walletAutoShieldControllerProvider top-level property
The auto-shield policy loop (§3.2i-3 (a); maintainer calls) — the
WalletSyncController structural sibling, but SNAPSHOT-driven: policy is
host-side (ADR-0529), proposeShield is the ready primitive, and every
refreshed balance snapshot (the sync edges refresh it) is an evaluation
point. Fires when ALL hold:
- a live session exists and the auto-shield switch is ON — a switch still LOADING never fires (a slow disk read must not race a persisted OFF),
- OS power-save is not active (maintainer call: DEFER, shield on the next normal-power evaluation; desktop is never power-save),
- the transparent balance ≥ max(host threshold, the SDK's own shielding
floor —
proposeShieldreturns null below it, a quiet no-op), - no manual shield flow is in flight (the sheet wins; skipping beats racing it for the same UTXOs), and
- the authorizer has not denied an automatic spend this session.
The money sequence is the manual shield's, verbatim discipline (#327/#330/
authorize exactly once with origin: automatic, identity fence
inside the action closure, at-most-one in-flight attempt, generation-
guarded continuations. FAILURE HONESTY: a failed/denied attempt leaves the
transparent figure visible (the state.rs invariant renders it) plus the
balance-card cue — never a silent retry-forever, never a hidden balance.
Implementation
final walletAutoShieldControllerProvider =
NotifierProvider<AutoShieldController, AutoShieldStatus>(
AutoShieldController.new,
);