7f01cafc62
Crypto Backend Refactoring
──────────────────────────
- Delete src/ed25519.js — all scalar/point operations now route through
the crypto provider (WASM/FFI/JSI backends only)
- Remove duplicate JS BigInt implementations of scReduce32, scReduce64,
scalarAdd, scalarMul from scanning.js, carrot.js, and carrot-scanning.js;
delegate to Rust backend via crypto/index.js
- Remove debug/test exports from index.js (randomPoint, testDouble,
getBasePoint, isOnCurve, etc.) that were only used during development
- Rebuild WASM binary (476KB → 487KB) with updated Rust crate
Consolidated CryptoNote Scanner (cn_scan)
─────────────────────────────────────────
- New Rust module crates/salvium-crypto/src/cn_scan.rs replaces 5-12
individual FFI round-trips per output with a single native call:
view tag check → derive subaddress pubkey → subaddress map lookup →
amount decryption → commitment mask → key image generation
- FFI wrapper salvium_cn_scan_output in ffi.rs + C header declaration
- FFI backend scanCnOutput() with full subaddress map marshaling
(32-byte key + u32 major/minor LE per entry) and JSON result parsing
- JSI backend delegation via this.native.cnScanOutput()
- wallet-sync.js _scanCNOutput() tries native path first when available
(FFI/JSI), falls through to existing JS pipeline for WASM/JS backends
- Change pub(crate) visibility on subaddress.rs cn_subaddress_secret_key
- 8 Rust unit tests covering view tag, amount, commitment mask,
subaddress matching, and key image generation
- Verified identical results: WASM (JS fallback) and FFI (native cn_scan)
produce same 964 outputs at same chain height; FFI is 3x faster sync
(0.8s vs 2.5s) with 12x less heap (12MB vs 150MB)
RCT Batch Signature Verification
─────────────────────────────────
- New Rust module crates/salvium-crypto/src/rct_verify.rs — single-call
verification of all ring signatures in a transaction (CLSAG + TCLSAG),
avoiding N individual JS↔Rust boundary crossings
- Computes pre-MLSAG message hash matching C++ get_pre_mlsag_hash
- FFI export salvium_verify_rct_signatures with flat byte array interface
- FFI backend verifyRctSignatures() method
- JS backend stub returns null (validation.js handles JS fallback)
- validation.js: 200+ lines of RCT verification logic including
flattenKeyImages, packTclsagSigsFlat, packClsagSigsFlat helpers
Transaction Expansion
─────────────────────
- transaction.js: add expandTransaction() matching C++ expand_transaction_2
(copies key images from prefix inputs into TCLSAG/CLSAG signature structs)
- New test/expand-transaction.test.js (634 lines)
- New test/rct-verify-testnet.test.js (430 lines)
Mining Resilience
─────────────────
- salvium-miner main.rs: retry get_info and get_block_template up to 5
times with 2s delay for transient daemon errors
- full-testnet.js mineTo(): retry miner up to 3 times with 3s delay,
check for partial progress between attempts
Testnet Tooling
───────────────
- sync-only.js: CRYPTO_BACKEND env var for A/B testing (wasm vs ffi)
- full-testnet.js: daemon URL update (node12.whiskymine.io)
- Debug scripts for cn_scan development (debug-cn-scan/marshal/match/wasm)
- Android .gitignore and build-bundle.sh for mobile builds
51 lines
2.4 KiB
JavaScript
51 lines
2.4 KiB
JavaScript
import { setCryptoBackend, getCryptoBackend, generateKeyDerivation, deriveSubaddressPublicKey, deriveViewTag } from '../src/crypto/index.js';
|
|
import { loadWalletFromFile } from './test-helpers.js';
|
|
import { DaemonRPC } from '../src/rpc/daemon.js';
|
|
import { bytesToHex, hexToBytes } from '../src/address.js';
|
|
|
|
const daemon = new DaemonRPC({ url: 'http://node12.whiskymine.io:29081' });
|
|
const path = process.env.HOME + '/testnet-wallet/wallet-a.json';
|
|
|
|
for (const backend of ['wasm', 'ffi']) {
|
|
await setCryptoBackend(backend);
|
|
const w = await loadWalletFromFile(path, 'testnet');
|
|
w.setDaemon(daemon);
|
|
const ws = w._ensureSync();
|
|
|
|
let logged = false;
|
|
const origScan = ws._scanCNOutput.bind(ws);
|
|
ws._scanCNOutput = async function(output, outputIndex, tx, txHash, txPubKey, header, precomputedDerivation) {
|
|
if (!logged) {
|
|
logged = true;
|
|
const outputPubKey = ws._extractOutputPubKey(output);
|
|
const derivation = precomputedDerivation || generateKeyDerivation(txPubKey, ws.keys.viewSecretKey);
|
|
console.log(backend + ' first CN scan:');
|
|
console.log(' outputPubKey:', outputPubKey ? bytesToHex(outputPubKey).slice(0,32) : 'null');
|
|
console.log(' txPubKey:', txPubKey ? bytesToHex(txPubKey).slice(0,32) : 'null');
|
|
console.log(' derivation:', derivation ? bytesToHex(derivation).slice(0,32) : 'null');
|
|
console.log(' viewTag:', output.viewTag);
|
|
console.log(' output.type:', output.type);
|
|
console.log(' rctType:', tx.rct?.type);
|
|
|
|
if (derivation) {
|
|
const vt = deriveViewTag(derivation, outputIndex);
|
|
console.log(' computed viewTag:', vt);
|
|
const derived = deriveSubaddressPublicKey(outputPubKey, derivation, outputIndex);
|
|
console.log(' derivedSpendPubKey:', derived ? bytesToHex(derived).slice(0,32) : 'null');
|
|
console.log(' mainSpendPubKey:', ws._mainSpendPubKeyBytes ? bytesToHex(ws._mainSpendPubKeyBytes).slice(0,32) : 'null');
|
|
if (derived && ws._mainSpendPubKeyBytes) {
|
|
const derivedHex = bytesToHex(derived);
|
|
const mainHex = bytesToHex(ws._mainSpendPubKeyBytes);
|
|
console.log(' match:', derivedHex === mainHex);
|
|
console.log(' subaddresses has:', ws.subaddresses.has(derivedHex));
|
|
}
|
|
}
|
|
}
|
|
return origScan(output, outputIndex, tx, txHash, txPubKey, header, precomputedDerivation);
|
|
};
|
|
|
|
await w.syncWithDaemon();
|
|
console.log(backend + ' outputs:', w._ensureStorage()._outputs.size);
|
|
console.log('');
|
|
}
|