Repository navigation
feat(core): add the Gate 3 slice 3B record-commit marker codec (#445) - #937
Conversation
Defines the single-record commit marker exactly as contract §5.4 specifies: content_digest, canonical_marker_body_bytes (sharing canonical AAD's tagged identity bindings), marker_entry_digest, strict decoding, and sealing each marker generation as its own record-commit record. ACTIVE, PENDING and RECOVERY_REQUIRED are admitted; deletion, migration and chunked states stay refused.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 10 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 80 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (7)
📝 WalkthroughWalkthroughThe pull request adds a public codec for version-1 ordinary-record commit markers. It supports canonical encoding, strict decoding, digest calculation, and sealing and opening protected records. Tests and contract documents describe supported states, validation rules, and work that remains outside this slice. ChangesRecord-commit marker codec
Priority: ⬇️ Low Merge Risk: 🔵 Low · up to The new commit-marker codec accepts pending generation numbers that skip values the storage contract forbids. It does not read or write user data yet, so current impact is limited. Tighten this validation and fix the small documentation typo before the commit protocol builds on the codec.
Comment |
Reviewer's GuideAdds and proves a generation-bound, strictly decoded Sequence diagram for generation-bound record-commit marker sealingsequenceDiagram
participant Caller
participant CommitMarker
participant RecordCodec
participant Envelope
Caller->>CommitMarker: CommitMarker::new(record, marker_generation, body)
CommitMarker->>CommitMarker: encode()
CommitMarker->>RecordCodec: seal_record(key, identity, metadata, body)
RecordCodec->>Envelope: record_generation = marker_generation
Envelope-->>Caller: sealed record-commit envelope
Caller->>CommitMarker: CommitMarker::open(key, record, envelope)
CommitMarker->>RecordCodec: open_record(key, marker_identity, envelope)
RecordCodec-->>CommitMarker: payload and envelope metadata
CommitMarker->>CommitMarker: decode(record, payload)
alt envelope generation matches marker_generation
CommitMarker-->>Caller: CommitMarker
else generation mismatch
CommitMarker-->>Caller: GenerationMismatch
end
Flow diagram for strict marker decoding and validationflowchart TD
A["CommitMarker::decode(record, bytes)"] --> B["Validate record-commit identity bindings"]
B --> C["Read generation and state code"]
C --> D{"Admitted state?"}
D -- No --> E["UnsupportedState"]
D -- Yes --> F["Decode state body"]
F --> G["Validate flags, counters, operation ID, schema, and chunking"]
G --> H{"Trailing bytes?"}
H -- Yes --> I["Corrupt"]
H -- No --> J["CommitMarker::new"]
J --> K["Canonical marker accepted"]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🏁 CodeAnt Quality Gate ResultsCommit: ✅ Overall Status: PASSEDQuality Gate Details
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Oct 1, 2026 4:24p.m. | Review ↗ | |
| Python | Oct 1, 2026 4:24p.m. | Review ↗ | |
| Rust | Oct 1, 2026 4:24p.m. | Review ↗ | |
| Shell | Oct 1, 2026 4:24p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
@codex review |
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
[check-pr-size] PR size is over the target tier (normal profile): 7 files, 1126 meaningful lines, 5 commits — limit ≤8 files / ≤400 lines / ≤6 commits. Consider splitting into smaller, independently reviewable PRs. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e185e4b119
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Actionable comments posted: 2
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
Review profile: CHILL
Plan: Essentials
Run ID: 30e83b50-9346-44fb-8cbc-fd37bca62015
📒 Files selected for processing (7)
CHANGELOG.mdcrates/worldscript-secure-storage/src/aad.rscrates/worldscript-secure-storage/src/lib.rscrates/worldscript-secure-storage/src/marker.rscrates/worldscript-secure-storage/tests/gate3b_marker_test.rsdocs/native/CORE-MIGRATION-LEDGER.mddocs/native/R15-SECURE-STORAGE-CONTRACT.md
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
There was a problem hiding this comment.
All reported issues were addressed across 7 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
2 issues found and verified against the latest diff
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="crates/worldscript-secure-storage/tests/gate3b_marker_test.rs">
<violation number="1" location="crates/worldscript-secure-storage/tests/gate3b_marker_test.rs:374">
P3: This test recomputes the digest with the same domain literal as `CONTENT_DIGEST_DOMAIN`, so a typo in that constant shared by both files would pass. The entry digest is pinned externally; pin `content_digest(envelope)` to a fixed vector (e.g. "0196e46d0ae351c775a39ac09e119fe0c91ab7dc36167d0c5f77f75f71ac5d31") alongside the structural assertion.</violation>
</file>
<file name="crates/worldscript-secure-storage/src/marker.rs">
<violation number="1" location="crates/worldscript-secure-storage/src/marker.rs:29">
P3: This defines a second, identical `MAX_OPERATION_ID_LEN = 128` constant for the same §6.1.2 bound that `anchor.rs` already exports (`pub const MAX_OPERATION_ID_LEN: usize = 128`, used by `identity.rs` for migration `operation_id`). The two can silently drift, and the marker body's only length-bounded field is formatted against an independent copy. Reuse `crate::anchor::MAX_OPERATION_ID_LEN` (or lift the bound to a shared module) instead of redeclaring it.</violation>
</file>
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
…ectors (#445) A pending marker's target is now exactly 1 for a first write and old + 1 otherwise; the canonical R-15 status token records the delivered marker codec; tests pin the contract's state codes, operation-id bound and content_digest vector instead of importing implementation constants; the marker reuses the crate's single operation-id bound.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 629000880d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@coderabbitai review |
|
There was a problem hiding this comment.
All reported issues were addressed across 4 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
…med headers as corrupt (#445)
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c31619dca0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
All reported issues were addressed across 3 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
The Security Audit on PR #937 head c31619d (CI/CD run 36882778130) reports GHSA-c475-qrg2-pj4r (CVSS 8.2) on basic-ftp 6.0.1, fixed in 6.2.1, reached only through dev/CI tooling (@lhci/cli and lighthouse via proxy-agent -> get-uri). The override floor moves from >=5.3.1 to >=6.2.1; the lockfile changes only basic-ftp. 6.2.1 (2026-08-27) is older than the 7-day minimumReleaseAge.
… (#939) * fix(deps): raise the basic-ftp override floor (fresh OSV finding, #938) The Security Audit on PR #937 head c31619d (CI/CD run 36882778130) reports GHSA-c475-qrg2-pj4r (CVSS 8.2) on basic-ftp 6.0.1, fixed in 6.2.1, reached only through dev/CI tooling (@lhci/cli and lighthouse via proxy-agent -> get-uri). The override floor moves from >=5.3.1 to >=6.2.1; the lockfile changes only basic-ftp. 6.2.1 (2026-08-27) is older than the 7-day minimumReleaseAge. * docs(changelog): record the basic-ftp override floor (PR #939) * docs(audit): record the raised basic-ftp override floor (#938)
…t-reconciliation # Conflicts: # CHANGELOG.md
|
@codex review |
There was a problem hiding this comment.
Gates Passed
3 Quality Gates Passed
See analysis details in CodeScene
Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…al marker bindings (#445) Follow-up to PR #937 review: an ordinary PENDING marker records the intent before ciphertext exists, so it carries no content_digest (§9 step 2); a header is an identity mismatch only when its bindings are canonical §6.2 bindings (non-empty UTF-8 direct values within the 256-byte cap, or hashed, never mixed) naming another identity, and corrupt otherwise.
…ciliation (#445) (#940) * feat(core): add the Gate 3 slice 3B commit protocol and startup reconciliation (#445) * fix(core): refuse digests on ordinary pending markers and non-canonical marker bindings (#445) Follow-up to PR #937 review: an ordinary PENDING marker records the intent before ciphertext exists, so it carries no content_digest (§9 step 2); a header is an identity mismatch only when its bindings are canonical §6.2 bindings (non-empty UTF-8 direct values within the 256-byte cap, or hashed, never mixed) naming another identity, and corrupt otherwise. * docs(r15): record Gate 3 slice 3B part 2 in the contract and ledger (#445) * docs(changelog): record Gate 3 slice 3B part 2 (PR #940) * fix(core): bind commit candidates to their staging provenance and harden reconciliation durability (#445) Review wave on PR #940: a write verifies the committed generation it replaces; the commit keeps the operation's staging name until ACTIVE is recorded and startup adopts a candidate only through it; the record directory is synced before ACTIVE; relocation syncs the new link before removing the old name and derives its tag from a digest of the operation ID; the chain load syncs the marker directory first and binds every marker to its file's generation; counters are allocated before any write. Commit APIs take a RecordStore context; the 3-OS CI step also runs the marker tests. * refactor(core): flatten candidate adoption and split the commit test fixtures (#445) * fix(core): fail closed on unexpected marker entries and verify the old generation before rollback (#445) Review wave 2 on PR #940: any non-canonical generation-* name in the marker directory is RECOVERY_REQUIRED; a rollback re-records ACTIVE(old) only after the old generation verifies; reconciliation reports the durability of the marker it wrote; record-directory listing has its own step. §5.4's direct bound is aligned with §6.2's 256-byte tagged-binding cap, and §20 notes the 3B staging retention. * docs(r15): scope the unexpected-marker rule and the rollback wording precisely (#445)
… (#939) * fix(deps): raise the basic-ftp override floor (fresh OSV finding, #938) The Security Audit on PR #937 head c31619d (CI/CD run 36882778130) reports GHSA-c475-qrg2-pj4r (CVSS 8.2) on basic-ftp 6.0.1, fixed in 6.2.1, reached only through dev/CI tooling (@lhci/cli and lighthouse via proxy-agent -> get-uri). The override floor moves from >=5.3.1 to >=6.2.1; the lockfile changes only basic-ftp. 6.2.1 (2026-08-27) is older than the 7-day minimumReleaseAge. * docs(changelog): record the basic-ftp override floor (PR #939) * docs(audit): record the raised basic-ftp override floor (#938)
…#937) * feat(core): add the Gate 3 slice 3B record-commit marker codec (#445) Defines the single-record commit marker exactly as contract §5.4 specifies: content_digest, canonical_marker_body_bytes (sharing canonical AAD's tagged identity bindings), marker_entry_digest, strict decoding, and sealing each marker generation as its own record-commit record. ACTIVE, PENDING and RECOVERY_REQUIRED are admitted; deletion, migration and chunked states stay refused. * docs(changelog): record the Gate 3 slice 3B marker codec (PR #937) * fix(core): require the exact next pending generation and pin marker vectors (#445) A pending marker's target is now exactly 1 for a first write and old + 1 otherwise; the canonical R-15 status token records the delivered marker codec; tests pin the contract's state codes, operation-id bound and content_digest vector instead of importing implementation constants; the marker reuses the crate's single operation-id bound. * fix(core): refuse fenced ordinary pending markers and classify malformed headers as corrupt (#445)
…ciliation (#445) (#940) * feat(core): add the Gate 3 slice 3B commit protocol and startup reconciliation (#445) * fix(core): refuse digests on ordinary pending markers and non-canonical marker bindings (#445) Follow-up to PR #937 review: an ordinary PENDING marker records the intent before ciphertext exists, so it carries no content_digest (§9 step 2); a header is an identity mismatch only when its bindings are canonical §6.2 bindings (non-empty UTF-8 direct values within the 256-byte cap, or hashed, never mixed) naming another identity, and corrupt otherwise. * docs(r15): record Gate 3 slice 3B part 2 in the contract and ledger (#445) * docs(changelog): record Gate 3 slice 3B part 2 (PR #940) * fix(core): bind commit candidates to their staging provenance and harden reconciliation durability (#445) Review wave on PR #940: a write verifies the committed generation it replaces; the commit keeps the operation's staging name until ACTIVE is recorded and startup adopts a candidate only through it; the record directory is synced before ACTIVE; relocation syncs the new link before removing the old name and derives its tag from a digest of the operation ID; the chain load syncs the marker directory first and binds every marker to its file's generation; counters are allocated before any write. Commit APIs take a RecordStore context; the 3-OS CI step also runs the marker tests. * refactor(core): flatten candidate adoption and split the commit test fixtures (#445) * fix(core): fail closed on unexpected marker entries and verify the old generation before rollback (#445) Review wave 2 on PR #940: any non-canonical generation-* name in the marker directory is RECOVERY_REQUIRED; a rollback re-records ACTIVE(old) only after the old generation verifies; reconciliation reports the durability of the marker it wrote; record-directory listing has its own step. §5.4's direct bound is aligned with §6.2's 256-byte tagged-binding cap, and §20 notes the 3B staging retention. * docs(r15): scope the unexpected-marker rule and the rollback wording precisely (#445)
User description
Part of #445 / #921 (Gate 3, slice 3B, part 1). No production authority switch:
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Scope
Slice 3B is split at its proof boundary:
record-commitmarker codec, which is pure, headless and vector-proven.PENDING→ stage/promote →ACTIVE), startup reconciliation, and orphan/superseded staging classification. It builds on this codec and on slice 3A'sstage_and_promote.What lands (
crates/worldscript-secure-storage/src/marker.rs)content_digest(§5.4): SHA-256 overworldscript-r15/content/v1and the completeWSR1envelope.CommitMarkerand its canonical body bytes (§5.4):marker_generationandstate_code, followed by the state body;tagged_identity_bindings, so rule D's direct/hashed choice has one implementation.marker_entry_digest, the value slice 3C's rootmarker_set_digestwill bind.ACTIVE,PENDING,RECOVERY_REQUIRED.DELETE_PENDING,TOMBSTONED(§8.5) andREAD_AUTHORITY_PENDING(migration) keep their reserved codes but are refused until their gates admit them.is_chunked = 1is also refused, because the chunked envelope is not implemented.0or1, and no trailing bytes are allowed;0oru64::MAX);1for a first write, otherwiseold + 1);operation_idmust be 1–128 bytes;record-commitrecord with enveloperecord_generation = marker_generation. Opening refuses a body whose generation differs from its envelope's, which prevents replay under another generation's name.Proof
tests/gate3b_marker_test.rs(17 tests):marker_entry_digestvector pinned from an independent Pythonhashlibcomputation;ACTIVEbodies;Local runs:
cargo clippy --all-targets -D warningsis clean, the full crate suite passes, andpnpm docs:check(including the R-15 gate status guard) passes.Docs
R15_GATE3token is nowSLICE_3B_MARKER_CODECin the status block and ledger row 10.Summary by Sourcery
Implement the headless Gate 3 slice 3B record-commit marker codec without changing production storage authority.
New Features:
Bug Fixes:
Enhancements:
Documentation:
Tests:
Chores:
Summary by cubic
Adds the Gate 3 slice 3B part 1
record-commitmarker codec to the headlessworldscript-secure-storagecrate: canonical body encoding, strict decoding, and generation-bound sealing of one record's commit marker, vector-proven against the contract. It decides no authority andPRODUCTION_AUTHORITY_SWITCH_ALLOWEDstaysNO; the commit write protocol and startup reconciliation are a later slice 3B part 2.What lands
content_digestis SHA-256 over the domain and the completeWSR1envelope;marker_entry_digestis the value slice 3C's rootmarker_set_digestwill bind.tagged_identity_bindings(pulled out ofaad.rs), so rule D's direct/hashed choice has one implementation.ACTIVE,PENDING, andRECOVERY_REQUIRED;DELETE_PENDING,TOMBSTONED,READ_AUTHORITY_PENDING, and chunked bodies keep reserved codes but are refused.1for a first write, otherwiseold + 1),operation_id1–128 bytes, an admitted record schema, and an ordinary-write fence of0(journal-owned positive fences refused). A well-formed foreignrecord-commitheader is an identity mismatch; truncated or malformed headers are corruption.record-commitrecord whose envelope generation must equal the body's — opening refuses a mismatch, blocking replay under another generation's name.docs:checkpass, and contract §20 and ledger row 10 are updated (R15_GATE3=SLICE_3B_MARKER_CODEC).Written for commit 525bad8. Summary will update on new commits.
Summary by CodeRabbit
CodeAnt-AI Description
Add a strict record-commit marker codec for protected storage
What Changed
ACTIVE,PENDING, andRECOVERY_REQUIREDrecord markers.Impact
✅ Strict marker validation✅ Replay-resistant record generations✅ Contract-pinned storage compatibility💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.