🤖 feat: record durable history acceptance for compaction replacement - #4182
🤖 feat: record durable history acceptance for compaction replacement#4182ThomasK33 wants to merge 1 commit into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5b87bd3f21
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5b87bd3 to
4031141
Compare
|
Addressed all three findings in
The repair passed independent review, 243 focused tests and full static checks. After a clean rebase onto main, 379 affected history/storage/context-budget tests and both TypeScript targets passed. The original acceptance commit and repair are unchanged by the rebase. Runtime integration remains a dependent layer. Generated with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4031141a98
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed the three current findings in
Validation: 652 affected tests passed, full static checks passed, and independent review approved the repair. Generated with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2297c64073
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
The post-fence window is real and deliberately has conservative invalidation semantics. Commit The test loses ownership while chat publication is staged, after the owned generation rename. It verifies byte-identical chat and archive, no acceptance callback or replacement witness, retention of the same Stop, rejection of the old journal, and successful fresh capture, replacement publication, and witnessed Stop retirement. The journal fixture proves storage eligibility and generation rejection; it does not claim a full live-compactor recovery test. The focused tests passed (60 cases), with TypeScript, ESLint, formatting, and independent review passing. The side effect is that already prepared compaction work may need recomputation. Treating the generation rename as accepted input would be unsafe: no durable user trigger or nonce witness exists at that point, yet acceptance permits closing rollback, retiring Stop, and delivery bookkeeping. A recoverable transaction spanning generation and history would impose a stronger contract than this layer provides. The inspected path preserves original history and allows a fresh attempt, so we are keeping the conservative fence and exact-history acceptance boundary rather than adding a new transaction mechanism. Please reassess Generated with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a057374906
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed acceptance before the append durability barrier in Replacement lookup and witnessed retirement share verification that flushes only the matched chat/archive artifacts, revalidates provenance, and preserves final ownership checks. Persistent flush failure therefore retains Stop across restart. Later successful verification can retire it without appending or rewriting the row. Tests also cover evidence changes and lease reclamation during the flush. The lower commit passes 182 real-file tests with 997 assertions and full Generated with |
|
@codex review Please review current head Generated with |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
81101dd to
8732215
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 87322156a6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review current head Generated with |
|
Codex Review: Didn't find any major issues. Delightful! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
8732215 to
9e5206e
Compare
|
Addressed PRRT_kwDOPxxmWM6hJfdX (finding) in the published lower layer Real-file controls cover failed directory flushes, later recovery without duplicate rows, evidence changes and reclaimed leases. The unchanged complete implementation has prior static, backend and focused IPC/UI evidence. The new V1 intermediate tree separately passed 257 tests and canonical static checks. The final top exactly restores the complete implementation plus main’s documentation-only update; no fresh wholesale run of that final tree is claimed. The PR body records the qualified evidence. Generated with |
|
@codex review Please review current head Generated with |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9e5206e6fb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed two findings in
The append operation also has a preserve-cancellation mode for #4209’s final publication fence: it compares the original nonce/generation and returns a durable append receipt without stamping a witness or retiring the scoped Stop. The oversized-row scan finding remains valid and open. A separately reviewed raw scanner prerequisite is being prepared; history-specific validation and integration must follow before this phase can merge. No oversized-row fix is claimed by this update. Validation: 78 lower replacement tests passed. Both integrated runtime candidates passed targeted tests and canonical static checks; the PR descriptions identify exact scope and trees. Generated with |
|
@codex review Please review current head Generated with |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
b6a99df to
9d9b990
Compare
|
Addressed all three remaining findings:
Lower repairs pass 172 tests / 1,012 assertions; reader integration passes 341 tests / 10,629 assertions. Both pass canonical static and independent review. Final phase integration on main Generated with |
|
@codex review Please review the current head after the complete phase was composed on current main. All known findings have fixes and replies in their owning layers; the eight-member phase stays held until all members are approved and green. Generated with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9d9b990309
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
Addressed 3990171603: the identity preflight now shares exact replay semantics with witness lookup for an already-stamped Resume carrying the captured nonce. Byte-identical archive copies (with or without final LF, including repeated copies) no longer prevent Retry after failed retirement. Duplicate active rows and nonce/ID/sequence/byte conflicts remain refusals; unstamped Resume and fresh-append identity rules are unchanged. Captured generation/provenance, exact locked target and flushed witness verification still apply. The three valid replay cases failed before the fix. All 125 replacement tests / 610 assertions and canonical static checks pass. Combined phase validation: 3,715 tests across 50 affected service suites passed (34,595 assertions). Full Generated with |
|
@codex review Please review the updated head Generated with |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a525cd935b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed 3991363619: the existing bounded identity scan also rejects an already-consumed cancellation nonce. Exact stamped Resume replay remains idempotent, and later input uses the retirement successor. Real second-instance tests cover active, archived and oversized witnesses, unrelated Resume refusal, and ordinary preserve-mode input. Runtime controls also preserve the first accepted row through failed unlink, refuse a second send, and accept an explicit retry exactly once after cleanup. Addressed 3991363634: commit bookkeeping retains the original append references captured before any await. Single and batch tests mutate the caller array during real staging and verify one durable receipt, correct metadata on the original rows, and no publication of the extra row. The cancellation layer passed 3,996 tests across 54 suites; the settled-Stop layer passed 4,064 across the same 54 suites. Its final test-only assertion adjustment also passed the complete affected 52-test suite. Both final runtime branches passed canonical static checks. Generated with |
|
@codex review Please review the updated head Generated with |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a0897dbf57
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
a0897db to
5b5854a
Compare
|
Addressed 3992064871: retirement catches and logs a throwing Addressed 3992064875: locked Resume eligibility uses the existing readable-history Addressed 3992064883: each persistence attempt owns its verification signal. A successor aborts only the obsolete attempt’s scan and exact-byte comparison; disposal completes before the successor starts storage publication. Current-operation verification failures still propagate. Held 8 MiB archive-read regressions cover single and repeated Stop supersession: the old implementation reads 258 chunks, while the fix stops after the held chunk and closes every handle before the successor acquires storage. All three findings reproduce against the original lower production with the final regression tests. The five affected lower/reader suites pass 323 tests / 5,994 assertions, and full TypeScript, focused lint, and formatting checks pass. Final integrated validation passes on #4191 Generated with |
|
@codex review Please review the updated head Final integrated validation passes on #4191 Generated with |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5b5854a27d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
--- _Generated with `xum` • Model: `unavailable` • Thinking: `unavailable` • Cost: `$unavailable`_ <!-- mux-attribution: model=unavailable thinking=unavailable costs=unavailable -->
5b5854a to
b5eb4ba
Compare
|
Addressed 3992430226: the under-lock verification catch returns superseded only after this attempt loses ownership. Current-operation failures still escape and retain retry debt. Real-file barriers at stamp revalidation and flush prove obsolete retirement settles before its successor, closes handles, and preserves the successor’s Stop. Addressed 3992430233: the bounded witness scan checks all otherwise eligible occurrences of the requested nonce, including different IDs/sequences in chat or archives. They must satisfy existing exact-byte replay equality; conflicting identities cannot authorize retirement. Same-nonce ambiguity refuses a later candidate, while unrelated-nonce ambiguity still permits an independent valid witness. Short-read and oversized-archive controls remain intact. Addressed 3992430243: an ineligible legacy system stamp no longer consumes a nonce during append/Resume acceptance. It still occupies its ID/sequence, so collision refusal remains conservative. Legitimate append and Resume regressions retain the old raw row and prove durable replacement/retirement. The final tests fail eight regressions against the original production while three controls pass. All 299 tests / 1,547 assertions across three affected lower suites pass with the fix, together with full TypeScript, focused lint and formatting. Final integrated validation passes on #4191 Generated with |
|
@codex review Please review updated head Final integrated validation passes on #4191 All eight members remain held until current-head review approval and required CI are complete. Generated with |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Retained Stop needs durable proof that a replacement was accepted before canceled recovery can be released. This layer adds guarded append, batch, and Resume publication, with receipts captured at the history commit point and witnesses verified across active history and archives. Runtime activation follows in #4191/#4209.
Acceptance rechecks the captured cancellation nonce, journal generation, physical lock, and logical ownership. Visible bytes are distinguished from durable receipts, including file and directory flush failures. Preserve-mode publication grants no replacement authority. Request-entry capture and explicit malformed/unsupported-record repair share the existing history lock so repair cannot adopt an intervening Stop. A committed context reset can report its exact predecessor and successor generation through an in-memory receipt; advancing the generation or exposing bytes alone grants no queue-refresh authority. Stop retirement similarly reports the exact predecessor and cleared successor only after verified deletion under that same lock, retaining the receipt obligation through failed-unlink retries.
Resume preserves the original row, signatures, and metadata. It accepts the exact typed target or its exact wire projection. Retrying an already stamped Resume can reuse byte-identical archive replay copies for its captured nonce; duplicate active rows or changes to identity, sequence, nonce, formatting, provenance, or generation still refuse authority. Ordinary unstamped Resume retains its existing checks. A consumed nonce cannot accept another replacement before retirement; the exact stamped Resume replay is the only reuse exception. Publication metadata is written back only to the original snapshotted message references, so caller array changes cannot interrupt the durable receipt.
Witness traversal uses #4221's bounded row adapter. Protected and invalid-UTF-8 rows still occupy identities; fingerprints can only conservatively reject collisions, while replay authority requires exact byte ranges. Ordinary append sequence allocation still has its existing large archive-tail read; this PR does not claim the entire append path has bounded memory.
A throwing retirement observer is logged after the state receipt and cannot skip directory durability or recreate deletion debt. Superseding a local retirement aborts that attempt’s provisional history scan and exact replay comparison through their existing cancellation signal; scanner handles are disposed before the queued Stop publishes. Current verification errors still propagate. Legacy array-coerced system rows cannot be stamped or used as replacement witnesses, while readable user and assistant compatibility remains unchanged.
Under-lock witness verification now returns superseded only when its original attempt lost ownership; current verification errors still propagate. Every eligible occurrence of a nonce must prove the same exact receipt, so conflicting eligible identities anywhere in active or archived history refuse retirement. Ineligible legacy system stamps cannot consume replacement authority, while still occupying their ID and sequence for collision checks.
Validation includes real-file crash replay, foreign-writer/CAS races, malformed-record recovery, and deterministic file/directory durability failures. Final integrated validation passes on #4191
052fc084517c1a6fd8cfbecdf08c05b635358a32(4026 tests / 36442 assertions) and #420902651d365f63c9dc04d95744207f42f8065d6f35(4095 tests / 36847 assertions), across 54 affected suites each. Full source/test TypeScript andmake static-checkpass on both exact commits.Risk: conservative refusal can delay recovery when ownership or history evidence is ambiguous; flush latency affects publication. Tests retain exact history-byte and foreign-writer assertions.
This is one layer of the cancellation phase: #4214 → #4215 → #4219 → #4221 → #4182 → #4187 → #4191 → #4209. All eight PRs merge together after every member has current-head approval and passing CI.
Generated with
xum• Model:unavailable• Thinking:unavailable• Cost:$unavailable