CI rehearsal only (do not merge) - #25
michael-moffett wants to merge 1 commit into
Conversation
Add a `surfnet_setMint` cheatcode that creates or patches a mint, optionally writing the Token-2022 `ConfidentialTransferMint` extension (authority, auditor ElGamal pubkey, auto-approve). Lead 3 of : builders must fork a mainnet mint today because there is no way to spin up a confidential-capable mint with a chosen auditor and decimals.
|
| }) | ||
| .transpose()?; | ||
|
|
||
| let extension_types = [ExtensionType::ConfidentialTransferMint]; |
There was a problem hiding this comment.
Existing mint extensions disappear
When setMint adds confidential support to an existing Token-2022 mint, this builder creates data containing only the confidential extension. If the mint had a transfer-fee configuration, that configuration disappears, so subsequent account setup and transfers no longer use the configured fee. Preserve the existing extensions or reject this update.
| ct.authority = authority.map(Into::into).unwrap_or_default(); | ||
| ct.auto_approve_new_accounts = conf.auto_approve_new_accounts.unwrap_or(true).into(); | ||
| ct.auditor_elgamal_pubkey = auditor_elgamal_pubkey | ||
| .map(|key| PodElGamalPubkey::from(key).into()) | ||
| .unwrap_or_default(); |
There was a problem hiding this comment.
Partial updates reset confidential settings
On an existing confidential mint, supplying just a new confidential.authority rebuilds the extension with no auditor and with autoApproveNewAccounts set to true. Omitted fields therefore do not retain their values as setMint promises; a partial update can silently remove the auditor or change how new accounts are approved.
| account.owner | ||
| ))); | ||
| } | ||
| account.lamports = lamports; |
There was a problem hiding this comment.
Mint updates discard excess lamports
When an existing mint holds more than the rent-exempt minimum, even a decimals-only setMint call replaces its lamport balance with that minimum. The excess balance is lost when the update is applied. Preserve the existing balance when updating a mint, adjusting it only if the new allocation requires more lamports.
| } else { | ||
| Self::SplToken(spl_token_interface::state::Mint { | ||
| is_initialized: true, | ||
| ..Default::default() | ||
| }) |
There was a problem hiding this comment.
Unsupported programs create unusable mints
A caller can supply a program ID other than SPL Token or Token-2022, but this fallback still creates an SPL Token-shaped mint owned by that program and reports success. SPL Token cannot use an account it does not own, while the supplied program need not understand this data. Reject unsupported IDs so callers do not end up with an unusable mint.
Fork CI only. Do not merge.