Skip to content

feat(minter): read and verify durable nonce accounts - #244

Open
gregorydemay wants to merge 8 commits into
mainfrom
feat/nonce-account-reading
Open

gregorydemay wants to merge 8 commits into
mainfrom
feat/nonce-account-reading

Conversation

@gregorydemay

@gregorydemay gregorydemay commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

The ckSOL minter gains the read path for its durable nonce accounts: a getAccountInfo-based RPC wrapper fetches an account at the finalized commitment level and parses the durable-nonce state into the authority and the current nonce value. A misconfigured nonce account (not a non-executable system program account, not an initialized nonce account, in the legacy nonce format, or with an authority other than the minter's main address) is reported as an error rather than trapping, so that the caller can skip the account and keep processing withdrawals with the other accounts of the pool.

The read path is intentionally not wired to any caller yet: the following PR of the stack uses it to build withdrawal transactions on durable nonces and to decide whether an in-flight withdrawal transaction has landed.

🤖 Generated with Claude Code

@gregorydemay
gregorydemay added this pull request to stack #242 October 5, 2026 13:53
@gregorydemay gregorydemay changed the title feat/nonce account reading feat(minter): read and display the nonce accounts of the pool Oct 5, 2026
Copilot AI balanced review requested due to automatic review settings October 5, 2026 14:10
@gregorydemay
gregorydemay force-pushed the feat/nonce-account-reading branch from 58b902c to 196ef63 Compare October 5, 2026 14:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Nonce parsing omits account ownership validation, and RPC mock IDs are incorrect for non-default pool sizes.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds durable nonce-account observation to the minter, exposing finalized on-chain nonce values on the dashboard.

Changes:

  • Adds nonce-account RPC parsing, verification, transient state, and retry scheduling.
  • Displays observed nonce values on the dashboard.
  • Adds unit/integration coverage, fixtures, dependencies, and design documentation.
File Description
minter/​templates/​dashboard.html Renders nonce accounts and observed values.
minter/​src/​withdraw/​nonce/​tests.rs Tests observation retries and authority validation.
minter/​src/​withdraw/​nonce/​mod.rs Implements nonce observation and verification.
minter/​src/​withdraw/​mod.rs Exposes the nonce module.
minter/​src/​test_fixtures/​mod.rs Adds nonce-account fixtures.
minter/​src/​state/​nonce_pool/​mod.rs Tracks transient observed nonces.
minter/​src/​state/​mod.rs Integrates observations and task guarding.
minter/​src/​rpc/​tests.rs Tests nonce-account RPC parsing.
minter/​src/​rpc/​mod.rs Adds the finalized account-information wrapper.
minter/​src/​main.rs Starts observation after installation and upgrades.
minter/​src/​dashboard/​mod.rs Supplies nonce data to the dashboard.
minter/​src/​constants.rs Defines RPC cycle allocation.
minter/​Cargo.toml Adds Solana account and nonce dependencies.
integration_tests/​tests/​solana_test_validator.rs Verifies dashboard convergence end to end.
integration_tests/​src/​validator.rs Reads nonce values from the validator.
integration_tests/​src/​lib.rs Supports dashboard queries and setup mocks.
integration_tests/​src/​fixtures.rs Adds nonce RPC mock responses.
integration_tests/​Cargo.toml Adds integration-test dependencies.
docs/​design.md Documents eager nonce observation.
Cargo.toml Declares workspace dependencies.
Cargo.lock Locks the added dependencies.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread integration_tests/src/fixtures.rs Outdated
Comment thread minter/src/rpc/mod.rs
@gregorydemay
gregorydemay removed this pull request from stack #242 October 5, 2026 14:26
@gregorydemay
gregorydemay force-pushed the feat/nonce-account-reading branch from 196ef63 to 112277a Compare October 5, 2026 14:28
@gregorydemay
gregorydemay added this pull request to stack #245 October 5, 2026 14:28
@gregorydemay gregorydemay changed the title feat(minter): read and display the nonce accounts of the pool feat(minter): read and verify durable nonce accounts Oct 5, 2026
Copilot AI balanced review requested due to automatic review settings October 5, 2026 15:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused read path validates the required nonce-account invariants and includes appropriate unit coverage.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@gregorydemay
gregorydemay marked this pull request as ready for review October 5, 2026 15:45
@gregorydemay
gregorydemay requested a review from a team as a code owner October 5, 2026 15:45
@zeropath-ai

zeropath-ai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ No security or compliance issues detected. Reviewed everything up to a035815.

Security Overview
Detected Code Changes
Change Type Relevant files
Enhancement ► minter/src/rpc/mod.rs
     Introduce get_nonce_account and NonceAccount handling with new GET_ACCOUNT_INFO_CYCLES usage and related data structures
Enhancement ► minter/src/constants.rs
     Add GET_ACCOUNT_INFO_CYCLES constant and documentation
Enhancement ► minter/src/rpc/tests.rs
     Add tests for get_nonce_account, plus updated imports and test coverage for nonce account scenarios
Enhancement ► integration_tests/src/lib.rs
     Update nonce account default type to solana_address::Address using address! macro
Enhancement ► minter/src/test_fixtures/mod.rs
     Expand fixtures to include RENT_EXEMPTION_THRESHOLD and FEE_PER_SIGNATURE, and add nonce account helpers and related imports
Enhancement ► minter/src/withdraw/mod.rs
     Expose nonce module as part of withdrawal subsystem
Enhancement ► minter/src/withdraw/nonce/mod.rs
     Add read_verified_nonce function to read and verify nonce account nonce value, including ReadNonceError type and related error handling
Enhancement ► minter/src/withdraw/nonce/tests.rs
     Add tests for read_verified_nonce behavior including authority checks and error cases
Enhancement ► minter/src/withdraw/nonce/tests.rs
     Cover get_nonce_account interaction paths in tests (existing file continues to test related nonce logic)
Enhancement ► minter/src/rpc/mod.rs (imports block)
     Import GetAccountInfoEncoding, GetAccountInfo results, and UiAccount for nonce handling

@gregorydemay
gregorydemay removed this pull request from stack #245 October 6, 2026 07:01
@gregorydemay
gregorydemay changed the base branch from feat/withdrawal-destination-filter to main October 6, 2026 07:01
@gregorydemay
gregorydemay changed the base branch from main to feat/withdrawal-destination-filter October 6, 2026 07:01
@gregorydemay
gregorydemay added this pull request to stack #246 October 6, 2026 07:02
@gregorydemay
gregorydemay removed this pull request from stack #246 October 6, 2026 08:30
@gregorydemay
gregorydemay added this pull request to stack #249 October 6, 2026 08:30
@gregorydemay
gregorydemay removed this pull request from stack #249 October 6, 2026 08:40
@gregorydemay
gregorydemay added this pull request to stack #250 October 6, 2026 08:40
Copilot AI balanced review requested due to automatic review settings October 6, 2026 11:05
@gregorydemay
gregorydemay force-pushed the feat/nonce-account-reading branch from 3be7c9c to 1370547 Compare October 6, 2026 11:05
@gregorydemay

Copy link
Copy Markdown
Contributor Author

🤖 Re the reinstallation review: added §3.2.3 in 0637d3f. A reinstall uses fresh nonce accounts by default; reusing existing ones is documented (not implemented) as passing each account's current on-chain nonce value in the init args and advancing it once with an advance-only transaction before first use. The §3.2.2 authority check also now describes the error-instead-of-trap behavior.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 13:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The read path validates all documented nonce-account invariants and has focused coverage for its success and rejection cases.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@gregorydemay
gregorydemay removed this pull request from stack #250 October 6, 2026 14:20
@gregorydemay
gregorydemay added this pull request to stack #253 October 6, 2026 14:26
@gregorydemay
gregorydemay removed this pull request from stack #253 October 6, 2026 14:29
@gregorydemay
gregorydemay added this pull request to stack #254 October 6, 2026 14:29
@gregorydemay
gregorydemay removed this pull request from stack #254 October 6, 2026 15:02
@gregorydemay
gregorydemay added this pull request to stack #256 October 6, 2026 15:02
Copilot AI balanced review requested due to automatic review settings October 6, 2026 15:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The read path validates all documented nonce-account invariants and is covered by focused tests.

Review effort: Balanced
Findings: None

Copilot AI balanced review requested due to automatic review settings October 7, 2026 07:56
@gregorydemay
gregorydemay force-pushed the feat/nonce-account-reading branch from 88b4b19 to 3193260 Compare October 7, 2026 07:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the stated read-only scope and handles the documented invalid-account cases with focused tests.

Review effort: Balanced
Findings: None

gregorydemay and others added 8 commits October 7, 2026 09:43
Add a getAccountInfo wrapper that reads a durable nonce account at
finalized commitment and parses its authority and nonce value, and a
verified read that traps when the authority is not the minter's main
address, since a wrong-authority account in the pool is a serious operator
error. The read path stays unwired until withdrawal submission uses it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Validate the owner and executable flag of a fetched account before
decoding its nonce state, so that a foreign account whose data happens to
deserialize as a nonce account is rejected with a dedicated error, which
the verified read escalates to a trap like an authority mismatch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…once account

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s not match

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 09:57
@gregorydemay
gregorydemay force-pushed the feat/nonce-account-reading branch from 3193260 to a035815 Compare October 7, 2026 09:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The read path matches the documented contract, with only a non-blocking RPC error-branch coverage gap.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Comment thread minter/src/rpc/mod.rs
Comment on lines +195 to +199
match result? {
MultiRpcResult::Consistent(Ok(Some(account))) => NonceAccount::try_from(account),
MultiRpcResult::Consistent(Ok(None)) => Err(GetNonceAccountError::AccountNotFound),
MultiRpcResult::Consistent(Err(e)) => Err(GetNonceAccountError::RpcError(e)),
MultiRpcResult::Inconsistent(_) => Err(GetNonceAccountError::InconsistentRpcResults),
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants