feat(money-account-upgrade-controller): persist upgrade status and add retry#9500
Merged
Merged
Conversation
Contributor
Author
|
@metamaskbot publish-preview |
Jwhiles
force-pushed
the
feat/money-account-upgrade-persisted-state-retry
branch
from
July 14, 2026 10:39
10d0bd7 to
b22654e
Compare
Contributor
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
Jwhiles
force-pushed
the
feat/money-account-upgrade-persisted-state-retry
branch
from
July 16, 2026 09:20
b22654e to
8b1e39b
Compare
Contributor
Author
|
@metamaskbot publish-preview |
Contributor
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
…d retry Track fully upgraded accounts in persisted controller state, keyed by lowercased address and fingerprinted against the active upgrade config, so upgradeAccount skips the step sequence once an account is recorded as upgraded and re-runs it when the config changes. Add upgradeAccountWithRetry, retrying failed attempts with capped exponential backoff (10s/20s/40s/60s, 5 attempts by default) and AbortSignal cancellation. Failures that cannot resolve by retrying (account delegated to a third-party EIP-7702 implementation, or unexpected on-chain code) are marked terminal via TerminalUpgradeError and are not retried. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… association conflicts as terminal A 409 from associateAddress whose disambiguating lookup confirms the address is not associated with the authenticated profile cannot resolve by retrying, so throw TerminalUpgradeError to stop the retry loop. If the lookup itself fails, the original retryable conflict still propagates. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Mark the state-shape change as BREAKING in the changelog; the release is already major via #9387. - Exclude upgradedAccounts from state logs (address-keyed enrollment data, matching precedent in other address-keyed controllers). - Validate that maxAttempts is an integer >= 1 so NaN cannot cause unbounded retries. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Jwhiles
force-pushed
the
feat/money-account-upgrade-persisted-state-retry
branch
from
July 20, 2026 10:37
5a47678 to
9a7bcfb
Compare
shane-t
previously approved these changes
Jul 20, 2026
Contributor
Author
|
@metamaskbot publish-preview |
Contributor
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
ffmcgee725
approved these changes
Jul 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation
This PR updates the money account upgrade process so that it records whether a particular run succeeds or fails. The purpose of doing this is so we can more easily tell when it is necessary to re-run the process from clients, and to avoid running it unnecessarily for users who are already upgraded.
The upgrade process now checks whether the upgrade has happened before starting, and if it has started skips, it also retries on a backoff for non terminal failures. Terminal failures which can't be recovered from (e.g. a mismatched delegation) cause us to stop immediately. When this PR is merged and released it will be rolled into this PR in the mobile client
References
Checklist
Note
Medium Risk
Breaking controller state shape and persisted upgrade semantics affect all consumers; mis-fingerprinting or stale skip logic could skip needed re-upgrades, while terminal misclassification could block or over-retry upgrades.
Overview
Breaking:
MoneyAccountUpgradeControllerStateis no longer empty—it now persistsupgradedAccounts(lowercased address → completion time + config fingerprint). The constructor accepts optional partialstateviagetDefaultMoneyAccountUpgradeControllerState().After a successful run,
upgradeAccountwrites that record and returns immediately on later calls when the fingerprint still matches the active chain/CHOMP/delegation config; a config change forces the full step sequence to run again. Failed runs are not persisted.Terminal failures: New
TerminalUpgradeError,MoneyAccountUpgradeStepError.terminal, andisTerminalMoneyAccountUpgradeErrorlet clients stop retrying unrecoverable cases. EIP-7702 and associate-address steps now throw terminal errors for third-party delegation, unexpected on-chain code, and confirmed cross-profile CHOMP address conflicts (ambiguous 409s stay retryable).The controller does not implement backoff/retry itself—that remains in host apps (e.g. mobile).
Reviewed by Cursor Bugbot for commit ed29035. Bugbot is set up for automated code reviews on this repo. Configure here.