Skip to content

CI rehearsal only (do not merge) - #25

Closed
michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a9
Closed

michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a9

Conversation

@michael-moffett

Copy link
Copy Markdown
Member

Fork CI only. Do not merge.

Add a `surfnet_setMint` cheatcode that creates or patches a mint, optionally writing the Token-2022 `ConfidentialTransferMint` extension (authority, auditor ElGamal pubkey, auto-approve).

Lead 3 of : builders must fork a mainnet mint today because there is no way to spin up a confidential-capable mint with a chosen auditor and decimals.
@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 2/5

[High risk] Adds a new test-only cheatcode for mint configuration.

The PR should not merge while updates can discard existing mint configuration and lamports.

Findings

  1. P1 Existing mint extensions disappear ▶
  2. P1 Partial updates reset confidential settings ▶
  3. P1 Mint updates discard excess lamports ▶
  4. P2 Unsupported programs create unusable mints ▶

Summary

Adds surfnet_setMint to create or update token mints, including a Token-2022 confidential-transfer extension, and exposes the method and update types through the Node SDK.

  • New Rust helpers pack mint base fields and construct confidential mint data.
  • Tests cover fresh mint creation, extension preservation for base-only updates, and confidential account use.
  • Existing mints need safer handling of extension data and lamports during updates.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A["surfnet_setMint request"] --> B["Load existing mint or generate one"]
  B --> C["Apply optional base-field updates"]
  C --> D{"confidential supplied?"}
  D -- No --> E["Patch base; retain extension bytes"]
  D -- Yes --> F["Build new mint with confidential extension only"]
  E --> G["Set lamports to rent minimum"]
  F --> G
  G --> H["Apply authoritative account update"]
Loading

Reviews (1) · Last reviewed commit: "feat(core): surfnet_setMint cheatcode wi..."

Comment thread crates/core/src/types.rs
})
.transpose()?;

let extension_types = [ExtensionType::ConfidentialTransferMint];

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Existing mint extensions disappear

When setMint adds confidential support to an existing Token-2022 mint, this builder creates data containing only the confidential extension. If the mint had a transfer-fee configuration, that configuration disappears, so subsequent account setup and transfers no longer use the configured fee. Preserve the existing extensions or reject this update.

Comment thread crates/core/src/types.rs
Comment on lines +1502 to +1506
ct.authority = authority.map(Into::into).unwrap_or_default();
ct.auto_approve_new_accounts = conf.auto_approve_new_accounts.unwrap_or(true).into();
ct.auditor_elgamal_pubkey = auditor_elgamal_pubkey
.map(|key| PodElGamalPubkey::from(key).into())
.unwrap_or_default();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Partial updates reset confidential settings

On an existing confidential mint, supplying just a new confidential.authority rebuilds the extension with no auditor and with autoApproveNewAccounts set to true. Omitted fields therefore do not retain their values as setMint promises; a partial update can silently remove the auditor or change how new accounts are approved.

account.owner
)));
}
account.lamports = lamports;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Mint updates discard excess lamports

When an existing mint holds more than the rent-exempt minimum, even a decimals-only setMint call replaces its lamport balance with that minimum. The excess balance is lost when the update is applied. Preserve the existing balance when updating a mint, adjusting it only if the new allocation requires more lamports.

Comment thread crates/core/src/types.rs
Comment on lines +1816 to +1820
} else {
Self::SplToken(spl_token_interface::state::Mint {
is_initialized: true,
..Default::default()
})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Unsupported programs create unusable mints

A caller can supply a program ID other than SPL Token or Token-2022, but this fallback still creates an SPL Token-shaped mint owned by that program and reports success. SPL Token cannot use an account it does not own, while the supplied program need not understand this data. Reject unsupported IDs so callers do not end up with an unusable mint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant