Add verified packed-catalog storage and publication foundations - #20
Merged
Merged
Conversation
Reuse the staged, resolved integration of pack-storage PR #19 with main.
forhappy
marked this pull request as ready for review
October 2, 2026 00:52
Bind exact retained descriptor membership and live successor authority to physical closure preparation. Preserve original source incarnations while writing successor index nodes, carry the checkpoint digest through catalog certificate v3 and reconciliation, and recheck custody in final publication. Extend owner restoration through publication. Completion retires the active operation, so verify its retained independent pin and original exact checkpoint receipt rather than expecting an active query after completion. Validation: 379 workspace library tests, all-target Clippy with warnings denied, formatting and diff checks pass locally. Prior-head CI fails native capture with WouldBlock; record that unresolved failure without weakening fences or deadlines.
Closing a CLOEXEC file in the parent does not release its exclusive lock while an unrelated pre-exec child still holds an inherited copy. Explicitly unlock only when the final capture file owner drops, preserving queued upload exclusion and native worker descendant drain. The deterministic regression reproduces WouldBlock before the fix on macOS and Linux and passes afterward. All 380 unique library tests pass locally and in an unprivileged Linux container; all-target Clippy with warnings denied passes. The precise failing phase of the earlier CI run remains unproven and fresh CI is required.
Reuse publication dispatch and per-job byte reservations for adopted checkpoints. Preserve original committed receipts separately from fresh custody and fence unusable bound sessions. Cover cancellation, uncertain recovery, authority changes, retained physical publication and mixed admission.
Retain Claim and Renew commands through shared publication admission, cancellation, close and uncertainty recovery. Preserve original receipts separately from fresh lease custody and reuse the shared session fence and generation pins. Cover owner restoration, original floors, authority races and retained physical publication.
Reuse operation admission, exact commands, worker/result slots and checkpoint ownership after Bind or bound Claim. Share session deadlines and permanent fences with bases and enforce a separate residence ceiling without a renewal loop. Preserve known receipts across failed fresh custody and cover cancellation, closed recovery, owner restore and native assembly.
Reuse authenticated artifacts, GitInput and the native input index for request-only checkpoints, exact append CAS and restored-owner reopening. Compute scoped and raw digests in one scan and retain spool admission through queued cancellation. The completed staging checkpoint slot previously refused the real native append. Permit only exact-predecessor replacement after known success, preserving unknown commands and original observers. Reject simultaneous Bind and append in SQL. Production cutover, durable native results and final ref-plan roots remain open.
Reuse the shared range tree and canonical ref plan for byte-bounded lexical keys, tombstones, weighted live seeks, exact conditional updates and streaming initial construction. Advance exhausted seek branches to later ancestor siblings so namespace validation cannot miss live descendants. Validate with 437 workspace library tests, all-target Clippy, stock-Git HTTP and signed-push recovery. Final root publication, existing-base bulk coalescing and production hard cutover remain open.
Reuse unaffected subtrees through a bounded sorted rewrite, preserve full expectation validation and canonical intent digests, and balance final leaf/internal groups. Release spool admission before disk credit so observable cleanup cannot race permit release. Validated with 443 workspace library tests, 1,000 queued-spool cancellation repetitions, all-target Clippy, and stock-Git HTTP and signed-push integrations. Authoritative root publication, serving cutover, and large-team capacity qualification remain outstanding.
Carry the selected ref descriptor through shared generation facts, lease/frontier queries and catalog attestations. Derive conditional ref transitions only from the prepared catalog capability, retain the exact descriptor through compaction, and refuse inline SQL writes against a selected root. Use one encoded context in the new v4 attestation payload to retain the existing 1 KiB bound. Eliminate the observed SSH fixture port-probe race. Verified with 447 library tests, all-target Clippy and HTTP, signed-push restore and RSA/ECDSA integration checks. Fresh initialization, final policy/check authority, short atomic publication and full cutover remain outstanding.
Use the merged Cellule owner-fence API and retain listener and native cleanup regression coverage. Scope retained Directory fixtures without accepting historical Repository code. Workspace libraries, final all-target Clippy, Python harness, and focused integrations pass.
Preserve bounded indexes, native admission and gateway-owned cache lifetime. Keep the prerequisite release rejection check and benchmark source identity regression. Updated compatibility tests, 96 Python harness tests and all-target Clippy pass.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Large Git histories need canonical object lookup and durable publication without an authoritative per-object placement inventory in the Repository Cell. This PR adds verified immutable pack/catalog storage, retained generation facts, fenced publication foundations and fair bounded command dispatch. The latest increment prepares exact native push outcomes as immutable artifacts and signs a joint catalog/ref/outcome input bounded by 8 KiB.
Resulting behavior
Validation
8bb0ee7head succeeded; new-head CI is separate evidence.Required implementation and release gates
The full implementation and capacity goal remains open. Preparation is conditional and grants no acknowledgement. The final bounded atomic root/outcome command must check actual fence, current ACL/lease/pin/guard, exact catalog CAS and signed ownership while recording the selected outcome. Immutable outcome-only completion, authorized durable replay, complete typed retention/collection and isolated restore, supervised takeover, coordinated producer/reader/schema hard cutover, file-backed intent/report handling, hard OS containment, accelerated reads/physical pack rewriting, continuous fair maintenance and hot-root progress remain required. Full-history Linux/Kubernetes/Chromium and the mandatory 10,000-developer mixed-load campaign remain unqualified.
The executable scope and remaining gates are in the implementation plan, large-team amendment, storage design and immutable outcome contract.
The previous 63,965-byte PR description is archived verbatim, including its historical validation and failures. This preserves the evidence while keeping the current description within GitHub's size limit.