Repository navigation
Conversation
) rescale re-derived quorum:M/N whenever the roster moved, keeping the ratio and flooring at a strict majority, so 3/5 shrinking to three members became 2/3 and 2/3 growing to four became 3/4: a rule change no member decided, and a client could not state how many signatures a change needs. CC 4.4.3.4.2.1 (normative) makes M an absolute count and N documentary, and persist v49's evaluator counts it that way. carry_quorum keeps M and updates N, lowering M only when the roster falls below it (persist refuses M > N, and a household that could never act again is a deadlock). A stored quorum no longer has to be a strict majority to parse; a DECLARED one still does (normalize_protocol). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
… is family|key (#681) accepted was read from a user_accepts field persist's TrustRootVerdict never had, so every root, including the one the node is entrenched under, read accepted:false. It is now the typed verdict's edge_exists (a live delegates_to(node -> root)). root_kind serialized as persist's enum spelling (Family/Key) against a route contract of family/key; it is now mapped from the typed field. A handler test through the real router pins both. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
…RSON keys (#683) GET /v1/federation/peers/{key_id}/sas derived the code from THIS NODE's key and the contact's PERSON key, so Alice's node showed sas(nodeA, Bob) and Bob's showed sas(nodeB, Alice) — two different pairs, so an honest comparison always read as a mismatch. When the peer's record is a person (identity_type user), the local side is now this node's OWNER, the pair a chat uses; node-to-node peers are unchanged. A node with no owner refuses by name (peers.sas_no_owner, 409; on the localization debt list, MAX_UNCOVERED 140). Pinned by a two-node, two-person test that both sides derive the same words and digits for each other. Also: an unused binding left by #686. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
POST …/peering/revoke takes a grant's attestation_id, and nothing listed them, so the app could withdraw only a grant it had received in the same session — consent met on paper and missed in practice (CC 1.5). The owner-gated GET returns every LIVE replication grant this node holds as receipts (the same revocation-folded read revoke checks against, owner-authored rows first), with peer_key_ids and withdrawable (exactly: the owner signed it — the rule revoke applies). The peering test lists the grant it just made and pins the rule. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
The response now carries audit_event_id: the hard_case:trace_erasure row persist records, found by its own coordinates (kind, target = the agent hash, emitted AT the erasure instant), so a client can point the person at the record of their erasure; null when nothing was erased (a repeat records no new row). scope_note cited closed CIRISPersist#573; the live gap is CIRISPersist#914. A test ingests a real batch, erases it, and requires the lookup to find the row. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
`/v1/accord/provision` is not a route. The refusal is now the localized `accord.family_not_supersedable` and names the real remedy: genesis/remint-source → genesis/propose + cosign → trust-root/import. The reserved change/supersede routes say why they refuse. MAX_UNCOVERED 140 → 141. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
`PUT …/sas {result: match|mismatch|withdrawn}` records the outcome and stamps
it (`sas_result`, `sas_result_at`). `{verified: bool}` still works: true is a
match, false is a withdrawal. Peer rows carry sas_verified, verified_at,
sas_result and sas_result_at. `PUT …/appearance` writes `alias_override`
(the local name; "" clears it), which the rows used to hard-code null.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
…om rows carry an envelope The detail read returns `moderators: null` with `moderators_readable: false` on a store error (widenings/revocations likewise null), where it used to return []. Every room row carries its envelope (subject, attester from the signed record by persist_row_hash, cohort_scope, dimension, persist_row_hash). The appoint route (2) waits on the per-community lens in persist's `appointed_moderators_of`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0125h5ochAX5H79GWi2AR4WF
…apped per client Every insert first drops grants more than 10 minutes past expiry (and their user_code index entries), so a late poll still reads 410 expired_token but the map no longer grows with uptime. The unauthenticated code-request leg refuses a ninth live pending code for one client_id (429 slow_down); the owner-session /delegate path is pruned, not capped. Also two clippy fixes in federation_admin.rs from the #680/#685 commits. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QdM21U8xUmHk2TwrMTKJPf
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Contributor
Author
|
Note for after the substrate adoption (#697, persist v51.0.0): a stalled trust root now resolves with 🤖 Generated with Claude Code |
This was referenced Sep 29, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes found by CIRISClient's CSD reviews, against integ/0.5.218. Each commit closes (or partly closes) one issue:
GET /v1/trust-root:acceptedis this node's own trust edge;root_kindisfamily|key.GET /v1/federation/peeringlists a person's live peering grants, so/peering/revokehas something to name.moderators: nullwithmoderators_readable: false, not[]; room rows carry their envelope. Part 2 (appoint route) waits on persist's per-community moderator lens.client_id(429slow_down).Local: full
cargo testgreen (the one red was a new test built against the pre-edit lib; rerun green), clippy-D warningsclean.Not in this PR: #687 (households: rename is S; listing pending quorum changes needs a decision on node-local vs replicated proposals).
🤖 Generated with Claude Code
https://claude.ai/code/session_01QdM21U8xUmHk2TwrMTKJPf