Skip to content

wasm: refuse unknown fields on every Arca object - #32

Merged
GracedEternalKingCabbageMan merged 1 commit into
sequentiafrom
fix/wasm-arca-dto-unknown-fields
Oct 3, 2026
Merged

GracedEternalKingCabbageMan merged 1 commit into
sequentiafrom
fix/wasm-arca-dto-unknown-fields

Conversation

@GracedEternalKingCabbageMan

Copy link
Copy Markdown
Collaborator

serde_wasm_bindgen reads a struct by asking the JavaScript object for each field the struct names. A field the struct does not name is therefore never seen, and deny_unknown_fields has nothing to refuse. Before this change:

  • new ArkVerifier(network, { operator, maxExitDelaySecond: 172800 }) was accepted, and the bound took its default. The new test fails with Missing expected exception.
  • signCsfs(..., { maxUncomitted: '9999000' }) ignored the misspelt field, so the ceiling fell back to 0. The signer refused for that reason instead: the committed outputs leave 9999000 atoms ... the ceiling is 0.

Every Arca object is now read whole first, with all of its keys, and only then converted into its type, where deny_unknown_fields applies at every level. That covers the policy and its fee-rate floor, the limits, the message, and the message's source, outputs and inputs. A source is read as a record or in the named form depending on whether it has record, so a stray field is named in the refusal instead of being reported as matching no variant.

Tested, wasm --dev --target nodejs:

  • ark_records.js refuses unknown field \maxExitDelaySecond`and, insideminReserveFeeRate, unknown field `mutliple``.
  • arca_signers.js refuses maxUncomitted in the limits, salts in a named source, leafId beside record, amount in an output, vout in an input, tme in an unroll and connectorAsset in a release.
  • The rest of both suites still passes.
  • ark_regtest (5 leaves accepted, 25 refused) and the signers' arca_regtest.py (Tests successful), whose objects all cross this boundary, pass.

serde_wasm_bindgen reads a struct by asking the JavaScript object for
each field the struct names, so a field it does not name is never seen
and deny_unknown_fields has nothing to refuse. A misspelt bound in the
verifier's policy (maxExitDelaySecond) was accepted and the bound took
its default; a misspelt ceiling in signCsfs's limits (maxUncomitted)
was ignored and the ceiling fell back to 0.

Every Arca object is now read whole first, every key with it, and then
into its type, where deny_unknown_fields applies at every level: the
policy and its fee-rate floor, the limits, the message, its source,
outputs and inputs. A source is read as a record or as the named form by
whether it has `record`, so a stray field is named in the refusal rather
than reported as matching no variant.
@GracedEternalKingCabbageMan
GracedEternalKingCabbageMan merged commit e266ce6 into sequentia Oct 3, 2026
11 of 17 checks passed
@GracedEternalKingCabbageMan
GracedEternalKingCabbageMan deleted the fix/wasm-arca-dto-unknown-fields branch October 3, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant