Repository navigation
feat(core): renew the lease through the conversion session (#445) - #1014
Conversation
ConversionSession::renew_lease builds the renewal from the session's own snapshot, commits it through commit_lease_renewal with the key route and active epoch the committed root names, re-reads the committed journal and checks the admission again. A failed step keeps the snapshot and a retry adopts what was written. It is the first caller of the D3b renewal.
…445) Contract paragraph on the session's steps, evidence section with the disclosed decisions and the mutation checks, and the changelog entry.
|
@codex review |
🤖 CodeAnt AI — Review Status
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Reviewer's GuideThis PR makes Sequence diagram for conversion session lease renewalsequenceDiagram
participant Session as ConversionSession
participant Admission as ExclusiveAdmissionGuard
participant Builder as renewed_lease
participant Commit as commit_lease_renewal
participant Journal as CommittedJournal
Session->>Admission: check_admitted()
Admission-->>Session: admitted
Session->>Builder: renewed_lease(manifest, fence, expires_unix_ms)
Builder-->>Session: successor manifest
Session->>Commit: commit_lease_renewal(fs, provider, layout, checkpoint)
Commit-->>Session: committed or error
Session->>Journal: read_committed_journal(fs, provider, layout, journal)
Journal-->>Session: authenticated manifest, root_key_ref, active_key_epoch
Session->>Admission: check_admitted()
Admission-->>Session: success or NotAdmitted
Flow diagram for retry-safe lease renewalflowchart TD
A[ConversionSession::renew_lease] --> B{"check_admitted()"}
B -- no --> X[Return NotAdmitted]
B -- yes --> C["renewed_lease(manifest, fence, expires_unix_ms)"]
C -- invalid successor --> Y[Return Migration error]
C -- valid --> D[commit_lease_renewal with root route and epoch]
D -- failure --> E[Keep session snapshot]
E --> F[Retry renew_lease]
F --> C
D -- success --> G[read_committed_journal]
G --> H[Replace session snapshot]
H --> I{"check_admitted()"}
I -- no --> J[Return NotAdmitted; commit remains]
I -- yes --> K[Renewal complete]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
[check-pr-size] PR size is over the target tier (normal profile): 8 files, 1042 meaningful lines, 7 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
|
Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 39 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 67 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (3)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (6)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe conversion session now renews its journal lease through a fenced operation. It builds a successor from its snapshot, commits using the committed root’s key route and active epoch, then reads back the journal and checks admission. Tests and documentation cover renewal outcomes, retries, and remaining conversion steps. ChangesConversion Session Lease Renewal
Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Lease renewal refuses a stale key route before changing the journal. No established issue prevents merging after normal checks.
Comment |
CodeAnt PR Risk: Medium Risk
Assessed commit: |
There was a problem hiding this comment.
Actionable comments posted: 3
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
- Review profile: CHILL
- Plan: Essentials
- Run ID:
c2448705-c94d-4464-84a1-8a5e04baf151
📒 Files selected for processing (8)
CHANGELOG.mdcrates/worldscript-secure-storage/src/authority.rscrates/worldscript-secure-storage/src/conversion.rscrates/worldscript-secure-storage/src/journal/mod.rscrates/worldscript-secure-storage/src/journal/state.rscrates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rsdocs/native/R15-SECURE-STORAGE-CONTRACT.mddocs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5e79683fd4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5e79683fd4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
…445) The renewal takes the root event through the held admission and reads the committed journal back under it, installing it only if it is the renewal just committed; a failed read-back spends the session. The journal directory is pinned below the admitted installation, a differing candidate of a crashed attempt is quarantined instead of blocking the next step, and the root commit with its durability result is returned.
|
@codex review |
|
@CodeAnt-AI review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5a702eeb1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…al paths (#445) Whatever the commit reports, the journal is read back under the same root event and the root says whether the step committed: a commit error that landed is reported as Committed and followed, an unsettled one spends the session. The session canonicalises the installation, the root and the journal directory once and does every file operation through those paths, so a symlink retargeted later cannot redirect a step. The helper the read-back tests share is no longer unix-only, which broke the Windows build.
|
@codex review |
|
@CodeAnt-AI review |
CodeAnt Nitpicks1 code suggestion1.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1f35fe81dd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A journal directory inside the authority root could collide with a root slot, so the session refuses it before any read, as it refuses a directory outside the installation. The error is renamed JournalMisplaced; the evidence records the path-based residual.
|
@codex review |
|
@CodeAnt-AI review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 050ff46f26
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…n calls it (#445) The residual list still named the lease renewal as outstanding after the conversion session started calling it. The bullet is removed and the conversion bullet narrowed to entering CONVERT, the cursor and the iteration.
|
@codex review |
|
@CodeAnt-AI review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3878372e22
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ror (#445) A step whose commit reported an error that the root shows to have landed returned before the final admission check, so a lost admission went unreported. Every step that landed is now followed by the check.
|
@codex review |
|
@CodeAnt-AI review |
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 505e1f5dd9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
User description
What
C2b-1: the conversion session renews its lease. After #1013 the session could only be read and
commit_lease_renewal(D3b) still had no caller.ConversionSession::renew_lease(&mut self, fs, provider, expires_unix_ms)is the first step that moves the journal through the gate.renewed_lease(manifest, fence, expires): fence checked, next revision, expiry replaced, the renewal relation proved (assert_renewal_successor: a named lease, an expiry strictly after the held one, not terminal), manifest encodable. The expiry is the caller's; Core reads no clockread_committed_journalalso returns the root key reference and active epoch the committed root names; the step carries those, so no key, route or epoch comes from the caller and the commit cannot meetKeyRotationNotAdmittedcommit_lease_renewalunder the session's journal directory; the session re-reads the committed journal (authenticated) and replaces its snapshot; admission checked againDecisions to review (mine, flagged on the admission #359 issuecomment-6072566564): renewal alone first, the smallest slice that gives D3b a caller (entering
CONVERTand the cursor follow in C2b-2); a lost admission after a step is reported asNotAdmittedeven though the step may have committed, because a check after the commit can report but not undo it; no internal retry; the key reference and epoch come from the committed root; the tests stay in the existing conversion test file (one responsibility), to be split into a support module if CodeScene flags cohesion, as on #1010. One finding while writing the retry test: a failed root commit that leaves a pending preparation is the root's own recovery (PreparationPendinguntil recovered), not the session's, so the retry claim is tested with the anchor refusing the preparation (nothing pending) and documented as such.Boundary matrix
StaleMigrationOwner), unroutable epoch (as C2a)Not in this PR
Entering
CONVERT, moving the cursor, takeover through the session (C2b-2 and later), the cursor-driven iteration (C2c), inheriting unchanged pages, bounded adapter defaults, reclaiming pending directories, the write barrier. Real record conversion stays Gate 5. No production authority switch.Verification
Local (
gate4d_conversion_entry_test, now 16 cases): the owner renews inADMITand inCONVERT, the session equals the expected renewal (revision plus one, expiry replaced, nothing else) and a fresh gate reads the same from the root, with the original lease long past its expiry; an expiry equal to or before the held one is refused with nothing written; a session whose journal another owner took over is refused as a stale owner before any write; with the anchor refusing the root's preparation the session keeps its snapshot, the journal holds the renewal as an unadopted candidate and the retry adopts it without rewriting the generation; an installation moved away before the step is refused before any write, and one moved away right after the last read of the step is reported while the step stays committed; the builder refuses another token, a missing lease and a terminal journal. The key-route, stream-capture and root-binding suites pass unchanged. Mutation-checked: the admission check before and after the step, the snapshot refresh, the carried epoch and fence, and each of the builder's three checks, removed one at a time, fails the test that owns it (the builder's fence check survived the session tests, because the session always passes its own token, and now has a direct test).cargo clippy --locked -p worldscript-secure-storage --all-targets -D warnings,cargo fmt --check,pnpm run docs:check. Size: 8 files, 3 commits, 791 insertions and 56 deletions after the review wave (about 480 of the insertions are tests, about 90 docs).Part of #359 and #445 (Linear QNB-11).
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Review wave 1 (head 5e79683 -> f5a702e)
Twelve threads from four reviewers, five root causes, one consolidated correction (
f5a702ee), every thread replied to and resolved:Unreadable,Superseded, thenSpent).try_root_commit,RootBusy) and commits with the newcommit_lease_renewal_held.CandidateConflict::Quarantine.renew_leasereturns theRootCommitted.The snapshot-versus-final-admission-check finding (CodeRabbit) was a contradiction in the documentation, not in the behaviour: after the commit the snapshot must follow the root. Five new tests and ten mutation checks; nine are killed, one survives by design (the comparison of the read-back with the committed renewal is defence in depth under the root event). Residual, stated in the contract: path-based file operations cannot be atomic with an identity check; the checks bracket every step and fail closed.
Review wave 2 (head f5a702e -> 1f35fe8)
Two further findings and one CI failure, one consolidated correction (
1f35fe81):Committed, kept snapshot, orUnsettledand spent).Secure Store Platform Evidence (windows-latest), deterministic): a new read-back test used a helper gated#[cfg(unix)]; the helper is no longer unix-only.Review wave 3 (head 1f35fe8 -> 050ff46)
Three Codex findings: a journal directory inside the authority root can collide with a root slot (fixed:
JournalMisplaced, before any read); journal I/O through a handle instead of a path (deferred with an acceptance criterion on #359:DurableFsis path-based for every journal-owner operation and the root commit, the residual is bounded to availability and stated in the contract and evidence); quarantining versus refusing unproven candidates (INVALID_WITH_EVIDENCE:Quarantineis the existing, bytes-preserving policy of the composed journal commits, requested by wave 1).Review waves 4 and 5 (head 050ff46 -> 505e1f5)
Two narrow follow-ups: the residual list in the evidence still named the renewal as outstanding (fixed, docs only,
3878372e), and a step that landed with a commit error returned before the final admission check (fixed,505e1f5d, tested and mutation-checked). The findings are converging on the same few lines; the head is now frozen unless a new P0/P1 or security finding arrives.CodeAnt-AI Description
Let conversion sessions extend their lease while preserving committed journal state
What Changed
Impact
✅ Longer conversion runs keep their lease✅ Stale owners cannot renew after a takeover✅ Interrupted renewals can be retried safely💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.