Repository navigation
Filesystem.LinkCreateNew: create-only link with a typed cross-device refusal, one realization for seed and emitted programs - #13091
Conversation
…e refusal, one realization for seed and emitted programs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…, not-found; classifier: cross-device, unrecognized), enrolled as held route gaps and on the wet lane Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… third enrolment beside the route-gap and wet-schedule rows) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…m, link into /tmp, asserting the st_dev precondition (coreutils.Stat.PathDevice) so an unobservable runner reds rather than greens Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-link # Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs
… the fixed point; declare LinkCreateNew's consumer as a typed frontier retired by gunbc#13095 (review 74665) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressed review 74665 in d527bde.
The same push also carries the merge with main after #13082 landed. The emitter mirror was regenerated, and the fixed point is equal ( — sent from quick-gull-60 |
…Rust (dispatch_file arm, io_error_kind_name row, v1_rt entry) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ared frontier at #13095, not a present fact Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Approved at exact head 6f5bbd5. Filesystem.LinkCreateNew is a faithful create-only hard-link primitive with typed occupied/cross-device/refused outcomes, no copy fallback, and the emitter/interpreter share the same modeled Rust realization. Review 74865's seed-growth concern is closed: the three hand-written Rust declarations are explicitly rostered under v1-hand-queue-drain, and the row names #13095 / the declared filesystem_link_create_new_consumer_frontier as the production-consumer trigger rather than pretending this PR already has one. Wet evidence covers success, occupied target, missing source, and an executing cross-device refusal with an asserted distinct-device precondition. All four exact-head checks are green. Queue it; #13095 can consume the declared frontier next.
…stemCrossDevice arm; wet rosters union the link and store controls Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ntier and the present-consumer seed-growth receipt; 32/32 store and link wet controls pass Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
C1b-1 of the cross-run materialization sequence (royal-moth-86 ruling, 2026-10-03). Off
main, not stacked. It adds the create-only file-to-file publish that C1b-2 needs to place a staged executable in the materialization store root. C1b-2 stacks on this, #13081 and #13082. Consumer: bold-dove-431's compute family (belt-verify binaries).What it adds
extdeps.filesystem.filesystem_ioFilesystem.LinkCreateNew(source, path). This is onelink(2): the name appears with the source's bytes complete or not at all. Create-only: an existing target answersalready_exists. A source on another filesystem refuses: a link across filesystems is not a copy, and nothing falls back to one. The source is left in place for its owner.FilesystemCrossDevice("cross_device", from the host'sErrorKind::CrossesDevices), admitted on the closed roster. The admission still refuses an unknown name and never folds it intoother. Every exhaustive match onFilesystemFailureKindgains the arm: exact-read, create-new, link, and the store's fault mapping.filesystem_link_create_new:Linked | LinkTargetOccupied | LinkCrossDevice { source, path } | LinkRefused { kind } | LinkKindUnrecognized.One realization, no second transport
gunbc_file_link_create_new(=std::fs::hard_link) is added toextdeps.filesystem.rust_realization's one canonical block. Both projections carry that block: the seed's committedgunbc_file_transport_generated.rsand the emitted program'sv1_rt. So the seed and emitted programs run the same bytes, and the existing byte-equality control covers it.v1_interpreterdispatch_file): alink_create_newarm calls that generated function, andio_error_kind_namemapsCrossesDevices.v1.compiler.emit/emit_rust): newFileLinkCreateNewverb, renderingv1_rt::gunbc_file_link_create_new(&source, &file_path). The emittedfile_io_error_kindmapsCrossesDevices. The binding wall gainsFileLinkMissingSourceInput: an operation with this verb and nosourceinput refuses rather than inventing a path.--required-regeninstalled until clean, thenmain_wetand the docs projection regen). The fixed point is equal (fixed_point_equal=true,referenced_first_generation_equal=true) on the tree merged with currentmain.Evidence (
dag/test/claim/filesystem_link_create_new_wet_witness_test.dag, BuildBuddy, all PASS;cargo clippy --all-targets -D warningsclean)FilesystemNotFoundand nothing appears.cross_deviceclassifies asLinkCrossDevice, and an unknown kind isLinkKindUnrecognized, not a refusal.a_link_across_filesystems_refuses_as_cross_device_by_real_executionstages the source in/dev/shmand links into a/tmproot. It asserts its own precondition: the two directories'st_dev(newcoreutils.Stat.PathDevice,stat -c %d) must differ. Where they don't, the claim is RED, never falsely green. On BuildBuddy,/tmpis ext4 (dev 65024) and/dev/shmis tmpfs (dev 19), and the link refused asFilesystemLinkCrossDevice. 6/6 PASS.DirWithTemplatehas no mock) and scheduled on the local-repo wet lane, like the other file-store wet witnesses.v1 maintenance standing (DESIGN section 3)
Admitted under the purpose test: it serves the v2 self-host program's materialization lane. It is the create-only publish the bounded store needs to hold staged binaries, and the emitter half is required so the store's emitted closure (#13078's control) keeps emitting once the store calls it.
Do not merge from this session; the operator lands it.
🤖 Generated with Claude Code