Skip to content

feat: working SPV mode, with identity creation support - #525

Merged
PastaPastaPasta merged 14 commits into
v1.0-devfrom
feat/working-spv
Feb 10, 2026
Merged

feat: working SPV mode, with identity creation support#525
PastaPastaPasta merged 14 commits into
v1.0-devfrom
feat/working-spv

Conversation

@PastaPastaPasta

@PastaPastaPasta PastaPastaPasta commented Feb 4, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • New Features

    • Added SPV finality event handling for asset lock proofs (instant and chain locks)
    • Integrated DAPI transaction queries for status verification
    • Display connected peer count in SPV sync status
    • Enhanced UI labels for keys, identities, and contracts
  • Bug Fixes

    • Fixed transaction broadcast synchronization
    • Improved balance synchronization after asset locks
    • Enhanced address balance refresh in receive dialog
  • Improvements

    • Optimized asset lock timeout based on backend mode (SPV vs RPC)
    • Better wallet state and UTXO management
    • Improved BIP32 account naming

Summary by CodeRabbit

  • New Features

    • SPV mode now handles finality events for improved transaction confirmation tracking.
    • Added unified transaction broadcasting across RPC and SPV backends.
    • Introduced UI helpers for clearer identity, contract, and key labeling.
  • Bug Fixes

    • Improved wallet balance accuracy after spending UTXOs.
    • Fixed core address balance refresh in wallet receive dialogs.
  • Refactoring

    • Streamlined transaction handling and asset lock proof waiting logic.
    • Centralized wallet balance recalculation across operations.

@coderabbitai

coderabbitai Bot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • ✅ Review completed - (🔄 Check again to review again)
📝 Walkthrough

Walkthrough

Updated dash-sdk dependency and added SPV-driven asset-lock finality handling. Asset-lock creation methods were converted to async and now broadcast transactions via a unified broadcast path. Identity registration/top-up and wallet balance/UTXO reconciliation were made backend-mode (RPC vs SPV) aware.

Changes

Cohort / File(s) Summary
Dependency Update
Cargo.toml
Bumped dash-sdk rev and expanded features (added core_quorum-validation, core_verification, core_rpc_client, core_spv).
Asset Lock Creation (Async)
src/backend_task/core/create_asset_lock.rs
Converted registration/top-up asset-lock creators to async fn returning Result<BackendTaskSuccessResult, String>; now use broadcast_raw_transaction and trigger wallet balance recalculation after broadcast.
Core Task Async Handling
src/backend_task/core/mod.rs
run_core_task now awaits asset-lock creation futures. SPV height for unsigned transaction building now uses spv_manager.status().sync_progress.header_height fallback.
Incoming Payments Comment
src/backend_task/dashpay/incoming_payments.rs
Updated comment to reference WalletEvent::TransactionReceived (no behavior change).
Identity Registration (Mode-Aware)
src/backend_task/identity/register_identity.rs
Branch flows by CoreBackendMode (Rpc vs Spv); replaced direct RPC sends with broadcast_raw_transaction, centralized proof waiting via wait_for_asset_lock_proof, and added mode-specific error/fallback handling and balance recalculation calls.
Top-Up Identity (Mode-Aware)
src/backend_task/identity/top_up_identity.rs
Similar mode-aware adjustments: use broadcast_raw_transaction, wait_for_asset_lock_proof, get_transaction_info, mode-specific retries/propagation, and wallet balance recalculation helpers.
Context & SPV Finality
src/context.rs
Added broadcast_raw_transaction, wait_for_asset_lock_proof, get_transaction_info and DapiTransactionInfo. Added SPV finality wiring (spv_setup_finality_listener, handle_spv_finality_event), SPV reconcile enhancements, and exported DerivationPathHelpers.
Wallet Balance Recalculation APIs
src/model/wallet/mod.rs
Added DerivationPathHelpers::is_bip32() and wallet methods recalculate_affected_address_balances and recalculate_address_balance to recompute/persist balances from UTXO state.
QualifiedIdentity / Decode Generics
src/model/qualified_identity/...
Made Decode/BorrowDecode impls generic over context type C for WalletDerivationPath and QualifiedIdentity; QualifiedIdentity decode now initializes several fields from DB defaults.
SPV Manager & Events
src/spv/manager.rs, src/spv/mod.rs
Introduced AssetLockFinalityEvent (InstantLock/ChainLock), register_finality_channel, expected_wallet_count startup coordination, connected_peers in status, and refactored event handlers; module visibility set to pub(crate) and crate-private re-export added.
Backend Wallet Flows
src/backend_task/wallet/*.rs
Replaced get_transaction_info_via_dapi calls with get_transaction_info; top-up/funding flows now use broadcast path and wallet balance recalculation helpers.
UI Helpers & Wallet Screens
src/ui/helpers.rs, src/ui/wallets/*
Added label helpers, token authorization helpers, compute_allowed_security_levels, and UI balance cache-refresh that reads SPV-derived address balances for display; minor label/description updates.

Sequence Diagram(s)

sequenceDiagram
    participant App as AppContext / Wallet
    participant SPV as SPV Manager
    participant Core as Core/RPC (DAPI)
    participant DB as Database
    participant UI as UI

    App->>SPV: broadcast_raw_transaction(tx)
    alt SPV backend active
        SPV->>SPV: accept & monitor tx (InstantLock/ChainLock)
    else RPC backend active
        SPV->>Core: send raw tx via RPC
        Core-->>SPV: tx accepted/confirmed
    end

    SPV->>DB: persist asset-lock transaction
    SPV->>DB: update UTXOs and address balances
    SPV-->>App: AssetLockFinalityEvent (InstantLock/ChainLock)
    App->>DB: recalculate_affected_address_balances(used_utxos)
    App->>UI: notify balance update
    UI->>DB: read updated balances
    DB-->>UI: return balances
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Poem

🐰 I hopped a patch across the chain,

Async hops make balance sane,
Instant locks and chain‑lock song,
RPC or SPV — both belong,
Wallets hum, UTXOs align.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main feature: SPV mode with identity creation support, matching the extensive SPV and identity-related changes throughout the changeset.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/working-spv

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/backend_task/identity/register_identity.rs (1)

165-194: ⚠️ Potential issue | 🟠 Major

The TODO accurately describes a real data integrity risk.

The UTXO removal timing issue (lines 165-169) is correctly flagged. If the asset lock proof times out or identity creation fails after line 180, the UTXOs will be permanently "lost" from wallet tracking even though they weren't actually spent. This could cause user confusion and balance discrepancies.

The current code stores the asset lock transaction in the DB (lines 155-163) which provides some recovery path, but the UTXO restoration logic would need to be implemented.

Would you like me to help design a recovery mechanism or open an issue to track this for Phase 2.2 as mentioned in the comment?

🤖 Fix all issues with AI agents
In `@src/backend_task/core/create_asset_lock.rs`:
- Around line 60-71: The calls that currently drop the Result from
wallet_guard.update_address_balance(&address, new_balance, self) must not be
ignored: check the Result and either log the error with context (address,
new_balance) using the project's logger/tracing macro or propagate the error up
by returning Err from the surrounding function; apply the same change to the
other occurrence around the 133-144 block. Locate the calls to
update_address_balance and replace the unused let _ = ... with a match or ?
handling that logs error details (including address and new_balance) or returns
the error so DB/state failures are visible.

In `@src/context.rs`:
- Around line 1575-1589: The broadcast_raw_transaction function currently calls
self.core_client.read().expect(...), which can panic on a poisoned lock; replace
this with proper error handling: attempt to acquire the RwLock via
self.core_client.read().map_err(|e| format!("core client lock poisoned: {}",
e))? (or match the Result and return Err(String) on poison) and then call
send_raw_transaction on the acquired guard, propagating send_raw_transaction
errors via map_err(|e| e.to_string()). Update the CoreBackendMode::Rpc arm to
return Err(String) instead of panicking while keeping the Spv branch unchanged;
references: broadcast_raw_transaction, core_client, core_backend_mode,
CoreBackendMode::Rpc, send_raw_transaction.

In `@src/spv/manager.rs`:
- Around line 1105-1121: The finality event forwarding currently uses
ftx.try_send(...) which can silently drop SyncEvent::InstantLockReceived and
SyncEvent::ChainLockReceived when the finality_tx buffer is full; update the
code in the block referencing finality_tx,
SyncEvent::InstantLockReceived/ChainLockReceived and AssetLockFinalityEvent to
use ftx.send(...).await (or otherwise await a send on the same channel) and
handle Err by logging the failure (include context like event type and
identifiers such as instant_lock.txid or chain_lock.block_height);
alternatively, if awaiting is unacceptable for backpressure reasons, increase
the finality_tx buffer capacity and still log try_send failures so these
critical events are never silently dropped.
🧹 Nitpick comments (6)
src/model/wallet/mod.rs (1)

143-147: Clarify BIP32 path shape and add a small test matrix.

is_bip32 currently matches any 2–3 component path starting with m/0', which can misclassify other 0'‑prefixed paths and would ignore non‑zero accounts if you ever expand BIP32 account usage. If the wallet only uses m/0'/index (or m/0'/change/index), tighten the match and add inline tests to lock in the intended structure.

🔧 Suggested tightening (aligns with current bootstrap_bip32_addresses shape)
-        let components = self.as_ref();
-        matches!(components.len(), 2..=3)
-            && components[0] == ChildNumber::Hardened { index: 0 }
+        match self.as_ref() {
+            [ChildNumber::Hardened { index: 0 }, ChildNumber::Normal { .. }] => true,
+            [ChildNumber::Hardened { index: 0 }, ChildNumber::Normal { .. }, ChildNumber::Normal { .. }] => true,
+            _ => false,
+        }

Optional inline tests:

#[cfg(test)]
mod tests {
    use super::*;

    #[test]
    fn is_bip32_matches_expected_paths() {
        let p1 = DerivationPath::from(vec![
            ChildNumber::Hardened { index: 0 },
            ChildNumber::Normal { index: 0 },
        ]);
        assert!(p1.is_bip32());

        let p2 = DerivationPath::from(vec![
            ChildNumber::Hardened { index: 0 },
            ChildNumber::Normal { index: 0 },
            ChildNumber::Normal { index: 1 },
        ]);
        assert!(p2.is_bip32());

        let p3 = DerivationPath::from(vec![
            ChildNumber::Hardened { index: 1 },
            ChildNumber::Normal { index: 0 },
        ]);
        assert!(!p3.is_bip32());
    }
}

As per coding guidelines: “Write unit tests inline in source files using #[test] attribute”.

src/model/qualified_identity/mod.rs (1)

273-291: Add inline tests for the new decode defaults

Please add #[test] coverage for decode defaults (e.g., wallet_index, top_ups, status, network) to lock in the new behavior.

As per coding guidelines: Write unit tests inline in source files using #[test] attribute.

src/ui/helpers.rs (1)

14-205: Add inline tests for the new helper logic.

compute_allowed_security_levels and check_token_authorization are core policy helpers; inline unit tests will lock in behavior across refactors. As per coding guidelines: Write unit tests inline in source files using #[test] attribute.

src/backend_task/identity/top_up_identity.rs (1)

210-242: Consider extracting duplicated timeout/wait logic into a helper function.

The asset lock proof waiting logic with timeout is duplicated between FundWithWallet (lines 210-242) and FundWithUtxo (lines 322-354). This includes identical timeout configuration, polling loop, and error handling.

♻️ Suggested helper function
async fn wait_for_asset_lock_proof(
    &self,
    tx_id: Txid,
    timeout_duration: Duration,
) -> Result<AssetLockProof, String> {
    match tokio::time::timeout(timeout_duration, async {
        loop {
            {
                let proofs = self.transactions_waiting_for_finality.lock().unwrap();
                if let Some(Some(proof)) = proofs.get(&tx_id) {
                    return proof.clone();
                }
            }
            tokio::time::sleep(Duration::from_millis(200)).await;
        }
    })
    .await
    {
        Ok(proof) => Ok(proof),
        Err(_) => {
            let mut proofs = self.transactions_waiting_for_finality.lock().unwrap();
            proofs.remove(&tx_id);
            Err(format!(
                "Timeout waiting for asset lock proof after {} seconds. \
                 The transaction may not have been confirmed by the network.",
                timeout_duration.as_secs()
            ))
        }
    }
}

Also applies to: 322-354

src/backend_task/identity/register_identity.rs (1)

196-225: Duplicated timeout/wait logic - same refactor applies here.

This is the same code duplication pattern as in top_up_identity.rs. The timeout logic for waiting on asset lock proofs could be extracted into a shared helper method on AppContext.

Also applies to: 336-365

src/context.rs (1)

817-836: Consider adding error logging when chain lock finality processing fails.

In the ChainLock branch (lines 817-836), errors from received_asset_lock_finality are silently ignored with let _ = ... (line 823). While individual failures shouldn't halt processing of other transactions, logging would help diagnose issues.

💡 Suggested improvement
                             if let Ok(Some((tx, ..))) =
                                 self.db.get_asset_lock_transaction(txid.as_byte_array())
                             {
-                                let _ = self.received_asset_lock_finality(
+                                if let Err(e) = self.received_asset_lock_finality(
                                     &tx,
                                     None,
                                     Some(tx_info.height),
-                                );
+                                ) {
+                                    tracing::debug!(
+                                        %txid,
+                                        error = %e,
+                                        "Failed to process chain lock finality for asset lock"
+                                    );
+                                }
                             }

Comment thread src/backend_task/core/create_asset_lock.rs Outdated
Comment thread src/context.rs Outdated
Comment thread src/spv/manager.rs
@thephez

thephez commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@PastaPastaPasta this PR summary isn't accurate, is it?

@PastaPastaPasta

Copy link
Copy Markdown
Member Author

Seems like it :) maybe it thought "master" was the base for the purpose of seeing what was included not v1.0-dev

@thephez

thephez commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

I've had it do that. Can you fix please?

@thephez

thephez commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@PastaPastaPasta PastaPastaPasta changed the title feat: working SPV mode with full wallet and DashPay support feat: working SPV mode, with identity creation support Feb 4, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Fix all issues with AI agents
In `@src/backend_task/identity/top_up_identity.rs`:
- Around line 208-237: The success branch currently leaves entries in
transactions_waiting_for_finality after returning the cloned asset_lock_proof,
causing an unbounded map growth; modify the code handling the
tokio::time::timeout loops (the block that awaits the asset_lock_proof using
tx_id and transactions_waiting_for_finality) so that once you obtain Ok(proof)
you acquire the same mutex, remove the entry for tx_id from
transactions_waiting_for_finality, then return the cloned proof; apply the same
removal change to the second identical loop (around the asset lock proof
consumption at the later occurrence) to ensure entries are cleaned up on success
as well as on timeout.
- Around line 118-138: The code panics on a poisoned RwLock read via
self.core_client.read().expect(...); replace the expect with a non-panicking
propagation: attempt to read the lock (self.core_client.read()) and map the
PoisonError into the function's error return (using map_err or ? after mapping)
so the error is returned rather than aborting; apply this change in the match
arm handling CoreBackendMode::Rpc where reload_utxos and
top_up_asset_lock_transaction are called (referenced symbols: self.core_client,
core_backend_mode / CoreBackendMode::Rpc, wallet.reload_utxos,
wallet.top_up_asset_lock_transaction) so that a poisoned lock yields a
propagated error instead of panic.

In `@src/spv/manager.rs`:
- Around line 818-821: The SPV client can miss historical transactions when all
wallets are locked because expected_wallet_count only counts open wallets;
update logic in the flow that computes expected_wallet_count (used before
calling build_client) to include wallets that exist but are locked so
start_height is not set to u32::MAX, or alternatively add logic in the wallet
unlock handler (where load_wallet_from_seed is called and reconciliation is
triggered) to call the DashSpvClient rescan/restart routine (or invoke
build_client again/trigger a filter rescan) when the first wallet transitions
from locked -> unlocked; modify the code around expected_wallet_count,
build_client, and the wallet event handler to implement one of these fixes and
ensure start_height and DashSpvClient state are updated to scan historical
filters for newly unlocked wallets.

Comment thread src/backend_task/identity/top_up_identity.rs
Comment thread src/backend_task/identity/top_up_identity.rs Outdated
Comment thread src/spv/manager.rs

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@src/backend_task/identity/register_identity.rs`:
- Around line 110-139: Replace the panic-causing .expect("Core client lock was
poisoned") in register_identity.rs with graceful error propagation like in
top_up_identity.rs: call self.core_client.read().map_err(|e| format!("core
client lock poisoned: {:?}", e))? and pass the resulting guard into
wallet.reload_utxos so the function returns an Err instead of panicking; update
the two places using self.core_client.read() in the Err(e) match branch (the
call in reload_utxos and any subsequent uses) to use the mapped error + ?
operator.

Comment thread src/backend_task/identity/register_identity.rs
Comment thread src/backend_task/core/mod.rs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR advances SPV mode to support identity registration/top-ups by wiring SPV finality events (instant/chain locks) into the app flow, improving SPV wallet reconciliation, and polishing related UI labeling.

Changes:

  • Add SPV finality event forwarding and DAPI-based chain-lock verification to unblock asset-lock proof creation for identity flows.
  • Refactor SPV runtime event subscriptions (sync/wallet/network), expose peer count, and adjust client startup behavior.
  • Improve UI labeling helpers (keys/identities/contracts) and tweak legacy BIP32 account naming/description.

Reviewed changes

Copilot reviewed 15 out of 16 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
src/ui/wallets/wallets_screen/mod.rs Refresh per-address receive balances from cached wallet state so SPV updates reflect in UI.
src/ui/wallets/account_summary.rs Improve legacy BIP32 account labeling and description text.
src/ui/helpers.rs Centralize UI label formatting and shared security-level / token-authorization logic.
src/spv/mod.rs Expose SPV manager module and re-export finality event type within the crate.
src/spv/manager.rs Rework SPV runtime subscriptions (sync/wallet/network/progress), add finality forwarding + connected peer count, change start behavior.
src/model/wallet/mod.rs Add DerivationPathHelpers::is_bip32 helper.
src/model/qualified_identity/mod.rs Update bincode Decode generic context signature.
src/model/qualified_identity/encrypted_key_storage.rs Update bincode Decode / BorrowDecode generic context signatures.
src/context.rs Add SPV finality listener handling, improve SPV reconcile (UTXO/balance/tx history), and add backend-agnostic tx broadcast helper.
src/backend_task/identity/top_up_identity.rs Use backend-agnostic tx broadcast + backend-specific proof timeout.
src/backend_task/identity/register_identity.rs Use backend-agnostic tx broadcast + backend-specific proof timeout and SPV-mode behavior.
src/backend_task/dashpay/incoming_payments.rs Update comment to reflect new wallet event source naming.
src/backend_task/core/mod.rs Await asset-lock creation tasks and adjust SPV tx building height source.
src/backend_task/core/create_asset_lock.rs Make asset-lock creation async, use unified broadcast, and update affected address balances after UTXO drops.
Cargo.toml Bump dash-sdk git revision.
Cargo.lock Update dependency lock entries for new dash-sdk / dashcore versions and related crates.
Comments suppressed due to low confidence (1)

src/context.rs:1038

  • During SPV reconcile, per-address balances are only updated for addresses present in per_address_sum (i.e., those with at least one UTXO). Addresses that previously had UTXOs but now have none will keep a stale non-zero balance in wallet.address_balances (and the Receive dialog reads from this cache). After building per_address_sum, consider iterating over the wallet’s known/watched addresses (or existing address_balances keys) and explicitly setting missing addresses to 0 (and optionally clearing entries no longer applicable).
            // Write per-address balances and UTXOs into wallet model
            if let Some(wref) = wallets_guard.get(seed_hash)
                && let Ok(mut w) = wref.write()
            {
                // Update in-memory UTXOs map
                w.utxos = new_utxos;

                for (addr, sum) in per_address_sum.into_iter() {
                    // Update wallet and DB through model helper
                    let _ = w.update_address_balance(&addr, sum, self);
                }

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/spv/manager.rs
Comment thread src/spv/manager.rs
Comment thread src/spv/manager.rs
Comment thread src/context.rs Outdated
Comment thread src/backend_task/core/mod.rs Outdated
Comment thread src/backend_task/identity/register_identity.rs Outdated
Comment thread src/backend_task/identity/register_identity.rs Outdated
Comment thread src/spv/manager.rs
Comment thread src/backend_task/core/create_asset_lock.rs Outdated
Comment thread src/spv/manager.rs
@@ -390,7 +415,7 @@ impl SpvManager {

rt.block_on(async move {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Creating a new thread here and starting second runtime doesn't look correct (but maybe a task for separate PR)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot create an issue to review thread model of spv and resolve this comment.

Comment thread src/spv/manager.rs
PastaPastaPasta added a commit that referenced this pull request Feb 9, 2026
- Rename get_transaction_info_via_dapi to get_transaction_info
- Extract wait_for_asset_lock_proof helper on AppContext (4 copies → 1)
- Extract recalculate_affected_address_balances and recalculate_address_balance
  helpers on Wallet (7 copies → helper calls)
- Fix unused height variable suppression in ChainLock handler
- Document single-subscriber semantics on register_finality_channel and
  register_reconcile_channel
- Fix pre-existing collapsible_if clippy warnings in determine_sync_stage

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (3)
src/backend_task/wallet/fund_platform_address_from_wallet_utxos.rs (2)

88-99: ⚠️ Potential issue | 🟡 Minor

Finality map entry leaks on broadcast failure.

If send_raw_transaction at line 98 fails, the entry inserted at line 91 is never removed from transactions_waiting_for_finality. Over repeated failures this map will grow unboundedly.

🛡️ Suggested fix
         // Step 3: Broadcast the transaction
-        self.core_client
+        if let Err(e) = self.core_client
             .read()
             .expect("Core client lock was poisoned")
             .send_raw_transaction(&asset_lock_transaction)
-            .map_err(|e| format!("Failed to broadcast asset lock transaction: {}", e))?;
+        {
+            // Clean up the finality tracking entry on broadcast failure
+            let mut proofs = self.transactions_waiting_for_finality.lock().unwrap();
+            proofs.remove(&tx_id);
+            return Err(format!("Failed to broadcast asset lock transaction: {}", e));
+        }

126-137: ⚠️ Potential issue | 🟠 Major

Unbounded wait loop with no timeout.

The loop at lines 128–137 polls transactions_waiting_for_finality every 200ms with no timeout. If the proof never arrives (e.g., transaction dropped, network issue), this function will hang indefinitely, blocking the backend task executor.

Other paths in this PR use wait_for_asset_lock_proof which presumably includes a timeout. Consider using the same centralized helper here for consistency and safety.

src/context.rs (1)

1035-1045: ⚠️ Potential issue | 🟠 Major

Reset balances for known addresses with zero UTXOs.
Currently only addresses present in per_address_sum are updated, so a spent-out address keeps a stale balance in memory/DB.

✅ Suggested fix
-                for (addr, sum) in per_address_sum.into_iter() {
-                    // Update wallet and DB through model helper
-                    let _ = w.update_address_balance(&addr, sum, self);
-                }
+                for addr in known_addresses.iter() {
+                    let sum = per_address_sum.get(addr).copied().unwrap_or(0);
+                    let _ = w.update_address_balance(addr, sum, self);
+                }
🤖 Fix all issues with AI agents
In `@src/backend_task/identity/register_identity.rs`:
- Around line 181-182: The call to
wallet.recalculate_affected_address_balances(&used_utxos, self) currently
ignores its Result which can hide failures and leave DB/wallet out of sync;
change the call sites (the one around the shown line and the similar call at the
later occurrence) to handle the Result instead of dropping it—either propagate
the error by returning a Result (use ? from the enclosing function) or
explicitly log the error (e.g., tracing::error! or your crate logger) and
return/abort as appropriate; update the enclosing function signature if you
choose propagation so the compiler surfaces the failure from
recalculate_affected_address_balances.

In `@src/model/wallet/mod.rs`:
- Around line 1816-1845: Add inline unit tests in this module using #[test] that
exercise recalculate_address_balance and recalculate_affected_address_balances:
create wallet state with addresses having zero UTXOs and with multiple addresses
sharing used_utxos, call the functions and assert address_balances (and
persisted DB via AppContext mock or in-memory test context) reflect zero for
empty-address and correct sums for multi-UTXO/multi-address cases; name tests
clearly (e.g., test_recalculate_address_balance_zero_utxos,
test_recalculate_affected_address_balances_multi_address) and ensure they seed
self.utxos and used_utxos appropriately and clean up any test context.
🧹 Nitpick comments (3)
src/ui/wallets/wallets_screen/mod.rs (1)

1893-1909: Platform address balances are not refreshed alongside Core addresses.

The new refresh block updates core_addresses balances from the wallet on every render, but platform_addresses in the same dialog are not similarly refreshed. If SPV updates platform balances while the Receive dialog is open, those won't be reflected until the dialog is reopened.

Additionally, parsing each address from its string representation on every frame is a minor overhead. Consider caching the typed Address alongside the string in core_addresses (e.g., Vec<(String, Address, u64)>) to avoid repeated parsing.

src/backend_task/wallet/fund_platform_address_from_wallet_utxos.rs (1)

123-123: Silently discarding the balance recalculation result.

let _ = wallet.recalculate_affected_address_balances(...) swallows any error. If recalculation fails, the UI will show stale balances with no indication of the problem. Consider logging a warning on failure so that issues are at least visible in traces.

🛡️ Suggested fix
-            let _ = wallet.recalculate_affected_address_balances(&used_utxos, self);
+            if let Err(e) = wallet.recalculate_affected_address_balances(&used_utxos, self) {
+                tracing::warn!("Failed to recalculate address balances after UTXO spend: {}", e);
+            }
src/backend_task/identity/top_up_identity.rs (1)

189-189: Silently discarding balance recalculation results (same pattern as other files).

Both recalculate_affected_address_balances (line 189) and recalculate_address_balance (line 263) discard their Result. Consider logging a warning on failure for debuggability, same as suggested for fund_platform_address_from_wallet_utxos.rs.

🛡️ Suggested fix (line 189)
-                        let _ = wallet.recalculate_affected_address_balances(&used_utxos, self);
+                        if let Err(e) = wallet.recalculate_affected_address_balances(&used_utxos, self) {
+                            tracing::warn!("Failed to recalculate address balances: {}", e);
+                        }
🛡️ Suggested fix (line 263)
-                        let _ = wallet.recalculate_address_balance(&input_address, self);
+                        if let Err(e) = wallet.recalculate_address_balance(&input_address, self) {
+                            tracing::warn!("Failed to recalculate address balance: {}", e);
+                        }

Also applies to: 263-263

Comment thread src/backend_task/identity/register_identity.rs Outdated
Comment thread src/model/wallet/mod.rs
PastaPastaPasta added a commit that referenced this pull request Feb 9, 2026
- Rename get_transaction_info_via_dapi to get_transaction_info
- Extract wait_for_asset_lock_proof helper on AppContext (4 copies → 1)
- Extract recalculate_affected_address_balances and recalculate_address_balance
  helpers on Wallet (7 copies → helper calls)
- Fix unused height variable suppression in ChainLock handler
- Document single-subscriber semantics on register_finality_channel and
  register_reconcile_channel
- Fix pre-existing collapsible_if clippy warnings in determine_sync_stage

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
PastaPastaPasta and others added 2 commits February 9, 2026 12:57
Add YAPPR key exchange flow for DashPay, QR scanner improvements,
state transition signing screen, and refactor UI helpers.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Replace orphaned SpvEvent handler with three new broadcast-based
handlers (SyncEvent, WalletEvent, NetworkEvent) that subscribe to
the actual event producers in dash-spv. This fixes wallet
reconciliation never being triggered by SPV events.

- Bump dash-sdk to fb055ec008 (picks up rust-dashcore 4d2a7018
  with WalletEvent support)
- Add spawn_sync_event_handler: triggers reconcile on
  BlockProcessed, ChainLockReceived, InstantLockReceived,
  SyncComplete
- Add spawn_wallet_event_handler: triggers reconcile on all
  wallet events (TransactionReceived, BalanceUpdated)
- Add spawn_network_event_handler: updates connected_peers count
  on PeersUpdated
- Add connected_peers field to SpvManager and SpvStatusSnapshot
- Fix reconcile channel race: register channel before starting
  SPV thread so handlers always capture a valid sender
- Improve reconcile: track in-memory UTXOs, log summaries, guard
  against wiping transaction history

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
PastaPastaPasta and others added 7 commits February 9, 2026 12:58
The receive dialog cached address balances at open time and never
updated them, so SPV balance changes were not reflected until the
dialog was closed and reopened.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Move these features to the feat/yappr-key-exchange branch. This branch
now focuses on SPV broadcast channel migration, dependency bumps, and
reconciliation fixes only.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Migrate transaction info queries, broadcasting, and finality detection
away from direct Core RPC calls so that identity registration and
top-up work in SPV-only mode. Key changes:

- Add `get_transaction_info_via_dapi()` using DAPI GetTransaction
- Add `broadcast_raw_transaction()` that routes via RPC or SPV
- Add SPV finality listener forwarding instant/chain lock events
- Make asset lock creation methods async for SPV broadcasting
- Use longer proof timeouts (5min) in SPV mode vs 2min for RPC
- Update address balances after asset lock UTXO consumption
- Add BIP32 derivation path detection for SPV address mapping
- Bump platform SDK rev to bcb41de347

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Propagate update_address_balance errors via ? in create_asset_lock.rs
- Replace .expect() with .map_err()? for core_client lock in broadcast_raw_transaction
- Log try_send failures for finality events in SPV manager instead of silently dropping

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Remove stale entries from transactions_waiting_for_finality on the
success path of asset lock proof timeout loops, preventing unbounded
map growth. Applied to both top_up_identity.rs and register_identity.rs.

Also replace .expect() on poisoned RwLock read of core_client with
graceful error propagation via map_err.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Rename get_transaction_info_via_dapi to get_transaction_info
- Extract wait_for_asset_lock_proof helper on AppContext (4 copies → 1)
- Extract recalculate_affected_address_balances and recalculate_address_balance
  helpers on Wallet (7 copies → helper calls)
- Fix unused height variable suppression in ChainLock handler
- Document single-subscriber semantics on register_finality_channel and
  register_reconcile_channel
- Fix pre-existing collapsible_if clippy warnings in determine_sync_stage

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@lklimek lklimek left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please review and resolve Copilot/Rabbit comments.

Comment thread src/spv/manager.rs
@@ -390,7 +415,7 @@ impl SpvManager {

rt.block_on(async move {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot create an issue to review thread model of spv and resolve this comment.

Copilot AI commented Feb 10, 2026

Copy link
Copy Markdown
Contributor

@lklimek I've opened a new pull request, #544, to work on those changes. Once the pull request is ready, I'll request review from you.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Fix all issues with AI agents
In `@src/backend_task/identity/top_up_identity.rs`:
- Around line 189-190: The call to
wallet.recalculate_affected_address_balances(&used_utxos, self) currently drops
its Result (let _ = ...); change this so errors are not ignored: either
propagate the error with the ? operator from the enclosing function (if it
returns a Result) or match the Result and log and return/handle the Err (e.g.,
tracing::error! or return Err(...)) to keep wallet/DB state consistent; apply
the same fix to the other identical call site (the second
recalculate_affected_address_balances invocation).

In `@src/backend_task/wallet/fund_platform_address_from_wallet_utxos.rs`:
- Line 127: The call to
wallet.recalculate_affected_address_balances(&used_utxos, self) currently
swallows errors (let _ = ...); change this to handle the Result properly: either
propagate the error by returning it (replace let _ = with
wallet.recalculate_affected_address_balances(&used_utxos, self)? if the
enclosing function returns Result) or explicitly log the error and context
(e.g., capture Err(e) and call error!(...) including used_utxos/self details) so
address-balance recalculation failures are not silently ignored.

In `@src/context.rs`:
- Around line 806-887: The function
spv_setup_finality_listener/handle_spv_finality_event uses
transactions_waiting_for_finality.lock().unwrap() twice (pending check and
pending_txids build) which can panic on poisoning and also silently drops errors
returned by received_asset_lock_finality; replace both unwrap() calls with
proper error handling (e.g., let transactions =
self.transactions_waiting_for_finality.lock().map_err(|_|
"transactions_waiting_for_finality lock poisoned".to_string())? ) to propagate
lock-poisoning as Err from handle_spv_finality_event, and change the calls to
self.received_asset_lock_finality(...) in both the InstantLock and ChainLock
branches to capture the Result and log failures via tracing::debug!("Finality
processing error: {}", e) (or propagate if appropriate) instead of ignoring them
so finality-processing failures are surfaced consistently with the overall error
handling.

In `@src/spv/manager.rs`:
- Around line 1033-1177: Add an inline test module (#[cfg(test)] mod tests) in
the same file and implement focused unit tests for determine_sync_stage and the
progress-mapping behavior used by spawn_progress_watcher: 1) write tests that
construct WatchSyncProgress instances (or minimal mocks/builders) with each
manager in SyncState::Syncing and assert determine_sync_stage returns the
expected SyncStage variant and that fields (e.g., pending, completed/total,
current/target, batch_size, start/end) are computed correctly, verifying the
pipeline priority (blocks > filters > filter_headers > masternodes > headers);
2) test the synced vs connecting edge cases by asserting determine_sync_stage
returns SyncStage::Complete when watch.is_synced() is true and
SyncStage::Connecting otherwise; 3) add an async test (#[tokio::test]) that
drives a tokio::sync::watch channel through spawn_progress_watcher (using the
same WatchSyncProgress values), waits for the task to process a change, and
asserts that sync_progress_state, detailed_progress_state, and status are
updated to Some(...) and the expected SpvStatus (Running when is_synced(),
Syncing otherwise); reference the functions/fields determine_sync_stage,
spawn_progress_watcher, WatchSyncProgress, SyncStage, SyncState, SyncProgress,
DetailedSyncProgress, SpvStatus, sync_progress_state, detailed_progress_state,
and status to locate code.

In `@src/ui/helpers.rs`:
- Around line 14-19: Add inline unit tests in src/ui/helpers.rs using #[test]
that exercise compute_allowed_security_levels and check_token_authorization;
create at least one test for compute_allowed_security_levels covering typical
inputs and edge cases (e.g., empty input, full access, and restricted inputs)
and assert the returned security level set/ordering, and create tests for
check_token_authorization covering authorized and unauthorized token scenarios
(including boundary cases like missing token or mismatched scopes) by calling
check_token_authorization directly and asserting Ok/Err or boolean results as
appropriate; place these tests in the same file below the helper functions and
use simple constructed inputs/mocks for any required structs so tests run
isolated and fast.
🧹 Nitpick comments (1)
src/model/qualified_identity/encrypted_key_storage.rs (1)

99-132: Consider extracting shared decoding logic.

The Decode and BorrowDecode implementations share identical logic (lines 59–92 vs 99–132). You could extract a generic helper to reduce duplication:

fn decode_wallet_derivation_path<D: Decoder>(decoder: &mut D) -> Result<WalletDerivationPath, DecodeError> {
    // shared logic here
}

This is a minor improvement and can be deferred.

Comment thread src/backend_task/identity/top_up_identity.rs Outdated
Comment thread src/backend_task/wallet/fund_platform_address_from_wallet_utxos.rs Outdated
Comment thread src/context.rs Outdated
Comment thread src/spv/manager.rs
Comment thread src/ui/helpers.rs
PastaPastaPasta and others added 5 commits February 10, 2026 09:25
…lently dropping

Replace `let _ = wallet.recalculate_*()` with `?` in 5 call sites so
database errors during address-balance recalculation are surfaced
instead of silently swallowed. This matches the existing pattern in
create_asset_lock.rs which already propagates these errors.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Resolve modify/delete conflict: upstream split src/context.rs into
src/context/{mod,wallet_lifecycle,transaction_processing,...}.rs while
our branch had SPV-specific additions. Reconciled by porting our changes
into the new submodule structure:

- wallet_lifecycle.rs: enhanced start_spv() with wallet counting,
  spv_setup_finality_listener + handler, removed AccountType::Standard
  filter, fixed balance method calls, enhanced UTXO reconciliation
  with in-memory map and unregistered address handling
- transaction_processing.rs: broadcast_raw_transaction(),
  wait_for_asset_lock_proof(), renamed get_transaction_info_via_dapi
  to get_transaction_info

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Passing height=0 into transaction construction when SPV hasn't synced
yet can lead to incorrect locktime/maturity behavior. Return an error
instead so the caller knows to wait for sync progress.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@PastaPastaPasta
PastaPastaPasta merged commit 0a31553 into v1.0-dev Feb 10, 2026
4 checks passed
@PastaPastaPasta
PastaPastaPasta deleted the feat/working-spv branch February 10, 2026 16:23
lklimek added a commit that referenced this pull request Feb 11, 2026
* feat: wallet unlock on wallet screen (#415)

* refactor: Amount type and AmountInput component (#417)

* feat: amount input, first building version

* test(amount): fixed tests

* chore: I think final

* chore: my_tokens display correct amount

* chore: transfer tokens update

* chore: hide unit on rewards estimate column

* chore: two new helper methods

* chore: I think finals

* cargo fmt

* feat: component trait

* impl Component for AmountInput

* chore: updated component trait

* chore: update for egui enabled state mgmt

* doc: component design pattern doc

* chore: component design pattern continued

* chore: amount improvements

* chore: copilot review

* chore: amount improvements

* backport: amount component from

* chore: fix imports

* chore: refactor

* chore: futher refactor

* chore: further refactor based on feedback

* doc: simplified component design pattern description

* chore: peer review

* doc: update docs

* chore: amount input

* test: run tests using github actions and fix failing tests (#422)

* fix: failing tests

* gha: run tests

* fix: tests fail due to lack of .env file

* fix: incorrect decimals handling on token create, mint and burn screens (#419)

* feat: amount input, first building version

* test(amount): fixed tests

* chore: I think final

* chore: my_tokens display correct amount

* chore: transfer tokens update

* chore: hide unit on rewards estimate column

* chore: two new helper methods

* chore: I think finals

* cargo fmt

* feat: component trait

* impl Component for AmountInput

* chore: updated component trait

* chore: update for egui enabled state mgmt

* doc: component design pattern doc

* chore: component design pattern continued

* chore: amount improvements

* chore: copilot review

* chore: amount improvements

* refactor: mint and burn token screens use AmountInput

* chore: use AmountInput on token creator screen

* fix: burn error handling

* feat: errors displayed in the AmountInput component

* fix: vertical align of amount input

* backport: amount component from

* chore: fix imports

* chore: refactor

* chore: futher refactor

* chore: further refactor based on feedback

* doc: simplified component design pattern description

* chore: peer review

* doc: update docs

* chore: amount input

* chore: fixes after merge

* chore: self-review

* feat: amout set decimal places + rename label => with_label

* refactor: amount input init on token screen

* chore: fix token creator layout

* chore: format base amount with leading zeros in confirmation

* chore: base supply 0 by default

* feat: add network field to identity structures (#423)

* feat: add network field to identity structures

* fix

* feat: add display for private key in both WIF and Hex formats (#424)

* feat: add display for private key in both WIF and Hex formats

* fix: display private keys as normal text and depend on color theme

---------

Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* feat: allow setting zmq uri in .env (#425)

* feat: allow setting ZMQ URI

* chore: rename zmq_endpoint to core_zmq_endpoint

* fix: failing test in token screen needed update

* fix: update CI to use rust version 1.88 to match rust-toolchain

* feat: better display in key selector (#429)

* refactor: unified confirmation dialog (#413)

* refactor: unified alert window

* chore: update CLAUDE to create reusable components whenever appropriate

* feat: correct confirm dialog on set token price screen

* chore: remove callbacks which are overkill

* chore: cargo fmt

* chore: doctest fix

* chore: impl Component for ConfirmationDialog

* chore: use WidgetText

* feat: Add Escape key handling for confirmation dialog

* chore: button inactive when in progress

* chore: fixes after merge

* chore: some theme improvements

* fmt and visual appeal

---------

Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* feat: nicer contract chooser panel (#426)

* feat: nicer contract chooser panel

* fmt

* clippy

* fix: token purchasability was not refreshing unless app restart (#432)

* fix: token action buttons alignment

* feat: nicer expanding tabs in token creator (#431)

* feat: nicer expanding tabs in token creator

* fix

* feat: implement new ConfirmationDialog component throughout app (#430)

* feat: implement new ConfirmationDialog component throughout app

* fix: remove backup files

* fix: confirmation dialog on withdrawal screen always showing "loading"

* feat: Dash Masternode List and Quorum Viewer (#428)

* a lot of work on DML viewer

* more work

* more work

* more work

* more work

* more work

* more work

* more work

* more work

* ui improvements

* ui improvements

* optimizations

* fast start

* more work

* more work

* more work

* fmt

* much more work

* fixes

* updates

* fix

* fmt

* revert

* update for dashcore 40

* params for testnet

* added testnet diff

* fixes

* clippy

* more clippy

* fixes

* clean UI

* use backend tasks

* backend messages

* coderabbit suggestions to add timeouts and prevent infinite loops

* transient and fatal errors

* update dash core configs for testnet

* fmt

* fix timeout

* fix h-3 error

* clear state when switching networks

---------

Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* chore: bump version to 1.0.0-dev (#439)

The 1.0-dev branch builds were still reporting as 0.9.0

* feat: add left panel button labels and create contract subscreen chooser panel (#441)

* feat: add left panel button labels and create contract subscreen chooser panel

* fmt

* feat: clarify identity index description for identity creation

* fix: screen button labels display hard to see in dark mode

* feat: left panel scroll (#443)

* feat: left panel scroll

* clippy

* feat: add existing identity by wallet + identity index (#444)

* feat: add existing identity by wallet + identity index

* fmt

* remove logging

* update derivation index label

* add robustness

* fix: screen button labels display hard to see in dark mode

* feat: left panel scroll (#443)

* feat: left panel scroll

* clippy

* feat: load all identities up to an index

* clippy

* fix

* feat: remove wallet (#445)

* feat: remove wallet

* clippy

* Clarify wallet removal warning message

Updated warning message for wallet removal to clarify that keys will no longer work unless the wallet is re-imported.

* fix: identity creation and top-up via QR code handling (#447)

* fix: identity creation handling

* cleanup

* cleanup

* fix identity topup too

* remove note

* fix: keyword search required new platform version plus error handling and UI updates (#449)

* fix: keyword search not displaying errors

* update platform version and keyword search cleanup

* fix

* fix: handle decimals and fix schedules on price and purchase screens (#412)

* fix: inactive button on set price group action

* chore: apply review feedback

* refactor: use token amount input

* chore: update AmountInput

* chore: tiered pricing

* chore: direct purchase

* chore: remove total agreed price

* chore: max amount input defaults to max_credits

* fmt

* fix

* clippy

---------

Co-authored-by: pauldelucia <pauldelucia2@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>

* fix: showing used asset locks as unused (#448)

* chore: remove unused task sender

* chore: update to Platform V10

* feat: GroveSTARK ZK proofs (#450)

* works

* works

* fix

* ok

* ok

* ok

* ok

* ok

* fix verification message showing in generation screen

* remove advanced settings. set default 16 grinding bits and 128 bit security

* ok

* lock

* ok

* clippy

* fmt

* clippy and fmt

* pin grovestark dep

* fix

* ok

* clippy

* rename file

* remove ProofData

* cleanup

* fix

* rename GroveStark to GroveSTARK

* rename zk_proofs_screen to grovestark_screen

* rename ZKProofs tool subscreen to GroveSTARK

* move grovestark prover to model

* rename ContractsDashpayComingSoon to ContractsDashpay

* rename ContractsDashpay to Dashpay

* rename dashpay stuff

* fixes

* ok

* update grovestark rev

* update

* chore: update grovestark rev

* chore: update platform to v2.1.2

* feat: derive keys from loaded wallets when loading identity by ID (#446)

* feat: derive keys from loaded wallets when loading identity

* clippy

* chore: update platform version

* ok

* cleanup ui

* cleanup ui

* set max index search to 30

* set max const

* k

* fix: wallet screen not updating wallets after network change (#451)

* fix: wallet screen not updating wallets after network change

* ui improvement

* clippy

* fix: some document actions were showing error when it was success (#452)

* fix: some document actions were showing error when it was success

* add space at bottom

* feat: wallet unlock button (#459)

* fix: scrollable unused asset locks on identity creation (#460)

* fix: no error display when trying to import a wallet twice on different networks (#466)

* fix: no error display when trying to import a wallet twice on different networks

* feat: add waiting for valid seed phrase message

* fix

* fix: logging should interpret RUST_LOG env variable (#467)

* feat: signed dmg for mac (#437)

* feat: signed mac binaries and dmg

* fix

* fix

* extra check

* app bundle

* fix

* fix icon

* feat: simplify icon padding to 3% for correct sizing

* ok

* ok

* fmt

* fix: split dmgs into arm64 and x86 instead of universal

* cleanup

* fmt

* fix naming

* ok

* fix

* disk space fix

* fix

* fix

* fix attempt

* fix: enhance disk space cleanup for macOS DMG creation

- Add more aggressive cleanup of Xcode caches and derived data
- Remove additional Cargo build artifacts (.rlib, .d files)
- Clean system-level caches to free maximum space
- Add cleanup step for both ARM64 and x86_64 macOS builds
- Remove temporary icon files after app bundle creation

This should resolve the "No space left on device" error during DMG creation
on GitHub Actions runners.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

* macos-latest

* latest for arm too

* revert

* re-revert

* clear cache

* fix

* cleanup

* try large

* omg

* apply suggestion

* cleanup

* fix

* fix

* fix

---------

Co-authored-by: Claude <noreply@anthropic.com>

* feat: HD wallet system, DashPay integration, SPV support, and more (#464)

* feat: dashpay

* ok

* ok

* remove doc

* ok

* ok

* database

* ok

* fix: use proper BackendTaskSuccessResults rather than Message

* fmt and clippy

* remove dashpay dip file

* logo and cleanup

* fix top panel spacing

* ui stuff

* fmt

* dip 14

* image fetching

* some fixes

* cleaning up

* todos

* feat: SPV phase 1 (#440)

* feat: spv in det

* ui

* progress bars

* working progress updates

* fmt

* fast sync

* add back progress monitoring

* back to git dep

* newer dashcore version

* deduplication

* spv context provider

* fixes

* small fix

* clippy fixes

* fixes

---------

Co-authored-by: Quantum Explorer <quantum@dash.org>

* feat: spv progress bars and sync from genesis when wallets are loaded (#454)

* feat: spv progress bars

* feat: start from 0 if syncing with wallets

* clippy

* fmt

* update

* fixes

* fix: add sdk features

* feat: add accounts and transactions to wallet screen

* clippy

* fmt

* fix: dashpay database table initialization was hanging on new db (#463)

* fix: display stuff

* add accounts and much progress

* feat: transaction history in wallet

* clippy

* ok

* feat: hd wallet

* send tx via wallet and wallet lock/unlock

* update to PeerNetworkManager

* ok

* ok

* ok

* fmt

* clippy

* clippy

* feat: clear SPV data button

* fix: switch from dash core rpc to spv mode

* feat: switch to DashSpvClientInterface

* clean spv button fix

* feat: send from wallet screen

* feat: platform addresses

* feat: platform address transitions

* feat: platform address transitions

* feat: move dashpay screen to top level

* platform addresses sdk

* remove async context provider fn

* lock

* update for new sdk with addresses and handle sdk result data

* chore: update grovestark dependency

* chore: update dash-sdk rev

* fmt

* remove elliptic curves patch

* clippy

* feat: use BackendTaskSuccessResult variants instead of Message(String)

* fmt

* clippy

* update DIP18 implementation, fixes and some features around wallets and PAs

* fix

* wallet unlock on wallet screen

* info popup component

* small fixes

* wallet unlock component

* fix startup panic

* welcome screen and dashpay stuff

* cargo fix

* cargo fmt

* chore: update deps to use most recent dash-sdk

* simplify welcome screen and move spv storage clear to advanced settings

* default connect to peers via SPV DNS seeds

* fix: exit app without waiting

* fix error message and reverse quorum hash on lookup

* fmt

* settings to turn off spv auto sync

* clippy

* work on getting started flow

* AddressProvider stuff

* address sync stuff

* many fixes all in one

* fix

* many fixes

* fixes

* amount input stuff

* alignment in identity create screen for adding keys

* more fixes

* many improvements

* simple token creator, word count selection for wallet seed phrases, more

* fix: platform address info storage

* feat: generate platform addresses and address sync post-checkpoint

* many things

* chore: update to recent changes in platform

* docs: added few lines about .env file

* fix: banned addresses and failure during address sync

* fix: updates for new platform and fee estimation

* fix: only take PA credits after checkpoint

* feat: fee estimation and display

* feat: fee estimation follow-up

* more on fee displays

* fix: proof logs in data contract create

* fix: white on white text for fee estimation display

* fix: always start as closed for advanced settings dropdown in settings screen

* fix: hard to see data contracts in the register contract screen

* fix: document create screen scroll

* fix: fee estimations accuracy

* fmt

* clippy auto fixes

* clippy manual fixes and pin dash-sdk dep

* fix failing tests

* fmt

* fix: update rust toolchain to 1.92

* refactor: hide SPV behind dev mode

* feat: warning about SPV being experimental

* cleanup based on claude review

* fmt

* cleanup based on another claude review

* fix: kittest failing

* fix: remove fee result display in success screens and clean up dashpay avatar display

* dashpay fixes and platform address fixes

* refactor: move some AppContext functions to backend_task module

* clippy

* clippy

* fix: refresh mode alignment in wallet screen and fmt

* fix: failing test due to test_db issue

* fix: dashpay avatar loading slow

* fix: add rocksdb deps to ci workflow

* fix: free up disk space in ci workflow

* fix: display warning when partial wallet refresh success occurs

* fix: propogate error for terminal balance sync

* feat: more aggressive disk cleanup in ci workflow

---------

Co-authored-by: Quantum Explorer <quantum@dash.org>
Co-authored-by: Lukasz Klimek <842586+lklimek@users.noreply.github.com>
Co-authored-by: Ivan Shumkov <ivanshumkov@gmail.com>

* feat: comprehensive test coverage implementation (#481)

* feat: comprehensive test suite

* fmt

* fix: cannot create identity from address due to wrong identity id (#470)

* feat: dashpay

* ok

* ok

* remove doc

* ok

* ok

* database

* ok

* fix: use proper BackendTaskSuccessResults rather than Message

* fmt and clippy

* remove dashpay dip file

* logo and cleanup

* fix top panel spacing

* ui stuff

* fmt

* dip 14

* image fetching

* some fixes

* cleaning up

* todos

* feat: SPV phase 1 (#440)

* feat: spv in det

* ui

* progress bars

* working progress updates

* fmt

* fast sync

* add back progress monitoring

* back to git dep

* newer dashcore version

* deduplication

* spv context provider

* fixes

* small fix

* clippy fixes

* fixes

---------

Co-authored-by: Quantum Explorer <quantum@dash.org>

* feat: spv progress bars and sync from genesis when wallets are loaded (#454)

* feat: spv progress bars

* feat: start from 0 if syncing with wallets

* clippy

* fmt

* update

* fixes

* fix: add sdk features

* feat: add accounts and transactions to wallet screen

* clippy

* fmt

* fix: dashpay database table initialization was hanging on new db (#463)

* fix: display stuff

* add accounts and much progress

* feat: transaction history in wallet

* clippy

* ok

* feat: hd wallet

* send tx via wallet and wallet lock/unlock

* update to PeerNetworkManager

* ok

* ok

* ok

* fmt

* clippy

* clippy

* feat: clear SPV data button

* fix: switch from dash core rpc to spv mode

* feat: switch to DashSpvClientInterface

* clean spv button fix

* feat: send from wallet screen

* feat: platform addresses

* feat: platform address transitions

* feat: platform address transitions

* feat: move dashpay screen to top level

* platform addresses sdk

* remove async context provider fn

* lock

* update for new sdk with addresses and handle sdk result data

* chore: update grovestark dependency

* chore: update dash-sdk rev

* fmt

* remove elliptic curves patch

* clippy

* feat: use BackendTaskSuccessResult variants instead of Message(String)

* fmt

* clippy

* update DIP18 implementation, fixes and some features around wallets and PAs

* fix

* wallet unlock on wallet screen

* info popup component

* small fixes

* wallet unlock component

* fix startup panic

* welcome screen and dashpay stuff

* cargo fix

* cargo fmt

* chore: update deps to use most recent dash-sdk

* simplify welcome screen and move spv storage clear to advanced settings

* default connect to peers via SPV DNS seeds

* fix: exit app without waiting

* fix error message and reverse quorum hash on lookup

* fmt

* settings to turn off spv auto sync

* clippy

* work on getting started flow

* AddressProvider stuff

* address sync stuff

* many fixes all in one

* fix

* many fixes

* fixes

* amount input stuff

* alignment in identity create screen for adding keys

* more fixes

* many improvements

* simple token creator, word count selection for wallet seed phrases, more

* fix: platform address info storage

* feat: generate platform addresses and address sync post-checkpoint

* many things

* fix: cannot create identity from address

* chore: update to recent changes in platform

* docs: added few lines about .env file

* fix: banned addresses and failure during address sync

* fix: updates for new platform and fee estimation

* fix: only take PA credits after checkpoint

* feat: fee estimation and display

* feat: fee estimation follow-up

* chore: fix build

* chore: correct platform revision

* refactor: don't query for nonce when creating identity

* more on fee displays

* fix: proof logs in data contract create

* fix: white on white text for fee estimation display

* fix: always start as closed for advanced settings dropdown in settings screen

* fix: hard to see data contracts in the register contract screen

* fix: document create screen scroll

* fix: fee estimations accuracy

* fmt

* clippy auto fixes

* clippy manual fixes and pin dash-sdk dep

* fix failing tests

* fmt

* fix: update rust toolchain to 1.92

* refactor: hide SPV behind dev mode

* feat: warning about SPV being experimental

* fix: platform nonces not updated in sync

* chore: cargo fmt

* deps: update platform repo

* chore: clippy and rabbit

* chore: rabbit review

* chore: enforce address networ with require_network()

* cleanup based on claude review

* fmt

* cleanup based on another claude review

* fix: kittest failing

* fix: remove fee result display in success screens and clean up dashpay avatar display

* dashpay fixes and platform address fixes

* deps: update platform repo

* chore: fixes after merge

* refactor: move some AppContext functions to backend_task module

* clippy

* clippy

* fix: refresh mode alignment in wallet screen and fmt

* chore: fmt

* fmt

---------

Co-authored-by: pauldelucia <pauldelucia2@gmail.com>
Co-authored-by: Paul DeLucia <69597248+pauldelucia@users.noreply.github.com>
Co-authored-by: Quantum Explorer <quantum@dash.org>
Co-authored-by: Ivan Shumkov <ivanshumkov@gmail.com>

* docs: add CLAUDE.md for Claude Code guidance (#484)

Adds documentation to help Claude Code (claude.ai/code) work effectively
with this codebase, including build commands, testing instructions,
architecture overview, and UI component patterns.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* build: update dash-sdk to use rust-dashcore v0.42-dev (#483)

* build: update dash-sdk to use rust-dashcore v0.41.0

Updates dash-sdk dependency to rev 7b2669c0b250504a4cded9e2b9e78551583e6744
which includes rust-dashcore v0.41.0.

Breaking changes addressed:
- WalletBalance: confirmed field renamed to spendable(), fields now methods
- WalletManager::new() now requires Network argument
- import_wallet_from_extended_priv_key() no longer takes network argument
- current_height() no longer takes network argument
- RequestSettings: removed max_decoding_message_size field
- sync_to_tip() removed - initial sync now handled by monitor_network()

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* style: apply cargo fmt

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* clippy

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* feat: hint text next to withdrawal destination input in dev mode with advanced options and owner key

* feat: implement asset lock creation and detail screens (#418)

* feat: implement asset lock creation and detail screens

* clippy fix

* some fixes

* fix: ui cleanup and backend fixes

* fix: clippy

* feat: tests

* fix: remove identity index selector for top ups

* fmt

* refactor: use `AmountInput` component

* fixes

* fix: clippy

---------

Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* fix: dev mode wouldnt toggle in left panel when unchecked in settings if config load failed (#488)

* fix: force Core RPC mode on app start if not in dev mode (#489)

* fix: display WIF format for manually added private keys (#496)

* fix: display WIF format for manually added private keys

Externally loaded identities with manually added private keys now show
both WIF and hex formats, matching the display for wallet-derived keys.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* clippy

* fmt

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* fix: security level validation for add key screen (#494)

* fix: auto-set security level based on key purpose in add key screen

When selecting a key purpose, automatically set the appropriate security
level and restrict available options: ENCRYPTION/DECRYPTION only allow
MEDIUM, TRANSFER only allows CRITICAL, and AUTHENTICATION allows
CRITICAL/HIGH/MEDIUM.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: disable security level dropdown when only one option is valid

Visually indicate to the user that the security level is fixed by the
protocol for certain key purposes (ENCRYPTION, DECRYPTION, TRANSFER).
Adds a hover tooltip explaining why the dropdown is disabled.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: remove redundant `contract_bounds_enabled` check for `has_multiple_security_levels` bool

* fmt

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: pauldelucia <pauldelucia2@gmail.com>

* fix: identity registration default key was using wrong `ContractBounds` (#487)

* fix: identity registration default key was using wrong ContractBounds

* feat: add tests

* fmt

* doc: update key descriptions

* feat: add coderabbit configuration file

* fix: document actions were auto selecting master keys but shouldnt (#493)

* fix: top up with QR was validating against wallet max balance (#492)

* fix: view platform address popup showing wrong address format (#500)

* fix: view platform address popup showing wrong address format

* fix: use helper

* feat: update sdk v3.0.1 hotfix.1 (#503)

* chore: update dash-sdk to v3.0.1-hotfix.1

Updates dash-sdk to v3.0.1-hotfix.1 to match testnet.

Breaking API changes addressed:
- WalletBalance.unconfirmed and .total are now fields instead of methods
- RequestSettings now requires max_decoding_message_size field

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fmt

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: ensure dev mode is off and spv sync off for new users (#504)

* fix: ensure dev mode is off and spv sync off for new users

* fix tests

* fix

* fix: update platform address prefix from dashevo to evo (#505)

* fix: update platform address prefix from dashevo to evo

Update address detection and UI hints to use the new shorter
platform address prefixes (evo1/tevo1) instead of the old format
(dashevo1/tdashevo1) to match SDK v3.0.1 changes.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: validate platform address network matches app network

Add network validation when parsing Bech32m Platform addresses to ensure
the address network prefix matches the app's configured network, showing
a descriptive error on mismatch.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fmt

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: platform address balance doubling after transfer and refresh (#502)

* fix: platform address balance doubling after transfer and refresh

* fix

* feat: add fee multiplier caching and use it across all UI screens (#506)

* feat: add fee multiplier caching and use it across all UI screens

- Add fee_multiplier_permille support to PlatformFeeEstimator
- Add fee multiplier caching in AppContext with getter/setter
- Add fee_estimator() helper method on AppContext
- Cache the fee multiplier when epoch info is fetched
- Display note when fee multiplier cache is updated
- Update all UI screens to use app_context.fee_estimator()

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fmt

* fix: apply fee multiplier to all estimation functions

Update all estimate_* functions to apply the fee multiplier to the
combined total (storage + processing/registration) rather than to
individual components, ensuring consistent fee calculation across
all state transition types per the Dash Platform spec.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor: reuse fee_estimator instance in token screens

Avoid duplicate construction and keep consistent multiplier snapshot
within the frame by reusing the existing fee_estimator variable.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor: use DEFAULT_FEE_MULTIPLIER_PERMILLE constant in AppContext

Keep the AppContext default in sync with the estimator's canonical value
instead of hardcoding 1000.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: take from multiple platform addresses in simple send flow (#501)

* fix: take from multiple platform addresses in simple send flow

* address selection algorithm

* fix

* fix: fee payer index lookup

* cleanup

* fix: use PlatformFeeEstimator for address transfer fees

- Replace custom fee calculation with PlatformFeeEstimator
- Simplify allocation logic by calculating fee upfront
- Use 20% safety buffer on fee estimates
- Remove complex iterative allocation loop

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fmt

* Add fee deficit check in platform address allocation

The fee payer must have enough remaining balance after their
contribution to cover the transaction fee. This change calculates
the fee deficit (if fee payer's remaining balance < estimated fee)
and adds it to the shortfall, preventing impossible sends from
being attempted.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Use actual input count for fee estimation in error messages

Changed estimate_platform_fee calls to use addresses_available
(the actual number of available inputs) instead of MAX_PLATFORM_INPUTS.
This provides more accurate fee estimates and max sendable amounts
in the error messages when transactions exceed available balance.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Filter destination address from preview allocation

The preview allocation now parses the destination platform address
and passes it to allocate_platform_addresses, ensuring the destination
is never shown as an input source. This matches the behavior of the
actual send logic.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fmt

* Filter destination from max calculation and improve warning message

The max amount calculation now excludes the destination address,
matching the allocation logic. This prevents showing an inflated
max when the destination is one of your own addresses.

Also improved the warning message to distinguish between exceeding
the address limit vs insufficient balance (including fees).

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fmt

* feat: use cached fee multiplier in send_screen

Update estimate_platform_fee and allocate_platform_addresses to accept
a PlatformFeeEstimator parameter, allowing the send screen to use the
cached network fee multiplier from app_context.fee_estimator().

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: address review comments in send_screen

- Add early return for empty sorted_addresses in allocate_platform_addresses
- Use safe string slicing in render_platform_source_breakdown to avoid panic
- Remove duplicate doc comment

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: prevent platform address balance doubling after internal updates (#507)

* fix: prevent platform address balance doubling after internal updates

Adds last_full_sync_balance column to track the balance checkpoint
for terminal sync pre-population, separate from the current balance.

Key changes:
- Add DB migration (v26) for last_full_sync_balance column
- Sync operations update last_full_sync_balance for next sync baseline
- Internal updates (after transfers) preserve last_full_sync_balance
- Terminal sync pre-populates with last_full_sync_balance, applies
  AddToCredits correctly without double-counting

This fixes the scenario where:
1. Transfer completes, balance updated internally
2. App restarts, refresh triggers terminal sync
3. Same AddToCredits was being re-applied because the pre-population
   baseline wasn't distinguishing between sync and internal updates

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: fix docblocks for is_sync_operation and last_full_sync_balance

- Remove duplicate/obsolete is_full_sync wording from set_platform_address_info
- Update last_full_sync_balance field doc to accurately describe when it's
  updated (during syncs) vs preserved (during internal updates)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: preserve last_full_sync_balance when removing duplicate address entries

Search for last_full_sync_balance from any canonical-equivalent entry
BEFORE removing duplicates, so the value isn't lost when the existing
entry has a different Address representation.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: fetch fresh nonces from platform for identity creation (#509)

When creating an identity with Platform Address funding, the cached
nonce could be stale (terminal-only sync only updates balance, not
nonce). This caused "Invalid address nonce" errors.

Now fetches fresh nonces from platform using AddressInfo::fetch_many()
before identity creation.

Note: The SDK's put_with_address_funding requires caller-provided nonces,
unlike transfer_address_funds which handles nonces internally. This
inconsistency should be addressed in the SDK.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: don't auto-generate platform address when opening receive dialog (#508)

Use platform_addresses() which checks watched_addresses for derived
Platform addresses, instead of only checking platform_address_info
which only contains synced addresses with balances.

A new address is now only generated if there are truly no Platform
addresses derived for the wallet, not just because they haven't
been synced yet.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: show N/A for UTXOs and Total Received columns on Platform addresses (#510)

Platform addresses don't have UTXOs (they have credits on Platform layer)
and we don't track historical received amounts for them. Showing 0 was
misleading - N/A is more accurate.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: reserve fees when using max button for platform address identity funding (#511)

* fix: reserve fees when using max button for platform address identity funding

When clicking the max button to fund identity creation or top-up from a
platform address, the full balance was used without reserving room for
transaction fees, causing "Insufficient combined address balances" errors.

Changes:
- Subtract estimated fee from max amount in identity creation screen
- Subtract estimated fee from max amount in identity top-up screen
- Fix fee estimation to use identity_create_asset_lock_cost (200M credits)
  instead of address_funding_asset_lock_cost (50M credits)
- Add storage-based fees to identity creation/top-up fee estimates
- Add new estimate_identity_topup_from_addresses() for platform address top-ups
- Add 20% safety buffer to account for fee variability
- Show hint explaining fee reservation when max is used

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: fix docstrings to correctly state 20% safety buffer

The docstrings incorrectly stated 10% safety buffer while the code
applies 20% via total / 5.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* Release SPV storage lock on shutdown (#517)

* Fix dark mode text colors (#515)

* Fix dark mode text and borders

* style: apply cargo fmt formatting

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: invalid min amount when transferring funds (#523)

* fix: invalid min amount when transferring funds

* chore: rabbit's feedback

* chore: update bincode to 2.0.1, dash-sdk to v3.1-dev, and grovestark (#526)

* chore: update bincode to 2.0.1, dash-sdk to v3.1-dev, and grovestark

- Update bincode from 2.0.0-rc.3 to 2.0.1
- Update dash-sdk to latest v3.1-dev (98a0ebec)
- Update grovestark to a70bdb1a
- Fix Decode/BorrowDecode implementations for bincode 2.0.1 API changes

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* chore: migrate to using dashpay/grovestark

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: pasta <pasta@dashboost.org>

* feat: use DAPI instead of Core RPC for historical asset lock transaction info (#528)

Replace core_client.get_raw_transaction_info() calls with a new
get_transaction_info_via_dapi() function that queries transaction status
via DAPI gRPC. This removes the dependency on a local Core RPC node for
checking whether asset lock transactions have been chainlocked, which is
needed for identity registration, top-up, and platform address funding
from asset locks.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: not enough balance to pay a fee in platform to core transfers (#513)

* fix: fee estimation for AddressCreditWithdrawalTransition

* chore: max button

* refactor: remove redundant code

* chore: better hint in platform-to-core

* Refactor token creator helpers (#518)

* refactor(tokens): simplify token creator helpers

* style: cargo fmt

* Simplify wallets UI helpers and send flow (#519)

* Simplify wallets UI helpers and send flow

* Fix wallets screen helper placement

* Fix refresh_on_arrival borrow

* Stabilize token UI tests config

* Simplify wallet send address type helper

* fix: handle RegisteredTokenContract result to clear token creation spinner (#529)

The backend task returned RegisteredTokenContract on success but the
tokens screen had no handler for it, causing the spinner to spin forever.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* fix: build fails for windows target (#527)

* fix: build fails for windows target

* build: only create a release when tag is set

* chore: remove redundant settings from release.yml

* doc: windows requirements

* fix: windows icon

* build: change grovestark revision

* chore: fmt

* fix: don't open console window on windows

* build: grovestark recent commit

* fix: critical wallet bugs (GH#522, GH#476, GH#478, GH#85) (#534)

* fix: auto-refresh wallet UTXOs on app startup (GH#522)

On startup, bootstrap_loaded_wallets now spawns background tasks to
refresh UTXOs from Core RPC for all HD and single-key wallets. This
ensures balances are current without requiring the user to manually
click Refresh. Only applies in RPC mode; SPV handles UTXOs via
reconciliation.

Task: 1.1a

* fix: respect fee_deduct_from_output flag in platform address funding (GH#476)

When the user selects "deduct from input", use an explicit output amount
for the destination and a separate change address for the fee remainder,
so the destination receives the exact requested amount.

Task: 1.1b

* fix: reserve estimated fees in wallet balance top-up max button (GH#478)

Task: 1.1c

* fix: prevent funding address reuse across identities (GH#85)

Task: 1.1d

* fix: add 5-minute timeout to asset lock proof wait loop (wallet-008)

Task: 1.1e

* fix: use wallet-controlled change address and epoch-aware fee estimator

Use a fresh wallet receive address for platform funding change output
instead of an ephemeral key-derived address, so surplus credits remain
spendable. Also switch to epoch-aware fee estimator for accurate fee
estimation when the network fee multiplier is above 1x.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address critical review issues in wallet funding

- Use try_lock() in tokio::select! timeout arm to avoid blocking the
  async runtime when another thread holds the mutex
- Use change_address() (BIP44 internal path) instead of receive_address()
  for deriving change addresses, ensuring proper path separation
- Replace .unwrap_or(0) with .ok_or() on BTreeMap index lookup to
  surface errors instead of silently targeting the wrong output

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: auto-refresh wallet UTXOs on asset lock proof timeout (RPC mode)

When the 5-minute timeout fires, the asset lock tx has already been
broadcast and UTXOs removed locally. Trigger a background wallet
refresh in RPC mode so spent inputs are reconciled against chain state.
SPV mode handles its own reconciliation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: fix rustfmt formatting in fee estimator chain

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: replace saturating_mul with checked_mul for duffs-to-credits conversion

Overflow now returns an explicit error with diagnostic info instead of
silently clamping to u64::MAX.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(tokens): restore token reorder assignment and distribution field checks (#535)

* Extract dialog rendering into wallets_screen/dialogs.rs module (#539)

Moved 4 dialog rendering functions and 10+ helper methods (~1151 lines)
from wallets_screen/mod.rs into a new dialogs.rs module. Includes
send, receive, fund platform, and private key dialogs plus their
state structs. mod.rs reduced from 3824 to 2673 lines.

Task: 3.2a

* build: update all dependencies (#531)

* fix: build fails for windows target

* build: only create a release when tag is set

* chore: remove redundant settings from release.yml

* doc: windows requirements

* fix: windows icon

* build: change grovestark revision

* chore: fmt

* fix: don't open console window on windows

* build: grovestark recent commit

* build: update dependencies

* chore: clippy

* chore: fmt

* build: update platform to most recent v3.1-dev

* feat: add key exchange protocol and state transition signing

Add YAPPR key exchange flow for DashPay, QR scanner improvements,
state transition signing screen, and refactor UI helpers.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: migrate SPV event handling to broadcast channels

Replace orphaned SpvEvent handler with three new broadcast-based
handlers (SyncEvent, WalletEvent, NetworkEvent) that subscribe to
the actual event producers in dash-spv. This fixes wallet
reconciliation never being triggered by SPV events.

- Bump dash-sdk to fb055ec008 (picks up rust-dashcore 4d2a7018
  with WalletEvent support)
- Add spawn_sync_event_handler: triggers reconcile on
  BlockProcessed, ChainLockReceived, InstantLockReceived,
  SyncComplete
- Add spawn_wallet_event_handler: triggers reconcile on all
  wallet events (TransactionReceived, BalanceUpdated)
- Add spawn_network_event_handler: updates connected_peers count
  on PeersUpdated
- Add connected_peers field to SpvManager and SpvStatusSnapshot
- Fix reconcile channel race: register channel before starting
  SPV thread so handlers always capture a valid sender
- Improve reconcile: track in-memory UTXOs, log summaries, guard
  against wiping transaction history

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: refresh receive dialog balances from wallet on each frame

The receive dialog cached address balances at open time and never
updated them, so SPV balance changes were not reflected until the
dialog was closed and reopened.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor: remove YAPPR key exchange and state transition signing

Move these features to the feat/yappr-key-exchange branch. This branch
now focuses on SPV broadcast channel migration, dependency bumps, and
reconciliation fixes only.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: replace Core RPC with DAPI for asset lock operations in SPV mode

Migrate transaction info queries, broadcasting, and finality detection
away from direct Core RPC calls so that identity registration and
top-up work in SPV-only mode. Key changes:

- Add `get_transaction_info_via_dapi()` using DAPI GetTransaction
- Add `broadcast_raw_transaction()` that routes via RPC or SPV
- Add SPV finality listener forwarding instant/chain lock events
- Make asset lock creation methods async for SPV broadcasting
- Use longer proof timeouts (5min) in SPV mode vs 2min for RPC
- Update address balances after asset lock UTXO consumption
- Add BIP32 derivation path detection for SPV address mapping
- Bump platform SDK rev to bcb41de347

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* style: apply cargo fmt formatting

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: handle ignored Results and avoid panic on poisoned lock

- Propagate update_address_balance errors via ? in create_asset_lock.rs
- Replace .expect() with .map_err()? for core_client lock in broadcast_raw_transaction
- Log try_send failures for finality events in SPV manager instead of silently dropping

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: clean up finality map on success and remove poisoned lock panic

Remove stale entries from transactions_waiting_for_finality on the
success path of asset lock proof timeout loops, preventing unbounded
map growth. Applied to both top_up_identity.rs and register_identity.rs.

Also replace .expect() on poisoned RwLock read of core_client with
graceful error propagation via map_err.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor: address PR #525 review feedback from @lklimek

- Rename get_transaction_info_via_dapi to get_transaction_info
- Extract wait_for_asset_lock_proof helper on AppContext (4 copies → 1)
- Extract recalculate_affected_address_balances and recalculate_address_balance
  helpers on Wallet (7 copies → helper calls)
- Fix unused height variable suppression in ChainLock handler
- Document single-subscriber semantics on register_finality_channel and
  register_reconcile_channel
- Fix pre-existing collapsible_if clippy warnings in determine_sync_stage

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Refactor masternode list diff screen state (#520)

* refactor: split masternode list diff screen state

* fix: avoid borrows in diff screen renders

* Initial plan

* refactor: split context.rs into focused submodules (#543)

Extract the monolithic 1795-line context.rs into a context/ module with
5 focused submodules, each grouping related AppContext methods:

- mod.rs (543 lines): struct definition, constructor, config/SDK methods
- wallet_lifecycle.rs (572 lines): SPV/wallet management and reconciliation
- identity_db.rs (205 lines): identity and DPNS database operations
- contract_token_db.rs (198 lines): contract and token database operations
- settings_db.rs (84 lines): settings cache and persistence
- transaction_processing.rs (231 lines): transaction finality handling

Pure extraction with no logic changes.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* refactor: extract address table, asset locks, and single-key view from wallets_screen (#542)

Continue the wallets_screen/mod.rs refactoring started in #539 (dialogs
extraction). Extract three more focused submodules:

- address_table.rs: SortColumn/SortOrder enums, AddressData struct,
  sorting logic, categorize_path, and the full address table renderer
- asset_locks.rs: asset lock table rendering and fund dialog triggers
- single_key_view.rs: single-key wallet detail view with UTXO display

Reduces mod.rs from 2662 to 1947 lines (-27%).

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(startup): harden cookie parsing, config save, and logger init (#537)

* fix(startup): harden cookie parsing, config save, and logger init

* style(logging): apply rustfmt in logger init

* fix(startup): use sync_all, fix Windows rename, and remove credential leak

- Use with_file_name instead of with_extension for temp file path clarity
- Replace flush() with sync_all() for crash-safe atomic config writes
- Handle Windows rename semantics by removing target before rename
- Remove raw cookie value from error message to prevent credential leakage

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: apply rustfmt

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(config): use NamedTempFile::persist() for atomic config save on Windows

Replace manual remove-then-rename sequence with tempfile::NamedTempFile
which uses MoveFileEx(MOVEFILE_REPLACE_EXISTING) on Windows for atomic
file replacement. This fixes two issues:
- Config loss if process crashes between remove_file and rename
- Open file handle on tmp file preventing rename on Windows

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix: propagate errors from wallet balance recalculation instead of silently dropping

Replace `let _ = wallet.recalculate_*()` with `?` in 5 call sites so
database errors during address-balance recalculation are surfaced
instead of silently swallowed. This matches the existing pattern in
create_asset_lock.rs which already propagates these errors.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore: update dash-sdk to platform rev 060515987a

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore: cargo fmt

* fix: connection status not clear (#532)

* fix: connection status not updated

* chore: rabbit feedback

* chore: typo + network changes

* chore: apply feedback

* chore: rabbit review

* chore: rabbit feedback

* chore: rabbitting

* chore: fmt

---------

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>

* fix: error when SPV sync height unknown instead of defaulting to 0

Passing height=0 into transaction construction when SPV hasn't synced
yet can lead to incorrect locktime/maturity behavior. Return an error
instead so the caller knows to wait for sync progress.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Merge pull request #548 from dashpay/chore/improve-claude-md

chore: improve CLAUDE.md with architecture documentation

* docs: use v1.0-dev for diffs etc agents (#551)

* fix: remove dead code with guaranteed mutex deadlock (#559)

* Initial plan

* Remove unused insert_remote_identity_if_not_exists function with deadlock bug

Co-authored-by: lklimek <842586+lklimek@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: lklimek <842586+lklimek@users.noreply.github.com>

* feat: add "Claim all" checkbox and complete merge with v1.0-dev

- Added claim_all boolean field to ClaimTokens task
- Updated handler to call claim_all_tokens or claim_token based on flag
- Added claim_all checkbox to UI (enabled by default)
- Added claimed_amount field to track tokens claimed
- Updated display_task_result to save and display claimed amount
- Updated success screen to show amount of tokens claimed
- Wire checkbox state to ClaimTokens backend task

Co-authored-by: lklimek <842586+lklimek@users.noreply.github.com>

---------

Co-authored-by: Paul DeLucia <69597248+pauldelucia@users.noreply.github.com>
Co-authored-by: lklimek <842586+lklimek@users.noreply.github.com>
Co-authored-by: QuantumExplorer <quantum@dash.org>
Co-authored-by: pauldelucia <pauldelucia2@gmail.com>
Co-authored-by: thephez <thephez@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ivan Shumkov <ivanshumkov@gmail.com>
Co-authored-by: PastaPastaPasta <6443210+PastaPastaPasta@users.noreply.github.com>
Co-authored-by: pasta <pasta@dashboost.org>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants