Skip to content

feat(reconciliation): LLM recovery agent contract and deterministic safety core (C02) - #20

Closed
kapustazh wants to merge 1 commit into
developfrom
milestone/c02-reconciliation-engine
Closed

kapustazh wants to merge 1 commit into
developfrom
milestone/c02-reconciliation-engine

Conversation

@kapustazh

@kapustazh kapustazh commented Sep 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Implements Coder C Milestone C02: LLM Recovery Agent and Deterministic Reconciliation.
Builds the RecoveryAdvisorPort contract, bounded 4-action advisory recommendation parser (WAIT, RECONCILE, ESCALATE, RETURN_EXISTING_RESULT), prompt injection defense, deterministic LLM recovery agent simulator, deterministic recovery safety core, safe reconciliation command vocabulary (reconciliation-command-v1), and provenance-labeled recovery view (recovery-view-v1).

Key guarantees:

  • Subgraph MCP observations and LLM recommendations are strictly non-authoritative and advisory. They can never grant settlement rights or submit payments (settlementPermission: 'NEVER').
  • RETURN_EXISTING_RESULT recommendation can ONLY transition an intent to COMMITTED if independent authoritative Arc on-chain transfer proof is present; otherwise, the safety core overrides the advisory recommendation and preserves HOLD_UNKNOWN.
  • Package is isolated with zero imports from private A/B modules and zero calls to SettlementPort.

Scope and acceptance criteria

  • The change is limited to the stated milestone or issue.
  • Acceptance criteria are listed and satisfied:
    • C02.1 — Evidence model & binding validation: exact binding to businessIntentId, requestFingerprint, network, tokenContract, recipient, and amountAtomic.
    • C02.2 — Evidence precedence & sanitized agent input: authoritative OneShot and Arc proof prioritized; candidate observations labeled untrusted data; credentials and sensitive keys redacted.
    • C02.3 — LLM recommendation contract: bounded 4-action contract with strict schema validation; prompt injection, fabricated evidence IDs, and unsupported actions fail closed to WAIT; deterministic agent simulator.
    • C02.4 — Safety-core commands and recovery view: WAIT -> HOLD_UNKNOWN, RECONCILE -> READ_ONLY_LOOKUP, ESCALATE -> ESCALATE_UNKNOWN; unverified RETURN_EXISTING_RESULT overridden to HOLD_UNKNOWN; verified Arc success -> MARK_COMMITTED; verified Arc revert -> MARK_FAILED_SAFE. Zero submit by construction.
    • C02.5 — Idempotency & determinism: repeat and reordered evaluations emit identical commands.
  • No unrelated cleanup is included.

Product and security invariants

  • Tenant isolation remains fail-closed.
  • Sponsor authorization, auditability, and daily caps remain enforced where applicable.
  • Recipients cannot modify sponsor controls or access sponsor-only data.
  • No secret, token, production identifier, or personal data is committed or pasted into review prompts.
  • Invariant notes: 1 business intent -> at most 1 committed settlement. UNKNOWN reconciles without blind retry. Advisory recommendations never grant settlement rights.

Validation

Commands and results:

pnpm typecheck: PASS (TypeScript 6.0.3 strict build)
pnpm lint: PASS (ESLint 10.10.0 strict rules)
pnpm format:check: PASS (Prettier code style)
pnpm check:generated: PASS (Generated contracts are current)
pnpm validate:fixtures: PASS (Validated 9 contracts-v1 fixtures)
pnpm test: PASS (9 test suites, 92 tests passing)
npx markdownlint-cli2: PASS (0 issues)

Independent review evidence

Gate A — exact candidate tree before push

  • Base commit SHA: 64d0a6f

  • Candidate tree SHA: 8105a511787fd9d31c1c3f3a1935729556d5ac74

  • Candidate commit SHA: 6dd2e37

  • Reviewer tool: free-pi-cli

  • Reviewer model: glm 5.3

  • Verdict: VERDICT: PASS

  • Findings or residual risks: None blocking.

  • The reviewed tree equals the committed tree.

Gate B — exact remote PR head

Risk and rollback

  • Residual risks: Subgraph MCP live connection and external LLM credentials remain unadmitted in C02 as planned; credentialed integration tests belong to C04/C06.
  • Rollback or recovery plan: Revert PR commit 6dd2e37 on develop.

Human merge

  • A human owner has reviewed the evidence and will perform the merge.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
oneshot 6dd2e37 Sep 07 2026, 04:31 PM

@kapustazh
kapustazh marked this pull request as ready for review September 7, 2026 16:19
@kapustazh

Copy link
Copy Markdown
Collaborator Author

Closed: opened in error; this lane belongs to Coder C.

@kapustazh kapustazh closed this Sep 7, 2026
@kapustazh
kapustazh deleted the milestone/c02-reconciliation-engine branch September 7, 2026 16:28
@kapustazh
kapustazh restored the milestone/c02-reconciliation-engine branch September 7, 2026 16:29
@kapustazh kapustazh reopened this Sep 7, 2026
@SuPuHe SuPuHe closed this Sep 7, 2026
@SuPuHe
SuPuHe deleted the milestone/c02-reconciliation-engine branch September 7, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants