Conversation
|
Follow-up |
…tom-genesis-psbt # Conflicts: # docs/release-notes/release-notes-0.9.0.md # lndservices/chain_bridge_test.go # tapdb/sqlc/querier.go
Use MintingBatch.Copy to avoid copying atomic state, cover staging isolation and error paths, and wrap wallet-anchor lines to satisfy CI lint.
|
Fork CI rehearsal passed at 7cc9a17 against upstream main 4466280, using unchanged workflows and an identical merge tree: CI — 40 jobs passed and backward compatibility passed. The fork-only release-note check was skipped; the unchanged checker passed separately using PR number 2238. Ready for maintainer approval of official upstream CI; these rehearsal results do not replace upstream checks. |
Integrate upstream cancellation lease cleanup through a shared dispatcher. Preserve batch-scoped custom leases and never unlock foreign custom-anchor inputs through the ordinary wallet fallback. Add mixed-input and all-foreign cancellation regressions. Signed-off-by: Sadiq Jaffer <sadiq.jaffer@satscryption.io>
|
Synced with upstream The cancellation conflicts with #2262 are resolved through one lease-release dispatcher. Ordinary wallet-funded batches retain upstream cleanup. Custom anchors release only recorded leases using the batch-specific owner ID; foreign inputs never reach the ordinary wallet-unlock fallback. Added mixed-input and all-foreign cancellation regressions. Publication/cancellation boundaries and immutable signed transactions are unchanged. Validation before updating this PR:
Failure history: attempt 1 had one PostgreSQL integration partition fail during daemon startup near the harness's 10-second readiness deadline. The retained logs show incomplete migrations/connection closure and one node opening RPC just after the deadline. The failed-only retry passed on the identical source and binary artifacts, without timeout or workflow changes. The initial failure remains recorded on the rehearsal PR; the underlying resource/timing cause is not conclusively established. The rehearsal retains its existing fork-only release-note metadata skip because its PR number differs from upstream #2238. The unchanged release-note script passed locally with |
Preserve both custom-anchor key repair queries and upstream orphan-UTXO candidate selection at their shared SQL insertion point. Keep generated bindings and upstream orphan-validation regressions intact. Signed-off-by: Sadiq Jaffer <sadiq.jaffer@satscryption.io>
|
Resolved the new merge conflict after upstream #2265 and fast-forwarded this PR to The conflict was two independent additions at the same position in Validation before this update:
The fork's existing release-note metadata job remains skipped because its PR number differs; the unchanged checker passed locally using The tested fork merge GitHub now reports this PR as conflict-free ( |
Integrate upstream cd3253d through a history-preserving merge. Retain custom genesis anchor changes alongside upstream proof encoding, grouped receive, invoice validation, integration coverage, and dependency updates. Signed-off-by: Sadiq Jaffer <sadiq.jaffer@satscryption.io>
Merge upstream 9bf78a5. Preserve custom-anchor publication retries and batch-scoped lease renewal after registering the new mint anchoring watcher, and release only recorded custom leases on durable abandonment. Retain legacy confirmation behavior and immutable signed packets. Regenerate SQL and RPC bindings with pinned tools and add watcher failure, confirmation, retry and abandonment regressions. Signed-off-by: Sadiq Jaffer <sadiq.jaffer@satscryption.io>
Merge upstream main (93420d4) into codex/issue-721-custom-genesis-psbt (d85ccfd). The PR's 33 commits are preserved. Upstream's re-org watcher rework removed the cultivator's legacy RegisterConfirmationsNtfn path, so confirmation is learned only by staking a mint anchoring and waiting on its delivered phase. Conflict resolutions: tapgarden/cultivator.go - Drop proofsWatched. It only gated ProofWatcher.WatchProofs on the legacy confirmation path, which upstream deleted. Nothing else reads it. UpdateMintingProofs is dropped with it. - Broadcast keeps upstream's anchoring-only flow: registerMintAnchoring before any Broadcast publish, then one goroutine waits on the registry. Re-apply the custom-genesis trace log (isCustomAnchorPsbt) and publishBroadcast. An earlier Committed-state publish may already have relayed the transaction, so a later publish error must not cancel confirmation tracking or return the batch to a mutable state. publishBroadcast renews custom-anchor leases and treats an ambiguous wallet rejection as still-watched. Non-custom publishes still fail the state step when PublishTransaction fails. tapgarden/planter.go - Cultivator config keeps upstream's anchoring waiter wiring and drops UpdateMintingProofs. CustomAnchorLeaseRenewalInterval is still passed through so Broadcast retries and lease renewal keep the PR's cadence. tapgarden/planter_test.go - mintAnchorings is upstream's trigger-outpoint lookup. assertTxPublished only waits on PublishReq. The legacy ConfReqSignal handshake is gone. assertAnchoringRegistered also rejects a non-zero confirmation subscription count. bench/fixture/mint_driver.go - The pump confirms a published genesis transaction on the mock re-org watcher (upstream). It no longer correlates ConfReqSignal with publishes. itest/assertions.go - AssertAssetsMintedAtOutpoint keeps the PR's outpoint check (AssetAnchorOutpointCheck, so a non-zero asset anchor index is asserted) and upstream's scriptKeyLocalCheck (external script keys are not required to be wallet-local). Tests: - Issue 721 stateful tests wait on mint anchorings instead of ConfReqSignal, deliver confirmation through confirmAnchoring, and fail registration with MockRegistrar.FailNextRegister. PauseNextRegister holds Register after the anchoring is stored so a lease fault can be injected before publishBroadcast. DropAnchorings covers a Broadcast batch whose anchoring was not persisted across restart. Co-authored-by: Sadiq Jaffer <SadiqJaf@users.noreply.github.com>
Summary
This adds a caller-controlled Bitcoin anchor PSBT flow for minting batches.
FundBatchcan accept a funded anchor PSBT plus explicit asset-anchor, change, and supply-precommit output indexes.PrepareBatchcommits the asset tree and pauses before Bitcoin publication so an external signer can finalize caller-controlled inputs.FinalizeBatchvalidates and merges the exact signed transaction, imports the anchor, persists the publication boundary, and resumes confirmation/proof handling.Safety properties
Compatibility and scope
The default minting path is unchanged.
This initial custom-anchor implementation requires the selected asset-anchor internal key to be owned by the backing
lndwallet. Arbitrary external or NUMS anchor internal keys require a different custody, spending, backup, and recovery model and are tracked separately in #2237.Validation
go test -p 1 ./tapgarden ./tapdb ./lndservices ./rpcserver ./tapnode/tapnodemock -count=1go test -race ./tapgarden -run '^(TestIssue721|TestCustomAnchorHistoricalKeyRepair)' -count=1 -timeout=180sgo test ./itest -run '^TestCustomAnchor(ForeignInputPreserved|SparseWalletCommitment|AuthorityCommitmentBindsFields|RegtestBits)$' -count=1go test -tags=itest ./itest -run '^$' -count=1git diff --checkFixes #721