Privacy-preserving circuit:
- Add ProgramImageClaim, letting a Deploy-created program's real image_id be
anchored to its account for privacy-circuit env::verify, with the sequencer
independently re-deriving the real image_id via get_program to authenticate
the claim (journal reconstruction, same pattern as public_actions pre-states).
- Fix compute_public_authorized_pdas and the private circuit's
resolve_authorization_and_record_bindings to use the caller's real recovered
image_id instead of bijection-guessing it from the caller's account_id, which
was wrong for Deploy-created callers.
Program storage:
- V03State::insert_program (used by both genesis's with_programs and live
ProgramDeploymentTransaction execution) now always writes the Deploy
two-account shape (ProgramData header + segment), not the legacy
PROGRAM_STORAGE_OWNER raw-elf shape. The header stays at the existing
bijection address so no dispatch-address reference needed to change; only
the segment (never a caller-facing address) moves to its PDA.
- Drop the now-redundant ProgramAlreadyExists pre-check in
ProgramDeploymentTransaction validation; PDA claiming already prevents
redeploying an account.
- Migrate remaining tests off ProgramDeploymentTransaction onto native Deploy
(sequencer_core, integration_tests' auth_transfer and block_size_limit),
adding a shared deploy_targets/deploy_transaction/encoded_tx_size helper.
Rebuild artifacts and the prebuilt test fixture for the circuit and program
storage changes.
- RESERVED_DEPLOYMENT_PROGRAM_ACCOUNT_ID: restore the SHA256 derivation
docstring that explains the constant instead of leaving it as an opaque
byte array, and switch the array itself to a hex literal (hex-literal,
already a workspace dependency) for readability.
- Rename the loader/loader_core crate to program_loader/program_loader_core
to disambiguate it, across the directory, package name, workspace
members/dependency alias, both dependent crates, and every call site.