• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 33997513952
87%

Build:
DEFAULT BRANCH: main
Ran 05 Sep 2026 11:05PM UTC
Jobs 1
Files 92
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

05 Sep 2026 11:01PM UTC coverage: 92.482% (-0.06%) from 92.546%
33997513952

push

github

web-flow
fix(keymaster): Make wallet creation a decision, not a side effect of reading (#1050)

* fix(keymaster): Make wallet creation a decision, not a side effect of reading

loadWallet minted a fresh mnemonic whenever the store read empty, from
any of its 29 internal callers, with nothing logged. An unmounted volume,
a wiped database or a changed ARCHON_KEYMASTER_DB replaced the node's
identity silently -- and a watch-only Bitcoin wallet built on the old
mnemonic then watches addresses the node can no longer spend from.

Whether an empty store is a first run or a lost one cannot be decided
from the store: both read as absent. So the surface decides.
`createWalletIfMissing` is off by default and loadWallet throws
WalletNotFoundError; `loadOrCreateWallet` is the explicit form for
callers that mean to provision.

The CLIs already gated this correctly -- an allowlist of commands that
may run without a wallet, and a hard error otherwise -- but the policy
lived in their bootstrap rather than in Keymaster, so the services and
the browser wallets never had it. Each surface now opts in where it
provisions: the CLIs, the wallet UI's setup flow, and the services'
startup path, which logs and counts it. ARCHON_KEYMASTER_REQUIRE_WALLET
makes an empty store fatal for a node that already holds an identity.

The MCP server's archon_create_wallet was spelled as loadWallet, relying
on the implicit create to do its work; it now names it.

Closes #1037

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GYGMfX3foBcVqP7AQNXjWj

* refactor(keymaster): Provision by calling it, not by setting a flag

The constructor option was the same defect in a smaller form: a boolean
read somewhere else decided whether a read could mint an identity, so
the call site still did not say. It also let the service log and count a
provisioning that had not happened yet -- the flag deferred the actual
newWallet back into loadWallet, contradicting the... (continued)

3923 of 4510 branches covered (86.98%)

Branch coverage included in aggregate %.

14 of 17 new or added lines in 3 files covered. (82.35%)

2 existing lines in 1 file now uncovered.

8563 of 8991 relevant lines covered (95.24%)

721.39 hits per line

Uncovered Changes

Lines Coverage ∆ File
3
91.22
-0.23% packages/keymaster/src/keymaster.ts

Coverage Regressions

Lines Coverage ∆ File
2
91.22
-0.23% packages/keymaster/src/keymaster.ts
Jobs
ID Job ID Ran Files Coverage
1 33997513952.1 05 Sep 2026 11:05PM UTC 184
93.56
GitHub Action Run
Source Files on build 33997513952
  • Tree
  • List 92
  • Changed 78
  • Source Changed 3
  • Coverage Changed 78
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #33997513952
  • 2890125e on github
  • Prev Build on main (#33970265106)
  • Next Build on main (#34003527198)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc