75 Commits

Author SHA1 Message Date
jonesmarvin8
6c0bd71523
refactor: PrivateUnauthorized authorization changed to true (#621)
* refactor: rename PrivateUnauthorized to PrivateForeignInit

The account_identity's is_authorized flag no longer determines
authorization for this variant, so keep the name tied to what
actually distinguishes it: no nsk, only npk (a foreign account init).

* chore: rebuild guest artifacts and bump spin to clear yanked advisory

Regenerate ELF artifacts after the PrivateForeignInit rename in lee_core
(compiled into every guest program), and update spin 0.9.8 -> 0.9.9 since
0.9.8 was yanked from crates.io, per cargo deny check advisories.

* test: align is_authorized with PrivateForeignInit's flipped semantics

Recipient pre-states built for PrivateForeignInit now need is_authorized:
true to match the assertion in output.rs. Also rewrites the boundary test
that checked the old invalid case to check the new one, and updates
stale "unauthorized" wording left over from the PrivateUnauthorized name.

* chore: rebuild guest artifacts

Reproducible across repeated local builds; likely toolchain drift since
the prior artifact commit rather than a source change, since no
guest-relevant source or Cargo.lock changed in between.

* fix(tests): align integration tests with PrivateForeignInit and regenerate fixture

prove_init_with_commitment_root (private.rs) and build_privacy_transaction
(tps.rs) still built PrivateForeignInit recipients with is_authorized: false,
same stale-semantics bug fixed earlier in the lee crate's own tests.

The prebuilt sequencer DB dump embeds program IDs derived from guest ELF
bytes, which shifted once the PrivateForeignInit rename changed lee_core
(compiled into every guest program). The stale dump caused widespread
"Unknown program" failures across integration test suites that exercise
deployed programs (wallet_ffi, auth_transfer, bridge, amm, token, pinata,
ata, indexer state-consistency checks). Regenerated via
`just regenerate-test-fixture`.

* fix(tests): rename leftover PrivateUnauthorized to PrivateForeignInit and regenerate fixture

* test: align is_authorized with PrivateForeignInit's flipped semantics

* chore: regenerate test fixture after rebase onto dev

* chore: regenerate test fixture after rebase onto dev

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 17:32:01 -04:00
jonesmarvin8
914f14e870
refactor(keycard_wallet): replace keycard-py with keycard-rs (#595)
* refactor(keycard_wallet): replace keycard-py (pyo3) with native keycard-rs

Rewrites the Keycard integration to talk to the LEE-flavored applet
directly from Rust via keycard-rs (pinned git dependency), dropping the
pyo3 shim, python_path.rs, and the vendored keycard-py Python library
entirely. Verified end-to-end against real hardware: pairing, PIN
verification, mnemonic loading, BIP340 Schnorr signing, and transfers
between keycard and public/private accounts.

Also cleans up the pyo3 usage that had leaked into wallet's signing
path (signing.rs, account_manager.rs) beyond the keycard CLI itself,
and trims wallet_with_keycard.sh's Python setup down to just pyscard,
which is only needed by the force_unpower.py test helper now.

* Updated to v2 secure communication

* ci: install libpcsclite-dev for pcsc crate builds

* docs(keycard): clarify personalization is mandatory and document default CA

Reinstalling the applet via `./gradlew install` wipes any existing
personalization regardless of firmware source, which wasn't previously
called out and is a common source of "card not available" confusion.
Also state plainly that personalization is required before any command
works, and document keycard-rs's actual baked-in default CA public key
instead of only describing the override mechanism.

Export KEYCARD_CA_PUBLIC_KEY in all keycard test scripts so they work
against the dev/test-CA personalization flow they rely on.

* fix(keycard): address PR #595 review comments

- Propagate the load_mnemonic error instead of swallowing it behind
  is_ok(), matching every other command handler in this file.
- Add deny.toml allowing the keycard-rs git source, fixing the
  source-not-allowed failure in `cargo deny check`. Licenses and
  advisories checks still have pre-existing, separate failures not
  addressed here.
- Drop the pinned rev for the keycard-rs git dependency so it tracks
  the upstream default branch instead.

* chore(deny): trim deny.toml to essentials and allow all in-use licenses

Replace the full cargo-deny init template with just the two sections
that matter: the keycard-rs git-source allowance, and an explicit
license allow-list covering every license currently in the dependency
tree. cargo deny check now passes on sources, bans, and licenses;
advisories still fails on a pre-existing, unrelated RUSTSEC advisory.

* fix(deny): remove second config and add source to the original one

* chore: pin keycard-rs dependency and fix factory-reset debug-gate doc

* chore: regenerate test fixture and lockfile after rebase onto dev

---------

Co-authored-by: Daniil Polyakov <arjentix@gmail.com>
2026-07-23 15:50:30 -04:00
Artem Gureev
0e4ab5006d feat(wallet): create a regular shared account under a supplied identifier 2026-07-22 22:31:32 +04:00
Artem Gureev
50a1972788 fix(wallet): catch up a shared account from genesis on registration 2026-07-22 22:31:32 +04:00
agureev
61cad70f9b feat(circuit): supply a view_tag on private-account updates 2026-07-22 22:31:31 +04:00
Pravdyvy
0b327795f4 fix(integration_tests): integration tests fix 2 2026-07-20 13:47:06 +03:00
Pravdyvy
231c2387e0 fix(integration_tests): integration tests fix 2026-07-20 12:26:42 +03:00
Pravdyvy
7b51d0c200 fix(wallet): removed redundant clones 2026-07-20 11:50:37 +03:00
Pravdyvy
eaa76f5e7e fix(wallet): suggestions 3 2026-07-20 11:34:05 +03:00
Pravdyvy
1ac56373b6 fix:(wallet): suggestion 2 2026-07-17 17:44:09 +03:00
Pravdyvy
b3810ff77d fix(wallet): added client rotation 2026-07-17 17:31:11 +03:00
Pravdyvy
0bc08c7357 fix(wallet): suggestions 2026-07-17 16:57:12 +03:00
Pravdyvy
ba741da37b Merge branch 'dev' into Pravdyvy/multi-sequencer-client 2026-07-15 13:45:44 +03:00
Pravdyvy
c3e8dd4040 fix(wallet): updated wallet config 2026-07-14 16:43:46 +03:00
Pravdyvy
ac2bf7f996 Merge branch 'dev' into Pravdyvy/multi-sequencer-client 2026-07-14 13:19:04 +03:00
Pravdyvy
bf237daf71 fix(tintegration_tests): tests work 2026-07-14 13:10:32 +03:00
Artem Gureev
e408c05297 feat(wallet): validate batched proofs against the root 2026-07-13 13:34:03 +00:00
Artem Gureev
8545ff1466 feat!(sequencer): serve proofs and root in one getProofsAndRoot RPC
BREAKING:

Before: An endpoint exposing getting a single proof for a commitment
existed.

After: There is one endpoint where you give a vector of commitments
and a vector of Maybe proofs back alongside the shared root.

Mitigation: Use the new rpc endpoint with the appopriate vector.
2026-07-13 13:34:03 +00:00
Pravdyvy
1615a06604 fix(wallet_ffi): tests and leading algorithm fixes 2026-07-13 15:37:25 +03:00
agureev
ae391612bd Merge remote-tracking branch 'origin/dev' into artem/change-wallet-balance-fetch 2026-07-13 15:19:06 +04:00
Pravdyvy
daabe7f29e fix(wallet): errors fixed, metric updates are now interiorly mutable 2026-07-13 12:52:57 +03:00
Pravdyvy
675e845237 fix(wallet_ffi): wallet_ffi fix 2026-07-10 16:21:03 +03:00
Pravdyvy
562696929c Merge branch 'dev' into Pravdyvy/multi-sequencer-client 2026-07-10 13:02:17 +03:00
Pravdyvy
d832559cc3 feat(wallet): leader choosing algorithm 2026-07-09 15:58:29 +03:00
agureev
a3593e36b7 refactor: change sync function name 2026-07-09 14:15:39 +04:00
Daniil Polyakov
7408955f08 feat!(wallet): wait for deploy tx inclusion in block
Breaking:
  1. Now a lot of wallet commands return `TransactionExecuted`, instead of `Empty`.
  2. Sequencer's `getTransaction()` RPC response changed from `tx` to `(tx, block_id)`
2026-07-09 00:32:53 +03:00
agureev
24faedd686 feat: relax the mask length requirement 2026-07-09 00:48:27 +04:00
agureev
bf86d0c05b Merge remote-tracking branch 'origin/dev' into artem/change-wallet-balance-fetch 2026-07-08 22:55:15 +04:00
Artem Gureev
b31aecd2c0 feat(wallet): reject length-mismatched privacy transactions 2026-07-08 18:45:27 +04:00
agureev
1bd396006b docs: fix typos 2026-07-08 16:36:05 +04:00
Pravdyvy
40fe9ff209 feat(wallet): metrics fetching and callibration 2026-07-08 14:18:52 +03:00
Pravdyvy
10c9d89ec8 feat(wallet): multi-sequencer client stub added 2026-07-07 15:14:49 +03:00
agureev
8e084e22d1 Merge remote-tracking branch 'origin/dev' into artem/viewing-key-binding 2026-07-02 20:04:30 +04:00
Artem Gureev
6c1dd53aa5 refactor(wallet): thread &Message through the view-tag sync passes 2026-07-02 14:13:30 +04:00
Artem Gureev
b6e148249e refactor(wallet): inline the hit loop in sync_updates_via_nullifiers 2026-07-02 14:13:29 +04:00
Artem Gureev
d2633af413 refactor(wallet): introduce a NullifierIndex struct 2026-07-01 22:24:41 +04:00
Artem Gureev
15f6306362 refactor(wallet): place private_accounts next to private_account 2026-07-01 21:57:08 +04:00
Artem Gureev
2a9c8574cd refactor(wallet): compute update nullifiers inlined 2026-07-01 21:57:06 +04:00
agureev
296afdc4a3 Merge remote-tracking branch 'origin/dev' into artem/change-wallet-balance-fetch 2026-07-01 21:12:14 +04:00
agureev
cb6d21a937 refactor: docs, renaming 2026-07-01 20:58:03 +04:00
Artem Gureev
ca8acb1c38 test(wallet): cover shared-account update sync 2026-07-01 19:36:17 +04:00
Artem Gureev
51cc82b50b docs: document new methods 2026-07-01 19:34:15 +04:00
Artem Gureev
f32e6bb178 refactor(key_protocol): use SharedAccountTag seed in GroupKeyHolder 2026-07-01 19:34:15 +04:00
Artem Gureev
d8e990a68f test(wallet): cover nullifier-based update sync 2026-07-01 19:34:04 +04:00
Artem Gureev
6bb2d7ffc3 refactor(wallet): move nullifier-watch sync onto UserKeyChain 2026-07-01 19:16:43 +04:00
Artem Gureev
5fda1608a3 feat(wallet): skip nullifier-handled slots in the view-tag pass 2026-07-01 19:16:42 +04:00
Artem Gureev
a24d2ca4ec fix(wallet): make nullifier watch updatable during sync 2026-07-01 19:16:42 +04:00
Artem Gureev
6025cb53ad feat(wallet): detect private-account updates via nullifier scanning 2026-07-01 19:16:41 +04:00
Artem Gureev
d09a4215d8 refactor(wallet): use shared-key derivation helper 2026-07-01 19:16:40 +04:00
Artem Gureev
eea069c663 feat(wallet): nullifier-watch for updated private accounts 2026-07-01 19:16:39 +04:00