Skip to content

[v0.17 EV-7b] Arm a cross-platform filesystem observer before the authoritative scan #1651

Description

@TheGreenCedar

Package EV-7b in the v0.17.0 consolidated remediation program.

Contract

Add the staged filesystem-observer root fix: arm before a complete streamed content scan, store observer identity and epoch in the ReadyLease, rehash dirty paths, rescan directory-event scope, remove the reliable-observer cap, and fall back to EV-7 typed unknown on overflow, unsupported WSL/network filesystems, or unavailable observation.

Dependencies

EV-78 and readiness lease package #1599.

Program boundaries

  • The implementation PR uses a codex/* branch, targets dev/codestory-next, and carries this issue as Closes #N.
  • Keep source, package, protected-host, installed-runtime, and publication proof distinct.
  • Preserve atomic old-or-new publication, pinned readers, crash recovery, content-verified freshness, fail-closed evidence, observational status/doctor, accelerated embedding without CPU fallback, proof-owned cleanup, and serial Cargo execution.
  • Do not touch product version surfaces. The release lane owns the single synchronized version change after implementation is integrated.
  • Run focused proof while iterating and the owning path gate on the accepted candidate; broad source proof remains once on the frozen release candidate.

Done when

Mac, Windows, and Linux parity matrices pass without per-operation full scans; overflow and unsupported filesystems never authorize freshness or force a hidden broad pass.

Refs #1200
Refs #1179

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p1Release blocker or high-risk reliability/security issuetype:contractRuntime, CLI, API, or evidence contract work

    Projects

    Status
    Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions