- mint_client: a stub mint shows swap() sends the full v2 keyset id when
given a cashuB short id, and leaves complete v1/v2 ids unchanged.
- fips::dial: the single-delivery decisions are now small functions
(fips_answer_is_final, fips_retryable). Tests cover them and, against a
silent local peer, check that a single-delivery request isn't resent
after a timeout while an ordinary one still is.
- content_server: an unreadable paid file returns Unavailable before the
payment gate runs, and a readable one still returns 402. Also covers
ensure_readable's grant/reopen behaviour. The podman grant is replaced
by a refusal under cfg(test) so results don't depend on the host.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
After the keyset-id fix, a Minibits paid download still failed and the
buyer lost the sats. What happened, 2026-09-29, amishparadise:
1. The seller redeemed the token, then failed to read the file. It was a
FileBrowser upload owned by the container subuid (100999) with mode
0640. The handler mapped that Err to 404.
2. The buyer's FIPS dial treats 404 as "fall back to Tor" and resent the
request with the same, now spent, token. The seller answered 402, and
the buyer showed "seller doesn't accept your Cashu mint".
Fixes:
- serve_content checks the file is readable before the paid gate. If it
isn't, it grants read with `podman unshare chmod a+r`, which matches
the other shared files. If that also fails it returns Unavailable (503)
without taking payment.
- The content handler returns 500 on internal errors and logs them,
instead of a silent 404.
- New PeerRequest::single_delivery(), used for the paid download: the
FIPS answer is final, FIPS retries only when it never connected, and
there's no Tor replay once the request may have been delivered.
- The buyer shows the seller's error text for non-402 failures.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>