Conversation
LexxXell
force-pushed
the
feat/identityFundingFromShieldedPool
branch
from
September 27, 2026 14:08
aa55d6f to
e2da6ed
Compare
This was referenced Sep 27, 2026
Collaborator
Author
|
Superseded by #177. The funding journal chain is parked on the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
The third funding source: an identity created straight out of the wallet's shielded pool, spending its own notes.
REGISTER_IDENTITY_FROM_SHIELDED_POOLconfirms whatPREPARE_IDENTITY_FUNDINGquoted withsource: 'shielded'.shieldedProtocolVersion/shieldedDenominations— the pool creates an identity only at fixed denominations, and which ones depends on the drive protocol (v12 and v13 are supported here). An unknown protocol yields an empty list, which is how a caller learns the source is unavailable rather than by failing later.selectShieldedIdentityNotes— covers the denomination largest note first, within the 5-note action limit. A balance spread over more notes than that cannot fund an identity even when the total looks sufficient, and that is said plainly.shieldedFallbackAddress— the Platform address the protocol returns the funds to if creation fails. It is the wallet's first Platform address, cached like any other so it can be shown later without the password; an xpub that does not match the seed is never overwritten silently.quoteShielded— builds and proves the transition at quote time, then stores it. Proving is the slow part, so a retry sends the stored bytes instead of proving again.failedwith that address in the message.GET_IDENTITY_FUNDING_SOURCESnow answers for all three sources. The shielded balance is included only when the request carries a password, since recovering notes needs the viewing key.SEND_SHIELDED_TRANSFER,UNSHIELD_TO_ADDRESSandWITHDRAW_SHIELDED_TO_COREare refused — they would spend the same notes and leave the proof unusable.The pool read still goes through the shared
loadUnspentShieldedNoteshelper; it moves intoShieldedServicewith #170, and this service then calls that instead.Backend only — no UI changes.
Testing
tsc --noEmit,ts-standardtest/api/private/identities/identityFunding.spec.ts— eight new cases: a quote at an allowed denomination stores the proof and a repeat prepare does not prove again; a denomination the protocol does not allow is refused before proving; a shielded top-up is refused with the v14 message; notes spread beyond the action limit are refused; a registration that created no identity ends as failed naming the fallback address; the notes are held against other shielded spends while pending; the sources answer lists denominations and includes the balance only with a password; an unknown protocol reports the source as unsupported.jest: 44 suites, 28 cases in the funding spec; the only failures are the network-dependent specs that flake ondeveloptoo and pass on a re-run.