# Review synthesis and disposition

The requested fresh sanity-check review ran before implementation. Actual Fable (`claude-fable-5-1`) and Zai (`glm-5.3`) reviewed the resulting code. Full reports are alongside this file.

Accepted and fixed:
- Fable: discovery reads head − 2. The sender now waits for the chain head to reach receipt block + 2 before refreshing or advancing a sequence, so completed funding/debt/roll steps appear in the next position read. A regression test covers the boundary.
- Fable: held aTokens need `fundFromHoldings`; the card offers Start received assets instead of a deposit that sizes only new funds. Fresh fund/activate dialogs reject already-started, stopped or expired positions. Funding rechecks before spending approval gas.
- Fable: raw reserve debt decides whether a roll needs priming, including dust below Aave's dollar precision. The destination is checked again after priming.
- Both: preserve the provider's wallet error detail and the explorer link for a reverted receipt. The Node suite also found and fixed read-only DOMException.message mutation on receipt timeout.
- Independently during implementation: disable creation inputs while preparing the immutable review; queued dialog-close events cannot cancel a newly reopened dialog.

Not adopted:
- Zai B1 proposed changing the one-year fee branch. The deployed Pair `_tariff` (source lines 649–654) explicitly sets `dt=0` if it exceeds MAX_TENOR, and the Factory (line 227) refuses terms over 365 days. The existing frontend matches this source. Applying the proposed cap would break parity with the contract. Fable independently confirmed the original fee calculation.
- Extra local transaction recovery, nonce locks and automatic replacement tracking remain omitted per the sanity critique. Wallet activity and fresh chain reads provide recovery.
- The creation parse-failure path already says to check My Wallet and wallet activity; it does not claim that the transaction failed or encourage automatic retry.

External integration witness:
- CoW accepted the exact generated v1.3.0 document with hooks v0.1.0, syncCollateral selector 0xeefc9473, gasLimit 150000, targeting predicted test address `0xa49A8df18CbFe0149A2422a371465cA8dCE68b22`.
- Registered hash `0xb6336f7d75648ae9e352a4184a6635c34790aaface57b87ce297920a0ffd9f6f`; GET returned 200 and byte-identical fullAppData. This registered metadata only: no position, wallet transaction or funds movement.
- Older trial pairs' registered documents do not contain this hook. New frontend creation includes it; Update collateral remains the manual backstop.

Review scope and approval limits:
- Automatic approval review rejected sharing private backend source with Zai. A reduced public frontend copy was approved and reviewed instead. Contract-specific Zai claims were checked locally against the actual source.
- Automatic approval review rejected a browser test that tried enabling a disabled Borrow button. That test was not executed. Normal UI review checks are used after the completed test/review gate enables live actions.
- No agent test signs or broadcasts a real wallet transaction. The user sends through their external wallet.

Additional direct Fable review (public files):
- Accepted: keep transaction dialogs open and disable dismissal while a send is active, preventing a second action against state that excludes the first pending transaction. Wallet identity changes still reset the operation; normal wallet rejection and receipt timeout restore controls.
- Accepted: validate a returned hash before retaining it or making an explorer link; recognize ACTION_REJECTED and WalletConnect 5000 rejection codes.
- Its head-minus-two and provider-error findings were already fixed.
- `primeFor` is repeatable while the destination remains open/unfunded/unexpired: it sets absolute delegation for source debt tokens and has no separate primed-state refusal. Spenders and delegation were independently witnessed in the deployed Base fork. The proposed fee-cap change remains rejected for the source-parity reason above.
