Skip to content

feat: run the shop's marketplace on staging with our own paykit server - #23

Merged
ovitrif merged 4 commits into
mainfrom
feat/shop-mixed
Oct 10, 2026
Merged

ovitrif merged 4 commits into
mainfrom
feat/shop-mixed

Conversation

@ovitrif

@ovitrif ovitrif commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Refs:

Description

  • Adds the shop-mixed profile and ./shop-mixed so that a Bitkit staging build can be tested against a Paykit Server version the staging Shop does not run: Paykit Server v0.1.0-rc11 (662dca06, paykit-rs ad3c7224 = v0.1.0-rc72, the version of the send-fix PRs) on the staging homeserver (homeserver.staging.pubky.app), watching Blocktank's staging regtest Electrum, behind a Cloudflare quick tunnel.

  • Adds a staging mode to the marketplace driver (MARKETPLACE_BACKEND=staging): staging homeserver and relay, the rc11 config schema ([signed_services], mainnet Pubky resolution, regtest chain), mining through Blocktank's regtest API, and a clear refusal for the headless-wallet commands, since Bitkit wallets are the seller and the buyer on staging.

  • Builds Paykit Server from its release tag with the classic builder and fails the build when the tag or its paykit-rs lock differs from the pins (the published rc11 image was never pushed: its Docker workflow run was cancelled).

  • Accepts the rc11 setup page markup in the driver's setup parsing.

  • ./shop-mixed purchase defaults the seller to the Bitkit seller on staging (7d0f9fe). Before it, purchase without --seller bitkit failed on the missing headless seller; the profile's startup proof ran at 9773509 and does not cover this change.

Out of Scope

  • marketplace profile: still Paykit Server 0ffd4da on the local Pubky testnet; moving it to rc11 needs its config writer on [signed_services].
  • Headless seller and buyer on staging: they would need staging invite codes and a funded staging wallet.

Design

N/A — no UI changes.

Preview

N/A — no user-visible changes.

QA Notes

Manual Tests

  • ./shop-mixed up on a Linux Docker host without BuildKit: image labels read paykit-server 662dca06 (v0.1.0-rc11), paykit-rs ad3c7224; /health/ready answers ready for postgres, electrum, paykit_delivery and outbox on loopback and through the tunnel URL.
  • ./shop-mixed setup-url: a pubkyauth://signin_grant link with cid=app.paykit.server and x-bitkit-claim=paykit-access-v1.watch-only-account-v1, and the public setup page.
  • ./shop-mixed seller-auth: the locks.app /pub/app.locks/:rw grant request on httprelay.staging.pubky.app.
  • Not run: a purchase between two Bitkit staging wallets.

@ovitrif ovitrif self-assigned this Oct 10, 2026

@talosmachina talosmachina left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 finding (1 P1). Adds the shop-mixed profile: Paykit Server v0.1.0-rc11 built from its tag on Synonym's staging homeserver and Blocktank's staging regtest chain behind a quick tunnel, plus a staging mode for the marketplace driver. Reviewed cdf10fc, full tier.

What I checked, and 6 candidates I ruled out

Read in full: marketplace/driver/driver.mjs (staging branches and every caller of pickSeller, readFixture, chainInfo/rpc), shop-mixed, the shop-mixed services in docker-compose.yml, both new Dockerfiles, docs/shop-mixed.md
Ran: built Dockerfile.staging, ran purchase --buyer <pubky> against a fixture holding only bitkit_seller (as seller-auth leaves it) with a stub answering /health/ready: FAIL: Cannot read properties of undefined (reading 'kind'). With --seller bitkit it gets past that line.
CI: no checks on this branch

Ruled out

  • Tag pin check on an annotated tag: v0.1.0-rc11 is annotated (8c16894), but after git clone --branch rev-parse HEAD is the peeled commit 662dca06, which is the pin.
  • Blocktank mine request shape: same endpoint and {count} body as bitkit-e2e-tests test/helpers/regtest.ts.
  • Headless commands reaching bitcoind on staging: seed, fund, receive, pay, peers, verify, verify-bitkit-seller exit before dispatch; status skips recordPaymentTx on staging; mine and info branch before any RPC.
  • Driver image without the helper binaries: the only callers (approveSetupAs, createBuyer, reader helpers) sit behind the refused commands.
  • Paykit Server starting before its config: the entrypoint waits for both files, and init-and-stay writes them before idling.
  • allowed_origins = ["*"] / trusted_proxy_hops = 1: deliberate and documented for the tunnel; a test-only stack.
  • Cold reader: the finding stood.

Merge confidence: 3/5, one P1 on the profile's documented purchase step.

Comment thread marketplace/driver/driver.mjs Outdated

@ovi-reviewer ovi-reviewer Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: ✅ Approve

Review: diff 9 files.

Configuration this profile supplies to the Bitkit send-fix acceptance pair, synonymdev/bitkit-android#1384 and synonymdev/bitkit-ios#844:

  • Paykit Server v0.1.0-rc11 (662dca0, paykit-rs ad3c722 = rc72)
  • the staging homeserver
  • Blocktank's staging regtest Electrum behind a quick tunnel

Proven in a separately assembled setup using this configuration with the same Paykit pins:

  • The Locks merchant acceptance passed on Android and on iOS: original invoice ec0d05 with amount_matched true, SDK request a7e5d0aa proof_submitted, one transaction 283f408b.
  • The full Shop order-paid acceptance used it as the Paykit Server: each was a 1,000-sat order with amount_matched true, the original SDK proof submitted, one transaction and the same order paid.
    • Android: order 89ca8c49, invoice 26c3a793, transaction ad00c6f4
    • iOS: order 0bd26696, invoice cff3c171, transaction 14a1d470

Proven by the profile's own lane proof:

  • its startup
  • the pinned revisions read from the image labels
  • a lane device's /health/ready request

Not proven:

  • The lane proof ran no purchase.

Found during those runs:

  • A driver trust overwrite, fixed in #24.

Reviewed by claude-opus-5-5 via gh-pr-review-loop skill
Commands: @ovi-reviewer review · test · retest

purchase passed 'headless' when --seller was absent, so pickSeller's staging default never applied and ./shop-mixed purchase failed on the undefined headless seller.
@ovitrif
ovitrif requested review from a team, ben-kaufman and coreyphillips and removed request for a team, ben-kaufman and coreyphillips October 10, 2026 11:27
@ovitrif
ovitrif merged commit 920166b into main Oct 10, 2026
@ovitrif
ovitrif deleted the feat/shop-mixed branch October 10, 2026 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants