fix(sdk): separate discovery deadlines from wallet operation timeouts - #581
Conversation
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Maintainer review of exact head Reviewed the complete authored and generated diff, discovery/operation lifecycle, and the existing React Native/XDM trust boundaries. Successful bounded probes now create operational transports without the probe-only timeout; transport selection priority, the discovered window.CWI binding, explicit caller-configured operation timeouts, origin/source checks, result validation, and pending-call bounds remain intact. The patch requires applications to update their bundled SDK and does not change wire formats or persisted data. Evidence: seven discovery regression/compatibility cases, 7,372 SDK tests in 208 suites, repository build/typecheck/health/lint/format, security audit, packed/browser/mobile consumers and conformance passed. Exact-head CI run 35907496276 is successful; attempt 2 reran a short completed job whose GitHub status was inconsistent, and all checks are now terminal. Patch coverage is 100% (5/5 changed lines), with zero Sonar issues/hotspots, zero open CodeQL alerts on the PR ref, and zero review threads. SDK 2.8.2 is a patch candidate. Merge is separate from protected publication; the resulting main commit must pass CI before release. This records the maintainer self-review allowed by the repository contribution/security policy, not an independent approval. |



Program and scope
Automatic React Native discovery currently succeeds with a 1,000 ms probe deadline and then keeps that deadline for every later operation. A valid authentication response at 1,200 ms is rejected after approximately 1,000 ms; XDM has the same defect with its 200 ms discovery deadline. This can fail ordinary permission prompts and slow wallet calls after successful connection.
The candidate keeps discovery bounded and uses a fresh operational RN/XDM substrate after a successful probe. Explicitly configured response timeouts, origin checks, response validation, pending-call limits and discovery listener cleanup are unchanged. No new API or wire format is introduced.
5ee292030(full SHA in the commit).Impact
@bsv/sdk2.8.2 patch candidate.Verification
pnpm install --frozen-lockfile --ignore-scripts; workspacepnpm build,pnpm typecheck,pnpm health:check,pnpm lint,pnpm format:check,pnpm audit:security: pass; no known audit vulnerabilities.pack:check,test:browser: pass, including exact tarball exports, ESM/CJS/type resolution, Vite/esbuild/UMD consumers and unchanged bundle budgets.pnpm conformance: 77 vector files / 6,699 vectors parse cleanly. TypeScript conformance runner: 6,490 tests passed; 211 unchanged governed skips.pnpm docs:examples: 8 examples against 21 exact package tarballs pass.Security and dependencies
Release and operations
No API, account-data or wire migration is required. Applications using auto-discovery must upgrade their bundled SDK; upgrading only the wallet does not replace the SDK served by a web application. Explicit substrate
responseTimeoutvalues continue to apply.Completion evidence
Final-head validation update
dc8f09e991d633fdfc909353588abc0d960b712fincludes reviewed main/Toolbox #579 and a seventh discovery regression proving the successfulwindow.CWIhost binding remains stable. This covers the branch missed by the first hosted patch-coverage run (80%); the repository patch gate now passes locally at 100% (5/5 changed line/branch points), using its normal LCOV path normalization. Root health, lint, format, workspace build and typecheck all pass after integration. Hosted checks are pending; this PR remains draft.