Skip to content

feat(core): add the Gate 3 slice 3B record-commit marker codec (#445) - #937

Merged
qnbs merged 5 commits into
mainfrom
feat/445-gate3b-commit-reconciliation
Oct 1, 2026
Merged

qnbs merged 5 commits into
mainfrom
feat/445-gate3b-commit-reconciliation

Conversation

@qnbs

@qnbs qnbs commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

User description

Part of #445 / #921 (Gate 3, slice 3B, part 1). No production authority switch: PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.

Scope

Slice 3B is split at its proof boundary:

  • 3B part 1 (this PR): the record-commit marker codec, which is pure, headless and vector-proven.
  • 3B part 2 (next PR): the commit write protocol (PENDING → stage/promote → ACTIVE), startup reconciliation, and orphan/superseded staging classification. It builds on this codec and on slice 3A's stage_and_promote.

What lands (crates/worldscript-secure-storage/src/marker.rs)

  • content_digest (§5.4): SHA-256 over worldscript-r15/content/v1 and the complete WSR1 envelope.
  • CommitMarker and its canonical body bytes (§5.4):
    • the header is the class token, the §6.2-tagged logical/project bindings, marker_generation and state_code, followed by the state body;
    • the bindings are reused from canonical AAD through a new crate-internal tagged_identity_bindings, so rule D's direct/hashed choice has one implementation.
  • marker_entry_digest, the value slice 3C's root marker_set_digest will bind.
  • Admitted states: ACTIVE, PENDING, RECOVERY_REQUIRED.
    • DELETE_PENDING, TOMBSTONED (§8.5) and READ_AUTHORITY_PENDING (migration) keep their reserved codes but are refused until their gates admit them.
    • is_chunked = 1 is also refused, because the chunked envelope is not implemented.
  • Strict decoding:
    • the identity must equal the requested record's marker;
    • flags must be exactly 0 or 1, and no trailing bytes are allowed;
    • counters follow the §5.4 lifecycle (never 0 or u64::MAX);
    • a pending target must be exactly the next generation (1 for a first write, otherwise old + 1);
    • operation_id must be 1–128 bytes;
    • the record schema must be admitted.
  • Sealing: each marker generation is sealed as its own record-commit record with envelope record_generation = marker_generation. Opening refuses a body whose generation differs from its envelope's, which prevents replay under another generation's name.

Proof

tests/gate3b_marker_test.rs (17 tests):

  • vectors assembled byte by byte from the contract text;
  • the marker_entry_digest vector pinned from an independent Python hashlib computation;
  • every truncation and trailing bytes;
  • non-canonical flags, chunked bodies and digestless ACTIVE bodies;
  • reserved and unknown states;
  • identity mismatch;
  • counter lifecycle, target ordering, operation-id bounds and schema admission;
  • rule-D hashed bindings;
  • seal/open identity binding and generation-replay refusal;
  • Debug redaction.

Local runs: cargo clippy --all-targets -D warnings is clean, the full crate suite passes, and pnpm docs:check (including the R-15 gate status guard) passes.

Docs

  • Contract §20 has a new slice 3B part 1 entry, and both status-split sentences are extended.
  • Ledger row 10 is updated.
  • The canonical R15_GATE3 token is now SLICE_3B_MARKER_CODEC in the status block and ledger row 10.

Summary by Sourcery

Implement the headless Gate 3 slice 3B record-commit marker codec without changing production storage authority.

New Features:

  • Add a headless protected-storage codec for creating, encoding, decoding, hashing, sealing, and opening record-commit markers for admitted ACTIVE, PENDING, and RECOVERY_REQUIRED states.

Bug Fixes:

  • Reject malformed, unsupported, identity-mismatched, invalid-generation, chunked, and replayed commit markers.

Enhancements:

  • Share canonical identity binding logic between AAD and marker encoding while enforcing strict lifecycle, schema, operation, and generation validation.

Documentation:

  • Document the slice 3B marker codec and update R-15 Gate 3 status to SLICE_3B_MARKER_CODEC while retaining the prohibition on production authority switching.

Tests:

  • Add contract-based byte vectors and adversarial coverage for marker encoding, decoding, digests, sealing, identity binding, validation, replay protection, and debug redaction.

Chores:

  • Record the marker codec in the unreleased changelog.

Summary by cubic

Adds the Gate 3 slice 3B part 1 record-commit marker codec to the headless worldscript-secure-storage crate: canonical body encoding, strict decoding, and generation-bound sealing of one record's commit marker, vector-proven against the contract. It decides no authority and PRODUCTION_AUTHORITY_SWITCH_ALLOWED stays NO; the commit write protocol and startup reconciliation are a later slice 3B part 2.

What lands

  • content_digest is SHA-256 over the domain and the complete WSR1 envelope; marker_entry_digest is the value slice 3C's root marker_set_digest will bind.
  • Marker identity bindings reuse canonical AAD through a new shared tagged_identity_bindings (pulled out of aad.rs), so rule D's direct/hashed choice has one implementation.
  • Admits ACTIVE, PENDING, and RECOVERY_REQUIRED; DELETE_PENDING, TOMBSTONED, READ_AUTHORITY_PENDING, and chunked bodies keep reserved codes but are refused.
  • Decoding is strict: identity match, flags exactly 0/1, no trailing bytes, lifecycle-safe counters, a pending target exactly the next generation (1 for a first write, otherwise old + 1), operation_id 1–128 bytes, an admitted record schema, and an ordinary-write fence of 0 (journal-owned positive fences refused). A well-formed foreign record-commit header is an identity mismatch; truncated or malformed headers are corruption.
  • Each marker generation seals as its own record-commit record whose envelope generation must equal the body's — opening refuses a mismatch, blocking replay under another generation's name.
  • 17 tests pin the contract's state codes, operation-id bound, fence rule, and both digest vectors to an independent Python computation; clippy, the crate suite, and docs:check pass, and contract §20 and ledger row 10 are updated (R15_GATE3=SLICE_3B_MARKER_CODEC).

Written for commit 525bad8. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Added support for encoding, validating, and sealing protected-storage markers that identify a record’s committed version and track pending or recovery-required states.
    • Marker data is checked for valid identity, generation, and supported record format. User data is not yet read or written through this codec; commit writing and startup recovery remain forthcoming.
  • Documentation
    • Updated secure-storage contract and migration notes to reflect the marker codec’s implementation status.

CodeAnt-AI Description

Add a strict record-commit marker codec for protected storage

What Changed

  • Adds encoding, decoding, hashing, sealing, and opening for ACTIVE, PENDING, and RECOVERY_REQUIRED record markers.
  • Rejects malformed, truncated, replayed, cross-record, unsupported, chunked, fenced, and invalid-generation markers instead of accepting them.
  • Enforces exact generation transitions, valid operation IDs and schemas, lifecycle counters, and identity bindings shared with canonical storage authentication.
  • Adds independent byte-level vectors and coverage for valid markers, rejection cases, digest calculation, sealing, replay protection, and operation-ID redaction.
  • Documents Gate 3 slice 3B part 1 as headless only; production storage authority, commit writes, and startup reconciliation remain unchanged.

Impact

✅ Strict marker validation
✅ Replay-resistant record generations
✅ Contract-pinned storage compatibility

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Defines the single-record commit marker exactly as contract §5.4 specifies: content_digest,
canonical_marker_body_bytes (sharing canonical AAD's tagged identity bindings), marker_entry_digest,
strict decoding, and sealing each marker generation as its own record-commit record. ACTIVE,
PENDING and RECOVERY_REQUIRED are admitted; deletion, migration and chunked states stay refused.
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 1, 2026 4:25pm UTC

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 10 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 80 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: b1e94c83-d1d8-4480-b7c7-7890445922ef

📥 Commits

Reviewing files that changed from the base of the PR and between e185e4b and 525bad8.

📒 Files selected for processing (7)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/aad.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/marker.rs
  • crates/worldscript-secure-storage/tests/gate3b_marker_test.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md
📝 Walkthrough

Walkthrough

The pull request adds a public codec for version-1 ordinary-record commit markers. It supports canonical encoding, strict decoding, digest calculation, and sealing and opening protected records. Tests and contract documents describe supported states, validation rules, and work that remains outside this slice.

Changes

Record-commit marker codec

Layer / File(s) Summary
Identity bindings and marker codec
crates/worldscript-secure-storage/src/aad.rs, crates/worldscript-secure-storage/src/marker.rs, crates/worldscript-secure-storage/src/lib.rs
The codec uses shared tagged identity bindings and exposes marker types and APIs. It encodes and validates marker bodies, computes digests, and seals and opens protected records with generation checks.
Codec validation and contract
crates/worldscript-secure-storage/tests/*, docs/native/R15-SECURE-STORAGE-CONTRACT.md, docs/native/CORE-MIGRATION-LEDGER.md, CHANGELOG.md
Integration tests cover byte encodings, digest domains, validation failures, identity bindings, and sealing. The contract, ledger, and changelog identify the implemented codec and note that the commit-write protocol and startup recovery remain unfinished.

Priority: ⬇️ Low

Merge Risk: 🔵 Low · up to e185e

The new commit-marker codec accepts pending generation numbers that skip values the storage contract forbids. It does not read or write user data yet, so current impact is limited. Tighten this validation and fix the small documentation typo before the commit protocol builds on the codec.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Reviewer's Guide

Adds and proves a generation-bound, strictly decoded record-commit marker codec that reuses canonical identity bindings, while updating R-15 documentation to reflect the headless Gate 3 slice 3B part 1 implementation; no commit protocol or production authority switch is included.

Sequence diagram for generation-bound record-commit marker sealing

sequenceDiagram
    participant Caller
    participant CommitMarker
    participant RecordCodec
    participant Envelope

    Caller->>CommitMarker: CommitMarker::new(record, marker_generation, body)
    CommitMarker->>CommitMarker: encode()
    CommitMarker->>RecordCodec: seal_record(key, identity, metadata, body)
    RecordCodec->>Envelope: record_generation = marker_generation
    Envelope-->>Caller: sealed record-commit envelope

    Caller->>CommitMarker: CommitMarker::open(key, record, envelope)
    CommitMarker->>RecordCodec: open_record(key, marker_identity, envelope)
    RecordCodec-->>CommitMarker: payload and envelope metadata
    CommitMarker->>CommitMarker: decode(record, payload)
    alt envelope generation matches marker_generation
        CommitMarker-->>Caller: CommitMarker
    else generation mismatch
        CommitMarker-->>Caller: GenerationMismatch
    end
Loading

Flow diagram for strict marker decoding and validation

flowchart TD
    A["CommitMarker::decode(record, bytes)"] --> B["Validate record-commit identity bindings"]
    B --> C["Read generation and state code"]
    C --> D{"Admitted state?"}
    D -- No --> E["UnsupportedState"]
    D -- Yes --> F["Decode state body"]
    F --> G["Validate flags, counters, operation ID, schema, and chunking"]
    G --> H{"Trailing bytes?"}
    H -- Yes --> I["Corrupt"]
    H -- No --> J["CommitMarker::new"]
    J --> K["Canonical marker accepted"]
Loading

File-Level Changes

Change Details Files
Introduces a pure, headless codec for single-record record-commit markers with canonical serialization, strict validation, hashing, and authenticated sealing/opening.
  • Adds content_digest, marker state/body types, canonical encoding, and marker_entry_digest.
  • Admits ACTIVE, PENDING, and RECOVERY_REQUIRED; rejects reserved/unknown states, chunked markers, invalid counters, schemas, identities, flags, operation IDs, and trailing data.
  • Binds marker identities through shared §6.2 tagged AAD bindings, including rule-D direct/hashed identity selection.
  • Seals markers as generation-addressed record-commit envelopes and rejects generation-replay mismatches.
crates/worldscript-secure-storage/src/marker.rs
crates/worldscript-secure-storage/src/aad.rs
crates/worldscript-secure-storage/src/lib.rs
Adds contract-derived proof coverage for marker vectors, malformed inputs, lifecycle rules, identity binding, digest domains, sealing, and debug redaction.
  • Builds independent byte-level vectors and pins the entry digest against an independent hash computation.
  • Covers truncation, trailing bytes, non-canonical flags, unsupported states/chunking/schemas, identity mismatches, counter ordering, operation-ID bounds, and round trips.
  • Verifies authenticated open behavior and refusal of cross-identity and cross-generation replay.
crates/worldscript-secure-storage/tests/gate3b_marker_test.rs
Updates R-15 documentation and implementation status to record Gate 3 slice 3B part 1 without changing production authority.
  • Documents the marker codec scope and explicitly separates it from the future commit protocol and reconciliation work.
  • Updates the migration ledger and contract status while retaining R15_GATE3=SLICE_3A_DURABLE_STAGING and PRODUCTION_AUTHORITY_SWITCH_ALLOWED=NO.
docs/native/CORE-MIGRATION-LEDGER.md
docs/native/R15-SECURE-STORAGE-CONTRACT.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codeant-ai

codeant-ai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 525bad8a
Scan Time: 2026-10-01 16:25:34 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found, 3 false positive secrets suppressed
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED No IAC issues

View Full Results

@deepsource-io

deepsource-io Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in ad89d4f...525bad8 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 1, 2026 4:24p.m. Review ↗
Python Oct 1, 2026 4:24p.m. Review ↗
Rust Oct 1, 2026 4:24p.m. Review ↗
Shell Oct 1, 2026 4:24p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

codescene-access[bot]

This comment was marked as outdated.

@qnbs
qnbs marked this pull request as ready for review October 1, 2026 14:23
@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai

codeant-ai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 525bad8 Oct 01, 2026 · 16:24 16:24
✅ Reviewed your PR e185e4b Oct 01, 2026 · 14:23 14:26

@codeant-ai

codeant-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @qnbs, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 days and 22 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

[check-pr-size] PR size is over the target tier (normal profile): 7 files, 1126 meaningful lines, 5 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs.

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Oct 1, 2026
codescene-access[bot]

This comment was marked as outdated.

Comment thread crates/worldscript-secure-storage/src/marker.rs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e185e4b119

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/marker.rs Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 30e83b50-9346-44fb-8cbc-fd37bca62015

📥 Commits

Reviewing files that changed from the base of the PR and between cd12c10 and e185e4b.

📒 Files selected for processing (7)
  • CHANGELOG.md
  • crates/worldscript-secure-storage/src/aad.rs
  • crates/worldscript-secure-storage/src/lib.rs
  • crates/worldscript-secure-storage/src/marker.rs
  • crates/worldscript-secure-storage/tests/gate3b_marker_test.rs
  • docs/native/CORE-MIGRATION-LEDGER.md
  • docs/native/R15-SECURE-STORAGE-CONTRACT.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Comment thread crates/worldscript-secure-storage/src/marker.rs
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/marker.rs Outdated
Comment thread crates/worldscript-secure-storage/tests/gate3b_marker_test.rs Outdated
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md
Comment thread docs/native/R15-SECURE-STORAGE-CONTRACT.md Outdated
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found and verified against the latest diff

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="crates/worldscript-secure-storage/tests/gate3b_marker_test.rs">

<violation number="1" location="crates/worldscript-secure-storage/tests/gate3b_marker_test.rs:374">
P3: This test recomputes the digest with the same domain literal as `CONTENT_DIGEST_DOMAIN`, so a typo in that constant shared by both files would pass. The entry digest is pinned externally; pin `content_digest(envelope)` to a fixed vector (e.g. "0196e46d0ae351c775a39ac09e119fe0c91ab7dc36167d0c5f77f75f71ac5d31") alongside the structural assertion.</violation>
</file>

<file name="crates/worldscript-secure-storage/src/marker.rs">

<violation number="1" location="crates/worldscript-secure-storage/src/marker.rs:29">
P3: This defines a second, identical `MAX_OPERATION_ID_LEN = 128` constant for the same §6.1.2 bound that `anchor.rs` already exports (`pub const MAX_OPERATION_ID_LEN: usize = 128`, used by `identity.rs` for migration `operation_id`). The two can silently drift, and the marker body's only length-bounded field is formatted against an independent copy. Reuse `crate::anchor::MAX_OPERATION_ID_LEN` (or lift the bound to a shared module) instead of redeclaring it.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/tests/gate3b_marker_test.rs
Comment thread crates/worldscript-secure-storage/src/marker.rs Outdated
…ectors (#445)

A pending marker's target is now exactly 1 for a first write and old + 1 otherwise; the canonical
R-15 status token records the delivered marker codec; tests pin the contract's state codes,
operation-id bound and content_digest vector instead of importing implementation constants; the
marker reuses the crate's single operation-id bound.
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 629000880d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/marker.rs
Comment thread crates/worldscript-secure-storage/src/marker.rs Outdated
@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/tests/gate3b_marker_test.rs Outdated
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c31619dca0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/worldscript-secure-storage/src/marker.rs
Comment thread crates/worldscript-secure-storage/src/marker.rs

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread crates/worldscript-secure-storage/src/marker.rs
Comment thread crates/worldscript-secure-storage/src/marker.rs
qnbs added a commit that referenced this pull request Oct 1, 2026
The Security Audit on PR #937 head c31619d (CI/CD run 36882778130) reports GHSA-c475-qrg2-pj4r
(CVSS 8.2) on basic-ftp 6.0.1, fixed in 6.2.1, reached only through dev/CI tooling (@lhci/cli and
lighthouse via proxy-agent -> get-uri). The override floor moves from >=5.3.1 to >=6.2.1; the
lockfile changes only basic-ftp. 6.2.1 (2026-08-27) is older than the 7-day minimumReleaseAge.
qnbs added a commit that referenced this pull request Oct 1, 2026
… (#939)

* fix(deps): raise the basic-ftp override floor (fresh OSV finding, #938)

The Security Audit on PR #937 head c31619d (CI/CD run 36882778130) reports GHSA-c475-qrg2-pj4r
(CVSS 8.2) on basic-ftp 6.0.1, fixed in 6.2.1, reached only through dev/CI tooling (@lhci/cli and
lighthouse via proxy-agent -> get-uri). The override floor moves from >=5.3.1 to >=6.2.1; the
lockfile changes only basic-ftp. 6.2.1 (2026-08-27) is older than the 7-day minimumReleaseAge.

* docs(changelog): record the basic-ftp override floor (PR #939)

* docs(audit): record the raised basic-ftp override floor (#938)
…t-reconciliation

# Conflicts:
#	CHANGELOG.md
@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@codeant-ai codeant-ai Bot added size:XXL This PR changes 1000+ lines, ignoring generated files and removed size:XL This PR changes 500-999 lines, ignoring generated files labels Oct 1, 2026

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gates Passed
3 Quality Gates Passed

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 525bad8af4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@qnbs
qnbs merged commit 90ae5c4 into main Oct 1, 2026
54 checks passed
@qnbs
qnbs deleted the feat/445-gate3b-commit-reconciliation branch October 1, 2026 16:56
qnbs added a commit that referenced this pull request Oct 1, 2026
…al marker bindings (#445)

Follow-up to PR #937 review: an ordinary PENDING marker records the intent before ciphertext exists,
so it carries no content_digest (§9 step 2); a header is an identity mismatch only when its bindings
are canonical §6.2 bindings (non-empty UTF-8 direct values within the 256-byte cap, or hashed, never
mixed) naming another identity, and corrupt otherwise.
@qnbs

qnbs commented Oct 1, 2026

Copy link
Copy Markdown
Owner Author

Note on the four review threads resolved above: after #937 was squash-merged, #940 was rebased onto main, so the cited follow-up commit 9eb6ce96 is now 7f18a9b0 (same change) in #940.

qnbs added a commit that referenced this pull request Oct 1, 2026
…ciliation (#445) (#940)

* feat(core): add the Gate 3 slice 3B commit protocol and startup reconciliation (#445)

* fix(core): refuse digests on ordinary pending markers and non-canonical marker bindings (#445)

Follow-up to PR #937 review: an ordinary PENDING marker records the intent before ciphertext exists,
so it carries no content_digest (§9 step 2); a header is an identity mismatch only when its bindings
are canonical §6.2 bindings (non-empty UTF-8 direct values within the 256-byte cap, or hashed, never
mixed) naming another identity, and corrupt otherwise.

* docs(r15): record Gate 3 slice 3B part 2 in the contract and ledger (#445)

* docs(changelog): record Gate 3 slice 3B part 2 (PR #940)

* fix(core): bind commit candidates to their staging provenance and harden reconciliation durability (#445)

Review wave on PR #940: a write verifies the committed generation it replaces; the commit keeps the
operation's staging name until ACTIVE is recorded and startup adopts a candidate only through it;
the record directory is synced before ACTIVE; relocation syncs the new link before removing the old
name and derives its tag from a digest of the operation ID; the chain load syncs the marker
directory first and binds every marker to its file's generation; counters are allocated before any
write. Commit APIs take a RecordStore context; the 3-OS CI step also runs the marker tests.

* refactor(core): flatten candidate adoption and split the commit test fixtures (#445)

* fix(core): fail closed on unexpected marker entries and verify the old generation before rollback (#445)

Review wave 2 on PR #940: any non-canonical generation-* name in the marker directory is
RECOVERY_REQUIRED; a rollback re-records ACTIVE(old) only after the old generation verifies;
reconciliation reports the durability of the marker it wrote; record-directory listing has its own
step. §5.4's direct bound is aligned with §6.2's 256-byte tagged-binding cap, and §20 notes the 3B
staging retention.

* docs(r15): scope the unexpected-marker rule and the rollback wording precisely (#445)
qnbs added a commit that referenced this pull request Oct 10, 2026
… (#939)

* fix(deps): raise the basic-ftp override floor (fresh OSV finding, #938)

The Security Audit on PR #937 head c31619d (CI/CD run 36882778130) reports GHSA-c475-qrg2-pj4r
(CVSS 8.2) on basic-ftp 6.0.1, fixed in 6.2.1, reached only through dev/CI tooling (@lhci/cli and
lighthouse via proxy-agent -> get-uri). The override floor moves from >=5.3.1 to >=6.2.1; the
lockfile changes only basic-ftp. 6.2.1 (2026-08-27) is older than the 7-day minimumReleaseAge.

* docs(changelog): record the basic-ftp override floor (PR #939)

* docs(audit): record the raised basic-ftp override floor (#938)
qnbs added a commit that referenced this pull request Oct 10, 2026
…#937)

* feat(core): add the Gate 3 slice 3B record-commit marker codec (#445)

Defines the single-record commit marker exactly as contract §5.4 specifies: content_digest,
canonical_marker_body_bytes (sharing canonical AAD's tagged identity bindings), marker_entry_digest,
strict decoding, and sealing each marker generation as its own record-commit record. ACTIVE,
PENDING and RECOVERY_REQUIRED are admitted; deletion, migration and chunked states stay refused.

* docs(changelog): record the Gate 3 slice 3B marker codec (PR #937)

* fix(core): require the exact next pending generation and pin marker vectors (#445)

A pending marker's target is now exactly 1 for a first write and old + 1 otherwise; the canonical
R-15 status token records the delivered marker codec; tests pin the contract's state codes,
operation-id bound and content_digest vector instead of importing implementation constants; the
marker reuses the crate's single operation-id bound.

* fix(core): refuse fenced ordinary pending markers and classify malformed headers as corrupt (#445)
qnbs added a commit that referenced this pull request Oct 10, 2026
…ciliation (#445) (#940)

* feat(core): add the Gate 3 slice 3B commit protocol and startup reconciliation (#445)

* fix(core): refuse digests on ordinary pending markers and non-canonical marker bindings (#445)

Follow-up to PR #937 review: an ordinary PENDING marker records the intent before ciphertext exists,
so it carries no content_digest (§9 step 2); a header is an identity mismatch only when its bindings
are canonical §6.2 bindings (non-empty UTF-8 direct values within the 256-byte cap, or hashed, never
mixed) naming another identity, and corrupt otherwise.

* docs(r15): record Gate 3 slice 3B part 2 in the contract and ledger (#445)

* docs(changelog): record Gate 3 slice 3B part 2 (PR #940)

* fix(core): bind commit candidates to their staging provenance and harden reconciliation durability (#445)

Review wave on PR #940: a write verifies the committed generation it replaces; the commit keeps the
operation's staging name until ACTIVE is recorded and startup adopts a candidate only through it;
the record directory is synced before ACTIVE; relocation syncs the new link before removing the old
name and derives its tag from a digest of the operation ID; the chain load syncs the marker
directory first and binds every marker to its file's generation; counters are allocated before any
write. Commit APIs take a RecordStore context; the 3-OS CI step also runs the marker tests.

* refactor(core): flatten candidate adoption and split the commit test fixtures (#445)

* fix(core): fail closed on unexpected marker entries and verify the old generation before rollback (#445)

Review wave 2 on PR #940: any non-canonical generation-* name in the marker directory is
RECOVERY_REQUIRED; a rollback re-records ACTIVE(old) only after the old generation verifies;
reconciliation reports the durability of the marker it wrote; record-directory listing has its own
step. §5.4's direct bound is aligned with §6.2's 256-byte tagged-binding cap, and §20 notes the 3B
staging retention.

* docs(r15): scope the unexpected-marker rule and the rollback wording precisely (#445)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL This PR changes 1000+ lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant