walletAutoShieldControllerProvider top-level property

NotifierProvider<AutoShieldController, AutoShieldStatus> walletAutoShieldControllerProvider
final

The auto-shield policy loop (§3.2i-3 (a); maintainer calls) — the WalletSyncController structural sibling, but SNAPSHOT-driven: policy is host-side (ADR-0529), proposeShield is the ready primitive, and every refreshed balance snapshot (the sync edges refresh it) is an evaluation point. Fires when ALL hold:

  • a live session exists and the auto-shield switch is ON — a switch still LOADING never fires (a slow disk read must not race a persisted OFF),
  • OS power-save is not active (maintainer call: DEFER, shield on the next normal-power evaluation; desktop is never power-save),
  • the transparent balance ≥ max(host threshold, the SDK's own shielding floor — proposeShield returns null below it, a quiet no-op),
  • no manual shield flow is in flight (the sheet wins; skipping beats racing it for the same UTXOs), and
  • the authorizer has not denied an automatic spend this session.

The money sequence is the manual shield's, verbatim discipline (#327/#330/ authorize exactly once with origin: automatic, identity fence inside the action closure, at-most-one in-flight attempt, generation- guarded continuations. FAILURE HONESTY: a failed/denied attempt leaves the transparent figure visible (the state.rs invariant renders it) plus the balance-card cue — never a silent retry-forever, never a hidden balance.

Implementation

final walletAutoShieldControllerProvider =
    NotifierProvider<AutoShieldController, AutoShieldStatus>(
      AutoShieldController.new,
    );