Skip to content

CI rehearsal only (do not merge) - #22

Closed
michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a6
Closed

michael-moffett wants to merge 1 commit into
mainfrom
surfpool-706-setmint-a6

Conversation

@michael-moffett

Copy link
Copy Markdown
Member

Fork CI only. Do not merge.

Add a `surfnet_setMint` cheatcode that creates or patches a mint, optionally writing the Token-2022 `ConfidentialTransferMint` extension (authority, auditor ElGamal pubkey, auto-approve).

Lead 3 of : builders must fork a mainnet mint today because there is no way to spin up a confidential-capable mint with a chosen auditor and decimals.
@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Medium risk] Adds test-only cheatcode for mint configuration.

The PR should not merge until setMint rejects existing accounts owned by unsupported programs.

Findings

  1. P1 Unsupported mint owner accepted ▶
  2. P2 Confidential authority cannot be cleared ▶

Summary

The PR adds surfnet_setMint for creating and updating token mints, including Token-2022 confidential-transfer configuration, and exposes it through the Node SDK.

  • Adds mint packing and extension-preservation helpers, RPC tests, generated types, and method registration.
  • Existing accounts with unsupported owners can be reported as successfully updated mints; confidential mint authorities cannot be cleared after being set.

Reviews (1) · Last reviewed commit: "feat(core): surfnet_setMint cheatcode wi..."

Comment on lines +2028 to +2035
let token_program_id = mint_account.clone().map_account()?.owner;
if let Some(requested) =
requested_token_program.filter(|requested| *requested != token_program_id)
{
return Err(Error::invalid_params(format!(
"mint {mint} is owned by {token_program_id}, not the requested token program {requested}"
)));
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Unsupported mint owner accepted

If an existing account has mint-shaped data but is owned by neither SPL Token nor Token-2022, calling setMint without tokenProgram accepts that owner. The update writes mint data but leaves the owner unchanged, so the RPC reports success while token programs cannot use the account as a mint. Reject unsupported owners before writing the update.

Comment thread crates/types/src/types.rs
Comment on lines +1274 to +1276
/// The authority that approves new confidential accounts and updates this
/// config (base58). Omitted keeps the current value, null when first written.
pub authority: Option<String>,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Confidential authority cannot be cleared

After a confidential mint authority is set, callers have no way to clear it. JSON null becomes None, which the update treats as “leave unchanged.” Unlike the auditor field, authority cannot distinguish an omitted value from an explicit null. This limits later configuration changes; give callers a distinct way to request clearing it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant