Skip to content

feat(core): gate the conversion driver on exclusive admission (#445) - #1013

Merged
qnbs merged 3 commits into
mainfrom
feat/445-gate4d-c2a-conversion-entry
Oct 9, 2026
Merged

qnbs merged 3 commits into
mainfrom
feat/445-gate4d-c2a-conversion-entry

Conversation

@qnbs

@qnbs qnbs commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

User description

What

The entry gate of the exclusive conversion driver (C2, first of three slices). Maintainer decision D: conversion must require exclusive admission by construction, re-read the authenticated root-bound manifest, and require final_inventory_captured = true. Until now the journal-owner operations took no admission guard, and nothing could read the committed journal state without a key in the caller's hands.

Step Rule
input &mut ExclusiveAdmissionGuard (a shared guard does not type-check: compile_fail doctest, with a positive twin proving it fails for that reason) and ConversionBegin{scope, journal, owner_id}; the root layout is derived from scope, so the root cannot differ from the one admitted
admission guards(scope) is checked before anything is read and again after the reads
read new read_committed_journal: binding from the committed root alone (NoLiveMigration if none), key through the key-epoch registry (JournalRoute errors), manifest by the exact root-named path authenticated against the binding digest; no sibling generation is read. begin_streamed_capture shares the binding read
gate phase ADMIT or CONVERT (TerminalPhase, RecoveryRequired, PhaseNotConvertible otherwise), final_inventory_captured (FinalInventoryNotCaptured), committed lease owner equal to the caller (ForeignLeaseOwner; an absent lease is foreign)
result a ConversionSession that keeps the &mut borrow (one session per admission) and exposes the manifest, binding and fence it read; no key held

Decisions to review (mine, flagged on the admission): three slices for the driver, this one mutating nothing so that the exclusivity proof lands before any conversion write; the layout is derived from the admitted scope; a foreign lease owner is refused rather than taken over, and whether exclusive admission may replace lease expiry as the proof that a former owner is gone is left open for the maintainer (the cross-process lease CAS stays residual); no clock is read. One correction to the admission text: it listed "operation mismatch" as a refusal, but the journal source's operation is a write-operation identifier for staging names, not the migration operation; the manifest is opened under the binding's operation identity, so that case is already covered by the authenticated load and is not a separate refusal.

Boundary matrix

Mutation none: no write, no lock, no key held; the tree is byte-identical after a begin or a refusal
Order admission identity, root binding, routed key, root-named manifest, admission identity again, then the phase, final-inventory and owner checks
Refusal guard for another installation (before any read), installation moved during the reads, no bound migration, unroutable epoch, route to another key, root-named bytes the binding does not name, other phase, final inventory not captured, other or no lease owner

Not in this PR

Entering CONVERT, advancing the cursor and renewing the lease through the gate (C2b), the cursor-driven iteration with a per-entry step and the crash/resume evidence (C2c), inheriting unchanged pages, bounded adapter defaults, reclaiming pending directories, the write barrier. Real record conversion stays Gate 5. No production authority switch.

Verification

Local: gate4d_conversion_entry_test (the owner in ADMIT and CONVERT gets the committed manifest, fence and binding with every file unchanged; every other phase refused with its own reason; no final inventory; lease of another owner, of the empty owner and of none; no binding; a root-named generation that is not the bound bytes; a guard for another installation refused with zero reads; an installation moved away during the reads refused; a newer sibling generation never read), the gate as a further operation in the key-route refusal table (revoked, unregistered, route to another key), and the root-binding, streaming-capture and route suites unchanged. Mutation-checked: each of the two admission checks (separately), each phase arm, the final-inventory requirement and the owner check, removed one at a time, fails the test that owns it. cargo clippy --locked -p worldscript-secure-storage --all-targets -D warnings, cargo fmt --check, pnpm run docs:check. Size: 9 files (one over the target of 8) and about 770 meaningful lines (over the 400 target, inside the hard tier): about 200 of them code and about 570 tests, of which about 240 are the compact root-bound fixture and the read-watching file system the two admission checks need; 2 commits.

Part of #359 and #445 (Linear QNB-11). Admission: #359 issuecomment-6071546090. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Summary by Sourcery

Require exclusive admission and authenticated committed journal state before allowing conversion to begin.

New Features:

  • Gate conversion entry behind a mutable exclusive admission guard and return a session only when the committed migration is convertible, complete, and owned by the caller.
  • Add committed journal reading from the authenticated root, registry-routed key, and exact root-named manifest without requiring callers to hold a key.

Bug Fixes:

  • Prevent conversion from starting for installations that are not admitted, change during reads, have untrusted or missing journal state, lack final inventory capture, or have a foreign or absent lease owner.

Enhancements:

  • Reuse committed-root binding resolution for streamed capture and expose the conversion session's authenticated manifest, binding, fence, and admission status.

Documentation:

  • Document the conversion entry gate contract, refusal conditions, security decisions, and remaining conversion-driver work.

Tests:

  • Add integration coverage for valid and refused conversion starts, mutation-free behavior, admission races, authenticated journal routing, and sibling-generation handling.

Chores:

  • Record the new conversion entry gate in the unreleased changelog and gap matrix.

Summary by cubic

Gates the conversion driver's entry behind exclusive admission and authenticated committed journal state, so conversion cannot begin against an installation that is not admitted or whose journal is not what the committed root vouches for.

Previously the journal-owner operations took no admission guard, and nothing read committed journal state without a key in hand. begin_conversion now takes &mut ExclusiveAdmissionGuard, derives the root layout from the admitted scope, checks admission before and after the reads, and re-reads the binding, the registry-routed key, and the root-named manifest. It returns a ConversionSession only when the operation is in ADMIT or CONVERT, the final inventory was captured, and the committed lease belongs to the caller. The gate writes nothing, holds no key, and reads no clock; begin_streamed_capture now shares the committed-root binding read.

Refusals

  • Guard for another installation (before any read) or installation moved during the reads
  • No bound migration, unroutable epoch, route to another key, or root-named bytes the binding does not name
  • Terminal phase, recovery required, or other phase; final inventory not captured; lease owned by another owner or by none

Written for commit 636dda8. Summary will update on new commits.

View guided diff Turn on auto-fix

Summary by CodeRabbit

  • New Features
    • Added a read-only conversion entry gate that verifies installation access, committed journal state, conversion phase, completed inventory capture, and lease ownership before allowing a conversion session.
  • Bug Fixes
    • Conversion entry now refuses mismatched or unbound journal generations, invalid key routes, changed installations, and leases owned by someone else.
  • Documentation
    • Updated the secure storage contract and Gate 4D documentation with conversion entry requirements and remaining work.

CodeAnt-AI Description

Require exclusive access and a ready journal before migration conversion

What Changed

  • Conversion can start only while exclusive access is held for the same installation; access is checked before and after reading the journal.
  • The gate uses the committed journal and allows only a new or resumed conversion with a captured final inventory and a lease owned by the caller. It rejects finished, recovery-required, incomplete, or foreign-owned states.
  • The gate ignores uncommitted sibling journal files and makes no changes; moving the journal remains a later step.

Impact

✅ Blocks conversion while other operations are active
✅ Rejects conversion without a captured inventory or matching lease owner
✅ Prevents sibling journal files from overriding committed conversion state

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

qnbs added 2 commits October 9, 2026 02:24
begin_conversion takes the installation's exclusive admission by mutable borrow, derives the root layout from the admitted scope, re-reads the committed binding, the registry-routed journal key and the root-named manifest, and returns a ConversionSession only for the owner of the lease while the operation is in ADMIT or CONVERT with the final inventory captured. It reads no clock, holds no key and writes nothing.
Contract paragraph, evidence section with the disclosed decisions and the mutation checks, gap-matrix line and changelog entry for the entry gate of the exclusive conversion driver.
@sourcery-ai

sourcery-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 11 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 636dda8 Oct 09, 2026 · 00:46 00:50
✅ Reviewed your PR 1683433 Oct 09, 2026 · 00:28 00:31

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 9, 2026 12:39am UTC

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai

codeant-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T00:42:22.379353Z 636dda8 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sourcery-ai

sourcery-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR implements the mutation-free C2a conversion entry gate: exclusive admission is enforced by the type and lifetime of the API, committed journal authority is reread from the authenticated root and key registry, and conversion begins only for an eligible phase, captured inventory, and matching lease owner, with extensive refusal and integrity coverage.

Sequence diagram for the exclusive conversion entry gate

sequenceDiagram
    participant Caller
    participant Gate as begin_conversion
    participant Admission as ExclusiveAdmissionGuard
    participant Authority as read_committed_journal
    participant Root as CommittedRoot
    participant Registry as KeyEpochRegistry
    participant Journal as JournalManifest

    Caller->>Gate: begin_conversion(&mut guard, fs, provider, begin)
    Gate->>Admission: guards(scope)
    alt NotAdmitted
        Admission-->>Gate: false
        Gate-->>Caller: ConversionError::NotAdmitted
    else Admitted
        Admission-->>Gate: true
        Gate->>Authority: read_committed_journal(root(scope), journal)
        Authority->>Root: load_committed_root
        Root-->>Authority: LiveMigration binding
        Authority->>Registry: route_journal_key
        Registry-->>Authority: journal key or JournalRoute error
        Authority->>Journal: load_authoritative_manifest(exact root-named path)
        Journal-->>Authority: authenticated manifest
        Authority-->>Gate: CommittedJournal
        Gate->>Admission: guards(scope)
        alt Admission changed
            Admission-->>Gate: false
            Gate-->>Caller: ConversionError::NotAdmitted
        else Still admitted
            Gate->>Gate: check_convertible(manifest, owner_id)
            alt Eligible phase, final inventory captured, matching owner
                Gate-->>Caller: ConversionSession holding &mut guard
            else Refusal
                Gate-->>Caller: phase, inventory, or lease-owner error
            end
        end
    end
Loading

Flow diagram for conversion entry refusal checks

flowchart TD
    A[begin_conversion] --> B{"guards(scope) before reads?"}
    B -- No --> X[NotAdmitted]
    B -- Yes --> C[Read committed root binding]
    C --> D[Route journal key through key registry]
    D --> E[Load exact root-named authenticated manifest]
    E --> F{"guards(scope) after reads?"}
    F -- No --> X
    F -- Yes --> G{"Phase is ADMIT or CONVERT?"}
    G -- DONE --> H[TerminalPhase]
    G -- RECOVERY_REQUIRED --> I[RecoveryRequired]
    G -- Other --> J[PhaseNotConvertible]
    G -- Yes --> K{"final_inventory_captured?"}
    K -- No --> L[FinalInventoryNotCaptured]
    K -- Yes --> M{"Lease owner equals owner_id?"}
    M -- No --> N[ForeignLeaseOwner]
    M -- Yes --> O[ConversionSession]
Loading

File-Level Changes

Change Details Files
Add an exclusive-admission conversion entry gate that revalidates installation identity and returns a borrow-held session only for authorized journal state.
  • Require a mutable ExclusiveAdmissionGuard, derive the root layout from its admitted scope, and verify admission before and after reads.
  • Read the committed binding, registry-routed journal key, and exact root-named authenticated manifest without exposing a key to callers.
  • Accept only ADMIT or CONVERT with final inventory captured and a lease owned by the caller; distinguish terminal, recovery, phase, inventory, ownership, and authority failures.
  • Return a ConversionSession exposing the committed manifest, binding, fence, and admission status while performing no writes, locking, clock reads, or key retention.
  • Add a compile-fail shared-guard API proof and comprehensive integration tests for refusal ordering, tampering, routing, sibling generations, admission changes, and mutation freedom.
crates/worldscript-secure-storage/src/conversion.rs
crates/worldscript-secure-storage/src/authority.rs
crates/worldscript-secure-storage/src/lib.rs
crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs
Document the new Gate 4D C2a contract and record it in the release changelog and gap/evidence matrices.
  • Describe the admission, authenticated reread, gate predicates, refusal behavior, and no-mutation guarantees.
  • Clarify that journal movement, cursor iteration, lease renewal, and record conversion remain follow-up slices.
CHANGELOG.md
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 636dda85
Scan Time: 2026-10-09 00:51:19 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED No IAC issues

View Full Results

codescene-access[bot]

This comment was marked as outdated.

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 9 files, 859 meaningful lines, 3 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 49 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 67 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 57449113-788d-4b72-9390-a49b5985add3
📥 Commits

Reviewing files that changed from the base of the PR and between 1683433 and 636dda8.

📒 Files selected for processing (2)
  • crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
  • crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 94dc13c3-99f0-45f5-86e7-587086c3cfb0
📥 Commits

Reviewing files that changed from the base of the PR and between d5878c1 and 1683433.

📒 Files selected for processing (9)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/conversion.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
  • crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
  • docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

Adds a read-only conversion entry gate. It checks exclusive installation admission and committed journal state, then admits only eligible phases with captured final inventory and a matching lease owner.

Changes

Conversion Entry Gate

Layer / File(s) Summary
Read committed journal state
crates/worldscript-secure-storage/src/authority.rs
Adds shared helpers for reading the committed live-migration binding and its root-named, registry-routed manifest. begin_streamed_capture uses the binding helper.
Validate and expose conversion entry
crates/worldscript-secure-storage/src/conversion.rs, crates/worldscript-secure-storage/src/lib.rs
Adds begin_conversion, its request and error types, and a session that retains the exclusive guard borrow. The gate checks admission before and after its reads, then validates phase, final inventory capture, and lease ownership. The crate root exports the conversion API.
Verify gate behavior and document conditions
crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs, crates/worldscript-secure-storage/tests/gate4d_journal_route_test.rs, docs/native/R15-SECURE-STORAGE-CONTRACT.md, docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md, docs/native/r15/GATE4D-SLICE-B-GAP-MATRIX.md, CHANGELOG.md
Tests cover accepted and rejected states, admission identity, root-bound journal selection, and journal-key routing. Documentation and the changelog describe the gate conditions and read-only behavior.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 16834

The read-only conversion entry gate is mergeable after normal checks; no actionable merge-blocking risk remains.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

CodeAnt PR Risk: Medium Risk

  • The PR needs attention before merging because the gate accepts an expired lease, while whether exclusive admission proves the former owner is gone remains unresolved.
  • This change only opens a read-only conversion session; journal movement, cursor advancement and crash-resume behavior are not included.

Assessed commit: 636dda85cb6c

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1683433016

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…ts (#445)

Windows creates operation-admission.lock when an admission is acquired, so a baseline taken before the acquire differed from the tree after it even though the gate wrote nothing. The snapshot helpers of the conversion entry test and the key-route test skip that file, whose bytes have no authority.
@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: 636dda85cb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

CodeAnt PR Risk "Medium" on 636dda8: classified INVALID_WITH_EVIDENCE as a defect, and recorded as the open question the PR body already flags. (1) Accepting a lease past its expiry is the contract merged in D3b (contract §10.1, "The renewal operation": no clock is read, the owner may still act after expiry while nobody has taken over, because a takeover advances the fence and the root lock serialises the two); the gate does not change that, it re-reads the committed manifest and refuses a foreign owner, so an owner that was taken over is refused. (2) The gate is read-only: it writes nothing, holds no key and cannot move the journal; every later mutation (C2b) goes through the fenced journal-owner operations that refuse a stale token before any write. (3) The unresolved part, whether exclusive admission may replace lease expiry as the proof that a former owner is gone (a takeover question, not a gate question), is a maintainer decision recorded as an acceptance criterion on #359 and is deliberately not decided here. No code change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL This PR changes 500-999 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant