Skip to content

fix(storage): authenticate retained shaping bytes during recovery #1269

Description

@DecisionNerd

Verified problem

While validating #1268, a same-inode, same-length mutation of shaped-identities.run after a returned shaping failure was accepted on reopen. The failing native regression is preserved in /tmp/gf1268-candidate-tests.log. Independent source review traced the cause to unchanged main code: authenticate_shaped_output calls the writer-receipt fast path, which returns a stored digest after only inode/link-count/length checks. Comparing stored digests does not authenticate current payload bytes. Incomplete cleanup used this path without a subsequent payload check. Completed public recovery also calls the existing supersession payload authenticator; that protection remains unchanged.

Scope and acceptance

  • Reproduce incomplete-shape corruption acceptance on current main; retain direct regression coverage for both incomplete and completed shape refusal, valid reopen/retry and replaced-inode/extra-link refusal.
  • Authenticate actual retained payload bytes at recovery/consumption trust boundaries. Keep efficient immediate writer accounting distinct; do not add compatibility readers or generic writer machinery.
  • Charge actual authentication read work and cache-release work accurately. Preserve exact identity, properties, cancellation, recovery and successor authority.
  • Prove corruption refusal without publication or destructive cleanup, and exact successful reconstruction/public lifecycle using relevant existing native fixtures.
  • Run changed-surface gates and exact-head required CI, squash merge and verify closure before perf(storage): retire consumed shaping roots before resolved merge peak #1268 proceeds.

This independent correctness blocker is a native child of #1194 and blocks #1268. It does not authorize S24/S26 or a new certification workflow. #1194 remains the capacity close gate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingcoreCore source code changes

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions