fix: validate authoritative reservation records before decisions - #43
Merged
Merged
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 44 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (10)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
flyingrobots
marked this pull request as ready for review
September 22, 2026 16:04
9 of 18 tasks
Snapshot validation and `sem list` matched semaphore refs with a glob that crosses '/', so refs/locks/sem/<name>/slots/meta (the slot of the valid job id `meta`) was validated as a meta record. Every later command then failed with store-read, and on main `sem list` already printed a `<name>/slots` line with an empty capacity, which is not valid JSON. Both now split the ref at the first '/' after the semaphore name. Also check for an empty stored path before the lexical-key pattern, which matched '//' first and left the "empty stored path" diagnosis unreachable. Refs #33
# Conflicts: # CHANGELOG.md
flyingrobots
added a commit
that referenced
this pull request
Oct 2, 2026
main's record validation (#43) now decodes stored capacity in doctor and every read, so doctor keeps main's validate_record path, and valid_capacity delegates to record_uint instead of carrying a second decimal parser.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A malformed lock blob could make
check x.mdreport an expired reservation with exit 0. Every refreshed snapshot now validates authoritative job/path records, semaphore metadata, and semaphore slots before normal commands use their fields. Errors produce structuredstore-readoutput with exit 2 before authoritative refs change. Doctor uses the same decoder to retain record findings without evaluating unsafe numeric input.Validation follows the ref's role. Directory and semaphore generation tokens remain opaque. Stored decimal fields normalize leading zeros and reject values outside the nonnegative signed 64-bit range; capacity must be positive. Older lock records that omit
familyretain the zero default. A maximum family generation remains readable, but child admission refuses to increment it before overflow.Fixes #33.
Validation:
3584fe6: 979 passed, 0 failed.make lintand generated-executable consistency passed.Two earlier full-suite attempts encountered host disk exhaustion and do not count as passing evidence. The final gate used a dedicated temporary directory after disk recovery.
PYTHONPATHexposed the existing jsonschema installation to the suite's isolated HOME; no dependencies were installed.