Stop ecash recovery failures from silently reusing or abandoning backup state

This commit is contained in:
archipelago
2026-10-06 14:34:25 -04:00
parent a7cc7084f2
commit 12e2a82b28
5 changed files with 245 additions and 33 deletions
+28
View File
@@ -76,3 +76,31 @@ ignored tests**. Logs: `/tmp/archy-peer-payment-selection-tests.log` and
`/tmp/archy-peer-payment-selection-full-tests.log`. Only the required isolated
runner was used. No live wallet data or real payments were involved. This is
source/test qualification; production build and deployment are separate.
## Recovery-metadata prerequisite qualified (2026-10-06)
Seed reads now distinguish genuine absence from I/O failure. Loading a damaged
recovery source returns an error instead of silently enabling random outputs.
A configured recovery source must reserve/derive outputs successfully before a
mint request; derivation/counter failures no longer fall back to random secrets.
Legacy wallets which genuinely have no seed retain their existing output path.
Counter reservations reject empty/corrupt/unreadable existing files rather than
resetting to zero. Updates use an owner-only sibling temporary file, file flush,
atomic replacement and directory flush before returning a usable reservation.
Invalid derivation is rejected before reserving counters. Existing counter
serialization within the management process is preserved; this is not a claim
that a new cross-process wallet lock or the purchase journal has been implemented.
Six new regressions cover damaged seed/counter reads, preserved damaged files,
concurrent reservations/reload/private permissions/temp cleanup, invalid keysets,
no silent random-output fallback and explicit legacy behavior. Wallet-focused
isolated result:150passed,0failed,1existing ignored. Full isolated result:
**1,755passed,0failed,5existing ignored**. Evidence:
`/tmp/archy-wallet-recovery-prerequisites-tests.log` and
`/tmp/archy-wallet-recovery-prerequisites-full-tests.log`.
Read-only checks found well-shaped seed/counter JSON on dev and Yaya; no secret
values were printed and no wallet files were changed by those checks. Production
build/deployment of this prerequisite remains pending. Durable initial purchase
intent, mint-operation recovery, seller receipt and refund recovery remain open.
+15
View File
@@ -831,3 +831,18 @@ payment recovery, timed FIPS playback and complete node-to-node acceptance remai
open. V4V managed installation still requires the pending node-only catalog
signature. The running dev/Yaya dashboard/backend builds are unchanged, and no
additional real payment was made.
Full-suite follow-up: IndeeHub `f2668c0` adds active-rental continuation and
`920f3b0` repairs the subscription regressions and records final qualification.
All143backend tests across14suites now pass, with no skipped/failed tests;
all94frontend tests pass. Both production builds and mobile/desktop library/rental
browser checks pass. Failed original logs are retained. The disposable database,
volume and fixture credentials were removed. These remain source/artifact checks;
no IndeeHub app update was deployed and the full paid-video flow is still open.
Payment-recovery prerequisite under qualification next: preserve errors reading
an existing Cashu seed/counter, stop random-output fallback when an established
recovery source fails, and atomically flush counter reservations before use.
Rust wallet tests are running only through the required isolated test runner.
No real wallet mutation or additional payment is involved. This prerequisite is
not a completed purchase journal, seller receipt or initial-payment recovery gate.