Skip to content

fix(authority): compare temporal scope bounds as instants - #125

Draft
RecursiveIntell wants to merge 1 commit into
mainfrom
fix/ares-authority-time-instants-20261004
Draft

RecursiveIntell wants to merge 1 commit into
mainfrom
fix/ares-authority-time-instants-20261004

Conversation

@RecursiveIntell

Copy link
Copy Markdown
Owner

What does this PR do?

Temporal attenuation currently compares normalized ISO timestamps as strings. A whole-second upper bound such as 00:00:00Z incorrectly admits a later child bound 00:00:00.100000Z, and same-second interval validation can reverse chronological order. Compare parsed UTC instants while preserving timestamp wire spelling and digest inputs.

Related Issue

Source-supported pure authority review finding. No deployed consumer or attribution to the active Ares incident has been established.

Type of Change

  • Bug fix

Changes Made

  • ares_runtime/authority.py: compare interval order and both subset bounds as UTC datetimes; reject widening before delegation charging.
  • Add 16 regressions covering mixed precision, equivalent time zones, both attenuation bounds and retained delegation budget after rejection.

How to Test

scripts/run_tests.sh -j 1 --file-retries 0 --file-timeout 90 tests/ares_runtime/test_authority_fractional_time.py tests/ares_runtime/test_authority.py tests/ares_runtime/test_authority_review_regressions.py -q

Exact focused tree 213ed87cd4f695c0e96e3f274838e39d464bfddf passed 37 tests, zero failures, three files, one worker and zero retries. Original implementation with the same final new test file has ten causal failures and six passing controls. A fresh independent source reviewer found no blocking findings.

Linux offline execution used a disposable source copy, hidden real home, temporary stores and Python network denial. A task-only interpreter shim skipped the optional bytecode cache prebuild for disk headroom; the canonical per-file runner and tests were unchanged. Source/index hashes stayed stable. Full-suite, installed application, provider/MCP and cross-platform runtime checks were not exercised.

Checklist

  • Conventional commit; focused source and tests only
  • Searched current open Ares PRs for overlap
  • Added meaningful regressions and ran focused compatibility checks
  • Full repository suite: not run in this bounded draft pass
  • Linux validation; no configuration, schema or architecture changes

Evidence and Rollback

Base 04997747879d54a242941d344c3a38293c307076, tree cbabd9591dc00fdf8deed90aeb3e8b1dc5bd2ebc. Exact forward/reverse index replay restored the base. Reverse delta SHA256: 7c0900fb9d118d189ee9433e30dab6027207fbf6e20d67d98eb8492f5c0b02b6.

Draft source proposal only. A future authorized rollback is reverting this focused commit; no activation, service, installed profile or live rollback action accompanies publication.

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 6f1b1a1 — fix(authority): compare temporal scope bounds as instants

⚠️ Warnings

OSV vulnerability scan · View job

96 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 4m41s vs 7m23s (-36.6%). 12 job(s) slower, 10 faster, 2 unchanged.

  • Python tests / Run tests slice 2/12: -105.0s
  • Python tests / Run tests slice 9/12: -88.0s
  • Python tests / Run tests slice 8/12: -82.0s
  • OS-specific tests / macOS-only tests: -75.0s
  • Python tests / Run tests slice 11/12: +65.0s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant