Serialize wallet mutations and preserve network and seed recovery state

This commit is contained in:
archipelago
2026-10-06 15:39:44 -04:00
parent 9f0df2ac44
commit 9c95b8732f
11 changed files with 322 additions and 70 deletions
+28
View File
@@ -142,3 +142,31 @@ whole-file replacement (not read-modify-write serialization), private permission
and retained targets on rename failure. Wallet tests:57passed. Full backend
qualification passes in `/tmp/archy-wallet-storage-tls-full-tests.log`. No live
wallet was altered. Operation serialization and recovery journal remain open.
### Serialized wallet mutations and seed durability
The wallet now serializes public mutations by canonical node data directory,
including network changes and seed establishment/import. Independent node
fixtures retain separate locks; nested send/swap paths use private implementations
under the outer lock. Streaming revenue records use the same boundary, and direct
wallet saves are restricted to the wallet module. This is in-process serialization,
not a cross-process transaction journal or a claim that an entire payment RPC is
recoverable.
Damaged network configuration now errors instead of silently choosing mainnet;
only an absent configuration retains the historical mainnet default. The previous
seed is durably copied to a unique private backup before atomic replacement,
rather than moved away before the replacement write succeeds.
Final isolated suite: **1,764 tests pass, zero failures, five existing skips**.
Log: /tmp/archy-wallet-mutation-seed-final-tests.log. Regressions include eight
simultaneous real HTTP/curve-signed fixture receipts plus sixteen history writes,
preserving255sats and24entries; canonical/symlink lock identity; damaged network
configuration; and simultaneous seed establishment/unique retained backups.
No live wallet data or additional real payments were used.
Still required: correlated purchase and mint-operation journal, recoverable
prepared outputs, quote/change handling and seller receipts, interrupted-operation
recovery and complete timed-playback integration. Higher-level Minibits claim and
purchase flows must pin their network/terms across their entire business operation;
serializing individual wallet calls alone does not provide that contract.
+21
View File
@@ -880,3 +880,24 @@ localhost replacement could alter external hostnames or paths. Exact authority
matching fixes these errors. The 22 focused launch/stable-URL/loader tests pass
after two new failures were reproduced. This is not claimed as the live gate
incident's cause. Production UI build passes (`/tmp/archy-https-runtime-ui-build.log`). This change is not yet deployed.
## Wallet storage and Yaya TLS qualification
Commits `719e7238` and `9f0df2ac` pass the complete isolated backend suite:
1,757passed, zero failures, five existing skips. Wallet storage tests57pass;
permission repair tests6pass; first-boot9and rotation8cases pass. Live Yaya's
root-only leaf key was confirmed by gate permission-denied logs; changing only
its group/mode restored authenticated HTTPS iframe200. No cert bytes, nginx
configuration or app processes changed. Normal trust and the exact operator
URL/app remain open. See `docs/https-app-gate-followup-20261006.md`.
Per-wallet mutation serialization is now being qualified separately. It uses
canonical data-directory locks so independent fixture nodes cannot deadlock one
another, and private nested helpers avoid recursive locking. Wallet network
changes and streaming revenue writes participate. This remains uncommitted
and is not a durable transaction journal.
Final wallet serialization/network/seed qualification:1,764backend tests pass,
zero failures, five existing skips. This includes the concurrent receipt/history
and seed-backup tests. Source is ready for review; not deployed, and the durable
purchase journal remains open.
+9
View File
@@ -378,3 +378,12 @@ as a substitute for repairing the standard public-channel experience.
- User reports opening apps inside an iframe on an HTTPS node shows the app gate, while opening the same app in a separate tab works. Reproduce both modes with the same authenticated session before identifying a cause.
- Trace generated launch origins, cookie attributes and scope, bootstrap redirects, iframe navigation and gate session exchange. Preserve authentication and public-management access restrictions; do not bypass the gate or expose credentials to embedded apps.
- Test HTTPS iframe and tab, HTTP LAN compatibility, desktop/mobile companion, reload, expired sessions, denied access and logout. Record actual-node evidence separately from fixtures. This remains open, not a confirmed diagnosis.
### Task 17 progress
Yaya's app gate could not read its root-only TLS leaf key; logs confirmed
permission denied. Correcting only its group/mode restored authenticated HTTPS
iframe loading, while unauthenticated requests still return401. Source fixes
cover startup migration, hostname regeneration, first boot and explicit rotation;
tests pass. Exact operator hostname/app, trusted TLS and companion acceptance
remain open. See `docs/https-app-gate-followup-20261006.md`.