Skip to content

CI rehearsal only (do not merge) - #28

Open
michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a12
Open

michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a12

Conversation

@michael-moffett

Copy link
Copy Markdown
Member

Fork CI only. Do not merge.

Add a `surfnet_setMint` cheatcode that creates or patches a mint, optionally writing the Token-2022 `ConfidentialTransferMint` extension (authority, auditor ElGamal pubkey, auto-approve).

Lead 3 of : builders must fork a mainnet mint today because there is no way to spin up a confidential-capable mint with a chosen auditor and decimals.
@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 2/5

[High risk] Adds test-only cheatcode for mint configuration.

The PR should not be merged until the SDK authority type, concurrent update handling, and existing-account initialization behavior are addressed.

Findings

  1. P1 SDK cannot clear authority ▶
  2. P1 Concurrent mint updates overwrite changes ▶
  3. P1 Uninitialized mint accounts are rejected ▶

Summary

Adds surfnet_setMint to create or update SPL Token and Token-2022 mints, including a confidential-transfer extension, with Rust tests and Node SDK bindings.

  • The generated SDK type omits a supported authority-clearing value.
  • Concurrent mint updates can lose changes, and an existing uninitialized mint account cannot be set up through this method.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A["surfnet_setMint"] --> B["Look up mint or generate default"]
  B --> C["Validate owner and apply fields"]
  C --> D["Preserve or add extensions"]
  D --> E["Top up rent and write account"]
Loading

Reviews (1) · Last reviewed commit: "feat(core): surfnet_setMint cheatcode wi..."

* The authority that approves new confidential accounts and updates this
* config (base58). Omitted keeps the current value, null when first written.
*/
authority?: string,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 SDK cannot clear authority

The Rust API accepts null for confidential.authority to clear an existing authority, but this generated type permits only string. A TypeScript caller cannot make that supported request without bypassing the type checker.

account.data = final_mint_bytes.clone();
Ok(())
})?;
svm_locker.apply_account_update(mint_account, AccountUpdatePolicy::Authoritative)?;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Concurrent mint updates overwrite changes

If two surfnet_setMint calls read the same mint before either writes, each builds a complete account from its earlier read. The later write can erase the other call’s update, even when the calls change different fields, because the write lock does not cover the read.

Comment on lines +2049 to +2050
let mut mint_data = MintAccount::unpack(mint_account.expected_data())
.map_err(|e| Error::invalid_params(format!("Failed to unpack mint data: {}", e)))?;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Uninitialized mint accounts are rejected

If an account is already allocated to a token program but is not initialized as a mint, the missing-account factory does not run. MintAccount::unpack then fails, so surfnet_setMint cannot configure that account, although it can create a mint at an absent address.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant