The "Code Review fixes" entries were committed with _pending_ hash
placeholders; point them at the commit that carries the fix.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A defensive review (prompted by an external File Pilot NULL-write crash in
its per-directory stats roll-up) checked whether Librarian shares that bug
class: a derived index guarded by a stale count/offset rather than the
destination's bounds.
Found and fixed one latent instance: `window_for` clamped `end` to `count`
but not `start`, so a list that shrank under a stale scroll offset could
yield an inverted `start..end` that violates the documented `0..count`
contract and panics any caller that slices `rows[start..end]` (the grid
does). Clamp `start` to `end` so the window is always well-formed.
- Add `rapid_churn_never_leaves_a_stale_row_index`: drives a real
create/delete burst (the `.lock` trigger) through the notify watcher and
asserts reconciliation (`retain_below` + the window clamp) never leaves an
out-of-bounds row index.
- Extend `visible_window_*` with a stale-scroll-past-end contract case.
- Document the analysis in docs/crash_class_review_filepilot.md.
Full librarian-app suite green (51); fmt + clippy clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>