Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2773532769 | ||
|
|
c86a2436e5 |
@@ -1,31 +0,0 @@
|
|||||||
# Blocking incident: Framework LND startup and false zero balance
|
|
||||||
|
|
||||||
Before starting or resuming work in this repository, read
|
|
||||||
`docs/incident-framework-lnd-startup.md` and check its status.
|
|
||||||
|
|
||||||
The user explicitly required this incident to take priority over later work.
|
|
||||||
While its status is OPEN:
|
|
||||||
|
|
||||||
- Surface this blocker at session start, including when the user asks for unrelated work.
|
|
||||||
- Prioritize investigation and repair on the actual Framework node. If access is
|
|
||||||
unavailable, ask for it and continue useful offline investigation; defer unrelated
|
|
||||||
work unless the user explicitly overrides this priority.
|
|
||||||
- A manual LND restart, a source patch, passing local tests, or publishing an OTA
|
|
||||||
does not resolve the incident. Do not mark it fixed until the Framework's startup,
|
|
||||||
Receive flow, and balance behavior are verified on the node, including a controlled
|
|
||||||
reboot with access and recovery arrangements in place.
|
|
||||||
- Preserve wallet identity, wallet/channel databases, credentials, and backups.
|
|
||||||
Never run wallet wipe/recreation as an automatic investigation or recovery step.
|
|
||||||
- Record evidence, changes, validation, and remaining work in the incident document.
|
|
||||||
|
|
||||||
This priority comes from the user's explicit instruction on 2026-09-15. It remains
|
|
||||||
in effect across sessions until the documented acceptance criteria are met or the
|
|
||||||
user explicitly changes it.
|
|
||||||
|
|
||||||
## Unit tests on a live node
|
|
||||||
|
|
||||||
Run backend unit tests through `scripts/test-backend-isolated.sh`. Do not run
|
|
||||||
unrestricted `cargo test` on a node with installed apps: older mocked-runtime
|
|
||||||
tests still reached real service commands. The runner isolates wallet data,
|
|
||||||
service buses, container storage, networking, and process IDs. Compilation with
|
|
||||||
`cargo test --no-run` is safe. Keep separately authorized live checks explicit.
|
|
||||||
@@ -2,29 +2,6 @@
|
|||||||
|
|
||||||
## Unreleased
|
## Unreleased
|
||||||
|
|
||||||
## v1.8.20-alpha (2026-09-29)
|
|
||||||
|
|
||||||
- Fixed Cashu file payments rejected despite a shared mint, and preserved the payment amount when mint fees reduce change.
|
|
||||||
- Payment failures now report whether a refund actually succeeded; missing files and unsupported payment methods are rejected before charging.
|
|
||||||
- Improved saving paid files into Files and reopening purchases without paying again.
|
|
||||||
- Bitcoin Core and Knots installation offers optional pruning on larger disks, using the same settings as automatic pruning.
|
|
||||||
- Fixed false missing-port checks that unnecessarily restarted Bitcoin and LND; recovery now respects managed shutdown timeouts.
|
|
||||||
- LND explains when it is waiting for Bitcoin installation, startup, or sync, without treating normal synchronization as a restart-worthy failure.
|
|
||||||
- Bitcoin startup messages explain block-index loading without exposing raw RPC errors, and Lightning keeps known balances clearly marked during outages.
|
|
||||||
- Changed the public transaction-explorer default to mempool.space while preserving local explorers and custom choices.
|
|
||||||
|
|
||||||
## v1.8.19-alpha (2026-09-28)
|
|
||||||
|
|
||||||
- Fixed the embedded AIUI chat page painting a second background and dark scrim over Archy’s dashboard background.
|
|
||||||
- Embedded AIUI now stays transparent so the dashboard background appears once.
|
|
||||||
- AIUI background fixes are now included reliably in OTA updates and fresh installations.
|
|
||||||
|
|
||||||
## v1.8.18-alpha (2026-09-18)
|
|
||||||
|
|
||||||
- Framework startup prioritizes Bitcoin and LND before unrelated containers, and unavailable LND balances remain unavailable instead of appearing as false zeroes.
|
|
||||||
- Cashu Receive guides unseeded wallets through recovery-phrase setup, with shorter backup guidance and a single-column layout.
|
|
||||||
- Added live Framework verification for automatic LND unlock, native balance preservation, Cashu address registration, and proof preservation.
|
|
||||||
|
|
||||||
## v1.8.17-alpha (2026-09-15)
|
## v1.8.17-alpha (2026-09-15)
|
||||||
|
|
||||||
- Minibits claims that every mint reports as already spent leave the retry queue, clearing repeated failure notices. Network errors and mixed mint failures remain queued for another attempt.
|
- Minibits claims that every mint reports as already spent leave the retry queue, clearing repeated failure notices. Network errors and mixed mint failures remain queued for another attempt.
|
||||||
|
|||||||
@@ -46,14 +46,13 @@ interface RateBucket {
|
|||||||
|
|
||||||
const rateBuckets = new Map<string, RateBucket>()
|
const rateBuckets = new Map<string, RateBucket>()
|
||||||
|
|
||||||
// Vite imports this module during builds too; cleanup must not keep the
|
// Clean up stale buckets every 5 minutes
|
||||||
// process alive once compilation has finished.
|
|
||||||
setInterval(() => {
|
setInterval(() => {
|
||||||
const now = Date.now()
|
const now = Date.now()
|
||||||
for (const [key, bucket] of rateBuckets) {
|
for (const [key, bucket] of rateBuckets) {
|
||||||
if (now > bucket.resetAt) rateBuckets.delete(key)
|
if (now > bucket.resetAt) rateBuckets.delete(key)
|
||||||
}
|
}
|
||||||
}, 5 * 60_000).unref()
|
}, 5 * 60_000)
|
||||||
|
|
||||||
function getClientIp(req: IncomingMessage): string {
|
function getClientIp(req: IncomingMessage): string {
|
||||||
return req.socket.remoteAddress ?? 'unknown'
|
return req.socket.remoteAddress ?? 'unknown'
|
||||||
|
|||||||
@@ -33,7 +33,6 @@ const PWA_CACHE_VERSION = '2'
|
|||||||
// Only embedded when explicitly requested via ?embedded param
|
// Only embedded when explicitly requested via ?embedded param
|
||||||
const _embeddedFlag = new URLSearchParams(window.location.search).has('embedded')
|
const _embeddedFlag = new URLSearchParams(window.location.search).has('embedded')
|
||||||
;(window as unknown as Record<string, unknown>).__AIUI_EMBEDDED__ = _embeddedFlag
|
;(window as unknown as Record<string, unknown>).__AIUI_EMBEDDED__ = _embeddedFlag
|
||||||
document.documentElement.classList.toggle('aiui-embedded', _embeddedFlag)
|
|
||||||
|
|
||||||
const router = createRouter({
|
const router = createRouter({
|
||||||
history: createWebHistory(import.meta.env.BASE_URL),
|
history: createWebHistory(import.meta.env.BASE_URL),
|
||||||
|
|||||||
@@ -2,13 +2,13 @@
|
|||||||
<div
|
<div
|
||||||
class="h-full flex flex-col relative overflow-hidden transition-colors duration-300"
|
class="h-full flex flex-col relative overflow-hidden transition-colors duration-300"
|
||||||
:class="[]"
|
:class="[]"
|
||||||
:style="isEmbedded
|
:style="isDark
|
||||||
? { background: 'transparent' }
|
? { background: '#000 url(' + bgImageUrl + ') center center / cover no-repeat fixed' }
|
||||||
: isDark
|
: isEmbedded
|
||||||
? { background: '#000 url(' + bgImageUrl + ') center center / cover no-repeat fixed' }
|
? { background: 'transparent' }
|
||||||
: { backgroundColor: '#f5f4f1' }"
|
: { backgroundColor: '#f5f4f1' }"
|
||||||
>
|
>
|
||||||
<div v-if="isDark && !isEmbedded" class="absolute inset-0 pointer-events-none bg-black/20" />
|
<div v-if="isDark" class="absolute inset-0 pointer-events-none bg-black/20" />
|
||||||
|
|
||||||
<!-- Desktop layout -->
|
<!-- Desktop layout -->
|
||||||
<div
|
<div
|
||||||
|
|||||||
@@ -57,8 +57,12 @@ body {
|
|||||||
width: 100%;
|
width: 100%;
|
||||||
height: 100%;
|
height: 100%;
|
||||||
overflow: hidden;
|
overflow: hidden;
|
||||||
/* Standalone canvas fallback. Embedded mode overrides this below so
|
/* Every page paints its own explicit background (bg-[#0a0a0a] / bg-[#faf9f6])
|
||||||
Archy's wallpaper remains visible through the iframe. */
|
EXCEPT the embedded Chat page, which intentionally goes transparent so
|
||||||
|
Archy's own dark chrome can show behind it (Chat.vue's iframe host). With
|
||||||
|
no background-color here, "transparent" fell through to the browser's
|
||||||
|
default white canvas instead. Match the theme's own dark/light default so
|
||||||
|
nothing above this ever needs to guess. */
|
||||||
background-color: #0a0a0a;
|
background-color: #0a0a0a;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -66,19 +70,6 @@ html.light body {
|
|||||||
background-color: #faf9f6;
|
background-color: #faf9f6;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* The host owns the wallpaper when AIUI is embedded. The document canvas
|
|
||||||
must be transparent too, otherwise it hides the host behind ChatPage. */
|
|
||||||
html.aiui-embedded {
|
|
||||||
/* Match Archy's dark canvas scheme. Browsers otherwise give an iframe
|
|
||||||
with a different scheme an opaque canvas despite transparent CSS. */
|
|
||||||
color-scheme: dark;
|
|
||||||
}
|
|
||||||
|
|
||||||
html.aiui-embedded,
|
|
||||||
html.aiui-embedded body {
|
|
||||||
background: transparent;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* ===== DARK MODE GLASSMORPHISM — from Archy ===== */
|
/* ===== DARK MODE GLASSMORPHISM — from Archy ===== */
|
||||||
|
|
||||||
@layer components {
|
@layer components {
|
||||||
|
|||||||
@@ -54,7 +54,7 @@ app:
|
|||||||
if [ -n "$RPC_TXRELAY_AUTH" ]; then
|
if [ -n "$RPC_TXRELAY_AUTH" ]; then
|
||||||
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
|
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
|
||||||
fi;
|
fi;
|
||||||
if [ "${BITCOIN_PRUNE:-0}" = "1" ] || [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
|
if [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
|
||||||
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
||||||
else
|
else
|
||||||
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
||||||
|
|||||||
@@ -60,7 +60,7 @@ app:
|
|||||||
if [ -n "$RPC_TXRELAY_AUTH" ]; then
|
if [ -n "$RPC_TXRELAY_AUTH" ]; then
|
||||||
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
|
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
|
||||||
fi;
|
fi;
|
||||||
if [ "${BITCOIN_PRUNE:-0}" = "1" ] || [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
|
if [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
|
||||||
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=2048 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=2048 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
||||||
else
|
else
|
||||||
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
||||||
|
|||||||
Generated
+1
-1
@@ -104,7 +104,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "archipelago"
|
name = "archipelago"
|
||||||
version = "1.8.20-alpha"
|
version = "1.8.17-alpha"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"archipelago-container",
|
"archipelago-container",
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "archipelago"
|
name = "archipelago"
|
||||||
version = "1.8.20-alpha"
|
version = "1.8.17-alpha"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
license.workspace = true
|
license.workspace = true
|
||||||
description = "Archipelago Bitcoin Node OS - Native backend"
|
description = "Archipelago Bitcoin Node OS - Native backend"
|
||||||
|
|||||||
@@ -138,19 +138,6 @@ impl ApiHandler {
|
|||||||
cors_origin: &str,
|
cors_origin: &str,
|
||||||
) -> Result<Response<hyper::Body>> {
|
) -> Result<Response<hyper::Body>> {
|
||||||
let suffix = path.strip_prefix("/proxy/lnd").unwrap_or("/");
|
let suffix = path.strip_prefix("/proxy/lnd").unwrap_or("/");
|
||||||
if suffix == "/archy-status" {
|
|
||||||
return Ok(Response::builder()
|
|
||||||
.status(StatusCode::OK)
|
|
||||||
.header("Content-Type", "application/json")
|
|
||||||
.header("Cache-Control", "no-store")
|
|
||||||
.header("Access-Control-Allow-Origin", cors_origin)
|
|
||||||
.header("Access-Control-Allow-Credentials", "true")
|
|
||||||
.header("Vary", "Origin")
|
|
||||||
.body(hyper::Body::from(
|
|
||||||
rpc.handle_lnd_readiness().await.to_string(),
|
|
||||||
))?);
|
|
||||||
}
|
|
||||||
|
|
||||||
let url = format!("{LND_REST_BASE_URL}{suffix}");
|
let url = format!("{LND_REST_BASE_URL}{suffix}");
|
||||||
// LND REST serves a self-signed cert and requires the admin macaroon.
|
// LND REST serves a self-signed cert and requires the admin macaroon.
|
||||||
// A bare reqwest::get() uses the default client, which rejects the
|
// A bare reqwest::get() uses the default client, which rejects the
|
||||||
|
|||||||
@@ -22,9 +22,9 @@ const FILE_CATALOG_PROTOCOL: &str = "https://archipelago.dev/protocols/file-cata
|
|||||||
/// Best-effort reclaim of an ecash payment token that was minted but the sale
|
/// Best-effort reclaim of an ecash payment token that was minted but the sale
|
||||||
/// didn't complete (seller unreachable or couldn't redeem it), so the buyer
|
/// didn't complete (seller unreachable or couldn't redeem it), so the buyer
|
||||||
/// doesn't lose the value. For Fedimint the spender can reissue its own
|
/// doesn't lose the value. For Fedimint the spender can reissue its own
|
||||||
/// un-redeemed notes; for Cashu the proofs are received back. Report the actual
|
/// un-redeemed notes; for Cashu the proofs are received back. Fails silently if
|
||||||
/// recovered amount, or explicitly say when a refund could not be confirmed.
|
/// the seller already claimed the token (then the value is genuinely gone).
|
||||||
async fn reclaim_spent_ecash(data_dir: &std::path::Path, token: &str, backend: &str) -> String {
|
async fn reclaim_spent_ecash(data_dir: &std::path::Path, token: &str, backend: &str) {
|
||||||
let res = match backend {
|
let res = match backend {
|
||||||
"fedimint" => crate::wallet::fedimint_client::reissue_into_any(data_dir, token)
|
"fedimint" => crate::wallet::fedimint_client::reissue_into_any(data_dir, token)
|
||||||
.await
|
.await
|
||||||
@@ -32,101 +32,16 @@ async fn reclaim_spent_ecash(data_dir: &std::path::Path, token: &str, backend: &
|
|||||||
_ => ecash::receive_token(data_dir, token).await,
|
_ => ecash::receive_token(data_dir, token).await,
|
||||||
};
|
};
|
||||||
match res {
|
match res {
|
||||||
Ok(sats) => {
|
Ok(sats) => tracing::info!(
|
||||||
tracing::info!("paid download: reclaimed {sats} sats after failed sale");
|
"paid download: reclaimed {sats} sats of unspent {backend} ecash after a failed sale"
|
||||||
format!("Refunded {sats} sats to your wallet.")
|
),
|
||||||
}
|
Err(e) => tracing::warn!(
|
||||||
Err(e) => {
|
"paid download: could not reclaim {backend} ecash (the peer may have already \
|
||||||
tracing::warn!("paid download: refund not confirmed: {e}");
|
claimed it): {e:#}"
|
||||||
"Your refund could not be confirmed. The seller may have received the payment. Do not pay again until this is checked.".to_string()
|
),
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Keep first purchases and cached repeats compatible with both existing clients.
|
|
||||||
fn paid_content_response(bytes: &[u8], mime: &str, paid_sats: u64) -> serde_json::Value {
|
|
||||||
use base64::Engine;
|
|
||||||
let data = base64::engine::general_purpose::STANDARD.encode(bytes);
|
|
||||||
serde_json::json!({
|
|
||||||
"data": data, "data_base64": data,
|
|
||||||
"size": bytes.len(), "size_bytes": bytes.len(),
|
|
||||||
"mime_type": mime, "paid_sats": paid_sats, "owned": true,
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
/// FileBrowser owns its files through a rootless UID mapping. Use its authenticated
|
|
||||||
/// API rather than writing host paths with the backend's unrelated UID. Its
|
|
||||||
/// override=false upload atomically refuses existing names, including races.
|
|
||||||
async fn file_purchase_in_files(
|
|
||||||
client: &reqwest::Client,
|
|
||||||
base_url: &str,
|
|
||||||
token: &str,
|
|
||||||
filename: &str,
|
|
||||||
mime: &str,
|
|
||||||
bytes: &[u8],
|
|
||||||
) -> Result<String> {
|
|
||||||
let folder = if mime.starts_with("image/") || mime.starts_with("video/") {
|
|
||||||
"Photos"
|
|
||||||
} else if mime.starts_with("audio/") {
|
|
||||||
"Music"
|
|
||||||
} else {
|
|
||||||
"Documents"
|
|
||||||
};
|
|
||||||
let mut folder_url = reqwest::Url::parse(base_url)?;
|
|
||||||
folder_url
|
|
||||||
.path_segments_mut()
|
|
||||||
.map_err(|_| anyhow::anyhow!("Invalid Files URL"))?
|
|
||||||
.extend(["api", "resources", folder, ""]);
|
|
||||||
let response = client
|
|
||||||
.get(folder_url.clone())
|
|
||||||
.header("X-Auth", token)
|
|
||||||
.send()
|
|
||||||
.await?;
|
|
||||||
if response.status() == reqwest::StatusCode::NOT_FOUND {
|
|
||||||
let response = client
|
|
||||||
.post(folder_url.clone())
|
|
||||||
.header("X-Auth", token)
|
|
||||||
.send()
|
|
||||||
.await?;
|
|
||||||
if response.status() != reqwest::StatusCode::CONFLICT {
|
|
||||||
response.error_for_status()?;
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
response.error_for_status()?;
|
|
||||||
}
|
|
||||||
let base = std::path::Path::new(filename)
|
|
||||||
.file_name()
|
|
||||||
.and_then(|n| n.to_str())
|
|
||||||
.filter(|n| !n.is_empty())
|
|
||||||
.unwrap_or("download");
|
|
||||||
let (stem, extension) = match base.rsplit_once('.') {
|
|
||||||
Some((stem, ext)) if !stem.is_empty() => (stem, format!(".{ext}")),
|
|
||||||
_ => (base, String::new()),
|
|
||||||
};
|
|
||||||
for attempt in 1..=100 {
|
|
||||||
let name = if attempt == 1 {
|
|
||||||
base.to_string()
|
|
||||||
} else {
|
|
||||||
format!("{stem} ({attempt}){extension}")
|
|
||||||
};
|
|
||||||
let mut url = folder_url.clone();
|
|
||||||
url.path_segments_mut().unwrap().pop_if_empty().push(&name);
|
|
||||||
url.query_pairs_mut().append_pair("override", "false");
|
|
||||||
let response = client
|
|
||||||
.post(url)
|
|
||||||
.header("X-Auth", token)
|
|
||||||
.body(bytes.to_vec())
|
|
||||||
.send()
|
|
||||||
.await?;
|
|
||||||
if response.status() == reqwest::StatusCode::CONFLICT {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
response.error_for_status()?;
|
|
||||||
return Ok(format!("{folder}/{name}"));
|
|
||||||
}
|
|
||||||
anyhow::bail!("Too many existing copies; purchased file remains in the purchase cache")
|
|
||||||
}
|
|
||||||
|
|
||||||
impl RpcHandler {
|
impl RpcHandler {
|
||||||
/// List content I'm sharing.
|
/// List content I'm sharing.
|
||||||
pub(super) async fn handle_content_list_mine(&self) -> Result<serde_json::Value> {
|
pub(super) async fn handle_content_list_mine(&self) -> Result<serde_json::Value> {
|
||||||
@@ -548,10 +463,17 @@ impl RpcHandler {
|
|||||||
crate::content_owned::read_owned(&self.config.data_dir, &o.onion, &o.content_id)
|
crate::content_owned::read_owned(&self.config.data_dir, &o.onion, &o.content_id)
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
let mut result = paid_content_response(&bytes, &mime, 0);
|
use base64::Engine;
|
||||||
result["already_owned"] = serde_json::json!(true);
|
return Ok(serde_json::json!({
|
||||||
result["filename"] = serde_json::json!(o.filename);
|
"owned": true,
|
||||||
return Ok(result);
|
"already_owned": true,
|
||||||
|
"filename": o.filename,
|
||||||
|
"mime_type": mime,
|
||||||
|
"size_bytes": bytes.len(),
|
||||||
|
"paid_sats": 0,
|
||||||
|
"data_base64":
|
||||||
|
base64::engine::general_purpose::STANDARD.encode(&bytes),
|
||||||
|
}));
|
||||||
}
|
}
|
||||||
// Cache record exists but bytes are gone — fall through and
|
// Cache record exists but bytes are gone — fall through and
|
||||||
// repurchase rather than stranding the user.
|
// repurchase rather than stranding the user.
|
||||||
@@ -625,27 +547,29 @@ impl RpcHandler {
|
|||||||
// Surface a real reason instead of the generic sanitized error (#30):
|
// Surface a real reason instead of the generic sanitized error (#30):
|
||||||
// the dial already tries FIPS/mesh then falls back to Tor, so a failure
|
// the dial already tries FIPS/mesh then falls back to Tor, so a failure
|
||||||
// here means the peer is genuinely unreachable on both transports.
|
// here means the peer is genuinely unreachable on both transports.
|
||||||
let (response, transport) =
|
let (response, transport) = match crate::fips::dial::PeerRequest::new(
|
||||||
match crate::fips::dial::PeerRequest::new(fips_npub.as_deref(), onion, &path)
|
fips_npub.as_deref(),
|
||||||
.service(crate::settings::transport::PeerService::PeerFiles)
|
onion,
|
||||||
.header("X-Federation-DID", local_did)
|
&path,
|
||||||
.header("X-Payment-Token", token_str.clone())
|
)
|
||||||
.timeout(std::time::Duration::from_secs(900))
|
.service(crate::settings::transport::PeerService::PeerFiles)
|
||||||
.send_get()
|
.header("X-Federation-DID", local_did)
|
||||||
.await
|
.header("X-Payment-Token", token_str.clone())
|
||||||
{
|
.timeout(std::time::Duration::from_secs(900))
|
||||||
Ok(v) => v,
|
.send_get()
|
||||||
Err(e) => {
|
.await
|
||||||
tracing::warn!("paid peer download dial failed for {}: {:#}", onion, e);
|
{
|
||||||
// The token was already minted/spent — reclaim it so the buyer
|
Ok(v) => v,
|
||||||
// doesn't lose the value when the seller was simply unreachable.
|
Err(e) => {
|
||||||
let refund =
|
tracing::warn!("paid peer download dial failed for {}: {:#}", onion, e);
|
||||||
reclaim_spent_ecash(&self.config.data_dir, &token_str, used_backend).await;
|
// The token was already minted/spent — reclaim it so the buyer
|
||||||
return Ok(serde_json::json!({
|
// doesn't lose the value when the seller was simply unreachable.
|
||||||
"error": format!("Could not reach the peer over mesh or Tor. {refund}")
|
reclaim_spent_ecash(&self.config.data_dir, &token_str, used_backend).await;
|
||||||
}));
|
return Ok(serde_json::json!({
|
||||||
}
|
"error": "Could not reach the peer over mesh or Tor — it may be offline. Your ecash was refunded to your wallet. Please try again."
|
||||||
};
|
}));
|
||||||
|
}
|
||||||
|
};
|
||||||
// Record which transport actually reached the peer (B14).
|
// Record which transport actually reached the peer (B14).
|
||||||
if let Err(e) = crate::federation::record_peer_transport(
|
if let Err(e) = crate::federation::record_peer_transport(
|
||||||
&self.config.data_dir,
|
&self.config.data_dir,
|
||||||
@@ -659,17 +583,25 @@ impl RpcHandler {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if response.status() == reqwest::StatusCode::PAYMENT_REQUIRED {
|
if response.status() == reqwest::StatusCode::PAYMENT_REQUIRED {
|
||||||
// A 402 can mean mint validation, network failure, underpayment,
|
// Payment was rejected by the seller. Surface the most likely cause
|
||||||
// or an unaccepted mint. Do not invent a mint-mismatch diagnosis.
|
// per backend — for ecash both sides must share a redemption network
|
||||||
|
// (a Cashu mint, or a Fedimint federation).
|
||||||
let body = response.text().await.unwrap_or_default();
|
let body = response.text().await.unwrap_or_default();
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
"paid download: seller {onion} rejected {used_backend} payment of {price_sats} sats: {body}"
|
"paid download: seller {onion} rejected {used_backend} payment of {price_sats} sats: {body}"
|
||||||
);
|
);
|
||||||
// Seller couldn't redeem the token — reclaim it so the buyer keeps
|
// Seller couldn't redeem the token — reclaim it so the buyer keeps
|
||||||
// their funds (the spent-but-unredeemed-notes case the user hit).
|
// their funds (the spent-but-unredeemed-notes case the user hit).
|
||||||
let refund = reclaim_spent_ecash(&self.config.data_dir, &token_str, used_backend).await;
|
reclaim_spent_ecash(&self.config.data_dir, &token_str, used_backend).await;
|
||||||
|
let hint = match used_backend {
|
||||||
|
"fedimint" => "the seller isn't in the same Fedimint federation as you",
|
||||||
|
_ => "the seller doesn't accept your Cashu mint",
|
||||||
|
};
|
||||||
return Ok(serde_json::json!({
|
return Ok(serde_json::json!({
|
||||||
"error": format!("The seller could not verify the payment. {refund}")
|
"error": format!(
|
||||||
|
"Payment rejected by the seller — {hint}. Your ecash was refunded to \
|
||||||
|
your wallet. Try the other ecash type, or use a shared mint/federation."
|
||||||
|
)
|
||||||
}));
|
}));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -677,9 +609,9 @@ impl RpcHandler {
|
|||||||
let status = response.status();
|
let status = response.status();
|
||||||
let body = response.text().await.unwrap_or_default();
|
let body = response.text().await.unwrap_or_default();
|
||||||
tracing::warn!("paid download: seller {onion} returned {status}: {body}");
|
tracing::warn!("paid download: seller {onion} returned {status}: {body}");
|
||||||
let refund = reclaim_spent_ecash(&self.config.data_dir, &token_str, used_backend).await;
|
reclaim_spent_ecash(&self.config.data_dir, &token_str, used_backend).await;
|
||||||
return Ok(serde_json::json!({
|
return Ok(serde_json::json!({
|
||||||
"error": format!("Peer returned an error ({status}). {refund}")
|
"error": format!("Peer returned an error ({status}). Your ecash was refunded to your wallet.")
|
||||||
}));
|
}));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -726,41 +658,63 @@ impl RpcHandler {
|
|||||||
tracing::warn!("paid download: failed to cache purchased content (non-fatal): {e:#}");
|
tracing::warn!("paid download: failed to cache purchased content (non-fatal): {e:#}");
|
||||||
}
|
}
|
||||||
|
|
||||||
// The durable purchased-content cache above is primary. A Files copy
|
// Auto-file the purchase into the user's Files area (2026-07-22):
|
||||||
// remains optional: a stopped FileBrowser must not undo a paid download.
|
// Photos for images/video, Music for audio, Documents otherwise —
|
||||||
let filed = async {
|
// same buckets the Cloud view uses. The in-app viewer still plays
|
||||||
let auth = self.handle_filebrowser_token().await?;
|
// from the purchase cache; this makes the file ALSO show up where
|
||||||
let token = auth
|
// files live, on every device, without relying on a browser
|
||||||
.get("token")
|
// download. Best-effort: never fail a paid download over it.
|
||||||
.and_then(|v| v.as_str())
|
{
|
||||||
.context("FileBrowser omitted its authentication token")?;
|
let folder = if mime_type.starts_with("image/") || mime_type.starts_with("video/") {
|
||||||
let client = reqwest::Client::builder()
|
"Photos"
|
||||||
.no_proxy()
|
} else if mime_type.starts_with("audio/") {
|
||||||
.redirect(reqwest::redirect::Policy::none())
|
"Music"
|
||||||
.timeout(std::time::Duration::from_secs(30))
|
} else {
|
||||||
.build()?;
|
"Documents"
|
||||||
file_purchase_in_files(
|
};
|
||||||
&client,
|
let base = std::path::Path::new(&filename)
|
||||||
"http://127.0.0.1:8083",
|
.file_name()
|
||||||
token,
|
.and_then(|n| n.to_str())
|
||||||
&filename,
|
.unwrap_or("download")
|
||||||
&mime_type,
|
.to_string();
|
||||||
&bytes,
|
let dir = self.config.data_dir.join("filebrowser").join(folder);
|
||||||
)
|
if let Err(e) = tokio::fs::create_dir_all(&dir).await {
|
||||||
.await
|
tracing::warn!("paid download: cannot create {}: {e}", dir.display());
|
||||||
}
|
} else {
|
||||||
.await;
|
// Don't clobber an existing file of the same name: "x.jpg"
|
||||||
match filed {
|
// → "x (2).jpg" etc.
|
||||||
Ok(path) => tracing::info!("paid download: filed into Files/{path}"),
|
let mut target = dir.join(&base);
|
||||||
Err(error) => tracing::warn!(
|
let (stem, ext) = match base.rsplit_once('.') {
|
||||||
"paid download: optional Files copy failed; purchase cache retained: {error}"
|
Some((s, e)) if !s.is_empty() => (s.to_string(), format!(".{e}")),
|
||||||
),
|
_ => (base.clone(), String::new()),
|
||||||
|
};
|
||||||
|
let mut n = 2;
|
||||||
|
while target.exists() {
|
||||||
|
target = dir.join(format!("{stem} ({n}){ext}"));
|
||||||
|
n += 1;
|
||||||
|
}
|
||||||
|
match tokio::fs::write(&target, &bytes).await {
|
||||||
|
Ok(()) => tracing::info!("paid download: filed into {}", target.display()),
|
||||||
|
Err(e) => tracing::warn!(
|
||||||
|
"paid download: filing into {} failed (non-fatal): {e}",
|
||||||
|
target.display()
|
||||||
|
),
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
use base64::Engine;
|
||||||
|
let encoded = base64::engine::general_purpose::STANDARD.encode(&bytes);
|
||||||
|
|
||||||
tracing::info!("paid download: received {} bytes from {onion} (paid {price_sats} sats via {used_backend})", bytes.len());
|
tracing::info!("paid download: received {} bytes from {onion} (paid {price_sats} sats via {used_backend})", bytes.len());
|
||||||
let mut result = paid_content_response(&bytes, &mime_type, price_sats);
|
Ok(serde_json::json!({
|
||||||
result["ecash_backend"] = serde_json::json!(used_backend);
|
"data": encoded,
|
||||||
Ok(result)
|
"size": bytes.len(),
|
||||||
|
"paid_sats": price_sats,
|
||||||
|
"ecash_backend": used_backend,
|
||||||
|
"mime_type": mime_type,
|
||||||
|
"owned": true,
|
||||||
|
}))
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Buyer side (#46): ask the selling node to mint a Lightning invoice for a
|
/// Buyer side (#46): ask the selling node to mint a Lightning invoice for a
|
||||||
@@ -1433,7 +1387,3 @@ impl RpcHandler {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
#[path = "content_tests.rs"]
|
|
||||||
mod tests;
|
|
||||||
|
|||||||
@@ -1,164 +0,0 @@
|
|||||||
use super::*;
|
|
||||||
use hyper::{
|
|
||||||
service::{make_service_fn, service_fn},
|
|
||||||
Body, Response, Server,
|
|
||||||
};
|
|
||||||
use std::{
|
|
||||||
collections::VecDeque,
|
|
||||||
convert::Infallible,
|
|
||||||
sync::{Arc, Mutex},
|
|
||||||
};
|
|
||||||
|
|
||||||
struct FilesApi {
|
|
||||||
url: String,
|
|
||||||
seen: Arc<Mutex<Vec<(String, String, Vec<u8>)>>>,
|
|
||||||
task: tokio::task::JoinHandle<()>,
|
|
||||||
}
|
|
||||||
impl Drop for FilesApi {
|
|
||||||
fn drop(&mut self) {
|
|
||||||
self.task.abort();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
fn files_api(statuses: Vec<u16>) -> FilesApi {
|
|
||||||
let statuses = Arc::new(Mutex::new(VecDeque::from(statuses)));
|
|
||||||
let seen = Arc::new(Mutex::new(Vec::new()));
|
|
||||||
let history = seen.clone();
|
|
||||||
let server = Server::bind(&([127, 0, 0, 1], 0).into());
|
|
||||||
let address = server.local_addr();
|
|
||||||
let service = make_service_fn(move |_| {
|
|
||||||
let statuses = statuses.clone();
|
|
||||||
let seen = history.clone();
|
|
||||||
async move {
|
|
||||||
Ok::<_, Infallible>(service_fn(move |request: hyper::Request<Body>| {
|
|
||||||
let statuses = statuses.clone();
|
|
||||||
let seen = seen.clone();
|
|
||||||
async move {
|
|
||||||
assert_eq!(request.headers().get("X-Auth").unwrap(), "test-session");
|
|
||||||
let method = request.method().to_string();
|
|
||||||
let uri = request.uri().to_string();
|
|
||||||
let body = hyper::body::to_bytes(request.into_body())
|
|
||||||
.await
|
|
||||||
.unwrap()
|
|
||||||
.to_vec();
|
|
||||||
seen.lock().unwrap().push((method, uri, body));
|
|
||||||
let status = statuses
|
|
||||||
.lock()
|
|
||||||
.unwrap()
|
|
||||||
.pop_front()
|
|
||||||
.expect("unexpected extra Files request");
|
|
||||||
Ok::<_, Infallible>(
|
|
||||||
Response::builder()
|
|
||||||
.status(status)
|
|
||||||
.body(Body::empty())
|
|
||||||
.unwrap(),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
}
|
|
||||||
});
|
|
||||||
FilesApi {
|
|
||||||
url: format!("http://{address}"),
|
|
||||||
seen,
|
|
||||||
task: tokio::spawn(async move {
|
|
||||||
server.serve(service).await.unwrap();
|
|
||||||
}),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn first_and_cached_paid_downloads_have_the_same_client_payload_contract() {
|
|
||||||
use base64::Engine;
|
|
||||||
for paid in [0, 1] {
|
|
||||||
let response = paid_content_response(&[0, 255, 123], "application/octet-stream", paid);
|
|
||||||
assert_eq!(response["data"], response["data_base64"]);
|
|
||||||
assert_eq!(
|
|
||||||
base64::engine::general_purpose::STANDARD
|
|
||||||
.decode(response["data"].as_str().unwrap())
|
|
||||||
.unwrap(),
|
|
||||||
[0, 255, 123]
|
|
||||||
);
|
|
||||||
assert_eq!(response["size"], 3);
|
|
||||||
assert_eq!(response["size_bytes"], 3);
|
|
||||||
assert_eq!(response["paid_sats"], paid);
|
|
||||||
assert_eq!(response["owned"], true);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn files_copy_uses_authenticated_api_and_preserves_existing_names() {
|
|
||||||
let api = files_api(vec![200, 409, 200]);
|
|
||||||
let client = reqwest::Client::new();
|
|
||||||
let path = file_purchase_in_files(
|
|
||||||
&client,
|
|
||||||
&api.url,
|
|
||||||
"test-session",
|
|
||||||
"../my #file?.txt",
|
|
||||||
"text/plain",
|
|
||||||
b"paid bytes",
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
assert_eq!(path, "Documents/my #file? (2).txt");
|
|
||||||
let seen = api.seen.lock().unwrap();
|
|
||||||
assert_eq!(seen[0].0, "GET");
|
|
||||||
assert_eq!(seen[0].1, "/api/resources/Documents/");
|
|
||||||
assert_eq!(seen.len(), 3);
|
|
||||||
for (_, uri, body) in &seen[1..] {
|
|
||||||
assert!(uri.contains("override=false"));
|
|
||||||
assert!(uri.contains("%23file%3F"));
|
|
||||||
assert!(!uri.contains("../"));
|
|
||||||
assert_eq!(body, b"paid bytes");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn files_copy_creates_missing_media_folder() {
|
|
||||||
for (mime, folder) in [
|
|
||||||
("image/png", "Photos"),
|
|
||||||
("video/mp4", "Photos"),
|
|
||||||
("audio/ogg", "Music"),
|
|
||||||
] {
|
|
||||||
let api = files_api(vec![404, 200, 200]);
|
|
||||||
let path = file_purchase_in_files(
|
|
||||||
&reqwest::Client::new(),
|
|
||||||
&api.url,
|
|
||||||
"test-session",
|
|
||||||
"file",
|
|
||||||
mime,
|
|
||||||
b"bytes",
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
assert_eq!(path, format!("{folder}/file"));
|
|
||||||
let seen = api.seen.lock().unwrap();
|
|
||||||
assert_eq!(seen[1].0, "POST");
|
|
||||||
assert!(seen[1].1.ends_with('/'));
|
|
||||||
assert!(seen[1].2.is_empty());
|
|
||||||
assert_eq!(seen[2].2, b"bytes");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn files_copy_fails_without_overwriting_or_claiming_success_on_errors() {
|
|
||||||
for statuses in [
|
|
||||||
vec![401],
|
|
||||||
vec![503],
|
|
||||||
vec![404, 500],
|
|
||||||
vec![200, 507],
|
|
||||||
vec![200, 403],
|
|
||||||
] {
|
|
||||||
let expected = statuses.len();
|
|
||||||
let api = files_api(statuses);
|
|
||||||
assert!(file_purchase_in_files(
|
|
||||||
&reqwest::Client::new(),
|
|
||||||
&api.url,
|
|
||||||
"test-session",
|
|
||||||
"file.txt",
|
|
||||||
"text/plain",
|
|
||||||
b"bytes"
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
assert_eq!(api.seen.lock().unwrap().len(), expected);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -73,86 +73,7 @@ struct LndChannelBalanceResponse {
|
|||||||
pending_open_local_balance: Option<LndAmount>,
|
pending_open_local_balance: Option<LndAmount>,
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Reject unavailable LND data before it can be decoded as an empty, zero wallet.
|
|
||||||
async fn get_lnd_json<T: serde::de::DeserializeOwned>(
|
|
||||||
client: &reqwest::Client,
|
|
||||||
url: &str,
|
|
||||||
macaroon_hex: &str,
|
|
||||||
) -> Result<T> {
|
|
||||||
client
|
|
||||||
.get(url)
|
|
||||||
.header("Grpc-Metadata-macaroon", macaroon_hex)
|
|
||||||
.send()
|
|
||||||
.await
|
|
||||||
.context("LND is unavailable; balance could not be checked")?
|
|
||||||
.error_for_status()
|
|
||||||
.context("LND is not ready; balance could not be checked")?
|
|
||||||
.json()
|
|
||||||
.await
|
|
||||||
.context("LND returned invalid wallet data")
|
|
||||||
}
|
|
||||||
|
|
||||||
fn checked_balances(
|
|
||||||
wallet: LndBalanceResponse,
|
|
||||||
channels: LndChannelBalanceResponse,
|
|
||||||
) -> Result<(i64, i64, i64)> {
|
|
||||||
fn sats(value: Option<String>) -> Result<i64> {
|
|
||||||
let value = value.context("LND omitted a balance; balance is unavailable")?;
|
|
||||||
let amount: i64 = value.parse().context("LND returned an invalid balance")?;
|
|
||||||
anyhow::ensure!(amount >= 0, "LND returned a negative balance");
|
|
||||||
Ok(amount)
|
|
||||||
}
|
|
||||||
Ok((
|
|
||||||
sats(wallet.total_balance)?,
|
|
||||||
sats(channels.local_balance.and_then(|a| a.sat))?,
|
|
||||||
sats(channels.pending_open_local_balance.and_then(|a| a.sat))?,
|
|
||||||
))
|
|
||||||
}
|
|
||||||
|
|
||||||
fn bitcoin_wait_state(
|
|
||||||
installed: bool,
|
|
||||||
running: bool,
|
|
||||||
fresh: bool,
|
|
||||||
ibd: Option<bool>,
|
|
||||||
) -> (&'static str, &'static str) {
|
|
||||||
if !installed {
|
|
||||||
("waiting_install", "Waiting for Bitcoin to be installed")
|
|
||||||
} else if !running {
|
|
||||||
("waiting_start", "Waiting for Bitcoin to start")
|
|
||||||
} else if !fresh || ibd.is_none() {
|
|
||||||
("waiting_start", "Waiting for Bitcoin to start")
|
|
||||||
} else if ibd == Some(true) {
|
|
||||||
("waiting_sync", "Waiting for Bitcoin to sync")
|
|
||||||
} else {
|
|
||||||
("bitcoin_ready", "Bitcoin is ready")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl RpcHandler {
|
impl RpcHandler {
|
||||||
pub(crate) async fn handle_lnd_readiness(&self) -> serde_json::Value {
|
|
||||||
let (data, _) = self.state_manager.get_snapshot().await;
|
|
||||||
if !data.server_info.status_info.containers_scanned {
|
|
||||||
return serde_json::json!({"state":"checking", "message":"Checking Bitcoin availability"});
|
|
||||||
}
|
|
||||||
let nodes: Vec<_> = ["bitcoin-core", "bitcoin-knots", "bitcoin"]
|
|
||||||
.iter()
|
|
||||||
.filter_map(|id| data.package_data.get(*id))
|
|
||||||
.collect();
|
|
||||||
let installed = !nodes.is_empty();
|
|
||||||
let running = nodes
|
|
||||||
.iter()
|
|
||||||
.any(|p| p.state == crate::data_model::PackageState::Running);
|
|
||||||
let bitcoin = crate::bitcoin_status::get_bitcoin_status().await;
|
|
||||||
let ibd = bitcoin
|
|
||||||
.blockchain_info
|
|
||||||
.as_ref()
|
|
||||||
.and_then(|v| v.get("initialblockdownload"))
|
|
||||||
.and_then(|v| v.as_bool());
|
|
||||||
let (state, message) =
|
|
||||||
bitcoin_wait_state(installed, running, bitcoin.ok && !bitcoin.stale, ibd);
|
|
||||||
serde_json::json!({"state": state, "message": message})
|
|
||||||
}
|
|
||||||
|
|
||||||
pub(in crate::api::rpc) async fn handle_lnd_getinfo(&self) -> Result<serde_json::Value> {
|
pub(in crate::api::rpc) async fn handle_lnd_getinfo(&self) -> Result<serde_json::Value> {
|
||||||
let macaroon_bytes = read_lnd_admin_macaroon().await?;
|
let macaroon_bytes = read_lnd_admin_macaroon().await?;
|
||||||
let macaroon_hex = hex::encode(&macaroon_bytes);
|
let macaroon_hex = hex::encode(&macaroon_bytes);
|
||||||
@@ -164,26 +85,45 @@ impl RpcHandler {
|
|||||||
.build()
|
.build()
|
||||||
.context("Failed to create HTTP client")?;
|
.context("Failed to create HTTP client")?;
|
||||||
|
|
||||||
let get_info: LndGetInfoResponse = get_lnd_json(
|
let get_info: LndGetInfoResponse = client
|
||||||
&client,
|
.get(format!("{LND_REST_BASE_URL}/v1/getinfo"))
|
||||||
&format!("{LND_REST_BASE_URL}/v1/getinfo"),
|
.header("Grpc-Metadata-macaroon", &macaroon_hex)
|
||||||
&macaroon_hex,
|
.send()
|
||||||
)
|
.await
|
||||||
.await?;
|
.context("LND REST connection failed")?
|
||||||
let channel_balance: LndChannelBalanceResponse = get_lnd_json(
|
.json()
|
||||||
&client,
|
.await
|
||||||
&format!("{LND_REST_BASE_URL}/v1/balance/channels"),
|
.context("Failed to parse LND getinfo response")?;
|
||||||
&macaroon_hex,
|
|
||||||
)
|
let channel_balance: LndChannelBalanceResponse = match client
|
||||||
.await?;
|
.get(format!("{LND_REST_BASE_URL}/v1/balance/channels"))
|
||||||
let wallet_balance: LndBalanceResponse = get_lnd_json(
|
.header("Grpc-Metadata-macaroon", &macaroon_hex)
|
||||||
&client,
|
.send()
|
||||||
&format!("{LND_REST_BASE_URL}/v1/balance/blockchain"),
|
.await
|
||||||
&macaroon_hex,
|
{
|
||||||
)
|
Ok(resp) => resp.json().await.unwrap_or(LndChannelBalanceResponse {
|
||||||
.await?;
|
local_balance: None,
|
||||||
let (balance_sats, channel_balance_sats, pending_open_balance) =
|
pending_open_local_balance: None,
|
||||||
checked_balances(wallet_balance, channel_balance)?;
|
}),
|
||||||
|
Err(_) => LndChannelBalanceResponse {
|
||||||
|
local_balance: None,
|
||||||
|
pending_open_local_balance: None,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
let wallet_balance: LndBalanceResponse = match client
|
||||||
|
.get(format!("{LND_REST_BASE_URL}/v1/balance/blockchain"))
|
||||||
|
.header("Grpc-Metadata-macaroon", &macaroon_hex)
|
||||||
|
.send()
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
Ok(resp) => resp.json().await.unwrap_or(LndBalanceResponse {
|
||||||
|
total_balance: None,
|
||||||
|
}),
|
||||||
|
Err(_) => LndBalanceResponse {
|
||||||
|
total_balance: None,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
let (identity_pubkey, uris) = map_identity(&get_info);
|
let (identity_pubkey, uris) = map_identity(&get_info);
|
||||||
|
|
||||||
@@ -195,9 +135,18 @@ impl RpcHandler {
|
|||||||
num_peers: get_info.num_peers.unwrap_or(0),
|
num_peers: get_info.num_peers.unwrap_or(0),
|
||||||
synced_to_chain: get_info.synced_to_chain.unwrap_or(false),
|
synced_to_chain: get_info.synced_to_chain.unwrap_or(false),
|
||||||
block_height: get_info.block_height.unwrap_or(0),
|
block_height: get_info.block_height.unwrap_or(0),
|
||||||
balance_sats,
|
balance_sats: wallet_balance
|
||||||
channel_balance_sats,
|
.total_balance
|
||||||
pending_open_balance,
|
.and_then(|s| s.parse().ok())
|
||||||
|
.unwrap_or(0),
|
||||||
|
channel_balance_sats: channel_balance
|
||||||
|
.local_balance
|
||||||
|
.and_then(|a| a.sat.and_then(|s| s.parse().ok()))
|
||||||
|
.unwrap_or(0),
|
||||||
|
pending_open_balance: channel_balance
|
||||||
|
.pending_open_local_balance
|
||||||
|
.and_then(|a| a.sat.and_then(|s| s.parse().ok()))
|
||||||
|
.unwrap_or(0),
|
||||||
};
|
};
|
||||||
|
|
||||||
Ok(serde_json::to_value(info)?)
|
Ok(serde_json::to_value(info)?)
|
||||||
@@ -319,76 +268,6 @@ impl RpcHandler {
|
|||||||
mod tests {
|
mod tests {
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn unavailable_balances_are_not_zero() {
|
|
||||||
for body in [r#"{}"#, r#"{"code":14,"message":"wallet locked"}"#] {
|
|
||||||
assert!(checked_balances(
|
|
||||||
serde_json::from_str(body).unwrap(),
|
|
||||||
serde_json::from_str(body).unwrap(),
|
|
||||||
)
|
|
||||||
.is_err());
|
|
||||||
}
|
|
||||||
for value in ["bad", "-1", "9223372036854775808"] {
|
|
||||||
let wallet = LndBalanceResponse {
|
|
||||||
total_balance: Some(value.into()),
|
|
||||||
};
|
|
||||||
let channels = serde_json::from_str(
|
|
||||||
r#"{"local_balance":{"sat":"5"},"pending_open_local_balance":{"sat":"0"}}"#,
|
|
||||||
)
|
|
||||||
.unwrap();
|
|
||||||
assert!(checked_balances(wallet, channels).is_err());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn verified_zero_and_nonzero_balances_survive() {
|
|
||||||
for expected in [0, 42] {
|
|
||||||
let wallet = LndBalanceResponse {
|
|
||||||
total_balance: Some(expected.to_string()),
|
|
||||||
};
|
|
||||||
let channels = serde_json::from_value(serde_json::json!({
|
|
||||||
"local_balance":{"sat":expected.to_string()},
|
|
||||||
"pending_open_local_balance":{"sat":"0"}
|
|
||||||
}))
|
|
||||||
.unwrap();
|
|
||||||
assert_eq!(
|
|
||||||
checked_balances(wallet, channels).unwrap(),
|
|
||||||
(expected, expected, 0)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn locked_wallet_http_response_is_not_successful_getinfo() {
|
|
||||||
use tokio::io::{AsyncReadExt, AsyncWriteExt};
|
|
||||||
let listener = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
|
|
||||||
let addr = listener.local_addr().unwrap();
|
|
||||||
let server = tokio::spawn(async move {
|
|
||||||
let (mut stream, _) = listener.accept().await.unwrap();
|
|
||||||
let mut buf = [0; 2048];
|
|
||||||
stream.read(&mut buf).await.unwrap();
|
|
||||||
let body =
|
|
||||||
r#"{"code":9,"message":"wallet locked, unlock it to enable full RPC access"}"#;
|
|
||||||
stream.write_all(format!(
|
|
||||||
"HTTP/1.1 503 Service Unavailable\r\nContent-Type: application/json\r\nContent-Length: {}\r\nConnection: close\r\n\r\n{}",
|
|
||||||
body.len(), body
|
|
||||||
).as_bytes()).await.unwrap();
|
|
||||||
});
|
|
||||||
let client = reqwest::Client::builder()
|
|
||||||
.no_proxy()
|
|
||||||
.timeout(std::time::Duration::from_secs(2))
|
|
||||||
.build()
|
|
||||||
.unwrap();
|
|
||||||
assert!(get_lnd_json::<LndGetInfoResponse>(
|
|
||||||
&client,
|
|
||||||
&format!("http://{addr}/v1/getinfo"),
|
|
||||||
"test"
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
server.await.unwrap();
|
|
||||||
}
|
|
||||||
|
|
||||||
/// A real compressed secp256k1 pubkey shape: 66 hex characters.
|
/// A real compressed secp256k1 pubkey shape: 66 hex characters.
|
||||||
const GOOD_PUBKEY: &str = "03a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90";
|
const GOOD_PUBKEY: &str = "03a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90";
|
||||||
|
|
||||||
@@ -462,44 +341,3 @@ mod tests {
|
|||||||
assert!(!is_valid_identity_pubkey(&"g".repeat(66)));
|
assert!(!is_valid_identity_pubkey(&"g".repeat(66)));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod dependency_readiness_tests {
|
|
||||||
use super::bitcoin_wait_state;
|
|
||||||
#[test]
|
|
||||||
fn waiting_states_cover_install_start_sync_outage_and_recovery() {
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(false, false, false, None).0,
|
|
||||||
"waiting_install"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, false, false, None).0,
|
|
||||||
"waiting_start"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, true, false, None).0,
|
|
||||||
"waiting_start"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, true, true, Some(true)).0,
|
|
||||||
"waiting_sync"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, true, true, Some(false)).0,
|
|
||||||
"bitcoin_ready"
|
|
||||||
);
|
|
||||||
// Previously synced cached information must not hide a current outage.
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, true, false, Some(false)).0,
|
|
||||||
"waiting_start"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, true, true, None).0,
|
|
||||||
"waiting_start"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
bitcoin_wait_state(true, true, true, Some(false)).0,
|
|
||||||
"bitcoin_ready"
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -133,36 +133,12 @@ async fn stream_lnd_transactions(sm: &crate::state::StateManager) -> Result<()>
|
|||||||
/// RPC-unreachable and locked-wallet states are deliberately NOT handled
|
/// RPC-unreachable and locked-wallet states are deliberately NOT handled
|
||||||
/// here — container-down is crash-recovery's job, and unlocking needs the
|
/// here — container-down is crash-recovery's job, and unlocking needs the
|
||||||
/// operator.
|
/// operator.
|
||||||
fn bitcoin_ready_for_lnd_watchdog(status: &crate::bitcoin_status::BitcoinNodeStatus) -> bool {
|
|
||||||
status.ok
|
|
||||||
&& !status.stale
|
|
||||||
&& status.age_ms < 30_000
|
|
||||||
&& status
|
|
||||||
.blockchain_info
|
|
||||||
.as_ref()
|
|
||||||
.and_then(|v| v.get("initialblockdownload"))
|
|
||||||
.and_then(|v| v.as_bool())
|
|
||||||
== Some(false)
|
|
||||||
}
|
|
||||||
|
|
||||||
pub(crate) fn spawn_lnd_health_watchdog() {
|
pub(crate) fn spawn_lnd_health_watchdog() {
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
let mut bad_minutes: u32 = 0;
|
let mut bad_minutes: u32 = 0;
|
||||||
let mut last_restart: Option<tokio::time::Instant> = None;
|
let mut last_restart: Option<tokio::time::Instant> = None;
|
||||||
let mut last_height: Option<u64> = None;
|
|
||||||
loop {
|
loop {
|
||||||
tokio::time::sleep(std::time::Duration::from_secs(60)).await;
|
tokio::time::sleep(std::time::Duration::from_secs(60)).await;
|
||||||
// Initial Bitcoin sync, warmup, and outages are dependencies to
|
|
||||||
// wait for, never evidence that LND is wedged. Do not accumulate
|
|
||||||
// restart pressure during a days-long initial block download.
|
|
||||||
let bitcoin = crate::bitcoin_status::get_bitcoin_status().await;
|
|
||||||
if !bitcoin_ready_for_lnd_watchdog(&bitcoin)
|
|
||||||
|| crate::app_ops::lifecycle_op_in_flight("lnd")
|
|
||||||
{
|
|
||||||
bad_minutes = 0;
|
|
||||||
last_height = None;
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
let Ok(bytes) = read_lnd_admin_macaroon().await else {
|
let Ok(bytes) = read_lnd_admin_macaroon().await else {
|
||||||
bad_minutes = 0; // no LND on this node (or not set up yet)
|
bad_minutes = 0; // no LND on this node (or not set up yet)
|
||||||
continue;
|
continue;
|
||||||
@@ -185,10 +161,6 @@ pub(crate) fn spawn_lnd_health_watchdog() {
|
|||||||
bad_minutes = 0; // down/locked — not the wedge signature
|
bad_minutes = 0; // down/locked — not the wedge signature
|
||||||
continue;
|
continue;
|
||||||
};
|
};
|
||||||
if !resp.status().is_success() {
|
|
||||||
bad_minutes = 0;
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
let Ok(info) = resp.json::<serde_json::Value>().await else {
|
let Ok(info) = resp.json::<serde_json::Value>().await else {
|
||||||
bad_minutes = 0;
|
bad_minutes = 0;
|
||||||
continue;
|
continue;
|
||||||
@@ -210,12 +182,7 @@ pub(crate) fn spawn_lnd_health_watchdog() {
|
|||||||
.get("num_pending_channels")
|
.get("num_pending_channels")
|
||||||
.and_then(|v| v.as_u64())
|
.and_then(|v| v.as_u64())
|
||||||
.unwrap_or(0);
|
.unwrap_or(0);
|
||||||
let height = info.get("block_height").and_then(|v| v.as_u64());
|
let wedged = !synced || (channels > 0 && peers == 0);
|
||||||
let progressing = height
|
|
||||||
.zip(last_height)
|
|
||||||
.is_some_and(|(now, before)| now > before);
|
|
||||||
last_height = height;
|
|
||||||
let wedged = !progressing && (!synced || (channels > 0 && peers == 0));
|
|
||||||
if !wedged {
|
if !wedged {
|
||||||
bad_minutes = 0;
|
bad_minutes = 0;
|
||||||
continue;
|
continue;
|
||||||
@@ -272,31 +239,3 @@ impl RpcHandler {
|
|||||||
Ok((client, macaroon_hex))
|
Ok((client, macaroon_hex))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod watchdog_dependency_tests {
|
|
||||||
use super::bitcoin_ready_for_lnd_watchdog;
|
|
||||||
use crate::bitcoin_status::BitcoinNodeStatus;
|
|
||||||
use serde_json::json;
|
|
||||||
#[test]
|
|
||||||
fn initial_sync_warmup_outage_stale_and_unknown_never_trigger_lnd_restart() {
|
|
||||||
let mut status = BitcoinNodeStatus::default();
|
|
||||||
assert!(!bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
status.ok = true;
|
|
||||||
status.blockchain_info = Some(json!({"initialblockdownload":true}));
|
|
||||||
assert!(!bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
status.blockchain_info = Some(json!({"initialblockdownload":false}));
|
|
||||||
assert!(bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
status.stale = true;
|
|
||||||
assert!(!bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
status.stale = false;
|
|
||||||
status.ok = false;
|
|
||||||
assert!(!bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
status.ok = true;
|
|
||||||
status.age_ms = 30_000;
|
|
||||||
assert!(!bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
status.age_ms = 0;
|
|
||||||
status.blockchain_info = Some(json!({}));
|
|
||||||
assert!(!bitcoin_ready_for_lnd_watchdog(&status));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -326,10 +326,6 @@ impl RpcHandler {
|
|||||||
// an older version pins it so install_fresh resolves that image and the
|
// an older version pins it so install_fresh resolves that image and the
|
||||||
// update badge stays suppressed. See docs/bitcoin-multi-version-design.md.
|
// update badge stays suppressed. See docs/bitcoin-multi-version-design.md.
|
||||||
if matches!(package_id, "bitcoin-core" | "bitcoin-knots") {
|
if matches!(package_id, "bitcoin-core" | "bitcoin-knots") {
|
||||||
if let Some(value) = params.get("prune") {
|
|
||||||
let prune = value.as_bool().context("prune must be a boolean")?;
|
|
||||||
crate::settings::bitcoin_storage::save(&self.config.data_dir, prune).await?;
|
|
||||||
}
|
|
||||||
if let Some(version) = params.get("version").and_then(|v| v.as_str()) {
|
if let Some(version) = params.get("version").and_then(|v| v.as_str()) {
|
||||||
persist_install_version_selection(package_id, version).await;
|
persist_install_version_selection(package_id, version).await;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -153,18 +153,8 @@ impl RpcHandler {
|
|||||||
let default = app_catalog::catalog_default_version(app_id);
|
let default = app_catalog::catalog_default_version(app_id);
|
||||||
let cfg = version_config::read(app_id);
|
let cfg = version_config::read(app_id);
|
||||||
let installed = installed_version(app_id).await;
|
let installed = installed_version(app_id).await;
|
||||||
let bitcoin_prune = if matches!(app_id, "bitcoin-core" | "bitcoin-knots") {
|
|
||||||
Some(
|
|
||||||
crate::settings::bitcoin_storage::load(&self.config.data_dir)
|
|
||||||
.await?
|
|
||||||
.prune,
|
|
||||||
)
|
|
||||||
} else {
|
|
||||||
None
|
|
||||||
};
|
|
||||||
|
|
||||||
Ok(serde_json::json!({
|
Ok(serde_json::json!({
|
||||||
"bitcoinPrune": bitcoin_prune,
|
|
||||||
"id": app_id,
|
"id": app_id,
|
||||||
"supportsVersions": supports_versions(app_id),
|
"supportsVersions": supports_versions(app_id),
|
||||||
"default": default,
|
"default": default,
|
||||||
|
|||||||
@@ -100,11 +100,7 @@ fn friendly_transient_error(has_cached_state: bool, err_msg: &str) -> String {
|
|||||||
.trim()
|
.trim()
|
||||||
.trim_end_matches('.');
|
.trim_end_matches('.');
|
||||||
let lower = detail.to_lowercase();
|
let lower = detail.to_lowercase();
|
||||||
let state = if lower.contains("loading block index") {
|
let state = if lower.contains("verifying blocks") {
|
||||||
Some("loading its block index. This can take a while after installation or restart")
|
|
||||||
} else if lower.contains("replaying blocks") {
|
|
||||||
Some("checking saved blocks before startup completes")
|
|
||||||
} else if lower.contains("verifying blocks") {
|
|
||||||
Some("verifying blocks after restart")
|
Some("verifying blocks after restart")
|
||||||
} else if lower.contains("connection reset") {
|
} else if lower.contains("connection reset") {
|
||||||
Some("starting up and not yet accepting RPC connections")
|
Some("starting up and not yet accepting RPC connections")
|
||||||
@@ -344,21 +340,3 @@ mod tests {
|
|||||||
assert!(msg.len() < 260);
|
assert!(msg.len() < 260);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod startup_message_tests {
|
|
||||||
#[test]
|
|
||||||
fn loading_block_index_is_explained_without_rpc_error_dump() {
|
|
||||||
for cached in [false, true] {
|
|
||||||
let message = super::friendly_transient_error(
|
|
||||||
cached,
|
|
||||||
r#"getblockchaininfo: Bitcoin RPC returned 500 Internal Server Error: {"error":{"code":-28,"message":"Loading block index…"}}"#,
|
|
||||||
);
|
|
||||||
assert!(message.contains("loading its block index"));
|
|
||||||
for raw in ["500", "-28", "Detail:", "getblockchaininfo", "{", "RPC"] {
|
|
||||||
assert!(!message.contains(raw));
|
|
||||||
}
|
|
||||||
assert_eq!(message.contains("last known state"), cached);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -313,7 +313,7 @@ async fn image_id(image_ref: &str) -> Option<String> {
|
|||||||
/// should reference (`localhost/<base>:latest` for build, registry
|
/// should reference (`localhost/<base>:latest` for build, registry
|
||||||
/// URL for pull).
|
/// URL for pull).
|
||||||
async fn ensure_image_present(spec: &CompanionSpec) -> Result<String> {
|
async fn ensure_image_present(spec: &CompanionSpec) -> Result<String> {
|
||||||
let mut local_image = format!("localhost/{}:latest", spec.image_base);
|
let local_image = format!("localhost/{}:latest", spec.image_base);
|
||||||
let local_image_compat = format!("localhost/{}:local", spec.image_base);
|
let local_image_compat = format!("localhost/{}:local", spec.image_base);
|
||||||
let registry_image = format!("{}/{}:latest", COMPANION_REGISTRY, spec.image_base);
|
let registry_image = format!("{}/{}:latest", COMPANION_REGISTRY, spec.image_base);
|
||||||
|
|
||||||
@@ -322,13 +322,11 @@ async fn ensure_image_present(spec: &CompanionSpec) -> Result<String> {
|
|||||||
for dir in spec.build_dir_candidates {
|
for dir in spec.build_dir_candidates {
|
||||||
let dockerfile = PathBuf::from(dir).join("Dockerfile");
|
let dockerfile = PathBuf::from(dir).join("Dockerfile");
|
||||||
if fs::try_exists(&dockerfile).await.unwrap_or(false) {
|
if fs::try_exists(&dockerfile).await.unwrap_or(false) {
|
||||||
// Older installers and self-update create :local themselves. It
|
// `:local` is a deliberate manual override — never auto-rebuild it.
|
||||||
// must receive source updates too; treating it as a permanent
|
|
||||||
// manual override silently kept the old LND UI after an OTA.
|
|
||||||
if image_exists(&local_image_compat).await {
|
if image_exists(&local_image_compat).await {
|
||||||
local_image = local_image_compat.clone();
|
return Ok(local_image_compat);
|
||||||
}
|
}
|
||||||
// Reuse either local tag only when the build context has NOT
|
// Reuse the auto-built `:latest` only when the build context has NOT
|
||||||
// changed since it was built. Without this staleness check an
|
// changed since it was built. Without this staleness check an
|
||||||
// already-present image is reused forever, so edits to the baked-in
|
// already-present image is reused forever, so edits to the baked-in
|
||||||
// context (Dockerfile, nginx.conf, …) never reach the node — this is
|
// context (Dockerfile, nginx.conf, …) never reach the node — this is
|
||||||
@@ -851,43 +849,20 @@ async fn needs_repair(spec: &CompanionSpec) -> Result<bool> {
|
|||||||
if !matches_known_shape {
|
if !matches_known_shape {
|
||||||
return Ok(true);
|
return Ok(true);
|
||||||
}
|
}
|
||||||
if let Some(image) = managed_local_image(spec, &on_disk) {
|
if on_disk.contains(&local_image) && !on_disk.contains(&local_image_compat) {
|
||||||
for dir in spec.build_dir_candidates {
|
for dir in spec.build_dir_candidates {
|
||||||
let dockerfile = PathBuf::from(dir).join("Dockerfile");
|
let dockerfile = PathBuf::from(dir).join("Dockerfile");
|
||||||
if fs::try_exists(&dockerfile).await.unwrap_or(false) {
|
if fs::try_exists(&dockerfile).await.unwrap_or(false) {
|
||||||
// Conservative on any timeout/error inside: reuse the cache.
|
// Conservative on any timeout/error inside: reuse the cache.
|
||||||
return Ok(context_is_newer_than_image(dir, &image).await);
|
return Ok(context_is_newer_than_image(dir, &local_image).await);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Ok(false)
|
Ok(false)
|
||||||
}
|
}
|
||||||
|
|
||||||
fn managed_local_image(spec: &CompanionSpec, unit: &str) -> Option<String> {
|
|
||||||
["latest", "local"]
|
|
||||||
.iter()
|
|
||||||
.map(|tag| format!("localhost/{}:{tag}", spec.image_base))
|
|
||||||
.find(|image| build_unit(spec, image).render() == unit)
|
|
||||||
}
|
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
#[test]
|
|
||||||
fn legacy_installer_local_tag_is_checked_for_source_updates_like_latest() {
|
|
||||||
for spec in ALL_COMPANIONS.iter().flat_map(|group| group.iter()) {
|
|
||||||
for tag in ["local", "latest"] {
|
|
||||||
let image = format!("localhost/{}:{tag}", spec.image_base);
|
|
||||||
let unit = build_unit(spec, &image).render();
|
|
||||||
assert_eq!(managed_local_image(spec, &unit), Some(image));
|
|
||||||
}
|
|
||||||
let registry = format!("{}/{}:latest", COMPANION_REGISTRY, spec.image_base);
|
|
||||||
assert_eq!(
|
|
||||||
managed_local_image(spec, &build_unit(spec, ®istry).render()),
|
|
||||||
None
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
fn names(specs: &[&'static CompanionSpec]) -> Vec<&'static str> {
|
fn names(specs: &[&'static CompanionSpec]) -> Vec<&'static str> {
|
||||||
|
|||||||
@@ -89,84 +89,136 @@ bitcoind.estimatemode=ECONOMICAL\n"
|
|||||||
Ok(EnsureOutcome::Written)
|
Ok(EnsureOutcome::Written)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Bitcoin can accept TCP while returning RPC_IN_WARMUP for many minutes.
|
|
||||||
/// Unlocking LND then triggers its short chain-backend timeout and a restart loop.
|
|
||||||
/// Leave the wallet intact and locked; the next reconciliation retries readiness.
|
|
||||||
async fn bitcoin_rpc_ready() -> bool {
|
|
||||||
let (user, password) = crate::bitcoin_rpc::bitcoin_rpc_credentials().await;
|
|
||||||
let client = match reqwest::Client::builder()
|
|
||||||
.no_proxy()
|
|
||||||
.timeout(std::time::Duration::from_secs(5))
|
|
||||||
.build()
|
|
||||||
{
|
|
||||||
Ok(client) => client,
|
|
||||||
Err(_) => return false,
|
|
||||||
};
|
|
||||||
let response = client.post(crate::constants::BITCOIN_RPC_URL)
|
|
||||||
.basic_auth(user, Some(password))
|
|
||||||
.json(&serde_json::json!({"jsonrpc":"1.0","id":"lnd-readiness","method":"getblockchaininfo","params":[]}))
|
|
||||||
.send().await;
|
|
||||||
match response {
|
|
||||||
Ok(response) if response.status().is_success() => response
|
|
||||||
.json::<serde_json::Value>()
|
|
||||||
.await
|
|
||||||
.is_ok_and(|value| bitcoin_readiness_response(&value)),
|
|
||||||
_ => false,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fn bitcoin_readiness_response(value: &serde_json::Value) -> bool {
|
|
||||||
value.get("error").is_none_or(|e| e.is_null())
|
|
||||||
&& value
|
|
||||||
.pointer("/result/blocks")
|
|
||||||
.and_then(|v| v.as_u64())
|
|
||||||
.is_some()
|
|
||||||
&& value
|
|
||||||
.pointer("/result/initialblockdownload")
|
|
||||||
.and_then(|v| v.as_bool())
|
|
||||||
.is_some()
|
|
||||||
}
|
|
||||||
|
|
||||||
pub async fn ensure_wallet_initialized() -> Result<()> {
|
pub async fn ensure_wallet_initialized() -> Result<()> {
|
||||||
let admin_macaroon = "/var/lib/archipelago/lnd/data/chain/bitcoin/mainnet/admin.macaroon";
|
let admin_macaroon = "/var/lib/archipelago/lnd/data/chain/bitcoin/mainnet/admin.macaroon";
|
||||||
let wallet_db = "/var/lib/archipelago/lnd/data/chain/bitcoin/mainnet/wallet.db";
|
let wallet_db = "/var/lib/archipelago/lnd/data/chain/bitcoin/mainnet/wallet.db";
|
||||||
if file_exists_as_root(wallet_db).await {
|
if file_exists_as_root(wallet_db).await {
|
||||||
// GetInfo can wait for Bitcoin sync even though the wallet is already
|
|
||||||
// unlocked. State RPC stays available during that normal startup phase.
|
|
||||||
let client = reqwest::Client::builder()
|
|
||||||
.no_proxy()
|
|
||||||
.timeout(std::time::Duration::from_secs(5))
|
|
||||||
.danger_accept_invalid_certs(true)
|
|
||||||
.build()?;
|
|
||||||
if wallet_is_unlocked(wallet_state(&client).await.as_deref()) {
|
|
||||||
return Ok(());
|
|
||||||
}
|
|
||||||
if file_exists_as_root(admin_macaroon).await && lnd_getinfo_ready(admin_macaroon).await {
|
if file_exists_as_root(admin_macaroon).await && lnd_getinfo_ready(admin_macaroon).await {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
if !bitcoin_rpc_ready().await {
|
match unlock_existing_wallet().await? {
|
||||||
tracing::debug!("[lnd] waiting for Bitcoin RPC readiness before wallet unlock");
|
true => {
|
||||||
return Ok(());
|
wait_for_admin_macaroon(admin_macaroon).await?;
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
false => {
|
||||||
|
// Every candidate password was actively rejected: this wallet was
|
||||||
|
// created with a password this node no longer has, so it can never
|
||||||
|
// auto-unlock unattended. Alpha nodes hold no real funds and a wallet
|
||||||
|
// locked with an unknown password is already inaccessible, so wipe +
|
||||||
|
// recreate it on the per-node secret to self-heal at boot.
|
||||||
|
recreate_wallet_destructively().await?;
|
||||||
|
wait_for_admin_macaroon(admin_macaroon).await?;
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
unlock_existing_wallet_no_wipe().await?;
|
|
||||||
wait_for_admin_macaroon(admin_macaroon).await?;
|
|
||||||
return Ok(());
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if !bitcoin_rpc_ready().await {
|
|
||||||
tracing::debug!("[lnd] waiting for Bitcoin RPC readiness before wallet initialization");
|
|
||||||
return Ok(());
|
|
||||||
}
|
|
||||||
init_wallet_via_rest().await?;
|
init_wallet_via_rest().await?;
|
||||||
wait_for_admin_macaroon(admin_macaroon).await
|
wait_for_admin_macaroon(admin_macaroon).await
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// LND data subdirectories holding wallet + channel + graph state. Removing them
|
||||||
|
/// returns LND to a NON_EXISTING wallet state. Funds-bearing data lives here too,
|
||||||
|
/// so deletion is destructive — only done once the wallet is already unrecoverable.
|
||||||
|
const LND_STATE_DIRS: &[&str] = &[
|
||||||
|
"/var/lib/archipelago/lnd/data/chain",
|
||||||
|
"/var/lib/archipelago/lnd/data/graph",
|
||||||
|
];
|
||||||
|
|
||||||
|
/// Podman container name for the core LND app (see `compute_container_name`:
|
||||||
|
/// non-UI core apps keep their bare id). LND runs as a plain bridge-network
|
||||||
|
/// container, not a Quadlet unit, so it is restarted via `podman`, not systemctl.
|
||||||
|
const LND_CONTAINER: &str = "lnd";
|
||||||
|
|
||||||
/// Canonical on-host admin macaroon — same path the RPC layer reads.
|
/// Canonical on-host admin macaroon — same path the RPC layer reads.
|
||||||
const LND_ADMIN_MACAROON: &str =
|
const LND_ADMIN_MACAROON: &str =
|
||||||
"/var/lib/archipelago/lnd/data/chain/bitcoin/mainnet/admin.macaroon";
|
"/var/lib/archipelago/lnd/data/chain/bitcoin/mainnet/admin.macaroon";
|
||||||
|
|
||||||
|
/// Archipelago data dir (default; not overridden in prod). Holds the
|
||||||
|
/// `user-stopped.json` that gates health-monitor auto-restart.
|
||||||
const ARCHY_DATA_DIR: &str = "/var/lib/archipelago";
|
const ARCHY_DATA_DIR: &str = "/var/lib/archipelago";
|
||||||
|
|
||||||
|
/// Destroy an unrecoverable LND wallet and recreate a fresh one keyed to the
|
||||||
|
/// per-node secret. Suppresses health-monitor auto-restart for the wipe window,
|
||||||
|
/// stops LND, deletes its wallet/chain/graph state as root, restarts it, waits
|
||||||
|
/// for NON_EXISTING, then inits a fresh wallet. Destructive — only called when no
|
||||||
|
/// candidate password can open the existing wallet.
|
||||||
|
async fn recreate_wallet_destructively() -> Result<()> {
|
||||||
|
tracing::warn!(
|
||||||
|
"[lnd] wallet is locked with an unknown password and cannot auto-unlock; \
|
||||||
|
wiping and recreating it on the per-node secret (DESTRUCTIVE)"
|
||||||
|
);
|
||||||
|
|
||||||
|
// The health monitor restarts any container it sees stopped; mark LND
|
||||||
|
// user-stopped so it doesn't re-launch (and re-open the wallet) mid-wipe.
|
||||||
|
// Always cleared below so LND auto-recovers normally afterwards.
|
||||||
|
let data_dir = std::path::Path::new(ARCHY_DATA_DIR);
|
||||||
|
crate::crash_recovery::mark_user_stopped(data_dir, LND_CONTAINER).await;
|
||||||
|
let result = wipe_and_reinit_wallet().await;
|
||||||
|
crate::crash_recovery::clear_user_stopped(data_dir, LND_CONTAINER).await;
|
||||||
|
result
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn wipe_and_reinit_wallet() -> Result<()> {
|
||||||
|
podman_user_scoped(&["stop", LND_CONTAINER])
|
||||||
|
.await
|
||||||
|
.context("stopping lnd before wallet wipe")?;
|
||||||
|
|
||||||
|
for dir in LND_STATE_DIRS {
|
||||||
|
let status = host_sudo(&["rm", "-rf", dir])
|
||||||
|
.await
|
||||||
|
.with_context(|| format!("removing {dir}"))?;
|
||||||
|
if !status.success() {
|
||||||
|
anyhow::bail!("removing {dir} exited with {status}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
podman_user_scoped(&["start", LND_CONTAINER])
|
||||||
|
.await
|
||||||
|
.context("restarting lnd after wallet wipe")?;
|
||||||
|
|
||||||
|
wait_for_wallet_state("NON_EXISTING").await?;
|
||||||
|
init_wallet_via_rest().await
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Run `podman <args>` inside a transient `systemd-run --user --scope`, matching
|
||||||
|
/// how the orchestrator/health-monitor manage rootless containers (keeps the
|
||||||
|
/// container out of the archipelago service's cgroup).
|
||||||
|
async fn podman_user_scoped(args: &[&str]) -> Result<()> {
|
||||||
|
let out = tokio::process::Command::new("systemd-run")
|
||||||
|
.args(["--user", "--scope", "--quiet", "--collect", "podman"])
|
||||||
|
.args(args)
|
||||||
|
.output()
|
||||||
|
.await
|
||||||
|
.with_context(|| format!("systemd-run --user --scope podman {}", args.join(" ")))?;
|
||||||
|
if !out.status.success() {
|
||||||
|
anyhow::bail!(
|
||||||
|
"podman {} failed: {}",
|
||||||
|
args.join(" "),
|
||||||
|
String::from_utf8_lossy(&out.stderr).trim()
|
||||||
|
);
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Poll `/v1/state` until LND reports `target`, or time out after ~120s.
|
||||||
|
async fn wait_for_wallet_state(target: &str) -> Result<()> {
|
||||||
|
let client = reqwest::Client::builder()
|
||||||
|
.no_proxy()
|
||||||
|
.timeout(std::time::Duration::from_secs(5))
|
||||||
|
.danger_accept_invalid_certs(true)
|
||||||
|
.build()
|
||||||
|
.context("building LND REST client")?;
|
||||||
|
for _ in 0..120 {
|
||||||
|
if wallet_state(&client).await.as_deref() == Some(target) {
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
tokio::time::sleep(std::time::Duration::from_secs(1)).await;
|
||||||
|
}
|
||||||
|
anyhow::bail!("LND did not reach state {target} after wallet wipe")
|
||||||
|
}
|
||||||
|
|
||||||
async fn file_exists_as_root(path: &str) -> bool {
|
async fn file_exists_as_root(path: &str) -> bool {
|
||||||
if std::path::Path::new(path).exists() {
|
if std::path::Path::new(path).exists() {
|
||||||
return true;
|
return true;
|
||||||
@@ -314,9 +366,6 @@ async fn unlock_existing_wallet_via_rest() -> Result<bool> {
|
|||||||
// exactly the nodes least able to afford it. Waiting longer costs nothing —
|
// exactly the nodes least able to afford it. Waiting longer costs nothing —
|
||||||
// a wrong password still exits on the first pass via `all_rejected`.
|
// a wrong password still exits on the first pass via `all_rejected`.
|
||||||
for _ in 0..UNLOCK_NOT_READY_ATTEMPTS {
|
for _ in 0..UNLOCK_NOT_READY_ATTEMPTS {
|
||||||
if wallet_is_unlocked(wallet_state(&client).await.as_deref()) {
|
|
||||||
return Ok(true);
|
|
||||||
}
|
|
||||||
let mut all_rejected = true;
|
let mut all_rejected = true;
|
||||||
for pw in &candidates {
|
for pw in &candidates {
|
||||||
match try_unlock_once(&client, pw).await {
|
match try_unlock_once(&client, pw).await {
|
||||||
@@ -341,8 +390,14 @@ async fn unlock_existing_wallet_via_rest() -> Result<bool> {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Unlock the existing wallet, preserving its identity and channel data when
|
/// Unlock an existing wallet WITHOUT the destructive fallback.
|
||||||
/// passwords are unavailable or rejected. Used by boot and credential rotation.
|
///
|
||||||
|
/// `ensure_wallet_initialized` wipes and recreates a wallet no candidate
|
||||||
|
/// password can open — correct for a boot path that must self-heal, and exactly
|
||||||
|
/// wrong for macaroon rotation, which restarts LND against a wallet the operator
|
||||||
|
/// still wants. Rotation calls this instead, so there is no code path from
|
||||||
|
/// "rotate my credentials" to "delete my wallet": a rejected password surfaces
|
||||||
|
/// as an error the caller reports, never as a wipe.
|
||||||
pub(crate) async fn unlock_existing_wallet_no_wipe() -> Result<()> {
|
pub(crate) async fn unlock_existing_wallet_no_wipe() -> Result<()> {
|
||||||
match unlock_existing_wallet().await? {
|
match unlock_existing_wallet().await? {
|
||||||
true => Ok(()),
|
true => Ok(()),
|
||||||
@@ -353,10 +408,6 @@ pub(crate) async fn unlock_existing_wallet_no_wipe() -> Result<()> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
fn wallet_is_unlocked(state: Option<&str>) -> bool {
|
|
||||||
matches!(state, Some("UNLOCKED" | "RPC_ACTIVE" | "SERVER_ACTIVE"))
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Current LND wallet state via the unauthenticated `/v1/state` endpoint
|
/// Current LND wallet state via the unauthenticated `/v1/state` endpoint
|
||||||
/// (NON_EXISTING / LOCKED / UNLOCKED / RPC_ACTIVE / …). None if unreachable.
|
/// (NON_EXISTING / LOCKED / UNLOCKED / RPC_ACTIVE / …). None if unreachable.
|
||||||
async fn wallet_state(client: &reqwest::Client) -> Option<String> {
|
async fn wallet_state(client: &reqwest::Client) -> Option<String> {
|
||||||
@@ -487,7 +538,7 @@ async fn init_wallet_via_rest() -> Result<()> {
|
|||||||
{
|
{
|
||||||
UnlockerResponse::Value(seed) => seed,
|
UnlockerResponse::Value(seed) => seed,
|
||||||
UnlockerResponse::WalletAlreadyExists => {
|
UnlockerResponse::WalletAlreadyExists => {
|
||||||
unlock_existing_wallet_no_wipe().await?;
|
unlock_existing_wallet().await?;
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
@@ -518,7 +569,7 @@ async fn init_wallet_via_rest() -> Result<()> {
|
|||||||
.await;
|
.await;
|
||||||
}
|
}
|
||||||
UnlockerResponse::WalletAlreadyExists => {
|
UnlockerResponse::WalletAlreadyExists => {
|
||||||
unlock_existing_wallet_no_wipe().await?;
|
unlock_existing_wallet().await?;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1152,44 +1203,3 @@ mod tests {
|
|||||||
.is_empty());
|
.is_empty());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod bitcoin_readiness_tests {
|
|
||||||
use super::bitcoin_readiness_response;
|
|
||||||
use serde_json::json;
|
|
||||||
#[test]
|
|
||||||
fn only_usable_bitcoin_rpc_allows_wallet_unlock() {
|
|
||||||
for response in [
|
|
||||||
json!({}),
|
|
||||||
json!({"error":{"code":-28,"message":"Loading block index"},"result":null}),
|
|
||||||
json!({"result":{"blocks":null}}),
|
|
||||||
] {
|
|
||||||
assert!(!bitcoin_readiness_response(&response));
|
|
||||||
}
|
|
||||||
// Initial sync is supported by LND. Loading the database is not.
|
|
||||||
for ibd in [true, false] {
|
|
||||||
assert!(bitcoin_readiness_response(
|
|
||||||
&json!({"result":{"blocks":100,"initialblockdownload":ibd},"error":null})
|
|
||||||
));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod syncing_wallet_state_tests {
|
|
||||||
#[test]
|
|
||||||
fn an_unlocked_wallet_waiting_for_chain_sync_is_never_unlocked_again() {
|
|
||||||
for state in ["UNLOCKED", "RPC_ACTIVE", "SERVER_ACTIVE"] {
|
|
||||||
assert!(super::wallet_is_unlocked(Some(state)));
|
|
||||||
}
|
|
||||||
for state in [
|
|
||||||
None,
|
|
||||||
Some("LOCKED"),
|
|
||||||
Some("NON_EXISTING"),
|
|
||||||
Some("WAITING_TO_START"),
|
|
||||||
Some("unknown"),
|
|
||||||
] {
|
|
||||||
assert!(!super::wallet_is_unlocked(state));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -798,10 +798,6 @@ fn host_port_bindings_drifted(
|
|||||||
}
|
}
|
||||||
|
|
||||||
async fn ensure_user_podman_socket() -> Result<()> {
|
async fn ensure_user_podman_socket() -> Result<()> {
|
||||||
// Unit tests inject a runtime; they must not restart the host Podman API.
|
|
||||||
if cfg!(test) {
|
|
||||||
return Ok(());
|
|
||||||
}
|
|
||||||
let socket_path = "/run/user/1000/podman/podman.sock";
|
let socket_path = "/run/user/1000/podman/podman.sock";
|
||||||
if podman_socket_accepts_connections(socket_path).await {
|
if podman_socket_accepts_connections(socket_path).await {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
@@ -1868,7 +1864,7 @@ impl ProdContainerOrchestrator {
|
|||||||
// Durable installation record, consulted alongside the perishable
|
// Durable installation record, consulted alongside the perishable
|
||||||
// `was_running` snapshot for desired-state recovery below.
|
// `was_running` snapshot for desired-state recovery below.
|
||||||
let installed_apps = crate::crash_recovery::load_installed_apps(&self.data_dir).await;
|
let installed_apps = crate::crash_recovery::load_installed_apps(&self.data_dir).await;
|
||||||
let (mut manifests, container_name_by_app_id): (
|
let (manifests, container_name_by_app_id): (
|
||||||
Vec<LoadedManifest>,
|
Vec<LoadedManifest>,
|
||||||
std::collections::HashMap<String, String>,
|
std::collections::HashMap<String, String>,
|
||||||
) = {
|
) = {
|
||||||
@@ -1899,15 +1895,6 @@ impl ProdContainerOrchestrator {
|
|||||||
.collect();
|
.collect();
|
||||||
(filtered, names)
|
(filtered, names)
|
||||||
};
|
};
|
||||||
// Wallet readiness must not wait behind unrelated image pulls/builds.
|
|
||||||
// A running LND container can still be locked after boot; its post-start
|
|
||||||
// hook must run promptly. Reconcile Bitcoin first, then LND, before the
|
|
||||||
// rest of the catalog. Each app still honors stopped/uninstalled markers.
|
|
||||||
manifests.sort_by_key(|lm| match lm.manifest.app.id.as_str() {
|
|
||||||
"bitcoin-knots" | "bitcoin-core" | "bitcoin" => 0,
|
|
||||||
"lnd" => 1,
|
|
||||||
_ => 2,
|
|
||||||
});
|
|
||||||
// Live container names (any state), for the same recovery check.
|
// Live container names (any state), for the same recovery check.
|
||||||
let present_containers: std::collections::HashSet<String> = self
|
let present_containers: std::collections::HashSet<String> = self
|
||||||
.runtime
|
.runtime
|
||||||
@@ -1917,11 +1904,6 @@ impl ProdContainerOrchestrator {
|
|||||||
.unwrap_or_default();
|
.unwrap_or_default();
|
||||||
let mut report = ReconcileReport::default();
|
let mut report = ReconcileReport::default();
|
||||||
let disk_gb = self.disk_gb().await;
|
let disk_gb = self.disk_gb().await;
|
||||||
let bitcoin_pruned = disk_gb < ARCHIVAL_BITCOIN_DISK_GB
|
|
||||||
|| crate::settings::bitcoin_storage::load(&self.data_dir)
|
|
||||||
.await
|
|
||||||
.map(|settings| settings.prune)
|
|
||||||
.unwrap_or(true);
|
|
||||||
// Register every candidate before the (sequential, possibly slow)
|
// Register every candidate before the (sequential, possibly slow)
|
||||||
// pass so the scanner overlays queued-but-down apps as Restarting
|
// pass so the scanner overlays queued-but-down apps as Restarting
|
||||||
// instead of Stopped. Each app is deregistered as its turn finishes,
|
// instead of Stopped. Each app is deregistered as its turn finishes,
|
||||||
@@ -1961,7 +1943,7 @@ impl ProdContainerOrchestrator {
|
|||||||
}
|
}
|
||||||
if mode == ReconcileMode::ExistingOnly
|
if mode == ReconcileMode::ExistingOnly
|
||||||
&& requires_archival_bitcoin(&app_id)
|
&& requires_archival_bitcoin(&app_id)
|
||||||
&& bitcoin_pruned
|
&& disk_gb < ARCHIVAL_BITCOIN_DISK_GB
|
||||||
{
|
{
|
||||||
report.record(
|
report.record(
|
||||||
&app_id,
|
&app_id,
|
||||||
@@ -3235,9 +3217,6 @@ impl ProdContainerOrchestrator {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async fn ensure_container_network(&self, manifest: &AppManifest) -> Result<()> {
|
async fn ensure_container_network(&self, manifest: &AppManifest) -> Result<()> {
|
||||||
if cfg!(test) {
|
|
||||||
return Ok(());
|
|
||||||
}
|
|
||||||
let Some(network) = manifest.app.container.network.as_deref() else {
|
let Some(network) = manifest.app.container.network.as_deref() else {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
};
|
};
|
||||||
@@ -3732,17 +3711,6 @@ impl ProdContainerOrchestrator {
|
|||||||
}
|
}
|
||||||
let mut env = manifest.app.environment.clone();
|
let mut env = manifest.app.environment.clone();
|
||||||
env.extend(manifest.app.container.resolve_derived_env(&facts));
|
env.extend(manifest.app.container.resolve_derived_env(&facts));
|
||||||
if matches!(manifest.app.id.as_str(), "bitcoin-core" | "bitcoin-knots") {
|
|
||||||
let storage = crate::settings::bitcoin_storage::load(&self.data_dir).await?;
|
|
||||||
env.retain(|entry| !entry.starts_with("BITCOIN_PRUNE="));
|
|
||||||
if storage.prune {
|
|
||||||
anyhow::ensure!(
|
|
||||||
manifest.app.container.custom_args.iter().any(|arg| arg.contains("BITCOIN_PRUNE")),
|
|
||||||
"This Bitcoin app definition cannot honor the pruning choice. Refresh the app catalog and try again."
|
|
||||||
);
|
|
||||||
env.push("BITCOIN_PRUNE=1".to_string());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// FM_BITCOIND_URL now comes from the manifest's {{BITCOIN_HOST}}
|
// FM_BITCOIND_URL now comes from the manifest's {{BITCOIN_HOST}}
|
||||||
// derived_env (works on Knots/Core/any distro). The old hardcoded
|
// derived_env (works on Knots/Core/any distro). The old hardcoded
|
||||||
@@ -6096,48 +6064,6 @@ app:
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn bitcoin_storage_choice_is_applied_and_old_catalog_cannot_silently_ignore_it() {
|
|
||||||
let rt = Arc::new(MockRuntime::default());
|
|
||||||
let mut orch = orch_with(rt).await;
|
|
||||||
let dir = tempfile::tempdir().unwrap();
|
|
||||||
orch.set_data_dir(dir.path().to_path_buf());
|
|
||||||
for id in ["bitcoin-core", "bitcoin-knots"] {
|
|
||||||
let mut old = pull_manifest(id, "docker.io/bitcoin/bitcoin:28");
|
|
||||||
// No preference: existing containers need no new environment flag.
|
|
||||||
crate::settings::bitcoin_storage::save(dir.path(), false)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
orch.resolve_dynamic_env(&mut old).await.unwrap();
|
|
||||||
assert!(!old
|
|
||||||
.app
|
|
||||||
.environment
|
|
||||||
.iter()
|
|
||||||
.any(|s| s.starts_with("BITCOIN_PRUNE=")));
|
|
||||||
crate::settings::bitcoin_storage::save(dir.path(), true)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
assert!(orch
|
|
||||||
.resolve_dynamic_env(&mut old)
|
|
||||||
.await
|
|
||||||
.unwrap_err()
|
|
||||||
.to_string()
|
|
||||||
.contains("cannot honor"));
|
|
||||||
let mut current = pull_manifest(id, "docker.io/bitcoin/bitcoin:28");
|
|
||||||
current
|
|
||||||
.app
|
|
||||||
.container
|
|
||||||
.custom_args
|
|
||||||
.push("if [ ${BITCOIN_PRUNE:-0} = 1 ]; then :; fi".into());
|
|
||||||
orch.resolve_dynamic_env(&mut current).await.unwrap();
|
|
||||||
assert!(current
|
|
||||||
.app
|
|
||||||
.environment
|
|
||||||
.iter()
|
|
||||||
.any(|s| s == "BITCOIN_PRUNE=1"));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn install_resolves_derived_and_secret_env_before_create() {
|
async fn install_resolves_derived_and_secret_env_before_create() {
|
||||||
let rt = Arc::new(MockRuntime::default());
|
let rt = Arc::new(MockRuntime::default());
|
||||||
@@ -6472,42 +6398,6 @@ app:
|
|||||||
assert!(cascade_pairs_for_report(&r, &none).is_empty());
|
assert!(cascade_pairs_for_report(&r, &none).is_empty());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn reconcile_wallet_start_precedes_unrelated_failed_image_pull() {
|
|
||||||
let rt = Arc::new(MockRuntime::default());
|
|
||||||
rt.set_state("bitcoin-knots", ContainerState::Exited);
|
|
||||||
rt.set_state("lnd", ContainerState::Exited);
|
|
||||||
*rt.fail_pull.lock().unwrap() = Some("registry unreachable".into());
|
|
||||||
let mut orch = orch_with(rt.clone()).await;
|
|
||||||
orch.set_disk_gb_for_test(2000);
|
|
||||||
for id in ["unrelated", "lnd", "bitcoin-knots"] {
|
|
||||||
orch.insert_manifest_for_test(
|
|
||||||
pull_manifest(id, &format!("docker.io/example/{id}:1")),
|
|
||||||
PathBuf::from(format!("/tmp/{id}")),
|
|
||||||
)
|
|
||||||
.await;
|
|
||||||
}
|
|
||||||
let report = orch.reconcile_all().await;
|
|
||||||
assert!(report.failures.iter().any(|(id, _)| id == "unrelated"));
|
|
||||||
let calls = rt.calls();
|
|
||||||
let bitcoin = calls
|
|
||||||
.iter()
|
|
||||||
.position(|c| c == "start_container:bitcoin-knots")
|
|
||||||
.unwrap();
|
|
||||||
let lnd = calls
|
|
||||||
.iter()
|
|
||||||
.position(|c| c == "start_container:lnd")
|
|
||||||
.unwrap();
|
|
||||||
let pull = calls
|
|
||||||
.iter()
|
|
||||||
.position(|c| c.starts_with("pull_image:"))
|
|
||||||
.unwrap();
|
|
||||||
assert!(
|
|
||||||
bitcoin < lnd && lnd < pull,
|
|
||||||
"wallet startup was delayed by unrelated recovery: {calls:?}"
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn reconcile_starts_exited_container() {
|
async fn reconcile_starts_exited_container() {
|
||||||
let rt = Arc::new(MockRuntime::default());
|
let rt = Arc::new(MockRuntime::default());
|
||||||
|
|||||||
@@ -676,13 +676,6 @@ pub async fn unit_exists(name: &str) -> bool {
|
|||||||
|
|
||||||
/// Resolve the per-user quadlet dir under $HOME. Created if missing.
|
/// Resolve the per-user quadlet dir under $HOME. Created if missing.
|
||||||
pub async fn unit_dir() -> Result<PathBuf> {
|
pub async fn unit_dir() -> Result<PathBuf> {
|
||||||
#[cfg(test)]
|
|
||||||
{
|
|
||||||
static TEST_UNITS: std::sync::OnceLock<PathBuf> = std::sync::OnceLock::new();
|
|
||||||
return Ok(TEST_UNITS
|
|
||||||
.get_or_init(|| tempfile::tempdir().unwrap().keep())
|
|
||||||
.clone());
|
|
||||||
}
|
|
||||||
let home = std::env::var_os("HOME")
|
let home = std::env::var_os("HOME")
|
||||||
.map(PathBuf::from)
|
.map(PathBuf::from)
|
||||||
.ok_or_else(|| anyhow!("HOME not set; cannot locate quadlet unit dir"))?;
|
.ok_or_else(|| anyhow!("HOME not set; cannot locate quadlet unit dir"))?;
|
||||||
@@ -817,11 +810,6 @@ async fn systemctl_user_status(
|
|||||||
args: &[&str],
|
args: &[&str],
|
||||||
timeout: Duration,
|
timeout: Duration,
|
||||||
) -> Result<std::process::ExitStatus> {
|
) -> Result<std::process::ExitStatus> {
|
||||||
#[cfg(test)]
|
|
||||||
{
|
|
||||||
use std::os::unix::process::ExitStatusExt;
|
|
||||||
return Ok(std::process::ExitStatus::from_raw(0));
|
|
||||||
}
|
|
||||||
let mut cmd = Command::new("systemctl");
|
let mut cmd = Command::new("systemctl");
|
||||||
cmd.arg("--user").args(args);
|
cmd.arg("--user").args(args);
|
||||||
cmd.kill_on_drop(true);
|
cmd.kill_on_drop(true);
|
||||||
@@ -868,10 +856,6 @@ async fn wait_not_deactivating(service: &str, timeout: Duration) -> bool {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async fn systemctl_user_output(args: &[&str], timeout: Duration) -> Result<std::process::Output> {
|
async fn systemctl_user_output(args: &[&str], timeout: Duration) -> Result<std::process::Output> {
|
||||||
#[cfg(test)]
|
|
||||||
{
|
|
||||||
anyhow::bail!("Unit tests have no real user service manager");
|
|
||||||
}
|
|
||||||
let mut cmd = Command::new("systemctl");
|
let mut cmd = Command::new("systemctl");
|
||||||
cmd.arg("--user").args(args);
|
cmd.arg("--user").args(args);
|
||||||
cmd.kill_on_drop(true);
|
cmd.kill_on_drop(true);
|
||||||
@@ -976,9 +960,6 @@ pub async fn disable_remove(unit_name: &str, dir: &Path) -> Result<()> {
|
|||||||
|
|
||||||
/// Is the quadlet-generated service currently active?
|
/// Is the quadlet-generated service currently active?
|
||||||
pub async fn is_active(service: &str) -> bool {
|
pub async fn is_active(service: &str) -> bool {
|
||||||
if cfg!(test) {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
Command::new("systemctl")
|
Command::new("systemctl")
|
||||||
.args(["--user", "is-active", "--quiet", service])
|
.args(["--user", "is-active", "--quiet", service])
|
||||||
.status()
|
.status()
|
||||||
|
|||||||
@@ -296,24 +296,6 @@ pub async fn serve_content(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
let file_path = content_file_path(data_dir, item);
|
|
||||||
if !file_path.exists() {
|
|
||||||
// The catalog entry survived (it's a separate JSON file) but its
|
|
||||||
// backing file is gone — most likely lost in an unrelated data-dir
|
|
||||||
// reset (a shared filebrowser file, 2026-07-01: two catalog entries
|
|
||||||
// outlived a filebrowser reinstall that wiped the files themselves).
|
|
||||||
// Leaving the entry in place would keep advertising it as available
|
|
||||||
// to every peer forever, each hitting the exact same dead end this
|
|
||||||
// one just did. Prune it so it stops being offered.
|
|
||||||
warn!(
|
|
||||||
content_id = %id,
|
|
||||||
filename = %item.filename,
|
|
||||||
"content catalog entry's file is missing on disk — pruning the stale entry"
|
|
||||||
);
|
|
||||||
prune_missing_content_entry(data_dir, id).await;
|
|
||||||
return Ok(ServeResult::NotFound);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check access control
|
// Check access control
|
||||||
if !owner_session {
|
if !owner_session {
|
||||||
match &item.access {
|
match &item.access {
|
||||||
@@ -325,12 +307,8 @@ pub async fn serve_content(
|
|||||||
// Each path only counts when the sharer accepts that method.
|
// Each path only counts when the sharer accepts that method.
|
||||||
let mut authorized = false;
|
let mut authorized = false;
|
||||||
if let Some(token) = payment_token {
|
if let Some(token) = payment_token {
|
||||||
let method = if token.trim().starts_with("cashu") {
|
if (method_accepted(&item.access, "ecash")
|
||||||
"ecash"
|
|| method_accepted(&item.access, "fedimint"))
|
||||||
} else {
|
|
||||||
"fedimint"
|
|
||||||
};
|
|
||||||
if method_accepted(&item.access, method)
|
|
||||||
&& verify_payment_token(data_dir, token, *price_sats).await
|
&& verify_payment_token(data_dir, token, *price_sats).await
|
||||||
{
|
{
|
||||||
authorized = true;
|
authorized = true;
|
||||||
@@ -358,6 +336,24 @@ pub async fn serve_content(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let file_path = content_file_path(data_dir, item);
|
||||||
|
if !file_path.exists() {
|
||||||
|
// The catalog entry survived (it's a separate JSON file) but its
|
||||||
|
// backing file is gone — most likely lost in an unrelated data-dir
|
||||||
|
// reset (a shared filebrowser file, 2026-07-01: two catalog entries
|
||||||
|
// outlived a filebrowser reinstall that wiped the files themselves).
|
||||||
|
// Leaving the entry in place would keep advertising it as available
|
||||||
|
// to every peer forever, each hitting the exact same dead end this
|
||||||
|
// one just did. Prune it so it stops being offered.
|
||||||
|
warn!(
|
||||||
|
content_id = %id,
|
||||||
|
filename = %item.filename,
|
||||||
|
"content catalog entry's file is missing on disk — pruning the stale entry"
|
||||||
|
);
|
||||||
|
prune_missing_content_entry(data_dir, id).await;
|
||||||
|
return Ok(ServeResult::NotFound);
|
||||||
|
}
|
||||||
|
|
||||||
let metadata = fs::metadata(&file_path)
|
let metadata = fs::metadata(&file_path)
|
||||||
.await
|
.await
|
||||||
.context("Failed to read file metadata")?;
|
.context("Failed to read file metadata")?;
|
||||||
@@ -577,7 +573,7 @@ pub async fn serve_content_preview(data_dir: &Path, id: &str) -> Result<PreviewR
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Verify a payment token covers the required amount.
|
/// Verify a payment token covers the required amount.
|
||||||
/// Accepts real Cashu tokens and Fedimint notes.
|
/// Accepts both cashuA tokens (real Cashu) and legacy cashuSend_ format.
|
||||||
/// Swaps proofs at the mint to verify they're unspent before accepting.
|
/// Swaps proofs at the mint to verify they're unspent before accepting.
|
||||||
async fn verify_payment_token(data_dir: &Path, token: &str, required_sats: u64) -> bool {
|
async fn verify_payment_token(data_dir: &Path, token: &str, required_sats: u64) -> bool {
|
||||||
match crate::wallet::ecash::verify_and_receive_payment(data_dir, token, required_sats).await {
|
match crate::wallet::ecash::verify_and_receive_payment(data_dir, token, required_sats).await {
|
||||||
|
|||||||
@@ -1,51 +0,0 @@
|
|||||||
//! Install-time pruning preference, shared by Bitcoin Core and Knots.
|
|
||||||
//! Missing preference preserves the existing disk-based automatic selection.
|
|
||||||
use anyhow::{Context, Result};
|
|
||||||
use serde::{Deserialize, Serialize};
|
|
||||||
use std::path::Path;
|
|
||||||
|
|
||||||
#[derive(Default, Serialize, Deserialize)]
|
|
||||||
pub struct BitcoinStorage {
|
|
||||||
pub prune: bool,
|
|
||||||
}
|
|
||||||
|
|
||||||
pub async fn load(data_dir: &Path) -> Result<BitcoinStorage> {
|
|
||||||
match tokio::fs::read(data_dir.join("settings/bitcoin-storage.json")).await {
|
|
||||||
Ok(bytes) => serde_json::from_slice(&bytes).context("Invalid Bitcoin storage settings"),
|
|
||||||
Err(e) if e.kind() == std::io::ErrorKind::NotFound => Ok(BitcoinStorage::default()),
|
|
||||||
Err(e) => Err(e.into()),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
pub async fn save(data_dir: &Path, prune: bool) -> Result<()> {
|
|
||||||
let dir = data_dir.join("settings");
|
|
||||||
tokio::fs::create_dir_all(&dir).await?;
|
|
||||||
let path = dir.join("bitcoin-storage.json");
|
|
||||||
let temporary = dir.join("bitcoin-storage.json.tmp");
|
|
||||||
tokio::fs::write(&temporary, serde_json::to_vec(&BitcoinStorage { prune })?).await?;
|
|
||||||
tokio::fs::rename(temporary, path).await?;
|
|
||||||
Ok(())
|
|
||||||
}
|
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod tests {
|
|
||||||
use super::*;
|
|
||||||
#[tokio::test]
|
|
||||||
async fn missing_setting_keeps_auto_and_explicit_pruning_survives_reload() {
|
|
||||||
let dir = tempfile::tempdir().unwrap();
|
|
||||||
assert!(!load(dir.path()).await.unwrap().prune);
|
|
||||||
save(dir.path(), true).await.unwrap();
|
|
||||||
assert!(load(dir.path()).await.unwrap().prune);
|
|
||||||
save(dir.path(), false).await.unwrap();
|
|
||||||
assert!(!load(dir.path()).await.unwrap().prune);
|
|
||||||
}
|
|
||||||
#[tokio::test]
|
|
||||||
async fn corrupt_setting_is_not_silently_changed_to_archival() {
|
|
||||||
let dir = tempfile::tempdir().unwrap();
|
|
||||||
save(dir.path(), true).await.unwrap();
|
|
||||||
tokio::fs::write(dir.path().join("settings/bitcoin-storage.json"), "broken")
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
assert!(load(dir.path()).await.is_err());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -7,5 +7,3 @@
|
|||||||
pub mod ai_permissions;
|
pub mod ai_permissions;
|
||||||
pub mod session_policy;
|
pub mod session_policy;
|
||||||
pub mod transport;
|
pub mod transport;
|
||||||
|
|
||||||
pub mod bitcoin_storage;
|
|
||||||
|
|||||||
@@ -1481,21 +1481,6 @@ pub async fn cancel_download(data_dir: &Path) -> Result<()> {
|
|||||||
/// service unit that inherits systemd's default protections (i.e. none
|
/// service unit that inherits systemd's default protections (i.e. none
|
||||||
/// of ours), escaping the namespace.
|
/// of ours), escaping the namespace.
|
||||||
pub(crate) async fn host_sudo(args: &[&str]) -> Result<std::process::ExitStatus> {
|
pub(crate) async fn host_sudo(args: &[&str]) -> Result<std::process::ExitStatus> {
|
||||||
#[cfg(test)]
|
|
||||||
{
|
|
||||||
anyhow::ensure!(
|
|
||||||
std::env::var("ARCHY_TEST_ISOLATED").as_deref() == Ok("1"),
|
|
||||||
"Host-operation tests require scripts/test-backend-isolated.sh"
|
|
||||||
);
|
|
||||||
let (program, args) = args.split_first().context("Missing test command")?;
|
|
||||||
// Run inside the test namespace, never escape through sudo/systemd-run.
|
|
||||||
return tokio::process::Command::new(program)
|
|
||||||
.args(args)
|
|
||||||
.status()
|
|
||||||
.await
|
|
||||||
.context("isolated test command failed");
|
|
||||||
}
|
|
||||||
|
|
||||||
let mut full: Vec<&str> = vec![
|
let mut full: Vec<&str> = vec![
|
||||||
"systemd-run",
|
"systemd-run",
|
||||||
"--wait",
|
"--wait",
|
||||||
@@ -1520,21 +1505,6 @@ pub(crate) async fn host_sudo(args: &[&str]) -> Result<std::process::ExitStatus>
|
|||||||
/// Same mechanism as `host_sudo` but captures stdout — for read-only probes
|
/// Same mechanism as `host_sudo` but captures stdout — for read-only probes
|
||||||
/// (e.g. `stat`) where the answer is in the output, not the exit status.
|
/// (e.g. `stat`) where the answer is in the output, not the exit status.
|
||||||
pub(crate) async fn host_sudo_output(args: &[&str]) -> Result<std::process::Output> {
|
pub(crate) async fn host_sudo_output(args: &[&str]) -> Result<std::process::Output> {
|
||||||
#[cfg(test)]
|
|
||||||
{
|
|
||||||
anyhow::ensure!(
|
|
||||||
std::env::var("ARCHY_TEST_ISOLATED").as_deref() == Ok("1"),
|
|
||||||
"Host-operation tests require scripts/test-backend-isolated.sh"
|
|
||||||
);
|
|
||||||
let (program, args) = args.split_first().context("Missing test command")?;
|
|
||||||
// Run inside the test namespace, never escape through sudo/systemd-run.
|
|
||||||
return tokio::process::Command::new(program)
|
|
||||||
.args(args)
|
|
||||||
.output()
|
|
||||||
.await
|
|
||||||
.context("isolated test command failed");
|
|
||||||
}
|
|
||||||
|
|
||||||
let mut full: Vec<&str> = vec![
|
let mut full: Vec<&str> = vec![
|
||||||
"systemd-run",
|
"systemd-run",
|
||||||
"--wait",
|
"--wait",
|
||||||
|
|||||||
@@ -489,6 +489,45 @@ pub fn amount_to_denominations(mut amount: u64) -> Vec<u64> {
|
|||||||
mod tests {
|
mod tests {
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
|
/// A v4 (cashuB) token always carries a v2 keyset id in its short
|
||||||
|
/// (8-byte) form — confirmed against the real cashu 0.17.5 crate
|
||||||
|
/// (`TokenV4Token`'s `serialize_v4_keyset_id` unconditionally narrows to
|
||||||
|
/// `ShortKeysetId`) and live against mint.minibits.cash (2026-09-18).
|
||||||
|
/// That is spec-compliant, not a bug here: a receiver MUST resolve the
|
||||||
|
/// short id against the mint's keyset list before spending it (see
|
||||||
|
/// `MintClient::resolve_truncated_keyset_ids`, and its missing call site
|
||||||
|
/// that this exact round trip caught in `ecash.rs`'s payment-receive
|
||||||
|
/// path). This test documents that the short form is what actually
|
||||||
|
/// crosses the wire, so nobody re-"fixes" serialize_v4 to defeat it.
|
||||||
|
#[test]
|
||||||
|
fn v4_round_trip_shortens_a_v2_keyset_id_by_design() {
|
||||||
|
let real_v2_id = "01fc0ec0e59cd6fa01b7a88f8cd77fce81fd1e64bca67d752e984992b7a3c3a821";
|
||||||
|
assert_eq!(real_v2_id.len(), 66);
|
||||||
|
let token = CashuToken {
|
||||||
|
token: vec![TokenEntry {
|
||||||
|
mint: "https://mint.minibits.cash/Bitcoin".to_string(),
|
||||||
|
proofs: vec![Proof {
|
||||||
|
amount: 2,
|
||||||
|
id: real_v2_id.to_string(),
|
||||||
|
secret: "abcdef1234567890".to_string(),
|
||||||
|
// secp256k1 generator point G — a genuinely valid
|
||||||
|
// compressed pubkey (the other tests' placeholder C
|
||||||
|
// value is not, and serialize_v4 is the first path
|
||||||
|
// here that actually parses it).
|
||||||
|
c: "0279be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798"
|
||||||
|
.to_string(),
|
||||||
|
}],
|
||||||
|
}],
|
||||||
|
memo: None,
|
||||||
|
unit: Some("sat".to_string()),
|
||||||
|
};
|
||||||
|
let v4 = token.serialize_v4().expect("serialize_v4 should accept a real v2 id");
|
||||||
|
let decoded = CashuToken::deserialize(&v4).unwrap();
|
||||||
|
let got_id = &decoded.token[0].proofs[0].id;
|
||||||
|
assert_eq!(got_id, "01fc0ec0e59cd6fa", "expected the short (8-byte) v2 form on the wire");
|
||||||
|
assert!(is_truncated_v2_keyset_id(got_id));
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_serialize_deserialize_roundtrip() {
|
fn test_serialize_deserialize_roundtrip() {
|
||||||
let token = CashuToken {
|
let token = CashuToken {
|
||||||
|
|||||||
@@ -775,9 +775,7 @@ pub async fn send_token_at(data_dir: &Path, mint_url: &str, amount_sats: u64) ->
|
|||||||
let mut all_target: Vec<u64> = send_denoms.clone();
|
let mut all_target: Vec<u64> = send_denoms.clone();
|
||||||
all_target.extend(&change_denoms);
|
all_target.extend(&change_denoms);
|
||||||
|
|
||||||
let swap_result = client
|
let swap_result = client.swap(&selected_proofs, &all_target).await?;
|
||||||
.swap_at_least(&selected_proofs, &all_target, amount_sats)
|
|
||||||
.await?;
|
|
||||||
|
|
||||||
// Mark original proofs as spent
|
// Mark original proofs as spent
|
||||||
wallet.mark_spent(&indices);
|
wallet.mark_spent(&indices);
|
||||||
@@ -1194,11 +1192,7 @@ pub async fn receive_token(data_dir: &Path, token_str: &str) -> Result<u64> {
|
|||||||
// Verify all mints in the token are accepted
|
// Verify all mints in the token are accepted
|
||||||
let accepted = load_accepted_mints(data_dir).await?;
|
let accepted = load_accepted_mints(data_dir).await?;
|
||||||
for mint_url in token.mint_urls() {
|
for mint_url in token.mint_urls() {
|
||||||
if !accepted
|
if !accepted.mints.iter().any(|m| m == mint_url) {
|
||||||
.mints
|
|
||||||
.iter()
|
|
||||||
.any(|m| m.trim_end_matches('/') == mint_url.trim_end_matches('/'))
|
|
||||||
{
|
|
||||||
anyhow::bail!("Mint '{}' is not in accepted mints list", mint_url);
|
anyhow::bail!("Mint '{}' is not in accepted mints list", mint_url);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1223,7 +1217,7 @@ pub async fn receive_token(data_dir: &Path, token_str: &str) -> Result<u64> {
|
|||||||
received_total += amount;
|
received_total += amount;
|
||||||
}
|
}
|
||||||
Err(e) => {
|
Err(e) => {
|
||||||
warn!("Failed to swap proofs from mint {}: {}", entry.mint, e);
|
warn!("Failed to swap proofs from mint {}: {:#}", entry.mint, e);
|
||||||
all_already_redeemed &= e.is::<super::mint_client::AlreadyRedeemed>();
|
all_already_redeemed &= e.is::<super::mint_client::AlreadyRedeemed>();
|
||||||
last_reason = Some(e.to_string());
|
last_reason = Some(e.to_string());
|
||||||
// Continue with other mints if any
|
// Continue with other mints if any
|
||||||
@@ -1304,10 +1298,22 @@ pub async fn verify_and_receive_payment(
|
|||||||
token_str: &str,
|
token_str: &str,
|
||||||
required_sats: u64,
|
required_sats: u64,
|
||||||
) -> Result<u64> {
|
) -> Result<u64> {
|
||||||
let token_str = token_str.trim();
|
// Handle legacy tokens
|
||||||
// Synthetic legacy balances are not cryptographic proof of payment.
|
|
||||||
if token_str.starts_with("cashuSend_") {
|
if token_str.starts_with("cashuSend_") {
|
||||||
anyhow::bail!("Legacy ecash cannot authorize a paid download");
|
let amount = token_str
|
||||||
|
.split('_')
|
||||||
|
.nth(1)
|
||||||
|
.and_then(|s| s.parse::<u64>().ok())
|
||||||
|
.unwrap_or(0);
|
||||||
|
if amount < required_sats {
|
||||||
|
anyhow::bail!(
|
||||||
|
"Insufficient payment: {} sats, need {} sats",
|
||||||
|
amount,
|
||||||
|
required_sats
|
||||||
|
);
|
||||||
|
}
|
||||||
|
let received = receive_legacy_token(data_dir, token_str).await?;
|
||||||
|
return Ok(received);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Fedimint notes (#3): a buyer whose balance is in Fedimint pays with notes
|
// Fedimint notes (#3): a buyer whose balance is in Fedimint pays with notes
|
||||||
@@ -1330,45 +1336,67 @@ pub async fn verify_and_receive_payment(
|
|||||||
|
|
||||||
// Parse and validate the token (cashuA or cashuB)
|
// Parse and validate the token (cashuA or cashuB)
|
||||||
let token = CashuToken::deserialize(token_str)?;
|
let token = CashuToken::deserialize(token_str)?;
|
||||||
if token.unit.as_deref().unwrap_or("sat") != "sat" {
|
let total = token.total_amount();
|
||||||
anyhow::bail!("Payment must be denominated in sats");
|
|
||||||
}
|
|
||||||
// A sale must redeem atomically at one mint. Otherwise a later mint
|
|
||||||
// failure can consume earlier inputs without delivering the purchase.
|
|
||||||
let entry = match token.token.as_slice() {
|
|
||||||
[entry] => entry,
|
|
||||||
_ => anyhow::bail!("Use a single-mint token for this payment"),
|
|
||||||
};
|
|
||||||
let total = entry
|
|
||||||
.proofs
|
|
||||||
.iter()
|
|
||||||
.try_fold(0u64, |sum, p| sum.checked_add(p.amount))
|
|
||||||
.ok_or_else(|| anyhow::anyhow!("Payment amount overflow"))?;
|
|
||||||
if total < required_sats {
|
if total < required_sats {
|
||||||
anyhow::bail!("Insufficient payment: {total} sats, need {required_sats} sats");
|
anyhow::bail!(
|
||||||
}
|
"Insufficient payment: {} sats, need {} sats",
|
||||||
let accepted = load_accepted_mints(data_dir).await?;
|
total,
|
||||||
if !accepted
|
required_sats
|
||||||
.mints
|
);
|
||||||
.iter()
|
|
||||||
.any(|m| m.trim_end_matches('/') == entry.mint.trim_end_matches('/'))
|
|
||||||
{
|
|
||||||
anyhow::bail!("Mint is not in the seller's accepted mints list");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
let client = mint_client(data_dir, &entry.mint).await?;
|
// Verify mints are accepted
|
||||||
let result = client
|
let accepted = load_accepted_mints(data_dir).await?;
|
||||||
.swap_at_least(
|
for mint_url in token.mint_urls() {
|
||||||
&entry.proofs,
|
if !accepted.mints.iter().any(|m| m == mint_url) {
|
||||||
&amount_to_denominations(total),
|
anyhow::bail!("Mint '{}' not accepted", mint_url);
|
||||||
required_sats,
|
}
|
||||||
)
|
}
|
||||||
.await?;
|
|
||||||
let received_total = result.new_proofs.iter().map(|p| p.amount).sum();
|
// Swap proofs at mint (this verifies they're unspent and gives us fresh proofs)
|
||||||
// Load after the network call, so an unrelated wallet update during the
|
|
||||||
// swap is not overwritten with a pre-swap snapshot.
|
|
||||||
let mut wallet = load_wallet(data_dir).await?;
|
let mut wallet = load_wallet(data_dir).await?;
|
||||||
wallet.add_proofs(entry.mint.trim_end_matches('/'), result.new_proofs);
|
let mut received_total = 0u64;
|
||||||
|
|
||||||
|
for entry in &token.token {
|
||||||
|
let client = mint_client(data_dir, &entry.mint).await?;
|
||||||
|
let entry_total: u64 = entry.proofs.iter().map(|p| p.amount).sum();
|
||||||
|
let target_amounts = amount_to_denominations(entry_total);
|
||||||
|
|
||||||
|
// The reference cashu crate's V4 (cashuB) encoder always writes a
|
||||||
|
// NUT-02 v2 keyset id in its short (8-byte) form — confirmed live
|
||||||
|
// against mint.minibits.cash (2026-09-18): every cashuB payment
|
||||||
|
// carrying that mint's active v2 keyset failed verification with a
|
||||||
|
// bare 422 "NUT02: ID length invalid" because this call skipped
|
||||||
|
// straight to swap() with the short id still attached. MintClient's
|
||||||
|
// own receive_token() already resolves this correctly; this is the
|
||||||
|
// same fix, just not routed through it (the loop here also tracks
|
||||||
|
// received_total/mint-scoped errors that receive_token() doesn't).
|
||||||
|
let proofs = client.resolve_truncated_keyset_ids(&entry.proofs).await;
|
||||||
|
|
||||||
|
match client.swap(&proofs, &target_amounts).await {
|
||||||
|
Ok(result) => {
|
||||||
|
let amount: u64 = result.new_proofs.iter().map(|p| p.amount).sum();
|
||||||
|
wallet.add_proofs(&entry.mint, result.new_proofs);
|
||||||
|
received_total += amount;
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
// {:#} walks the full anyhow context chain, including the raw
|
||||||
|
// mint response body `mint_error()` attaches as the cause —
|
||||||
|
// {} prints only the friendly top-level message and silently
|
||||||
|
// discards the one thing that would explain a bare 422.
|
||||||
|
warn!("Payment verification failed at mint {}: {:#}", entry.mint, e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if received_total < required_sats {
|
||||||
|
anyhow::bail!(
|
||||||
|
"Payment verification failed: only {} of {} sats verified",
|
||||||
|
received_total,
|
||||||
|
required_sats
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
wallet.record_tx(
|
wallet.record_tx(
|
||||||
TransactionType::Receive,
|
TransactionType::Receive,
|
||||||
@@ -2452,7 +2480,3 @@ mod tests {
|
|||||||
assert_eq!(w.mint_url, "https://mint.minibits.cash/Bitcoin");
|
assert_eq!(w.mint_url, "https://mint.minibits.cash/Bitcoin");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
#[path = "payment_tests.rs"]
|
|
||||||
mod payment_tests;
|
|
||||||
|
|||||||
@@ -114,27 +114,68 @@ fn describe_mint_error_code(code: i64) -> Option<&'static str> {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Render a FastAPI-style validation error list — `detail` as an array of
|
||||||
|
/// `{"loc": [...], "msg": "...", "type": "..."}` objects — into one line per
|
||||||
|
/// entry. This is the shape FastAPI (and therefore most Cashu mint
|
||||||
|
/// implementations, including Nutshell) actually sends for a 422, not the
|
||||||
|
/// plain string the rest of this file otherwise expects; without this a
|
||||||
|
/// mint's real reason (e.g. `body -> inputs -> 0 -> id: NUT02: ID length
|
||||||
|
/// invalid`) was silently replaced with "no further detail".
|
||||||
|
fn describe_validation_errors(detail: &serde_json::Value) -> Option<String> {
|
||||||
|
let items = detail.as_array()?;
|
||||||
|
if items.is_empty() {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
let lines: Vec<String> = items
|
||||||
|
.iter()
|
||||||
|
.filter_map(|item| {
|
||||||
|
let msg = item.get("msg").and_then(|m| m.as_str())?;
|
||||||
|
let loc = item
|
||||||
|
.get("loc")
|
||||||
|
.and_then(|l| l.as_array())
|
||||||
|
.map(|parts| {
|
||||||
|
parts
|
||||||
|
.iter()
|
||||||
|
.map(|p| p.as_str().map(str::to_string).unwrap_or_else(|| p.to_string()))
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join(" -> ")
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
Some(if loc.is_empty() {
|
||||||
|
msg.to_string()
|
||||||
|
} else {
|
||||||
|
format!("{loc}: {msg}")
|
||||||
|
})
|
||||||
|
})
|
||||||
|
.collect();
|
||||||
|
(!lines.is_empty()).then(|| lines.join("; "))
|
||||||
|
}
|
||||||
|
|
||||||
/// Parse a mint's error body (`{"code": N, "detail": "..."}`) and pick the
|
/// Parse a mint's error body (`{"code": N, "detail": "..."}`) and pick the
|
||||||
/// best user-facing message: the plain-language translation when we know the
|
/// best user-facing message: the plain-language translation when we know the
|
||||||
/// code, otherwise the mint's own `detail` text, otherwise the raw body.
|
/// code, otherwise the mint's own `detail` text (a plain string, or a
|
||||||
|
/// FastAPI-style validation-error array), otherwise the raw body.
|
||||||
fn describe_mint_error_body(status: reqwest::StatusCode, body: &str) -> String {
|
fn describe_mint_error_body(status: reqwest::StatusCode, body: &str) -> String {
|
||||||
let parsed: Option<serde_json::Value> = serde_json::from_str(body).ok();
|
let parsed: Option<serde_json::Value> = serde_json::from_str(body).ok();
|
||||||
let code = parsed
|
let code = parsed
|
||||||
.as_ref()
|
.as_ref()
|
||||||
.and_then(|v| v.get("code"))
|
.and_then(|v| v.get("code"))
|
||||||
.and_then(|c| c.as_i64());
|
.and_then(|c| c.as_i64());
|
||||||
let detail = parsed
|
let detail = parsed.as_ref().and_then(|v| v.get("detail"));
|
||||||
.as_ref()
|
|
||||||
.and_then(|v| v.get("detail"))
|
|
||||||
.and_then(|d| d.as_str());
|
|
||||||
|
|
||||||
if let Some(friendly) = code.and_then(describe_mint_error_code) {
|
if let Some(friendly) = code.and_then(describe_mint_error_code) {
|
||||||
return friendly.to_string();
|
return friendly.to_string();
|
||||||
}
|
}
|
||||||
match detail {
|
if let Some(d) = detail {
|
||||||
Some(d) if !d.is_empty() => d.to_string(),
|
if let Some(s) = d.as_str() {
|
||||||
_ => format!("mint returned {} with no further detail", status),
|
if !s.is_empty() {
|
||||||
|
return s.to_string();
|
||||||
|
}
|
||||||
|
} else if let Some(rendered) = describe_validation_errors(d) {
|
||||||
|
return rendered;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
format!("mint returned {} with no further detail", status)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Build the error for a failed mint HTTP call: `op` + status + raw body as
|
/// Build the error for a failed mint HTTP call: `op` + status + raw body as
|
||||||
@@ -153,20 +194,6 @@ fn mint_error(op: &str, status: reqwest::StatusCode, body: &str) -> anyhow::Erro
|
|||||||
cause.context(describe_mint_error_body(status, body))
|
cause.context(describe_mint_error_body(status, body))
|
||||||
}
|
}
|
||||||
|
|
||||||
fn fee_adjusted_targets(requested: &[u64], mut available: u64) -> Vec<u64> {
|
|
||||||
let mut outputs = Vec::new();
|
|
||||||
for &amount in requested {
|
|
||||||
if available >= amount {
|
|
||||||
outputs.push(amount);
|
|
||||||
available -= amount;
|
|
||||||
} else {
|
|
||||||
outputs.extend(amount_to_denominations(available));
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
outputs
|
|
||||||
}
|
|
||||||
|
|
||||||
/// HTTP client for a single Cashu mint.
|
/// HTTP client for a single Cashu mint.
|
||||||
pub struct MintClient {
|
pub struct MintClient {
|
||||||
url: String,
|
url: String,
|
||||||
@@ -526,21 +553,6 @@ impl MintClient {
|
|||||||
/// Swap proofs for new proofs of different denominations.
|
/// Swap proofs for new proofs of different denominations.
|
||||||
/// This is how we "receive" a token — swap it for fresh proofs that only we know.
|
/// This is how we "receive" a token — swap it for fresh proofs that only we know.
|
||||||
pub async fn swap(&self, inputs: &[Proof], target_amounts: &[u64]) -> Result<SwapResult> {
|
pub async fn swap(&self, inputs: &[Proof], target_amounts: &[u64]) -> Result<SwapResult> {
|
||||||
self.swap_at_least(inputs, target_amounts, 0).await
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Refuse a payment whose mint fees would leave the seller underpaid,
|
|
||||||
/// before consuming any input proofs.
|
|
||||||
pub async fn swap_at_least(
|
|
||||||
&self,
|
|
||||||
inputs: &[Proof],
|
|
||||||
target_amounts: &[u64],
|
|
||||||
minimum: u64,
|
|
||||||
) -> Result<SwapResult> {
|
|
||||||
// V4 tokens carry short keyset IDs. Every swap path (including paid
|
|
||||||
// files and streams) must expand these, not only wallet imports.
|
|
||||||
let resolved = self.resolve_truncated_keyset_ids(inputs).await?;
|
|
||||||
let inputs = resolved.as_slice();
|
|
||||||
let keyset = self.get_active_sat_keyset().await?;
|
let keyset = self.get_active_sat_keyset().await?;
|
||||||
|
|
||||||
// NUT-02: a mint may charge a per-input fee, and it rejects the swap
|
// NUT-02: a mint may charge a per-input fee, and it rejects the swap
|
||||||
@@ -548,35 +560,16 @@ impl MintClient {
|
|||||||
// should equal outputs less fee`). Applied here rather than at each
|
// should equal outputs less fee`). Applied here rather than at each
|
||||||
// call site so send, receive and cross-mint swaps are all covered.
|
// call site so send, receive and cross-mint swaps are all covered.
|
||||||
// Fee-free mints (Minibits) compute 0 and are unaffected.
|
// Fee-free mints (Minibits) compute 0 and are unaffected.
|
||||||
anyhow::ensure!(!inputs.is_empty(), "No input proofs to swap");
|
let inputs_total: u64 = inputs.iter().map(|p| p.amount).sum();
|
||||||
let inputs_total = inputs
|
let fee = match self.get_keysets().await {
|
||||||
.iter()
|
Ok(ks) => super::cashu::swap_fee_for(inputs, &ks),
|
||||||
.try_fold(0u64, |sum, p| sum.checked_add(p.amount))
|
Err(e) => {
|
||||||
.context("Input amount overflow")?;
|
debug!("Could not read keyset fees ({e:#}) — assuming fee-free mint");
|
||||||
let keysets = self.get_keysets().await?;
|
0
|
||||||
let mut fee_ppk = 0u64;
|
}
|
||||||
for proof in inputs {
|
};
|
||||||
let input_keyset = keysets
|
|
||||||
.iter()
|
|
||||||
.find(|k| k.id == proof.id)
|
|
||||||
.context("The mint does not recognize an input keyset")?;
|
|
||||||
anyhow::ensure!(
|
|
||||||
input_keyset.unit == "sat",
|
|
||||||
"Input keyset is not denominated in sats"
|
|
||||||
);
|
|
||||||
fee_ppk = fee_ppk
|
|
||||||
.checked_add(input_keyset.input_fee_ppk)
|
|
||||||
.context("Mint fee overflow")?;
|
|
||||||
}
|
|
||||||
let fee = fee_ppk.div_ceil(1000);
|
|
||||||
let spendable = inputs_total.saturating_sub(fee);
|
let spendable = inputs_total.saturating_sub(fee);
|
||||||
if spendable < minimum {
|
let requested: u64 = target_amounts.iter().sum();
|
||||||
anyhow::bail!("Payment would leave {spendable} sats after mint fees; need {minimum} sats. No proofs were redeemed.");
|
|
||||||
}
|
|
||||||
let requested = target_amounts
|
|
||||||
.iter()
|
|
||||||
.try_fold(0u64, |sum, amount| sum.checked_add(*amount))
|
|
||||||
.context("Output amount overflow")?;
|
|
||||||
let owned_targets: Vec<u64>;
|
let owned_targets: Vec<u64>;
|
||||||
let target_amounts: &[u64] = if requested > spendable {
|
let target_amounts: &[u64] = if requested > spendable {
|
||||||
if spendable == 0 {
|
if spendable == 0 {
|
||||||
@@ -587,10 +580,7 @@ impl MintClient {
|
|||||||
debug!(
|
debug!(
|
||||||
"Reducing swap outputs {requested} -> {spendable} to cover a {fee} sat mint fee"
|
"Reducing swap outputs {requested} -> {spendable} to cover a {fee} sat mint fee"
|
||||||
);
|
);
|
||||||
// Callers put payment outputs before change. Keep that prefix
|
owned_targets = amount_to_denominations(spendable);
|
||||||
// intact while fees reduce change; re-splitting the entire sum
|
|
||||||
// can omit a payment denomination after consuming the inputs.
|
|
||||||
owned_targets = fee_adjusted_targets(target_amounts, spendable);
|
|
||||||
&owned_targets
|
&owned_targets
|
||||||
} else {
|
} else {
|
||||||
target_amounts
|
target_amounts
|
||||||
@@ -635,9 +625,6 @@ impl MintClient {
|
|||||||
|
|
||||||
let mut new_proofs = Vec::new();
|
let mut new_proofs = Vec::new();
|
||||||
for (sig, (secret, r, amount)) in signatures.iter().zip(blinding_data.iter()) {
|
for (sig, (secret, r, amount)) in signatures.iter().zip(blinding_data.iter()) {
|
||||||
if sig.amount != *amount || sig.id != keyset.id {
|
|
||||||
anyhow::bail!("Mint returned a swap signature for an unexpected amount or keyset");
|
|
||||||
}
|
|
||||||
let c_prime = sig.c_prime_as_pubkey()?;
|
let c_prime = sig.c_prime_as_pubkey()?;
|
||||||
let mint_key = keyset.key_for_amount(*amount)?;
|
let mint_key = keyset.key_for_amount(*amount)?;
|
||||||
let c = bdhke::unblind_signature(&c_prime, r, &mint_key)?;
|
let c = bdhke::unblind_signature(&c_prime, r, &mint_key)?;
|
||||||
@@ -784,35 +771,43 @@ impl MintClient {
|
|||||||
/// Repair proofs whose keyset id is a truncated NUT-02 **v2** id.
|
/// Repair proofs whose keyset id is a truncated NUT-02 **v2** id.
|
||||||
///
|
///
|
||||||
/// A v2 keyset id is 33 bytes (version byte `0x01` + 32-byte hash), but
|
/// A v2 keyset id is 33 bytes (version byte `0x01` + 32-byte hash), but
|
||||||
/// compact V4 tokens carry an 8-byte short ID. The swap endpoint needs
|
/// wallets written against the original 8-byte format truncate it when
|
||||||
/// the full ID restored from the mint's keyset list. The mint then reads the `0x01` version, expects 33
|
/// they build a token. The mint then reads the `0x01` version, expects 33
|
||||||
/// bytes, and rejects the swap — reported as
|
/// bytes, and rejects the swap — reported as
|
||||||
/// `inputs[0].id: NUT02: ID length invalid` behind a bare 422 (seen with
|
/// `inputs[0].id: NUT02: ID length invalid` behind a bare 422 (seen with
|
||||||
/// a Minibits-issued token, 2026-08-17).
|
/// a Minibits-issued token, 2026-08-17).
|
||||||
///
|
///
|
||||||
/// The id only names which keyset signed the proof, so restoring the full
|
/// The id only names which keyset signed the proof, so restoring the full
|
||||||
/// id the mint advertises is exactly what the sender meant. It is also
|
/// id the mint advertises is exactly what the sender meant. It is also
|
||||||
/// safe to attempt: the mint still verifies the proof signature. Unknown
|
/// safe to attempt: an id that names the wrong keyset fails signature
|
||||||
/// or ambiguous short IDs are rejected before redemption.
|
/// verification at the mint and no coins move. Anything already valid, or
|
||||||
async fn resolve_truncated_keyset_ids(&self, proofs: &[Proof]) -> Result<Vec<Proof>> {
|
/// with no unambiguous match, is passed through untouched so the mint's
|
||||||
|
/// own error is what the operator sees.
|
||||||
|
pub(crate) async fn resolve_truncated_keyset_ids(&self, proofs: &[Proof]) -> Vec<Proof> {
|
||||||
let needs_repair = proofs.iter().any(|p| is_truncated_v2_keyset_id(&p.id));
|
let needs_repair = proofs.iter().any(|p| is_truncated_v2_keyset_id(&p.id));
|
||||||
if !needs_repair {
|
if !needs_repair {
|
||||||
return Ok(proofs.to_vec());
|
return proofs.to_vec();
|
||||||
}
|
}
|
||||||
|
|
||||||
// The mint's own keyset list, in the reference implementation's shape
|
// The mint's own keyset list, in the reference implementation's shape
|
||||||
// so its NUT-02 resolver can consume it directly.
|
// so its NUT-02 resolver can consume it directly.
|
||||||
let known = self.get_cdk_keysets().await?;
|
let known = match self.get_cdk_keysets().await {
|
||||||
|
Ok(k) => k,
|
||||||
|
Err(e) => {
|
||||||
|
debug!("Could not list keysets to repair truncated keyset ids: {e:#}");
|
||||||
|
return proofs.to_vec();
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
proofs
|
proofs
|
||||||
.iter()
|
.iter()
|
||||||
.cloned()
|
.cloned()
|
||||||
.map(|mut p| {
|
.map(|mut p| {
|
||||||
if is_truncated_v2_keyset_id(&p.id) {
|
if let Some(full) = super::cashu::resolve_keyset_id(&p.id, &known) {
|
||||||
p.id = super::cashu::resolve_keyset_id(&p.id, &known)
|
debug!("Expanded short keyset id {} to {} for swap", p.id, full);
|
||||||
.context("The mint cannot resolve this short keyset ID unambiguously")?;
|
p.id = full;
|
||||||
}
|
}
|
||||||
Ok(p)
|
p
|
||||||
})
|
})
|
||||||
.collect()
|
.collect()
|
||||||
}
|
}
|
||||||
@@ -848,7 +843,7 @@ impl MintClient {
|
|||||||
let mut all_new_proofs = Vec::new();
|
let mut all_new_proofs = Vec::new();
|
||||||
|
|
||||||
for entry in &token.token {
|
for entry in &token.token {
|
||||||
if entry.mint.trim_end_matches('/') != self.url {
|
if entry.mint != self.url {
|
||||||
debug!(
|
debug!(
|
||||||
"Skipping proofs from different mint {} (ours: {})",
|
"Skipping proofs from different mint {} (ours: {})",
|
||||||
entry.mint, self.url
|
entry.mint, self.url
|
||||||
@@ -859,7 +854,8 @@ impl MintClient {
|
|||||||
let total: u64 = entry.proofs.iter().map(|p| p.amount).sum();
|
let total: u64 = entry.proofs.iter().map(|p| p.amount).sum();
|
||||||
let target_amounts = amount_to_denominations(total);
|
let target_amounts = amount_to_denominations(total);
|
||||||
|
|
||||||
let result = self.swap(&entry.proofs, &target_amounts).await?;
|
let proofs = self.resolve_truncated_keyset_ids(&entry.proofs).await;
|
||||||
|
let result = self.swap(&proofs, &target_amounts).await?;
|
||||||
all_new_proofs.extend(result.new_proofs);
|
all_new_proofs.extend(result.new_proofs);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -895,6 +891,31 @@ mod tests {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_fastapi_validation_error_array_is_rendered_not_swallowed() {
|
||||||
|
// FastAPI's actual 422 shape — `detail` is a list of
|
||||||
|
// {loc, msg, type}, not the plain string the rest of this file
|
||||||
|
// otherwise expects. Confirmed live against mint.minibits.cash
|
||||||
|
// (2026-09-18): this used to collapse to "mint returned 422
|
||||||
|
// Unprocessable Entity with no further detail", discarding the one
|
||||||
|
// piece of text that actually explains the failure.
|
||||||
|
let body = serde_json::json!({
|
||||||
|
"detail": [
|
||||||
|
{"loc": ["body", "inputs", 0, "id"], "msg": "NUT02: ID length invalid", "type": "value_error"}
|
||||||
|
]
|
||||||
|
})
|
||||||
|
.to_string();
|
||||||
|
let msg = super::describe_mint_error_body(reqwest::StatusCode::UNPROCESSABLE_ENTITY, &body);
|
||||||
|
assert_eq!(msg, "body -> inputs -> 0 -> id: NUT02: ID length invalid");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn an_empty_validation_error_array_falls_back_to_the_generic_message() {
|
||||||
|
let body = serde_json::json!({"detail": []}).to_string();
|
||||||
|
let msg = super::describe_mint_error_body(reqwest::StatusCode::UNPROCESSABLE_ENTITY, &body);
|
||||||
|
assert_eq!(msg, "mint returned 422 Unprocessable Entity with no further detail");
|
||||||
|
}
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
|
|||||||
@@ -1,428 +0,0 @@
|
|||||||
//! Real HTTP/curve-signature regressions for paid Cashu redemption.
|
|
||||||
use super::*;
|
|
||||||
use crate::wallet::{bdhke, cashu::Proof};
|
|
||||||
use bitcoin::secp256k1::{PublicKey, Scalar, Secp256k1, SecretKey};
|
|
||||||
use hyper::{
|
|
||||||
service::{make_service_fn, service_fn},
|
|
||||||
Body, Request, Response, Server,
|
|
||||||
};
|
|
||||||
use serde_json::{json, Value};
|
|
||||||
use std::{
|
|
||||||
convert::Infallible,
|
|
||||||
sync::{Arc, Mutex},
|
|
||||||
};
|
|
||||||
|
|
||||||
const ACTIVE: &str = "0011223344556677";
|
|
||||||
const V2: &str = "011111111111111111111111111111111111111111111111111111111111111111";
|
|
||||||
|
|
||||||
struct Mint {
|
|
||||||
url: String,
|
|
||||||
requests: Arc<Mutex<Vec<Value>>>,
|
|
||||||
task: tokio::task::JoinHandle<()>,
|
|
||||||
failure: Arc<std::sync::atomic::AtomicU16>,
|
|
||||||
}
|
|
||||||
impl Drop for Mint {
|
|
||||||
fn drop(&mut self) {
|
|
||||||
self.task.abort();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fn signing_key() -> SecretKey {
|
|
||||||
SecretKey::from_slice(&[7; 32]).unwrap()
|
|
||||||
}
|
|
||||||
fn signed_point(point: PublicKey) -> String {
|
|
||||||
point
|
|
||||||
.mul_tweak(&Secp256k1::new(), &Scalar::from(signing_key()))
|
|
||||||
.unwrap()
|
|
||||||
.to_string()
|
|
||||||
}
|
|
||||||
fn proof(id: &str, amount: u64) -> Proof {
|
|
||||||
let secret = format!("test-{id}-{amount}");
|
|
||||||
Proof {
|
|
||||||
amount,
|
|
||||||
id: id.into(),
|
|
||||||
c: signed_point(bdhke::hash_to_curve(secret.as_bytes()).unwrap()),
|
|
||||||
secret,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
impl Mint {
|
|
||||||
async fn start(fee: u64, failure: Option<u16>) -> Self {
|
|
||||||
let listener = std::net::TcpListener::bind("127.0.0.1:0").unwrap();
|
|
||||||
listener.set_nonblocking(true).unwrap();
|
|
||||||
let url = format!("http://{}", listener.local_addr().unwrap());
|
|
||||||
let requests = Arc::new(Mutex::new(Vec::new()));
|
|
||||||
let seen = requests.clone();
|
|
||||||
let failure = Arc::new(std::sync::atomic::AtomicU16::new(failure.unwrap_or(0)));
|
|
||||||
let rejection = failure.clone();
|
|
||||||
let spent = Arc::new(Mutex::new(std::collections::HashSet::<String>::new()));
|
|
||||||
let service = make_service_fn(move |_| {
|
|
||||||
let seen = seen.clone();
|
|
||||||
let rejection = rejection.clone();
|
|
||||||
let spent = spent.clone();
|
|
||||||
async move {
|
|
||||||
Ok::<_, Infallible>(service_fn(move |req: Request<Body>| {
|
|
||||||
let seen = seen.clone();
|
|
||||||
let rejection = rejection.clone();
|
|
||||||
let spent = spent.clone();
|
|
||||||
async move {
|
|
||||||
let mut status = 200;
|
|
||||||
let body = match req.uri().path() {
|
|
||||||
"/v1/keysets" => json!({"keysets":[
|
|
||||||
{"id": ACTIVE,"unit":"sat","active":true,"input_fee_ppk":fee},
|
|
||||||
{"id": V2,"unit":"sat","active":false,"input_fee_ppk":fee}
|
|
||||||
]}),
|
|
||||||
"/v1/keys" => {
|
|
||||||
let public =
|
|
||||||
PublicKey::from_secret_key(&Secp256k1::new(), &signing_key())
|
|
||||||
.to_string();
|
|
||||||
let keys: serde_json::Map<String, Value> = (0..16)
|
|
||||||
.map(|i| ((1u64 << i).to_string(), json!(public)))
|
|
||||||
.collect();
|
|
||||||
json!({"keysets":[{"id": ACTIVE,"unit":"sat","keys":keys}]})
|
|
||||||
}
|
|
||||||
"/v1/swap" => {
|
|
||||||
let body: Value = serde_json::from_slice(
|
|
||||||
&hyper::body::to_bytes(req.into_body()).await.unwrap(),
|
|
||||||
)
|
|
||||||
.unwrap();
|
|
||||||
seen.lock().unwrap().push(body.clone());
|
|
||||||
let inputs = body["inputs"].as_array().unwrap();
|
|
||||||
let outputs = body["outputs"].as_array().unwrap();
|
|
||||||
let code = rejection.load(std::sync::atomic::Ordering::SeqCst);
|
|
||||||
if code != 0 {
|
|
||||||
status = code;
|
|
||||||
json!({"detail":"mock mint rejection"})
|
|
||||||
} else if inputs.iter().any(|p| p["id"] != V2 && p["id"] != ACTIVE)
|
|
||||||
{
|
|
||||||
status = 422;
|
|
||||||
json!({"detail":[{"msg":"NUT02: ID length invalid"}]})
|
|
||||||
} else if inputs.iter().any(|p| {
|
|
||||||
spent
|
|
||||||
.lock()
|
|
||||||
.unwrap()
|
|
||||||
.contains(p["secret"].as_str().unwrap())
|
|
||||||
}) {
|
|
||||||
status = 400;
|
|
||||||
json!({"code":11001,"detail":"Token Already Spent"})
|
|
||||||
} else {
|
|
||||||
let total: u64 =
|
|
||||||
inputs.iter().map(|p| p["amount"].as_u64().unwrap()).sum();
|
|
||||||
let out: u64 =
|
|
||||||
outputs.iter().map(|p| p["amount"].as_u64().unwrap()).sum();
|
|
||||||
assert_eq!(
|
|
||||||
out,
|
|
||||||
total - (inputs.len() as u64 * fee).div_ceil(1000)
|
|
||||||
);
|
|
||||||
for p in inputs {
|
|
||||||
spent
|
|
||||||
.lock()
|
|
||||||
.unwrap()
|
|
||||||
.insert(p["secret"].as_str().unwrap().into());
|
|
||||||
}
|
|
||||||
json!({"signatures":outputs.iter().map(|o| json!({
|
|
||||||
"amount":o["amount"],"id":ACTIVE,
|
|
||||||
"C_":signed_point(o["B_"].as_str().unwrap().parse().unwrap())
|
|
||||||
})).collect::<Vec<_>>()})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
_ => {
|
|
||||||
status = 404;
|
|
||||||
json!({})
|
|
||||||
}
|
|
||||||
};
|
|
||||||
Ok::<_, Infallible>(
|
|
||||||
Response::builder()
|
|
||||||
.status(status)
|
|
||||||
.header("Content-Type", "application/json")
|
|
||||||
.body(Body::from(body.to_string()))
|
|
||||||
.unwrap(),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
}
|
|
||||||
});
|
|
||||||
let server = Server::from_tcp(listener).unwrap().serve(service);
|
|
||||||
let task = tokio::spawn(async move {
|
|
||||||
server.await.unwrap();
|
|
||||||
});
|
|
||||||
Self {
|
|
||||||
url,
|
|
||||||
requests,
|
|
||||||
task,
|
|
||||||
failure,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
async fn wallet(&self) -> tempfile::TempDir {
|
|
||||||
let dir = tempfile::tempdir().unwrap();
|
|
||||||
save_accepted_mints(
|
|
||||||
dir.path(),
|
|
||||||
&AcceptedMints {
|
|
||||||
mints: vec![format!("{}/", self.url)],
|
|
||||||
},
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
dir
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn paid_v4_inactive_v2_keyset_is_expanded_and_cryptographic_proofs_saved() {
|
|
||||||
let mint = Mint::start(0, None).await;
|
|
||||||
let dir = mint.wallet().await;
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(V2, 64), proof(V2, 32), proof(V2, 4)])
|
|
||||||
.serialize_v4()
|
|
||||||
.unwrap();
|
|
||||||
let decoded = CashuToken::deserialize(&token).unwrap();
|
|
||||||
assert_eq!(
|
|
||||||
decoded.token[0].proofs[0].id.len(),
|
|
||||||
16,
|
|
||||||
"reproduce the short V4 ID"
|
|
||||||
);
|
|
||||||
assert_eq!(
|
|
||||||
verify_and_receive_payment(dir.path(), &token, 100)
|
|
||||||
.await
|
|
||||||
.unwrap(),
|
|
||||||
100
|
|
||||||
);
|
|
||||||
let wallet = load_wallet(dir.path()).await.unwrap();
|
|
||||||
assert_eq!(wallet.balance(), 100);
|
|
||||||
for p in wallet.proofs {
|
|
||||||
assert_eq!(
|
|
||||||
p.proof.c,
|
|
||||||
signed_point(bdhke::hash_to_curve(p.proof.secret.as_bytes()).unwrap())
|
|
||||||
);
|
|
||||||
}
|
|
||||||
assert!(mint.requests.lock().unwrap()[0]["inputs"]
|
|
||||||
.as_array()
|
|
||||||
.unwrap()
|
|
||||||
.iter()
|
|
||||||
.all(|p| p["id"] == V2));
|
|
||||||
assert!(verify_and_receive_payment(dir.path(), &token, 100)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
assert_eq!(load_wallet(dir.path()).await.unwrap().balance(), 100);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn paid_v3_full_v2_and_v1_ids_work() {
|
|
||||||
for id in [V2, ACTIVE] {
|
|
||||||
let mint = Mint::start(0, None).await;
|
|
||||||
let dir = mint.wallet().await;
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(id, 128)])
|
|
||||||
.serialize()
|
|
||||||
.unwrap();
|
|
||||||
assert_eq!(
|
|
||||||
verify_and_receive_payment(dir.path(), &token, 100)
|
|
||||||
.await
|
|
||||||
.unwrap(),
|
|
||||||
128
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn fees_cannot_consume_underpayment_and_allowed_fees_credit_actual_value() {
|
|
||||||
let mint = Mint::start(1000, None).await;
|
|
||||||
let dir = mint.wallet().await;
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(V2, 128)])
|
|
||||||
.serialize_v4()
|
|
||||||
.unwrap();
|
|
||||||
assert!(verify_and_receive_payment(dir.path(), &token, 128)
|
|
||||||
.await
|
|
||||||
.unwrap_err()
|
|
||||||
.to_string()
|
|
||||||
.contains("after mint fees"));
|
|
||||||
assert!(mint.requests.lock().unwrap().is_empty());
|
|
||||||
assert_eq!(
|
|
||||||
verify_and_receive_payment(dir.path(), &token, 127)
|
|
||||||
.await
|
|
||||||
.unwrap(),
|
|
||||||
127
|
|
||||||
);
|
|
||||||
assert_eq!(load_wallet(dir.path()).await.unwrap().balance(), 127);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn rejected_mint_response_does_not_credit_wallet() {
|
|
||||||
for status in [200, 400, 422, 500, 503] {
|
|
||||||
let mint = Mint::start(0, Some(status)).await;
|
|
||||||
let dir = mint.wallet().await;
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(V2, 128)])
|
|
||||||
.serialize_v4()
|
|
||||||
.unwrap();
|
|
||||||
assert!(verify_and_receive_payment(dir.path(), &token, 100)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
assert_eq!(load_wallet(dir.path()).await.unwrap().balance(), 0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn invalid_untrusted_multimint_and_underpaid_tokens_never_reach_swap() {
|
|
||||||
let mint = Mint::start(0, None).await;
|
|
||||||
let dir = mint.wallet().await;
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(V2, 128)]);
|
|
||||||
let mut invalid = vec![
|
|
||||||
"cashuSend_500_abc_1700000000".into(),
|
|
||||||
"cashuBinvalid".into(),
|
|
||||||
];
|
|
||||||
let mut wrong_unit = token.clone();
|
|
||||||
wrong_unit.unit = Some("usd".into());
|
|
||||||
invalid.push(wrong_unit.serialize().unwrap());
|
|
||||||
let mut multi = token.clone();
|
|
||||||
multi.token.push(token.token[0].clone());
|
|
||||||
invalid.push(multi.serialize().unwrap());
|
|
||||||
let mut untrusted = token.clone();
|
|
||||||
untrusted.token[0].mint = "http://127.0.0.1:1".into();
|
|
||||||
invalid.push(untrusted.serialize().unwrap());
|
|
||||||
for id in ["00ffffffffffffff", "01ffffffffffffff"] {
|
|
||||||
invalid.push(
|
|
||||||
CashuToken::new(&mint.url, vec![proof(id, 128)])
|
|
||||||
.serialize()
|
|
||||||
.unwrap(),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
for value in invalid {
|
|
||||||
assert!(verify_and_receive_payment(dir.path(), &value, 100)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
}
|
|
||||||
assert!(
|
|
||||||
verify_and_receive_payment(dir.path(), &token.serialize().unwrap(), 129)
|
|
||||||
.await
|
|
||||||
.is_err()
|
|
||||||
);
|
|
||||||
assert!(mint.requests.lock().unwrap().is_empty());
|
|
||||||
assert_eq!(load_wallet(dir.path()).await.unwrap().balance(), 0);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn buyer_token_rejected_by_seller_can_be_refunded_without_balance_loss() {
|
|
||||||
let mint = Mint::start(0, Some(422)).await;
|
|
||||||
let buyer = mint.wallet().await;
|
|
||||||
let seller = mint.wallet().await;
|
|
||||||
let mut wallet = load_wallet(buyer.path()).await.unwrap();
|
|
||||||
wallet.mint_url = mint.url.clone();
|
|
||||||
wallet.add_proofs(&mint.url, vec![proof(V2, 64), proof(V2, 32), proof(V2, 4)]);
|
|
||||||
save_wallet(buyer.path(), &wallet).await.unwrap();
|
|
||||||
let token = send_token(buyer.path(), 100).await.unwrap();
|
|
||||||
assert_eq!(load_wallet(buyer.path()).await.unwrap().balance(), 0);
|
|
||||||
assert!(verify_and_receive_payment(seller.path(), &token, 100)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
mint.failure.store(0, std::sync::atomic::Ordering::SeqCst);
|
|
||||||
assert_eq!(receive_token(buyer.path(), &token).await.unwrap(), 100);
|
|
||||||
assert_eq!(load_wallet(buyer.path()).await.unwrap().balance(), 100);
|
|
||||||
assert_eq!(load_wallet(seller.path()).await.unwrap().balance(), 0);
|
|
||||||
assert!(receive_token(buyer.path(), &token).await.is_err());
|
|
||||||
assert_eq!(load_wallet(buyer.path()).await.unwrap().balance(), 100);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn unreachable_mint_does_not_credit_seller() {
|
|
||||||
let mint = Mint::start(0, None).await;
|
|
||||||
let dir = mint.wallet().await;
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(V2, 128)])
|
|
||||||
.serialize_v4()
|
|
||||||
.unwrap();
|
|
||||||
mint.task.abort();
|
|
||||||
tokio::task::yield_now().await;
|
|
||||||
assert!(verify_and_receive_payment(dir.path(), &token, 100)
|
|
||||||
.await
|
|
||||||
.is_err());
|
|
||||||
assert_eq!(load_wallet(dir.path()).await.unwrap().balance(), 0);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn send_with_fees_preserves_payment_denominations_and_saves_change() {
|
|
||||||
// 128 inputs - 2 fee = 126. Splitting 126 as one sum omits 1,
|
|
||||||
// which is needed for a 65-sat payment, after consuming the inputs.
|
|
||||||
let mint = Mint::start(1000, None).await;
|
|
||||||
let buyer = mint.wallet().await;
|
|
||||||
let mut wallet = load_wallet(buyer.path()).await.unwrap();
|
|
||||||
wallet.mint_url = mint.url.clone();
|
|
||||||
let first = proof(V2, 64);
|
|
||||||
let mut second = first.clone();
|
|
||||||
second.secret.push_str("-second");
|
|
||||||
second.c = signed_point(bdhke::hash_to_curve(second.secret.as_bytes()).unwrap());
|
|
||||||
wallet.add_proofs(&mint.url, vec![first, second]);
|
|
||||||
save_wallet(buyer.path(), &wallet).await.unwrap();
|
|
||||||
let encoded = send_token(buyer.path(), 65).await.unwrap();
|
|
||||||
assert_eq!(
|
|
||||||
CashuToken::deserialize(&encoded).unwrap().total_amount(),
|
|
||||||
65
|
|
||||||
);
|
|
||||||
assert_eq!(load_wallet(buyer.path()).await.unwrap().balance(), 61);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn paid_file_gate_delivers_bytes_only_after_payment_and_does_not_charge_missing_files() {
|
|
||||||
use crate::content_server::{
|
|
||||||
self, AccessControl, Availability, ContentCatalog, ContentItem, ServeResult,
|
|
||||||
};
|
|
||||||
for (exists, accepts_cashu, price) in [
|
|
||||||
(true, true, 100),
|
|
||||||
(true, false, 100),
|
|
||||||
(false, true, 100),
|
|
||||||
(true, true, 129),
|
|
||||||
] {
|
|
||||||
let mint = Mint::start(0, None).await;
|
|
||||||
let seller = mint.wallet().await;
|
|
||||||
let item = ContentItem {
|
|
||||||
id: "paid-test".into(),
|
|
||||||
filename: "test.txt".into(),
|
|
||||||
mime_type: "text/plain".into(),
|
|
||||||
size_bytes: 5,
|
|
||||||
description: String::new(),
|
|
||||||
added_at: String::new(),
|
|
||||||
availability: Availability::AllPeers,
|
|
||||||
access: AccessControl::Paid {
|
|
||||||
price_sats: price,
|
|
||||||
accepted: vec![if accepts_cashu { "ecash" } else { "fedimint" }.into()],
|
|
||||||
},
|
|
||||||
};
|
|
||||||
content_server::save_catalog(seller.path(), &ContentCatalog { items: vec![item] })
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
if exists {
|
|
||||||
tokio::fs::create_dir_all(seller.path().join("content/files"))
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
tokio::fs::write(seller.path().join("content/files/test.txt"), b"hello")
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
}
|
|
||||||
let token = CashuToken::new(&mint.url, vec![proof(V2, 128)])
|
|
||||||
.serialize_v4()
|
|
||||||
.unwrap();
|
|
||||||
let result = content_server::serve_content(
|
|
||||||
seller.path(),
|
|
||||||
"paid-test",
|
|
||||||
Some(&token),
|
|
||||||
None,
|
|
||||||
None,
|
|
||||||
None,
|
|
||||||
false,
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
if exists && accepts_cashu && price <= 128 {
|
|
||||||
match result {
|
|
||||||
ServeResult::Ok(bytes, mime) => {
|
|
||||||
assert_eq!(bytes, b"hello");
|
|
||||||
assert_eq!(mime, "text/plain");
|
|
||||||
}
|
|
||||||
_ => panic!("paid content was not delivered"),
|
|
||||||
}
|
|
||||||
assert_eq!(load_wallet(seller.path()).await.unwrap().balance(), 128);
|
|
||||||
} else {
|
|
||||||
assert!(matches!(
|
|
||||||
result,
|
|
||||||
ServeResult::NotFound | ServeResult::PaymentRequired(_)
|
|
||||||
));
|
|
||||||
assert_eq!(load_wallet(seller.path()).await.unwrap().balance(), 0);
|
|
||||||
assert!(mint.requests.lock().unwrap().is_empty());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+18
-60
@@ -989,7 +989,7 @@
|
|||||||
|
|
||||||
// ── State ───────────────────────────────────────────────────────
|
// ── State ───────────────────────────────────────────────────────
|
||||||
let unit = 'sats';
|
let unit = 'sats';
|
||||||
let state = { readiness: null, info: null, channels: [], pending: null, peers: [], payments: [], invoices: [], txns: [], fees: null, graph: null };
|
let state = { info: null, channels: [], pending: null, peers: [], payments: [], invoices: [], txns: [], fees: null, graph: null };
|
||||||
let peerSort = { col: 'peer', dir: 1 };
|
let peerSort = { col: 'peer', dir: 1 };
|
||||||
let activityFilter = 'all';
|
let activityFilter = 'all';
|
||||||
let logsLoaded = false;
|
let logsLoaded = false;
|
||||||
@@ -1142,19 +1142,9 @@
|
|||||||
}
|
}
|
||||||
|
|
||||||
async function refreshAll() {
|
async function refreshAll() {
|
||||||
if (state.refreshing) return;
|
|
||||||
state.refreshing = true;
|
|
||||||
const icon = document.getElementById('refreshIcon');
|
const icon = document.getElementById('refreshIcon');
|
||||||
if (icon) icon.classList.add('animate-spin-slow');
|
if (icon) icon.classList.add('animate-spin-slow');
|
||||||
try {
|
try {
|
||||||
state.readiness = await lndSafe('/archy-status', null);
|
|
||||||
if (state.readiness && state.readiness.state.startsWith('waiting_')) {
|
|
||||||
state.info = null;
|
|
||||||
state.onchainStale = true;
|
|
||||||
state.chanbalStale = true;
|
|
||||||
renderAll();
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const [info, channels, pending, peers, fees, graph, payments, invoices, txns] = await Promise.all([
|
const [info, channels, pending, peers, fees, graph, payments, invoices, txns] = await Promise.all([
|
||||||
lndSafe('/v1/getinfo', null),
|
lndSafe('/v1/getinfo', null),
|
||||||
lndSafe('/v1/channels', { channels: [] }),
|
lndSafe('/v1/channels', { channels: [] }),
|
||||||
@@ -1176,17 +1166,10 @@
|
|||||||
state.invoices = (invoices && invoices.invoices) || [];
|
state.invoices = (invoices && invoices.invoices) || [];
|
||||||
state.txns = (txns && txns.transactions) || [];
|
state.txns = (txns && txns.transactions) || [];
|
||||||
|
|
||||||
// Preserve known balances on outage; never decode an error as zero.
|
// Balances are separate so one failing endpoint can't blank the rest.
|
||||||
const [onchain, chanbal] = await Promise.all([
|
state.onchain = await lndSafe('/v1/balance/blockchain', null);
|
||||||
lndSafe('/v1/balance/blockchain', null),
|
state.chanbal = await lndSafe('/v1/balance/channels', null);
|
||||||
lndSafe('/v1/balance/channels', null),
|
|
||||||
]);
|
|
||||||
state.onchainStale = !validBalance(onchain && (onchain.confirmed_balance ?? onchain.total_balance));
|
|
||||||
state.chanbalStale = !validBalance(chanbal && (chanbal.local_balance?.sat ?? chanbal.balance));
|
|
||||||
if (!state.onchainStale) state.onchain = onchain;
|
|
||||||
if (!state.chanbalStale) state.chanbal = chanbal;
|
|
||||||
} finally {
|
} finally {
|
||||||
state.refreshing = false;
|
|
||||||
if (icon) icon.classList.remove('animate-spin-slow');
|
if (icon) icon.classList.remove('animate-spin-slow');
|
||||||
}
|
}
|
||||||
renderAll();
|
renderAll();
|
||||||
@@ -1209,17 +1192,11 @@
|
|||||||
const pill = document.getElementById('headerStatusPill');
|
const pill = document.getElementById('headerStatusPill');
|
||||||
const dot = document.getElementById('headerStatusDot');
|
const dot = document.getElementById('headerStatusDot');
|
||||||
|
|
||||||
const waiting = state.readiness && state.readiness.state.startsWith('waiting_');
|
if (!g) {
|
||||||
if (!g || waiting) {
|
setText('headerStatusText', 'Unreachable');
|
||||||
setText('headerStatusText', waiting ? state.readiness.message : 'Connecting to LND');
|
pill.className = 'pill bad';
|
||||||
pill.className = 'pill warn';
|
dot.className = 'status-dot-sm bg-red';
|
||||||
dot.className = 'status-dot-sm bg-yellow';
|
document.getElementById('syncCard').style.display = 'none';
|
||||||
document.getElementById('syncCard').style.display = '';
|
|
||||||
setText('syncSubtitle', waiting ? state.readiness.message + '. Lightning will become available automatically.' : 'Checking Lightning availability. Retrying automatically.');
|
|
||||||
setText('syncBlockLabel', '');
|
|
||||||
setText('syncPercent', '');
|
|
||||||
document.getElementById('syncProgressBar').style.width = '0%';
|
|
||||||
for (const id of ['syncChain', 'syncGraph', 'syncHeight', 'syncPeers']) setText(id, '—');
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1260,11 +1237,6 @@
|
|||||||
}
|
}
|
||||||
|
|
||||||
// ── Balances ────────────────────────────────────────────────────
|
// ── Balances ────────────────────────────────────────────────────
|
||||||
function validBalance(value) {
|
|
||||||
return (typeof value === 'number' || (typeof value === 'string' && /^\d+$/.test(value)))
|
|
||||||
&& Number.isSafeInteger(Number(value)) && Number(value) >= 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
function renderBalances() {
|
function renderBalances() {
|
||||||
const onchainConfirmed = num(state.onchain && (state.onchain.confirmed_balance ?? state.onchain.total_balance));
|
const onchainConfirmed = num(state.onchain && (state.onchain.confirmed_balance ?? state.onchain.total_balance));
|
||||||
const onchainUnconfirmed = num(state.onchain && state.onchain.unconfirmed_balance);
|
const onchainUnconfirmed = num(state.onchain && state.onchain.unconfirmed_balance);
|
||||||
@@ -1281,23 +1253,22 @@
|
|||||||
const haveOnchain = !!state.onchain;
|
const haveOnchain = !!state.onchain;
|
||||||
const haveChan = !!cb;
|
const haveChan = !!cb;
|
||||||
|
|
||||||
setBalance('balTotal', haveOnchain && haveChan ? onchainConfirmed + lnLocal : null);
|
setBalance('balTotal', haveOnchain || haveChan ? onchainConfirmed + lnLocal : null);
|
||||||
setText('balTotalSub', state.onchainStale || state.chanbalStale ? 'balance unavailable · last known values' : haveOnchain && haveChan ? 'on-chain + lightning' : 'waiting for LND');
|
setText('balTotalSub', haveOnchain || haveChan ? 'on-chain + lightning' : 'waiting for LND');
|
||||||
setBalance('balLightning', haveChan ? lnLocal : null);
|
setBalance('balLightning', haveChan ? lnLocal : null);
|
||||||
setText('balLightningSub', !haveChan ? 'waiting for LND' : state.chanbalStale ? 'last known balance'
|
setText('balLightningSub', !haveChan ? 'waiting for LND'
|
||||||
: lnPending > 0 ? fmtAmount(lnPending) + ' pending open' : 'spendable over channels');
|
: lnPending > 0 ? fmtAmount(lnPending) + ' pending open' : 'spendable over channels');
|
||||||
setBalance('balOnchain', haveOnchain ? onchainConfirmed : null);
|
setBalance('balOnchain', haveOnchain ? onchainConfirmed : null);
|
||||||
setText('balOnchainSub', !haveOnchain ? 'waiting for LND' : state.onchainStale ? 'last known balance'
|
setText('balOnchainSub', !haveOnchain ? 'waiting for LND'
|
||||||
: onchainUnconfirmed > 0 ? fmtAmount(onchainUnconfirmed) + ' unconfirmed' : 'confirmed');
|
: onchainUnconfirmed > 0 ? fmtAmount(onchainUnconfirmed) + ' unconfirmed' : 'confirmed');
|
||||||
|
|
||||||
const liquidityReady = haveChan && !state.chanbalStale && !!state.info;
|
setText('liqLocal', fmtAmount(lnLocal));
|
||||||
setText('liqLocal', liquidityReady ? fmtAmount(lnLocal) : '—');
|
setText('liqRemote', fmtAmount(lnRemote));
|
||||||
setText('liqRemote', liquidityReady ? fmtAmount(lnRemote) : '—');
|
|
||||||
const total = lnLocal + lnRemote;
|
const total = lnLocal + lnRemote;
|
||||||
const localPct = total > 0 ? (lnLocal / total) * 100 : 50;
|
const localPct = total > 0 ? (lnLocal / total) * 100 : 50;
|
||||||
document.getElementById('liqBarLocal').style.width = (liquidityReady ? localPct : 0) + '%';
|
document.getElementById('liqBarLocal').style.width = localPct + '%';
|
||||||
document.getElementById('liqBarRemote').style.width = (liquidityReady ? 100 - localPct : 0) + '%';
|
document.getElementById('liqBarRemote').style.width = (100 - localPct) + '%';
|
||||||
setText('liqHint', !liquidityReady ? 'Channel capacity is unavailable while waiting for LND.' : total > 0
|
setText('liqHint', total > 0
|
||||||
? Math.round(localPct) + '% of your channel capacity is outbound (sendable).'
|
? Math.round(localPct) + '% of your channel capacity is outbound (sendable).'
|
||||||
: 'Open a channel to start sending and receiving over Lightning.');
|
: 'Open a channel to start sending and receiving over Lightning.');
|
||||||
}
|
}
|
||||||
@@ -1313,15 +1284,6 @@
|
|||||||
|
|
||||||
function renderSummary() {
|
function renderSummary() {
|
||||||
const g = state.info;
|
const g = state.info;
|
||||||
if (!g) {
|
|
||||||
for (const id of ['statPeers', 'statActiveChannels', 'statCapacity', 'statRoutingMonth', 'healthHeight', 'healthPending', 'chActive', 'chInactive', 'chPending', 'chCapacity']) setText(id, '—');
|
|
||||||
for (const id of ['statChannelsSub', 'channelsLinkSub']) setText(id, 'Waiting for LND');
|
|
||||||
for (const id of ['healthChain', 'healthGraph']) {
|
|
||||||
const pill = document.getElementById(id);
|
|
||||||
pill.textContent = '—'; pill.className = 'pill warn';
|
|
||||||
}
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const chans = state.channels;
|
const chans = state.channels;
|
||||||
const active = chans.filter(c => c.active).length;
|
const active = chans.filter(c => c.active).length;
|
||||||
const inactive = chans.length - active;
|
const inactive = chans.length - active;
|
||||||
@@ -1359,10 +1321,6 @@
|
|||||||
function renderChannels() {
|
function renderChannels() {
|
||||||
const el = document.getElementById('channelList');
|
const el = document.getElementById('channelList');
|
||||||
if (!el) return;
|
if (!el) return;
|
||||||
if (!state.info) {
|
|
||||||
el.innerHTML = '<div class="empty-state">Waiting for LND. Existing channels will appear when it is ready.</div>';
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const q = (document.getElementById('channelFilter').value || '').toLowerCase();
|
const q = (document.getElementById('channelFilter').value || '').toLowerCase();
|
||||||
let list = state.channels.slice();
|
let list = state.channels.slice();
|
||||||
if (q) list = list.filter(c => String(c.remote_pubkey || '').toLowerCase().includes(q) || String(c.chan_id || '').includes(q));
|
if (q) list = list.filter(c => String(c.remote_pubkey || '').toLowerCase().includes(q) || String(c.chan_id || '').includes(q));
|
||||||
|
|||||||
@@ -3,31 +3,6 @@
|
|||||||
Working backlog of forward-looking items not yet scoped into a dedicated plan
|
Working backlog of forward-looking items not yet scoped into a dedicated plan
|
||||||
doc. See [`ROADMAP.md`](ROADMAP.md) for the curated, public-facing direction.
|
doc. See [`ROADMAP.md`](ROADMAP.md) for the curated, public-facing direction.
|
||||||
|
|
||||||
## Blocking incident — before unrelated work
|
|
||||||
|
|
||||||
- **OPEN: Framework LND startup / missing Receive address / false zero balance.**
|
|
||||||
User requires investigation and a verified fix on the actual node before later
|
|
||||||
unrelated work. Startup and native balances were verified on the actual node;
|
|
||||||
final display confirmation is pending. See the incident record for evidence.
|
|
||||||
See [incident evidence and closure criteria](incident-framework-lnd-startup.md)
|
|
||||||
and the repository `AGENTS.md` session-start instructions.
|
|
||||||
|
|
||||||
## Current repair and release tasks — 2026-09-29
|
|
||||||
|
|
||||||
Release is blocked until these pass; see [execution record](repair-release-20260929.md).
|
|
||||||
|
|
||||||
- [ ] Fix Cashu paid-file redemption between dev and Shorty; test keyset IDs,
|
|
||||||
mint errors, fees, and refund reporting before live validation.
|
|
||||||
- [ ] Complete the remaining Framework incident verification and evidence.
|
|
||||||
- [ ] Replace the unavailable tx1138.com explorer default with mempool.space;
|
|
||||||
migrate the old default with fresh consent and preserve custom/local explorers.
|
|
||||||
- [ ] Offer pruning in the Bitcoin installation version modal, using the same
|
|
||||||
pruning settings as automatic pruning even on large disks.
|
|
||||||
- [ ] Explain Bitcoin warmup without raw RPC errors; gate LND unlock on Bitcoin
|
|
||||||
RPC readiness and show install/start/sync waiting states with automatic recovery.
|
|
||||||
- [ ] Test the completed changes on this development box, then publish a new
|
|
||||||
signed OTA and raw ISO release. Record any remaining verification gaps.
|
|
||||||
|
|
||||||
## Dev & build process (priority)
|
## Dev & build process (priority)
|
||||||
|
|
||||||
- Formalize the contributor workflow: releases, CI, maintainers, automated
|
- Formalize the contributor workflow: releases, CI, maintainers, automated
|
||||||
|
|||||||
@@ -1,405 +0,0 @@
|
|||||||
# Framework: LND startup, missing Receive address, false zero balance
|
|
||||||
|
|
||||||
**Status: CLOSED WITH OPERATOR ACCEPTANCE — startup, native balances, Cashu address and source integration verified; user accepted the remaining display check and authorized release on 2026-09-30.**
|
|
||||||
|
|
||||||
Reported: 2026-09-15. Source inspected: main at `3b9b74da` (v1.8.17-alpha publication).
|
|
||||||
The Framework's installed version and exact incident time have not been verified.
|
|
||||||
|
|
||||||
## Mandatory priority across sessions
|
|
||||||
|
|
||||||
The user explicitly requested that this be investigated and fixed on the node
|
|
||||||
before resuming unrelated work in later sessions. `AGENTS.md` in the repository
|
|
||||||
and `/home/archipelago/.codex/AGENTS.md` carry this session-start priority.
|
|
||||||
Only live verification below, or an explicit user change of priority, clears it.
|
|
||||||
|
|
||||||
## Reported observations
|
|
||||||
|
|
||||||
- Framework stopped showing its Lightning address in Receive.
|
|
||||||
- After a restart, LND did not initialize and the UI displayed a balance of zero.
|
|
||||||
- Manually restarting LND restored operation.
|
|
||||||
- Node access will be supplied later. No Framework connection, restart, wallet
|
|
||||||
operation, or deployment was performed during this offline investigation.
|
|
||||||
- Still clarify whether the restart was a full reboot or management-service
|
|
||||||
restart, and which Receive item vanished: a Lightning invoice, an on-chain
|
|
||||||
address, or the Cashu tab's `@minibits.cash` address.
|
|
||||||
|
|
||||||
A successful manual restart is a workaround, not a root cause or durable fix.
|
|
||||||
The zero display does not establish that any funds were lost. Its relation to
|
|
||||||
v1.8.17-alpha is unknown; do not infer a release regression from timing alone.
|
|
||||||
|
|
||||||
## Confirmed source findings
|
|
||||||
|
|
||||||
### 1. LND errors can be presented as successful zero balances
|
|
||||||
|
|
||||||
`core/archipelago/src/api/rpc/lnd/info.rs`, `handle_lnd_getinfo`:
|
|
||||||
|
|
||||||
- `/v1/getinfo` is decoded without checking HTTP success. Its response fields are
|
|
||||||
optional, so an error object such as `{"code":14,"message":"wallet not ready"}`
|
|
||||||
can deserialize with every expected field absent instead of rejecting the call.
|
|
||||||
- Channel and blockchain balance requests suppress connection/JSON failures and
|
|
||||||
substitute responses with absent balances. HTTP status is not checked here either.
|
|
||||||
- Missing or unparsable balances become `0` through `unwrap_or(0)`.
|
|
||||||
- `neode-ui/src/views/Home.vue`, `loadWeb5Status`, treats this RPC response as
|
|
||||||
success, sets the wallet connected flag, overwrites prior balances, and can
|
|
||||||
persist the false zero in the wallet snapshot. Its existing failure handling
|
|
||||||
preserves prior balances only when the RPC actually rejects.
|
|
||||||
|
|
||||||
This is a confirmed code defect and a plausible explanation for the reported
|
|
||||||
display. It is not proof of the Framework's failure sequence.
|
|
||||||
|
|
||||||
Required fix: reject unsuccessful/incomplete LND balance responses or model
|
|
||||||
availability explicitly end to end. Never translate unavailable data into a
|
|
||||||
verified zero. Preserve known balances with a clear unavailable/stale indication;
|
|
||||||
show an unknown state when no valid balance is known. Genuine successful zeros
|
|
||||||
must still render as zero. Cover outage, partial failure, cold load, and recovery.
|
|
||||||
|
|
||||||
### 2. Startup readiness and wallet unlock need live evidence
|
|
||||||
|
|
||||||
- `main.rs` runs crash/container boot recovery before starting the reconciler.
|
|
||||||
- `crash_recovery.rs` can start existing containers directly.
|
|
||||||
- `container/prod_orchestrator.rs` runs LND post-start hooks on explicit restart
|
|
||||||
and on normal reconciliation of already-running containers. Therefore it is
|
|
||||||
incorrect to conclude that running containers categorically skip unlock.
|
|
||||||
- `container/lnd.rs::ensure_wallet_initialized` checks wallet existence and
|
|
||||||
`/v1/getinfo`, then attempts unlock. Its unlock wait budget is approximately ten
|
|
||||||
minutes; per-request timeouts can extend elapsed time. Historical comments
|
|
||||||
describe slow database startup and restart loops, but that is not Framework evidence.
|
|
||||||
- `health_monitor.rs` models LND's Bitcoin dependency. Container-running state
|
|
||||||
alone is not proof of wallet readiness, Bitcoin connectivity, or invoice readiness.
|
|
||||||
|
|
||||||
Investigate boot ordering, Bitcoin readiness, listener/port mapping, wallet unlock,
|
|
||||||
mount availability, stopped markers, restart counters, and actual reconcile logs.
|
|
||||||
|
|
||||||
### 3. Destructive automatic recovery exists; exclude it from diagnosis
|
|
||||||
|
|
||||||
`container/lnd.rs::ensure_wallet_initialized` calls
|
|
||||||
`recreate_wallet_destructively` when all candidate passwords are rejected. That
|
|
||||||
function can delete the LND chain and graph data directories. Its comment assumes
|
|
||||||
alpha wallets hold no real funds; that assumption must not guide this investigation.
|
|
||||||
|
|
||||||
No evidence establishes that it ran on Framework. Preserve the original wallet
|
|
||||||
and channels; rejected passwords must lead to a recoverable error, not automatic
|
|
||||||
wallet deletion. Review and disable this destructive fallback before using a
|
|
||||||
modified initialization path as a repair. The existing
|
|
||||||
`unlock_existing_wallet_no_wipe` demonstrates the non-destructive error behavior.
|
|
||||||
|
|
||||||
### 4. The missing address must be identified precisely
|
|
||||||
|
|
||||||
`ReceiveBitcoinModal.vue` generates Lightning invoices using `lnd.createinvoice`
|
|
||||||
after a readiness check, and Bitcoin addresses using `lnd.newaddress`. Its Cashu
|
|
||||||
Lightning address uses `wallet.ecash-lnaddress` and the Minibits service separately.
|
|
||||||
Do not assume the Minibits address disappears because LND is down. Trace the actual
|
|
||||||
tab and response once the user clarifies and the node can be inspected.
|
|
||||||
|
|
||||||
## Next session: live investigation order
|
|
||||||
|
|
||||||
1. Request Framework access and verify node identity without publishing its hostname,
|
|
||||||
address, credentials, or wallet identifiers. Do not substitute the development box.
|
|
||||||
2. Record installed backend/image versions, boot and incident timestamps, and exact
|
|
||||||
restart/action sequence. Capture current and previous-boot management/LND logs
|
|
||||||
before another restart can obscure evidence. Keep raw logs private and redact
|
|
||||||
secrets, invoices, wallet identifiers, and personally identifying data in summaries.
|
|
||||||
3. Read container/service state, restart counters, mounts, stopped markers, listener
|
|
||||||
mappings, Bitcoin readiness, LND wallet state, and authenticated API results.
|
|
||||||
Never dump container environments, macaroons, passwords, seeds, or wallet databases.
|
|
||||||
4. Compare HTTP status and data from LND getinfo/balance endpoints with the RPC and
|
|
||||||
visible Receive/balance state. Distinguish unavailable data, locked wallet,
|
|
||||||
syncing wallet, and genuine zero. Preserve last-known balance evidence privately.
|
|
||||||
5. Establish whether the manual restart ran a missing/failed hook, waited out a
|
|
||||||
dependency, refreshed networking/credentials, or masked another failure.
|
|
||||||
6. Implement the evidenced startup repair and unavailable-balance handling with
|
|
||||||
regressions. Preserve wallet/channel state and arrange recovery access before
|
|
||||||
deploying or deliberately rebooting the node.
|
|
||||||
|
|
||||||
## Acceptance criteria — all required to close
|
|
||||||
|
|
||||||
- [x] Root cause of Framework startup failure supported by node evidence.
|
|
||||||
- [x] Fix implemented and focused regression tests pass.
|
|
||||||
- [ ] Failed, locked, delayed, and partial LND responses never masquerade as a
|
|
||||||
fresh zero balance; genuine zero remains correct.
|
|
||||||
- [x] Existing wallet identity and channel state preserved through the repair.
|
|
||||||
- [x] Framework starts LND and reaches usable wallet readiness after a controlled
|
|
||||||
full reboot, without manually restarting LND.
|
|
||||||
- [ ] The originally affected Receive flow works after boot and after recovery;
|
|
||||||
outages show an actionable state and recover without requiring a page reload.
|
|
||||||
- [ ] Display confirmation pending; authenticated LND balances match pre-reboot values.
|
|
||||||
- [x] LND logs show no restart loop, repeated unlock failure, or wallet-recreation path.
|
|
||||||
- [ ] Evidence, tested versions, deployment, and limitations recorded here; user
|
|
||||||
informed of live results. Only then set status RESOLVED and clear the blockers.
|
|
||||||
|
|
||||||
## Work completed so far
|
|
||||||
|
|
||||||
2026-09-15: source investigation and persistent session-start instructions only.
|
|
||||||
No code fix, release, node deployment, or live reproduction for this incident yet.
|
|
||||||
|
|
||||||
## Live evidence captured 2026-09-15
|
|
||||||
|
|
||||||
Access was provided during the same session. Read-only inspection confirmed:
|
|
||||||
|
|
||||||
- Framework runs `1.8.17-alpha-dev`; the current full boot began at 18:40:09 UTC.
|
|
||||||
- LND opened its databases in 6.7 seconds and requested its wallet password at
|
|
||||||
18:40:20. It then rejected GetInfo/ChannelBalance/WalletBalance as wallet locked.
|
|
||||||
- The management service's first sequential reconcile pass was occupied by
|
|
||||||
unrelated image recovery, including a missing voice image from 18:40:24 and
|
|
||||||
later a missing Core Lightning image. Manifests are iterated from a HashMap;
|
|
||||||
wallet readiness has no initial priority. Boot recovery itself completed at
|
|
||||||
18:40:18; the first full app-reconcile report appeared at 18:44:34.
|
|
||||||
- The user's manual LND restart was recorded at 18:42:33. The replacement LND
|
|
||||||
process started at 18:42:40, requested its password at 18:43:05, and unlocked
|
|
||||||
at 18:43:07 through the explicit restart hook. This supports delayed unlock
|
|
||||||
behind unrelated recovery, rather than a missing wallet or bad password.
|
|
||||||
- At inspection, `/v1/state` reports SERVER_ACTIVE; getinfo reports chain and
|
|
||||||
graph sync and two active channels. Both authenticated balance endpoints
|
|
||||||
report nonzero balances. No wallet-recreation event was found in captured logs.
|
|
||||||
- The Minibits RPC separately fails with “The ecash wallet has no seed yet”.
|
|
||||||
`wallet/cashu_seed.json` and `wallet/minibits.json` are absent. The existing
|
|
||||||
ecash wallet is present with proofs and an August modification timestamp.
|
|
||||||
Do not overwrite it or generate an unrelated recovery identity. Still identify
|
|
||||||
which Receive item the user meant before declaring this part repaired.
|
|
||||||
|
|
||||||
Private raw evidence: `/home/archipelago/.local/state/archy-incidents/framework-lnd-20260915/`.
|
|
||||||
Files have mode 0600 and the directory 0700. Do not commit or publish raw logs.
|
|
||||||
|
|
||||||
Candidate changes on `investigate/framework-lnd-startup`:
|
|
||||||
|
|
||||||
- Run Bitcoin and LND reconciliation before unrelated image pulls/builds.
|
|
||||||
- Reject failed/incomplete LND balance responses instead of manufacturing zeros.
|
|
||||||
- Preserve known Home balances on invalid responses, visibly label unavailable
|
|
||||||
balances, and clear the warning after a successful refresh.
|
|
||||||
- Remove automatic destructive wallet recreation; failed unlock preserves data.
|
|
||||||
- Add backend outage/zero/ordering regressions and UI failure/recovery coverage.
|
|
||||||
|
|
||||||
These changes are not yet deployed or verified through a Framework reboot.
|
|
||||||
|
|
||||||
### Candidate validation and staging
|
|
||||||
|
|
||||||
Source fix commit: `4237fb5e` on `investigate/framework-lnd-startup`.
|
|
||||||
|
|
||||||
- 44 focused backend tests passed (including LND errors, genuine zero, startup ordering).
|
|
||||||
- 58 additional reconciliation/update tests passed.
|
|
||||||
- 12 Home UI tests passed, including outage/partial response/cold-load/recovery cases.
|
|
||||||
- Rust formatting, frontend type checking and production build passed.
|
|
||||||
- Optimized backend build passed in 8m02s.
|
|
||||||
- Both candidate artifacts were copied to Framework and SHA-256 matched locally.
|
|
||||||
- Private on-node baseline and static channel backup are under
|
|
||||||
`/var/lib/archipelago/support/framework-lnd-20260915/`, along with the previous
|
|
||||||
backend, dashboard, and `rollback.sh`. This directory is root-only.
|
|
||||||
- Candidate staged at `/tmp/archy-framework-candidate/`; not applied yet.
|
|
||||||
- A timing confirmation for the maintenance restart/full reboot was requested
|
|
||||||
because it interrupts all node services. Do not reboot while that is pending.
|
|
||||||
- SSH works through the temporary control socket
|
|
||||||
`/tmp/archy-framework-connection/control`. No SSH password was saved to disk.
|
|
||||||
- The supplied SSH password did not authenticate to the dashboard. Do not guess
|
|
||||||
additional passwords or alter dashboard authentication. Native LND diagnostics
|
|
||||||
are authenticated using its existing local macaroon without printing it.
|
|
||||||
|
|
||||||
Status remains OPEN until deployment and live boot/Receive/balance verification.
|
|
||||||
|
|
||||||
### Authorized deployment and full reboot — 2026-09-15
|
|
||||||
|
|
||||||
The user answered “yes please” to applying the staged fix and rebooting. Timing
|
|
||||||
approval is no longer pending. Applied the staged backend and dashboard after
|
|
||||||
rechecking both checksums and rollback copies. There were no pending channel
|
|
||||||
HTLCs at reboot. No wallet data, secrets, or recovery identities were replaced.
|
|
||||||
|
|
||||||
Live results:
|
|
||||||
|
|
||||||
- A different boot ID confirms a full reboot occurred.
|
|
||||||
- Running backend on disk matches candidate SHA-256
|
|
||||||
`5a354f76ebe619561eef0d318e4f41f177d04004682504d7434d632733f8e298`.
|
|
||||||
- Management service started around 19:23:57 UTC; LND asked for its wallet
|
|
||||||
password at 19:24:10 and logged automatic unlock at 19:24:18. No manual LND
|
|
||||||
restart or interactive unlock was used after this reboot.
|
|
||||||
- LND reports SERVER_ACTIVE and chain sync. Its identity and channel-point set
|
|
||||||
are identical to the private pre-reboot baseline; both channels are active.
|
|
||||||
- On-chain and Lightning balances exactly equal the pre-reboot values.
|
|
||||||
- LND container and systemd restart counts are zero after recovery.
|
|
||||||
- Public HTTP checks on the node returned 200 for the dashboard index and new
|
|
||||||
Home bundle; their bytes match the installed candidate, including the new
|
|
||||||
unavailable-balance notice.
|
|
||||||
- Captured post-reboot management and LND journals in the private local evidence
|
|
||||||
directory. Detailed before/after identity, channel, and balance records remain
|
|
||||||
in the root-only support directory on Framework.
|
|
||||||
|
|
||||||
The user was asked to refresh the dashboard and confirm the originally missing
|
|
||||||
Receive item and displayed balances. Keep OPEN until that reply is assessed;
|
|
||||||
Minibits seed absence was a separate finding and must not be mistaken for an
|
|
||||||
LND startup failure. Candidate is a direct node deployment, not a newly signed
|
|
||||||
fleet release. The source branch must be integrated before a subsequent release
|
|
||||||
can preserve this fix across the fleet.
|
|
||||||
|
|
||||||
### Cashu Receive follow-up
|
|
||||||
|
|
||||||
The user confirmed that the remaining error is specifically on the Ecash tab:
|
|
||||||
“Lightning address unavailable — you can still paste a token below.”
|
|
||||||
|
|
||||||
Read-only checks confirm Framework has an encrypted node master seed, existing
|
|
||||||
Cashu proofs, and neither `wallet/cashu_seed.json` nor `wallet/minibits.json`.
|
|
||||||
The existing Minibits handler requires an ecash seed, but setup was available
|
|
||||||
only through the Settings backup screen; Receive hid the actionable cause.
|
|
||||||
|
|
||||||
UI fix commit: `a3b64670`.
|
|
||||||
|
|
||||||
- Receive checks the non-secret seed status when registration fails.
|
|
||||||
- Unseeded wallets get the existing password/TOTP/backup-passphrase-verified setup
|
|
||||||
component directly in Receive, with import/restore controls excluded from this
|
|
||||||
focused setup screen. Setup derives from the saved node seed when present.
|
|
||||||
- The recovery words stay in the existing local reveal UI, are cleared on Done,
|
|
||||||
and are never emitted to Receive. Receive retries registration after Done.
|
|
||||||
- Seeded wallets with service outages get Retry, without offering a new identity.
|
|
||||||
- Ten focused Receive/backup tests and the production UI build passed.
|
|
||||||
- Deployed the dashboard change without restarting services; live HTTP index and
|
|
||||||
setup bundle returned 200 and byte-matched the candidate.
|
|
||||||
- Backed up original Cashu proofs to the root-only support directory as
|
|
||||||
`ecash-before-address-setup.json`. No seed or proof mutation was performed by
|
|
||||||
the assistant. Prior LND-fixed dashboard is also backed up there.
|
|
||||||
|
|
||||||
The user was asked to refresh Receive → Ecash → Set up address, authenticate in
|
|
||||||
that node UI, and click Done. Dashboard password is required to decrypt the node
|
|
||||||
seed; the SSH password did not authenticate to the dashboard. Do not request or
|
|
||||||
print recovery words, bypass authentication, or create an unrelated random seed.
|
|
||||||
After completion, verify saved seed/profile presence, registration success,
|
|
||||||
address display, and unchanged original proofs before closing the incident.
|
|
||||||
|
|
||||||
### Cashu setup completed and verified — 2026-09-15
|
|
||||||
|
|
||||||
The user initially reported a forgotten passphrase, then said “did it now”. No
|
|
||||||
independent-seed fallback was implemented or used. The user completed the existing
|
|
||||||
password-verified setup themselves; the assistant did not receive recovery words.
|
|
||||||
|
|
||||||
Read-only node verification confirmed:
|
|
||||||
|
|
||||||
- `wallet/cashu_seed.json` exists, is nonempty, and records source `node-seed`.
|
|
||||||
- `wallet/minibits.json` exists with a `@minibits.cash` address and no pending claims.
|
|
||||||
- The original ecash wallet file is byte-for-byte unchanged from the protected
|
|
||||||
pre-setup copy; every original proof is preserved.
|
|
||||||
- The registered address's public LNURL-pay metadata returns HTTP 200, tag
|
|
||||||
`payRequest`, an HTTPS callback, and a valid amount range. No invoice was paid
|
|
||||||
and no funded payment test was performed.
|
|
||||||
|
|
||||||
LND automatic startup and native balances were already verified after the full
|
|
||||||
reboot. Cashu setup and address registration are now also verified on Framework.
|
|
||||||
Do not ask for the forgotten passphrase again or propose a replacement Cashu seed.
|
|
||||||
|
|
||||||
Remaining: integrate the tested source branch before the next fleet release;
|
|
||||||
record final human confirmation of the rendered dashboard balance (native balances
|
|
||||||
match exactly, and UI failure/recovery regressions pass). Keep this follow-up
|
|
||||||
visible across sessions; do not rebuild/reboot/reinitialize a working wallet just
|
|
||||||
to repeat already completed checks.
|
|
||||||
|
|
||||||
### Backup copy and layout — 2026-09-15
|
|
||||||
|
|
||||||
At the user's request, shortened the ecash backup explanations and stacked each
|
|
||||||
card section's text and full-width action vertically. Kept the distinction
|
|
||||||
between node-derived and separate phrases, and the warning that a newly created
|
|
||||||
phrase covers future coins rather than existing legacy coins.
|
|
||||||
|
|
||||||
All 10 Receive/backup tests and the production UI build pass. Deployed the UI to
|
|
||||||
Framework without a restart; served index and backup-component bundle match the
|
|
||||||
build byte-for-byte. The prior UI is saved as `web-ui-before-backup-copy` in the
|
|
||||||
protected incident directory. Source integration and final rendered dashboard
|
|
||||||
balance confirmation remain pending as above.
|
|
||||||
|
|
||||||
### LNURL comment-length report — 2026-09-15
|
|
||||||
|
|
||||||
User reports a maximum-comment-length error in some sending wallets. Live
|
|
||||||
Framework address metadata advertises integer `commentAllowed: 100`. The QR
|
|
||||||
contains the address only; Archy's Receive UI does not add a comment. The
|
|
||||||
Minibits-hosted callback returned invoices for omitted/empty comments, 100 ASCII
|
|
||||||
characters, 101 ASCII characters, and 100 accented characters. These were unpaid
|
|
||||||
invoice requests at the advertised minimum amount; no funds were sent.
|
|
||||||
|
|
||||||
The callback did not reproduce the error, including beyond its advertised limit.
|
|
||||||
Sending-wallet validation against the advertised 100-character limit is therefore
|
|
||||||
a hypothesis, not a confirmed root cause. Asked which wallets fail and whether
|
|
||||||
an empty comment also fails. Need that result before selecting a code fix.
|
|
||||||
The service controls the advertised limit; changing local Receive text or QR
|
|
||||||
cannot raise it for other wallets.
|
|
||||||
|
|
||||||
### Primal Spark: automatic recipient note exceeds the address limit
|
|
||||||
|
|
||||||
User clarified that no comment was entered and the sender is Primal Spark.
|
|
||||||
Checked Framework's management journal over the preceding 20 minutes: no
|
|
||||||
comment-length errors, service active, and zero pending Minibits claims. Recent
|
|
||||||
claim polling connected to and disconnected from the relay normally. Historical
|
|
||||||
seed-authentication failures preceded the successful setup already documented.
|
|
||||||
|
|
||||||
The live address's Minibits `text/plain` description is **101 ASCII characters**,
|
|
||||||
while `commentAllowed` is **100**. Description template (address redacted):
|
|
||||||
`Pay to [ADDRESS] with Lightning. Receiver will receive ecash into Minibits Wallet.`
|
|
||||||
|
|
||||||
Primal Android source at `36939db97213e7f8eeefaa4adaf125d839fc662e`:
|
|
||||||
- `WalletTextParserImpl.handleLnUrlText` assigns the parsed description to
|
|
||||||
`DraftTx.noteRecipient`, including for Lightning-address input.
|
|
||||||
- `TransactionEditor` initializes its editable recipient note from that value.
|
|
||||||
- `SparkWalletServiceImpl` passes it untrimmed to `PrepareLnurlPayRequest.comment`.
|
|
||||||
- Breez Spark source at `8bb38ec292a590907360c4e7f2a4134b8f09de9e`,
|
|
||||||
`common/src/lnurl/pay.rs::validate_user_input`, rejects a comment exceeding the
|
|
||||||
limit with the exact reported error before requesting the callback.
|
|
||||||
|
|
||||||
This identifies a concrete compatibility failure: the address description can
|
|
||||||
become an automatic over-limit comment without the sender typing anything.
|
|
||||||
The user confirmed that explicitly clearing the prefilled recipient note made
|
|
||||||
the payment work, and supplied the same description observed in live metadata.
|
|
||||||
This confirms the automatic-comment compatibility failure. The installed Primal
|
|
||||||
platform/version was not captured. Node logs alone cannot show sender-side
|
|
||||||
validation or requests to the external Minibits callback.
|
|
||||||
|
|
||||||
Durable upstream correction: Primal should keep receiver metadata separate from
|
|
||||||
the sender's comment and enforce the limit on actual user comments. Minibits can
|
|
||||||
also shorten its description or raise its advertised comment limit. Archy does
|
|
||||||
not serve this external LNURL metadata; do not rename an existing wallet address,
|
|
||||||
rotate its seed, or claim that a local dashboard edit fixes this sender behavior.
|
|
||||||
|
|
||||||
### Primal workaround confirmed by user
|
|
||||||
|
|
||||||
The user confirmed successful payment after removing the automatic description.
|
|
||||||
The permanent sender-side correction is to leave the recipient comment empty by
|
|
||||||
default and retain receiver metadata only as display text. In Primal Android,
|
|
||||||
remove the assignment of the LNURL description to the draft recipient note in
|
|
||||||
`WalletTextParserImpl.handleLnUrlText`; also validate explicitly entered comments
|
|
||||||
against the endpoint's limit. No upstream change has been submitted or deployed.
|
|
||||||
Existing Framework addresses and wallet identities remain unchanged.
|
|
||||||
|
|
||||||
### Can Archy shorten the current address description?
|
|
||||||
|
|
||||||
Inspected Minibits' public wallet client (`src/services/minibitsService.ts`,
|
|
||||||
`updateWalletProfile`) and `WalletProfileRecord`. The supported profile update
|
|
||||||
fields are name, lud16, and avatar; there is no exposed LNURL description or
|
|
||||||
comment-limit setting. Its public web repository also contains no implementation
|
|
||||||
of the LNURL metadata endpoint or description template.
|
|
||||||
|
|
||||||
For the existing `@minibits.cash` address, no supported client-side mechanism
|
|
||||||
to shorten this text was found. Do not send guessed profile-update fields or
|
|
||||||
rename the address to disguise the problem. A Minibits server change could use
|
|
||||||
`Pay to [ADDRESS]`, well below the current limit. Controlling this metadata in
|
|
||||||
Archy would instead require an Archy-hosted LNURL service/address and correct
|
|
||||||
invoice metadata binding; rewriting the QR label or only proxying edited metadata
|
|
||||||
is insufficient. No wallet/profile mutations were made during this investigation.
|
|
||||||
|
|
||||||
### Source integration confirmed — 2026-09-29
|
|
||||||
|
|
||||||
`git merge-base --is-ancestor 4237fb5e HEAD` succeeds on main at
|
|
||||||
`540639d2`. The previously tested startup ordering, safe unlock, and unavailable
|
|
||||||
balance fixes are integrated and included in the intervening releases. The
|
|
||||||
earlier “source integration pending” notes above are historical, not current.
|
|
||||||
The user reports no further Framework incidents. Requested final confirmation
|
|
||||||
of rendered balances and Receive; do not mark closed without that response.
|
|
||||||
|
|
||||||
A separate startup failure was observed on the development box today when Core
|
|
||||||
was installed against existing block data: Core made steady replay progress,
|
|
||||||
while LND exited on its short “bitcoind start timeout”. Candidate work defers
|
|
||||||
unlock until authenticated Bitcoin RPC answers, with dependency waiting states
|
|
||||||
in the LND UI. This is not evidence of a new failure on Framework.
|
|
||||||
|
|
||||||
### Operator acceptance and release authorization — 2026-09-30
|
|
||||||
|
|
||||||
After being told that final rendered balance/Receive confirmation remained and
|
|
||||||
SSH access was unavailable, the user replied: “that's fine I believe it'd fixed,
|
|
||||||
please release”. This explicitly accepts proceeding past the remaining human
|
|
||||||
display check. Close this incident with operator acceptance based on the earlier
|
|
||||||
controlled reboot, preserved identity/channels/native balances, working Receive
|
|
||||||
address/payment, source integration, and the user's report of no further issues.
|
|
||||||
No new direct Framework inspection or on-screen verification is claimed today.
|
|
||||||
Reopen investigation if the original startup, Receive, or false-zero symptom
|
|
||||||
recurs; preserve the wallet and channels.
|
|
||||||
@@ -1,259 +0,0 @@
|
|||||||
# Repair and release execution — 2026-09-29
|
|
||||||
|
|
||||||
**Status: IN PROGRESS. Do not publish an OTA or ISO until the release gates pass.**
|
|
||||||
|
|
||||||
User requires all tasks completed and tested on the development box before the
|
|
||||||
next OTA and raw ISO. Passing unit tests alone does not establish live correctness.
|
|
||||||
|
|
||||||
## Confirmed evidence
|
|
||||||
|
|
||||||
- Dev-to-Shorty 100-sat Cashu file purchases failed twice. Both sellers' and
|
|
||||||
buyers' accepted mints match. Shorty's mint swap returned HTTP 422; both
|
|
||||||
attempted purchases were refunded 100 sats. The old message guessed a mint
|
|
||||||
mismatch without evidence.
|
|
||||||
- Wallet import repaired truncated V2 keyset IDs, while paid-content redemption
|
|
||||||
bypassed that repair. Central swap repair and protocol-level regression tests now pass.
|
|
||||||
- Core installation on dev reused existing chain data. At 17:42 UTC it was
|
|
||||||
advancing through block replay with no Core container restarts. At 17:49 UTC
|
|
||||||
it had connected to peers and started transaction-index synchronization.
|
|
||||||
- LND exited repeatedly with `bitcoind start timeout` while Core loaded. After
|
|
||||||
Core became available LND stayed running and reported waiting for backend sync.
|
|
||||||
- Framework source fix 4237fb5e is already an ancestor of main. Existing live
|
|
||||||
reboot/native balance evidence is in the incident document. Final display
|
|
||||||
confirmation remains pending.
|
|
||||||
|
|
||||||
## Changes under validation
|
|
||||||
|
|
||||||
- Cashu V4/V2 ID expansion at every swap; fee-aware underpayment rejection;
|
|
||||||
single-mint/sat-only/cryptographic paid tokens; no false mint-mismatch or
|
|
||||||
unconditional refund claims. Missing content checked before redemption.
|
|
||||||
- mempool.space default; migrate old tx1138 default with fresh consent, retain
|
|
||||||
local explorer priority and custom preferences.
|
|
||||||
- Core/Knots optional pruning on the version modal and app detail install path;
|
|
||||||
persist choice across runtime restarts; use identical 50,000 MiB automatic
|
|
||||||
pruning entrypoint behavior on large and small disks.
|
|
||||||
- Plain Bitcoin block-index startup message; defer LND wallet initialization or
|
|
||||||
unlock until Bitcoin RPC is usable; authenticated dependency status and LND UI
|
|
||||||
waiting states; no partial total displayed as a complete balance.
|
|
||||||
|
|
||||||
## Validation and release gates
|
|
||||||
|
|
||||||
- [x] Final backend regression suite passes (including mock mint HTTP and real
|
|
||||||
curve signatures, v1/full-v2/truncated-v2, fees, errors, duplicate redemption).
|
|
||||||
- [x] Initial explorer and pruning modal tests pass: 15 tests.
|
|
||||||
- [x] Both actual manifest entrypoints tested with isolated fake bitcoind across
|
|
||||||
6 disk/choice combinations each. No existing chain pruned for this test.
|
|
||||||
- [x] Initial LND UI install/start/sync/recovery and invalid-balance tests pass.
|
|
||||||
- [x] Frontend production build and relevant existing wallet tests pass (34
|
|
||||||
focused tests, including 12 Home failure/recovery checks). Final UI suite: 1,120 passed; production build passed. Full release harness and final frontend follow-up passed.
|
|
||||||
- [x] Fault tests and final source review complete.
|
|
||||||
- [x] Candidate deployed with rollback to dev and Shorty; hashes verified.
|
|
||||||
- [x] Live paid-file purchase succeeds; failed purchase/refund behavior verified.
|
|
||||||
- [x] Live waiting/UI verified on dev; recovery covered by deterministic tests.
|
|
||||||
- [x] Framework operator acceptance and authorization to release recorded.
|
|
||||||
- [x] Release version/changelog, catalog/image implications, signing prepared.
|
|
||||||
- [ ] Signed OTA built, tested, published to git and ngit.
|
|
||||||
- [ ] Raw ISO built, boot-tested, signed and published; download command supplied.
|
|
||||||
|
|
||||||
Tests must not wipe/recreate wallets, prune the operator's existing full chain,
|
|
||||||
or claim that arbitrary failures can never happen. Record material gaps before
|
|
||||||
release. Signing keys remain with the user; prepare concrete artifacts first.
|
|
||||||
|
|
||||||
### Further startup findings
|
|
||||||
|
|
||||||
Live dev `/v1/state` returned `RPC_ACTIVE` while `/v1/getinfo` timed out during
|
|
||||||
Bitcoin initial sync. Candidate startup now recognizes the already-unlocked
|
|
||||||
state instead of repeating unlock attempts for ten minutes. The health watchdog
|
|
||||||
also now excludes Bitcoin initial sync, warmup, unavailable/stale status and
|
|
||||||
LND height progress from its restart criteria. A later observed `podman restart`
|
|
||||||
was externally initiated; its precise caller has not yet been established, so
|
|
||||||
the watchdog defect is a source finding rather than a confirmed attribution.
|
|
||||||
|
|
||||||
Framework SSH rejected the previously provided login on 2026-09-29. No password
|
|
||||||
was saved and no wallet changes were attempted. The human display-confirmation
|
|
||||||
question remains pending. Do not repeat a Framework reboot to reconfirm old work.
|
|
||||||
|
|
||||||
LND UI waiting-state, stale-balance, partial-failure/recovery and prompt-render
|
|
||||||
tests pass (4 Node tests). Waiting states avoid calls to LND endpoints that block
|
|
||||||
until sync, and prevent overlapping refreshes.
|
|
||||||
|
|
||||||
### Final source validation
|
|
||||||
|
|
||||||
The final backend suite passed: 1,548 passed, zero failed, four existing ignored
|
|
||||||
live/hardware tests. Includes saved pruning preference, rejecting an old catalog
|
|
||||||
that cannot honor explicit pruning, and all nine paid-Cashu protocol tests.
|
|
||||||
Unsigned candidate catalog passes strict drift and fleet registry trust checks.
|
|
||||||
The release gate caught a missing What's New entry; generated it from the curated
|
|
||||||
changelog and reran the frontend gate/build. No public release has been changed.
|
|
||||||
|
|
||||||
At 18:23 UTC dev Bitcoin exited with status 137 and restarted; current container
|
|
||||||
is not marked OOM-killed and no kernel/oomd record identified the cause. Bitcoin
|
|
||||||
is replaying blocks again (height 482071 at 18:31 UTC). Installed old LND continues
|
|
||||||
to time out while Bitcoin RPC warms up. Candidate is not deployed yet; verify its
|
|
||||||
readiness deferral live before declaring this fixed. Do not attribute the Bitcoin
|
|
||||||
exit to a specific actor without evidence.
|
|
||||||
|
|
||||||
### Doctor restart cause established and repaired
|
|
||||||
|
|
||||||
Full system journal identifies container-doctor at 18:23:21 UTC issuing raw
|
|
||||||
`podman restart bitcoin-core` for an allegedly missing 8333 listener. The same
|
|
||||||
script restarted LND at 17:57:48 and 18:23:35 UTC. The port was actually listening.
|
|
||||||
Reproduced the original `ss | awk | grep -q` pipeline returning `0 141 0`: grep
|
|
||||||
exits after its match, awk gets SIGPIPE, and pipefail falsely reports no listener.
|
|
||||||
The raw restart also enforces a short stop timeout and races Quadlet cleanup.
|
|
||||||
|
|
||||||
The repaired check consumes the entire socket snapshot, distinguishes inspection
|
|
||||||
failure from a missing port, and leaves containers running when inspection fails.
|
|
||||||
Necessary restarts use their managed systemd units and shutdown timeouts; unmanaged
|
|
||||||
Bitcoin/LND fallback receives 600/330-second grace respectively. Regression uses
|
|
||||||
20,000 socket rows plus mocked service/container commands and passes. Thirty
|
|
||||||
read-only checks of the actual Bitcoin listener pass. Script deployed to dev and
|
|
||||||
Shorty with root-only rollback copies. OTA runtime payload includes scripts/.
|
|
||||||
This evidence supersedes the earlier unknown-caller/unknown-exit attribution.
|
|
||||||
|
|
||||||
### Initial candidate live validation — 18:48 UTC
|
|
||||||
|
|
||||||
Source 0f85f588, optimized backend SHA256
|
|
||||||
84434c495c5f8472cf6bfcb6c65e762502c74718ad88271619373335c0054bb6,
|
|
||||||
deployed to dev and Shorty with matching hashes and rollback copies. Both
|
|
||||||
management services restarted; wallets/channels were not reset. Old embedded
|
|
||||||
runtime assets restored the old doctor on backend startup; updated the live
|
|
||||||
script AND embedded runtime copy on both nodes. Final OTA will contain the new
|
|
||||||
script directly.
|
|
||||||
|
|
||||||
Authenticated dev readiness transitioned from waiting_start to waiting_sync.
|
|
||||||
Real Chromium at 1440px and 390px showed Waiting for Bitcoin to sync, an unknown
|
|
||||||
balance, and no blocked native LND calls. Screenshot review also caught invented
|
|
||||||
zero capacity/channel counts during waiting: corrected them and the empty-channel
|
|
||||||
recommendation; five UI regression tests now pass.
|
|
||||||
|
|
||||||
Real Minibits Cashu purchase from dev to Shorty succeeded for one sat and returned
|
|
||||||
the expected 44 bytes. A rejected one-sat underpayment was refunded exactly, and
|
|
||||||
two cached downloads charged zero. Temporary seller files/catalog entries removed.
|
|
||||||
The first test runner expected data_base64 while the first-purchase API returns
|
|
||||||
data; cached responses use data_base64. Existing purchase clients only consume
|
|
||||||
data, so a follow-up normalizes both response variants to both fields.
|
|
||||||
|
|
||||||
The optional Files copy failed because FileBrowser owns host paths as mapped UID
|
|
||||||
100000. Follow-up uses its authenticated API with override=false and collision
|
|
||||||
suffixes. A live API probe succeeded, refused overwrite with HTTP409, preserved
|
|
||||||
original bytes, and cleaned up. New protocol tests cover folder creation, escaped
|
|
||||||
names, collisions, authentication failure, disk-full, and unavailable service.
|
|
||||||
Full backend suite for these follow-ups is running; do not package the earlier
|
|
||||||
backend as final.
|
|
||||||
|
|
||||||
### Follow-up validation and OTA delivery check
|
|
||||||
|
|
||||||
Paid-response and Files API regressions passed in the full backend run: 1,552
|
|
||||||
passed, zero failed, four existing ignored tests. Live browser waiting checks
|
|
||||||
passed again after removing invented zero capacity and channel counts.
|
|
||||||
|
|
||||||
OTA inspection found that companion image :local (created by old installers and
|
|
||||||
used on dev) bypassed both source-staleness detection and rebuilding. The earlier
|
|
||||||
assumption that build-context detection covered these nodes was incorrect.
|
|
||||||
Follow-up applies the existing source-mtime/stamp checks to both :local and
|
|
||||||
:latest, preserving the existing tag and rebuilding only stale source. Existing
|
|
||||||
image-ID comparison then restarts the UI companion onto the new image. This does
|
|
||||||
not restart LND itself. Regression covers every companion's two local tags; final
|
|
||||||
backend suite is running. Verify the resulting live rebuilt image before release.
|
|
||||||
|
|
||||||
### Test isolation finding — release remains blocked
|
|
||||||
|
|
||||||
The next full run passed 1,552 tests but one existing boot-loop timing test failed.
|
|
||||||
Its output and node logs exposed an independent test defect: MockRuntime tests
|
|
||||||
still invoked real Quadlet service operations and Podman socket recovery. These
|
|
||||||
caused further LND/companion restarts during unrestricted unit runs. They were not
|
|
||||||
a recurrence of the repaired doctor port check. Stopped unrestricted testing;
|
|
||||||
LND has remained running since 19:02:46 UTC during isolated test execution.
|
|
||||||
|
|
||||||
New isolated runner hides live wallets, service buses, container storage and host
|
|
||||||
process IDs, supplies a private network and temporary writable fixture paths,
|
|
||||||
and keeps host filesystems read-only. An independent boundary probe passed.
|
|
||||||
Test-only service helpers use a temporary Quadlet directory and simulated service
|
|
||||||
results; mocked runtimes skip real Podman socket/network provisioning. Host file
|
|
||||||
helpers require the isolated-runner marker and execute inside the namespace
|
|
||||||
instead of escaping through sudo/systemd-run. Release harness and AGENTS now
|
|
||||||
require this runner. Initial isolation trials correctly blocked host operations
|
|
||||||
and exposed fixture permission assumptions; final runner compiles and executes
|
|
||||||
the full suite with those fixture paths isolated. No final pass claimed yet.
|
|
||||||
|
|
||||||
Main dashboard candidate and AIUI build at b634f41a are now deployed on dev; served
|
|
||||||
index SHA matches the build. Live package.versions returns bitcoinPrune=false
|
|
||||||
for Core and Knots, preserving current automatic mode. Existing full chain stays
|
|
||||||
unpruned. Final backend (Files/cached response/legacy UI delivery follow-ups) is
|
|
||||||
not yet deployed; earlier 0f85f588 backend remains live on both nodes.
|
|
||||||
|
|
||||||
Final isolated backend run: **1,553 passed, zero failed, four existing ignored**
|
|
||||||
in 13 seconds after compilation. Boundary probe confirms no host service buses,
|
|
||||||
live wallet data, host process IDs, or external network. Bitcoin/LND start times
|
|
||||||
remained unchanged during isolated execution. Production helpers are unchanged;
|
|
||||||
the namespace-specific command behavior is compiled only into unit tests.
|
|
||||||
Release and ISO gates now use the isolated runner.
|
|
||||||
|
|
||||||
### Final backend deployment and App Store follow-up — 19:36 UTC
|
|
||||||
|
|
||||||
Full release harness passed: static/catalog checks, frontend type-check and
|
|
||||||
1,117 frontend tests, cargo-check, and isolated backend suite (1,553 passed,
|
|
||||||
four existing ignored). Final optimized backend built successfully; SHA256
|
|
||||||
16a173129672cbb40c250446ec52ba4a9bd1974cbb3a4988f90c6f3187b7a1f7.
|
|
||||||
Deployed to dev. Legacy :local LND companion automatically rebuilt at 19:35 UTC
|
|
||||||
and restarted onto image 702c0cd88fb5c8a561c76dabdb96c40648dd62d401c78f2e10d4318b06f02abe.
|
|
||||||
Served UI bytes match candidate source. Native Bitcoin/LND start times unchanged.
|
|
||||||
|
|
||||||
Actual desktop pruning screenshot exposed horizontal overflow; moved the
|
|
||||||
explanation below the app header. The App Store uses Marketplace.vue, a separate
|
|
||||||
install path from Discover.vue. Its first Install button bypassed the version
|
|
||||||
modal. The browser check therefore sent an unintended Knots install request at
|
|
||||||
19:28 UTC. Core remained running, no Knots container was created, and the full
|
|
||||||
chain was not pruned. Removed only the newly created Knots installed-app record
|
|
||||||
and newly created version config; preserved root-only rollback copies.
|
|
||||||
|
|
||||||
Marketplace now uses the shared version/pruning modal. Added integration tests
|
|
||||||
for both Core and Knots: no install request until confirmation, selected version
|
|
||||||
and pruning forwarded, cancellation sends no install request. Four Marketplace
|
|
||||||
tests pass (three new plus existing refresh check). Further browser checks block
|
|
||||||
package.install requests at their network boundary. Final frontend rebuild and
|
|
||||||
post-fix live checks remain pending. Final paid-file follow-up is still pending.
|
|
||||||
|
|
||||||
### Unsigned release candidate ready — 19:46 UTC
|
|
||||||
|
|
||||||
Final frontend source/build attribution: 3612458e. Production dashboard and AIUI
|
|
||||||
builds passed. Final frontend suite: 1,120 tests across 139 files passed.
|
|
||||||
Desktop 1280px and mobile 390px browser checks passed for the app detail pruning
|
|
||||||
choice and App Store version modal; no horizontal overflow and no installation
|
|
||||||
request. Screenshot review confirms readable controls and explanation. Browser
|
|
||||||
installation requests are blocked during these selection-only checks.
|
|
||||||
|
|
||||||
Final backend SHA above matches both dev and Shorty. A fresh one-sat purchase
|
|
||||||
passed on those exact binaries: correct file bytes, both response field aliases,
|
|
||||||
exact one-sat refund on underpayment, zero-charge cached repeat, and exact Files
|
|
||||||
copy. Temporary seller entries/files and Files test copy removed; transaction
|
|
||||||
audit and owned cache retained. Total net transfer during the two live purchase
|
|
||||||
rounds: two sats from dev to Shorty. Desktop/mobile LND waiting checks passed
|
|
||||||
again on the automatically rebuilt companion. Native Bitcoin and LND stayed up.
|
|
||||||
|
|
||||||
Prepared, unsigned files:
|
|
||||||
- releases/pending/v1.8.20-alpha/app-catalog.json
|
|
||||||
- releases/pending/v1.8.20-alpha/manifest.json
|
|
||||||
|
|
||||||
Staged OTA backend: 64,716,656 bytes, SHA256
|
|
||||||
16a173129672cbb40c250446ec52ba4a9bd1974cbb3a4988f90c6f3187b7a1f7.
|
|
||||||
Frontend archive: 97,152,297 bytes, SHA256
|
|
||||||
658b78fce0dfa20a627c987dd153b24cbac15adbde905cc6518744c637e12802.
|
|
||||||
Artifact sizes/hashes/release notes validate. Checked actual archive: flat
|
|
||||||
layout, readable root permissions, exact doctor/LND UI source bytes, and fresh
|
|
||||||
AIUI attribution. Catalog has zero metadata drift and passes fleet registry trust.
|
|
||||||
|
|
||||||
Remaining: user-local release-root signatures, Framework's final display
|
|
||||||
confirmation, signed publication to git/ngit, then raw ISO build/boot test/signing
|
|
||||||
and publication. No v1.8.20 public release or tag exists yet. Four pre-existing
|
|
||||||
hardware/live tests remain ignored. Bitcoin sync-to-ready recovery is covered
|
|
||||||
by deterministic tests; the live node remains in initial sync. Do not describe
|
|
||||||
these checks as proof against every possible network/payment failure.
|
|
||||||
|
|
||||||
### Signing and release authorization — 2026-09-30
|
|
||||||
|
|
||||||
Both catalog and OTA signatures verify against the pinned release root. Staged
|
|
||||||
artifact hash/size checks and catalog drift/trust checks pass. User accepted the
|
|
||||||
remaining Framework display check and explicitly authorized release. Publication
|
|
||||||
and ISO build may proceed; do not regenerate the signed manifest or artifacts.
|
|
||||||
Generated
+2
-2
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"version": "1.8.19-alpha",
|
"version": "1.8.17-alpha",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"version": "1.8.19-alpha",
|
"version": "1.8.17-alpha",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@scure/bip39": "^2.2.0",
|
"@scure/bip39": "^2.2.0",
|
||||||
"@types/dompurify": "^3.0.5",
|
"@types/dompurify": "^3.0.5",
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "1.8.20-alpha",
|
"version": "1.8.17-alpha",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"start": "./start-dev.sh",
|
"start": "./start-dev.sh",
|
||||||
|
|||||||
@@ -42,7 +42,6 @@ export interface PackageVersionsResponse {
|
|||||||
pinnedVersion: string | null
|
pinnedVersion: string | null
|
||||||
autoUpdate: boolean
|
autoUpdate: boolean
|
||||||
versions: CatalogVersionInfo[]
|
versions: CatalogVersionInfo[]
|
||||||
bitcoinPrune?: boolean | null
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export interface AppGatePortStatus {
|
export interface AppGatePortStatus {
|
||||||
|
|||||||
@@ -1,21 +0,0 @@
|
|||||||
<template>
|
|
||||||
<div class="mt-5 space-y-2">
|
|
||||||
<label class="flex items-center gap-2 text-sm text-white/80">
|
|
||||||
<input v-model="model" type="checkbox" class="accent-orange-400" />
|
|
||||||
Prune Bitcoin to save disk space
|
|
||||||
</label>
|
|
||||||
<p class="text-xs text-white/50">
|
|
||||||
Keeps about 50 GB of recent blocks, using the same settings as automatic
|
|
||||||
pruning on smaller disks. All blocks are still downloaded and verified.
|
|
||||||
Mempool and other apps that need the full blockchain won’t be available.
|
|
||||||
Turning pruning off later requires downloading the blockchain again.
|
|
||||||
</p>
|
|
||||||
<p v-if="!model" class="text-xs text-white/50">
|
|
||||||
Automatic pruning still applies on disks smaller than 1 TB.
|
|
||||||
</p>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</template>
|
|
||||||
<script setup lang="ts">
|
|
||||||
const model = defineModel<boolean>({ default: false })
|
|
||||||
</script>
|
|
||||||
@@ -3,9 +3,6 @@ import { ref, computed, onMounted } from 'vue'
|
|||||||
import { rpcClient } from '@/api/rpc-client'
|
import { rpcClient } from '@/api/rpc-client'
|
||||||
import SeedRevealPanel from '@/components/SeedRevealPanel.vue'
|
import SeedRevealPanel from '@/components/SeedRevealPanel.vue'
|
||||||
|
|
||||||
defineProps<{ setupOnly?: boolean }>()
|
|
||||||
const emit = defineEmits<{ ready: [] }>()
|
|
||||||
|
|
||||||
// Ecash (Cashu) wallet backup card — the same shape as the node recovery
|
// Ecash (Cashu) wallet backup card — the same shape as the node recovery
|
||||||
// phrase and the Lightning seed cards, deliberately: a third reveal pattern
|
// phrase and the Lightning seed cards, deliberately: a third reveal pattern
|
||||||
// would be a third thing to learn.
|
// would be a third thing to learn.
|
||||||
@@ -105,14 +102,12 @@ async function submitReveal() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function closeReveal() {
|
function closeReveal() {
|
||||||
const established = revealedWords.value.length > 0
|
|
||||||
showRevealModal.value = false
|
showRevealModal.value = false
|
||||||
revealedWords.value = []
|
revealedWords.value = []
|
||||||
revealPassword.value = ''
|
revealPassword.value = ''
|
||||||
revealCode.value = ''
|
revealCode.value = ''
|
||||||
revealPassphrase.value = ''
|
revealPassphrase.value = ''
|
||||||
showRevealPassphrase.value = false
|
showRevealPassphrase.value = false
|
||||||
if (established) emit('ready')
|
|
||||||
}
|
}
|
||||||
|
|
||||||
async function copyRevealedWords() {
|
async function copyRevealedWords() {
|
||||||
@@ -226,54 +221,61 @@ async function restoreFromPhrase() {
|
|||||||
Your ecash has no backup yet
|
Your ecash has no backup yet
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="flex flex-col gap-3">
|
<div class="flex items-start justify-between gap-4">
|
||||||
<div class="min-w-0">
|
<div class="min-w-0">
|
||||||
<h2 class="text-xl font-semibold text-white/96 mb-1">{{ setupOnly ? 'Set up your Cashu Lightning address' : 'Ecash backup phrase' }}</h2>
|
<h2 class="text-xl font-semibold text-white/96 mb-1">Ecash backup phrase</h2>
|
||||||
|
|
||||||
<p v-if="status?.active && status?.source === 'node-seed'" class="text-sm leading-relaxed text-white/60">
|
<p v-if="status?.active && status?.source === 'node-seed'" class="text-sm text-white/60">
|
||||||
Your node's recovery phrase also recovers this ecash phrase. Reveal its 24 words
|
Your ecash wallet has its own 24-word phrase, derived from this node's recovery
|
||||||
to restore in a compatible Cashu wallet without sharing your node's phrase.
|
phrase — so the words you already wrote down cover your ecash too. Reveal it here
|
||||||
|
if you want to restore your ecash into another wallet (Minibits, Nutstash,
|
||||||
|
<span class="font-mono">cdk-cli</span>) without handing over the node's own seed.
|
||||||
</p>
|
</p>
|
||||||
<p v-else-if="status?.active" class="text-sm leading-relaxed text-white/60">
|
<p v-else-if="status?.active" class="text-sm text-white/60">
|
||||||
Save your 24-word ecash phrase to restore this wallet here or in another
|
Your ecash wallet has its own 24-word phrase. Reveal it to write it down, or to
|
||||||
compatible Cashu wallet.
|
restore your ecash into another wallet (Minibits, Nutstash,
|
||||||
|
<span class="font-mono">cdk-cli</span>).
|
||||||
</p>
|
</p>
|
||||||
<p v-else class="text-sm leading-relaxed text-white/60">
|
<p v-else class="text-sm text-white/60">
|
||||||
If this node's coin file is lost, your ecash is lost. Set up a phrase to recover
|
Ecash is a bearer instrument: the coins live in a file on this node, and right now
|
||||||
future coins; existing coins aren't covered.
|
nothing can bring them back if that file is lost. Setting up a backup phrase fixes
|
||||||
|
that for every coin minted from then on.
|
||||||
<template v-if="status?.derivable_from_node_seed">
|
<template v-if="status?.derivable_from_node_seed">
|
||||||
Your node's recovery phrase will also recover this phrase.
|
It's derived from this node's recovery phrase, so there's nothing new to write down.
|
||||||
</template>
|
</template>
|
||||||
<template v-else>
|
<template v-else>
|
||||||
This node has no saved seed, so write down and keep the new phrase separately.
|
This node has no encrypted seed backup to derive from, so the phrase will be its
|
||||||
|
own — you'll need to write these words down and keep them.
|
||||||
</template>
|
</template>
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p v-if="status?.source === 'independent' || status?.source === 'imported'" class="mt-2 text-xs text-orange-300/90">
|
<p v-if="status?.source === 'independent' || status?.source === 'imported'" class="mt-2 text-xs text-orange-300/90">
|
||||||
{{ status?.source === 'imported' ? 'This imported phrase' : 'This phrase' }} is separate
|
This wallet's phrase was <strong>not</strong> derived from the node's recovery
|
||||||
from your node's backup. <strong>Only these words recover this ecash wallet.</strong>
|
phrase{{ status?.source === 'imported' ? ' — it was imported' : '' }}, so restoring
|
||||||
|
the node will not bring the ecash back. Only these words will.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
class="w-full glass-button rounded-lg px-4 py-2 text-sm font-medium"
|
class="shrink-0 glass-button rounded-lg px-4 py-2 text-sm font-medium"
|
||||||
:class="!status?.active ? 'bg-orange-500/20 border-orange-400/30' : ''"
|
:class="!status?.active ? 'bg-orange-500/20 border-orange-400/30' : ''"
|
||||||
@click="openReveal"
|
@click="openReveal"
|
||||||
>{{ status?.active ? 'Reveal' : (setupOnly ? 'Set up address' : 'Set up backup') }}</button>
|
>{{ status?.active ? 'Reveal' : 'Set up backup' }}</button>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div v-if="status?.active && !setupOnly" class="mt-4 pt-4 border-t border-white/10">
|
<div v-if="status?.active" class="mt-4 pt-4 border-t border-white/10">
|
||||||
<div class="flex flex-col gap-3">
|
<div class="flex items-start justify-between gap-4">
|
||||||
<p class="text-sm leading-relaxed text-white/60 min-w-0">
|
<p class="text-sm text-white/60 min-w-0">
|
||||||
<span class="text-white/80 font-medium">Restore from this phrase.</span>
|
<span class="text-white/80 font-medium">Restore from this phrase.</span>
|
||||||
Recover unspent coins from your mint. Safe to repeat; coins you already hold
|
Asks your mint which coins it has signed for these words and puts back any that
|
||||||
won't be duplicated.
|
are still unspent. Safe to run at any time — it never duplicates coins you already
|
||||||
|
hold.
|
||||||
</p>
|
</p>
|
||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
class="w-full glass-button rounded-lg px-4 py-2 text-sm font-medium disabled:opacity-50"
|
class="shrink-0 glass-button rounded-lg px-4 py-2 text-sm font-medium disabled:opacity-50"
|
||||||
:disabled="restoring"
|
:disabled="restoring"
|
||||||
@click="restoreFromPhrase"
|
@click="restoreFromPhrase"
|
||||||
>{{ restoring ? 'Scanning…' : 'Restore' }}</button>
|
>{{ restoring ? 'Scanning…' : 'Restore' }}</button>
|
||||||
@@ -282,16 +284,16 @@ async function restoreFromPhrase() {
|
|||||||
<p v-if="restoreError" role="alert" class="mt-3 text-xs alert-error px-3 py-2 rounded-lg">{{ restoreError }}</p>
|
<p v-if="restoreError" role="alert" class="mt-3 text-xs alert-error px-3 py-2 rounded-lg">{{ restoreError }}</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div v-if="!setupOnly" class="mt-4 pt-4 border-t border-white/10">
|
<div class="mt-4 pt-4 border-t border-white/10">
|
||||||
<div class="flex flex-col gap-3">
|
<div class="flex items-start justify-between gap-4">
|
||||||
<p class="text-sm leading-relaxed text-white/60 min-w-0">
|
<p class="text-sm text-white/60 min-w-0">
|
||||||
<span class="text-white/80 font-medium">Use a phrase from another wallet.</span>
|
<span class="text-white/80 font-medium">Use a phrase from another wallet.</span>
|
||||||
Import a phrase from Minibits, Nutstash or <span class="font-mono">cdk-cli</span>
|
Point this wallet at a phrase you already have — from Minibits, Nutstash or
|
||||||
to restore its coins here.
|
<span class="font-mono">cdk-cli</span> — so its coins can be restored here.
|
||||||
</p>
|
</p>
|
||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
class="w-full glass-button rounded-lg px-4 py-2 text-sm font-medium"
|
class="shrink-0 glass-button rounded-lg px-4 py-2 text-sm font-medium"
|
||||||
@click="openImport"
|
@click="openImport"
|
||||||
>Import</button>
|
>Import</button>
|
||||||
</div>
|
</div>
|
||||||
@@ -317,7 +319,7 @@ async function restoreFromPhrase() {
|
|||||||
</template>
|
</template>
|
||||||
|
|
||||||
<template v-else>
|
<template v-else>
|
||||||
<p class="text-sm leading-relaxed text-white/60 mb-4">
|
<p class="text-sm text-white/60 mb-4">
|
||||||
Paste the 24-word phrase from the other wallet. The coins already in this wallet
|
Paste the 24-word phrase from the other wallet. The coins already in this wallet
|
||||||
stay spendable either way.
|
stay spendable either way.
|
||||||
</p>
|
</p>
|
||||||
@@ -374,8 +376,9 @@ async function restoreFromPhrase() {
|
|||||||
</h3>
|
</h3>
|
||||||
|
|
||||||
<template v-if="revealedWords.length === 0">
|
<template v-if="revealedWords.length === 0">
|
||||||
<p class="text-sm leading-relaxed text-white/60 mb-4">
|
<p class="text-sm text-white/60 mb-4">
|
||||||
Confirm your credentials to {{ status?.active ? 'reveal' : 'set up' }} your ecash phrase.
|
Confirm your credentials to
|
||||||
|
{{ status?.active ? 'display the 24-word ecash phrase' : 'derive and display your ecash backup phrase' }}.
|
||||||
</p>
|
</p>
|
||||||
<form @submit.prevent="submitReveal" class="space-y-3">
|
<form @submit.prevent="submitReveal" class="space-y-3">
|
||||||
<div>
|
<div>
|
||||||
@@ -404,12 +407,12 @@ async function restoreFromPhrase() {
|
|||||||
<SeedRevealPanel :words="revealedWords" />
|
<SeedRevealPanel :words="revealedWords" />
|
||||||
<p class="text-xs text-white/40 mt-3">
|
<p class="text-xs text-white/40 mt-3">
|
||||||
<template v-if="revealedSource === 'node-seed'">
|
<template v-if="revealedSource === 'node-seed'">
|
||||||
Your node's recovery phrase recovers this ecash wallet too. Use these words
|
Derived from this node's recovery phrase — restoring the node restores this
|
||||||
separately in a compatible Cashu (NUT-13) wallet.
|
ecash wallet too. These words also restore it into any NUT-13 wallet.
|
||||||
</template>
|
</template>
|
||||||
<template v-else>
|
<template v-else>
|
||||||
Write these words down. They are the <strong>only</strong> way to recover
|
This phrase is independent of the node's recovery phrase. It is the
|
||||||
this ecash wallet; your node's phrase won't recover it.
|
<strong>only</strong> way to restore this ecash wallet — write it down.
|
||||||
</template>
|
</template>
|
||||||
</p>
|
</p>
|
||||||
<div class="flex gap-2 pt-4">
|
<div class="flex gap-2 pt-4">
|
||||||
|
|||||||
@@ -31,7 +31,7 @@
|
|||||||
class="w-full rounded-lg bg-white/[0.06] border border-white/10 text-white px-3 py-2 text-sm font-mono focus:outline-none focus:border-orange-400/60"
|
class="w-full rounded-lg bg-white/[0.06] border border-white/10 text-white px-3 py-2 text-sm font-mono focus:outline-none focus:border-orange-400/60"
|
||||||
/>
|
/>
|
||||||
<p class="text-[11px] text-white/40 mt-1">
|
<p class="text-[11px] text-white/40 mt-1">
|
||||||
Defaults to mempool.space. Any Mempool-compatible instance works — you can change this
|
Defaults to tx1138.com. Any Mempool-compatible instance works — you can change this
|
||||||
any time in Settings → System.
|
any time in Settings → System.
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -35,8 +35,6 @@
|
|||||||
<p class="text-white/40 text-xs">{{ t('marketplace.installModalHint') }}</p>
|
<p class="text-white/40 text-xs">{{ t('marketplace.installModalHint') }}</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<BitcoinPruningChoice v-if="isBitcoin && !loading" v-model="prune" />
|
|
||||||
|
|
||||||
<template #footer>
|
<template #footer>
|
||||||
<div class="flex gap-2 mt-6">
|
<div class="flex gap-2 mt-6">
|
||||||
<button
|
<button
|
||||||
@@ -60,10 +58,9 @@
|
|||||||
</template>
|
</template>
|
||||||
|
|
||||||
<script setup lang="ts">
|
<script setup lang="ts">
|
||||||
import { computed, ref, watch } from 'vue'
|
import { ref, watch } from 'vue'
|
||||||
import { useI18n } from 'vue-i18n'
|
import { useI18n } from 'vue-i18n'
|
||||||
import BaseModal from './BaseModal.vue'
|
import BaseModal from './BaseModal.vue'
|
||||||
import BitcoinPruningChoice from './BitcoinPruningChoice.vue'
|
|
||||||
import { rpcClient, type CatalogVersionInfo } from '../api/rpc-client'
|
import { rpcClient, type CatalogVersionInfo } from '../api/rpc-client'
|
||||||
import { displayVersion } from '@/utils/version'
|
import { displayVersion } from '@/utils/version'
|
||||||
|
|
||||||
@@ -76,16 +73,13 @@ const props = defineProps<{
|
|||||||
const emit = defineEmits<{
|
const emit = defineEmits<{
|
||||||
close: []
|
close: []
|
||||||
// Emits the version string the runner chose (e.g. "latest" or "29.3.knots20260508").
|
// Emits the version string the runner chose (e.g. "latest" or "29.3.knots20260508").
|
||||||
confirm: [version: string, prune?: boolean]
|
confirm: [version: string]
|
||||||
}>()
|
}>()
|
||||||
|
|
||||||
const { t } = useI18n()
|
const { t } = useI18n()
|
||||||
const loading = ref(false)
|
const loading = ref(false)
|
||||||
const versions = ref<CatalogVersionInfo[]>([])
|
const versions = ref<CatalogVersionInfo[]>([])
|
||||||
const selected = ref('')
|
const selected = ref('')
|
||||||
const prune = ref(false)
|
|
||||||
const pruneKnown = ref(false)
|
|
||||||
const isBitcoin = computed(() => ['bitcoin-core', 'bitcoin-knots'].includes(props.appId))
|
|
||||||
|
|
||||||
// Latest reads as a sentence (no "v" prefix); concrete versions are normalized.
|
// Latest reads as a sentence (no "v" prefix); concrete versions are normalized.
|
||||||
function optionLabel(v: CatalogVersionInfo): string {
|
function optionLabel(v: CatalogVersionInfo): string {
|
||||||
@@ -98,16 +92,12 @@ function optionLabel(v: CatalogVersionInfo): string {
|
|||||||
|
|
||||||
async function load() {
|
async function load() {
|
||||||
loading.value = true
|
loading.value = true
|
||||||
prune.value = false
|
|
||||||
pruneKnown.value = false
|
|
||||||
versions.value = []
|
versions.value = []
|
||||||
selected.value = ''
|
selected.value = ''
|
||||||
try {
|
try {
|
||||||
const info = await rpcClient.getPackageVersions(props.appId)
|
const info = await rpcClient.getPackageVersions(props.appId)
|
||||||
// catalog_versions() returns the list default(=latest)-first, so versions[0]
|
// catalog_versions() returns the list default(=latest)-first, so versions[0]
|
||||||
// is the latest — pre-select it.
|
// is the latest — pre-select it.
|
||||||
pruneKnown.value = typeof info.bitcoinPrune === 'boolean'
|
|
||||||
prune.value = info.bitcoinPrune === true
|
|
||||||
versions.value = info.versions || []
|
versions.value = info.versions || []
|
||||||
selected.value = info.default || versions.value.find((v) => v.default)?.version || versions.value[0]?.version || 'latest'
|
selected.value = info.default || versions.value.find((v) => v.default)?.version || versions.value[0]?.version || 'latest'
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
@@ -121,7 +111,7 @@ async function load() {
|
|||||||
|
|
||||||
function confirm() {
|
function confirm() {
|
||||||
if (!selected.value) return
|
if (!selected.value) return
|
||||||
emit('confirm', selected.value, isBitcoin.value && (pruneKnown.value || prune.value) ? prune.value : undefined)
|
emit('confirm', selected.value)
|
||||||
}
|
}
|
||||||
|
|
||||||
watch(
|
watch(
|
||||||
|
|||||||
@@ -77,13 +77,8 @@
|
|||||||
<div v-else-if="lnAddressLoading" class="mb-4 text-center text-white/50 text-sm py-4">
|
<div v-else-if="lnAddressLoading" class="mb-4 text-center text-white/50 text-sm py-4">
|
||||||
{{ t('receiveBitcoin.lnAddressLoading') }}
|
{{ t('receiveBitcoin.lnAddressLoading') }}
|
||||||
</div>
|
</div>
|
||||||
<div v-else-if="lnAddressNeedsSetup" class="mb-3">
|
|
||||||
<p class="text-sm text-white/70 mb-3">Set up this wallet's recovery phrase once to enable its Lightning address.</p>
|
|
||||||
<EcashSeedBackup setup-only @ready="loadLnAddress" />
|
|
||||||
</div>
|
|
||||||
<div v-else-if="lnAddressError" class="mb-3 text-xs text-white/40">
|
<div v-else-if="lnAddressError" class="mb-3 text-xs text-white/40">
|
||||||
{{ t('receiveBitcoin.lnAddressUnavailable') }}
|
{{ t('receiveBitcoin.lnAddressUnavailable') }}
|
||||||
<button type="button" class="glass-button rounded-lg px-3 py-2 ml-2" @click="loadLnAddress">Retry</button>
|
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="mb-3">
|
<div class="mb-3">
|
||||||
@@ -137,7 +132,6 @@ import { useI18n } from 'vue-i18n'
|
|||||||
import { rpcClient } from '@/api/rpc-client'
|
import { rpcClient } from '@/api/rpc-client'
|
||||||
import BaseModal from '@/components/BaseModal.vue'
|
import BaseModal from '@/components/BaseModal.vue'
|
||||||
import CopyButton from '@/components/CopyButton.vue'
|
import CopyButton from '@/components/CopyButton.vue'
|
||||||
import EcashSeedBackup from '@/components/EcashSeedBackup.vue'
|
|
||||||
import PaymentSuccessPane, { type SuccessRow } from '@/components/PaymentSuccessPane.vue'
|
import PaymentSuccessPane, { type SuccessRow } from '@/components/PaymentSuccessPane.vue'
|
||||||
import { explainReceiveAddressFailure } from '@/utils/bitcoinReceive'
|
import { explainReceiveAddressFailure } from '@/utils/bitcoinReceive'
|
||||||
import { useLightningRequired } from '@/composables/useLightningRequired'
|
import { useLightningRequired } from '@/composables/useLightningRequired'
|
||||||
@@ -220,7 +214,6 @@ const error = ref('')
|
|||||||
const lnAddress = ref('')
|
const lnAddress = ref('')
|
||||||
const lnAddressLoading = ref(false)
|
const lnAddressLoading = ref(false)
|
||||||
const lnAddressError = ref(false)
|
const lnAddressError = ref(false)
|
||||||
const lnAddressNeedsSetup = ref(false)
|
|
||||||
// A payment the backend fetched (and so already consumed at Minibits) but
|
// A payment the backend fetched (and so already consumed at Minibits) but
|
||||||
// couldn't redeem yet — it's queued for automatic retry, not lost, but the
|
// couldn't redeem yet — it's queued for automatic retry, not lost, but the
|
||||||
// operator should see it rather than have it be a silent, unbounded wait.
|
// operator should see it rather than have it be a silent, unbounded wait.
|
||||||
@@ -237,7 +230,6 @@ async function loadLnAddress() {
|
|||||||
if (lnAddress.value || lnAddressLoading.value) return
|
if (lnAddress.value || lnAddressLoading.value) return
|
||||||
lnAddressLoading.value = true
|
lnAddressLoading.value = true
|
||||||
lnAddressError.value = false
|
lnAddressError.value = false
|
||||||
lnAddressNeedsSetup.value = false
|
|
||||||
try {
|
try {
|
||||||
const res = await rpcClient.call<{ address?: string }>({
|
const res = await rpcClient.call<{ address?: string }>({
|
||||||
method: 'wallet.ecash-lnaddress',
|
method: 'wallet.ecash-lnaddress',
|
||||||
@@ -253,16 +245,6 @@ async function loadLnAddress() {
|
|||||||
}
|
}
|
||||||
} catch {
|
} catch {
|
||||||
lnAddressError.value = true
|
lnAddressError.value = true
|
||||||
// A legacy wallet may hold valid proofs without having a recovery phrase.
|
|
||||||
// Use the existing authenticated setup flow; never silently create a new
|
|
||||||
// identity or send the user to an unexplained generic service error.
|
|
||||||
try {
|
|
||||||
const seedStatus = await rpcClient.call<{ active: boolean; can_activate: boolean }>({
|
|
||||||
method: 'wallet.ecash-seed-status',
|
|
||||||
timeout: 5000,
|
|
||||||
})
|
|
||||||
lnAddressNeedsSetup.value = seedStatus.active === false && seedStatus.can_activate === true
|
|
||||||
} catch { /* Keep the retryable service error when status is unavailable. */ }
|
|
||||||
} finally {
|
} finally {
|
||||||
lnAddressLoading.value = false
|
lnAddressLoading.value = false
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -185,7 +185,7 @@
|
|||||||
@change="saveExplorer"
|
@change="saveExplorer"
|
||||||
/>
|
/>
|
||||||
<p class="text-[11px] text-white/40 mt-1">
|
<p class="text-[11px] text-white/40 mt-1">
|
||||||
Any Mempool-compatible instance works. Default: mempool.space.
|
Any Mempool-compatible instance works. Default: tx1138.com.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<div class="mt-3 p-3 rounded-lg border border-amber-400/25 bg-amber-500/10 text-amber-200/80 text-xs leading-relaxed">
|
<div class="mt-3 p-3 rounded-lg border border-amber-400/25 bg-amber-500/10 text-amber-200/80 text-xs leading-relaxed">
|
||||||
|
|||||||
@@ -22,37 +22,6 @@ describe('EcashSeedBackup reveal credentials (#127)', () => {
|
|||||||
document.body.innerHTML = ''
|
document.body.innerHTML = ''
|
||||||
})
|
})
|
||||||
|
|
||||||
it('signals readiness only after authenticated setup is finished and clears the words', async () => {
|
|
||||||
vi.mocked(rpcClient.call).mockImplementation(async ({ method }) => {
|
|
||||||
if (method === 'wallet.ecash-seed-status') {
|
|
||||||
return { active: false, can_activate: true, derivable_from_node_seed: true, source: null } as never
|
|
||||||
}
|
|
||||||
if (method === 'wallet.ecash-seed-reveal') {
|
|
||||||
return { words: [...Array(23).fill('abandon'), 'art'], source: 'node-seed' } as never
|
|
||||||
}
|
|
||||||
throw new Error('unexpected request')
|
|
||||||
})
|
|
||||||
wrapper = mount(EcashSeedBackup, { props: { setupOnly: true }, attachTo: document.body })
|
|
||||||
await flushPromises()
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
const cancel = Array.from(document.body.querySelectorAll('button')).find(b => b.textContent === 'Cancel')!
|
|
||||||
cancel.click()
|
|
||||||
await flushPromises()
|
|
||||||
expect(wrapper.emitted('ready')).toBeUndefined()
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
const password = document.body.querySelector<HTMLInputElement>('input[autocomplete="current-password"]')!
|
|
||||||
password.value = 'test-password'
|
|
||||||
password.dispatchEvent(new Event('input', { bubbles: true }))
|
|
||||||
document.body.querySelector('form')!.dispatchEvent(new Event('submit', { bubbles: true, cancelable: true }))
|
|
||||||
await flushPromises()
|
|
||||||
expect(wrapper.emitted('ready')).toBeUndefined()
|
|
||||||
Array.from(document.body.querySelectorAll('button')).find(b => b.textContent === 'Done')!.click()
|
|
||||||
await flushPromises()
|
|
||||||
expect(wrapper.emitted('ready')).toEqual([[]])
|
|
||||||
expect(document.body.querySelector('[aria-labelledby="reveal-ecash-seed-title"]')).toBeNull()
|
|
||||||
expect(document.body.textContent).not.toContain('abandon')
|
|
||||||
})
|
|
||||||
|
|
||||||
it('asks for a separate backup passphrase only after password decryption fails', async () => {
|
it('asks for a separate backup passphrase only after password decryption fails', async () => {
|
||||||
vi.mocked(rpcClient.call)
|
vi.mocked(rpcClient.call)
|
||||||
.mockResolvedValueOnce({
|
.mockResolvedValueOnce({
|
||||||
|
|||||||
@@ -1,67 +0,0 @@
|
|||||||
import { mount, flushPromises } from '@vue/test-utils'
|
|
||||||
import { describe, it, expect, vi } from 'vitest'
|
|
||||||
import { createI18n } from 'vue-i18n'
|
|
||||||
import InstallVersionModal from '../InstallVersionModal.vue'
|
|
||||||
const versions = vi.hoisted(() => vi.fn())
|
|
||||||
vi.mock('../../api/rpc-client', () => ({ rpcClient: { getPackageVersions: versions } }))
|
|
||||||
const i18n = createI18n({ legacy: false, locale: 'en', missingWarn: false, fallbackWarn: false, messages: { en: { common: { install: 'Install', cancel: 'Cancel' } } } })
|
|
||||||
function modal(id = 'bitcoin-core') {
|
|
||||||
return mount(InstallVersionModal, {
|
|
||||||
props: { show: true, appId: id, app: { id, title: id } },
|
|
||||||
global: { plugins: [i18n], stubs: { BaseModal: { template: '<div><slot/><slot name="footer"/></div>' } } },
|
|
||||||
})
|
|
||||||
}
|
|
||||||
describe('Bitcoin install storage choice', () => {
|
|
||||||
it.each(['bitcoin-core', 'bitcoin-knots'])('sends chosen version and explicit pruning for %s', async id => {
|
|
||||||
versions.mockResolvedValue({ bitcoinPrune: false, default: 'latest', versions: [{ version: 'latest' }, { version: '28.4' }] })
|
|
||||||
const wrapper = modal(id)
|
|
||||||
await flushPromises()
|
|
||||||
await wrapper.get('select').setValue('28.4')
|
|
||||||
await wrapper.get('input[type=checkbox]').setValue(true)
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
expect(wrapper.emitted('confirm')).toEqual([['28.4', true]])
|
|
||||||
expect(wrapper.text()).toContain('automatic pruning')
|
|
||||||
expect(wrapper.text()).toContain('Mempool')
|
|
||||||
})
|
|
||||||
it('keeps automatic disk selection by default and resets on reopening', async () => {
|
|
||||||
versions.mockResolvedValue({ bitcoinPrune: false, versions: [{ version: 'latest' }] })
|
|
||||||
const wrapper = modal()
|
|
||||||
await flushPromises()
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
expect(wrapper.emitted('confirm')).toEqual([['latest', false]])
|
|
||||||
await wrapper.get('input').setValue(true)
|
|
||||||
await wrapper.setProps({ show: false })
|
|
||||||
await wrapper.setProps({ show: true })
|
|
||||||
await flushPromises()
|
|
||||||
expect((wrapper.get('input').element as HTMLInputElement).checked).toBe(false)
|
|
||||||
})
|
|
||||||
it('still allows choosing pruning when version lookup fails', async () => {
|
|
||||||
versions.mockRejectedValue(new Error('offline'))
|
|
||||||
const wrapper = modal()
|
|
||||||
await flushPromises()
|
|
||||||
await wrapper.get('input').setValue(true)
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
expect(wrapper.emitted('confirm')).toEqual([['latest', true]])
|
|
||||||
})
|
|
||||||
it('remembers the node pruning preference when reinstalling or switching Bitcoin variants', async () => {
|
|
||||||
versions.mockResolvedValue({ bitcoinPrune: true, versions: [{ version: 'latest' }] })
|
|
||||||
const wrapper = modal('bitcoin-knots')
|
|
||||||
await flushPromises()
|
|
||||||
expect((wrapper.get('input').element as HTMLInputElement).checked).toBe(true)
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
expect(wrapper.emitted('confirm')).toEqual([['latest', true]])
|
|
||||||
})
|
|
||||||
it('does not turn off a saved pruning preference when its lookup fails', async () => {
|
|
||||||
versions.mockRejectedValue(new Error('offline'))
|
|
||||||
const wrapper = modal()
|
|
||||||
await flushPromises()
|
|
||||||
await wrapper.get('button').trigger('click')
|
|
||||||
expect(wrapper.emitted('confirm')).toEqual([['latest', undefined]])
|
|
||||||
})
|
|
||||||
it('does not offer Bitcoin settings for other apps', async () => {
|
|
||||||
versions.mockResolvedValue({ bitcoinPrune: false, versions: [{ version: 'latest' }] })
|
|
||||||
const wrapper = modal('other')
|
|
||||||
await flushPromises()
|
|
||||||
expect(wrapper.find('input').exists()).toBe(false)
|
|
||||||
})
|
|
||||||
})
|
|
||||||
@@ -1,7 +1,6 @@
|
|||||||
import { flushPromises, mount } from '@vue/test-utils'
|
import { flushPromises, mount } from '@vue/test-utils'
|
||||||
import { beforeEach, describe, expect, it, vi } from 'vitest'
|
import { beforeEach, describe, expect, it, vi } from 'vitest'
|
||||||
import ReceiveBitcoinModal from '../ReceiveBitcoinModal.vue'
|
import ReceiveBitcoinModal from '../ReceiveBitcoinModal.vue'
|
||||||
import EcashSeedBackup from '../EcashSeedBackup.vue'
|
|
||||||
import { rpcClient } from '@/api/rpc-client'
|
import { rpcClient } from '@/api/rpc-client'
|
||||||
|
|
||||||
vi.mock('vue-router', () => ({
|
vi.mock('vue-router', () => ({
|
||||||
@@ -40,51 +39,6 @@ beforeEach(() => {
|
|||||||
// unmounts the dialog — but the RPC-eager tab switch is exactly the kind of
|
// unmounts the dialog — but the RPC-eager tab switch is exactly the kind of
|
||||||
// path a future change could regress, so it's worth pinning down.
|
// path a future change could regress, so it's worth pinning down.
|
||||||
describe('ReceiveBitcoinModal — ecash tab click', () => {
|
describe('ReceiveBitcoinModal — ecash tab click', () => {
|
||||||
it('offers authenticated setup for an unseeded wallet and retries the address after setup', async () => {
|
|
||||||
let active = false
|
|
||||||
vi.mocked(rpcClient.call).mockImplementation(async ({ method }) => {
|
|
||||||
if (method === 'wallet.ecash-lnaddress') {
|
|
||||||
if (!active) throw new Error('The ecash wallet has no seed yet')
|
|
||||||
return { address: 'someone@minibits.cash' } as never
|
|
||||||
}
|
|
||||||
if (method === 'wallet.ecash-seed-status') {
|
|
||||||
return { active, can_activate: true, derivable_from_node_seed: true, source: null } as never
|
|
||||||
}
|
|
||||||
return {} as never
|
|
||||||
})
|
|
||||||
const wrapper = mount(ReceiveBitcoinModal, { props: { show: true }, attachTo: document.body })
|
|
||||||
const tab = Array.from(document.body.querySelectorAll('button')).find(b => b.textContent?.toLowerCase().includes('ecash'))!
|
|
||||||
tab.click()
|
|
||||||
await flushPromises()
|
|
||||||
expect(document.body.textContent).toContain('Set up your Cashu Lightning address')
|
|
||||||
expect(document.body.textContent).not.toContain('receiveBitcoin.lnAddressUnavailable')
|
|
||||||
expect(vi.mocked(rpcClient.call).mock.calls.some(([r]) => r.method === 'wallet.ecash-seed-reveal')).toBe(false)
|
|
||||||
active = true
|
|
||||||
wrapper.findComponent(EcashSeedBackup).vm.$emit('ready')
|
|
||||||
await flushPromises()
|
|
||||||
expect(document.body.textContent).toContain('someone@minibits.cash')
|
|
||||||
expect(wrapper.emitted('close')).toBeFalsy()
|
|
||||||
wrapper.unmount()
|
|
||||||
})
|
|
||||||
|
|
||||||
it('keeps a seeded wallet on the retry path during a service outage', async () => {
|
|
||||||
vi.mocked(rpcClient.call).mockImplementation(async ({ method }) => {
|
|
||||||
if (method === 'wallet.ecash-seed-status') return { active: true, can_activate: true } as never
|
|
||||||
throw new Error('service unavailable')
|
|
||||||
})
|
|
||||||
const wrapper = mount(ReceiveBitcoinModal, { props: { show: true }, attachTo: document.body })
|
|
||||||
Array.from(document.body.querySelectorAll('button')).find(b => b.textContent?.toLowerCase().includes('ecash'))!.click()
|
|
||||||
await flushPromises()
|
|
||||||
expect(wrapper.findComponent(EcashSeedBackup).exists()).toBe(false)
|
|
||||||
expect(document.body.textContent).toContain('receiveBitcoin.lnAddressUnavailable')
|
|
||||||
const retry = Array.from(document.body.querySelectorAll('button')).find(b => b.textContent === 'Retry')!
|
|
||||||
expect(retry).toBeTruthy()
|
|
||||||
retry.click()
|
|
||||||
await flushPromises()
|
|
||||||
expect(vi.mocked(rpcClient.call).mock.calls.filter(([r]) => r.method === 'wallet.ecash-lnaddress')).toHaveLength(2)
|
|
||||||
wrapper.unmount()
|
|
||||||
})
|
|
||||||
|
|
||||||
it('does not close/emit when the ecash tab is clicked and the RPC succeeds', async () => {
|
it('does not close/emit when the ecash tab is clicked and the RPC succeeds', async () => {
|
||||||
vi.mocked(rpcClient.call).mockResolvedValue({ address: 'someone@minibits.cash' } as never)
|
vi.mocked(rpcClient.call).mockResolvedValue({ address: 'someone@minibits.cash' } as never)
|
||||||
|
|
||||||
|
|||||||
@@ -76,24 +76,6 @@ describe('useTxExplorer.openTx', () => {
|
|||||||
expect(openSession).toHaveBeenCalledWith('mempool', { path: `/tx/${TX}` })
|
expect(openSession).toHaveBeenCalledWith('mempool', { path: `/tx/${TX}` })
|
||||||
})
|
})
|
||||||
|
|
||||||
it('does not open an external explorer while container discovery is pending', async () => {
|
|
||||||
const external = vi.spyOn(window, 'open').mockImplementation(() => null)
|
|
||||||
let finish!: () => void
|
|
||||||
ensureFetched.mockImplementationOnce(() => new Promise<void>(resolve => {
|
|
||||||
finish = () => { fetched = true; resolve() }
|
|
||||||
}))
|
|
||||||
const { openTx, setExplorer } = useTxExplorer()
|
|
||||||
setExplorer(DEFAULT_TX_EXPLORER, true)
|
|
||||||
const opening = openTx(TX)
|
|
||||||
expect(external).not.toHaveBeenCalled()
|
|
||||||
expect(openSession).not.toHaveBeenCalled()
|
|
||||||
finish()
|
|
||||||
await opening
|
|
||||||
expect(openSession).toHaveBeenCalledWith('mempool', { path: `/tx/${TX}` })
|
|
||||||
expect(external).not.toHaveBeenCalled()
|
|
||||||
external.mockRestore()
|
|
||||||
})
|
|
||||||
|
|
||||||
it('asks for consent only when Mempool genuinely is not installed', async () => {
|
it('asks for consent only when Mempool genuinely is not installed', async () => {
|
||||||
containerState = 'not-installed'
|
containerState = 'not-installed'
|
||||||
const { openTx, pendingTx } = useTxExplorer()
|
const { openTx, pendingTx } = useTxExplorer()
|
||||||
@@ -102,23 +84,3 @@ describe('useTxExplorer.openTx', () => {
|
|||||||
expect(pendingTx.value).toBe(TX)
|
expect(pendingTx.value).toBe(TX)
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
|
|
||||||
describe('explorer default migration', () => {
|
|
||||||
beforeEach(() => { localStorage.clear(); vi.resetModules() })
|
|
||||||
it('uses mempool.space with consent for a new browser', async () => {
|
|
||||||
const { useTxExplorer } = await import('../useTxExplorer')
|
|
||||||
expect(useTxExplorer().prefs.value).toEqual({ url: 'https://mempool.space', acknowledged: false })
|
|
||||||
})
|
|
||||||
it.each(['https://tx1138.com', 'https://tx1138.com/', 'http://tx1138.com'])('migrates %s and resets consent', async url => {
|
|
||||||
localStorage.setItem('archipelago.tx-explorer.v1', JSON.stringify({ url, acknowledged: true }))
|
|
||||||
const { useTxExplorer } = await import('../useTxExplorer')
|
|
||||||
expect(useTxExplorer().prefs.value).toEqual({ url: 'https://mempool.space', acknowledged: false })
|
|
||||||
expect(JSON.parse(localStorage.getItem('archipelago.tx-explorer.v1')!)).toEqual(useTxExplorer().prefs.value)
|
|
||||||
})
|
|
||||||
it('preserves a custom explorer and its consent', async () => {
|
|
||||||
const prefs = { url: 'https://my-explorer.example', acknowledged: true }
|
|
||||||
localStorage.setItem('archipelago.tx-explorer.v1', JSON.stringify(prefs))
|
|
||||||
const { useTxExplorer } = await import('../useTxExplorer')
|
|
||||||
expect(useTxExplorer().prefs.value).toEqual(prefs)
|
|
||||||
})
|
|
||||||
})
|
|
||||||
|
|||||||
@@ -17,8 +17,8 @@ import { ref } from 'vue'
|
|||||||
import { useAppLauncherStore } from '@/stores/appLauncher'
|
import { useAppLauncherStore } from '@/stores/appLauncher'
|
||||||
import { useContainerStore } from '@/stores/container'
|
import { useContainerStore } from '@/stores/container'
|
||||||
|
|
||||||
export const DEFAULT_TX_EXPLORER = 'https://mempool.space'
|
export const DEFAULT_TX_EXPLORER = 'https://tx1138.com'
|
||||||
export const EXPLORER_PLACEHOLDER = DEFAULT_TX_EXPLORER
|
export const EXPLORER_PLACEHOLDER = 'https://mempool.guide'
|
||||||
|
|
||||||
const KEY = 'archipelago.tx-explorer.v1'
|
const KEY = 'archipelago.tx-explorer.v1'
|
||||||
|
|
||||||
@@ -30,13 +30,7 @@ interface TxExplorerPrefs {
|
|||||||
function loadPrefs(): TxExplorerPrefs {
|
function loadPrefs(): TxExplorerPrefs {
|
||||||
const defaults: TxExplorerPrefs = { url: DEFAULT_TX_EXPLORER, acknowledged: false }
|
const defaults: TxExplorerPrefs = { url: DEFAULT_TX_EXPLORER, acknowledged: false }
|
||||||
try {
|
try {
|
||||||
const stored = { ...defaults, ...JSON.parse(localStorage.getItem(KEY) || '{}') }
|
return { ...defaults, ...JSON.parse(localStorage.getItem(KEY) || '{}') }
|
||||||
// Changing operators requires fresh consent, even if the old one was trusted.
|
|
||||||
if (typeof stored.url === 'string' && /^https?:\/\/tx1138\.com\/*$/i.test(stored.url.trim())) {
|
|
||||||
localStorage.setItem(KEY, JSON.stringify(defaults))
|
|
||||||
return defaults
|
|
||||||
}
|
|
||||||
return stored
|
|
||||||
} catch {
|
} catch {
|
||||||
return defaults
|
return defaults
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -672,11 +672,6 @@ async function handleInstall(app: MarketplaceApp) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
||||||
if (['bitcoin-core', 'bitcoin-knots'].includes(app.id)) {
|
|
||||||
installModalApp.value = app
|
|
||||||
showInstallModal.value = true
|
|
||||||
return
|
|
||||||
}
|
|
||||||
// Multi-version apps (Bitcoin Knots / Core): let the runner pick a version up
|
// Multi-version apps (Bitcoin Knots / Core): let the runner pick a version up
|
||||||
// front via a full-screen modal (latest pre-selected) instead of silently
|
// front via a full-screen modal (latest pre-selected) instead of silently
|
||||||
// installing the default. Best-effort — if the lookup fails we install directly.
|
// installing the default. Best-effort — if the lookup fails we install directly.
|
||||||
@@ -691,19 +686,19 @@ async function handleInstall(app: MarketplaceApp) {
|
|||||||
startInstall(app)
|
startInstall(app)
|
||||||
}
|
}
|
||||||
|
|
||||||
function startInstall(app: MarketplaceApp, versionOverride?: string, prune?: boolean) {
|
function startInstall(app: MarketplaceApp, versionOverride?: string) {
|
||||||
if (app.source === 'local') {
|
if (app.source === 'local') {
|
||||||
installApp(app, versionOverride, prune)
|
installApp(app, versionOverride)
|
||||||
} else {
|
} else {
|
||||||
installCommunityApp(app, versionOverride, prune)
|
installCommunityApp(app, versionOverride)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function onInstallModalConfirm(version: string, prune?: boolean) {
|
function onInstallModalConfirm(version: string) {
|
||||||
const app = installModalApp.value
|
const app = installModalApp.value
|
||||||
showInstallModal.value = false
|
showInstallModal.value = false
|
||||||
installModalApp.value = null
|
installModalApp.value = null
|
||||||
if (app) startInstall(app, version, prune)
|
if (app) startInstall(app, version)
|
||||||
}
|
}
|
||||||
|
|
||||||
function viewAppDetails(app: MarketplaceApp) {
|
function viewAppDetails(app: MarketplaceApp) {
|
||||||
@@ -779,25 +774,25 @@ function failInstall(app: MarketplaceApp, err: unknown) {
|
|||||||
trackTimeout(() => { serverStore.clearInstallProgress(app.id) }, 5000)
|
trackTimeout(() => { serverStore.clearInstallProgress(app.id) }, 5000)
|
||||||
}
|
}
|
||||||
|
|
||||||
async function installApp(app: MarketplaceApp, versionOverride?: string, prune?: boolean) {
|
async function installApp(app: MarketplaceApp, versionOverride?: string) {
|
||||||
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
||||||
queueInstall(app)
|
queueInstall(app)
|
||||||
installToast(app)
|
installToast(app)
|
||||||
try {
|
try {
|
||||||
const installUrl = app.url || app.manifestUrl || app.s9pkUrl
|
const installUrl = app.url || app.manifestUrl || app.s9pkUrl
|
||||||
await rpcClient.call({ method: 'package.install', params: { id: app.id, url: installUrl, version: versionOverride || app.version, ...(prune === undefined ? {} : { prune }) }, timeout: 600000 })
|
await rpcClient.call({ method: 'package.install', params: { id: app.id, url: installUrl, version: versionOverride || app.version }, timeout: 600000 })
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
if (import.meta.env.DEV) console.error('Installation failed:', err)
|
if (import.meta.env.DEV) console.error('Installation failed:', err)
|
||||||
failInstall(app, err)
|
failInstall(app, err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async function installCommunityApp(app: MarketplaceApp, versionOverride?: string, prune?: boolean) {
|
async function installCommunityApp(app: MarketplaceApp, versionOverride?: string) {
|
||||||
if (installingApps.has(app.id) || isInstalled(app.id) || !app.dockerImage) return
|
if (installingApps.has(app.id) || isInstalled(app.id) || !app.dockerImage) return
|
||||||
queueInstall(app)
|
queueInstall(app)
|
||||||
installToast(app)
|
installToast(app)
|
||||||
try {
|
try {
|
||||||
const installParams: Record<string, unknown> = { id: app.id, dockerImage: app.dockerImage, version: versionOverride || app.version, ...(prune === undefined ? {} : { prune }) }
|
const installParams: Record<string, unknown> = { id: app.id, dockerImage: app.dockerImage, version: versionOverride || app.version }
|
||||||
if ((app as Record<string, unknown>).containerConfig) {
|
if ((app as Record<string, unknown>).containerConfig) {
|
||||||
installParams.containerConfig = (app as Record<string, unknown>).containerConfig
|
installParams.containerConfig = (app as Record<string, unknown>).containerConfig
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -133,7 +133,6 @@
|
|||||||
class="order-2 lg:order-none"
|
class="order-2 lg:order-none"
|
||||||
:animate="animateCards"
|
:animate="animateCards"
|
||||||
:wallet-connected="walletConnected"
|
:wallet-connected="walletConnected"
|
||||||
:wallet-balance-unavailable="walletBalanceUnavailable"
|
|
||||||
:wallet-onchain="walletOnchain"
|
:wallet-onchain="walletOnchain"
|
||||||
:wallet-lightning="walletLightning"
|
:wallet-lightning="walletLightning"
|
||||||
:wallet-ecash="walletEcash"
|
:wallet-ecash="walletEcash"
|
||||||
@@ -686,7 +685,6 @@ async function devFaucet() { try { await rpcClient.call({ method: 'dev.faucet',
|
|||||||
// readout instead; a rail only becomes a number when a call actually
|
// readout instead; a rail only becomes a number when a call actually
|
||||||
// succeeds, so a real 0 is still a real 0.
|
// succeeds, so a real 0 is still a real 0.
|
||||||
const walletConnected = ref(false)
|
const walletConnected = ref(false)
|
||||||
const walletBalanceUnavailable = ref(false)
|
|
||||||
const walletOnchain = ref<number | null>(null)
|
const walletOnchain = ref<number | null>(null)
|
||||||
const walletLightning = ref<number | null>(null)
|
const walletLightning = ref<number | null>(null)
|
||||||
const walletEcash = ref<number | null>(null)
|
const walletEcash = ref<number | null>(null)
|
||||||
@@ -777,24 +775,13 @@ async function loadWeb5Status() {
|
|||||||
// call, which is what makes the card feel like an app launch.
|
// call, which is what makes the card feel like an app launch.
|
||||||
const balances = Promise.allSettled([
|
const balances = Promise.allSettled([
|
||||||
rpcClient.call<{ balance_sats: number; channel_balance_sats: number }>({ method: 'lnd.getinfo', timeout: 5000, dedup: true })
|
rpcClient.call<{ balance_sats: number; channel_balance_sats: number }>({ method: 'lnd.getinfo', timeout: 5000, dedup: true })
|
||||||
.then(res => {
|
.then(res => { walletOnchain.value = res.balance_sats || 0; walletLightning.value = res.channel_balance_sats || 0; walletConnected.value = true; walletInfoFailures = 0 })
|
||||||
if (!Number.isSafeInteger(res.balance_sats) || res.balance_sats < 0 ||
|
|
||||||
!Number.isSafeInteger(res.channel_balance_sats) || res.channel_balance_sats < 0) {
|
|
||||||
throw new Error('LND balance is unavailable')
|
|
||||||
}
|
|
||||||
walletOnchain.value = res.balance_sats
|
|
||||||
walletLightning.value = res.channel_balance_sats
|
|
||||||
walletConnected.value = true
|
|
||||||
walletBalanceUnavailable.value = false
|
|
||||||
walletInfoFailures = 0
|
|
||||||
})
|
|
||||||
.catch(() => {
|
.catch(() => {
|
||||||
// A single slow poll must NOT flip the card to "disconnected" and
|
// A single slow poll must NOT flip the card to "disconnected" and
|
||||||
// hide balances the user already knows — busy nodes routinely blow
|
// hide balances the user already knows — busy nodes routinely blow
|
||||||
// the 5s budget mid-payment or during IO storms (a test node user
|
// the 5s budget mid-payment or during IO storms (a test node user
|
||||||
// report: balances vanished while a payment settled). Only call it
|
// report: balances vanished while a payment settled). Only call it
|
||||||
// disconnected after three consecutive failures (~30s of silence).
|
// disconnected after three consecutive failures (~30s of silence).
|
||||||
walletBalanceUnavailable.value = true
|
|
||||||
walletInfoFailures += 1
|
walletInfoFailures += 1
|
||||||
if (walletInfoFailures >= 3) walletConnected.value = false
|
if (walletInfoFailures >= 3) walletConnected.value = false
|
||||||
}),
|
}),
|
||||||
|
|||||||
@@ -137,7 +137,7 @@
|
|||||||
:tier-label="getAppTier(app.id)"
|
:tier-label="getAppTier(app.id)"
|
||||||
:install-blocked-reason="installBlockedReason(app.id)"
|
:install-blocked-reason="installBlockedReason(app.id)"
|
||||||
@view="viewAppDetails"
|
@view="viewAppDetails"
|
||||||
@install="handleInstall(app)"
|
@install="app.source === 'local' ? installApp(app) : installCommunityApp(app)"
|
||||||
@launch="launchInstalledApp"
|
@launch="launchInstalledApp"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
@@ -153,13 +153,7 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<!-- End Scrollable Apps Section -->
|
<!-- End Scrollable Apps Section -->
|
||||||
<InstallVersionModal
|
|
||||||
:show="showInstallModal"
|
|
||||||
:app-id="installModalApp?.id || ''"
|
|
||||||
:app="installModalApp"
|
|
||||||
@close="showInstallModal = false; installModalApp = null"
|
|
||||||
@confirm="onInstallModalConfirm"
|
|
||||||
/>
|
|
||||||
</div>
|
</div>
|
||||||
</template>
|
</template>
|
||||||
|
|
||||||
@@ -181,13 +175,11 @@ import { useCollapsingHeaderTabs } from '@/composables/useCollapsingHeaderTabs'
|
|||||||
import { useContainersScanTimeout } from '@/composables/useContainersScanTimeout'
|
import { useContainersScanTimeout } from '@/composables/useContainersScanTimeout'
|
||||||
import { useCachedResource } from '@/composables/useCachedResource'
|
import { useCachedResource } from '@/composables/useCachedResource'
|
||||||
import RefreshIndicator from '@/components/RefreshIndicator.vue'
|
import RefreshIndicator from '@/components/RefreshIndicator.vue'
|
||||||
import InstallVersionModal from '@/components/InstallVersionModal.vue'
|
|
||||||
import { APP_STORE_CATEGORIES, APP_STORE_SECTIONS } from './appStoreCategories'
|
import { APP_STORE_CATEGORIES, APP_STORE_SECTIONS } from './appStoreCategories'
|
||||||
import MarketplaceAppCard from './marketplace/MarketplaceAppCard.vue'
|
import MarketplaceAppCard from './marketplace/MarketplaceAppCard.vue'
|
||||||
import {
|
import {
|
||||||
type MarketplaceApp,
|
type MarketplaceApp,
|
||||||
INSTALLED_ALIASES,
|
INSTALLED_ALIASES,
|
||||||
MULTI_VERSION_APP_IDS,
|
|
||||||
getAppTier,
|
getAppTier,
|
||||||
categorizeCommunityApp,
|
categorizeCommunityApp,
|
||||||
getCuratedAppList,
|
getCuratedAppList,
|
||||||
@@ -214,8 +206,6 @@ const appStoreSections = computed(() => APP_STORE_SECTIONS)
|
|||||||
|
|
||||||
// Installation state — uses global store so it persists across navigation
|
// Installation state — uses global store so it persists across navigation
|
||||||
const installingApps = server.installingApps
|
const installingApps = server.installingApps
|
||||||
const showInstallModal = ref(false)
|
|
||||||
const installModalApp = ref<MarketplaceApp | null>(null)
|
|
||||||
const electrumxArchiveWarning = 'You need a full archival bitcoin node before downloading ElectrumX'
|
const electrumxArchiveWarning = 'You need a full archival bitcoin node before downloading ElectrumX'
|
||||||
|
|
||||||
function installToast(app: MarketplaceApp) {
|
function installToast(app: MarketplaceApp) {
|
||||||
@@ -528,34 +518,7 @@ function failInstall(app: MarketplaceApp, err: unknown) {
|
|||||||
trackTimeout(() => { server.clearInstallProgress(app.id) }, 5000)
|
trackTimeout(() => { server.clearInstallProgress(app.id) }, 5000)
|
||||||
}
|
}
|
||||||
|
|
||||||
function handleInstall(app: MarketplaceApp) {
|
async function installApp(app: MarketplaceApp) {
|
||||||
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
|
||||||
const blocked = installBlockedReason(app.id)
|
|
||||||
if (blocked) {
|
|
||||||
toast.error(blocked)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if (MULTI_VERSION_APP_IDS.has(app.id)) {
|
|
||||||
installModalApp.value = app
|
|
||||||
showInstallModal.value = true
|
|
||||||
return
|
|
||||||
}
|
|
||||||
startInstall(app)
|
|
||||||
}
|
|
||||||
|
|
||||||
function startInstall(app: MarketplaceApp, version?: string, prune?: boolean) {
|
|
||||||
if (app.source === 'local') void installApp(app, version, prune)
|
|
||||||
else void installCommunityApp(app, version, prune)
|
|
||||||
}
|
|
||||||
|
|
||||||
function onInstallModalConfirm(version: string, prune?: boolean) {
|
|
||||||
const app = installModalApp.value
|
|
||||||
showInstallModal.value = false
|
|
||||||
installModalApp.value = null
|
|
||||||
if (app) startInstall(app, version, prune)
|
|
||||||
}
|
|
||||||
|
|
||||||
async function installApp(app: MarketplaceApp, versionOverride?: string, prune?: boolean) {
|
|
||||||
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
if (installingApps.has(app.id) || isInstalled(app.id)) return
|
||||||
const blocked = installBlockedReason(app.id)
|
const blocked = installBlockedReason(app.id)
|
||||||
if (blocked) {
|
if (blocked) {
|
||||||
@@ -573,7 +536,7 @@ async function installApp(app: MarketplaceApp, versionOverride?: string, prune?:
|
|||||||
const installUrl = app.url || app.manifestUrl || app.s9pkUrl
|
const installUrl = app.url || app.manifestUrl || app.s9pkUrl
|
||||||
await rpcClient.call({
|
await rpcClient.call({
|
||||||
method: 'package.install',
|
method: 'package.install',
|
||||||
params: { id: app.id, url: installUrl, version: versionOverride || app.version, ...(prune === undefined ? {} : { prune }) },
|
params: { id: app.id, url: installUrl, version: app.version },
|
||||||
timeout: 600000,
|
timeout: 600000,
|
||||||
})
|
})
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
@@ -582,7 +545,7 @@ async function installApp(app: MarketplaceApp, versionOverride?: string, prune?:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async function installCommunityApp(app: MarketplaceApp, versionOverride?: string, prune?: boolean) {
|
async function installCommunityApp(app: MarketplaceApp) {
|
||||||
if (installingApps.has(app.id) || isInstalled(app.id) || !app.dockerImage) return
|
if (installingApps.has(app.id) || isInstalled(app.id) || !app.dockerImage) return
|
||||||
const blocked = installBlockedReason(app.id)
|
const blocked = installBlockedReason(app.id)
|
||||||
if (blocked) {
|
if (blocked) {
|
||||||
@@ -595,7 +558,7 @@ async function installCommunityApp(app: MarketplaceApp, versionOverride?: string
|
|||||||
installToast(app)
|
installToast(app)
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const installParams: Record<string, unknown> = { id: app.id, dockerImage: app.dockerImage, version: versionOverride || app.version, ...(prune === undefined ? {} : { prune }) }
|
const installParams: Record<string, unknown> = { id: app.id, dockerImage: app.dockerImage, version: app.version }
|
||||||
if (app.containerConfig) installParams.containerConfig = app.containerConfig
|
if (app.containerConfig) installParams.containerConfig = app.containerConfig
|
||||||
await rpcClient.call({
|
await rpcClient.call({
|
||||||
method: 'package.install',
|
method: 'package.install',
|
||||||
|
|||||||
@@ -74,7 +74,7 @@
|
|||||||
<button
|
<button
|
||||||
v-if="!isInstalled"
|
v-if="!isInstalled"
|
||||||
@click="installApp"
|
@click="installApp"
|
||||||
:disabled="demoNoInstall || installing || (isBitcoinInstall && !prunePrefsLoaded) || (!installBlockedReason && !app.manifestUrl && !app.dockerImage)"
|
:disabled="demoNoInstall || installing || (!installBlockedReason && !app.manifestUrl && !app.dockerImage)"
|
||||||
:title="demoNoInstall ? 'Not available in the demo' : (installBlockedReason || undefined)"
|
:title="demoNoInstall ? 'Not available in the demo' : (installBlockedReason || undefined)"
|
||||||
class="glass-button glass-button-sm px-6 py-2.5 rounded-lg text-sm font-semibold flex items-center gap-2 disabled:opacity-50 disabled:cursor-not-allowed"
|
class="glass-button glass-button-sm px-6 py-2.5 rounded-lg text-sm font-semibold flex items-center gap-2 disabled:opacity-50 disabled:cursor-not-allowed"
|
||||||
>
|
>
|
||||||
@@ -90,12 +90,6 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<BitcoinPruningChoice
|
|
||||||
v-if="!isInstalled && isBitcoinInstall && prunePrefsLoaded"
|
|
||||||
v-model="pruneOnInstall"
|
|
||||||
class="hidden md:block"
|
|
||||||
/>
|
|
||||||
|
|
||||||
<!-- Mobile: Two Column Grid Layout -->
|
<!-- Mobile: Two Column Grid Layout -->
|
||||||
<div class="md:hidden">
|
<div class="md:hidden">
|
||||||
<!-- Top: Icon + Info -->
|
<!-- Top: Icon + Info -->
|
||||||
@@ -143,7 +137,6 @@
|
|||||||
{{ $ver(v.version) }}{{ v.default ? ' — latest' : '' }}{{ v.deprecated ? ' (deprecated)' : '' }}
|
{{ $ver(v.version) }}{{ v.default ? ' — latest' : '' }}{{ v.deprecated ? ' (deprecated)' : '' }}
|
||||||
</option>
|
</option>
|
||||||
</select>
|
</select>
|
||||||
<BitcoinPruningChoice v-if="!isInstalled && isBitcoinInstall && prunePrefsLoaded" v-model="pruneOnInstall" class="mb-4" />
|
|
||||||
|
|
||||||
<!-- Bottom: Action Buttons -->
|
<!-- Bottom: Action Buttons -->
|
||||||
<div class="grid grid-cols-2 gap-2">
|
<div class="grid grid-cols-2 gap-2">
|
||||||
@@ -160,7 +153,7 @@
|
|||||||
<button
|
<button
|
||||||
v-else
|
v-else
|
||||||
@click="installApp"
|
@click="installApp"
|
||||||
:disabled="demoNoInstall || installing || (isBitcoinInstall && !prunePrefsLoaded) || (!installBlockedReason && !app.manifestUrl && !app.dockerImage)"
|
:disabled="demoNoInstall || installing || (!installBlockedReason && !app.manifestUrl && !app.dockerImage)"
|
||||||
:title="demoNoInstall ? 'Not available in the demo' : (installBlockedReason || undefined)"
|
:title="demoNoInstall ? 'Not available in the demo' : (installBlockedReason || undefined)"
|
||||||
class="glass-button glass-button-sm px-4 py-2.5 rounded-lg text-sm font-semibold flex items-center justify-center gap-2 disabled:opacity-50 disabled:cursor-not-allowed col-span-2"
|
class="glass-button glass-button-sm px-4 py-2.5 rounded-lg text-sm font-semibold flex items-center justify-center gap-2 disabled:opacity-50 disabled:cursor-not-allowed col-span-2"
|
||||||
>
|
>
|
||||||
@@ -381,7 +374,6 @@
|
|||||||
</template>
|
</template>
|
||||||
|
|
||||||
<script setup lang="ts">
|
<script setup lang="ts">
|
||||||
import BitcoinPruningChoice from '@/components/BitcoinPruningChoice.vue'
|
|
||||||
import { ref, computed, onMounted, onBeforeUnmount } from 'vue'
|
import { ref, computed, onMounted, onBeforeUnmount } from 'vue'
|
||||||
import { IS_DEMO, isDemoApp } from '@/composables/useDemoIntro'
|
import { IS_DEMO, isDemoApp } from '@/composables/useDemoIntro'
|
||||||
import { useRouter, useRoute } from 'vue-router'
|
import { useRouter, useRoute } from 'vue-router'
|
||||||
@@ -416,10 +408,6 @@ const bitcoinPruned = ref(false)
|
|||||||
// Hidden when an app offers only one version — install stays one-click.
|
// Hidden when an app offers only one version — install stays one-click.
|
||||||
const installVersions = ref<{ version: string; default: boolean; deprecated: boolean; eol: string | null }[]>([])
|
const installVersions = ref<{ version: string; default: boolean; deprecated: boolean; eol: string | null }[]>([])
|
||||||
const selectedInstallVersion = ref('')
|
const selectedInstallVersion = ref('')
|
||||||
const pruneOnInstall = ref(false)
|
|
||||||
const pruneSettingKnown = ref(false)
|
|
||||||
const prunePrefsLoaded = ref(false)
|
|
||||||
const isBitcoinInstall = computed(() => ['bitcoin-core', 'bitcoin-knots'].includes(app.value?.id || ''))
|
|
||||||
const backButtonLabel = computed(() => route.query.from === 'home' ? t('marketplaceDetails.backToHome') : t('marketplaceDetails.backToStore'))
|
const backButtonLabel = computed(() => route.query.from === 'home' ? t('marketplaceDetails.backToHome') : t('marketplaceDetails.backToStore'))
|
||||||
const electrumxArchiveWarning = 'You need a full archival bitcoin node before downloading ElectrumX'
|
const electrumxArchiveWarning = 'You need a full archival bitcoin node before downloading ElectrumX'
|
||||||
|
|
||||||
@@ -599,13 +587,10 @@ onMounted(() => {
|
|||||||
// cached entry is missing or past its TTL, so a repeat open inside the TTL
|
// cached entry is missing or past its TTL, so a repeat open inside the TTL
|
||||||
// paints from cache with no new RPC.
|
// paints from cache with no new RPC.
|
||||||
async function loadInstallVersions() {
|
async function loadInstallVersions() {
|
||||||
if (isBitcoinInstall.value || versionsResource.data.value === null || versionsResource.isStale.value) {
|
if (versionsResource.data.value === null || versionsResource.isStale.value) {
|
||||||
await versionsResource.refresh()
|
await versionsResource.refresh()
|
||||||
}
|
}
|
||||||
const info = versionsResource.data.value
|
const info = versionsResource.data.value
|
||||||
pruneSettingKnown.value = !versionsResource.error.value && typeof info?.bitcoinPrune === 'boolean'
|
|
||||||
pruneOnInstall.value = pruneSettingKnown.value && info?.bitcoinPrune === true
|
|
||||||
prunePrefsLoaded.value = true
|
|
||||||
if (!info || !info.supportsVersions || info.versions.length < 2) {
|
if (!info || !info.supportsVersions || info.versions.length < 2) {
|
||||||
installVersions.value = []
|
installVersions.value = []
|
||||||
return
|
return
|
||||||
@@ -716,7 +701,6 @@ async function installApp() {
|
|||||||
id: app.value.id,
|
id: app.value.id,
|
||||||
dockerImage: app.value.dockerImage,
|
dockerImage: app.value.dockerImage,
|
||||||
version: chosenVersion,
|
version: chosenVersion,
|
||||||
...(isBitcoinInstall.value && (pruneSettingKnown.value || pruneOnInstall.value) ? { prune: pruneOnInstall.value } : {}),
|
|
||||||
}
|
}
|
||||||
if (app.value.containerConfig) installParams.containerConfig = app.value.containerConfig
|
if (app.value.containerConfig) installParams.containerConfig = app.value.containerConfig
|
||||||
await rpcClient.call({
|
await rpcClient.call({
|
||||||
@@ -733,7 +717,6 @@ async function installApp() {
|
|||||||
id: app.value.id,
|
id: app.value.id,
|
||||||
url: installUrl,
|
url: installUrl,
|
||||||
version: chosenVersion,
|
version: chosenVersion,
|
||||||
...(isBitcoinInstall.value && (pruneSettingKnown.value || pruneOnInstall.value) ? { prune: pruneOnInstall.value } : {}),
|
|
||||||
},
|
},
|
||||||
timeout: 600000,
|
timeout: 600000,
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -2,9 +2,6 @@ import { flushPromises, mount } from '@vue/test-utils'
|
|||||||
import { createPinia } from 'pinia'
|
import { createPinia } from 'pinia'
|
||||||
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'
|
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'
|
||||||
import Marketplace from '../Marketplace.vue'
|
import Marketplace from '../Marketplace.vue'
|
||||||
import { rpcClient } from '@/api/rpc-client'
|
|
||||||
import InstallVersionModal from '@/components/InstallVersionModal.vue'
|
|
||||||
import MarketplaceAppCard from '../marketplace/MarketplaceAppCard.vue'
|
|
||||||
|
|
||||||
// Mirrors the CloudPeersRefresh.test.ts pattern (in-repo convention for
|
// Mirrors the CloudPeersRefresh.test.ts pattern (in-repo convention for
|
||||||
// mounting a view directly with its heavier deps mocked at the module
|
// mounting a view directly with its heavier deps mocked at the module
|
||||||
@@ -47,37 +44,22 @@ vi.mock('@/composables/useMarketplaceApp', () => ({
|
|||||||
}))
|
}))
|
||||||
|
|
||||||
vi.mock('@/composables/useToast', () => ({
|
vi.mock('@/composables/useToast', () => ({
|
||||||
useToast: () => ({ success: vi.fn(), error: toastErrorMock, info: toastInfoMock, action: vi.fn() }),
|
useToast: () => ({ success: vi.fn(), error: toastErrorMock, info: toastInfoMock }),
|
||||||
}))
|
}))
|
||||||
|
|
||||||
vi.mock('@/api/rpc-client', () => ({
|
vi.mock('@/api/rpc-client', () => ({
|
||||||
rpcClient: {
|
rpcClient: {
|
||||||
call: vi.fn(),
|
call: vi.fn(),
|
||||||
marketplaceDiscover: vi.fn().mockResolvedValue({ apps: [] }),
|
marketplaceDiscover: vi.fn().mockResolvedValue({ apps: [] }),
|
||||||
getPackageVersions: vi.fn(),
|
|
||||||
},
|
},
|
||||||
}))
|
}))
|
||||||
|
|
||||||
vi.mock('../discover/curatedApps', () => ({
|
|
||||||
fetchAppCatalog: vi.fn().mockResolvedValue({
|
|
||||||
apps: ['bitcoin-core', 'bitcoin-knots'].map(id => ({
|
|
||||||
id, title: id, version: '29.0', description: 'Bitcoin node',
|
|
||||||
dockerImage: `registry.example/${id}:29.0`, source: 'community',
|
|
||||||
})),
|
|
||||||
}),
|
|
||||||
}))
|
|
||||||
|
|
||||||
describe('Marketplace tracer tab: background refresh failure (D-07)', () => {
|
describe('Marketplace tracer tab: background refresh failure (D-07)', () => {
|
||||||
beforeEach(() => {
|
beforeEach(() => {
|
||||||
vi.stubGlobal('ResizeObserver', vi.fn(() => ({ observe: vi.fn(), disconnect: vi.fn() })))
|
vi.stubGlobal('ResizeObserver', vi.fn(() => ({ observe: vi.fn(), disconnect: vi.fn() })))
|
||||||
routerPushMock.mockClear()
|
routerPushMock.mockClear()
|
||||||
toastErrorMock.mockClear()
|
toastErrorMock.mockClear()
|
||||||
toastInfoMock.mockClear()
|
toastInfoMock.mockClear()
|
||||||
vi.mocked(rpcClient.call).mockReset()
|
|
||||||
vi.mocked(rpcClient.getPackageVersions).mockResolvedValue({
|
|
||||||
supportsVersions: true, default: '29.0', bitcoinPrune: false,
|
|
||||||
versions: [{ version: '29.0', default: true, deprecated: false, eol: null }],
|
|
||||||
} as Awaited<ReturnType<typeof rpcClient.getPackageVersions>>)
|
|
||||||
})
|
})
|
||||||
|
|
||||||
afterEach(() => {
|
afterEach(() => {
|
||||||
@@ -107,38 +89,4 @@ describe('Marketplace tracer tab: background refresh failure (D-07)', () => {
|
|||||||
|
|
||||||
wrapper.unmount()
|
wrapper.unmount()
|
||||||
})
|
})
|
||||||
|
|
||||||
it.each(['bitcoin-core', 'bitcoin-knots'])('requires the version modal before installing %s and forwards pruning', async (id) => {
|
|
||||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({ ok: true, json: async () => ({ blockchain_info: { pruned: false } }) }))
|
|
||||||
const wrapper = mount(Marketplace, { global: { plugins: [createPinia()], stubs: { Teleport: true } } })
|
|
||||||
await flushPromises()
|
|
||||||
const card = wrapper.findAllComponents(MarketplaceAppCard).find(c => c.props('app').id === id)!
|
|
||||||
expect(card.exists()).toBe(true)
|
|
||||||
card.vm.$emit('install', card.props('app'))
|
|
||||||
await flushPromises()
|
|
||||||
const installs = () => vi.mocked(rpcClient.call).mock.calls.filter(([request]) => request.method === 'package.install')
|
|
||||||
expect(installs()).toHaveLength(0)
|
|
||||||
const modal = wrapper.findComponent(InstallVersionModal)
|
|
||||||
expect(modal.props('show')).toBe(true)
|
|
||||||
await modal.get('input[type="checkbox"]').setValue(true)
|
|
||||||
await modal.get('button.glass-button-warning').trigger('click')
|
|
||||||
await flushPromises()
|
|
||||||
expect(installs()).toHaveLength(1)
|
|
||||||
expect(installs()[0]?.[0].params).toMatchObject({ id, version: '29.0', prune: true })
|
|
||||||
expect(modal.props('show')).toBe(false)
|
|
||||||
wrapper.unmount()
|
|
||||||
})
|
|
||||||
|
|
||||||
it('cancels Bitcoin selection without sending an installation request', async () => {
|
|
||||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({ ok: true, json: async () => ({ blockchain_info: { pruned: false } }) }))
|
|
||||||
const wrapper = mount(Marketplace, { global: { plugins: [createPinia()], stubs: { Teleport: true } } })
|
|
||||||
await flushPromises()
|
|
||||||
const card = wrapper.findAllComponents(MarketplaceAppCard).find(c => c.props('app').id === 'bitcoin-knots')!
|
|
||||||
card.vm.$emit('install', card.props('app'))
|
|
||||||
await flushPromises()
|
|
||||||
wrapper.findComponent(InstallVersionModal).vm.$emit('close')
|
|
||||||
await flushPromises()
|
|
||||||
expect(vi.mocked(rpcClient.call).mock.calls.filter(([request]) => request.method === 'package.install')).toHaveLength(0)
|
|
||||||
wrapper.unmount()
|
|
||||||
})
|
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -238,47 +238,6 @@ describe('Home tab cache (Task 2): system/update/storage groups + wallet freshne
|
|||||||
wrapper.unmount()
|
wrapper.unmount()
|
||||||
})
|
})
|
||||||
|
|
||||||
it.each(['failure', 'missing', 'partial'])('preserves known balances during %s and clears the warning on recovery', async (failure) => {
|
|
||||||
const wrapper = mountHomeHost()
|
|
||||||
await settle()
|
|
||||||
const home = wrapper.findComponent(Home)
|
|
||||||
const refresh = () => (home.vm as unknown as { loadWeb5Status: () => Promise<void> }).loadWeb5Status()
|
|
||||||
rpcCallMock.mockImplementationOnce(async () => {
|
|
||||||
if (failure === 'failure') throw new Error('wallet locked')
|
|
||||||
return failure === 'partial' ? { balance_sats: 0 } : {}
|
|
||||||
})
|
|
||||||
await refresh()
|
|
||||||
await settle()
|
|
||||||
const card = wrapper.findComponent(HomeWalletCard)
|
|
||||||
expect(card.props('walletOnchain')).toBe(5000)
|
|
||||||
expect(card.props('walletLightning')).toBe(2500)
|
|
||||||
expect(card.find('[data-testid="wallet-balance-unavailable"]').text()).toContain('last known')
|
|
||||||
const snapshot = JSON.parse(localStorage.getItem('archy-wallet-snapshot-v1')!)
|
|
||||||
expect(snapshot.onchain).toBe(5000)
|
|
||||||
expect(snapshot.lightning).toBe(2500)
|
|
||||||
rpcCallMock.mockImplementationOnce(async () => ({ balance_sats: 0, channel_balance_sats: 0, synced_to_chain: true }))
|
|
||||||
await refresh()
|
|
||||||
await settle()
|
|
||||||
expect(card.props('walletOnchain')).toBe(0)
|
|
||||||
expect(card.props('walletLightning')).toBe(0)
|
|
||||||
expect(card.find('[data-testid="wallet-balance-unavailable"]').exists()).toBe(false)
|
|
||||||
wrapper.unmount()
|
|
||||||
})
|
|
||||||
|
|
||||||
it('shows unknown rather than zero when the first LND request fails', async () => {
|
|
||||||
rpcCallMock.mockImplementation(async (request) => {
|
|
||||||
if (request.method === 'lnd.getinfo') throw new Error('wallet locked')
|
|
||||||
return defaultRpcCallImpl(request)
|
|
||||||
})
|
|
||||||
const wrapper = mountHomeHost()
|
|
||||||
await settle()
|
|
||||||
const card = wrapper.findComponent(HomeWalletCard)
|
|
||||||
expect(card.props('walletOnchain')).toBeNull()
|
|
||||||
expect(card.props('walletLightning')).toBeNull()
|
|
||||||
expect(card.find('[data-testid="wallet-balance-unavailable"]').text()).toContain('unavailable')
|
|
||||||
wrapper.unmount()
|
|
||||||
})
|
|
||||||
|
|
||||||
it('no sessionStorage key exists for the wallet resource after a mount and reactivation cycle', async () => {
|
it('no sessionStorage key exists for the wallet resource after a mount and reactivation cycle', async () => {
|
||||||
const wrapper = mountHomeHost()
|
const wrapper = mountHomeHost()
|
||||||
await settle()
|
await settle()
|
||||||
|
|||||||
@@ -54,12 +54,6 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<p v-if="walletBalanceUnavailable" data-testid="wallet-balance-unavailable" class="text-sm text-amber-200 mb-3" role="status">
|
|
||||||
{{ walletOnchain != null || walletLightning != null
|
|
||||||
? 'Bitcoin and Lightning balances could not be refreshed. Showing last known amounts.'
|
|
||||||
: 'Bitcoin and Lightning balances are unavailable while the wallet starts or reconnects.' }}
|
|
||||||
</p>
|
|
||||||
|
|
||||||
<!-- Incoming Transactions Panel -->
|
<!-- Incoming Transactions Panel -->
|
||||||
<transition name="incoming-tx-slide">
|
<transition name="incoming-tx-slide">
|
||||||
<div v-if="showIncomingTxPanel && incomingTransactions.length > 0" class="mb-4 rounded-xl overflow-hidden border border-green-500/20">
|
<div v-if="showIncomingTxPanel && incomingTransactions.length > 0" class="mb-4 rounded-xl overflow-hidden border border-green-500/20">
|
||||||
@@ -227,7 +221,6 @@ export interface WalletTransaction {
|
|||||||
const props = defineProps<{
|
const props = defineProps<{
|
||||||
animate: boolean
|
animate: boolean
|
||||||
walletConnected: boolean
|
walletConnected: boolean
|
||||||
walletBalanceUnavailable?: boolean
|
|
||||||
// `null` = not loaded yet, `0` = genuinely empty. Keeping those apart is
|
// `null` = not loaded yet, `0` = genuinely empty. Keeping those apart is
|
||||||
// what lets the card show a pixel readout instead of claiming a figure.
|
// what lets the card show a pixel readout instead of claiming a figure.
|
||||||
walletOnchain: number | null
|
walletOnchain: number | null
|
||||||
|
|||||||
@@ -362,47 +362,6 @@ init()
|
|||||||
</button>
|
</button>
|
||||||
</div>
|
</div>
|
||||||
<div class="overflow-y-auto flex-1 min-h-0 space-y-6 pr-1">
|
<div class="overflow-y-auto flex-1 min-h-0 space-y-6 pr-1">
|
||||||
<!-- v1.8.20-alpha -->
|
|
||||||
<div>
|
|
||||||
<div class="flex items-center gap-2 mb-3">
|
|
||||||
<span class="text-xs font-mono px-2 py-0.5 rounded bg-orange-500/20 text-orange-300">v1.8.20-alpha</span>
|
|
||||||
<span class="text-xs text-white/40">September 29, 2026</span>
|
|
||||||
</div>
|
|
||||||
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
|
||||||
<p>Fixed Cashu file payments rejected despite a shared mint, and preserved the payment amount when mint fees reduce change.</p>
|
|
||||||
<p>Payment failures now report whether a refund actually succeeded; missing files and unsupported payment methods are rejected before charging.</p>
|
|
||||||
<p>Improved saving paid files into Files and reopening purchases without paying again.</p>
|
|
||||||
<p>Bitcoin Core and Knots installation offers optional pruning on larger disks, using the same settings as automatic pruning.</p>
|
|
||||||
<p>Fixed false missing-port checks that unnecessarily restarted Bitcoin and LND; recovery now respects managed shutdown timeouts.</p>
|
|
||||||
<p>LND explains when it is waiting for Bitcoin installation, startup, or sync, without treating normal synchronization as a restart-worthy failure.</p>
|
|
||||||
<p>Bitcoin startup messages explain block-index loading without exposing raw RPC errors, and Lightning keeps known balances clearly marked during outages.</p>
|
|
||||||
<p>Changed the public transaction-explorer default to mempool.space while preserving local explorers and custom choices.</p>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
<!-- v1.8.19-alpha -->
|
|
||||||
<div>
|
|
||||||
<div class="flex items-center gap-2 mb-3">
|
|
||||||
<span class="text-xs font-mono px-2 py-0.5 rounded bg-orange-500/20 text-orange-300">v1.8.19-alpha</span>
|
|
||||||
<span class="text-xs text-white/40">September 28, 2026</span>
|
|
||||||
</div>
|
|
||||||
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
|
||||||
<p>Fixed the embedded AIUI chat page painting a second background and dark scrim over Archy’s dashboard background.</p>
|
|
||||||
<p>Embedded AIUI now stays transparent so the dashboard background appears once.</p>
|
|
||||||
<p>AIUI background fixes are now included reliably in OTA updates and fresh installations.</p>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
<!-- v1.8.18-alpha -->
|
|
||||||
<div>
|
|
||||||
<div class="flex items-center gap-2 mb-3">
|
|
||||||
<span class="text-xs font-mono px-2 py-0.5 rounded bg-orange-500/20 text-orange-300">v1.8.18-alpha</span>
|
|
||||||
<span class="text-xs text-white/40">September 18, 2026</span>
|
|
||||||
</div>
|
|
||||||
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
|
||||||
<p>Framework startup prioritizes Bitcoin and LND before unrelated containers, and unavailable LND balances remain unavailable instead of appearing as false zeroes.</p>
|
|
||||||
<p>Cashu Receive guides unseeded wallets through recovery-phrase setup, with shorter backup guidance and a single-column layout.</p>
|
|
||||||
<p>Added live Framework verification for automatic LND unlock, native balance preservation, Cashu address registration, and proof preservation.</p>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
<!-- v1.8.17-alpha -->
|
<!-- v1.8.17-alpha -->
|
||||||
<div>
|
<div>
|
||||||
<div class="flex items-center gap-2 mb-3">
|
<div class="flex items-center gap-2 mb-3">
|
||||||
|
|||||||
+18
-17
@@ -1,29 +1,30 @@
|
|||||||
{
|
{
|
||||||
"changelog": [
|
"changelog": [
|
||||||
"Fixed the embedded AIUI chat page painting a second background and dark scrim over Archy’s dashboard background.",
|
"Minibits claims that every mint reports as already spent leave the retry queue, clearing repeated failure notices. Network errors and mixed mint failures remain queued for another attempt.",
|
||||||
"Embedded AIUI now stays transparent so the dashboard background appears once.",
|
"Minibits polls its primary relay first and connects to public fallback relays only when the primary is unreachable, reducing unnecessary connections.",
|
||||||
"AIUI background fixes are now included reliably in OTA updates and fresh installations."
|
"Large payment backlogs are fetched from newest to oldest with a saved cursor, so polling can resume after interruptions or page limits. Payments sharing the same timestamp remain reachable.",
|
||||||
|
"Added regression coverage for spent-claim classification, wrapped and mixed mint errors, same-second payments, and interrupted or multi-poll backlogs."
|
||||||
],
|
],
|
||||||
"components": [
|
"components": [
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.17-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.17-alpha/archipelago",
|
||||||
"name": "archipelago",
|
"name": "archipelago",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.17-alpha",
|
||||||
"sha256": "bb500d02567ad16179179d43138cc6fdafee680835262026eeaa7d1bc8cdd307",
|
"sha256": "32a7b009eb58f8c9f256e6597711a77ded11e15d5865a3fe16901603264e1f70",
|
||||||
"size_bytes": 64495784
|
"size_bytes": 64953344
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.17-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago-frontend-1.8.19-alpha.tar.gz",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.17-alpha/archipelago-frontend-1.8.17-alpha.tar.gz",
|
||||||
"name": "archipelago-frontend-1.8.19-alpha.tar.gz",
|
"name": "archipelago-frontend-1.8.17-alpha.tar.gz",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.17-alpha",
|
||||||
"sha256": "fbbaa237e2ea4e9e576dda9b15fdcf3c59c40bc55bfee4ebbea303b0172fc49b",
|
"sha256": "faf692e9a0e16268357bcac2bf86b62950ae49663e3c95982e54a132bb761980",
|
||||||
"size_bytes": 97142031
|
"size_bytes": 98801608
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"release_date": "2026-09-28",
|
"release_date": "2026-09-15",
|
||||||
"signature": "4da9bf766d94c2de6641619a36663106791c7a1d342b729c666662cdde1feabdf11c51994c1cbbe2a0e2b270c316d77763435e976ce22730855b3822bc9d390a",
|
"signature": "c8196fe278a5747b3c3ba3bf70998874f1e3e6eedbdab33b9e33c3339a3769ab4431f41d99924ec4cdd15a5ffed299a5af786c7ab5e9d084cdc11beabbee9103",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"version": "1.8.19-alpha"
|
"version": "1.8.17-alpha"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -618,7 +618,7 @@
|
|||||||
},
|
},
|
||||||
"container": {
|
"container": {
|
||||||
"custom_args": [
|
"custom_args": [
|
||||||
"BITCOIND=\"$(command -v bitcoind || true)\"; if [ -z \"$BITCOIND\" ]; then\n BITCOIND=\"$(find /opt -path '*/bin/bitcoind' -type f 2>/dev/null | sort | tail -n 1)\";\nfi; if [ -z \"$BITCOIND\" ]; then\n echo \"bitcoind not found in image\" >&2;\n exit 127;\nfi; RPC_USER=\"$(printenv BITCOIN_RPC_USER)\"; RPC_PASS=\"$(printenv BITCOIN_RPC_PASS)\"; RPC_CONF=\"/tmp/rpc.conf\"; umask 077; { echo \"rpcuser=$RPC_USER\"; echo \"rpcpassword=$RPC_PASS\"; } > \"$RPC_CONF\"; if [ -f /home/bitcoin/.bitcoin/bitcoin.conf ]; then\n echo \"archipelago: ignoring legacy datadir bitcoin.conf; RPC config comes from $RPC_CONF\" >&2;\nfi; RPC_TXRELAY_AUTH=\"$(printenv BITCOIN_RPC_TXRELAY_RPCAUTH || true)\"; DISK_GB_VALUE=\"$(printenv DISK_GB || true)\"; RPC_HEADROOM=\"-rpcthreads=16 -rpcworkqueue=256\"; RPC_TXRELAY_FLAGS=\"-rpcwhitelistdefault=0\"; if [ -n \"$RPC_TXRELAY_AUTH\" ]; then\n RPC_TXRELAY_FLAGS=\"$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips\";\nfi; if [ \"${BITCOIN_PRUNE:-0}\" = \"1\" ] || [ \"${DISK_GB_VALUE:-0}\" -lt 1000 ]; then\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nelse\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nfi"
|
"BITCOIND=\"$(command -v bitcoind || true)\"; if [ -z \"$BITCOIND\" ]; then\n BITCOIND=\"$(find /opt -path '*/bin/bitcoind' -type f 2>/dev/null | sort | tail -n 1)\";\nfi; if [ -z \"$BITCOIND\" ]; then\n echo \"bitcoind not found in image\" >&2;\n exit 127;\nfi; RPC_USER=\"$(printenv BITCOIN_RPC_USER)\"; RPC_PASS=\"$(printenv BITCOIN_RPC_PASS)\"; RPC_CONF=\"/tmp/rpc.conf\"; umask 077; { echo \"rpcuser=$RPC_USER\"; echo \"rpcpassword=$RPC_PASS\"; } > \"$RPC_CONF\"; if [ -f /home/bitcoin/.bitcoin/bitcoin.conf ]; then\n echo \"archipelago: ignoring legacy datadir bitcoin.conf; RPC config comes from $RPC_CONF\" >&2;\nfi; RPC_TXRELAY_AUTH=\"$(printenv BITCOIN_RPC_TXRELAY_RPCAUTH || true)\"; DISK_GB_VALUE=\"$(printenv DISK_GB || true)\"; RPC_HEADROOM=\"-rpcthreads=16 -rpcworkqueue=256\"; RPC_TXRELAY_FLAGS=\"-rpcwhitelistdefault=0\"; if [ -n \"$RPC_TXRELAY_AUTH\" ]; then\n RPC_TXRELAY_FLAGS=\"$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips\";\nfi; if [ \"${DISK_GB_VALUE:-0}\" -lt 1000 ]; then\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nelse\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nfi"
|
||||||
],
|
],
|
||||||
"data_uid": "100101:100101",
|
"data_uid": "100101:100101",
|
||||||
"derived_env": [
|
"derived_env": [
|
||||||
@@ -768,7 +768,7 @@
|
|||||||
},
|
},
|
||||||
"container": {
|
"container": {
|
||||||
"custom_args": [
|
"custom_args": [
|
||||||
"BITCOIND=\"$(command -v bitcoind || true)\"; if [ -z \"$BITCOIND\" ]; then\n BITCOIND=\"$(find /opt -path '*/bin/bitcoind' -type f 2>/dev/null | sort | tail -n 1)\";\nfi; if [ -z \"$BITCOIND\" ]; then\n echo \"bitcoind not found in image\" >&2;\n exit 127;\nfi; RPC_USER=\"$(printenv BITCOIN_RPC_USER)\"; RPC_PASS=\"$(printenv BITCOIN_RPC_PASS)\"; RPC_CONF=\"/tmp/rpc.conf\"; umask 077; { echo \"rpcuser=$RPC_USER\"; echo \"rpcpassword=$RPC_PASS\"; } > \"$RPC_CONF\"; if [ -f /home/bitcoin/.bitcoin/bitcoin.conf ]; then\n echo \"archipelago: ignoring legacy datadir bitcoin.conf; RPC config comes from $RPC_CONF\" >&2;\nfi; RPC_TXRELAY_AUTH=\"$(printenv BITCOIN_RPC_TXRELAY_RPCAUTH || true)\"; DISK_GB_VALUE=\"$(printenv DISK_GB || true)\"; RPC_HEADROOM=\"-rpcthreads=16 -rpcworkqueue=256\"; RPC_TXRELAY_FLAGS=\"-rpcwhitelistdefault=0\"; if [ -n \"$RPC_TXRELAY_AUTH\" ]; then\n RPC_TXRELAY_FLAGS=\"$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips\";\nfi; if [ \"${BITCOIN_PRUNE:-0}\" = \"1\" ] || [ \"${DISK_GB_VALUE:-0}\" -lt 1000 ]; then\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=2048 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nelse\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nfi"
|
"BITCOIND=\"$(command -v bitcoind || true)\"; if [ -z \"$BITCOIND\" ]; then\n BITCOIND=\"$(find /opt -path '*/bin/bitcoind' -type f 2>/dev/null | sort | tail -n 1)\";\nfi; if [ -z \"$BITCOIND\" ]; then\n echo \"bitcoind not found in image\" >&2;\n exit 127;\nfi; RPC_USER=\"$(printenv BITCOIN_RPC_USER)\"; RPC_PASS=\"$(printenv BITCOIN_RPC_PASS)\"; RPC_CONF=\"/tmp/rpc.conf\"; umask 077; { echo \"rpcuser=$RPC_USER\"; echo \"rpcpassword=$RPC_PASS\"; } > \"$RPC_CONF\"; if [ -f /home/bitcoin/.bitcoin/bitcoin.conf ]; then\n echo \"archipelago: ignoring legacy datadir bitcoin.conf; RPC config comes from $RPC_CONF\" >&2;\nfi; RPC_TXRELAY_AUTH=\"$(printenv BITCOIN_RPC_TXRELAY_RPCAUTH || true)\"; DISK_GB_VALUE=\"$(printenv DISK_GB || true)\"; RPC_HEADROOM=\"-rpcthreads=16 -rpcworkqueue=256\"; RPC_TXRELAY_FLAGS=\"-rpcwhitelistdefault=0\"; if [ -n \"$RPC_TXRELAY_AUTH\" ]; then\n RPC_TXRELAY_FLAGS=\"$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips\";\nfi; if [ \"${DISK_GB_VALUE:-0}\" -lt 1000 ]; then\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=50000 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=2048 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nelse\n exec \"$BITCOIND\" -datadir=/home/bitcoin/.bitcoin -conf=\"$RPC_CONF\" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;\nfi"
|
||||||
],
|
],
|
||||||
"data_uid": "100101:100101",
|
"data_uid": "100101:100101",
|
||||||
"derived_env": [
|
"derived_env": [
|
||||||
@@ -1378,67 +1378,6 @@
|
|||||||
},
|
},
|
||||||
"version": "0.1.0-preview"
|
"version": "0.1.0-preview"
|
||||||
},
|
},
|
||||||
"cuprate-ui": {
|
|
||||||
"image": "source.archipelago-foundation.org/lfg2025/cuprate-ui:1.7.123-alpha",
|
|
||||||
"manifest": {
|
|
||||||
"app": {
|
|
||||||
"container": {
|
|
||||||
"build": {
|
|
||||||
"context": "/opt/archipelago/docker/cuprate-ui",
|
|
||||||
"dockerfile": "Dockerfile",
|
|
||||||
"tag": "localhost/cuprate-ui:local"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"dependencies": [
|
|
||||||
{
|
|
||||||
"app_id": "cuprate"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"description": "Archipelago-native HTTP frontend for the Cuprate Monero node. Runs nginx\ninside a container, serves a static status dashboard, and proxies\n/cuprate-rpc/ to the cuprate restricted RPC on 127.0.0.1:18090 (the\npublished host port for the container's 18089). No credentials are\ninjected — the restricted RPC is Monero's own safe-for-public subset — so\nthe nginx.conf is baked into the image and there is no rendered-config\nbind-mount like bitcoin-ui's.\n",
|
|
||||||
"environment": [],
|
|
||||||
"health_check": {
|
|
||||||
"endpoint": "http://127.0.0.1:18091",
|
|
||||||
"interval": "30s",
|
|
||||||
"path": "/",
|
|
||||||
"retries": 3,
|
|
||||||
"timeout": "5s",
|
|
||||||
"type": "http"
|
|
||||||
},
|
|
||||||
"id": "cuprate-ui",
|
|
||||||
"metadata": {
|
|
||||||
"author": "Archipelago",
|
|
||||||
"category": "money",
|
|
||||||
"icon": "/assets/img/app-icons/cuprate.svg",
|
|
||||||
"repo": "https://github.com/Cuprate/cuprate",
|
|
||||||
"tier": "optional"
|
|
||||||
},
|
|
||||||
"name": "Cuprate UI",
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"auth": "gated",
|
|
||||||
"bind": "127.0.0.1",
|
|
||||||
"container": 18091,
|
|
||||||
"host": 18091,
|
|
||||||
"protocol": "tcp",
|
|
||||||
"session_passthrough": true
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"resources": {
|
|
||||||
"memory_limit": "64Mi"
|
|
||||||
},
|
|
||||||
"security": {
|
|
||||||
"network_policy": "host",
|
|
||||||
"readonly_root": false
|
|
||||||
},
|
|
||||||
"upstream": {
|
|
||||||
"kind": "internal"
|
|
||||||
},
|
|
||||||
"version": "1.0.0",
|
|
||||||
"volumes": []
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"version": "1.7.123-alpha"
|
|
||||||
},
|
|
||||||
"electrs-ui": {
|
"electrs-ui": {
|
||||||
"image": "source.archipelago-foundation.org/lfg2025/electrs-ui:1.7.123-alpha",
|
"image": "source.archipelago-foundation.org/lfg2025/electrs-ui:1.7.123-alpha",
|
||||||
"manifest": {
|
"manifest": {
|
||||||
@@ -5525,7 +5464,7 @@
|
|||||||
"tag": "NOSTR IDENTITY // YOUR NODE"
|
"tag": "NOSTR IDENTITY // YOUR NODE"
|
||||||
},
|
},
|
||||||
"schema": 1,
|
"schema": 1,
|
||||||
"signature": "bbcc938b855c1cb5d803e4510e1aac3259fbf3eabf6f36294c7773634047a3d5edb5b37a17d01d62d1407e5701c62853e15e20e15cc7f486b8975b22eeb94c07",
|
"signature": "e716a9069021af87a2252d7561c01153f17c5630d7c36d8fdc1be1c7aa40560d09557513c0e09835a6b76b52b4f7edf0619cbaff02ac1d9d818066f67046e401",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"storefront": {
|
"storefront": {
|
||||||
"popular": [
|
"popular": [
|
||||||
@@ -5546,10 +5485,10 @@
|
|||||||
"id": "archipelago-source",
|
"id": "archipelago-source",
|
||||||
"installLabel": "Install GitWorkshop",
|
"installLabel": "Install GitWorkshop",
|
||||||
"launchLabel": "Open GitWorkshop",
|
"launchLabel": "Open GitWorkshop",
|
||||||
"path": "/npub1w3sqdkrhn0gyuvsex32effzgnfpyde6qrrc4u467flg5e9txh4wsfn5vjg/relay.ngit.dev/archy",
|
"path": "/npub1w3sqdkrhn0gyuvsex32effzgnfpyde6qrrc4u467flg5e9txh4wsfn5vjg/archy",
|
||||||
"tag": "NGIT // NOSTR // NO SILO"
|
"tag": "NGIT // NOSTR // NO SILO"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"updated": "2026-09-29"
|
"updated": "2026-09-15"
|
||||||
}
|
}
|
||||||
|
|||||||
+18
-17
@@ -1,29 +1,30 @@
|
|||||||
{
|
{
|
||||||
"changelog": [
|
"changelog": [
|
||||||
"Fixed the embedded AIUI chat page painting a second background and dark scrim over Archy’s dashboard background.",
|
"Minibits claims that every mint reports as already spent leave the retry queue, clearing repeated failure notices. Network errors and mixed mint failures remain queued for another attempt.",
|
||||||
"Embedded AIUI now stays transparent so the dashboard background appears once.",
|
"Minibits polls its primary relay first and connects to public fallback relays only when the primary is unreachable, reducing unnecessary connections.",
|
||||||
"AIUI background fixes are now included reliably in OTA updates and fresh installations."
|
"Large payment backlogs are fetched from newest to oldest with a saved cursor, so polling can resume after interruptions or page limits. Payments sharing the same timestamp remain reachable.",
|
||||||
|
"Added regression coverage for spent-claim classification, wrapped and mixed mint errors, same-second payments, and interrupted or multi-poll backlogs."
|
||||||
],
|
],
|
||||||
"components": [
|
"components": [
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.17-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.17-alpha/archipelago",
|
||||||
"name": "archipelago",
|
"name": "archipelago",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.17-alpha",
|
||||||
"sha256": "bb500d02567ad16179179d43138cc6fdafee680835262026eeaa7d1bc8cdd307",
|
"sha256": "32a7b009eb58f8c9f256e6597711a77ded11e15d5865a3fe16901603264e1f70",
|
||||||
"size_bytes": 64495784
|
"size_bytes": 64953344
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.17-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago-frontend-1.8.19-alpha.tar.gz",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.17-alpha/archipelago-frontend-1.8.17-alpha.tar.gz",
|
||||||
"name": "archipelago-frontend-1.8.19-alpha.tar.gz",
|
"name": "archipelago-frontend-1.8.17-alpha.tar.gz",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.17-alpha",
|
||||||
"sha256": "fbbaa237e2ea4e9e576dda9b15fdcf3c59c40bc55bfee4ebbea303b0172fc49b",
|
"sha256": "faf692e9a0e16268357bcac2bf86b62950ae49663e3c95982e54a132bb761980",
|
||||||
"size_bytes": 97142031
|
"size_bytes": 98801608
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"release_date": "2026-09-28",
|
"release_date": "2026-09-15",
|
||||||
"signature": "4da9bf766d94c2de6641619a36663106791c7a1d342b729c666662cdde1feabdf11c51994c1cbbe2a0e2b270c316d77763435e976ce22730855b3822bc9d390a",
|
"signature": "c8196fe278a5747b3c3ba3bf70998874f1e3e6eedbdab33b9e33c3339a3769ab4431f41d99924ec4cdd15a5ffed299a5af786c7ab5e9d084cdc11beabbee9103",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"version": "1.8.19-alpha"
|
"version": "1.8.17-alpha"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,34 +0,0 @@
|
|||||||
{
|
|
||||||
"changelog": [
|
|
||||||
"Fixed Cashu file payments rejected despite a shared mint, and preserved the payment amount when mint fees reduce change.",
|
|
||||||
"Payment failures now report whether a refund actually succeeded; missing files and unsupported payment methods are rejected before charging.",
|
|
||||||
"Improved saving paid files into Files and reopening purchases without paying again.",
|
|
||||||
"Bitcoin Core and Knots installation offers optional pruning on larger disks, using the same settings as automatic pruning.",
|
|
||||||
"Fixed false missing-port checks that unnecessarily restarted Bitcoin and LND; recovery now respects managed shutdown timeouts.",
|
|
||||||
"LND explains when it is waiting for Bitcoin installation, startup, or sync, without treating normal synchronization as a restart-worthy failure.",
|
|
||||||
"Bitcoin startup messages explain block-index loading without exposing raw RPC errors, and Lightning keeps known balances clearly marked during outages.",
|
|
||||||
"Changed the public transaction-explorer default to mempool.space while preserving local explorers and custom choices."
|
|
||||||
],
|
|
||||||
"components": [
|
|
||||||
{
|
|
||||||
"current_version": "1.8.20-alpha",
|
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.20-alpha/archipelago",
|
|
||||||
"name": "archipelago",
|
|
||||||
"new_version": "1.8.20-alpha",
|
|
||||||
"sha256": "16a173129672cbb40c250446ec52ba4a9bd1974cbb3a4988f90c6f3187b7a1f7",
|
|
||||||
"size_bytes": 64716656
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"current_version": "1.8.20-alpha",
|
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.20-alpha/archipelago-frontend-1.8.20-alpha.tar.gz",
|
|
||||||
"name": "archipelago-frontend-1.8.20-alpha.tar.gz",
|
|
||||||
"new_version": "1.8.20-alpha",
|
|
||||||
"sha256": "658b78fce0dfa20a627c987dd153b24cbac15adbde905cc6518744c637e12802",
|
|
||||||
"size_bytes": 97152297
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"release_date": "2026-09-29",
|
|
||||||
"signature": "326cab454902abcb4f8037751af67aaae2860ecf00300177ec377a1f223a6a85b6e92d49297e7bc29a73220d501e6f4c83ee23477e2b688e33e19d093c6d210b",
|
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
|
||||||
"version": "1.8.20-alpha"
|
|
||||||
}
|
|
||||||
@@ -112,9 +112,10 @@ VERSION="$(grep -m1 '^version' core/archipelago/Cargo.toml | sed 's/.*"\(.*\)".*
|
|||||||
if [ "$SKIP_GATES" = "0" ]; then
|
if [ "$SKIP_GATES" = "0" ]; then
|
||||||
stage "release-gate-harness" bash tests/release/run.sh
|
stage "release-gate-harness" bash tests/release/run.sh
|
||||||
stage "catalog-drift-strict" python3 scripts/check-app-catalog-drift.py --release --strict
|
stage "catalog-drift-strict" python3 scripts/check-app-catalog-drift.py --release --strict
|
||||||
# The release harness runs the full backend suite inside namespaces.
|
# Full Rust suite — the release harness only runs a 6-module slice;
|
||||||
# Never execute unrestricted tests on a node with live wallets/services.
|
# ~1000 tests otherwise go unverified at ISO time (hardening plan §H).
|
||||||
|
stage "cargo-test-full" timeout 5400 env CARGO_INCREMENTAL=0 \
|
||||||
|
nice -n 10 cargo test --manifest-path core/Cargo.toml -p archipelago --bin archipelago
|
||||||
else
|
else
|
||||||
echo; echo "═══ [gates] SKIPPED (--skip-gates)"
|
echo; echo "═══ [gates] SKIPPED (--skip-gates)"
|
||||||
fi
|
fi
|
||||||
|
|||||||
+11
-42
@@ -47,33 +47,13 @@ podman_rootless() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
port_is_listening() {
|
port_is_listening() {
|
||||||
local port="$1" protocol="${2:-tcp}" listeners
|
local port="$1"
|
||||||
|
local protocol="${2:-tcp}"
|
||||||
case "$protocol" in
|
case "$protocol" in
|
||||||
tcp) listeners=$(ss -ltn 2>/dev/null) || return 2 ;;
|
tcp) ss -ltn 2>/dev/null ;;
|
||||||
udp) listeners=$(ss -lun 2>/dev/null) || return 2 ;;
|
udp) ss -lun 2>/dev/null ;;
|
||||||
*) return 2 ;;
|
*) return 1 ;;
|
||||||
esac
|
esac | awk '{print $4}' | grep -Eq "(^|:)$port$"
|
||||||
# Consume the whole snapshot. grep -q closed the old pipe early, so awk
|
|
||||||
# received SIGPIPE and pipefail turned a FOUND port into a failed check.
|
|
||||||
awk -v port="$port" '$4 ~ ("(^|:)" port "$") { found=1 } END { exit !found }' <<< "$listeners"
|
|
||||||
}
|
|
||||||
|
|
||||||
restart_rootless_container() {
|
|
||||||
local name="$1" unit
|
|
||||||
unit=$(podman_rootless inspect "$name" --format '{{index .Config.Labels "PODMAN_SYSTEMD_UNIT"}}' 2>/dev/null) || return 1
|
|
||||||
if [[ "$unit" =~ ^[a-zA-Z0-9_.@-]+\.service$ ]]; then
|
|
||||||
# Respect the managed service's shutdown timeout and --rm lifecycle.
|
|
||||||
# Raw podman restart uses a short timeout and races Quadlet cleanup.
|
|
||||||
if [ "$(id -u)" = 0 ]; then
|
|
||||||
sudo -u archipelago env XDG_RUNTIME_DIR="/run/user/$(id -u archipelago)" systemctl --user restart "$unit"
|
|
||||||
else
|
|
||||||
systemctl --user restart "$unit"
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
local grace=30
|
|
||||||
case "$name" in bitcoin|bitcoin-core|bitcoin-knots) grace=600 ;; lnd) grace=330 ;; esac
|
|
||||||
podman_rootless restart --time "$grace" "$name"
|
|
||||||
fi
|
|
||||||
}
|
}
|
||||||
|
|
||||||
run_fix() {
|
run_fix() {
|
||||||
@@ -593,27 +573,19 @@ fix_missing_rootless_ports() {
|
|||||||
bindings=$(podman_rootless inspect "$name" --format '{{range $p,$bindings := .NetworkSettings.Ports}}{{if $bindings}}{{range $bindings}}{{printf "%s %s\n" $p .HostPort}}{{end}}{{end}}{{end}}' 2>/dev/null | sort -u)
|
bindings=$(podman_rootless inspect "$name" --format '{{range $p,$bindings := .NetworkSettings.Ports}}{{if $bindings}}{{range $bindings}}{{printf "%s %s\n" $p .HostPort}}{{end}}{{end}}{{end}}' 2>/dev/null | sort -u)
|
||||||
[ -n "$bindings" ] || continue
|
[ -n "$bindings" ] || continue
|
||||||
|
|
||||||
local missing=() inspection_failed=false status
|
local missing=()
|
||||||
local container_binding host_port protocol
|
local container_binding host_port protocol
|
||||||
while read -r container_binding host_port; do
|
while read -r container_binding host_port; do
|
||||||
[ -n "$container_binding" ] && [ -n "$host_port" ] || continue
|
[ -n "$container_binding" ] && [ -n "$host_port" ] || continue
|
||||||
protocol="${container_binding##*/}"
|
protocol="${container_binding##*/}"
|
||||||
status=0
|
if ! port_is_listening "$host_port" "$protocol"; then
|
||||||
port_is_listening "$host_port" "$protocol" || status=$?
|
missing+=("$host_port/$protocol")
|
||||||
case "$status" in
|
fi
|
||||||
0) ;;
|
|
||||||
1) missing+=("$host_port/$protocol") ;;
|
|
||||||
*) inspection_failed=true ;;
|
|
||||||
esac
|
|
||||||
done <<< "$bindings"
|
done <<< "$bindings"
|
||||||
|
|
||||||
if $inspection_failed; then
|
|
||||||
log "WARN: cannot inspect listeners for $name; leaving it running"
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
if [ ${#missing[@]} -gt 0 ]; then
|
if [ ${#missing[@]} -gt 0 ]; then
|
||||||
log "Restarting $name: missing rootlessport listener(s): ${missing[*]}"
|
log "Restarting $name: missing rootlessport listener(s): ${missing[*]}"
|
||||||
if restart_rootless_container "$name" >/dev/null 2>&1; then
|
if podman_rootless restart "$name" >/dev/null 2>&1; then
|
||||||
fixed=true
|
fixed=true
|
||||||
else
|
else
|
||||||
log "WARN: failed to restart $name for missing rootlessport listener(s)"
|
log "WARN: failed to restart $name for missing rootlessport listener(s)"
|
||||||
@@ -704,9 +676,6 @@ fix_archipelago_dialout() {
|
|||||||
|
|
||||||
# ── Main ─────────────────────────────────────────────────────
|
# ── Main ─────────────────────────────────────────────────────
|
||||||
|
|
||||||
# Allow regression tests to source helpers without running repairs.
|
|
||||||
[[ "${BASH_SOURCE[0]}" != "$0" ]] && return 0
|
|
||||||
|
|
||||||
# If remote host provided, run via SSH
|
# If remote host provided, run via SSH
|
||||||
if [ -n "$1" ] && [ "$1" != "--local" ]; then
|
if [ -n "$1" ] && [ "$1" != "--local" ]; then
|
||||||
REMOTE_HOST="$1"
|
REMOTE_HOST="$1"
|
||||||
|
|||||||
@@ -78,17 +78,15 @@ if [ -z "$FRONTEND_ARCHIVE" ]; then
|
|||||||
STAGING_DIR=$(mktemp -d -t archipelago-frontend.XXXXXX)
|
STAGING_DIR=$(mktemp -d -t archipelago-frontend.XXXXXX)
|
||||||
echo "Staging frontend archive in $STAGING_DIR..."
|
echo "Staging frontend archive in $STAGING_DIR..."
|
||||||
cp -r "$FRONTEND_DIST/." "$STAGING_DIR/"
|
cp -r "$FRONTEND_DIST/." "$STAGING_DIR/"
|
||||||
# create-release.sh folds the freshly built AIUI into FRONTEND_DIST.
|
# Bake AIUI in so fresh installs pick it up. OTA already
|
||||||
# Never overlay it with the older demo bundle (or nest aiui/aiui/).
|
# carries-forward the existing aiui/ if the tarball lacks one
|
||||||
if [ ! -f "$STAGING_DIR/aiui/index.html" ] || \
|
# (update.rs:922), but including it here makes the tarball
|
||||||
[ ! -f "$STAGING_DIR/aiui/BUILD-INFO" ]; then
|
# the single source of truth instead of relying on a side-
|
||||||
echo "Error: fresh AIUI payload missing from frontend dist" >&2
|
# effect of the in-place swap.
|
||||||
exit 1
|
if [ -d "$PROJECT_ROOT/demo/aiui" ] && [ -f "$PROJECT_ROOT/demo/aiui/index.html" ]; then
|
||||||
|
echo " Including AIUI from demo/aiui/"
|
||||||
|
cp -r "$PROJECT_ROOT/demo/aiui" "$STAGING_DIR/aiui"
|
||||||
fi
|
fi
|
||||||
grep -Fxq "commit=$(git -C "$PROJECT_ROOT" rev-parse HEAD)" "$STAGING_DIR/aiui/BUILD-INFO" || {
|
|
||||||
echo "Error: AIUI payload was not built from the current commit" >&2
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
# OTA bridge for nodes running older updaters: they only know how to
|
# OTA bridge for nodes running older updaters: they only know how to
|
||||||
# apply the backend binary and frontend archive. Carry host runtime
|
# apply the backend binary and frontend archive. Carry host runtime
|
||||||
# assets inside the frontend tarball; the new backend promotes them
|
# assets inside the frontend tarball; the new backend promotes them
|
||||||
|
|||||||
@@ -169,11 +169,15 @@ else
|
|||||||
fi
|
fi
|
||||||
cd "$PROJECT_ROOT"
|
cd "$PROJECT_ROOT"
|
||||||
|
|
||||||
# Build AIUI from the same source as the release. The checked-in demo bundle
|
# npm run build wipes web/dist — fold AIUI straight back in. The OTA tarball
|
||||||
# can predate source fixes and must never overwrite the production payload.
|
# bakes it from demo/aiui independently, but build-iso-release.sh's
|
||||||
bash "$SCRIPT_DIR/build-aiui.sh"
|
# verify-artifacts guard checks web/dist/neode-ui/aiui and failed on two
|
||||||
rm -rf "$PROJECT_ROOT/web/dist/neode-ui/aiui"
|
# consecutive releases (.127, .129) because this fold-in was manual.
|
||||||
cp -r "$PROJECT_ROOT/aiui/packages/app/dist" "$PROJECT_ROOT/web/dist/neode-ui/aiui"
|
if [ -d "$PROJECT_ROOT/demo/aiui" ] && [ -f "$PROJECT_ROOT/demo/aiui/index.html" ]; then
|
||||||
|
rm -rf "$PROJECT_ROOT/web/dist/neode-ui/aiui"
|
||||||
|
cp -r "$PROJECT_ROOT/demo/aiui" "$PROJECT_ROOT/web/dist/neode-ui/aiui"
|
||||||
|
echo " AIUI folded into web/dist from demo/aiui"
|
||||||
|
fi
|
||||||
|
|
||||||
# npm run build can silently no-op (vue-tsc EACCES burned us before) — a stale
|
# npm run build can silently no-op (vue-tsc EACCES burned us before) — a stale
|
||||||
# dist would ship with a perfectly valid sha256. Require the freshly built
|
# dist would ship with a perfectly valid sha256. Require the freshly built
|
||||||
|
|||||||
@@ -1,47 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Compile normally; execute unit tests away from real wallets, service buses,
|
|
||||||
# container storage, processes and networking. Never silently fall back to host.
|
|
||||||
set -euo pipefail
|
|
||||||
REPO=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)
|
|
||||||
command -v systemd-run >/dev/null
|
|
||||||
command -v unshare >/dev/null
|
|
||||||
command -v setpriv >/dev/null
|
|
||||||
sudo -n true || { echo 'Isolated backend tests require noninteractive sudo for systemd namespaces.' >&2; exit 1; }
|
|
||||||
metadata=$(mktemp)
|
|
||||||
trap 'rm -f "$metadata"' EXIT
|
|
||||||
if ! cargo test --manifest-path "$REPO/core/Cargo.toml" -p archipelago --bin archipelago \
|
|
||||||
--locked --no-run --message-format=json --config 'profile.test.package.archipelago.opt-level=0' > "$metadata"; then
|
|
||||||
python3 - "$metadata" <<'PYDIAG'
|
|
||||||
import json,sys
|
|
||||||
for line in open(sys.argv[1]):
|
|
||||||
try: item=json.loads(line)
|
|
||||||
except json.JSONDecodeError: continue
|
|
||||||
rendered=item.get('message',{}).get('rendered') if item.get('reason')=='compiler-message' else None
|
|
||||||
if rendered: print(rendered,file=sys.stderr,end='')
|
|
||||||
PYDIAG
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
executable=$(python3 - "$metadata" <<'PY'
|
|
||||||
import json,sys
|
|
||||||
found=[]
|
|
||||||
for line in open(sys.argv[1]):
|
|
||||||
try: item=json.loads(line)
|
|
||||||
except json.JSONDecodeError: continue
|
|
||||||
if item.get('reason')=='compiler-artifact' and item.get('profile',{}).get('test') and item.get('executable'):
|
|
||||||
found.append(item['executable'])
|
|
||||||
assert len(found)==1, f'Expected one unit test executable, got {len(found)}'
|
|
||||||
print(found[0])
|
|
||||||
PY
|
|
||||||
)
|
|
||||||
[[ -x "$executable" ]]
|
|
||||||
unit="archy-isolated-tests-$(date +%s)-$$"
|
|
||||||
sudo -n systemd-run --unit="$unit" --wait --pipe --collect \
|
|
||||||
--property="WorkingDirectory=$REPO/core" \
|
|
||||||
--property=PrivateNetwork=yes --property=PrivateTmp=yes --property=PrivateDevices=yes \
|
|
||||||
--property=ProtectSystem=strict --property=ProtectHome=read-only \
|
|
||||||
--property=NoNewPrivileges=yes \
|
|
||||||
--property='TemporaryFileSystem=/run:rw /var/lib/archipelago:rw /var/lib/containers:rw /root:rw' \
|
|
||||||
--setenv=ARCHY_TEST_ISOLATED=1 \
|
|
||||||
/usr/bin/unshare --pid --fork --mount-proc --kill-child \
|
|
||||||
/usr/bin/setpriv --bounding-set=-all,+chown,+dac_override,+fowner,+setuid,+setgid,+kill \
|
|
||||||
"$executable" --test-threads=4 "$@"
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
"""Exercise actual manifest entrypoints with a fake bitcoind; no node data touched."""
|
|
||||||
import json
|
|
||||||
import os
|
|
||||||
from pathlib import Path
|
|
||||||
import subprocess
|
|
||||||
import tempfile
|
|
||||||
import unittest
|
|
||||||
import yaml
|
|
||||||
|
|
||||||
ROOT = Path(__file__).resolve().parents[2]
|
|
||||||
|
|
||||||
class PruningEntrypoint(unittest.TestCase):
|
|
||||||
def test_auto_and_user_choice_for_both_bitcoin_implementations(self):
|
|
||||||
for app in ('bitcoin-core', 'bitcoin-knots'):
|
|
||||||
manifest = yaml.safe_load((ROOT / 'apps' / app / 'manifest.yml').read_text())
|
|
||||||
command = manifest['app']['container']['custom_args'][0]
|
|
||||||
for disk, choice, pruned in [(500,'0',True),(999,'0',True),(1000,'0',False),(2000,'0',False),(2000,'1',True),(500,'1',True)]:
|
|
||||||
with self.subTest(app=app,disk=disk,choice=choice), tempfile.TemporaryDirectory() as directory:
|
|
||||||
root = Path(directory)
|
|
||||||
binary = root / 'bitcoind'
|
|
||||||
binary.write_text('#!/usr/bin/env python3\nimport json,sys\nprint(json.dumps(sys.argv[1:]))\n')
|
|
||||||
binary.chmod(0o755)
|
|
||||||
env = dict(os.environ, PATH=directory+':'+os.environ['PATH'], DISK_GB=str(disk), BITCOIN_PRUNE=choice,
|
|
||||||
BITCOIN_RPC_USER='test',BITCOIN_RPC_PASS='test')
|
|
||||||
# Isolate the ephemeral RPC config too.
|
|
||||||
script = command.replace('/tmp/rpc.conf',str(root/'rpc.conf'))
|
|
||||||
args = json.loads(subprocess.check_output(['sh','-c',script],env=env,text=True))
|
|
||||||
self.assertEqual('-prune=50000' in args,pruned)
|
|
||||||
self.assertEqual('-txindex=1' in args,not pruned)
|
|
||||||
self.assertIn('-server=1',args)
|
|
||||||
|
|
||||||
if __name__ == '__main__': unittest.main()
|
|
||||||
@@ -1,40 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# No real service/container operations: all external operations are replaced.
|
|
||||||
set -euo pipefail
|
|
||||||
source "$(dirname "$0")/../../scripts/container-doctor.sh"
|
|
||||||
ss() {
|
|
||||||
[[ "${SS_FAIL:-0}" == 0 ]] || return 1
|
|
||||||
printf 'LISTEN 0 4096 *:8333 *:*\n'
|
|
||||||
# More than a pipe buffer, reliably reproducing grep -q / pipefail SIGPIPE.
|
|
||||||
awk 'BEGIN { for(i=0;i<20000;i++) print "LISTEN 0 4096 127.0.0.1:1234 *:*" }'
|
|
||||||
}
|
|
||||||
port_is_listening 8333
|
|
||||||
port_is_listening 1234 udp
|
|
||||||
if port_is_listening 833; then exit 1; else [[ $? == 1 ]]; fi
|
|
||||||
if SS_FAIL=1 port_is_listening 8333; then exit 1; else [[ $? == 2 ]]; fi
|
|
||||||
calls=$(mktemp)
|
|
||||||
trap 'rm -f "$calls"' EXIT
|
|
||||||
podman_rootless() {
|
|
||||||
case "$1" in
|
|
||||||
ps) echo bitcoin-core ;;
|
|
||||||
inspect)
|
|
||||||
if [[ "$*" == *PODMAN_SYSTEMD_UNIT* ]]; then echo "${TEST_UNIT:-bitcoin-core.service}";
|
|
||||||
else echo '8333/tcp 8333'; fi ;;
|
|
||||||
restart) echo "podman $*" >> "$calls" ;;
|
|
||||||
*) exit 1 ;;
|
|
||||||
esac
|
|
||||||
}
|
|
||||||
id() { echo 1000; }
|
|
||||||
systemctl() { echo "systemctl $*" >> "$calls"; }
|
|
||||||
# Healthy listener and failed ss inspection must not restart anything.
|
|
||||||
fix_missing_rootless_ports && exit 1
|
|
||||||
SS_FAIL=1 fix_missing_rootless_ports && exit 1
|
|
||||||
[[ ! -s "$calls" ]]
|
|
||||||
# A real missing listener restarts its managed unit, preserving stop timeout.
|
|
||||||
ss() { echo 'LISTEN 0 4096 *:1234 *:*'; }
|
|
||||||
fix_missing_rootless_ports
|
|
||||||
grep -Fx 'systemctl --user restart bitcoin-core.service' "$calls"
|
|
||||||
: > "$calls"
|
|
||||||
TEST_UNIT='<no value>' restart_rootless_container bitcoin-core
|
|
||||||
grep -Fx 'podman restart --time 600 bitcoin-core' "$calls"
|
|
||||||
echo 'PASS: healthy/missing/failed listener checks and safe managed/unmanaged restart'
|
|
||||||
@@ -1,109 +0,0 @@
|
|||||||
const test = require('node:test');
|
|
||||||
const assert = require('node:assert/strict');
|
|
||||||
const fs = require('node:fs');
|
|
||||||
const vm = require('node:vm');
|
|
||||||
const html = fs.readFileSync('docker/lnd-ui/index.html', 'utf8');
|
|
||||||
function extract(name) {
|
|
||||||
const start = html.indexOf(' function '+name+'(');
|
|
||||||
const end = html.indexOf('\n }', start)+10;
|
|
||||||
assert.ok(start >= 0 && end > start);
|
|
||||||
return html.slice(start, end);
|
|
||||||
}
|
|
||||||
function fixture() {
|
|
||||||
const elements = new Map();
|
|
||||||
const el = id => { if (!elements.has(id)) elements.set(id,{style:{},textContent:'',className:''}); return elements.get(id) };
|
|
||||||
const ctx = {state:{info:null,readiness:null}, document:{getElementById:el}, setText:(id,v)=>el(id).textContent=v,fmtCount:String};
|
|
||||||
vm.createContext(ctx);
|
|
||||||
vm.runInContext(extract('renderHeader')+'\n'+extract('validBalance'),ctx);
|
|
||||||
return {ctx,el};
|
|
||||||
}
|
|
||||||
test('missing, starting and syncing Bitcoin each show waiting and recover',()=>{
|
|
||||||
const {ctx,el}=fixture();
|
|
||||||
for (const [state,message] of [['waiting_install','Waiting for Bitcoin to be installed'],['waiting_start','Waiting for Bitcoin to start'],['waiting_sync','Waiting for Bitcoin to sync']]) {
|
|
||||||
ctx.state.readiness={state,message}; ctx.renderHeader();
|
|
||||||
assert.equal(el('headerStatusText').textContent,message);
|
|
||||||
assert.equal(el('syncCard').style.display,'');
|
|
||||||
assert.match(el('syncSubtitle').textContent,/automatically/);
|
|
||||||
assert.equal(el('syncPercent').textContent,'');
|
|
||||||
}
|
|
||||||
ctx.state.readiness={state:'bitcoin_ready'};
|
|
||||||
ctx.state.info={synced_to_chain:true,synced_to_graph:true};
|
|
||||||
ctx.renderHeader();
|
|
||||||
assert.equal(el('headerStatusText').textContent,'Running');
|
|
||||||
assert.equal(el('syncCard').style.display,'none');
|
|
||||||
ctx.state.info=null;ctx.state.readiness=null;ctx.renderHeader();
|
|
||||||
assert.equal(el('headerStatusText').textContent,'Connecting to LND');
|
|
||||||
});
|
|
||||||
test('balances reject missing, malformed, fractional and negative values; real zero remains valid',()=>{
|
|
||||||
const {ctx}=fixture();
|
|
||||||
for (const v of [null,undefined,'',{},false,-1,'-1','garbage',1.5,'1.5',Infinity,Number.MAX_SAFE_INTEGER+1]) assert.equal(ctx.validBalance(v),false,String(v));
|
|
||||||
for(const v of [0,'0',123,'123']) assert.equal(ctx.validBalance(v),true,String(v));
|
|
||||||
});
|
|
||||||
|
|
||||||
test('failed and partial balance polls retain known balances and label them stale; recovery clears flags',async()=>{
|
|
||||||
const {ctx,el}=fixture();
|
|
||||||
el('refreshIcon').classList={add(){},remove(){}};
|
|
||||||
const start=html.indexOf(' async function refreshAll()');
|
|
||||||
const end=html.indexOf('\n }',start)+10;
|
|
||||||
vm.runInContext(html.slice(start,end),ctx);
|
|
||||||
let responses={
|
|
||||||
'/v1/getinfo':{synced_to_chain:true},
|
|
||||||
'/v1/balance/blockchain':{confirmed_balance:'500',unconfirmed_balance:'0'},
|
|
||||||
'/v1/balance/channels':{local_balance:{sat:'250'}},
|
|
||||||
};
|
|
||||||
ctx.lndSafe=async(path,fallback)=>responses[path]??fallback;
|
|
||||||
ctx.renderAll=()=>{};
|
|
||||||
await ctx.refreshAll();
|
|
||||||
assert.equal(ctx.state.onchain.confirmed_balance,'500');
|
|
||||||
assert.equal(ctx.state.chanbal.local_balance.sat,'250');
|
|
||||||
responses={};await ctx.refreshAll();
|
|
||||||
assert.equal(ctx.state.onchain.confirmed_balance,'500');
|
|
||||||
assert.equal(ctx.state.chanbal.local_balance.sat,'250');
|
|
||||||
assert.equal(ctx.state.onchainStale,true);assert.equal(ctx.state.chanbalStale,true);
|
|
||||||
responses={'/v1/balance/blockchain':{confirmed_balance:'0'},'/v1/balance/channels':{error:'locked'}};
|
|
||||||
await ctx.refreshAll();
|
|
||||||
assert.equal(ctx.state.onchain.confirmed_balance,'0');
|
|
||||||
assert.equal(ctx.state.chanbal.local_balance.sat,'250');
|
|
||||||
assert.equal(ctx.state.onchainStale,false);assert.equal(ctx.state.chanbalStale,true);
|
|
||||||
responses={'/v1/balance/blockchain':{confirmed_balance:'600'},'/v1/balance/channels':{local_balance:{sat:'300'}}};
|
|
||||||
await ctx.refreshAll();
|
|
||||||
assert.equal(ctx.state.onchain.confirmed_balance,'600');
|
|
||||||
assert.equal(ctx.state.chanbal.local_balance.sat,'300');
|
|
||||||
assert.equal(ctx.state.onchainStale,false);assert.equal(ctx.state.chanbalStale,false);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('waiting renders promptly without querying unavailable LND endpoints, then resumes after Bitcoin sync',async()=>{
|
|
||||||
const {ctx,el}=fixture();
|
|
||||||
el('refreshIcon').classList={add(){},remove(){}};
|
|
||||||
const start=html.indexOf(' async function refreshAll()');
|
|
||||||
vm.runInContext(html.slice(start,html.indexOf('\n }',start)+10),ctx);
|
|
||||||
let readiness={state:'waiting_sync',message:'Waiting for Bitcoin to sync'};
|
|
||||||
const calls=[];let renders=0;
|
|
||||||
ctx.lndSafe=async(path,fallback)=>{calls.push(path);return path==='/archy-status'?readiness:fallback};
|
|
||||||
ctx.renderAll=()=>{renders++;ctx.renderHeader()};
|
|
||||||
await ctx.refreshAll();
|
|
||||||
assert.deepEqual(calls,['/archy-status']);
|
|
||||||
assert.equal(renders,1);
|
|
||||||
assert.equal(el('headerStatusText').textContent,'Waiting for Bitcoin to sync');
|
|
||||||
assert.equal(ctx.state.onchain,undefined);
|
|
||||||
assert.equal(ctx.state.refreshing,false);
|
|
||||||
readiness={state:'bitcoin_ready',message:'Bitcoin is ready'};
|
|
||||||
await ctx.refreshAll();
|
|
||||||
assert.ok(calls.includes('/v1/getinfo'));
|
|
||||||
assert.ok(calls.includes('/v1/balance/blockchain'));
|
|
||||||
});
|
|
||||||
|
|
||||||
test('cold waiting never invents zero channel capacity or an empty wallet recommendation',()=>{
|
|
||||||
const {ctx,el}=fixture();
|
|
||||||
Object.assign(ctx,{num:v=>Number(v)||0,fmtAmount:String,fmtAmountShort:String,setBalance:(id,v)=>el(id).value=v});
|
|
||||||
vm.runInContext(extract('renderBalances')+'\n'+extract('renderSummary')+'\n'+extract('renderChannels'),ctx);
|
|
||||||
ctx.state.channels=[];
|
|
||||||
ctx.renderBalances();ctx.renderSummary();ctx.renderChannels();
|
|
||||||
for(const id of ['liqLocal','liqRemote','statActiveChannels','healthPending','chActive']) assert.equal(el(id).textContent,'—');
|
|
||||||
assert.equal(el('balTotal').value,null);
|
|
||||||
assert.match(el('liqHint').textContent,/waiting for LND/);
|
|
||||||
assert.doesNotMatch(el('channelList').innerHTML,/No payment channels yet/);
|
|
||||||
ctx.state.info={};ctx.state.chanbal={local_balance:{sat:'0'}};
|
|
||||||
ctx.renderBalances();
|
|
||||||
assert.equal(el('liqLocal').textContent,'0');
|
|
||||||
});
|
|
||||||
@@ -72,9 +72,6 @@ summary() {
|
|||||||
stage "git-diff-check" git diff --check
|
stage "git-diff-check" git diff --check
|
||||||
stage "cargo-fmt" timeout 240 cargo fmt --manifest-path core/Cargo.toml --all --check
|
stage "cargo-fmt" timeout 240 cargo fmt --manifest-path core/Cargo.toml --all --check
|
||||||
stage "manifest-shell" python3 scripts/check-manifest-shell.py
|
stage "manifest-shell" python3 scripts/check-manifest-shell.py
|
||||||
stage "doctor-ports" bash tests/regression/container-doctor-ports.sh
|
|
||||||
stage "bitcoin-pruning" python3 tests/regression/bitcoin-prune-entrypoint.py
|
|
||||||
stage "lnd-ui-readiness" node --test tests/regression/lnd-ui-readiness.cjs
|
|
||||||
stage "catalog-drift" python3 scripts/check-app-catalog-drift.py --release --strict
|
stage "catalog-drift" python3 scripts/check-app-catalog-drift.py --release --strict
|
||||||
|
|
||||||
# Validate the artifact that will actually be signed and published, not only
|
# Validate the artifact that will actually be signed and published, not only
|
||||||
@@ -169,7 +166,9 @@ stage "cargo-check" timeout 580 cargo check --manifest-path core/Cargo.toml
|
|||||||
# 2026-08-20 1500s died at unit 427/429 (the archipelago bin test, the biggest
|
# 2026-08-20 1500s died at unit 427/429 (the archipelago bin test, the biggest
|
||||||
# link) on a loaded, swapping dev box, again without running a single test.
|
# link) on a loaded, swapping dev box, again without running a single test.
|
||||||
# 3600s leaves headroom; a warm target/ finishes in a fraction of it.
|
# 3600s leaves headroom; a warm target/ finishes in a fraction of it.
|
||||||
stage "cargo-test-isolated" timeout 3600 bash scripts/test-backend-isolated.sh
|
stage "cargo-test-weekly" timeout 3600 env CARGO_INCREMENTAL=0 \
|
||||||
|
cargo test --manifest-path core/Cargo.toml -p archipelago -- \
|
||||||
|
update:: lnd container::image_versions upgrade_preserves_container scanner drift missing_secret collision
|
||||||
|
|
||||||
# ── Stage 4: live node smoke ─────────────────────────────────────────
|
# ── Stage 4: live node smoke ─────────────────────────────────────────
|
||||||
if [[ $LIVE -eq 1 ]]; then
|
if [[ $LIVE -eq 1 ]]; then
|
||||||
@@ -216,7 +215,7 @@ if [[ $LIVE -eq 1 ]]; then
|
|||||||
[ -z "$st" ] && continue
|
[ -z "$st" ] && continue
|
||||||
seen=1
|
seen=1
|
||||||
echo "LND($port) state: $st"
|
echo "LND($port) state: $st"
|
||||||
echo "$st" | grep -qE "UNLOCKED|RPC_ACTIVE|SERVER_ACTIVE" && { echo "OK: LND wallet is unlocked"; exit 0; }
|
echo "$st" | grep -q "RPC_ACTIVE" && { echo "OK: LND wallet is unlocked"; exit 0; }
|
||||||
echo "$st" | grep -qE "NON_EXISTING|WAITING_TO_START" && { echo "OK: LND wallet not initialized yet — not a lock regression"; exit 0; }
|
echo "$st" | grep -qE "NON_EXISTING|WAITING_TO_START" && { echo "OK: LND wallet not initialized yet — not a lock regression"; exit 0; }
|
||||||
done
|
done
|
||||||
[ -z "$seen" ] && { echo "SKIP: LND /v1/state not reachable on 18080/8080"; exit 0; }
|
[ -z "$seen" ] && { echo "SKIP: LND /v1/state not reachable on 18080/8080"; exit 0; }
|
||||||
|
|||||||
Reference in New Issue
Block a user