Skip to content

Test writer authority refusal after lock-entry replacement - #170

Merged
flyingrobots merged 6 commits into
mainfrom
test/169-writer-acquisition-identity
Oct 3, 2026
Merged

flyingrobots merged 6 commits into
mainfrom
test/169-writer-acquisition-identity

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Landed

Merged as d7c761e5cad8c4ba3a1ebb56c0e171ef6036910d after fresh independent approval and all four hosted jobs passed for e5b176a2e3a0c15d686b98685417067947d15520. The signed integration commit preserves the approved tree. Final Code Lawyer closure supersedes the pre-landing status below.

Problem and result

Closes #169 under audit #131. The previous replacement test called only an identity checker and stayed green when acquisition ignored its refusal. An initial stronger test still survived verification being moved before the kernel lock. The final test replaces the opened lock entry at a private deterministic checkpoint after locking and requires that no writer authority escape, with exact refusal and both files' bytes preserved.

Change kind: test-oracle correction with a private scheduling seam. Main already orders locking and verification correctly; no unmodified-parent production bug is alleged. The branch starts at main 6051abb25a9fd33ae7ee0de5614514b709a4d82a with no unmerged feature prerequisite. Current landing head: e5b176a2e3a0c15d686b98685417067947d15520, integrating main eb506dfb3830a32b0aec6a963c69da4f87012161; the CHANGELOG conflict preserves both histories.

Invariant and approach

KEEP-RECOVERY-004 requires canonical entry identity to agree with the opened handle after kernel acquisition before returning writer authority. Ordinary and initialization acquisition delegate to the same body with a no-op checkpoint. The private test checkpoint first observes real contention through an independently opened handle, then replaces the pathname under the existing root-then-file locks; it exposes no public callback, acquires no extra locks, and needs no sleep, stress loop or global mutable hook.

The experiment enters the shared module capability boundary after outer pathname opening. Existing public tests retain ordinary success, exclusion, missing-file and no-follow coverage. The helper-only test is retired because its refusal claim is subsumed by the stronger authority-boundary law. Rejected alternatives: source-call counts, a duplicated checker, uncontrolled race scheduling, or narrowing the after-lock contract.

RED / GREEN and review

Portable checked-in receipts include exact mutation patches, replay commands, toolchain/features/profiles, raw RED output and restored GREEN output. Ignoring refusal survives the old tests; verifying before locking survives the initial stronger test. Both fail the final test with replacement received writer authority. Independent wrong-phase and destructive-original/replacement mutations fail their intended assertions. A removed-call dead-code compilation failure is explicitly excluded from runtime RED.

After restoration and cache timestamp invalidation, focused copied-Docker debug/release acquisition, public lock and initialization laws pass; all-feature workspace/all-target Clippy passes. Pinned Markdown lint passes. The earlier broad run refused unsupported overlay scratch in unrelated platform laws; that setup failure is preserved. Corrected validation binds both library and integration scratch roots to ext4 without bypassing admission.

The prior 985830e full local validation completed successfully. Final focused debug/release, formatting, source-structure, all-feature Clippy and Markdown checks pass after adding an independent callback-time contention witness. Moving the checkpoint before locking survives 1b27e4c and fails the new witness with Some(Ok(())); portable survivor/RED/GREEN receipts are checked in. The receipt whitespace gate is also fixed. All four required hosted CI jobs passed on historical head 1d81c74 (run 37095885373), and independent Codex delta review approved that head. All three hosted threads were resolved after verification. Fresh full copied-Docker validation, hosted checks and independent Codex review are running on the integrated landing head; historical approvals are not transferred. The maintainer has authorized normal merging only after the current candidate passes those gates.

Compatibility and operational implications

Production code gains only the private no-op scheduling seam; lock ordering, identity verification, error propagation and guard construction retain their public behavior. No public API, on-disk format, content identity, dependency, platform admission, synchronization, recovery protocol or performance change is intended. No benchmark improvement is claimed.

Existing no-follow and identity protections remain intact. The test covers a controlled real file/lock transition; it does not establish every raw namespace race or physical power-loss behavior. Resource-enforcement gaps remain disclosed in the consolidated evidence.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 21 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: cc6378aa-776f-419e-9e54-efab4c5979c7
📥 Commits

Reviewing files that changed from the base of the PR and between 1d81c74 and e5b176a.

📒 Files selected for processing (23)
  • CHANGELOG.md
  • docs/formats/segment-store-v1/requirements.md
  • docs/testing-evidence/writer-acquisition-identity.md
  • docs/testing-evidence/writer-acquisition-identity/README.md
  • docs/testing-evidence/writer-acquisition-identity/checkpoint-green.txt
  • docs/testing-evidence/writer-acquisition-identity/early-checkpoint-red.txt
  • docs/testing-evidence/writer-acquisition-identity/early-checkpoint-survived.txt
  • docs/testing-evidence/writer-acquisition-identity/early-checkpoint.patch
  • docs/testing-evidence/writer-acquisition-identity/early-order-red.txt
  • docs/testing-evidence/writer-acquisition-identity/early-order-survived.txt
  • docs/testing-evidence/writer-acquisition-identity/early-order.patch
  • docs/testing-evidence/writer-acquisition-identity/ignored-refusal-red.txt
  • docs/testing-evidence/writer-acquisition-identity/ignored-refusal.patch
  • docs/testing-evidence/writer-acquisition-identity/lost-original-red.txt
  • docs/testing-evidence/writer-acquisition-identity/lost-original.patch
  • docs/testing-evidence/writer-acquisition-identity/lost-replacement-red.txt
  • docs/testing-evidence/writer-acquisition-identity/lost-replacement.patch
  • docs/testing-evidence/writer-acquisition-identity/old-oracle-survived.txt
  • docs/testing-evidence/writer-acquisition-identity/restored-green.txt
  • docs/testing-evidence/writer-acquisition-identity/wrong-phase-red.txt
  • docs/testing-evidence/writer-acquisition-identity/wrong-phase.patch
  • src/adapters/filesystem_writer_lock.rs
  • src/adapters/filesystem_writer_lock_tests.rs

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 3e778f35-ad68-40cd-9e1a-03f86fbb2cd6
📥 Commits

Reviewing files that changed from the base of the PR and between 6051abb and 1d81c74.

📒 Files selected for processing (23)
  • CHANGELOG.md
  • docs/formats/segment-store-v1/requirements.md
  • docs/testing-evidence/writer-acquisition-identity.md
  • docs/testing-evidence/writer-acquisition-identity/README.md
  • docs/testing-evidence/writer-acquisition-identity/checkpoint-green.txt
  • docs/testing-evidence/writer-acquisition-identity/early-checkpoint-red.txt
  • docs/testing-evidence/writer-acquisition-identity/early-checkpoint-survived.txt
  • docs/testing-evidence/writer-acquisition-identity/early-checkpoint.patch
  • docs/testing-evidence/writer-acquisition-identity/early-order-red.txt
  • docs/testing-evidence/writer-acquisition-identity/early-order-survived.txt
  • docs/testing-evidence/writer-acquisition-identity/early-order.patch
  • docs/testing-evidence/writer-acquisition-identity/ignored-refusal-red.txt
  • docs/testing-evidence/writer-acquisition-identity/ignored-refusal.patch
  • docs/testing-evidence/writer-acquisition-identity/lost-original-red.txt
  • docs/testing-evidence/writer-acquisition-identity/lost-original.patch
  • docs/testing-evidence/writer-acquisition-identity/lost-replacement-red.txt
  • docs/testing-evidence/writer-acquisition-identity/lost-replacement.patch
  • docs/testing-evidence/writer-acquisition-identity/old-oracle-survived.txt
  • docs/testing-evidence/writer-acquisition-identity/restored-green.txt
  • docs/testing-evidence/writer-acquisition-identity/wrong-phase-red.txt
  • docs/testing-evidence/writer-acquisition-identity/wrong-phase.patch
  • src/adapters/filesystem_writer_lock.rs
  • src/adapters/filesystem_writer_lock_tests.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (2)
  • GitHub Check: Runtime fuzz smoke
  • GitHub Check: Rust quality gates
🔇 Additional comments (23)
src/adapters/filesystem_writer_lock.rs (1)

100-100: LGTM!

Also applies to: 101-101, 107-111, 122-122

src/adapters/filesystem_writer_lock_tests.rs (1)

19-19: LGTM!

Also applies to: 21-21, 23-23, 25-41, 43-61

docs/testing-evidence/writer-acquisition-identity.md (1)

3-3: LGTM!

Also applies to: 7-11, 15-21, 25-27

docs/testing-evidence/writer-acquisition-identity/README.md (1)

3-3: LGTM!

Also applies to: 7-17, 19-27, 29-38, 40-56

docs/testing-evidence/writer-acquisition-identity/early-checkpoint.patch (1)

1-12: LGTM!

docs/testing-evidence/writer-acquisition-identity/early-checkpoint-red.txt (1)

1-22: LGTM!

docs/testing-evidence/writer-acquisition-identity/early-checkpoint-survived.txt (1)

1-8: LGTM!

docs/testing-evidence/writer-acquisition-identity/early-order-red.txt (1)

1-19: LGTM!

docs/testing-evidence/writer-acquisition-identity/early-order-survived.txt (1)

1-8: LGTM!

docs/testing-evidence/writer-acquisition-identity/early-order.patch (1)

1-14: LGTM!

docs/testing-evidence/writer-acquisition-identity/ignored-refusal-red.txt (1)

1-19: LGTM!

docs/testing-evidence/writer-acquisition-identity/ignored-refusal.patch (1)

1-11: LGTM!

docs/testing-evidence/writer-acquisition-identity/lost-original-red.txt (1)

1-23: LGTM!

docs/testing-evidence/writer-acquisition-identity/lost-original.patch (1)

1-11: LGTM!

docs/testing-evidence/writer-acquisition-identity/lost-replacement-red.txt (1)

1-24: LGTM!

docs/testing-evidence/writer-acquisition-identity/lost-replacement.patch (1)

1-11: LGTM!

docs/testing-evidence/writer-acquisition-identity/wrong-phase-red.txt (1)

1-22: LGTM!

docs/testing-evidence/writer-acquisition-identity/wrong-phase.patch (1)

1-11: LGTM!

docs/testing-evidence/writer-acquisition-identity/old-oracle-survived.txt (1)

1-44: LGTM!

docs/testing-evidence/writer-acquisition-identity/checkpoint-green.txt (1)

1-22: LGTM!

docs/testing-evidence/writer-acquisition-identity/restored-green.txt (1)

1-94: LGTM!

docs/formats/segment-store-v1/requirements.md (1)

121-121: LGTM!

CHANGELOG.md (1)

11-11: LGTM!


Summary by CodeRabbit

  • Bug Fixes
    • Writer-lock acquisition now refuses authority when the lock file is replaced during acquisition, while preserving the contents of both the displaced and replacement files.
  • Documentation
    • Added testing evidence documenting the replacement scenario, its results, and the limits of what the tests establish.
    • Updated the relevant recovery requirement with a link to the acquisition evidence.

Walkthrough

The writer-lock test now replaces the lock-file entry during acquisition, after the kernel lock is held and before identity verification. It checks for refusal, the exact error, and preserved file contents. New documentation records mutation results, replay instructions, validation runs, and evidence limits.

Changes

Writer-lock identity verification

Layer / File(s) Summary
Acquisition checkpoint and replacement test
src/adapters/filesystem_writer_lock.rs, src/adapters/filesystem_writer_lock_tests.rs, docs/testing-evidence/writer-acquisition-identity.md
acquire delegates to acquire_with, which runs its callback after acquiring the file lock and before checking the directory entry identity. The test replaces the entry at that checkpoint and checks contention, the VerifyFileIdentity/InvalidData refusal, and retained file contents.
Mutation calibration evidence
docs/testing-evidence/writer-acquisition-identity.md, docs/testing-evidence/writer-acquisition-identity/README.md, docs/testing-evidence/writer-acquisition-identity/*
The evidence records mutation patches and test outcomes for checkpoint and verification order, ignored refusal, file contents, and error phase. It also records replay instructions and the scope of the evidence.
Validation receipts and evidence anchors
docs/testing-evidence/writer-acquisition-identity/README.md, docs/testing-evidence/writer-acquisition-identity/checkpoint-green.txt, docs/testing-evidence/writer-acquisition-identity/restored-green.txt, docs/formats/segment-store-v1/requirements.md, CHANGELOG.md
The records include successful debug and release tests, development-profile checks, replay setup, and evidence limits. The requirement and changelog refer to the acquisition-boundary evidence.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 1d81c

The replacement test covers the intended acquisition boundary, and no merge-blocking issue is established. Merge after the remaining hosted checks and approval.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 1d81c

The change strengthens a deterministic refusal test without changing how production callers receive writing permission. The checkpoint is private, production supplies no caller-controlled behavior, and identity verification still precedes returned authority.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The exercised interference scenario requires filesystem authority to rename or replace writer.lock within the selected store. Its demonstrated outcome concerns that store's writer authority. The private checkpoint does not add a production interface through which callers can supply executable behavior.

Trust Boundaries and Controls

  • observed — Root locking remains nonblocking and exclusive, and lock-file opening retains no-follow behavior. Identity verification reopens the canonical entry and rejects a mismatch with VerifyFileIdentity and InvalidData. These controls predate the PR and remain enforced after the new checkpoint.

Resilience and Maintainability Implications

  • observed — The strengthened oracle checks that a separate handle encounters the held kernel lock, that acquisition returns the precise identity-refusal error, and that original and replacement contents remain intact. It therefore guards against skipping refusal or moving verification before locking. These are source-level assertions; tests were not executed during this assessment.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 2 files. (21 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #169 requires a deterministic KEEP-RECOVERY-004 test at the writer-authority boundary. acquire_with invokes its private checkpoint after acquire_lock and before verify_current_identity; pr…
Out of Scope Changes check ✅ Passed The private seam, replacement test, mutation receipts, requirement-ledger update, changelog entry, and evidence documentation all support issue #169's acquisition-boundary evidence repair. The reviewe…
Title check ✅ Passed The title clearly and concisely describes the main change: testing writer-authority refusal after lock-entry replacement.
Description check ✅ Passed The description covers the problem, invariant, approach, change kind, rejected alternatives, test evidence, compatibility, and operational limits. It is mostly complete, but it does not include separa…
Full details: Docstring Coverage

Explanation

Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 2 files. (21 skipped: 21 unsupported.)

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A lock is held; the checkpoint waits.
The pathname changes; the check still runs.
No guard returns for the changed entry.
Both files keep the bytes they held.
Test receipts record each measured step.

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T04:16:57.095512Z 1d81c74 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 789229a238

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/adapters/filesystem_writer_lock_tests.rs Outdated
Comment thread docs/testing-evidence/writer-acquisition-identity.md Outdated
@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent adversarial review — PR #170

Reviewed in an isolated checkout at exact pushed head 6a5958b9f27b81be70b25e1c680398258818e2f8, branch test/169-writer-acquisition-identity, against main 6051abb25a9fd33ae7ee0de5614514b709a4d82a. This is the user-authorized independent Codex fallback under the complete agy-review protocol. The initial candidate 789229a23830079d12d5f8e8092479d79d18ef3d is superseded by the documentation correction in 6a5958b.

Findings

No verified source or scoped acceptance blocker remains. The replacement law tests the actual shared authority-producing acquisition boundary, not the identity checker in isolation. It detects the ignored-refusal mutant that the previous law and adjacent suites survive. The exact diagnostic and both retained-byte assertions have distinct runtime falsification receipts.

The original evidence paragraph incorrectly described all focused execution as ext4. The final paragraph at docs/testing-evidence/writer-acquisition-identity.md:23 corrects that distinction and preserves the failed broader setup attempt. I independently inspected the sandbox fallback and both current ext4 mounts. This correction closes the documentation issue; it does not turn the original failed run into a successful run.

Verification Checklist

  • Identity, scope and integration: Git and live GitHub agree on the full final head, branch and base above; the checkout is clean. Inspected the complete four-file diff and both commits (789229a, 6a5958b). There are no merge commits to audit. The only Rust change is src/adapters/filesystem_writer_lock_tests.rs; production, dependencies, features, public APIs and formats are byte-unchanged from the stated main base. The work closes the observable oracle-repair outcome of issue Calibrate writer authority against lock-entry replacement during acquisition #169 without depending on unmerged Preserve platform admission across public catalog publisher routes (T-12.2) #150 or Replace catalog scan source-text assertion with runtime cost evidence #168.
  • Actual authority path: src/adapters/filesystem_writer_lock_tests.rs:18 obtains the existing sandbox, writes a literal original, acquires the real root lock and opens the original file; lines 24–28 deterministically replace its pathname. Line 30 invokes production FilesystemWriterLock::acquire, not a duplicate checker. Production src/adapters/filesystem_writer_lock.rs:96 checks regular-file metadata, captures device/inode, takes the real kernel file lock at line 109, propagates identity refusal at line 110, and constructs authority only at line 111. Lines 30–42 of the test reject an escaped guard and require Io/VerifyFileIdentity/InvalidData; lines 43–50 independently compare both persisted byte strings. Keeping the original handle alive across replacement prevents inode reuse from making the two entries accidentally identical.
  • Ordinary and initialization parallel paths: filesystem_writer_lock.rs:72 → :80 → :96 and :86 → :96 use the same acquisition implementation. Ordinary acquisition never creates a missing lock file (:195); initialization uses create-new with existing-file fallback (:182) and synchronizes only a successfully acquired guard (:90). Root acquisition (:123, :138) precedes file locking (:152). Both use nonblocking locks; open options retain no-follow and nonblocking behavior (:201). The changed test does not bypass file locking or the identity guard.
  • Remaining production callers: src/adapters/filesystem_initialization_storage.rs:84 delegates to initialize_in and retains the typed lock error as the I/O source before storing authority. src/adapters/filesystem_store_initializer.rs:109, filesystem_version_two_admission.rs:82, filesystem_recovery_stage_discarder.rs:79, and store_migration/filesystem_migration_recovery.rs:62 delegate to try_acquire_in, preserve the lock error in their dedicated variants and only continue namespace/inventory admission after success. No parallel authority-returning path introduced or rerouted by this PR escapes the shared guard.
  • Errors and state transitions: filesystem_writer_lock.rs:160 reopens the canonical entry with the same no-follow options, reads device/inode, and returns the explicit mismatch error. writer_lock_acquire_error.rs:10 preserves the original I/O source and :41 exposes it through Error::source; phase vocabulary is in writer_lock_acquire_phase.rs:7. Refusal propagates before constructing Self; owned file handles close on error. This test establishes one controlled open → replace → lock → refuse transition and unchanged file contents. It does not establish every raw namespace race, public-entry-point scheduling, recovery from process death, or physical power-loss behavior; no such claim is added.
  • Existing public outcome evidence: tests/catalog_writer_lock.rs:18 covers acquisition, second-writer exclusion, release/reacquisition and retained bytes; :37 covers replacement after an already-returned first guard; :60 covers missing evidence without creation; :81 covers no-follow refusal and target preservation. These remain unchanged. The distinction between their post-return replacement and the new pre-return replacement is accurate. Initialization port tests remain port evidence, not substitutes for kernel behavior.
  • Old-oracle survivor: Inspected the actual original/mutant source diff and 131/initialization/identity-call-mutant/survived.log: ignoring the production checker's result retains a runtime PASS for the old helper law, four public lock laws, two initialization port laws and seven filesystem initializer laws. The removed-call attempt in dead-code-rejection.log reaches dead-code compilation failure for production builds and is explicitly excluded from successful runtime calibration. No unmodified-parent product defect is claimed.
  • New refusal calibration: 169/ignored-refusal-red.log compiles and executes the new law and fails with replacement received writer authority, corresponding to current test line 32. This directly demonstrates the corrected authority-outcome oracle.
  • Diagnostic and preservation calibration: Inspected original/mutant sources, replay commands, exit status 101 and runtime RED logs in 169/wrong-phase, 169/lost-original, and 169/lost-replacement. The first changes only the mismatch phase to Acquire and reaches the exact diagnostic assertion. The second truncates displaced.lock before returning the same refusal and fails the original-byte assertion with an empty observed value. The third truncates writer.lock and reaches the replacement-byte assertion with an empty observed value. Earlier byte/diagnostic assertions do not conceal those intended failures. Raw assertion line numbers for the byte comparisons precede final formatting; failure expressions and literal byte arrays match current lines 43 and 47. The recorded original production source matches the reviewed source. The calibration script restores the original and touches source timestamps after each mutation; mutations are not present in the PR.
  • Restored GREEN and execution profile: Inspected 169/green.log: the strengthened law passes debug/release, as do the four public lock laws, two initialization port laws and seven filesystem initializer laws; workspace/all-target/all-feature Clippy completes successfully. These are inspected author-run receipts, not reviewer-run tests. The changed test uses real files and locks even when its initial library scratch filesystem is overlay. tests/segment_filesystem_stage/sandbox.rs:19 selects compile-time CARGO_TARGET_TMPDIR or falls back to source-local target/tmp; src/adapters/mod.rs:131 shares that fixture with library laws. I verified current findmnt results show ext4 for both the copied source's target/tmp and the dedicated target's tmp.
  • First failure and corrected validation: 169/final-validation.log preserves three failures in unchanged production-platform laws caused by unsupported scratch platform admission (including one downstream expected-error mismatch), with 350 other library tests passing. This is not a RED regression of the new law. 169/final-corrected-validation.log is a separate, still-running corrected validation receipt at review time. I did not modify or execute Rust in its running source/build tree. No full-chain success is claimed here.
  • Constants, numbers and documentation: Checked all changed prose in CHANGELOG.md:11, docs/formats/segment-store-v1/requirements.md:121, and all 25 lines of the new evidence document against source and receipts. The issue references and pinned main SHA are historical coordinates, not measurements. The unchanged requirement's exact device/inode rule matches production and the controlled fixture. The literal original/replacement payloads have independent expected values and direct destructive calibration. There are no new timing, size, buffer, throughput, memory, or performance thresholds to justify. No numerical result is promoted into universal correctness. The fixture's one owned sandbox and the debug/release execution statements are supported; overlay/ext4 provenance is now distinguished correctly.
  • Repository standards and structural scope: Read applicable AGENTS.md, Testing Standards and enforcement profile. The test declares medium size, specified oracle KEEP-RECOVERY-004 and deletion criterion at lines 13–15; the evidence declares a test-oracle correction rather than an invented runtime bug fix. Removing the helper-only law is justified by the stronger acquisition-boundary experiment. The changed file has 53 lines and the straight-line law remains within hard size/nesting limits. No production abstraction, dependency-direction change, parser, durable codec, arithmetic, whole-content allocation, optimization or synchronization change needs a new protocol rationale or benchmark. No sleep, test-order dependency, random schedule or new shared mutable hook is introduced. Existing per-test resource/isolation and measurement enforcement gaps are explicitly disclosed, not certified as solved or waived. This review does not reopen those mainline-wide gaps as unrelated work.
  • Hosted review surfaces: Queried live PR body, issue Calibrate writer authority against lock-entry replacement during acquisition #169, review bodies, global discussion and inline review threads. Every queried connection ended with hasNextPage: false; there were no review bodies or inline threads. The two global comments report CodeRabbit's review limit and a running hosted Codex review of the initial candidate. The CodeRabbit status is not an approval. No actionable hosted finding was available at inspection time; subsequent feedback still requires reconciliation.

Execution and remaining gates

Executed only read-only Git/source/receipt inspection, live GitHub queries, git diff --check, and read-only Docker mount inspection. No host Rust, Python, mutation replay, test rerun, configuration change, external comment, commit or source edit was performed by this reviewer.

Final-head GitHub checks at inspection: dependency policy succeeded; Rust quality gates, documentation/workflow integrity and runtime fuzz smoke were in progress. The corrected complete local validation was also in progress. This is an exact-head independent source/evidence approval, not an assertion that required validation is complete or permission to merge. Final checks, any later feedback, and human merge authorization remain separate gates.

APPROVE — 6a5958b9f27b81be70b25e1c680398258818e2f8

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 985830ef5f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/adapters/filesystem_writer_lock.rs
@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent adversarial delta review — PR #170

Reviewed in an isolated checkout at exact pushed head 985830ef5f6b0a5e60ebc416bcfd4685ec751bfe, branch test/169-writer-acquisition-identity, against main 6051abb25a9fd33ae7ee0de5614514b709a4d82a. This user-authorized independent Codex fallback follows the agy-review protocol. The prior 6a5958b approval is historical; this review incorporates both late hosted findings and the complete remediation delta.

Findings

P2 — Checked-in receipt whitespace fails the required documentation gate. docs/testing-evidence/writer-acquisition-identity/early-order-survived.txt:9, lost-original-red.txt:24, and old-oracle-survived.txt:45 each end with an extra blank line. Read-only git diff --check 6051abb..HEAD reproduces the warnings. The final-head hosted Documentation and workflow integrity job 111123963056, run 37095326623, fails its empty-tree-to-HEAD whitespace check with exactly these three diagnostics and exit code 2. This is a demonstrated integration blocker, not a product-locking defect. Remove only the redundant trailing blank lines, disclose that output normalization alongside the existing path normalization, and rerun the required check without weakening it.

No additional verified source defect or scoped test-oracle blocker was found. Both late substantive findings are closed by the inspected implementation and portable evidence. The live PR description was still stale at first inspection (prior head, no production code change, replacement before acquisition); I notified the author to reconcile this hosted description. That metadata correction needs no source change.

Verification Checklist

  • Exact scope and integration: Verified clean checkout and matching live GitHub full head/base. Inspected all 18 delta files, including every mutation patch and captured output; the full PR has 19 files. The only delta commit is 985830e; no merge commits exist in the PR. No unrelated feature dependency, format/API/dependency change, or public callback was introduced. Unlike the earlier candidate, this head does change production source by adding a private scheduling seam, accurately disclosed in CHANGELOG line 11 and the evidence page line 3.
  • Ordinary production acquisition: src/adapters/filesystem_writer_lock.rs:72 → :80 → :96 → :106. The wrapper at line 101 supplies a no-op closure. The shared body checks metadata/regular-file kind at lines 112–118, performs real kernel locking at line 120, invokes the synchronous checkpoint at line 121, verifies canonical identity at line 122, and constructs authority at line 123. No fallible production check is swallowed, duplicated or reordered by the extraction.
  • Initialization and parallel callers: filesystem_writer_lock.rs:86 → :96 follows the same body, then synchronizes the acquired file at line 90. Ordinary open-existing and initialization create-new/fallback semantics remain at lines 207 and 194; no-follow options remain at line 213. Root locking at lines 135/150 still precedes file locking at line 164. Unchanged callers filesystem_initialization_storage.rs:84, filesystem_store_initializer.rs:109, filesystem_version_two_admission.rs:82, filesystem_recovery_stage_discarder.rs:79, and store_migration/filesystem_migration_recovery.rs:62 retain the same typed wrapping and stop before later admission if acquisition refuses. Prior full-path inspection remains applicable; the delta introduces no alternative authority path.
  • Checkpoint scope and locking: acquire_with is private, synchronous and FnOnce; its only production caller passes || {}. Its only other call is the colocated unit law. The comment at lines 104–105 documents execution under root-then-file locks and forbids additional fixture locks. No global hook, public callback registration, dynamic shared scheduler, asynchronous cancellation or new lock order exists. The test performs owned filesystem rename/write operations in that documented critical section. Callback unwinding would drop local handles; production does not invoke user code.
  • Final controlled schedule: filesystem_writer_lock_tests.rs:18 opens the root/original handle; lines 25–31 replace the pathname inside the after-lock checkpoint. Line 32 propagates fixture failure before interpreting the product result. Lines 33–45 require no escaped authority and exact Io/VerifyFileIdentity/InvalidData. Lines 46 and 50 independently inspect original and replacement bytes. The pinned original inode remains alive. This now exercises open → kernel lock → replacement → verification → refusal; it does not purport to be a public-entry-point scheduler or exhaustive raw namespace race proof.
  • Error/refusal preservation: Identity verification at filesystem_writer_lock.rs:172 retains the same canonical no-follow reopen, device/inode observation and explicit InvalidData mismatch. writer_lock_acquire_error.rs:10 and its Error::source implementation remain unchanged; failures exit before guard construction. No synchronization or recovery behavior changed. Existing public laws at tests/catalog_writer_lock.rs:18, :37, :60, and :81 still exercise ordinary exclusion/reacquisition, post-return replacement exclusion, missing-file refusal and no-follow preservation. Initialization port evidence remains distinguished from actual kernel evidence.
  • Hosted ordering finding: Inspected 169/early-identity/original.rs, mutant.rs, candidate-original.rs, candidate-mutant.rs, survived.log and red.log. Moving verification before locking survives the earlier test and fails the final law at replacement received writer authority. The final original production source is byte-identical to the reviewed source. The checked-in early-order.patch performs exactly that reorder while leaving the checkpoint after the lock. The test is sensitive to the promised order rather than simply to refusal existence. My earlier approval did not establish this order sensitivity; the late finding and final experiment correct that evidence gap.
  • All prior assertions recalibrated: Checked final ignored-refusal, wrong-phase, lost-original, and lost-replacement receipts. They compile and fail respectively at escaped authority, exact phase diagnostic, original byte comparison, and replacement byte comparison. Earlier assertions do not mask the intended destructive-byte failures. Checked patch content against raw mutant intent. Expected literal byte arrays match the final test. Formatting shifts in captured assertion coordinates are explicitly disclosed in the replay page; named expressions still identify the current assertions.
  • Portable evidence finding: docs/testing-evidence/writer-acquisition-identity/README.md:7 pins survivor revisions; line 9 records Rust/Cargo versions, host, features, filesystem and profiles; lines 19–25 provide apply/run/reverse/touch replay, lines 29–35 map each mutation to its actual failure, and lines 41–50 provide restored validation commands. All five patches pass read-only git apply --check against this head. All eight checked-in output files match corresponding raw logs after the stated source/target prefix normalization, including the old-oracle survivor using its distinct keep131-init path. Outputs are accessible from the repository, not private-path claims. Old helper/suite survival and the excluded removed-call dead-code attempt remain correctly distinguished. No full-suite mutant survival claim is made.
  • Restored validation: ordering-green.log matches checked-in restored-green.txt: final strengthened law, four public lock laws, two initialization port laws and seven filesystem initializer laws pass debug/release; all-feature workspace/all-target Clippy passes. These are inspected receipts, not reviewer-run tests. The test counts describe observed runs, not correctness totals. Sources were restored and timestamps invalidated between mutations. The updated evidence preserves the earlier overlay setup failure and distinguishes initial overlay calibration from final ext4 scratch. Previous direct inspection established both copied-tree scratch mounts as ext4; no platform admission bypass is added by this delta.
  • Constants and numerical claims: Verified toolchain coordinates with read-only Docker rustc -Vv and cargo -V: 1.96.0, the recorded compiler/Cargo hashes and dates, and aarch64-unknown-linux-gnu agree. Main/prior revision coordinates are accurate. No new timing, memory, buffer, throughput or numerical performance budget is introduced. Captured durations and counts remain historical observations, not threshold promises. Reviewed CHANGELOG, unchanged KEEP-RECOVERY-004 requirement anchor, all evidence prose and the complete replay table against source/raw evidence.
  • Repository standards: Applicable AGENTS, Testing Standards and enforcement profile reviewed in the parent review remain binding. Medium size, named specified oracle, deletion/subsumption criterion, controlled schedule and independent literal byte expectations remain present. The new seam has four parameters and stays within function/file/nesting limits; dependencies still point inward as before. No parser/codec/serialization change calls for new fuzz or format vectors; no optimization or benchmark claim is introduced. The private checkpoint and locking rationale are documented next to the code and in the evidence page. No sleeps, randomized scheduling, network calls or shared mutable global state are added. Existing resource-ceiling/network-denial enforcement gaps are explicitly disclosed rather than claimed solved or waived.
  • All review surfaces: Queried live PR body, review bodies, global discussion, inline threads and each thread's comments; every pageInfo reported hasNextPage: false. The two hosted P2 threads are the ordering and portable-evidence findings assessed above; both remained mechanically unresolved at query time. CodeRabbit remains rate-limited, not approving. Hosted Codex is reviewing the new head. Prior review feedback was posted before the remediation. New feedback must still be reconciled if it arrives later.

Execution and limitations

Executed only read-only Git/source/receipt comparisons, patch applicability checks, live GitHub queries and job-log inspection, plus container tool-version queries. No host Rust tests, mutation replay, source edits, comments, delegation or configuration changes were performed. The report is the sole written artifact. The running copied validation tree and target were not modified or used for tests by this reviewer.

The exact-head local final-985830e-validation.log was still running. Hosted dependency policy passed; Rust quality and runtime fuzz checks were still running; documentation/workflow integrity demonstrably failed as described above. Neither pending checks nor earlier green results are transferred to this head. No physical power-loss, exhaustive schedule, public race-entry or universal lock correctness claim is inferred from these finite experiments. Human merge authorization remains separate from any eventual approval.

REQUEST CHANGES — 985830ef5f6b0a5e60ebc416bcfd4685ec751bfe

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent adversarial delta review — PR #170

Reviewed in an isolated checkout at exact pushed head 1b27e4c6d2e791b8088123793befc219a97937c2, against main 6051abb25a9fd33ae7ee0de5614514b709a4d82a, using the authorized independent Codex fallback and agy-review protocol. This review checks the four-file whitespace/documentation delta from 985830e, retains its verified path/evidence inspection, and reconciles new live hosted feedback.

Findings

P2 — The claimed after-lock schedule has no independent lock-held observation. At src/adapters/filesystem_writer_lock_tests.rs:25, the checkpoint only renames and writes the lock pathname. The test never observes that the opened original file is already kernel-locked at that moment. Moving after_acquire() from src/adapters/filesystem_writer_lock.rs:121 to immediately before acquire_lock leaves the same original handle, replacement pathname, eventual successful file lock, VerifyFileIdentity/InvalidData result and both byte assertions. Thus the law can remain green while no longer executing its claimed post-kernel-lock schedule. The existing early-order.patch moves verification, not the checkpoint, and does not calibrate this distinct regression.

This is a verified test-evidence gap, not a claim that current production orders the checkpoint incorrectly. It is also the new hosted P2 on 985830e, discovered during this review's live feedback refresh. Add an independent observation inside the checkpoint that the original file's kernel lock is held, such as a separately opened handle's typed nonblocking contention result, before replacement. Calibrate moving the checkpoint before locking against that observation, then restore and validate debug/release. Preserve the narrow private boundary and avoid a global hook.

The preceding whitespace P2 is closed: the three redundant EOF blank lines are removed and the normalization is disclosed accurately. No other verified finding is added.

Verification Checklist

  • Exact head, scope and merges: Local and live GitHub head match 1b27e4c6d2e791b8088123793befc219a97937c2; checkout is clean and base unchanged. The sole delta commit changes only the receipt README and three receipt endings. No Rust, mutation patch, expected diagnostic, assertion, API, format, dependency, lock-order or runtime policy changed. No merge commit was introduced. The prior full-path review applies to these identical source blobs.
  • Whitespace repair: Inspected all four diffs. docs/testing-evidence/writer-acquisition-identity/README.md:3 now discloses redundant trailing-blank-line removal in addition to absolute-prefix normalization. Only the final blank line is removed from early-order-survived.txt, lost-original-red.txt, and old-oracle-survived.txt; their actual outcomes and diagnostics remain identical. Executed the same empty-tree-to-HEAD git diff --check as the failing hosted step; it now passes. The previous observed hosted exit 2 is preserved as historical failure rather than reclassified as GREEN.
  • Production and parallel paths retained: filesystem_writer_lock.rs:72 → :80 → :96 → :106 handles ordinary acquisition. Initialization :86 delegates to the same wrapper and syncs only a successful guard at :90. Metadata admission :112, identity capture :118, kernel lock :120, checkpoint :121, identity verification :122, guard construction :123 remain in the correct current order. Root acquisition :135/:150 precedes file locking :164; create-new/fallback :194, existing open :207, and no-follow options :213 are unchanged. Current production uses a private no-op checkpoint, not a public callback or global scheduler.
  • Callers and error state: filesystem_initialization_storage.rs:84, filesystem_store_initializer.rs:109, filesystem_version_two_admission.rs:82, filesystem_recovery_stage_discarder.rs:79, and store_migration/filesystem_migration_recovery.rs:62 still propagate typed lock failures before continuing admission. Canonical entry verification at filesystem_writer_lock.rs:172 and source-preserving writer_lock_acquire_error.rs:10 remain unchanged. Refusal precedes construction and local handles drop normally; no new cancellation, recovery, shutdown or durability behavior exists in this delta.
  • Permanent law and coverage gap: Test lines 18–22 prepare owned actual files/root authority; lines 25–31 replace inside the callback, line 32 separates fixture failure, lines 33–45 require precise refusal, and lines 46/50 preserve both byte strings. These outcomes are meaningful but do not independently establish callback-time lock ownership, as the new finding explains. Existing public laws at tests/catalog_writer_lock.rs:18, :37, :60, and :81 retain ordinary acquisition/exclusion/reacquisition, post-return replacement exclusion, missing-file and no-follow coverage; they do not fill this new callback-time gap.
  • Previously established calibration remains valid: The unchanged checked-in patches and raw outputs establish old helper survival under ignored refusal, initial acquisition-test survival under early verification, and final runtime RED for early verification, ignored refusal, wrong phase, lost original bytes and lost replacement bytes. These were compared to raw scratch artifacts in the preceding exact-head review, including source diffs, intended assertion failures and restored GREEN. The EOF normalization does not alter those results. None of those five mutants moves the callback itself before locking. No runtime execution of that new mutant was performed by this reviewer; its surviving state transition is identified by direct source inspection.
  • Portable evidence and numbers: Replay README lines 7–11 retain pinned source coordinates, Rust/Cargo 1.96.0, aarch64 host, features/profiles and explicit resource/isolation limits. Lines 19–25 and 29–35 retain replay and mutant/outcome mapping; lines 41–50 retain restoration commands. Versions, raw-output normalization and all five patch applicability checks were verified in the preceding review and are unchanged. Counts/timings are historical receipt observations, not thresholds. No new numeric performance, buffer, timeout, size or memory claim is added. The known callback-time omission narrows the evidence for the schedule statement; it does not falsify the observed refusal/byte-preservation receipts.
  • Repository standards: Applicable AGENTS, Testing Standards and enforcement profile remain binding. Medium size, KEEP-RECOVERY-004 oracle and helper-test deletion criterion remain at test lines 13–15. Callback and test structure remain within hard limits; the new delta needs no runtime test solely for whitespace. The test-oracle gap is governed by the requirement to construct deterministic schedules and demonstrate load-bearing assertions can fail. Existing mainline resource/network-denial gaps remain disclosed, not newly solved, waived or expanded into unrelated findings. No parser, persistent codec, optimization or durability change calls for unrelated new campaigns.
  • Review/global/inline pagination: Refreshed live review bodies, global comments, all inline threads and thread comments; every connection ended with hasNextPage: false. The original ordering and portable-evidence threads have author remediation responses and remain substantively closed as previously inspected. A new hosted checkpoint-lock observation thread provides the new evidence above. CodeRabbit and hosted Codex are processing the final head; neither running review is an approval. The PR body now describes the private after-lock seam correctly, although its current-head/status text still named 985830e when queried; the author already identified that metadata update as pending.

Execution and remaining gates

Executed read-only Git/source/receipt inspection, the exact whitespace check, and live GitHub queries. No host Rust, test replay, source edits, configuration changes, external comments or delegation. Only this report was written.

The author reports full local 985830e validation exited 0; I inspected its completed tail through documentation generation. Its Rust source is byte-identical to this head, but that does not transfer hosted check status. On run 37095729022, dependency policy passed while Rust quality, documentation/workflow integrity and runtime fuzz were still in progress at inspection. The declared pinned Markdown validation was not rerun by this reviewer. No physical power-loss, exhaustive interleaving or public-entry-point race guarantee is inferred. Human merge authorization remains separate.

REQUEST CHANGES — 1b27e4c6d2e791b8088123793befc219a97937c2

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent adversarial delta review — PR #170

Reviewed in an isolated checkout at exact pushed head 1d81c749c1203115cae049227fd58e971a22cbed, branch test/169-writer-acquisition-identity, against main 6051abb25a9fd33ae7ee0de5614514b709a4d82a. This is the authorized independent Codex fallback under the agy-review protocol. The bounded delta follows the full 1b27e4c feedback posted before remediation.

Findings

No verified source or scoped acceptance blocker remains. The callback now independently observes actual kernel contention on the original file before replacement. Its new assertion rejects the precise checkpoint-before-lock mutant that survived the previous law. The earlier verification-order, portable-receipt and whitespace findings remain closed; their distinct evidence and limitations are preserved.

Verification Checklist

  • Exact identity, delta and integration: Local Git and live GitHub agree on the full head and base above; checkout is clean. Inspected the complete delta: independent contention observation in the existing law, a clarified production comment, two evidence-page updates, and the new portable patch/survivor/RED/GREEN artifacts. No executable production statement changes from 1b27e4c; no merge commits exist in the PR. No dependency, format, public API, feature, platform-admission or recovery change is hidden in this delta.
  • Independent callback-time observation: src/adapters/filesystem_writer_lock_tests.rs:23 opens a separate file handle before mutation; it is not a clone sharing the production open-file description. Inside the callback, line 28 performs real nonblocking try_lock on that independently opened original file before rename/write at lines 29–33. Lines 37–40 require exactly Some(Err(TryLockError::WouldBlock)); skipped callback, unexpected success and other I/O failures cannot satisfy it. Line 35 closes the contender, including a lock it might have obtained in a mutant run. Fixture failure remains separated at line 36. This observes a kernel outcome at the controlled point instead of trusting a callback name or source-text sequence.
  • Production authority path: src/adapters/filesystem_writer_lock.rs:72 → :80 → :96 → :107 remains ordinary acquisition. The private wrapper at line 101 supplies a no-op callback. The shared body admits metadata/regular kind at lines 113–119, locks at line 121, calls the checkpoint at line 122, verifies current identity at line 123 and constructs the guard at line 124. Current order is correct. The comment at lines 104–106 accurately permits a nonblocking contention probe and forbids waiting for another lock. There is no public callback, global mutable hook, asynchronous work or additional blocking lock order.
  • Initialization and parallel paths: Initialization at filesystem_writer_lock.rs:86 uses the same wrapper and syncs only a returned guard at line 90. Root lock acquisition at lines 136/151 precedes file locking at line 165. Create-new/fallback at line 195, existing-file open at line 208 and no-follow options at line 214 remain unchanged. Previously inspected callers filesystem_initialization_storage.rs:84, filesystem_store_initializer.rs:109, filesystem_version_two_admission.rs:82, filesystem_recovery_stage_discarder.rs:79, and store_migration/filesystem_migration_recovery.rs:62 preserve their typed errors and stop before later admission on refusal. No parallel path is rerouted by this delta.
  • Errors, guard state and retained evidence: Canonical identity verification at filesystem_writer_lock.rs:173 retains the same no-follow reopening, device/inode comparison and InvalidData mismatch. writer_lock_acquire_error.rs:10 retains typed phase and original I/O source. The permanent law still rejects escaped authority at test line 43, requires exact Io/VerifyFileIdentity/InvalidData at lines 44–53, and compares original/replacement bytes independently at lines 54/58. Existing public tests at tests/catalog_writer_lock.rs:18, :37, :60, and :81 retain ordinary success/exclusion/reacquisition, post-return replacement, missing-file and no-follow behavior. No error swallowing, changed guard lifetime, synchronization protocol or recovery transition is introduced.
  • New falsification evidence: Inspected raw 169/early-checkpoint/original.rs, mutant.rs, final-original.rs, final-mutant.rs, survived.log, red.log and green.log, and compared the final original production file to this head. The mutant only moves the callback before file locking. Its prior-head survivor is a real executed PASS; the final law compiles and fails at the new named assertion with Some(Ok(())). This is the intended missing-contention observation, not an earlier setup or unrelated refusal failure. With the original order restored, the strengthened law passes debug/release and all-feature workspace/all-target Clippy completes. Those receipts are inspected author executions, not reviewer reruns.
  • Portable replay and receipt integrity: The new early-checkpoint.patch describes exactly the observed reorder. Read-only git apply --check passes for all six checked-in patches against the resulting head. The new checked-in survivor, RED and GREEN text files match raw scratch logs after documented build-prefix normalization and removal of redundant trailing blank lines. README line 55 identifies the exact survivor revision, intended RED, restored GREEN and shared execution profile. No diagnostic, expected value or observed result was edited away.
  • Prior calibration retained with honest coordinates: The early-verification, ignored-refusal, wrong-phase, lost-original and lost-replacement receipts remain historical evidence from the earlier after-lock law. The new contention probe does not change the kernel ordering exercised by those five mutations: each still performs the production lock before the callback, so it does not mask their later refusal/diagnostic/byte outcomes. They are not presented here as freshly rerun on this head. The documentation explicitly separates this new checkpoint-order calibration from the preceding verification-order calibration. Earlier helper-only survival, excluded removed-call dead-code failure, and overlay setup failure remain distinct.
  • Constants and documentation: Checked both changed evidence pages, all new captured figures and the comment against source/raw evidence. Rust/Cargo 1.96.0, aarch64 host, default-feature debug RED, debug/release GREEN and ext4 scratch are inherited from the recorded profile verified in the preceding reviews; no new platform or toolchain measurement is claimed. Captured test counts and durations are run observations, not correctness metrics or limits. No new buffer, timeout, allocation, memory, throughput or performance threshold exists. The independent original-handle probe and exact WouldBlock statement at evidence-page line 9 match the implementation. The final PR body now identifies this exact head and describes the seam and new witness.
  • Repository standards and structure: Applicable AGENTS, Testing Standards and enforcement profile remain binding. The law retains medium size, specified KEEP-RECOVERY-004 oracle, owned scratch state and deletion criterion at lines 13–15. One nonblocking probe supplies the previously absent schedule witness without a sleep, stress loop, ambient shared hook or test-order dependence. The 64-line test file and law remain within hard structural limits; no new production policy abstraction or codec is introduced. The callback-locking rationale remains colocated. Per-test resource/network-denial enforcement gaps are disclosed, not treated as implemented or waived. No unrelated parser, format, performance or physical-durability campaign is required by this bounded test correction.
  • Whitespace gate: Executed the exact empty-tree-to-HEAD git diff --check again; it passes. The prior three-EOF-blank-line integration blocker remains fixed, including the newly added output files.
  • Hosted review and all pages: Refreshed live PR body, review bodies, global comments, inline threads and every thread's comments. Every connection ended with hasNextPage: false. The three historical hosted concerns are substantively addressed as described above, though thread resolution remains a separate workflow action. CodeRabbit was processing earlier selected changes and hosted Codex was reviewing this head; no additional actionable finding was present in the inspected responses. Future feedback still requires reconciliation.

Execution and limits

Executed only read-only Git/source/receipt comparisons, patch applicability, the whitespace check and live GitHub inspection. No host Rust, test execution, mutation replay, source edit, comment, configuration change or delegation. Only this report was written.

The new checked-in and raw focused GREEN receipts establish the executed debug/release law and Clippy results described above. Formatting, source-structure and Markdown were reported passed by the author; this reviewer did not independently rerun those tools. The earlier full local 985830e validation remains historical, not a final-head hosted check result. All four required checks on exact-head run 37095885373 were in progress at inspection. No prior CI green is transferred.

This finite experiment proves neither every raw namespace interleaving nor a public-entry-point race schedule, restart recovery, physical power loss or universal kernel-lock correctness. Those limits do not prevent it from closing the specific authority-acquisition oracle gap. Approval is the independent source/evidence verdict for this exact head; required checks, later feedback and human merge authorization remain separate gates.

APPROVE — 1d81c749c1203115cae049227fd58e971a22cbed

@flyingrobots

Copy link
Copy Markdown
Owner Author

Activity Summary — candidate 1d81c74

Obligation Fix and evidence Disposition
P2 after-lock verification ordering 985830e: after-lock checkpoint; moving verification before locking now fails the authority assertion. Closed; hosted thread resolved.
P2 portable calibration receipts 985830e: patches, commands, environment and actual RED/GREEN outputs checked in. Closed; hosted thread resolved.
P2 receipt EOF whitespace 1b27e4c: removed trailing blank lines and disclosed normalization; required documentation gate passes. Closed.
P2 checkpoint must independently observe lock ownership 1d81c74: independently opened handle must observe WouldBlock inside checkpoint; callback-before-lock mutant fails with Some(Ok(())). Closed; hosted thread resolved.

Independent Codex review following the agy-review protocol approves this exact head with its complete Verification Checklist: #170 (comment).

All four required hosted jobs pass on this exact head: https://github.com/flyingrobots/keep/actions/runs/37095885373. Focused final Docker debug/release, formatting, source-structure, all-feature Clippy and Markdown checks pass; the prior broad local run at985830e is retained as historical evidence, not transferred CI. The complete final hosted Rust chain covers the final head.

All three inline threads are resolved after published fixes and independent verification. All review/comment connections were exhausted; there are no active changes-requested reviews or remaining verified findings. CodeRabbit is still pending, not approving. Human merge authorization remains separate; no merge was performed.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent adversarial exact-head review — PR #170

Reviewed flyingrobots/keep PR #170, branch test/169-writer-acquisition-identity, at e5b176a2e3a0c15d686b98685417067947d15520, tree 4edf8d00941d65083bfcad60bdb51bb0a6eb2f26, targeting main eb506dfb3830a32b0aec6a963c69da4f87012161. This is the user-authorized independent Codex fallback under the full agy-review protocol. CodeRabbit and hosted Codex are currently rate-limited; CodeRabbit's approval and the prior independent approval name 1d81c749c1203115cae049227fd58e971a22cbed, not this merge candidate.

Findings

No verified source defect or scoped acceptance blocker remains. The permanent law observes actual contention on a separately opened original file inside the checkpoint, replaces its pathname, then requires no returned authority, the exact identity-refusal boundary, and preservation of both byte strings. Production uses the same acquisition body with a private no-op checkpoint. All three prior hosted P2 concerns and the receipt-whitespace P2 remain closed at this exact head.

The verdict is a bounded source/evidence approval of this candidate. It is not repository-wide certification, a physical power-loss claim, or permission to bypass remaining hosted/protection gates.

Verification Checklist

Exact identity, complete diff and review surfaces

  • Verified clean local checkout, full HEAD and tree using Git; independently queried the live PR head/branch/base name and live main SHA, which agree with the coordinates above. Inspected the complete 23-file diff against current main: two Rust files, CHANGELOG, one requirements row and the evidence/receipt directory. README, dependency manifests/lockfile, toolchain, feature declarations and workflows have no topic changes. The live PR description now identifies the integrated head/base and accurately distinguishes test-oracle correction from a runtime bug fix.
  • Read every body in the supplied fully paginated queue, initially seven global comments, six review records and three threads with all six inline comments. Read the refreshed queue, now eight global comments, including the complete CodeRabbit comment delta and the new hosted Codex usage-limit response. The other six global bodies, all review records and all thread comments are unchanged in the refreshed queue. All three threads are resolved; the sole APPROVED review belongs to the historical 1d81c74 head. Empty review bodies were inspected as empty, not skipped. The current rate-limit notices provide no approval. Pagination collection is owned by the parent; this reviewer inspected both complete captured queues and independently refreshed live PR identity/body.

Every authority-producing path and its consumers

  • Ordinary acquisition: src/adapters/filesystem_writer_lock.rs:72 → :80 → :96 → :107. Root acquisition at :81/:136/:151 precedes opening the existing file at :82/:208; the wrapper at :101 supplies || {}. The shared body admits metadata and regular-file kind at :113–:119, acquires the nonblocking file lock at :121/:165, executes the checkpoint at :122, propagates canonical identity verification at :123/:173, and constructs authority only at :124. Compared line by line with current main's former single body at :96: metadata/identity → kernel acquisition → identity verification → guard construction retain their order and errors. There is no alternative authority-returning body.
  • Initialization parity: filesystem_writer_lock.rs:86 → :96 → the same :107 body. Its distinct ingress uses create-new/existing fallback at :195, while ordinary acquisition uses existing-only at :208. Both retain no-follow/nonblocking read/write options at :214. Initialization synchronizes only a successfully returned guard at :90; missing-file creation remains confined to initialization. Both production paths have exactly the same identity refusal before returning a guard.
  • Initializer and reopened admissions: src/adapters/filesystem_initialization_storage.rs:84 → lock initialization filesystem_writer_lock.rs:86, storing the guard only at initialization-storage :86; filesystem_store_initializer.rs:82 → initialized storage, then retained admission at :93. Published reopen filesystem_store_initializer.rs:109 → filesystem_writer_lock.rs:80, with typed WriterLock failure before namespace admission at initializer :114. Version-two reopen filesystem_version_two_admission.rs:51/:68 → :81 → writer acquisition at :82; both preserve typed error before namespace/record checks at :87/:91 and retained admission at :97.
  • Recovery acquisitions: filesystem_recovery_stage_discarder.rs:38/:65 → :78 → writer acquisition at :79, typed refusal before inventory opening at :84, guard retained at :88. Migration recovery store_migration/filesystem_migration_recovery.rs:42 and its private/repository routes → :61 → writer acquisition at :62, typed refusal before migrating-namespace admission at :67, then ownership into locked inventory at :72. Repository recovery ingress in filesystem_migration_repository_tasks.rs:63 delegates to the same recover_root at :69; it cannot bypass lock identity verification.
  • Guard-consuming publication/migration/retention paths: filesystem_catalog_publisher.rs:55 consumes admission into the retained guard at :59/:74. Repository publisher :94 → filesystem_platform_admission.rs:33 → production platform-profile admission at :38 → ordinary publisher; the private unit-test bypass at platform-admission :54 remains distinct. Migration inventory filesystem_inventory_reader.rs:48 → :61 retains the guard at :89; repository migration filesystem_migration_repository_tasks.rs:35 consumes the supplied guard at :45/:46. Retention authority retention/filesystem_retention_authority.rs:63 consumes version-two admission and retains its guard at :78. None manufactures lock authority or reroutes around the shared acquisition body.
  • Repository process/restart consumers: xtask/.../production_protocol/initialization.rs:30 retains initialized writer authority via :38; its publisher route at :42 now uses ordinary platform initialization :45 and publisher :47. production_protocol/migration.rs:25 → public lock acquisition → migration authority at :27; restart/migration.rs:72 → shared recovery ingress and :88 → public forward-retry acquisition. restart/semantic.rs:44 checks post-process-death reacquisition and drops the guard at :46. These routes preserve precise verification error sources in their task errors. Public lock laws at tests/catalog_writer_lock.rs:18, :37, :60, :81 independently retain acquisition/exclusion/reacquisition, post-return replacement, missing-file and no-follow evidence. Initialization port laws remain separately labeled port evidence.

Controlled experiment, errors and state transitions

  • The changed test at src/adapters/filesystem_writer_lock_tests.rs:17 owns scratch state, retains the root/original handle at :20–:22, and opens an independent contender at :23; this is a separate open, not a cloned open-file description. The callback at :27 probes actual nonblocking contention at :28 before rename/write at :29–:33. Assertion :37 requires exactly Some(Err(TryLockError::WouldBlock)); missing callback, other I/O errors and successful contention probes all fail. drop(contender) at :35 closes any lock obtained by a mutant. Fixture errors propagate separately at :36; escaped authority fails at :43; exact Io/VerifyFileIdentity/InvalidData is required at :44; independent byte comparisons are at :54 and :58. The original inode remains alive across replacement, preventing inode-reuse ambiguity.
  • filesystem_writer_lock.rs:173 reopens the canonical entry with the same no-follow options, reads actual device/inode at :182, and refuses mismatch at :186. writer_lock_acquire_error.rs:11/:41 preserves the I/O source; writer_lock_acquire_phase.rs:7 retains the exact phase vocabulary. Busy root/file locks and inspection/open/sync errors stop at their original boundaries. Refusal occurs before guard construction and owned handles close on error; production invokes no user callback. There is no new async cancellation, retry, shutdown hold, stream, configuration or durability state. The private synchronous callback documents root-then-file locks and prohibits waiting for another lock at writer-lock :104–:106. The experiment's filesystem operations are deliberate test scheduling within this documented section.

Merge audit and preserved incoming contracts

  • Audited the only merge in main..HEAD, e5b176a2e3a0c15d686b98685417067947d15520, against both parents: topic 1d81c749c1203115cae049227fd58e971a22cbed and main eb506dfb3830a32b0aec6a963c69da4f87012161, plus its combined diff. The CHANGELOG conflict adds the topic entry and all incoming main entries without dropping either side. Requirements retain every incoming row change plus the topic's KEEP-RECOVERY-004 evidence extension. Topic Rust and all acquisition evidence blobs are byte-identical to the previous topic parent. Against main, the only changed runtime file is writer-lock's private seam; the only changed test source is its law.
  • Inspected the incoming merge history and both-parent writer-acquisition diffs; none of its 19 mainline/synchronization merges changes writer-lock or the direct initializer/version-two/discard acquisition ingress. The following first-parent integration boundaries and their contracts are preserved byte-for-byte from main in this candidate:
Incoming merge Contract checked for integration
d0cff10d7c911d33d615c3aa2246ae2b4497432a (#172) Partial seal framing refuses proven corruption before truncation classification; recovery_segment_classifier.rs:69 → recovery_segment_seal_framing::validate, exact Seal source at classifier :72.
182e49520f98c6035828a739dcf3c224df535b84 (#158) Sealed stage remains inaccessible; observed_segment_stage.rs:79 → preserved sealed conversion at :83, without giving storage to a callback.
64fafe3ddcc92bcc45a461a0161030b87559070d (#157) Repository catalog publisher retains full platform admission despite its legacy name; publisher :94 → platform admission :33/:38.
1325841cbcd27f4c504870728e3ca87d87a2c4cc (#156) Public admitted filesystem stage target and owned scratch fixtures retained; no stage/publication body is changed by the acquisition seam.
d08fafb2280a480a3c7d9460d13d53bbed4ae46b (#159) Independent release/restore model, expected generations/anchors and exact stale/retry refusals retained unchanged.
34d70909b0cd93f6b020a59d4d40f43b07971cd8 (#160) Real process reader fences retain kernel exclusion, death/release and persistent identity evidence.
1c2b9d788fd4029d2469d2651faf0f8db2e0869e (#175) tests/reader_fence_process/fixture.rs:32 moves the initialized guard into migration authority; :41 returns that live authority. Both process laws retain it at reader_fence_process.rs:27/:70, require exact Busy at :30/:73, and release only at :57/:86. No release/reacquire gap is reintroduced.
80d23f51897085bac34bb5c4db067d0627748e13 (#161) Completed migration calls verify_complete before returning a success receipt: migration_recovery_execution.rs:147 → :149; filesystem implementation filesystem_migration_recovery.rs:86 → version-two namespace admission. Restart namespace/pool/record evidence remains intact.
5179ed78a74d19a3c24f300acbc5228144e6628a (#162) Migration compatibility examples, runtime recovery-planner fuzz witness and retained seed/corpus assets preserved unchanged.
eb506dfb3830a32b0aec6a963c69da4f87012161 (#167) Independent generated catalog histories and precise transition refusal coordinates preserved unchanged.

The nine incoming branch-synchronization merges also checked for acquisition overlap/preservation were e781c0b276ec4d1f66a76668bd31893261a2e6dd, 657593fe50c824dd31dc328bf9e696183ef20767, 05658799fb259a445f68c8bd434135483d491e40, 64bbbf915d87e43fa5c902ddeb0d893f246f9af5, ee21b01d7b7740eaa56116809630534ea7caa05b, ff6f5be4b98e985e00601ab3e854a95e87aa9b34, 2f22d0d9097820503d2a81085bb748273de9f56d, 6e7e2d6a9c965f0240e006c7d45a5bc3c7010d37, and 239bd19553449f8e509cc7752f142f7e2c4e46ff. This checks the topic's integration with reviewed main; it does not claim a fresh exhaustive audit of every unrelated incoming implementation.

  • Read the binding Retention recovery, crash-matrix evidence, reader fence, and model-based transitions (item 6) #99 landing scope at docs/testing-evidence/retention-landing.md:9, :11, :13: incomplete stages require explicit disposition, cooperative writer authority does not isolate concurrent raw namespace mutation, and execution failure is not rollback. Its implementation/evidence and v2 recovery documents have no candidate diff from main. The changed evidence's explicit public-entry/raw-race limit at writer-acquisition-identity.md:11 agrees; the new test does not weaken no-follow, identity, corruption or evidence checks or revive automatic incomplete-stage disposal.

Falsification, raw receipts, every number and standards

  • All six checked-in patches pass read-only git apply --check at the exact candidate. Compared each mutation with its retained original/mutant source: early verification, early checkpoint, ignored refusal, wrong phase, destructive displaced file, destructive replacement file. The final original in raw 169/early-checkpoint/final-original.rs matches current production byte-for-byte. The six RED receipts execute the named law and reach their intended outcome, rather than compilation/setup failure: authority escape (early-order-red.txt:11, ignored-refusal-red.txt:11); missing contention (early-checkpoint-red.txt:13); wrong phase (wrong-phase-red.txt:13); empty observed original (lost-original-red.txt:14–:16); empty observed replacement (lost-replacement-red.txt:13–:15). Each independent load-bearing assertion has falsification evidence.
  • Compared all eleven captured output files byte-for-byte to their original raw logs after only the documented source/target-prefix normalization and redundant trailing-blank-line removal. All match. Raw coordinates are keep-audit/131/initialization/identity-call-mutant/survived.log; keep-audit/169/early-identity/{survived,red}.log; keep-audit/169/early-checkpoint/{survived,red,green}.log; keep-audit/169/{ignored-refusal,wrong-phase,lost-original,lost-replacement}/red.log; and keep-audit/169/ordering-green.log. The six original/mutant source pairs are retained alongside those raw runs. The old helper survivor genuinely passes the old library law, four public lock laws, two initialization port laws and seven initializer laws. Earlier verification/checkpoint survivors each execute one law and pass. No full-suite mutant-survival claim is inferred.
  • Historical coordinates remain explicit: main 6051abb... for old helper survival, 6a5958b... for early verification survival, 1b27e4c... for early-checkpoint survival, the earlier after-lock law for five REDs, and the contention-witness law for the checkpoint RED. README :56 distinguishes the newest experiment from earlier historical receipts. The added witness does not mask the earlier mutants because those five retain actual locking before callback execution. Those five mutations were not freshly executed by this reviewer or promoted into current-head reruns. Removed-call dead-code rejection and the earlier overlay setup failure remain excluded from behavioral RED.
  • Read every changed CHANGELOG/requirements/evidence paragraph and the complete replay table. All test counts, filtered counts, compilation/test durations, PIDs and byte arrays in the eleven text artifacts exactly match the original output comparison; they are historical observations, not correctness totals or budgets. The literal original/replacement strings correspond to the 17/20-byte arrays in destructive RED receipts. Source/toolchain coordinates, Rust/Cargo 1.96.0 and the aarch64 target agree with recorded profiles; fresh validation records Rust 1.96.0 and aarch64. There is no new timing, rate, buffer, timeout, allocation, memory, size or performance threshold to reconcile; no measured performance improvement is claimed. Existing incoming numeric evidence is unchanged from main and remains historical with its own pinned coordinates; this topic does not retune it. No stale new README numeric claim exists because README is unchanged.
  • Read applicable AGENTS.md, binding Testing Standards and enforcement profile. The law explicitly declares medium size, specified KEEP-RECOVERY-004 oracle and helper-test subsumption/deletion criterion at test :13–:15. The evidence declares an oracle correction with a private seam, not an invented unmodified-parent runtime bug. One straight-line, controlled filesystem experiment with literal independent expectations has no sleep, stress loop, uncontrolled schedule, global hook or new network dependency. Scratch ownership is supplied by tests/segment_filesystem_stage/sandbox.rs:19; library/integration root selection is explicit at :20–:25. The changed 64-line test file/law, 222-line production file and four-parameter private seam remain within hard structure limits. No new codec/parser, external arithmetic, unsafe code, public boolean argument, dependency-owned public type, persistent encoding or optimization is introduced. Callback lock ordering/rationale is colocated in source and the evidence. Per-test memory/deadline/network-denial enforcement gaps are disclosed at receipt README :11; this approval does not certify those existing gaps as solved or waived. No imported repository's change-kind or prose rule was imposed.
  • Executed the exact empty-tree-to-HEAD whitespace check, which passes. Read-only patch applicability and receipt/source comparisons pass. Historical redundant EOF blank-line failures are preserved as historical failures and remain fixed.

Execution and coverage limits

Executed by this reviewer: read-only Git identity/history/diffs and clean-state checks; live GitHub PR/main identity/body reads; full queue and refreshed delta inspection; six patch-applicability checks; exact whitespace check; original/mutant source comparisons; eleven normalized raw-output comparisons; read-only Docker toolchain/version and scratch-mount inspection. The absolute container Cargo/Rustc binaries report the documented 1.96.0 hashes/dates and aarch64 target, and both copied-source and target scratch roots independently resolve to ext4. An initial container shell lacked Cargo/Rustc on PATH; explicit installed binary paths resolved that inspection issue without configuration changes. Only this report was written. No host Rust execution, mutation replay, source/configuration edit, comment publication, commit, merge or delegation occurred.

Inspected fresh parent-run execution: the completed copied-Docker chain in 170-validation.log, pinned at lines 1–2 to tree 4edf8d00941d65083bfcad60bdb51bb0a6eb2f26, with Rust/aarch64/ext4 observations at lines 3–10. The parent observed terminal exit 0; I inspected commands and outputs through its final successful fuzz Clippy line. It executes golden-worldline, debug and optimized production crash matrices, conformance, source structure, formatting, all-feature/no-default workspace checks and Clippy with -D warnings, complete all-feature debug/release workspace tests, all-feature doctests, documentation generation, explicit pinned-toolchain checking, and fuzz formatting/build/Clippy. The new acquisition law passes at lines 186 and 2247; public lock, initializer, reader-fence and incoming integration suites run in both profiles. This is fresh exact-tree execution, not transferred historical GREEN. The reviewer inspected this execution rather than launching a duplicate campaign.

Inspected historical execution: all checked-in/raw survivor, six RED, restored debug/release public and initialization laws, and all-feature Clippy receipts described above. They remain historical assertion calibration. Fresh Docker execution confirms the unmutated merged tree.

Skipped or outside this review: fresh mutation replay, reordered focused scheduling beyond the full suite's parallel execution, standalone new performance/resource experiments, exhaustive raw namespace/public-entry interleaving exploration and physical power-loss testing. The topic adds no parser, durable format or performance behavior requiring a new such campaign. The fresh local chain builds/checks fuzz targets but does not itself establish a live runtime fuzz smoke campaign; the current hosted fuzz job, hosted Rust completion, dependency/security policy status, later feedback and branch protections remain parent-owned gates. Static inspection and process-death recovery are not physical power-loss evidence; green tests do not prove absence of regressions.

This source/evidence approval is valid only for the full head below. Any changed head requires renewed review, and historical bot approvals are not transferred.

APPROVE — e5b176a2e3a0c15d686b98685417067947d15520

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer activity summary — landing candidate

Exact candidate e5b176a2e3a0c15d686b98685417067947d15520, tree 4edf8d00941d65083bfcad60bdb51bb0a6eb2f26, integrates main eb506dfb3830a32b0aec6a963c69da4f87012161. Change kind: test-oracle correction with a private deterministic scheduling seam. No unmodified-parent product bug is claimed.

Obligation Severity / source Final disposition and evidence
After-lock replacement schedule P2 hosted review Closed by private checkpoint in 985830e; early verification mutation escapes authority and fails the final law.
Reproducible calibration P2 hosted review Closed by checked-in patches, commands, source/toolchain/profile coordinates and raw survivor/RED/GREEN output in 985830e.
Receipt whitespace P2 independent review Closed by 1b27e4c; normalization is disclosed and final documentation/whitespace gates pass.
Independent observation of lock ownership P2 hosted and independent reviews Closed by 1d81c74; a separate open must observe WouldBlock in the callback. Early-checkpoint mutation fails at the intended assertion.
Refusal, diagnostic and retained bytes #169 acceptance Six distinct calibrated controls cover ordering, refusal, precise phase and both files' contents. All eleven portable receipt files match retained raw output after documented normalization.
Mainline integration Landing review e5b176a preserves both CHANGELOG histories and requirement rows; topic source/receipts remain unchanged from the prior candidate. Incoming #175 continuous writer authority and #99 scope are preserved.
Exact-head independent approval Authorized Codex fallback GPT-6.1 high-reasoning APPROVE, with complete path, merge and evidence checklist.
Local checks Exact candidate tree Full copied-Docker chain passed: conformance/worldline/structure, both crash campaigns, feature checks, formatting/Clippy, debug/release suites, doctests/rustdoc, pinned toolchain and fuzz build/Clippy. Actual ext4 scratch was verified for library and integration roots.
Hosted checks Exact candidate SHA All four jobs in run 37156717967 pass.
Review queue Final paginated GraphQL refresh All review bodies, global discussion and three resolved inline threads reconciled. No active changes-requested review or new actionable finding. CodeRabbit's old approval is historical; current rate limit and hosted Codex quota notice are not approvals.

CodeRabbit's automatic “Bug Fixes” summary is broader than this PR: production already propagated identity refusal; this repairs the evidence and adds a private no-op scheduling seam. Its optional docstring-percentage warning is not a repository acceptance metric; public API documentation and required documentation gates pass.

The test observes a real controlled kernel/filesystem transition at the shared acquisition boundary, not every public-entry schedule or arbitrary concurrent raw namespace mutation. It does not claim physical power-loss coverage or implemented per-test resource ceilings. Historical failed setup and compilation attempts remain excluded from runtime RED.

MERGE GATE: OPEN. The maintainer has already authorized normal merging after clean current-head review and green validation. Repository protections remain enforced.

@flyingrobots
flyingrobots merged commit d7c761e into main Oct 3, 2026
5 checks passed
@flyingrobots
flyingrobots deleted the test/169-writer-acquisition-identity branch October 3, 2026 22:04
flyingrobots added a commit that referenced this pull request Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Calibrate writer authority against lock-entry replacement during acquisition

1 participant