You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds real support for muxed (M…) account destinations to token transfer, and hardens muxed handling across the sibling token commands.
token transfer --to now accepts a muxed (M…) destination — both a direct strkey and an alias whose stored key is muxed. The address is passed through as a muxed ScAddress, and the Stellar Asset Contract records its mux id in the transfer event (to_muxed_id). Verified end-to-end against a local network (protocol 28).
UnresolvedScAddress::resolve no longer silently collapses a muxed key to its base G… account; it resolves to ScAddress::MuxedAccount, so a transfer reaches the exact recipient (mux id included) that was named.
The sibling commands still reject muxed accounts up front with a single generic muxed (M…) accounts are not yet supported message, because the host genuinely rejects them there (verified: approve --spender, transfer-from --to, and any muxed source account fail mid-simulation with an opaque host error). The transaction source can't be muxed yet either (see Support muxed (M…) source accounts in the contract invoke pipeline #2645).
is_muxed_alias now preserves a ShadowedReservedAlias collision as a non-muxed result, so an ambiguous reserved-alias config surfaces the actionable collision error rather than the generic muxed message.
Why
Muxed destinations are supported on-chain for transfer, so the CLI should encode them instead of rejecting or silently downgrading to the base account (which would target a different recipient than the one named). Where the host does not yet accept muxed accounts, a clear up-front error beats an opaque simulation failure.
Testing
Unit tests: resolve_preserves_muxed_account_alias, is_muxed_alias_false_when_reserved_alias_is_shadowed.
Integration tests (soroban-test): transfer_to_muxed_destination_succeeds, transfer_to_muxed_alias_succeeds (assert the base account's balance moves), plus the retained muxed-source / sibling rejection tests.
Known limitations
Muxed accounts remain unsupported as a transaction source (#2645) and as approve/transfer-from/burn-from address arguments, matching current host behavior.
Because is_muxed_alias returns false for an already-parsed UnresolvedScAddress::Resolved, a literal --spender M… bypasses this guard and reaches approve, even though the host rejects muxed spenders. That preserves the opaque simulation failure this preflight is meant to avoid; check both literal and alias-resolved muxed addresses, and cover the literal case with a regression test.
The new check covers only aliases. A literal --from M… is already a Resolved address, so it bypasses this branch and is passed to burn_from, leaving the user with the host's opaque muxed-account failure rather than the command's clear error. Check resolved muxed addresses as well and add the corresponding direct-strkey regression test.
This guard only detects muxed aliases, so literal --from M… or --to M… values are parsed as resolved addresses and bypass it. The command then sends a muxed argument to the host, which rejects these positions with the opaque simulation error described in the surrounding comment; include resolved muxed addresses in the preflight instead of intentionally passing them through.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds real support for muxed (
M…) account destinations totoken transfer, and hardens muxed handling across the sibling token commands.token transfer --tonow accepts a muxed (M…) destination — both a direct strkey and an alias whose stored key is muxed. The address is passed through as a muxedScAddress, and the Stellar Asset Contract records its mux id in the transfer event (to_muxed_id). Verified end-to-end against a local network (protocol 28).UnresolvedScAddress::resolveno longer silently collapses a muxed key to its baseG…account; it resolves toScAddress::MuxedAccount, so a transfer reaches the exact recipient (mux id included) that was named.muxed (M…) accounts are not yet supportedmessage, because the host genuinely rejects them there (verified:approve --spender,transfer-from --to, and any muxed source account fail mid-simulation with an opaque host error). The transaction source can't be muxed yet either (see Support muxed (M…) source accounts in the contract invoke pipeline #2645).is_muxed_aliasnow preserves aShadowedReservedAliascollision as a non-muxed result, so an ambiguous reserved-alias config surfaces the actionable collision error rather than the generic muxed message.Why
Muxed destinations are supported on-chain for
transfer, so the CLI should encode them instead of rejecting or silently downgrading to the base account (which would target a different recipient than the one named). Where the host does not yet accept muxed accounts, a clear up-front error beats an opaque simulation failure.Testing
resolve_preserves_muxed_account_alias,is_muxed_alias_false_when_reserved_alias_is_shadowed.soroban-test):transfer_to_muxed_destination_succeeds,transfer_to_muxed_alias_succeeds(assert the base account's balance moves), plus the retained muxed-source / sibling rejection tests.Known limitations
Muxed accounts remain unsupported as a transaction source (#2645) and as
approve/transfer-from/burn-fromaddress arguments, matching current host behavior.