mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-12 01:07:46 +00:00
An independent review of the concurrent-servicing changes found two real bugs (the quartz/authorizer concurrency core reviewed clean): - Notification TOCTOU. SignerConsentCoordinator did a non-atomic "if pending empty → cancel notification" in the resolving request's finally. A request arriving concurrently could post the shared full-screen-intent notification between another request's empty-check and its cancel, wiping the new request's only surface while backgrounded — it then sat unseen until the 120s timeout denied it. Add/show and remove/empty-check/cancel now run under one surfaceLock, so a live request's notification can't be cancelled out. - Batched selection re-seeded to all-selected on any pending-set change (fail-open). Because requests are serviced concurrently, the pending set changes under an open sheet; re-seeding silently re-checked deselected items and auto-checked newly-arrived requests, so "Allow selected" could grant ops the user deselected or never saw. Now seed once and reconcile incrementally (selected ∩ tokens): deselections survive and a new request is never auto-selected. Also default the batch "Remember" toggle off. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015FHr2mu5SiHwYNR7evYUuF