-
Notifications
You must be signed in to change notification settings - Fork 53
fix: dispatch buyer payouts at most once per settled order #881
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 5 commits
Commits
Show all changes
9 commits
Select commit
Hold shift + click to select a range
811254c
fix: dispatch buyer payouts at most once per settled order
Catrya bf66db9
test: cover the in-flight payout marker and swap guard
Catrya 8a7cccf
fix: guard payout reconciliation with a claim-age grace window
Catrya bad6c9d
fix: scope in-flight payout marker release to the claimed hash
Catrya fe24e04
fix: validate payout hash length and reuse the shared hex decoder
Catrya b7a21e6
fix: gate payout finalization side-effects on claim ownership
Catrya 8a56dfb
fix: reconcile the payout claim inline when send_payment errors
Catrya 6abbfc0
fix: make the payout claim token unique per claim and align reconcile…
Catrya 2e404cc
test: cover reconcile_inflight_payout branches, fixing its failure bo…
Catrya File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| -- Track the payment hash of an in-flight buyer payout so a | ||
| -- `settled-hold-invoice` order is paid at most once. | ||
| -- | ||
| -- While this column is non-NULL a payout for the order is considered in | ||
| -- flight: the failed-payment retry job skips the order and `AddInvoice` | ||
| -- swaps are rejected, so no second payout can be dispatched against the | ||
| -- same settled escrow. A reconciliation job resolves the marker against | ||
| -- LND (Succeeded -> finalize, Failed/Unknown -> clear & re-arm retry, | ||
| -- InFlight -> wait) so a stranded payout neither drains funds nor blocks | ||
| -- the order forever. | ||
| ALTER TABLE orders ADD COLUMN payout_payment_hash char(64); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| -- Timestamp (unix seconds) when a buyer payout was claimed, sealed together | ||
| -- with `payout_payment_hash` in the same CAS. | ||
| -- | ||
| -- Reconciliation ignores a marker younger than a grace window so a just-claimed | ||
| -- payout is never misread as "unknown to LND" during the brief window between | ||
| -- the claim and LND registering the payment. Without it, a reconciliation tick | ||
| -- landing in that window could clear the marker and let a second payout be | ||
| -- dispatched for the same escrow (a scriptable timing race). | ||
| ALTER TABLE orders ADD COLUMN payout_claimed_at integer; |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.