Skip to content

feat(core): stage a captured inventory one page at a time (#445) - #1010

Merged
qnbs merged 7 commits into
mainfrom
feat/445-gate4d-streaming-capture-stage
Oct 8, 2026
Merged

qnbs merged 7 commits into
mainfrom
feat/445-gate4d-streaming-capture-stage

Conversation

@qnbs

@qnbs qnbs commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

User description

What

Stage one of the streaming capture: an inventory built and staged one page at a time, so a very large inventory no longer has to be resident as entries plus an equally large sealed copy (the format allows a million entries of up to a kilobyte).

A page cannot be written to its final place as it is sealed: that place is keyed by the page-set digest, which needs every page's envelope digest, and sealing uses a fresh nonce, so a second pass would bind different bytes. So each envelope is kept on disk, in a private pending directory with the layout of a digest directory (inventory/pending-<revision>-<random>/page-<i>/generation-<g>.wsr1), until the digest is known.

Step Rule
StreamedCapture::begin fence; the caller is the committed owner under the committed manifest; the manifest is the exact root-named generation; the inventory is open (DISCOVER/ADMIT, not final, nothing converted); the announced total is within the bound. Nothing is created
push_page the context must be the one the capture started under (same journal directory, a key that opens the root-named manifest), checked before anything is sealed; next index and the capture's generation assigned; non-empty page; entries valid and strictly ascending across pages; sealed once under the operation's epoch; reference recorded; envelope staged and synced; bytes dropped
finish exactly the announced total; the successor is built by the same function capture_inventory ends in; a failure removes the staged pages
StagedCapture::discard removes the staged page files of a capture that will not be promoted
load_staged_page exact path, bounded; a missing file is Corrupt, never RecoveryRequired (a staged page is a candidate, not authority); the envelope hashes to the reference before it is opened; opens only as this operation's page, epoch compared before the key is used

Staged files are never authority: the manifest does not name them, no reader looks for them. A failure the caller can handle removes the pages staged so far (best effort, including the page in flight), and discard does the same for a finished capture; the files of a killed attempt and the empty page directories stay as inert residue, because the file system abstraction has no directory removal, and reclaiming them is a recorded follow-up. capture_inventory is split into the page-dependent part and the successor build (capture_successor) with no behaviour change; store_page is parameterised by directory.

Differences from the admission (disclosed)

  1. The inventory digest commits to the total entry count before any entry (Β§5.4), so begin takes the total up front and the caller counts before it streams. The admission did not say so.
  2. begin takes a journal context that carries the key and a CaptureStart request (the manifest the root binding names, the fence, the binding and the announced total); the authority-level wrapper that routes the key from the root arrives with stage two, because the routed key has to be resolved again at promotion anyway.
  3. The admission planned a counting file system to bound the page size. Peak memory is not measured: it is bounded by construction, since StreamedCapture has no field that can hold a page or an envelope and a push drops both before it returns.
  4. The tests are a file of their own, gate4d_stream_capture_test, over the generic journal fixtures (TempDir, ObservedFs, the committed journal) that moved out of support/inventory.rs into support/journal_fixture.rs. My first head put them into the store test, which made that file lose its cohesion (CodeScene); a separate file over the whole inventory fixtures would have needed a dead-code suppression, so the fixtures were split instead. The two existing tests that use the inventory fixtures include both modules and are otherwise unchanged.

Decisions flagged on the admission: pending directory plus re-promote instead of a locator or nonce change; reclaiming abandoned pending directories is a follow-up criterion; the builder assigns indexes and generations; the in-memory API stays.

Boundary matrix

Mutation none to the root or the manifest chain; only files under a private inventory/pending-* directory; additive API, no caller yet
Order early authority checks, then page by page: assign, validate and absorb, seal, reference, stage, drop
Refusal stale or foreign owner, a manifest that is not the root-named one, an inventory that is not open, a total above the bound, an empty page, entries out of order, more or fewer entries than announced: each before anything is created (begin) or before the next page is staged

Not in this PR

Stage two (promotion of the staged pages under the root lock and the journal mutex, re-reading and re-verifying each page, the key-routing wrapper and the composed commit), reclaiming abandoned pending directories, the C2 driver, inheriting unchanged pages, the write barrier. No production authority switch.

Verification

Local: fifteen tests in gate4d_stream_capture_test β€” the streamed successor equals what capture_inventory builds from the staged pages (one entry, uneven and even splits, one page, the final capture in ADMIT, a full page plus one with 4097 entries); an empty inventory stages nothing; the staged files are exactly the pending layout under a pending- name; the staged pages are accepted by the existing store; every way a capture cannot start is refused with nothing created; out-of-order pages, a total exceeded or not reached and an empty page; a failure partway removes the pages it staged, also when the failing page was already promoted, a capture that ends short and a discarded capture leave no page file, and a failed removal is not an error; a push under another key or into a journal directory holding an identical copy of the root-named generation is refused before anything is staged; a missing staged page is Corrupt; two attempts under one operation id never share a directory; a changed, swapped, out-of-range or wrongly keyed staged page is refused. Mutation-checked: no digest absorption, no root-named check, no open-inventory check, no pending- prefix, a pending directory named by the caller's operation id, a shifted page directory and no digest check on read each fail the test that owns them. The whole crate suite (49 passing results), cargo clippy --all-targets -D warnings, cargo fmt --check, pnpm run docs:check.

Part of #359 and #445 (Linear QNB-11). Admission: #359 issuecomment-6062112221. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Summary by Sourcery

Stage captured inventories incrementally through private pending pages while preserving existing manifest construction and authority boundaries.

New Features:

  • Add a public streamed inventory capture API that accepts entries page by page and stages sealed pages in private pending storage.
  • Add verified loading of staged pages for later promotion.

Bug Fixes:

  • Prevent invalid, incomplete, foreign, or tampered streamed captures from being accepted or leaving their staged files behind when cleanup is possible.
  • Treat missing staged pages as corrupt capture artifacts rather than journal recovery states.

Enhancements:

  • Refactor inventory capture successor construction so in-memory and streamed captures share the same validation and manifest-building path.
  • Bind captures to their starting journal and key context and keep only the current page in memory while streaming.

Documentation:

  • Document the stage-one streaming capture contract, pending-page lifecycle, validation rules, cleanup behavior, and stage-two follow-up.

Tests:

  • Add comprehensive streaming capture coverage for page ordering, announced totals, staging layout, context validation, cleanup, tampering, and compatibility with the existing inventory store.

Chores:

  • Extract shared journal test fixtures for inventory and streaming capture tests.

Summary by CodeRabbit

  • New Features
    • Added page-by-page inventory capture with an upfront entry count, ordered-page validation, and staged-page verification.
    • Captures remain bound to the original journal and key. On handled failures or explicit discard, staged files are removed where possible.
    • Staged captures can be read back and passed to the existing inventory storage flow.
  • Documentation
    • Documented streaming capture requirements, staged-page verification, failure handling, and the remaining promotion and commit work.

CodeAnt-AI Description

Stage large inventory captures one page at a time

What Changed

  • Large inventories can be captured page by page, without keeping every sealed page in memory at once.
  • Captures check the announced entry total, entry order, and journal ownership; invalid attempts are refused.
  • Staged pages remain uncommitted until a later promotion step and are checked before use. Handled failures and discarded captures remove their staged files when possible.

Impact

βœ… Lower memory for large inventory captures
βœ… Fewer abandoned page files after handled failures
βœ… Changed or missing staged pages rejected before use

πŸ’‘ Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

The inventory store and capture_inventory hold every sealed page in
memory, and the format allows a million entries. A page cannot be written
to its final place as it is sealed: that place is keyed by the page-set
digest, which needs every page's envelope digest, and sealing uses a
fresh nonce, so a second pass would bind different bytes.

StreamedCapture takes the entries page by page, assigns the page index
and generation, checks that they are valid and strictly ascending across
pages, seals each page once and stages its envelope in a private
inventory/pending-* directory, keeping one page and one reference per
page in memory. The total is announced up front because the inventory
digest commits to it first. finish builds the successor with the same
function capture_inventory ends in, and load_staged_page confirms a
staged page against its reference before it is opened. Staged files are
never authority. Promotion under the root lock is the next stage.
@sourcery-ai

sourcery-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 hours and 52 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

πŸ€– CodeAnt AI β€” Review Status

Status Commit Started (UTC) Finished (UTC)
βœ… Reviewed your PR 63e8236 Oct 08, 2026 Β· 18:06 18:10
βœ… Incremental review completed 63e8236 Oct 08, 2026 Β· 18:04 18:04
βœ… Reviewed your PR 2dac290 Oct 08, 2026 Β· 17:30 17:37
βœ… Reviewed your PR 27f0528 Oct 08, 2026 Β· 16:53 16:58
βœ… Reviewed your PR 07bdc86 Oct 08, 2026 Β· 16:37 16:37

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 8, 2026 6:05pm UTC

@codeant-ai

codeant-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! πŸŽ‰

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X Β·
Reddit Β·
LinkedIn

@sourcery-ai

sourcery-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Reviewer's Guide

Implements stage one of streaming inventory capture: callers announce the total, push validated pages that are sealed once and durably stored in randomized inert pending directories, then finish to produce the same validated successor manifest as the existing in-memory capture; staged pages can be authenticated on readback, while promotion and commit remain deferred to stage two.

Sequence diagram for staged streaming inventory capture

sequenceDiagram
    participant Caller
    participant StreamedCapture
    participant InventoryVerifier
    participant PendingStore
    participant SuccessorBuilder

    Caller->>StreamedCapture: begin(ctx, committed, fence, live, entry_count)
    StreamedCapture->>StreamedCapture: assert_page_promote_authority()
    StreamedCapture->>StreamedCapture: assert_root_named_manifest()
    StreamedCapture->>StreamedCapture: assert_inventory_open()
    StreamedCapture-->>Caller: StreamedCapture
    loop Each page
        Caller->>StreamedCapture: push_page(ctx, entries)
        StreamedCapture->>InventoryVerifier: absorb_page(page)
        StreamedCapture->>PendingStore: seal_inventory_pages()
        StreamedCapture->>PendingStore: store_page_at()
        PendingStore-->>StreamedCapture: synced envelope
        StreamedCapture-->>Caller: StreamedCapture
    end
    Caller->>StreamedCapture: finish()
    StreamedCapture->>InventoryVerifier: finish_digest()
    StreamedCapture->>SuccessorBuilder: capture_successor()
    SuccessorBuilder-->>Caller: StagedCapture
Loading

Sequence diagram for authenticated staged page loading

sequenceDiagram
    participant Caller
    participant PendingStore
    participant PageReader

    Caller->>PendingStore: load_staged_page(ctx, staged, page_index)
    PendingStore->>PendingStore: read_envelope()
    PendingStore->>PendingStore: content_digest(envelope)
    alt reference digest matches
        PendingStore->>PageReader: open_stored_page()
        PageReader-->>Caller: StagedPage
    else digest mismatch or invalid reference
        PendingStore-->>Caller: JournalError
    end
Loading

File-Level Changes

Change Details Files
Add a public streaming capture API that validates and stages inventory pages incrementally without retaining sealed pages or envelopes in memory.
  • Validate fence, ownership, root binding, open inventory state, announced count, page ordering, and page non-emptiness.
  • Assign page indexes and capture generation, seal each page once, compute its reference, and durably stage it under a randomized pending directory.
  • Build the staged successor manifest with the existing capture successor logic and expose staged metadata.
  • Re-export the streaming types and staged-page loader through the crate API.
crates/worldscript-secure-storage/src/journal/stream_capture.rs
crates/worldscript-secure-storage/src/journal/mod.rs
crates/worldscript-secure-storage/src/lib.rs
Make capture and page-storage internals reusable for both in-memory and streamed capture paths.
  • Split successor-manifest construction from page collection and reuse it in both capture implementations.
  • Parameterize page storage by destination directory while preserving staging, promotion, and sync behavior.
  • Expose bounded envelope reading and epoch-safe page opening for staged-page loading.
crates/worldscript-secure-storage/src/journal/capture.rs
crates/worldscript-secure-storage/src/journal/inventory_store.rs
crates/worldscript-secure-storage/src/journal/inventory_read.rs
Provide authenticated readback of pending pages before future promotion.
  • Resolve only the exact bounded path recorded for the requested page.
  • Verify the envelope content digest against its page reference before decryption.
  • Open the page with the expected index, generation, operation epoch, and key, and verify its entry count.
crates/worldscript-secure-storage/src/journal/stream_capture.rs
Document and test the stage-one streaming-capture contract and its failure behavior.
  • Cover successor equivalence, empty captures, pending layout, store compatibility, authority refusals, ordering/count validation, partial failures, independent retries, and tampered or mis-keyed pages.
  • Add contract and evidence documentation describing inert pending files, memory bounds, disclosed deviations, and stage-two follow-up work.
  • Record the feature in the unreleased changelog.
crates/worldscript-secure-storage/tests/gate4d_inventory_store_test.rs
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md
CHANGELOG.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 63e8236c
Scan Time: 2026-10-08 18:35:25 UTC

βœ… Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets βœ… PASSED 0 secrets found
Duplicate Code βœ… PASSED 1.0% duplicated
SAST βœ… PASSED No security issues
Bugs βœ… PASSED Rating S: No bugs
IAC βœ… PASSED No IAC issues

View Full Results

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Oct 8, 2026
codescene-access[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the hard tier (normal profile): 16 files, 1718 meaningful lines, 7 commits β€” limit ≀20 files / ≀1200 lines / ≀10 commits. Consider splitting into smaller, independently reviewable PRs.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack β†’

No actionable comments were generated in the recent review. πŸŽ‰

ℹ️ Recent review info
βš™οΈ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: b6419716-e706-48fc-a259-5b9c72825485
πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between 07bdc86 and 63e8236.

πŸ“’ Files selected for processing (5)
  • crates/worldscript-secure-storage/src/journal/stream_capture.rs
  • crates/worldscript-secure-storage/tests/gate4d_stream_capture_test.rs
  • crates/worldscript-secure-storage/tests/support/journal_fixture.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


πŸ“ Walkthrough

Walkthrough

The journal adds streaming inventory capture. It stages sealed pages in a private pending directory, validates the announced entry count and page ordering, builds a successor manifest, and verifies staged pages against their references. Promotion and composed commit remain outside this change.

Changes

Streaming inventory capture

Layer / File(s) Summary
Capture and journal anchor primitives
crates/worldscript-secure-storage/src/journal/capture.rs, crates/worldscript-secure-storage/src/journal/durable.rs, crates/worldscript-secure-storage/src/journal/inventory_read.rs, crates/worldscript-secure-storage/src/journal/inventory_store.rs
Shared helpers calculate the next revision and build a validated successor manifest. Journal code can verify root-named manifest anchors. Page storage and read helpers are available to the streaming module.
Stream, stage, and verify pages
crates/worldscript-secure-storage/src/journal/stream_capture.rs, crates/worldscript-secure-storage/src/journal/mod.rs, crates/worldscript-secure-storage/src/lib.rs, crates/worldscript-secure-storage/tests/*, crates/worldscript-secure-storage/tests/support/*, CHANGELOG.md, docs/native/R15-SECURE-STORAGE-CONTRACT.md, docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md, docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md
StreamedCapture checks authority and inventory state, stages validated pages, and builds a successor after the announced total is met. load_staged_page verifies staged pages against their references. Tests cover validation, staging, cleanup, and readback. The changelog and contract documents describe stage one; promotion and composed commit remain pending.

Priority: βž– Normal

Merge Risk: βšͺ Minimal Β· up to 63e82

No actionable merge-blocking issue is established; the PR is mergeable after normal checks.

  • Autopilot Β· Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs
Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs Outdated
@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

CodeAnt Nitpicks

1 code suggestion

1. A same-path, same-key context can use a different DurableFs backing store, so successive pushes scatter pages and the capture is incomplete when loaded or promoted from one store.

Api mismatch Β· crates/worldscript-secure-storage/src/journal/stream_capture.rs:250-255

@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

CodeAnt PR Risk: Medium Risk

  • The PR needs attention before merging because abandoned streamed captures can leave pending page files indefinitely.
  • A killed attempt or dropped StagedCapture cannot be reclaimed by this API; repeated attempts can consume disk, and cleanup is deferred.

Assessed commit: 63e8236c75c2

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f610b6475d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs
Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs Outdated
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
πŸ“ Code Review βœ… Completed 2026-10-08T18:11:06.572543Z 63e8236 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with πŸ‘€ while any review is running, comments if it has suggestions, and reacts with πŸ‘ once all reviews finish with no findings.

…quest struct (#445)

CodeScene flagged two things on the first head. begin took five
arguments; it now takes the context and a CaptureStart request (the
manifest the root binding names, the fence, the binding and the announced
total). The streaming tests made the inventory store test lose its
cohesion; they are a file of their own, over the generic journal fixtures
(TempDir, ObservedFs, the committed journal) that moved out of the
inventory fixtures into support/journal_fixture.rs, so a test that needs
only a committed journal does not carry the page fixtures and no lint
suppression is needed. The two existing tests that used the inventory
fixtures include both modules and are otherwise unchanged.
Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs
Comment thread crates/worldscript-secure-storage/tests/gate4d_inventory_store_test.rs Outdated
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codeant-ai codeant-ai Bot added size:XXL This PR changes 1000+ lines, ignoring generated files and removed size:XL This PR changes 500-999 lines, ignoring generated files labels Oct 8, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 4317ed77dd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

βœ… All modified and coverable lines are covered by tests.
βœ… All tests successful. No failed tests found.

πŸ“’ Thoughts on this report? Let us know!

…up after a failure (#445)

Review of the first heads found four real gaps in the staging stage.

A push took whichever context it was given, so a context with another key
staged pages the routed journal key cannot open, and another journal
directory moved the directory-sync boundary. The capture now remembers its
journal directory and the binding it started from, and every push first
requires the same directory and a key that opens the root-named manifest.

A push or a finish that failed after earlier pages were written left them
behind. A failure the caller can handle now removes the staged page files
on the way out, best effort and including the page in flight, finish takes
the context for that, and StagedCapture::discard does the same for a
finished capture that will not be promoted. Empty directories and the
files of a killed attempt stay, because the file system abstraction cannot
remove a directory; reclaiming them is a recorded follow-up.

A missing staged page was reported as RecoveryRequired by the reader
shared with authoritative pages. A staged page is a candidate, so a
missing one is now Corrupt, never a recovery state of the journal.
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 07bdc86b0b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs Outdated
#445)

The cleanup of a failed, short or discarded capture removed every
completed page unconditionally, so a page that had been replaced after it
was staged would have been deleted with the rest. Every removal now
checks the file against the digest the capture recorded for it, the same
rule the page in flight already followed, so only bytes this capture
wrote are ever deleted.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 27f0528e19

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs Outdated
Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs
Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs Outdated
…tures uniquely owned (#445)

A push that failed because its page slot was already taken left the
staging link that the failed promotion reports; the cleanup now removes
it under the same digest rule as the staged pages. StagedCapture is a
handle to files on disk, so it is no longer Clone: discarding one copy
would have invalidated the other.
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/tests/support/journal_fixture.rs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2dac290c61

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/journal/stream_capture.rs
…create test directories exclusively (#445)

A promotion that succeeds but cannot unlink its staging link reports
success with the link still present, and the cleanup only knew the names
of the pages. The capture now stages under its own random identity
instead of the caller's operation id, so the name of every staging link
follows from the capture itself and the cleanup removes it, under the
same digest rule as the pages.

The test directory fixture moved out of the inventory fixtures with a
predictable name that create_dir_all accepted when it already existed.
It now creates the directory exclusively and skips a name that is taken,
so Drop only removes what it created.

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 63e8236c75

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

Final disposition census β€” head 63e8236c

HEAD = 63e8236c75c209acedb1d4a2773664c73942f920   7 signed commits   exact-head CI + CodeQL: success (39 pass / 3 skipped / 0 fail)
REVIEW THREADS = 15 / 15 resolved, 0 unresolved
Codex = exact head: one P3 prose finding, deferred below, nothing else   CodeScene = 3/3 gates passed (approved)
CodeAnt = gates pass (1.0% duplicated), PR Risk Medium (known residue, deferred below)   Codecov patch = success
Sourcery / DeepSource / cubic = rate-limited or skipped: NO_SIGNAL
SIZE = 16 files, 1718 meaningful lines, 7 commits β€” over the target (8 / 400 / 6) and over the checker's hard tier on lines (20 / 1200 / 10), inside the absolute ceiling (30 / 3000 / 15); the size job passes

The size comes from the test file and from two things that count twice: the journal fixtures moved out of support/inventory.rs into support/journal_fixture.rs, and five review waves that each added tests. Stage two is planned to stay under the target.

Wave Finding Disposition
1 CodeScene begin had five arguments VALID_AND_FIXED β€” a CaptureStart request
1 CodeScene the streaming tests made gate4d_inventory_store_test lose cohesion (10.00 β†’ 8.82) VALID_AND_FIXED β€” a test file of their own over support/journal_fixture.rs, split out of the inventory fixtures; no suppression
2 CodeAnt + Codex a push seals with whatever context it is given VALID_AND_FIXED β€” the capture is bound to its journal directory and to the key that opens the root-named manifest
2 CodeAnt abandoned captures leak disk VALID_AND_FIXED for every failure the caller can handle (failed push, failed or short finish, discard); VALID_AND_DEFERRED_WITH_ACCEPTANCE_CRITERION for a killed attempt, a dropped finished capture and the empty page directories (no directory removal in DurableFs) β€” reclaiming is recorded on #359
2 Codex a missing staged page was RecoveryRequired VALID_AND_FIXED β€” Corrupt, never a recovery state of the journal
3 CodeAnt the manifest was re-read and re-opened on every push VALID_AND_FIXED β€” begin keeps the authenticated bytes, a push reads nothing (a test counts the reads)
3 Codex cleanup removed the slot in flight unconditionally VALID_AND_FIXED β€” removed only if it holds exactly the staged bytes
4 Codex completed pages removed unconditionally VALID_AND_FIXED β€” one rule for every removal: the file must still hash to the digest the capture recorded
4 Codex the staging link of a failed promotion is left behind VALID_AND_FIXED
4 Codex verify and delete are not atomic INVALID_WITH_EVIDENCE β€” DurableFs has no unlink by handle; the directory is private, randomly named and never authority, so a racing writer there already has write access to the authoritative journal; stated as a limit in the evidence
4 Codex StagedCapture is Clone VALID_AND_FIXED β€” not Clone
5 CodeAnt TempDir accepted a predictable existing path VALID_AND_FIXED β€” exclusive creation; the code predates the PR (moved)
5 Codex the staging link of a successful promotion is lost to the cleanup VALID_AND_FIXED β€” the capture stages under its own identity so every link name is known
6 Codex (P3) the evidence says eighteen tests, the file has nineteen VALID_AND_DEFERRED_WITH_ACCEPTANCE_CRITERION β€” stage two rewrites that paragraph and stops quoting a count
CodeAnt nitpick two different DurableFs stores behind one path and key INVALID_WITH_EVIDENCE β€” a store is identified by its path; two backing stores for one journal directory are outside the contract of every journal operation, each of which takes its file system per call
CodeAnt PR Risk abandoned captures leave pending files VALID_AND_DEFERRED_WITH_ACCEPTANCE_CRITERION β€” the reclamation criterion above

Differences from the admission, disclosed in the PR and the evidence: the total is announced up front (the inventory digest commits to it first); begin takes a journal context carrying the key and the key-routing wrapper arrives with stage two; peak memory is bounded by construction and not measured by a counting file system; the tests are a file of their own.

Proof: 19 tests in gate4d_stream_capture_test, mutation-checked for every behaviour above (digest absorption, the root-named, open-inventory and context checks, the pending- name, the caller's operation id, the page directory, the digest check on read, each cleanup site, the slot in flight, the foreign file, the replaced page, both staging links, the manifest read per push, and the missing-page class). Whole crate suite (50 passing results), clippy -D warnings, fmt --check, docs:check.

Scope: staging only. No promotion, no composed commit, no C2, no graphify. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL This PR changes 1000+ lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant