Codebase-wide rename of the stale loader_core crate name to
program_loader_core (192 call sites, plus Cargo.toml dependency
declarations), needed after the loader crate's rename landed upstream.
ping_receiver/wrapped_token's UpdateSources handler, cross_zone_inbox's
inbox_source_marker_account_id (moved from the now-superseded
cross_zone_marker crate), and several test/genesis call sites still
referenced ProgramId-bijection addresses or pre-unification struct
shapes (CrossZoneMessage.src_program_id, WrappedTokenConfig/
ReceiverConfig field types, InboxInstruction::Dispatch's tuple form)
that this branch's own dispatch-address unification had already moved
past elsewhere.
Programs dispatch at the address seeded via with_programs/a live Deploy
(loader_core::immutable_deploy_account_id), not the bijection
AccountId::from(program_id) used by the legacy ProgramDeploymentTransaction
storage shape. This sweep threads the correct address through
lee/lez/integration_tests/wallet-ffi call sites and fixes 7 dispatch-address
bugs the mismatch was masking: bijection-vs-real-PDA mismatches in
lez/wallet's native_token_transfer facade, integration_tests'
auth_transfer/private and private_pda suites, wallet-ffi's
generic_transaction FFI boundary, a stale assertion in program_deployment.rs,
and a stale expected-error string in cross_zone_state_machine.rs.
Also includes a full clippy/fmt pass: doc-comment reflow, #[expect(...)]
attribute additions, redundant type-annotation/unused-import removal, and
two assert!s added purely for bounds-check elision on already-guarded
slices — no logic changes. Both CI clippy invocations and cargo fmt --check
are clean.
Verified: RISC0_DEV_MODE=1 cargo test -p lee --lib (214 passed) and the
broader sanity set across lee/wallet/bridge_lock_core/ping_core/
cross_zone_outbox_core/sequencer_core (mock features) both green.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Privacy-preserving circuit:
- Add ProgramImageClaim, letting a Deploy-created program's real image_id be
anchored to its account for privacy-circuit env::verify, with the sequencer
independently re-deriving the real image_id via get_program to authenticate
the claim (journal reconstruction, same pattern as public_actions pre-states).
- Fix compute_public_authorized_pdas and the private circuit's
resolve_authorization_and_record_bindings to use the caller's real recovered
image_id instead of bijection-guessing it from the caller's account_id, which
was wrong for Deploy-created callers.
Program storage:
- V03State::insert_program (used by both genesis's with_programs and live
ProgramDeploymentTransaction execution) now always writes the Deploy
two-account shape (ProgramData header + segment), not the legacy
PROGRAM_STORAGE_OWNER raw-elf shape. The header stays at the existing
bijection address so no dispatch-address reference needed to change; only
the segment (never a caller-facing address) moves to its PDA.
- Drop the now-redundant ProgramAlreadyExists pre-check in
ProgramDeploymentTransaction validation; PDA claiming already prevents
redeploying an account.
- Migrate remaining tests off ProgramDeploymentTransaction onto native Deploy
(sequencer_core, integration_tests' auth_transfer and block_size_limit),
adding a shared deploy_targets/deploy_transaction/encoded_tx_size helper.
Rebuild artifacts and the prebuilt test fixture for the circuit and program
storage changes.
- RESERVED_DEPLOYMENT_PROGRAM_ACCOUNT_ID: restore the SHA256 derivation
docstring that explains the constant instead of leaving it as an opaque
byte array, and switch the array itself to a hex literal (hex-literal,
already a workspace dependency) for readability.
- Rename the loader/loader_core crate to program_loader/program_loader_core
to disambiguate it, across the directory, package name, workspace
members/dependency alias, both dependent crates, and every call site.