Skip to content

dir-sim: git-consumable, ViewActors, Graph groups, persistence (image/restore/revert) - #1473

Merged
AdaWorldAPI merged 6 commits into
mainfrom
ccr-0455e606-wmtsor
Oct 11, 2026
Merged

AdaWorldAPI merged 6 commits into
mainfrom
ccr-0455e606-wmtsor

Conversation

@AdaWorldAPI

@AdaWorldAPI AdaWorldAPI commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

HubSPO wishlist item 1, ISS-LG-DIRSIM-NOT-GIT-CONSUMABLE.

lance-graph-dir-sim depended on four OGAR crates by ../../../OGAR path, so no repository without an OGAR sibling checkout could depend on it. They are now git dependencies (AdaWorldAPI/OGAR, branch main), the same shape lance-graph-ogar uses. A [patch."https://github.com/AdaWorldAPI/OGAR"] in this crate's own root redirects them onto the sibling checkout, so this crate's build and the Identity CI still test a paired OGAR change before it merges.

Cargo applies [patch] only in the workspace root. A consumer that also names OGAR by path (Spear, Stalwart) must repeat the patch, or it builds two ogar-dir-core crates whose types don't unify. Merge order: the Spear and Stalwart root patches land first; on their own they are harmless. This PR merges after them.

Test plan

  • cargo +1.99.0 test --manifest-path crates/lance-graph-dir-sim/Cargo.toml: all pass. The lockfile has no git OGAR source (the patch applies), and Cargo gives no unused-patch warning.
  • A git consumer: a throwaway crate outside any checkout depending on lance-graph-dir-sim by git (this branch), with no patch, passes cargo check. Its lockfile resolves ogar-dir-core from git+https://github.com/AdaWorldAPI/OGAR?branch=main.

Also in this PR (HubSPO wishlist #2, #19, #3)

  • ViewActors (feature rbac, W-2): an ActorSource over a View. Roles are granted to groups by GUID (GroupRoles) and inherited through SID chains only (View::security_identifiers), so a distribution group passes on nothing. A role the binding does not declare is dropped; a group whose grants were never read grants nothing and is named (unread_groups); only the principal holds roles. Four disable runs red.
  • from_graph observes Graph groups and their direct members (GroupMembers): no location, securityEnabled as read, an address only when mailEnabled was read true. Needs OGAR plan(palantir-parity-cascade-v2)+ledger(soa-dto-deps)+post-merge(#352) #353 (ogar_az::group) on OGAR main before CI can build it. Three disable runs red.
  • W-3 persistence, probe first (plan .claude/plans/dir-sim-persist-v1.md, D-DSP-0/1): VersionStore::image() / restore() hold the history as its inputs (root observations, dictionary in id order, versions verbatim, tags, verdicts) and restore a store that answers every read the same way; a damaged image is refused. VersionStore::revert(current, earlier, evidence) records the undo as a new version under REVERT. Five + one disable runs red. The Lance writer (D-DSP-2) is a separate crate, so dir-sim keeps its no-I/O rule.

Verification: cargo +1.99.0 clippy --all-targets --features rbac -D warnings, cargo +1.99.0 test --features rbac (all suites), fmt; all with CARGO_PROFILE_DEV_DEBUG=0 CARGO_INCREMENTAL=0.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg


Generated by Claude Code

ISS-LG-DIRSIM-NOT-GIT-CONSUMABLE: the four ../../../OGAR path deps made
dir-sim unbuildable from any repository without an OGAR sibling, so
HubSPO-rs could not depend on it. OGAR is now a git dependency; a
[patch] keeps this crate's own build and CI on the sibling checkout.
Consumers that also name OGAR by path repeat the [patch] in their root.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T08:01:37.603605Z c471e8b PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 55489793-9b9c-4308-b90c-7cab1556b61e



📥 Commits

Reviewing files that changed from the base of the PR and between 27c1008 and c471e8b.




📒 Files selected for processing (1)
  • crates/lance-graph-dir-sim/Cargo.toml



Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.





📝 Walkthrough
📝 Walkthrough
📝 Walkthrough

Walkthrough

The crate manifest now documents its workspace exclusion and downstream patch requirement. It uses OGAR dependencies from the upstream Git repository’s main branch and adds a root-level patch that redirects them to sibling checkouts.

Changes

OGAR dependency configuration

Layer / File(s) Summary
OGAR dependency sources
crates/lance-graph-dir-sim/Cargo.toml
The manifest documents the workspace exclusion and patch requirement for path-based consumers. Four OGAR dependencies now use the upstream Git repository’s main branch, and a root-level patch redirects them to sibling checkouts.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: claude





Merge Risk: ⚪ Minimal · up to c471e

The dependency change follows repository guidance, and its local patch matches the CI checkout. Available evidence shows no concrete merge-blocking risk.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title identifies the main change: making dir-sim git-consumable. The additional feature references are not covered by this changeset, but they do not make the title unrelated.

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks the manifest with care
Four Git paths lead to OGAR’s lair
A local patch points close at hand
Workspace notes explain the plan
The rabbit hops through dependencies there

Comment @coderabbitai help to get the list of available commands.

…arries

A reusable ActorSource over a View (feature rbac). Roles are granted to
groups by GUID (GroupRoles) and inherited through SID chains only
(View::security_identifiers), so a distribution group passes on nothing.
A role the binding does not declare is dropped; a group whose grants were
never read grants nothing and is named (unread_groups); only the principal
holds roles.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
Group records (ogar-az AzKind::Group) become groups of the observation:
no location (Graph reports no on-premises DN for a group), the
securityEnabled flag as read, and an address only when mailEnabled was
read as true. GroupMembers carries each group's direct members; nesting
and the SID chain stay the view's walk.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
VersionStore::image() returns the history as its inputs: each root's
observation, the dictionary in id order, every version verbatim, tags and
verdicts. VersionStore::restore() interns the dictionary in order, rebuilds
each root and re-applies each delta to its parent; the restored store
answers every read the same way. A damaged image is refused, never half
restored. No I/O: a storage crate writes the image (plan
dir-sim-persist-v1).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
VersionStore::revert(current, earlier, evidence) records diff(current,
earlier) as a simulated version on top of current, under the REVERT rule
with version:<earlier> as its first evidence. History is never rewritten;
a revert with nothing to undo creates no version.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@AdaWorldAPI AdaWorldAPI changed the title dir-sim: depend on OGAR by git so other repos can depend on dir-sim dir-sim: git-consumable, ViewActors, Graph groups, persistence (image/restore/revert) Oct 11, 2026

Copy link
Copy Markdown
Owner Author

Exchange dir-sim fidelity failed on ef93f9ec with unresolved import ogar_az::group: the job checked out OGAR main before OGAR #353 (which adds that module) merged. #353 is merged now; re-running the job once.


Generated by Claude Code

@AdaWorldAPI
AdaWorldAPI merged commit 8bb3288 into main Oct 11, 2026
14 of 15 checks passed
AdaWorldAPI pushed a commit that referenced this pull request Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants