forked from bitcoinafterlife/bal-electrum-plugin
feat(will): invalidate signed will on postpone + add Server status column
Postpone safety (Strategy B): - A signed/sent will carries an immutable locktime; postponing the delivery time previously did nothing, so a will-executor could still broadcast the old (earlier-locktime) transaction and execute the inheritance too early. - core/will.py: add WillPostponedException and detect postpone by comparing the requested locktime against w.tx.locktime (the locktime frozen in the signed transaction) instead of the in-memory heir entry, which is updated together with the new value and would always compare equal. - gui/qt/dialogs.py (BalBuildWillDialog.task_phase1, the real path used by Tools -> Prepare): handle WillPostponedException before NotCompleteWill; return (None, tx) to trigger sign + broadcast of the invalidation, then the user presses Prepare again to rebuild/re-sign/re-send (two explicit steps). - gui/qt/window.py: mirror the branch in build_inheritance_transaction with an explanatory message; wording aligned to the 'Prepare' button. - gui/qt/common.py: export WillPostponedException. - A postpone on a will that was never signed/sent just rebuilds (no on-chain fee). Server status column: - gui/qt/lists.py: add a dedicated 'Server' column to PreviewList with an always-readable label and a tooltip (will-executor URL + state). - gui/qt/theme.py: add server_status_text() and server_status_tooltip(), reusing the existing status flags. - gui/qt/common.py: export the new theme helpers. Docs: update README.md, bal/README.md and CHANGELOG_REFACTOR.md. Tests: 182 passed; smoke + external-zip OK; ruff has no new real findings.
This commit is contained in:
committed by
steal
parent
4e027d9e8b
commit
343046ed34
42
README.md
42
README.md
@@ -68,6 +68,48 @@ Copy the `bal/` directory into your Electrum installation's
|
||||
`electrum/plugins/` directory, so that `electrum/plugins/bal/manifest.json`
|
||||
exists, then enable it from **Tools → Plugins**.
|
||||
|
||||
## Inheritance safety: anticipate / postpone
|
||||
|
||||
A will transaction is signed with a **fixed, immutable locktime** and then
|
||||
optionally sent to will-executor servers, which are economically incentivised
|
||||
to broadcast it (they collect fees). Because the locktime is baked into the
|
||||
signed transaction, simply changing the delivery time later is **not enough**:
|
||||
the old, already-signed transaction keeps living on the will-executors.
|
||||
|
||||
The plugin handles the two cases as follows (triggered when you press
|
||||
**Tools → Prepare**):
|
||||
|
||||
* **Anticipate** (new delivery time *earlier* than the signed locktime): the
|
||||
will is treated as expired and you are asked to **invalidate** the old
|
||||
transaction on-chain, then rebuild.
|
||||
* **Postpone** (new delivery time *later* than the signed locktime) on a will
|
||||
that was already **signed and/or pushed**: the previously committed coins
|
||||
must be invalidated on-chain **first**, otherwise a will-executor could
|
||||
broadcast the old (earlier-locktime) transaction and execute the inheritance
|
||||
*too early*. The plugin detects this by comparing the requested locktime with
|
||||
the locktime **frozen inside the signed transaction** (`tx.locktime`), and
|
||||
asks you to sign and broadcast an invalidation transaction. After it is
|
||||
broadcast, press **Prepare** again to rebuild, re-sign and re-send the new
|
||||
(postponed) inheritance. Postponing a will that was *never* signed/sent just
|
||||
rebuilds it (no on-chain fee).
|
||||
|
||||
## Transaction list: the "Server" column
|
||||
|
||||
The will transaction list shows a dedicated **Server** column so you always
|
||||
know whether each inheritance transaction is actually stored on the
|
||||
will-executor servers, independently of the row colour:
|
||||
|
||||
| Label | Meaning |
|
||||
| --- | --- |
|
||||
| `Confirmed on server` | the will-executor confirmed it stored the transaction |
|
||||
| `Sent (not checked)` | pushed to the will-executor, not yet re-checked |
|
||||
| `Send failed` / `Not on server` | push failed or the server no longer has it |
|
||||
| `Signed (not sent)` | signed locally, not sent to any will-executor |
|
||||
| `Not sent` | not signed/sent yet |
|
||||
|
||||
Hovering the cell shows a tooltip with the will-executor URL and the current
|
||||
state.
|
||||
|
||||
## Testing
|
||||
|
||||
```bash
|
||||
|
||||
Reference in New Issue
Block a user