With PathCheckMinInterval removed, a non-empty merkleProofCache is trusted
forever unless force=true is passed. Previously only the two lightpush retry
paths ever passed force=true; the REST relay publish handlers (static and
auto-sharding) and the broker proof provider had no rejection feedback loop,
so a sliding root window would permanently reject their messages until restart.
- REST relay handlers: run validateMessage first; if it returns
RlnValidatorErrorMsg, force-refresh the cached path and retry validation once
before publishing — mirroring the lightpush reactive pattern.
- Broker provider (rln.nim): decode the generated proof bytes, call
validateRoot on the embedded Merkle root, and force-refresh + regenerate
when the root is outside the acceptance window — since the broker has no
external rejection signal to react to.
Tests added for all three new paths, using the corrupted-cache technique
(all-zero merkleProofCache → garbage root → rejection → retry).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>