CR clause sweep: encrypted-bot footprint + 0-line diff, emission-by-version, puppet global state, mid-txn crash, ack-then-crash, unknown type through windows #163

Open
opened 2026-08-27 19:21:22 +02:00 by thecrealm · 0 comments
Owner

Review finding 2026-08-27 (D9). Remaining PARTIAL clauses with no dedicated test:

  • CR-10/NFR-10: only the unencrypted bot graph is gated — add a checkBotFootprint over an encrypted-bot sample (no SQL/UI/timeline, native crypto allowed);
  • CR-20/NFR-11: "E2EE + 0 lines" — diff the encrypted e2e bot body against the golden sample;
  • CR-11: emission switches with negotiated version (≥ stable-since → stable, below → unstable/refused); raw-lane send(room, "org.matrix.msc…") refused;
  • CR-9: a ghost send leaves bot-principal facts, cursor and compat standing byte-identical;
  • CR-1: crash injected mid-transaction (facts written, cursor pending) on a durable store;
  • CR-5: deterministic ack-then-crash-before-echo → no resend, echo reconciles;
  • CR-3: unknown event type through TimelineWindow and SingleRoomView with the envelope intact;
  • CR-7: appservice ghost send into unknown encryption state refused typed;
  • CR-14: a gate that fails if katrix-bot gains an optIn / internal reference;
  • CR-18: durable-store leg (APPSERVICE in the replay corpus, ref #101) and replay with the same txn id but different events;
  • §10.5.2: SendQueue.abort() and both ordering policies' blocking semantics; downloadThumbnail; autojoin rejecting filter; one-line durable identity at bot level; SAS cancel when the peer MAC omits its own device key.
    Acceptance: each clause has a test naming its CR id.
Review finding 2026-08-27 (D9). Remaining PARTIAL clauses with no dedicated test: - CR-10/NFR-10: only the unencrypted bot graph is gated — add a `checkBotFootprint` over an encrypted-bot sample (no SQL/UI/timeline, native crypto allowed); - CR-20/NFR-11: "E2EE + 0 lines" — diff the encrypted e2e bot body against the golden sample; - CR-11: emission switches with negotiated version (≥ stable-since → stable, below → unstable/refused); raw-lane `send(room, "org.matrix.msc…")` refused; - CR-9: a ghost send leaves bot-principal facts, cursor and compat standing byte-identical; - CR-1: crash injected mid-transaction (facts written, cursor pending) on a durable store; - CR-5: deterministic ack-then-crash-before-echo → no resend, echo reconciles; - CR-3: unknown event type through `TimelineWindow` and `SingleRoomView` with the envelope intact; - CR-7: appservice ghost send into unknown encryption state refused typed; - CR-14: a gate that fails if `katrix-bot` gains an `optIn` / internal reference; - CR-18: durable-store leg (APPSERVICE in the replay corpus, ref #101) and replay with the same txn id but different events; - §10.5.2: `SendQueue.abort()` and both ordering policies' blocking semantics; `downloadThumbnail`; autojoin rejecting filter; one-line durable identity at bot level; SAS cancel when the peer MAC omits its own device key. Acceptance: each clause has a test naming its CR id.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
thecrealm/katrix#163
No description provided.