Repository navigation
fix(disclosure): persist attempt before irreversible delivery - #721
imran-siddique merged 6 commits into
Conversation
|
🔴 Contributor Check: HIGH
Automated check by AgenTrust Contributor Check. |
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
imran-siddique
left a comment
There was a problem hiding this comment.
Recheck approval validity after the audit write, immediately before delivery, and add a regression covering expiry during that write.
|
Addressed the requested pre-delivery validity recheck. The gate now revalidates a scoped approval after the durable audit write and immediately before the irreversible delivery callback. Added a regression where the first two validity checks succeed and the approval expires during the audit-write window; delivery remains unattempted and the one-use request stays consumed. Updated the disclosure contract text accordingly. Verification: targeted disclosure/sink tests 83 passed; ruff clean; mypy clean; full suite 2411 passed, 37 skipped (environment-dependent), with only existing Python ctypes deprecation warnings. |
imran-siddique
left a comment
There was a problem hiding this comment.
@altrudev the recheck is right. One consequence of where it sits: when it fails, the attempt row is already durable as delivery_attempted/unknown and stays that way, so the store reports a possible disclosure that was never attempted, and the returned denial has no event_id to tie it to that row. Downgrade the row best-effort to not attempted on that path, the way acknowledge upgrades it on success, keep unknown if that write fails, and return the event_id. Extend your expiry regression to assert the stored row. Can you have it up by 9 October?
|
Addressed the second review through a bounded DDC/Frequency pass on exact head The final pre-delivery validity failure now reconciles the already-durable prepared event instead of leaving a false possible-disclosure signal:
The disclosure contract text was updated to match that state machine. Verification from a fresh checkout on the current head:
Claim boundary is unchanged: |
imran-siddique
left a comment
There was a problem hiding this comment.
The final recheck now leaves the row as not_attempted with the denial's disposition and returns its event_id, and keeps unknown when the corrective write fails. Both paths are pinned by tests. Approving.
Summary
Closes the local crash-window evidence gap identified in #660 around irreversible disclosure delivery.
This keeps the existing ordering:
verify -> consume request ID -> recheck validityand adds:
persist minimized attempt(unknown) -> deliver exact bytes -> best-effort durable acknowledgeBehavior
recipient.deliver()unknownif delivery is interrupted or the post-delivery audit update failsacknowledgedonly after normal callback returnevent_id,disposition,reason, anddeliveryTests
Added restart and storage-failure coverage, including:
BaseExceptioninterruption leaves unknownValidation run from exact upstream baseline
4acb813487375578098cd4a23620ecdd647bc6cf:git diff --check: cleanThis does not change the release authorization model, confinement claims, downstream execution claims, or disclosure claim ceilings.