fix(machine): guard the availability beacon sign against bunker blips #67
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "beacon-sign-guard"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found during the 2026-06-22 secure-cash-in smoke: two
Uncaught (in promise) BunkerTimeoutError: bunker sign_event: no response in 10000msappeared on the Sintra a few minutes after the (successful) cash-in, during what looks like a transient bunker watchdog blip.Cause
The availability beacon's
createSignedEvent(a bunker round-trip) sat outside itstry/catch— onlynostrClient.publish(event)was guarded — andpublish(snap)is fire-and-forget. So a transientBunkerTimeoutError/BunkerRejectedErrorduring the periodic sign surfaced as an uncaught promise rejection.Fix
Move the sign inside the
try. The beacon re-publishes every interval, so swallow + log is the right behaviour for a transient signer blip. (A persistent revoke still gets caught at the next init → "Pairing Required"; full mid-session re-pair detection remains the separate Phase D follow-up.)One-file change; typecheck 12/12, machine 29 tests green. Independent of the cash-in PR (#66).
Do NOT use the MCP merge endpoint — merge via the Forgejo UI after review.
🤖 Generated with Claude Code
6d9f5c3d99toa762a7ea40