• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

tari-project / tari / 35758794166
72%

Build:
DEFAULT BRANCH: development
Ran 22 Sep 2026 05:59PM UTC
Jobs 1
Files 780
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

22 Sep 2026 05:09PM UTC coverage: 63.925% (+0.5%) from 63.43%
35758794166

push

github

web-flow
fix(wallet): use the wallet output's own commitment mask key id when signing a multisig withdrawal (#8010)

## Depends on

This PR depends on #8009 — `PrepareWithdrawMultisigTransaction` (and the
whole multisig-withdrawal lookup path) is broken without that fix, so
this bug could not previously be exercised end-to-end via the real RPC
surface. Branched from that fix's branch.

## Bug

`TransactionServiceRequest::SignOneSidedWithdrawMultisigTransaction`
fabricates a brand new `TariKeyId::DHCommitmentMask` key id from the
wallet's raw view key and the input's `sender_offset_public_key`,
instead of using the key id that is already attached to the
`WalletOutput` being spent:

```rust
for pair_output in &mut request.info.inputs.iter_mut() {
    let view_key = key_manager.get_view_key();
    let spend_key = key_manager.get_spend_key();

    let commitment_mask_key_id = TariKeyId::DHCommitmentMask {
        private_key: view_key.key_id.clone().into(),
        public_key: pair_output.sender_offset_public_key().clone(),
    };
    let script_pubkey = key_manager
        .stealth_address_script_spending_key(&commitment_mask_key_id, &spend_key.pub_key)?;
    ...
```

Real on-chain multisig deposit outputs (produced by
`create_deposit_multisig_transaction` via `RecipientSpec::stealth(...)`
with `RecipientKeys::DiffieHellman`) carry a `commitment_mask_key_id`
field that is a `TariKeyId::Encrypted{ encrypted, key }` variant — an
encrypted wrapper around the real commitment mask private key, **not** a
freshly re-derivable `DHCommitmentMask`.

Because the handler ignores `pair_output.commitment_mask_key_id()` (the
real key id already on the output) and instead fabricates a different
key id from scratch, `stealth_address_script_spending_key` computes a
**different** public key than the one baked into the deposit's script
`PushPubKey` opcode at creation time. This trips the handler's own
consistency check unconditionally:

```rust
if pushed_pk != &script_pubkey {
    r... (continued)

0 of 1 new or added line in 1 file covered. (0.0%)

45 existing lines in 17 files now uncovered.

91208 of 142680 relevant lines covered (63.92%)

304215.57 hits per line

Uncovered Changes

Lines Coverage ∆ File
1
0.0
0.0% base_layer/wallet/src/transaction_service/service.rs

Coverage Regressions

Lines Coverage ∆ File
11
71.03
-0.93% comms/core/src/connectivity/manager.rs
6
86.84
-1.1% comms/core/src/connection_manager/peer_connection.rs
6
92.18
-1.27% comms/dht/src/outbound/broadcast.rs
5
55.63
2.25% base_layer/core/src/chain_storage/lmdb_db/lmdb_db.rs
3
81.87
-0.61% base_layer/transaction_components/src/validation/aggregate_body/aggregate_body_internal_validator.rs
3
81.25
-4.69% comms/core/src/pipeline/outbound.rs
1
98.88
-1.12% base_layer/common_types/src/dammsum.rs
1
66.14
10.15% base_layer/core/src/chain_storage/blockchain_database.rs
1
87.34
-0.1% base_layer/core/src/proof_of_work/cuckaroo_pow.rs
1
98.24
-0.15% base_layer/core/src/proof_of_work/monero_rx/merkle_tree.rs
1
90.0
-0.18% base_layer/p2p/src/services/liveness/service.rs
1
72.15
-0.42% comms/core/src/connection_manager/listener.rs
1
83.24
-0.54% comms/core/src/connectivity/proactive_dialer.rs
1
67.98
-0.49% comms/core/src/connectivity/requester.rs
1
82.94
-0.2% comms/core/src/noise/socket.rs
1
36.36
-9.09% comms/dht/src/outbound/error.rs
1
33.96
-1.89% comms/dht/src/outbound/message.rs
Jobs
ID Job ID Ran Files Coverage
1 35758794166.1 22 Sep 2026 05:59PM UTC 780
63.92
GitHub Action Run
Source Files on build 35758794166
  • Tree
  • List 780
  • Changed 30
  • Source Changed 1
  • Coverage Changed 30
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35758794166
  • 584394d2 on github
  • Prev Build on development (#35739439001)
  • Next Build on development (#35840025433)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc