Repository navigation
feat: run the shop's marketplace on staging with our own paykit server - #23
Conversation
talosmachina
left a comment
There was a problem hiding this comment.
1 finding (1 P1). Adds the shop-mixed profile: Paykit Server v0.1.0-rc11 built from its tag on Synonym's staging homeserver and Blocktank's staging regtest chain behind a quick tunnel, plus a staging mode for the marketplace driver. Reviewed cdf10fc, full tier.
What I checked, and 6 candidates I ruled out
Read in full: marketplace/driver/driver.mjs (staging branches and every caller of pickSeller, readFixture, chainInfo/rpc), shop-mixed, the shop-mixed services in docker-compose.yml, both new Dockerfiles, docs/shop-mixed.md
Ran: built Dockerfile.staging, ran purchase --buyer <pubky> against a fixture holding only bitkit_seller (as seller-auth leaves it) with a stub answering /health/ready: FAIL: Cannot read properties of undefined (reading 'kind'). With --seller bitkit it gets past that line.
CI: no checks on this branch
Ruled out
- Tag pin check on an annotated tag:
v0.1.0-rc11is annotated (8c16894), but aftergit clone --branchrev-parse HEADis the peeled commit662dca06, which is the pin. - Blocktank mine request shape: same endpoint and
{count}body asbitkit-e2e-teststest/helpers/regtest.ts. - Headless commands reaching bitcoind on staging:
seed,fund,receive,pay,peers,verify,verify-bitkit-sellerexit before dispatch;statusskipsrecordPaymentTxon staging;mineandinfobranch before any RPC. - Driver image without the helper binaries: the only callers (
approveSetupAs,createBuyer, reader helpers) sit behind the refused commands. - Paykit Server starting before its config: the entrypoint waits for both files, and
init-and-staywrites them before idling. allowed_origins = ["*"]/trusted_proxy_hops = 1: deliberate and documented for the tunnel; a test-only stack.- Cold reader: the finding stood.
Merge confidence: 3/5, one P1 on the profile's documented purchase step.
There was a problem hiding this comment.
Verdict: ✅ Approve
Review: diff 9 files.
Configuration this profile supplies to the Bitkit send-fix acceptance pair, synonymdev/bitkit-android#1384 and synonymdev/bitkit-ios#844:
- Paykit Server v0.1.0-rc11 (662dca0, paykit-rs ad3c722 = rc72)
- the staging homeserver
- Blocktank's staging regtest Electrum behind a quick tunnel
Proven in a separately assembled setup using this configuration with the same Paykit pins:
- The Locks merchant acceptance passed on Android and on iOS: original invoice ec0d05 with amount_matched true, SDK request a7e5d0aa proof_submitted, one transaction 283f408b.
- The full Shop order-paid acceptance used it as the Paykit Server: each was a 1,000-sat order with amount_matched true, the original SDK proof submitted, one transaction and the same order paid.
- Android: order 89ca8c49, invoice 26c3a793, transaction ad00c6f4
- iOS: order 0bd26696, invoice cff3c171, transaction 14a1d470
Proven by the profile's own lane proof:
- its startup
- the pinned revisions read from the image labels
- a lane device's /health/ready request
Not proven:
- The lane proof ran no purchase.
Found during those runs:
- A driver trust overwrite, fixed in #24.
Reviewed by claude-opus-5-5 via gh-pr-review-loop skill
Commands: @ovi-reviewer review · test · retest
purchase passed 'headless' when --seller was absent, so pickSeller's staging default never applied and ./shop-mixed purchase failed on the undefined headless seller.
Refs:
Description
Adds the
shop-mixedprofile and./shop-mixedso that a Bitkit staging build can be tested against a Paykit Server version the staging Shop does not run: Paykit Server v0.1.0-rc11 (662dca06, paykit-rsad3c7224= v0.1.0-rc72, the version of the send-fix PRs) on the staging homeserver (homeserver.staging.pubky.app), watching Blocktank's staging regtest Electrum, behind a Cloudflare quick tunnel.Adds a staging mode to the marketplace driver (
MARKETPLACE_BACKEND=staging): staging homeserver and relay, the rc11 config schema ([signed_services], mainnet Pubky resolution, regtest chain), mining through Blocktank's regtest API, and a clear refusal for the headless-wallet commands, since Bitkit wallets are the seller and the buyer on staging.Builds Paykit Server from its release tag with the classic builder and fails the build when the tag or its paykit-rs lock differs from the pins (the published rc11 image was never pushed: its Docker workflow run was cancelled).
Accepts the rc11 setup page markup in the driver's setup parsing.
./shop-mixed purchasedefaults the seller to the Bitkit seller on staging (7d0f9fe). Before it,purchasewithout--seller bitkitfailed on the missing headless seller; the profile's startup proof ran at 9773509 and does not cover this change.Out of Scope
marketplaceprofile: still Paykit Server0ffd4daon the local Pubky testnet; moving it to rc11 needs its config writer on[signed_services].Design
N/A — no UI changes.
Preview
N/A — no user-visible changes.
QA Notes
Manual Tests
./shop-mixed upon a Linux Docker host without BuildKit: image labels readpaykit-server 662dca06 (v0.1.0-rc11), paykit-rs ad3c7224;/health/readyanswersreadyfor postgres, electrum, paykit_delivery and outbox on loopback and through the tunnel URL../shop-mixed setup-url: apubkyauth://signin_grantlink withcid=app.paykit.serverandx-bitkit-claim=paykit-access-v1.watch-only-account-v1, and the public setup page../shop-mixed seller-auth: thelocks.app/pub/app.locks/:rwgrant request onhttprelay.staging.pubky.app.