Skip to content

fix: require recovery lookup config - #44

Merged
kapustazh merged 1 commit into
developfrom
fix/production-recovery-config
Sep 8, 2026
Merged

kapustazh merged 1 commit into
developfrom
fix/production-recovery-config

Conversation

@kapustazh

@kapustazh kapustazh commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Remove fake production recovery identities and require validated Graph lookup configuration before any MCP call.

Scope and acceptance criteria

  • The change is limited to the production recovery configuration boundary.
  • Token, sender, numeric block window, deployment ID, and manifest CID are explicit.
  • Invalid lookup input fails before MCP use.
  • Unavailable MCP/advisor defaults remain fail-closed.
  • No unrelated cleanup is included.

Product and security invariants

  • Tenant isolation remains fail-closed.
  • Sponsor authorization, auditability, and daily caps remain enforced where applicable.
  • Recipients cannot modify sponsor controls or access sponsor-only data.
  • No secret, token, production identifier, or personal data is committed or pasted into review prompts.

Invariant notes:

Recovery still has zero settlement submissions. UNKNOWN is preserved without authoritative Arc proof. Provider credentials remain external.

Validation

Commands and results:

pnpm lint: PASS
pnpm typecheck: PASS
pnpm test: PASS (54 files, 868 tests)
pnpm --filter @oneshot/reconciliation test: PASS (74 tests)
pnpm --filter @oneshot/worker test -- --run test/p4-composition.test.ts: PASS
git diff --check: PASS
Targeted Prettier check: PASS
pnpm format:check: baseline FAIL only on two untouched generated subgraph files

Independent review evidence

Gate A — exact candidate tree before push

  • Base commit SHA: 48391e4

  • Candidate tree SHA: c63a4410a12044df11a419768fedf073392198a1

  • Candidate commit SHA: 8ed6096

  • Reviewer tool: free-pi-cli

  • Reviewer model: deepseek-v4-flash

  • Verdict: VERDICT: PASS

  • Findings or residual risks: no blockers; token propagation assertion could be stricter; finite numeric window has no maximum span guard.

  • The reviewed tree equals the committed tree.

Gate B — exact remote PR head

  • Pull request URL/number: fix: require recovery lookup config #44 (fix: require recovery lookup config #44)

  • Remote head commit SHA: 8ed6096

  • Remote head tree SHA: c63a4410a12044df11a419768fedf073392198a1

  • Reviewer tool: free-pi-cli

  • Reviewer model: deepseek-v4-flash

  • Verdict: VERDICT: PASS

  • Findings or residual risks: no blocking findings; token test could be stricter; numeric block window has no maximum span guard; live canonical Graph deployment/manifest IDs and live MCP/model adapters remain unconfigured by design.

  • Gate B reviewed the current remote head and matches Gate A's approved tree.

  • Agent policy / repository-policy and all applicable CI checks pass.

Risk and rollback

  • Residual risks: live canonical Graph identities and live MCP/model evidence are still absent; fallback remains selected.
  • Rollback or recovery plan: revert commit 8ed6096; unavailable ports remain the safe fallback.

Human merge

  • A human owner has reviewed the evidence and will perform the merge.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
oneshot 8ed6096 Sep 08 2026, 10:56 PM

@kapustazh
kapustazh marked this pull request as ready for review September 8, 2026 23:05
@kapustazh
kapustazh merged commit 97e56b5 into develop Sep 8, 2026
4 checks passed
@SuPuHe SuPuHe mentioned this pull request Sep 8, 2026
12 of 14 tasks
@kapustazh
kapustazh deleted the fix/production-recovery-config branch September 9, 2026 01:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant