Repository navigation
feat(core): enter CONVERT and move the cursor through the conversion session (#445) - #1015
Conversation
…session (#445) enter_convert (idempotent) and advance_cursor (forward only, inside the inventory, in CONVERT only) share one private step with renew_lease, which commits through commit_lease_renewal_held or the new commit_journal_checkpoint_held; every outcome after a landed commit is followed by the admission check.
…sion session (#445) Contract paragraph on the three steps and the uniform finalisation rule, evidence section with the disclosed decisions and the mutation checks, narrowed residual list and the changelog entry.
|
@codex review |
🤖 CodeAnt AI — Review Status
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Reviewer's GuideThis PR implements C2b-2 by adding idempotent entry into Sequence diagram for conversion session checkpointssequenceDiagram
participant Caller
participant Session as ConversionSession
participant Admission
participant Root as RootCommitGuard
participant Authority
participant Journal
Caller->>Session: enter_convert() or advance_cursor(cursor)
Session->>Session: ready()
Session->>Admission: check_admitted()
Admission-->>Session: admission held
Session->>Session: transition_phase() or checkpoint_progress()
Session->>Root: root_guard()
Root-->>Session: held root event
Session->>Authority: commit_journal_checkpoint_held()
Authority->>Journal: commit successor
Authority-->>Session: commit result
Session->>Journal: read_committed_journal()
Journal-->>Session: committed journal
Session->>Session: settle()
Session->>Admission: check_admitted()
Admission-->>Session: admission status
Session-->>Caller: RootCommitted or ConversionError
Flow diagram for conversion entry and cursor validationflowchart TD
A[ConversionSession step] --> B{Session spent?}
B -- Yes --> C[Spent]
B -- No --> D{Admission valid?}
D -- No --> E[NotAdmitted]
D -- Yes --> F{Operation}
F -- enter_convert --> G{Phase already CONVERT?}
G -- Yes --> H[Return None; no write]
G -- No --> I[transition_phase to CONVERT]
F -- advance_cursor --> J{Phase is CONVERT?}
J -- No --> K[WrongPhase]
J -- Yes --> L[checkpoint_progress]
L --> M{Cursor valid and non-regressive?}
M -- No --> N[Refuse before write]
M -- Yes --> O[Build successor]
I --> O
O --> P[Commit held journal operation]
P --> Q[Read back committed journal]
Q --> R[Settle outcome]
R --> S{Admission still valid?}
S -- No --> T[NotAdmitted first]
S -- Yes --> U[Return commit or settled error]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
[check-pr-size] PR size is over the target tier (normal profile): 6 files, 519 meaningful lines, 3 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
|
Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 43 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 67 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (4)
📝 WalkthroughWalkthroughConversion sessions now support entry into CONVERT and constrained checkpoint cursor advancement. Lease renewal and checkpoint commits use a shared step routine that reads back the journal and checks admission after commit outcomes, except for a refusal known to have written nothing. ChangesConversion Session Progression
Priority: ⬇️ Low Merge Risk: 🔵 Low · up to A failed checkpoint can report a commit error instead of lost admission. This narrow case should be corrected or explicitly accepted before merging.
Comment |
CodeAnt NitpicksNo threshold-suppressed suggestions found in the latest review. |
CodeAnt PR Risk: Low Risk
Assessed commit: |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
- Review profile: CHILL
- Plan: Essentials
- Run ID:
2fc25db2-7f97-425f-b493-bbac65cff659
📒 Files selected for processing (6)
CHANGELOG.mdcrates/worldscript-secure-storage/src/authority.rscrates/worldscript-secure-storage/src/conversion.rscrates/worldscript-secure-storage/tests/gate4d_conversion_entry_test.rsdocs/native/R15-SECURE-STORAGE-CONTRACT.mddocs/native/r15/GATE4D-JOURNAL-DURABLE-EVIDENCE.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5643d18fc7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
… every commit outcome (#445) A session already in CONVERT now confirms against the committed root that its snapshot is still the journal before it reports that there is nothing to enter, and the admission check follows every outcome of the commit call, a refusal that left a candidate included. The cursor is documented as checked against the manifest's extent only.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
@CodeAnt-AI review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
|
Reviewer state on the final head 8e102ba, recorded before the merge: Codex answered the last two |
|
You have reached your Codex usage limits. You can see your limits in the Codex usage dashboard. |
User description
What
C2b-2: the conversion session enters
CONVERTand moves the checkpoint cursor. After #1014 the session had one step (renew_lease) written as one method. The other two steps differ from it only in the pure successor builder (transition_phase,checkpoint_progress, both already proved) and in the journal-owner operation that commits it, so the three now share one private step and one finalisation rule.Quarantine, the commit returned: all as in #1014StepKind::Renewal->commit_lease_renewal_held;StepKind::Checkpoint-> the newcommit_journal_checkpoint_held(the body ofcommit_journal_checkpointunder a root event the caller holds; the public function acquires the lock and delegates, ascommit_lease_renewaldoes)enter_converttransition_phasetoCONVERT: cursor(0, 0), revision plus one, fence kept. A session already inCONVERTwrites nothing and returnsNone; a spent session isSpentbefore that answeradvance_cursorCONVERTonly (WrongPhase), thencheckpoint_progress: never backwards, inside the extent, an equal cursor accepted; all refused before any writeAuthority(a refusal that certainly wrote nothing) is followed by the admission check,NotAdmittedfirst. This closes the criterion recorded from the #1014 review (#359 issuecomment-6073926777)Decisions to review (mine, flagged on the admission, #359 issuecomment-6074467323): one private step shared by three public methods;
enter_convertidempotent so a resumed session can call it unconditionally; the cursor moves inCONVERTonly, and an equal cursor is a valid checkpoint ascheckpoint_progressdefines it; the admission check also followsUnsettled(whether it landed is unknown and the session is spent either way); a new_heldfunction rather than a flag.Boundary matrix
Not in this PR
The cursor-driven iteration with a per-entry step and the crash/resume evidence (C2c),
CONVERT->VERIFY, takeover through the session, handle-relative adapter I/O (criterion on #359), inheriting unchanged pages, bounded adapter defaults, reclaiming pending directories, the write barrier. Real record conversion stays Gate 5. No production authority switch.Verification
Local (
gate4d_conversion_entry_test, now 33 cases):ADMIT->CONVERTmoves the phase and the revision only, the session and a fresh gate agree and the root is one generation further; a second call and a resumed session inCONVERTwrite nothing; three forward checkpoints (one at the same cursor) are accepted and a regressive cursor, a page past the extent and an entry past the extent are refused with nothing written; the cursor inADMITisWrongPhase; a session another owner took over from is refused before any write; the lease is renewed after enteringCONVERT; with the installation moved away at the moment the read-back fails, the admission loss is reported first both after a successful commit and after a commit that reported an error; a spent session inCONVERTdoes not claim it has nothing to enter. The key-route, stream-capture and root-binding suites pass unchanged. Mutation-checked: the idempotence, the spent check of the no-op, the phase check of the cursor, the commit dispatch and each of the two finalisation rules, removed one at a time, fail the test that owns them.cargo clippy --locked -p worldscript-secure-storage --all-targets -D warnings,cargo fmt --check,pnpm run docs:check. Checked against the #1014 review checklist before the first push (outcome matrix, Windows portability of every helper, residual lists). Size: 6 files, about 400 meaningful lines, 2 commits.Part of #359 and #445 (Linear QNB-11).
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Review wave 1 (head 5643d18 -> 8e102ba)
Three threads, one consolidated correction (
8e102ba1), every thread replied to and resolved:enter_converton an overtaken snapshot (Codex P2): the no-op confirms against the committed root and isSuperseded(spent) after a takeover (fixed, tested, mutation-checked).checkpoint_progress(D3a) checks the manifest's extent only, the contract does not say whether the entry index is page-local, and the pages are read only by the iteration (VALID_AND_DEFERRED_WITH_ACCEPTANCE_CRITERIONon Desktop fs-data key-rotation migration is not crash-resumable (mixed-key state possible) #359, to C2c; the limit is documented onadvance_cursor, in the contract and in the evidence).CodeAnt-AI Description
Enter conversion and track checkpoint progress
What Changed
CONVERTfromADMITwith the cursor at the start. A resumed session confirms its journal is still current and makes no duplicate write.CONVERT, without moving backwards or exceeding the inventory’s page-count and total-entry limits. Repeating the current cursor is allowed.Impact
✅ No duplicate writes when resuming CONVERT✅ Rejected backward or out-of-range progress✅ Admission loss reported first after write attempts💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.