CI rehearsal only (do not merge) - #20
michael-moffett wants to merge 1 commit into
Conversation
Add a `surfnet_setMint` cheatcode that creates or patches a mint, optionally writing the Token-2022 `ConfidentialTransferMint` extension (authority, auditor ElGamal pubkey, auto-approve). Lead 3 of : builders must fork a mainnet mint today because there is no way to spin up a confidential-capable mint with a chosen auditor and decimals.
|
| // A mint's address is not derived from the token program, so an | ||
| // existing mint may belong to another one, which would never | ||
| // read the Token-2022 extension written here. | ||
| if confidential.is_some() && account.owner != token_program_id { |
There was a problem hiding this comment.
Base updates skip owner validation When an existing mint is owned by Token-2022 but
tokenProgram is omitted, this check is skipped because the update is not confidential. setMint changes the Token-2022 mint and returns success even though the request defaulted to SPL Token. It can also change another program-owned account if its data decodes as a mint. Check ownership for base-field updates too.
| let token_program_id = match some_token_program_str { | ||
| Some(token_program_str) => match verify_pubkey(&token_program_str) { | ||
| Ok(res) => res, | ||
| Err(e) => return e.into(), | ||
| }, | ||
| None => spl_token_interface::id(), | ||
| }; |
There was a problem hiding this comment.
Unsupported programs receive mint accounts When creating a mint,
tokenProgram accepts any valid public key. For every program other than Token-2022, the new account receives SPL Token mint data but is owned by the supplied program. An unrelated program cannot use that account as a token mint, yet setMint returns success. Reject unsupported program IDs before creating the account.
| /// The auditor's ElGamal public key (base58 or base64, 32 bytes), which every | ||
| /// confidential transfer on this mint also encrypts its amount to. Omitted | ||
| /// keeps the current value, null (no auditor) when first written. | ||
| pub auditor_elgamal_pubkey: Option<String>, |
There was a problem hiding this comment.
Configured auditor cannot be cleared Once
auditorElgamalPubkey is set, this update type provides no way to restore the no-auditor state. Omitting it or sending JSON null preserves the existing key. This makes tests that need to remove a configured auditor use another way to change the mint; provide an explicit clear value, as mintAuthority does.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Fork CI only. Do not merge.