audit id003 _send 100ms setTimeout — possible escrow→stack race on Sintras #46
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
While investigating the MEI/EBDS bill-tear root cause on the BATM3
(PR #45), the
id003 driver was inspected for an analogous timing concern.
The MEI tear is fixed by polling at 100 ms inside the validator's
escrow grace window. id003 already polls at 100 ms — but it has a
separate concern that warrants a focused audit before we declare the
JCM iVIZION path equally safe.
The concern
packages/hal/src/validators/id003/index.ts:276-289:Every host command is delayed by
POLLING_INTERVAL(100 ms) before theserial write actually fires. Functionally this is a defensive pause to
"prevent interleaved commands" — but it means a host
stack()callarrives at the validator 100 ms after we decide to stack.
For id003 / JCM iVIZION the bill is mechanically gripped and stationary
during the host-decision phase, so this 100 ms is normally harmless.
But:
within 100 ms vs how often it slips longer (no equivalent of the
EBDS escrow watchdog landing in PR #45).
large Vue re-renders, GC pauses on the Aaeon UP Board — which
memory/sintra_perf_constraints.mdnotes is constrained) theeffective delay could be 100 ms + scheduler latency.
spec describes one, default behavior varies by firmware), we'd be
in the same family of failure as the MEI.
The "interleaved commands" rationale is also undocumented — it'd be
worth tracing back where that came from. If it's a paranoia hold-over
from the original lamassu-machine and not actually load-bearing on
modern JCM firmware, the
setTimeoutcould be dropped entirely.Suggested work
id003 FSM (
packages/hal/src/validators/id003/id003-fsm.ts).Deploy to one Sintra (Atitlan?), collect a week of journals, see
whether escrow → vendValid is ever over ~250 ms in practice.
reference for "Timeout to prevent interleaved commands." If no
protocol justification surfaces, remove the setTimeout and make
_sendsynchronous (with the polling stop/start brackets kept).versions, gate it behind a per-model flag rather than always-on.
Scope explicitly out
This isn't urgent. We have zero field reports of id003-related
bill tears on the Sintras and Douros — the only torn bills came from
the BATM3, which is the EBDS code path. This is preventive work to
make sure we'd actually catch a similar issue if it surfaced.
References
sintra_perf_constraints.md(Aaeon UP Board scheduler constraints)
packages/hal/src/validators/id003/index.ts🤖 Filed via Claude Code