Skip to content

fix(canton): require confirmed funds before settle success - #32

Closed
PhilBot402 wants to merge 1 commit into
philbot-canton-3242-head-eb5cfrom
philbot-canton-settle-confirm-eb5c
Closed

PhilBot402 wants to merge 1 commit into
philbot-canton-3242-head-eb5cfrom
philbot-canton-settle-confirm-eb5c

Conversation

@PhilBot402

Copy link
Copy Markdown
Owner

Description

Canton settle was returning success: true when /execute had committed but the funds-moved read was inconclusive. Success now requires a read that proves funds moved, the same bar as other networks.

A timeout, transport error, 5xx, or unreadable confirmation returns non-terminal settlement_pending with a non-empty transaction (the updateId, or the submission id when the update id is not known yet). @x402/core retries settle once with the same payload. That retry re-reads the same submission and does not relay again. It returns success only if funds moved. A still-unreadable read is terminal unexpected_canton_ledger_error. A read that shows the transfer did not deliver is invalid_exact_canton_execute_failed.

There is no further retry and no replay cache. The in-memory entry exists only so that one retry can re-read; it is dropped on the retry, and a later settle relays again. The ledger still rejects a replay once the input holdings are spent.

Sits on upstream PR 3242 head 48f6414c (Denend:feat/mechanisms-canton).

Tests

  • pnpm exec tsc --noEmit in typescript/packages/mechanisms/canton
  • pnpm exec vitest run (103 tests) and pnpm exec vitest run --config vitest.integration.config.ts (5 tests)
  • New test/unit/settle.test.ts: success only on a proven transfer; pending then one confirm; terminal failure if the re-read is still unreadable; a later settle relays again; unknown execute with a submission id is pending, without an id is terminal

Checklist

  • I have formatted and linted my code
  • All new and existing tests pass
  • My commits are signed (required for merge) -- you may need to rebase if you initially pushed unsigned commits
  • I added a changelog fragment for user-facing changes (docs-only changes can skip)

AI disclosure: automated by @phdargen. Use your own judgement.

Open in Web Open in Cursor 

Success is returned only when the funds-moved read proves delivery.
A timeout or unreadable confirmation returns settlement_pending so
core can retry settle once; that retry re-reads the same submission
and then succeeds or fails terminally.

Co-authored-by: PhilBot <PhilBot402@users.noreply.github.com>
@PhilBot402 PhilBot402 closed this Sep 30, 2026
@cursor
cursor Bot deleted the philbot-canton-settle-confirm-eb5c branch September 30, 2026 11:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant