Skip to content

fix(cloud): re-land money gates clobbered by #11271 stale-base squash (#11413) - #11422

Merged
lalalune merged 1 commit into
developfrom
fix/11413-restore-money-gates
Jul 2, 2026
Merged

lalalune merged 1 commit into
developfrom
fix/11413-restore-money-gates

Conversation

@NubsCarson

Copy link
Copy Markdown
Member

Part of #11413 (the #11271 mass-revert incident). Re-lands the launch-critical cloud money gates that #11271's stale-base squash byte-reverted and are still missing at develop tip.

Method (blob-identity, not diff-by-eye)

For each file the clobber squash (5b714c7) touched, compared: develop-tip blob vs clobbered blob vs correct pre-clobber blob (5b714c7^). These files are exact reverts (develop-tip == clobbered, != correct), restored via git checkout 5b714c74e60^ -- <path>:

File Restores Impact
eliza-app/provisioning-agent/route.ts #11240 org-credit gate HIGH money — zero/neg-balance orgs could provision free dedicated-agent compute (gate + 402 was gone)
v1/apps/[id]/chat/stream-refund.ts #11218 app-chat stream refund money-path refund
shared/lib/steward-sync.ts #11270 awaited-provisioning reliability
+ provisioning-agent-default-image.test.ts, apps-chat-stream-refund.test.ts tests coverage

Explicitly NOT touched

#11271's intended change — influencer-marketplace.ts escrow CAS fix (#11167) — is correct at tip and kept (the audit excludes it; blindly restoring to parent would revert the escrow fix).

Verification

  • bun run --cwd packages/cloud/api typecheck → exit 0, 0 errors (the @/lib/*→../shared/src/lib/* alias resolves checkAgentCreditGate to the surviving shared agent-billing-gate.ts).
  • bun run --cwd packages/cloud/shared typecheck → 0 errors.
  • bun test __tests__/provisioning-agent-default-image.test.ts __tests__/apps-chat-stream-refund.test.ts → 11 pass / 0 fail.

Scope note

This is the money-gate slice. The full #11413 audit (183 safe byte-identical restores + 102 reconcile + 7 deletes, incl. the ~223-file #11259 LifeOps runtime) is posted on the umbrella for the coordinated re-land — kept out of this PR to keep the launch-critical money fix small and reviewable. cc @lalalune (money-path merge). — nubs-cloud [cloud-frontdoor]

…sh (#11413)

PR #11271 (intended scope: one escrow file) squashed from a stale base and
byte-reverted ~302 files, incl. merged cloud money gates still missing at
develop tip. Blob-identity audit (develop-tip == clobbered blob, != correct
pre-clobber blob at 5b714c7^) confirms these are exact reverts; restored
from the pre-clobber parent:

- provisioning-agent/route.ts — #11240 org-credit gate on dedicated-agent
  provisioning (checkAgentCreditGate → 402 insufficient_credits) was gone;
  zero/negative-balance orgs could provision free compute.
- v1/apps/[id]/chat/stream-refund.ts — #11218 app-chat stream refund path.
- shared/lib/steward-sync.ts — #11270 awaited-provisioning fix.
- + restored provisioning-agent-default-image + apps-chat-stream-refund tests.

Excluded #11271's INTENDED change (influencer-marketplace.ts escrow fix) — that
content is correct and kept. Verified: cloud/api + cloud/shared typecheck clean
(0 errors); restored tests 11 pass / 0 fail.

Part of the #11413 umbrella restore (full blob audit posted there). Refs #11240 #11218 #11270.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@coderabbitai

coderabbitai Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b69a55ef-81a6-4cbe-88ce-9f1f24858ba3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/11413-restore-money-gates

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lalalune
lalalune merged commit 4ef73fd into develop Jul 2, 2026
35 of 43 checks passed
@lalalune
lalalune deleted the fix/11413-restore-money-gates branch July 2, 2026 10:02
lalalune pushed a commit that referenced this pull request Jul 2, 2026
…ey gate #11271 clobbered that neither #11403 nor #11422 covers (#11429)

#11271 clobbered 3 [cloud-security] money gates. Coverage on develop:
- #11227 pairing-token gate → my #11403 (merged; only this commit landed).
- #11240 eliza-app provisioning gate → shaw's #11422 (open).
- #11261 shared-turn refund guard → NOT restored by either. Fell through the
  cracks (my #11403's 2nd commit never merged; #11422's 5 files don't touch
  eliza-sandbox). Still a live hole: on the DEFAULT (shared) agent tier, a throw
  between reserveCredits and settle strands the hold (settleReservation(0) was
  back to 2 — the pre-existing degraded+billing-catch paths; my outer guard, the
  3rd, was gone).

eliza-sandbox.ts EVOLVED since (#11402 secret-encryption, #11375 quota), so this
re-applies ONLY the outer try/catch → settleReservation(0) guard onto the current
file — verified the #11402/#11375 changes are preserved (25 evolution markers
intact; no reverse-clobber). Test restored (was deleted by #11271).

typecheck + biome clean; shared-turn refund test 2 pass. This closes the last
open #11271 [cloud-security] money hole. Refs #11271 #11413 #11419. [cloud-security]
lalalune pushed a commit that referenced this pull request Jul 2, 2026
…#11271 (#11432)

* test(cloud): restore group-l (app-charges) + group-m (direct-crypto) money e2e coverage clobbered by #11271

#11271's stale-base squash reverted these two MONEY e2e suites to older, smaller
versions (group-l 369→351, group-m 237→215 lines) — untracked, uncovered by the
money-gate restores (#11403/#11422/#11429 were code, not these e2e suites).
group-a/group-b were re-grown post-clobber; group-l/group-m were not, so their
lost app-charge + direct-crypto assertions are still missing on develop.

Restored to the exact pre-clobber content (git checkout 5b714c7^; untouched
since the clobber, so drift-free) + biome-formatted. These suites run against the
deployed Worker/staging in CI and skip silently with no env, so this adds no
red-CI risk locally; it recovers real money e2e coverage (the app-charge billing
and direct-crypto deposit paths) for the launch. Both files parse + lint clean.

Part of the #11271 cleanup (#11413/#11419). The money CODE was already verified
sound (direct-crypto: on-chain amount + signed-quote + idempotent dedupe); this
restores its e2e guardrails. Refs #11271 #11413. [cloud-security]

* test(cloud): also restore group-k (affiliate earnings) money e2e clobbered by #11271

Same #11271 stale-base clobber reduced the affiliate-earnings e2e suite
(128→113 lines), uncovered by the code restores. Restored to pre-clobber
(checkout 5b714c7^; untouched since) + biome-formatted; parses + lint clean.
Affiliate = money-in path. Refs #11271 #11413. [cloud-security]

* test(cloud): also restore direct-wallet-payments money integration test clobbered by #11271

#11271 reduced the direct-wallet (crypto money-in) integration suite (1659→1619
lines, 39 cases). Untouched since the clobber → restored to pre-clobber
(checkout 5b714c7^) + biome-formatted. Skips locally w/o env (0 pass/39 skip/
0 fail), runs in CI — no red-CI risk; recovers money-in integration coverage.
The direct-wallet CODE was already verified sound (on-chain amount + signed-quote
+ idempotent dedupe + payer-proof); this restores its integration guardrails.
Refs #11271 #11413. [cloud-security]
@github-actions github-actions Bot added the Tests label Jul 2, 2026
@claude

claude Bot commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude encountered an error —— View job


I'll analyze this and get back to you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants