Skip to content

Remove pre-review CLI dead code - #46

Merged
BenWestgate merged 1 commit into
codex/37-mixed-case-correctionfrom
codex/v1-pre-review-cleanup
Oct 1, 2026
Merged

BenWestgate merged 1 commit into
codex/37-mixed-case-correctionfrom
codex/v1-pre-review-cleanup

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Remove the mechanical cleanup items recorded by the adversarial-review triage and reduce installed review surface without changing user-visible behavior:

  • remove the redundant _create terminal guard;
  • remove the permanently false correction ambiguity return field and unreachable consumer while preserving the mixed-case required-before-optional scheduling and capture accounting;
  • update test doubles/mocks to the resulting three-value _correction_candidates() contract;
  • remove the fake Bitcoin Core initialize(private=...) state that production does not expose;
  • move correction helpers used only by tests/benchmarks from src/codex32/indel.py to tools/correction_reference.py;
  • remove the tracked extra blank line in pyproject.toml.

Why this now precedes #57

The current Core-native reviewability-v1 base increased installed source enough that the focused #57 restore-authentication change reaches 5,228 production logical lines by itself, exceeding the maintainer-authorized <5200 gate. The already-reviewed mechanical cleanup is independent of that security behavior and reduces the #42 tip from 5,124 to 5,030 lines. Applying it first lets #57 remain focused and keeps every intermediate commit inside the existing budget without raising the cap or taking a risky refactor merely to save lines.

Current head 0867a1b is one focused Ben Westgate-authored cleanup commit stacked directly on #42 (4be79a7). Conflict resolution deliberately preserved #42's current wallet behavior; #57-specific record/fingerprint behavior is no longer bundled into this cleanup.

Validation

  • installed production logical review lines: 5,030, below <5200;
  • local exact-head suite: 898 passed normally;
  • local exact-head optimized suite: 898 passed under python -O;
  • all 232 CLI tests pass;
  • strict mypy passes on all 21 source files;
  • Ruff check and format check pass;
  • correction constants verification passes;
  • frozen differential correction verifier passes all 57 cases;
  • git diff --check is clean.

Human review order is now #42 → #46 → refreshed #57. #80 and #81 follow #57. This ordering is mechanical: it exists to keep the authorized review-size invariant true at every step.

Intentional non-goals: no correction-policy change, wallet-identity change, helper/API publication, or fuzzing-policy change. Those are owned by #42/#45, #57/#81, #53, and #40/#47 respectively.

AI assistance was used for the user-authorized restack/conflict validation; the squash/restack does not substitute for responsible maintainer review.

@BenWestgate

Copy link
Copy Markdown
Owner Author

Agent handoff: before declaring the pre-review cleanup complete, read the ignored local checklist at docs/planning/v1-pre-review-cleanup.md. It records the three changes in this PR, validation commands, related gates #38–#41, and explicit non-goals. Please respond here if the local file is missing or any checklist item is not represented by commit 11e1a2d.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate added area: cli Command-line interface behavior. gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. labels Sep 24, 2026

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

Concept ACK. Code looks right; not ACKing 7e7c649 until the merge commits are gone.

  • Removed branches are unreachable: _create already requires a TTY on stdin/stdout, and _connected_core never returns None. ambiguous was always False.
  • Rebase away 825b863/ccabfee.
  • The PR body points to docs/planning/v1-pre-review-cleanup.md, which is local and ignored, so reviewers can't read it. Inline the non-goals or drop the pointer.
  • Conflicts with #53 and #57.

Copy link
Copy Markdown
Owner Author

Review follow-up: the PR body no longer points reviewers at the ignored local planning file; the non-goals are now inline. The remaining NACK item is the branch history itself: rebase away the two base-refresh merge commits before human review. I’m leaving #46 behind #45 in the review order until that rewrite is done.

@BenWestgate
BenWestgate force-pushed the codex/39-correct-exit-status branch from 5a826bd to eb7cfdd Compare September 27, 2026 03:20
@BenWestgate BenWestgate added area: correction Correction engine and correction UX. area: wallet/core Wallet integration and Bitcoin Core boundaries. labels Sep 27, 2026 — with ChatGPT Codex Connector
@BenWestgate
BenWestgate force-pushed the codex/v1-pre-review-cleanup branch from 7e7c649 to 28b06c6 Compare September 27, 2026 16:36

Copy link
Copy Markdown
Owner Author

Release-gate follow-up: the earlier history NACK is resolved. Current head 28b06c6 is one human-authored cleanup commit directly on #45 head eb7cfdd; the base-refresh merges and agent-authored commit are gone, and fresh Python package run 36333842809 completed successfully. The remaining dependency is sequencing, not a defect in this head: review/merge #45, then #57, then refresh this one cleanup commit once onto the integrated reviewability-v1 tip because it overlaps #57 in cli.py/tests/test_cli.py.

@BenWestgate
BenWestgate force-pushed the codex/39-correct-exit-status branch 8 times, most recently from d1ecc82 to c943e9a Compare September 28, 2026 03:48
@BenWestgate

Copy link
Copy Markdown
Owner Author

Release-gate refresh note: final #45 is now c943e9a and #57 is eff541c0. I simulated reviewability-v1 → #42 → #45 → #57: all three merge cleanly. Reapplying this cleanup then conflicts only in src/codex32/cli.py and tests/test_cli.py, where the refresh must preserve #57’s restore-identity parameters/behavior while removing the dead cleanup paths. No final review requested until that one refresh is done after the prerequisites land.

@BenWestgate

Copy link
Copy Markdown
Owner Author

Final-refresh addendum: disposable replay of this single cleanup commit on the current combined #12/#13/#59/#7/#51/#33/#42/#45/#57 stack resolves only the expected cli.py/test_cli.py conflicts when replayed as a commit, but the resulting installed package is 5,098 logical review lines. That fails the documented <5000 v1 invariant. Tracked as #61.

Do not raise the budget in this PR. The post-prerequisite cleanup refresh must either recover at least 99 real review lines while preserving #42/#57 behavior or compose with a separate focused cleanup that does, then rerun the exact combined-tree size test.

@BenWestgate
BenWestgate force-pushed the codex/39-correct-exit-status branch 2 times, most recently from 19a59dd to 3d5e60d Compare September 28, 2026 23:21

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review, posted at the maintainer's request.

Not ACKing 28b06c6 yet: this head is intentionally stale/conflicting. Refresh it after #42/#45/#57 land, then rerun validation.

@BenWestgate
BenWestgate force-pushed the codex/39-correct-exit-status branch 3 times, most recently from bfd8b1b to 794f898 Compare September 29, 2026 23:44
@BenWestgate
BenWestgate force-pushed the codex/v1-pre-review-cleanup branch from 28b06c6 to 9a3b845 Compare September 30, 2026 01:19
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Reassign the expected_fingerprint argument instead of copying it into a
local, and give existing_secret its None default before the source
checks instead of in an else branch.

Behavior is unchanged. The installed package drops from 5161 to 5159
logical review lines, which keeps the integrated #7/#42/#57/#46/#80/#81
tip under the <5200 budget.

Security: the record gate still runs before any card is generated or
shown, and interrupts at that gate still raise _WalletSetupInterrupted.

Validation: ruff check, ruff format --check, mypy src/codex32, and
pytest (918 passed, with and without -O).

Refs #81, #38.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018az69UX4773mYohXAtE8kD
@BenWestgate

Copy link
Copy Markdown
Owner Author

AI-assisted release-gate recheck at exact head 0793590. Code ACK. I reviewed the current one-commit delta after the correction helper split: it preserves _scheduled_candidates() and the required-before-optional/capture-ledger behavior, removes only the permanently-false ambiguity field and consumers, unreachable TTY/disconnected-Core branches, the fake-only private= test parameter, and reference-only indel helpers from installed source. Exact-head run 36801637475 is green and there are no unresolved review threads. No remaining code blocker in #46 itself; final integration still waits for human integration of #42, then the one-time #57 refresh. The commit is already Ben Westgate-authored.

Remove unreachable creation guards and the permanently false correction ambiguity field, align the CLI test Core stub with production, and move reference-only correction helpers out of the installed package.\n\nSecurity: fail-closed correction and wallet behavior are unchanged.\n\nRefs #38.
@BenWestgate
BenWestgate force-pushed the codex/v1-pre-review-cleanup branch from 0793590 to 0867a1b Compare October 1, 2026 03:01
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate
BenWestgate changed the base branch from 30-recorded-fingerprint-gate to codex/37-mixed-case-correction October 1, 2026 03:02

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release-gate ACK 0867a1b.

I re-reviewed the refreshed one-commit cleanup on current #42. The earlier nACK was mechanical/staleness only; current head removes the unreachable _create guards, permanently-false ambiguity field, drifted Core test-double state, and reference-only installed helpers without changing correction policy or wallet behavior. The branch is now one Ben Westgate-authored commit with no unresolved inline threads. Exact-head local validation passed 898 tests normally and under python -O, all 232 CLI tests, strict mypy, Ruff check/format, correction-constant verification, all 57 frozen differential cases, and git diff --check.

No code blocker remains from this review. The dependency-aware order is #42 → #46 → #57; placing this mechanical cleanup before #57 keeps the installed-source budget below the authorized <5200 cap at every intermediate tip.

@BenWestgate

Copy link
Copy Markdown
Owner Author

Agent exact-head review on 0867a1b:

  • reviewed the full one-commit diff against correct: Interpret mixed-case damage #42;
  • removed correction helpers are referenced only from tests/ and tools/, not installed production code;
  • the correction ambiguity field was permanently false and its removal leaves the fail-closed incomplete/no-candidate behavior intact;
  • the duplicate _create TTY guard is unreachable after the existing enclosing interactive-terminal check;
  • affected local suite: 349 passed; git diff --check is clean; exact-head GitHub CI is green.

No code blocker found. One non-blocking commit-message nit remains: the commit body contains literal \\n\\n escape text (and a trailing quote) instead of paragraph breaks. Fix that when the human rewrites/signs the commit for integration; rewriting #46 solely for this nit now would unnecessarily invalidate the already-reviewed #57 stack.

BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Reassign the expected_fingerprint argument instead of copying it into a
local, and give existing_secret its None default before the source
checks instead of in an else branch.

Behavior is unchanged. The installed package drops from 5161 to 5159
logical review lines, which keeps the integrated #7/#42/#57/#46/#80/#81
tip under the <5200 budget.

Security: the record gate still runs before any card is generated or
shown, and interrupts at that gate still raise _WalletSetupInterrupted.

Validation: ruff check, ruff format --check, mypy src/codex32, and
pytest (918 passed, with and without -O).

Refs #81, #38.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018az69UX4773mYohXAtE8kD
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Backup creation rejects a noninteractive terminal before this branch, so the later stdin.isatty() rejection can never run. Removing it preserves the interactive behavior and leaves the integrated source under its strict review line budget. Refs #46 and #81.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@BenWestgate
BenWestgate merged commit cd46d3f into codex/37-mixed-case-correction Oct 1, 2026
10 checks passed
@BenWestgate
BenWestgate deleted the codex/v1-pre-review-cleanup branch October 1, 2026 06:59
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Every correction plan returned its target set, that same set as primary, an empty reduced set, and a true timed flag. Only the targets and primary set were consumed. Derive primary from targets at the call site and remove the other fields. The search engine also accepted reduced without reading it, so remove that argument and update its test and benchmark callers. Search order and capture accounting remain unchanged. Refs #46.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
The preceding all-isinstance check rejects every non-share, so the list-comprehension predicate in recovery could never discard an item. Pass the validated list directly, using a type cast to express the established invariant to mypy. Recovery still copies and validates the sequence internally. Refs #46.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Reassign the expected_fingerprint argument instead of copying it into a
local, and give existing_secret its None default before the source
checks instead of in an else branch.

Behavior is unchanged. The installed package drops from 5161 to 5159
logical review lines, which keeps the integrated #7/#42/#57/#46/#80/#81
tip under the <5200 budget.

Security: the record gate still runs before any card is generated or
shown, and interrupts at that gate still raise _WalletSetupInterrupted.

Validation: ruff check, ruff format --check, mypy src/codex32, and
pytest (918 passed, with and without -O).

Refs #81, #38.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018az69UX4773mYohXAtE8kD
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Backup creation rejects a noninteractive terminal before this branch, so the later stdin.isatty() rejection can never run. Removing it preserves the interactive behavior and leaves the integrated source under its strict review line budget. Refs #46 and #81.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Every correction plan returned its target set, that same set as primary, an empty reduced set, and a true timed flag. Only the targets and primary set were consumed. Derive primary from targets at the call site and remove the other fields. The search engine also accepted reduced without reading it, so remove that argument and update its test and benchmark callers. Search order and capture accounting remain unchanged. Refs #46.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
The preceding all-isinstance check rejects every non-share, so the list-comprehension predicate in recovery could never discard an item. Pass the validated list directly, using a type cast to express the established invariant to mypy. Recovery still copies and validates the sequence internally. Refs #46.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Reassign the expected_fingerprint argument instead of copying it into a
local, and give existing_secret its None default before the source
checks instead of in an else branch.

Behavior is unchanged. The installed package drops from 5161 to 5159
logical review lines, which keeps the integrated #7/#42/#57/#46/#80/#81
tip under the <5200 budget.

Security: the record gate still runs before any card is generated or
shown, and interrupts at that gate still raise _WalletSetupInterrupted.

Validation: ruff check, ruff format --check, mypy src/codex32, and
pytest (918 passed, with and without -O).

Refs #81, #38.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018az69UX4773mYohXAtE8kD
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Backup creation rejects a noninteractive terminal before this branch, so the later stdin.isatty() rejection can never run. Removing it preserves the interactive behavior and leaves the integrated source under its strict review line budget. Refs #46 and #81.
BenWestgate added a commit that referenced this pull request Oct 1, 2026
Remove unreachable creation guards and the permanently false correction ambiguity field, align the CLI test Core stub with production, and move reference-only correction helpers out of the installed package.

Security: fail-closed correction and wallet behavior are unchanged.

Refs #38.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Every correction plan returned its target set, that same set as primary, an empty reduced set, and a true timed flag. Only the targets and primary set were consumed. Derive primary from targets at the call site and remove the other fields. The search engine also accepted reduced without reading it, so remove that argument and update its test and benchmark callers. Search order and capture accounting remain unchanged. Refs #46.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
The preceding all-isinstance check rejects every non-share, so the list-comprehension predicate in recovery could never discard an item. Pass the validated list directly, using a type cast to express the established invariant to mypy. Recovery still copies and validates the sequence internally. Refs #46.
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Reassign the expected_fingerprint argument instead of copying it into a
local, and give existing_secret its None default before the source
checks instead of in an else branch.

Behavior is unchanged. The installed package drops from 5161 to 5159
logical review lines, which keeps the integrated #7/#42/#57/#46/#80/#81
tip under the <5200 budget.

Security: the record gate still runs before any card is generated or
shown, and interrupts at that gate still raise _WalletSetupInterrupted.

Validation: ruff check, ruff format --check, mypy src/codex32, and
pytest (918 passed, with and without -O).

Refs #81, #38.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018az69UX4773mYohXAtE8kD
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Backup creation rejects a noninteractive terminal before this branch, so the later stdin.isatty() rejection can never run. Removing it preserves the interactive behavior and leaves the integrated source under its strict review line budget. Refs #46 and #81.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: cli Command-line interface behavior. area: correction Correction engine and correction UX. area: wallet/core Wallet integration and Bitcoin Core boundaries. gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant