refactor: PrivateUnauthorized authorization changed to true (#621)

* refactor: rename PrivateUnauthorized to PrivateForeignInit

The account_identity's is_authorized flag no longer determines
authorization for this variant, so keep the name tied to what
actually distinguishes it: no nsk, only npk (a foreign account init).

* chore: rebuild guest artifacts and bump spin to clear yanked advisory

Regenerate ELF artifacts after the PrivateForeignInit rename in lee_core
(compiled into every guest program), and update spin 0.9.8 -> 0.9.9 since
0.9.8 was yanked from crates.io, per cargo deny check advisories.

* test: align is_authorized with PrivateForeignInit's flipped semantics

Recipient pre-states built for PrivateForeignInit now need is_authorized:
true to match the assertion in output.rs. Also rewrites the boundary test
that checked the old invalid case to check the new one, and updates
stale "unauthorized" wording left over from the PrivateUnauthorized name.

* chore: rebuild guest artifacts

Reproducible across repeated local builds; likely toolchain drift since
the prior artifact commit rather than a source change, since no
guest-relevant source or Cargo.lock changed in between.

* fix(tests): align integration tests with PrivateForeignInit and regenerate fixture

prove_init_with_commitment_root (private.rs) and build_privacy_transaction
(tps.rs) still built PrivateForeignInit recipients with is_authorized: false,
same stale-semantics bug fixed earlier in the lee crate's own tests.

The prebuilt sequencer DB dump embeds program IDs derived from guest ELF
bytes, which shifted once the PrivateForeignInit rename changed lee_core
(compiled into every guest program). The stale dump caused widespread
"Unknown program" failures across integration test suites that exercise
deployed programs (wallet_ffi, auth_transfer, bridge, amm, token, pinata,
ata, indexer state-consistency checks). Regenerated via
`just regenerate-test-fixture`.

* fix(tests): rename leftover PrivateUnauthorized to PrivateForeignInit and regenerate fixture

* test: align is_authorized with PrivateForeignInit's flipped semantics

* chore: regenerate test fixture after rebase onto dev

* chore: regenerate test fixture after rebase onto dev

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
jonesmarvin8 2026-07-23 17:32:01 -04:00 committed by GitHub
parent 914f14e870
commit 6c0bd71523
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
26 changed files with 95 additions and 95 deletions

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

View File

@ -624,7 +624,7 @@ async fn prove_init_with_commitment_root(
let npk = NullifierPublicKey::from(&nsk);
let vpk = ViewingPublicKey::from_bytes(vec![4_u8; 1184]).unwrap();
let recipient_account_id = AccountId::for_regular_private_account(&npk, &vpk, 0);
let recipient = AccountWithMetadata::new(Account::default(), false, recipient_account_id);
let recipient = AccountWithMetadata::new(Account::default(), true, recipient_account_id);
let (output, _) = execute_and_prove(
vec![sender_pre, recipient],
@ -633,7 +633,7 @@ async fn prove_init_with_commitment_root(
})?,
vec![
InputAccountIdentity::Public,
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk,
random_seed: [0; 32],
npk,

View File

@ -272,7 +272,7 @@ fn build_privacy_transaction() -> PrivacyPreservingTransaction {
let recipient_npk = NullifierPublicKey::from(&recipient_nsk);
let recipient_pre = AccountWithMetadata::new(
Account::default(),
false,
true,
AccountId::for_regular_private_account(&recipient_npk, &recipient_vpk, 0),
);
@ -299,7 +299,7 @@ fn build_privacy_transaction() -> PrivacyPreservingTransaction {
membership_proof: proof,
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_vpk,
random_seed: [0; 32],
npk: recipient_npk,

View File

@ -119,7 +119,7 @@ pub fn compute_circuit_output(
new_nonce,
);
}
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk,
random_seed,
npk,
@ -135,8 +135,8 @@ pub fn compute_circuit_output(
"Found new private account with non default values",
);
assert!(
!pre_state.is_authorized,
"Found new private account marked as authorized."
pre_state.is_authorized,
"Found new private account marked as unauthorized."
);
let new_nullifier = (

View File

@ -49,7 +49,7 @@ pub enum InputAccountIdentity {
},
/// Init of a standalone private account the caller does not own (e.g. a recipient who
/// doesn't yet exist on chain). No `nsk`, no membership proof.
PrivateUnauthorized {
PrivateForeignInit {
vpk: ViewingPublicKey,
random_seed: [u8; 32],
npk: NullifierPublicKey,
@ -127,7 +127,7 @@ impl InputAccountIdentity {
Self::Public
| Self::PrivateAuthorizedInit { .. }
| Self::PrivateAuthorizedUpdate { .. }
| Self::PrivateUnauthorized { .. } => None,
| Self::PrivateForeignInit { .. } => None,
}
}
}

View File

@ -60,7 +60,7 @@ fn prove_privacy_preserving_execution_circuit_public_and_private_pre_accounts()
let recipient_account_id =
AccountId::for_regular_private_account(&recipient_keys.npk(), &recipient_keys.vpk(), 0);
let recipient = AccountWithMetadata::new(Account::default(), false, recipient_account_id);
let recipient = AccountWithMetadata::new(Account::default(), true, recipient_account_id);
let balance_to_move: u128 = 37;
@ -89,7 +89,7 @@ fn prove_privacy_preserving_execution_circuit_public_and_private_pre_accounts()
Program::serialize_instruction(balance_to_move).unwrap(),
vec![
InputAccountIdentity::Public,
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -144,7 +144,7 @@ fn prove_privacy_preserving_execution_circuit_fully_private() {
let recipient_account_id =
AccountId::for_regular_private_account(&recipient_keys.npk(), &recipient_keys.vpk(), 0);
let recipient = AccountWithMetadata::new(Account::default(), false, recipient_account_id);
let recipient = AccountWithMetadata::new(Account::default(), true, recipient_account_id);
let balance_to_move: u128 = 37;
let mut commitment_set = CommitmentSet::with_capacity(2);
@ -205,7 +205,7 @@ fn prove_privacy_preserving_execution_circuit_fully_private() {
.expect("sender's commitment must be in the set"),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -249,12 +249,12 @@ fn init_note_view_tag_is_derived_from_account_keys() {
let keys = test_private_account_keys_1();
let identifier: u128 = 0;
let account_id = AccountId::for_regular_private_account(&keys.npk(), &keys.vpk(), identifier);
let account = AccountWithMetadata::new(Account::default(), false, account_id);
let account = AccountWithMetadata::new(Account::default(), true, account_id);
let (output, proof) = execute_and_prove(
vec![account],
Program::serialize_instruction(()).unwrap(),
vec![InputAccountIdentity::PrivateUnauthorized {
vec![InputAccountIdentity::PrivateForeignInit {
vpk: keys.vpk(),
random_seed: [0; 32],
npk: keys.npk(),
@ -318,7 +318,7 @@ fn circuit_fails_when_chained_validity_windows_have_empty_intersection() {
let account_keys = test_private_account_keys_1();
let pre = AccountWithMetadata::new(
Account::default(),
false,
true,
AccountId::for_regular_private_account(&account_keys.npk(), &account_keys.vpk(), 0),
);
@ -342,7 +342,7 @@ fn circuit_fails_when_chained_validity_windows_have_empty_intersection() {
let result = execute_and_prove(
vec![pre],
instruction,
vec![InputAccountIdentity::PrivateUnauthorized {
vec![InputAccountIdentity::PrivateForeignInit {
vpk: account_keys.vpk(),
random_seed: [0; 32],
npk: account_keys.npk(),
@ -493,7 +493,7 @@ fn private_pda_withdraw() {
/// Shared regular private account: receives funds via `authenticated_transfer` directly,
/// no custom program needed. This demonstrates the non-PDA shared account flow where
/// keys are derived from GMS via `derive_keys_for_shared_account`. The shared account
/// uses the standard unauthorized private account path and works with auth-transfer's
/// uses the standard foreign private account path and works with auth-transfer's
/// transfer path like any other private account.
#[test]
fn shared_account_receives_via_simple_transfer() {
@ -514,9 +514,9 @@ fn shared_account_receives_via_simple_transfer() {
sender_id,
);
// Recipient: shared private account (new, unauthorized)
// Recipient: shared private account (new, foreign)
let shared_account_id = AccountId::from((&shared_npk, &shared_keys.vpk(), shared_identifier));
let recipient = AccountWithMetadata::new(Account::default(), false, shared_account_id);
let recipient = AccountWithMetadata::new(Account::default(), true, shared_account_id);
let balance_to_move: u128 = 100;
let instruction = Program::serialize_instruction(balance_to_move).unwrap();
@ -526,7 +526,7 @@ fn shared_account_receives_via_simple_transfer() {
instruction,
vec![
InputAccountIdentity::Public,
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: shared_keys.vpk(),
random_seed: [0; 32],
npk: shared_npk,
@ -578,10 +578,10 @@ fn private_authorized_init_encrypts_regular_kind_with_identifier() {
);
}
/// `PrivateUnauthorized` with a non-default identifier produces a ciphertext that decrypts
/// `PrivateForeignInit` with a non-default identifier produces a ciphertext that decrypts
/// to `PrivateAccountKind::Regular` carrying the correct identifier.
#[test]
fn private_unauthorized_init_encrypts_regular_kind_with_identifier() {
fn private_foreign_init_encrypts_regular_kind_with_identifier() {
let program = crate::test_methods::claimer();
let keys = test_private_account_keys_1();
let identifier: u128 = 99;
@ -592,12 +592,12 @@ fn private_unauthorized_init_encrypts_regular_kind_with_identifier() {
&Nonce::private_account_nonce_init(&recipient_id),
);
let ssk = SharedSecretKey::encapsulate_deterministic(&keys.vpk(), &esk).0;
let recipient = AccountWithMetadata::new(Account::default(), false, recipient_id);
let recipient = AccountWithMetadata::new(Account::default(), true, recipient_id);
let (output, _) = execute_and_prove(
vec![recipient],
Program::serialize_instruction(()).unwrap(),
vec![InputAccountIdentity::PrivateUnauthorized {
vec![InputAccountIdentity::PrivateForeignInit {
vpk: keys.vpk(),
random_seed: [0; 32],
npk: keys.npk(),
@ -731,7 +731,7 @@ fn private_pda_init_identifier_mismatch_fails() {
let npk = keys.npk();
let seed = PdaSeed::new([42; 32]);
let account_id = AccountId::for_private_pda(&program.id(), &seed, &npk, &keys.vpk(), 5);
let pre_state = AccountWithMetadata::new(Account::default(), false, account_id);
let pre_state = AccountWithMetadata::new(Account::default(), true, account_id);
let result = execute_and_prove(
vec![pre_state],

View File

@ -49,7 +49,7 @@ fn circuit_fails_if_invalid_auth_keys_are_provided() {
);
let private_account_2 = AccountWithMetadata::new(
Account::default(),
false,
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -69,7 +69,7 @@ fn circuit_fails_if_invalid_auth_keys_are_provided() {
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -103,7 +103,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_balance_is_provid
balance: 1,
..Account::default()
},
false,
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -119,7 +119,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_balance_is_provid
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -153,7 +153,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_program_owner_is_
program_owner: [0, 1, 2, 3, 4, 5, 6, 7],
..Account::default()
},
false,
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -169,7 +169,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_program_owner_is_
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -203,7 +203,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_data_is_provided(
data: b"hola mundo".to_vec().try_into().unwrap(),
..Account::default()
},
false,
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -219,7 +219,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_data_is_provided(
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -253,6 +253,54 @@ fn circuit_should_fail_if_new_private_account_with_non_default_nonce_is_provided
nonce: Nonce(0xdead_beef),
..Account::default()
},
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
let result = execute_and_prove(
vec![private_account_1, private_account_2],
Program::serialize_instruction(10_u128).unwrap(),
vec![
InputAccountIdentity::PrivateAuthorizedUpdate {
vpk: sender_keys.vpk(),
random_seed: [0; 32],
view_tag: 0,
nsk: sender_keys.nsk,
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
identifier: 0,
commitment_root: DUMMY_COMMITMENT_HASH,
},
],
&program.into(),
);
assert!(matches!(result, Err(LeeError::CircuitProvingError(_))));
}
#[test]
fn circuit_should_fail_if_new_private_account_is_provided_with_default_values_but_marked_as_unauthorized()
{
let program = crate::test_methods::simple_balance_transfer();
let sender_keys = test_private_account_keys_1();
let recipient_keys = test_private_account_keys_2();
let private_account_1 = AccountWithMetadata::new(
Account {
program_owner: program.id(),
balance: 100,
..Account::default()
},
true,
(&sender_keys.npk(), &sender_keys.vpk(), 0),
);
let private_account_2 = AccountWithMetadata::new(
Account::default(),
// This should be set to true in normal circumstances
false,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -269,55 +317,7 @@ fn circuit_should_fail_if_new_private_account_with_non_default_nonce_is_provided
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
identifier: 0,
commitment_root: DUMMY_COMMITMENT_HASH,
},
],
&program.into(),
);
assert!(matches!(result, Err(LeeError::CircuitProvingError(_))));
}
#[test]
fn circuit_should_fail_if_new_private_account_is_provided_with_default_values_but_marked_as_authorized()
{
let program = crate::test_methods::simple_balance_transfer();
let sender_keys = test_private_account_keys_1();
let recipient_keys = test_private_account_keys_2();
let private_account_1 = AccountWithMetadata::new(
Account {
program_owner: program.id(),
balance: 100,
..Account::default()
},
true,
(&sender_keys.npk(), &sender_keys.vpk(), 0),
);
let private_account_2 = AccountWithMetadata::new(
Account::default(),
// This should be set to false in normal circumstances
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
let result = execute_and_prove(
vec![private_account_1, private_account_2],
Program::serialize_instruction(10_u128).unwrap(),
vec![
InputAccountIdentity::PrivateAuthorizedUpdate {
vpk: sender_keys.vpk(),
random_seed: [0; 32],
view_tag: 0,
nsk: sender_keys.nsk,
membership_proof: (0, vec![]),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -781,7 +781,7 @@ fn private_unauthorized_uninitialized_account_can_still_be_claimed() {
// remains allowed.
let unauthorized_account = AccountWithMetadata::new(
Account::default(),
false,
true,
(&private_keys.npk(), &private_keys.vpk(), 0),
);
@ -790,7 +790,7 @@ fn private_unauthorized_uninitialized_account_can_still_be_claimed() {
let (output, proof) = execute_and_prove(
vec![unauthorized_account],
Program::serialize_instruction(()).unwrap(),
vec![InputAccountIdentity::PrivateUnauthorized {
vec![InputAccountIdentity::PrivateForeignInit {
vpk: private_keys.vpk(),
random_seed: [0; 32],
npk: private_keys.npk(),

View File

@ -270,7 +270,7 @@ fn shielded_balance_transfer_for_tests(
let recipient = AccountWithMetadata::new(
Account::default(),
false,
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -279,7 +279,7 @@ fn shielded_balance_transfer_for_tests(
Program::serialize_instruction(balance_to_move).unwrap(),
vec![
InputAccountIdentity::Public,
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),
@ -320,7 +320,7 @@ fn private_balance_transfer_for_tests(
);
let recipient_pre = AccountWithMetadata::new(
Account::default(),
false,
true,
(&recipient_keys.npk(), &recipient_keys.vpk(), 0),
);
@ -338,7 +338,7 @@ fn private_balance_transfer_for_tests(
.expect("sender's commitment must be in state"),
identifier: 0,
},
InputAccountIdentity::PrivateUnauthorized {
InputAccountIdentity::PrivateForeignInit {
vpk: recipient_keys.vpk(),
random_seed: [0; 32],
npk: recipient_keys.npk(),

View File

@ -126,7 +126,7 @@ fn validity_window_works_in_privacy_preserving_transactions(
let account_keys = test_private_account_keys_1();
let pre = AccountWithMetadata::new(
Account::default(),
false,
true,
(&account_keys.npk(), &account_keys.vpk(), 0),
);
let mut state = V03State::new().with_test_programs();
@ -138,7 +138,7 @@ fn validity_window_works_in_privacy_preserving_transactions(
let (output, proof) = crate::privacy_preserving_transaction::circuit::execute_and_prove(
vec![pre],
Program::serialize_instruction(instruction).unwrap(),
vec![InputAccountIdentity::PrivateUnauthorized {
vec![InputAccountIdentity::PrivateForeignInit {
vpk: account_keys.vpk(),
random_seed: [0; 32],
npk: account_keys.npk(),
@ -191,7 +191,7 @@ fn timestamp_validity_window_works_in_privacy_preserving_transactions(
let account_keys = test_private_account_keys_1();
let pre = AccountWithMetadata::new(
Account::default(),
false,
true,
(&account_keys.npk(), &account_keys.vpk(), 0),
);
let mut state = V03State::new().with_test_programs();
@ -203,7 +203,7 @@ fn timestamp_validity_window_works_in_privacy_preserving_transactions(
let (output, proof) = crate::privacy_preserving_transaction::circuit::execute_and_prove(
vec![pre],
Program::serialize_instruction(instruction).unwrap(),
vec![InputAccountIdentity::PrivateUnauthorized {
vec![InputAccountIdentity::PrivateForeignInit {
vpk: account_keys.vpk(),
random_seed: [0; 32],
npk: account_keys.npk(),

View File

@ -256,7 +256,7 @@ impl AccountManager {
identifier,
} => {
let acc = lee_core::account::Account::default();
let auth_acc = AccountWithMetadata::new(acc, false, (&npk, &vpk, identifier));
let auth_acc = AccountWithMetadata::new(acc, true, (&npk, &vpk, identifier));
let mut random_seed: [u8; 32] = [0; 32];
OsRng.fill_bytes(&mut random_seed);
let pre = AccountPreparedData {
@ -437,7 +437,7 @@ impl AccountManager {
identifier: pre.identifier,
commitment_root: self.dummy_commitment_root,
},
(None, _) => InputAccountIdentity::PrivateUnauthorized {
(None, _) => InputAccountIdentity::PrivateForeignInit {
vpk: pre.vpk.clone(),
random_seed: pre.random_seed,
npk: pre.npk,