Skip to content

feat(rust): harden acquisition reports and add source corrections - #596

Open
LIghtJUNction wants to merge 5 commits into
mainfrom
codex/rust-acquisition-report-audit-20261004
Open

LIghtJUNction wants to merge 5 commits into
mainfrom
codex/rust-acquisition-report-audit-20261004

Conversation

@LIghtJUNction

@LIghtJUNction LIghtJUNction commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • make Rust acquisition self-report writes atomic with PostgreSQL UPSERT ... RETURNING, rejecting invalid user IDs before storage
  • implement Rust GET/POST /api/admin/acquisition/users/:id/corrections with Go-compatible details/write permissions and target-role boundaries
  • preserve append-only correction history with row-locked optimistic concurrency and HTTP 409 stale-write handling
  • keep 365-day reads and writes consistent: an expired hidden head restarts at visible revision 0 under the same row lock, while a concurrent stale writer still conflicts
  • enforce source/reason validation, explicit consent denial, historical source fallback, and retention privacy
  • cover the 100-row correction history cap and exclude expired rows before pagination
  • add HTTP contract coverage for role/permission boundaries, invalid targets, oversized and malformed bodies, missing users, successful writes, stale revisions, and persisted reads
  • update the exact real-integration inventory from 9 to 13 acquisition tests

Verification

  • local real-integration inventory gate: passed (113 ignored tests across 10 modules)
  • current head: rustfmt, Clippy, RustSec, route/behavior alignment, workflow contracts, root-route acceptance, and web checks: passed
  • current ordinary acquisition suite: 3 passed, 13 PostgreSQL tests inventoried/ignored
  • last fully reached acquisition PostgreSQL suite: 11/11 passed; the two newer retention/pagination/HTTP additions compile and are inventoried, but the aggregate runner is currently stopped before acquisition by the base blocker below
  • current full workspace and PostgreSQL jobs reach the existing base-branch blocker in ai_directory.rs before the acquisition PostgreSQL suite: PR run 3428
  • unchanged base 3ce27fe6 has the same two CurrencyUnavailable failures: main run 3424

Coverage note

The non-PostgreSQL instrumentation baseline that identified this area remains acquisition.rs 40.00%, data.rs 3.17%, and store.rs 0.69%. Ignored database tests are not credited by that baseline; this PR adds six durable PostgreSQL correction/report tests plus an always-on HTTP contract test, including permission/status mapping, expired-head recovery, optimistic concurrency, and pagination branches. The static route gate remains at zero unclassified outside-baseline routes. A fresh numerical LLVM coverage result is not claimed while the base-branch workspace failure prevents a clean full run.

Scope

Rust backend only. No Go backend, frontend, or database migration changes.

@LIghtJUNction
LIghtJUNction force-pushed the codex/rust-acquisition-report-audit-20261004 branch from f5208c6 to e72328a Compare October 4, 2026 00:51
@LIghtJUNction
LIghtJUNction marked this pull request as ready for review October 4, 2026 01:02
Copilot AI balanced review requested due to automatic review settings October 4, 2026 01:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-05T01:02:20.530190Z 134105e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@LIghtJUNction
LIghtJUNction marked this pull request as draft October 5, 2026 00:28
@LIghtJUNction
LIghtJUNction force-pushed the codex/rust-acquisition-report-audit-20261004 branch from e72328a to 02a21a7 Compare October 5, 2026 00:29
@LIghtJUNction LIghtJUNction changed the title fix(rust): make acquisition self-report writes atomic feat(rust): harden acquisition reports and add source corrections Oct 5, 2026
@LIghtJUNction
LIghtJUNction force-pushed the codex/rust-acquisition-report-audit-20261004 branch 2 times, most recently from cb8ef7e to c2e242d Compare October 5, 2026 00:35
Make self-report writes atomic and add the Rust acquisition correction read/write contract with optimistic concurrency, consent and role safeguards, retention filtering, and PostgreSQL integration coverage.
@LIghtJUNction
LIghtJUNction force-pushed the codex/rust-acquisition-report-audit-20261004 branch from c2e242d to 134105e Compare October 5, 2026 00:45
@LIghtJUNction
LIghtJUNction marked this pull request as ready for review October 5, 2026 00:57

Copy link
Copy Markdown
Collaborator Author

发现一个 365 天保留期边界上的功能问题(按当前 head 134105e3 静态核对,未另行执行复现):旧修正记录被隐藏后,页面无法再保存新的修正。

  • corrections() 对过期 head 返回 null,但数据库中的非零 revision 仍然存在。
  • 前端 因此提交 expected_revision: 0;save_correction() 对现存 head 不做修改,读取旧 revision 后返回 409。再次刷新仍是 head: null,所以只要过期 head 保留,这个重试循环就无法前进。
  • 新增 retention 测试 已构造这一状态,但在确认隐藏/保留后结束了,没有验证随后新增修正。

建议接着覆盖“读取过期 head → 按返回值提交新修正 → 成功,再提交旧版本仍应 409”的回归,并让保留期过滤与并发版本协议一致;修复时仍需保持旧 source/reason 不再展示、历史审计及并发写入边界。Go 对照实现也有相同读写条件,单纯保持 Go/Rust 一致并不能排除这一交互问题。

Keep acquisition correction read retention and optimistic write revisions consistent, preserve append-only expired audit rows, and cover the 100-row history boundary.

Copy link
Copy Markdown
Collaborator Author

已修复上述 365 天边界回归(head 1e4d745)。

实现保持旧审计行 append-only,但在 FOR UPDATE 行锁内用与读取端相同的 retention cutoff 计算可见 revision:过期且已隐藏的 head 按 revision 0 开启新可见链;首个写入提交后,第二个并发 revision-0 写入仍返回 conflict。

新增回归覆盖:

  • 读取过期 head / items 均为空;
  • 按返回的 revision 0 可成功保存;
  • 新 head/items 只暴露保留期内内容;
  • 过期 source/reason 不重新泄露,旧数据库审计行仍保留;
  • 后续 stale revision 0 仍冲突;
  • 101 条近期记录返回 100 条且 has_more=true,过期高 ID 行在分页前过滤。

当前 PR 已合入最新 main 并恢复 mergeable。格式、Clippy、RustSec、路由/行为对齐等已通过;完整 PostgreSQL 门禁被 base main 本身现有的 ai_directory.rs 失败提前中止(main run 3368 与 PR run 3370 同测试同位置),未改动该无关模块。

Exercise administrator role and permission gates, request validation, target-role boundaries, status mapping, optimistic conflict responses, and successful PostgreSQL-backed correction reads and writes.

Copy link
Copy Markdown
Collaborator Author

今日继续补强 Rust acquisition 覆盖(head 996ef9b):

  • 新增无需数据库的 correction admin HTTP 合约测试,覆盖低权限 GET/POST 403、无效用户 ID 400、超大请求体 413,且确认都在触达存储前失败。
  • 新增 PostgreSQL HTTP 集成测试,覆盖目标角色边界、details/write 权限拆分、404/400、成功写入、stale revision 409,以及随后读取持久化 head/items。
  • acquisition 普通套件已通过:3 passed / 13 ignored;真实集成清单门禁已通过:113 个 ignored tests / 10 modules,acquisition 精确清单由 12 增至 13。
  • rustfmt、Clippy、RustSec、路由/行为对齐、workflow/resource safety、root-route acceptance 和 web checks 均通过。

完整 workspace 与 PostgreSQL aggregate job 仍在 acquisition 之前被 base main 的两个 ai_directory.rs / CurrencyUnavailable 失败中断:PR run 3428。未改动的 base 3ce27fe6 同样失败:main run 3424。因此本轮不虚报 13/13 数据库执行结果或新的 LLVM 覆盖率数值。

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants