Skip to content

fix(protocol): use native token ID and pin signer dependencies - #158

Merged
mellowcroc merged 4 commits into
mainfrom
fix/sca-token-id
Oct 2, 2026
Merged

mellowcroc merged 4 commits into
mainfrom
fix/sca-token-id

Conversation

@mellowcroc

Copy link
Copy Markdown
Collaborator

Findings

Addresses F-2026-19093 and F-2026-19127.

  • Treat the signed proposal tokenId as Mina's native token identifier and update contract checks, event consumers, lightnet fixtures, and online/offline signing together.
  • Pin stable o1js@3.0.0 directly in contracts, use npm mina-signer@4.1.0 across the signing surfaces, and remove the vendored signer submodule. Update the offline WASM shim, CI/release packaging, and audit guides for the new dependency layout.

This PR targets #157 (fix/sca-contract-rules) and is followed by fix/sca-event-memo in stack #156. Offline request/response format remains v1.

Validation and merge gate

On the rebased full local stack: contracts build; 153 focused contract tests, 13 UI tests, and 27 offline CLI tests passed. Contract and CLI tests used SKIP_PROOFS=1. The SCA patches were unchanged by the rebase.

The complete offline end-to-end run with real proofs timed out during the first proof in the earlier local attempt and has not been completed on this head. It remains a merge gate, along with source-bound testnet/mainnet VK and hosted checks. No deployment or release is included.

graikos
graikos previously approved these changes Oct 2, 2026
Comment thread docs/security-audit-guide.md Outdated
Base automatically changed from fix/sca-contract-rules to main October 2, 2026 09:31
@mellowcroc
mellowcroc merged commit 8a20f90 into main Oct 2, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants