diff --git a/docs/adr/005-cash-out-dispense-outcome.md b/docs/adr/005-cash-out-dispense-outcome.md index 6740b96..c68a89d 100644 --- a/docs/adr/005-cash-out-dispense-outcome.md +++ b/docs/adr/005-cash-out-dispense-outcome.md @@ -472,7 +472,12 @@ a candidate issue. 9. **The partial-dispense guard's message is wrong for internal legs.** "Lightning payments can't be clawed back" is true of `autoforward` and false of the LNbits-internal legs, which are compensatable. Make the guard leg-aware or correct the message. -10. **Review scope.** This document traced the cash-out path: state machine → HAL → ledger → +10. **`packages/hal` has no tests.** `pnpm test` there exits 1 with "No test files found." + The F56 note-length table that produced a production fault on a GTQ Tejo was carried + byte for byte from lamassu with nothing over it; the fix landed the same way. A table test + asserting every currency's window is centred on its note length is a few lines, and + `dispenseConfirmed` (Decision 3) needs the harness to exist before it can be tested. +11. **Review scope.** This document traced the cash-out path: state machine → HAL → ledger → transport → settlement → distribution → dashboard. The cash-in path shares the settlement pipeline and has its own money-at-risk shape in `create_withdraw` (server-side amounts, `max_cash_in_sats`); it has not been reviewed to the same depth and is the obvious next