• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 35046717144
95%

Build:
DEFAULT BRANCH: main
Ran 16 Sep 2026 02:11AM UTC
Jobs 1
Files 99
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

16 Sep 2026 02:06AM UTC coverage: 92.409% (-0.01%) from 92.422%
35046717144

push

github

web-flow
fix(gatekeeper): Reject a backdated proof once the chain has committed the operation (#1145)

* fix(gatekeeper): Reject a backdated proof once the chain has committed the operation

An asset operation is authorized by the controller's document resolved at
the operation's own proof.created -- a timestamp the signer chooses. A key
rotated out of the controller can therefore name a created from before
the rotation and be authorized by the document that still listed it, so
rotation never revokes a leaked key's power over the agent's assets.
Demonstrated for the legacy and bound proof suites, and with the
controller registered and confirmed on chain: the chain orders the forgery
after the rotation and the gatekeeper accepts it anyway, because
authorization never consults that order (#1131).

Once a chain has committed an operation it has a position the signer did
not choose. controllerAt resolves the controller there instead: by ordinal
when controller and operation share a chain, since every event in a block
shares the block's time and only the ordinal orders a rotation against an
operation committed earlier in the same block (#1136); by time across
chains. An unanchored controller stamps its events with each node's clock,
so it falls back to proof.created rather than fork on import order, which
is what #1134 did. Threaded through import, the verify replay, and the
confirmation replace path -- which swapped in the confirmed twin without
re-verifying, and would have laundered a locally accepted forgery into
confirmed state. It is re-verified against the version it chained from,
as replay does; resolving at present would judge a self-update by the
document it produced.

The verdict must not depend on arrival order. Only the node's own registry
mediator can vouch that a chain committed an event, and it delivers block
by block; a relaying peer or an operator restoring an export can vouch for
neither the chain nor its order (an export is sorted by proof.create... (continued)

4216 of 4846 branches covered (87.0%)

Branch coverage included in aggregate %.

44 of 46 new or added lines in 2 files covered. (95.65%)

8846 of 9289 relevant lines covered (95.23%)

787.4 hits per line

Uncovered Changes

Lines Coverage ∆ File
2
95.83
-0.28% packages/gatekeeper/src/gatekeeper.ts
Jobs
ID Job ID Ran Files Coverage
1 35046717144.1 16 Sep 2026 02:11AM UTC 198
93.5
GitHub Action Run
Source Files on build 35046717144
  • Tree
  • List 99
  • Changed 86
  • Source Changed 2
  • Coverage Changed 86
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #35046717144
  • 4ea2e8f8 on github
  • Prev Build on main (#34892184804)
  • Next Build on main (#35108030922)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc