Skip to content

[Guardian] Validate sequenced S3 keys and simplify readers - #1351

Merged
mskd12 merged 8 commits into
mainfrom
codex/guardian-s3-key-validation
Oct 6, 2026
Merged

mskd12 merged 8 commits into
mainfrom
codex/guardian-s3-key-validation

Conversation

@mskd12

@mskd12 mskd12 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Validate every listed ceremony, KP-share state, and committee-update key before selecting the highest numeric sequence. Reject malformed keys and KP-share keys from another sharing sequence. Add tests for numeric ordering at digit-width boundaries and for invalid key formats. S3 key formats and serialized records remain unchanged.

Group S3 reader methods by log type, centralize current-build checks and message extraction, and remove the duplicate ceremony-state wrapper. Log successful record verification from the read helpers, and log the ceremony and KP-share sequence maxima separately in next_sharing_seq.

Limiter recovery now returns an error for a non-withdrawal log under withdraw/ instead of skipping it.

Share two pieces of limiter logic between the guardian and the node's mirror (crates/hashi/src/guardian_limiter.rs), with no behavior change:

  • LimiterState::capped_to replaces the cap in limiter recovery and in LocalLimiter::adopt_config.
  • LimiterState::capacity_at replaces the inline refill math in RateLimiter::consume and the mirror's project_capacity. consume still rejects a timestamp before last_updated_at first, so the saturating subtraction gives the same result there.

Validation: cargo check passed for the key-validation and reader commits. make fmt completed Rust and protobuf formatting, then stopped because prettier-move is not installed; no Move files changed. Four focused key-validation and ordering tests passed during development. The limiter commits were formatted only. Full tests and lints are left to CI.

@mskd12
mskd12 marked this pull request as ready for review October 6, 2026 01:51
@mskd12
mskd12 requested a review from bmwill as a code owner October 6, 2026 01:51
@mskd12
mskd12 requested a review from 0xsiddharthks October 6, 2026 01:51
mskd12 and others added 4 commits October 6, 2026 11:00
Limiter recovery now returns an error for a non-withdrawal log under
`withdraw/` instead of skipping it, using `VerifiedLogEntry::extract`.

Move the capacity cap to `LimiterState::capped_to` and use it in the
node's `LocalLimiter::adopt_config`. Clarify why recovery does not wait
for `write_completion_time`.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Add `LimiterState::capacity_at` and call it from `RateLimiter::consume`
and from the node's `LimiterView`, replacing the mirror's private
`project_capacity`. No behavior change: `consume` still rejects a
timestamp before `last_updated_at` before it computes the capacity.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- Add S3NumericDirectory::sort_desc and use it in limiter recovery and the
  proxy's wid-log walk, so the proxy also rejects non-numeric directories.
- Add WithdrawalLogMessage::seq_from_object_key next to object_key and use
  it in the proxy instead of a private parser.
- Require every key in a scanned hour to parse; a noncanonical key now fails
  the proxy lookup closed instead of being skipped.
- Document the proxy's stop rule and add tests for the key parser.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@mskd12
mskd12 merged commit 7ed69bb into main Oct 6, 2026
14 checks passed
@mskd12
mskd12 deleted the codex/guardian-s3-key-validation branch October 6, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants