cli: Announce recovery secret switch - #95
BenWestgate wants to merge 1 commit into
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
12d2098 to
23dae08
Compare
|
Agent release-gate review at exact head ACK on behavior. The adversarial-review finding was the silent mid-recovery mode switch: after compatible shares are already accepted, supplying a complete secret intentionally supersedes them. This patch preserves that policy and emits the notice only when Verification:
No code blocker found. Integration blocker remains authorship policy only: this is a Codex-authored commit and should be human-reviewed/re-written or squashed under the responsible human author before merge, as the PR body already records. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted review performed at the maintainer's request and disclosed per docs/developer/AI_POLICY.md.
No correctness findings. The change is narrowly scoped: it preserves the existing recovery behavior when a complete valid secret is entered after shares, but makes the mode switch explicit before returning the secret. The notice is conditioned on accepted, so it does not add noise when the secret is the first input. Focused recovery/secret tests pass locally (17 passed), and the exact-head GitHub matrix is green. Ready for human review/rewrite-squash under the repository authorship policy.
23dae08 to
30062fd
Compare
7686cb0 to
aa2d333
Compare
30062fd to
cebecfc
Compare
aa2d333 to
9f88b21
Compare
cebecfc to
4ea72bb
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Exact-head release-gate re-review: ACK 4ea72bb. This remains the same reviewed one-line behavior change by stable patch-id: when a complete valid secret is supplied after accepted shares, the CLI explicitly announces that it is switching to that secret; first-input secret recovery stays quiet. The exact integrated tip passes 935 tests normally and optimized, including the focused recovery-switch regression, and remains 5,193 <5200. No code blocker found. The agent-authored commit requires responsible-human rewrite/squash before integration.
9f88b21 to
1d5b6f5
Compare
4ea72bb to
3d8510a
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head re-review: ACK 3d8510a.
The current diff is still the focused disclosure fix: when a complete valid secret is supplied after shares have already been accepted, recovery explicitly tells the operator it is switching to that secret; the first-input secret path stays quiet. There are no inline review threads, and exact-head Python-package run 666 succeeded.
No code blocker found. The agent-authored commit still requires responsible-human rewrite/squash before integration.
Entering a complete valid secret during interactive share recovery intentionally supersedes the partial share set. Previously that mode switch happened silently, which made correct behavior look like discarded input. Emit one explicit notice only when shares were already accepted, and pin the behavior in the existing interactive recovery regression. Refs #38
3d8510a to
5e44dcb
Compare
1d5b6f5 to
b2aafde
Compare
|
@codex review |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head review: ACK 5e44dcb. The intentional complete-secret switch is now announced only after shares were accepted; behavior is otherwise unchanged. Exact-head package CI is green.
What
When a complete valid secret is supplied after one or more shares were accepted, keep the existing deliberate behavior of ending share recovery and using that secret, but state that choice explicitly before returning it.
Why
The adversarial review correctly reproduced a silent mode switch. The switch itself is intentional; the defect is that already-accepted shares appeared to vanish without explanation.
Review shape
Current head
5e44dcbis the same one focused #95 commit mechanically replayed directly onto refreshed #81 (b2aafde). The review delta remains two source/test files with three added lines.Validation
The three secret-after-compatible-shares regressions pass normally and under
python -O. The exact-head GitHub matrices are green,git diff --checkis clean, and Codex found no major issue on reviewed commit5e44dcb22e. The composed refreshed stack also passes all 941 tests normally and all 941 underpython -O, plus Ruff, format, strict mypy, and correction-constant verification.Refs #38.
Human integration order is #57 → #105 → #99 → #80 → #81 → #95. This commit is agent-authored and requires responsible-human review/rewrite or squash under repository policy before integration.