Skip to content

feat(cas): verify complete objects before atomic output promotion - #769

Merged
flyingrobots merged 3 commits into
mainfrom
feat/physical-content-port
Oct 7, 2026
Merged

flyingrobots merged 3 commits into
mainfrom
feat/physical-content-port

Conversation

@flyingrobots

Copy link
Copy Markdown
Owner

Existing CAS APIs do not provide a common fallible complete-object boundary with atomic caller output. This additive port stages under explicit per-object byte limits, verifies the Echo hash and exact length, and promotes only a sealed complete object. MemoryTier and DiskTier implement the same borrowed-view and explicit-publication contract. Existing consumers retain compatible APIs.

Closes #760. The shared backend-neutral conformance suite covers staging invisibility, empty/text/chunk-boundary bytes, missing content, wrong length, source failure, capacity refusal, unavailable atomic output, and failed promotion. Disk corruption and publication failure, plus partial and ignored writer failures, preserve previous visible output.

Validation in the reusable guarded Docker worker: all34 echo-cas tests pass on Rust1.90, strict all-target Clippy and workspace fmt pass. The initial narrow run passed all three new tests but Clippy caught an unused test import, corrected before the full gate. Canonical boundary, package README, and changelog state the actual behavior.

Limits: private payload staging is bounded per object, not aggregate retained MemoryTier capacity or RSS. Missing content is an operational capability error; no authenticated absence, pinned filesystem generation, synchronization, retention, or crash-durability evidence is claimed. Keep is not a dependency and current consumers are not rerouted. #761 owns the optional experimental backend.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: flyingrobots/echo/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: a5721a5b-9962-4afa-8e9a-5eddcc2e070a
📥 Commits

Reviewing files that changed from the base of the PR and between 7dde48b and 7802d89.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • crates/echo-cas/README.md
  • crates/echo-cas/src/disk.rs
  • crates/echo-cas/src/lib.rs
  • crates/echo-cas/src/physical_content.rs
  • crates/echo-cas/tests/common/physical_content.rs
  • crates/echo-cas/tests/physical_content.rs
  • docs/architecture/echo-keep-physical-content-boundary.md
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T17:11:13.848147Z 7802d89 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 834196cfe0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/echo-cas/src/physical_content.rs Outdated
Comment thread crates/echo-cas/src/physical_content.rs
Comment thread crates/echo-cas/src/physical_content.rs Outdated
@flyingrobots

Copy link
Copy Markdown
Owner Author

Adversarial Independent Review: PR #769 (flyingrobots/echo)

  • Branch: feat/physical-content-port
  • Head SHA: 834196cfe0244819d452f5a03bf0f0ea59b98c06
  • Target Main SHA: 7dde48b223ed105c13a1b70afb6a1a07d1dc308e
  • Fork Base SHA: 18b22e362e986f3e2509856433d040f33dc81bd2
  • Tracking Issue: Add the Echo physical-content port and existing CAS adapters #760 (K02: Fallible complete-object port)
  • Review Mode: Read-only static inspection and evidence audit. No host execution, no Docker, no modifications.

Findings

[P4] Asymmetry in early byte-budget refusal between staging and reconstruction

  • File:Line: crates/echo-cas/src/physical_content.rs:171-179 vs crates/echo-cas/src/physical_content.rs:237-243
  • Concrete Scenario:
    In reconstruct_quarantined, if target.length > destination.byte_limit(), the function fails fast upfront with ContentError::ResourceLimit before executing the reconstruction closure.
    Conversely, in StagedContent::read_expected, target.length is not checked against byte_limit prior to pulling bytes from source. If a caller passes target.length > byte_limit and source yields fewer bytes than target.length (e.g. an immediate EOF or truncated source), read_expected reports ContentError::Mismatch instead of ContentError::ResourceLimit. If source yields bytes exceeding byte_limit, io::copy fails and reports ContentError::ResourceLimit.
  • Evidence:
    reconstruct_quarantined:
    let limit = destination.byte_limit();
    if usize::try_from(target.length).ok().is_none_or(|n| n > limit) {
        return Err(ContentError::ResourceLimit);
    }
    StagedContent::read_expected:
    let mut buffer = PrivateContentBuffer::new(byte_limit);
    io::copy(source, &mut buffer).map_err(|error| buffer.map_error(error))?;
    Ok(Self(VerifiedContent::seal(target, buffer.bytes)?))
  • Suggested Fix:
    Add a fast-path refusal in StagedContent::read_expected when usize::try_from(target.length).ok().is_none_or(|n| n > byte_limit) to reject oversize targets with ContentError::ResourceLimit without unnecessarily reading from source.

[P5] Disparate error wrapping between disk view reconstruction and disk backend publication


Runtime Path Trace

Operation / Code Path Entry Point Staging / Execution Verification / Sealing Promotion / Emission
Staged Expected Ingestion StagedContent::read_expected PrivateContentBuffer::write via io::copy bounded by byte_limit VerifiedContent::seal (checks target.length and BLAKE3 target.hash) Produces private StagedContent; dropping publishes nothing
Memory Tier Publication MemoryTier::publish_content Transfers bytes from content.0.bytes() MemoryTier::put_verified verifies hash before inserting into blobs Emits ContentReceipt (establishes_durability: false)
Disk Tier Publication DiskTier::publish_content Writes .tmp file in blob partition directory DiskTier::put_verified verifies hash before write; atomic rename Emits ContentReceipt (establishes_durability: false)
Memory View Reconstruction MemoryContentView::reconstruct Calls reconstruct_quarantined with in-memory lookup PrivateContentBuffer stages bytes; VerifiedContent::seal checks identity MemoryContentDestination::promote swaps visible buffer atomically
Disk View Reconstruction DiskContentView::reconstruct Streams from std::fs::File via io::copy into staging Re-hashes file bytes; rejects corrupted/truncated files via VerifiedContent::seal TransactionalContentDestination::promote only on seal success

Merges and Integration Audit

  1. Branch Divergence Structure:
    • Merge Base: 18b22e362e986f3e2509856433d040f33dc81bd2
    • PR Head: 834196cfe0244819d452f5a03bf0f0ea59b98c06 (1 commit ahead of base)
    • Target Main: 7dde48b223ed105c13a1b70afb6a1a07d1dc308e (6 commits ahead of base: PR fix: bound Action WAL parent replay and retained states #767 fix/study-recovery-replay)
    • No merge commits exist within feat/physical-content-port.
  2. Target Divergence Semantic Check:
    • Main added WAL recovery replay cursor reuse in warp-core (trusted_runtime_host.rs, provenance_store.rs, WAL.md).
    • feat/physical-content-port modifies only echo-cas and documentation.
    • The only shared file between branch and target main is CHANGELOG.md.
    • In CHANGELOG.md, 7dde48b2 added an entry under ### Fixed, while 834196cf added an entry under ### Added.
    • git merge-tree 18b22e36 834196cf 7dde48b2 completes cleanly with exit code 0 and zero conflict markers.
    • No recovery call sites in warp-core or runtime call physical-content APIs; zero integration friction or broken invariants.

Constants & Numeric Evidence Verification

Claim / Constant Location Raw Evidence / Coordinate Audit Result
All 34 echo-cas tests pass PR #769 body, line 5 retained evidence: k02-green.log:6,29,39,48,60 (17 unit + 4 disk + 3 physical + 10 retention) Verified Exact (34 passed, 0 failed)
Initial Clippy failure on unused Write PR #769 body, line 5 retained evidence: k02-initial.log:4,24-28 (unused import: Write in physical_content.rs:15:21, exit code 101) Verified Exact
Three new tests added PR #769 body, line 5 retained evidence: k02-green.log:39-44 (prefix_and_ignored_writer_failure..., memory_complete_object..., disk_complete_object...) Verified Exact
Rust toolchain 1.90.0 / 1.96.0 PR #769 body, line 5 retained evidence: k02-green.sh:1-3 (cargo +1.90.0 test, cargo +1.90.0 clippy, cargo +1.96.0 fmt) Verified Exact
Chunk-boundary test constant 262_145 crates/echo-cas/tests/common/physical_content.rs:20 262_145 bytes = 256 * 1024 + 1 (256 KiB chunk boundary + 1 byte) Verified Exact
Build cache usage: 13,348,293,696 B retained evidence: k02-green.result.json:3 13.35 GiB <= 20 GiB host build budget Verified Within Bound
Test data usage: 4,255,566,912 B retained evidence: k02-green.result.json:4 3.96 GiB <= 4 GiB aggregate data budget Verified Within Bound
Log output usage: 16,029,981 B retained evidence: k02-green.result.json:5 15.29 MiB <= 128 MiB log budget Verified Within Bound
Free disk floors: 728 GB host / 692 GB VM retained evidence: k02-green.result.json:6-7 Both well above 50 GiB safety floor Verified Within Bound
Code SHA256 hashes matching HEAD retained evidence: k02-green.manifest.json:5-7 physical_content.rs: cb5140d6...
common/physical_content.rs: 4158a0e1...
tests/physical_content.rs: ff12bab4...
Verified 100% Identical to HEAD
Post-gate documentation additions Git commit 834196cf vs k02-green.manifest.json CHANGELOG.md, crates/echo-cas/README.md, and echo-keep-physical-content-boundary.md updated after gate Verified Documented & Grounded

Invariant & Contract Analysis

  1. Quarantine & Output Invisibility:
    PrivateContentBuffer is private to physical_content.rs. The reconstruction closure only receives a &mut dyn Write. Visible output is held in MemoryContentDestination::visible and is never touched until VerifiedContent::seal has cryptographically verified the BLAKE3 digest and exact byte count. In case of any error (source error, hash mismatch, length mismatch, allocation failure, or promotion error), previous visible output is completely preserved.
  2. Ignored Writer / Backend Overrun Protection:
    In PrivateContentBuffer::write, if length exceeds limit or allocation fails, self.resource_failure is latched to true. In reconstruct_quarantined, even if a misbehaving reconstruction callback catches and swallows the write error, staging.resource_failure is checked independently before sealing.
  3. Allocation Refusal & Resource Discipline:
    Allocation is checked using self.bytes.try_reserve_exact(bytes.len()) before extending the buffer. Host allocation refusal latches resource_failure and maps to ContentError::ResourceLimit without panicking.
  4. Missing Content vs Absence Refusal:
    Missing content returns ContentError::CapabilityUnavailable. It does not return an authenticated absence refusal, adhering to the boundary architecture that DiskTier/MemoryTier cannot prove non-membership.
  5. No Synchronization or Durability Claims:
    ContentReceipt::establishes_durability and ContentReceipt::establishes_complete_view return false. DiskTier::publish_content relies on POSIX directory rename without fsync, matching its explicit lack of crash-durability claims.
  6. No Causal Authority:
    VerifiedContent and ContentReceipt bind only ContentTarget (BLAKE3 hash and byte length). They grant no causal authority, worldline state, or commit validity.
  7. SPDX Headers:
    All 8 modified files conform to repository SPDX policy (Apache-2.0 for Rust code, Apache-2.0 OR LicenseRef-MIND-UCAL-1.0 for Markdown). Validated via scripts/check_spdx.sh --check.

Mandatory Verification Checklist


Verdict

APPROVE

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e0494292a7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/echo-cas/tests/physical_content.rs Outdated
@flyingrobots

Copy link
Copy Markdown
Owner Author

Adversarial Independent Review: PR #769 (flyingrobots/echo)

  • Repository: flyingrobots/echo
  • Branch: feat/physical-content-port
  • Head SHA: 7802d898a933e41fdccd7a8e4651a1e295b4e3b8
  • Target Main SHA: 7dde48b223ed105c13a1b70afb6a1a07d1dc308e
  • Fork Base SHA: 18b22e362e986f3e2509856433d040f33dc81bd2
  • Tracking Issue: Add the Echo physical-content port and existing CAS adapters #760 (K02: Additive Echo-owned fallible complete-object port)
  • Review Mode: Read-only static inspection, git queries, and evidence audit. Clean checkout at the reviewed checkout. No code mutations, commits, comments, merges, subagents, host tests, Docker executions, or artifact files.

1. Findings and Resolution Audit

Verified Defects (P0–P5)

  • None. No unresolved code defects, invariant violations, or resource regressions were demonstrated in the current HEAD snapshot (7802d898).

Reconciled and Resolved Review Items

  1. [RESOLVED] Thread 0: Upfront length preflight in StagedContent::read_expected
  2. [RESOLVED] Thread 1: Windows duplicate disk publication premise
  3. [RESOLVED] Thread 2: Overlong reconstruction latching as identity mismatch
  4. [RESOLVED] Thread 3: Conformance disk fixture collision isolation
    • File:Line: crates/echo-cas/tests/physical_content.rs:53-68
    • Resolution: Commit 7802d898 replaces non-exclusive directory creation with exclusive fs::create_dir across a bounded 1024-slot PID-based search loop. It never reuses or clears stale fixtures.
  5. [RECONCILED] agyP5: Error variant distinction between read view and publication

2. Review Protocol Verification

1. Runtime Code Path Trace & Parallel Path Parity

Operation / Path Entry Point Staging & Bounds Verification & Sealing Promotion & Output
Staged Ingestion StagedContent::read_expected PrivateContentBuffer::write via io::copy, checked against byte_limit and expected_length VerifiedContent::seal (checks target.length and BLAKE3 target.hash) Produces private StagedContent; dropping publishes nothing
Memory Publication MemoryTier::publish_content N/A (consumes verified StagedContent) Checked by MemoryTier::put_verified Stores in memory map; returns ContentReceipt (durability=false, complete_view=false)
Disk Publication DiskTier::publish_content N/A (consumes verified StagedContent) Checked by DiskTier::put_verified Writes temp file, atomic fs::rename; returns ContentReceipt (durability=false, complete_view=false)
Memory View Reconstruct MemoryContentView::reconstruct reconstruct_quarantined with private PrivateContentBuffer Reads from MemoryTier::get, sealed via VerifiedContent::seal Calls TransactionalContentDestination::promote; emits ContentReceipt
Disk View Reconstruct DiskContentView::reconstruct reconstruct_quarantined with private PrivateContentBuffer Streams file via DiskTier::blob_path, sealed via VerifiedContent::seal Calls TransactionalContentDestination::promote; emits ContentReceipt
Memory Destination Promotion MemoryContentDestination::promote Bound check against limit Sealed handle ownership transfer Replaces visible buffer atomically; leaves previous bytes unchanged on any error

2. Merges and Integration Audit

  • Branch Commits: 3 linear commits (834196cf, e0494292, 7802d898) on base 18b22e36. No internal merge commits exist on the branch.
  • Target Main Divergence (18b22e36..7dde48b2): PR fix: bound Action WAL parent replay and retained states #767 introduced WAL recovery replay bounds in crates/warp-core/src/trusted_runtime_host.rs and docs/topics/WAL.md.
  • Target Integration Diff: PR feat(cas): verify complete objects before atomic output promotion #769 touches exclusively crates/echo-cas, docs/architecture/echo-keep-physical-content-boundary.md, and CHANGELOG.md. Zero overlap with warp-core recovery paths. git merge-tree 18b22e36 7802d898 7dde48b2 completes cleanly with 0 conflicts. No existing callers are rerouted.

3. Claims Line-by-Line Audit

  • Rebuttal of Windows Rename Defect: Confirmed by pinned Rust 1.90 standard library source. Duplicate publication idempotency verified by test.
  • Overlong Rejection Invariant: Confirmed that identity_failure is latched before resource_failure in PrivateContentBuffer::write and takes precedence in failure().
  • Test Isolation Invariant: Confirmed that fresh_disk_fixture loops with fs::create_dir and does not delete or reuse preexisting paths.

4. Constants Against Raw Evidence

Constant / Parameter Declared Location Bound / Value Raw Evidence Coordinate Verified Status
Max Fixture Search Slots tests/physical_content.rs:53 1024 slots k02-fresh-fixture-gate.log Bounded iteration; terminates with AlreadyExists if exhausted
Test Conformance Payload tests/common/physical_content.rs:20 262,145 bytes (256 KiB + 1) k02-fresh-fixture-gate.log Verifies chunk boundary crossing
Worker Build Budget Launch Contract 20 GiB (21,474,836,480 B) Measured: 13,355,391,484 B Pass (62.2% of budget)
Worker Data Budget Launch Contract 4 GiB (4,294,967,296 B) Measured: 4,262,595,068 B Pass (99.2% of budget)
Worker Log Budget Launch Contract 128 MiB (134,217,728 B) Measured: 18,819,936 B Pass (14.0% of budget)
Host Disk Floor Workstation Guard >= 50 GiB free Measured: 727,068,368,896 B Pass (~677 GiB free)
VM Disk Floor Workstation Guard >= 50 GiB free Measured: 691,347,476,480 B Pass (~643 GiB free)

5. Document Figures and Numeric Claims

  • Test Counts:
    • k02-green.log: 34 tests passed (17 unit + 4 disk + 3 physical_content + 10 semantic_retention).
    • k02-fresh-fixture-gate.log: 36 tests passed (17 unit + 4 disk + 5 physical_content + 10 semantic_retention). Two new witnesses added: impossible_staging_budget_does_not_read_source and overlong_reconstruction_is_mismatch_at_any_sufficient_budget.
  • Working Tree File Hashes:
    Every file in the HEAD working tree exactly matches k02-fresh-fixture-gate.manifest.json:
    • CHANGELOG.md: fe418497cc72ddae13cc05c85067d8473c466b8a7ec11823ae899e54d56f8bcb
    • crates/echo-cas/README.md: 701598accf72c8eef0a3973e9839c08038c7064e30b19c2fe45aaad3d80c9b3b
    • crates/echo-cas/src/disk.rs: 641f915138d47eab2e56ead3ee472bd3993c4854e81f2bba8c162e0768dc9f17
    • crates/echo-cas/src/lib.rs: e11a7a5c38c35676a8e44702a61e97272a3ea780296bb5f3622201d2636cd601
    • crates/echo-cas/src/physical_content.rs: 1136f9c1b8f4914e9db9c770b7c8ffe332484e07ec997c3d80edcd0b264d095c
    • crates/echo-cas/tests/common/physical_content.rs: 0db74fe6aa86eaf8a8e30e6a8293bb1d65d7d19c4142a2ac1da9082c5bfd4479
    • crates/echo-cas/tests/physical_content.rs: 28f373eb9737b11a0b2c137cf3cd501cf8b9aed2b539103ece5b46bc418b679b
    • docs/architecture/echo-keep-physical-content-boundary.md: f9cddefbc202943992f55bac16ef731dc6c954732a55ee91d2019bc6f7f6d427

6. State Machine and Error Transitions

  • Preflight Refusal: target.length > byte_limit immediately yields ResourceLimit without source reads or callback execution.
  • Mid-stream Source Interruption: Propagates underlying io::Error directly. Latched failures take precedence.
  • Overlong Output / Swallowed Writer Failure: Callback writing beyond expected_length latches identity_failure = true. reconstruct_quarantined checks staging.failure() before examining callback return, ensuring Mismatch is returned even if the callback swallowed the error.
  • Hash / Length Corruption: Recomputing BLAKE3 on sealed buffer detects truncation or alteration and yields Mismatch. Destination is not touched.
  • Destination Atomic Promotion Failure: TransactionalContentDestination::promote failure returns the operational error while preserving prior visible content.
  • Missing Content: Returns CapabilityUnavailable. No authenticated absence claim is emitted.

7. Repository Standards Audit

  • AGENTS.md / Documentation Rules:
  • Rust Standards:
    • Edition 2021/2024 compliance; strict Clippy with -D warnings passes without warnings.
    • Zero unwrap(), expect(), panic!, or unsafe blocks in library code. Checked constructors and typed errors maintained.

3. Verification Checklist & Coverage Status

Check Item Status Method / Coordinates Evidence / Coverage Notes
All Code Paths Traced Verified Static Inspection (physical_content.rs:1-376) All runtime ingestion, publication, view reconstruction, and destination paths mapped
Merge History Audited Verified Git Tree Audit (git log, git merge-tree) Linear branch (3 commits); clean 3-way merge into target main 7dde48b2
Resolved Review Threads Verified Code Inspection & Thread History All 4 GitHub review threads verified resolved in source
Constants & Budget Limits Verified Manifest & Result Audit Resource limits, timeouts, and byte limits checked against raw logs
Source Hash Parity Verified Python SHA256 Check All 8 working tree files match k02-fresh-fixture-gate.manifest.json
Cargo Test Suite (36 tests) Inspected Sealed Gate (k02-fresh-fixture-gate.log) All 36 CAS tests pass in guarded Linux container
Clippy & Workspace Fmt Inspected Sealed Gate (k02-fresh-fixture-gate.log) -D warnings on Rust 1.90 and cargo fmt --check pass
Git Diff Whitespace Verified Git Read Query (git diff --check) 0 whitespace or formatting errors
Windows Native Execution Unavailable Static Source Inspection Only Verified stdlib source (sys/fs/windows.rs); native Windows kernel execution unrun
Hardware Power-Loss Durability Unavailable Protocol Review Only Explicitly out of scope: receipts declare establishes_durability() == false

APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer audit at7802d898a933e41fdccd7a8e4651a1e295b4e3b8: all complete-object ingestion, publication, borrowed-view, quarantine, sealing and promotion paths were inspected. The shared suite passes on memory and disk, including repeat publication, source/promotion failure, resource refusal and corruption. Impossible budgets refuse before I/O; excess bytes are Mismatch at any sufficient budget. Test roots are exclusively created and never reuse stale directories.

Guarded Docker evidence at the exact candidate:36 CAS tests, strict all-target Clippy on Rust1.90, workspace fmt and whitespace pass. Canonical boundary, package README and changelog describe actual per-object bounds and unsupported evidence. Existing consumers remain compatible.

The Windows rename claim is contradicted by pinned Rust1.90 source; native Windows execution is unrun. The earlier P5 wrapping observation is a lawful diagnostic distinction, independently reconciled by agy: reads preserve stream I/O, while publication preserves existing DiskTier path/operation context. Both retain original causes and carry no content proposition on error.

Current-head independent agy APPROVE includes its full checklist. All four actionable/disputed threads are reconciled. No authenticated absence, pinned filesystem generation, retention, synchronization, crash-durability or aggregate MemoryTier-budget claim is made. Final merge is conditioned on live head, CI, reviews and protections.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add the Echo physical-content port and existing CAS adapters

1 participant