fix(cloud): restore the 3 [cloud-security] money fixes clobbered by #11271 (#11227 + #11240 + #11261) - #11403
Conversation
…it gate clobbered by #11271 The bad-rebase merge #11271 (5b714c7, "fold rejectDelivered into the fenced generic refund()") was cut from a stale branch and silently reverted ~15k lines across the repo (304 files) — including my merged #11227 (#11224): the checkAgentCreditGate → 402 on the pairing-token dedicated re-provision path. On develop, `checkAgentCreditGate` count in pairing-token/route.ts was 0. Impact: a credit-suspended / zero-balance org could again pair a stopped/reaped DEDICATED agent and re-provision its container for free (the #10902-family hole #11227 closed). Shared agents still early-return, so the gate only fences the dedicated (paid) case — no over-blocking. This re-applies #11227 verbatim (it applied cleanly onto develop, confirming #11271 reverted exactly the pre-#11227 state and nothing touched the file since). Tests restored + green (9 pass, incl. the suspended-org-402 + funded-org-no-regression cases). STOPGAP: the correct fix for the whole #11271 regression is a wholesale `git revert 5b714c7` + a clean re-apply of the legit rejectDelivered fold (see charter #11157). If that revert lands, drop this PR in favor of it. Filing this now because the pairing-token slice is a LIVE money hole and was untracked. Money-path — flagging for maintainer merge. Refs #11271 #11224. [cloud-security]
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
lalalune
left a comment
There was a problem hiding this comment.
Reviewed locally. This is the same dedicated-only gate shape we validated for #11227: shared sandboxes return AGENT_WEB_UI_NOT_READY before worker/provision/credit logic, and stopped dedicated sandboxes now call checkAgentCreditGate before enqueueing paid provision work.
Local Windows validation:
git diff --check origin/develop...HEADpassed.bunx @biomejs/biome@2.5.2 check "packages/cloud/api/v1/eliza/agents/[agentId]/pairing-token/route.ts" "packages/cloud/api/v1/eliza/agents/[agentId]/pairing-token/route.test.ts"passed.bun test 'packages/cloud/api/v1/eliza/agents/[agentId]/pairing-token/route.test.ts'passed 9/9.bun run --cwd packages/cloud/api typecheckpassed.
…ey gate #11271 clobbered that neither #11403 nor #11422 covers (#11429) #11271 clobbered 3 [cloud-security] money gates. Coverage on develop: - #11227 pairing-token gate → my #11403 (merged; only this commit landed). - #11240 eliza-app provisioning gate → shaw's #11422 (open). - #11261 shared-turn refund guard → NOT restored by either. Fell through the cracks (my #11403's 2nd commit never merged; #11422's 5 files don't touch eliza-sandbox). Still a live hole: on the DEFAULT (shared) agent tier, a throw between reserveCredits and settle strands the hold (settleReservation(0) was back to 2 — the pre-existing degraded+billing-catch paths; my outer guard, the 3rd, was gone). eliza-sandbox.ts EVOLVED since (#11402 secret-encryption, #11375 quota), so this re-applies ONLY the outer try/catch → settleReservation(0) guard onto the current file — verified the #11402/#11375 changes are preserved (25 evolution markers intact; no reverse-clobber). Test restored (was deleted by #11271). typecheck + biome clean; shared-turn refund test 2 pass. This closes the last open #11271 [cloud-security] money hole. Refs #11271 #11413 #11419. [cloud-security]
…#11271 (#11432) * test(cloud): restore group-l (app-charges) + group-m (direct-crypto) money e2e coverage clobbered by #11271 #11271's stale-base squash reverted these two MONEY e2e suites to older, smaller versions (group-l 369→351, group-m 237→215 lines) — untracked, uncovered by the money-gate restores (#11403/#11422/#11429 were code, not these e2e suites). group-a/group-b were re-grown post-clobber; group-l/group-m were not, so their lost app-charge + direct-crypto assertions are still missing on develop. Restored to the exact pre-clobber content (git checkout 5b714c7^; untouched since the clobber, so drift-free) + biome-formatted. These suites run against the deployed Worker/staging in CI and skip silently with no env, so this adds no red-CI risk locally; it recovers real money e2e coverage (the app-charge billing and direct-crypto deposit paths) for the launch. Both files parse + lint clean. Part of the #11271 cleanup (#11413/#11419). The money CODE was already verified sound (direct-crypto: on-chain amount + signed-quote + idempotent dedupe); this restores its e2e guardrails. Refs #11271 #11413. [cloud-security] * test(cloud): also restore group-k (affiliate earnings) money e2e clobbered by #11271 Same #11271 stale-base clobber reduced the affiliate-earnings e2e suite (128→113 lines), uncovered by the code restores. Restored to pre-clobber (checkout 5b714c7^; untouched since) + biome-formatted; parses + lint clean. Affiliate = money-in path. Refs #11271 #11413. [cloud-security] * test(cloud): also restore direct-wallet-payments money integration test clobbered by #11271 #11271 reduced the direct-wallet (crypto money-in) integration suite (1659→1619 lines, 39 cases). Untouched since the clobber → restored to pre-clobber (checkout 5b714c7^) + biome-formatted. Skips locally w/o env (0 pass/39 skip/ 0 fail), runs in CI — no red-CI risk; recovers money-in integration coverage. The direct-wallet CODE was already verified sound (on-chain amount + signed-quote + idempotent dedupe + payer-proof); this restores its integration guardrails. Refs #11271 #11413. [cloud-security]
|
Claude encountered an error —— View job I'll analyze this and get back to you. |
Restores the 3 [cloud-security] money fixes that #11271's bad rebase clobbered AND that no one re-did.
#11271 (
5b714c74e6, the rejectDelivered refund fold) was cut from a stale branch and reverted ~15k lines across 304 files (root-cause on charter #11157). It clobbered 5 of my merged fixes. Two were already re-implemented by the fleet (#11218→#11278, #11255→#11369) — this PR does NOT touch those. The remaining three had no re-do and were live money holes:Restored to the exact pre-clobber state (
git checkout 5b714c74e6^ -- <files>; nothing touched them after #11271, so drift-free + brings back the deleted shared-turn test). Tests green: pairing-token 9 pass, provisioning-agent 4 pass, shared-turn 2 pass. biome clean.[cloud-security]