Repository navigation
feat(minter): read and verify durable nonce accounts - #244
gregorydemay wants to merge 8 commits into
Conversation
58b902c to
196ef63
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Nonce parsing omits account ownership validation, and RPC mock IDs are incorrect for non-default pool sizes.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds durable nonce-account observation to the minter, exposing finalized on-chain nonce values on the dashboard.
Changes:
- Adds nonce-account RPC parsing, verification, transient state, and retry scheduling.
- Displays observed nonce values on the dashboard.
- Adds unit/integration coverage, fixtures, dependencies, and design documentation.
| File | Description |
|---|---|
minter/templates/dashboard.html |
Renders nonce accounts and observed values. |
minter/src/withdraw/nonce/tests.rs |
Tests observation retries and authority validation. |
minter/src/withdraw/nonce/mod.rs |
Implements nonce observation and verification. |
minter/src/withdraw/mod.rs |
Exposes the nonce module. |
minter/src/test_fixtures/mod.rs |
Adds nonce-account fixtures. |
minter/src/state/nonce_pool/mod.rs |
Tracks transient observed nonces. |
minter/src/state/mod.rs |
Integrates observations and task guarding. |
minter/src/rpc/tests.rs |
Tests nonce-account RPC parsing. |
minter/src/rpc/mod.rs |
Adds the finalized account-information wrapper. |
minter/src/main.rs |
Starts observation after installation and upgrades. |
minter/src/dashboard/mod.rs |
Supplies nonce data to the dashboard. |
minter/src/constants.rs |
Defines RPC cycle allocation. |
minter/Cargo.toml |
Adds Solana account and nonce dependencies. |
integration_tests/tests/solana_test_validator.rs |
Verifies dashboard convergence end to end. |
integration_tests/src/validator.rs |
Reads nonce values from the validator. |
integration_tests/src/lib.rs |
Supports dashboard queries and setup mocks. |
integration_tests/src/fixtures.rs |
Adds nonce RPC mock responses. |
integration_tests/Cargo.toml |
Adds integration-test dependencies. |
docs/design.md |
Documents eager nonce observation. |
Cargo.toml |
Declares workspace dependencies. |
Cargo.lock |
Locks the added dependencies. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
196ef63 to
112277a
Compare
|
✅ No security or compliance issues detected. Reviewed everything up to a035815. Security OverviewDetected Code Changes
|
3be7c9c to
1370547
Compare
|
🤖 Re the reinstallation review: added §3.2.3 in 0637d3f. A reinstall uses fresh nonce accounts by default; reusing existing ones is documented (not implemented) as passing each account's current on-chain nonce value in the init args and advancing it once with an advance-only transaction before first use. The §3.2.2 authority check also now describes the error-instead-of-trap behavior. |
88b4b19 to
3193260
Compare
Add a getAccountInfo wrapper that reads a durable nonce account at finalized commitment and parses its authority and nonce value, and a verified read that traps when the authority is not the minter's main address, since a wrong-authority account in the pool is a serious operator error. The read path stays unwired until withdrawal submission uses it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Validate the owner and executable flag of a fetched account before decoding its nonce state, so that a foreign account whose data happens to deserialize as a nonce account is rejected with a dedicated error, which the verified read escalates to a trap like an authority mismatch. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…once account Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s not match Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
3193260 to
a035815
Compare
| match result? { | ||
| MultiRpcResult::Consistent(Ok(Some(account))) => NonceAccount::try_from(account), | ||
| MultiRpcResult::Consistent(Ok(None)) => Err(GetNonceAccountError::AccountNotFound), | ||
| MultiRpcResult::Consistent(Err(e)) => Err(GetNonceAccountError::RpcError(e)), | ||
| MultiRpcResult::Inconsistent(_) => Err(GetNonceAccountError::InconsistentRpcResults), |


The ckSOL minter gains the read path for its durable nonce accounts: a
getAccountInfo-based RPC wrapper fetches an account at thefinalizedcommitment level and parses the durable-nonce state into the authority and the current nonce value. A misconfigured nonce account (not a non-executable system program account, not an initialized nonce account, in the legacy nonce format, or with an authority other than the minter's main address) is reported as an error rather than trapping, so that the caller can skip the account and keep processing withdrawals with the other accounts of the pool.The read path is intentionally not wired to any caller yet: the following PR of the stack uses it to build withdrawal transactions on durable nonces and to decide whether an in-flight withdrawal transaction has landed.
🤖 Generated with Claude Code