Repository navigation
fix(vibenet): port demo engine to Keystore-free EIP-8130 accounts - #2067
Merged
Merged
Conversation
Vibenet was reset on 2026-10-02 to Keystore-free EIP-8130, where the sender is a plain secp256k1 EOA. The docs engine still derived a CREATE2 smart account over an implementation that no longer exists, so every live Stablecoin, Asset, and Payments flow fell back to its offline mock. - Re-pin docs/static/aa.txt from base/ui vendor/aa at 1888b88 (ui #177), minified with esbuild 0.25.9 exactly as the previous pin. - Engine v7: the account is toEoaAccount(privateKeyToAccount(pk)); gas is estimated with the K1 sender authenticator; calls are signed as raw phases with an explicit from; receipts are polled over HTTP and checked with allPhasesSucceeded. Implementation resolution and deployment gating are removed, and keccak256 constants are precomputed. - Bump the account storage key to v2 and drop v1 smart-account records. - Test that every engine import exists in the pinned bundle, the keccak constants, and that the shared account is the signer EOA and signs a K1-authenticated EIP-8130 transaction.
Contributor
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
Collaborator
✅ Heimdall Review Status
|
youssefea
marked this pull request as ready for review
October 5, 2026 17:04
soheimam
approved these changes
Oct 5, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed? Why?
Vibenet was reset on 2026-10-02 to Keystore-free EIP-8130: senders are now plain secp256k1 EOAs authenticated by the K1 authenticator (base/ui #177, commit
1888b88, "account demo on Keystore-free EIP-8130 (EOA + delegation)"). The docs demo engine still built a CREATE2 smart account over an EIP-8130 account implementation, so all live demo flows (StablecoinDemo, AssetDemo, and the live PaymentsDemo flows) fell back to their offline mocks.Root cause and evidence (2026-10-05 health check, re-checked here):
/api/vibenet/contractsno longer returns aneip8130block, and the fallbackDefaultAccountpinned inaa.txt(0x81309c54…ADEf) has no code. SoresolveImplementation()returns null,probeCapabilities()reports not live, andengine.getSharedAccount()throws (PaymentsDemo used that throw to go offline).feat/aa-tx-split(chunter-cb/viem@1c72469). That build drops the exports the docs engine imported (newSmartAccount,canonicalAuthenticators,encodeWalletCalls,vibenetDevnetDeployment,waitForTransactionReceipt,keccak256,key) and addstoEoaAccount,k1Authenticator,parseReceiptFields,allPhasesSucceeded, and others.Changes (these mirror ui
app/vibenet/demos/account/useAccountEngine.tsxsignComposed):SDK re-pin.
docs/static/aa.txtis rebuilt from base/uivendor/aa/index.js@1888b88(source sha256876eefde…183c), minified withesbuild@0.25.9 --minify --format=esm --target=es2022 --legal-comments=none. The same command reproduces the previous pin byte-for-byte (28b89794…441d). The new artifact is sha256378b3d6c…7197, andaa.meta.jsonis updated to match.vibenet-engine.txtv7 (the snippets now fetch?v=7):toEoaAccount(privateKeyToAccount(pk)), so the address is the EOA. The salt, implementation,accountChanges/createChange,resolveImplementation, and the deploy gating (waitUntilDeployed) are removed.estimateGasnow runs on every send, withsenderAuthAuthenticator: k1Authenticator,nonceKey: 0n, and metadata asdataSuffix. There is nosenderActorIdanymore.encodeWalletCalls), andsignTransactionnow passesfrom.getTransactionReceipt(which appliesparseReceiptFields), and success requiresallPhasesSucceeded.randomHex(32).probeCapabilities()no longer gates on an account implementation.Stale storage. The account key moves to
base.docs.vibenet.account.v2, and v1 smart-account records are removed on load.Snippets. The engine URL is bumped, the account-key reads move to v2, outdated "account implementation" comments are fixed, and PaymentsDemo no longer special-cases the removed "no live EIP-8130 account implementation" error.
Tests.
scripts/test-vibenet-engine.mjsnow checks:./aa.txtexists in the pinned bundle (this is what would have caught this bug);getSharedAccount()returns the signer's own EOA, and that account signs a K1-authenticated EIP-8130 tx with raw phases;A small test-only
scripts/lib/keccak256.mjsreplaces the bundle's keccak256 inpayments-demo.test.mjs.Intentional gaps, same as before and narrower than ui: a single K1 owner, self-paid gas, nonceKey 0, and HTTP polling instead of the WebSocket watcher.
Notes to reviewers
Live verification
Vibenet stalled at block 76697 after the 2026-10-02 reset; it was reset again on 2026-10-05 at 15:24 UTC and is producing blocks. base/ui
vendor/aais unchanged since1888b88, so the pin in this PR is current.Before/after on the new chain (
StablecoinDemo issue):mint devwith production CSP enforced: PASS, live on Vibenet (1 tx).Full harness on this branch (
run.sh --docs-repo <checkout> --base-url http://localhost:3333 --enforce-prod-csp, 2026-10-05 16:50 UTC, 804 s): 68/68 pass, 0 fail, 0 skip. All 40 live flows completed on chain (126 tx hashes verified); all 28 mock flows unchanged.Sample txs:
0x879ecf7fb6e2867b855b6a74078ba599b837bf091a3f26ae6ee9480910c0a6560xa765ab1a9c8c540db285abfb0de3b9d51fc3cad28a137bb5acd6c64755923f300x73206790370dca5ea2f54dfe9afd3950f33ec62638c675e23430e4a37c7a2af9How has it been tested?
npm test: 113/113 pass.node scripts/test-vibenet-engine.mjs: passes. With the old engine against the new bundle it fails (Failed to evaluate the Vibenet engine: keccak256 is not a function, the same failure the live pages hit). The new import-existence check guards the same thing directly.node scripts/simulate-payments-vibenet.mjs: all checks pass (read-onlyeth_callsimulation of 21 calls on USDV and escrow).createStablecoin(Stablecoin flow) and a USDVmintviasendCalls(Payments flow). Only the balance read,eth_sendRawTransaction, and the receipt poll were stubbed.eth_estimateGasaccepted both EOA-sender requests:0x6fa82for createB20 and0x12cfcfor the USDV mint.0x79signed transactions.eth_sendRawTransactiondecoded them and recovered the sender. It was then rejected only for funds (insufficient funds for gas * price + value: have 0 want 2000000000000000, which is the 2M gas floor × 1 gwei), not for decoding or authentication.Residual risks: the on-chain behaviour of the live flows (receipt shapes, phase statuses, policy/memo logs) is unverified until the harness runs. The only signing evidence so far is the RPC's decode-and-reject.
Screenshots
N/A. No rendered copy changes. Live/offline behaviour is unchanged while Vibenet is down: demos show the labeled offline mock.
Generated with Toshi