Integrate msgctl OAuth authority fixes, bounty acceptance and bounded HTTP reads - #196
Conversation
… reads Preserve original PR heads as parents. Clarify msgctl package and command names, and distinguish the published PyPI package from current source candidates.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
All eleven blobs from PR #195 exactly match the existing candidate. Retain that integration head as a parent without changing the source tree.
…note lifecycle Add thirteen real PostgreSQL vectors across SOUL, AGENTS, Notes and Legacy. Verify exact history/content proofs, current authority loss, full-row rollback for body tampering/foreign signatures and note archive/restore proof conservation.
|
Current-head coordination: 14022b6 applies the Ruff formatting correction to the 13 new personal-statement PostgreSQL vectors introduced by 95f5c6b. The complete #192/#194 fixes and #195 history remain present; the new tests add useful evidence and should stay. Please keep this candidate's scope stable while its complete current-head CI finishes, and put further independent additions in follow-up PRs. Substantive pushes restart final-tree verification; earlier green runs cannot establish this newer tree. Continue all required checks and assertions. #195 is now documented as superseded by this PR, so there is one integration path. |
|
The current 14022b6 full-suite failures in the new note/legacy revocation vectors are a fixture API mismatch at tests/test_personal_signed_boundaries.py:102: PostgresSession has no put() method. The assertions before that setup step pass; this does not establish a production revocation failure. I am preparing the minimal replacement with the existing save_credential(updated_credential, subject.auth_version) API, preserving all 13 vectors and subsequent conservation assertions. Evidence: https://github.com/TokenNotIncluded/msg.lmm.best/actions/runs/36702779809/job/109846412688 |
|
Fixed the fixture mismatch in 9224dee (tree e20b8c97): use save_credential with the owner's current auth_version instead of the nonexistent put method. This changes only test setup; all 13 vectors and every revocation/history/conservation assertion remain. Ruff check/format and Python 3.15 compilation pass. The real PostgreSQL assertions and full combined gates are running on this new head; earlier deployment/locale passes are not claimed as its final result. |
…ates Preserve the concurrent save_credential setup fix at 9224dee. Keep the complete core gate and run these thirteen cases in the targeted dual-locale workflow as well.
|
Final validation for 597cb1d / tree 2dc9744c is green: all 12 applicable PR workflows passed, including all eight core shards and the aggregate check confirming 2,662 distinct non-overlapping test nodes. Both focused locales passed 133 tests, including all 13 personal-statement vectors after the fixture correction. C took 283.50s of tests / 6m01s overall; en_US.utf8 took 195.83s / 4m11s overall, within the unchanged 10-minute budget. Downloaded deployment artifact 11092170741 and verified ZIP SHA-256 bc2254e97ab9510780ffdb81d6d9541e9c95dd31051ba3301d746a3bbd7690ae. Its source tree matches 2dc9744c and all 42 installed official self-tests pass. The superseded push integration cancellation is not counted as a pass. No merge or production action has been completed by this validation. Full gate: https://github.com/TokenNotIncluded/msg.lmm.best/actions/runs/36704637603 |
Current main merged OAuth #189 without the closed follow-up #192. This integration brings the latest #192 source-ceiling/read-only-userinfo fixes into main, retaining the active-vault/current-policy rules for custodial login and the existing one-hour-bootstrap-expiry positive regression.
Also includes #191/#193 public Bounty lifecycle and real CLI restart/replay assertions, and #194 bounded malformed Range handling. Original heads c92135b, a02c956 and 0f057bf are additional parents; #187/#188 and already-merged #190 remain in the main parent. No author branch is overwritten.
Clarifies the project/PyPI name msgctl and commands msg/msgd in both READMEs and deployment handoff. PyPI 0.1.0a1 is already published; its exact wheel/sdist digests are recorded separately from the candidate. Corrects the changelog's unimplemented 1.x version claim without changing metadata or publishing a package.
Individual artifact verification completed: #192 tree13f4c2b has exact2590 core+8 conformance,120 real-PG regressions in each C/en_US.utf8,597 formatted files; #193 tree0c92b908 has exact2594+8,591 formatted files. Both have zero Ruff/stderr, matching core/deploy wheel+sdist,release hash locks,installed server12,real sshd7 and official selftest42. These results do not substitute for this combined tree.
Concurrent #195 head 4488343 is also preserved as an additional parent; all eleven blobs matched exactly.
Adds thirteen real PostgreSQL acceptance vectors across SOUL, AGENTS, Notes and Legacy: exact independently signed history/content bytes, anonymous/foreign current+fixed+history reads and search privacy, current signing-key revocation with full-row conservation, body tampering/foreign-content-key full rollback, signed Notes archive/restore proof preservation. No new production bypass or assertion weakening. Refs #77.
Latest candidate head 597cb1d, tree 2dc9744ccc417c12ed2dbdbe160eb6cc5a552a67. Full combined exact-node-ID, quality, applicable specialist and installed-package deployment gates are required before merge. No production access, money changes, external messages, recovery promotion or PyPI upload.
Refs #72,#76,#78,#79,#82,#83,#84.
The first new-personal core run exposed a test setup AttributeError at tx.put (not a production behavior failure). Corrected to the actual save_credential(credential, expected_auth_version) interface. The completed shards' negative signature and signed note lifecycle cases had passed; all current-key/privacy cases and the complete combined tree are rerun, with the thirteen new cases also in both focused locales. No skip/xfail or loosened assertion.
The concurrent setup fix 9224dee is preserved as the direct parent. No force update was used.