Skip to content

fix(cloud): restore the 3 [cloud-security] money fixes clobbered by #11271 (#11227 + #11240 + #11261) - #11403

Merged
lalalune merged 1 commit into
developfrom
nubs/restore-11227-pairing-gate-clobbered-by-11271
Jul 2, 2026
Merged

lalalune merged 1 commit into
developfrom
nubs/restore-11227-pairing-gate-clobbered-by-11271

Conversation

@NubsCarson

@NubsCarson NubsCarson commented Jul 2, 2026 •

Copy link
Copy Markdown
Member

Restores the 3 [cloud-security] money fixes that #11271's bad rebase clobbered AND that no one re-did.

#11271 (5b714c74e6, the rejectDelivered refund fold) was cut from a stale branch and reverted ~15k lines across 304 files (root-cause on charter #11157). It clobbered 5 of my merged fixes. Two were already re-implemented by the fleet (#11218→#11278, #11255→#11369) — this PR does NOT touch those. The remaining three had no re-do and were live money holes:

Fix Hole re-opened Restored
#11227 pairing-token: suspended org re-provisions a stopped DEDICATED agent free gate + 2 tests
#11240 eliza-app provisioning-agent: suspended org's first dedicated provision free gate + test
#11261 shared-runtime turn: a throw between reserve and settle strands the hold (DEFAULT tier) outer refund guard + test

Restored to the exact pre-clobber state (git checkout 5b714c74e6^ -- <files>; nothing touched them after #11271, so drift-free + brings back the deleted shared-turn test). Tests green: pairing-token 9 pass, provisioning-agent 4 pass, shared-turn 2 pass. biome clean.

⚠️ STOPGAP: the cleaner fix for the FULL #11271 regression (persona #11333, lifeops #11376, CI workflows, benchmarks, 300+ files) is a wholesale surgical revert (recipe on #11157). If that lands, it restores these too — drop this PR then. Filing because these 3 were untracked live money holes I found by auditing #11271's money collateral. Money-path — maintainer merge. Refs #11271 #11224 #11169. [cloud-security]

…it gate clobbered by #11271

The bad-rebase merge #11271 (5b714c7, "fold rejectDelivered into the fenced
generic refund()") was cut from a stale branch and silently reverted ~15k lines
across the repo (304 files) — including my merged #11227 (#11224): the
checkAgentCreditGate → 402 on the pairing-token dedicated re-provision path.
On develop, `checkAgentCreditGate` count in pairing-token/route.ts was 0.

Impact: a credit-suspended / zero-balance org could again pair a stopped/reaped
DEDICATED agent and re-provision its container for free (the #10902-family hole
#11227 closed). Shared agents still early-return, so the gate only fences the
dedicated (paid) case — no over-blocking.

This re-applies #11227 verbatim (it applied cleanly onto develop, confirming
#11271 reverted exactly the pre-#11227 state and nothing touched the file since).
Tests restored + green (9 pass, incl. the suspended-org-402 + funded-org-no-regression cases).

STOPGAP: the correct fix for the whole #11271 regression is a wholesale
`git revert 5b714c7` + a clean re-apply of the legit rejectDelivered fold
(see charter #11157). If that revert lands, drop this PR in favor of it. Filing
this now because the pairing-token slice is a LIVE money hole and was untracked.
Money-path — flagging for maintainer merge. Refs #11271 #11224. [cloud-security]

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@coderabbitai

coderabbitai Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 09f124a2-8861-4f1b-8d17-a66464bf8a3b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch nubs/restore-11227-pairing-gate-clobbered-by-11271

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lalalune lalalune left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed locally. This is the same dedicated-only gate shape we validated for #11227: shared sandboxes return AGENT_WEB_UI_NOT_READY before worker/provision/credit logic, and stopped dedicated sandboxes now call checkAgentCreditGate before enqueueing paid provision work.

Local Windows validation:

  • git diff --check origin/develop...HEAD passed.
  • bunx @biomejs/biome@2.5.2 check "packages/cloud/api/v1/eliza/agents/[agentId]/pairing-token/route.ts" "packages/cloud/api/v1/eliza/agents/[agentId]/pairing-token/route.test.ts" passed.
  • bun test 'packages/cloud/api/v1/eliza/agents/[agentId]/pairing-token/route.test.ts' passed 9/9.
  • bun run --cwd packages/cloud/api typecheck passed.

@lalalune
lalalune merged commit abe6764 into develop Jul 2, 2026
35 of 44 checks passed
@lalalune
lalalune deleted the nubs/restore-11227-pairing-gate-clobbered-by-11271 branch July 2, 2026 09:17
@NubsCarson NubsCarson changed the title fix(cloud): restore #11227 pairing-token credit gate clobbered by #11271's bad rebase fix(cloud): restore the 3 [cloud-security] money fixes clobbered by #11271 (#11227 + #11240 + #11261) Jul 2, 2026
lalalune pushed a commit that referenced this pull request Jul 2, 2026
…ey gate #11271 clobbered that neither #11403 nor #11422 covers (#11429)

#11271 clobbered 3 [cloud-security] money gates. Coverage on develop:
- #11227 pairing-token gate → my #11403 (merged; only this commit landed).
- #11240 eliza-app provisioning gate → shaw's #11422 (open).
- #11261 shared-turn refund guard → NOT restored by either. Fell through the
  cracks (my #11403's 2nd commit never merged; #11422's 5 files don't touch
  eliza-sandbox). Still a live hole: on the DEFAULT (shared) agent tier, a throw
  between reserveCredits and settle strands the hold (settleReservation(0) was
  back to 2 — the pre-existing degraded+billing-catch paths; my outer guard, the
  3rd, was gone).

eliza-sandbox.ts EVOLVED since (#11402 secret-encryption, #11375 quota), so this
re-applies ONLY the outer try/catch → settleReservation(0) guard onto the current
file — verified the #11402/#11375 changes are preserved (25 evolution markers
intact; no reverse-clobber). Test restored (was deleted by #11271).

typecheck + biome clean; shared-turn refund test 2 pass. This closes the last
open #11271 [cloud-security] money hole. Refs #11271 #11413 #11419. [cloud-security]
lalalune pushed a commit that referenced this pull request Jul 2, 2026
…#11271 (#11432)

* test(cloud): restore group-l (app-charges) + group-m (direct-crypto) money e2e coverage clobbered by #11271

#11271's stale-base squash reverted these two MONEY e2e suites to older, smaller
versions (group-l 369→351, group-m 237→215 lines) — untracked, uncovered by the
money-gate restores (#11403/#11422/#11429 were code, not these e2e suites).
group-a/group-b were re-grown post-clobber; group-l/group-m were not, so their
lost app-charge + direct-crypto assertions are still missing on develop.

Restored to the exact pre-clobber content (git checkout 5b714c7^; untouched
since the clobber, so drift-free) + biome-formatted. These suites run against the
deployed Worker/staging in CI and skip silently with no env, so this adds no
red-CI risk locally; it recovers real money e2e coverage (the app-charge billing
and direct-crypto deposit paths) for the launch. Both files parse + lint clean.

Part of the #11271 cleanup (#11413/#11419). The money CODE was already verified
sound (direct-crypto: on-chain amount + signed-quote + idempotent dedupe); this
restores its e2e guardrails. Refs #11271 #11413. [cloud-security]

* test(cloud): also restore group-k (affiliate earnings) money e2e clobbered by #11271

Same #11271 stale-base clobber reduced the affiliate-earnings e2e suite
(128→113 lines), uncovered by the code restores. Restored to pre-clobber
(checkout 5b714c7^; untouched since) + biome-formatted; parses + lint clean.
Affiliate = money-in path. Refs #11271 #11413. [cloud-security]

* test(cloud): also restore direct-wallet-payments money integration test clobbered by #11271

#11271 reduced the direct-wallet (crypto money-in) integration suite (1659→1619
lines, 39 cases). Untouched since the clobber → restored to pre-clobber
(checkout 5b714c7^) + biome-formatted. Skips locally w/o env (0 pass/39 skip/
0 fail), runs in CI — no red-CI risk; recovers money-in integration coverage.
The direct-wallet CODE was already verified sound (on-chain amount + signed-quote
+ idempotent dedupe + payer-proof); this restores its integration guardrails.
Refs #11271 #11413. [cloud-security]
@claude

claude Bot commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude encountered an error —— View job


I'll analyze this and get back to you.

@github-actions github-actions Bot added the Tests label Jul 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants