Priority: P0 — research-first: the swap crash window can silently destroy received value; the correct fix shape (pre-persisted swap intents) must be designed, not improvised.
I maintainer di solito rispondono entro 1 giorno
@Amperstrand ci sta già lavorando.
Dal 8/10/2026.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
Direzione di ricerca
Start with wallet/wallet.go and wallet/storage/bolt.go, then read the CDK saga references named in the issue and inspect TollGate startup. First produce the requested research document: map crash windows for swap, mint, and melt, and compare pre-persisted intents with accept-and-bound reconciliation. Done means the document records a decision and supporting evidence; implementation and crash-injection tests are subsequent work.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Priority: P0 — research-first: the swap crash window can silently destroy received value; the correct fix shape (pre-persisted swap intents) must be designed, not improvised.
Problem
In gonuts Receive, the swap secrets (secrets, rs) exist only in memory (swapRequestPayload). The mint consumes the input proofs the moment the swap request lands; if the process dies (or panics, or the disk fills) after PostSwap succeeds but before SaveProofs, the newly issued outputs are unrecoverable: the wallet cannot unblind signatures without rs, and the mint has burned the inputs. The customer's token is gone with no local trace of the outputs.
The same window exists in MintTokens (mint signatures → SaveProofs) and in Melt (change proofs → save).
Why it matters
This is the fund-safety gap that CDK's wallet saga exists to close (saga record with counter range + blinded messages persisted before the network call; recovery replays or restores). gonuts has no equivalent. Probability is low per-request but non-zero over fleet lifetime (OOM, power loss, flash-full — flash-full is realistic on 8 MB routers), and the blast radius is total for the affected swap. We must either close it or consciously accept and bound it — but not leave it undocumented.
Current behavior (source refs, gonuts v0.11.2)
wallet/wallet.go:822-840—createSwapRequestbuildsoutputs, secrets, rsin memory.wallet/wallet.go:723-732— swap POST thenSaveProofs(newProofs); nothing durable before the POST except the counter increment (which only prevents reuse, it does not enable recovery).- CDK reference model:
crates/cdk/src/wallet/swap/saga/{mod,resume}.rs—add_saga(with counter_start/end, blinded messages) beforepost_swap;resume_swap_sagareplays via NUT-19-cached responses or/restore-style checks.
Desired invariant
At any crash point, either (a) the operation's inputs were not consumed, or (b) enough durable state exists to reconstruct the outputs (secrets + rs + expected signatures) and complete the operation at next boot. No crash window may destroy issued-but-unstored value.
Proposed scope (research deliverable first, then implementation PRs)
- Research doc (
docs/in gonuts or TollGate): enumerate every in-flight monetary operation in gonuts and its crash windows (swap/mint/melt × before-POST/after-POST-before-save); for each, what durable pre-state would enable recovery; evaluate two designs:
a. Pre-persist swap intents: bbolt bucketpending_opsstoring{opId, mint, keysetId, counter range, outputs, secrets, rs, inputs Ys}written in the same tx as the counter increment; removed afterSaveProofs; boot-time resume: re-POST (NUT-19 replay-safe? verify mints' behavior on identical swap re-POST — cdk-mintd caches; Nutshell?) or verify inputs' spend state + mint restore API availability.
b. Accept-and-bound: document the window, add wallet balance-vs-mint reconciliation tooling to detect the loss after the fact (weaker; only acceptable if (a) proves infeasible). - Decide per-operation; implement (a) where feasible (swap first — it is the customer-facing path).
- TollGate side: boot triggers resume before serving payments.
Areas / files
gonuts wallet/wallet.go, wallet/storage/bolt.go; TollGate startup.
Acceptance criteria (for the implementation phase)
- Test kills the process (SIGKILL) between POST-swap and SaveProofs with a mint that recorded the swap; on restart the wallet completes the swap and the proofs appear (balance preserved).
- Research doc merged with the decision and evidence.
Required tests
- Crash-injection harness at the exact boundary (proxy that forwards to mint, then kills the process before response handling).
Failure-injection tests
- Kill pre-POST (after intent write) → resume completes or compensates (inputs unspent → re-derive fresh range).
- Kill post-POST → resume recovers outputs.
- Mint lost the swap (never received) → resume re-POSTs identical request (assert mint idempotency behavior; document per-mint divergence).
Compatibility
Storage addition only; old DBs unaffected.
Dependencies
After G03's storage canonicalization lands (same file, avoid conflicts).
Out of scope
- Full saga machinery beyond recovery of in-flight ops (business-level saga is TollGate-side, separate issue).
- Lingua principale
- Go
- Stelle
- 12
- Fork
- 14
- Merge medio
- 1g 6h
- PR unite (30g)
- 217
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di OpenTollGate/tollgate-module-basic-go
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Forse già presa @Amperstrand l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
OpenTollGate/tollgate-module-basic-go#726 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
rebrand-literal-gutter: uhttpd section-vocabulary check trips on a COMMENT (uhttpd.luci in 92-tollgate-admin-setup:178)Forse già presa @Amperstrand l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
OpenTollGate/tollgate-module-basic-go#723 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
OpenTollGate/tollgate-module-basic-go#768 ·
I maintainer di solito rispondono entro 1 giorno
-
Four drift fences for tests/contract/ (+ test.yml clean-container lane + pre-commit wiring)Forse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
OpenTollGate/tollgate-module-basic-go#767 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
OpenTollGate/tollgate-module-basic-go#763 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di OpenTollGate/tollgate-module-basic-go
Issue simili
-
Discriminator mapping keys are listed in a random orderForse già presa @reuvenharrison l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Idle compaction monitors LIST the replica every tick when the newest destination file spans more than one TXIDForse già presa @pishuv l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
benbjohnson/litestream#1563 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
agent-research agent-review-finding chore
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
jordansmall/spindrift#4922 ·
I maintainer di solito rispondono entro 1 giorno
-
gcsartifact: deleting a missing version returns an errorForse già presa @ktsoator l’ha presa oggi. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 2 giorni