ChainedCall.pre_states: Vec<AccountWithMetadata> becomes pre_state_refs: Vec<AccountId>. A calling program no longer supplies the concrete account value (or an is_authorized claim) for an account it hands to a chained call — it only names which account, and the protocol (sequencer for public transactions, host driver for privacy-preserving ones) resolves the real, currently-tracked value itself before invoking the callee. This removes two things simultaneously: the burden on guest programs to predict another call's outcome before it happens (the calling program previously had no reliable way to know it), and the ability to supply a stale or entirely fabricated account value at all. The malicious_injector/malicious_launderer guest programs and malicious_authorization_changer, which existed specifically to demonstrate that forgery, are deleted — the attack they showed is now a compile-time impossibility rather than something caught after the fact by a runtime check. The privacy circuit itself (execution_state.rs) needed no logic changes: it never trusted a caller-supplied pre-state in the first place, only the callee's own proven echo against its internally tracked state. The public path already had the tracking map it needed (state_diff); the privacy host driver gained one (materialized_state), plus first-sighting position tracking so a chained call's private-PDA authorization can be verified the same way the circuit derives it internally. Regenerates all lee_core/lez guest artifacts and the prebuilt sequencer db fixture via `just build-artifacts`, required since ChainedCall's shape is part of the proven wire format.
Programs
This crate serves two purposes at once:
- Provide one entrypoint for
cargo risczero buildto build guest binaries used in LEZ in one shot. - Provide access to the built binaries wrapped with
Programtype.
Binaries
This crate contains binaries taken from sub-directories: one per each program. This binaries are meant to be compiled with cargo risczero build. No other use is intended for them.
Library
You may import this crate as a library but it will only make sense if you enable artifacts feature flag.
Enabling this flag will make crate expect that binaries where already built and put in the right place (use just build-artifacts for that).
Why not just risc0_build::embed_methods() ?
Because this will either provide non-deterministic guest build or requires Docker. And forcing to use Docker to build the project is not an option for us especially because we also build Docker images for our services, which would mean we would have to call docker from docker (and this is not really feasible).
risc0_build::embed_methods() works well when you don't need deterministic build or Docker is not a problem. This is the case for our tests and we use it there.