• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 35000110920
92%
main: 95%

Build:
Build:
LAST BUILD BRANCH: fix/1288-runtime-wallet-recovery
DEFAULT BRANCH: main
Ran 15 Sep 2026 05:17PM UTC
Jobs 1
Files 99
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Sep 2026 05:14PM UTC coverage: 92.407% (-0.02%) from 92.422%
35000110920

Pull #1145

github

macterra
fix(gatekeeper): Reject a backdated proof once the chain has committed the operation

An asset operation is authorized by the controller's document resolved at
the operation's own proof.created -- a timestamp the signer chooses. A key
rotated out of the controller can therefore name a created from before
the rotation and be authorized by the document that still listed it, so
rotation never revokes a leaked key's power over the agent's assets.
Demonstrated for the legacy and bound proof suites, and with the
controller registered and confirmed on chain: the chain orders the forgery
after the rotation and the gatekeeper accepts it anyway, because
authorization never consults that order (#1131).

Once a chain has committed an operation it has a position the signer did
not choose. controllerAt resolves the controller there instead: by ordinal
when controller and operation share a chain, since every event in a block
shares the block's time and only the ordinal orders a rotation against an
operation committed earlier in the same block (#1136); by time across
chains. An unanchored controller stamps its events with each node's clock,
so it falls back to proof.created rather than fork on import order, which
is what #1134 did. Threaded through import, the verify replay, and the
confirmation replace path -- which swapped in the confirmed twin without
re-verifying, and would have laundered a locally accepted forgery into
confirmed state. It is re-verified against the version it chained from,
as replay does; resolving at present would judge a self-update by the
document it produced.

The verdict must not depend on arrival order. Only the node's own registry
mediator can vouch that a chain committed an event, and it delivers block
by block; a relaying peer or an operator restoring an export can vouch for
neither the chain nor its order (an export is sorted by proof.created).
importRelayedBatch downgrades what such a source claims to an unconfirmed
hint, and the untr... (continued)
Pull Request #1145: fix(gatekeeper): Reject a backdated proof once the chain has committed the operation

4209 of 4837 branches covered (87.02%)

Branch coverage included in aggregate %.

33 of 36 new or added lines in 2 files covered. (91.67%)

17 existing lines in 1 file now uncovered.

8837 of 9281 relevant lines covered (95.22%)

785.27 hits per line

Uncovered Changes

Lines Coverage ∆ File
3
95.78
-0.34% packages/gatekeeper/src/gatekeeper.ts

Coverage Regressions

Lines Coverage ∆ File
17
95.78
-0.34% packages/gatekeeper/src/gatekeeper.ts
Jobs
ID Job ID Ran Files Coverage
1 35000110920.1 15 Sep 2026 05:17PM UTC 198
93.49
GitHub Action Run
Source Files on build 35000110920
  • Tree
  • List 99
  • Changed 86
  • Source Changed 2
  • Coverage Changed 86
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #35000110920
  • Pull Request #1145
  • PR Base - main (#34892184804)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc