Skip to content

fix(cmc): retry ICP burns that fail after cycles were already delivered - #11269

Open
Rachit2323 wants to merge 1 commit into
dfinity:masterfrom
Rachit2323:fix/cmc-pending-burn-retry
Open

fix(cmc): retry ICP burns that fail after cycles were already delivered#11269
Rachit2323 wants to merge 1 commit into
dfinity:masterfrom
Rachit2323:fix/cmc-pending-burn-retry

Conversation

@Rachit2323

Copy link
Copy Markdown
Contributor

The problem

When you send ICP to get cycles, CMC does two things: give you the cycles, then burn your ICP. If the burn fails, it just logs it and forgets. You keep the cycles, but your ICP never actually gets burned.
No retry, ever.

What I did

If the burn fails, save it instead of forgetting it. Try again every heartbeat until it works. Never repeat the "give you cycles" part again - only retry the burn.

Testing

Added tests for the new save/retry logic. All existing tests still pass.

@github-actions github-actions Bot added the fix label Aug 22, 2026
@basvandijk basvandijk added the security-review-passed IDX or InfraSec have concluded it's safe to run CI on the external PR. label Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@Rachit2323
Rachit2323 marked this pull request as ready for review August 23, 2026 04:51
@Rachit2323
Rachit2323 requested a review from a team as a code owner August 23, 2026 04:51

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):

  1. Update unreleased_changelog.md (if there are behavior changes, even if they are
    non-breaking).

  2. Are there BREAKING changes?

  3. Is a data migration needed?

  4. Security review?

How to Satisfy This Automatic Review

  1. Go to the bottom of the pull request page.

  2. Look for where it says this bot is requesting changes.

  3. Click the three dots to the right.

  4. Select "Dismiss review".

  5. In the text entry box, respond to each of the numbered items in the previous
    section, declare one of the following:

  • Done.

  • $REASON_WHY_NO_NEED. E.g. for unreleased_changelog.md, "No
    canister behavior changes.", or for item 2, "Existing APIs
    behave as before.".

Brief Guide to "Externally Visible" Changes

"Externally visible behavior change" is very often due to some NEW canister API.

Changes to EXISTING APIs are more likely to be "breaking".

If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.

If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.

Reference(s)

For a more comprehensive checklist, see here.

GOVERNANCE_CHECKLIST_REMINDER_DEDUP

@zeropath-ai

zeropath-ai Bot commented Aug 23, 2026

Copy link
Copy Markdown

No security or compliance issues detected. Reviewed everything up to 204431f.

Security Overview
Detected Code Changes
Change Type Relevant files
Enhancement ► rs/nns/cmc/src/main.rs
    Add PendingBurn struct, PendingBurns tracking, and retry logic for pending burns
► rs/nns/cmc/unreleased_changelog.md
    Update changelog entry: retried failed ICP burns after CMC notification processing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

external-contributor fix @governance-team security-review-passed IDX or InfraSec have concluded it's safe to run CI on the external PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants