Skip to content

CI rehearsal only (do not merge) - #20

Closed
michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a4
Closed

michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a4

Conversation

@michael-moffett

Copy link
Copy Markdown
Member

Fork CI only. Do not merge.

Add a `surfnet_setMint` cheatcode that creates or patches a mint, optionally writing the Token-2022 `ConfidentialTransferMint` extension (authority, auditor ElGamal pubkey, auto-approve).

Lead 3 of : builders must fork a mainnet mint today because there is no way to spin up a confidential-capable mint with a chosen auditor and decimals.
@greptile-apps

greptile-apps Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 3/5

The PR should not merge until setMint rejects mismatched existing mint owners and unsupported token programs for new mints.

Findings

  1. P1 Base updates skip owner validation ▶
  2. P1 Unsupported programs receive mint accounts ▶
  3. P2 Configured auditor cannot be cleared ▶

Summary

Adds surfnet_setMint to create or patch SPL Token and Token-2022 mints, including confidential-transfer mint configuration, and exposes the method and update types through the Node SDK.

  • Preserves existing mint extensions and tops up lamports to the rent floor.
  • Adds Rust tests for mint creation, extension updates, and confidential token-account use.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A["setMint(mint, update, tokenProgram?)"] --> B{"Mint exists?"}
  B -- No --> C["Create initialized mint"]
  B -- Yes --> D["Read existing mint data"]
  C --> E["Apply base-field update"]
  D --> E
  E --> F{"Confidential update?"}
  F -- Yes --> G["Merge Token-2022 extension"]
  F -- No --> H["Preserve existing extension bytes"]
  G --> I["Top up rent and write account"]
  H --> I
Loading

Reviews (1) · Last reviewed commit: "feat(core): surfnet_setMint cheatcode wi..."

// A mint's address is not derived from the token program, so an
// existing mint may belong to another one, which would never
// read the Token-2022 extension written here.
if confidential.is_some() && account.owner != token_program_id {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Base updates skip owner validation When an existing mint is owned by Token-2022 but tokenProgram is omitted, this check is skipped because the update is not confidential. setMint changes the Token-2022 mint and returns success even though the request defaulted to SPL Token. It can also change another program-owned account if its data decodes as a mint. Check ownership for base-field updates too.

Comment on lines +1982 to +1988
let token_program_id = match some_token_program_str {
Some(token_program_str) => match verify_pubkey(&token_program_str) {
Ok(res) => res,
Err(e) => return e.into(),
},
None => spl_token_interface::id(),
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Unsupported programs receive mint accounts When creating a mint, tokenProgram accepts any valid public key. For every program other than Token-2022, the new account receives SPL Token mint data but is owned by the supplied program. An unrelated program cannot use that account as a token mint, yet setMint returns success. Reject unsupported program IDs before creating the account.

Comment thread crates/types/src/types.rs
Comment on lines +1277 to +1280
/// The auditor's ElGamal public key (base58 or base64, 32 bytes), which every
/// confidential transfer on this mint also encrypts its amount to. Omitted
/// keeps the current value, null (no auditor) when first written.
pub auditor_elgamal_pubkey: Option<String>,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Configured auditor cannot be cleared Once auditorElgamalPubkey is set, this update type provides no way to restore the no-auditor state. Omitting it or sending JSON null preserves the existing key. This makes tests that need to remove a configured auditor use another way to change the mint; provide an explicit clear value, as mintAuthority does.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant