report_establishes_exactly_the_requested_depth ... ok +test false_profile_boundaries_pass_chunk_identity_and_fail_only_the_complete_blob ... ok + +test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-source-sha256.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-source-sha256.txt new file mode 100644 index 00000000..570981e7 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-source-sha256.txt @@ -0,0 +1,1124 @@ +c6245cfc55d0a32eb82828deb0757c6cf114e0e46ca47a2a3104baf588b29f68 Cargo.lock +38e3e8fcfb5825818a45c2a8615f7ff87a3e0bfae04601453689a6ad932ca1ae Cargo.toml +bdc08c3be2420714de02ee83157e5084a32e2f43f2b064684994e750245f7782 rust-toolchain.toml +42d3ee9a4a2df4b05ed49ab77b22915da152c1980bd99ab8ae6ee7de537010ea src/adapters/admitted_catalog.rs +398a3d020b93112b94aae883bfe27f4af878938280158c12edbfc74e32bdc2cf src/adapters/admitted_recovery_stage_bytes.rs +d21d9e60ba545c1b3221f358d088bac5fb9721f00a8fcaabf80b207800400579 src/adapters/admitted_segment.rs +ea080891b2d6624f8b30bfe19e866bb3bb3f83e7b1742d70ad39a8b85e543f88 src/adapters/admitted_segment_record.rs +cfb64792523c657b82e889d6c3477bb2d104657a561ad9825980b7d1e559e3bc src/adapters/authenticated_read/mod.rs +ca6cd3d9fed73a3db2c197730f9b02a6738a08650c51e97800023388761edbc0 src/adapters/authenticated_read/profile_error_mapping.rs +1d3853b65a0e7c4d3e605c8e4cdb3ddbe7ba5254a021de3f12a88c0879faab07 src/adapters/authenticated_read/range_failure_mapping.rs +43281cbd1934468f30cc9a53147e44d66d3d933c303798310e619b3081eb5184 src/adapters/authenticated_read/range_read_error.rs +a55c7413253e62c4bb7dec485fb7a4ac5187a0a6ae696de53e863244da1bff1f src/adapters/authenticated_read/range_read_error_display.rs +141146433120bd2d86a39b4368942b170003629daf88116bc4cb3d1a29f5263f src/adapters/authenticated_read/range_read_error_mapping.rs +9049944ae18b640fc0519266bebf72f3dc925d059fa12ec50c65d2f6d47c0fe0 src/adapters/authenticated_read/reconstruction_error.rs +2adcfc845407633e32e468a80bfabbd9f98eca58411f89fe0d57517ce9259ad4 src/adapters/authenticated_read/reconstruction_error_display.rs +9b02a33ef5171bff33602ad7161694000a3761a2c8708a1b0a16b397d034f42f src/adapters/authenticated_read/reconstruction_error_mapping.rs +b5ab6bd1bdd48575570ffb808f087964353582acc8787f641efaf85619c5ac6f src/adapters/authenticated_read/reconstruction_failure_mapping.rs +5112e096ec0345671dc390abd048ee16cef15d117a5f170c1b71ed25b7c86346 src/adapters/blob_id_binary.rs +f9c8a0c60b94c106c1e4372190c5375471dc85a56b6e51e2701a5bc29a27dcb5 src/adapters/blob_id_binary_error.rs +ca2045850d1260e9871de306167e74f897bfc175ddd392ce670a12bfe4ce0dcf src/adapters/blob_id_text.rs +33aa2ef6b9c5192035270a7c3728b5a4f39ce2ed95e8d3ad94f98b9062fceadc src/adapters/blob_id_text_error.rs +2ed98409aba90883e91fb8b11030e122bb51a5ff74f0ea29985e4b2ccb9e8960 src/adapters/blob_verification.rs +10ccb980e6cb4b26a858fb99cf4a7fa008a909fb5eda7f77a4d91d289e80f262 src/adapters/canonical_catalog.rs +c9a640dd4253a03b4c17af7120eb8273cc0f81062784f430c3c279b13fb0a1b4 src/adapters/canonical_publication_head.rs +2345985bf324a5b3d3e5ba99d864fd4a79e83b6d46ced4c7a013e51ad3c166c6 src/adapters/catalog_admission.rs +9a7aad78013c26c0185f124f6322d24ebcf5af620f759d1297b1904c32c387d8 src/adapters/catalog_admission_error.rs +799f7e5344688d67eb813d66a17337817ab152d2adebe7b2b9ec31a96565412b src/adapters/catalog_admission_error_display.rs +eb5e605aa41f31569faccdabbe18c1b3216185c05606b0d91944ea4137065947 src/adapters/catalog_allocation_phase.rs +757d0c19b189b37abe7364504fe32b7795179270aaf0473a64791c01a44a261f src/adapters/catalog_byte_verification.rs +f0e1a9ea0ab4ef7783d28366c5039a2736e46be7039c3db4b648b5e537395fe6 src/adapters/catalog_decode_error.rs +e40ff2e396c3fb9d760f935c0da906480ad48759f432b3d4acc947cefcdfa86b src/adapters/catalog_decode_error_display.rs +2a38ffe854e25fb3e72839338da2c28e3898ff7433bb4b1899aa1d75d8c39b43 src/adapters/catalog_decoder.rs +8914c80ddf863ae7b721928a3f263c86381088a13e486c0ca16d783b616f0838 src/adapters/catalog_encode_error.rs +60ef6c47f3fee9daaf8c73457244cfe9faa8cae3cadc79828b05774be91cb199 src/adapters/catalog_encoder.rs +dee0067d0831bcd089d6547c090d0cb973f926c74788384f19de6eb7516fed66 src/adapters/catalog_encoding_entry.rs +5c5c823b5170c634237a10cc1a8fc261a7275fd9df874ddbaab35ab5eb0fdf59 src/adapters/catalog_entries.rs +383c399226d1fb4f8291d74538bc7fc792a4a39ecb6d13b0aa91bacb55017ae1 src/adapters/catalog_entry_decode_error.rs +b142028f0d7dc3527861527b419bc23fa1d8655256463f79a7351e8484fcb7a0 src/adapters/catalog_entry_decode_error_display.rs +fc4752864be43aed0fa20abbf1cc2d22fd00a2e4b988f3b8ae55e8b461aa9690 src/adapters/catalog_entry_decoder.rs +8cb6ecd229601d46266f266e33a4519fbab929efdc36a61157b14e21941be6b9 src/adapters/catalog_entry_fields.rs +28fd974df4602510a1726c8c12ac6c67922d1e192269d63a37a939013004d66c src/adapters/catalog_entry_plan.rs +6f46cdd7d53cd8972ed384886a6f5cf43b780fd6ad00042ad1e0561d9eea9366 src/adapters/catalog_entry_sequence.rs +c6a470f0e200222eb318895d3fb37e59ccba255c0c51f23b6fc62a0533bcade6 src/adapters/catalog_header_decoder.rs +9519cef3f96ba61cf4496aec761352064b7a5f9f987a998e07ac521781dd044e src/adapters/catalog_header_encoding.rs +2631f012bf094a2f8470ec03d4f236719da5c6f6bf25f06d8276ba2b70a66823 src/adapters/catalog_integrity.rs +ec7c49f402edbac56a9a378bdcf4f4bef5b9fdbb66393f9e5d7a5d821fbee2c7 src/adapters/catalog_publication.rs +293fcb71bfd3efb3a4aafd2c75f502cb1afa046b3699da06eb9504556a2ea28d src/adapters/catalog_publication_error.rs +eedeb6033a40b6b8dfaa0d3fe1ed2d22df0ff911729ead237cccaf28b1890939 src/adapters/catalog_publication_execution.rs +561a9e889a3e2a02eff5a851ba5a5467abb31fc620d01661ddcd959608c0976d src/adapters/catalog_publication_expectation.rs +a3cf22fa1a9ffcce7f4ccbad98d40a935bb348f3860c317b289f4e6069ca6b35 src/adapters/catalog_publication_outcome.rs +5da4f121c15d795761b9226b1d21f7e198b61d45866446f275fb90981115c2f1 src/adapters/catalog_publication_phase.rs +d4f7b967279cfbf3f26b6dd109c9bf811dca5cb2503bcd736473ba6f9a7d7da9 src/adapters/catalog_publication_readiness.rs +7477965d9948a3fd02a819661e5989f0019cdae548bc8bd096382d9e418a35ed src/adapters/catalog_publication_receipt.rs +11bfca3e21ac3cda03ac7015fb65bb5ae17123f9411584ade67d5188650be5bd src/adapters/catalog_publication_storage.rs +67a2b544044af159c08fc7be586fb744c44c7ca4d0f68f27733c4ac67df1120b src/adapters/catalog_record_binding.rs +1762bd6d7fbe77352dc74b4ec7aae29aa884b34942223712d31255f8096664fc src/adapters/catalog_restart_artifact.rs +84f50ad39e1f2ddc6d366215a797685c008eca51c3591424d7954bdd78d2a98b src/adapters/catalog_restart_byte_limit.rs +dcdefc2be962570d32f7c434b8e6a0dec8ac3cae4b4c1a627f7770b15dc1ed26 src/adapters/catalog_restart_error.rs +1ae956906418f16b14a3a1970881451bb1df7654b0f95b308a8b3474d4c12457 src/adapters/catalog_restart_io.rs +d4cbe067861c20783ecd484fad2756531e0acf8e5a809d46b1be8501e4837938 src/adapters/catalog_restart_loader.rs +6117345bc994c06f804d2f69f6849a2faac6bf7f1a41593f6ef232ca78b165cb src/adapters/catalog_restart_phase.rs +e1669cbc6e880ef490023654b8e912bd31c850a31d4676fba93d946bb70e144a src/adapters/catalog_restart_policy.rs +13b81fc419491f312f628fe405192368964c4244bc25f0aecdf0e4be9dae7763 src/adapters/catalog_restart_segments.rs +9f51b1231b52a543f2bf9a4dad95362876c1844db4daba9f780f50f1853a91b7 src/adapters/catalog_snapshot.rs +7e5c5383292c0234c33d9e75d1bbb4ac6b149ed382ffac154d9aa7d234326c3b src/adapters/catalog_snapshot_admission.rs +4b8ead58e0fb98ac1a574a829511b7d5cda62a9bcaa6eebf7178db43a7d514d1 src/adapters/catalog_snapshot_error.rs +7ecf7fc9f403929522f1aa3319a70cd3be15554408f5690bb43942a8c6be3c67 src/adapters/catalog_successor.rs +107935166bde784fa6954faccf15fa4d0009791e5732197af7b771a5a1c791b0 src/adapters/catalog_transition.rs +5a8494054322447e4fbd35dbec58e7209705278c040d5f5cf302edd22880dc04 src/adapters/catalog_transition_error.rs +7267deb63dd27d15f0c48242ad85b9fc088aff1e634c25080f94fc966e59b4f8 src/adapters/catalog_verification.rs +a92fd69ecfdf01c8a1f13529361ececde7ef8e91098005e09b3f04e9bcbabc92 src/adapters/checksummed_catalog.rs +77e765e6e7e962d1231e5939d5b98ee4a96d10049e48fc29a953a8141737087b src/adapters/checksummed_publication_head.rs +10a93df8d38d63abd092e2310b50b8c3b84bde99df8367ff8339a7e2993510d8 src/adapters/checksummed_segment_record.rs +ccb6c08ffd54307ccddb2aeb5c2b71a6252b97355da443627f7898fe54489a7f src/adapters/closed_segment.rs +d1eef7507e51df3af77d7bfe54645a3e82746c269260a9bc3b612df8df158af2 src/adapters/compaction/error.rs +3b61524e01892613363ca4b84b785cddcc78796d555cd1ad3e1a909ae95e6e03 src/adapters/compaction/filesystem.rs +bf0918960d22d326a24381421fa22ab2c63773100a6c38bbcd78739440cbe2a8 src/adapters/compaction/filesystem_tests.rs +490a24945a06e383e9920ae282906939e765ee071f416e8e2c45504dd2865a52 src/adapters/compaction/interruption_tests.rs +91ba2fe7eb5c6fdb02a3decb66c6b4a6d8190044bf72fa65ff51fd70f1077de3 src/adapters/compaction/mod.rs +fb005737da0023d8fd353611a14976f2ddd188386a7bee43cc553aad9e55f9da src/adapters/compaction/observation.rs +0b2e775dfa099e5bbc0c4b12d39abc34751b6ae77b3fc0cbf3feebb419b16c4d src/adapters/compaction/plan.rs +1be315b806365c9b294689017d5f1ff8b87f91ba9c9152ce74a9ed75fe4f3d54 src/adapters/compaction/recovery.rs +bbc5dfb48f1b11943f21a2a3b3f9159b75a1807c3920f187aa73e450f1cb9666 src/adapters/compaction/test_fixture.rs +6865f6021cd4a215457bac5d233ef96c530ae8c37113e3e344ac2f0ffb97db94 src/adapters/decoded_catalog_entry.rs +98b30e889dcaaf3b73cfb7b51a81459ff1031ed18d5d20e3082dc11e812c326d src/adapters/digest_hex.rs +e01bf1b2348eed2f07c3dcf536b823495324a0484e5c36197617407fa6ddbd0d src/adapters/durable/error.rs +9af988b060940016879a153247eb97e569d9170566210a36d751c2e7a6ba2383 src/adapters/durable/ingestion_bound_tests.rs +03451bc901aa409cf03cf15ef31b88177b302d4d0b61561fb0ea0aa959660a1b src/adapters/durable/ingestion_error.rs +36a77dde08544aedd3d1f153d735e38c97b30db04abf25f7f3be78964b85c22e src/adapters/durable/ingestion_receipt.rs +1675eaf6fdcab1964c2d1cdc31b7f261e6d3df1976b6246eca84e536531ee58c src/adapters/durable/layout_reads.rs +267f5a910834a62f7a91bed229734f16f9b53dc5824a2ecf3279509b10c3f833 src/adapters/durable/mod.rs +b642889b269d46d24bb1502e4ea1d9c16c3950240ee1448b08a228b37681f2e1 src/adapters/durable/port.rs +8b85f34c6d181563eb04e64fe6301199d2a7e6d653b2d9f7cbdace8f707ab982 src/adapters/durable/port_tests.rs +849b6c422df5d4fc0613e8d8118d99c72044b7799f80feadf0956a67901a673d src/adapters/durable/rationale.md +19167ea268097446a90a006e5c22f865c0bdffce1fdbb08044d67878dc2a5320 src/adapters/durable/receipt.rs +0a8cf0e8c2dde154fb5b0dda4b486cbb5cafa96d68ff48b4b40aeab9caa224f3 src/adapters/durable/recovery.rs +73f4a21a2785ea9629b20dce7be94691db9374f1b236725ad217781dbc037627 src/adapters/durable/refusal_source_tests.rs +8b878ebbcc74c187598f4ef1ad989fc7892b62eee87b1fe45005861c090c34be src/adapters/durable/retained_anchors.rs +62784d06694fb20a52501ae08dc8769da66b77b00bbfa1558d4fe12bd86dcf5e src/adapters/durable/snapshot.rs +73e7f728fd9a89f13137d82dc4e8665a3d1dc982ad1f3a1f6d29bdcab21760ed src/adapters/durable/staged.rs +da661ae0c2761ada92b3c499860fc461ca162e30a529ecb02a5250df016cf653 src/adapters/durable/store.rs +ba43b64fcdd6f72173ad52496ac812d75df3a9089038a4ac8441232d53299c2a src/adapters/durable/test_fixture.rs +4cdf410ec78c775835b5ec957dbc7c4330322c8dfee4f377b99da8d7df2fc4db src/adapters/durable/tests.rs +7aa93b572130ff85001e58112906944112a194261ed67b888bece9f0cdf521ee src/adapters/durable/transfer_source.rs +16932e457b2c3040764d517e2f5cefe7d188080ecd8747109b2db925b3ffa4f8 src/adapters/durable/transfer_tests.rs +50495417df22036b4929d0ce759a2083ec52fee73efc09c26254407f9e54dbbf src/adapters/durable/view.rs +b79d77f0e2ab0a49dae681ae61ed131c5c142fa2b536026ef3e938de824d5329 src/adapters/durable/writer.rs +d0288bfafd66bb6ebce70a9a4239e60ee5262f281165c5dd13977793277a217d src/adapters/durable/writer_sink.rs +edbf3b5e9fbd3e54e97f77d343969d7a571cf7b2796b52e7d1f03c97c8667330 src/adapters/durable/writer_tests.rs +38d9714a9add537ba93138fa6ed82086f24f6c3372da70fe7fa68250d3c9552b src/adapters/exports.rs +d9d8191b4c87a75821512cd1cbe5989bf7cd19145e0c3f4cdbf18a30933b0b6a src/adapters/filesystem_catalog_artifact.rs +b2007255191a59fb9ef7015fcd9b9e997c780a984d14ebf04b31d087503fd61b src/adapters/filesystem_catalog_catalog.rs +2902edfe8a64e2f2291153886e404d55441752e58fb3da463c2265ba142bb77e src/adapters/filesystem_catalog_current.rs +b83334d92d2ce50d55a9e3ba02ec3de085bb8213d99252d48b46c9baccdfccf0 src/adapters/filesystem_catalog_head.rs +69b2ebdb6064e8279026a1a036c0f770c8a30c63f326cf0dd1a4d7e82ff6e8b2 src/adapters/filesystem_catalog_publication_error.rs +b9c19bd027d17977a5bffa8b7c5f3efaa91ac0e97fa1e73506af7a63aef0413d src/adapters/filesystem_catalog_publisher.rs +83b5d4413e8fac519ba069eaf4193b8981feb65fff85eb6efa334666d929c6fd src/adapters/filesystem_catalog_publisher_tests.rs +d42a4a483858d88443cd0d636c32955e6af761bbb324d6c549ee96791e9cff56 src/adapters/filesystem_catalog_segment.rs +4c610036b913668797df74c3150ef2b02477d9f30c141a85efbd17854edbcdc5 src/adapters/filesystem_catalog_snapshot.rs +40afba8b9c0af35f5eb5bc3cd4d6efefe57dddcd35950c2c1403c3c71759c2e1 src/adapters/filesystem_catalog_storage.rs +0d24ebea7591253afee211a331efc9c42bd73cc9b9eb8b12e8fd3a04b463cecc src/adapters/filesystem_exact_record.rs +9c79f01ac85c50174f78735bd2dbcd0930a31d08bbd9d496080220765df19098 src/adapters/filesystem_exact_record_tests.rs +6d91b2965f1ba93067bef7958a00b10a9a5862dc535466d05ee7d87d92ca6337 src/adapters/filesystem_initialization_namespace.rs +033939cfc50c52400a7d58d121a3f54bd8b68a52ca2799fc3ea4e248f203fdba src/adapters/filesystem_initialization_storage.rs +94d72490ab2683243e1cf8f5281df1f26699554e13f5c219146cc89310f3a371 src/adapters/filesystem_namespace_refusal.rs +23c2026586cf3287d881841d55a55d3a717008324c52422a718350dde4ffc937 src/adapters/filesystem_platform_admission.rs +bdb0f3ec2f11ded872e08b6f5d1a34807176aab45f01e5d9b61548ffadcdae15 src/adapters/filesystem_platform_admission_error.rs +83b6ddd86aa3f6671c6b8b3f07ef596d002c4fbef3ffef6937319d95501e5a77 src/adapters/filesystem_platform_profile.rs +ac97a22b9253ca50204cb2a13d4256f36f8ecf7437f5be2f2f10d91840cd6402 src/adapters/filesystem_platform_profile_policy_tests.rs +9ab13d56cfdc39883688a3f5123ce9a8c656186120697f996caaad0158ec3d59 src/adapters/filesystem_platform_profile_tests.rs +cd9518f02f0e333305eec32e2995f9d0996be71822581c27196785553485a205 src/adapters/filesystem_publisher_authority.rs +cf9288db7d2d005845d41b397b8e0353f2128584080e4cded9bd4e0bde540362 src/adapters/filesystem_recovery_inventory_reader.rs +0aeac4ef7d5c82eaa41b97bffe42dc8a093448691d7a1146cce2edf9e2be5a2d src/adapters/filesystem_recovery_inventory_scan.rs +20ff7c4fd2a7380862a48ad9b00ff78a8b0b94dc1e4b5115880606eb2813f85e src/adapters/filesystem_recovery_inventory_tests.rs +c2a28df3355cde9e8c2f09ad85ff569eb77ce6bc58eaa3dfd6329783c1649000 src/adapters/filesystem_recovery_namespace.rs +b42fbc6901414ded6f9ad89de500c0af0827ed89e7e249873e053eafaf532b94 src/adapters/filesystem_recovery_next_head_candidate.rs +420e64fb0f1437d5656304965ebc2c08d72a149ffd8e64cb1fc3795569f1a443 src/adapters/filesystem_recovery_next_head_finalization_open_error.rs +3f50c49095b6274abec7fe865e21525a177feaf4a69a158ad870c6282fc3ea92 src/adapters/filesystem_recovery_next_head_finalization_storage.rs +13df4d630f2b8a97f2f3de8ef79ea13ab18280496cfd19eb656c7b74ad74f55e src/adapters/filesystem_recovery_next_head_finalization_tests.rs +973c861473c8a021fb7540436f5f48408dc46f655ae4bc5329cfdacdb07d00e4 src/adapters/filesystem_recovery_next_head_finalization_tests/fixture.rs +8135e3c8b1ba6132f9f6708304f7d4e6ab79ea3b405dc75111f4f0b3fb1ef02c src/adapters/filesystem_recovery_next_head_finalization_tests/namespace_laws.rs +aaf1b2862aa5281935ce91e70c1ef9259cf7c372ca57f4e3b7f994ad8c9b5878 src/adapters/filesystem_recovery_next_head_finalization_tests/refusal_laws.rs +541748746812d2c46af139c525dccd84a65e2c567902f664e95c11aee9e47339 src/adapters/filesystem_recovery_next_head_finalization_tests/replacement_laws.rs +f13c0622cff73a818add837728b55b89f138b8607960ddc6666d427bdd835892 src/adapters/filesystem_recovery_next_head_finalizer.rs +32a2c962c3c6522440573e6bde7917f510cbbc5f822bca2dba66d91b46f1c6a6 src/adapters/filesystem_recovery_segment_resume_open_error.rs +a89093149f170dea2d02e029ffd5caea9728d69945d284296e9bd4c777d34623 src/adapters/filesystem_recovery_segment_resume_storage.rs +b1d34ff0b8c38dc6097eb096d0965a4a5263a670f04206a87fcd86ef47a76053 src/adapters/filesystem_recovery_segment_resume_tests.rs +e8dd43488c728e27b64d4a39aec037698288d8f36ba6a72189184d4663b8b321 src/adapters/filesystem_recovery_segment_resume_tests/fixture.rs +66627639f84d31256732ab270ae51c973de36c4db778e4020c94772839556454 src/adapters/filesystem_recovery_segment_resume_tests/refusal_laws.rs +f8bc800db403265f7a2c99bdb30ea3f7710bfe30e78938ecb301c0310dbc7569 src/adapters/filesystem_recovery_segment_resumer.rs +317fbf3ce39a8e9f84d84bdac0cca905d37c94f2034103b12d6e00772ec8dd23 src/adapters/filesystem_recovery_segment_stage.rs +6f50e3bca8ba89c6f9a0344184156b4cc7cf84ee81a80fb8811971aca190f62c src/adapters/filesystem_recovery_stage.rs +29c1dfb32989cca84b85e9f76103a2bf8a71e282325d8f4b7030f1c751b2d62b src/adapters/filesystem_recovery_stage_completer.rs +73810f0df0d23251210bfa4721b7cb0b4fe307d31f5fd9de25bb8c2bca6974c4 src/adapters/filesystem_recovery_stage_completion_open_error.rs +589ab554f9b3133e708fd51b65daac1c587501c547a7b6c4ff5fa2a0ca69e17b src/adapters/filesystem_recovery_stage_completion_pool.rs +d435349c28ae307ba99c1d6164815f2309ca8a09c11a87e840558f3b0c856c0c src/adapters/filesystem_recovery_stage_completion_storage.rs +fef34211ce9e54d79f4b84871986bb3e151c0173cc833e42c7dac4f8c100ef19 src/adapters/filesystem_recovery_stage_completion_tests.rs +7e0f04e7479082b96115aa4c6446b60b8f1d88a5a44497250bed58f181c77f78 src/adapters/filesystem_recovery_stage_completion_tests/fixture.rs +5fceacc389eb7a37f87fa1d0ee3f96ddc110126f2ad3b81bdab95eb6f1d93a5d src/adapters/filesystem_recovery_stage_completion_tests/refusal_laws.rs +cda0e236ffa4dd320087b0e03c8e993d12fe2539229899cd74a7b0e7bd3078d6 src/adapters/filesystem_recovery_stage_completion_tests/replacement_laws.rs +68af99505a7911cde7412ff3e9812e01657e848b779ef65559c70c84bb8324a4 src/adapters/filesystem_recovery_stage_discard_open_error.rs +91d91a38c5972d2b44c8085d159d1015505d3b49e9e35495c64ee6c1551cd7c5 src/adapters/filesystem_recovery_stage_discard_storage.rs +f0e4bc38962c0882ad961f800ea06f99b5ca7665933010386f5f6bf3f075c1eb src/adapters/filesystem_recovery_stage_discard_tests.rs +7f04bcaa23e5266bac0eb34d6fb11678e8aff18a73131bd934773a1fc0b5fb47 src/adapters/filesystem_recovery_stage_discard_tests/fixture.rs +15436ba766530947a2203aecfa094bf573e7662ad134e751b665e9b19fe7f3ea src/adapters/filesystem_recovery_stage_discarder.rs +595f14c0fcffac9b70d4e735e2b6d8e349fff6cc65876dce438a49a5fa8f4b04 src/adapters/filesystem_recovery_stage_error.rs +098f7ffcc43fe5e68cc09258309b3ec75f30c07c5b2e3b78788818b7d73c4fc1 src/adapters/filesystem_recovery_stage_error_display.rs +1b73453ce978f983a783dce8403a36e1680ca719e1ae566af83c31b6cf22c895 src/adapters/filesystem_recovery_stage_materialization.rs +2e98a79507ef8cf678ca4452ce7b51cc27dec972e28eb9a30a15141c9f669d17 src/adapters/filesystem_recovery_stage_sync.rs +854c146ab3d6ac10a87c7fbe0f217ed1a0bfceff8852e8db8ebcbac7b6cc4bc9 src/adapters/filesystem_recovery_stage_tests.rs +4217f58b07c57230be6fce6396bb9bb57eec58db17d7e3f70e6aa0c4d4bb1535 src/adapters/filesystem_root_binding.rs +960caa963b61991fc4437b36dde1e24638c695db39e5b92f3265351052dadf6c src/adapters/filesystem_root_identity.rs +80b9d9b380386bd951e8af3f14a9fd1063c7c9b48249f50f16b2ef3f56ed8bea src/adapters/filesystem_segment_stage.rs +666e45008cc7d6a7fef1216bce6682fa23d7cbb1f3bd86eeb9c237813dad6ae7 src/adapters/filesystem_segment_stage_tests.rs +7e4dd3cb0922cf865799665d2493c5e8d96334a7fde0d1cae9a7e825fdab577a src/adapters/filesystem_stage_observation.rs +fdd24db5ce642faa0e6ea29bbb6873d44869c2b6467144f86b061a2ebd376c9c src/adapters/filesystem_store_initializer.rs +0321d4c3144305ac5efa7140a9f3cb2421509e7f0b9ee39ae0c355831af77371 src/adapters/filesystem_store_initializer_tests.rs +0ebd86465ea7844db649148b861ae5c2de0e4b9cc4fa7dc842b74c68bb03a918 src/adapters/filesystem_version_two_admission.rs +bbd14772bbcbe81081180502867fd5f5c830cd0e59eb54c9a33e52b846b75449 src/adapters/filesystem_version_two_record_refusal.rs +0d8711f09091817cf44295ae3c53f968443223365e1f4021dcb5cbf925076ef7 src/adapters/filesystem_version_two_records.rs +86ba02f04cfc45a53fb8f766ceb9db0b5aa2fe59af2a9c3ceaff2f6db440909b src/adapters/filesystem_writer_lock.rs +b948a2253034ba0910d146b43070e8a52044e27792e689a11e99173a63f9b246 src/adapters/filesystem_writer_lock_tests.rs +4b706e062f2f04d2232a6c8af2ad059daa0032fdb2fa4ca95cf02f5234a59c67 src/adapters/framed_blake3.rs +9faeadab19daf90b0ef111332a0d120fd064241d62b46ce303c2e99aa3b367f5 src/adapters/gc/admitted_disposition.rs +b30ddac6c57436e7e4c1da99c118b018e7029786fc8cf86b33adea440f21eda7 src/adapters/gc/admitted_intent.rs +78f7acf422ead6ecb8ffca78701964423bfb70f033d84f7f750efe3996d000db src/adapters/gc/admitted_receipt.rs +4beb6506ccac6fa29f7f4a79fe163e122d23e6467e82f3ed91b1f5d3fde9c068 src/adapters/gc/candidate.rs +47a1ed0037a0e5a850541a44acd6b5d2ee3d9d1e27d9706695a4023ef548acd5 src/adapters/gc/canonical_disposition.rs +8d1107d5ccc61581ac1b99dcff0c9b084956b46cfe658e33bd5f6d3a74684f83 src/adapters/gc/canonical_intent.rs +c495a3bfc923f11e9369d4d8f962a12b30187043fa314199b9caa85e06aa2e9a src/adapters/gc/canonical_receipt.rs +da6cfa069278bce470a0de4045f5374b839f4d84aa8b9d04dad843aa820ef0cc src/adapters/gc/disposition.rs +b7a7ee4abe055d67de95763e76c8d14ba11782fd8ed03e6a4eec468e299618ad src/adapters/gc/disposition_decode_error.rs +eefeaf54c7dfcc354fe5e8b59bff557c777621a2763b44cce32fc5053992575d src/adapters/gc/disposition_decoder.rs +673cde8c1f5df94aeca10121c47c7dfa462489cb67dc23e0e0716b8b6d130768 src/adapters/gc/disposition_encoder.rs +4bc311f29755aabadb67e661408267a9d13fd9518eed76db7250359c59ead366 src/adapters/gc/disposition_enums.rs +934ef23e1995a110a9a80b9395c11310d008d846020e3047c8191a3f69690cac src/adapters/gc/disposition_format.rs +5d237542f51c77e55e98f4d9915dfce1c1e3bf208e39be762b3c534a8519793d src/adapters/gc/evidence_digests.rs +846312f3085cc606dd101253c6272629e3ad8ce172bf63a83663d4dabe2ec986 src/adapters/gc/execution.rs +de8e35f0c2c5b4736cfc31d3510b274193fa874744fb4742ed141854c65958ec src/adapters/gc/execution_phase.rs +3fc779c22af904c92fb0ba79c434a99fea57c3a224c3f2793f442385c558d801 src/adapters/gc/execution_storage.rs +46ddbe7b086ad9c9151ac84532af21d862c2fc072b66a2375794850fabe05d6f src/adapters/gc/filesystem_gc_authority.rs +312ca5127010dca0952fe05bd6dc0c9427d8815806826472f9d6bd7a3217be45 src/adapters/gc/filesystem_gc_error.rs +2454057c7a4059334b2987cf0be7174f4cbe248b1cdc4dd0803bca9354f26202 src/adapters/gc/filesystem_gc_residue.rs +97d147c92be6e8d69ea6a3f1f05800e8a9dd5962f9c873308f641655352f8720 src/adapters/gc/filesystem_gc_storage.rs +a5680a9bdded58d9f5a4e6847f25d7e29ca7300b46ea9ff6448495f549ff2a92 src/adapters/gc/filesystem_gc_tests.rs +e5dda24c98ee61f9e5fb494ed07c8559fb73339744bc9f1b470e392d356a86c1 src/adapters/gc/intent.rs +7bcbbc503d50b6ce382753d0e5d10dd2fcbf97ad11233b54fe0e9a679c08685c src/adapters/gc/intent_candidate_decoder.rs +b8b2b8776ed3fdc55f0a091a6b147120ba0db438a2b51b7ff99e6bed287982c8 src/adapters/gc/intent_coordinates.rs +cfc6a8805ec684f9f432bbfb355911e19551c54e7b1e960aaacb000f462204a7 src/adapters/gc/intent_decode_error.rs +e6683ca2afb601a20c767707ad95c628c12ea4bd2f71b5ec0db7250c90e8941a src/adapters/gc/intent_decode_error_display.rs +492da9869fb97c8a314be0f48281ce62231642d1513affd1cd9300b65826c9ed src/adapters/gc/intent_decoder.rs +a880f9db2b00040fd7ca47c9820112d61e061d35261dfb7a985a99c62853e6c2 src/adapters/gc/intent_encoder.rs +f8975e45a43203308da6a5b22a860711eeb29730520563f458b5e71284aad9a7 src/adapters/gc/intent_error.rs +fd7b86568de047e4ad950e6ad9bc15a6e7efe6a4a65ca2e6cfb116dce262e0ab src/adapters/gc/intent_field_decoder.rs +d86182f0e25067c3c8be431f71152e000d6fe99eeffc38aa274141976f4db9ee src/adapters/gc/intent_format.rs +ef5933917dcda952196bfd86b47e3878f895bddfbccd509a8b365f298953de9e src/adapters/gc/intent_header_decoder.rs +08949b5b694a8c22aced458c12db299ed003002701ccc47fb1721b76ee089d1c src/adapters/gc/intent_integrity.rs +d27fe8ca5c09ceb028f36282df76a7b2a94b8109155cd4207298921271b3b7e3 src/adapters/gc/intent_semantic_header.rs +4895c5cd4a8105b7ac4746a24ea58053ccaac31d42733026586d8e3b187f8f08 src/adapters/gc/liveness_coordinates.rs +cd9afaf28464cf315826e9c0fda659c53721c18f90f068cea79c320a0e7bb0f0 src/adapters/gc/liveness_observation.rs +e40181834a02d0074b4560e4200d8374acf62d2d421d495093bedf1b891ae9d8 src/adapters/gc/liveness_observation_error.rs +1139bd22f5be988f95314c251f0a3350be05f62681fcda4c0a8ea343159d57df src/adapters/gc/liveness_observation_tests.rs +2c178e847be0d616eb90c725e1db870b0909726f3e875a2b07f742f1244d9864 src/adapters/gc/liveness_snapshot.rs +7b57834d2ead721cad194b517d96aa0e09c8f9a97816508b0db138dfdcd991da src/adapters/gc/mod.rs +3ff067d21572cd03cba6d01b210a1f7558f72059ed24038fb49d44b2343c2b39 src/adapters/gc/plan.rs +2bfabe154115e28dd62c9e1ca95410465831f05e32d2695d680e7b49211fca00 src/adapters/gc/plan_error.rs +379b52206e13aa7cb24f1d1104772baf5bd4de8da7188802a89b3ff9c94c6adc src/adapters/gc/plan_limits.rs +bddcd165d272c55d68ccc390ad366d898f0d2d9febc7b940275bfa909641f1db src/adapters/gc/plan_model_tests.rs +b22ab6ebef9c9ad40a5debb4de5dab2228088995aad83505ea8f149dd1a21e3c src/adapters/gc/planner.rs +34f799c400d8d48068e333844d8c381a78cdf7b3a9c9f34caf91c5677a0aeda8 src/adapters/gc/planner_tests.rs +c6ff7f584f8a778f02f64ede4c6d1d18496325576b1d718350ab073743295e17 src/adapters/gc/rationale.md +f258975e94cc3b919022af852e4a3380c472f6d2b24d098d94b7e0fe05e30ff7 src/adapters/gc/reader_lock_device.rs +89779af24bee48acf366ed9b54a56d600c243cae72d74a76a95c99d60bbab2cb src/adapters/gc/reader_lock_file.rs +6804a95856400c9c3a223e3d88dd8dfe8c86f3d796c79ae6c97f021639c0c55b src/adapters/gc/reader_lock_identity.rs +914b2b07728a51ca579aff5e794b7a20ff8d7b6fef97f8af556461743646a93b src/adapters/gc/reader_lock_mount.rs +748e56c28edd66d8481ac36bf86a52f20b5bcc92658f6bc776a99204b4d122d8 src/adapters/gc/receipt.rs +33a62aa4580a5f0ca678f45ece69c521d68c5ce1a9e2d5d4e424282d6aa8ceb5 src/adapters/gc/receipt_bytes.rs +1f162b0852b1a8cab4c4e25cfdf0cfb63e46e1d84affc6881bc88623276cb298 src/adapters/gc/receipt_decode_error.rs +4f0c6b049a71caa85931c1aa7a7b782346b7d1fa476a61ec41b62428cfc32306 src/adapters/gc/receipt_decoder.rs +a5567851360c0c860d2b3ee2abf53d8e4631e433936f885fecee447361af70a3 src/adapters/gc/receipt_encoder.rs +2a8a71ea564bfe50938c8c552232c6c0559e388b80e26d73c297b0d0c149433e src/adapters/gc/receipt_format.rs +1dbd5b3c9f35d46a347658abfd8805f4eb2812b3f9555e0dce5414c2e1b8e3bf src/adapters/gc/record_digests.rs +aa16bf80acb8880253c1c61eda581790683d2a50ff78dbc0e8a473034f61cb18 src/adapters/gc/recovery_plan.rs +13a555d88491a1d7e709c2112569feb010442bcc0227a52491dc9d90b520a62c src/adapters/gc/recovery_residue.rs +ec2e600ffccfdb66513596f65d2eb2a0c60821899bd0d96a48fde0576c8e98e9 src/adapters/gc/retained_closure.rs +a466414a2c90e1bf3ba24cd7404e6396cd14c6c8bdc94f72755caa922e3c1bfb src/adapters/gc/retirement_intent.rs +0f9d88efebd253fd603af885421b02c6a1631de82b1d14a3d7b4efbb8af2b3cb src/adapters/gc/segment_classification.rs +216091a98ae6c2f757932cfd0e09a7015e52f97c634eb32255cae14b9fd7cf60 src/adapters/gc/segment_pool_inventory.rs +323d23267517b91da70f102e04dec51871f54623c5976a6c57e7d9d5db188b49 src/adapters/layout_decode_error.rs +e5097702150d1425eaec41dff587b6fc9ed25963d24416ee1e3f6265ff61d2c7 src/adapters/layout_decode_error_display.rs +418c78be4cdfb8ba4026bbe94e9c31d83d0d312bbe85e3a5fc59e1e88b08ce95 src/adapters/layout_decode_policy.rs +8940e89ef813c30d9cd2f10344eac89d6e8fba8c76002d5c5fb2603d000bdc13 src/adapters/layout_encode_error.rs +01f891d53940f9a7b64b909d3f6453e0d4a6363496cce51bad2df8c3ca07b6a0 src/adapters/layout_header_decoder.rs +436668e4293d1d37ca8618ef1c263d8479f0af061b69ba9360612f282ae8335c src/adapters/layout_id_binary.rs +75bcfc38686a21d99c57e264e1a4d4f843ff1fc8495dd3967196d0f60f714bdd src/adapters/layout_id_binary_error.rs +3fe39632357d6f1e66b24be1ba332611c838f06986bee8927e7175670b9d396b src/adapters/layout_id_text.rs +b0a1b83ba2403a8001b46e7410af8b81850bd042efe8f0ba4dd856700103005f src/adapters/layout_id_text_error.rs +4afc54cad4ff8f3054b02fca205e1e0a81a002e5cbdf755b52456641c09d0522 src/adapters/layout_record.rs +e6178d3abf506dd022b5686b7c6721fc2a2c026929a698183bcfd7ca197b7bf0 src/adapters/layout_record_decoder.rs +0e83dd19bbc5d2a8c6aecb755d2de05dba8d77032c7d891abb6cbef3d4cd1c7b src/adapters/layout_record_encoder.rs +49eb7ba5267761fed9f730f56b46a618338c41f1325a35a6891cd49b9e5f3998 src/adapters/layout_record_format.rs +826f3fe0be7dc2372de9bcce0461527a5c1a28144e97b343f1c4e6cb19599192 src/adapters/layout_record_framing.rs +0b0d9690a0843d4ad6a3fae41ea302a00ce9840181a88f5ae8c5d966da57806d src/adapters/loaded_segment.rs +4ff28d5e2c6925e50a257bf859fd57479a879d327fcafd71d99ca58e0426a014 src/adapters/lower_hex.rs +87762fbfd660326c9cc92f3b99a6d10e4c62cf975d35cde90ad3aded91e3ba05 src/adapters/mod.rs +17b58f0969a89388e2e4abe4161e8f6807b64a161d09e6f516e90db047e56458 src/adapters/observed_segment_stage.rs +dc0f17d78c1b9273b31b9f461a00c91c8e955f446f08305330fbf09769896670 src/adapters/opened_reusable_segment.rs +9570b812da6c4d4dbba330bd0362bb753c0a933b315d08a5a664bc5eeb69b813 src/adapters/physical_pool_name.rs +d81fd64a37ce0a220586e8d183ee70c8af93a8a813ccf8a536e0335bb7540e8a src/adapters/pipeline/cancellation.rs +44d364158e9163107ae7d0556729ee4433ab2f5f187a350ce0ad750560a0d23c src/adapters/pipeline/copy.rs +40584a67b83745ed5d438356f772cadf7d0ca7a50ae9cc75728c6c8e0c134548 src/adapters/pipeline/error.rs +9887a2018b1de46c99b56dbca324579ef925a450093a62921e5da885161487f2 src/adapters/pipeline/mod.rs +bc173e02fa0ab2cc60496d9f5c0f8cdfdab778e1362e71e28a5c7e07e51d5368 src/adapters/pipeline/receipt.rs +1309c0f9c822fb8eff25cd81ecc55656f6139e32cbbffdb695ec867816e1e319 src/adapters/pipeline/sink.rs +03e998b32f674ac4a84f8264df39bac6f4bd1e13b2d784467d3b1b6ea9fd8db4 src/adapters/pipeline/tests.rs +dc4de074868d3091793244e122327708b5606fcd2bce4a3df24fc61f57d7d13d src/adapters/pipeline/transfer.rs +11d59f95c6d092a49670f3564672f638578659548360a3be061e10b7d655e29e src/adapters/pipeline/window.rs +5b56ca44466619b59e7b40299b1d1c294330e25dbd4ea1aa825c505e55ce2def src/adapters/publication_head_decode_error.rs +6ff53843229157a8178913660382dbd1eabaaae8dc5e817eac05714f0ac38c5d src/adapters/publication_head_decode_error_display.rs +d50cd98679277ee2a8d1fdf145af324458900b2a32c4420d2edd658d7ab0918b src/adapters/publication_head_decoder.rs +1cd7d8f0743875879d5d48f21481d2f197f21b752d2fda7385763267e1e19885 src/adapters/publication_head_encoder.rs +0905c902f94a2593e9b7a90638e65a0e598c56cf1b371776cced0e7be844548c src/adapters/recovery.rs +a72d1a6c3bf974c132c494bd65e24cf685d0240063b7801cb738d16503c2d50b src/adapters/recovery/rationale.md +cc9b83b781ff7c797218def8eac3bff8672b7a31e8f01ac4f26e255929880529 src/adapters/recovery/recovery_catalog_stage.rs +0f130e330fdcc40031d1a09424e401052cc7cd48530b6fd3a0e4c2d4e697722e src/adapters/recovery/recovery_catalog_stage_error.rs +c734e82dfe1f017c2438b75a9fd9dd4b21c64e71ef8a6085ee758f4cc1853dde src/adapters/recovery/recovery_entry_name.rs +3c5dc6f19033dac21bf0cdd1b8df693883743fc2e70aa64dec85f346930e1607 src/adapters/recovery/recovery_entry_role.rs +87944cf4204b557c68a2b6e426bb3b3d381b5322e32711b473b85325c0bab2c1 src/adapters/recovery/recovery_fixed_field_prefix.rs +388270df125b230ca2769d5c13a55f6ffcce294f4dc63f66ee05b105829b8b8d src/adapters/recovery/recovery_inventory.rs +467e93d5d97326f86c14436f57d86a8af5ba1b3f0c7cb68c7dd4c943c6053601 src/adapters/recovery/recovery_inventory_error.rs +b04a0d6290b21d5e85b8a79830e1d65a94cde0367e56a937a73c56e638d17c3b src/adapters/recovery/recovery_inventory_limit.rs +32a184af31551fef3b54f071754b2d868125115f113dfcacc2bc5e0a9716036d src/adapters/recovery/recovery_inventory_operation.rs +08603ad72ac7dda6b67d33a2c39e81e4f70425e56ccae13c4224f2db7f9adb7c src/adapters/recovery/recovery_inventory_storage.rs +d4513acfa536935c87517f1588ee1d1aa6059282ce2111c87c440435284a58c4 src/adapters/recovery/recovery_name_classification.rs +ec1f17a30009b8a54b6b608d958fddfe28d74242b2ba4495287ff80b6ab5b15a src/adapters/recovery/recovery_name_classification_error.rs +131e1f34cc0ce91329b0e310f8295a0e533f3c5b63c1f4f0af51b85947fd0c4a src/adapters/recovery/recovery_name_manifest.rs +6f43e8a3e201006343ee92a2b810702304f25a4d311f3f0447e0dbaed52453ed src/adapters/recovery/recovery_namespace.rs +a7be1374db658da4b0daf57eea75949e9dead7f8d15070b277e9f0a737523ccf src/adapters/recovery/recovery_next_head_finalization_error.rs +01453555e712cb0885fea3452180a0e8538ff82fa6fd9151cefbf0cfda76bebd src/adapters/recovery/recovery_next_head_finalization_executor.rs +adf1c3b749caec1a7b24e7f86ee921cc996a5b440896f6ede9104810dab05f3c src/adapters/recovery/recovery_next_head_finalization_outcome.rs +378f4e42af9263d42ec715f9d2f64df9d8a1b64bb458abb124a4b74176a57355 src/adapters/recovery/recovery_next_head_finalization_plan_error.rs +01794d6d6b82796264db6fd24981f1f470c6be5232cf620b4cfac11e1535fc09 src/adapters/recovery/recovery_next_head_finalization_planner.rs +e8b6aadb97b15a6df706c140fcacf37596056dc31f8129f1c1c4fac17d886d92 src/adapters/recovery/recovery_next_head_finalization_readiness.rs +e5083ea2ad8d9269b92a48b07750425b5ee3bb229dc7df3e5113ffd8fec7a88d src/adapters/recovery/recovery_next_head_finalization_receipt.rs +db08fdcc096d139e12e7d7498d1c453aa74925415cd20087e79612dbcf563527 src/adapters/recovery/recovery_next_head_finalization_request.rs +6341199d3ff072bd0a38e4e0e0bb132b326bc897d5808b98d0cefb5669bb0db4 src/adapters/recovery/recovery_next_head_finalization_storage.rs +af3f22d288134252f8d732231291c60e887bfb49382a560cee4515b74a455303 src/adapters/recovery/recovery_next_head_finalization_storage_error.rs +416b5ff89c227c2c518e16b9966bed71bd83ea1f5edb8bfc06ca0d5a9ef33a3d src/adapters/recovery/recovery_next_head_finalization_target.rs +ccc33ade602f034afe160b9aa5fc9378ed6f6587e77498ac210dbfafe52c3889 src/adapters/recovery/recovery_next_head_stage.rs +cad3e3a953f08bc183a5c461f37728b39b74732b6c65dbd1c579e86daac9c852 src/adapters/recovery/recovery_next_head_stage_error.rs +3b7072a6bfefb63d46bafebfd259429302af474e2416d2a3c6c6609a0ede6247 src/adapters/recovery/recovery_pool_name.rs +54522b21b5bb1091172bb7dd3f988c3194160d2f5d6aa03790884b9d718a8dd3 src/adapters/recovery/recovery_pool_name_error.rs +8b9f23ed1eebbb14be87d006f41ffdc011299ec8164537586d3a90a3699df424 src/adapters/recovery/recovery_publication_fixed_framing.rs +eacbd46e25bb60f0a2f8917a273e9029bf1b0c29934d338e67a63079fc6c3a18 src/adapters/recovery/recovery_publication_stage_classifier.rs +398f7079e53834ce8a7973adf03951e3cebceacdaff107cd8137dc506279449e src/adapters/recovery/recovery_required_entry.rs +374d7b21347ba1822301a016e00b49dac17f8d8af858c226ff7d4c0082390e6a src/adapters/recovery/recovery_segment_classifier.rs +5bd46689d592ac7fa264cc8af4a234602b960209ede98a0d8c492e9faaa31e08 src/adapters/recovery/recovery_segment_fixed_framing.rs +13adaf48fcf9896057992f75985240609f9f664cc11b4de9d3b4b916fb725b8b src/adapters/recovery/recovery_segment_resume_error.rs +c98e4c8af1ce57158bb22e7b7a0727257eed258c3cfb8c9b65b3a8c7a01a9306 src/adapters/recovery/recovery_segment_resume_executor.rs +7f2a6045e605966cafc63515e95f54a8c841dea8b7b77da08a1b7519bc38b3a0 src/adapters/recovery/recovery_segment_resume_plan_error.rs +1a51e59aeb8f9daf07241af50558063588822e718d9f10c69eaa09006dbf3ebd src/adapters/recovery/recovery_segment_resume_planner.rs +3e79c7099f12d1c35bd56bbbb71e53d7a62208faac5237b0c7add50dda651a36 src/adapters/recovery/recovery_segment_resume_request.rs +27829e8d45fdd89cd29da421e091edad62ffee171af51a30a6c0d86965e39d59 src/adapters/recovery/recovery_segment_resume_state.rs +0d3df76dd221d20aa2cd2f4ff48c1bbd79432c14d7f804e0d27825ffe1ef28c9 src/adapters/recovery/recovery_segment_resume_storage.rs +674f9ff1936daa5e5ccd7b62e8243c1a5a0ca840da46f258a07f6dee59ab96a2 src/adapters/recovery/recovery_segment_resume_storage_error.rs +da17bae92302f8f0de6336ec2a4daacd24eb0b001f1aae5cde8dba464ee908e5 src/adapters/recovery/recovery_segment_seal_framing.rs +c98b5fd2b0fbd2a26d57b5e6925e0c7b999f29cae86d9705f8f28f0831254ca8 src/adapters/recovery/recovery_segment_stage.rs +dd96c0c169b738a861e017b3e6443559f92b3781b8cf79075e7fc53c2f7f1d7e src/adapters/recovery/recovery_segment_stage_error.rs +e0b97ca2b3364e041b14dbb305544da42966bd1b8799af2da290299590d0165d src/adapters/recovery/recovery_segment_truncation.rs +39104f36b7a228d963032b914468b94d596cd310ae41caa890b4c2b5c059f3d7 src/adapters/recovery/recovery_stage.rs +387c417c23f5c95b71f066e29d1baec2bd2935f4423fcc3c581e5225c0a22410 src/adapters/recovery/recovery_stage_assessment.rs +b82aa5019ed9722b9980b822b7ce65e14172b85b3308e2d5ea2a932c18b725f8 src/adapters/recovery/recovery_stage_assessment_error.rs +ebf65728880636208f718baca51c04c9e910591a528cd7ec233b8755153c23cf src/adapters/recovery/recovery_stage_assessor.rs +4f6a31ebb4ad087fd394103b382fe36dafbe245bd9a32017819e0607f595b7d8 src/adapters/recovery/recovery_stage_byte_admission.rs +742099853717a0b51d66bb871db90a0bdd04b0fb515a2f3b6af4bda1d52568b2 src/adapters/recovery/recovery_stage_byte_admission_error.rs +cd574c4fb4b849be4ea1ca5d69dca8fcd6a4e3185bb64fa2b0b6d2aab68e9201 src/adapters/recovery/recovery_stage_completion_error.rs +223330ec9d7f7eab7df1f71c475a3326c758ad74b8ffbfcb812a86eefc3a1a0a src/adapters/recovery/recovery_stage_completion_executor.rs +9874f867812903f115975c37b70f6aa49881fc2ef0cd296d384b4975ff5e9a4a src/adapters/recovery/recovery_stage_completion_plan_error.rs +7f1aefecd01bccf42c5f010362d0896ad6cc57f45a1adad1abae909934c4da23 src/adapters/recovery/recovery_stage_completion_planner.rs +26b06531f84df92c4ef98f61977e0aa042f6304a9e7b0164dfd99cacb2d7249e src/adapters/recovery/recovery_stage_completion_pool.rs +836d19fde258c9785233a522c1b75b9af87ff98be1ce30dc911a9a227273904d src/adapters/recovery/recovery_stage_completion_receipt.rs +75ece2f479921eb9f854f9fda4e02345f2dce7b5ccd9fdf19e37faf6f0c6d351 src/adapters/recovery/recovery_stage_completion_request.rs +1916a6eef67f89c5493921def4ad873db9cd36cccae48c188bb15fcf5328c608 src/adapters/recovery/recovery_stage_completion_storage.rs +8cabc347b28dc1ff1de872b42611db0db8d2e00525f3a81f056fc160de27ee77 src/adapters/recovery/recovery_stage_completion_storage_error.rs +2ac6c3619573de6a2be32702c35404177010efae95b73ff8d7dfcba36607ceb2 src/adapters/recovery/recovery_stage_completion_target.rs +5c7fe2dd6af6eda12f3390ce15547ff2fc3c2c54345aedef4cd9c3da4452c73a src/adapters/recovery/recovery_stage_discard_error.rs +012768488712a249fa1030bdd4b690b24ea091ec232424e3cc1a9c05435c406f src/adapters/recovery/recovery_stage_discard_executor.rs +ee74cc0a72320cb41b9cbfd7e48a6a3722612d4fb4f1ffa09019318f5612f6e5 src/adapters/recovery/recovery_stage_discard_outcome.rs +3b365d24b82134e9c8ca9d5efa56b25d70e6ce177be11d9c8846524811666457 src/adapters/recovery/recovery_stage_discard_plan_error.rs +88ab9fe03f5a57f172e6c5d567c7513541f438b785ebf7fbf0eb08668cde8d95 src/adapters/recovery/recovery_stage_discard_planner.rs +101d4aa22d6399060db47b5ab8bef43a78b15aaf731196fea92812fcd8393440 src/adapters/recovery/recovery_stage_discard_reason.rs +1039de7aadc1d7884ac498e26d0207a6b21498fc333a6e199eb346f402e59f93 src/adapters/recovery/recovery_stage_discard_receipt.rs +0eb14a504f6713c927c1cb08bf0e9e89d28c526195d5d931173fbfd144e4c4e4 src/adapters/recovery/recovery_stage_discard_request.rs +0e7ba5e581779ecbea8b36bfb3406131ec0d61f3eae89df01b88d8f660edeec1 src/adapters/recovery/recovery_stage_discard_storage.rs +0adfc56dfc3bbda38f8dfb1449bdf37ca6bb0e269a56cb780dabd8d9c239e995 src/adapters/recovery/recovery_stage_discard_storage_error.rs +01147db2462033fac0d7ad48b1d5a927fe84306d42d1aecd29d1bf58812f4f10 src/adapters/recovery/recovery_stage_evidence.rs +c54df27d6794f765aa9f91d042b9f2d9bc9c01f5e6d905cf688f4eb0484e7c59 src/adapters/recovery/recovery_stage_fingerprint.rs +7f8c8f275f81876da1ab157b5f6f6af1b0b07f2e908765be6e3e9874ac118c05 src/adapters/recovery/recovery_stage_fingerprint_algorithm.rs +e61de7633b6fbb7d89e1f6e99bc1d3b029c0092a2ce3d7969217d981efecd8e0 src/adapters/recovery/recovery_stage_fingerprint_error.rs +c95b5de6fbcaa069438556004a5968daf0e3b9695071efc63beb74072bc471b7 src/adapters/recovery/recovery_stage_fingerprinter.rs +4b9c22c9b86f592c651dbf9cc54e881d2db989b3a55058b3be9b0722d3e53d0d src/adapters/recovery/recovery_stage_length.rs +f01251ad358d984205160c80a1dfd562755e429f9d27bfaa5214bbaf2d61c9ef src/adapters/recovery/recovery_stage_metadata.rs +618dcd466e0c4d2e85a8c2b08065ca8db489a2ffa8fdcc59412025c02c93558a src/adapters/recovery/recovery_stage_metadata_error.rs +1532576915fdc8b956756964f12a8817347921cdd51f12ad25748bcf34276c0e src/adapters/recovery/recovery_stage_parent.rs +3ae777fcdac0f50c383d193662f70a8c44d9aee778d864425c1ec27c2070a90d src/adapters/recovery/recovery_stage_pool_outcome.rs +69b27bf337f2e950ae73fab62b247fad185d662c4e5a73564cddd69e459b6add src/adapters/recovery/recovery_stage_synchronization_outcome.rs +5c9e05b008fd3b94b084a0dd07e2e2d744caf9bac9f9a96ca7544178a5bd3442 src/adapters/repository_initialization_storage.rs +05c281025d4b2182574111f78e7bb5987961067fa633b184fce94fa62a169dc8 src/adapters/retention.rs +dc72b40133b20f83b0da6abc404fdfcc4bf2f1f53f9d41429fe7fc0d9c9a9395 src/adapters/retention/admitted_manifest.rs +4053a8122bb05f51e7ed5489f11b2227a22f6fbed347de7685648f79466eae76 src/adapters/retention/admitted_root.rs +6f0f516fbe5bad96674d8678993fc4ae59894242167b35770d535bf199957350 src/adapters/retention/canonical_head.rs +2fd941e666a6ef588878adae501426648fc57344101de717ec0ca9592556316f src/adapters/retention/canonical_manifest.rs +25cdd93374fbaeb430315fa0e31846e2dced33c4b64346f75e54d3cc010a3ef9 src/adapters/retention/canonical_root.rs +8eceac5f961235b4dd7d0e578ac28e64972a32d4724d8579032a18a468e8f1e0 src/adapters/retention/checksummed_head.rs +00b0dc4f215edaea1dfde3e9ed4930693345c9f2ab12ee2233510825de9dd6f5 src/adapters/retention/closure_accounting.rs +484aba335fb2f622ccfc8892f1742840a47a2837d26268a18d599bac2f53b264 src/adapters/retention/closure_digest.rs +da0efdd595cb94467936ba1b8f32e7f7a54d4c6b433825c9746b705ece455639 src/adapters/retention/closure_error.rs +7c31be681c1e5b5dc26d7ca8b7061fbe021dc15af2f9e4781586b2226cd68e1e src/adapters/retention/closure_error_display.rs +cab725720394c643b856a251111ac9213953af3e9226d78b160872111533fdf5 src/adapters/retention/closure_member.rs +05bbb886d68ff6a021d1ee8ce04795109a80d6501bb64a2af496eef70562d081 src/adapters/retention/closure_profile_error.rs +ffe7de9d07072372cfde6362c2a7df69c24555161fb3439438c5f94b68c4949d src/adapters/retention/closure_verifier.rs +99a3ceaf8978d776152bc52f9d2229211ea8cd0df987f77c8e2933ea12a00a45 src/adapters/retention/disposition_execution.rs +cc99426019218350b0f0bd9a3ffee99ed24270d34d0800092e12b9279a425b0e src/adapters/retention/disposition_plan.rs +2ee3716e87205d16850af7715d517ecd94c1fc6e6346489216311630a70f704f src/adapters/retention/disposition_storage.rs +683231338cbd8ca4ab9d2de946f83cd0010fee117971abf91d66abdd419401c0 src/adapters/retention/durable_read_law_tests.rs +22cd655e2491a2d29a6b231d3be5190dec85cabe3f3f5995a4ae15899a41f152 src/adapters/retention/durable_view_law_tests.rs +d436f0e38c190f31024f23d11330a7fef20f241adae8393d7142dc54a922709e src/adapters/retention/filesystem_recovery_admission_tests.rs +d7920936977c48eed16e98e99c18c01a7a89b17d144d8b29a3184fd2d6092983 src/adapters/retention/filesystem_retention_anchor_order_prefix_tests.rs +06883b927dbd2789844117456a31ebb7b3c4f2ba338cc9db8ed6807418899946 src/adapters/retention/filesystem_retention_attempt.rs +b2fa7891d7895f29a32bbf2deb9efc38a4fcfcc36a48746794cc0d302a1b3b58 src/adapters/retention/filesystem_retention_attempt_tests.rs +75c6e4c075834cf616ac91e1329372ff3b3dba1041e80f80de4c718e21003f88 src/adapters/retention/filesystem_retention_authority.rs +80ac763a185ea70e61531636f4c0c1e76d80de0c00afc9417be1230a979437c8 src/adapters/retention/filesystem_retention_authority_error.rs +cab781b5b9cce155cbbf27ef8528edefeb252d0d13b8ce4296a12de07bfa0afb src/adapters/retention/filesystem_retention_body_prefix_tests.rs +4614452a6f7b52d9c15f5abbedee9e78fe1efaaff427361f6f752e6cbc0c0cc9 src/adapters/retention/filesystem_retention_capacity_tests.rs +804229d1d428a1fc51da10d6317f81d679c3bc29116f52f37d779b157af9d989 src/adapters/retention/filesystem_retention_catalog.rs +2633ea4af860ac75571186b13b08d3b56ee36cdada3adc8d94741ed20bb7fa2e src/adapters/retention/filesystem_retention_catalog_tests.rs +746d2836c5b02dded4b3dc32ef3e12b80e776c29ec93872282ff4cb9d1e01f53 src/adapters/retention/filesystem_retention_closure_admission.rs +b8866542b16daa9327b31e34fe1623a58ae971006d2bf6cb40a32e2b2435a78b src/adapters/retention/filesystem_retention_closure_prefix_tests.rs +a9da88ba98fd28ae3819b76609c1f673f6720de7b3eb380734083205d840fe5a src/adapters/retention/filesystem_retention_current.rs +39e26b9784fb88ed5fc0d0e872c11b1f87b92e0c7d314724af993e94c6e39145 src/adapters/retention/filesystem_retention_current_tests.rs +81c064a820fe6b075b04ab0a22d178e353bb301532e838ced0235e2e9c0c4abc src/adapters/retention/filesystem_retention_disposition.rs +4ea65e84d681a4332a0d5c88828422af4782389bf4f9145827c0dcc0d44954e9 src/adapters/retention/filesystem_retention_disposition_evidence.rs +32ce6e9fc3c0df5972b1d05c85fa9eecf01ce4a99661b8c1f32622aadae2857a src/adapters/retention/filesystem_retention_disposition_storage.rs +5f8e073759cf24cae5115bb405fac933245c1009cee31a148712fb6c7aea6061 src/adapters/retention/filesystem_retention_disposition_tests.rs +0d47612701b4fe6306938358c9017fd9834fa407bfbfd72fffc74155dc819236 src/adapters/retention/filesystem_retention_expectation_tests.rs +56c608e9bdfa1cc5e18d3450da68d43e8e9aa6d696cabac361140cb7d504abe8 src/adapters/retention/filesystem_retention_fifo_tests.rs +4f8a0006ddd8d1a2ea81bb3996fc23c15b516d47651a969bceabf8975472562e src/adapters/retention/filesystem_retention_forward_error_tests.rs +0c62b6e3683b5a5f203f96e8c3f139dd6b5e89ad914c378c84cb34d9ad199401 src/adapters/retention/filesystem_retention_framing_prefix_tests.rs +794d33d6b60f7b609b6bf1a1cc623c71e6331e9a6d5f310d2436694ba3003ee3 src/adapters/retention/filesystem_retention_generation_refusal_tests.rs +7cd6111fa4cf390d83a099506840af91c4ad7d21d1181db866fd4e82bf6be798 src/adapters/retention/filesystem_retention_incomplete_disposition_tests.rs +6c8f2e122931bdceb122b64ab964e048a5cf2d75548388d6d9455c33f239043c src/adapters/retention/filesystem_retention_member_tests.rs +64729527f3780782fc12d768925160b1c68a965faddbfa95cd287a7e2eed3dc6 src/adapters/retention/filesystem_retention_migration_completion_tests.rs +1b1045e530c12e971978f3f90c4e2020d1a23bf9ebb109eee5688aa0d7a146f5 src/adapters/retention/filesystem_retention_namespace.rs +6d6c5d5c8aae38f4446880050fbca4ef25b4f0851048403d6349c4683b08349c src/adapters/retention/filesystem_retention_namespace_tests.rs +ca3f894fba7daff16474fb9780b5b3d3ae33b1f10cc76e204fae33d085fa420b src/adapters/retention/filesystem_retention_observation_error_tests.rs +325f25bc617b088e0840f9f2b1c408fcd214388bee741419a466ebf9a4f2b4a5 src/adapters/retention/filesystem_retention_partial_anchor_tests.rs +4f3cb72314d320c8cf757d829ff49a152e8ed007928335fbbe3118ee7d7a48a3 src/adapters/retention/filesystem_retention_partial_entry_tests.rs +a88c8b62e45001a08bdcff52d9880e44e5336cc7d6f7af69d79e2ca07fa27b3a src/adapters/retention/filesystem_retention_partial_history_tests.rs +b26f29826633562b1af4d166bdb6543f799e7185f4456e90cd201a30662c5b88 src/adapters/retention/filesystem_retention_partial_integrity_tests.rs +167465cd75a9031e9d00d8b46d78cbdd578bf9dab3b3d330f5ce58bf70df2323 src/adapters/retention/filesystem_retention_partial_profile_tests.rs +85dcae2343e9c0b60a1542628d22263d274feff2d27ccac8b9fba1a862793190 src/adapters/retention/filesystem_retention_pool_name.rs +9f41482e2f5595553f9a46a9771a5f54f5bbd46bd229863823d819c4b746fa3c src/adapters/retention/filesystem_retention_publication_closure_tests.rs +700937554108edc710a6b822762cfbebda620f5ab5fcc1882b49a8dfa7caead1 src/adapters/retention/filesystem_retention_recovery.rs +ff355d124543e2abb2fee6bbcebc5a46f1108bcfeef464037215936dfbc6ea62 src/adapters/retention/filesystem_retention_recovery_closure_law_tests.rs +aa8e7a0677b213722cb1c5aa1583d9bb83da43a20c6028517449f5392e3a32c2 src/adapters/retention/filesystem_retention_recovery_closure_tests.rs +5828d3d0dd6f0b0792a272614d109ec1836c10521b31b4f5c791e0b9e0983c68 src/adapters/retention/filesystem_retention_recovery_directory_tests.rs +54057d98c0faabe278d670bbf2272e237cf883704a839a57351d2b8dd4048005 src/adapters/retention/filesystem_retention_recovery_discard_prefix_tests.rs +be665c6fd2c2f7e226df623e51b9f2b3c5ad26b4054fbb2a0f6affcedcf79e9a src/adapters/retention/filesystem_retention_recovery_effect_tests.rs +9025fcb346c6fe733a0ea7ab0bdf41ccb9ef8fc2f53906a37efa49330c37dbc0 src/adapters/retention/filesystem_retention_recovery_entry_set_tests.rs +b41e3766e1456a17b331554d12453b0887493406040a2a0b2f425e27ed47426a src/adapters/retention/filesystem_retention_recovery_error.rs +d23a05f6d68dc25ea8a205f8afc0481e25a45aaddd76cc46118393ac49d0e548 src/adapters/retention/filesystem_retention_recovery_head_binding_tests.rs +2ade54eb35f1d7cf786dce1fa72d15f35968fa1f742c894464905447b58fff64 src/adapters/retention/filesystem_retention_recovery_history_domain_tests.rs +1b460a3f51d0dd5ca3bfa1e1a3688f15071da7346a3cbabb5980bd124e6187d0 src/adapters/retention/filesystem_retention_recovery_history_tests.rs +d88cdc6cfe256ba58e606e415bd7219633912b090a5635eb4c28f168685f967c src/adapters/retention/filesystem_retention_recovery_identity_tests.rs +2ea29e9d5718aba378b760c6d8d99886e5bc90f83238ae3f7375a47b178fe0d1 src/adapters/retention/filesystem_retention_recovery_namespace_tests.rs +c28e208c90313db3d1d4627aed718b2739aeffce2370874de36403d09ca68e39 src/adapters/retention/filesystem_retention_recovery_observation.rs +4f70a3bbd402bbe2533d2642cdc0c2a20d61e38d02df9c8796e0172fbb517776 src/adapters/retention/filesystem_retention_recovery_policy.rs +2c5c79507bd6c1c402bb5113daf87656416ecfd0f5d30265575fca1100318237 src/adapters/retention/filesystem_retention_recovery_policy_tests.rs +6af3fe7b64bb514008943d354f43bf5fe32b5bbce7de817f0808683eec343975 src/adapters/retention/filesystem_retention_recovery_predecessor_tests.rs +955d94ed9587baacd97ce4c3f92d3da9051a1a04734b6232d94b30fdc05a989a src/adapters/retention/filesystem_retention_recovery_prefix_tests.rs +a5cbd49b30ae8bf34d1da58ee9e9edf9f3330a658b03ba2a8e294bb769843edc src/adapters/retention/filesystem_retention_recovery_roots.rs +7d2854da94e4a7a8fd6f718f2151346fd4470dfd400b1cdad7f83cddd5637d9e src/adapters/retention/filesystem_retention_recovery_storage_error_tests.rs +679cd9283323dcd768352248aba6d05da75b303a34ccf1270b68eceae51d9355 src/adapters/retention/filesystem_retention_recovery_tests.rs +dd723d6c9e7015527dd568c114ff164667a047e68bd514d9833d85f1327991f6 src/adapters/retention/filesystem_retention_refusal.rs +acf7521c0880b9f8adb3dabdee9d51e91c67c121408f7e8ced85904eddf30015 src/adapters/retention/filesystem_retention_short_count_tests.rs +a5664052b89d62b159ac0e16098d9b7651cdeb96d49d255c5bcd7276d9acfa70 src/adapters/retention/filesystem_retention_short_framing_tests.rs +8a2984780233185f702e33259100d34a1514e174eebe70d21dd69b8930eec700 src/adapters/retention/filesystem_retention_short_head_tests.rs +38524099b2996a4964bb82244155aec07859c4377f1432342ef82646dc7ab52d src/adapters/retention/filesystem_retention_short_history_tests.rs +2d02f10b80048b11b5e7309efff7cb38d2a067a4f3e1ac8595a4bcdf6001de85 src/adapters/retention/filesystem_retention_short_namespace_tests.rs +4a65e54801ca2016c759a9994a438df91ab24fe108395a1273eb08a796b39b17 src/adapters/retention/filesystem_retention_short_policy_tests.rs +17c4a6630228ddfc964ad2676a186984189a3f94365ef3145084e39d667e4207 src/adapters/retention/filesystem_retention_snapshot.rs +c54a972328891865ff0add5dcccfb31621b40c4219c94347e0b5118f3bcc25df src/adapters/retention/filesystem_retention_snapshot_coordinate_tests.rs +d22ad02427e3a3db6778e8c6cfad0b601aa2df7e527f9c47e8c29b71266ffba9 src/adapters/retention/filesystem_retention_snapshot_error.rs +38fb4fe75186bd1643064b65674b46e2c545885ee2727c954bfdd6ae338a40f3 src/adapters/retention/filesystem_retention_snapshot_error_tests.rs +54986675bd36fd49b34595c4c7d29327995b20b46e6a89a43786cfb68cf4ab55 src/adapters/retention/filesystem_retention_snapshot_identity_tests.rs +ed9a633dbac6171ddb3d2c0426d7b628c717baa41e444a4ba33d610405bada46 src/adapters/retention/filesystem_retention_snapshot_moving_error_tests.rs +d5cbc266d9b55b2d028bcd02c0c0f63b984d49c90a42d655bce1eeb4f34c60a2 src/adapters/retention/filesystem_retention_snapshot_pinning_tests.rs +11ac57fdef7d6d13fc483bbb8d7c7466ff0e3f26fb0f904f242cdea3ae98c215 src/adapters/retention/filesystem_retention_snapshot_tests.rs +6c640c1d717a2b9df42fa0fd4f426d415d283188e0ec30c8ca2b6c8254c580b8 src/adapters/retention/filesystem_retention_stage.rs +075e51939dac2d674227d41e5d3ea93dc696fa59293e1f1616fe5298e793aad5 src/adapters/retention/filesystem_retention_storage.rs +a158be7e43e1ba194224a78a544184f90d755f80c48aa1552c5c694c7b156600 src/adapters/retention/filesystem_retention_storage_tests.rs +4cbdaa9e8833127d58f1bc7264c3b4637867d4317fe91d30483568c122b58fa6 src/adapters/retention/filesystem_retention_successor_tests.rs +fa03c7d94354b4ecc599f231a87b26f3a379163137dcd34aa1be10fa127d28a0 src/adapters/retention/filesystem_retention_test_fixture.rs +7644fc8699000192b4959a31b2045c5bb54bdf8e5b1a9dad096e0320483f1479 src/adapters/retention/filesystem_retention_verification.rs +892f9612343a75a60a1c7146567cf14ac2cf1d10c0ac79a8b513f64bc77be489 src/adapters/retention/filesystem_verification_law_tests.rs +f45f42c4850d0d85bd059b0eb474468d2c36710434800ad8a6a88f25e67b4618 src/adapters/retention/filesystem_version_two_admission_tests.rs +ef898ce81a0e9cb6eb595e3350c80b53fde8e73b85652e5e8796f0b3d5ddfa6b src/adapters/retention/head_decode_error.rs +bd6d87b589474f370322798baa97236f4f203b506c9d4535e76a64ef0acab161 src/adapters/retention/head_decode_error_display.rs +7a8ee64603e28c3072b5de1f889e7860d6d300316c690d58262a091168d7b4f0 src/adapters/retention/head_decoder.rs +9cfea8ab26c787f73b1231bbaf446dd262ffd1c0f430352f060a6db0cc0a721d src/adapters/retention/head_encoder.rs +fb2916fecad2def74888c3e04c16e13dbc0d9a659cd82a5a6d5195135da68c73 src/adapters/retention/manifest_decode_error.rs +827cfb9480f208612275fe30f5598b36467f48b34c925c477e5eec7a2d92630e src/adapters/retention/manifest_decode_error_display.rs +c6ddc364ac5e4c218993475972441ecc400e827f960bd1701200983a406766cc src/adapters/retention/manifest_decoder.rs +0b226e7d0da0ea61fa5bf23a169e90e1de02d454eb9b8f63a6e3fdb708e15610 src/adapters/retention/manifest_encode_error.rs +5252d69b9bda08f3158e2ee1c6e200f3133c1447468d153b4138412debddde2a src/adapters/retention/manifest_encoder.rs +70c7c85a1e2ee71bf1cfc20e48e2643041588157ba9cde54a6aa14cbf7ce24a2 src/adapters/retention/manifest_entry_decoder.rs +8b28e19c15833935f26aa73dc1a3e69e3a3088be99f9639c9bd17290eb7552a1 src/adapters/retention/manifest_entry_update.rs +58b3955e50a8b18936ec8484830a33e5f870e2171da7e17724934fd4afa2592e src/adapters/retention/manifest_field_decoder.rs +bb279030f885a6eb59a5514acd1e774a6dbd78982acc94538c3ba7ee1579da95 src/adapters/retention/manifest_header_decoder.rs +540b80f1f83006a24f805339d1bbeccaadefb288c3f5be28de7a444336f8dbd3 src/adapters/retention/manifest_integrity.rs +06ef4b0f38c218a958e28df62b92c876e56ffcce72432f69b2d5efc0893e264e src/adapters/retention/manifest_semantic_header.rs +942add162426887b71a0dd3cf7f3cc6fe6f7c8086e641cc9eca3837198c5cfb9 src/adapters/retention/namespace_admission.rs +22cfa075a671e69c1363d37a9ea1f8567a460cec5b93c0318cba9d8d18777b62 src/adapters/retention/prepared_publication.rs +7438fedd0008682874f5e09863c656d7d4ac6e3f52478ba2d75443baae93671c src/adapters/retention/publication_error.rs +c388e676d8be8359f8258bed74cc32afe6fbbf42430d53ec995c0f7986c396b6 src/adapters/retention/publication_execution.rs +5e24000c823ade29c6c2f0a9fbdb5fec8811d1e4d280ed4172ff94f5586f7066 src/adapters/retention/publication_outcome.rs +17eb3173aec18232a0872bc37380afc9eec2799da5e1bbb87e2ace441d4c67f6 src/adapters/retention/publication_phase.rs +6d5214d5d321d58ffcce3c6db9d1e4ec77f0d253aee7e77b5eb4ab2e5f221f01 src/adapters/retention/publication_preparation.rs +e53d3dd528c71e6ebd0b0e3bdb5abafad3ada88c35b65f765b86270cf0697035 src/adapters/retention/publication_preparation_error.rs +e5383c70b7b7a48213ef7edb8d3181388418373bf774197841a400bdb84cf74b src/adapters/retention/publication_receipt.rs +44fda76755f5a8f3b825c4fe4b094fe4adefc374beea7a0fb8a45389e319cc3f src/adapters/retention/publication_storage.rs +c497276068964af10f1a49c36e1df9f6bfa2cb95f0757eb859f90e85fa219b69 src/adapters/retention/reader_attempt_limit.rs +6861d7353eef25edb7031bf1e94b1e290acd5d805971ebb2e608b27fb6716a2f src/adapters/retention/reader_fence.rs +a5a46c2fca7f2091a08b989b00baacbf1be112d5078f95e13f4aaf3317b8ef31 src/adapters/retention/reader_fence_tests.rs +1b4149125b82f6e354d2c20fd2e19de5f0ac35bbd17eeb776b020e30787575c3 src/adapters/retention/reader_platform_law_tests.rs +1e8936003d76fe0c09c3aa53715080b32226640ebd4436b75a794fbb0a480fb5 src/adapters/retention/recovery_evidence.rs +369d5a7dcd0bde2c63552bfc777e1367b3a27a469864aa531abbdb5b58a5ddb4 src/adapters/retention/recovery_execution.rs +0ed3d7d68f426feaff03bbb62e1c0b27e3c4222c167b076544015042607d2004 src/adapters/retention/recovery_execution_tests.rs +ae4221d54aabe0d83af96671b0f5bfe72e6de3a403d16745af3a6a42cc321fee src/adapters/retention/recovery_head_length_tests.rs +b10b66ebd1ba7eadf569a29c073325a405709d2528bc4d5bf5992328fc6d9cf1 src/adapters/retention/recovery_manifest_entries.rs +d910bad3d34dbbabfe9854729b044ff79df4fab2c33f776e504f57305d83a3f5 src/adapters/retention/recovery_plan.rs +2a568a1d419aa57b2edde5740f7965e9110d1189d3d4ca3b3d25f3385ce4e153 src/adapters/retention/recovery_planner.rs +d32c4415297a9a5e26a61ad209a9dbf03e262d9afdaa23fd4a8690852cd47eab src/adapters/retention/recovery_planner_tests.rs +1e2b64ea1ceec74fc442bb07d2f2817528cd26f28aaf3ab8e3b7f76ebd2c19fb src/adapters/retention/recovery_refusal.rs +68df5ce47c1ba5b72fe1c41c50c9303dfb2814e5b69e91fd55e443d7130eb4cd src/adapters/retention/recovery_stage_assessment.rs +676611ae6aca7aa9cf86c5f34c2ea4eee3cae72409fac248a1410bcef2bf3255 src/adapters/retention/recovery_storage.rs +963aeea24b5956979d162e8742d0db2ad1029f97bf1f6f5e35464725373cff4c src/adapters/retention/retention_model_refusal.rs +694dc53425d1e6520df27ff4ce6ea26fc2aa14d8c26a3e332542fdc3dc8cab19 src/adapters/retention/retention_model_tests.rs +c8229f25e9531fc8497778266978abc863ead75d987d87c9800b7584fc5511da src/adapters/retention/retention_record_refusal.rs +dba87dc275cc0915a09afad5e7396bb7ff32fb3892ceb4e0b5688ae0cda044d9 src/adapters/retention/retention_storage_error.rs +53b7fad8a4c8a82b210040ceb887dafe2c5e59a370b511ff99d48a1cad38dfb6 src/adapters/retention/retention_storage_error_law_tests.rs +bf4fb7de0c4d7a57d8583b9538ccd2265d02d191f069b8b80accafca39763038 src/adapters/retention/retention_storage_progress.rs +c6969d373247933cbd5eb89dad07655efe204df7faf29ec2cea2fba5ce60ba3e src/adapters/retention/retention_view_collector.rs +c29eb2d6d8963d2bef18e6bb40f3a92510a7b063ed6bd5d5c54548d685f3c3b0 src/adapters/retention/retention_view_collector_tests.rs +46cf1c95f2f0721108c239a9f177d443835aac2f0ebb3c4e58795d638e18af2f src/adapters/retention/retention_view_coordinate_law_tests.rs +1bdf384f10d6fe16825bd51f0bc2afbfa04812db114fa445c50fe0d0c66dda8c src/adapters/retention/root_anchor_decoder.rs +60b60bef6970957cda70a301cff0b780cbbd8c806b7dbbeb36f8fc864fe88992 src/adapters/retention/root_anchor_order_prefix.rs +78a5434227217e0f8ba91d95276bd7e4a5718d3d6f50b75230f030bef6ae98f5 src/adapters/retention/root_anchor_prefix.rs +26c05bff0e98c39c52dfe2231416a8ee71336a767af49a628df942091296e16f src/adapters/retention/root_decode_error.rs +5952e90e80fd499dd9ff5016420c18cbe5e9213027b80e4eb8283ba4d8d731ca src/adapters/retention/root_decode_error_display.rs +500081f216652ac68efa44dd6486a3cee1e22cf5542d349ba4e56e345f58616b src/adapters/retention/root_decoder.rs +0f4718e8259106cc9f6a55ece8cc29190a86d5e6d3ee20cd9325a57c3290db70 src/adapters/retention/root_encode_error.rs +703b439f8349c0efd22043d8ad2de4a79cf149c895df61aba4dadbb51f890f2e src/adapters/retention/root_encoder.rs +7555d28f1e309e744302a45568af091c2250721fd2a293232cde91a7a1bc4632 src/adapters/retention/root_field_decoder.rs +fd05cdb6fb6b6231b9c9579447daec8c1e130915423eb44bd887f382b5508302 src/adapters/retention/root_header_decoder.rs +8158354b526dc4bb20dff23c6c0e5cbd73fe6b82f25f5febd3683e6dc82859e6 src/adapters/retention/root_integrity.rs +84fbb0b3229e0d702ec29202b763bbd806dfd5b85a4fb7bd9c3cc56b8d7621a1 src/adapters/retention/root_semantic_header.rs +e7194fbf474ed6b3a22aecf8881b8b4cc672cf5fd63d4a4002bc8af182ac5a67 src/adapters/retention/root_verification.rs +82b739ac0ef7a1956392ce9d54f1da14d6ad8e167eb604084e9307ae735ffc94 src/adapters/retention/selected_root_refusal.rs +ae78c32265ed3ca7ebb6e4295c8d24f2342415aca99064af53d389aa6000bdc7 src/adapters/retention/stage_closure_limit_admission.rs +392a87fe74dbbf8bdf66d2d56ff3d602b83e33727d14eb1628d2a5d7492f579a src/adapters/retention/stage_fixed_field_admission.rs +854d7d2cda2d9db17b3ecb08392306f09991c040a15653ad2dae8d2df5d6985a src/adapters/retention/stage_framing_prefix.rs +45f4d36acd6e187a8587f67f09bf192a98e4d6d21091af62ff1d85cd63418855 src/adapters/retention/stage_generation_admission.rs +42c32d30f16d869530b250c31f4e99d784dd29c129765256ada6f619e62bd700 src/adapters/retention/stage_history_admission.rs +f7cbf7d28fe66f2a6064b5ccf366421f3e7aafe70c939fe06ecb61cd0f35e301 src/adapters/retention/stage_prefix_admission.rs +4479f8094cc8a7a2d748d159201d5e27bd23b2fc901cd0e7a17e4701c863a39d src/adapters/retention/stage_record_integrity.rs +74d0cdade0195f79f9fced29bb286ae330bd70de5fddc5adbdce4711576286e1 src/adapters/retention/stage_root_policy_admission.rs +a9b702fb631fe33c4e9900c81913a8c00d625ef030a30111eeedf5831d27e777 src/adapters/retention/successor_manifest.rs +46a505d0960a8ed87bf2339603f5815d035aee20d10648d201186ef865bc9f0f src/adapters/retention/transition_disposition.rs +7aa9fcb7f27e53366f13d2e52f083443a372f2d62c3fc6a4086c30ec0e6641f4 src/adapters/retention/transition_error.rs +9db1e38b5017eee140a23bcef50968a455841cdfdbdec73e8703f89d1c5b7fe8 src/adapters/retention/transition_planner.rs +8b9632e374ee30baef7b417c417fbbdc1cb39bdc0556b315c1bc76a6304a8842 src/adapters/retention/transition_preflight.rs +b49c601cf353aa79f7568fc04bac42cd878b0927a256b2c60a933b39b16a376e src/adapters/retention/transition_preflight_error.rs +f1d1d21e8453e9badd7e3268a3b02dec2ae839f3d1c8883c3bbcb048a3a141cc src/adapters/retention/transition_readiness.rs +3b85329149dafd3c71e909103c2b32dc237fc68b1cc9bcd2ff9910da7e6751f2 src/adapters/retention/verification_namespace_kind_tests.rs +b6c118d2b124c1a4a48702bbcaa13ad0c63e135d96025ac66ffe0f97ead04c4c src/adapters/retention/verification_namespace_law_tests.rs +64bc9c349ba07e2aa1974276bdcace95bfc9da24ff8a32bfbf290631706abaad src/adapters/retention/verification_observation_error.rs +783029daf4de0b0e6bb595a2623d4e81ac4e3c9f83cc23732345abf8bd42cac9 src/adapters/retention/verification_root_kind_tests.rs +75ccaeca2e37ca9ffc01ad9d4d06556e6d4036859ea2733b0fcf57f357d27e6b src/adapters/retention/verification_selection_law_tests.rs +052d08c4285849aab89b47616bb7463b93fe621f1bb2c589e689633a33afbf55 src/adapters/retention/verification_store_admission_tests.rs +ad5e2116324b86fa579eb55b8682f921a98397c883626a502aa5075b1d39b8d7 src/adapters/retention/verification_unsupported_depth_tests.rs +3ac206d8b31c8ff61565399a323edd02364787e6d012a50ad186e80f4b78bc25 src/adapters/retention/verification_view_collector.rs +ef728990d0b87b5375ba5ce27f04c53ad0cd071e992d895ad8951cd5a4d3e781 src/adapters/retention/verified_closure.rs +f7cd0606c80bfe64490366e9c4fad0acb2a1659bdba0a6686759a710bb41fac1 src/adapters/sealed_segment.rs +c6346ab70bacc120a3280af0fdec8b0b5b2a0810dd02b7d5bbd476a905f25163 src/adapters/segment_digest_builder.rs +76325a3851f3b88071962276f2174b96367dabcfaf1afc49d09742cabd14e314 src/adapters/segment_header.rs +97af7590e8060c250aceac15e5574208f2d0fd21bb24eaf455747060de99c012 src/adapters/segment_header_admission.rs +d917d848412821188b3aebf4c5d0263eaa4d3835014ad9e0acdff1b982644c44 src/adapters/segment_header_decoder.rs +406745c5eb7a64fcdf4c100afcc89c83350616cffc8d1fd3cd2186c4270ffba9 src/adapters/segment_header_encoding.rs +9ebf1493e50ea6a865b2a877dbfe3c292f05b54606e5d0b9776dfe847a2f11ee src/adapters/segment_header_error.rs +90a407a258162dc1f2b9ad8ec05a881f3754b2e51b1cc90196fd763a67098de8 src/adapters/segment_header_error_display.rs +469287fc77e538bad95b921675d8c8437a151d193049fd61f65e136c4842e662 src/adapters/segment_identity_index.rs +c1eab10ff2cb75f793d0a28456881136bd9b30d6f77752019d04affb8bf8fc32 src/adapters/segment_publication.rs +c893e500a4e3417c16ed3cdc245b1773b588440a92e6deb71314c72ec2fa124f src/adapters/segment_publication_error.rs +dd7f48575b443663350e97b4d50db832c7997726c6c5a1e819758268397ef256 src/adapters/segment_read_error.rs +f96aac475f16cd0afc1c52ba4d595f8920c618f0a15ce7ecaa98f4509e6c5f63 src/adapters/segment_read_error_display.rs +b4ec2f5b7501cea9259a0a2bfdf3e199ecfd2b2bc82470bfc83e6477ede4a3a1 src/adapters/segment_read_policy.rs +953b661f5d1b4ce718a9b747f31cc5b3736914f665d9b089a14f958bd235d674 src/adapters/segment_reader.rs +da4c629ede5aee3456722811446969b917ae18eb015513e95ca9f8039dfbb7d7 src/adapters/segment_record_admission.rs +072daab0ae7211909f7c256df351459d852ae486c162b6085e123f6fcaa955de src/adapters/segment_record_admission_error.rs +a759a0672ba01f792b1750114580c17c94c11b208a241260f366e555b8d5d4f1 src/adapters/segment_record_admission_error_display.rs +918ddb08df74b34ec4e9c2e66f381e8889fa1428b666b40138c5789491d5d496 src/adapters/segment_record_checksum.rs +d836b1324a649d2b71ef5d0bd708144e71e9cad8ec05ad0ebdab7cfae0dbf29d src/adapters/segment_record_cursor.rs +d41769e5a675f11ca59f78f29c88d5449e5c2ba91a464416c9ff769f8a66ad84 src/adapters/segment_record_cursor_decode.rs +9d566f5f185e7b417685fe1906338b1fdfbce23abc66a778c65c9be12e9cabc4 src/adapters/segment_record_decode_error.rs +aebeb7e5eca6068ce804fdeb8a38cf4000f0af813d76655a5c8d9f612531b26a src/adapters/segment_record_decode_error_display.rs +fdd3a4411d451490c8920426550acd6e5e7bbde9261c4b1caee80d3e197dce1b src/adapters/segment_record_decoder.rs +ed00e7e1f912021ca099a11cbdbe88df1469b5e4fa8e583c427ed4ae6c619390 src/adapters/segment_record_header.rs +b4848c33df40695dc6ae2f9311049e1d502be917c4d324a1c2866f459bd62df6 src/adapters/segment_record_header_admission.rs +4e2f2444014e9b58476369615fed0e97bda07877886e08e0e4e8ceea2668c35a src/adapters/segment_record_header_decoder.rs +cd32fb84478934d7270750e83aa7455f12255eb54f14432d6ac702eb3357cda2 src/adapters/segment_record_header_encoding.rs +1fba64d670ca8922f2e881aaef715b3ead4d0a155b888ff3f62c411fe69b3ff7 src/adapters/segment_record_header_error.rs +809c45dbcec4d09b9c0aab6eabe6e04fae9905e39f24e80cfac39ab248c0dc2c src/adapters/segment_record_header_error_display.rs +2d3c28eb0e3b36f5e5243f55bc0ca8170f371b904947290aab2eabdccf3bed5c src/adapters/segment_record_header_tests.rs +3878c23f75cd025596d3ca44e3b10884c6002e34f627b6113da043fb7e535bf9 src/adapters/segment_record_identity.rs +0da95c9275107e25820ad9f7dad1cb3e56dd5ef53bd50331c44dbda054e5f335 src/adapters/segment_record_identity_admission.rs +2e3aede954104e8c0219ae09c0a47f73df866cee550ad72d8eb3388293e1c48b src/adapters/segment_record_identity_encoding.rs +e12ce958c64ebc8804f527e6c0778120cb6fe8bac9e60f599f7b3e64fa00cacb src/adapters/segment_record_kind.rs +0387d0a443824405847793f08a179993e6d096469a049c93af7c8a571eaeeb11 src/adapters/segment_record_length.rs +52adb4f8ba2a9c7e2366b7838e79356335d436ad113dd2defa98e90e72345f03 src/adapters/segment_record_limit.rs +a2b200a7fe067e2ed525fad82d4f48fc5641d3fa85f78f810e4f3d2d9a934686 src/adapters/segment_record_payload_length.rs +5d1b083132a35800611fb923b379f0b0ffc4f2c74516784ea54e1b91aec04bb8 src/adapters/segment_record_verification.rs +77a6691eb9393a4bd688eb4a22151c676f55436733e4b7dba3c3abf09f9a7137 src/adapters/segment_records.rs +10b463cc26e7b2878560428016b26ed09d4fb14a38074e89ec10c634b96e2963 src/adapters/segment_seal.rs +1b8674c7b206db9dd7903645ec58e7555aabfba5253d19bc3c41aa8084b3adb2 src/adapters/segment_seal_admission.rs +f754a848a9fb8d97f8ad68a740d2bb96f77b73285ea6a8a35547a9bbddb690c2 src/adapters/segment_seal_builder.rs +e2745730f57fd494eabda92d0399fc1d8be8669dc4547ef5628e8a9e7781b67e src/adapters/segment_seal_decoder.rs +7d6e2a669a1d8ab8c8eae1165e4641778a956ca1101b8d1586fbaa295436dd4c src/adapters/segment_seal_encoding.rs +1194dfa672487086cfaf98443652833f9ae7923d857beafb3631d1c1b28c9917 src/adapters/segment_seal_envelope.rs +5b64055f1b4cc0b4778bc05bc0cf1040a93287bb37fe851234a603117e704a88 src/adapters/segment_seal_envelope_admission.rs +92e3cbacda703a5c8a64b6b8a25a0276bf567a57da91bf01d412147be122d03e src/adapters/segment_seal_error.rs +6189e570ef2f92666f6988685026913cdaf209cadbb454fa52c0a760dce15b8d src/adapters/segment_seal_error_display.rs +d6e99114e3cabf5a13b09b2b0a7d8cf106e2406ec11a07692307ba411a53f1d2 src/adapters/segment_seal_hash.rs +2125ad02e64e7b48a3881ffc556ac7713b532349f927c42e31ac63a58c4ce531 src/adapters/segment_stage.rs +63bea9188e2c259049fbe3be7b1a5d828c9b18fc6cacba5c7c50cf4abacaae0a src/adapters/segment_stage_create_error.rs +10a696aea3c48ad9f19695671ebe37e5c19dae619e10d82609f01deb2579f0c2 src/adapters/segment_stage_create_error_display.rs +e1ccf272922f5321c5ae9e64b70ff8a20e1432e22d7911b3ca247c360e767f31 src/adapters/segment_stage_observer.rs +585bc09fee95c4fce29055cc13c35a8699f8d84f3b54af38d2e2d1d857a3cc90 src/adapters/segment_stage_write.rs +35aae77e49be1d610ab2d3a7630ea091fdfcd1b3af2241e555fd5c4c361345d6 src/adapters/segment_verification.rs +c33fc180770255f9117b7e681b722e7623e26bd110293968679023f186999668 src/adapters/segment_write_error.rs +c840b728bc1e0a0a47704f23437c6d4edf05781354895de16ff59680c1b4530a src/adapters/segment_write_error_display.rs +ca3d138730df71845bbcfe30dbf14ed41c41f5641e82300226da3ace0af0241f src/adapters/segment_write_phase.rs +0eb6303b2fa4042126bc35d7f01fe2b1016e1eb46c14a54522c09c3cfee08ea2 src/adapters/staged_segment.rs +f25427ef25d2d3593d5c5d3c4d078356951118714a0d764968d85c2a2ad20418 src/adapters/storage_profile_id_text.rs +433deac1a893b69f7c727690e06c5cb524cd73d34425d80aa50a65b686cebaf0 src/adapters/storage_profile_id_text_error.rs +944dfb927827e7b841fe8ac7949f6db76b21ccfb7798378451b865a1559dd772 src/adapters/store_initialization.rs +2898563e6edcf9f351478a6a30fa07da2795fde79d418373ad36dd91f4e2265c src/adapters/store_initialization_error.rs +e757d3fd33ea398d3dd66fb1e6a677f35fef1a43afc8c147b09e2bb1d1c18f8a src/adapters/store_initialization_phase.rs +2cb2d0f1d164074f7be4600b413aa69cad05ef6c65c526effe11e0e8ce8bbb4c src/adapters/store_initialization_receipt.rs +74b05d388cf445c71dbe1f9682a4e16f942551cd36a382929c996545ed82a3ea src/adapters/store_initialization_storage.rs +c4e2a5374472e1507049977a0483f7fc8b20e76a164ac3620d428e544d0df21f src/adapters/store_migration.rs +7f1a290223209022064efe89dc0fc1a9af2d1ee10dd531d6dff1b7c5c5bdddd3 src/adapters/store_migration/admitted_format_marker.rs +6a2a1683105d7cf08b2d75f6fee2e7a467ca4c925f5a95a3e3429dd787c9c0ca src/adapters/store_migration/admitted_migration_intent.rs +0a88390e1a65f9510655d58e7fdaf2ca441daebfa57e0e2e173e52ab90400a76 src/adapters/store_migration/admitted_migration_receipt.rs +5c2d20ee8658807ba9b2453a0cd10a92897922aa2a6e635be7e7dc2885ec2b80 src/adapters/store_migration/canonical_format_marker.rs +1b46a10379c6627ce382d9d230d49fc8cb46ec70e6b38b717cdad4ef3abc9200 src/adapters/store_migration/canonical_migration_intent.rs +7d7374ed9d496f0862077dd101aff426622c328d9976687f1d5ae82de00311af src/adapters/store_migration/canonical_migration_receipt.rs +aa72fbd44d34d6420a5fca3a6eb8367dd25732ac8c41d4a6a884faeeea2b1a0f src/adapters/store_migration/empty_disposition_set_digest.rs +59d99b3570062eb2231936337a16447a514154b432480d2138515850e4d80c1d src/adapters/store_migration/filesystem_inventory_catalog_errors.rs +e3f2dcd5bf1c2f573cf190b02316db5f70c4164aacae1f6dfb45f024de2fdab3 src/adapters/store_migration/filesystem_inventory_catalogs.rs +ec7c3455bed3351843fdd307b480f3ee66753f85a6c01f479b121fb13d7c68b6 src/adapters/store_migration/filesystem_inventory_catalogs_refusal_tests.rs +05d879fab898721eccc7582c24e2829c8858a230a77051f31c1ebcaca37f9ac6 src/adapters/store_migration/filesystem_inventory_catalogs_test_fixture.rs +57b3a7736f3b811c3fd854e8667e851e22b26cc39dd13153340bb76b107a9bab src/adapters/store_migration/filesystem_inventory_catalogs_tests.rs +37c445bfac065b58f48bdc16e73801622a9778d4929a11a5ccfd7d61fb21b570 src/adapters/store_migration/filesystem_inventory_directory.rs +a8e9c6ebff2abb5dea1bb9139c9e97069652c116cf472c667d1df4d8dd0b8785 src/adapters/store_migration/filesystem_inventory_error.rs +65c3ce6ec0654079e9cae83e7badce4c353bbbc90d2962feb716f4ef09838153 src/adapters/store_migration/filesystem_inventory_error_display.rs +9dc3777d1293f4f0ba92edf9e3c738d692ebb54fb68e5c1ee1151e88bfd475ac src/adapters/store_migration/filesystem_inventory_file.rs +0d6523ff9dee5c5513516d74c8e4f5e451b18137b4050ec88094999de16fc1b8 src/adapters/store_migration/filesystem_inventory_file_tests.rs +e9da171e8898df5b2a7bbecda39b38cf6eacde32c02e952f21638b5fe9ae6e48 src/adapters/store_migration/filesystem_inventory_names.rs +6fea24b7fb1be866b1f78496a19eb828407b0eb8426ced5989f6f892069b1d2f src/adapters/store_migration/filesystem_inventory_names_tests.rs +af8867af2619a1d8611ab7189ef9b72d48800df2d2d297a71f1c597ec0c71429 src/adapters/store_migration/filesystem_inventory_reader.rs +2870c72692eb71176cf715464736e9087fe4a90e074000fbafa54ff4ea82a222 src/adapters/store_migration/filesystem_inventory_reader_tests.rs +cf4d328aec194e400894e4200bbe02b76bb275a8508df3a6223e4d9068d7243f src/adapters/store_migration/filesystem_inventory_segments.rs +e59bc03088e43860475927dffc16d7ae093c019cc32419d2d21810daf1116906 src/adapters/store_migration/filesystem_inventory_segments_refusal_tests.rs +c63e2524e098291fb834cad1da539bf0d8258dd3692d4272168471ad730d0a3e src/adapters/store_migration/filesystem_inventory_segments_test_fixture.rs +b252f3b3af4572af0fa012172039426fd50f819869e31c29874d28844d9e9827 src/adapters/store_migration/filesystem_inventory_segments_tests.rs +becc5961f3b70b17484cd11f75c8ac28dacdeda39909763cf2121d84586b2d9f src/adapters/store_migration/filesystem_migration_authority.rs +700b0bcd0fb09609025ab8c81bdbd3c1e8814ea34136aed190eb76489eb48ad1 src/adapters/store_migration/filesystem_migration_authority_error.rs +cb809f155e4a343fb941f645b19df1e73876dd6bb6816ca48a42a1194e7e4e53 src/adapters/store_migration/filesystem_migration_authority_error_display.rs +96f5bcfc6ec5794b37dbde54135f7f245b723d7429a582cb812a415ce86dbfab src/adapters/store_migration/filesystem_migration_authority_tests.rs +2ed2039fd0b17c91c881366ba68ac5c8a6bd03816fa1776375cdf59089ddd81d src/adapters/store_migration/filesystem_migration_authority_validation.rs +14d9021e102f31f98c301623b1c28795194afd5ae34cd82372c4292c9e88880f src/adapters/store_migration/filesystem_migration_compatibility_tests.rs +df119712b5988eb58fb3ec3c514ae47dff57b514af5e9fef9adad4e858f4c2ee src/adapters/store_migration/filesystem_migration_current_recovery_tests.rs +bf16d43e60a4ac77ad08f1136bb3c10a7c2395cc19c53d38b607e8adad53844b src/adapters/store_migration/filesystem_migration_fixed_artifact.rs +0ce36d87c1981d3089d4e9383be6cdab76d1fee1ef1b645be06e0c0c149e2c27 src/adapters/store_migration/filesystem_migration_namespace.rs +4fdf311c2401659f6687909956160cee547aab90f96509b4fcc1602b4abdb55f src/adapters/store_migration/filesystem_migration_namespace_directory.rs +061595aef384e50939bd09fc956bdd9bf5b8bd56e6b138b19c9f607e6c24f959 src/adapters/store_migration/filesystem_migration_pair_admission_tests.rs +e5fd47ef88d722674dc8094707182748f032e62d014e60ab3fd8b2c0656f8883 src/adapters/store_migration/filesystem_migration_reader_fence.rs +aa459bb77d58270e6d929451749ea1f6242333aa503781262b05c5bb198cb6a6 src/adapters/store_migration/filesystem_migration_receipt_evidence_tests.rs +c82fe5278812680cb2442b480926d8bf4c4c882703be3bd3ec00c23e1f1390d9 src/adapters/store_migration/filesystem_migration_recovery.rs +7c7b14ad9814c66abf131efd24e1da19c4c7783708c7685eeb8f81af9f74a4d5 src/adapters/store_migration/filesystem_migration_recovery_refusal.rs +70ab9e14230fb8656bff92e59073c39edad05607543778f651815ca521f55754 src/adapters/store_migration/filesystem_migration_recovery_tests.rs +ebc49c661ddab3887966e3f5417dee41cae2402b8d6975a29ccc6b4c2471c3cd src/adapters/store_migration/filesystem_migration_recovery_truncation_tests.rs +020ccb3dee631c7365c37c49757d0baf5e78ed6e0d35f5d82e109c0ad7fb6307 src/adapters/store_migration/filesystem_migration_remount_tests.rs +31de3619fc637f88578c13c94c3988ea358f86741ab83d398542206fb83ebdfa src/adapters/store_migration/filesystem_migration_repository_tasks.rs +260aaea0e6cdb77d68d14ca3ea4de7044b7b46260b34cabde9dbc995bbc280ca src/adapters/store_migration/filesystem_migration_residue.rs +714b71296625d36f3b90e3321a7ccf414acb8e31cc627984085b850b31b79708 src/adapters/store_migration/filesystem_migration_residue_kind_tests.rs +c78e2b51072daa5583e841e8fdceda07dc6a3257deaeaca65a6b556df5e430be src/adapters/store_migration/filesystem_migration_restart_namespace_tests.rs +2a2e2987c731d5e311d2a11633ed2f0eccd3c9d759abea67322a8adaf688c90a src/adapters/store_migration/filesystem_migration_restart_order_tests.rs +36493a9ee5db1864a862a5d64249228741663fd81ec18a69d31d40cbf82d2bc3 src/adapters/store_migration/filesystem_migration_restart_pair_tests.rs +6ec94cd29d590e96760cf68ad977a2f85756bec3ddc4e875111cc2e4ba5ada6f src/adapters/store_migration/filesystem_migration_restart_pool_tests.rs +87f2771efa04614848949d617c247c2c478030282808a74a495d6dab26fc7209 src/adapters/store_migration/filesystem_migration_restart_record_tests.rs +8eb8bf88a4a580e83bed62d5d92675b20bf1ad9a94b675fe0e52d892dcb7a5bb src/adapters/store_migration/filesystem_migration_restart_root_tests.rs +c4f9d8a8f2bf96be5db104c427474ac2bd8f2d94dd850af5bfc72cba5076ec1b src/adapters/store_migration/filesystem_migration_restart_test_fixture.rs +5ee40d985d3aa944a6d64d671bdd62f20bf082a71d0a8ea0ba97d94b0096df94 src/adapters/store_migration/filesystem_migration_storage.rs +aab0da3cb9f6c4344d8278b2fe9235c1b3f83af5886422014729e319bb2c743e src/adapters/store_migration/filesystem_migration_storage_tests.rs +11593ba5ef53039f4f1f7f2ecfc932014591f05d826f53e2cc21701226e69f90 src/adapters/store_migration/filesystem_migration_test_fixture.rs +903fef2138b83573db5a910e253f510c77c7975092c7888d4dbe7820ec6f198c src/adapters/store_migration/format_definition_digest.rs +e3d296a444f271ceb6b67d20a388919a9245ca24f9fc243bf65e2649950a8027 src/adapters/store_migration/format_marker_decode_error.rs +2495929dafa47b28857c487409bc6bd2a77e922883802fab0e010252469890a6 src/adapters/store_migration/format_marker_decode_error_display.rs +53dfc1e4e55fb5656eea9cbabfb539e8f0ee76c31b95f9563ddf08a2abf48dee src/adapters/store_migration/format_marker_decoder.rs +815718adcfe2b275ab3ecb890b0c63900b59f698a3a7d899bddfdb69eb3503ba src/adapters/store_migration/format_marker_digest.rs +e73fedf3e352c6d4c2e51cdc57291949e49d2a1a2d3b1b109a11bdc6e2aca0db src/adapters/store_migration/format_marker_encoder.rs +9bb507522900298bc33895ad50ca077705a53d0662b9e914c7c749acc7a63b67 src/adapters/store_migration/immutable_pool_inventory_digest.rs +2bcbbf68726364322c5f5455d9ff0343adf73d1bb499c8743c5b8675ee1259c3 src/adapters/store_migration/initial_gc_state_digest.rs +4ab80eccd70698771b91003c6a4f99d7c8f9a58a023a8e465230a290427b8cd1 src/adapters/store_migration/initial_retention_state_digest.rs +29f327adafbcdf43a181f364def1617864a2a5836981e928d4d09ee8a370ab97 src/adapters/store_migration/migration_catalog_admission.rs +5e92023a7fecca62d3f7f61b0eba365e18b037e8c4d02a51a0813c56fb4c9a03 src/adapters/store_migration/migration_catalog_coordinates.rs +b8d8a20929eb0a4711c6e1a8032f862dc38345f65d8e74acc4b931780d577a6e src/adapters/store_migration/migration_catalog_plan.rs +b4bc84caa6b7873e988ec6380b7e3ecbf13aa9b241531eee287ef34c67b02c73 src/adapters/store_migration/migration_catalog_records.rs +13d9da0bc679b9fd1725c94253c0290d74178ca5e760a1b2406b7007c9695a2a src/adapters/store_migration/migration_error.rs +c53397a325a2f5b70185d0d96c996f8cb9ae0a35d623c2d6fef433892e22ae5d src/adapters/store_migration/migration_execution.rs +3afde08caef4a72324271e6c2c2f43ed5a5fd976da29e8a4db8148bfd3f4a8d6 src/adapters/store_migration/migration_intent_decode_error.rs +7219718f33ea913029a60fa5e78216255e9adc26f6b5fc3063f64cb44c2a411e src/adapters/store_migration/migration_intent_decode_error_display.rs +4e9f450ef07c570b2d0841da835088bf145f5716fa45e188a7dcbc803e3650c2 src/adapters/store_migration/migration_intent_decoder.rs +7c240294f48a34709be15b742b9568b5f38f566413e456fa488091dda46fa634 src/adapters/store_migration/migration_intent_digest.rs +16ed4b3781cdf5069bc1b44eecd5d3938630409ef7adc907ede0d1e3560c8fad src/adapters/store_migration/migration_intent_encoder.rs +31feb851f15c47ee9454d5d279ac6f263cb2c40f268da1bd3d9695fa94b952fd src/adapters/store_migration/migration_intent_format.rs +30e00a0b7d286df0f6afc529610a289ddba5dbabc60f20ab045ac0cd212c032c src/adapters/store_migration/migration_inventory_entry.rs +46a2767a23453e3bdedb820c34089325398de53d9806f3fb00981aa7cc4763bf src/adapters/store_migration/migration_inventory_entry_count.rs +0f8c3ba489b6e6e713e8ef8ee8af7572d8c90089f729ab357c8142389a0beb11 src/adapters/store_migration/migration_inventory_entry_count_error.rs +e653194db5d08e233c2218a5710eab6c90d8b077b0f094b12f9b828dcb4906ab src/adapters/store_migration/migration_inventory_error.rs +5dceb9cd5385fcb4a1a09d01904c932ca799c0407e9e1793d4d99e36d6d9a379 src/adapters/store_migration/migration_inventory_hasher.rs +2a73b012d4e797bd44cb97b171627e77c7902f20e34c548eced78c5069e9ccb0 src/adapters/store_migration/migration_namespace_prefix.rs +8cd58c0ce7598ea6c4adf7c01211728868240f407974d2010e05d26227c7e06b src/adapters/store_migration/migration_phase.rs +cbbeb50806443de7f180fbd3a363e0537b97f1ae0dfd32e06508c848f4aa0c92 src/adapters/store_migration/migration_receipt_decode_error.rs +c3b0b184b65c57eb5fa936900198a4520757611b44b5cde91bd286c0a1a399da src/adapters/store_migration/migration_receipt_decode_error_display.rs +0d6b3722ca7fa2de53a8a7927e8ba294c9673bc0183891f29b42960168209b4e src/adapters/store_migration/migration_receipt_decoder.rs +2306c6b05531caebeda14a8ac345431b0572591e79793c6c1ef4353122261871 src/adapters/store_migration/migration_receipt_encoder.rs +15467b8877a31aee483ffa8edea1acb536fa5c47a210055ac4a5b2fdb16698c4 src/adapters/store_migration/migration_receipt_format.rs +aefa02c785c6077d5e9bc7ddb3d45f118ca4f1488d883b0e2ff97c90e5535fd5 src/adapters/store_migration/migration_receipt_initial_state.rs +4b23842e29fbcdfc9c96bbe94eb9ed0133c81606c916224ccf9becff91c56874 src/adapters/store_migration/migration_record_bytes.rs +d12861d6e02e908e7427510e2d600ccf65f58f4e003d051970a5a9fa20a92913 src/adapters/store_migration/migration_recovery_ambiguity.rs +ea6c55ee5d1016f765c7a7ba8675783e7354ea9bc0b4b915f1b1925311e661ed src/adapters/store_migration/migration_recovery_ambiguity_display.rs +36f646450c8cfe80c461f454d2e85fafe6e683b0c6b3f700598d49f4c61f0c58 src/adapters/store_migration/migration_recovery_execution.rs +950896561d43b00ea0a3e9fe0c0e3b8f608c7d85060449e4a9624921516de882 src/adapters/store_migration/migration_recovery_plan.rs +0bcb75b855f283b9fe648900eeee119aaa7a18f678fd37170c60fb68fa9d504e src/adapters/store_migration/migration_recovery_planner.rs +ae854197cb059c890e42600c9e661d49c7d84a2d22e8399b900149cde1aff3e6 src/adapters/store_migration/migration_recovery_residue.rs +f6c67dd72c2a13db32d14dbc8f4ee52a291cd2277d9b0fe31d8a916162a915ce src/adapters/store_migration/migration_recovery_storage.rs +4b6e03026e4d195144d5c76f4cce5c342fdc5cc4ca6c99cfd5c99da39748a690 src/adapters/store_migration/migration_resumption.rs +e9d6066eb56e32b80f55765aa504d7bb15662029e30a74565ed7b98aaf9a733f src/adapters/store_migration/migration_stage_decode_error.rs +d80ab70bd785f1e8fb1df18c99b5b81354fbc8b945ac820468fc91245f744228 src/adapters/store_migration/migration_storage.rs +e27184b1e3afc02eab79d836b931d4161e40f0d6d6c99ed6145cd35fa5d998e6 src/adapters/store_migration/migration_synchronization_mask.rs +f0c8504ddcb788be25eecfe3757894f8c507f91c20b7a83c7c1c84512e9d636e src/adapters/store_migration/rationale.md +11c5af226adfa8d1eaff31b460f23f86c96281b1e89f703fbac9fdc3cdf3255a src/adapters/store_migration/store_identifier.rs +cc7eeafd06a491b84e707d401546d3e63ecbae74e3efca1fa3fe3ed79eda5cf5 src/adapters/store_migration/store_root_identity.rs +7abd31aff27369b42dbbe49d7ea66050e6d9146a5769c7baad4eec759b02d7b8 src/adapters/sync_capable_directory.rs +f23580a4170f3a5b02214a0048707c0bfbde85253373499c008db99da6016eec src/adapters/verification_admission.rs +327a4932dd40f670072e1f156dce0683f9e17d7cc2a9d568ee14793eb97f27b7 src/adapters/verification_decode_error.rs +79bc0a4c94f246e1c2dec12895dc8f72f32e8e337c51a5218df0c4491a293806 src/adapters/verification_error.rs +11f8f40b1ef0b5d7b63deb9b70c4fbf810606997159819f3ddaaab680a776bd2 src/adapters/verification_failure_class.rs +a1b88737b93ce8b853ceb08d1798268c2897b8d0741d6cf3807418e02ff16252 src/adapters/verification_ingress.rs +c7cc07f2ce1e9bc8be26e10eab485f5fddc737fda6e31f3bd25776cc0d4a43d6 src/adapters/verification_receipt/canonical.rs +973acc15e3c296a4c5ee8d0012f97a7fc0a2f340fa46426772496f55632db5e8 src/adapters/verification_receipt/decode_error.rs +cee45e0c6219d9e6ee00d3fe7b95b351ec9ed318e9b5354037d75e872c982c3c src/adapters/verification_receipt/decoder.rs +717fff9890c142daab86bcfe406dfdd0afa03bb51511ef32a38428e75b73fb01 src/adapters/verification_receipt/decoder_semantics.rs +39ddac92df7d198fdb1cfab6d16f9fdfdaebf1f0f8bf188bbd0aab7e28310725 src/adapters/verification_receipt/encoder.rs +623a2531fdcc522c94bf61cebb8620faf5fec0a483baa728f03ed4bde3f13d61 src/adapters/verification_receipt/enums.rs +abdc55b49ced28c437880c538f2c589d2e7880030f6d7737fbdfce3042d9ed0c src/adapters/verification_receipt/format.rs +81e8d5336caa9ff120cf07807c6be5b9c30be441f36a1cb3eb0901c688ac696d src/adapters/verification_receipt/mod.rs +33c078dee6a470c03a00f2017500ce8a754df44a916fd9a491ca2ce378757769 src/adapters/verification_receipt/projection.rs +50385a7092954bc70226c62ae1c4be40b28d2350719c410717017aef57ae18bd src/adapters/verification_receipt/projection_error.rs +7119a29558de7cd32be8c24e66c58eaac1d5e4177b4a68dabafcf9d0517f9f8d src/adapters/verification_receipt/receipt.rs +83a76d0c1ddfa867b90ecd6ce26fcd422f6a58b0654f7c910074cb94be3fd98d src/adapters/verification_receipt/subject.rs +113edbfe06162efdff805d0dc3a7f088a1de3a6fa509590bb938a326e18556c3 src/adapters/writer_lock_acquire_error.rs +c86e73ee50bced9bf42a8acc6c630a620fe27b40ca53410ed6584d8294328fde src/adapters/writer_lock_acquire_phase.rs +a2163d4c737f2b263f86f256743b27ba6b3c8d497f1b579cd7bdd5204b9260d7 src/authenticated_read/chunk_reader.rs +44eeda34ac8c0a2bf00da97b70027c51f1230147f9c03ecfb5c8e5ea2321d9eb src/authenticated_read/chunk_verification.rs +eea6c6a9aab4a9db5d6654af65d84a002d655127c7fbdb0738ff576fb5c411e5 src/authenticated_read/mod.rs +63460cb530ab64f2ab352c9043a0c2353998d0f1725d1c8dd1a92dffc85aa0f2 src/authenticated_read/output_write.rs +4cda65a7710145d3e1cc8202bb463e113c6f8cade0ace6c2402f8aed829b38bc src/authenticated_read/profile_verification.rs +db9ae971ad1b4079a8ee2f66062f341f64e3c1d5eb71151361982fd40a6f6bda src/authenticated_read/range_read_execution.rs +a386c3ffd1f9e3dd30bb1f2ec3e123a2fa66052d0bb04d406312abe6188d30ac src/authenticated_read/range_read_failure.rs +fd9bbb09fdd76dbf9464716a9f6b7d4f0f9d9c6311ddcb3ea67c3c30d7543986 src/authenticated_read/range_read_receipt.rs +7deac8a17ce0d1f4adb958d20393519a2dec4fa64ec7cc8c7456a3eef40891dd src/authenticated_read/rationale.md +2b65e42497fb28cb3af3e90f7cf31c44ddda8a427ed90d83ebabfd176c60ad7a src/authenticated_read/reconstruction.rs +2cc0ed512035414c76630851eba1c3bde11f07075e1c3d3d5609746c2acc93ff src/authenticated_read/reconstruction_failure.rs +117f9d880b8805c48585ea1678d4f0ef71352068c0f3f312cd94fe6458d58491 src/authenticated_read/reconstruction_receipt.rs +1557e1e4d36eaa35899c5babbbcbfc03322b0377bfe25dbf71338c2e43becefd src/blob/byte_length.rs +2c56a128d55ecd43fb2b6b9b78638678a1e937d506bc2f5f713ef3dacf7c4f84 src/blob/byte_offset.rs +1d85da5d0e0983069c7ae7be1ada17b67aa5d8392834d050f0214ab7df033ad0 src/blob/byte_range.rs +694dcabf3ccebc0555fccae4809a033c8af943612fbda716e38435e950773d49 src/blob/hasher.rs +19f51a3e260234e3d94bb85bc37d9fc7c2d6966373373c6f4eb35ee0d61d9747 src/blob/id.rs +f65010211959225d42c4eedcc9b3b8b13a3782d47f07545ac9e2a1405f373b3f src/blob/length.rs +31e98b0e3f6f31b12a163578a237d85ee616f21a1637e97431f6b12bc92bcbf7 src/blob/mod.rs +0dd0e9e6581373b0e746a4732f53c535eb4803cb41154c6af65afd661c04e236 src/catalog/digest.rs +5410c80f71a856812d731df7e9ca8da291b1ad81534ac1c86c5841b59c65341b src/catalog/generation.rs +24b82580782c651ec5f0d4b1094fce03dd19e20f754067fbd35a860e5dfd2f27 src/catalog/generation_error.rs +e009a2b5b5ee3c15793376db4b9f2aaf3f15f869f29f24b78341e72030704e9d src/catalog/length.rs +51fa22c7a3d42001960c9ba2ab93cda4946faeaa5cebe2c0dce5b9df43ed6e5e src/catalog/length_error.rs +b820bf7bf1b88523325cc98391781d7d054bf6915020e6d7f2c7543211fb57aa src/catalog/mod.rs +7cd34b73150dd2c867398e12c1a79f3d185c41333a2760a3a6948add370f7853 src/chunk/detector.rs +7ca21e08c9de408bdb84008bbbc19cad7a991435dc4598de1ee822555d9c5519 src/chunk/detector_feed.rs +8f30e52ff7fc8c51485aefbfa18441bca3aa1b5f8c8119ef1d25c185be12990d src/chunk/detector_tests.rs +71134c433afdf4ccce80194f6025726a35c493a04fa665697fa83c118783e18e src/chunk/error.rs +abbe333b27a037ebe8aaa8a1f06a1a18c5d4408f95cd9142d3eb6618dcd5ff11 src/chunk/gear_table.rs +be01b8577db47c6e76a6c42dd721a37958cf6fc509960dcbfab0109784f6d88c src/chunk/hasher.rs +6329263634ca96e18a2c510c15957aecd79afcd10b59e384bdd6f2c34080297e src/chunk/id.rs +4d661d3aec8b978576ad2a2a9c10e4f92389209599d44bbc2ac5db1962daaf41 src/chunk/id_tests.rs +7b373da4f4f0e849b447d03a61e1b76d0195ba4af33ced204fcb77546b50b372 src/chunk/length.rs +76a53c0a2788d3e6774d644936131b6f5b6b82e4aef0d15b1dbc66dec908ece6 src/chunk/mod.rs +c4f0f08c064c00a744e1d1efc508accae9c3738bbf1ab448e51af4ff2ea49422 src/chunk/offset.rs +0477f1f1772e22098a7304ecec7b6bf9e5acb682695081e2c8d18e61a707d267 src/chunk/span.rs +c897b15028f22c6981f4f30071da5401c0297cd0c19e138c1ffa7302d93a4350 src/gc/generation.rs +58cfbc1a1a84294a6c09b2164e581a0bcb88aba04b2c02938534a96b1299c3fd src/gc/generation_error.rs +769e88a59ed31c947a052d7c8db13b39b46db8445b6e61d5b7182b64f227d9b3 src/gc/mod.rs +8781433b0635d874cb50df388d932984bb73b9043871c2ef9141a473074914e3 src/layout/admitted.rs +69bde2b44f882839ddcd368abf12eb3aa4c1ff6b89fa80e85590bcf647fa66ac src/layout/decoded_admission.rs +1eac56b77be1cf86c730eca0c92d5b3b5c67cb1b50eb0cda1d8ca3b82e38fc7a src/layout/entry.rs +44d0792bce2e40cb8605813770bbd72ac435596cb0e6705709304731c95315c5 src/layout/entry_limit.rs +4e3992dddc3c07ec8985f3c7d39555b1674bff7eccd15005d9ceee04077ee4f3 src/layout/id.rs +236c10f1d3054151c88bdbccc360f02eda5d023c10420b8c6ffa9d49f4d35e00 src/layout/id_mismatch.rs +d0e844cc52d0d9152c83b8d28c8dce7d11b805aa73a0aac87db0ffb4bce7898e src/layout/mod.rs +7e055bcacb863c38eda681a37aa273a24c0c299f2cbaa6feadc1232af037e573 src/layout/range_plan.rs +8c5140a20be815d8f210541d3d8e014a3d9363bed05b762aaae27926502f64e6 src/layout/range_plan_error.rs +e1606575b373b8649830489666fdefaa62ffdc2a9944af0ac0826acd0ab1a2d4 src/layout/record_length.rs +8481194312a8494c8a48d2fd711f0cf69c1bd8266199bcc94f7379e07e09c56d src/layout/validation.rs +8d3c1d6dbbb691fe6bafcf3cdd16761d1ea80b9441e83652a9c9d80cbded9d5f src/layout/validation_error.rs +69772b6d73e9ade16f71ac6d694527deb65e0e5f1ebe566f0ec19ee3c544938b src/lib.rs +a49f90172c87981479078de4a93e300b1799ec50c92d4dc4e45b8b66361b5e07 src/profile/admission_error.rs +2530841ce3d6afa15e1f8456c7cd65075b139ebf82cac2ee043820de91bce33c src/profile/boundary.rs +d5c417e521a362e7c7823a22138bdd90b0d72b846417c2dbdfbbcb4703de4a3d src/profile/id.rs +ef3130da6184dac8d9186512039b66cbed6d2c0f788be7d74fac365dcf430c4b src/profile/mod.rs +2e56f3645f87ebe25cea2ae445a942970b1dc8a00fd1650f1729e524a235e384 src/profile/registered.rs +906872edbd3e23078876dfe272fd09820ec1974bd39519a3fbd9ad44190c2522 src/profile/verification.rs +013686f4947a676492dc26b4e2dcfc956488be1c32fff9928da67a0be070858e src/profile/verification_error.rs +be68245dee9526bf618dd6f9e1033a55716b5ebd345390a480f51a76fc2c2e6c src/reference/capacity.rs +51153190991ff616a7d24d35bc6259881fe8f29cb0cb41541c5b80220b9c9cc2 src/reference/chunk_source.rs +cf26c32fca3de2a607f6eb9e9a13521786519e8697f0ee3904b88f49c56dcf0c src/reference/chunk_staging.rs +4d719d3ebefc5e410096fdf9fc9cf7b63138ed1898e1ccd8956f14e78f2385fe src/reference/ingestion.rs +caf109a8c59042b852a0db898f4a43699be3aea9f96211e9cfdd3096b337066c src/reference/ingestion_error.rs +5c1068ce4fb2e42f8a182aa63d75ea8c7004e6530471831262bbdad844dc4483 src/reference/mod.rs +dd797e9438f739353cc804125564ba72082767e2e426ca9efc57158feb0e7f64 src/reference/port.rs +26f0bde8bcf7a1e33e7f3a561a5df9933a569b2c6b92cfd7d596db8bc5b3b177 src/reference/publish_error.rs +bab8ce9350a82fe018fd08783272b9fb7276af975402222ca2b412de8849a05e src/reference/published_blob.rs +dbab02282c92c38c3e3be583e459ed2cec02dd7b95963445354bec4c691adef2 src/reference/range_read.rs +a1aaa04b7f020707fd091eda5dded0c39f4d465cfd1b40f4455ba0d92e1a955a src/reference/range_read_tests.rs +04432f874d77b756a14279bb9f5e5b73537134108169e43c0a1f384efdbbf549 src/reference/reconstruction.rs +d253eeb7b8101741de4e6c725c4e5c255449203f326cc814ee73363f4677f722 src/reference/reconstruction_tests.rs +86b8748c138f9ff120201149ed9af8382ec6c1dcd3fe1d2c3dd5d5e7d7587c4d src/reference/staged_blob.rs +476b22801063e249715a6d8c8e207e614f8cffc5e9126a7ca3545cf1cd263b7d src/reference/staged_blob_tests.rs +c7de7cacdf70a9b276edc11bb5fc61fa173be8355a1c07bf949844c557bff43f src/reference/store.rs +bb02b229bb91e937cf0d66ad62548240a56047190cb637b3573459b5add912e2 src/reference/transfer_source.rs +a44317c3305f5c7b4404950666a5fe9fd3abe0f4e3642548788af6c9b63bf061 src/reference/verification.rs +d8eaa4d41214cc71c3d7ae19bac68dfc513bc79d07cd26d416462f9137273654 src/reference/verification_context.rs +180aa032909d5090ebbcbfc2956ef8b99188a29994551f87faecb514720a3069 src/reference/verification_outcome.rs +3c7cd2d2ff36d67f283b01a70ef2b3a183717ef6218f97159ba91e3fae0c7435 src/reference/verification_source.rs +5fd7a3a94bedd08fbc1b7487f7de790114486ba67e278f0ff2314ab187f37f80 src/reference/verification_tests.rs +a737207b699337c7c3367cdc87a4acb69422fef62fb2b6e4ab766206b788193e src/retention/anchor.rs +b1c5468fe8a2a5c6d519b1d7bd10da22a7332af7be02e653b8e0556ab8f96e44 src/retention/anchor_set_digest.rs +4d19a4d6da655d3c0f11a1dba603dc74ee22a0a15d40bbc6663a61f87e0a8b99 src/retention/closure_counter.rs +d5ecb14b790d7758a731238ef1e1c3110013115ab789f66f44b74093a0f9ab3b src/retention/closure_digest.rs +4e1bfa52319fdab8d4e83074a210a221f3f5138484c629d46da82d925d8738f6 src/retention/closure_limit.rs +f1b0819226dc8dbc595877966110374419836ddc5fcb2b7870d009daa416800d src/retention/closure_limit_error.rs +3762fac74de8be51f5b2bcafabc1e969c050962bfa41f782935117d6b28257c3 src/retention/closure_limits.rs +a43762c34c68dbf6ebc3b49efdb2fce5d48435f3fbb14c24c00ea3b3d896ab7d src/retention/closure_usage.rs +fb4de2b55840ffaca2c0a8d2352e48bb8f60df8b195c99875abb53384c0188c8 src/retention/generation_expectation.rs +2c5c67d05889566f2b72c712f3a2eecc8838dedbaa197bd06bb4c5d97ec0ec0c src/retention/head.rs +fe31dd5d57b4ff17652c2a9e9a5a98a142994d3eb49051806d4f6fdb96ff69ce src/retention/head_error.rs +cf69dff037c1c072c9d31483a73130f8ba20e8e0d538e7c4c4862ade2691b041 src/retention/liveness_generation.rs +083ed3a6ad9ddeaa6f84bbeecfe7605c14a946643fbf6339689147a454512612 src/retention/liveness_generation_error.rs +d98bde11a7ab56f6c68999a81f84e9723e9466abc8acb91122d7240e26b3c671 src/retention/manifest.rs +52fc748fe642ca64859e5955a371b54a9121447dae75ce594f9685e26d9ae14a src/retention/manifest_digest.rs +5eba678bbc2bebf7fe8b1e3b97e94451afd9affc53fb2ce67bf354fcc54cc4aa src/retention/manifest_entry.rs +3ef3d58530258262eab21b75e403e3377bc8530a67ef4eb70c08946e1e59c650 src/retention/manifest_error.rs +043f94a2918cd1bbb8fb3efdc339c9f289b636907a36a07b43f827dc2c0758af src/retention/manifest_length.rs +c4ebb574edfad9cd4bfed3746e54983012d6506234910ba1256fd0074f73b537 src/retention/manifest_length_error.rs +1ca5e45ac4569a39c4dd9bc2161f07edf5228c1c7103f71ffc7c4ad8e15b30e8 src/retention/mod.rs +ca665b0b207c01007139ca27197229c392d9a2f29d015945dbd3088cf6339edc src/retention/namespace.rs +594eb8ccd30296e159aa3e20615bcffa4665de731531a382cb0b3ccb6fab0ea9 src/retention/namespace_digest.rs +9220f4a69e8b646a2065271cb1631a4758a2dc1323b3d460e3574d1eb7892281 src/retention/namespace_error.rs +9adb7dda27de0bd66f2ab352d534daaaaac467b7f85878618aec512fa6b0f56a src/retention/policy.rs +3d2bddea4d93183e9812f586a36b07d8c62218c92f7f65ba2201c18240054e4c src/retention/profile.rs +332b9ca71c835bb98f217f561cc5935d9684f99530c443a7046e8619fd9d95ce src/retention/profile_admission_error.rs +03499f28c0685c71a06591b9e58a49833e749fbafdc18133f9b046a184ab16c7 src/retention/root.rs +9b7e540203d28bd1cee672c4f5654db42febe5a8146af8f2ae4c4fb02e4366f9 src/retention/root_digest.rs +625ac99a8fb51b4af2feca24c32c9b3dbefe79bb22cda885626b5c8f9ca7f75d src/retention/root_error.rs +5016e5790e18daa8fa7254939fafc1da2b6622f3e3b430cc14b2cbac99d5753a src/retention/root_generation.rs +a5b31b271d862f72b602152277ae1d514f1da94283b5ee095f6358a787a9862e src/retention/root_generation_error.rs +fae8eb656c7d6fff917f193dccf99477af228e1d9e05614c9e79a63582b19a03 src/retention/view_coordinates.rs +0393e9f277f9abbbce1e80f50abff77f8f9d530de952bd66edfac9d9b066281e src/segment_digest.rs +406c0f4c12df34d21009523b34b2c90a493afd1c086d37581fab16cb0356d0bd src/store/limits.rs +ebf85894786ad6955108c2d89072a15b51f700b284783ac960609e318ca26c86 src/store/mod.rs +8a8a20cc78bf794600318687acdd9e11c97671e5d971b3343885f5e814e6fa8a src/store/port_laws.rs +ec02fcbcda99fb01bd483d0e1103b6d21676f521f1a6d04e7edcdb9059cf4dda src/store/reads.rs +80f2d5989dc89b26fafcfdce8ad23b7b7024b920a8aee2793926b94cb19427f7 src/store/reference_port_tests.rs +4c4f61ab64bc721e858809efa2cab0fd6ec6dd36076c257720ee6cee8e9a7a6b src/store/staging.rs +cf51fbc21a6877bb82d327785218aa0c88029075ed2dd1a69aec2b1ecc6e418b src/store/transfer_source.rs +0526cdfa094a9456d2fa2b95fb1d81c3fffead436bb4dbaa7c3807dae97b6fd0 src/verification.rs +a1f278d72bf9e24daa203445bcee8593aff4a2f353090d016629009c3cb3480a src/verification/depth.rs +5de53a8800cd70e09a28b4e2ef4200ed3024d4a749c6db50f03783ca6674a0ba src/verification/evidence.rs +c9f92462bd45588df0e448f98bc754e24b4198d329c98d278eab20ea78bbab2e src/verification/layout_details.rs +85ddb31f7832e5acde476e3e0b8d1a8f8bbb90b8bb6ebdb5cf6c6fe81bce3297 src/verification/observation.rs +46105ce6ef4e9278c665004cca19c77bb2dc78e22deda4541a09a12ab64cf1cf src/verification/rationale.md +c6d2a2f798794b10d7dbf3564814ad7eefe7ab2adec16d0608a489f608330c71 src/verification/refusal.rs +10239315a4d68b1282c7ebf7f3a61058a496429184228ff07c4faff62838d34c src/verification/report.rs +1ebb949ab4af67440c470a0a941ecbc4ef1601f41994157755edd758245b41fb src/verification/subject.rs +57420da0bfa0ad5d4605f0c7fdd9873364294702591f1e5bfecd826ca13c74b6 tests/adapters_layout_contract.rs +fb0f79feed1bcbe23cdfc997610b19aac2c3ef5cd6151315b282830a7f8d75ac tests/blob_verification.rs +36429527b6e3a19c1a7baada8d64dd71c29f21c3be1c73ed056f00092573cd65 tests/blob_verification/profile_law.rs +9f519686e8f6950a585e00f452f5bb67729fa83d3856b73060ee22399d95a9c1 tests/blob_verification/refusal_laws.rs +a32ad8ec8d8eeeadc09302ea986534b2961b7ad782244933fc30794939fe8068 tests/blob_verification/root_laws.rs +28ef97d8090b6d321ed4d16a39e7636ba2494a776a05cc091a1bc2f525ad7706 tests/catalog.rs +ac1100eb806cdd398eed4dc6fb2df6ec9016727e6cad0293bff784a2f688be4e tests/catalog/entry_laws.rs +e7d7431688effd5c1e602252a3f1a6a96d3e63bb281e7973afa38673a4a719a5 tests/catalog/format_oracle.rs +69fc699b8ec2e2e8e3781bdbcfa32c4ba282b2f7b45b1f21ed7697f0c030e3b9 tests/catalog/header_laws.rs +e2fd29d95d9446804b9baf85f4be26839b6af3d069d74c7e809c3db486247773 tests/catalog/integrity_laws.rs +2b7f7f854992e0009429acfb78549ebe45c4f18465b2ae3d66f31c2c848843bf tests/catalog/mutation_support.rs +975ccb685a0ab5c6855cefc9246591106753af0b629268a207c7aa75fe449887 tests/catalog/ordering_laws.rs +3cf9f4732312c7f06df2a6ff0924d1c72966b86cfeda49494a4af0e547a974ab tests/catalog_encoding.rs +7ce5486c2b409fc05eff1a4abc04536faa32a59312e5976fc4374d305e6bd234 tests/catalog_filesystem_publication/authority_laws.rs +55f47f5fa0e083851c6b4684806b37e4fd291a489a4eb72bc67c799e935366d1 tests/catalog_filesystem_publication/directory_laws.rs +8e9e4cb8e11000f7e3fbc4b7de906a3b5564269c2f08d821c1f6f394412b6350 tests/catalog_filesystem_publication/initialization_laws.rs +d319d9fcd7cda24c3312bc1290576b09c793be5289e1d2ca5aaef8c22400098f tests/catalog_filesystem_publication/refusal_laws.rs +a1b500945503bdda8484617c7c64835cbf813ce7e3d9f0839b5b64faf8aab2a9 tests/catalog_generation.rs +64669c2f8feefe2132131349ccb571fa9ba55b8b21df02fe713b1455c0af1c8a tests/catalog_locations.rs +67369a7c2c3290de519160278ac8c701f2f4f87320e562e57d5d37475a97b3d8 tests/catalog_locations/refusal_laws.rs +534125db903340b1518393d49dad75c6d1c76a232e81eb4e699ebd634f2b0399 tests/catalog_model.rs +90ae7853709bf02ce02a4d29967241e45856df8a8a64aff9a49a9b79cf44a7bc tests/catalog_model/generated_histories.rs +aef0a8bc5e1526da50bb00f41f7c72f0cbf83be21b36748f7bb772d4320bb2ce tests/catalog_model/record_inputs.rs +04510a3805763bca32522aa1be4d227fd70cb69a84dc6b922df48deb39ec3ac0 tests/catalog_model/transition_refusals.rs +55e9ea40f7613df8fb71b1e0d426b7c766d5d4981a9566a8069ae6fa116e8ee9 tests/catalog_platform_admission.rs +375f3dc62aa76a85a14b01db2c2f5a81ed2ea18de0917fdf41f5c6785097762b tests/catalog_platform_admission/unsupported_directory.rs +d6823197b451acdd9dcf1c156648fe230a92ba28a7c5e7e70bcee89acff6298d tests/catalog_publication.rs +aad51e14b67d4e3b631237537ec32c03a6bddd72b122e549cac7a189d496e225 tests/catalog_publication/closed_stage_laws.rs +8ba045d943b4a07e0bf82d32bf9dda551031624569ff1f15ef7480b31a7867f0 tests/catalog_publication/preflight_laws.rs +9ed8c360a33d386d2485dbc168b5756655e5e8ff445538f99f07104822845d0a tests/catalog_publication/recording_storage.rs +782e6cbf8fd6b8da20650f6c7359deede7ff7d302ef24da413b939a45ffb2b6f tests/catalog_publication/segment_selection.rs +baa32ef7dd2fda6cdee158029981b0e18b23537336420d1a9d682ed5d78970e4 tests/catalog_restart.rs +1404fa916444fdcba66747471e008065db4b5c16cbbc1b29bdc459dde063c893 tests/catalog_restart/refusal_laws.rs +fce87f2cc66f43863406a00c44eba7a271cefdd230ab7d0d0b87343e6bf84c37 tests/catalog_restart/verification_laws.rs +58a7c4b0d76dcb3fbff8efb23ed2de19e0e4fcfee7fe77e2256345f4788afee4 tests/catalog_snapshot.rs +cb0d26e1c18bdcff6b81077a910db6748a799e51388390babcb0033f1695e974 tests/catalog_transition.rs +f1c6784f720a8c3156c53c85377a7ebb5c266f8443e142fbf4651bc0168eee40 tests/catalog_verification.rs +4ed82d4bdc2502c8237580847d321f98ba10c93cfb24fb48fe65c9d2c02b2aaa tests/catalog_verification_ceiling.rs +dfee43a23ae8d92964edee6be08459c42052eadd670d338d89a4173c438b542b tests/catalog_writer_lock.rs +6f7ab604643baca6c36401167403340353e5749b3aeb1806c66c9dae22686fa1 tests/content_store_port.rs +7a7e5381ec04c0be45e5bed6cdb114ae93566a6d5d57eaa435c53790874dc8c8 tests/fixtures/recovery/README.md +77815c0dbd6fc9756fc0e81da4cb7e60a0886d84c034b2a03fde63b05bc98beb tests/fixtures/recovery/unsupported-partial-seal-version.hex +ecbdba446913fcfc801a76d05f60b03d8a6cdad63835f9afa5517624d61e965a tests/gc_authority_root.rs +97ead0cd5677513eadc054fe5e68bd7bd5181649d0528da69f974494386eea82 tests/gc_retirement_intent.rs +d16c75526e01a054b2bfbebdfd12ddbd3a3f992368770fd1e826e0038c5d4ef0 tests/gc_retirement_intent/mutation_laws.rs +df8d736a40942b0225adf5325ffcc4b192da2a7359c943c35593e6c8664651a1 tests/gc_retirement_intent/opaque_coordinate_laws.rs +4f404aadfb4720f528f88160999c3ecc039ed7c0f0c944068c0a015437aea6b1 tests/gc_retirement_receipt.rs +b8be4775762ee7c59a50d4194d1e04959b97f09bb9fc2ccf3606c14297eee3e4 tests/golden_file_worldline.rs +43dc08c374d2189168c5afe407171b2154e01665ce3ead2afc2dab5fbe7d8f51 tests/golden_file_worldline/durable_assertions.rs +9dfa6d09a930420095100405613dc15aa6c3877508ecad7c0c4927f5524553d2 tests/golden_file_worldline/durable_closure_refusal.rs +8506f0a34e28e859d89a855b663a786d6907fb247f49714cf94292016cbd06a9 tests/golden_file_worldline/durable_corruption_laws.rs +ab0a7f144141d6077a37adcfe4611967131c0e1324c1a6043a2f3e23158f33b7 tests/golden_file_worldline/durable_diagnostic_laws.rs +6bc4abf022b7c472ef09f43b36a3a86f3e2cca316e0ccb02b67a4b5d6407906c tests/golden_file_worldline/durable_fixture.rs +34a55965ea7f6e31f66ae92b144e47174011c65da6cdfcc5e6d729f23ce01542 tests/golden_file_worldline/durable_layout_laws.rs +0e85623d09e8784dd082501727d9a3cc491a1fb4c4f43cd7b70f90c9ffc055e1 tests/golden_file_worldline/durable_locator_laws.rs +6f4d9611d34a59422b7c522137ba004bcbd53ff70398bac321fcc805a4434871 tests/golden_file_worldline/durable_namespace_laws.rs +7402530f6d13475015be9bf3bc0b1c74a4e56c6651290420e7fd742c34c789a4 tests/golden_file_worldline/durable_output_laws.rs +ea03b0f2f892be579d32abf903f826d75d1fb90d9d4b9ce896d534b1e11e1274 tests/golden_file_worldline/durable_range_properties.rs +87090f5eaea1617dda3622aeb8fca60cc3751c1ba4f637c4faf84214d95661a5 tests/golden_file_worldline/durable_read_memory.rs +0425d2abf427047de6d520535289f130ac780daa17e5bead26bd007e665cf8a2 tests/golden_file_worldline/durable_refusal_laws.rs +229691d0e0573391d99c1a48a37989d5d9f345fa503a6a891eacfdf040217d6d tests/golden_file_worldline/durable_writer_failures.rs +0a2535cce5a3caf702c811b51a9f39b78541b9593af6adfa3640af8bab8b7225 tests/golden_file_worldline/harness_failure.rs +844a35e588270922ee96925a51d71116775324b4a3c88c36aef0a36ad0cc4ad1 tests/golden_file_worldline/identity_assertions.rs +fa1df392aefce24e5d18b0fa852809aaeae2d512f01675c4145584f2e14489dd tests/golden_file_worldline/identity_corpus.rs +32efe47efb2b022c11435aed6ac2349ca9d9b486f038de50fd960eb82d736fdd tests/golden_file_worldline/mutation_assertions.rs +6a4e0b1e6d5f48195535d9d3c9fb60e652883f0564a3cd590156a4a2d3521104 tests/golden_file_worldline/reference_model.rs +be16c1a4018449b8d075d60068ec47f98d743526c504d032b6edc17b12fe3e28 tests/golden_file_worldline/scenario_corpus.rs +bc01454224c54e05c06b6d8f3c9fc88e57cb281c94b4dfb1d76c04d5bd798970 tests/golden_file_worldline/storage_assertions.rs +a624a15956e3404024df2d672264f2a7517f67021c80b4f5e343b133305ffbd6 tests/golden_file_worldline/suite.rs +495de0f64562c1cbd12fb6f599bdf8ab7e8f8274f6c81c762092e4f6f627a1e9 tests/layout_decode.rs +5066d13343e5bc48f4fd861f3993a193d3963f69942185e9f9d8d5627d78eded tests/layout_id.rs +52381a20b61eca12dfe789afffc581ca87bce82401826460dfbcd2ec2f5a3d06 tests/layout_mutations.rs +ff97c85d0b7cd2661a82866de369cdd1ee2f17d3493ab1b2e9afd59b25164ff0 tests/layout_mutations/support.rs +e2ea41878992a1349a346755a3c74d4e93076f3fa9e3459371d47ebae83f7506 tests/layout_oracle.rs +aedf739f7903cc07d6dd3a3ec4d5789ccde96014968aeb2cb2d564ee8f95479b tests/layout_oracle/support.rs +0a416c42410e5c0b79b512aa511d1a18b17c573ec05844318a8055a7b4cac5c2 tests/layout_properties.rs +75006abe080d0182ae59230e3b7b792fc6ae57be993460e07ae60a2dbcd9bf81 tests/layout_record.rs +5883a04f8a7185cb5b014e8f57e6d1096abab1c732a661d7a99eb06a5512938f tests/migration_descriptor_exhaustion.rs +f182b64af836cef27ce5c3e7bdb9e5b06d5ae6c7ebf8ffc7c1ef3b3f0e32e80d tests/observed_segment_stage.rs +e176655602d52c217a23ecebd3823c165fd5246a95cbcdb759cc8dedd7d7083a tests/observed_segment_stage/byte_equivalence.rs +0e544d56cb4685efd20b8e48dff0410a50397958abfbefccf7ed9af92e04568d tests/observed_segment_stage/durability_failure.rs +0e406a04d5097e75e89dbbea3b4f8a2d2c9fe3426a131651a8f71cd4ce58f6a8 tests/publication_head.rs +e39e24e73a1273a10b7c23cd1861431dea3c9ac355ebf6729c924ee6615e436e tests/publication_head/format_oracle.rs +ce824afbd0a50a06c4454ea1e15d277e07ea616bf9733bf3f67e675bb0439d4c tests/range_plan.rs +76096df5aa4503eb81f81958520dfc21a10e0eed54231286289dc3e6da9a9f21 tests/range_read.rs +9c2861b253b7c23bc6fb44f9145188d146dd5543cd05ecf2d8a1c2eac7e67d07 tests/range_read_contract.rs +a8e6e311de294391f770ad2b47516ea8599684ec50f211ca75210ff801fdeaac tests/range_read_entrypoints.rs +10e42c228c893023d030eb08198c9711b6157cd00f43c54f189cc065399e85b7 tests/range_read_failures.rs +b9bc46a6ca4eaaaa812693d4187b12c880e48e68f10fec481956ce463aeb27fb tests/range_read_properties.rs +d0b45449d0c0e44b20ce1cf8fc32668cc2ca326670a9b1f3b0a7902941f719d2 tests/reader_fence_process.rs +090ed50ff35ded2e8e1caffe1f590c0d672f8f197ddbc797d6505dd587500038 tests/reader_fence_process/fixture.rs +8a3aad64aea7c67f3aa2ae42d9f0df38d250e0479825cd5bd5a4a1888d4e0444 tests/reader_fence_process/reader.rs +7630ecc65c9e6d4e4ca33c459da955b1f9350334d7ac5cdb074803c41aec409e tests/recovery_disposition_receipt.rs +e4e640fdbb25894cc01a47357eb9a812c15055c976b98d4716d1ea789b85683b tests/recovery_inventory.rs +f796e950d33a8a828290d98b9c1b6381b75e41cb51e7ff5f62e1238c37fd045f tests/recovery_inventory/inventory_double.rs +f51ad5ffebe271eb9b2db35db5149e522d1227d2e94c7ff648fb26c29a646b03 tests/recovery_inventory/refusal_laws.rs +82ef7f3d103795da07cea21dc8fcffd9d4278df6c6cbb5c4e146049aa8531886 tests/recovery_name_classification.rs +b4868ca10e0a1e35c8d2922b8000e8dd0d483b9338c56a16439fee0a3723c314 tests/recovery_name_classification/grammar_laws.rs +e8ba4ba00472d5141db12f6e452e10f403005598a88879334255269b4bc01989 tests/recovery_name_classification/refusal_laws.rs +a10954f37a8826a42ee7ee0e55821293c5c9b91f1134bb4da7ec5de8582b7cf8 tests/recovery_name_classification_memory.rs +64d1533e48ae99157f0f57ed2793c001cf7aca1acef9c0cb6feab853260d8e97 tests/recovery_next_head_finalization.rs +c4ebe3492758ec449a95fa848126bbda1ae4bf1de8e79bdd94e0f95e2cc639bc tests/recovery_next_head_finalization/execution_laws.rs +6f31e647beadf6db70c9c030df5cc5256b98f0670bd592e3e010e069d111d34e tests/recovery_next_head_finalization/planning_laws.rs +0c86b2ef73ab908dfffcaee12d73826097c3d1f0fd7c45a7873cc6c5218cf24c tests/recovery_next_head_finalization/storage_double.rs +64636fbcbf08e3f3c7120f2363668f9878eada0b970e872f762a03b993ba49c7 tests/recovery_partial_seal.rs +6a99186f328631c3d79358e2dcd1ecd51f60a9c56c3ab7ce6f2a3937f2427650 tests/recovery_partial_seal/framing_laws.rs +452ab4adb20292659a35a7c1d840b4e4d026124b60d2b12d16570956079de0fe tests/recovery_publication_stage_classification.rs +af585d62c7bd0ef53107363f3f6677b521ac22c80484de04ce1893e773df3f6d tests/recovery_publication_stage_classification/catalog_laws.rs +55c29f71daa32205588c83b0ec40d1b3710aa7d64401e6c866051343b6a5fd37 tests/recovery_publication_stage_classification/next_head_laws.rs +198baf01dde0b8dffd6cc5d6acc1ac2538aee15f82db78c2776d81c38bc81f34 tests/recovery_segment_classification.rs +8922599ec3ea46f1bbce8b23f3921b68b595a0cad64b83a571a6df6f8853b4ce tests/recovery_segment_classification/refusal_laws.rs +a60a8bfe413a54dc7a7c70481ba4321e1d0d62c882a3e5afe225ccece09a937b tests/recovery_segment_classification/state_laws.rs +9cffb84b6498fff20c1969245729d918ffe9866fdb223f4ede536afab4579514 tests/recovery_segment_resume.rs +7ec6a3c24ab020aebd2ad38daf038cfe5ef8f503be7e53b096e89aa9164a9baa tests/recovery_segment_resume/execution_laws.rs +902bbe6070e7d33ebf3e4e0f4b091eb8fb2ce95c988888de4dfd49bffdddec06 tests/recovery_segment_resume/planning_laws.rs +11edd99480e4f4e229e2426aa03bb72ec85d32e49bc0013e7932e4eb75e0f9b2 tests/recovery_segment_resume/storage_double.rs +1f008df87ffecb13198f2a0a330471727b6fc90c291506519e186164facc6200 tests/recovery_stage_assessment.rs +277fb756ced8cc05b1e988a7858cacf09cb7a28d7950e57760702d32f906fc54 tests/recovery_stage_assessment/admission_laws.rs +59353ff31e882e797c77b7040289051dd6bdc2e554991eb08b0ab5f65ebf99a8 tests/recovery_stage_assessment/assessment_laws.rs +bf63f27db63ad48fab33c321fbdd7a14d912630cf12209bb26a44925ed02214e tests/recovery_stage_completion.rs +b4fcc3761e2b9cd50ef8ecead39b9dd5e9c5b1f58d9f50d267b40962600f8204 tests/recovery_stage_completion/execution_laws.rs +f8ad96b899405369e3bba045cd1f28b15f16bbc304318513580e23ef6d1f4353 tests/recovery_stage_completion/planning_laws.rs +70eb0d41883e0bd4767bacd8c228f329e263a8581699a0c235b6d431c88595ec tests/recovery_stage_completion/retry_laws.rs +976580f4f71619df3d7824b1f72c4e6c3c4c9b74040fd9882dfbb3a34f49008a tests/recovery_stage_completion/storage_double.rs +58cfbcd755633d628e648c66c8c6060babcd5b6d993e5e72196c635483fedf95 tests/recovery_stage_discard.rs +d442be5125005beb933b0775c4bf233040f762de4e56f9b9b38e3c9dd22777d0 tests/recovery_stage_discard/execution_laws.rs +628afb8776f5e7d58a5870fb6918838b8f3cb4e34d4af39d0ef3a38a33a954d5 tests/recovery_stage_discard/planning_laws.rs +6118e86b7b75b462feab96298cec6fb0e6f938a1cb0daea9c9a3761b068f7961 tests/recovery_stage_discard/storage_double.rs +45cf09645198973a532f0b0a6a2bb83d847fcf02ae1116da7799417f16069f54 tests/recovery_stage_fingerprint.rs +358cc4481bc4306a6cdd1d61393df53683ac9ecc007f19b434fb3e166d7a4d96 tests/recovery_stage_fingerprint/reader_laws.rs +5ed9f91b1806181b967669a110ca75a58e8d4008a73c6b8319c1a87258043581 tests/recovery_stage_fingerprint_memory.rs +89d09cf5414e46e9879a92f063551db0d4cd74ffc61569f209df887be3cc52fe tests/reference_store_contract.rs +25dbc3fe0979fd6c60b27c3593c1baceb8af50b9d5d892307a4b95488675d336 tests/retention_closure.rs +6ff66d4482fea5562547ce8dfcf7fb6038ed6271b9b89fcdf8892e5f4a099abd tests/retention_closure/adversarial_catalog_laws.rs +ca1f35e74ede923ac81ec4dde608042df970f6c92ad6bda9e6674ff6e7324e70 tests/retention_closure/closure_model_laws.rs +388103f6865904c839900b488e73551298928e7c432fab3db9ac1e8b526c94e7 tests/retention_closure/limit_precedence_laws.rs +63217e6f1e0b01a6f5da6bd33633e759056a12aafb213b47c7bcf9f52543083f tests/retention_closure/memory_stage.rs +0df40c51219d9ef17054df4394819f74963b8b69a844b1037d7bead438334204 tests/retention_closure/one_zero_bundle.rs +077d696c3e38fa1fdeac9a0f7642e7e585f6f1352faa7fc239d89c1f7c0216e8 tests/retention_closure/repeated_chunk_law.rs +83a2ec8f6713366d6b39703a6d28caed973fdffcb3d6b6adf589e8688479f994 tests/retention_core_architecture_contract.rs +9325f127aecb038c18cc9869cc289d00dd71fe97182f21b8fdb9b7e256821ccf tests/retention_head_codec.rs +7aee4e507d7a5caf6511d4b5dbf498f54fc8a173720bb82179fc1524ee1e1c46 tests/retention_head_codec/mutation_laws.rs +4bb4bf560b64b517606eea9da34648f02496b7792ed246d13b2697e11f98025d tests/retention_manifest_codec.rs +3ffd936472e461101a16a945a46d6061e2d0471ff09935168f4940ed1618d051 tests/retention_manifest_codec/mutation_laws.rs +1aadf0d5d1610493cfef662feb46282dcef1c5a23bb3095c3cab2accc4f737db tests/retention_manifest_codec/refusal_laws.rs +2fd24dabec6c8be83e20f6e0339857f4aa277736d9f09120e46ee5ea55a136c5 tests/retention_preflight.rs +3868d606331b71ba9703be76ac206ad0969322f630568ebbd03f0b5894c4a283 tests/retention_publication_execution.rs +26a0b41f67e154b4a4166e1e5ae2978e9f9e5a12941ea5756b5ae1f36a95c102 tests/retention_publication_execution/refusal_laws.rs +5f6b5a900e8b16f31da2e1086b1e71a2618bad587d0016f482c0aa37daa9312d tests/retention_publication_phase.rs +1402cfa937f70b5550d1e2d55d2d0b87d3febd30374aca0b6917348a143defee tests/retention_publication_preparation.rs +b3ea3cfc249591ce9a6eeb2bd9c4316e86db542f29a950ef4e3947cd5663b5b4 tests/retention_publication_preparation/fixture.rs +9ddb78eca0270ff6d6efb7460d65e5f7068d1ae0d2bfc366e59d77c22b83c247 tests/retention_publication_preparation/initial_laws.rs +85bc08564a5acda5ec798ba0d8f8f43f754cab83f36acfcca85bfd82df7cd966 tests/retention_publication_preparation/refusal_laws.rs +4f4c571196c877d4bfd7a1ebe8298a0ccef471fc27e7a93d90a01e8e7773e489 tests/retention_publication_preparation/successor_laws.rs +9dd64a49f7fd42f0affa624301497eb1bda170e485e487f7e6d4bc76543732e5 tests/retention_publication_storage.rs +a9ab7b12063f7494a4ebe9a6e832648fe77ba77ca0bcba6b50a4c2f35b056733 tests/retention_publication_storage/recording_storage.rs +0948deb6cbe51ec43403a37b5c5254159cc71b41a9d845dddaeb9aeffe02dff0 tests/retention_root_decoding.rs +a128b6ecc591fa28e4aafa79d611fa2aa40c33b3b8604be83855321cdfb38890 tests/retention_root_decoding/mutation_laws.rs +a6069dfab4405f9bf4279260048d3d483528dbd0ef5a607376af1f73987e6432 tests/retention_root_encoding.rs +d427023b109df428abb488ea11a1f70c92c8d96fa3f86f68902c3fa4ffd9f4b7 tests/retention_stage_generation.rs +9839aadbfceb5602136495db7e0042a3f870c4962d43e46bf6784ee610295679 tests/retention_stage_prefix.rs +16194b7811a382a0c437aac99560dad92405ce940d204b8b12ee245df3074bf3 tests/retention_transition.rs +b8da8873f4a3636c2b5e794c1a09ff14f29e27046df3f93bc158ecf0e3e05f74 tests/retention_transition/refusal_laws.rs +e6db909117cba2bc8f106b56dc5a50f5606ed1f202bfcab9ec0a3041203bd320 tests/retention_values.rs +224dfd3612fce3d0d95e8772b0a042e28e417978df165e5f2824815b2c5a72ba tests/segment.rs +4f3ccfed4035c31d59b8198d532bd711a44aed83bed385f8439d2270ed614e9d tests/segment/format_oracle.rs +6893d65e18446db525f32e41ec06492e986b1e143edbb73a4158bd636a7e1a72 tests/segment/framing_laws.rs +80037ba56f7e4a40621befe110149d12b1cd6a15a24c186236ecec9e9f578413 tests/segment/identity_laws.rs +be77342ae44429b97a3f22f383256b2bf3912570ae149cb6aac51513fb52e664 tests/segment/record_checksum_oracle.rs +825a928859e396c8214719df57b98c39dd5740c9f3fb585a0f8e712f81c8eb23 tests/segment_filesystem_stage.rs +8e9dbf462b4655f9e304875f18f8536e475822cb8e4e201086bd1cd538f49820 tests/segment_filesystem_stage/sandbox.rs +a4a83d78b6d33cb5e910919ab43e36b32b5d40223efd54d55017ad16895282fe tests/segment_header.rs +11d5a339d6e4675aac2d553d2201ccdcb8e02a4e98515de65b1e3b1739a600f0 tests/segment_header/mutation_laws.rs +9a7c97ee2dcf0138754fbdc507d68e646047fe43297b3bd1306477de7636c989 tests/segment_memory.rs +6c17bddb3208b2b71e8d7c976b362fd41622c424faa714ceedd1f68d007cd153 tests/segment_record.rs +d88aadd020bc7e99a66ebf9449f8e460a494faeb302862377eb35cb254b6abc6 tests/segment_record/admission_laws.rs +195f6b6eb1a85e99c76b5a5de508bf6b5267f60cfc36bbb536a490436fac5499 tests/segment_record/framing_laws.rs +0967dd013206f18e22d7b6fba178586c461f7c5447c4194105349d02ed90f3e6 tests/segment_record_header.rs +1f9e8edfb451b75a24efa8a9e50b8ac712a2b550e17f256c795c2b0349829e9c tests/segment_record_header/framing_laws.rs +66574f0bb8a7cbab59b245736e0dabd6449b5fb34ba61f269ceed7a70579d7ad tests/segment_record_header/identity_laws.rs +9611d5719a2d42180b57ec0f8b92cb797adfe2d51649d6f0f8d077ab2e0c5ec3 tests/segment_record_memory.rs +8154e65c75c19436f3b39ee1d725b8bffcc5ea780bc538b49b7691a321433e38 tests/segment_seal.rs +943b575c2d4e465a2fa28a6da4b8effa6c7707596c754921775027331799ca6c tests/segment_seal/framing_laws.rs +effede835d7456d841493b59bfa5d8af907fb200319b063f6dee12472672cae0 tests/segment_seal/integrity_laws.rs +07f3431575d836ee7fc3f1f2b4b8fcfd204c51cf9cbcf672fa0b3cbdb0108649 tests/segment_seal/length_laws.rs +005ea0059435f72f5941de9046c42483d38e79591f9311009ef0b9272a07ed29 tests/segment_seal_memory.rs +9850150911bc56083067214f195ea34b0502b86e11e851d4ddd5f9ff585ca0a1 tests/segment_store_mutations.rs +c2d1457e1dbdc99277e1a4a04cf59c32cd4cc7d7ec0549abdd52115cab2d2e62 tests/segment_store_mutations/classify.rs +fd3c8bfc880ef9e883a3c624943f38b607703bfc758ec447c15a37054cadfee2 tests/segment_store_mutations/fixtures.rs +feea8edb814f8d3b64a92210b4a9d0b31f83710965f809a6bfe7694f5e60681d tests/segment_store_mutations/ledger.rs +44c846e6acb7e3b1939c1fb46f1aae8b0a7e56f170e211c30aa00231307dda81 tests/segment_store_mutations/recipes.rs +e38de9fec27cfcef63f350aef739ea6785152a355577459f4041d4ab3affabdb tests/segment_verification.rs +da54e7eead40e802e6e4ca641f9c8dfeea8fd8d82a9ec5a6981eaee371b4af2b tests/segment_verification/record_laws.rs +ad0796e6ce8dea90290c25f79a2b9e835adb9b32ede86427b44d87d00244d726 tests/segment_writer.rs +79eabed0f6f11c369fb9ae40a0524d677ced262b58372390bc56ea372b1963ee tests/segment_writer/durability_laws.rs +7c3e29f6848aaa3fe92791cb649250432195c052734bffbdc260044e4b3ad678 tests/segment_writer/refusal_laws.rs +092bd9129fa11f72f4cfa5dabd65f35810f7e76e4e9bf7d1ed5ac66ddd4d35da tests/segment_writer/stage_double.rs +7f86def7533fae4ff1f9ac23f1416ad67167b7cebd4ed56f407fbc619a433132 tests/segment_writer/write_contract_laws.rs +ad4d1e7454a66c73c5a15ce3fa0bc96e35d05298868236b0d1c1666924b2a2f3 tests/storage_profile_identity.rs +b5b8b7fdc53e6a0de0ad96e0b9cedac8ec3e7e145fe4045c6c93b609e0875eef tests/store_format_marker.rs +9872b64a55412b9a8d947830e4231be80a5937e7a32a9996a9f81e9c6c874222 tests/store_initialization.rs +f9d24eb908e8d18a6e34247a121e86536db43649648f8ced8c3fb6efb0e8493a tests/store_migration_compatibility.rs +a2c485bea3ae90bb385173c2bc63ec074bdb98e54e5bb9886e024cbd18888df5 tests/store_migration_execution.rs +daa03663f81a8a025e1e6b3105517bef603fc858be8289f0e3b0819c24352cda tests/store_migration_intent.rs +b574ffff037ecc7c9d1e56636b7bf73f3c601239bdaf51a8169648d424aa388e tests/store_migration_intent/fixture.rs +b2cf19ebc8473e85657bc4f2603992217e08bdedc3b0f032f3214c0decec7659 tests/store_migration_intent_encoding.rs +0e35d65785aef663ad4f8b7143c73565b1b008c97c1625ae2b72a8c2597ebc76 tests/store_migration_inventory.rs +a8385f5496f4e523c0c24305153535a821b4ba90cc8a58234c0cf3512a97ced2 tests/store_migration_phase.rs +1ec5e38510524c6c93af54269a97a97c3edc4009243d9f6e341a92a96a9617e6 tests/store_migration_receipt.rs +56e98bdea011383f6a246fd0c4248475165a529c4f5d1dc3462eff628b9cee59 tests/store_migration_receipt/binding_laws.rs +a7a7a87a75f18eabb3d76b41f90c4348c5c3cb5bc7b5f3c82dcda95ce6d4e42e tests/store_migration_receipt/fixture.rs +a09514f8e41b441f724627c2a741b3af5a6f37a93f3521a0ac8a56c51abc322b tests/store_migration_receipt/harness.rs +40c70075a5b593a609b9c47e4bbcff277152b7938cf221764b39db74b6960aa6 tests/store_migration_receipt_encoding.rs +5c759da82f2f9ebc063ccbe7dc943006634e4f99957ce042274192374614630e tests/store_migration_recovery.rs +790ae980900bc0b9b1e5074eeff43dcc1f3e78a1a4da1bf20197146464c5f0c7 tests/store_migration_recovery_order.rs +7e1db99be774cc99ffbf97bf4a79ed0c2b37b3a64f0dcec6b8d0c41ec54eab75 tests/store_migration_storage.rs +3edb62e70cb1119d1c1996f556c0a4e5f86d76fc49ffe0002beff23379cc9141 tests/store_migration_storage/recording_storage.rs +b82192b1dcea580923f2374de726bc4cfad7f7e8aba50a85c314bb8024863360 tests/streaming_cas.rs +deb0e0b4a654bc0c1d073620d120e79c56d8cb64e485b33c9aa071bedbdf5ddd tests/streaming_cas/ingestion_laws.rs +21ed741040ef47053d54211bba2244465b729ce2604370e59fd1229d6f4bbf1b tests/streaming_cas/model_laws.rs +82846f3b8f5facf18f096fd6e918d400f96a95a1b79a082740487abbcf7eaf92 tests/streaming_cas/reconstruction_laws.rs +7a3669814eded89de1c75d265f8da5a6302851c8edacdb8e9ea7794ca0c4d69a tests/streaming_cas/refusal_laws.rs +250748a88014900e45883c92bb437982814a29deae706dc911e9ba13a5e5844e tests/streaming_cas_memory.rs +6210d27c09d01457b122b35ea3cac576e807b156dd69d1c4b418197a1cdf90f3 tests/streaming_cdc.rs +2ce61ab8839d88bdeea0573f7033cc4e14f280d31b5b36284a7bd93d1a71af73 tests/streaming_cdc/boundary_corpus.rs +f9065965ce99881b7378b31c1fff76601ce9d4cb0a0deced3f9fb0d5a572c598 tests/streaming_cdc/detector_support.rs +4218862d67784e403fba01be0138bf0ef3370feb827a57b44870beda659a9eae tests/streaming_cdc/fixture_syntax.rs +1a5c40c9e9fd1573dd40b872b71b4ecca6a1c71ce963c116b66ea4724a829ce3 tests/streaming_cdc/harness_failure.rs +5dab6b3951f28cd76dca7bfac3d9c18090e979960f126fd3b79f21055d470935 tests/streaming_cdc/mutation_corpus.rs +1387c5645173f68a4f5349092148c053eeab554900d80bd3b6572f87c46a77d3 tests/streaming_cdc/source_corpus.rs +c16c23ff86c25c088fe02b7b1b90825df1ea3d3522d642575f8359960c1619b8 tests/streaming_cdc/suite.rs +d4d76596b90f900230f569ee8b0efc88f3dc2a23a55a61e042b056f5362a403e tests/streaming_cdc_memory.rs +3d282125ae8d7b306900cfd34331d8a852d862e584249edac4a63c1df73f42b4 tests/support/byte_patches.rs +593a79a824c8161089b5821481d1d85629c7e2cd88993d54bfb0554e23cf7f0e tests/support/byte_readers.rs +1a9e4feff3bd43785114342955c602df101646501b452099ab17965ff530d535 tests/support/byte_writers.rs +d9daf1811a146f95924036f2ba6052b8d373a61a067f5ca19454891a6bf75b9a tests/support/mod.rs +a1cda60b293b75957e87132fa7007f88dbed00b5f301cfc290e9b87127d57012 tests/transfer_pipeline_memory.rs +11bd01addb17c4e2408c9954346354daa293f3567e7586f32f178bfe73bd4c93 tests/verification_corruption/layout_decode.rs +bf058fa393e77f282c07ca9b85865a2e45f04fc7157621a0ef9c2f73f67573fb tests/verification_corruption/observation.rs +0b04198e4c798c52ad64b8d8d9a5648a137f990dd9b5530f227c6e1dd778987b tests/verification_corruption/root_decode.rs +613d08705ccc951200f995cf6d86ad5ac4ca6d3d2fab23ee55105cbc03cad14e tests/verification_ingress.rs +15cebf1bfe293dad90e53e4ad03c4e4eecb82a1ed7061c70205470d0e6a8da44 tests/verification_receipt.rs +5532c2015a276f7bbbb59a2eaf54593c3c5861e651893efb37c3d49767eedd03 tests/verification_receipt/matrix.rs +4337e5a79006e08de10784dceecae29fafd8dda58e3f9bd1aaaf11b6e183e6fb tests/verification_receipt/oracle.rs +cc184ca922a5c497c54873d04f542a451ce71afda760f1cd46fbd23549fd2491 tests/verification_report.rs +0926cc2f82363e843477593bff83d42de0254d865293e64daa776521b32226d2 tests/verification_view.rs +f976d6571b6fb7dde267237c72543952e27f580f9d830137d12be3d7194d02ae tests/version_two_admission_contract.rs diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-unit-build-2.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-unit-build-2.txt new file mode 100644 index 00000000..6169ee75 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-unit-build-2.txt @@ -0,0 +1,3 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `test` profile [unoptimized + debuginfo] target(s) in 4.00s + Executable unittests src/lib.rs (/build/keep107-coordinate-target/debug/deps/keep-d7b438b48cea5d61) diff --git a/docs/audits/pr-landing-evidence/107-integration/107-integration-unit-build.txt b/docs/audits/pr-landing-evidence/107-integration/107-integration-unit-build.txt new file mode 100644 index 00000000..1a3aba73 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-integration-unit-build.txt @@ -0,0 +1,602 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) +error[E0433]: cannot find `filesystem_retention_test_fixture` in `super` + --> src/adapters/retention/filesystem_retention_recovery_effect_tests.rs:92:16 + | +92 | super::filesystem_retention_test_fixture::catalog_policy()?, + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ could not find `filesystem_retention_test_fixture` in `super` + | +help: consider importing this module through its public re-export + | + 3 + use crate::adapters::filesystem_retention_test_fixture; + | +help: if you import `filesystem_retention_test_fixture`, refer to it directly + | +92 - super::filesystem_retention_test_fixture::catalog_policy()?, +92 + filesystem_retention_test_fixture::catalog_policy()?, + | + +error[E0433]: cannot find `filesystem_retention_test_fixture` in `super` + --> src/adapters/retention/filesystem_retention_recovery_storage_error_tests.rs:248:16 + | +248 | super::filesystem_retention_test_fixture::catalog_policy()?, + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ could not find `filesystem_retention_test_fixture` in `super` + | +help: consider importing this module through its public re-export + | + 3 + use crate::adapters::filesystem_retention_test_fixture; + | +help: if you import `filesystem_retention_test_fixture`, refer to it directly + | +248 - super::filesystem_retention_test_fixture::catalog_policy()?, +248 + filesystem_retention_test_fixture::catalog_policy()?, + | + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/compaction/filesystem_tests.rs:102:52 + | +102 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | + 29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | + 51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... + 68 | / pub fn reopen_unchecked_for_repository_tasks( + 69 | | store_root: &Path, + 70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +102 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +102 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/compaction/test_fixture.rs:75:52 + | +75 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | +29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | +51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... +68 | / pub fn reopen_unchecked_for_repository_tasks( +69 | | store_root: &Path, +70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +75 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +75 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/compaction/test_fixture.rs:159:52 + | +159 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(root)?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | + 29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | + 51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... + 68 | / pub fn reopen_unchecked_for_repository_tasks( + 69 | | store_root: &Path, + 70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +159 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(root)?; +159 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(root)?; + | + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/durable/ingestion_bound_tests.rs:18:52 + | +18 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | +29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | +51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... +68 | / pub fn reopen_unchecked_for_repository_tasks( +69 | | store_root: &Path, +70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +18 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +18 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0599]: no variant named `RetainedRoot` found for enum `durable::error::DurableStoreError` + --> src/adapters/durable/refusal_source_tests.rs:33:49 + | +33 | assert!(matches!(&error, DurableStoreError::RetainedRoot { .. })); + | ^^^^^^^^^^^^ variant not found in `durable::error::DurableStoreError` + | + ::: src/adapters/durable/error.rs:17:1 + | +17 | pub enum DurableStoreError { + | -------------------------- variant `RetainedRoot` not found here + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/durable/test_fixture.rs:89:52 + | +89 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | +29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | +51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... +68 | / pub fn reopen_unchecked_for_repository_tasks( +69 | | store_root: &Path, +70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +89 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +89 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0308]: mismatched types + --> src/adapters/durable/tests.rs:24:8 + | + 24 | Ok(DurableStore::open( + | _____--_^ + | | | + | | arguments to this enum variant are incorrect + 25 | | root, + 26 | | catalog_policy()?, + 27 | | ReaderAttemptLimit::DEFAULT, + 28 | | )) + | |_____^ expected `DurableStore`, found `Result` + | + = note: expected struct `durable::store::DurableStore` + found enum `Result` +help: the type constructed contains `Result` due to the type of the argument passed + --> src/adapters/durable/tests.rs:24:5 + | + 24 | Ok(DurableStore::open( + | _____^ - + | |________| + 25 | || root, + 26 | || catalog_policy()?, + 27 | || ReaderAttemptLimit::DEFAULT, + 28 | || )) + | ||_____-^ + | |______| + | this argument influences the type of `Ok` +note: tuple variant defined here + --> /usr/local/rustup/toolchains/1.96.0-aarch64-unknown-linux-gnu/lib/rustlib/src/rust/library/core/src/result.rs:561:5 + | +561 | Ok(#[stable(feature = "rust1", since = "1.0.0")] T), + | ^^ +help: use the `?` operator to extract the `Result` value, propagating a `Result::Err` value to the caller + | + 28 | )?) + | + + +error[E0308]: mismatched types + --> src/adapters/durable/tests.rs:48:9 + | +47 | snapshot.view().retention(), + | --------------------------- this expression has type `Option` +48 | crate::adapters::GcRetentionState::Published { generation, .. } if generation.get() == 1 + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ expected `Option`, found `GcRetentionState` + | + = note: expected enum `Option` + found enum `liveness_coordinates::GcRetentionState` + +error[E0600]: cannot apply unary operator `!` to type `Result` + --> src/adapters/durable/tests.rs:51:9 + | + 51 | assert!(snapshot.contains_blob(entry.target)); + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ cannot apply unary operator `!` + | +note: `Result` does not implement `Not` + --> /usr/local/rustup/toolchains/1.96.0-aarch64-unknown-linux-gnu/lib/rustlib/src/rust/library/core/src/result.rs:557:1 + | +557 | pub enum Result { + | ^^^^^^^^^^^^^^^^^^^^^ `Result` is defined in another crate + +error[E0600]: cannot apply unary operator `!` to type `Result` + --> src/adapters/durable/tests.rs:104:13 + | +104 | assert!(!snapshot.contains_blob(unanchored.target)); + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ cannot apply unary operator `!` + | +note: `Result` does not implement `Not` + --> /usr/local/rustup/toolchains/1.96.0-aarch64-unknown-linux-gnu/lib/rustlib/src/rust/library/core/src/result.rs:557:1 + | +557 | pub enum Result { + | ^^^^^^^^^^^^^^^^^^^^^ `Result` is defined in another crate + +error[E0308]: mismatched types + --> src/adapters/durable/tests.rs:135:9 + | +134 | let view = FilesystemRetentionSnapshot::load_under_writer_authority( + | -------------------------------------------------------- arguments to this function are incorrect +135 | sandbox.path(), + | ^^^^^^^^^^^^^^ expected `&Dir`, found `&Path` + | + = note: expected reference `&cap_std::fs::Dir` + found reference `&Path` +note: associated function defined here + --> src/adapters/retention/filesystem_retention_snapshot.rs:159:32 + | +159 | pub(in crate::adapters) fn load_under_writer_authority( + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^ +160 | root: &Dir, + | ---------- + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/durable/tests.rs:141:52 + | +141 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | + 29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | + 51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... + 68 | / pub fn reopen_unchecked_for_repository_tasks( + 69 | | store_root: &Path, + 70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +141 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +141 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0308]: mismatched types + --> src/adapters/durable/tests.rs:165:9 + | +164 | let fenced = FilesystemRetentionSnapshot::load_under_writer_authority( + | -------------------------------------------------------- arguments to this function are incorrect +165 | sandbox.path(), + | ^^^^^^^^^^^^^^ expected `&Dir`, found `&Path` + | + = note: expected reference `&cap_std::fs::Dir` + found reference `&Path` +note: associated function defined here + --> src/adapters/retention/filesystem_retention_snapshot.rs:159:32 + | +159 | pub(in crate::adapters) fn load_under_writer_authority( + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^ +160 | root: &Dir, + | ---------- + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/durable/tests.rs:180:52 + | +180 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | + 29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | + 51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... + 68 | / pub fn reopen_unchecked_for_repository_tasks( + 69 | | store_root: &Path, + 70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +180 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +180 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0599]: no method named `snapshot` found for enum `Result` in the current scope + --> src/adapters/durable/transfer_tests.rs:32:6 + | + 27 | let snapshot = DurableStore::open( + | ____________________- + 28 | | sandbox.path(), + 29 | | catalog_policy()?, + 30 | | ReaderAttemptLimit::DEFAULT, + 31 | | ) + 32 | | .snapshot()?; + | | -^^^^^^^^ method not found in `Result` + | |_____| + | + | +note: the method `snapshot` exists on the type `durable::store::DurableStore` + --> src/adapters/durable/store.rs:106:5 + | +106 | pub fn snapshot(&self) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +help: use the `?` operator to extract the `durable::store::DurableStore` value, propagating a `Result::Err` value to the caller + | + 31 | )? + | + + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/durable/transfer_tests.rs:64:52 + | +64 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | +29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | +51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... +68 | / pub fn reopen_unchecked_for_repository_tasks( +69 | | store_root: &Path, +70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +64 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(sandbox.path())?; +64 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(sandbox.path())?; + | + +error[E0599]: no method named `snapshot` found for enum `Result` in the current scope + --> src/adapters/durable/transfer_tests.rs:80:6 + | + 75 | let snapshot = DurableStore::open( + | ____________________- + 76 | | sandbox.path(), + 77 | | catalog_policy()?, + 78 | | ReaderAttemptLimit::DEFAULT, + 79 | | ) + 80 | | .snapshot()?; + | | -^^^^^^^^ method not found in `Result` + | |_____| + | + | +note: the method `snapshot` exists on the type `durable::store::DurableStore` + --> src/adapters/durable/store.rs:106:5 + | +106 | pub fn snapshot(&self) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +help: use the `?` operator to extract the `durable::store::DurableStore` value, propagating a `Result::Err` value to the caller + | + 79 | )? + | + + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/durable/writer_tests.rs:23:52 + | +23 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(root)?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | +29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | +51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... +68 | / pub fn reopen_unchecked_for_repository_tasks( +69 | | store_root: &Path, +70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +23 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(root)?; +23 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(root)?; + | + +error[E0599]: no method named `snapshot` found for enum `Result` in the current scope + --> src/adapters/durable/writer_tests.rs:67:6 + | + 62 | let snapshot = DurableStore::open( + | ____________________- + 63 | | sandbox.path(), + 64 | | catalog_policy()?, + 65 | | ReaderAttemptLimit::DEFAULT, + 66 | | ) + 67 | | .snapshot()?; + | | -^^^^^^^^ method not found in `Result` + | |_____| + | + | +note: the method `snapshot` exists on the type `durable::store::DurableStore` + --> src/adapters/durable/store.rs:106:5 + | +106 | pub fn snapshot(&self) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +help: use the `?` operator to extract the `durable::store::DurableStore` value, propagating a `Result::Err` value to the caller + | + 66 | )? + | + + +error[E0599]: no method named `snapshot` found for enum `Result` in the current scope + --> src/adapters/durable/writer_tests.rs:119:6 + | +114 | let snapshot = DurableStore::open( + | ____________________- +115 | | sandbox.path(), +116 | | catalog_policy()?, +117 | | ReaderAttemptLimit::DEFAULT, +118 | | ) +119 | | .snapshot()?; + | | -^^^^^^^^ method not found in `Result` + | |_____| + | + | +note: the method `snapshot` exists on the type `durable::store::DurableStore` + --> src/adapters/durable/store.rs:106:5 + | +106 | pub fn snapshot(&self) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +help: use the `?` operator to extract the `durable::store::DurableStore` value, propagating a `Result::Err` value to the caller + | +118 | )? + | + + +error[E0599]: no method named `snapshot` found for enum `Result` in the current scope + --> src/adapters/durable/writer_tests.rs:165:6 + | +160 | let snapshot = DurableStore::open( + | ____________________- +161 | | sandbox.path(), +162 | | catalog_policy()?, +163 | | ReaderAttemptLimit::DEFAULT, +164 | | ) +165 | | .snapshot()?; + | | -^^^^^^^^ method not found in `Result` + | |_____| + | + | +note: the method `snapshot` exists on the type `durable::store::DurableStore` + --> src/adapters/durable/store.rs:106:5 + | +106 | pub fn snapshot(&self) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +help: use the `?` operator to extract the `durable::store::DurableStore` value, propagating a `Result::Err` value to the caller + | +164 | )? + | + + +error[E0599]: no method named `snapshot` found for enum `Result` in the current scope + --> src/adapters/durable/writer_tests.rs:242:6 + | +237 | let snapshot = DurableStore::open( + | ____________________- +238 | | sandbox.path(), +239 | | catalog_policy()?, +240 | | ReaderAttemptLimit::DEFAULT, +241 | | ) +242 | | .snapshot()?; + | | -^^^^^^^^ method not found in `Result` + | |_____| + | + | +note: the method `snapshot` exists on the type `durable::store::DurableStore` + --> src/adapters/durable/store.rs:106:5 + | +106 | pub fn snapshot(&self) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +help: use the `?` operator to extract the `durable::store::DurableStore` value, propagating a `Result::Err` value to the caller + | +241 | )? + | + + +error[E0600]: cannot apply unary operator `!` to type `Result` + --> src/adapters/durable/writer_tests.rs:244:5 + | +244 | assert!(ContentReads::contains_blob(&snapshot, anchored.target)); + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ cannot apply unary operator `!` + | +note: `Result` does not implement `Not` + --> /usr/local/rustup/toolchains/1.96.0-aarch64-unknown-linux-gnu/lib/rustlib/src/rust/library/core/src/result.rs:557:1 + | +557 | pub enum Result { + | ^^^^^^^^^^^^^^^^^^^^^ `Result` is defined in another crate + +error[E0599]: no associated function or constant named `reopen_unchecked_for_tests` found for struct `filesystem_version_two_admission::FilesystemVersionTwoAdmission` in the current scope + --> src/adapters/gc/filesystem_gc_tests.rs:57:52 + | +57 | let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(root)?; + | ^^^^^^^^^^^^^^^^^^^^^^^^^^ associated function or constant not found in `filesystem_version_two_admission::FilesystemVersionTwoAdmission` + | + ::: src/adapters/filesystem_version_two_admission.rs:29:1 + | +29 | pub struct FilesystemVersionTwoAdmission { + | ---------------------------------------- associated function or constant `reopen_unchecked_for_tests` not found for this struct + | +note: if you're trying to build a new `filesystem_version_two_admission::FilesystemVersionTwoAdmission` consider using one of the following associated functions: + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen + filesystem_version_two_admission::FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks + --> src/adapters/filesystem_version_two_admission.rs:51:5 + | +51 | pub fn reopen(store_root: &Path) -> Result { + | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +... +68 | / pub fn reopen_unchecked_for_repository_tasks( +69 | | store_root: &Path, +70 | | ) -> Result { + | |_______________________________________________________^ +help: there is an associated function `reopen_unchecked_for_repository_tasks` with a similar name + | +57 - let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_tests(root)?; +57 + let admission = FilesystemVersionTwoAdmission::reopen_unchecked_for_repository_tasks(root)?; + | + +Some errors have detailed explanations: E0308, E0433, E0599, E0600. +For more information about an error, try `rustc --explain E0308`. +error: could not compile `keep` (lib test) due to 26 previous errors diff --git a/docs/audits/pr-landing-evidence/107-integration/107-provenance-parent-probe.rs b/docs/audits/pr-landing-evidence/107-integration/107-provenance-parent-probe.rs new file mode 100644 index 00000000..9811a5e0 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-provenance-parent-probe.rs @@ -0,0 +1,35 @@ +//! Runtime reproduction against the unfixed PR's original infallible projection API. +mod support; +use std::{error::Error, io::Cursor}; +use keep::{BlobId, CanonicalVerificationReceipt, LayoutEntryLimit, ReferenceStore, + ReferenceStoreCapacity, VerificationDepth, VerificationError, VerificationReceipt, + VerificationSubject, VerificationView}; + +fn unrelated_durable_view() -> Result> { + let bytes = support::decode_hex(include_str!("../conformance/verification-receipt/v1/durable-corrupt-chunk-refusal.hex").trim())?; + Ok(CanonicalVerificationReceipt::decode(&bytes)?.receipt().view()) +} + +#[test] +fn reference_report_must_not_acquire_unrelated_durable_provenance() -> Result<(), Box> { + let mut store = ReferenceStore::new(ReferenceStoreCapacity::new(1_048_576)); + let published = store.stage(&mut Cursor::new(b"reference only"), LayoutEntryLimit::MAXIMUM)?.commit(&mut store)?; + let report = store.verify(VerificationSubject::Blob(published.target()), VerificationDepth::CompleteBlobIdentity)?; + let unrelated = unrelated_durable_view()?; + let projected = VerificationReceipt::from_report(&report, unrelated); + assert_ne!(projected.view(), unrelated, "reference report must not acquire unrelated durable provenance"); + Ok(()) +} + +#[test] +fn reference_refusal_must_not_acquire_unrelated_durable_provenance() -> Result<(), Box> { + let store = ReferenceStore::new(ReferenceStoreCapacity::new(1_048_576)); + let target = BlobId::hash_bytes(b"absent reference blob")?; + let Err(VerificationError::Refused(refusal)) = store.verify(VerificationSubject::Blob(target), VerificationDepth::CompleteBlobIdentity) else { + return Err("expected reference absence".into()); + }; + let unrelated = unrelated_durable_view()?; + let projected = VerificationReceipt::from_refusal(&refusal, unrelated); + assert_ne!(projected.view(), unrelated, "reference refusal must not acquire unrelated durable provenance"); + Ok(()) +} diff --git a/docs/audits/pr-landing-evidence/107-integration/107-provenance-parent-red.txt b/docs/audits/pr-landing-evidence/107-integration/107-provenance-parent-red.txt new file mode 100644 index 00000000..afdff1fa --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-provenance-parent-red.txt @@ -0,0 +1,70 @@ + Compiling rustix v1.1.4 + Compiling bitflags v2.13.1 + Compiling io-lifetimes v2.0.4 + Compiling io-lifetimes v3.0.1 + Compiling linux-raw-sys v0.12.1 + Compiling io-extras v0.19.0 + Compiling proc-macro2 v1.0.107 + Compiling find-msvc-tools v0.1.9 + Compiling once_cell v1.21.4 + Compiling cap-primitives v4.0.2 + Compiling shlex v2.0.1 + Compiling unicode-ident v1.0.24 + Compiling quote v1.0.47 + Compiling ambient-authority v0.0.2 + Compiling maybe-owned v0.3.4 + Compiling cap-std v4.0.2 + Compiling ipnet v2.12.0 + Compiling libc v0.2.186 + Compiling anstyle v1.0.14 + Compiling clap_lex v1.1.0 + Compiling cc v1.3.0 + Compiling cap-fs-ext v4.0.2 + Compiling cfg-if v1.0.4 + Compiling clap_builder v4.6.2 + Compiling arrayref v0.3.9 + Compiling arrayvec v0.7.8 + Compiling constant_time_eq v0.4.2 + Compiling condtype v1.3.0 + Compiling regex-lite v0.1.9 + Compiling allocation-counter v0.8.1 + Compiling syn v2.0.119 + Compiling blake3 v1.8.5 + Compiling clap v4.6.4 + Compiling fs-set-times v0.20.3 + Compiling rustix-linux-procfs v0.1.1 + Compiling divan-macros v0.1.21 + Compiling keep v0.0.0 (/build/keep107-coordinate-source) + Compiling divan v0.1.21 + Finished `test` profile [unoptimized + debuginfo] target(s) in 3.12s + Running tests/verification_provenance_regression.rs (/build/keep107-root-binding-parent-target/debug/deps/verification_provenance_regression-3769290823161818) + +running 2 tests +test reference_refusal_must_not_acquire_unrelated_durable_provenance ... FAILED +test reference_report_must_not_acquire_unrelated_durable_provenance ... FAILED + +failures: + +---- reference_refusal_must_not_acquire_unrelated_durable_provenance stdout ---- + +thread 'reference_refusal_must_not_acquire_unrelated_durable_provenance' (893) panicked at tests/verification_provenance_regression.rs:33:5: +assertion `left != right` failed: reference refusal must not acquire unrelated durable provenance + left: Durable { catalog_generation: CatalogGeneration(2), catalog_digest: CatalogDigest([234, 125, 0, 85, 253, 33, 240, 14, 217, 72, 9, 239, 78, 103, 29, 114, 250, 46, 106, 74, 93, 158, 206, 251, 35, 243, 163, 32, 162, 218, 217, 147]), retention: Published { generation: LivenessGeneration(1), manifest_digest: RetentionManifestDigest([244, 107, 150, 162, 191, 51, 121, 50, 12, 245, 158, 138, 241, 91, 157, 16, 141, 224, 96, 37, 196, 21, 48, 123, 40, 149, 55, 20, 189, 122, 128, 235]) } } + right: Durable { catalog_generation: CatalogGeneration(2), catalog_digest: CatalogDigest([234, 125, 0, 85, 253, 33, 240, 14, 217, 72, 9, 239, 78, 103, 29, 114, 250, 46, 106, 74, 93, 158, 206, 251, 35, 243, 163, 32, 162, 218, 217, 147]), retention: Published { generation: LivenessGeneration(1), manifest_digest: RetentionManifestDigest([244, 107, 150, 162, 191, 51, 121, 50, 12, 245, 158, 138, 241, 91, 157, 16, 141, 224, 96, 37, 196, 21, 48, 123, 40, 149, 55, 20, 189, 122, 128, 235]) } } +note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace + +---- reference_report_must_not_acquire_unrelated_durable_provenance stdout ---- + +thread 'reference_report_must_not_acquire_unrelated_durable_provenance' (894) panicked at tests/verification_provenance_regression.rs:20:5: +assertion `left != right` failed: reference report must not acquire unrelated durable provenance + left: Durable { catalog_generation: CatalogGeneration(2), catalog_digest: CatalogDigest([234, 125, 0, 85, 253, 33, 240, 14, 217, 72, 9, 239, 78, 103, 29, 114, 250, 46, 106, 74, 93, 158, 206, 251, 35, 243, 163, 32, 162, 218, 217, 147]), retention: Published { generation: LivenessGeneration(1), manifest_digest: RetentionManifestDigest([244, 107, 150, 162, 191, 51, 121, 50, 12, 245, 158, 138, 241, 91, 157, 16, 141, 224, 96, 37, 196, 21, 48, 123, 40, 149, 55, 20, 189, 122, 128, 235]) } } + right: Durable { catalog_generation: CatalogGeneration(2), catalog_digest: CatalogDigest([234, 125, 0, 85, 253, 33, 240, 14, 217, 72, 9, 239, 78, 103, 29, 114, 250, 46, 106, 74, 93, 158, 206, 251, 35, 243, 163, 32, 162, 218, 217, 147]), retention: Published { generation: LivenessGeneration(1), manifest_digest: RetentionManifestDigest([244, 107, 150, 162, 191, 51, 121, 50, 12, 245, 158, 138, 241, 91, 157, 16, 141, 224, 96, 37, 196, 21, 48, 123, 40, 149, 55, 20, 189, 122, 128, 235]) } } + + +failures: + reference_refusal_must_not_acquire_unrelated_durable_provenance + reference_report_must_not_acquire_unrelated_durable_provenance + +test result: FAILED. 0 passed; 2 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + +error: test failed, to rerun pass `--test verification_provenance_regression` diff --git a/docs/audits/pr-landing-evidence/107-integration/107-reference-consumers-debug.txt b/docs/audits/pr-landing-evidence/107-integration/107-reference-consumers-debug.txt new file mode 100644 index 00000000..7ecc6516 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-reference-consumers-debug.txt @@ -0,0 +1,14 @@ + Checking keep v0.0.0 (/build/keep107-integration-round2) + Finished `dev` profile [unoptimized + debuginfo] target(s) in 2.38s + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `test` profile [unoptimized + debuginfo] target(s) in 2.93s + +running 5 tests +test unsupported_depths_refuse_with_the_exact_supported_set ... ok + Running tests/verification_report.rs (/build/keep107-coordinate-target/debug/deps/verification_report-f5826e29a50f794b) +test a_wrong_target_passes_chunk_identity_and_fails_only_the_complete_blob ... ok +test a_report_establishes_exactly_the_requested_depth ... ok +test absent_subjects_are_missing_evidence_against_the_complete_view ... ok +test false_profile_boundaries_pass_chunk_identity_and_fail_only_the_complete_blob ... ok + +test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s diff --git a/docs/audits/pr-landing-evidence/107-integration/107-root-binding-green-1.txt b/docs/audits/pr-landing-evidence/107-integration/107-root-binding-green-1.txt new file mode 100644 index 00000000..fe6a95d7 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-root-binding-green-1.txt @@ -0,0 +1,9 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `test` profile [unoptimized + debuginfo] target(s) in 3.03s + Running tests/gc_authority_root.rs (/build/keep107-coordinate-target/debug/deps/gc_authority_root-77a332d5e3506dac) + +running 2 tests +test compaction_refuses_an_observation_locator_for_another_store ... ok +test gc_refuses_an_observation_locator_for_another_store ... ok + +test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.31s diff --git a/docs/audits/pr-landing-evidence/107-integration/107-root-binding-red-1.txt b/docs/audits/pr-landing-evidence/107-integration/107-root-binding-red-1.txt new file mode 100644 index 00000000..cc2cfdfc --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-root-binding-red-1.txt @@ -0,0 +1,61 @@ + Compiling rustix v1.1.4 + Compiling io-lifetimes v3.0.1 + Compiling bitflags v2.13.1 + Compiling io-lifetimes v2.0.4 + Compiling linux-raw-sys v0.12.1 + Compiling io-extras v0.19.0 + Compiling proc-macro2 v1.0.107 + Compiling quote v1.0.47 + Compiling once_cell v1.21.4 + Compiling cap-primitives v4.0.2 + Compiling shlex v2.0.1 + Compiling find-msvc-tools v0.1.9 + Compiling unicode-ident v1.0.24 + Compiling maybe-owned v0.3.4 + Compiling ambient-authority v0.0.2 + Compiling cap-std v4.0.2 + Compiling ipnet v2.12.0 + Compiling libc v0.2.186 + Compiling clap_lex v1.1.0 + Compiling cap-fs-ext v4.0.2 + Compiling cfg-if v1.0.4 + Compiling cc v1.3.0 + Compiling anstyle v1.0.14 + Compiling arrayref v0.3.9 + Compiling constant_time_eq v0.4.2 + Compiling arrayvec v0.7.8 + Compiling condtype v1.3.0 + Compiling regex-lite v0.1.9 + Compiling allocation-counter v0.8.1 + Compiling clap_builder v4.6.2 + Compiling syn v2.0.119 + Compiling blake3 v1.8.5 + Compiling clap v4.6.4 + Compiling rustix-linux-procfs v0.1.1 + Compiling fs-set-times v0.20.3 + Compiling divan-macros v0.1.21 + Compiling keep v0.0.0 (/build/keep107-coordinate-source) + Compiling divan v0.1.21 + Finished `test` profile [unoptimized + debuginfo] target(s) in 3.78s + Running tests/gc_authority_root.rs (/build/keep107-root-binding-parent-target/debug/deps/gc_authority_root-77a332d5e3506dac) + +running 2 tests +test gc_refuses_an_observation_locator_for_another_store ... FAILED +test compaction_refuses_an_observation_locator_for_another_store ... FAILED + +failures: + +---- gc_refuses_an_observation_locator_for_another_store stdout ---- +Error: Io { phase: AdmitPlatform, source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } } + +---- compaction_refuses_an_observation_locator_for_another_store stdout ---- +Error: Io { phase: AdmitPlatform, source: Custom { kind: Unsupported, error: "store namespace does not satisfy one local writable case-sensitive ext4 profile" } } + + +failures: + compaction_refuses_an_observation_locator_for_another_store + gc_refuses_an_observation_locator_for_another_store + +test result: FAILED. 0 passed; 2 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s + +error: test failed, to rerun pass `--test gc_authority_root` diff --git a/docs/audits/pr-landing-evidence/107-integration/107-root-binding-red-2.txt b/docs/audits/pr-landing-evidence/107-integration/107-root-binding-red-2.txt new file mode 100644 index 00000000..190c8489 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-root-binding-red-2.txt @@ -0,0 +1,23 @@ + Finished `test` profile [unoptimized + debuginfo] target(s) in 0.02s + Running tests/gc_authority_root.rs (/build/keep107-root-binding-parent-target/debug/deps/gc_authority_root-77a332d5e3506dac) + +running 2 tests +test compaction_refuses_an_observation_locator_for_another_store ... FAILED +test gc_refuses_an_observation_locator_for_another_store ... FAILED + +failures: + +---- compaction_refuses_an_observation_locator_for_another_store stdout ---- +Error: "compaction must refuse mixed authority and observation roots before effects" + +---- gc_refuses_an_observation_locator_for_another_store stdout ---- +Error: "GC must refuse mixed authority and observation roots before effects" + + +failures: + compaction_refuses_an_observation_locator_for_another_store + gc_refuses_an_observation_locator_for_another_store + +test result: FAILED. 0 passed; 2 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.71s + +error: test failed, to rerun pass `--test gc_authority_root` diff --git a/docs/audits/pr-landing-evidence/107-integration/107-verification-receipt-green-1.txt b/docs/audits/pr-landing-evidence/107-integration/107-verification-receipt-green-1.txt new file mode 100644 index 00000000..f0e7fc52 --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/107-verification-receipt-green-1.txt @@ -0,0 +1,15 @@ + Compiling keep v0.0.0 (/build/keep107-integration-round2) + Finished `test` profile [unoptimized + debuginfo] target(s) in 2.34s + Running tests/verification_receipt.rs (/build/keep107-coordinate-target/debug/deps/verification_receipt-443fd900bf0a4d6d) + +running 8 tests +test a_reference_refusal_cannot_be_relabeled_as_durable ... ok +test golden_receipts_match_the_oracle_and_decode_from_another_process ... ok +test a_reference_report_cannot_be_relabeled_as_durable ... ok +test the_golden_report_and_refusals_state_exactly_their_frozen_coordinates ... ok +test every_reference_store_outcome_projects_and_round_trips ... ok +test a_refusal_never_decodes_as_a_report_and_a_report_never_as_a_refusal ... ok +test snapshot_binding_is_refused_instead_of_encoded_as_another_depth ... ok +test every_structural_field_has_one_exact_first_refusal ... ok + +test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s diff --git a/docs/audits/pr-landing-evidence/107-integration/README.md b/docs/audits/pr-landing-evidence/107-integration/README.md new file mode 100644 index 00000000..7bc8dedd --- /dev/null +++ b/docs/audits/pr-landing-evidence/107-integration/README.md @@ -0,0 +1,36 @@ +# PR 107 integration checkpoint + +Change kinds: bug fixes for mixed-store authority and receipt provenance; integration adaptations preserving main's fallible reads, subject-specific verification and typed error sources. This is unfinished local work combining PR `7cdc2cfbef59407f3c38881b39a290cb85501f9b` with main `3165890e9291cfb5fe10e81a9d7cd151f3e59464`, not a reviewed candidate or a landed change. Owner: `@flyingrobots`; the change author supplies evidence and an independent reviewer must assess the eventual exact candidate. + +The [source manifest](107-integration-source-sha256.txt) identifies the checkpoint's source and tests. Prior runs belong to their recorded incremental source states; they are not represented as validation of an immutable integration commit. The complete working copy and staged patch are preserved locally while documentation and tooling merge conflicts remain. Committed log copies omit surplus terminal blank lines; the original outputs remain preserved locally. + +## Claims and runtime evidence + +| Claim and independent oracle | Falsification | Current focused evidence and limits | +| --- | --- | --- | +| GC and compaction mutation authority cannot accept an observation locator naming another complete store. Oracle: admitted device/inode identity, the exact typed mismatch and unchanged bytes in both stores. | [Parent runtime RED](107-root-binding-red-2.txt) fails both intended public assertions on the unfixed PR. The parent product authority source was verified against `7cdc2cf`; only the test and shared fixture were supplied. [First attempt](107-root-binding-red-1.txt) failed ext4 setup and is invalid RED. | [Debug](107-integration-focused-debug.txt) and [release](107-integration-focused-release.txt) pass the public laws with capability-bound observations. This does not prove atomic pathname mutation against arbitrary concurrent raw namespace changes or close the remaining nested-directory/effect review. | +| Reference reports and refusals cannot acquire caller-selected durable provenance. Oracle: reference operations observed no durable catalog or retention view. | [Parent probe](107-provenance-parent-probe.rs) and [runtime RED](107-provenance-parent-red.txt) demonstrate both relabelings through the original infallible APIs. The probe adapts to that historical API; it is not byte-identical to the new fallible regression. | Checked projections reject `ViewMismatch`; [debug](107-integration-focused-debug.txt) and [release](107-integration-focused-release.txt) pass. Frozen report/refusal bytes match the independent codec oracle and live reference projections. `SnapshotBinding` has no v1 wire slot and is refused. Live durable projection remains unsupported; decoding historical durable receipts grants no live verification authority. | +| Reference verification preserves the requested subject/depth, missing evidence, corruption coordinates and exact supported set. Oracle: explicit public claims, known bytes and deliberately contradictory layouts. | Existing wrong-target, missing-chunk and profile-boundary cases remain permanent runtime checks. This checkpoint does not claim fresh mutation calibration of every inherited assertion. | [Consumer adaptation](107-reference-consumers-debug.txt) and [release](107-integration-focused-release.txt) pass. Main's catalog/blob/segment/view laws also pass in the [focused debug run](107-integration-focused-debug.txt). No global depth ordering is inferred. | +| Durable reads, ingestion, transfer, reader fencing, GC restart prefixes and ordinary compaction retain their existing runtime outcomes. Oracle: exact reconstructed bytes, typed refusals, published coordinates and reopened state. | The [initial run](107-integrated-runtime-debug.txt) used an overlay-backed unit-test scratch directory and failed platform admission; it is setup failure, not product RED. | The corrected ext4 [debug run](107-integrated-runtime-debug-2.txt) and [release run](107-integrated-runtime-release.txt) pass these focused groups. The release log subsequently records failed Clippy consumer checks; the final [Clippy and segment-law run](107-integration-clippy-tests-4.txt) passes after the documented adaptations. Existing passing compaction laws do not close the separate recovery findings. | + +## Execution and policy boundaries + +All Rust execution used a copied Linux aarch64 Docker source tree, pinned Rust/Cargo 1.96.0, locked offline dependency resolution and `CARGO_INCREMENTAL=0`. Filesystem runtime laws used the existing ext4 loop image, with separate bind-mounted scratch directories for integration and unit tests. The first unit run's fallback scratch path was on overlay; mounting that path on ext4 corrected the setup without changing product code. + +The exact focused commands are `cargo test --locked --test gc_authority_root --test verification_receipt --test catalog_verification --test catalog_verification_ceiling --test segment_verification --test blob_verification --test verification_ingress --test verification_view --test content_store_port`, `cargo test --locked --test verification_report`, and the corresponding `--release` run for `gc_authority_root`, `verification_receipt` and `verification_report`. Unit groups run with `cargo test --locked --lib` followed by each filter `reference::verification`, `adapters::durable::`, `adapters::gc::filesystem_gc_tests` and `adapters::compaction::filesystem_tests`, in both profiles. Final static validation uses `cargo clippy --locked --lib --tests --all-features -- -D warnings`; the subsequent segment commands select `segment_verification` and `segment_store_mutations`. Formatting uses `cargo fmt --package keep` in Docker. + +Reference/codec laws are small; real-filesystem laws are medium. These runs establish no per-test resource ceilings, egress sandbox, measured suite budget or complete policy compliance. Those remain an explicit landing gate; the approved #106 waiver does not apply. No new nondeterministic schedule or sleep was introduced. Existing interrupted-prefix laws exercise their recorded deterministic protocol boundaries, not physical power loss. This is not the full workspace, crash, fuzz, dependency, documentation or final hosted acceptance chain. + +The original [unit compilation failure](107-integration-unit-build.txt), [successful rebuilt unit executable](107-integration-unit-build-2.txt), and intermediate [Clippy failures](107-integration-clippy-tests-2.txt) with [fixture visibility follow-up](107-integration-clippy-tests-3.txt) remain preserved. They are static evidence only. The initial [receipt run](107-verification-receipt-green-1.txt) and [root-binding run](107-root-binding-green-1.txt) are historical incremental checks, not additional independent approvals. + +## Expectation and deletion decisions + +The former global-depth-order assertions in `verification_report` and `ledger_stages_order_like_verification_depths` are removed because main deliberately makes depths subject-specific and Eq-only. They asserted enum ordering, not a runtime verification promise. Exact supported-set refusals, requested-depth reports, frozen wire code checks and every frozen mutation's first-refusal assertion remain; wire code order is confined to the v1 codec. + +The source-string test `reference_chunk_reads_do_not_depend_on_transfer_adapters` is removed because it depended on the moved `reference/chunk_reader.rs` path and a spelling search that could reject comments or miss aliased imports. Architectural dependency direction remains a source-review obligation, not a claim of automated enforcement; reference/durable transfer runtime tests remain. The unused old verification error/display modules are removed after their consumers move to main's typed boundary errors; reference stage context is preserved in the shared error source. + +Receipt callers now handle a typed projection result instead of assuming every supplied view is truthful. Durable test callers propagate lookup errors, check the full retention head and preserve the exact selected-root error chain. These adaptations retain successful runtime expectations rather than converting errors into absence or suppressing failing assertions. + +## Remaining landing work + +The [closure ledger](../../pr-landing-2026-10-03.md#107-integration-closure-ledger) remains authoritative. Open blockers include compaction preflight before mutation, precise current-catalog error handling, bounded rereads, observed identity for derivable-stage cleanup, complete GC/disposition effect accounting, documentation/tooling integration, policy disposition, full final validation and exact-head independent review. No finding is closed merely because these focused groups pass. diff --git a/docs/audits/pr-landing-evidence/94/README.md b/docs/audits/pr-landing-evidence/94/README.md new file mode 100644 index 00000000..00b7a5c1 --- /dev/null +++ b/docs/audits/pr-landing-evidence/94/README.md @@ -0,0 +1,34 @@ +# PR 94 hosted benchmark evidence + +This is measurement evidence for the BLAKE3 upgrade, not a new performance threshold or a claim of universal equivalence. The [successful hosted run](https://github.com/flyingrobots/keep/actions/runs/37168090008) executes the existing source-bound benchmark in Docker. The separate [validation workflow](https://github.com/flyingrobots/keep/blob/0a194bfd0b6e27acfa02ccdb007564804947fc2a/.github/workflows/pr94-benchmark-evidence.yml) is evidence orchestration; it is not part of the product candidate. + +## Exact coordinates and controls + +Baseline: `11bc72c41cc379944766adbdef60f046e786b820`, tree `01c712f41fac391e14bde02cd84be3150596fd85`. Candidate: `9a7a46ec6d5043f61222c2f75fc7c49a16002cd3`, tree `9de5045171b4a779456a66ebc9b7cc96125c372b`. Each Docker copy checks out the original commit from bundled history and verifies cleanliness before and after measurement; no synthetic commit or candidate source change supplies the coordinates. + +The digest-pinned image is `rust@sha256:58fe97504a0e4cbba5d85599619a589923d3e779472a6fb0840d58d1c4ba99d7`. Both copies use Rust 1.96.0 and x86_64-unknown-linux-gnu on the same AMD EPYC 7763 runner, with a two-CPU quota and 6 GiB container memory limit. Build directories are separate. Preparation fetches dependencies and builds the optimized benchmark before disconnecting the Docker network; the retained container inspection reports no attached networks during measurement. + +Order is baseline-1, candidate-1, candidate-2, baseline-2, bounding linear host drift without pretending that a shared hosted runner is a dedicated performance laboratory. Each report contains 100 timed samples after five warmups for each of the existing 13 scenarios and five profiles. The existing protocol reports p50/p95/p99 wall time, CPU measures, allocation measures and mandatory behavioral verification. Its performance-threshold row remains explicitly unconfigured. + +## Raw results and comparison + +The four files below are copied byte-for-byte from the hosted artifact. The job artifact additionally retains preparation logs, actual CPU metadata, clean-tree coordinates, image identity and full Docker resource/network inspection. + +| Report | SHA-256 | +| --- | --- | +| [baseline-1.tsv](baseline-1.tsv) | `7ea622ee433cd029dea14d2aef6b9b2574bd3de165efeb3ebc76754168fc9908` | +| [candidate-1.tsv](candidate-1.tsv) | `f178cab9e8e258f9f15e57ab8af3aab51fbe8283acd2d2161de0ae8da2b25eca` | +| [candidate-2.tsv](candidate-2.tsv) | `07982178b974968e85b53c5f092cfd96f1111eeb9cc17fe806db3056e5181fca` | +| [baseline-2.tsv](baseline-2.tsv) | `1e6018d2db7419b2e966f406ad84e65199374ea57107c9dab8f23b62d6fb9c83` | + +[comparison.tsv](comparison.tsv) reports `(candidate-1 statistic + candidate-2 statistic) / (baseline-1 statistic + baseline-2 statistic)` separately for each row's p50 and p99 wall time. These are ratios of averages of per-run quantiles, not pooled quantiles, confidence intervals or significance tests. All row names are included; no unfavorable result is omitted. + +Across the 13 scenarios, p50 ratios range from 0.982336 to 1.030927 and p99 ratios from 0.764819 to 1.065063. Many-tiny-blobs has the largest p50 increase, about 3.1%; early-deletion has the largest scenario p99 increase, about 6.5%. Among profiles, keep-fastcdc-64-256-1024 has a p99 ratio of 1.083662. These observed increases remain visible; the run does not justify a blanket “no performance regression” statement. + +Total allocation count, total allocated bytes and peak live heap agree across all four runs for every scenario and profile. This is the benchmark's incremental heap accounting, not process RSS or a whole-system memory guarantee. + +## Limits and prior failures + +The original local attempt refused an inherited CARGO_TARGET_DIR; after clearing it, the local ARM Docker profile refused missing CPU-model metadata. Neither attempt yielded measurements. Hosted execution uses actual supported metadata and does not relabel either refusal as a BLAKE3 failure or fabricate a local success. + +This is one same-host experiment with order control and existing protocol verification. It does not supply a long-term variance baseline, p99 confidence interval, all-platform performance result, new harness calibration, physical power-loss evidence or ordinary-test resource-policy compliance. It supplies the previously missing benchmark execution/comparison evidence for this dependency upgrade. The source reviewer and existing final-head CI gates remain separate; #179's unapproved policy disposition is not waived here. diff --git a/docs/audits/pr-landing-evidence/94/baseline-1.tsv b/docs/audits/pr-landing-evidence/94/baseline-1.tsv new file mode 100644 index 00000000..f4dc2f12 --- /dev/null +++ b/docs/audits/pr-landing-evidence/94/baseline-1.tsv @@ -0,0 +1,39 @@ +schema keep.streaming-cas-baseline/v1 +metadata build-profile optimized-release +metadata git-commit 11bc72c41cc379944766adbdef60f046e786b820 +metadata git-tree clean +metadata rustc-version rustc 1.96.0 (ac68faa20 2026-05-25) +metadata target-triple x86_64-unknown-linux-gnu +metadata os-description Linux 6.17.0-1022-azure x86_64 +metadata cpu-model AMD EPYC 7763 64-Core Processor +metadata cpu-clock process +metadata peak-memory incremental-live-heap +metadata verification mandatory +metadata timing-unit nanoseconds +metadata byte-unit bytes +metadata ratio-encoding exact-numerator-denominator +metadata logical-cpu-count 2 +metadata sample-count 100 +metadata warmup-count 5 +scenario-header name verification sample-count logical-bytes physical-bytes-read physical-bytes-written source-bytes-read output-bytes-written read-amplification-numerator read-amplification-denominator write-amplification-numerator write-amplification-denominator deduplication-ratio-numerator deduplication-ratio-denominator reused-unique-chunks chunk-instances operation-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns p50-cpu-time-ns p95-cpu-time-ns p99-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-allocation-count peak-live-heap-bytes +scenario cold-ingest ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 13 1 266231754 393858351 3932620 3979850 4012900 393945145 3933669 3980987 4014200 2800 132013200 20 1313464 +scenario warm-ingest ingest-chunk-and-blob-identity 100 1048576 1048576 0 1048576 0 1048576 1048576 0 1048576 1048576 0 13 13 1 265138795 395481921 3919204 4047934 4293221 395555949 3920223 4050266 4273735 600 26508400 3 263488 +scenario repeated-near-neighbor-edits ingest-chunk-and-blob-identity 100 8388608 6191702 2196906 8388608 0 6191702 8388608 2196906 8388608 8388608 2196906 74 100 4 255786124 3279539901 32660367 33041798 34723001 3279298683 32663270 33044552 34726325 6800 327809000 40 2470386 +scenario early-insertion ingest-chunk-and-blob-identity 100 4198400 1997398 2201002 4198400 0 1997398 4198400 2201002 4198400 4198400 2201002 24 50 2 249656818 1681668472 16746389 16941913 18101225 1681591818 16748389 16938284 18103230 5400 274622600 38 2472826 +scenario early-deletion ingest-chunk-and-blob-identity 100 4190208 1997398 2192810 4190208 0 1997398 4190208 2192810 4190208 4190208 2192810 24 50 2 251229246 1667882249 16660319 16826269 16936543 1667745449 16661035 16802690 16938263 5400 273803400 38 2464634 +scenario many-tiny-blobs ingest-chunk-and-blob-identity 100 32896 0 32896 32896 0 0 32896 32896 32896 32896 32896 0 256 256 27932995 117767533 1173548 1198543 1202350 117842753 1174464 1199531 1203328 191200 6764795200 889 538368 +scenario large-binary ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 15 1 252053287 416013617 4132323 4236676 4728122 416064387 4133322 4225113 4729936 3000 132031600 22 1313464 +scenario high-deduplication ingest-chunk-and-blob-identity 100 4194304 2097152 2097152 4194304 0 2097152 4194304 2097152 4194304 4194304 2097152 25 50 2 251450944 1668040660 16672058 16863956 17039874 1668015211 16664954 16855779 17042138 5000 264075200 36 2368392 +scenario zero-deduplication ingest-chunk-and-blob-identity 100 3145728 0 3145728 3145728 0 0 3145728 3145728 3145728 3145728 3145728 0 44 2 237252930 1325896375 13234901 13389108 13484265 1325975202 13236307 13391478 13486365 7500 369104000 58 3417440 +scenario sequential-range-reads selected-complete-chunks 100 1048576 3413411 0 0 1048576 3413411 1048576 0 1048576 1048576 0 0 46 32 764568849 137146053 1369183 1388348 1395280 137247411 1370130 1389696 1396208 0 0 0 0 +scenario random-range-reads selected-complete-chunks 100 131072 2396798 0 0 131072 2396798 131072 0 131072 131072 0 0 33 32 133388941 98263018 979796 1005193 1024048 98322405 980772 1001150 1011940 0 0 0 0 +scenario whole-blob-verification chunks-profile-and-blob 100 1048576 1048576 0 0 1048576 1048576 1048576 0 1048576 1048576 0 0 15 1 368218356 284770159 2843120 2868197 2893354 284788469 2844193 2866485 2894337 0 0 0 0 +scenario varied-input-partitioning ingest-chunk-and-blob-identity 100 262144 0 262144 262144 0 0 262144 262144 262144 262144 262144 0 4 4 68524125 382557236 3802227 3895692 3962136 382653198 3803135 3896639 3964366 4000 132846400 6 328488 +profile-header name provenance minimum-kib target-kib maximum-kib timed-input sample-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-heap-bytes base-unique-chunks base-materialized-bytes insertion-reused-chunks deletion-reused-chunks neighbor-reused-chunks +profile keep-fastcdc-4-16-64 keep.fastcdc-gear64/v1 4 16 64 large-text 100 573639496 182793550 1822757 1840301 1915190 182864486 200 364000 3640 86 2097152 81 85 85 +profile keep-fastcdc-16-64-256 keep.fastcdc-gear64/v1 16 64 256 large-text 100 676129598 155085061 1547625 1578683 1615682 155137145 200 98800 988 25 2097152 24 24 24 +profile keep-fastcdc-64-256-1024 keep.fastcdc-gear64/v1 64 256 1024 large-text 100 708586378 147981394 1479187 1496800 1515465 148061459 200 24400 244 5 2097152 4 4 4 +profile fixed-64 benchmark.fixed-size/v1 64 64 64 large-text 100 2627822521 39902847 395958 410485 410997 40002089 200 71200 712 32 2097152 0 0 31 +profile git-cas-buzhash-64-256-1024 git-cas@432c5d9effb12c9f66536f1386791bb4421f3cea 64 256 1024 large-text 100 391587618 267775576 2617159 3001826 3109436 267877877 200 24400 244 5 2097152 4 4 4 +threshold-header metric status rationale +threshold all-performance-metrics unconfigured requires-controlled-baseline-history diff --git a/docs/audits/pr-landing-evidence/94/baseline-2.tsv b/docs/audits/pr-landing-evidence/94/baseline-2.tsv new file mode 100644 index 00000000..316ad74d --- /dev/null +++ b/docs/audits/pr-landing-evidence/94/baseline-2.tsv @@ -0,0 +1,39 @@ +schema keep.streaming-cas-baseline/v1 +metadata build-profile optimized-release +metadata git-commit 11bc72c41cc379944766adbdef60f046e786b820 +metadata git-tree clean +metadata rustc-version rustc 1.96.0 (ac68faa20 2026-05-25) +metadata target-triple x86_64-unknown-linux-gnu +metadata os-description Linux 6.17.0-1022-azure x86_64 +metadata cpu-model AMD EPYC 7763 64-Core Processor +metadata cpu-clock process +metadata peak-memory incremental-live-heap +metadata verification mandatory +metadata timing-unit nanoseconds +metadata byte-unit bytes +metadata ratio-encoding exact-numerator-denominator +metadata logical-cpu-count 2 +metadata sample-count 100 +metadata warmup-count 5 +scenario-header name verification sample-count logical-bytes physical-bytes-read physical-bytes-written source-bytes-read output-bytes-written read-amplification-numerator read-amplification-denominator write-amplification-numerator write-amplification-denominator deduplication-ratio-numerator deduplication-ratio-denominator reused-unique-chunks chunk-instances operation-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns p50-cpu-time-ns p95-cpu-time-ns p99-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-allocation-count peak-live-heap-bytes +scenario cold-ingest ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 13 1 266481263 393489579 3924546 3981854 4038299 393537807 3926045 3982981 4038574 2800 132013200 20 1313464 +scenario warm-ingest ingest-chunk-and-blob-identity 100 1048576 1048576 0 1048576 0 1048576 1048576 0 1048576 1048576 0 13 13 1 266030019 394157021 3935637 3984439 3998384 394176662 3936594 3981397 3993660 600 26508400 3 263488 +scenario repeated-near-neighbor-edits ingest-chunk-and-blob-identity 100 8388608 6191702 2196906 8388608 0 6191702 8388608 2196906 8388608 8388608 2196906 74 100 4 256339674 3272457931 32715672 32877364 33063961 3272412595 32707342 32880546 33066984 6800 327809000 40 2470386 +scenario early-insertion ingest-chunk-and-blob-identity 100 4198400 1997398 2201002 4198400 0 1997398 4198400 2201002 4198400 4198400 2201002 24 50 2 250045270 1679055950 16760547 16929672 17012707 1679111286 16759089 16918456 17001341 5400 274622600 38 2472826 +scenario early-deletion ingest-chunk-and-blob-identity 100 4190208 1997398 2192810 4190208 0 1997398 4190208 2192810 4190208 4190208 2192810 24 50 2 251493763 1666127992 16641164 16820839 17018778 1666089222 16639987 16818791 17020928 5400 273803400 38 2464634 +scenario many-tiny-blobs ingest-chunk-and-blob-identity 100 32896 0 32896 32896 0 0 32896 32896 32896 32896 32896 0 256 256 24733307 133002834 1184468 1938044 2163373 133103603 1185374 1939003 2164323 191200 6764795200 889 538368 +scenario large-binary ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 15 1 253277994 414002015 4130791 4200961 4229375 414073823 4131178 4202140 4230544 3000 132031600 22 1313464 +scenario high-deduplication ingest-chunk-and-blob-identity 100 4194304 2097152 2097152 4194304 0 2097152 4194304 2097152 4194304 4194304 2097152 25 50 2 250997352 1671055076 16686909 16825508 17143561 1671085846 16688517 16827887 17145711 5000 264075200 36 2368392 +scenario zero-deduplication ingest-chunk-and-blob-identity 100 3145728 0 3145728 3145728 0 0 3145728 3145728 3145728 3145728 3145728 0 44 2 236887588 1327941246 13266943 13377138 13548318 1327944392 13264972 13378884 13550274 7500 369104000 58 3417440 +scenario sequential-range-reads selected-complete-chunks 100 1048576 3413411 0 0 1048576 3413411 1048576 0 1048576 1048576 0 0 46 32 768800327 136391201 1360867 1378249 1385162 136468139 1361824 1378155 1386129 0 0 0 0 +scenario random-range-reads selected-complete-chunks 100 131072 2396798 0 0 131072 2396798 131072 0 131072 131072 0 0 33 32 134114730 97731248 973034 1000295 1023839 97838933 974020 1001221 1025005 0 0 0 0 +scenario whole-blob-verification chunks-profile-and-blob 100 1048576 1048576 0 0 1048576 1048576 1048576 0 1048576 1048576 0 0 15 1 384915571 272417142 2719260 2750498 2820007 272513817 2720232 2751481 2821241 0 0 0 0 +scenario varied-input-partitioning ingest-chunk-and-blob-identity 100 262144 0 262144 262144 0 0 262144 262144 262144 262144 262144 0 4 4 68189350 384435397 3805054 3887998 4564800 384470070 3806010 3889196 4565710 4000 132846400 6 328488 +profile-header name provenance minimum-kib target-kib maximum-kib timed-input sample-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-heap-bytes base-unique-chunks base-materialized-bytes insertion-reused-chunks deletion-reused-chunks neighbor-reused-chunks +profile keep-fastcdc-4-16-64 keep.fastcdc-gear64/v1 4 16 64 large-text 100 565683954 185364282 1850550 1872741 1885535 185399303 200 364000 3640 86 2097152 81 85 85 +profile keep-fastcdc-16-64-256 keep.fastcdc-gear64/v1 16 64 256 large-text 100 671706442 156106289 1560229 1576549 1594452 156194947 200 98800 988 25 2097152 24 24 24 +profile keep-fastcdc-64-256-1024 keep.fastcdc-gear64/v1 64 256 1024 large-text 100 708487464 148002054 1479598 1499707 1512109 148099066 200 24400 244 5 2097152 4 4 4 +profile fixed-64 benchmark.fixed-size/v1 64 64 64 large-text 100 2573138460 40750858 407970 417999 426255 40853073 200 71200 712 32 2097152 0 0 31 +profile git-cas-buzhash-64-256-1024 git-cas@432c5d9effb12c9f66536f1386791bb4421f3cea 64 256 1024 large-text 100 405847753 258366836 2576082 2631146 2694884 258402259 200 24400 244 5 2097152 4 4 4 +threshold-header metric status rationale +threshold all-performance-metrics unconfigured requires-controlled-baseline-history diff --git a/docs/audits/pr-landing-evidence/94/candidate-1.tsv b/docs/audits/pr-landing-evidence/94/candidate-1.tsv new file mode 100644 index 00000000..58e0e983 --- /dev/null +++ b/docs/audits/pr-landing-evidence/94/candidate-1.tsv @@ -0,0 +1,39 @@ +schema keep.streaming-cas-baseline/v1 +metadata build-profile optimized-release +metadata git-commit 9a7a46ec6d5043f61222c2f75fc7c49a16002cd3 +metadata git-tree clean +metadata rustc-version rustc 1.96.0 (ac68faa20 2026-05-25) +metadata target-triple x86_64-unknown-linux-gnu +metadata os-description Linux 6.17.0-1022-azure x86_64 +metadata cpu-model AMD EPYC 7763 64-Core Processor +metadata cpu-clock process +metadata peak-memory incremental-live-heap +metadata verification mandatory +metadata timing-unit nanoseconds +metadata byte-unit bytes +metadata ratio-encoding exact-numerator-denominator +metadata logical-cpu-count 2 +metadata sample-count 100 +metadata warmup-count 5 +scenario-header name verification sample-count logical-bytes physical-bytes-read physical-bytes-written source-bytes-read output-bytes-written read-amplification-numerator read-amplification-denominator write-amplification-numerator write-amplification-denominator deduplication-ratio-numerator deduplication-ratio-denominator reused-unique-chunks chunk-instances operation-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns p50-cpu-time-ns p95-cpu-time-ns p99-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-allocation-count peak-live-heap-bytes +scenario cold-ingest ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 13 1 266140558 393993312 3935857 3971674 4002133 394013248 3936915 3972812 3993511 2800 132013200 20 1313464 +scenario warm-ingest ingest-chunk-and-blob-identity 100 1048576 1048576 0 1048576 0 1048576 1048576 0 1048576 1048576 0 13 13 1 265580364 394824370 3941897 3971714 4022558 394905238 3942866 3972671 4023927 600 26508400 3 263488 +scenario repeated-near-neighbor-edits ingest-chunk-and-blob-identity 100 8388608 6191702 2196906 8388608 0 6191702 8388608 2196906 8388608 8388608 2196906 74 100 4 255303404 3285740757 32728600 32964660 34033974 3285575518 32725225 32956889 34016806 6800 327809000 40 2470386 +scenario early-insertion ingest-chunk-and-blob-identity 100 4198400 1997398 2201002 4198400 0 1997398 4198400 2201002 4198400 4198400 2201002 24 50 2 249727494 1681192536 16737801 16881770 19110005 1681272697 16738791 16883993 19112365 5400 274622600 38 2472826 +scenario early-deletion ingest-chunk-and-blob-identity 100 4190208 1997398 2192810 4190208 0 1997398 4190208 2192810 4190208 4190208 2192810 24 50 2 247930385 1690074408 16741759 17546199 19348420 1690133433 16738801 17548133 19351111 5400 273803400 38 2464634 +scenario many-tiny-blobs ingest-chunk-and-blob-identity 100 32896 0 32896 32896 0 0 32896 32896 32896 32896 32896 0 256 256 27190108 120985175 1204947 1235744 1263847 121074593 1205973 1237311 1265063 191200 6764795200 889 538368 +scenario large-binary ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 15 1 250750349 418175289 4176859 4223966 4242241 418203081 4177745 4223740 4244950 3000 132031600 22 1313464 +scenario high-deduplication ingest-chunk-and-blob-identity 100 4194304 2097152 2097152 4194304 0 2097152 4194304 2097152 4194304 4194304 2097152 25 50 2 249068954 1683993095 16805638 16970184 17075862 1684002423 16806177 16966817 17078174 5000 264075200 36 2368392 +scenario zero-deduplication ingest-chunk-and-blob-identity 100 3145728 0 3145728 3145728 0 0 3145728 3145728 3145728 3145728 3145728 0 44 2 236558892 1329786406 13278553 13411631 13485018 1329891905 13279538 13403610 13486816 7500 369104000 58 3417440 +scenario sequential-range-reads selected-complete-chunks 100 1048576 3413411 0 0 1048576 3413411 1048576 0 1048576 1048576 0 0 46 32 772353410 135763756 1354806 1372198 1406442 135865783 1355743 1373115 1407590 0 0 0 0 +scenario random-range-reads selected-complete-chunks 100 131072 2396798 0 0 131072 2396798 131072 0 131072 131072 0 0 33 32 134996635 97092790 967985 982812 1002520 97190467 968950 983738 1004516 0 0 0 0 +scenario whole-blob-verification chunks-profile-and-blob 100 1048576 1048576 0 0 1048576 1048576 1048576 0 1048576 1048576 0 0 15 1 384964442 272382559 2719059 2751048 2805159 272434251 2719871 2752141 2806232 0 0 0 0 +scenario varied-input-partitioning ingest-chunk-and-blob-identity 100 262144 0 262144 262144 0 0 262144 262144 262144 262144 262144 0 4 4 69860641 375238465 3744089 3795956 3856339 375259557 3744976 3796403 3857687 4000 132846400 6 328488 +profile-header name provenance minimum-kib target-kib maximum-kib timed-input sample-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-heap-bytes base-unique-chunks base-materialized-bytes insertion-reused-chunks deletion-reused-chunks neighbor-reused-chunks +profile keep-fastcdc-4-16-64 keep.fastcdc-gear64/v1 4 16 64 large-text 100 574581296 182493932 1822498 1840010 1882510 182600950 200 364000 3640 86 2097152 81 85 85 +profile keep-fastcdc-16-64-256 keep.fastcdc-gear64/v1 16 64 256 large-text 100 666808183 157253019 1570056 1586237 1605302 157321870 200 98800 988 25 2097152 24 24 24 +profile keep-fastcdc-64-256-1024 keep.fastcdc-gear64/v1 64 256 1024 large-text 100 704823012 148771533 1481602 1520475 1674522 148874569 200 24400 244 5 2097152 4 4 4 +profile fixed-64 benchmark.fixed-size/v1 64 64 64 large-text 100 2501485634 41918130 416006 433308 439229 42002412 200 71200 712 32 2097152 0 0 31 +profile git-cas-buzhash-64-256-1024 git-cas@432c5d9effb12c9f66536f1386791bb4421f3cea 64 256 1024 large-text 100 406786235 257770767 2576472 2596330 2630413 257827257 200 24400 244 5 2097152 4 4 4 +threshold-header metric status rationale +threshold all-performance-metrics unconfigured requires-controlled-baseline-history diff --git a/docs/audits/pr-landing-evidence/94/candidate-2.tsv b/docs/audits/pr-landing-evidence/94/candidate-2.tsv new file mode 100644 index 00000000..53d026e8 --- /dev/null +++ b/docs/audits/pr-landing-evidence/94/candidate-2.tsv @@ -0,0 +1,39 @@ +schema keep.streaming-cas-baseline/v1 +metadata build-profile optimized-release +metadata git-commit 9a7a46ec6d5043f61222c2f75fc7c49a16002cd3 +metadata git-tree clean +metadata rustc-version rustc 1.96.0 (ac68faa20 2026-05-25) +metadata target-triple x86_64-unknown-linux-gnu +metadata os-description Linux 6.17.0-1022-azure x86_64 +metadata cpu-model AMD EPYC 7763 64-Core Processor +metadata cpu-clock process +metadata peak-memory incremental-live-heap +metadata verification mandatory +metadata timing-unit nanoseconds +metadata byte-unit bytes +metadata ratio-encoding exact-numerator-denominator +metadata logical-cpu-count 2 +metadata sample-count 100 +metadata warmup-count 5 +scenario-header name verification sample-count logical-bytes physical-bytes-read physical-bytes-written source-bytes-read output-bytes-written read-amplification-numerator read-amplification-denominator write-amplification-numerator write-amplification-denominator deduplication-ratio-numerator deduplication-ratio-denominator reused-unique-chunks chunk-instances operation-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns p50-cpu-time-ns p95-cpu-time-ns p99-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-allocation-count peak-live-heap-bytes +scenario cold-ingest ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 13 1 267186285 392451281 3917333 3962968 4005436 392496717 3918240 3964277 3992679 2800 132013200 20 1313464 +scenario warm-ingest ingest-chunk-and-blob-identity 100 1048576 1048576 0 1048576 0 1048576 1048576 0 1048576 1048576 0 13 13 1 267537885 391935519 3913505 3963398 4004636 392032360 3914783 3964597 4006064 600 26508400 3 263488 +scenario repeated-near-neighbor-edits ingest-chunk-and-blob-identity 100 8388608 6191702 2196906 8388608 0 6191702 8388608 2196906 8388608 8388608 2196906 74 100 4 256938054 3264836733 32628695 32861980 32966314 3264730036 32629146 32848567 32968731 6800 327809000 40 2470386 +scenario early-insertion ingest-chunk-and-blob-identity 100 4198400 1997398 2201002 4198400 0 1997398 4198400 2201002 4198400 4198400 2201002 24 50 2 250406675 1676632616 16762842 16855284 17026734 1676734760 16762265 16857642 17028973 5400 274622600 38 2472826 +scenario early-deletion ingest-chunk-and-blob-identity 100 4190208 1997398 2192810 4190208 0 1997398 4190208 2192810 4190208 4190208 2192810 24 50 2 251671596 1664950700 16638090 16747563 16816142 1664939574 16635308 16743009 16800329 5400 273803400 38 2464634 +scenario many-tiny-blobs ingest-chunk-and-blob-identity 100 32896 0 32896 32896 0 0 32896 32896 32896 32896 32896 0 256 256 26656919 123405109 1225995 1265188 1310322 123480103 1226982 1266436 1311711 191200 6764795200 889 538368 +scenario large-binary ingest-chunk-and-blob-identity 100 1048576 0 1048576 1048576 0 0 1048576 1048576 1048576 1048576 1048576 0 15 1 253720946 413279241 4119558 4175492 4223181 413326456 4120227 4176672 4224272 3000 132031600 22 1313464 +scenario high-deduplication ingest-chunk-and-blob-identity 100 4194304 2097152 2097152 4194304 0 2097152 4194304 2097152 4194304 4194304 2097152 25 50 2 251842598 1665446600 16648259 16764976 16798228 1665477911 16648452 16762536 16800406 5000 264075200 36 2368392 +scenario zero-deduplication ingest-chunk-and-blob-identity 100 3145728 0 3145728 3145728 0 0 3145728 3145728 3145728 3145728 3145728 0 44 2 238041011 1321506734 13206183 13294859 13341386 1321530006 13207533 13296881 13343067 7500 369104000 58 3417440 +scenario sequential-range-reads selected-complete-chunks 100 1048576 3413411 0 0 1048576 3413411 1048576 0 1048576 1048576 0 0 46 32 766514421 136797948 1363421 1385373 1400059 136900816 1364439 1386310 1401168 0 0 0 0 +scenario random-range-reads selected-complete-chunks 100 131072 2396798 0 0 131072 2396798 131072 0 131072 131072 0 0 33 32 133703373 98031932 978253 995696 1010824 98136494 979220 996682 1012101 0 0 0 0 +scenario whole-blob-verification chunks-profile-and-blob 100 1048576 1048576 0 0 1048576 1048576 1048576 0 1048576 1048576 0 0 15 1 380794828 275365084 2745066 2804577 2852556 275457469 2745990 2805852 2854212 0 0 0 0 +scenario varied-input-partitioning ingest-chunk-and-blob-identity 100 262144 0 262144 262144 0 0 262144 262144 262144 262144 262144 0 4 4 69941019 374807231 3741894 3779555 3828024 374782226 3742703 3776505 3829304 4000 132846400 6 328488 +profile-header name provenance minimum-kib target-kib maximum-kib timed-input sample-count logical-bytes-per-second total-wall-time-ns p50-wall-time-ns p95-wall-time-ns p99-wall-time-ns total-cpu-time-ns total-allocation-count total-allocated-bytes peak-live-heap-bytes base-unique-chunks base-materialized-bytes insertion-reused-chunks deletion-reused-chunks neighbor-reused-chunks +profile keep-fastcdc-4-16-64 keep.fastcdc-gear64/v1 4 16 64 large-text 100 575613239 182166762 1819271 1840149 1872671 182235595 200 364000 3640 86 2097152 81 85 85 +profile keep-fastcdc-16-64-256 keep.fastcdc-gear64/v1 16 64 256 large-text 100 676935504 154900429 1547245 1571248 1592008 155005035 200 98800 988 25 2097152 24 24 24 +profile keep-fastcdc-64-256-1024 keep.fastcdc-gear64/v1 64 256 1024 large-text 100 705614447 148604667 1480711 1515676 1606345 148706172 200 24400 244 5 2097152 4 4 4 +profile fixed-64 benchmark.fixed-size/v1 64 64 64 large-text 100 2644049731 39657953 394375 409544 418681 39742949 200 71200 712 32 2097152 0 0 31 +profile git-cas-buzhash-64-256-1024 git-cas@432c5d9effb12c9f66536f1386791bb4421f3cea 64 256 1024 large-text 100 399723235 262325506 2615686 2667093 2736692 262395949 200 24400 244 5 2097152 4 4 4 +threshold-header metric status rationale +threshold all-performance-metrics unconfigured requires-controlled-baseline-history diff --git a/docs/audits/pr-landing-evidence/94/comparison.tsv b/docs/audits/pr-landing-evidence/94/comparison.tsv new file mode 100644 index 00000000..12b9e03c --- /dev/null +++ b/docs/audits/pr-landing-evidence/94/comparison.tsv @@ -0,0 +1,19 @@ +kind name p50-wall-candidate-over-baseline p99-wall-candidate-over-baseline allocation-coordinates-equal +scenario cold-ingest 0.999494 0.994581 true +scenario warm-ingest 1.000071 0.968111 true +scenario repeated-near-neighbor-edits 0.999713 0.988395 true +scenario early-insertion 0.999812 1.029128 true +scenario early-deletion 1.002353 1.065063 true +scenario many-tiny-blobs 1.030927 0.764819 true +scenario large-binary 1.004030 0.945066 true +scenario high-deduplication 1.002846 0.990950 true +scenario zero-deduplication 0.999354 0.992373 true +scenario sequential-range-reads 0.995669 1.009372 true +scenario random-range-reads 0.996624 0.983132 true +scenario whole-blob-verification 0.982336 0.990260 true +scenario varied-input-partitioning 0.984055 0.901187 true +profile keep-fastcdc-4-16-64 0.991414 0.988017 true +profile keep-fastcdc-16-64-256 1.003040 0.996005 true +profile keep-fastcdc-64-256-1024 1.001192 1.083662 true +profile fixed-64 1.008027 1.024674 true +profile git-cas-buzhash-64-256-1024 0.999791 0.924674 true