Repository navigation
Fail instead of silently dropping Plutus scripts the era does not support - #1363
Open
carbolymer wants to merge 1 commit into
Open
carbolymer wants to merge 1 commit into
carbolymer wants to merge 1 commit into
Conversation
carbolymer
added this pull request to stack #1364
September 30, 2026 13:48
4 tasks done
carbolymer
force-pushed
the
mgalazyn/fix/unsupported-plutus-language-error
branch
2 times, most recently
from
October 1, 2026 19:25
1c03d44 to
ed67933
Compare
carbolymer
force-pushed
the
mgalazyn/fix/unsupported-plutus-language-error
branch
from
October 1, 2026 20:13
ed67933 to
62d4680
Compare
carbolymer
marked this pull request as ready for review
October 1, 2026 20:13
carbolymer
requested review from
a team,
CarlosLopezDeLara,
Jimbo4350,
disassembler,
erikd and
palas
as code owners
October 1, 2026 20:13
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The dependency bump is misclassified and the experimental API migration note inaccurately describes two previous return types.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Prevents unsupported Plutus scripts from being silently omitted during transaction construction.
Changes:
- Returns explicit errors for unsupported witness and reference-script languages.
- Adds regression tests, V4 fixtures, and golden output.
- Updates Plutus dependencies and changelog fragments.
| File | Description |
|---|---|
flake.lock |
Updates the CHaP revision. |
cardano-api/test/cardano-api-test/Test/Cardano/Api/Transaction/Body/Plutus/Scripts.hs |
Adds unsupported-language regression tests. |
cardano-api/test/cardano-api-golden/Test/Golden/ErrorsSpec.hs |
Adds the new output-error golden case. |
cardano-api/test/cardano-api-golden/files/errors/Cardano.Api.Tx.Body.TxBodyError/TxBodyOutputReferenceScriptLanguageNotSupportedInEra.txt |
Records the new error message. |
cardano-api/src/Cardano/Api/Tx/Internal/Output.hs |
Validates output reference-script languages. |
cardano-api/src/Cardano/Api/Tx/Internal/Body.hs |
Applies validation during body creation. |
cardano-api/src/Cardano/Api/Experimental/Tx/Internal/TxScriptWitnessRequirements.hs |
Propagates unsupported-language failures. |
cardano-api/src/Cardano/Api/Experimental/Tx/Internal/BodyContent/New.hs |
Adds and returns the unsigned-transaction error. |
cardano-api/src/Cardano/Api/Experimental/Tx/Internal/AnyWitness.hs |
Changes script extraction to Either. |
cardano-api/src/Cardano/Api/Experimental/Plutus/Internal/Shim/LegacyScripts.hs |
Adapts legacy witness conversion. |
cardano-api/src/Cardano/Api/Experimental/AnyScriptWitness.hs |
Detects unsupported inline script languages. |
cardano-api/gen/Test/Gen/Cardano/Api/Typed.hs |
Restricts generation to supported languages. |
cardano-api/gen/Test/Gen/Cardano/Api/Hardcoded.hs |
Adds Plutus V4 fixtures. |
cardano-api/cardano-api.cabal |
Requires Plutus 1.71 dependencies. |
cabal.project |
Advances the CHaP index state. |
.changes/plutus-1-71-bump.yml |
Documents the dependency bump. |
.changes/legacy-tx-body-unsupported-reference-script-language-error.yml |
Documents the legacy API break. |
.changes/experimental-tx-unsupported-plutus-language-error.yml |
Documents the experimental API break. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| description: | | ||
| `makeUnsignedTx` now fails with `MakeUnsignedTxPlutusLanguageNotSupportedInEra` when an inline Plutus script uses a language the era does not support. | ||
| Before, the script was silently dropped from the witness set while its redeemer was kept, so the transaction failed on submission. | ||
| `getAnyWitnessScript`, `getAnyPlutusWitnessPlutusScript`, `getTxScriptWitnessRequirements` and `getTxScriptWitnessesRequirements` now return `Either L.Language` instead of `Maybe`. |
Comment on lines
+228
to
+229
| -- | An inline Plutus witness must be rejected, not silently dropped with its | ||
| -- redeemer, when the era does not support its language. V4 fails in Conway. |
Contributor
|
What about this approach? master...jordan/plutus-language-in-era-vs-master |
carbolymer
force-pushed
the
mgalazyn/fix/unsupported-plutus-language-error
branch
from
October 7, 2026 07:19
62d4680 to
4f7d365
Compare
The experimental transaction builder now returns MakeUnsignedTxPlutusLanguageNotSupportedInEra instead of dropping an inline script while keeping its redeemer. createTransactionBody now fails with TxOutputReferenceScriptLanguageNotSupportedInEra for an output or return collateral whose reference script language is unsupported in the era. The test generator derives Plutus languages from scriptLanguageSupportedInEra instead of a hand-rolled table with an undefined arm.
carbolymer
force-pushed
the
mgalazyn/fix/unsupported-plutus-language-error
branch
from
October 7, 2026 13:33
4f7d365 to
b2764fd
Compare
3 of 4 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

cardano-api dropped Plutus scripts silently when the era did not support their language.
This PR turns both cases into errors.
makeUnsignedTxnow fails withMakeUnsignedTxPlutusLanguageNotSupportedInErawhen an inline Plutus script uses a language the era does not support.Before, the script was dropped from the witness set while its redeemer was kept, and the transaction failed on submission.
getAnyWitnessScriptandgetAnyPlutusWitnessPlutusScriptnow returnEither L.Languageinstead ofMaybe.getTxScriptWitnessRequirementsandgetTxScriptWitnessesRequirementsnow returnEither L.Language (TxScriptWitnessRequirements era)instead ofTxScriptWitnessRequirements era.This is a breaking change to the experimental API.
createTransactionBodynow fails withTxOutputReferenceScriptLanguageNotSupportedInErawhen an output or the return collateral carries a reference script in a language the era does not support.Before, the output was built without the script.
This adds a constructor to
TxOutputError, which is a breaking change.The test generators now take the supported Plutus languages from
scriptLanguageSupportedInEra.The Plutus V4 generators use a validator compiled against Plutus V4 with plutus 1.70; its bytes equal the V3 always-succeeds script, because the validator ignores its argument.
Context
Found while adding Plutus V4 support to cardano-cli:
Enabling Plutus V4 in the Dijkstra era is stacked on this PR and waits for a ledger fix:
PlutusV4scripts totransaction_witness_setCDDL cardano-ledger#5403How to trust this PR
Three new properties in Test.Cardano.Api.Transaction.Body.Plutus.Scripts: an inline Plutus V4 witness is rejected in Conway, a Plutus V4 reference witness is still accepted, and createTransactionBody rejects a Plutus V4 reference script on a Conway output.
A new golden covers the error message.
All tests in cardano-api-test and cardano-api-golden pass.
Checklist