refactor(messages): delete online messages (cleanup pass 2) - #1050
Conversation
Owner ruling, 2026-09-28. The placeholder sweep left a question open: build the receive side for online messages, or delete them. The answer is delete. Why: - message.send had no caller. The frontend sender was deleted as uncalled in #1003, and no Kotlin or Rust code called the route. - No specification defines messaging. - The route took its sender and relationship tip from its caller and signed them as this device. - Nothing received what it sent. The inbox listed a message envelope under the sender its header named, unverified. What goes: - Wire: OnlineMessageRequest and OnlineMessageResponse are deleted. Envelope field 41 is reserved by number and name. The frontend protos are regenerated. - SDK: the message.send route and its logic, the envelope builder's message arm, and B0xEntryKind::Message with its inbox listing are deleted. - SDK: the spool submission is now transfer-only. - Its submission id is required; the random, non-idempotent fallback that only messages used is gone. - The sender-tip field that only messages read is gone. - A signature-length check stood in for verification the send path already does. It is gone. - So is a decode-and-assert of the request the builder had just encoded. - Core: the online-message signing and nonce helpers, their tests, and three domain tags (online-message, online-message nonce, b0x msgid) are deleted. The tag registry's expected count is now 350. CONFORMANCE_GAPS §6.38 records the deletion.
Local verificationBase: The change was first built on #1048's branch and ran the wider set below there. After #1048 merged, it was moved onto main unchanged: On this base (
On the pre-merge base, same change:
Lint and gates (this base):
Independent review: the Gemini gate is satisfied with the committed tree |
What this does
Deletes online messages. This is cleanup pass 2, on the owner's ruling of 2026-09-28. The placeholder sweep had left a question open: build the receive side, or delete. The answer is delete.
Why they go
message.sendhad no caller. The frontend sender was deleted as uncalled in fix: frontend sweep, continued — history, the pending list and cancel, balances and the send flow as Rust reports them #1003, and no Kotlin or Rust code called the route.inbox.pulllisted a message envelope under the sender its header named, unverified, and no poll consumed one. The only message envelopes a device could receive were ones anyone sealed to it.Deleted
OnlineMessageRequestandOnlineMessageResponse. Envelope field 41 is reserved by number and name, and the frontend protos are regenerated.message.sendroute, its logic, its dispatch arm and its flow-mapping row;B0xEntryKind::Messageand the inbox's message listing.DSM/online-message/v3andDSM/online-message/nonce/v3.What only messages needed, now gone. The spool submission is transfer-only.
DSM/b0x-msgidare deleted.Also: the bridge docs named
wallet.sendas an invoke example. That route was deleted in #1048, and the docs now namewallet.sendSmart. Recorded inCONFORMANCE_GAPS.md§6.38.Deployment
No client schema change. An older build's
message.sendenvelope is not an entry for this build. Like any copy that is not recognized, it stays on the spool and is read again on each poll. This build sends none.Verification
Per-module counts are in the PR comment. CI runs the board.