Repository navigation
WO29 Slice B: Windows observed-bus widening + macOS declared-unproven - #61
Merged
Merged
Conversation
…unproven WO29 Items 2 + 3 (Slice B), on top of merged Slice A (037f62b). Windows (crates/windows-drive-locality): - Widen the observed local-bus list with SD (12) and MMC (13) alongside ATA/SATA/NVMe (Item 2: the widening is observation-only; no bus type independently earns proved — the Slice A grant-first demotion is unchanged). - Cause-specific observed-but-unproven verdicts with named reasons instead of reasonless Unknown: - windows_locality_unproven_removable_media_v0 (removable backing disk) - windows_locality_unproven_unsupported_bus_v0 (bus not on observed list) - windows_locality_unproven_removable_status_unreadable_v0 (disk descriptor query failed on a complete extent topology) - Complete observed-fact record on every Unproven path: dependency walk, each extent, each disk's numeric+name bus type and RemovableMedia value with query provenance, before/after observation and equality, the configured observed-bus list, one-line P1-P4 mapping, classification with provenance. Unavailable facts recorded as unavailable, never silently dropped. - All other closed paths (dependency/extent/close/topology-record failures) stay closed Unknown; FixedLocal stays unreachable from the live classifier. macOS (src/native_path.rs, src/run.rs): - Item 3: the macOS classifier entry point declares Unproven by policy with the named reason macos_locality_unproven_declared_v0; no Linux mountinfo probing on macOS; never fixed-local. Matching trust admission and P2-P4 enforcement are unchanged. - run.rs binds treat the declared verdict as missing observation (trust-coverable), never proof and never a contradiction; evidence lines and the trust bundle carry the reason and facts verbatim. Tests (Linux host): windows-drive-locality 25 passed; hum bin 625 passed including 2 new macOS entry-point/consumer tests. Windows native execution, physical SD/MMC hardware, and native macOS execution are unavailable here; Windows coverage is Linux-host fixtures plus cross-target compile, with native execution left to CI. Also records the Slice A merge in WORKORDER_29.md (PR #59 squash-merged as 037f62b; main-push run 36503074709 terminal success 2026-09-28).
…k query outcomes, membership-before-cause) Corrections per independent-review findings (Ocean-authorized bounded consolidation on draft PR #61): - native_path.rs: add the missing test-only Windows match arm for LocalityEvidence::MacOS in is_fixed_local (was E0004 under --tests --target x86_64-pc-windows-msvc; production cross-compilation never exercised it). Declared-unproven macOS is never fixed-local. New Windows-test-config test pins it. - windows-drive-locality: replace the all-or-nothing QueryState<Vec<DiskObservation>> descriptor walk with per-disk DiskQueryRecord { disk_number, outcome } where outcome is Observed/Failed/Undecodable/NotAttempted. The walk aborts after the first non-observed disk; later disks are NotAttempted, never failed. - Reducer validates exact disk-record membership (sorted record numbers == sorted/deduplicated required disks) BEFORE cause selection: missing/extraneous/duplicate records fail closed (Unknown), never reach removable/unsupported cause paths. - Partial descriptor-query outcomes yield cause-specific Unproven with the unreadable reason, preserving all available per-disk facts -- never reasonless Unknown. Tests: crate 28 pass (3 new: membership adversarial cases + valid multi-disk controls + partial-outcome fact preservation); bin 625 pass (incl. macos selectors); cli_wo29_trust_locality 7 pass; Windows test-target and production cross-compilation checks clean; fmt/clippy -D warnings/text hygiene/public readiness clean. Not covered here: native Windows execution of the new Windows-test-config test (CI/Codex), native macOS execution (unavailable), physical SD/MMC hardware (fixtures only).
…turned-locality path The returned locality evidence (Windows producer -> reducer -> runtime external-trust binder) conflated distinct per-disk outcomes and wiped available observations on the cleanup and topology-contradiction paths. Producer (crates/windows-drive-locality): - New DiskQueryOutcome::OpenFailed: a device that never opened is not a descriptor query that ran and failed (previously `Failed`), so the evidence never claims a query ran that never ran. - A failed CloseHandle no longer discards a successful observation: the observation is kept, the walk continues to later disks, and the cleanup failure is carried as a named fact instead of replacing the observation with `Failed`. Reducer: - A known before/after contradiction now returns a closed `Unknown` carrying a structured contradiction marker plus the before/after facts (new `ClassifiedDrive::contradiction`), instead of an empty closed verdict that erased the contradiction. - Cleanup failure no longer wipes the observed-fact record: it is a named `cleanup:` fact line and the verdict follows the observed matrix. - Inner identity validation: an `Observed` record whose inner `DiskObservation.disk_number` disagrees with the record's outer `disk_number` fails closed before cause selection (outer membership validation is unchanged). Runtime binder (src/run.rs): - `bind_observed_backing_evidence` rejects a contradicted bundle with `ContradictoryBackingEvidence` before payload consumption, even when serials and disk topology would otherwise agree: matching trust covers missing evidence, never contradictory evidence. Controls (production-connected, injected controls labelled in comments): open-failure vs descriptor-query-failure distinction, cleanup-failure observation retention, before/after contradiction marker through the reducer (contradiction vs missing-evidence `Unknown`), contradiction rejection through the actual binder (Windows-native), inner/outer disk-identity mismatch rejection with a valid multi-disk control, and the preliminary removable path through the actual reducer; the existing missing/duplicate-record regressions are preserved unchanged. Evidence: windows-drive-locality 31/31, hum binary 625/625, `cargo fmt --all -- --check`, `cargo clippy --workspace --all-targets -- -D warnings`, text hygiene, and public readiness clean; x86_64-pc-windows-msvc test-target and production cross-compilation clean. Native Windows execution of the new binder control rides CI; native macOS execution remains unavailable.
…for invalid/contradictory evidence - Thread volume-close outcome through classify_full preliminary/dependency early returns; cleanup facts preserved including close failure - Render close/extent bundles honestly: complete-after shown as available observation; ApiFailure/Partial as unavailable, never contradiction; not-attempted named only when the query genuinely never ran - Inner disk-identity mismatch (outer disk 0 / Observed inner disk 99) now carries the contradiction marker and rejects through the actual external-trust binder before payload consumption - Distinguish unavailable after-queries from observed disagreements; genuine contradiction still rejects - Production-used injection seam controls exercise orchestration, early returns, and cleanup; new Windows binder test through actual bind_observed_backing_evidence Tests: windows-drive-locality 46/46, hum 625/625; x86_64-pc-windows-msvc test+production configs clean.
…when after mapping is unavailable Finding P1: classify_evidence_detail returned a closed verdict immediately on after.mapping ApiFailure/Partial, bypassing the disk-record and contradiction validation below it — and clearing backing_device_identity, so the runtime binder admitted inconsistent evidence as trust-coverable. The unavailable after mapping is now carried as a flag through the full validation chain: - dependency, extents, exact outer disk-record membership, inner observed-disk identity, and per-disk outcomes all validate first; - the drive type is checked independently of the mapping query: a positively observed Fixed -> Remote change is a genuine contradiction even when the after mapping itself is unavailable (unobserved drive types stay missing evidence, never disagreement); - the final verdict stays closed Unknown with no contradiction marker for genuinely unavailable after mappings, but retains the VALIDATED disk identities so the actual binder compares them against the opened observation (mismatch rejects; agreement stays trust-coverable); - cause-specific Unproven paths still run when the disk query genuinely failed, with the unavailable after named as unavailable in the facts — never 'mismatch'. Tests: 52/52 windows-drive-locality lib (6 new combined-cause controls covering ApiFailure and Partial: retained identities, inner/outer record invalidity, independent drive-type disagreement, cause-specific Unproven preservation), 625/625 hum bin (2 new binder controls: retained identities bind against the opened observation; drive-type contradiction rejects before payload). cargo fmt --check, clippy -D warnings, text hygiene (657 files), public readiness (657 files), Windows test-target and production compilations all pass.
… Unproven causes Codex accept-with-required-fix, two findings. Finding 1 (complete after mapping, classify_evidence_detail): the before/after check compared the whole preliminary record, so before Fixed + after DRIVE_UNKNOWN + identical complete mapping + matching disk evidence set contradiction=true and the binder rejected. DRIVE_UNKNOWN means undetermined, not an observed different drive type. The mapping and the drive type are now compared independently: unequal complete mappings contradict; a positively observed different after drive type (e.g. Fixed -> Remote) contradicts; DRIVE_NO_ROOT_DIR keeps its existing rejecting handling (separately documented meaning, never treated as missing). An undetermined after drive type with an otherwise consistent record is trust-coverable: the verdict takes the observed-but-unproven path with the validated disk identities retained for the binder, and the facts render 'undetermined (drive type)' instead of 'mismatch'. Finding 2 (unavailable after mapping): the final branch computed the cause-specific determination (removable SD, unsupported bus) but discarded it, returning unproven_reason=None. With complete removable-SD or unsupported-bus observations and after ApiFailure/Partial, the named Unproven cause is now preserved alongside the unavailable-query facts and the retained binding identity (new closed_retained_unproven verdict). The after query is still recorded as unavailable — never claimed succeeded — and the verdict stays closed Unknown with no contradiction marker. Controls: 5 new injected orchestration controls through the real production seam (undetermined drive type trust-coverable; MissingRoot and observed Remote still reject; removable and unsupported-bus causes preserved under ApiFailure AND Partial) plus 2 run.rs binder controls passing the actual returned verdicts into the actual external-trust binder (matching opened evidence admits; mismatched disk identity rejects). Genuine missingness stays trust-coverable; every unavailable query is not rejected. Gates on the exact candidate: windows-drive-locality 57/57, hum bin 625/625, x86_64-pc-windows-msvc test + production configurations compile clean, fmt/clippy/-D warnings/text hygiene/public readiness clean. No local Full campaign.
…pping state Remaining P1 from independent review: drive_type_observed_changed treated DRIVE_NO_ROOT_DIR as missing evidence on the unavailable-after path, so an observed Fixed->DRIVE_NO_ROOT_DIR transition was trust-covered when the after mapping was ApiFailure/Partial. DRIVE_NO_ROOT_DIR means the root path is invalid - an observed invalid-root disagreement, not undetermined (Unknown) and not missing. The shared comparison helper now names MissingRoot as an observed disagreement, so the invalid-root transition carries the rejecting contradiction marker identically in all three after-mapping states (Complete, ApiFailure, Partial). The complete-mapping branch drops its explicit MissingRoot clause (now covered by the helper); unrelated Other handling is unchanged. The invalid-root observation is preserved alongside the unavailable-mapping facts; the after query is never claimed succeeded. Matching trust still cannot waive the marker. Controls: new orchestration test covers ApiFailure AND Partial through the real production seam; existing complete-mapping test re-passes; new cfg(windows) binder test proves the actual external-trust binder refuses the marked verdict before payload consumption even with matching serial. DRIVE_UNKNOWN trust-coverable controls, mapping/Remote contradictions, named causes, and disk-identity binding preserved. Tests: windows-drive-locality 58/58; hum bin 625/625; Windows test and production targets cross-compile clean; fmt/clippy/hygiene/readiness clean. No local Full campaign.
undergroundrap
marked this pull request as ready for review
September 29, 2026 06:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WO29 Items 2 + 3 (Slice B) implementation, on top of merged Slice A (
037f62b2).Item 2 — Windows: widen observed local-bus facts to fixed, non-removable eMMC/SD
crates/windows-drive-locality: SD (12) and MMC (13) join the observed local-bus list alongside ATA/SATA/NVMe. Observation only — no bus independently earnsproved; the Slice A grant-first demotion is unchanged.Unknown:windows_locality_unproven_removable_media_v0(removable backing disk)windows_locality_unproven_unsupported_bus_v0(bus not on the observed list)windows_locality_unproven_removable_status_unreadable_v0(disk-descriptor query failed on a complete extent topology)Unprovenpath: dependency walk, each extent, each disk numeric+name bus type andRemovableMediavalue with query provenance, before/after observation and equality, the configured observed-bus list, one-line P1–P4 mapping, classification with provenance. Unavailable facts recorded as unavailable, never dropped.Unknown;FixedLocalstays unreachable from the live classifier.Item 3 — macOS: declared unprovable (grant only)
Unprovenby policy with the named reasonmacos_locality_unproven_declared_v0; no Linux mountinfo probing on macOS; never fixed-local. Matching trust admission and P2–P4 enforcement unchanged.run.rsbinds treat the declared verdict as missing observation (trust-coverable), never proof and never a contradiction; evidence lines and the trust bundle carry the reason/facts verbatim.Evidence
windows-drive-locality25/25;humbin 625/625 incl. 2 new macOS entry-point/consumer tests.cargo fmt --checkclean,cargo clippy --workspace --all-targets -- -D warningsclean,tools/test_ci_policy.ps1436 assertions, text hygiene + public readiness clean.x86_64-pc-windows-msvc, crate tests + bin) clean — compile-only credit; native Windows execution, physical SD/MMC hardware, and native macOS execution unavailable here and left to CI.Ready for independent Codex review. Draft until CI Full is green.