Skip to content

docs(storage): record the ingest authentication regime and its closeout evidence (#1384) - #1555

Merged
DecisionNerd merged 5 commits into
mainfrom
docs/1384-auth-regime-closeout
Sep 22, 2026
Merged

DecisionNerd merged 5 commits into
mainfrom
docs/1384-auth-regime-closeout

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes the documentation half of #1384: the ADR of record for the authentication regime, the surviving-boundary justification ledger with measured costs, and the integrated-tree measurement that closes the acceptance criteria.

Contents

Validation

  • Receipts verified against rung digests by make retain-ladder-evidence before anything was copied.
  • All rungs passed with correctness, digest reconciliation and result-digest checks; admission projection admitted S20.
  • Docs-only diff (ADR, evidence, archive, index rows); no code paths touched.

Closes #1384


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: CurateLabs/graphforge/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 9951858d-f9e1-43e2-be6b-25f8c36611a3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added documentation Improvements or additions to documentation release:none No release note or version impact labels Sep 22, 2026
@DecisionNerd
DecisionNerd force-pushed the docs/1384-auth-regime-closeout branch from c6fcd70 to 2edb011 Compare September 22, 2026 20:15
@blacksmith-sh

This comment has been minimized.

@DecisionNerd DecisionNerd added the core Core source code changes label Sep 22, 2026
@DecisionNerd

Copy link
Copy Markdown
Contributor Author

Third CI iteration root-caused: //crates/graphforge-cli:verify failed in Bazel because a_corrupted_reachable_object_is_refused_one_way_or_another flips bytes[0] of the first object directory order returns — and a populated project can legitimately retain zero-byte CAS objects, so enumeration order decides between a real bit-flip and an index panic. Bazel passed on main at the same tree (0016934), confirming order-dependence, not the docs diff. Fixed in 5f8814c by skipping zero-byte objects when selecting the corruption target; the test's intent (corrupt a reachable non-empty object, assert fail-closed refusal) is unchanged. The first two failures were the ADR-number collision with the concurrently merged research ADRs (renumbered to 0045 with regenerated indexes).

@DecisionNerd
DecisionNerd added this pull request to the merge queue Sep 22, 2026
Merged via the queue into main with commit 18b8c8a Sep 22, 2026
23 checks passed
@DecisionNerd
DecisionNerd deleted the docs/1384-auth-regime-closeout branch September 22, 2026 22:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core Core source code changes documentation Improvements or additions to documentation release:none No release note or version impact

Projects

None yet

Development

Successfully merging this pull request may close these issues.

perf(storage): eliminate the redundant authentication passes that dominate ingest

1 participant