Repository navigation
Conversation
5e83117 to
95ca72e
Compare
ae3031c to
51df479
Compare
95ca72e to
e3dcdad
Compare
51df479 to
5f46965
Compare
5f46965 to
bb32b44
Compare
e3dcdad to
4ae3b4b
Compare
bb32b44 to
6e610c5
Compare
4ae3b4b to
0a82765
Compare
|
@rain-marvin review |
|
🔎 Reviewing |
There was a problem hiding this comment.
This PR lets mint recovery finish an orchestrator mint that landed on-chain after its automatic retries ran out. Before, the "did it land?" check only looked in receipt inventory, which never holds orchestrator receipts, so such a mint was abandoned as retry exhaustion. Now the exhausted arm also classifies the mint's own stored transaction; a provider error there is "cannot tell", not "not landed", and the ready and waiting arms keep the inventory-only check so an outage still uses the step's longer budget. SPEC.md is updated to match.
Overall read: the change is small, well scoped and well tested, and the error handling fails closed. One minor gap: once the gate sees the transaction as mined, the exhausted arm hands off to the general recovery step, which classifies again and can authorize a resubmission if that second answer differs. The orchestrator is not live and its nonce check blocks a second share mint, so this does not block the merge.
claude-opus-5-5 · high · 17 min
0a82765 to
67ec497
Compare
6e610c5 to
0f6d109
Compare
492daa0 to
cec8506
Compare
0cb312b to
1741db2
Compare
cec8506 to
aaea145
Compare
1741db2 to
37fd021
Compare
aaea145 to
596db03
Compare
37fd021 to
7fdc532
Compare
596db03 to
3025e61
Compare
c5129cb to
ceb828f
Compare
3025e61 to
6bd00f5
Compare
ceb828f to
ff6d720
Compare
0c9b723 to
1487d7b
Compare
ff6d720 to
224bc7d
Compare
|
@CodeRabbit review |
✅ Action performedReview finished.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour. WalkthroughMint recovery now checks for an already-landed mint after automatic retries are exhausted. For orchestrator mints, it can use the stored transaction’s classification and record a confirmed landing without submitting another deposit. Ready, waiting, and post-submit paths continue to use inventory-only checks. The specification and tests cover these recovery paths and unreadable landing checks. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to This change lets mints that land on-chain after retries are exhausted be recovered instead of being reported as failures. No merge-blocking risk remains in the reviewed changes, and the orchestrator is not yet enabled. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
Comment |
agryaznov
left a comment
There was a problem hiding this comment.
just one nit, otherwise LGTM
|
@rain-marvin review |
|
🔎 Reviewing |
There was a problem hiding this comment.
This PR fixes how the mint recovery worker handles an orchestrator mint whose automatic retries have run out. Before, the "did it land?" check looked only at receipt inventory, which never holds orchestrator receipts, so a landed orchestrator mint was always abandoned as retry exhaustion. Now the exhausted arm classifies the mint's own stored transaction and, when it is mined, records the landing through a record-only path (record_exhausted_orchestrator_landing) that never sends RetryMint. The ready and waiting arms keep the inventory-only check, and an unanswerable classification ends as "could not tell" instead of "not landed".
Overall read: the change is correct and safe. The earlier concern that a second, disagreeing classification could resubmit past the retry cap is fixed: the exhausted orchestrator path no longer goes through drive_one_step, and the tests cover it. Nothing here can double-mint or record a false success, and the orchestrator mode is not live yet. Two minor gaps remain, both in the same gate: it reduces the classification to a bool and keeps no memory between polls, so a mint that is still pending at exhaustion, or that was seen mined once but failed to record, can still be abandoned and is only picked up again after a restart.
claude-opus-5-5 · high · 13 min
Merge activity
|
1487d7b to
f338c17
Compare
224bc7d to
1d66499
Compare
…atic retries run out
1d66499 to
bc28aa7
Compare
f338c17 to
eb53282
Compare

Orchestrator mints that land on-chain after automatic retries exhaust are now recovered and driven to completion instead of being abandoned. The existing "did it land?" gate only checked receipt inventory, which never holds orchestrator receipts (the orchestrator does), so a landed exhausted orchestrator mint was incorrectly reported as retry-exhaustion failure. The exhausted arm now classifies the mint's own stored transaction as a fallback.
Closes RAI-2814
Contributes to RAI-2601
Contributes to RAI-1215
Live effect: none (orchestrator not yet enabled) · Risk: low (feature not live; guards against false abandonment) · Ships: on merge
Decisions
InventoryOrOwnTransaction); ready/waiting arms do not (Inventory). A provider outage in ready/waiting should count against the step's long no-progress budget, not trigger early abandonment via the gate's few-backoff limit.FailedToLoadReceipt), not "not landed." Reading unanswerable as "not landed" would abandon a mint whose deposit succeeded.Risks
Proof
exhausted_orchestrator_mint_that_landed_is_recovered: landed exhausted mint is recorded and sent to callback, not abandoned.exhausted_orchestrator_mint_still_pending_is_abandoned: pending exhausted mint is abandoned as before.exhausted_orchestrator_mint_unclassifiable_is_not_reported_exhausted: unclassifiable ends as "cannot tell," not "retry exhaustion."Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.