Expose behavior, not internals.
Preserve native wallet and mint behavior while the lab drives response loss, duplicates, crashes, and Mint ambiguity.
Adapter guide Review wallet lifecycle scopeCashu delivery fault injection and recovery evidence
Inject response loss, retries, duplicates, and process crashes across real wallets and mints—then prove every implementation converges.
npx --yes cashu-fault-lab@0.3.0 demoDeterministic fault trace
The lab repeats the exact delivery after transport ambiguity, then checks proof state and durable credit before it calls the run converged.
First-party reproducible evidence
This v0.3.0 run used the public npm package in a clean directory with Node 24 and Docker, exactly as a new user would. First-party reproducible evidence is not independent wallet validation or certification.
npx --yes cashu-fault-lab@0.3.0 demo --seed cashu-fault-lab-v0.3.0-public --artifact ../v0.3.0-demo.json --report ../v0.3.0-demo.htmlPackage cashu-fault-lab@0.3.0; the recorded seed for this run is cashu-fault-lab-v0.3.0-public.
cashu-fault-lab@0.3.0 downloaded from npm
10 checks · 0 failed · 0 warned
2 attempts · 1 redemption start · 1 merchant credit
15 passed · 0 failed · 3 not applicable
Secret-scanned JSON and HTML reports retained
0 containers · 0 networks · 0 volumes
npx commands, environment checks, and the final Docker demo result.Every evaluated invariant remains visible; unsupported observations are never promoted to passes.
Unavailable or out-of-scope observations, with the reason kept visible.
no-false-rejection-after-possible-consumptionNo rejected receipt was observed.
crash-recoveryThe scenario does not restart a component.
transport-convergenceThe scenario does not use multiple transports.
Checks supported by the artifact’s declared evidence basis.
at-most-once-redemption-startat-most-one-merchant-credit-per-requestat-most-one-merchant-credit-per-deliveryproof-set-exclusivitydelivery-identity-immutabilityexact-net-amountno-premature-settlementmonotonic-receiptsstable-duplicate-responseeventual-terminal-or-recovery-stateretry-convergenceindependent-mint-evidenceindependent-ledger-evidencereproducibilityno-unsupported-passRepository fault programs
Choose a deterministic break point, inspect its exact command sequence, and link every run back to reviewed JSON.
50checked-in scenarios
Lose requests or responses across HTTP and Nostr, then repeat the exact delivery.
04 programsRestart senders and receivers around persistence, settlement, and receipt boundaries.
15 programsChallenge single-use guarantees with duplicates, conflicts, and concurrent delivery.
09 programsProbe malformed input, CORS, redirects, and server-side request boundaries.
04 programsIntegrate and validate
Connect a wallet through the language-neutral adapter contract, inspect its trust boundary, and keep release claims tied to independent evidence.
Preserve native wallet and mint behavior while the lab drives response loss, duplicates, crashes, and Mint ambiguity.
Adapter guide Review wallet lifecycle scopeImplementations own persistence and recovery. The oracle evaluates safety and liveness from evidence outside the implementation.
ArchitectureThe deterministic run is useful evidence, not certification. Qualification still needs independent pairs, mints, and review.
Validation statusContribution