3046 Commits

Author SHA1 Message Date
jonesmarvin8
6c0bd71523
refactor: PrivateUnauthorized authorization changed to true (#621)
* refactor: rename PrivateUnauthorized to PrivateForeignInit

The account_identity's is_authorized flag no longer determines
authorization for this variant, so keep the name tied to what
actually distinguishes it: no nsk, only npk (a foreign account init).

* chore: rebuild guest artifacts and bump spin to clear yanked advisory

Regenerate ELF artifacts after the PrivateForeignInit rename in lee_core
(compiled into every guest program), and update spin 0.9.8 -> 0.9.9 since
0.9.8 was yanked from crates.io, per cargo deny check advisories.

* test: align is_authorized with PrivateForeignInit's flipped semantics

Recipient pre-states built for PrivateForeignInit now need is_authorized:
true to match the assertion in output.rs. Also rewrites the boundary test
that checked the old invalid case to check the new one, and updates
stale "unauthorized" wording left over from the PrivateUnauthorized name.

* chore: rebuild guest artifacts

Reproducible across repeated local builds; likely toolchain drift since
the prior artifact commit rather than a source change, since no
guest-relevant source or Cargo.lock changed in between.

* fix(tests): align integration tests with PrivateForeignInit and regenerate fixture

prove_init_with_commitment_root (private.rs) and build_privacy_transaction
(tps.rs) still built PrivateForeignInit recipients with is_authorized: false,
same stale-semantics bug fixed earlier in the lee crate's own tests.

The prebuilt sequencer DB dump embeds program IDs derived from guest ELF
bytes, which shifted once the PrivateForeignInit rename changed lee_core
(compiled into every guest program). The stale dump caused widespread
"Unknown program" failures across integration test suites that exercise
deployed programs (wallet_ffi, auth_transfer, bridge, amm, token, pinata,
ata, indexer state-consistency checks). Regenerated via
`just regenerate-test-fixture`.

* fix(tests): rename leftover PrivateUnauthorized to PrivateForeignInit and regenerate fixture

* test: align is_authorized with PrivateForeignInit's flipped semantics

* chore: regenerate test fixture after rebase onto dev

* chore: regenerate test fixture after rebase onto dev

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 17:32:01 -04:00
jonesmarvin8
914f14e870
refactor(keycard_wallet): replace keycard-py with keycard-rs (#595)
* refactor(keycard_wallet): replace keycard-py (pyo3) with native keycard-rs

Rewrites the Keycard integration to talk to the LEE-flavored applet
directly from Rust via keycard-rs (pinned git dependency), dropping the
pyo3 shim, python_path.rs, and the vendored keycard-py Python library
entirely. Verified end-to-end against real hardware: pairing, PIN
verification, mnemonic loading, BIP340 Schnorr signing, and transfers
between keycard and public/private accounts.

Also cleans up the pyo3 usage that had leaked into wallet's signing
path (signing.rs, account_manager.rs) beyond the keycard CLI itself,
and trims wallet_with_keycard.sh's Python setup down to just pyscard,
which is only needed by the force_unpower.py test helper now.

* Updated to v2 secure communication

* ci: install libpcsclite-dev for pcsc crate builds

* docs(keycard): clarify personalization is mandatory and document default CA

Reinstalling the applet via `./gradlew install` wipes any existing
personalization regardless of firmware source, which wasn't previously
called out and is a common source of "card not available" confusion.
Also state plainly that personalization is required before any command
works, and document keycard-rs's actual baked-in default CA public key
instead of only describing the override mechanism.

Export KEYCARD_CA_PUBLIC_KEY in all keycard test scripts so they work
against the dev/test-CA personalization flow they rely on.

* fix(keycard): address PR #595 review comments

- Propagate the load_mnemonic error instead of swallowing it behind
  is_ok(), matching every other command handler in this file.
- Add deny.toml allowing the keycard-rs git source, fixing the
  source-not-allowed failure in `cargo deny check`. Licenses and
  advisories checks still have pre-existing, separate failures not
  addressed here.
- Drop the pinned rev for the keycard-rs git dependency so it tracks
  the upstream default branch instead.

* chore(deny): trim deny.toml to essentials and allow all in-use licenses

Replace the full cargo-deny init template with just the two sections
that matter: the keycard-rs git-source allowance, and an explicit
license allow-list covering every license currently in the dependency
tree. cargo deny check now passes on sources, bans, and licenses;
advisories still fails on a pre-existing, unrelated RUSTSEC advisory.

* fix(deny): remove second config and add source to the original one

* chore: pin keycard-rs dependency and fix factory-reset debug-gate doc

* chore: regenerate test fixture and lockfile after rebase onto dev

---------

Co-authored-by: Daniil Polyakov <arjentix@gmail.com>
2026-07-23 15:50:30 -04:00
jonesmarvin8
7bc4c460a2
fix!(state_machine): reject public transactions that silently drop a d… (#625)
* fix(state_machine): reject public transactions that silently drop a declared account

ValidatedStateDiff::from_public_transaction never checked that the accounts
touched in a program's output matched the caller-declared message.account_ids
— it just folded whatever pairs the program returned into the diff. A program
(or a macro-generated dispatcher wrapping one) that silently drops an account
from both sides of its own output together stays internally consistent
(pre_states.len() == post_states.len()) and passes validate_execution's
existing checks, so the dropped account simply vanishes with no error.

Add a check after the chained-call loop: every account_id in
message.account_ids must appear in the final state_diff, or the transaction is
rejected with the new DeclaredAccountMissingFromOutput error.

Add a dropped_account test-guest program that reproduces the exact shape of
the bug (two pre_states in, one consistent (pre, post) pair out) and a
regression test proving the transaction is now rejected. Verified the test
fails with Ok(()) when the check is removed, and passes once it's restored.

* style: tighten comments and apply nightly rustfmt

Condense the explanatory comments on the new account-accounting check and the
dropped_account test guest, and fix imprecise wording (the account is dropped
from both pre_state and post_states together, not just pre_state). Also
applies cargo +nightly fmt's wrapping of the new error message.

* chore: regenerate test fixture after rebase onto dev
2026-07-23 12:09:16 -04:00
erhant
6a1a2911d9
Merge pull request #603 from logos-blockchain/erhant/lez-two-tip-chain-state
feat!(indexer, sequencer): common two-tip chain state for decentralized sequencing
2026-07-23 12:44:23 +03:00
erhant
2abb643129 chore: regenerate test fixture for the view-tag circuit 2026-07-23 12:01:24 +03:00
erhant
71b59ac1b8 fix(sequencer): add apply_produced which is like apply_adopted but for our own block, which is not in channel yet 2026-07-23 11:43:57 +03:00
erhant
1feebc1d91 fix(chain_state): dont allow same hash+msgId on a different blockId 2026-07-23 11:43:57 +03:00
erhant
caf38ebc0a chore: drop unused sequencer_service_protocol dep from integration_tests 2026-07-23 11:43:57 +03:00
erhant
8d09ffd733 feat(sequencer): two-tier chain state and multi-sequencer support
Decentralized-sequencing foundation: a shared chain_state crate (two-tier
head/final ChainState, apply_block, AcceptOutcome, StallReason, and the
absorbed channel-consistency machinery), turn-gated block production, the
publisher follow path for adopted/orphaned/finalized peer blocks, and
persistence that keeps disk order equal to apply order under the chain lock.

Rebased onto dev after #600/#606: chain_consistency is absorbed into
chain_state, the sequencer bootstrap's verify_and_reconstruct is re-wired
onto the two-tier ChainState (reconstruction applies channel history
through the final tier and persists via the follow-path primitives), and
test fixtures adopt the SequencerSetup builder extended with
with_bedrock_signing_key.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 11:43:57 +03:00
Artem Gureev
6987a38da3
Merge pull request #591 from logos-blockchain/artem/view-tag-randomization
feat(circuit): view tag randomization for updated accounts
2026-07-23 11:37:22 +04:00
Artem Gureev
0e4ab5006d feat(wallet): create a regular shared account under a supplied identifier 2026-07-22 22:31:32 +04:00
Artem Gureev
50a1972788 fix(wallet): catch up a shared account from genesis on registration 2026-07-22 22:31:32 +04:00
Artem Gureev
3474b375e4 test(circuit): view_tag is derived on init, passed through on update 2026-07-22 22:31:32 +04:00
agureev
61cad70f9b feat(circuit): supply a view_tag on private-account updates 2026-07-22 22:31:31 +04:00
Daniil Polyakov
b31ae10ee5
Merge pull request #606 from logos-blockchain/arjentix/sequencer-bootstrap
feat(sequencer): bootstrap state from Bedrock
2026-07-22 15:12:00 +03:00
Daniil Polyakov
e440430a50 feat(sequencer): add more reconstruction tests 2026-07-21 22:46:47 +03:00
Daniil Polyakov
61f17612d9 fix(storage): rename ZonCursor to ZoneAnchor 2026-07-21 22:46:47 +03:00
Daniil Polyakov
e3442c695f fix(sequencer): fix silent reconstruction when only genesis was committed 2026-07-21 22:46:47 +03:00
Daniil Polyakov
8fdc3f203d fix(sequencer): don't increment withdrawals count on reconstruction to prevent phantom counts 2026-07-21 22:46:47 +03:00
Daniil Polyakov
3e7e9ed4e1 fix(sequencer): fix double mint on deposit when reconstructing state 2026-07-21 22:46:47 +03:00
Daniil Polyakov
10e61bd354 fix(justfile): regenerate test fixture on artifacts rebuild 2026-07-21 22:46:47 +03:00
Daniil Polyakov
da2afba75a chore(lock): bump spin to 0.9.9 to satisfy cargo deny 2026-07-21 22:46:35 +03:00
Daniil Polyakov
2d5489c04e feat(sequencer): bootstrap state from Bedrock 2026-07-21 22:46:25 +03:00
Pravdyvy
ba43713328
Merge pull request #600 from logos-blockchain/Pravdyvy/multi-sequencer-client
feat(wallet)!: Multi-sequencer client
2026-07-21 14:30:27 +03:00
Pravdyvy
0b327795f4 fix(integration_tests): integration tests fix 2 2026-07-20 13:47:06 +03:00
Pravdyvy
231c2387e0 fix(integration_tests): integration tests fix 2026-07-20 12:26:42 +03:00
Pravdyvy
7b51d0c200 fix(wallet): removed redundant clones 2026-07-20 11:50:37 +03:00
Pravdyvy
eaa76f5e7e fix(wallet): suggestions 3 2026-07-20 11:34:05 +03:00
Pravdyvy
a0971018ea Merge branch 'dev' into Pravdyvy/multi-sequencer-client 2026-07-17 17:54:20 +03:00
Pravdyvy
1ac56373b6 fix:(wallet): suggestion 2 2026-07-17 17:44:09 +03:00
Pravdyvy
b3810ff77d fix(wallet): added client rotation 2026-07-17 17:31:11 +03:00
Pravdyvy
0bc08c7357 fix(wallet): suggestions 2026-07-17 16:57:12 +03:00
Daniil Polyakov
041cf68cd6
Merge pull request #618 from logos-blockchain/arjentix/ci-docker-image
feat(ci): use docker image for ci
2026-07-17 02:00:07 +03:00
Daniil Polyakov
2e80f4e8b2 feat(ci): pin versions of tools in ci image 2026-07-16 22:45:24 +03:00
Daniil Polyakov
56eb8d146f feat(ci): don't rebuild ci image twice for different jobs 2026-07-16 16:54:39 +03:00
Daniil Polyakov
f70b90981a fix(ci): add safe directory to git config for bench-regression job fix 2026-07-16 16:54:39 +03:00
Daniil Polyakov
e081205d95 fix(ci): run docker-dependent tests in the CI image via docker run 2026-07-16 16:54:39 +03:00
Daniil Polyakov
6dce78dd8b feat(ci): use docker image for ci 2026-07-16 16:54:39 +03:00
Moudy
390f4b48d9
Merge pull request #629 from logos-blockchain/fix-macos-metal-xcrun-cache
fix(macos): nuke xcrun cache
2026-07-16 14:48:00 +02:00
Siddarth Kumar
a7e06a6609
fix(macos): nuke xcrun cache 2026-07-16 17:10:21 +05:30
Pravdyvy
441e43ef91 Merge branch 'dev' into Pravdyvy/multi-sequencer-client 2026-07-15 16:40:38 +03:00
Pravdyvy
ea41d5a738
Merge pull request #582 from logos-blockchain/Pravdyvy/pda-account-id-generation
feat(wallet_ffi): pda account id generation in FFI
2026-07-15 16:18:23 +03:00
Pravdyvy
7cc094f3a4 fix(ci): fixtures and artifacts 2026-07-15 15:01:47 +03:00
Pravdyvy
7d0a2832d9 fix(deny): deny fix 2026-07-15 14:35:13 +03:00
Pravdyvy
ba741da37b Merge branch 'dev' into Pravdyvy/multi-sequencer-client 2026-07-15 13:45:44 +03:00
Pravdyvy
651229c454 fix(wallet_ffi): merge upfix 2026-07-15 13:35:53 +03:00
Pravdyvy
e4fd9b2397 Merge branch 'dev' into Pravdyvy/pda-account-id-generation 2026-07-15 12:57:16 +03:00
Artem Gureev
2dd472217f
Merge pull request #598 from logos-blockchain/artem/batched-merkle-proofs
feat!: batched merkle proof fetching
2026-07-15 10:04:39 +04:00
Pravdyvy
c3e8dd4040 fix(wallet): updated wallet config 2026-07-14 16:43:46 +03:00
Pravdyvy
f2a7cb45fd fix(fixtures): updated test fixtures 2026-07-14 14:53:07 +03:00