Postpone safety (Strategy B):
- A signed/sent will carries an immutable locktime; postponing the delivery
time previously did nothing, so a will-executor could still broadcast the
old (earlier-locktime) transaction and execute the inheritance too early.
- core/will.py: add WillPostponedException and detect postpone by comparing
the requested locktime against w.tx.locktime (the locktime frozen in the
signed transaction) instead of the in-memory heir entry, which is updated
together with the new value and would always compare equal.
- gui/qt/dialogs.py (BalBuildWillDialog.task_phase1, the real path used by
Tools -> Prepare): handle WillPostponedException before NotCompleteWill;
return (None, tx) to trigger sign + broadcast of the invalidation, then the
user presses Prepare again to rebuild/re-sign/re-send (two explicit steps).
- gui/qt/window.py: mirror the branch in build_inheritance_transaction with an
explanatory message; wording aligned to the 'Prepare' button.
- gui/qt/common.py: export WillPostponedException.
- A postpone on a will that was never signed/sent just rebuilds (no on-chain
fee).
Server status column:
- gui/qt/lists.py: add a dedicated 'Server' column to PreviewList with an
always-readable label and a tooltip (will-executor URL + state).
- gui/qt/theme.py: add server_status_text() and server_status_tooltip(),
reusing the existing status flags.
- gui/qt/common.py: export the new theme helpers.
Docs: update README.md, bal/README.md and CHANGELOG_REFACTOR.md.
Tests: 182 passed; smoke + external-zip OK; ruff has no new real findings.