fix(qortal): bound history recovery and expose partial accounting - #60
Merged
OswaldKardingson merged 2 commits intoSep 23, 2026
Merged
OswaldKardingson merged 2 commits into
OswaldKardingson merged 2 commits into
Conversation
QuickMythril
marked this pull request as draft
September 22, 2026 14:47
QuickMythril
force-pushed
the
fix/qortal-history-recovery-budget
branch
from
September 22, 2026 15:25
7354f9c to
61b2b07
Compare
Share a five-second deadline across optional connection and outgoing recovery so historical metadata cannot monopolize an embedding Core's native lane. Separate outgoing accounting from display amounts, preserve known zero, and filter expired intents using scanned height before applying the history limit. Use guarded raw transaction value balances to establish the fee for confirmed restored accounting without assuming unrecovered outputs are padding. Preserve positive unknown-recipient remainders, reject conflicting stored accounting, and isolate stricter scope checks from the GUI's transfer splitting. Add deadline, accounting, expiry, fee, and encrypted-output regressions. Keep the legacy response strict when the outgoing total cannot be established.
Add qortal_list_transactions_partial through the existing JSON bridge. Retain incomplete rows with null totals, separate estimates, pending state, available recipient metadata, and transaction-scoped diagnostics. Existing list consumers keep their strict schema and must explicitly adopt the new response contract. Document consumer requirements and add serialization, mixed-history, pending, and scope regressions. Exercise cross-pool fee extraction with actual Ironwood builder padding. No generated bindings or storage migration are required.
QuickMythril
force-pushed
the
fix/qortal-history-recovery-budget
branch
from
September 22, 2026 16:41
61b2b07 to
6b19fb1
Compare
QuickMythril
marked this pull request as ready for review
September 22, 2026 22:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(qortal): bound history recovery and expose partial accounting
Qortal JNI history can exceed an embedding Core's native-call timeout while recovering historical recipients. Give connection and all outgoing recovery one shared five-second deadline, one attempt per transaction-hash candidate, and cancellation of unfinished futures. Synchronous database reads and transaction decoding remain outside that deadline.
Separate outgoing accounting from display amounts, whose fee semantics differ between send intents and historical net rows. Confirmed local spent inputs, attributed internal receipts, and an established fee provide an exact fallback; known zero remains distinct from unknown. Filter expired unmined intents using scanned height before applying the limit. Isolate dangling-scope checks from existing GUI transfer splitting.
Sapling and Ironwood builders can pad with outputs that do not recover under the wallet's keys. Do not infer that every missing output is padding, or require dummy outputs to decrypt to complete locally established accounting. For supported fully shielded transactions, derive the fee with the parsed transaction's checked
fee_paidcalculation after verifying its txid. Require no transparent inputs or outputs and no unsupported pool components. That fee completes confirmed, attributed restored-history accounting without a stored send intent, including custom and dust-adjusted fees. Raw fee evidence supersedes a conflicting stored fee and invalidates its old fallback; recompute only with the required local accounting. Retain positive unknown-recipient remainders.Add the explicit typed JSON method
qortal_list_transactions_partialthrough the existing JNIinvokeJsonbridge. It retains eligible rows with null unknown totals, separate default-fee estimates, available recipient metadata, completeness diagnostics, and unconfirmed state. Aggregate amount/fee fields use decimal strings. Pending or scope-uncertain rows without independent total evidence remain visible as incomplete; a recovered subtotal is not presented as an exact total.Compatibility: existing
list/qortal_list_transactionsretain their strict response and can still reject unresolved pending or restored rows. Consumers must explicitly adopt the partial method to gain partial availability; a native update alone does not fix consumers that continue to call strictlist. No command-table alias is required because the JNI JSON entry point already exists. Consumer integration must preserve null/estimated amounts, avoid inferring direction from an unknown amount, and count the fee once per transaction. Core/Home/Wallet consumer changes are outside this native PR. The integrated consumer stack has been deployed for local acceptance using the JNI artifacts built from this PR head.The two commits separate deadline/accounting work from the explicit partial API.
docs/qortal-handoff.mddocuments the behavior and limitations. No storage migration, generated bindings, Flutter source, signing behavior, or platform-specific source is changed. The existing payment-disclosure fixture is extended only under tests.Validation: the full all-features Rust workspace suite passed 892 tests, with zero failures and 45 ignored. Final strict all-targets/all-features Clippy and formatting checks pass. All 20 targeted Qortal adapter tests pass, including real Ironwood builder padding and a shielded cross-pool fee fixture, Sapling dummy versus missing positive outputs, raw/stored fee disagreement, vin-only and vout-only guards, negative fees, txid mismatch, pending rows, scope, deadline/cancellation, expiry, and serialization. Independent final source review reports no remaining production blocker. Automated tests used synthetic fixtures. Flutter/platform checks were performed in CI. At head
6b19fb18, CI completed with 32 successful and 15 skipped jobs, including all five Qortal JNI platform packages. Following deployment of the matching native artifacts with the Core/Home/Wallet consumers, the wallet owner reported that the integrated application works as expected. This is owner-reported local acceptance, not exhaustive platform or funded-send validation.