cli: Remove unreachable recovery and search paths - #105
BenWestgate wants to merge 9 commits into
Conversation
Apply the established majority-case interpretation to standalone correction while preserving immutable context, entered edit semantics, and disclosure accounting. Account the normalized retry frontier even when the first optional search reaches its deadline after finding a candidate, so cumulative capture mass remains fail-closed. Fixes #37.
Give standalone correction a stable status contract: 0 for already-valid input, 1 when a suggestion is emitted, 2 for command or input syntax errors, and 3 when no usable suggestion is emitted. Keep incomplete best-effort suggestions at status 1 and document status 3 only for incomplete searches without a usable suggestion. Fixes #39.
Remove unreachable creation guards and the permanently false correction ambiguity field, align the CLI test Core stub with production, and move reference-only correction helpers out of the installed package. Security: fail-closed correction and wallet behavior are unchanged. Refs #38.
Normalize ordinary grouping spaces before locating the immutable prefix and interpreting mixed case. The correction search already uses compacted positions, so using raw offsets could turn locked header letters into erasures and hide a recoverable candidate. Add a public API regression with a grouped locked header and five mistyped lowercase symbols. Preserve the original input for displayed edit diagnostics. refs #37
Exercise the embedded five-minority-symbol recovery path with its production ten-second deadline and require both scheduled interpretations to complete. This makes the reviewer timing condition explicit instead of inferring it from scheduling order. Security: fail if either mixed-case interpretation cannot finish the shared required/optional search on the regression case. refs #37
Replace the assert-complete deadline test with two counter-examples: five minority-case P that only the erasure reading corrects, and fifteen minority-case X with one mistyped that only case normalization corrects. Each case checks that its other reading alone finds nothing and that the shared schedule still returns the backup within the ten-second deadline. On the first case the normalized reading's exhaustive optional search takes minutes, so the test cannot require a complete search; it requires the truncation to be reported. Make _scheduled_candidates report that truncation. Combine both full passes' completeness instead of keeping only the later pass, and mark returned candidates search_complete=False when either pass truncated, so a copy from a completed earlier pass cannot hide the later timeout. refs #37 Claude-Session: https://claude.ai/code/session_013gZvwvuocM7a7Ut4kiBFHw
Gate restore and existing-seed wallet initialization on the independently recorded BIP32 master fingerprint before any Bitcoin Core wallet mutation. Keep the correction path from disclosing or reusing a fingerprint derived from the candidate being authenticated. Fixes #30.
Every correction plan returned its target set, that same set as primary, an empty reduced set, and a true timed flag. Only the targets and primary set were consumed. Derive primary from targets at the call site and remove the other fields. The search engine also accepted reduced without reading it, so remove that argument and update its test and benchmark callers. Search order and capture accounting remain unchanged. Refs #46.
The preceding all-isinstance check rejects every non-share, so the list-comprehension predicate in recovery could never discard an item. Pass the validated list directly, using a type cast to express the established invariant to mypy. Recovery still copies and validates the sequence internally. Refs #46.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted release-gate re-review performed at the maintainer's request and disclosed per docs/developer/AI_POLICY.md.
ACK d886238.
This is the same two-commit cleanup previously reviewed as #98, replayed directly on refreshed #57. Stable patch-ids match #98 exactly. The changes only remove provably redundant correction-plan state and the already-type-checked share filter; correction scheduling, capture accounting, wallet behavior, and public input validation are unchanged.
Current-base verification: 101 focused CLI/correction tests passed, and the installed source is 5,179 logical lines under the authorized <5200 cap. No correctness blocker found.
a7efaae to
054e8d9
Compare
Restore the focused cleanup review boundary after #98 was mechanically absorbed into the #80 branch while the stack was reordered to preserve the
<5200source budget.The two commits are patch-identical to reviewed #98:
_correction_planprimary/reduced/timed state and_search_many(reduced=...)argument;recover_secret()instead of filtering it a second time.No correction scheduling, capture accounting, wallet behavior, or public input validation changes. The cleanup reduces the #57 tip from 5,193 to 5,179 logical source lines, which lets #80 and the later restore follow-ups remain under the maintainer-approved
<5200gate.Validation on this exact tree:
Human review order: #42 → #57 → this PR → #80 → #81 → #95.
Refs #46 and #98. Agent-authored cleanup; responsible-human rewrite or squash is required by repository policy before final integration.