RelayerCore release 0.1.0

Status, replay & limits

Submission status semantics, process-local idempotency and replay coordination, and authoritative on-chain nullifier protection.

Relay submission and Solana finality are separate. POST /relay returns a signature after RPC submission. GET /status/:signature polls RPC and reports submitted, processed, confirmed, finalized or failed.

If RPC does not return a status record, the status endpoint reports submitted; missing status is not proof of failure. A finalized execution error is failed with ONCHAIN_FAILED.

Idempotency and replay

The relayer memoizes transaction message hashes to signatures for up to 24 hours and holds short-lived (pool, nullifier) replay leases for up to 120 seconds. The rate limiter, idempotency cache, replay tracker and concurrency limiter are in-memory maps local to a warm service process. They are not shared durable state across serverless instances or cold starts.

The exact same signed message is deterministic under the relayer Ed25519 key and Solana deduplicates the same signature. Different concurrent requests can still race across service instances. Core's canonical spent-nullifier PDA is the global replay authority; at most one transaction for a note nullifier can succeed, though a losing transaction can incur a fee.

PreviousPolicy validationNext Versioned transactions
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.