Repository navigation
Include native assets in estimateBalancedTxBody's declared UTxO value - #1366
Open
carbolymer wants to merge 1 commit into
Open
carbolymer wants to merge 1 commit into
carbolymer wants to merge 1 commit into
Conversation
carbolymer
force-pushed
the
mgalazyn/fix/build-estimate-multiasset
branch
from
October 5, 2026 16:18
bb6305b to
8b6a97b
Compare
carbolymer
force-pushed
the
mgalazyn/fix/build-estimate-multiasset
branch
2 times, most recently
from
October 6, 2026 09:46
0bb1736 to
d8f558d
Compare
carbolymer
marked this pull request as ready for review
October 6, 2026 09:59
carbolymer
requested review from
CarlosLopezDeLara,
Jimbo4350,
disassembler,
erikd and
palas
as code owners
October 6, 2026 09:59
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The public behavioral change must be classified as breaking in the changelog fragment.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates transaction fee estimation to preserve native assets and return balance errors instead of ledger exceptions.
Changes:
- Builds fake UTxOs using the full declared value.
- Validates negative ADA and native-asset balances earlier.
- Adds regression tests and updates documentation/changelog.
| File | Description |
|---|---|
.changes/estimate-balanced-tx-body-native-assets.yml |
Documents the behavioral fix. |
cardano-api/src/Cardano/Api/Tx/Internal/Fee.hs |
Fixes legacy balancing and validation. |
cardano-api/src/Cardano/Api/Experimental/Tx/Internal/Fee.hs |
Fixes experimental balancing and validation. |
cardano-api/test/cardano-api-test/Test/Cardano/Api/Transaction/Autobalance.hs |
Adds legacy regression coverage. |
cardano-api/test/cardano-api-test/Test/Cardano/Api/Experimental/Fee.hs |
Adds experimental regression coverage. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| project: cardano-api | ||
| pr: 1366 | ||
| kind: | ||
| - bugfix |
carbolymer
force-pushed
the
mgalazyn/fix/build-estimate-multiasset
branch
from
October 6, 2026 10:06
d8f558d to
f5849a3
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Context
Follow-up to
#1365
which fixed
estimateBalancedTxBodyfor transactions with no outputs.Copilot's review on that PR pointed out that the fake UTxO entry used for balance evaluation carried only ADA, so native assets in the declared total UTxO value were dropped.
That limitation predates PR 1365 (it was marked with a
TODO: Include multiassets) and also affected transactions that do have outputs: only the tokens present in the first output were represented in the fake entry.createFakeUTxOin bothCardano.Api.Tx.Internal.FeeandCardano.Api.Experimental.Tx.Internal.Feenow builds the single fake entry at the change address holding the full available value, ADA and native assets together.The first-output template is gone, and the now-unused legacy helper
updateTxOutwas removed.The public
totalUTxOValueHaddock now says the value includes native assets.cardano-cli transaction build-estimatealready parses a multi-asset--total-utxo-value, so it benefits from this fix without any changes on its side.This is a behaviour change worth calling out: tokens present in outputs but missing from the declared total now fail with a negative balance error, instead of passing by accident when they happened to sit in the first output.
The negative balance check for native assets now runs before the fee-estimation body is built.
Previously, when an explicit output spent tokens that were not on the fake input, the estimate aborted with the ledger's "Illegal Value in TxOut" exception instead of returning an error, because Conway outputs are compacted eagerly and reject negative quantities.
Two more paths that reached the same ledger exception are guarded as well.
checkNonNegativein both modules now rejects negative token quantities before the zero-ADA branch, which computed a minimum UTxO from a still-negative value.The legacy
estimateBalancedTxBodynow rejects deposits that exceed the declared ADA with a balance error, as the experimental one already did.How to trust this PR
Four regression properties cover this:
prop_estimateBalancedTxBody_keeps_native_assets_in_changeandprop_estimateBalancedTxBody_fails_on_undeclared_native_assetsinTest.Cardano.Api.Experimental.Feeprop_estimate_balanced_tx_body_keeps_native_assets_in_changeandprop_estimate_balanced_tx_body_fails_on_undeclared_native_assetsinTest.Cardano.Api.Transaction.AutobalanceThe first property in each pair declares a total UTxO value of 150 ADA plus 10 tokens, spends 10 ADA plus 3 tokens to an explicit output, and asserts the change output carries the remaining ADA minus fee and the remaining 7 tokens.
The second property in each pair declares an ADA-only total but spends tokens, and asserts the result is the negative balance error rather than an exception.
Three further properties cover the guarded paths:
prop_make_transaction_body_auto_balance_fails_on_zero_ada_negative_assetsandprop_estimate_balanced_tx_body_fails_when_deposits_exceed_declared_adainTest.Cardano.Api.Transaction.Autobalance, andprop_makeTransactionBodyAutoBalance_fails_on_zero_ada_negative_assetsinTest.Cardano.Api.Experimental.Fee.Each forces the returned error, so a ledger exception would fail the test.
Checklist
.changes/🤖 Generated with Claude Code