bitspire/apps/machine/electron
Padreug e8106b665a feat(machine): durable dispense-report outbox to spirekeeper (ADR-005 §2)
Every cash-out now produces one report_dispense — on success as well as
failure — and the machine does not stop sending it until spirekeeper
acknowledges it.

state.db gains a dispense_reports table (migration v13 → v14): the report
is written INSIDE recordTransaction's SQLite transaction, alongside the
transactions row, so a crash between the two cannot lose it. Rows carry
attempts / last_attempt_at / last_error / acked_at. Three IPC calls
(pending / ack / note-attempt) expose it to the renderer.

The store builds the report when a cash-out reaches complete,
dispenseFault or outOfCash: txid, payment hash, dispense_confirmed,
error / error_code / raw_code / error_class, per-denomination requested
vs dispensed vs rejected, the per-bay cassette record verbatim, and
counts_uncertain. The success report is what lets the server capture
(distribute) the settlement; the failure report is what puts a customer
on the owed-cash worklist instead of leaving the only record on the ATM.

Delivery is at-least-once: a flusher drains pending rows after each
persist, on relay (re)connect, and every 60 s, acking only on an OK reply
and backing off 30 s · 2^attempts (capped 1 h) otherwise. While
spirekeeper has not registered the RPC every send fails the same way; the
backoff keeps that quiet and the rows wait — this half ships first.

The lightning service exposes reportDispense; the function pointer is
set at all three lightning-init sites so the flusher works on every path.
2026-10-10 21:37:47 +02:00
..
__tests__ feat(cassettes): consume operator operations instead of counts 2026-09-23 12:55:52 +02:00
boltcard-session.test.ts feat(machine): open a verified Bolt Card session at tap-to-enter 2026-09-20 17:07:16 +02:00
boltcard-session.ts feat(machine): open a verified Bolt Card session at tap-to-enter 2026-09-20 17:07:16 +02:00
fund-atm.ts chore(machine): fund-atm resumes from binding; VITE_SPIRE_SEED docs/env 2026-06-19 00:15:59 +02:00
hal-service.ts feat(machine): value-confirmed dispense, cash-out hold, fault screens, counts-uncertain on zero-with-error (ADR-005 §3–§5) 2026-10-10 21:37:47 +02:00
lnurl-pay.test.ts feat(machine): open a verified Bolt Card session at tap-to-enter 2026-09-20 17:07:16 +02:00
lnurl-pay.ts feat(machine): open a verified Bolt Card session at tap-to-enter 2026-09-20 17:07:16 +02:00
lnurl-withdraw.test.ts feat(machine): open a verified Bolt Card session at tap-to-enter 2026-09-20 17:07:16 +02:00
lnurl-withdraw.ts feat(machine): open a verified Bolt Card session at tap-to-enter 2026-09-20 17:07:16 +02:00
main.ts feat(machine): durable dispense-report outbox to spirekeeper (ADR-005 §2) 2026-10-10 21:37:47 +02:00
nfc-service.test.ts fix(machine): read NTAG424 NDEF via Capability Container (Bolt Card FileID) 2026-08-05 20:02:26 +02:00
nfc-service.ts fix(nfc): bail out when pcscd is absent instead of spinning the main thread 2026-09-29 22:49:45 +02:00
preload.ts feat(machine): durable dispense-report outbox to spirekeeper (ADR-005 §2) 2026-10-10 21:37:47 +02:00
state-store.ts feat(machine): durable dispense-report outbox to spirekeeper (ADR-005 §2) 2026-10-10 21:37:47 +02:00
tsconfig.json feat(machine): add HAL IPC bridge for real hardware in Electron 2026-02-25 17:02:13 -05:00
tsconfig.preload.json feat(docker): add dev.sh with auto-funding and ATM app setup 2026-02-15 14:19:16 -05:00