Skip to content

wasm: export coin checks, forfeits and releases for Arca - #33

Merged
GracedEternalKingCabbageMan merged 1 commit into
sequentiafrom
feature/wasm-arca-coin-forfeit-release
Oct 3, 2026
Merged

GracedEternalKingCabbageMan merged 1 commit into
sequentiafrom
feature/wasm-arca-coin-forfeit-release

Conversation

@GracedEternalKingCabbageMan

Copy link
Copy Markdown
Collaborator

A page could verify a leaf taken from a round, but not a coin received out of round, and it could not build what it signs when it gives a leaf up: the forfeit and the release. The native kit already has these. The bindings now carry them on ArkVerifier, each at the median time the call names.

Coins.

  • verifyCoin(coin, rounds, ownerKey, ownerNonce, now, chain?) checks a coin record against the rounds and boards its lineage came from, for the wallet's key and nonce.
  • The lineage check needs the chain, which a page can only reach asynchronously. So coinLineage(coin, rounds, now) first lists the lineage scripts and boards to look up, and verifyCoin then takes what the chain source found ({ paid, spent }).
  • A coin with a lineage script paid or a board spent is refused, kind on_chain. Without chain, the verdict says the coin rests on the operator's rule.

Forfeits and releases. forfeitRefresh, forfeitOffboard, releaseRefresh and releaseOffboard wrap the native builders, so h and M come from the leaf and round the wallet validated. Each returns the message in the form signCsfs takes, with its digest, and gives M in display hex.

Byte-order vector. It gains a release (M in display hex at the edge, internal order in the message, taken from the Arca signer vectors) and a received coin (its asset in display hex as the kit gives it, internal order in the record). Both are checked in Rust and through the bindings.

Tested:

  • ark_records.js:
    • every received coin in the transfer vectors verifies (7 coins; 2 of them rest on a board);
    • a paid lineage script and a spent board are refused with on_chain;
    • the record promising one leaf twice is refused with salt, another key or nonce with owner, and a missing board transaction with round;
    • { payd: [] } is refused: unknown field \payd``.
  • ark_regtest:
    • the node mines a round that pays the wallet a new leaf, an offboard output and the operator's connector at output 2;
    • the four digests built through the bindings equal the native ones, and M is that round's connector asset;
    • the four signatures signCsfs makes with the old leaves' keys verify natively;
    • a release signed for this round does not verify for another round's M;
    • refused: a connector at the wrong output; the new or old leaf checked against the wrong round; another nonce; an unknown offboard field; a ceiling below the margin.
  • arca_signers.js, arca_regtest.py (Tests successful), lwk_signer (26 tests; 27 with ark) and lwk_wollet ark:: (29) all pass.

A page could verify a leaf taken from a round but not a coin received
out of round, and could not build what it signs when it gives a leaf up:
the forfeit and the release. The native kit has had these; the bindings
now carry them, on ArkVerifier and at the median time each call names.

verifyCoin checks a coin record against the rounds and boards its
lineage came from, for the wallet's key and nonce. The lineage check
needs the chain, which a page reaches only asynchronously, so
coinLineage first names the lineage scripts and boards to look up, and
verifyCoin then takes what the chain source found ({ paid, spent }):
a coin with a lineage script paid or a board spent is refused, kind
on_chain; without it the verdict says the coin rests on the operator's
rule.

forfeitRefresh, forfeitOffboard, releaseRefresh and releaseOffboard wrap
the native builders, so h and M come from the leaf and round the wallet
validated. Each returns the message as signCsfs takes it, with its
digest, and M in display hex.

The byte-order vector gains a release (M display at the edge, internal
in the message, from the Arca signer vectors) and a received coin (its
asset display as the kit gives it, internal in the record), each
checked in Rust and through the bindings. ark_regtest mines a round
paying a new leaf, an offboard output and the operator's connector;
the bindings' four digests equal the native ones and the signatures
they make with the old leaves' keys verify natively.
@GracedEternalKingCabbageMan
GracedEternalKingCabbageMan merged commit 58e66f1 into sequentia Oct 3, 2026
11 of 17 checks passed
@GracedEternalKingCabbageMan
GracedEternalKingCabbageMan deleted the feature/wasm-arca-coin-forfeit-release branch October 3, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant