Skip to content

Build and inspect Dijkstra protected payments with Receiving witnesses - #1456

Closed
colll78 wants to merge 6 commits into
IntersectMBO:masterfrom
colll78:codex/cip-160-receiving
Closed

colll78 wants to merge 6 commits into
IntersectMBO:masterfrom
colll78:codex/cip-160-receiving

Conversation

@colll78

@colll78 colll78 commented Oct 7, 2026 •

Copy link
Copy Markdown

Summary

protected destination + V4 witness for each protected output index
  build/raw/offline estimate through cardano-api
  inspect protected outputs, recipient keys and Receiving budgets
  collect sender/recipient signatures over the same body
  assemble with the existing witness workflow

Adds address protection and inspection, raw output-indexed V4 witnesses, shared
native script supply, consumed-input references and protected change. Repeated
script hashes retain independent redeemers and budgets. Missing authorization
identifies the original protected destination. Offline witness counts include
native reference signers. Script-address construction supports V4 while preserving
native/V1–V3 hashes. Pool-query compatibility preserves ordinary JSON and reports
unavailable BLS registration history as null.

Exported command records change; CLI 11.3.0.0 follows the repository's PVP
second-component major bump. Nested construction remains available through
the experimental API's child-body entrypoints.

The upstream six-field ledger-state migration preserves the six CLI outer JSON keys. currentStakeDistribution now reads the coherent current set snapshot; nested ledger-state JSON/CBOR follows upstream.

Evidence

All local compilation/runtime evidence below uses GHC 9.6.7 with the coordinated native integration graph (blockio +serialblockio, crypto -external-libsodium-vrf). Normal default-flag source resolution, Nix evaluation and remote CI are separate evidence.

The preceding per-output implementation passed all 81 CLI units and 820 goldens, including all 621 generated help cases, real V4 evaluation, repeated output indices and budgets, references, protected change, recipient/native signatures and pool-query schema checks. Its normal five-target graph resolved with default backends and one time provider; Linux/Windows derivation evaluations and ordinary compiler/platform checks passed. These results retain their pre-upstream-state-migration scope.

  • Fresh CLI production/executable and owning unit targets compile and link strictly against the merged ledger. Eight affected Receiving/genesis regressions pass; the actual lowercase pool-state schema property passes separately.
  • A private check through the public CLI JSON instance passes against the fresh library: exactly six CLI keys (and six API keys), epoch 7, an independently authored nonempty current SET distribution rather than a different MARK snapshot, and encode/toJSON equality. Actual library, harness and binary hashes were verified.
  • The coordinated ledger source list includes the migrated Shelley test suite, preventing selection of its stale published predecessor. The corrected owning-target build passes without weakening strict warnings or decoder tests.
  • Signed CLI 9fa37476 is published with the final dependency pins. Its three normal native default/CI dry-runs pass with 690 components and all five owning components. Genuine existing Linux and Windows executable derivation evaluations pass with 693/5 and 685/5 components, retaining the exact locks and default flags. These are resolution/evaluation proofs, without a completed Nix build or new remote-CI pass.
  • The coordinated node 14ee5ef4 is published; its normal source graph and existing Linux/Windows executable evaluations pass. Fresh-head remote CI remains pending. Existing source distributions contain the Receiving modules, genuine V4 fixture and changed help assets; earlier exact formatter/gild checks retain their recorded scope.

Merge Danger

Door: two-way

Blast Radius: Consumers

Public command-record constructors and dependency bounds change. This depends
on ledger #6153,
Plutus #7982,
API #1370,
DNS #177 and
consensus #2373.
The coordinated local-node create, submit and spend regression passes, as does
same-database relay restart with complete UTxO comparison and subsequent spending.
Node #6727 retains the
remaining scheduled-activation, snapshot, rollback and Leios coverage gaps.

The upstream ledger-state JSON/CBOR schema changes with this dependency update. Existing outer JSON keys remain stable. Old persisted NES/Mark states require replay; current-format restart does not establish old-format restoration.

At the 16:24 UTC snapshot, the sole failed CLI workflow is the known fork-ancestry Check git dependencies gate. Compiler/test jobs remain pending; no current compiler/test failure is visible. Dependency acceptance remains an external merge gate.

{-# LANGUAGE DataKinds #-}
{-# LANGUAGE FlexibleContexts #-}
{-# LANGUAGE GADTs #-}
{-# LANGUAGE LambdaCase #-}
stakingCredentials = mempty -- QueryPoolStateResult does not provide delegators
PoolParams
{ poolParameters = (\deposit -> L.mkStakePoolState deposit stakingCredentials pp) <$> mDeposit
{ poolParameters = (\deposit -> (pp, deposit)) <$> mDeposit
, futurePoolParameters = do
futurePp <- Map.lookup kh qpsrFutureStakePoolParams
(\deposit -> L.mkStakePoolState deposit stakingCredentials futurePp) <$> mDeposit
(\deposit -> (futurePp, deposit)) <$> mDeposit
Comment on lines +389 to +393
( \witness -> case witness of
ShelleyKeyWitness _ wit -> do
H.assert (verifyWitVKey originalHash wit)
H.assert (not (verifyWitVKey changedHash wit))
_ -> H.failure
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants