Skip to content

fix(vibenet): port demo engine to Keystore-free EIP-8130 accounts - #2067

Merged
youssefea merged 2 commits into
masterfrom
fix/vibenet-keystore-free-eip8130-20261005
Oct 5, 2026
Merged

youssefea merged 2 commits into
masterfrom
fix/vibenet-keystore-free-eip8130-20261005

Conversation

@youssefea

@youssefea youssefea commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What changed? Why?

Vibenet was reset on 2026-10-02 to Keystore-free EIP-8130: senders are now plain secp256k1 EOAs authenticated by the K1 authenticator (base/ui #177, commit 1888b88, "account demo on Keystore-free EIP-8130 (EOA + delegation)"). The docs demo engine still built a CREATE2 smart account over an EIP-8130 account implementation, so all live demo flows (StablecoinDemo, AssetDemo, and the live PaymentsDemo flows) fell back to their offline mocks.

Root cause and evidence (2026-10-05 health check, re-checked here):

  • /api/vibenet/contracts no longer returns an eip8130 block, and the fallback DefaultAccount pinned in aa.txt (0x81309c54…ADEf) has no code. So resolveImplementation() returns null, probeCapabilities() reports not live, and engine.getSharedAccount() throws (PaymentsDemo used that throw to go offline).
  • The ui vendor bundle was rebuilt from viem feat/aa-tx-split (chunter-cb/viem@1c72469). That build drops the exports the docs engine imported (newSmartAccount, canonicalAuthenticators, encodeWalletCalls, vibenetDevnetDeployment, waitForTransactionReceipt, keccak256, key) and adds toEoaAccount, k1Authenticator, parseReceiptFields, allPhasesSucceeded, and others.

Changes (these mirror ui app/vibenet/demos/account/useAccountEngine.tsx signComposed):

  • SDK re-pin. docs/static/aa.txt is rebuilt from base/ui vendor/aa/index.js @ 1888b88 (source sha256 876eefde…183c), minified with esbuild@0.25.9 --minify --format=esm --target=es2022 --legal-comments=none. The same command reproduces the previous pin byte-for-byte (28b89794…441d). The new artifact is sha256 378b3d6c…7197, and aa.meta.json is updated to match.

  • vibenet-engine.txt v7 (the snippets now fetch ?v=7):

    • The account is toEoaAccount(privateKeyToAccount(pk)), so the address is the EOA. The salt, implementation, accountChanges/createChange, resolveImplementation, and the deploy gating (waitUntilDeployed) are removed.
    • estimateGas now runs on every send, with senderAuthAuthenticator: k1Authenticator, nonceKey: 0n, and metadata as dataSuffix. There is no senderActorId anymore.
    • Calls are signed as raw phases (no encodeWalletCalls), and signTransaction now passes from.
    • Receipts come from HTTP polling of getTransactionReceipt (which applies parseReceiptFields), and success requires allPhasesSucceeded.
    • The structural gas floor follows ui: 2 × (45k + 22k per call).
    • The bundle no longer exports keccak256, so the role IDs, policy scopes, and the PolicyCreated/Memo topics are precomputed constants. Token salts come from randomHex(32).
    • probeCapabilities() no longer gates on an account implementation.
  • Stale storage. The account key moves to base.docs.vibenet.account.v2, and v1 smart-account records are removed on load.

  • Snippets. The engine URL is bumped, the account-key reads move to v2, outdated "account implementation" comments are fixed, and PaymentsDemo no longer special-cases the removed "no live EIP-8130 account implementation" error.

  • Tests. scripts/test-vibenet-engine.mjs now checks:

    • every name the engine imports from ./aa.txt exists in the pinned bundle (this is what would have caught this bug);
    • the engine uses the Keystore-free surface and none of the removed names;
    • each precomputed constant equals its keccak256;
    • getSharedAccount() returns the signer's own EOA, and that account signs a K1-authenticated EIP-8130 tx with raw phases;
    • the storage key is bumped;
    • receipts are polled.

    A small test-only scripts/lib/keccak256.mjs replaces the bundle's keccak256 in payments-demo.test.mjs.

Intentional gaps, same as before and narrower than ui: a single K1 owner, self-paid gas, nonceKey 0, and HTTP polling instead of the WebSocket watcher.

Notes to reviewers

Live verification

Vibenet stalled at block 76697 after the 2026-10-02 reset; it was reset again on 2026-10-05 at 15:24 UTC and is producing blocks. base/ui vendor/aa is unchanged since 1888b88, so the pin in this PR is current.

Before/after on the new chain (StablecoinDemo issue):

  • docs.base.org (master): FAIL, falls back to the offline mock ("Vibenet has no live EIP-8130 account implementation").
  • This branch, local mint dev with production CSP enforced: PASS, live on Vibenet (1 tx).

Full harness on this branch (run.sh --docs-repo <checkout> --base-url http://localhost:3333 --enforce-prod-csp, 2026-10-05 16:50 UTC, 804 s): 68/68 pass, 0 fail, 0 skip. All 40 live flows completed on chain (126 tx hashes verified); all 28 mock flows unchanged.

Sample txs:

  • Stablecoin issue: 0x879ecf7fb6e2867b855b6a74078ba599b837bf091a3f26ae6ee9480910c0a656
  • Asset create: 0xa765ab1a9c8c540db285abfb0de3b9d51fc3cad28a137bb5acd6c64755923f30
  • Payments accept: 0x73206790370dca5ea2f54dfe9afd3950f33ec62638c675e23430e4a37c7a2af9

How has it been tested?

  • npm test: 113/113 pass.
  • node scripts/test-vibenet-engine.mjs: passes. With the old engine against the new bundle it fails (Failed to evaluate the Vibenet engine: keccak256 is not a function, the same failure the live pages hit). The new import-existence check guards the same thing directly.
  • node scripts/simulate-payments-vibenet.mjs: all checks pass (read-only eth_call simulation of 21 calls on USDV and escrow).
  • Offline dry run against the real Vibenet RPC (blocks were not needed). The engine ran createStablecoin (Stablecoin flow) and a USDV mint via sendCalls (Payments flow). Only the balance read, eth_sendRawTransaction, and the receipt poll were stubbed.
    • The node's EIP-8130 eth_estimateGas accepted both EOA-sender requests: 0x6fa82 for createB20 and 0x12cfc for the USDV mint.
    • The engine produced type 0x79 signed transactions.
    • Submitting the signed createB20 bytes for real to eth_sendRawTransaction decoded them and recovered the sender. It was then rejected only for funds (insufficient funds for gas * price + value: have 0 want 2000000000000000, which is the 2M gas floor × 1 gwei), not for decoding or authentication.
  • No sample tx hashes yet, because the chain is stalled (see above).

Residual risks: the on-chain behaviour of the live flows (receipt shapes, phase statuses, policy/memo logs) is unverified until the harness runs. The only signing evidence so far is the RPC's decode-and-reject.

Screenshots

N/A. No rendered copy changes. Live/offline behaviour is unchanged while Vibenet is down: demos show the labeled offline mock.

Generated with Toshi

Vibenet was reset on 2026-10-02 to Keystore-free EIP-8130, where the sender
is a plain secp256k1 EOA. The docs engine still derived a CREATE2 smart
account over an implementation that no longer exists, so every live
Stablecoin, Asset, and Payments flow fell back to its offline mock.

- Re-pin docs/static/aa.txt from base/ui vendor/aa at 1888b88 (ui #177),
  minified with esbuild 0.25.9 exactly as the previous pin.
- Engine v7: the account is toEoaAccount(privateKeyToAccount(pk)); gas is
  estimated with the K1 sender authenticator; calls are signed as raw phases
  with an explicit from; receipts are polled over HTTP and checked with
  allPhasesSucceeded. Implementation resolution and deployment gating are
  removed, and keccak256 constants are precomputed.
- Bump the account storage key to v2 and drop v1 smart-account records.
- Test that every engine import exists in the pinned bundle, the keccak
  constants, and that the shared account is the signer EOA and signs a
  K1-authenticated EIP-8130 transaction.
@mintlify

mintlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
base 🟢 Ready View Preview Oct 5, 2026, 5:08 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@cb-heimdall

cb-heimdall commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Heimdall Review Status

Requirement Status More Info
Reviews ✅ 1/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

@youssefea
youssefea merged commit 1169505 into master Oct 5, 2026
16 checks passed
@youssefea
youssefea deleted the fix/vibenet-keystore-free-eip8130-20261005 branch October 5, 2026 17:16

This branch was successfully deployed

1 active deployment
staging - docs — b150f8d2 Deployed Oct 5, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants