Repository navigation
cli: Announce recovery secret switch - #95
BenWestgate wants to merge 1 commit into
Conversation
This comment has been minimized.
This comment has been minimized.
12d2098 to
23dae08
Compare
|
Agent release-gate review at exact head ACK on behavior. The adversarial-review finding was the silent mid-recovery mode switch: after compatible shares are already accepted, supplying a complete secret intentionally supersedes them. This patch preserves that policy and emits the notice only when Verification:
No code blocker found. Integration blocker remains authorship policy only: this is a Codex-authored commit and should be human-reviewed/re-written or squashed under the responsible human author before merge, as the PR body already records. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted review performed at the maintainer's request and disclosed per docs/developer/AI_POLICY.md.
No correctness findings. The change is narrowly scoped: it preserves the existing recovery behavior when a complete valid secret is entered after shares, but makes the mode switch explicit before returning the secret. The notice is conditioned on accepted, so it does not add noise when the secret is the first input. Focused recovery/secret tests pass locally (17 passed), and the exact-head GitHub matrix is green. Ready for human review/rewrite-squash under the repository authorship policy.
23dae08 to
30062fd
Compare
7686cb0 to
aa2d333
Compare
30062fd to
cebecfc
Compare
aa2d333 to
9f88b21
Compare
cebecfc to
4ea72bb
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Exact-head release-gate re-review: ACK 4ea72bb. This remains the same reviewed one-line behavior change by stable patch-id: when a complete valid secret is supplied after accepted shares, the CLI explicitly announces that it is switching to that secret; first-input secret recovery stays quiet. The exact integrated tip passes 935 tests normally and optimized, including the focused recovery-switch regression, and remains 5,193 <5200. No code blocker found. The agent-authored commit requires responsible-human rewrite/squash before integration.
9f88b21 to
1d5b6f5
Compare
4ea72bb to
3d8510a
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head re-review: ACK 3d8510a.
The current diff is still the focused disclosure fix: when a complete valid secret is supplied after shares have already been accepted, recovery explicitly tells the operator it is switching to that secret; the first-input secret path stays quiet. There are no inline review threads, and exact-head Python-package run 666 succeeded.
No code blocker found. The agent-authored commit still requires responsible-human rewrite/squash before integration.
3d8510a to
5e44dcb
Compare
1d5b6f5 to
b2aafde
Compare
|
@codex review |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head review: ACK 5e44dcb. The intentional complete-secret switch is now announced only after shares were accepted; behavior is otherwise unchanged. Exact-head package CI is green.
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head review at 5e44dcb: no findings. The CLI now makes the complete-secret override explicit without changing acceptance logic.
b2aafde to
9769a5f
Compare
5e44dcb to
0aab056
Compare
This comment has been minimized.
This comment has been minimized.
|
@codex review Current head was mechanically restacked onto the refreshed audit stack after #57's documentation-only follow-up. Please review this exact head for correctness/regressions; the composed stack passes 941 tests normally and under |
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head review, posted at the maintainer's request.
ACK 0aab056 for code review. The restack preserves the focused disclosure fix: a complete secret entered after accepted shares explicitly announces the switch; first-input secret recovery stays quiet. The fresh Python-package run is queued. No findings.
This comment has been minimized.
This comment has been minimized.
|
@codex review Please review current head |
This comment has been minimized.
This comment has been minimized.
9769a5f to
ada987b
Compare
Entering a complete valid secret during interactive share recovery intentionally supersedes the partial share set. Previously that mode switch happened silently, which made correct behavior look like discarded input. Emit one explicit notice only when shares were already accepted, and pin the behavior in the existing interactive recovery regression. Refs #38
0aab056 to
278be78
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head review: ACK 278be78. The existing intentional behavior—accept a complete valid secret and stop using the previously entered shares—remains unchanged; the only behavioral delta is an explicit notice when that switch happens after accepted shares. Exact-head Python-package CI is green, the regression asserts the notice, and there are no unresolved review threads. No correctness or release blocker found.
What
When a complete valid secret is supplied after one or more shares were accepted, keep the existing deliberate behavior of ending share recovery and using that secret, but state that choice explicitly before returning it.
Why
The adversarial review correctly reproduced a silent mode switch. The switch itself is intentional; the defect is that already-accepted shares appeared to vanish without explanation.
Review shape
Current head
278be78is the same reviewed one-commit #95 patch mechanically replayed directly onto current #81 (ada987b). Its stable patch ID is unchanged; the review delta remains two source/test files with three added lines.Validation
Exact-head GitHub Python-package CI is green. The composed exact current tip passes all 941 tests normally and all 941 under
python -O, Ruff, strict mypy, correction-constant verification, andgit diff --check. The secret-after-compatible-shares regressions are included.Refs #38.
Human integration order is #57 → #105 → #99 → #80 → #81 → #95. This commit is agent-authored and requires responsible-human review/rewrite or squash under repository policy before integration.