BIGHT token markInfraVerifiable Storage

Failure paths

Bad paths end in named states.

Replay attempts, stale receipts, missing proofs, unavailable records, and blocked payment paths should become bounded public terminal labels instead of silent confusion.

Choose the next Infra action.

Wallet, purchase, storage, proof, retrieval, contracts, and status are kept as separate product lanes.

Allowed outcomes

Every failure must land on one of these public outcomes. Anything else is an incomplete product state.

Failure matrix

Awaiting live data

Allowed outcomes

Awaiting live data

Outcome counts

Awaiting live data

Named failure cases

The matrix is intentionally concrete: wrong signer is not the same as wrong chain, and hot-provider failure is not the same as cold-retention delay.

Failure cases

Awaiting live data

Receipts and retry rules

Failure receipts explain what happened, what can be retried, and what cannot be inferred from the failure.

Failure outcomes

Awaiting live data

Product boundary

A visible failure is healthier than a hidden success claim. Infra should say stale, refused, queued, quarantined, downgraded, repairing, or terminal when that is the real state.

Replay

Replay and duplicate evidence links to canonical state instead of creating duplicate payment, work, or storage.

Storage

Hot provider failure, cold restore delay, provider proof mismatch, repair exhaustion, and capacity exhaustion stay separate.

Website

Website stale head or public stats conflict becomes stale or refused public state, not chain truth.

Interop

QUAD/Core, Bridge, and Liquid outages queue, retry, or stale-label their paths without inventing sibling-chain facts.