Skip to content

fix(cert-var): certify the initial value and relax the freshness check - #1489

Merged
marc0olo merged 1 commit into
masterfrom
fix/cert-var-initial-certification
Sep 28, 2026
Merged

marc0olo merged 1 commit into
masterfrom
fix/cert-var-initial-certification

Conversation

@marc0olo

Copy link
Copy Markdown
Member

Two fixes to the Motoko cert-var example.

  • The initial value was never certified. Certified data starts empty on install, so a get before the first set returned value = 0 with an empty certified_data, and the frontend's check 4 failed. The actor now certifies its initial value at install (CD.set(blobOfNat32(value)) in the actor body). Verified on a fresh local install: certified_data = 00000000. After an upgrade, the certified value still matches.
  • The freshness check allowed 5 seconds. A client whose clock is a few seconds off failed a valid certificate. It now allows 5 minutes, which is the window Certificate.create() itself enforces by default (maxAgeInMinutes). The README says so too.

The spec link in the frontend comment pointed to the retired sdk.dfinity.org; it now links the certified data section of the interface spec.

mops check passes, test.sh passes 4/4, and the frontend shows "Success: Fully certified query response." in a browser.

Certified data starts empty, so a get before the first set failed
verification. The 5-second freshness window failed on small client clock
skew; it now matches the 5 minutes Certificate.create allows. Also replaces
a dead sdk.dfinity.org spec link.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Add coverage verifying the initial value is certified immediately after deployment.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Updates the Motoko cert-var example to certify its initial value and allow the SDK’s five-minute freshness window.

Changes:

  • Certifies the initial value during installation.
  • Relaxes freshness validation from five seconds to five minutes.
  • Updates documentation and the interface specification link.
File Summary
motoko/​cert-var/​README.md Documents the five-minute freshness window.
motoko/​cert-var/​frontend/​index.html Updates freshness validation and the specification link.
motoko/​cert-var/​backend/​main.mo Certifies the initial value; a pre-mutation regression test is requested.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread motoko/cert-var/backend/main.mo
@marc0olo
marc0olo merged commit 2887be0 into master Sep 28, 2026
7 checks passed
@marc0olo
marc0olo deleted the fix/cert-var-initial-certification branch September 28, 2026 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants