Repository navigation
[Guardian] Validate sequenced S3 keys and simplify readers - #1351
Merged
Merged
Conversation
Limiter recovery now returns an error for a non-withdrawal log under `withdraw/` instead of skipping it, using `VerifiedLogEntry::extract`. Move the capacity cap to `LimiterState::capped_to` and use it in the node's `LocalLimiter::adopt_config`. Clarify why recovery does not wait for `write_completion_time`. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Add `LimiterState::capacity_at` and call it from `RateLimiter::consume` and from the node's `LimiterView`, replacing the mirror's private `project_capacity`. No behavior change: `consume` still rejects a timestamp before `last_updated_at` before it computes the capacity. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- Add S3NumericDirectory::sort_desc and use it in limiter recovery and the proxy's wid-log walk, so the proxy also rejects non-numeric directories. - Add WithdrawalLogMessage::seq_from_object_key next to object_key and use it in the proxy instead of a private parser. - Require every key in a scanned hour to parse; a noncanonical key now fails the proxy lookup closed instead of being skipped. - Document the proxy's stop rule and add tests for the key parser. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
0xsiddharthks
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Validate every listed ceremony, KP-share state, and committee-update key before selecting the highest numeric sequence. Reject malformed keys and KP-share keys from another sharing sequence. Add tests for numeric ordering at digit-width boundaries and for invalid key formats. S3 key formats and serialized records remain unchanged.
Group S3 reader methods by log type, centralize current-build checks and message extraction, and remove the duplicate ceremony-state wrapper. Log successful record verification from the read helpers, and log the ceremony and KP-share sequence maxima separately in
next_sharing_seq.Limiter recovery now returns an error for a non-withdrawal log under
withdraw/instead of skipping it.Share two pieces of limiter logic between the guardian and the node's mirror (
crates/hashi/src/guardian_limiter.rs), with no behavior change:LimiterState::capped_toreplaces the cap in limiter recovery and inLocalLimiter::adopt_config.LimiterState::capacity_atreplaces the inline refill math inRateLimiter::consumeand the mirror'sproject_capacity.consumestill rejects a timestamp beforelast_updated_atfirst, so the saturating subtraction gives the same result there.Validation:
cargo checkpassed for the key-validation and reader commits.make fmtcompleted Rust and protobuf formatting, then stopped becauseprettier-moveis not installed; no Move files changed. Four focused key-validation and ordering tests passed during development. The limiter commits were formatted only. Full tests and lints are left to CI.