Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Priority: P0 — research-first: the swap crash window can silently destroy received value; the correct fix shape (pre-persisted swap intents) must be designed, not improvised.

Aperta
#497 5 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@Amperstrand ci sta già lavorando.

Dal 8/10/2026.

  • #771 di @Amperstrand — aperta
  • #793 di @Amperstrand — aperta

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
go
Ambito
backend, databases

Direzione di ricerca

Start with wallet/wallet.go and wallet/storage/bolt.go, then read the CDK saga references named in the issue and inspect TollGate startup. First produce the requested research document: map crash windows for swap, mint, and melt, and compare pre-persisted intents with accept-and-bound reconciliation. Done means the document records a decision and supporting evidence; implementation and crash-injection tests are subsequent work.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Priority: P0 — research-first: the swap crash window can silently destroy received value; the correct fix shape (pre-persisted swap intents) must be designed, not improvised.

Problem

In gonuts Receive, the swap secrets (secrets, rs) exist only in memory (swapRequestPayload). The mint consumes the input proofs the moment the swap request lands; if the process dies (or panics, or the disk fills) after PostSwap succeeds but before SaveProofs, the newly issued outputs are unrecoverable: the wallet cannot unblind signatures without rs, and the mint has burned the inputs. The customer's token is gone with no local trace of the outputs.

The same window exists in MintTokens (mint signatures → SaveProofs) and in Melt (change proofs → save).

Why it matters

This is the fund-safety gap that CDK's wallet saga exists to close (saga record with counter range + blinded messages persisted before the network call; recovery replays or restores). gonuts has no equivalent. Probability is low per-request but non-zero over fleet lifetime (OOM, power loss, flash-full — flash-full is realistic on 8 MB routers), and the blast radius is total for the affected swap. We must either close it or consciously accept and bound it — but not leave it undocumented.

Current behavior (source refs, gonuts v0.11.2)

  • wallet/wallet.go:822-840 — createSwapRequest builds outputs, secrets, rs in memory.
  • wallet/wallet.go:723-732 — swap POST then SaveProofs(newProofs); nothing durable before the POST except the counter increment (which only prevents reuse, it does not enable recovery).
  • CDK reference model: crates/cdk/src/wallet/swap/saga/{mod,resume}.rs — add_saga (with counter_start/end, blinded messages) before post_swap; resume_swap_saga replays via NUT-19-cached responses or /restore-style checks.

Desired invariant

At any crash point, either (a) the operation's inputs were not consumed, or (b) enough durable state exists to reconstruct the outputs (secrets + rs + expected signatures) and complete the operation at next boot. No crash window may destroy issued-but-unstored value.

Proposed scope (research deliverable first, then implementation PRs)

  1. Research doc (docs/ in gonuts or TollGate): enumerate every in-flight monetary operation in gonuts and its crash windows (swap/mint/melt × before-POST/after-POST-before-save); for each, what durable pre-state would enable recovery; evaluate two designs:
    a. Pre-persist swap intents: bbolt bucket pending_ops storing {opId, mint, keysetId, counter range, outputs, secrets, rs, inputs Ys} written in the same tx as the counter increment; removed after SaveProofs; boot-time resume: re-POST (NUT-19 replay-safe? verify mints' behavior on identical swap re-POST — cdk-mintd caches; Nutshell?) or verify inputs' spend state + mint restore API availability.
    b. Accept-and-bound: document the window, add wallet balance-vs-mint reconciliation tooling to detect the loss after the fact (weaker; only acceptable if (a) proves infeasible).
  2. Decide per-operation; implement (a) where feasible (swap first — it is the customer-facing path).
  3. TollGate side: boot triggers resume before serving payments.

Areas / files

gonuts wallet/wallet.go, wallet/storage/bolt.go; TollGate startup.

Acceptance criteria (for the implementation phase)

  • Test kills the process (SIGKILL) between POST-swap and SaveProofs with a mint that recorded the swap; on restart the wallet completes the swap and the proofs appear (balance preserved).
  • Research doc merged with the decision and evidence.

Required tests

  • Crash-injection harness at the exact boundary (proxy that forwards to mint, then kills the process before response handling).

Failure-injection tests

  • Kill pre-POST (after intent write) → resume completes or compensates (inputs unspent → re-derive fresh range).
  • Kill post-POST → resume recovers outputs.
  • Mint lost the swap (never received) → resume re-POSTs identical request (assert mint idempotency behavior; document per-mint divergence).

Compatibility

Storage addition only; old DBs unaffected.

Dependencies

After G03's storage canonicalization lands (same file, avoid conflicts).

Out of scope

  • Full saga machinery beyond recovery of in-flight ops (business-level saga is TollGate-side, separate issue).
Lingua principale
Go
Stelle
12
Fork
14
Merge medio
1g 6h
PR unite (30g)
217

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di OpenTollGate/tollgate-module-basic-go

Tutte le issue di OpenTollGate/tollgate-module-basic-go

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.