Skip to content

docs: document malformed isAuthorized results (base-std@3820cf0) - #2072

Merged
youssefea merged 4 commits into
masterfrom
docs/sync-code-change-3820cf0
Oct 5, 2026
Merged

youssefea merged 4 commits into
masterfrom
docs/sync-code-change-3820cf0

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Source PR: base/base-std#234 — docs(policy): document malformed isAuthorized results

Merge commit: 3820cf0
Author: @rayyan224

Auto-generated from the source PR above.

Reviewer checklist

Before merging, confirm each item below. The validator catches structural problems (raw HTML, dangerous URLs, secrets); these items need a human eye.

  • Anchor text on every new link reads honestly — no click here, no link text that contradicts its target host.
  • Every newly introduced external URL (listed below) points to a host you expect to see in Coinbase docs.
  • Frontmatter title / description still match the page's role (reference vs. overview vs. conceptual).
  • Any <Warning> added describes a real breaking change in the source PR, not a paraphrase the model invented.

Newly introduced external URLs

No new external URLs in this sync.

Files touched

  • docs/base-chain/specs/reference/b20/changelog/02-cobalt-policyregistry-composite-policy.mdx
  • docs/base-chain/specs/reference/b20/changelog/03-denim-policyregistry-not-policy.mdx
  • docs/build-on-base/integrate-defi/list-tokenized-stocks.mdx
  • docs/build-on-base/issue-rwa/restrict-transfer-initiators.mdx
  • docs/build-on-base/issue-rwa/seize-and-cancel-units.mdx
  • docs/build-on-base/issue-stablecoins/block-an-account.mdx
  • docs/build-on-base/issue-stablecoins/restrict-who-can-hold.mdx
  • docs/specifications/b20/concepts/policies.mdx
  • docs/specifications/b20/introduction.mdx
  • docs/specifications/b20/reference/constants.mdx
  • docs/specifications/b20/reference/interfaces/i-policy-registry/index.mdx
  • docs/specifications/b20/reference/interfaces/i-policy-registry/is-authorized.mdx
  • docs/upgrades/beryl/b20.mdx

Source provenance

Each row shows which file(s) in base/base-std@3820cf0 drove an edit to a docs page. Click into a source file to verify the claim before merging.

Docs page Source file(s) in base
docs/base-chain/specs/reference/b20/changelog/02-cobalt-policyregistry-composite-policy.mdx src/interfaces/IPolicyRegistry.sol
docs/base-chain/specs/reference/b20/changelog/03-denim-policyregistry-not-policy.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/integrate-defi/list-tokenized-stocks.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-rwa/restrict-transfer-initiators.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-rwa/seize-and-cancel-units.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-stablecoins/block-an-account.mdx src/interfaces/IPolicyRegistry.sol
docs/build-on-base/issue-stablecoins/restrict-who-can-hold.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/concepts/policies.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/introduction.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/reference/constants.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/reference/interfaces/i-policy-registry/index.mdx src/interfaces/IPolicyRegistry.sol
docs/specifications/b20/reference/interfaces/i-policy-registry/is-authorized.mdx src/interfaces/IPolicyRegistry.sol
docs/upgrades/beryl/b20.mdx src/interfaces/IPolicyRegistry.sol

Opened by Apply Base Std Update workflow.

@github-actions
github-actions Bot requested a review from rayyan224 October 5, 2026 15:51
@cb-heimdall

cb-heimdall commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Heimdall Review Status

Requirement Status More Info
Reviews ✅ 2/2
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

@mintlify

mintlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
base 🟢 Ready View Preview Oct 5, 2026, 7:22 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

The sync repeated the full malformed/unknown/inverted isAuthorized rules
on every page that mentions isAuthorized. Keep the canonical table on the
is-authorized reference and the Policies concept page; elsewhere use one
sentence and a link.

- Revert restrict-transfer-initiators and restrict-who-can-hold (passing
  mentions only).
- Revert the Cobalt changelog and Beryl upgrade pages: historical records,
  and this source change is a NatSpec clarification, not a Cobalt/Beryl
  change.
- Seize and Cancel Units, Block an Account: keep the task-specific risk in
  one sentence and link to the reference.
- List Tokenized Stocks, B20 introduction: one sentence each.
- is-authorized: turn leftover Dev/Param/Return lines into Parameters and
  Returns sections and fix Access Control (as approved in #2054).

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
@soheimam

soheimam commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Replaces closed #2054 (re-run to get a signed bot commit after #2068). dde43737 is a manual follow-up to the regenerated sync:

Why: this source change (base-std@3820cf0) only clarifies the isAuthorized NatSpec. The sync sent every page that mentions isAuthorized to the model, and the prompt requires an edit on any page that mentions a changed symbol, so the same malformed/unknown/inverted rules were restated on ~10 pages.

What changed

  • Full rules stay on the is-authorized reference and the Policies concept page. Elsewhere it's one sentence plus a link.
  • Reverted: Restrict Who Can Initiate Transfers and Restrict Who Can Hold It (passing mentions only), plus the Cobalt changelog and Beryl upgrade pages (historical records, not affected by this change).
  • Kept: a short note on Seize and Cancel Units (an unknown or malformed ID on SEIZE_EXEMPT_POLICY makes holders seizable) and on Block an Account (an unknown blocklist ID returns true for everyone).
  • is-authorized.mdx: Parameters/Returns sections and Access Control cleanup, as approved in docs: document malformed isAuthorized results (base-std@3820cf0) #2054.

Note for reviewers: the content was regenerated by Sonnet 5.5, so the wording differs from what was approved in #2054. lint-mdx and terminology checks pass.

🤖 Reply generated with Toshi

Comment thread docs/build-on-base/issue-stablecoins/block-an-account.mdx Outdated
Comment thread docs/specifications/b20/concepts/policies.mdx Outdated
Drops the Block an Account note and the Policies 'Malformed and unknown IDs'
section; the rules remain on the isAuthorized reference page.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
@cb-heimdall

Copy link
Copy Markdown
Collaborator

Review Error for rayyan224 @ 2026-10-05 20:03:01 UTC
User failed mfa authentication, see go/mfa-help

@roethke
roethke self-requested a review October 5, 2026 20:16
@youssefea
youssefea merged commit 39612e1 into master Oct 5, 2026
15 checks passed
@youssefea
youssefea deleted the docs/sync-code-change-3820cf0 branch October 5, 2026 20:17
soheimam added a commit that referenced this pull request Oct 6, 2026
* test(docs-sync): add eval harness and the base-std@3820cf0 case

run-eval.mjs runs the working-tree (or --code-ref) sync code against a
pinned docs commit in a throwaway worktree and scores the result against
the case's expectations: pages that must, may, and must not change, edit
budgets for secondary pages, and restatement of full rules outside their
owner pages.

The first case is base-std#234 (3820cf0), a NatSpec-only clarification of
isAuthorized that the sync spread across ~10 pages (#2054, #2069, #2072).

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* fix(docs-sync): stop guide pages being edited for passing mentions

- Rule 5: guides and concept pages change only when the source change
  makes a step, outcome, revert, or recommended setting on the page wrong;
  otherwise they are returned unchanged. Add 'one owner per fact': full
  behavior lives on the owning reference page; other pages link to it.
- Rule 6: inventory documented surfaces, not mentions. A manifest entry
  that matches only a mention is not an intersection. Comment-only diffs
  clarify behavior; edit only statements they show to be wrong.
- Step 4: polish only edited paragraphs; callouts only for real behavior
  changes, never for clarifications.
- The anti-noop rule now applies to reference and changelog-entry pages
  that document the changed symbol, not to pages that only mention it.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* fix(docs-sync): route comment-only changes to reference pages; skip historical pages

- isCommentOnlyChange: a dispatch whose source diff only edits Solidity
  comments is a clarification. Symbol-mention routing then reaches only
  function-reference and interface-index pages, and the prompt is told
  the change type.
- symbolRouteGate: pages found only by symbol mention are not routed when
  they are changelog entries for an earlier hardfork or upgrades/<fork>/
  pages for a fork other than the newest. Path-routed pages are unaffected.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* test(docs-sync): add base-std@1505323 recall case; must_mention and warn

1505323-token-self-recipient replays base-std#232, a real behavior change
(transfers, mints, and seizes to the token's own address now revert) that
reaches src/ only as NatSpec. It guards the other direction from the
3820cf0 case: the five function references that list InvalidReceiver must
change, and their added lines must state the new condition.

- must_mention: a regex the added lines of a page must match, so a
  cosmetic edit to a required page does not count.
- unlisted_pages: "warn" reports pages outside the lists without failing.
- README: how to run the evals and what each case guards.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* fix(docs-sync): find NatSpec-documented members; guard code samples and retry streams

From the base-std@1505323 eval (0/2 before, 6/6 after across both cases):

- natspecDocumentedSymbols: a NatSpec hunk usually stops above the
  declaration it documents, so mint.mdx was skipped whenever the model's
  manifest happened not to name mint. Walk the post-change source (already
  fetched for changelog entries) from each changed comment line to the next
  declaration; function-reference pages for those members are always called.
- isCommentOnlyChange: reference mocks (test/lib/mocks/) count as code. Base
  Std is interface-only, so NatSpec plus a mock change is a behavior change,
  not a clarification. The prompt no longer lets the model infer
  "clarification" from a comment-only diff slice; only the flag decides.
- restoreCodeSamples: on guide pages, when no signature changed upstream,
  restore fenced code blocks (not mermaid) the model altered. A run had
  rewritten send-a-payout's functionName to "simulateContract".
- normalizeForNoop: table re-padding alone is a noop.
- llm/client: retry mid-stream overloaded/api errors twice with backoff;
  the SDK's maxRetries only covers the initial response, and one such error
  failed a whole sync in the eval.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

* docs(docs-sync): shrink the evals README section to a pointer

Usage lives in the run-eval.mjs header and each case documents itself;
the README only needs to say when to run it.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

---------

Co-authored-by: Toshi <toshi-noreply@coinbase.com>

This branch was successfully deployed

1 active deployment
staging - docs — fd966ab6 Deployed Oct 5, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants