Skip to content

Support protected addresses and Dijkstra Receiving witnesses - #1370

Draft
colll78 wants to merge 4 commits into
IntersectMBO:masterfrom
colll78:codex/cip-160-receiving
Draft

colll78 wants to merge 4 commits into
IntersectMBO:masterfrom
colll78:codex/cip-160-receiving

Conversation

@colll78

@colll78 colll78 commented Oct 7, 2026 •

Copy link
Copy Markdown

Summary

Construct Dijkstra Receiving witnesses using Map Word32 (AnyScriptWitness era), keyed by each protected output's original body-local position.

outputs: ordinary[0], Plutus A[1], key[2], native[3], Plutus A[4]
Receiving redeemers: 1 → its own redeemer/budget, 4 → its own redeemer/budget

Same-hash and identical Plutus outputs retain separate contexts and budgets. Native scripts and authorization remain shared by hash, without Plutus redeemers. Protected key signatures remain deduplicated.

Balancing and offline fee estimation preserve authored output positions and append change. Balancing evaluates final outputs, including protected change, preserves each output's budget and isolates parent/child reports. Fees include recipient/native signatures and unsigned child witness sizes. Construction rejects protected collateral returns and changes that invalidate signed children. Protected addresses retain their identity through API, RPC and WASM conversions.

RPC preserves separate Receiving indices, payloads, budgets and traces. Its current wire enum lacks Guarding and Receiving constructors, so both use UNSPECIFIED; the API purposes remain typed.

Dependencies are the coordinated ledger #6153, Plutus #7982, consensus 5.x #2373, addresses #483, keys #11 and config #31 proposals. The normal project pins the published per-output ledger and consensus sources; its normal public graph solves all 13 owning components with tests and the benchmark enabled.

Evidence

  • Before: upstream builders cannot construct output-indexed Receiving witnesses. After: all 293 API unit tests pass, including genuine validator checks for repeated outputs, separate redeemers, missing indices, one-output failures, budgets, change and parent/child isolation.
  • After the offline-estimation correction, all 293 API unit tests and 125 golden tests pass again. The CLI also passes all 81 unit and 820 golden tests, including native reference fees and protected change.
  • All 171 RPC tests passed at the preceding per-output checkpoint, including sparse Receiving indices 1/4 with distinct payloads, budgets, traces and error indices.
  • The revised API library compiles all 147 modules with GHC 9.6.7 and -Werror. The normal public project solves all 13 owning components at immutable source pins; the separate full local integration graph solves 869 components.
  • Final package-only sdist includes eight genuine V4 fixture artifacts and their provenance README. Independent byte/hash checks, exact Fourmolu 0.18, HLint 3.10 and diff checks pass.
  • The native TypeScript-generator golden passes. At the exact published head, remote CI passes the GHC 9.6/9.10/9.12/9.14 matrix, Windows 9.12, formatting and protobuf checks. The HLS check remains running.
  • Remote WASM CI cross-builds wasm32-wasi and passes Jest, browser, Node, Elm and demo regressions. Binding quickstarts pass against real local clusters; Go queries tip/parameters. These are generic platform checks, without Receiving-specific binding coverage or direct execution of the pure WASI artifact.

Merge Danger

Door: two-way

Blast Radius: consumers

Address and body-content constructors change; proposed development versions are cardano-api 11.9 and cardano-api-gen 10.3. Dependency acceptance and protocol activation remain separate decisions.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant