Skip to content

refactor(messages): delete online messages (cleanup pass 2) - #1050

Merged
cryptskii merged 1 commit into
mainfrom
refactor/delete-online-messages
Sep 28, 2026
Merged

cryptskii merged 1 commit into
mainfrom
refactor/delete-online-messages

Conversation

@cryptskii

Copy link
Copy Markdown
Collaborator

What this does

Deletes online messages. This is cleanup pass 2, on the owner's ruling of 2026-09-28. The placeholder sweep had left a question open: build the receive side, or delete. The answer is delete.

Why they go

Deleted

  • Wire: OnlineMessageRequest and OnlineMessageResponse. Envelope field 41 is reserved by number and name, and the frontend protos are regenerated.
  • SDK:
    • the message.send route, its logic, its dispatch arm and its flow-mapping row;
    • the envelope builder's message arm;
    • B0xEntryKind::Message and the inbox's message listing.
  • Core: the online-message signing and nonce helpers, their tests, and the tags DSM/online-message/v3 and DSM/online-message/nonce/v3.

What only messages needed, now gone. The spool submission is transfer-only.

  • The submission id is required and deterministic. The random fallback (OS entropy, where a retry spooled a new row) and its tag DSM/b0x-msgid are deleted.
  • So is the sender-tip field that only messages read.
  • So are two self-checks:
    • a signature-length check, standing in for SPHINCS+ verification the send path already performs;
    • a decode-and-assert of the request the builder had just encoded.
  • The tag registry's expected count is 350.

Also: the bridge docs named wallet.send as an invoke example. That route was deleted in #1048, and the docs now name wallet.sendSmart. Recorded in CONFORMANCE_GAPS.md §6.38.

Deployment

No client schema change. An older build's message.send envelope is not an entry for this build. Like any copy that is not recognized, it stays on the spool and is read again on each poll. This build sends none.

Verification

Per-module counts are in the PR comment. CI runs the board.

Owner ruling, 2026-09-28. The placeholder sweep left a question open: build
the receive side for online messages, or delete them. The answer is delete.

Why:
- message.send had no caller. The frontend sender was deleted as uncalled in
  #1003, and no Kotlin or Rust code called the route.
- No specification defines messaging.
- The route took its sender and relationship tip from its caller and signed
  them as this device.
- Nothing received what it sent. The inbox listed a message envelope under
  the sender its header named, unverified.

What goes:
- Wire: OnlineMessageRequest and OnlineMessageResponse are deleted. Envelope
  field 41 is reserved by number and name. The frontend protos are
  regenerated.
- SDK: the message.send route and its logic, the envelope builder's message
  arm, and B0xEntryKind::Message with its inbox listing are deleted.
- SDK: the spool submission is now transfer-only.
  - Its submission id is required; the random, non-idempotent fallback that
    only messages used is gone.
  - The sender-tip field that only messages read is gone.
  - A signature-length check stood in for verification the send path
    already does. It is gone.
  - So is a decode-and-assert of the request the builder had just encoded.
- Core: the online-message signing and nonce helpers, their tests, and three
  domain tags (online-message, online-message nonce, b0x msgid) are deleted.
  The tag registry's expected count is now 350.

CONFORMANCE_GAPS §6.38 records the deletion.
@cryptskii

Copy link
Copy Markdown
Collaborator Author

Local verification

Base: origin/main 5ce689646. Toolchain: pinned 1.98.0. These are targeted runs, not the board; CI runs the board.

The change was first built on #1048's branch and ran the wider set below there. After #1048 merged, it was moved onto main unchanged: cherry-pick --no-commit, the baseline regenerated, a fresh Gemini round. The modules it touches were then run again on this base.

On this base (cargo test --locked -p <crate> --release --lib <module> -- --test-threads=1, on the storage node's own code on Postgres):

Module Passed / failed
dsm_sdk handlers::recipient_dispatch 12 / 0
handlers::storage_routes 7 / 0
handlers::app_router_impl 18 / 0
handlers::sender_admission_tests 15 / 0
handlers::node_e2e_tests 8 / 0
sdk::b0x_sdk 31 / 0 (the message-entry test is deleted with its concept)
dsm envelope 19 / 0 (four message-helper tests are deleted)
dsm common::domain_tags 8 / 0 (the registry count is 350)

On the pre-merge base, same change:

Module Passed / failed
wallet_routes 22 / 0
online_finalize 8 / 0
recipient_admission_tests 5 / 0
bilateral_finality_tests 12 / 0
relationship_finalized 2 / 0
token_create_tests 8 / 0
bluetooth::offline_step_tests 25 / 0
core_sdk 6 / 0
inbox_poller 17 / 0
storage::client_db 322 / 0
dsm --test economic_peer_evidence 4 / 0

Lint and gates (this base):

  • make lint exit 0: fmt --check, clippy --all-targets -D warnings, frontend eslint.
  • The real-code guard passes against main; its baseline has 0 lines added and 6 removed.
  • All 12 CI static gates pass:
    • conformance_evidence.py: 779 rows, 2765 tests indexed
    • flow_mapping_assertions.sh, with the message.send row removed
    • production_safety_checks.sh
    • no_clock_and_no_json.sh
    • check-spdx.sh
    • check_forbidden_symbols.sh
    • ci_scan.sh
    • codegen_enforce.sh
    • flow_assertions.sh
    • guard_protos.sh
    • bridge_contracts_gate.sh
    • bridge_rpc_names.py
  • Android: cargo ndk -t arm64-v8a --platform 23 check --package dsm_sdk --features=jni,bluetooth exit 0.
  • Frontend: type-check exit 0. jest E2E.transferProof, E2E.sendOnlineTransfer, wallet.test and encoding_decoding_helpers: 4 suites, 43 / 43.
  • No Kotlin or Java source refers to the deleted types.

Independent review: the Gemini gate is satisfied with the committed tree 843c2f858fab. That was round 1 on this branch; the same change was also satisfied as round 6 on #1048's branch.

@cryptskii
cryptskii merged commit 918814f into main Sep 28, 2026
12 checks passed
@cryptskii
cryptskii deleted the refactor/delete-online-messages branch September 28, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant