Repository navigation
feat(minter): read and verify durable nonce accounts - #244
Merged
Merged
Conversation
gregorydemay
added this pull request to stack #242
October 5, 2026 13:53
gregorydemay
force-pushed
the
feat/nonce-account-reading
branch
from
October 5, 2026 14:10
58b902c to
196ef63
Compare
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Nonce parsing omits account ownership validation, and RPC mock IDs are incorrect for non-default pool sizes.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds durable nonce-account observation to the minter, exposing finalized on-chain nonce values on the dashboard.
Changes:
- Adds nonce-account RPC parsing, verification, transient state, and retry scheduling.
- Displays observed nonce values on the dashboard.
- Adds unit/integration coverage, fixtures, dependencies, and design documentation.
| File | Description |
|---|---|
minter/templates/dashboard.html |
Renders nonce accounts and observed values. |
minter/src/withdraw/nonce/tests.rs |
Tests observation retries and authority validation. |
minter/src/withdraw/nonce/mod.rs |
Implements nonce observation and verification. |
minter/src/withdraw/mod.rs |
Exposes the nonce module. |
minter/src/test_fixtures/mod.rs |
Adds nonce-account fixtures. |
minter/src/state/nonce_pool/mod.rs |
Tracks transient observed nonces. |
minter/src/state/mod.rs |
Integrates observations and task guarding. |
minter/src/rpc/tests.rs |
Tests nonce-account RPC parsing. |
minter/src/rpc/mod.rs |
Adds the finalized account-information wrapper. |
minter/src/main.rs |
Starts observation after installation and upgrades. |
minter/src/dashboard/mod.rs |
Supplies nonce data to the dashboard. |
minter/src/constants.rs |
Defines RPC cycle allocation. |
minter/Cargo.toml |
Adds Solana account and nonce dependencies. |
integration_tests/tests/solana_test_validator.rs |
Verifies dashboard convergence end to end. |
integration_tests/src/validator.rs |
Reads nonce values from the validator. |
integration_tests/src/lib.rs |
Supports dashboard queries and setup mocks. |
integration_tests/src/fixtures.rs |
Adds nonce RPC mock responses. |
integration_tests/Cargo.toml |
Adds integration-test dependencies. |
docs/design.md |
Documents eager nonce observation. |
Cargo.toml |
Declares workspace dependencies. |
Cargo.lock |
Locks the added dependencies. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
gregorydemay
removed this pull request from stack #242
October 5, 2026 14:26
gregorydemay
force-pushed
the
feat/nonce-account-reading
branch
from
October 5, 2026 14:28
196ef63 to
112277a
Compare
gregorydemay
added this pull request to stack #245
October 5, 2026 14:28
gregorydemay
marked this pull request as ready for review
October 5, 2026 15:45
|
✅ No security or compliance issues detected. Reviewed everything up to 20d266d. Security OverviewDetected Code Changes
|
gregorydemay
removed this pull request from stack #245
October 6, 2026 07:01
gregorydemay
changed the base branch from
feat/withdrawal-destination-filter
to
main
October 6, 2026 07:01
gregorydemay
changed the base branch from
main
to
feat/withdrawal-destination-filter
October 6, 2026 07:01
gregorydemay
added this pull request to stack #246
October 6, 2026 07:02
gregorydemay
removed this pull request from stack #246
October 6, 2026 08:30
gregorydemay
added this pull request to stack #249
October 6, 2026 08:30
gregorydemay
removed this pull request from stack #249
October 6, 2026 08:40
gregorydemay
added this pull request to stack #250
October 6, 2026 08:40
gregorydemay
force-pushed
the
feat/nonce-account-reading
branch
from
October 6, 2026 11:05
3be7c9c to
1370547
Compare
gregorydemay
force-pushed
the
feat/nonce-account-reading
branch
from
October 7, 2026 07:56
88b4b19 to
3193260
Compare
Add a getAccountInfo wrapper that reads a durable nonce account at finalized commitment and parses its authority and nonce value, and a verified read that traps when the authority is not the minter's main address, since a wrong-authority account in the pool is a serious operator error. The read path stays unwired until withdrawal submission uses it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Validate the owner and executable flag of a fetched account before decoding its nonce state, so that a foreign account whose data happens to deserialize as a nonce account is rejected with a dedicated error, which the verified read escalates to a trap like an authority mismatch. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…once account Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s not match Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gregorydemay
force-pushed
the
feat/nonce-account-reading
branch
from
October 7, 2026 09:57
3193260 to
a035815
Compare
…ccount Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 7, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


The ckSOL minter gains the read path for its durable nonce accounts: a
getAccountInfo-based RPC wrapper fetches an account at thefinalizedcommitment level and parses the durable-nonce state into the authority and the current nonce value. A misconfigured nonce account (not a non-executable system program account, not an initialized nonce account, in the legacy nonce format, or with an authority other than the minter's main address) is reported as an error rather than trapping, so that the caller can skip the account and keep processing withdrawals with the other accounts of the pool.The read path is intentionally not wired to any caller yet: the following PR of the stack uses it to build withdrawal transactions on durable nonces and to decide whether an in-flight withdrawal transaction has landed.
🤖 Generated with Claude Code