Skip to content

feat(core): stage a streamed inventory without handling a journal key (#445) - #1012

Merged
qnbs merged 3 commits into
mainfrom
feat/445-gate4d-streaming-capture-session
Oct 8, 2026
Merged

qnbs merged 3 commits into
mainfrom
feat/445-gate4d-streaming-capture-session

Conversation

@qnbs

@qnbs qnbs commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

User description

What

Stage two (b) of the streaming capture: the staging stage no longer takes anything from its caller that the root already names. After #1011, StreamedCapture::begin and push_page still took the journal key (through the context), the committed manifest and the root binding from the caller, and the commit took a committed manifest and a journal directory that it compared with the staged one by spelling (a finding deferred on #1011).

Step Rule
begin_streamed_capture reads the binding from the committed root (NoLiveMigration if none), routes the journal key through the key-epoch registry (JournalRoute errors), loads the committed manifest by the exact root-named path under that key, and starts the stage-one capture over it (so the token, the open inventory and the announced total are checked as before). The caller supplies the journal source (directory and write operation), the owner's token and the announced total. Nothing is created and no lock is taken
StagingSession::push_page / finish the stage-one operations under the key and the directory the session holds: staging handles no key and spells the journal directory once
commit_streamed_inventory_capture no longer takes a committed manifest or a journal directory: it promotes into the directory the capture was staged in and loads the committed manifest from the root under the routed key while the lock is held, inside the shared core

Decisions to review (mine, flagged on the admission): the session reads the manifest and the binding itself, which goes beyond the QNB-11 text (it names only the key); StreamedInventoryCapture changes shape (S2a had no caller); the session holds the routed key for its lifetime and the commit routes again, so a key that went stale in between is refused at promotion; staging stays lock-free.

Boundary matrix

Mutation none at the start (nothing is created before the first page); otherwise the pending files of stage one and the commit's journal and root writes, as before
Order root binding, routed key, root-named manifest, then the stage-one checks; at the commit the shared core under the root lock
Refusal no bound migration, an unroutable epoch (revoked, unregistered), a route to another key (Open(Tampered)), a stale token, a journal that moved on since the capture began (StaleMigrationOwner before any write, staged files kept)

Not in this PR

The C2 driver, reclaiming abandoned pending directories, inheriting unchanged pages, the write barrier. No production authority switch.

Verification

Local: the stage-two cases of #1011 run unchanged in substance against the smaller input, and now stage through a session with no key, manifest or binding in the caller's hands (the happy path still equals the in-memory capture of the same pages and verifies); a session is refused before anything is created with a stale token and with no bound migration; a commit after the owner moved the journal on is refused before any write with the staged files kept; the route refuses the session with a revoked or unregistered epoch and with a route to another key, beside the other journal-owner operations. Mutation-checked: a fixed journal key in the session, no binding requirement, and a wrong committed revision in the commit each fail the test that owns them. The whole crate suite (50 passing results), cargo clippy --all-targets -D warnings, cargo fmt --check, pnpm run docs:check. Size: 8 files, about 415 meaningful lines, 1 commit.

Part of #359 and #445 (Linear QNB-11). Admission: #359 issuecomment-6069756829. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Summary by Sourcery

Route streamed inventory staging from authenticated root state and remove redundant journal authority inputs from the capture API.

New Features:

  • Add an authority-level staging session that derives journal state from the authenticated root and routes the journal key automatically.
  • Allow streamed inventory pages to be staged and committed without caller-supplied keys, manifests, bindings, or journal directories.

Bug Fixes:

  • Reject stale or changed journal ownership before writes while retaining finished staged files for retry.

Enhancements:

  • Load root-bound manifests during commit and simplify staged-capture cleanup so discarding requires only the file system.
  • Document the streamed capture staging-session contract and its retention behavior.

Documentation:

  • Document the stage-two streaming session, root-derived authority checks, and retry-safe staged-file retention.

Tests:

  • Cover early refusal, journal routing, root-only session startup, stale-owner commits, keyless discard, and successful session-based capture flows.

Chores:

  • Update the public storage API and changelog for the new streamed capture staging workflow.

Summary by cubic

Staging a streamed inventory no longer takes the journal key, the committed manifest, or the root binding from its caller, and the commit no longer takes a committed manifest or a journal directory.

begin_streamed_capture reads the live migration binding from the committed root alone (catalog pages are not read, so a capture of a million-record inventory does not first materialise it), routes the journal key through the key-epoch registry, loads the committed manifest from the exact root-named path, and returns a StagingSession that stages page by page under a held key and journal directory. commit_streamed_inventory_capture promotes into the directory the capture was staged in and loads the committed manifest from the root under the routed key while the root lock is held. Discarding a finished capture now needs only the file system, since a session caller never held a key. Docs now separate the cleanup of an incomplete capture (a handled failure removes pages staged so far) from the retention of a finished one (a failed promotion or commit keeps the staged files until the root commits).

Behavior changes

  • Callers of the staging path supply only the journal source, the owner's token, and the announced total; the commit requires neither a committed manifest nor a journal directory.
  • Nothing is created and no lock is taken at session start, so early refusals (no bound migration, revoked or unregistered epoch, route to another key, stale token, journal moved on) happen before any write.

Decisions to review

  • The session reads the manifest and binding itself, which goes beyond the QNB-11 text (it names only the key).
  • The session holds the routed key for its lifetime and the commit routes again, so a key that went stale in between is refused at promotion.
  • StreamedInventoryCapture changes shape; stage two (a) had no caller.

Written for commit 56c89a8. Summary will update on new commits.

View guided diff Turn on auto-fix

Summary by CodeRabbit

  • New Features
    • Streamed inventory capture now starts from the authenticated root, which routes the journal key and selects the directory for staging.
    • Capture commits now retrieve the committed manifest from the root and promote staged pages from their original staging directory.
    • Staged pages are removed only after the root commits the complete set.
  • Bug Fixes
    • Capture operations are refused when the migration fence is stale, no migration is bound, or the journal advances after staging.

CodeAnt-AI Description

Route streamed inventory capture from the committed root

What Changed

  • Capture sessions now get the journal key, binding, and starting manifest from the committed root, so callers only provide the journal location, owner token, and expected entry count.
  • Starting a session no longer loads catalog pages and refuses missing or stale authority before creating files. Commits recheck the current manifest and use the directory where the capture was staged.
  • Finished captures can be discarded without a journal key, and staged pages remain available after a rejected or failed commit.

Impact

βœ… No journal key needed to stage inventory
βœ… Catalog pages stay unloaded during capture startup
βœ… Staged pages remain available for commit retries

πŸ’‘ Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

…#445)

Staging still took the journal key, the committed manifest and the root
binding from its caller, and the commit took a committed manifest and a
journal directory that it compared with the staged one by spelling.

begin_streamed_capture reads the binding from the committed root, routes
the journal key through the key-epoch registry, loads the committed
manifest by the exact root-named path under that key and starts the
stage-one capture over it. The returned StagingSession stages page by
page under that key and one journal directory value, so the caller never
handles a key and never spells the directory twice.

commit_streamed_inventory_capture loses its committed-manifest and
journal-directory inputs: it promotes into the directory the capture was
staged in and loads the committed manifest from the root under the routed
key while the lock is held.
@sourcery-ai

sourcery-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 9 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

πŸ€– CodeAnt AI β€” Review Status

Status Commit Started (UTC) Finished (UTC)
βœ… Reviewed your PR 56c89a8 Oct 08, 2026 Β· 23:05 23:10
βœ… Reviewed your PR d6f6894 Oct 08, 2026 Β· 22:28 22:29
βœ… Reviewed your PR b29d001 Oct 08, 2026 Β· 22:12 22:16

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 8, 2026 11:06pm UTC

@codeant-ai

codeant-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! πŸŽ‰

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X Β·
Reddit Β·
LinkedIn

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
πŸ“ Code Review βœ… Completed 2026-10-08T23:09:17.256679Z 56c89a8 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with πŸ‘€ while any review is running, comments if it has suggestions, and reacts with πŸ‘ once all reviews finish with no findings.

@sourcery-ai

sourcery-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Reviewer's Guide

The PR moves streamed inventory staging behind an authority-owned StagingSession: the root and key-epoch registry determine the binding, routed key, and committed manifest at start, while the session retains the staging directory and key for lock-free page operations. Commit re-routes and re-reads authority state under the root lock, promotes into the session’s directory, and fails safely when ownership or revision changes; tests and contract documentation cover the new API and refusal semantics.

Sequence diagram for streamed inventory staging and commit

sequenceDiagram
    participant Caller
    participant Authority
    participant Root as CommittedRoot
    participant Registry as KeyEpochRegistry
    participant Journal
    participant Lock as RootLock

    Caller->>Authority: begin_streamed_capture(fs, provider, layout, begin)
    Authority->>Root: load_catalog()
    Root-->>Authority: live_migration binding
    Authority->>Registry: resolve_journal_key(journal)
    Registry-->>Authority: routed key
    Authority->>Journal: load_authoritative_manifest(root-named path)
    Journal-->>Authority: committed manifest
    Authority->>Journal: StreamedCapture::begin(token, total)
    Authority-->>Caller: StagingSession(key, journal_dir)

    loop Each page
        Caller->>Authority: StagingSession::push_page(entries)
        Authority->>Journal: StreamedCapture::push_page(entries)
        Journal-->>Authority: updated staging capture
        Authority-->>Caller: StagingSession
    end

    Caller->>Authority: StagingSession::finish()
    Authority->>Journal: StreamedCapture::finish()
    Journal-->>Caller: StagedCapture

    Caller->>Authority: commit_streamed_inventory_capture(capture)
    Authority->>Lock: acquire root lock
    Authority->>Registry: resolve_journal_key(root binding)
    Registry-->>Authority: routed key
    Authority->>Root: load_authoritative_manifest(root-named path)
    Root-->>Authority: committed manifest
    Authority->>Journal: promote_staged_inventory_fenced(staged directory)
    Authority->>Root: publish successor and advance binding
    Authority->>Lock: release root lock
    Authority-->>Caller: committed manifest
Loading

Flow diagram for streamed capture refusal and commit safety

flowchart TD
    A[begin_streamed_capture] --> B{Bound live migration?}
    B -- No --> X[NoLiveMigration]
    B -- Yes --> C[resolve_journal_key]
    C --> D{Journal route valid?}
    D -- No --> Y[JournalRoute error]
    D -- Yes --> E[load_authoritative_manifest]
    E --> F[StreamedCapture::begin]
    F --> G[StagingSession stages pages lock-free]
    G --> H[finish -> StagedCapture]
    H --> I[commit_streamed_inventory_capture]
    I --> J[Root lock]
    J --> K[resolve_journal_key and load_authoritative_manifest]
    K --> L{Owner and revision still valid?}
    L -- No --> M[Refuse before promotion; keep staged files]
    L -- Yes --> N[promote_staged_inventory_fenced]
    N --> O[Publish successor and advance root binding]
Loading

File-Level Changes

Change Details Files
Introduces an authority-level staging session that derives journal authority from the authenticated root instead of requiring callers to provide it.
  • Reads the live-migration binding from the root and routes the journal key through the epoch registry.
  • Loads the root-named committed manifest before starting stage-one capture validation.
  • Stores the routed key and journal directory in the session and uses them for page staging and finishing.
  • Preserves lock-free staging and early refusal behavior without creating files.
crates/worldscript-secure-storage/src/authority.rs
crates/worldscript-secure-storage/src/lib.rs
Makes streamed inventory commit authoritative over the staged capture's directory and the root's current manifest.
  • Removes committed-manifest and journal-directory caller inputs from the streamed commit handle.
  • Re-routes the journal key and loads the root-named manifest while holding the shared commit lock.
  • Promotes staged pages using the directory captured by the staging session.
  • Rejects captures when the journal owner or committed revision changed, while retaining staged files for retry.
crates/worldscript-secure-storage/src/authority.rs
Updates integration coverage to exercise the new caller-facing API and its refusal and retry guarantees.
  • Stages complete inventories through StagingSession without exposing a key, manifest, or binding to test callers.
  • Verifies no writes occur for stale tokens, missing bindings, revoked or unregistered epochs, and routes to another key.
  • Verifies a journal move between staging and commit is rejected before writes and preserves pending files.
  • Retains successful promotion, page-integrity, manifest-failure, root-failure, and retry scenarios.
crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs
crates/worldscript-secure-storage/tests/gate4d_root_binding_test.rs
Documents and announces the new streaming-capture authority boundary.
  • Adds the release changelog entry for the staging-session API and commit input changes.
  • Updates the secure-storage contract and Gate 4D evidence with ordering, refusal, mutation, and lock-scope rules.
  • Removes this completed slice from the outstanding gap matrix.
CHANGELOG.md
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 56c89a81
Scan Time: 2026-10-08 23:10:47 UTC

βœ… Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets βœ… PASSED 0 secrets found
Duplicate Code βœ… PASSED 0.0% duplicated
SAST βœ… PASSED No security issues
Bugs βœ… PASSED Rating S: No bugs
IAC βœ… PASSED No IAC issues

View Full Results

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Oct 8, 2026
codescene-access[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 10 files, 520 meaningful lines, 3 commits β€” limit ≀8 files / ≀400 lines / ≀6 commits. Consider splitting into smaller, independently reviewable PRs.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack β†’

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 6 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 67 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

βš™οΈ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: f09c9b69-9328-481d-b3d5-b6ab7072d4fe
πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between b29d001 and 56c89a8.

πŸ“’ Files selected for processing (6)
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/journal/stream_capture.rs
  • crates/worldscript-secure-storage/tests/gate4d_root_binding_test.rs
  • crates/worldscript-secure-storage/tests/gate4d_stream_capture_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
πŸ“ Walkthrough

Walkthrough

The change adds an authority-managed staging session for streamed inventory capture. It routes the journal key and reads binding and manifest data from the root. Commit now uses the staged capture’s directory and loads the committed manifest from the root.

Changes

Root-routed streamed capture

Layer / File(s) Summary
Start and stage a capture
crates/worldscript-secure-storage/src/authority.rs, crates/worldscript-secure-storage/src/lib.rs, crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs, crates/worldscript-secure-storage/tests/gate4d_root_binding_test.rs, docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
begin_streamed_capture reads root-bound journal state, routes the key, and returns a StagingSession. The session stages pages using its retained key and directory. Tests cover session-start refusal cases.
Commit staged capture
crates/worldscript-secure-storage/src/authority.rs, crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs, crates/worldscript-secure-storage/tests/gate4d_root_binding_test.rs, docs/native/R15-SECURE-STORAGE-CONTRACT.md, docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md, docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md, CHANGELOG.md
Commit takes the staged capture and fence, routes the journal key, and loads the committed manifest from the root under the lock. Updated tests cover refusal, failure, and retry behavior. Documentation and the changelog describe the revised flow.

Priority: ⬇️ Low

Merge Risk: πŸ”΅ Low Β· up to b29d0

Clarify when staged files are removed so callers can implement failure cleanup and commit retries consistently. This bounded documentation issue does not block merging.

  • Autopilot Β· Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
βš™οΈ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 13816b07-02bc-4fac-93f4-3986f63e3ff1
πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between abd49cf and b29d001.

πŸ“’ Files selected for processing (8)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs
  • crates/worldscript-secure-storage/tests/gate4d_root_binding_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
  • docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md Outdated
@codeant-ai

codeant-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

CodeAnt PR Risk: Low Risk

  • The PR appears safe to merge: staging routes the journal key from the authenticated root, and commit reloads the root-named manifest under the lock.
  • Added tests cover stale fences, a journal moved during staging, refused routing, tampered pages, and retry preservation.

Assessed commit: 56c89a817d02

…tention of a finished one (#445)

The contract paragraph on streamed captures said both that a handled
failure removes the pages staged so far and that staged files are removed
only after the root has committed. The first applies while a capture is
being staged, the second to a finished capture through its promotion and
commit; the paragraph now says which is which.
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d6f6894b39

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/authority.rs Outdated
Comment thread crates/worldscript-secure-storage/src/authority.rs
@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

βœ… All modified and coverable lines are covered by tests.
βœ… All tests successful. No failed tests found.

πŸ“’ Thoughts on this report? Let us know!

…without a key (#445)

begin_streamed_capture read the whole catalog (load_catalog) only to take
the live-migration binding out of the root, which for a catalog of a
million records materialises it before the first page of a memory-bounded
capture. It now reads the committed root alone.

StagedCapture::discard required a journal context and so a journal key,
which a caller that staged through a session never holds; it only ever
needed the file system, so it takes that.
@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Health Improved (1 files improve in Code Health)

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

View Improvements
File Code Health Impact Categories Improved
gate4d_root_binding_test.rs 6.81 β†’ 7.02 Code Duplication

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 56c89a817d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@codeant-ai

codeant-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown

CodeAnt Nitpicks

1 code suggestion

1. A replacement can land after the digest read but before remove_file, so discard may unlink a file this capture did not stage.

Race condition Β· crates/worldscript-secure-storage/src/journal/stream_capture.rs:142-144

@qnbs

qnbs commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

Final disposition census β€” head 56c89a81

HEAD = 56c89a817d02ba0b87a4a42c3326284910405009   3 signed commits   exact-head CI + CodeQL: success (37 pass / 2 skipped / 0 fail)
REVIEW THREADS = 3 / 3 resolved, 0 unresolved   merge state CLEAN
Codex = exact head, no major issues (πŸ‘)   CodeScene = approved (Code Health improved, gates passed)   CodeAnt = gates pass, PR Risk Low
CodeRabbit = reviewed, one finding fixed   Codecov patch = success   Sourcery / DeepSource / cubic = rate-limited or skipped: NO_SIGNAL
SIZE = 8 files, about 420 meaningful lines for the first commit (inside the normal-tier target), 3 commits
Finding Disposition
CodeRabbit (Minor), contract: the paragraph said both that a handled failure removes the staged pages and that staged files are removed only after the root commit VALID_AND_FIXED in d6f6894b β€” it now separates the cleanup of an incomplete capture (while staging) from the retention of a finished one (through promotion and commit, unless discarded); documentation only
Codex P2: begin_streamed_capture loaded the whole catalog only to take the live-migration binding from the root, which contradicts a memory-bounded capture VALID_AND_FIXED in 56c89a81 β€” it reads the committed root alone; observable: a catalog page that no longer verifies makes load_catalog fail (control) while the session still starts; mutation-checked
Codex P2: StagedCapture::discard required a journal context and so a key, which a session caller never holds VALID_AND_FIXED in 56c89a81 β€” it takes the file system only; tested with a session-staged capture and StdFs alone
CodeAnt nitpick: a file can be replaced between the digest read and the removal in discard DUPLICATE of the INVALID_WITH_EVIDENCE classification on #1010 (no unlink by handle in DurableFs; the directory is private, randomly named and never authority; stated as a limit in the evidence)

Decisions flagged on the admission and not changed by review: the session reads the manifest and binding itself (beyond the QNB-11 text); StreamedInventoryCapture changes shape; the session holds the routed key for its lifetime; staging stays lock-free.

Proof: the stage-two (a) cases pass unchanged in substance against the smaller input and now stage through a session; a session is refused with a stale token and with no bound migration; a commit after the journal moved on is refused before any write with the staged files kept; the route refuses the session with a revoked or unregistered epoch and a route to another key; a session starts with an unreadable catalog page; a finished capture is discarded with no key. Mutation-checked for the key route, the binding requirement, the committed revision and the root-only start. The whole crate suite (50 passing results), clippy -D warnings, fmt --check, docs:check.

Scope: the key-routed staging session and the smaller commit input only. No C2, reclamation, inheriting pages or graphify. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

@qnbs
qnbs merged commit d5878c1 into main Oct 8, 2026
51 checks passed
@qnbs
qnbs deleted the feat/445-gate4d-streaming-capture-session branch October 8, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant