fix(machine): guard the availability beacon sign against bunker blips #67

Merged
padreug merged 1 commit from beacon-sign-guard into dev 2026-06-22 13:56:30 +00:00
Owner

Found during the 2026-06-22 secure-cash-in smoke: two Uncaught (in promise) BunkerTimeoutError: bunker sign_event: no response in 10000ms appeared on the Sintra a few minutes after the (successful) cash-in, during what looks like a transient bunker watchdog blip.

Cause

The availability beacon's createSignedEvent (a bunker round-trip) sat outside its try/catch — only nostrClient.publish(event) was guarded — and publish(snap) is fire-and-forget. So a transient BunkerTimeoutError / BunkerRejectedError during the periodic sign surfaced as an uncaught promise rejection.

Fix

Move the sign inside the try. The beacon re-publishes every interval, so swallow + log is the right behaviour for a transient signer blip. (A persistent revoke still gets caught at the next init → "Pairing Required"; full mid-session re-pair detection remains the separate Phase D follow-up.)

One-file change; typecheck 12/12, machine 29 tests green. Independent of the cash-in PR (#66).

Do NOT use the MCP merge endpoint — merge via the Forgejo UI after review.

🤖 Generated with Claude Code

Found during the 2026-06-22 secure-cash-in smoke: two `Uncaught (in promise) BunkerTimeoutError: bunker sign_event: no response in 10000ms` appeared on the Sintra a few minutes *after* the (successful) cash-in, during what looks like a transient bunker watchdog blip. ### Cause The availability beacon's `createSignedEvent` (a bunker round-trip) sat **outside** its `try/catch` — only `nostrClient.publish(event)` was guarded — and `publish(snap)` is fire-and-forget. So a transient `BunkerTimeoutError` / `BunkerRejectedError` during the periodic sign surfaced as an **uncaught promise rejection**. ### Fix Move the sign inside the `try`. The beacon re-publishes every interval, so swallow + log is the right behaviour for a transient signer blip. (A *persistent* revoke still gets caught at the next init → "Pairing Required"; full mid-session re-pair detection remains the separate Phase D follow-up.) One-file change; typecheck 12/12, machine 29 tests green. Independent of the cash-in PR (#66). Do NOT use the MCP merge endpoint — merge via the Forgejo UI after review. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
The beacon's createSignedEvent (a bunker round-trip) sat OUTSIDE its try/catch,
and publish() is fire-and-forget — so a transient BunkerTimeoutError /
BunkerRejectedError during the periodic sign surfaced as an uncaught promise
rejection (seen on the Sintra after a bunker watchdog blip during the cash-in
smoke). Move the sign inside the try; the beacon re-publishes every interval, so
swallow + log is correct.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
padreug force-pushed beacon-sign-guard from 6d9f5c3d99 to a762a7ea40 2026-06-22 13:56:10 +00:00 Compare
padreug deleted branch beacon-sign-guard 2026-06-22 13:56:31 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/bitspire!67
No description provided.