Repository navigation
Harden recovery sponsorship and refine the public journey - #2
Conversation
|
@codex security review\n\nPlease security-review the exact current head commit 491bda7, including the exit kill switch, submitted-receipt reconciliation, ambiguous RPC handling, pool-class/action pinning, split-budget migration, rate-limit ordering, live claim-capacity gate, and browser funding fail-closed behavior. Do not approve a different head. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex security review Please security-review the exact current head commit 491bda7, including the exit kill switch, submitted-receipt reconciliation, ambiguous RPC handling, pool-class/action pinning, split-budget migration, rate-limit ordering, live claim-capacity gate, and browser funding fail-closed behavior. Do not approve a different head. |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 491bda7477
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review New commit 3bd52cd invalidates the prior review. Please review this exact current head. Re-check all PR #1 findings plus the realistic NORMAL mode, generalized exact-note CLAIM/CANCEL_REFUND sponsor, one-outstanding-reserve funding-capacity rule, invitation-to-Mainnet parity checks, and owner cancellation UX. Perform a full-tree correctness, reliability, privacy, migration, and test-coverage review. Do not approve a different head. |
|
@codex security review Security-review exact head 3bd52cd. Focus on the shared 12→6 STRK one-exit allowance, zero-liability funding admission, live class/liability reads, owner-vs-successor authorization domains, cancellation irreversibility, submitted-exit reconciliation, rate-limit ordering, and kill-switch behavior. Do not approve a different head. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3bd52cd1c8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review\n\nNew commit 16c7e13 invalidates every prior review. Review this exact current head and confirm all findings on 3bd52cd are fully resolved. Re-check the full tree, including conservative legacy exposure migration, kill-switch-safe receipt-only reconciliation, stable vault/action exit limiting, live checkpoint funding-capacity enforcement, truthful non-atomic admission wording, reliability, privacy, UX, and regression coverage. Do not approve a different head. |
|
@codex security review\n\nSecurity-review exact current head 16c7e13. Verify all prior findings are resolved and re-audit the complete public tree, especially migration exposure, kill-switch reconciliation without rebroadcast, stable exit abuse keys, funding checkpoint fail-closed behavior, shared nonce/budget invariants, exact-note CLAIM/CANCEL_REFUND validation, ambiguous RPC handling, and secrets/privacy boundaries. Do not approve a different head. |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
1 similar comment
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 16c7e1368c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review\n\nNew commit a1ab105 invalidates all prior reviews. Review this exact current head, not any predecessor. Confirm every PR #2 thread is resolved, including the two previously hidden findings: fresh browser and checkpoint capacity reads before funding, and ledger-aware capacity covering freeze, active reservations, and same-day exit exposure. Re-audit the complete tree for correctness, security, reliability, privacy, UX, migration, and test coverage. |
|
@codex security review\n\nSecurity-review exact current head a1ab105, not any predecessor. Re-check every prior finding plus the fresh pre-action browser capacity check, authoritative checkpoint-side chain-and-ledger recheck, Durable Object freeze/active/spend capacity handling, non-atomic concurrency disclosure, exact-note exits, ambiguous RPC reconciliation, and all budget/nonce boundaries. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a1ab1055c5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review\n\nNew exact head cafd4df invalidates all prior reviews. Review this exact commit only. The final correction combines active control and exit reservations because both occupy the shared neutral nonce lane, while only exit reserved/spent totals count against the exit-day ceiling. Confirm every existing review thread and the complete tree are clean. |
|
@codex security review\n\nSecurity-review exact head cafd4df only. Verify ledger-aware capacity includes active control and exit reservations, exit-only daily exposure, sponsorship freeze, live chain capacity, fresh browser/checkpoint reads, and every previously reported budget, reconciliation, rate-limit, privacy, and exact-note invariant. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cafd4dfd36
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review\n\nNew exact head 85e5ec4 invalidates every prior review. Review this exact commit only and re-audit the complete tree. Confirm all eleven existing review threads are resolved, especially authenticated-before-victim-quota ordering, deterministic hash persistence for every ambiguous exit response, fresh-only checkpoint admission after receipt reconciliation, and global cross-class/cross-day active-nonce capacity. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d5e9abe412
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review New exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b417d23a1e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Documentation-only commit |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3625810583
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Retry because the prior request received no connector acknowledgement: review exact current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3625810583
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9a64fbfbc8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Review exact current head |
|
@codex review Review exact current head |
|
@codex review Correction: review exact current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 81da0d191b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Review exact current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 12e4366f30
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Review exact current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c0b822795
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Review exact current head |
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Outcome
Closes every actionable Codex finding, hardens repeatable private-exit sponsorship, and upgrades the public owner/successor product without changing the deployed Cairo contract.
Security and reliability
Complete public product
Exact-head evidence
Merge remains prohibited until a completed clean top-level
@codex reviewcovers exact head89b02ac2ad603864ceb76fad3b25cc5ad65dabc0, every actionable thread is resolved, and required CI remains green. Any new commit invalidates the review.