Skip to content

Preserve durable broadcast attempts and nonce recovery - #120

Draft
csmithington wants to merge 1 commit into
joshstevens19:masterfrom
usherlabs:upstream/transaction-integrity
Draft

csmithington wants to merge 1 commit into
joshstevens19:masterfrom
usherlabs:upstream/transaction-integrity

Conversation

@csmithington

Copy link
Copy Markdown

Summary

This is the generic transaction-integrity portion of Usher's downstream recovery work, prepared on a single commit directly above canonical v0.14.0. It contains no FIET policy values, fork governance files, or reproducible-build metadata.

  • persist the exact signed transaction hash and applicable gas snapshot before any RPC send
  • keep ambiguous broadcast attempts durable and recover them from the live row plus ordered audit history
  • persist nonce repair before mutating in-memory transaction, queue, or nonce-manager state
  • release reserved nonces only for failures proven to occur before broadcast evidence
  • preserve original nonces through replacement/cancellation and canonical clone/blob semantics
  • keep live normal wallet indexes stable and non-colliding while preserving private-key and clone namespaces
  • add the v1.0.4 lookup/uniqueness indexes used by recovery and wallet allocation

This currently includes the accepted/pending hash contract from #119 because the queue may durably accept a transaction before a hash is exposed to the request handler. It should be rebased after #119 is decided.

Validation

  • cargo fmt --all -- --check
  • cargo clippy -- -D warnings -A clippy::uninlined_format_args
  • cargo test --exclude rust-sdk-playground --workspace (51 core tests plus workspace/doc tests)
  • npm run build in sdk/typescript

Review notes

The behavioral changes are intentionally kept together where ordering is the invariant: signed evidence must become durable before broadcast, and database repair must precede memory repair. The PR is draft to allow maintainer review of the migration and recovery model before merge.

Persist signed attempt evidence before RPC broadcast, recover ambiguous sends from durable history, and keep nonce and wallet-index state coherent across failures.
@vercel

vercel Bot commented Aug 5, 2026

Copy link
Copy Markdown

@csmithington is attempting to deploy a commit to the joshaavecom's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant