From 56cc8d80ef99a734d680f401ce88a9bd3858bb6a Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Tue, 22 Sep 2026 14:57:07 -0400 Subject: [PATCH] fix(operate): say a revoke pauses after the grace window A deleted record keeps its subtree writing until the deployment's grace window runs out, six hours by default, so the flag's help, the printed result and the walk's paused edge now say so and name the lock or the stop that acts at once. Co-Authored-By: Claude Opus 5.5 (1M context) Change-Id: I6467ba2ad4449a6825d11b2deeae66d0971928b9 --- crates/didbot-operator/src/bin/didbot-operator.rs | 9 ++++++--- crates/didbot-operator/src/operate/account.rs | 4 ++-- crates/didbot-operator/src/operate/walk.rs | 6 ++++-- docs/cli.md | 5 +++-- plan/ownership.md | 6 +++--- 5 files changed, 18 insertions(+), 12 deletions(-) diff --git a/crates/didbot-operator/src/bin/didbot-operator.rs b/crates/didbot-operator/src/bin/didbot-operator.rs index 4f2f2f73..8178cfbc 100644 --- a/crates/didbot-operator/src/bin/didbot-operator.rs +++ b/crates/didbot-operator/src/bin/didbot-operator.rs @@ -88,7 +88,8 @@ enum Verb { #[arg(long, conflicts_with = "revoke")] check: bool, /// Delete your bot.did.operator record for , which pauses it and everything - /// beneath it at the deployment's next poll + /// beneath it after the deployment's grace window (six hours by default). `didbot + /// account lock ` stops an account now, and `didbot estop --pause` a server #[arg(long)] revoke: bool, /// A server's hostname, or an account's @@ -471,8 +472,10 @@ async fn revoke_record(name: &str, operator: &str, json: Json) -> Result<(), Ref |_| { format!( "deleted {}, which named {}\n\ - the deployment reads this at its next operator poll and pauses that account \ - and everything beneath it; this command does not wait for that to happen.", + it and everything beneath it pause after the deployment's grace window (six \ + hours by default); this command does not wait for that to happen.\n\ + `didbot account lock {name} --server ` stops an account now, and \ + `didbot estop --pause --server ` a server.", revoked.record_uri, revoked.subject ) }, diff --git a/crates/didbot-operator/src/operate/account.rs b/crates/didbot-operator/src/operate/account.rs index ec95b331..45540886 100644 --- a/crates/didbot-operator/src/operate/account.rs +++ b/crates/didbot-operator/src/operate/account.rs @@ -552,8 +552,8 @@ pub struct Revoked { /// /// The read is what makes this safe to run against a typo: a key that holds /// some other account's claim is left alone and named in the refusal. The -/// deployment reads the deletion at its next operator poll, which is what -/// pauses the account and everything beneath it. +/// deployment's operator poll pauses the account and everything beneath it +/// once it has gone the grace window without reading the record. pub async fn revoke( own_pds: &W, operator_did: &str, diff --git a/crates/didbot-operator/src/operate/walk.rs b/crates/didbot-operator/src/operate/walk.rs index 41f3aa18..029a87a8 100644 --- a/crates/didbot-operator/src/operate/walk.rs +++ b/crates/didbot-operator/src/operate/walk.rs @@ -71,8 +71,10 @@ pub enum WalkError { /// both. #[error( "{operator} holds no bot.did.operator/{name}: the edge from {account} up to it is \ - paused, whether the record was taken back or never written, and a deployment \ - hosting {account} stops it and everything beneath it at its next poll" + paused, whether the record was taken back or never written. A deployment hosting \ + {account} stops it and everything beneath it after the deployment's grace window \ + (six hours by default); `didbot account lock` stops an account now, and `didbot \ + estop --pause` a server" )] Paused { /// The account below the edge. diff --git a/docs/cli.md b/docs/cli.md index 2a01dae7..c74a7381 100644 --- a/docs/cli.md +++ b/docs/cli.md @@ -325,8 +325,9 @@ didbot app end-logins --client https://app.example/client.json \ the operator's own repository rather than the deployment: it deletes `bot.did.operator/` there, through the delete action of the same scope the claim was written with, after reading the record back and confirming it -names that account. The deployment finds that at its next poll and pauses -the account and everything beneath it. +names that account. The deployment pauses the account and everything beneath +it after its grace window, six hours by default. `didbot account lock ` +stops an account at once, and `didbot estop --pause` stops a server. ## The agent host's commands diff --git a/plan/ownership.md b/plan/ownership.md index f33889f4..5e5dce28 100644 --- a/plan/ownership.md +++ b/plan/ownership.md @@ -154,9 +154,9 @@ new account is the authorization. --revoke ` reads `bot.did.operator/` out of the human's own repository, confirms it names that account, and deletes it through the delete action of the scope the claim was written under. - The deployment's poll pauses the account and everything beneath it; - `didbot operate --check` names the edge as paused from then on - (`operate::walk::WalkError::Paused`). + The deployment's poll pauses the account and everything beneath it + after the grace window; `didbot operate --check` names the edge as + paused from then on (`operate::walk::WalkError::Paused`). - [x] **The operator acts on one hosted account.** `POST /dashboard/api/accounts/{did}/lock`, `unlock`, `lift-quarantine`, -- 2.51.2