Skip to content

CLI: Improve recovery in transaction submit with durable nonce - #76

Open
mcintyre94 wants to merge 1 commit into
submit-relay-signaturefrom
submit-recovery
Open

mcintyre94 wants to merge 1 commit into
submit-relay-signaturefrom
submit-recovery

Conversation

@mcintyre94

@mcintyre94 mcintyre94 commented Oct 2, 2026 •

Copy link
Copy Markdown
Member
  • We now check signatures before checking the nonce
  • If the nonce value has changed, we check the transaction status before failing. We look up our fee payer and get their signature (which becomes the transaction signature), and look up that transaction with the RPC.
    • If it has succeeded, then this is a re-submit, we return with that signature.
    • If it failed, then the durable nonce will still have advanced. We print the error it failed with and the new durable nonce value, all relay signers will need to re-sign with this value.
    • If it is not found then we report that another transaction (which may have succeeded or failed) has advanced the nonce, and again the new value to sign with
    • If the RPC node has no history (eg the local one), we also report this

Note: a downside of this method to get the signature is that if the fee payer is a hardware wallet then it'll be prompted to sign at this point. This is harmless because the transaction now has an invalid durable nonce value and cannot land. We print a message to stderr only if the fee payer is interactive.

All of these changes are intended to improve UX for migration, which is exposed to the complexity of durable nonces.

@mcintyre94
mcintyre94 added this pull request to stack #72 October 2, 2026 17:06
@mcintyre94 mcintyre94 changed the title submit recovery Improve recovery in transaction submit with durable nonce Oct 2, 2026
@mcintyre94 mcintyre94 changed the title Improve recovery in transaction submit with durable nonce CLI: Improve recovery in transaction submit with durable nonce Oct 6, 2026
@mcintyre94
mcintyre94 marked this pull request as ready for review October 6, 2026 17:20
- We now check signatures before checking the nonce
- If the nonce value has changed, we check the transaction status before
  failing. We look up our fee payer and get their signature (which
  becomes the transaction signature), and look up that transaction with
  the RPC.
  - If it has succeeded, then this is a re-submit, we return with that
    signature.
  - If it failed, then the durable nonce will still have advanced. We
    print the error it failed with and the new durable nonce value, all
    relay signers will need to re-sign with this value.
  - If it is not found then we report that another transaction (which
    may have succeeded or failed) has advanced the nonce, and again the
    new value to sign with
  - If the RPC node has no history (eg the local one), we also report
    this

Note: a downside of this method to get the signature is that if the fee
payer is a hardware wallet then it'll be prompted to sign at this point.
This is harmless because the transaction now has an invalid durable
nonce value and cannot land. We print a message to stderr only if the
fee payer is interactive.

All of these changes are intended to improve UX for migration, which is
exposed to the complexity of durable nonces.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant