Skip to content

feat: recover exhausted orchestrator mints via own transaction classification - #436

Closed
rouzwelt wants to merge 1 commit into
2026-09-24-rai-2644from
2026-10-01-rai-2814
Closed

rouzwelt wants to merge 1 commit into
2026-09-24-rai-2644from
2026-10-01-rai-2814

Conversation

@rouzwelt

@rouzwelt rouzwelt commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Orchestrator mints that land on-chain after automatic retries exhaust are now recovered and driven to completion instead of being abandoned. The existing "did it land?" gate only checked receipt inventory, which never holds orchestrator receipts (the orchestrator does), so a landed exhausted orchestrator mint was incorrectly reported as retry-exhaustion failure. The exhausted arm now classifies the mint's own stored transaction as a fallback.

Closes RAI-2814

Contributes to RAI-2601
Contributes to RAI-1215

Live effect: none (orchestrator not yet enabled) · Risk: low (feature not live; guards against false abandonment) · Ships: on merge

Decisions

  • Exhausted arm classifies the orchestrator mint's own transaction (InventoryOrOwnTransaction); ready/waiting arms do not (Inventory). A provider outage in ready/waiting should count against the step's long no-progress budget, not trigger early abandonment via the gate's few-backoff limit.
  • Unanswerable classifications return "cannot tell" (FailedToLoadReceipt), not "not landed." Reading unanswerable as "not landed" would abandon a mint whose deposit succeeded.

Risks

  • Bug in classification could record failed orchestrator mint as successful. Limited by: orchestrator not yet live; three new tests verify exhausted/pending/unclassifiable cases; vault-direct path unchanged.

Proof


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@rouzwelt rouzwelt self-assigned this Oct 1, 2026
@linear-code

linear-code Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

RAI-2814

RAI-1215

RAI-2601

rouzwelt commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator Author

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more


How to use the Graphite Merge Queue

Add the label add-to-gt-merge-queue to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

rouzwelt commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

@rain-marvin review

@rain-marvin

rain-marvin Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔎 Reviewing 6e610c5, started by @rouzwelt. The review will appear here when it's done.

@rain-marvin rain-marvin Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR lets mint recovery finish an orchestrator mint that landed on-chain after its automatic retries ran out. Before, the "did it land?" check only looked in receipt inventory, which never holds orchestrator receipts, so such a mint was abandoned as retry exhaustion. Now the exhausted arm also classifies the mint's own stored transaction; a provider error there is "cannot tell", not "not landed", and the ready and waiting arms keep the inventory-only check so an outage still uses the step's longer budget. SPEC.md is updated to match.

Overall read: the change is small, well scoped and well tested, and the error handling fails closed. One minor gap: once the gate sees the transaction as mined, the exhausted arm hands off to the general recovery step, which classifies again and can authorize a resubmission if that second answer differs. The orchestrator is not live and its nonce check blocks a second share mint, so this does not block the merge.

claude-opus-5-5 · high · 17 min

Comment thread src/mint/recovery.rs
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from 492daa0 to cec8506 Compare October 3, 2026 15:32
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from 0cb312b to 1741db2 Compare October 3, 2026 15:32
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from cec8506 to aaea145 Compare October 3, 2026 15:39
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from 1741db2 to 37fd021 Compare October 3, 2026 15:39
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from aaea145 to 596db03 Compare October 3, 2026 17:05
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from 37fd021 to 7fdc532 Compare October 3, 2026 17:05
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from 596db03 to 3025e61 Compare October 3, 2026 22:17
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch 2 times, most recently from c5129cb to ceb828f Compare October 4, 2026 02:56
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from 3025e61 to 6bd00f5 Compare October 4, 2026 02:56
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from ceb828f to ff6d720 Compare October 4, 2026 04:20
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch 2 times, most recently from 0c9b723 to 1487d7b Compare October 4, 2026 04:33
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from ff6d720 to 224bc7d Compare October 4, 2026 04:33

rouzwelt commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator Author

@CodeRabbit review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Team
  • Run ID: d0c9b3ac-3677-4fd1-acbd-42853955b782
📥 Commits

Reviewing files that changed from the base of the PR and between 224bc7d and 1487d7b.

📒 Files selected for processing (2)
  • SPEC.md
  • src/mint/recovery.rs

Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour.


Walkthrough

Mint recovery now checks for an already-landed mint after automatic retries are exhausted. For orchestrator mints, it can use the stored transaction’s classification and record a confirmed landing without submitting another deposit. Ready, waiting, and post-submit paths continue to use inventory-only checks. The specification and tests cover these recovery paths and unreadable landing checks.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 1487d

This change lets mints that land on-chain after retries are exhausted be recovered instead of being reported as failures. No merge-blocking risk remains in the reviewed changes, and the orchestrator is not yet enabled.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: recovering exhausted orchestrator mints by classifying their own transactions.
Description check ✅ Passed The description explains the recovery change, its behavior, risks, and tests. It is directly related to the changeset.
Docstring Coverage ✅ Passed Docstring coverage is 80.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 1 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@agryaznov agryaznov left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just one nit, otherwise LGTM

Comment thread src/mint/recovery.rs

rouzwelt commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

@rain-marvin review

@rain-marvin

rain-marvin Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🔎 Reviewing 1487d7b, started by @rouzwelt. The review will appear here when it's done.

@rain-marvin rain-marvin Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR fixes how the mint recovery worker handles an orchestrator mint whose automatic retries have run out. Before, the "did it land?" check looked only at receipt inventory, which never holds orchestrator receipts, so a landed orchestrator mint was always abandoned as retry exhaustion. Now the exhausted arm classifies the mint's own stored transaction and, when it is mined, records the landing through a record-only path (record_exhausted_orchestrator_landing) that never sends RetryMint. The ready and waiting arms keep the inventory-only check, and an unanswerable classification ends as "could not tell" instead of "not landed".

Overall read: the change is correct and safe. The earlier concern that a second, disagreeing classification could resubmit past the retry cap is fixed: the exhausted orchestrator path no longer goes through drive_one_step, and the tests cover it. Nothing here can double-mint or record a false success, and the orchestrator mode is not live yet. Two minor gaps remain, both in the same gate: it reduces the classification to a bool and keeps no memory between polls, so a mint that is still pending at exhaustion, or that was seen mined once but failed to record, can still be abandoned and is only picked up again after a restart.

claude-opus-5-5 · high · 13 min

Comment thread src/mint/recovery.rs
Comment thread src/mint/recovery.rs
@graphite-app

graphite-app Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Merge activity

  • Oct 6, 4:11 PM UTC: rouzwelt added this pull request to the Graphite merge queue.
  • Oct 6, 4:12 PM UTC: The Graphite merge queue removed this pull request due to downstack failures on PR #419.
  • Oct 6, 4:12 PM UTC: The Graphite merge queue removed this pull request due to downstack failures on PR #419.
  • Oct 6, 11:43 PM UTC: rouzwelt added this pull request to the Graphite merge queue.
  • Oct 6, 11:44 PM UTC: CI is running for this pull request on a draft pull request (#455) due to your merge queue CI optimization settings.
  • Oct 6, 11:44 PM UTC: Merged by the Graphite merge queue via draft PR: #455.

@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from 1487d7b to f338c17 Compare October 6, 2026 18:14
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from 224bc7d to 1d66499 Compare October 6, 2026 18:14
@rouzwelt
rouzwelt force-pushed the 2026-09-24-rai-2644 branch from 1d66499 to bc28aa7 Compare October 6, 2026 19:49
@rouzwelt
rouzwelt force-pushed the 2026-10-01-rai-2814 branch from f338c17 to eb53282 Compare October 6, 2026 19:49
@graphite-app graphite-app Bot closed this Oct 6, 2026
@github-actions github-actions Bot added the externally-merged Graphite MQ merged this PR; Linear should treat the close as a merge label Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

externally-merged Graphite MQ merged this PR; Linear should treat the close as a merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants