Skip to content

cli: Remove unreachable recovery and search paths - #105

Open
BenWestgate wants to merge 9 commits into
30-recorded-fingerprint-gatefrom
codex/remove-unreachable-v1-branches
Open

BenWestgate wants to merge 9 commits into
30-recorded-fingerprint-gatefrom
codex/remove-unreachable-v1-branches

Conversation

@BenWestgate

Copy link
Copy Markdown
Owner

Restore the focused cleanup review boundary after #98 was mechanically absorbed into the #80 branch while the stack was reordered to preserve the <5200 source budget.

The two commits are patch-identical to reviewed #98:

  • remove the unused _correction_plan primary/reduced/timed state and _search_many(reduced=...) argument;
  • pass the already-type-checked share list directly to recover_secret() instead of filtering it a second time.

No correction scheduling, capture accounting, wallet behavior, or public input validation changes. The cleanup reduces the #57 tip from 5,193 to 5,179 logical source lines, which lets #80 and the later restore follow-ups remain under the maintainer-approved <5200 gate.

Validation on this exact tree:

Human review order: #42 → #57 → this PR → #80 → #81 → #95.

Refs #46 and #98. Agent-authored cleanup; responsible-human rewrite or squash is required by repository policy before final integration.

BenWestgate and others added 9 commits September 30, 2026 21:35
Apply the established majority-case interpretation to standalone correction while preserving immutable context, entered edit semantics, and disclosure accounting. Account the normalized retry frontier even when the first optional search reaches its deadline after finding a candidate, so cumulative capture mass remains fail-closed.

Fixes #37.
Give standalone correction a stable status contract: 0 for already-valid input, 1 when a suggestion is emitted, 2 for command or input syntax errors, and 3 when no usable suggestion is emitted. Keep incomplete best-effort suggestions at status 1 and document status 3 only for incomplete searches without a usable suggestion.

Fixes #39.
Remove unreachable creation guards and the permanently false correction ambiguity field, align the CLI test Core stub with production, and move reference-only correction helpers out of the installed package.

Security: fail-closed correction and wallet behavior are unchanged.

Refs #38.
Normalize ordinary grouping spaces before locating the immutable prefix and interpreting mixed case. The correction search already uses compacted positions, so using raw offsets could turn locked header letters into erasures and hide a recoverable candidate.

Add a public API regression with a grouped locked header and five mistyped lowercase symbols. Preserve the original input for displayed edit diagnostics.

refs #37
Exercise the embedded five-minority-symbol recovery path with its production ten-second deadline and require both scheduled interpretations to complete. This makes the reviewer timing condition explicit instead of inferring it from scheduling order.

Security: fail if either mixed-case interpretation cannot finish the shared required/optional search on the regression case.

refs #37
Replace the assert-complete deadline test with two counter-examples:
five minority-case P that only the erasure reading corrects, and
fifteen minority-case X with one mistyped that only case
normalization corrects. Each case checks that its other reading alone
finds nothing and that the shared schedule still returns the backup
within the ten-second deadline. On the first case the normalized
reading's exhaustive optional search takes minutes, so the test cannot
require a complete search; it requires the truncation to be reported.

Make _scheduled_candidates report that truncation. Combine both full
passes' completeness instead of keeping only the later pass, and mark
returned candidates search_complete=False when either pass truncated,
so a copy from a completed earlier pass cannot hide the later timeout.

refs #37

Claude-Session: https://claude.ai/code/session_013gZvwvuocM7a7Ut4kiBFHw
Gate restore and existing-seed wallet initialization on the independently recorded BIP32 master fingerprint before any Bitcoin Core wallet mutation. Keep the correction path from disclosing or reusing a fingerprint derived from the candidate being authenticated.

Fixes #30.
Every correction plan returned its target set, that same set as primary, an empty reduced set, and a true timed flag. Only the targets and primary set were consumed. Derive primary from targets at the call site and remove the other fields. The search engine also accepted reduced without reading it, so remove that argument and update its test and benchmark callers. Search order and capture accounting remain unchanged. Refs #46.
The preceding all-isinstance check rejects every non-share, so the list-comprehension predicate in recovery could never discard an item. Pass the validated list directly, using a type cast to express the established invariant to mypy. Recovery still copies and validates the sequence internally. Refs #46.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted release-gate re-review performed at the maintainer's request and disclosed per docs/developer/AI_POLICY.md.

ACK d886238.

This is the same two-commit cleanup previously reviewed as #98, replayed directly on refreshed #57. Stable patch-ids match #98 exactly. The changes only remove provably redundant correction-plan state and the already-type-checked share filter; correction scheduling, capture accounting, wallet behavior, and public input validation are unchanged.

Current-base verification: 101 focused CLI/correction tests passed, and the installed source is 5,179 logical lines under the authorized <5200 cap. No correctness blocker found.

@BenWestgate BenWestgate added area: cli Command-line interface behavior. area: correction Correction engine and correction UX. gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. labels Oct 1, 2026
@BenWestgate
BenWestgate force-pushed the 30-recorded-fingerprint-gate branch from a7efaae to 054e8d9 Compare October 1, 2026 22:02

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: cli Command-line interface behavior. area: correction Correction engine and correction UX. gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants