Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Pin confirmed-tx API reads to a chain view and stamp the tip - #200

Merged
reardencode merged 7 commits into
masterfrom
query/chain-view
Aug 23, 2026
Merged

Pin confirmed-tx API reads to a chain view and stamp the tip#200
reardencode merged 7 commits into
masterfrom
query/chain-view

Conversation

@rearden-grok

Copy link
Copy Markdown
Contributor

Why

Yuval pointed out that Electrum and Esplora have an A-B-A hole: a
same-height reorg can leave txid:height (and a height-keyed join cache)
unchanged while merkle proofs and confirming block hashes moved.

We researched:

  • mempool/mempool#6584 — stamp the chain tip hash on every API response so sequential fetches detect tip movement, including A-B-A. A start/end tip GET is still racy unless the payload is consistent with that hash.
  • spesmilo/electrum-protocol#2 — 1.7 added chaintip, then reverted it in #17 because ElectrumX is bitcoind middleware and cannot pin. That argument does not apply here.

What

Confirmed-tx reads pin {height, hash, header_fk} of the published tip
(Query::pin_chain_view). Extension leaves a prefix pin live. Disconnect
or same-height replace dies the pin; run_at_chain_view retries (bound 8)
then StoreError::Stalenot a writer lock and not MVCC.

SurfaceSnapshot token
Esplora HTTPX-Bitcoin-Chain-Tip + X-Bitcoin-Chain-Tip-Height (CORS-exposed). Pin death → 503.
Electrum TCPJSON-RPC extra members chain_tip / chain_tip_height next to result (ping/version omit). server.features.chain_tip.
Electrum statusPreimage is txid:height:blockhash: for confirmed rows so same-height replace changes status. Reorg restatuses every watch.
SH join slotKeyed on tip hash, not height.

We stamp tip, not only the last relevant history tx. We do not serve
“as of hash H” after H is disconnected.

Docs: COMPAT.md, docs/concurrency.md (reader pin+retry), docs/crash-recovery.md.

Test plan

  • Query: pin live across extension; dead after same-height replace; SH slot miss; retry helper; stale is not Corrupt.
  • Esplora: header matches /blocks/tip/hash; omitted on empty chain; changes after same-height replace.
  • Electrum: get_history stamps chain_tip; ping omits it; status includes blockhash; reorg notifies a dropped scripthash.

Do not merge unless asked.

rbitcoin-grok added 7 commits August 22, 2026 16:14
Confirmed-tx API reads need a snapshot token that is the tip hash, not
only height. Capture height+hash+header_fk; still_live is true while
confirmed[height] is that fk so extension keeps a prefix pin and
same-height replace does not.
Same-height reorg reused the connection join because the slot keyed on
height. Store the pin hash; is_confirmed_strong_at(view.height) hides
creates above the pin so a prefix view cannot leak the live tip.
A request that straddles a disconnect must not return a torn mix.
run_at_chain_view pins, runs the body, and retries up to 8 times if
confirmed[height] moved. Exhaustion is StoreError::Stale, not Corrupt.
Sequential fetches need a snapshot token that is the tip hash, not
height. Pin before the handler; if that prefix is still published,
stamp hash+height and CORS-expose them. A same-height replace kills
the pin and yields 503 so the client retries an honest body.
Electrum is TCP, not HTTP, so the snapshot token is an extra JSON-RPC
member next to result. get_history / get_balance / listunspent /
transaction.get / get_merkle retry while the pin stays live. ping and
version omit the fields. server.features.chain_tip advertises it.
Legacy status is SHA256 of txid:height, so a same-height replace is
silent. Include the confirming block hash in the preimage. TipNotify
carries reorg_from_height so a reorg restatuses every watch even when
the new block does not touch the script.
Document reader pin+retry (no pause-queries), Esplora tip headers, and
Electrum chain_tip + status blockhash. Credit Yuval for raising A-B-A;
cite mempool/mempool#6584 and spesmilo/electrum-protocol#2 (#17 revert).
@reardencode
reardencode merged commit 6e76f1f into masterAug 23, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@reardencode