Repository navigation
fix(standards): seal PSWAP paybacks and remainders - #3927
Merged
Merged
Conversation
partylikeits1983
requested review from
PhilippGackstatter and
zeapoz
and removed request for
zeapoz
September 23, 2026 16:48
partylikeits1983
marked this pull request as ready for review
September 23, 2026 16:48
zeapoz
reviewed
Sep 24, 2026
zeapoz
left a comment
Collaborator
There was a problem hiding this comment.
Looks good! Left two questions on the test code
PhilippGackstatter
approved these changes
Sep 24, 2026
PhilippGackstatter
left a comment
Contributor
There was a problem hiding this comment.
LGTM! Consider removing the explicit attachment check if you can confirm it's redundant.
Fumuran
approved these changes
Sep 25, 2026
Fumuran
left a comment
Contributor
There was a problem hiding this comment.
Looks great, have just two optional nits
| dup exec.output_note::get_assets_info | ||
| # => [ASSETS_COMMITMENT, num_assets, note_idx, EXPECTED_ASSETS_COMMITMENT] | ||
|
|
||
| movup.4 eq.1 assert.err=ERR_PSWAP_OUTPUT_ALTERED |
Contributor
There was a problem hiding this comment.
optional nit: I would probably create a constant for the expected number of assets and use it here instead of plain 1
Collaborator
There was a problem hiding this comment.
Similarly, there's another plain 1 that could be an associated constant in the Rust TryFrom impl:
zeapoz
approved these changes
Sep 25, 2026
| dup exec.output_note::get_assets_info | ||
| # => [ASSETS_COMMITMENT, num_assets, note_idx, EXPECTED_ASSETS_COMMITMENT] | ||
|
|
||
| movup.4 eq.1 assert.err=ERR_PSWAP_OUTPUT_ALTERED |
Collaborator
There was a problem hiding this comment.
Similarly, there's another plain 1 that could be an associated constant in the Rust TryFrom impl:
partylikeits1983
added this pull request to stack #3948
September 25, 2026 10:43
Co-authored-by: Andrey Khmuro <andrey@polygon.technology>
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PSWAP leaves its payback and remainder outputs mutable after filling an order. The filler can append another asset later in the transaction, changing the payback commitment or making the remainder fail its single asset check.
After asset callbacks finish, PSWAP checks that each output has the expected asset, amount, and attachment. It then calls
output_note::sealto prevent further changes. Regression tests cover complete fill paybacks, partial fill paybacks, remainders, public/private visibility, additional assets, balance increases, and callback mutations.Depends on #3923 and is based on
ajl-output-note-seal. This changes the PSWAP script root; existing notes retain their original script. Storage and Rust APIs are unchanged.