Skip to content

Add private PSWAP cancellation through a separate account - #3911

Draft
partylikeits1983 wants to merge 8 commits into
ajl-pswap-private-paybacksfrom
ajl-pswap-fixed-recipient
Draft

partylikeits1983 wants to merge 8 commits into
ajl-pswap-private-paybacksfrom
ajl-pswap-fixed-recipient

Conversation

@partylikeits1983

@partylikeits1983 partylikeits1983 commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Adds cancellation to the shielded order flow (private P2ID paybacks), stacked on #3918. This implements the cancellation flow in the updated proposal.

Cancellation verifies the RECIPIENT hash preimage without requiring the target account (the recipient of the P2ID) to execute the transaction. The user builds and proves the transaction locally through a public NoAuth account. The PSWAP note script returns the full remaining balance in a private P2ID to the committed recipient.

Cancellation now checks that the refund contains the full remaining balance and no attachments, then seals it with output_note::seal from #3923. This prevents later mutations to the refund. The kernel sealing API (#3923) and PSWAP output sealing (#3927) are already merged into next.

Knowledge of the hash preimage authorizes cancellation but cannot change the AccountId destination of the refund. Cancellation fees are funded separately. Public paybacks and creator reclaim in the unshielded flow remain the same.

The private refund should first be committed on chain, then consumed as an authenticated input. Unauthenticated consumption exposes the NoteId and links the refund to the consuming account. Timing and funding correlations remain possible.

About 70% of this diff is integration tests: invalid preimages and cancellation arguments, private fee funding and change, and the router creation, half-fill, cancellation, and collection flow with local proofs. The rest is mainly the MASM cancellation path, Rust helpers, documentation, and updated benchmark costs. The diff is relative to #3918.

Closes #3909.

partylikeits1983 added a commit that referenced this pull request Sep 21, 2026
Record the dependency on ajl-pswap-private-paybacks while retaining the
complete implementation already tested in PR #3911. The merged tree is
identical to 20c7bf9; only the branch ancestry changes.

This separates the cancellation, refund, fee-funding, and router-flow
review without rewriting the existing pull request history.
@partylikeits1983 partylikeits1983 changed the title Use a fixed P2ID payback recipient for each PSWAP order Add private PSWAP cancellation through a separate account Sep 21, 2026
@partylikeits1983
partylikeits1983 changed the base branch from next to ajl-pswap-private-paybacks September 21, 2026 19:24
@partylikeits1983
partylikeits1983 added this pull request to stack #3922 September 22, 2026 10:36
@partylikeits1983
partylikeits1983 force-pushed the ajl-pswap-fixed-recipient branch from ea83723 to d8e2034 Compare September 22, 2026 14:15
Propagate the output-note sealing dependency from PR #3918 so private cancellation can compile and enforce immutable refunds.
Integrate current next through the payback branch and use the merged sealing
implementation. Preserve attachment-free cancellation refunds and verify
issuer callbacks cannot alter their assets or add attachments before sealing.

Retain current release history, remove superseded callback tests, and refresh
PSWAP fill costs with the cancellation dispatcher.
# Conflicts:
#	crates/miden-testing/tests/scripts/pswap.rs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make P2ID output notes RECIPIENT constant in PSWAP note

1 participant