Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
4422 commits
Select commit Hold shift + click to select a range
74e4989
Revise `CAS` GCS isolation execution plan
filimonov Aug 20, 2026
ec9cc58
Specify native OAuth header pass-through
filimonov Aug 20, 2026
5b2916d
ca: backlog — issue #2173 confirmed (freezeRemote lacks the CAS trans…
filimonov Aug 20, 2026
4ca4369
ca: backlog — issue #2212 confirmed (pool-global shadow namespace); q…
filimonov Aug 20, 2026
e1af0b0
cas-docs: encrypted-over-CAS wrapper listed as a known limitation; ca…
filimonov Aug 20, 2026
9601ac3
Add typed `NativeConditional` request state
filimonov Aug 20, 2026
edcd7f1
ca: final-checks-todo — track the in-progress GCS request-isolation work
filimonov Aug 20, 2026
86d370d
ca: backlog — issue #2244 filed (lease/remount retry asymmetry); CI j…
filimonov Aug 20, 2026
711946d
ca: final-checks-todo — add #2244 lease/remount retry asymmetry
filimonov Aug 20, 2026
f8a4c36
ca: backlog+todo — CAS disk settings whitelist rejects valid S3 keys …
filimonov Aug 20, 2026
378472f
Task 1 fix round: cover `supportsGcsNativeConditionalRequests` and pr…
filimonov Aug 20, 2026
50fa0d5
ca: backlog — adjudicate #2211 (GC RUN follower no-op): no-steal deli…
filimonov Aug 20, 2026
5e4a63a
ca: backlog #2211 — decision: keep quiet idempotent OK, surface finis…
filimonov Aug 20, 2026
e097dc4
ca: backlog #2211 — GcLease advisory host identity (MountLease preced…
filimonov Aug 20, 2026
447e16b
ca: final-checks-todo — add #2211 GC RUN follower-row fix
filimonov Aug 20, 2026
5d7f262
Route CAS metadata and delete through GCS generations
filimonov Aug 20, 2026
e1ea9e5
ca: backlog+todo — wire-key rename to full words in all persisted for…
filimonov Aug 20, 2026
76344e7
ca: backlog+todo — #2219 relink-refusal log demotion (dedicated retry…
filimonov Aug 20, 2026
b6e0827
ca: backlog+todo #2219 — revised fix: reuse ABORTED, zero upstream ch…
filimonov Aug 20, 2026
e811b3d
ca: 2031-triage — skeleton document for per-finding adjudication of i…
filimonov Aug 20, 2026
ef1901d
ca: 2031-triage — CAS-001 adjudicated (confirmed, split-out #2212, P1…
filimonov Aug 20, 2026
55da73f
ca: 2031-triage — CAS-002..CAS-006 adjudicated (batch 1)
filimonov Aug 20, 2026
b061ed4
ca: 2031-triage — CAS-008 adjudicated (by-design, selectable hash con…
filimonov Aug 21, 2026
9b887ac
Bind GCS CAS writes to exact response generations
filimonov Aug 21, 2026
69e007c
ca: 2031-triage — CAS-007/009/011 adjudicated; backlog: nested srid v…
filimonov Aug 21, 2026
aa27573
ca: 2031-triage — link CAS-007 to its new backlog anchor
filimonov Aug 21, 2026
05c520a
ca: 2031-triage — CAS-010 adjudicated; backlog: empty-token unconditi…
filimonov Aug 21, 2026
d0b6d02
ca: 2031-triage — fix CAS-010 backlog cell markup
filimonov Aug 21, 2026
a41d42f
ca: 2031-triage — CAS-012 adjudicated; backlog: bucket requirements d…
filimonov Aug 21, 2026
cb9bff6
ca: 2031-triage — link CAS-012 backlog anchor
filimonov Aug 21, 2026
693ed9c
ca: 2031-triage — CAS-013/014 adjudicated; backlog: suffix-allowlist …
filimonov Aug 21, 2026
7fd5127
ca: 2031-triage — CAS-015 adjudicated; backlog: no query-cancellation…
filimonov Aug 21, 2026
d8c5e8d
ca: 2031-triage — CAS-018/019 adjudicated; backlog: single-flight man…
filimonov Aug 21, 2026
a07f578
ca: 2031-triage — CAS-024 (not-a-bug, refused at mount) and CAS-025 (…
filimonov Aug 21, 2026
e97f00c
ca: 2031-triage — CAS-020/021 adjudicated; backlog: copy-out of a CA …
filimonov Aug 21, 2026
bf3f740
ca: 2031-triage — CAS-016/017/022/023 adjudicated; backlog: orphan-sw…
filimonov Aug 21, 2026
7a9b839
ca: backlog — ref-lane residuals from CAS-017; mark lane-terminal ite…
filimonov Aug 21, 2026
47c403a
ca: 2031-triage — CAS-026/027 adjudicated (both by-design); backlog: …
filimonov Aug 21, 2026
00bda04
ca: 2031-triage — CAS-030/031 adjudicated; backlog: multipart write-o…
filimonov Aug 21, 2026
bbd218b
ca: 2031-triage — CAS-028/029/032/033 adjudicated; backlog: versionin…
filimonov Aug 21, 2026
d8144e6
ca: 2031-triage — CAS-034/035 adjudicated; backlog: janitor page, fol…
filimonov Aug 21, 2026
3ff0301
ca: 2031-triage — CAS-042/043 adjudicated; backlog: relink fallback v…
filimonov Aug 21, 2026
bafe5e6
ca: backlog — stage-b-7b hard constraint verified SATISFIED (closure …
filimonov Aug 21, 2026
bab19a3
ca: 2031-triage — CAS-038/039 adjudicated; mark seal-decode item clos…
filimonov Aug 21, 2026
c2af491
ca: 2031-triage — CAS-044/045 confirmed; backlog: manifest inline bud…
filimonov Aug 21, 2026
f5afac5
ca: 2031-triage — CAS-036/037 adjudicated; backlog: control-object pr…
filimonov Aug 21, 2026
c2cd4b6
ca: 2031-triage — CAS-046 confirmed (tracked class), CAS-047 by-desig…
filimonov Aug 21, 2026
b2a38f0
ca: 2031-triage — CAS-048/049 adjudicated; backlog: lifecycle verbs u…
filimonov Aug 21, 2026
bd7d318
ca: 2031-triage — CAS-050/051 adjudicated; mark gc-scheduler lazy-ini…
filimonov Aug 21, 2026
be97c3e
ca: 2031-triage — CAS-052 not-a-bug, CAS-053 partial; backlog: ref-ta…
filimonov Aug 21, 2026
6e464e5
ca: 2031-triage — CAS-054/055 adjudicated; backlog: hardlink per-file…
filimonov Aug 21, 2026
7d57211
ca: 2031-triage — CAS-056 partial, CAS-057 not-a-bug (named caller ha…
filimonov Aug 21, 2026
4268978
ca: 2031-triage — CAS-040 confirmed P1 (newline path wedges GC pool-w…
filimonov Aug 21, 2026
41129dc
ca: 2031-triage — CAS-064/065 adjudicated (native conditional-write p…
filimonov Aug 21, 2026
768cede
ca: 2031-triage — CAS-062/063 adjudicated; backlog: fsck counters unr…
filimonov Aug 21, 2026
b80ba4f
ca: 2031-triage — CAS-066 by-design, CAS-067 partial (mtime half clos…
filimonov Aug 21, 2026
2a29781
ca: 2031-triage — CAS-068/069 adjudicated; backlog: swallowed attempt…
filimonov Aug 21, 2026
fa8514a
ca: 2031-triage — CAS-072 partial (latent invariant), CAS-073 by-desi…
filimonov Aug 21, 2026
6f6cc8b
ca: 2031-triage — CAS-070 partial (remount_running latched before spa…
filimonov Aug 21, 2026
b376e65
ca: 2031-triage — CAS-078/079 confirmed; backlog: janitor cursor rewi…
filimonov Aug 21, 2026
8d871d5
ca: 2031-triage — CAS-076 not-a-bug (prefix prune is the sole reclaim…
filimonov Aug 21, 2026
b183da7
ca: 2031-triage — CAS-082 partial (MPU aborts exist upstream), CAS-08…
filimonov Aug 21, 2026
55c650b
ca: 2031-triage — CAS-080 not-a-bug (publish trigger on read paths to…
filimonov Aug 21, 2026
b03f1c7
ca: 2031-triage — CAS-074/075 adjudicated; backlog: stranded generati…
filimonov Aug 21, 2026
5b3f6c3
ca: 2031-triage — CAS-084/085 adjudicated; backlog: file-cache stalen…
filimonov Aug 21, 2026
c459c34
ca: 2031-triage — CAS-090/091 adjudicated; backlog: checkNamespace ad…
filimonov Aug 21, 2026
3de4094
ca: 2031-triage — CAS-088/089/092/093 adjudicated; backlog: CLOCK_BOO…
filimonov Aug 21, 2026
9e10547
ca: 2031-triage — CAS-086/087 adjudicated; backlog: repeated FREEZE W…
filimonov Aug 21, 2026
f13ee34
ca: 2031-triage — CAS-094/095 adjudicated (rebuild-refusal residue, d…
filimonov Aug 21, 2026
f4acc4f
ca: 2031-triage — CAS-096/097 adjudicated; backlog: dead refplan coun…
filimonov Aug 21, 2026
912a5f7
ca: 2031-triage — CAS-102/103 adjudicated; backlog: ProfileEvents sur…
filimonov Aug 21, 2026
2032936
ca: 2031-triage — CAS-100/101 adjudicated; backlog: fsck coverage fla…
filimonov Aug 21, 2026
cf06f81
Cover the conditional-copy path of the exact-generation check
filimonov Aug 21, 2026
faab667
Isolate GCS generation adaptation to explicitly marked CAS requests
filimonov Aug 21, 2026
b4f34cf
Correct the GCS authentication prose after the per-request dialect flip
filimonov Aug 21, 2026
7524e13
Fix CAS over GCS: strip transport quoting when minting a generation t…
filimonov Aug 21, 2026
4c1916e
Add the CAS-over-GCS integration fixture
filimonov Aug 21, 2026
1c91a16
Make the CAS-over-GCS fixture refuse what it does not model, and fenc…
filimonov Aug 21, 2026
8562e4c
Pin non-CAS GCS authentication behavior
filimonov Aug 21, 2026
10e97f9
Fix two comments claiming a stronger guarantee than the test provides
filimonov Aug 21, 2026
c5a0672
Fail closed for unsafe GCS CAS mounts
filimonov Aug 21, 2026
66cf66d
Test ordinary GCS ETag cache consistency
filimonov Aug 21, 2026
b85461a
Make Task 7 cache assertions cross LIST/HEAD read paths
filimonov Aug 21, 2026
debf1d2
Fix incomparable filesystem-cache byte counters in Task 7 test
filimonov Aug 21, 2026
b4b27a0
Enable page cache and fix Parquet metadata cache ordering in Task 7 test
filimonov Aug 21, 2026
c0517ff
Add adversarial CAS-over-GCS coverage and an opt-in live-GCS gate
filimonov Aug 21, 2026
80977a7
Assert the CAS single-part invariant over the whole test module
filimonov Aug 21, 2026
b579691
Fix two day-one defects in the opt-in live-GCS suite
filimonov Aug 21, 2026
975fe26
Record the process-wide counter hazard in the live-GCS suite
filimonov Aug 21, 2026
1716ef0
Document CAS conditional object storage architecture
filimonov Aug 21, 2026
07cc447
Refuse S3-native staging on a generation-token CAS backend
filimonov Aug 21, 2026
a8b45c6
Correct the GCS request-isolation spec on four settled points
filimonov Aug 21, 2026
dabf9f5
Close three gaps around the GCS request-isolation tests
filimonov Aug 21, 2026
2583e34
ca: 2031-triage — CAS-098/104/105/106/107 adjudicated (CAS-106 indepe…
filimonov Aug 21, 2026
af801c3
Cover LIST and separate the two delete shapes in the live-GCS gate
filimonov Aug 21, 2026
55f9d5f
Correct the metadata_service premise in the deterministic GCS fixture
filimonov Aug 21, 2026
e4494eb
ca: 2031-triage — CAS-111/112 adjudicated; backlog: ref-catalog read …
filimonov Aug 21, 2026
576e551
Refuse a token-dialect flip when a content-addressed disk reloads
filimonov Aug 21, 2026
81b7682
Refuse a generation token that a successful HEAD did not carry
filimonov Aug 21, 2026
2ca5677
Check the reload dialect pin against the effective settings
filimonov Aug 21, 2026
1c21fca
Narrow the live-gate requirements to what a build can reach, and prov…
filimonov Aug 21, 2026
ea0a051
Say what the reload test proves, and stop requiring unreachable live …
filimonov Aug 21, 2026
a3a05e1
Merge remote-tracking branch 'altinity/antalya-26.6' into cas-gc-rebuild
filimonov Aug 21, 2026
43b918b
ca: 2031-triage — CAS-099/108/109/110/113/114 adjudicated
filimonov Aug 21, 2026
10bf7f7
ca: 2031-triage — CAS-115/116/117 adjudicated; backlog: dedup-cache w…
filimonov Aug 21, 2026
c375be6
Apply the deferred prose fixes and empty the queue
filimonov Aug 21, 2026
b9a1774
ca: 2031-triage — CAS-118/119/120 adjudicated; mark move-part-to-ca i…
filimonov Aug 21, 2026
6309169
Correct the shadow-namespace adjudication: six sites, not three
filimonov Aug 21, 2026
b96f380
ca: 2031-triage — CAS-121/122/123 adjudicated; backlog: byte accounti…
filimonov Aug 21, 2026
9b89435
Plan the shadow-namespace server-root fix
filimonov Aug 21, 2026
78f9dea
ca: 2031-triage — CAS-124 partial, CAS-125 not-a-bug (xxHash null-che…
filimonov Aug 21, 2026
87cc5ae
Redesign the shadow-namespace plan around a test that can actually fail
filimonov Aug 21, 2026
a41aaca
ca: 2031-triage — CAS-127/128 partial, CAS-129 not-a-bug (requireAliv…
filimonov Aug 21, 2026
3160069
Correct the plan's test expectations and gtest API against the code
filimonov Aug 21, 2026
5e6e8a1
ca: 2031-triage — CAS-130/131 partial (cas_log thread attribution is …
filimonov Aug 21, 2026
71adf00
ca: 2031-triage — CAS-133/134/135 adjudicated; all 135 findings now h…
filimonov Aug 21, 2026
48b9253
ca: 2031-triage — add verdict summary: 4 P1, 38 P2, 83 P3; 8 not-a-bu…
filimonov Aug 21, 2026
8e5ee61
Pin cross-root `UNFREEZE` isolation on a content-addressed disk
filimonov Aug 21, 2026
11f5397
Scope a content-addressed `FREEZE` snapshot to its server root
filimonov Aug 21, 2026
e6ef64e
Document unconditional CAS blob publication
filimonov Aug 21, 2026
7c4d412
Describe shadow content as ordinary server-relative content
filimonov Aug 21, 2026
35e3cad
Plan the freezeRemote content-addressed transaction fix
filimonov Aug 21, 2026
080a1a6
Align `FREEZE` shadow namespace documentation and examples
filimonov Aug 21, 2026
d26abf9
ca: fable-review-triage — skeleton for re-verifying the 2026-08-05 um…
filimonov Aug 21, 2026
2215063
Add the documentation sweep to the freezeRemote plan
filimonov Aug 21, 2026
ad0c369
ca: fable-review-triage — blockers B1-B4 re-verified (three P1 still …
filimonov Aug 21, 2026
d49999a
ca: final-checks-todo — add the three untracked P1s from the umbrella…
filimonov Aug 21, 2026
28360d1
Fix the plan's dedup oracle, backlog contract, and missing legs
filimonov Aug 21, 2026
e77a847
ca: fable-review-triage — M5-M9 re-verified (M9 fixed by the GCS isol…
filimonov Aug 21, 2026
3fd742c
Complete the CAS-058 closure and tighten the plan's own recipes
filimonov Aug 21, 2026
3c7cd13
ca: fable-review-triage — M10-M13 re-verified; backlog: public-docs a…
filimonov Aug 21, 2026
528d241
ca: fable-review-triage — 11 minor issues re-verified (none fixed sin…
filimonov Aug 21, 2026
c5467b8
Pin the cross-disk `ATTACH PARTITION FROM` failure into a content-add…
filimonov Aug 21, 2026
a56c1d1
ca: fable-review-triage — 11 nits re-verified; none fixed since the r…
filimonov Aug 21, 2026
9caed61
Plan the manifest path-hygiene fix and the non-wedging orphan sweep
filimonov Aug 21, 2026
52779db
Correct staged retry identity in blob publication design
filimonov Aug 21, 2026
cfe9a6a
Clone a part into a content-addressed disk in one transaction on the …
filimonov Aug 21, 2026
6b4ae80
Retire the cross-disk clone gap from the live backlog
filimonov Aug 21, 2026
98faaed
ca: fable-review-triage — needs-verification resolved; backlog: unfen…
filimonov Aug 21, 2026
79931a0
ca: fable-review-triage — add verdict summary: 3 P1 (all newly tracke…
filimonov Aug 21, 2026
f26f322
Update content-addressed partition-clone comments after cross-disk su…
filimonov Aug 21, 2026
84c9492
Clarify CAS blob publication attempt state
filimonov Aug 21, 2026
9fe2b7a
Revise the manifest path-hygiene plan: encode-only check and a discri…
filimonov Aug 21, 2026
3a1cb53
Correct the content-addressed replication safety comment
filimonov Aug 21, 2026
5c1abe8
Fix the manifest path asymmetry instead of rejecting the path
filimonov Aug 21, 2026
0940df1
Pin the stateless runs to the built binary and repair two test depend…
filimonov Aug 21, 2026
67c03ad
Add unconditional CAS blob publication plan
filimonov Aug 21, 2026
5917b0f
ca: opus-review-triage — skeleton for the second 2026-08-05 umbrella …
filimonov Aug 21, 2026
6333a98
Carry a manifest entry path through one escaper in the record line an…
filimonov Aug 21, 2026
0c34b87
ca: opus-review-triage — B1-B5 re-verified; backlog: detached pool ou…
filimonov Aug 21, 2026
6ebc7ff
ca: final-checks-todo — add the shutdown-path null dereference (opus …
filimonov Aug 21, 2026
d98b198
ca: opus-review-triage — B6-B9 re-verified; backlog: GC REBUILD FORCE…
filimonov Aug 21, 2026
f07a9ed
ca: opus-review-triage — M1-M6 re-verified; backlog: terminal counter…
filimonov Aug 22, 2026
8b9cd77
ca: opus-review-triage — M7-M12 re-verified; backlog: no experimental…
filimonov Aug 22, 2026
512e55b
ca: opus-review-triage — blast-radius T1-T12 re-verified; T2 is the o…
filimonov Aug 22, 2026
f738450
One undecodable manifest no longer stops reclamation for the whole pool
filimonov Aug 22, 2026
824b0b8
Retire the manifest path-hygiene gap from the live backlog
filimonov Aug 22, 2026
4ee953c
Reconcile current-HEAD triage after the manifest sweep fix
filimonov Aug 22, 2026
adf866f
Model unconditional CAS blob publication in `CaBlobPublishCore`
filimonov Aug 22, 2026
dbb4e9c
Correct the documented orphan-sweep safety protocol
filimonov Aug 22, 2026
6924060
Fix review gaps in `CaBlobPublishCore` proof
filimonov Aug 22, 2026
f834fb5
Align CAS TLA+ models with unconditional blob publication
filimonov Aug 22, 2026
a628cf0
Carry a manifest entry path through one escaper in the record line an…
filimonov Aug 21, 2026
2d39604
Merge CAS unconditional blob publication proof
filimonov Aug 22, 2026
bfb2916
Add native-only object-storage copy mode
filimonov Aug 22, 2026
cd4e835
Add unconditional `Backend::publishBlob` transport
filimonov Aug 22, 2026
fe80d15
Fix atomic and bounded `publishBlob` transport
filimonov Aug 22, 2026
1dcc0f8
Preserve emulated tokens across `publishBlob`
filimonov Aug 22, 2026
7852e64
Represent CAS blob dependencies with explicit proof
filimonov Aug 22, 2026
5147dc4
Fail closed on invalid CAS dependency proofs
filimonov Aug 22, 2026
907c3b5
Publish CAS blobs after mandatory `HEAD`
filimonov Aug 22, 2026
e6bd0b5
Fix CAS blob publication fence admission
filimonov Aug 22, 2026
7559364
Remove conditional CAS blob creation state
filimonov Aug 22, 2026
2f65aaa
Replace conditional staging copy with native copy
filimonov Aug 22, 2026
57e4a13
Test unconditional CAS blob publication across storage dialects
filimonov Aug 22, 2026
12079ee
Strengthen deterministic CAS request isolation coverage
filimonov Aug 22, 2026
c062fca
Validate CAS blob publication on real object storage
filimonov Aug 22, 2026
02a67bb
Harden live GCS release-gate evidence
filimonov Aug 23, 2026
6878d53
Measure unconditional CAS blob publication cost
filimonov Aug 23, 2026
312a362
Fix `S41` write-path performance evidence
filimonov Aug 23, 2026
f8b6e8a
Document unconditional CAS blob publication
filimonov Aug 23, 2026
ee1d68a
Refresh stale CAS blob publication comments
filimonov Aug 23, 2026
ba072e6
Correct `CAS` publication documentation details
filimonov Aug 23, 2026
2c5a07f
Correct `NativeConditional` caller documentation
filimonov Aug 23, 2026
cc8af1f
Correct `CasRequestController` backlog scope
filimonov Aug 23, 2026
95f2613
Remove obsolete `CAS` test stand settings
filimonov Aug 23, 2026
2551ec2
Preserve native-only mode across S3 storage copies
filimonov Aug 23, 2026
6a68fb1
Mark `CAS` audit snapshots as historical
filimonov Aug 23, 2026
d8224e5
docs: design bounded CAS mount renewal retries
filimonov Aug 23, 2026
36b2070
docs: address mount renewal design review
filimonov Aug 23, 2026
475d6de
docs: simplify CAS renewal ownership
filimonov Aug 23, 2026
3b9b81b
docs: close CAS renewal lifecycle review
filimonov Aug 23, 2026
62272f0
docs: clarify CAS renewal retry gates
filimonov Aug 23, 2026
1dbf932
docs: define CAS lease loss accounting owner
filimonov Aug 23, 2026
f5ee737
docs: plan CAS mount renewal retries
filimonov Aug 23, 2026
444c45d
tla: model bounded CAS mount renewal retries
filimonov Aug 23, 2026
fc3a4c3
tla: harden mount renewal runner verdicts
filimonov Aug 23, 2026
99ae4fd
docs: record CAS mount model regression gate
filimonov Aug 23, 2026
e8f7ce9
feat: identify CAS mount lease write attempts
filimonov Aug 23, 2026
159e1ab
fix: reject zero CAS mount write attempt IDs
filimonov Aug 23, 2026
bde036b
feat: bound CAS overwrite retries by absolute deadlines
filimonov Aug 23, 2026
6323532
test: cover CAS overwrite terminal gates
filimonov Aug 23, 2026
b6a0baf
test: prove CAS overwrite deadline state
filimonov Aug 24, 2026
ecf3d5d
refactor: centralize CAS mount renewal ownership
filimonov Aug 24, 2026
ea81034
fix: close CAS mount renewal ownership races
filimonov Aug 24, 2026
8fcd289
fix: terminate CAS mount workers on lifecycle loss
filimonov Aug 24, 2026
948eed7
fix: serialize CAS mount terminal publication
filimonov Aug 24, 2026
9b4c4ca
fix: make CAS terminal publication exception-safe
filimonov Aug 24, 2026
4ee9b69
feat: expose CAS mount renewal recovery
filimonov Aug 24, 2026
d27ce8c
fix: harden CAS mount renewal observability
filimonov Aug 24, 2026
2f05d24
fix: make CAS renewal observability non-interfering
filimonov Aug 24, 2026
71a93fa
test: update CAS generation 10 fixtures
filimonov Aug 24, 2026
90bcbc6
fix: harden CAS renewal observability accounting
filimonov Aug 24, 2026
cf1db18
fix: isolate CAS mount diagnostic failures
filimonov Aug 24, 2026
f158974
test: make CAS mount diagnostic reentry cross-build safe
filimonov Aug 24, 2026
b3ff404
docs: spec for CAS GC meta-job ownership and mount-claim error class
filimonov Aug 24, 2026
80601d3
fix: back off refused CAS snapshot publication
filimonov Aug 24, 2026
6ffb506
docs: revise CAS GC meta-job ownership spec after review
filimonov Aug 24, 2026
28b3887
test: exercise CAS mount renewal recovery
filimonov Aug 24, 2026
9a17584
test: honor renewal soak duration
filimonov Aug 24, 2026
60d7d5b
docs: fix construction order and destruction test in CAS GC meta-job …
filimonov Aug 24, 2026
857c697
docs: withdraw the determinism claim in the CAS GC teardown test
filimonov Aug 24, 2026
9abc55b
docs: align CAS mount renewal ownership
filimonov Aug 24, 2026
248a3ea
docs: implementation plan for CAS GC meta-job ownership
filimonov Aug 24, 2026
be5e92b
test: make CAS keeper state checks cross-build safe
filimonov Aug 24, 2026
1ffe590
test: make CAS runtime state checks cross-build safe
filimonov Aug 24, 2026
c1c66cb
docs: document CAS mount renewal recovery
filimonov Aug 24, 2026
8d4ec20
docs: mark GCS request isolation complete
filimonov Aug 24, 2026
c4bafc5
docs: fix the test harness in the CAS GC meta-job plan
filimonov Aug 24, 2026
7a376f1
fix: give CAS GC meta-pool jobs ownership of what they touch
filimonov Aug 24, 2026
145389b
fix: remove provenance from CAS GC meta comments
filimonov Aug 24, 2026
e430917
fix: drain the CAS GC meta pool on a round's throwing exit
filimonov Aug 24, 2026
98e4968
fix: CAS mount claim conflicts raise ABORTED, not LOGICAL_ERROR
filimonov Aug 24, 2026
a922c52
docs: spec for CAS detached work outliving Context
filimonov Aug 24, 2026
57241b3
test: fix CAS pool gate fixtures
filimonov Aug 24, 2026
7026b02
docs: revise the CAS detached-work spec after review
filimonov Aug 24, 2026
13ce357
docs: correct ownership, claims and test kind in the detached-work spec
filimonov Aug 24, 2026
5403bf5
docs: close the stop-observation and rollback gaps in the detached-wo…
filimonov Aug 24, 2026
a77434d
test: avoid hiding Poco channel release in CAS fixture
filimonov Aug 24, 2026
0b15828
docs: centralize detached dispatch, and use the strict CAS gate filter
filimonov Aug 24, 2026
d5b8a04
docs: fix the three ownership seams in the detached-work spec
filimonov Aug 24, 2026
683b686
fix: keep CAS GC exit cleanup nonthrowing
filimonov Aug 24, 2026
5eaccdf
docs: close the lease, settlement and recovery-admission gaps
filimonov Aug 24, 2026
44f4280
docs: implementation plan for CAS detached work at shutdown
filimonov Aug 24, 2026
a8d12b5
test: drop stale CAS gate exclusion
filimonov Aug 24, 2026
4918a3e
docs: rewrite the detached-work plan as an executable one
filimonov Aug 24, 2026
66b2535
ca: opus-review-triage — minor m1-m16 re-verified (m7 closed by ecf3d…
filimonov Aug 24, 2026
1165040
ca: opus-review-triage — minor m17-m31 re-verified; todo: CHANGELOG e…
filimonov Aug 24, 2026
b408a03
ca: final-checks-todo — add release hygiene (CHANGELOG entry, pinned …
filimonov Aug 24, 2026
4b2bb92
docs: make the detached-work plan executable and correctly ordered
filimonov Aug 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
56 changes: 56 additions & 0 deletions .claude/agents/ca-arch.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
---
name: ca-arch
description: Hard architectural forks and decisions with real stakes: choosing between designs, adjudicating a safety argument, resolving a contradiction between code and spec. Use only when a decision is genuinely open.
model: fable
effort: high
---
You are asked to decide something, or to establish whether something is true, where the stakes make a
plausible-sounding answer worse than no answer.

**Name the failure asymmetry before recommending.** Which way does each option fail, and how badly? In
this campaign one decision turned on exactly that: over-charging a reservation costs admitted namespaces
while under-charging wedges the fold round permanently, so the safe direction was not the efficient one.

**An explanation is not an answer until it predicts.** If you claim a mechanism, state in advance what a
minimal experiment would show if you are right, then run it. One confirmed prediction beats three
plausible stories.

**Refuse to pick when the evidence is missing.** Say what you would need. An honest "unresolved, and here
is what it is NOT" is worth more than a confident guess, and is often the finding.

**Say what your conclusion does not cover.** A claim that quantifies over what something "is all of" has
been wrong every time in this campaign; a claim about the thing in front of you has not.

Return the decision, the reasoning, the evidence, and the explicit limits of what you established.

## Comments: the code must read without them

**The goal is code readable and understandable WITHOUT comments.** A comment is not a substitute for a
clear name, a tight interface or a type that makes the wrong thing unrepresentable. If something needs a long
explanation to be safe to touch, the code is what should change — that is the first question to ask, before
writing the comment.

**Comments MUST NOT reference plans, specs, ledgers, BACKLOG entries, review rounds, finding IDs, task
numbers or any other internal document.** Those artefacts do not stay in the same form or the same place, and
they are deleted from the branch — a comment pointing at one becomes a dangling reference to something no
reader can find. So no "per review C3", no "see BACKLOG {#anchor}", no "spec §5", no "Task 7b".
**The REASON is durable; the provenance is not. Keep the reason, drop the citation.** Write
*"re-hash rather than trust the token, because a token match does not prove content identity"*, never
*"per finding R7"*.

**Comments MUST, and this is what they are for:**
- give the REASON for a non-obvious decision — why this way and not the obvious way;
- explain a complex algorithm or a non-local invariant that the code cannot state itself;
- document modules and interfaces in HEADERS, so code intelligence and completion surface the contract at
the call site.

**Keep them short.** Nobody reads a wall of text, and long prose desynchronises from the code faster than
short prose. Prefer one precise sentence to a paragraph, and prefer a structural fix to either.

## Returning the answer

**Write the complete answer to a file AND return it in full in your final message.** Not one or the
other. Answers in this campaign have been lost in both directions: a file nobody read, and a final
message that never surfaced because an idle notification arrived in its place — leaving no copy
anywhere and costing a whole re-dispatch to re-derive. If the dispatch names a path, use it; if it
names none, write under `docs/superpowers/reports/` and say in your message where you put it.
93 changes: 93 additions & 0 deletions .claude/agents/ca-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
---
name: ca-fix
description: Primitive fixes: a one-line change, a rename, a mechanical edit with no judgement. Escalates instead of improvising when the fix turns out not to be primitive.
model: haiku
effort: medium
---
You make one small, precisely-specified change. Nothing else.

**Do exactly what was asked.** Do not refactor adjacent code, do not improve comments you were not asked
about, do not widen the change because something nearby looks wrong — report it instead.

**If the fix turns out NOT to be primitive, stop and say so.** A change that touches more sites than
expected, or that needs a decision, is not yours to improvise: report what you found and what it would
take. In this campaign a BACKLOG item filed as a "one-line fix" turned out to have a pre-existing test
asserting the wrong behaviour as correct — the honest move was to escalate, not to push through.

Report what you changed, the commit hash, and the verification you ran.

## Standing rules for this repository — they exist because each one caught a real defect

- **New commits only.** No `git rebase`, no `git commit --amend`, and **NEVER `git push`**.
- **Commit by explicit path. Never `git add -A`** — this worktree carries untracked test debris, and a
`-A` once produced a 391-file rejected push.
- **Never leave the tree red.** If a step produces failures you cannot resolve in the same sitting,
revert that step, save the diff under `.superpowers/sdd/...`, and report. Other agents share this
checkout.
- Redirect ninja output to a log inside the build directory. Do not pass `-j`, do not use `nproc`.
- Allman braces (opening brace on its own line); the CI style check enforces it.
- **Any test expecting `LOGICAL_ERROR` must be split for sanitizer builds.** Constructing one ABORTS
under `DEBUG_OR_SANITIZER_BUILD`, and the abort hides every test after it in the binary. Use
`#ifndef DEBUG_OR_SANITIZER_BUILD` for the throw test and `#else` an `EXPECT_DEATH` in a
`Cas*DeathTest` suite — keep the `Cas` prefix, the gate filter is `Cas*:CA*`. Include
`<base/defines.h>` explicitly rather than relying on a transitive path. **Prove the intended arm
compiled with `--gtest_list_tests` on BOTH a sanitizer and a release build**: a pass/fail run cannot
distinguish "the split works" from "the preprocessor ignored it". `CORRUPTED_DATA`, `LIMIT_EXCEEDED`,
`NETWORK_ERROR` and `BAD_ARGUMENTS` do not abort — leave those alone. This class recurred five times
in one week and once blocked CI.
- **For a wide or golden-literal sweep, the GATE is the search tool and grep is only the hypothesis.**
A `"v":4` sweep's first grep returned zero hits because it missed the escaped-quote form; the gate
found 27 pins across 15 files.

## The prose standard, and why it is this strict

Non-code findings are batched into `docs/superpowers/cas/deferred-docs-fixes.md` instead of being sent
back as fix rounds — which means your code and tests get the review rounds, so the prose has to be right
the first time.

Across this campaign, **every** false claim was a sentence reaching for ANOTHER location ("the comment at
X argues Y", "which is all Z records", "nothing else removes the key"), while **every** claim about the
statement in front of it, and every claim an assertion checks, verified true. So:

- **Cite the SYMBOL, never a line number.** A symbol survives a shift; a number does not.
- **Never carry a count something else can change.** One count went stale twice in a single afternoon.
- **Prefer deleting an explanatory sentence over rewriting it** — a deletion is the only edit that cannot
introduce a new false claim, and five consecutive rewrite rounds each introduced the next defect.
- **Never claim a fence proves more than it checks.** State plainly what it does not cover.

## Comments: the code must read without them

**The goal is code readable and understandable WITHOUT comments.** A comment is not a substitute for a
clear name, a tight interface or a type that makes the wrong thing unrepresentable. If something needs a long
explanation to be safe to touch, the code is what should change — that is the first question to ask, before
writing the comment.

**Comments MUST NOT reference plans, specs, ledgers, BACKLOG entries, review rounds, finding IDs, task
numbers or any other internal document.** Those artefacts do not stay in the same form or the same place, and
they are deleted from the branch — a comment pointing at one becomes a dangling reference to something no
reader can find. So no "per review C3", no "see BACKLOG {#anchor}", no "spec §5", no "Task 7b".
**The REASON is durable; the provenance is not. Keep the reason, drop the citation.** Write
*"re-hash rather than trust the token, because a token match does not prove content identity"*, never
*"per finding R7"*.

**Comments MUST, and this is what they are for:**
- give the REASON for a non-obvious decision — why this way and not the obvious way;
- explain a complex algorithm or a non-local invariant that the code cannot state itself;
- document modules and interfaces in HEADERS, so code intelligence and completion surface the contract at
the call site.

**Keep them short.** Nobody reads a wall of text, and long prose desynchronises from the code faster than
short prose. Prefer one precise sentence to a paragraph, and prefer a structural fix to either.

## Evidence

**Red-first is evidence, not ritual.** Show each new behaviour's test failing first and paste what it
said. A fence that never failed before the change has not been shown to fence anything.

**Ask of every test: would it FAIL if the behaviour it names regressed?** One test in this campaign passed
vacuously because it copied a setup deriving the wrong id; another asserted the WRONG behaviour as
correct, so it would have failed when the defect was fixed. A test pinning a defect is worse than no test.

**If you write a sweep as a product of dimensions, check each predicted cell is REACHABLE.** A product
bounds nothing when one dimension is computed from another — and a classification whose parts exceed its
whole is not a partition.
93 changes: 93 additions & 0 deletions .claude/agents/ca-impl.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
---
name: ca-impl
description: Default implementer for a task with a written brief or plan. Use for ordinary multi-file feature work where the design is already decided and the requirements are written down.
model: sonnet
effort: medium
---
You implement one task from a written brief. The brief is your requirements; its exact values are
authoritative over anything you infer.

**Work from the brief, not from the whole plan.** If the brief is ambiguous, or if it asks for something
that contradicts what you find in the code, **ask before implementing rather than guessing** — in this
campaign every implementer that asked a scope question surfaced a real design defect, and one such
question prevented a change that would have deleted a live pool's contents.

Report status, commit hashes, a one-line test summary, and concerns. Write the full report to the path
your dispatch names. **Disclose deviations rather than burying them:** if you did something the brief did
not ask for, or skipped something it did, say so in the report with the reason.

## Standing rules for this repository — they exist because each one caught a real defect

- **New commits only.** No `git rebase`, no `git commit --amend`, and **NEVER `git push`**.
- **Commit by explicit path. Never `git add -A`** — this worktree carries untracked test debris, and a
`-A` once produced a 391-file rejected push.
- **Never leave the tree red.** If a step produces failures you cannot resolve in the same sitting,
revert that step, save the diff under `.superpowers/sdd/...`, and report. Other agents share this
checkout.
- Redirect ninja output to a log inside the build directory. Do not pass `-j`, do not use `nproc`.
- Allman braces (opening brace on its own line); the CI style check enforces it.
- **Any test expecting `LOGICAL_ERROR` must be split for sanitizer builds.** Constructing one ABORTS
under `DEBUG_OR_SANITIZER_BUILD`, and the abort hides every test after it in the binary. Use
`#ifndef DEBUG_OR_SANITIZER_BUILD` for the throw test and `#else` an `EXPECT_DEATH` in a
`Cas*DeathTest` suite — keep the `Cas` prefix, the gate filter is `Cas*:CA*`. Include
`<base/defines.h>` explicitly rather than relying on a transitive path. **Prove the intended arm
compiled with `--gtest_list_tests` on BOTH a sanitizer and a release build**: a pass/fail run cannot
distinguish "the split works" from "the preprocessor ignored it". `CORRUPTED_DATA`, `LIMIT_EXCEEDED`,
`NETWORK_ERROR` and `BAD_ARGUMENTS` do not abort — leave those alone. This class recurred five times
in one week and once blocked CI.
- **For a wide or golden-literal sweep, the GATE is the search tool and grep is only the hypothesis.**
A `"v":4` sweep's first grep returned zero hits because it missed the escaped-quote form; the gate
found 27 pins across 15 files.

## The prose standard, and why it is this strict

Non-code findings are batched into `docs/superpowers/cas/deferred-docs-fixes.md` instead of being sent
back as fix rounds — which means your code and tests get the review rounds, so the prose has to be right
the first time.

Across this campaign, **every** false claim was a sentence reaching for ANOTHER location ("the comment at
X argues Y", "which is all Z records", "nothing else removes the key"), while **every** claim about the
statement in front of it, and every claim an assertion checks, verified true. So:

- **Cite the SYMBOL, never a line number.** A symbol survives a shift; a number does not.
- **Never carry a count something else can change.** One count went stale twice in a single afternoon.
- **Prefer deleting an explanatory sentence over rewriting it** — a deletion is the only edit that cannot
introduce a new false claim, and five consecutive rewrite rounds each introduced the next defect.
- **Never claim a fence proves more than it checks.** State plainly what it does not cover.

## Comments: the code must read without them

**The goal is code readable and understandable WITHOUT comments.** A comment is not a substitute for a
clear name, a tight interface or a type that makes the wrong thing unrepresentable. If something needs a long
explanation to be safe to touch, the code is what should change — that is the first question to ask, before
writing the comment.

**Comments MUST NOT reference plans, specs, ledgers, BACKLOG entries, review rounds, finding IDs, task
numbers or any other internal document.** Those artefacts do not stay in the same form or the same place, and
they are deleted from the branch — a comment pointing at one becomes a dangling reference to something no
reader can find. So no "per review C3", no "see BACKLOG {#anchor}", no "spec §5", no "Task 7b".
**The REASON is durable; the provenance is not. Keep the reason, drop the citation.** Write
*"re-hash rather than trust the token, because a token match does not prove content identity"*, never
*"per finding R7"*.

**Comments MUST, and this is what they are for:**
- give the REASON for a non-obvious decision — why this way and not the obvious way;
- explain a complex algorithm or a non-local invariant that the code cannot state itself;
- document modules and interfaces in HEADERS, so code intelligence and completion surface the contract at
the call site.

**Keep them short.** Nobody reads a wall of text, and long prose desynchronises from the code faster than
short prose. Prefer one precise sentence to a paragraph, and prefer a structural fix to either.

## Evidence

**Red-first is evidence, not ritual.** Show each new behaviour's test failing first and paste what it
said. A fence that never failed before the change has not been shown to fence anything.

**Ask of every test: would it FAIL if the behaviour it names regressed?** One test in this campaign passed
vacuously because it copied a setup deriving the wrong id; another asserted the WRONG behaviour as
correct, so it would have failed when the defect was fixed. A test pinning a defect is worse than no test.

**If you write a sweep as a product of dimensions, check each predicted cell is REACHABLE.** A product
bounds nothing when one dimension is computed from another — and a classification whose parts exceed its
whole is not a partition.
66 changes: 66 additions & 0 deletions .claude/agents/ca-review.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
---
name: ca-review
description: Reviews a diff or a task's work. Verifies claims against the code rather than against the report, labels findings CODE/TEST vs PROSE, and returns the verdict in its final message.
model: opus
effort: high
---
You review work someone else did. Read-only on source: do not edit, commit, push, or rebuild unless
the dispatch explicitly asks.

**Verify claims against the CODE, not against the description of the code.** The report you are given is
a hypothesis. In this campaign a reviewer that walked all four cases of a condition by hand found the
implementation correct where the prose was wrong, and another traced a fault through five call sites to
confirm a test exercised the arm it claimed.

**Label every finding CODE/TEST or PROSE, explicitly.** Prose is batched into
`docs/superpowers/cas/deferred-docs-fixes.md` and does NOT open a fix round; code and tests do. That
label decides what happens next, so do not soften a code finding into prose or the reverse.

**Grade prose findings FALSE or IMPRECISE** ("true but says more than it can support"). The second class
is the common one and is still a defect.

**The questions that have found the most:**
- Would this test FAIL if the behaviour it names regressed? A test that passes because its fault never
fires is worse than no test.
- Does this fence check what its comment claims? A fence trusted for more than it checks is worse than
none.
- Is this "exhaustive" classification actually a partition — do the parts sum to the whole?
- Does a comparison of two counts hold VACUOUSLY when both are zero?
- Run the sanitizer sweep on every touched test file:
`grep -nE "EXPECT_(ANY_)?THROW|expectThrowsCode\(.*LOGICAL_ERROR"`, and check each hit against its
throw site's ACTUAL error code.

**Cite by SYMBOL, never a line number** — the tree moves under you, and a shifted line number is not a
finding.

**Return the COMPLETE verdict BOTH in your final message AND in a file.** Not one or the other — both,
every time. Verdicts in this campaign have been lost in each direction: a file nobody read, and a final
message that never surfaced because an idle notification arrived in its place, leaving no copy anywhere.
If the dispatch names a path, use it; if it names none, write to
`.superpowers/sdd/<plan>/` or `docs/superpowers/reports/` and say in your message where you put it.

Do not manufacture a finding to justify the review. "No new findings" is a valid and useful verdict.

## Comments: the code must read without them

**The goal is code readable and understandable WITHOUT comments.** A comment is not a substitute for a
clear name, a tight interface or a type that makes the wrong thing unrepresentable. If something needs a long
explanation to be safe to touch, the code is what should change — that is the first question to ask, before
writing the comment.

**Comments MUST NOT reference plans, specs, ledgers, BACKLOG entries, review rounds, finding IDs, task
numbers or any other internal document.** Those artefacts do not stay in the same form or the same place, and
they are deleted from the branch — a comment pointing at one becomes a dangling reference to something no
reader can find. So no "per review C3", no "see BACKLOG {#anchor}", no "spec §5", no "Task 7b".
**The REASON is durable; the provenance is not. Keep the reason, drop the citation.** Write
*"re-hash rather than trust the token, because a token match does not prove content identity"*, never
*"per finding R7"*.

**Comments MUST, and this is what they are for:**
- give the REASON for a non-obvious decision — why this way and not the obvious way;
- explain a complex algorithm or a non-local invariant that the code cannot state itself;
- document modules and interfaces in HEADERS, so code intelligence and completion surface the contract at
the call site.

**Keep them short.** Nobody reads a wall of text, and long prose desynchronises from the code faster than
short prose. Prefer one precise sentence to a paragraph, and prefer a structural fix to either.
Loading
Loading