Repository navigation
feat!: spec 17 - shield proof (circuit 3), native-asset-only pool, crates bumped (node/runtime 0.3.0) - #155
Merged
Merged
Conversation
…ates bumped (node/runtime 0.3.0)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Runtime spec 17 / tx 5. A shield must now prove that its note is worth exactly the deposit.
Before this change, nothing tied a shield's commitment to its amount: a deposit of 1 could insert a note worth 1000, and unshielding that note drained other depositors' funds.
Shield proof (circuit 3)
shield). Public inputs arecommitment, value, asset_id, with the same arity at every version.primitives/zk-verifier:CIRCUIT_ID_SHIELD,SHIELD_PUBLIC_INPUTS, andhas_memo_layout. Only transfer and unshield bind memos.pallet-zk-verifier:CircuitId::SHIELD,ShieldStatement,ZkVerifierPort::verify_shield_proof, andencode_shield.shield(asset_id, amount, commitment, encrypted_memo, proof, circuit_version)is checked in this order:shield_batch: each entry carries its own proof and version. One bad proof reverts the whole batch.shield(uint32,bytes32,bytes,bytes,uint32), selector0xf25897e0(was0x9feb22ea). The old calldata reverts.Native asset only
The pool always moves
T::Currency, so a note of a verified non-native asset was backed by ORB.shield,unshield,private_transferandclaim_relay_feesnow refuse any asset other thanNATIVE_ASSET_IDwithAssetNotSupported, throughAssetOperation::ensure_movable.Multi-asset support stays in place: assets are still part of the commitment and there is still a balance per asset. Enabling another asset only needs a fungibles backend and relaxing that single check.
Refactor
ShieldOperation::execute(depositor, &proof, ShieldRequest)has the same shape as unshield and transfer.ShieldRequest::from_batch_itemsplits a batch entry.Proof/MAX_PROOF_SIZE(512) is the single proof bound. Every call and the precompile use it. The encoding is unchanged.Versions
orbinum-zk-verifierpallet-zk-verifierpallet-shielded-poolpallet-evm-precompile-shielded-poolorbinum-runtime/orbinum-nodeChangelogs and
RUNTIME_VERSIONS.md(spec 17) are updated.scripts/vk/workflows/setup-dev.shalso registers shield.Test plan
cargo test:pallet-shielded-pool390,pallet-zk-verifier128, precompile 91.pallet-shielded-poolwithskip-proof-verification+runtime-benchmarks: 387.c + r).cargo clippy --all-targets: no warnings.cargo check -p orbinum-runtime --features runtime-benchmarkspasses.--devnode,e2e-shield-live.cjs: 71/71.msg.valuerefunded on revert, offsets past the calldata or pointing at the memo.--devnode,e2e-shield-clients-live.cjs: 37/37.wallet-sdk+ts-protocol, the extrinsic, the precompile andshieldBatch.