Cashu Fault Lab

Cashu delivery fault injection and recovery evidence

Make Cashu delivery fail safely.

Inject response loss, retries, duplicates, and process crashes across real wallets and mints—then prove every implementation converges.

npx --yes cashu-fault-lab@0.3.0 demo
Next / verified run evidence
Seed
cashu-fault-lab-v0.3.0-public
Fault program
http-response-lost
Evidence
18 invariants
Outcome
✓ passed
Verified public-package run passed
Package
cashu-fault-lab@0.3.0
Evidence
15 passed · 3 not applicable
Cleanup
0 containers · 0 networks · 0 volumes

Deterministic fault trace

A lost response is not a lost result.

The lab repeats the exact delivery after transport ambiguity, then checks proof state and durable credit before it calls the run converged.

  1. 01Reserve proofs
  2. 02Send delivery
  3. 03Response lost
  4. 04Exact retry
  5. 05Recover proofs
  6. 06One durable credit

First-party reproducible evidence

Evidence, not a success boolean.

This v0.3.0 run used the public npm package in a clean directory with Node 24 and Docker, exactly as a new user would. First-party reproducible evidence is not independent wallet validation or certification.

Exact public commandnpx --yes cashu-fault-lab@0.3.0 demo --seed cashu-fault-lab-v0.3.0-public --artifact ../v0.3.0-demo.json --report ../v0.3.0-demo.html
Scenariohttp-response-lost
Run passed
Seed
cashu-fault-lab-v0.3.0-public
Commands
3
Timeline observations
14
Invariants evaluated
18

Package cashu-fault-lab@0.3.0; the recorded seed for this run is cashu-fault-lab-v0.3.0-public.

  • 01
    Public package

    cashu-fault-lab@0.3.0 downloaded from npm

  • 02
    Environment doctor

    10 checks · 0 failed · 0 warned

  • 03
    Fault and recovery

    2 attempts · 1 redemption start · 1 merchant credit

  • 04
    Oracle evaluation

    15 passed · 0 failed · 3 not applicable

  • 05
    Evidence artifacts

    Secret-scanned JSON and HTML reports retained

  • 06
    Docker cleanup

    0 containers · 0 networks · 0 volumes

The real user path: public npx commands, environment checks, and the final Docker demo result.
The generated HTML report is a human view of the same machine-readable artifact.
  • Passed15
  • Failed0
  • Not observable0
  • Not applicable3

Invariant evidence states

Every evaluated invariant remains visible; unsupported observations are never promoted to passes.

Requires context

Unavailable or out-of-scope observations, with the reason kept visible.

3
  • No false rejection after possible consumptionno-false-rejection-after-possible-consumption
    Evidence basisDerived

    No rejected receipt was observed.

    Not applicable
  • Crash recoverycrash-recovery
    Evidence basisDerived

    The scenario does not restart a component.

    Not applicable
  • Transport convergencetransport-convergence
    Evidence basisDerived

    The scenario does not use multiple transports.

    Not applicable

Supported by reviewed evidence

Checks supported by the artifact’s declared evidence basis.

15
  • At most once redemption startat-most-once-redemption-start
    Evidence basisAdapter claimed
    Passed
  • At most one merchant credit per requestat-most-one-merchant-credit-per-request
    Evidence basisAdapter claimed
    Passed
  • At most one merchant credit per deliveryat-most-one-merchant-credit-per-delivery
    Evidence basisAdapter claimed
    Passed
  • Proof set exclusivityproof-set-exclusivity
    Evidence basisAdapter claimed
    Passed
  • Delivery identity immutabilitydelivery-identity-immutability
    Evidence basisAdapter claimed
    Passed
  • Exact net amountexact-net-amount
    Evidence basisAdapter claimed
    Passed
  • No premature settlementno-premature-settlement
    Evidence basisAdapter claimed
    Passed
  • Monotonic receiptsmonotonic-receipts
    Evidence basisDerived
    Passed
  • Stable duplicate responsestable-duplicate-response
    Evidence basisAdapter claimed
    Passed
  • Eventual terminal or recovery stateeventual-terminal-or-recovery-state
    Evidence basisDerived
    Passed
  • Retry convergenceretry-convergence
    Evidence basisDerived
    Passed
  • Independent mint evidenceindependent-mint-evidence
    Evidence basisAdapter claimed
    Passed
  • Independent ledger evidenceindependent-ledger-evidence
    Evidence basisAdapter claimed
    Passed
  • Reproducibilityreproducibility
    Evidence basisDerived
    Passed
  • No unsupported passno-unsupported-pass
    Evidence basisDerived
    Passed

Repository fault programs

Explore fault scenarios

Choose a deterministic break point, inspect its exact command sequence, and link every run back to reviewed JSON.

50checked-in scenarios

  • RETRYResponse loss and retry

    Lose requests or responses across HTTP and Nostr, then repeat the exact delivery.

    04 programs
  • RECOVERCrash recovery

    Restart senders and receivers around persistence, settlement, and receipt boundaries.

    15 programs
  • RACEDuplicate and concurrency

    Challenge single-use guarantees with duplicates, conflicts, and concurrent delivery.

    09 programs
  • BOUNDARYSecurity and malformed transport

    Probe malformed input, CORS, redirects, and server-side request boundaries.

    04 programs
Explore all scenarios

Integrate and validate

Integrate and validate without changing implementation behavior.

Connect a wallet through the language-neutral adapter contract, inspect its trust boundary, and keep release claims tied to independent evidence.

02 / Trust boundary

Keep evaluation independent.

Implementations own persistence and recovery. The oracle evaluates safety and liveness from evidence outside the implementation.

Architecture
03 / Release gate

Experimental developer preview

The deterministic run is useful evidence, not certification. Qualification still needs independent pairs, mints, and review.

Validation status

Contribution

Add an adapter. Break a delivery. Improve the evidence.