Skip to content

cli: Announce recovery secret switch - #95

Open
BenWestgate wants to merge 1 commit into
codex/30-existing-fingerprint-before-sharesfrom
codex/recovery-secret-switch-notice
Open

BenWestgate wants to merge 1 commit into
codex/30-existing-fingerprint-before-sharesfrom
codex/recovery-secret-switch-notice

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

What

When a complete valid secret is supplied after one or more shares were accepted, keep the existing deliberate behavior of ending share recovery and using that secret, but state that choice explicitly before returning it.

Why

The adversarial review correctly reproduced a silent mode switch. The switch itself is intentional; the defect is that already-accepted shares appeared to vanish without explanation.

Validation

  • focused interactive recovery regression: 3 passed;
  • full suite: 876 passed;
  • full suite under python -O: 876 passed;
  • Ruff check/format: clean;
  • strict mypy across 21 source files: clean;
  • git diff --check: clean.

Refs #38.

AI assistance: this focused follow-up is agent-authored. A responsible human should review and rewrite/squash it under the repository authorship policy before integration.

Current stack: head cebecfc is the same reviewed one-commit patch replayed directly on #81 (aa2d333); its stable patch-id is unchanged. The resulting library/CLI tip is 5,190 logical source lines. Human review order is #42 → #57 → #105 → #80 → #81 → #95.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate added area: cli Command-line interface behavior. bug Something isn't working gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. labels Oct 1, 2026
@BenWestgate
BenWestgate force-pushed the codex/recovery-secret-switch-notice branch from 12d2098 to 23dae08 Compare October 1, 2026 04:26
@BenWestgate

Copy link
Copy Markdown
Owner Author

Agent release-gate review at exact head 23dae08:

ACK on behavior. The adversarial-review finding was the silent mid-recovery mode switch: after compatible shares are already accepted, supplying a complete secret intentionally supersedes them. This patch preserves that policy and emits the notice only when accepted is non-empty, immediately before returning the complete secret.

Verification:

  • exact diff is limited to two production lines plus one regression assertion;
  • the existing compatible-share/secret regression passes 3/3 normally and 3/3 under python -O;
  • git diff --check is clean;
  • exact-head GitHub matrix is green and there are no review threads.

No code blocker found. Integration blocker remains authorship policy only: this is a Codex-authored commit and should be human-reviewed/re-written or squashed under the responsible human author before merge, as the PR body already records.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted review performed at the maintainer's request and disclosed per docs/developer/AI_POLICY.md.

No correctness findings. The change is narrowly scoped: it preserves the existing recovery behavior when a complete valid secret is entered after shares, but makes the mode switch explicit before returning the secret. The notice is conditioned on accepted, so it does not add noise when the secret is the first input. Focused recovery/secret tests pass locally (17 passed), and the exact-head GitHub matrix is green. Ready for human review/rewrite-squash under the repository authorship policy.

@BenWestgate
BenWestgate force-pushed the codex/recovery-secret-switch-notice branch from 23dae08 to 30062fd Compare October 1, 2026 18:30
@BenWestgate
BenWestgate changed the base branch from reviewability-v1 to codex/30-existing-fingerprint-before-shares October 1, 2026 18:30
@BenWestgate
BenWestgate force-pushed the codex/30-existing-fingerprint-before-shares branch from 7686cb0 to aa2d333 Compare October 1, 2026 18:36
@BenWestgate
BenWestgate force-pushed the codex/recovery-secret-switch-notice branch from 30062fd to cebecfc Compare October 1, 2026 18:36
@BenWestgate
BenWestgate force-pushed the codex/30-existing-fingerprint-before-shares branch from aa2d333 to 9f88b21 Compare October 1, 2026 22:15
@BenWestgate
BenWestgate force-pushed the codex/recovery-secret-switch-notice branch from cebecfc to 4ea72bb Compare October 1, 2026 22:16

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head release-gate re-review: ACK 4ea72bb. This remains the same reviewed one-line behavior change by stable patch-id: when a complete valid secret is supplied after accepted shares, the CLI explicitly announces that it is switching to that secret; first-input secret recovery stays quiet. The exact integrated tip passes 935 tests normally and optimized, including the focused recovery-switch regression, and remains 5,193 <5200. No code blocker found. The agent-authored commit requires responsible-human rewrite/squash before integration.

@BenWestgate
BenWestgate force-pushed the codex/30-existing-fingerprint-before-shares branch from 9f88b21 to 1d5b6f5 Compare October 2, 2026 08:59
Entering a complete valid secret during interactive share recovery intentionally supersedes the partial share set. Previously that mode switch happened silently, which made correct behavior look like discarded input.

Emit one explicit notice only when shares were already accepted, and pin the behavior in the existing interactive recovery regression.

Refs #38
@BenWestgate
BenWestgate force-pushed the codex/recovery-secret-switch-notice branch from 4ea72bb to 3d8510a Compare October 2, 2026 09:08

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: cli Command-line interface behavior. bug Something isn't working gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants