Skip to content

Milestone/b01 sdk network compatibility - #23

Closed
SuPuHe wants to merge 2 commits into
developfrom
milestone/b01-sdk-network-compatibility
Closed

SuPuHe wants to merge 2 commits into
developfrom
milestone/b01-sdk-network-compatibility

Conversation

@SuPuHe

@SuPuHe SuPuHe commented Sep 7, 2026

Copy link
Copy Markdown
Member

test

selezenart and others added 2 commits September 7, 2026 15:45
… classifier

Implements B02 for the Coder B lane as pure adapter logic with no network, no
durable state, and no credential.

Canonical request (B02.1, B02.2). One intent produces byte-stable calldata, a
keccak256 payload fingerprint, a provider idempotency key, and a reference ID.
Serialization writes an explicit field order rather than relying on
JSON.stringify over an object literal, whose key order depends on construction
order; two workers building the same obligation must fingerprint identically or
the provider key stops collapsing duplicates. Addresses are lowercased so
checksummed and non-checksummed spellings cannot fingerprint apart. A golden
vector pins the exact bytes, because changing any of them changes every
in-flight idempotency key. The 24-hour provider window is documented as
supplemental: OneShot durable state remains the authority past it.

Only the direct transfer path is built. B01.3 recorded the Arc Memo forwarded
call NOT_SUPPORTED, so no memo calldata builder exists to be reached by
mistake.

Policy fixture (B02.3). Expresses the required Privy policy as rules over the
documented condition fields, terminated by an unconditional default deny.
assessPolicySoundness catches the two ways such a policy silently stops
protecting anything: losing its terminal deny, or dropping a constrained
dimension. A keccak256 digest lets readiness detect drift, since the policy
lives in Privy configuration outside this repository and can be edited without
a commit. The digest ignores recipient ordering so an operator relisting the
same addresses does not read as drift.

Receipt verification (B02.4). Confirmation requires a final receipt and exactly
one Transfer matching sender, recipient, and amount, emitted by the configured
token. status: 1 alone is not confirmation, and tests cover the cases that
would otherwise pass: no logs, a redirected recipient, an amount off by one
atomic unit, a Transfer from an impostor contract, and two matching transfers,
which would mean more value moved than was authorized.

Outcome classifier (B02.5). Doubt is structural. DEFINITELY_NOT_SUBMITTED is
granted only for narrow pre-flight proofs where nothing was broadcast; every
ambiguous signal and every unrecognized response shape falls through to
POSSIBLY_SUBMITTED, including a response kind from a future provider version.
A receipt that fails to prove settlement is POSSIBLY_SUBMITTED, never
DEFINITELY_NOT_SUBMITTED: absence of proof is not proof of absence.
feat(settlement): canonical request, policy fixture, receipt, and classifier (B02)
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
oneshot 1dda3c1 Sep 07 2026, 05:23 PM

@SuPuHe SuPuHe closed this Sep 7, 2026
@SuPuHe
SuPuHe deleted the milestone/b01-sdk-network-compatibility branch September 7, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants