Skip to content

Harden recovery sponsorship and refine the public journey - #2

Merged
dolepee merged 26 commits into
mainfrom
ui/recovery-drill-polish
Aug 29, 2026
Merged

dolepee merged 26 commits into
mainfrom
ui/recovery-drill-polish

Conversation

@dolepee

@dolepee dolepee commented Aug 29, 2026 •

Copy link
Copy Markdown
Owner

Outcome

Closes every actionable Codex finding, hardens repeatable private-exit sponsorship, and upgrades the public owner/successor product without changing the deployed Cairo contract.

Security and reliability

  • fails closed before ordinary funding unless live exit capacity is executable
  • serializes the supported public funding route with owner-bound admission
  • persists deterministic hashes and exact signed artifacts before broadcast
  • fences hashless and prepared retries with owner tokens and bounded takeover
  • reconciles ambiguous checkpoint, cancellation and claim attempts byte-for-byte after reload
  • keeps matching exit reconciliation reachable after terminal vault state
  • clears retained packages only after confirmed terminal failure or success
  • pins pool, contract, token, amount, state, epoch, nonce, signer and exact destination note
  • separates control and exit budgets while preserving the shared nonce lane
  • reports capacity from allowance, balance, liabilities, daily exposure and active reservations

Complete public product

  • canonical NORMAL mode: 30-day inactivity and 7-day grace
  • clearly labelled five-minute Recovery Drill
  • owner-key exact-note private cancellation with irreversible-action confirmation
  • successor-key exact-note private claim
  • mandatory plaintext-secret warning plus backup download-and-restore verification before funding
  • direct owner invitation recovery after browser-state loss
  • reload-persistent contextual receipts and multi-vault invitation storage
  • compatible non-prerelease Ready 5.x policy at or above 5.33.9 with runtime capability checks
  • responsive, keyboard-visible, reduced-motion, 44px-target interface
  • real manifest, robots, sitemap, RFC 9116 security metadata and Cloudflare Pages headers

Exact-head evidence

  • Cairo: 63/63
  • client: 52/52
  • relayer: 84/84
  • public product: 32/32
  • Worker typecheck, lint, production/staging dry-runs and startup profile: pass
  • web TypeScript and production build: pass
  • locked Sierra/CASM artifact verification: pass
  • production npm audits: zero reported vulnerabilities
  • required GitHub CI: green

Merge remains prohibited until a completed clean top-level @codex review covers exact head 89b02ac2ad603864ceb76fad3b25cc5ad65dabc0, every actionable thread is resolved, and required CI remains green. Any new commit invalidates the review.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review\n\nPlease review the exact current head commit 491bda7. Confirm every actionable finding from PR #1 is fully resolved, and perform a full-tree correctness, reliability, privacy, UX, migration, and test-coverage review. Do not limit the review to the displayed diff.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review\n\nPlease security-review the exact current head commit 491bda7, including the exit kill switch, submitted-receipt reconciliation, ambiguous RPC handling, pool-class/action pinning, split-budget migration, rate-limit ordering, live claim-capacity gate, and browser funding fail-closed behavior. Do not approve a different head.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-08-29T13:03:06.958594Z 89b02ac Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review the exact current head commit 491bda7. Confirm every actionable finding from PR #1 is fully resolved, and perform a full-tree correctness, reliability, privacy, UX, migration, and test-coverage review. Do not limit the review to the displayed diff.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review

Please security-review the exact current head commit 491bda7, including the exit kill switch, submitted-receipt reconciliation, ambiguous RPC handling, pool-class/action pinning, split-budget migration, rate-limit ordering, live claim-capacity gate, and browser funding fail-closed behavior. Do not approve a different head.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Unknown error
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 491bda7477

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/src/main.ts Outdated
Comment thread relayer/src/budget.ts
Comment thread relayer/src/index.ts Outdated
Comment thread relayer/src/exit-executor.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

New commit 3bd52cd invalidates the prior review. Please review this exact current head. Re-check all PR #1 findings plus the realistic NORMAL mode, generalized exact-note CLAIM/CANCEL_REFUND sponsor, one-outstanding-reserve funding-capacity rule, invitation-to-Mainnet parity checks, and owner cancellation UX. Perform a full-tree correctness, reliability, privacy, migration, and test-coverage review. Do not approve a different head.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review

Security-review exact head 3bd52cd. Focus on the shared 12→6 STRK one-exit allowance, zero-liability funding admission, live class/liability reads, owner-vs-successor authorization domains, cancellation irreversibility, submitted-exit reconciliation, rate-limit ordering, and kill-switch behavior. Do not approve a different head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3bd52cd1c8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread relayer/src/index.ts
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review\n\nNew commit 16c7e13 invalidates every prior review. Review this exact current head and confirm all findings on 3bd52cd are fully resolved. Re-check the full tree, including conservative legacy exposure migration, kill-switch-safe receipt-only reconciliation, stable vault/action exit limiting, live checkpoint funding-capacity enforcement, truthful non-atomic admission wording, reliability, privacy, UX, and regression coverage. Do not approve a different head.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review\n\nSecurity-review exact current head 16c7e13. Verify all prior findings are resolved and re-audit the complete public tree, especially migration exposure, kill-switch reconciliation without rebroadcast, stable exit abuse keys, funding checkpoint fail-closed behavior, shared nonce/budget invariants, exact-note CLAIM/CANCEL_REFUND validation, ambiguous RPC handling, and secrets/privacy boundaries. Do not approve a different head.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review\n\nExact-head clarification: review commit 16c7e13. This is the current PR head; no shorter or different revision is acceptable for the merge gate. Review the full tree and all previously reported findings.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review\n\nExact-head clarification: security-review commit 16c7e13. This is the current PR head; no shorter or different revision is acceptable for the merge gate. Re-audit the full tree and all previously reported findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Unknown error
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

1 similar comment
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Unknown error
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 16c7e1368c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread relayer/src/index.ts Outdated
Comment thread relayer/src/exit-executor.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review\n\nNew commit a1ab105 invalidates all prior reviews. Review this exact current head, not any predecessor. Confirm every PR #2 thread is resolved, including the two previously hidden findings: fresh browser and checkpoint capacity reads before funding, and ledger-aware capacity covering freeze, active reservations, and same-day exit exposure. Re-audit the complete tree for correctness, security, reliability, privacy, UX, migration, and test coverage.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review\n\nSecurity-review exact current head a1ab105, not any predecessor. Re-check every prior finding plus the fresh pre-action browser capacity check, authoritative checkpoint-side chain-and-ledger recheck, Durable Object freeze/active/spend capacity handling, non-atomic concurrency disclosure, exact-note exits, ambiguous RPC reconciliation, and all budget/nonce boundaries.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a1ab1055c5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread relayer/src/exit-executor.ts Outdated
Comment thread relayer/src/exit-executor.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review\n\nNew exact head cafd4df invalidates all prior reviews. Review this exact commit only. The final correction combines active control and exit reservations because both occupy the shared neutral nonce lane, while only exit reserved/spent totals count against the exit-day ceiling. Confirm every existing review thread and the complete tree are clean.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex security review\n\nSecurity-review exact head cafd4df only. Verify ledger-aware capacity includes active control and exit reservations, exit-only daily exposure, sponsorship freeze, live chain capacity, fresh browser/checkpoint reads, and every previously reported budget, reconciliation, rate-limit, privacy, and exact-note invariant.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cafd4dfd36

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread relayer/src/exit-executor.ts Outdated
Comment thread relayer/src/exit-executor.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review\n\nNew exact head 85e5ec4 invalidates every prior review. Review this exact commit only and re-audit the complete tree. Confirm all eleven existing review threads are resolved, especially authenticated-before-victim-quota ordering, deterministic hash persistence for every ambiguous exit response, fresh-only checkpoint admission after receipt reconciliation, and global cross-class/cross-day active-nonce capacity.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d5e9abe412

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread relayer/src/index.ts Outdated
Comment thread web/src/operations.ts
Comment thread relayer/src/executor.ts
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

New exact head b417d23a1e6aa9b22f08e5c07b13abc937d0da2b invalidates every prior review. Review this exact commit only and re-audit the complete tree. Confirm all prior findings are resolved, especially adopted-checkpoint admission reuse, browser same-token reconciliation after ambiguous checkpoint outcomes, and live-owner fencing before any prepared exact-transaction rebroadcast. Re-check sponsorship, nonce, funding-admission, exact-note, privacy, migration, reliability, UX, and regression coverage. Do not approve a different head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b417d23a1e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/src/operations.ts
Comment thread relayer/src/executor.ts Outdated
Comment thread relayer/src/budget.ts
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Documentation-only commit 36258105830501f1cd64995f1ed101e77b6207a6 is the new exact PR head and invalidates every prior review. Review this exact head only. Runtime code remains the tested b417d23 correction; this commit aligns the production operations runbook with the implemented two-minute live-owner fence for both hashless and prepared RESERVED transactions. Re-audit the complete tree and confirm every prior finding remains resolved. Do not approve a different head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3625810583

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread relayer/src/exit-executor.ts Outdated
Comment thread web/src/main.ts Outdated
Comment thread relayer/src/executor.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Retry because the prior request received no connector acknowledgement: review exact current head 36258105830501f1cd64995f1ed101e77b6207a6 only. CI is green. Confirm the complete tree and every existing finding are clean; do not review or approve another head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3625810583

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/src/main.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 9a64fbfbc80d274a394d4a7728f40126c1a010bf. This revision fixes all currently open exact-retry findings: owner-aware checkpoint reconciliation after reload, lease renewal for adopted hashless reservations, prepared-exit rebroadcast fencing, and durable exact cancellation/claim package reconciliation. Local evidence: relayer check 84/84, client 52/52, production web build, Worker dry-runs/startup, zero reported npm vulnerabilities. Do not rely on prior-head reviews.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9a64fbfbc8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/src/main.ts
Comment thread web/src/main.ts Outdated
Comment thread web/src/operations.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Review exact current head e61be579a1fbd34ec2d913767eaa61eb459161ff; it supersedes and invalidates the earlier 9a64fbf request. In addition to the exact-retry fixes, this head requires backup restore before funding, warns that backups are plaintext secrets, adds direct owner reserve restoration and reload-persistent contextual receipts, accepts only compatible non-prerelease Ready 5.x versions at/above 5.33.9, adds 12 public-product tests to CI, and hardens narrow/mobile overflow. Local evidence: relayer 84/84, client 52/52, web 12/12, production builds, zero reported npm vulnerabilities. Re-audit the complete exact head and all prior findings.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Review exact current head $(git rev-parse HEAD) only; it supersedes all prior-head requests. This final metadata/security slice adds real robots, sitemap, manifest, security.txt, a private disclosure policy, and Cloudflare Pages HSTS/nosniff/frame/referrer/permissions/cross-origin headers. CSP is intentionally not claimed while the audited dependency bundle still emits an eval warning. Re-audit the full head, including the prior exact-retry and resilient-onboarding changes. Local web evidence: 12/12 tests, production build, manifest JSON and sitemap XML validation, all static routes present, zero reported npm vulnerabilities.

@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Correction: review exact current head 81da0d191b796adb888cc50b82de92b47ab0e78e only. The immediately preceding comment contained an unexpanded shell placeholder; ignore it. This exact head includes the retry, resilient-onboarding, web-test, mobile hardening, and public metadata/security changes. Re-audit the complete tree and all prior findings; do not approve another head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 81da0d191b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/public/.well-known/security.txt Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Review exact current head 12e4366f305ff834a2b2e46ce595a0baebf3047b only. It supersedes every prior-head request. This head closes the three P1 retry dead ends from the 9a64fbf review (retained checkpoint form admission, terminal-state exit reconciliation, and terminal reverted-receipt cleanup) and corrects the RFC 9116 expiry found on 81da0d1. All actionable review threads have exact-head responses and are resolved. Local web evidence: 12/12 tests, TypeScript and production build pass, corrected security metadata is present in dist, diff checks pass, and npm reports zero production vulnerabilities. Re-audit the complete tree and do not approve another head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 12e4366f30

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/src/operations.ts Outdated
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Review exact current head 7c0b8227956c5628e52f004db9210efb94d3c407 only. It supersedes the completed 12e4366 review. This head fixes its P2 finding by retaining the owner-bound checkpoint admission token for post-lease simulation_failed responses and adds direct positive/definitive classification regressions. The finding thread has an exact-head response and is resolved. Local evidence: public product 22/22, TypeScript and production build pass, diff checks pass, and npm reports zero production vulnerabilities; the previously green 63/63 Cairo, 52/52 client and 84/84 relayer surfaces are unchanged. Re-audit the complete exact head and do not approve another head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c0b822795

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/src/operations.ts
Comment thread web/src/operations.ts Outdated
Comment thread web/src/checkpoint-policy.ts
@dolepee

dolepee commented Aug 29, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Review exact current head 89b02ac2ad603864ceb76fad3b25cc5ad65dabc0 only. It supersedes the completed 7c0b822 review. This head fixes all three findings from that review: hashless relayed checkpoint duplicates retain their admission owner, hashless relayed exit duplicates retain the exact private package, and post-admission submission_not_started plus the complete identified post-admission outcome set retain the owner token. All three threads have exact-head responses and are resolved. Local evidence: public product 32/32, TypeScript and production build pass, diff checks pass, zero reported npm vulnerabilities; unchanged surfaces remain 63/63 Cairo, 52/52 client and 84/84 relayer. Re-audit the complete exact head and do not approve another head.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

Reviewed commit: 89b02ac2ad

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@dolepee
dolepee merged commit 1ab66bb into main Aug 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant