Conversation
Four flags and two modes, 64 combinations; the guarded operations reach exactly the 21 the product's rules allow. The shortcut's disable-sso checks authentication but not the shard latch: enable-legacy-auth, shard, disable-sso reaches a forbidden state, and only in that order. --fiber cfg.region shows the EU deployment is safe from it by accident. v2 adds a billing flag whose enable turns tenancy on: compare reports never-unsafe LOST in one move, and check reports the new operation unadmitted. final-phase names exactly the sharded configurations. Cross-check 56 -> 60 properties (58 compared); 329 checks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
Superseded: reached main through #10. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #8 (base
payments).Adds
config-space/: four feature flags and two modes (64 combinations) under four product rules, with admin operations whose guards are the rules read as preconditions.disable-ssochecks authentication but not the shard latch. The routeenable-legacy-auth → shard → disable-ssoreaches a forbidden state, and only in that order: disable SSO first andshardrefuses.recoverablestill holds, which is why the bug would ship.--fiber cfg.region(FR-10): only the US fiber fails. The EU deployment is protected by accident, because legacy auth is forbidden there and is the route's first step.new-billing, whose enable also turns tenancy on.compare:never-unsafe LOST witness: 1. enable-new-billing.checkalso reportsunadmitted enable-new-billing.final-phase(ct.rules §3) names exactly the sharded configurations. That is what the one-wayshardcosts, asked without a goal.Differences from the plan: the pair is the realistic one-condition mistake the plan described, not an "everything unguarded" UI, which would break every rule trivially.
Cross-check: 56 → 60 properties (58 compared).
./run-tests.sh all: 329 checks, 0 failed.🤖 Generated with Claude Code