Skip to content

feat(core): renew the lease through the conversion session (#445) - #1014

Merged
qnbs merged 7 commits into
mainfrom
feat/445-gate4d-c2b1-renew-lease
Oct 9, 2026
Merged

qnbs merged 7 commits into
mainfrom
feat/445-gate4d-c2b1-renew-lease

Conversation

@qnbs

@qnbs qnbs commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

User description

What

C2b-1: the conversion session renews its lease. After #1013 the session could only be read and commit_lease_renewal (D3b) still had no caller. ConversionSession::renew_lease(&mut self, fs, provider, expires_unix_ms) is the first step that moves the journal through the gate.

Step Rule
builder new pure renewed_lease(manifest, fence, expires): fence checked, next revision, expiry replaced, the renewal relation proved (assert_renewal_successor: a named lease, an expiry strictly after the held one, not terminal), manifest encodable. The expiry is the caller's; Core reads no clock
key route read_committed_journal also returns the root key reference and active epoch the committed root names; the step carries those, so no key, route or epoch comes from the caller and the commit cannot meet KeyRotationNotAdmitted
step admission checked; successor built from the session's own snapshot; fresh write-operation identifier; commit_lease_renewal under the session's journal directory; the session re-reads the committed journal (authenticated) and replaces its snapshot; admission checked again
failure the snapshot is kept; a retry rebuilds the identical successor and the journal adopts it if the first attempt had written it

Decisions to review (mine, flagged on the admission #359 issuecomment-6072566564): renewal alone first, the smallest slice that gives D3b a caller (entering CONVERT and the cursor follow in C2b-2); a lost admission after a step is reported as NotAdmitted even though the step may have committed, because a check after the commit can report but not undo it; no internal retry; the key reference and epoch come from the committed root; the tests stay in the existing conversion test file (one responsibility), to be split into a support module if CodeScene flags cohesion, as on #1010. One finding while writing the retry test: a failed root commit that leaves a pending preparation is the root's own recovery (PreparationPending until recovered), not the session's, so the retry claim is tested with the anchor refusing the preparation (nothing pending) and documented as such.

Boundary matrix

Mutation one renewal generation in the journal and one root commit, through the existing fenced operation; nothing before the commit
Order admission, successor built and proved against the snapshot, commit under the root lock (which repeats every authority check), authenticated re-read, admission again
Refusal admission not held (before any write), expiry not strictly forward, no lease to renew, terminal journal, stale snapshot (another owner took over: StaleMigrationOwner), unroutable epoch (as C2a)

Not in this PR

Entering CONVERT, moving the cursor, takeover through the session (C2b-2 and later), the cursor-driven iteration (C2c), inheriting unchanged pages, bounded adapter defaults, reclaiming pending directories, the write barrier. Real record conversion stays Gate 5. No production authority switch.

Verification

Local (gate4d_conversion_entry_test, now 16 cases): the owner renews in ADMIT and in CONVERT, the session equals the expected renewal (revision plus one, expiry replaced, nothing else) and a fresh gate reads the same from the root, with the original lease long past its expiry; an expiry equal to or before the held one is refused with nothing written; a session whose journal another owner took over is refused as a stale owner before any write; with the anchor refusing the root's preparation the session keeps its snapshot, the journal holds the renewal as an unadopted candidate and the retry adopts it without rewriting the generation; an installation moved away before the step is refused before any write, and one moved away right after the last read of the step is reported while the step stays committed; the builder refuses another token, a missing lease and a terminal journal. The key-route, stream-capture and root-binding suites pass unchanged. Mutation-checked: the admission check before and after the step, the snapshot refresh, the carried epoch and fence, and each of the builder's three checks, removed one at a time, fails the test that owns it (the builder's fence check survived the session tests, because the session always passes its own token, and now has a direct test). cargo clippy --locked -p worldscript-secure-storage --all-targets -D warnings, cargo fmt --check, pnpm run docs:check. Size: 8 files, 3 commits, 791 insertions and 56 deletions after the review wave (about 480 of the insertions are tests, about 90 docs).

Part of #359 and #445 (Linear QNB-11). PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Review wave 1 (head 5e79683 -> f5a702e)

Twelve threads from four reviewers, five root causes, one consolidated correction (f5a702ee), every thread replied to and resolved:

  1. The read-back was unvalidated and unlocked (CodeAnt, CodeRabbit, Codex x4): a takeover could land between the commit and the re-read and be installed as the session's snapshot. The read-back now runs under the same root event as the commit and is installed only if it is the renewal just committed; a failed or different read-back spends the session (Unreadable, Superseded, then Spent).
  2. The commit was not bound to the held admission (Codex x2): the step now takes the root event through the admission (try_root_commit, RootBusy) and commits with the new commit_lease_renewal_held.
  3. The journal directory was not pinned (Codex): pinned at begin, required strictly below the admitted installation, checked by every step. Disclosed decision: the contract does not place the journal.
  4. A differing candidate of a crashed attempt blocked every later renewal (Codex): CandidateConflict::Quarantine.
  5. The durability result was discarded (Codex): renew_lease returns the RootCommitted.

The snapshot-versus-final-admission-check finding (CodeRabbit) was a contradiction in the documentation, not in the behaviour: after the commit the snapshot must follow the root. Five new tests and ten mutation checks; nine are killed, one survives by design (the comparison of the read-back with the committed renewal is defence in depth under the root event). Residual, stated in the contract: path-based file operations cannot be atomic with an identity check; the checks bracket every step and fail closed.

Review wave 2 (head f5a702e -> 1f35fe8)

Two further findings and one CI failure, one consolidated correction (1f35fe81):

  • A commit that reports an error after it landed (Codex): the step now reads the root back under the root event whatever the commit reported and lets the root settle the outcome (Committed, kept snapshot, or Unsettled and spent).
  • A symlinked journal directory (Codex, CodeAnt): the session does every file operation through canonical paths validated at begin, so a symlink retargeted later cannot redirect a step.
  • Windows build (Secure Store Platform Evidence (windows-latest), deterministic): a new read-back test used a helper gated #[cfg(unix)]; the helper is no longer unix-only.

Review wave 3 (head 1f35fe8 -> 050ff46)

Three Codex findings: a journal directory inside the authority root can collide with a root slot (fixed: JournalMisplaced, before any read); journal I/O through a handle instead of a path (deferred with an acceptance criterion on #359: DurableFs is path-based for every journal-owner operation and the root commit, the residual is bounded to availability and stated in the contract and evidence); quarantining versus refusing unproven candidates (INVALID_WITH_EVIDENCE: Quarantine is the existing, bytes-preserving policy of the composed journal commits, requested by wave 1).

Review waves 4 and 5 (head 050ff46 -> 505e1f5)

Two narrow follow-ups: the residual list in the evidence still named the renewal as outstanding (fixed, docs only, 3878372e), and a step that landed with a commit error returned before the final admission check (fixed, 505e1f5d, tested and mutation-checked). The findings are converging on the same few lines; the head is now frozen unless a new P0/P1 or security finding arrives.


CodeAnt-AI Description

Let conversion sessions extend their lease while preserving committed journal state

What Changed

  • Owners can renew their lease during conversion, provided the new expiry is later. An expired lease can still be renewed if no other owner has taken over.
  • Renewals are refused if another owner has taken over, and invalid renewals leave the journal unchanged.
  • Interrupted renewals can be retried; sessions stop accepting steps if they cannot confirm the committed result.
  • Sessions refuse journal locations outside the installation or inside the authority root, and do not write through a replaced or redirected journal directory.

Impact

✅ Longer conversion runs keep their lease
✅ Stale owners cannot renew after a takeover
✅ Interrupted renewals can be retried safely

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

qnbs added 2 commits October 9, 2026 03:58
ConversionSession::renew_lease builds the renewal from the session's own snapshot, commits it through commit_lease_renewal with the key route and active epoch the committed root names, re-reads the committed journal and checks the admission again. A failed step keeps the snapshot and a retry adopts what was written. It is the first caller of the D3b renewal.
…445)

Contract paragraph on the session's steps, evidence section with the disclosed decisions and the mutation checks, and the changelog entry.
@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 505e1f5 Oct 09, 2026 · 03:30 03:34
✅ Reviewed your PR 3878372 Oct 09, 2026 · 03:13 03:13
✅ Incremental review completed 3878372 Oct 09, 2026 · 03:09 03:09
✅ Incremental review completed 3878372 Oct 09, 2026 · 03:08 03:23
✅ Reviewed your PR 050ff46 Oct 09, 2026 · 03:00 03:06

@sourcery-ai

sourcery-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 5 days and 8 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 9, 2026 3:30am UTC

@codeant-ai

codeant-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T03:35:26.437534Z 505e1f5 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sourcery-ai

sourcery-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR makes ConversionSession::renew_lease the first journal-mutating conversion step: it validates and builds a deterministic successor from the session snapshot, commits it through the existing fenced operation using root-authoritative key routing, re-reads the authenticated committed state, and preserves retry-safe failure semantics. It also extends committed-journal routing data, adds fault-injection and mutation-focused tests, and documents the C2b-1 contract.

Sequence diagram for conversion session lease renewal

sequenceDiagram
    participant Session as ConversionSession
    participant Admission as ExclusiveAdmissionGuard
    participant Builder as renewed_lease
    participant Commit as commit_lease_renewal
    participant Journal as CommittedJournal

    Session->>Admission: check_admitted()
    Admission-->>Session: admitted
    Session->>Builder: renewed_lease(manifest, fence, expires_unix_ms)
    Builder-->>Session: successor manifest
    Session->>Commit: commit_lease_renewal(fs, provider, layout, checkpoint)
    Commit-->>Session: committed or error
    Session->>Journal: read_committed_journal(fs, provider, layout, journal)
    Journal-->>Session: authenticated manifest, root_key_ref, active_key_epoch
    Session->>Admission: check_admitted()
    Admission-->>Session: success or NotAdmitted
Loading

Flow diagram for retry-safe lease renewal

flowchart TD
    A[ConversionSession::renew_lease] --> B{"check_admitted()"}
    B -- no --> X[Return NotAdmitted]
    B -- yes --> C["renewed_lease(manifest, fence, expires_unix_ms)"]
    C -- invalid successor --> Y[Return Migration error]
    C -- valid --> D[commit_lease_renewal with root route and epoch]
    D -- failure --> E[Keep session snapshot]
    E --> F[Retry renew_lease]
    F --> C
    D -- success --> G[read_committed_journal]
    G --> H[Replace session snapshot]
    H --> I{"check_admitted()"}
    I -- no --> J[Return NotAdmitted; commit remains]
    I -- yes --> K[Renewal complete]
Loading

File-Level Changes

Change Details Files
Added lease-renewal construction with strict successor validation.
  • Introduced renewed_lease to advance the journal revision and replace the expiry without reading a clock.
  • Validated the fence, lease ownership/forward expiry, terminal state, and manifest encoding.
  • Exported the builder and its related execution errors.
crates/worldscript-secure-storage/src/journal/state.rs
crates/worldscript-secure-storage/src/journal/mod.rs
Implemented lease renewal as a durable conversion-session step.
  • Added ConversionSession::renew_lease with admission checks before and after commit.
  • Built successors from the session snapshot, generated a fresh operation ID, and committed through commit_lease_renewal.
  • Retained the snapshot on failure and refreshed it from an authenticated committed-journal read on success or retry.
  • Carried the root-named key reference and active epoch rather than accepting routing data from callers.
crates/worldscript-secure-storage/src/conversion.rs
Extended committed-journal reads to preserve the root-authoritative route.
  • Added a committed-route structure containing the live migration, root key reference, and active key epoch.
  • Updated journal reads and streamed capture setup to use the centralized committed route.
crates/worldscript-secure-storage/src/authority.rs
Added comprehensive renewal behavior and fault-injection coverage.
  • Covered renewal in ADMIT and CONVERT, invalid expiry, stale ownership, retry adoption, builder refusals, and admission loss before or after commit.
  • Verified that committed root state, session snapshots, fences, routes, and generation writes have the expected behavior.
crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
Documented the C2b-1 renewal slice and its operational guarantees.
  • Updated the changelog, secure-storage contract, and durable-evidence documentation with the step ordering, failure semantics, route authority, and follow-up scope.
CHANGELOG.md
docs/native/R15-SECURE-STORAGE-CONTRACT.md
docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 505e1f5d
Scan Time: 2026-10-09 03:54:24 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED No IAC issues

View Full Results

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 8 files, 1042 meaningful lines, 7 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 39 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 67 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: ebbb872e-aacb-4fec-b557-d666c8a8f003
📥 Commits

Reviewing files that changed from the base of the PR and between 3878372 and 505e1f5.

📒 Files selected for processing (3)
  • crates/worldscript-secure-storage/src/conversion.rs
  • crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: bc0bdca5-db5c-458d-9bff-cc71b89ecafa
📥 Commits

Reviewing files that changed from the base of the PR and between 5e79683 and 3878372.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/conversion.rs
  • crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The conversion session now renews its journal lease through a fenced operation. It builds a successor from its snapshot, commits using the committed root’s key route and active epoch, then reads back the journal and checks admission. Tests and documentation cover renewal outcomes, retries, and remaining conversion steps.

Changes

Conversion Session Lease Renewal

Layer / File(s) Summary
Committed route and held commit
crates/worldscript-secure-storage/src/authority.rs
Committed journal reads now retain the root key reference and active key epoch alongside the live-migration binding. Renewal can commit with a caller-held root guard.
Pinned session lease renewal
crates/worldscript-secure-storage/src/journal/state.rs, crates/worldscript-secure-storage/src/journal/mod.rs, crates/worldscript-secure-storage/src/conversion.rs
The journal state builds a validated lease-renewal successor. ConversionSession::renew_lease checks the pinned journal and admission, commits using the committed route and epoch, then reads back the journal to settle the result.
Renewal tests and documentation
crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs, CHANGELOG.md, docs/native/R15-SECURE-STORAGE-CONTRACT.md, docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
Tests cover successful renewals, invalid requests, stale ownership, retries, candidate conflicts, and admission or read-back failures. Documentation describes the renewal flow and notes that entering CONVERT and advancing the cursor remain unimplemented.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 38783

Lease renewal refuses a stale key route before changing the journal. No established issue prevents merging after normal checks.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

CodeAnt PR Risk: Medium Risk

  • The PR needs attention before merging because journal and root file operations remain path-based.
  • A directory can be renamed or replaced after identity checks but before an operation, potentially misplacing journal data and requiring recovery.

Assessed commit: 505e1f5dd92a

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: c2448705-c94d-4464-84a1-8a5e04baf151
📥 Commits

Reviewing files that changed from the base of the PR and between d50dcbb and 5e79683.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/authority.rs
  • crates/worldscript-secure-storage/src/conversion.rs
  • crates/worldscript-secure-storage/src/journal/mod.rs
  • crates/worldscript-secure-storage/src/journal/state.rs
  • crates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rs
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
  • docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5e79683fd4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5e79683fd4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
@codecov

codecov Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

…445)

The renewal takes the root event through the held admission and reads the committed journal back under it, installing it only if it is the renewal just committed; a failed read-back spends the session. The journal directory is pinned below the admitted installation, a differing candidate of a crashed attempt is quarantined instead of blocking the next step, and the root commit with its durability result is returned.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codeant-ai codeant-ai Bot added size:XL This PR changes 500-999 lines, ignoring generated files and removed size:L This PR changes 100-499 lines, ignoring generated files labels Oct 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5a702eeb1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs
Comment thread crates/worldscript-secure-storage/src/conversion.rs
…al paths (#445)

Whatever the commit reports, the journal is read back under the same root event and the root says whether the step committed: a commit error that landed is reported as Committed and followed, an unsettled one spends the session. The session canonicalises the installation, the root and the journal directory once and does every file operation through those paths, so a symlink retargeted later cannot redirect a step. The helper the read-back tests share is no longer unix-only, which broke the Windows build.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codeant-ai

codeant-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

CodeAnt Nitpicks

1 code suggestion

1. check_admitted runs before path-based journal I/O, so a concurrent rename can redirect publication into a replacement directory and commit a root binding there.

Race condition · crates/worldscript-secure-storage/src/conversion.rs:299-302

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1f35fe81dd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/conversion.rs
Comment thread crates/worldscript-secure-storage/src/conversion.rs Outdated
Comment thread crates/worldscript-secure-storage/src/conversion.rs
A journal directory inside the authority root could collide with a root slot, so the session refuses it before any read, as it refuses a directory outside the installation. The error is renamed JournalMisplaced; the evidence records the path-based residual.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 050ff46f26

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md Outdated
…n calls it (#445)

The residual list still named the lease renewal as outstanding after the conversion session started calling it. The bullet is removed and the conversion bullet narrowed to entering CONVERT, the cursor and the iteration.
@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

codescene-access[bot]

This comment was marked as outdated.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3878372e22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/conversion.rs
…ror (#445)

A step whose commit reported an error that the root shows to have landed returned before the final admission check, so a lost admission went unreported. Every step that landed is now followed by the check.
@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@qnbs

qnbs commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

@CodeAnt-AI review

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 505e1f5dd9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/conversion.rs

This branch was successfully deployed

1 active deployment
Preview — 505e1f5d Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL This PR changes 500-999 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant