- W1-3 (Med): updateWalletIndexForActiveWallet stamped syncedHere in the markOpened block
at bare connect (idHash still empty), letting a freshly-restored wallet skip its needed
rescan. syncedHere is now stamped only once the wallet's identity is verified (idHash
non-empty), so it takes effect at the post-address-refresh index update; lastOpenedEpoch
still records at open.
- Startup guard (the W1-1 launch counterpart): App::init now exists()-checks the recorded
active wallet before the daemon is configured. A non-default active wallet moved/deleted
between sessions falls back to the default wallet.dat with a warning, instead of the
daemon silently auto-creating an empty wallet under the missing name. Runs before the PIN
vault init so the vault is scoped to the wallet actually opened.
Completes P1-B. Remaining P1: W3-3 (sweep opid persistence) deferred for careful
adversarially-reviewed work — re-tracking a stale opid could hang the migration if the op
poller doesn't time out; the existing balance/mined gates already prevent fund loss. See
docs/wallet-hardening.md.
Build-clean; ctest 1/1.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>