Skip to content

docs: document malformed isAuthorized results (base-std@3820cf0) - #2054

Closed
github-actions[bot] wants to merge 0 commit into
masterfrom
docs/sync-code-change-3820cf0
Closed

github-actions[bot] wants to merge 0 commit into
masterfrom
docs/sync-code-change-3820cf0

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Source PR: base/base-std#234 — docs(policy): document malformed isAuthorized results

Merge commit: 3820cf0
Author: @rayyan224

Auto-generated from the source PR above.

Reviewer checklist

Before merging, confirm each item below. The validator catches structural problems (raw HTML, dangerous URLs, secrets); these items need a human eye.

  • Anchor text on every new link reads honestly — no click here, no link text that contradicts its target host.
  • Every newly introduced external URL (listed below) points to a host you expect to see in Coinbase docs.
  • Frontmatter title / description still match the page's role (reference vs. overview vs. conceptual).
  • Any <Warning> added describes a real breaking change in the source PR, not a paraphrase the model invented.

Newly introduced external URLs

No new external URLs in this sync.

Files touched

  • docs/base-chain/specs/reference/b20/changelog/03-denim-b20-transfer-executor-enforcement.mdx
  • docs/base-chain/specs/reference/b20/changelog/03-denim-policyregistry-not-policy.mdx
  • docs/build-on-base/issue-rwa/restrict-transfer-initiators.mdx
  • docs/build-on-base/issue-rwa/seize-and-cancel-units.mdx
  • docs/build-on-base/issue-stablecoins/block-an-account.mdx
  • docs/build-on-base/issue-stablecoins/restrict-who-can-hold.mdx
  • docs/specifications/b20/introduction.mdx
  • docs/specifications/b20/reference/constants.mdx
  • docs/specifications/b20/reference/interfaces/i-policy-registry/index.mdx
  • docs/specifications/b20/reference/interfaces/i-policy-registry/is-authorized.mdx

Source provenance

Each row shows which file(s) in base/base-std@3820cf0 drove an edit to a docs page. Click into a source file to verify the claim before merging.

Docs page Source file(s) in base
docs/base-chain/specs/reference/b20/changelog/03-denim-b20-transfer-executor-enforcement.mdx src/interfaces/IPolicyRegistry.sol
docs/base-chain/specs/reference/b20/changelog/03-denim-policyregistry-not-policy.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-rwa/restrict-transfer-initiators.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-rwa/seize-and-cancel-units.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-stablecoins/block-an-account.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-stablecoins/restrict-who-can-hold.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/introduction.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/reference/constants.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/reference/interfaces/i-policy-registry/index.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/reference/interfaces/i-policy-registry/is-authorized.mdx src/interfaces/IPolicyRegistry.sol

Opened by Apply Base Std Update workflow.

@mintlify

mintlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
base 🟢 Ready View Preview Oct 5, 2026, 1:46 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@github-actions
github-actions Bot requested a review from rayyan224 October 1, 2026 16:58
@cb-heimdall

cb-heimdall commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

🟡 Heimdall Review Status

Requirement Status More Info
Reviews 🟡 0/2
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

⚠️ Ignored Reviews (1)

Reviewer Reason
soheimam Bound to another issue (#2056)

@cb-heimdall

Copy link
Copy Markdown
Collaborator

Review Error for rayyan224 @ 2026-10-02 13:55:32 UTC
User failed mfa authentication, see go/mfa-help

ericbrown99 pushed a commit that referenced this pull request Oct 5, 2026
* ci(docs-sync): create sync commits via GitHub API so they are signed

master requires verified signatures, and the workflow's local git commit
was unsigned, blocking every sync PR (e.g. #2054). Commit through GraphQL
createCommitOnBranch instead, which GitHub signs as github-actions[bot].

Same GITHUB_TOKEN and contents: write; no new secrets, keys, or actions.
The path allowlist is re-checked in the script, and only regular 100644
files are accepted.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* chore(docs-sync): default to claude-sonnet-5-5

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

---------

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
@github-actions github-actions Bot closed this Oct 5, 2026
@github-actions
github-actions Bot force-pushed the docs/sync-code-change-3820cf0 branch from 049c161 to 1b23213 Compare October 5, 2026 15:22
soheimam added a commit that referenced this pull request Oct 5, 2026
Each page call returns the full regenerated page. Under Sonnet 5.5 the
4096-token cap truncated seize-and-cancel-units.mdx (8,955 chars), so the
page was rejected and dropped from the sync PR (#2069 vs #2054).

- DEFAULT_MAX_TOKENS: 4096 -> 16384 (CLAUDE_MAX_TOKENS still overrides)
- MAX_REGENERABLE_CHARS: 10000 -> 32000 to match the new budget
  (~2.2 chars/token measured on Sonnet 5.5)

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
soheimam added a commit that referenced this pull request Oct 5, 2026
The sync repeated the full malformed/unknown/inverted isAuthorized rules
on every page that mentions isAuthorized. Keep the canonical table on the
is-authorized reference and the Policies concept page; elsewhere use one
sentence and a link.

- Revert restrict-transfer-initiators and restrict-who-can-hold (passing
  mentions only).
- Revert the Cobalt changelog and Beryl upgrade pages: historical records,
  and this source change is a NatSpec clarification, not a Cobalt/Beryl
  change.
- Seize and Cancel Units, Block an Account: keep the task-specific risk in
  one sentence and link to the reference.
- List Tokenized Stocks, B20 introduction: one sentence each.
- is-authorized: turn leftover Dev/Param/Return lines into Parameters and
  Returns sections and fix Access Control (as approved in #2054).

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
youssefea added a commit that referenced this pull request Oct 5, 2026
* docs: sync from base-std@3820cf0

* docs: trim isAuthorized restatements to the pages that need them

The sync repeated the full malformed/unknown/inverted isAuthorized rules
on every page that mentions isAuthorized. Keep the canonical table on the
is-authorized reference and the Policies concept page; elsewhere use one
sentence and a link.

- Revert restrict-transfer-initiators and restrict-who-can-hold (passing
  mentions only).
- Revert the Cobalt changelog and Beryl upgrade pages: historical records,
  and this source change is a NatSpec clarification, not a Cobalt/Beryl
  change.
- Seize and Cancel Units, Block an Account: keep the task-specific risk in
  one sentence and link to the reference.
- List Tokenized Stocks, B20 introduction: one sentence each.
- is-authorized: turn leftover Dev/Param/Return lines into Parameters and
  Returns sections and fix Access Control (as approved in #2054).

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* docs: remove isAuthorized restatements per review feedback

Drops the Block an Account note and the Policies 'Malformed and unknown IDs'
section; the rules remain on the isAuthorized reference page.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: sohey <soheimam@gmail.com>
Co-authored-by: Toshi <toshi-noreply@coinbase.com>
Co-authored-by: Youssef <youcefea99@gmail.com>
soheimam added a commit that referenced this pull request Oct 6, 2026
* test(docs-sync): add eval harness and the base-std@3820cf0 case

run-eval.mjs runs the working-tree (or --code-ref) sync code against a
pinned docs commit in a throwaway worktree and scores the result against
the case's expectations: pages that must, may, and must not change, edit
budgets for secondary pages, and restatement of full rules outside their
owner pages.

The first case is base-std#234 (3820cf0), a NatSpec-only clarification of
isAuthorized that the sync spread across ~10 pages (#2054, #2069, #2072).

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* fix(docs-sync): stop guide pages being edited for passing mentions

- Rule 5: guides and concept pages change only when the source change
  makes a step, outcome, revert, or recommended setting on the page wrong;
  otherwise they are returned unchanged. Add 'one owner per fact': full
  behavior lives on the owning reference page; other pages link to it.
- Rule 6: inventory documented surfaces, not mentions. A manifest entry
  that matches only a mention is not an intersection. Comment-only diffs
  clarify behavior; edit only statements they show to be wrong.
- Step 4: polish only edited paragraphs; callouts only for real behavior
  changes, never for clarifications.
- The anti-noop rule now applies to reference and changelog-entry pages
  that document the changed symbol, not to pages that only mention it.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* fix(docs-sync): route comment-only changes to reference pages; skip historical pages

- isCommentOnlyChange: a dispatch whose source diff only edits Solidity
  comments is a clarification. Symbol-mention routing then reaches only
  function-reference and interface-index pages, and the prompt is told
  the change type.
- symbolRouteGate: pages found only by symbol mention are not routed when
  they are changelog entries for an earlier hardfork or upgrades/<fork>/
  pages for a fork other than the newest. Path-routed pages are unaffected.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* test(docs-sync): add base-std@1505323 recall case; must_mention and warn

1505323-token-self-recipient replays base-std#232, a real behavior change
(transfers, mints, and seizes to the token's own address now revert) that
reaches src/ only as NatSpec. It guards the other direction from the
3820cf0 case: the five function references that list InvalidReceiver must
change, and their added lines must state the new condition.

- must_mention: a regex the added lines of a page must match, so a
  cosmetic edit to a required page does not count.
- unlisted_pages: "warn" reports pages outside the lists without failing.
- README: how to run the evals and what each case guards.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* fix(docs-sync): find NatSpec-documented members; guard code samples and retry streams

From the base-std@1505323 eval (0/2 before, 6/6 after across both cases):

- natspecDocumentedSymbols: a NatSpec hunk usually stops above the
  declaration it documents, so mint.mdx was skipped whenever the model's
  manifest happened not to name mint. Walk the post-change source (already
  fetched for changelog entries) from each changed comment line to the next
  declaration; function-reference pages for those members are always called.
- isCommentOnlyChange: reference mocks (test/lib/mocks/) count as code. Base
  Std is interface-only, so NatSpec plus a mock change is a behavior change,
  not a clarification. The prompt no longer lets the model infer
  "clarification" from a comment-only diff slice; only the flag decides.
- restoreCodeSamples: on guide pages, when no signature changed upstream,
  restore fenced code blocks (not mermaid) the model altered. A run had
  rewritten send-a-payout's functionName to "simulateContract".
- normalizeForNoop: table re-padding alone is a noop.
- llm/client: retry mid-stream overloaded/api errors twice with backoff;
  the SDK's maxRetries only covers the initial response, and one such error
  failed a whole sync in the eval.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* docs(docs-sync): shrink the evals README section to a pointer

Usage lives in the run-eval.mjs header and each case documents itself;
the README only needs to say when to run it.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

---------

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

This branch was successfully deployed

1 active deployment
staging - docs — 1b232132 Deployed Oct 5, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants