processors/token_transfer: stop coercing a bytes to_muxed_id to 32 bytes - #5985
Merged
Merged
Conversation
A to_muxed_id of type ScvBytes was copied into a fixed 32-byte buffer, so a shorter value was right-padded with zeroes and a longer one truncated to its first 32 bytes. Either way the event reported a muxed id the contract never emitted, silently and with no way for a consumer to tell it apart from a real 32-byte value. The idiom came from NewMuxedInfoFromMemo, where the source is an xdr.Hash and the fixed size is therefore exact. Here the source is an xdr.ScBytes of any length: only a classic transaction memo maps to 32 bytes, while a contract may put any byte string in to_muxed_id. MuxedInfo_Hash.Hash is a []byte, so report what was emitted and let the consumer decide what to make of it. Fixes #5984 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
tamirms
force-pushed
the
fix-to-muxed-id-bytes-coercion
branch
from
August 19, 2026 16:10
6d5c0d1 to
810da12
Compare
tamirms
marked this pull request as ready for review
August 19, 2026 17:09
Contributor
There was a problem hiding this comment.
Pull request overview
Preserves contract-emitted to_muxed_id byte lengths instead of silently padding or truncating them.
Changes:
- Copies
ScvBytesusing its original length. - Adds short, long, and empty-byte regression tests.
- Documents the fix in the changelog.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
processors/token_transfer/contract_events.go |
Preserves emitted byte length. |
processors/token_transfer/contract_events_test.go |
Adds boundary regression coverage. |
CHANGELOG.md |
Records the bug fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
chowbao
approved these changes
Aug 19, 2026
hypekostas
pushed a commit
to stellar/stellar-disbursement-platform-backend
that referenced
this pull request
Sep 4, 2026
Bumps the minor-and-patch group with 10 updates: | Package | From | To | | -------------------------------------------------------------------------------- | --------- | --------- | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.43.6` | `1.44.0` | | [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.37` | `1.32.40` | | [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.19.36` | `1.19.39` | | [github.com/aws/aws-sdk-go-v2/service/ses](https://github.com/aws/aws-sdk-go-v2) | `1.37.6` | `1.38.0` | | [github.com/aws/aws-sdk-go-v2/service/sns](https://github.com/aws/aws-sdk-go-v2) | `1.42.6` | `1.43.0` | | [github.com/getsentry/sentry-go](https://github.com/getsentry/sentry-go) | `0.48.0` | `0.49.0` | | [github.com/go-chi/chi/v5](https://github.com/go-chi/chi) | `5.3.1` | `5.3.2` | | [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus) | `1.10.1` | `1.10.2` | | [github.com/stellar/go-stellar-sdk](https://github.com/stellar/go-stellar-sdk) | `0.7.2` | `0.7.3` | | [github.com/stretchr/testify](https://github.com/stretchr/testify) | `1.12.0` | `1.12.1` | Updates `github.com/aws/aws-sdk-go-v2` from 1.43.6 to 1.44.0 ### Commits * [`a30468c`](aws/aws-sdk-go-v2@a30468c) Release 2026-08-26 * [`d3df5a1`](aws/aws-sdk-go-v2@d3df5a1) Regenerated Clients * [`387db29`](aws/aws-sdk-go-v2@387db29) Update API model * [`79d4bda`](aws/aws-sdk-go-v2@79d4bda) upgrade smithy-go to v1.28.1 ([#3534](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3534)) * [`c5510c6`](aws/aws-sdk-go-v2@c5510c6) Set Content-Length when the request body is set instead of via middleware ([#3](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3)...) * [`655faba`](aws/aws-sdk-go-v2@655faba) Release 2026-08-25 * [`ba4b661`](aws/aws-sdk-go-v2@ba4b661) Regenerated Clients * [`4301eac`](aws/aws-sdk-go-v2@4301eac) Update API model * [`276eacc`](aws/aws-sdk-go-v2@276eacc) Make X-Amz-Checksum-Mode appear on query parameters on presigned URLs ([#3530](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3530)) * [`f39a59d`](aws/aws-sdk-go-v2@f39a59d) Schema serde json 2 ([#3531](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3531)) * Additional commits viewable in [compare view](aws/aws-sdk-go-v2@v1.43.6...v1.44.0) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.37 to 1.32.40 ### Commits * [`a30468c`](aws/aws-sdk-go-v2@a30468c) Release 2026-08-26 * [`d3df5a1`](aws/aws-sdk-go-v2@d3df5a1) Regenerated Clients * [`387db29`](aws/aws-sdk-go-v2@387db29) Update API model * [`79d4bda`](aws/aws-sdk-go-v2@79d4bda) upgrade smithy-go to v1.28.1 ([#3534](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3534)) * [`c5510c6`](aws/aws-sdk-go-v2@c5510c6) Set Content-Length when the request body is set instead of via middleware ([#3](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3)...) * [`655faba`](aws/aws-sdk-go-v2@655faba) Release 2026-08-25 * [`ba4b661`](aws/aws-sdk-go-v2@ba4b661) Regenerated Clients * [`4301eac`](aws/aws-sdk-go-v2@4301eac) Update API model * [`276eacc`](aws/aws-sdk-go-v2@276eacc) Make X-Amz-Checksum-Mode appear on query parameters on presigned URLs ([#3530](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3530)) * [`f39a59d`](aws/aws-sdk-go-v2@f39a59d) Schema serde json 2 ([#3531](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3531)) * Additional commits viewable in [compare view](aws/aws-sdk-go-v2@config/v1.32.37...config/v1.32.40) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.36 to 1.19.39 ### Commits * [`a30468c`](aws/aws-sdk-go-v2@a30468c) Release 2026-08-26 * [`d3df5a1`](aws/aws-sdk-go-v2@d3df5a1) Regenerated Clients * [`387db29`](aws/aws-sdk-go-v2@387db29) Update API model * [`79d4bda`](aws/aws-sdk-go-v2@79d4bda) upgrade smithy-go to v1.28.1 ([#3534](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3534)) * [`c5510c6`](aws/aws-sdk-go-v2@c5510c6) Set Content-Length when the request body is set instead of via middleware ([#3](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3)...) * [`655faba`](aws/aws-sdk-go-v2@655faba) Release 2026-08-25 * [`ba4b661`](aws/aws-sdk-go-v2@ba4b661) Regenerated Clients * [`4301eac`](aws/aws-sdk-go-v2@4301eac) Update API model * [`276eacc`](aws/aws-sdk-go-v2@276eacc) Make X-Amz-Checksum-Mode appear on query parameters on presigned URLs ([#3530](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3530)) * [`f39a59d`](aws/aws-sdk-go-v2@f39a59d) Schema serde json 2 ([#3531](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3531)) * Additional commits viewable in [compare view](aws/aws-sdk-go-v2@credentials/v1.19.36...credentials/v1.19.39) Updates `github.com/aws/aws-sdk-go-v2/service/ses` from 1.37.6 to 1.38.0 ### Commits * [`0ab2d66`](aws/aws-sdk-go-v2@0ab2d66) Release 2025-08-11 * [`ae81008`](aws/aws-sdk-go-v2@ae81008) Regenerated Clients * [`6cf56c1`](aws/aws-sdk-go-v2@6cf56c1) Update endpoints model * [`5e25292`](aws/aws-sdk-go-v2@5e25292) Update API model * [`14e9fb7`](aws/aws-sdk-go-v2@14e9fb7) upgrade to smithy v1.61.0 * [`fcdf6ab`](aws/aws-sdk-go-v2@fcdf6ab) regen * [`2230299`](aws/aws-sdk-go-v2@2230299) fix changelog * [`76aa8d7`](aws/aws-sdk-go-v2@76aa8d7) feat: add support for per service options to Config ([#3145](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3145)) * [`8afe327`](aws/aws-sdk-go-v2@8afe327) Release 2025-08-08 * [`4d6e55d`](aws/aws-sdk-go-v2@4d6e55d) Regenerated Clients * Additional commits viewable in [compare view](aws/aws-sdk-go-v2@service/fis/v1.37.6...v1.38.0) Updates `github.com/aws/aws-sdk-go-v2/service/sns` from 1.42.6 to 1.43.0 ### Commits * [`4fef345`](aws/aws-sdk-go-v2@4fef345) Release 2026-07-21 * [`6275419`](aws/aws-sdk-go-v2@6275419) Regenerated Clients * [`f859830`](aws/aws-sdk-go-v2@f859830) Update API model * [`278591d`](aws/aws-sdk-go-v2@278591d) Add an option to clients to disable clock skew ([#3483](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3483)) * [`d132ac7`](aws/aws-sdk-go-v2@d132ac7) Fix Clock Skew according to internal specification ([#3472](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3472)) * [`03519c9`](aws/aws-sdk-go-v2@03519c9) Release 2026-07-20 * [`dda3efb`](aws/aws-sdk-go-v2@dda3efb) Regenerated Clients * [`348cec0`](aws/aws-sdk-go-v2@348cec0) Update API model * [`f4fd272`](aws/aws-sdk-go-v2@f4fd272) Release 2026-07-17 * [`8e4cbc8`](aws/aws-sdk-go-v2@8e4cbc8) Regenerated Clients * Additional commits viewable in [compare view](aws/aws-sdk-go-v2@service/sqs/v1.42.6...v1.43.0) Updates `github.com/getsentry/sentry-go` from 0.48.0 to 0.49.0 ### Release notes *Sourced from [github.com/getsentry/sentry-go's releases](https://github.com/getsentry/sentry-go/releases).* > ## 0.49.0 > > ### Breaking Changes 🛠 > > * removing DisableLogs and DisableMetrics client options. Sending metrics and logs is already gated by the usage of our APIs already, so having a global kill switch is counter intuitive. Users that won't to opt out should just not call the relevant APIs or setup the integrations. by [@giortzisg](https://github.com/giortzisg) in [#1392](https://redirect.github.com/getsentry/sentry-go/pull/1392) > > ### New Features ✨ > > * add `WithProxy` option for OTLP. This allows setting an `otlptracehttp.HTTPTransportProxyFunc` for the span exporter by [@pierrre](https://github.com/pierrre) in [#1377](https://redirect.github.com/getsentry/sentry-go/pull/1377) > > ### Bug Fixes 🐛 > > * (echo) Propagate span through request context by [@EricGusmao](https://github.com/EricGusmao) in [#1385](https://redirect.github.com/getsentry/sentry-go/pull/1385) > * Skip recover frames on panic. This changes stacktrace behavior for captured panics, removing `sentry.Recover` frames to focus on the actual panic frames. The changes might affect issue grouping. by [@giortzisg](https://github.com/giortzisg) in [#1364](https://redirect.github.com/getsentry/sentry-go/pull/1364) > > ### Internal Changes 🔧 > > #### Deps > > * Bump github.com/labstack/echo/v5 from 5.0.3 to 5.2.0 in /echo by [@dependabot](https://github.com/dependabot) in [#1399](https://redirect.github.com/getsentry/sentry-go/pull/1399) > * Bump github.com/gorilla/websocket from 1.5.1 to 1.5.3 by [@dependabot](https://github.com/dependabot) in [#1397](https://redirect.github.com/getsentry/sentry-go/pull/1397) > * Bump getsentry/craft from 2.26.6 to 2.27.2 by [@dependabot](https://github.com/dependabot) in [#1381](https://redirect.github.com/getsentry/sentry-go/pull/1381) > * Bump actions/setup-go from 6.4.0 to 7.0.0 by [@dependabot](https://github.com/dependabot) in [#1382](https://redirect.github.com/getsentry/sentry-go/pull/1382) > * Bump actions/checkout from 6.0.3 to 7.0.1 by [@dependabot](https://github.com/dependabot) in [#1380](https://redirect.github.com/getsentry/sentry-go/pull/1380) > * Bump google.golang.org/grpc to 1.82.1 and golang.org/x/sys to 0.46.0 by [@dependabot](https://github.com/dependabot) in [#1375](https://redirect.github.com/getsentry/sentry-go/pull/1375) > * Bump golang.org/x/text to v0.39.0 and x/net to v0.56.0 by [@giortzisg](https://github.com/giortzisg) in [#1374](https://redirect.github.com/getsentry/sentry-go/pull/1374) ### Changelog *Sourced from [github.com/getsentry/sentry-go's changelog](https://github.com/getsentry/sentry-go/blob/master/CHANGELOG.md).* > ## 0.49.0 > > ### Breaking Changes 🛠 > > * removing DisableLogs and DisableMetrics client options. Sending metrics and logs is already gated by the usage of our APIs already, so having a global kill switch is counter intuitive. Users that won't to opt out should just not call the relevant APIs or setup the integrations. by [@giortzisg](https://github.com/giortzisg) in [#1392](https://redirect.github.com/getsentry/sentry-go/pull/1392) > > ### New Features ✨ > > * add `WithProxy` option for OTLP. This allows setting an `otlptracehttp.HTTPTransportProxyFunc` for the span exporter by [@pierrre](https://github.com/pierrre) in [#1377](https://redirect.github.com/getsentry/sentry-go/pull/1377) > > ### Bug Fixes 🐛 > > * (echo) Propagate span through request context by [@EricGusmao](https://github.com/EricGusmao) in [#1385](https://redirect.github.com/getsentry/sentry-go/pull/1385) > * Skip recover frames on panic. This changes stacktrace behavior for captured panics, removing `sentry.Recover` frames to focus on the actual panic frames. The changes might affect issue grouping. by [@giortzisg](https://github.com/giortzisg) in [#1364](https://redirect.github.com/getsentry/sentry-go/pull/1364) > > ### Internal Changes 🔧 > > #### Deps > > * Bump github.com/labstack/echo/v5 from 5.0.3 to 5.2.0 in /echo by [@dependabot](https://github.com/dependabot) in [#1399](https://redirect.github.com/getsentry/sentry-go/pull/1399) > * Bump github.com/gorilla/websocket from 1.5.1 to 1.5.3 by [@dependabot](https://github.com/dependabot) in [#1397](https://redirect.github.com/getsentry/sentry-go/pull/1397) > * Bump getsentry/craft from 2.26.6 to 2.27.2 by [@dependabot](https://github.com/dependabot) in [#1381](https://redirect.github.com/getsentry/sentry-go/pull/1381) > * Bump actions/setup-go from 6.4.0 to 7.0.0 by [@dependabot](https://github.com/dependabot) in [#1382](https://redirect.github.com/getsentry/sentry-go/pull/1382) > * Bump actions/checkout from 6.0.3 to 7.0.1 by [@dependabot](https://github.com/dependabot) in [#1380](https://redirect.github.com/getsentry/sentry-go/pull/1380) > * Bump google.golang.org/grpc to 1.82.1 and golang.org/x/sys to 0.46.0 by [@dependabot](https://github.com/dependabot) in [#1375](https://redirect.github.com/getsentry/sentry-go/pull/1375) > * Bump golang.org/x/text to v0.39.0 and x/net to v0.56.0 by [@giortzisg](https://github.com/giortzisg) in [#1374](https://redirect.github.com/getsentry/sentry-go/pull/1374) ### Commits * [`78b09d1`](getsentry/sentry-go@78b09d1) release: 0.49.0 * [`eff9f37`](getsentry/sentry-go@eff9f37) build(deps): bump github.com/labstack/echo/v5 from 5.0.3 to 5.2.0 in /echo (#... * [`c60a2f6`](getsentry/sentry-go@c60a2f6) feat!: remove DisableLogs and DisableMetrics options ([#1392](https://redirect.github.com/getsentry/sentry-go/issues/1392)) * [`c3f2330`](getsentry/sentry-go@c3f2330) build(deps): bump github.com/gorilla/websocket from 1.5.1 to 1.5.3 ([#1397](https://redirect.github.com/getsentry/sentry-go/issues/1397)) * [`9bb14a7`](getsentry/sentry-go@9bb14a7) fix(echo): propagate span through request context ([#1385](https://redirect.github.com/getsentry/sentry-go/issues/1385)) * [`fb9acd8`](getsentry/sentry-go@fb9acd8) build(deps): bump getsentry/craft from 2.26.6 to 2.27.2 ([#1381](https://redirect.github.com/getsentry/sentry-go/issues/1381)) * [`17f540e`](getsentry/sentry-go@17f540e) feat(otel/otlp): add WithProxy option to span exporter ([#1377](https://redirect.github.com/getsentry/sentry-go/issues/1377)) * [`ed9834e`](getsentry/sentry-go@ed9834e) build(deps): bump actions/setup-go from 6.4.0 to 7.0.0 ([#1382](https://redirect.github.com/getsentry/sentry-go/issues/1382)) * [`af6d9db`](getsentry/sentry-go@af6d9db) build(deps): bump actions/checkout from 6.0.3 to 7.0.1 ([#1380](https://redirect.github.com/getsentry/sentry-go/issues/1380)) * [`93223f7`](getsentry/sentry-go@93223f7) build(deps): bump google.golang.org/grpc to 1.82.1 and golang.org/x/sys to 0.... * Additional commits viewable in [compare view](getsentry/sentry-go@v0.48.0...v0.49.0) Updates `github.com/go-chi/chi/v5` from 5.3.1 to 5.3.2 ### Release notes *Sourced from [github.com/go-chi/chi/v5's releases](https://github.com/go-chi/chi/releases).* > ## v5.3.2 > > ## What's Changed > > * feat(middleware): add text/markdown, text/csv, text/vtt to default compressible types by [@VojtechVitek](https://github.com/VojtechVitek) in [go-chi/chi#1151](https://redirect.github.com/go-chi/chi/pull/1151) > * docs: deployment recipe for middleware.ClientIPFromXFFTrustedProxies() by [@VojtechVitek](https://github.com/VojtechVitek) in [go-chi/chi#1111](https://redirect.github.com/go-chi/chi/pull/1111) > * fix: don't drop handlers that collide with a Mount()/Route() pattern by [@VojtechVitek](https://github.com/VojtechVitek) in [go-chi/chi#1148](https://redirect.github.com/go-chi/chi/pull/1148) > * Don't duplicate methods in Allow: header for 405 responses by [@flimzy](https://github.com/flimzy) in [go-chi/chi#1029](https://redirect.github.com/go-chi/chi/pull/1029) > * fix(middleware): reject catch-all compress wildcards by [@VojtechVitek](https://github.com/VojtechVitek) in [go-chi/chi#1156](https://redirect.github.com/go-chi/chi/pull/1156) > > * `middleware.NewCompressor(level, "/*")` never worked and silently compressed nothing. Instead of turning it into a compress-everything catch-all (as proposed in [go-chi/chi#868](https://redirect.github.com/go-chi/chi/issues/868) and [go-chi/chi#1121](https://redirect.github.com/go-chi/chi/pull/1121)), we decided to reject both `"/*"` and `"*/*"` at construction and panic. Compressing every response wastes CPU on already-compressed types (zip, jpeg, png), which is why the middleware keeps a curated default list. Users should pass explicit content types. > **Full Changelog**: go-chi/chi@v5.3.1...v5.3.2 ### Commits * [`3893906`](go-chi/chi@3893906) fix(middleware): reject catch-all compress wildcards `"/*"` and `"*/*"` ([#1156](https://redirect.github.com/go-chi/chi/issues/1156)) * [`9b6ddcd`](go-chi/chi@9b6ddcd) Don't duplicate methods in Allow: header for 405 responses ([#1029](https://redirect.github.com/go-chi/chi/issues/1029)) * [`29164f0`](go-chi/chi@29164f0) fix: don't drop handlers that collide with a Mount()/Route() pattern ([#1148](https://redirect.github.com/go-chi/chi/issues/1148)) * [`bc02284`](go-chi/chi@bc02284) docs: deployment recipe + verify checklist for ClientIPFromXFFTrustedProxies ... * [`60ecea5`](go-chi/chi@60ecea5) feat(middleware): add text/markdown, text/csv, text/vtt to default compressib... * See full diff in [compare view](go-chi/chi@v5.3.1...v5.3.2) Updates `github.com/sirupsen/logrus` from 1.10.1 to 1.10.2 ### Release notes *Sourced from [github.com/sirupsen/logrus's releases](https://github.com/sirupsen/logrus/releases).* > ## v1.10.2 > > # Logrus v1.10.2 > > This is a small maintenance release that updates `github.com/stretchr/testify` to v1.12.1, removing the legacy `gopkg.in/yaml.v3` dependency from Logrus' dependency graph. There are no functional changes in this release. > > Dependency Changes > > * update github.com/stretchr/testify to v1.12.1 > > **Full Changelog**: sirupsen/logrus@v1.10.1...v1.10.2 ### Changelog *Sourced from [github.com/sirupsen/logrus's changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md).* > ## 1.10.2 > > Changed: > > * Update `github.com/stretchr/testify` to v1.12.1, removing the legacy `gopkg.in/yaml.v3` dependency. ### Commits * [`6d6a132`](sirupsen/logrus@6d6a132) Merge pull request [#1586](https://redirect.github.com/sirupsen/logrus/issues/1586) from thaJeztah/prepare_v1.10.2 * [`4f94653`](sirupsen/logrus@4f94653) update changelog for v1.10.2 * [`87434bb`](sirupsen/logrus@87434bb) Merge pull request [#1585](https://redirect.github.com/aws/aws-sdk-go-v2/issues/1585) from thaJeztah/bump_testify * [`e7d2120`](sirupsen/logrus@e7d2120) chore(deps): bump github.com/stretchr/testify v1.12.1 * See full diff in [compare view](sirupsen/logrus@v1.10.1...v1.10.2) Updates `github.com/stellar/go-stellar-sdk` from 0.7.2 to 0.7.3 ### Release notes *Sourced from [github.com/stellar/go-stellar-sdk's releases](https://github.com/stellar/go-stellar-sdk/releases).* > ## v0.7.3 > > ## What's Changed > > * changelog: cut the Pending section as 0.7.2, and record 0.7.1 by [@Shaptic](https://github.com/Shaptic) in [stellar/go-stellar-sdk#5980](https://redirect.github.com/stellar/go-stellar-sdk/pull/5980) > * xdr: export LedgerCloseMetaView.LedgerHeader by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5982](https://redirect.github.com/stellar/go-stellar-sdk/pull/5982) > * processors/token_transfer: accept a Void-encoded to_muxed_id in V4 event data by [@tamirms](https://github.com/tamirms) in [stellar/go-stellar-sdk#5983](https://redirect.github.com/stellar/go-stellar-sdk/pull/5983) > * processors/token_transfer: stop coercing a bytes to_muxed_id to 32 bytes by [@tamirms](https://github.com/tamirms) in [stellar/go-stellar-sdk#5985](https://redirect.github.com/stellar/go-stellar-sdk/pull/5985) > * rpcclient: add Client.URL() to expose configured RPC server URL by [@Dione-b](https://github.com/Dione-b) in [stellar/go-stellar-sdk#5973](https://redirect.github.com/stellar/go-stellar-sdk/pull/5973) > > ## New Contributors > > * [@Dione-b](https://github.com/Dione-b) made their first contribution in [stellar/go-stellar-sdk#5973](https://redirect.github.com/stellar/go-stellar-sdk/pull/5973) > > **Full Changelog**: stellar/go-stellar-sdk@v0.7.2...v0.7.3 ### Changelog *Sourced from [github.com/stellar/go-stellar-sdk's changelog](https://github.com/stellar/go-stellar-sdk/blob/main/CHANGELOG.md).* > # Changelog > > This repository adheres to [Go module Versioning](https://go.dev/doc/modules/version-numbers). > > This monorepo contains a number of sdk's: > > * `horizonclient` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/clients/horizonclient/CHANGELOG.md)) > * `txnbuild` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/txnbuild/CHANGELOG.md)) > * `rpcclient` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/clients/rpcclient/CHANGELOG.md)) > * `corelient` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/clients/stellarcore/CHANGELOG.md)) > > Official project releases may be found here: https://github.com/stellar/go-stellar-sdk/releases > > ## Pending > > ### New Features > > * xdr: Added `LedgerCloseMetaView.LedgerHeader()`, exposing the version-resolving header accessor that already backs `LedgerSequence`, `LedgerCloseTime`, `LedgerHash`, and `PreviousLedgerHash` ([#5982](https://redirect.github.com/stellar/go-stellar-sdk/pull/5982)) > * rpcclient: Add `Client.URL()` to expose the configured RPC server URL ([#5885](https://redirect.github.com/stellar/go-stellar-sdk/issues/5885)) > > ### Bug Fixes > > * processors/token_transfer: Accept a `to_muxed_id` bound to `Void` in V4 event data. CAP-0067 specifies that the key is simply absent when there is no muxed destination, and that form already parsed. `Void` is what a contract emits instead if it publishes its event data as a `#[contracttype]` struct with an `Option` field — the natural way to write it before CAP-0086's sparse maps, which omit the key. Such an event previously failed to parse and was dropped from the event stream entirely, silently ([#5983](https://redirect.github.com/stellar/go-stellar-sdk/pull/5983)) > * processors/token_transfer: Report a `to_muxed_id` of type `ScvBytes` at the length the contract emitted. It was previously copied into a fixed 32-byte buffer, so a shorter value was right-padded with zeroes and a longer one truncated, reporting a muxed id that was never emitted. Only a classic transaction memo maps to a fixed 32 bytes here; a contract may put any byte string in `to_muxed_id` ([#5984](https://redirect.github.com/stellar/go-stellar-sdk/issues/5984)) ### Commits * [`83d7730`](stellar/go-stellar-sdk@83d7730) rpcclient: add Client.URL() to expose configured RPC server URL ([#5973](https://redirect.github.com/stellar/go-stellar-sdk/issues/5973)) * [`968da50`](stellar/go-stellar-sdk@968da50) processors/token_transfer: stop coercing a bytes to_muxed_id to 32 bytes ([#5985](https://redirect.github.com/stellar/go-stellar-sdk/issues/5985)) * [`a7921dd`](stellar/go-stellar-sdk@a7921dd) processors/token_transfer: accept a Void-encoded to_muxed_id in V4 event data... * [`7cf2188`](stellar/go-stellar-sdk@7cf2188) xdr: export LedgerCloseMetaView.LedgerHeader ([#5982](https://redirect.github.com/stellar/go-stellar-sdk/issues/5982)) * [`91e2cdd`](stellar/go-stellar-sdk@91e2cdd) changelog: cut the Pending section as 0.7.2, and record 0.7.1 ([#5980](https://redirect.github.com/stellar/go-stellar-sdk/issues/5980)) * See full diff in [compare view](stellar/go-stellar-sdk@v0.7.2...v0.7.3) Updates `github.com/stretchr/testify` from 1.12.0 to 1.12.1 ### Release notes *Sourced from [github.com/stretchr/testify's releases](https://github.com/stretchr/testify/releases).* > ## v1.12.1 > > This is the first release which has the minimum dependencies practical in testify v1. The last remaining dependencies are github.com/stretchr/objx which itself has no dependencies, and go.yaml.in/yaml/v3. Removing objx would require v2, it cannot be vendored. Removing YAML would require vendoring the yaml library, which would do more harm than good. It's better to become aware of vulnerabilities in the official yaml package than to attempt to maintain our own. > > ## What's Changed > > * Change yaml library to `go.yaml.in/yaml/v3` by [@harryzcy](https://github.com/harryzcy) in [stretchr/testify#1935](https://redirect.github.com/stretchr/testify/pull/1935) > * change yaml library to go.yaml.in/yaml/v3 by [@boekkooi-impossiblecloud](https://github.com/boekkooi-impossiblecloud) in [stretchr/testify#1772](https://redirect.github.com/stretchr/testify/pull/1772) > > ## New Contributors > > * [@harryzcy](https://github.com/harryzcy) made their first contribution in [stretchr/testify#1935](https://redirect.github.com/stretchr/testify/pull/1935) > * [@boekkooi-impossiblecloud](https://github.com/boekkooi-impossiblecloud) made their first contribution in [stretchr/testify#1772](https://redirect.github.com/stretchr/testify/pull/1772) > > **Full Changelog**: stretchr/testify@v1.12.0...v1.12.1 > > ## What's Changed > > * Change yaml library to `go.yaml.in/yaml/v3` by [@harryzcy](https://github.com/harryzcy) in [stretchr/testify#1935](https://redirect.github.com/stretchr/testify/pull/1935) > * change yaml library to go.yaml.in/yaml/v3 by [@boekkooi-impossiblecloud](https://github.com/boekkooi-impossiblecloud) in [stretchr/testify#1772](https://redirect.github.com/stretchr/testify/pull/1772) > > ## New Contributors > > * [@harryzcy](https://github.com/harryzcy) made their first contribution in [stretchr/testify#1935](https://redirect.github.com/stretchr/testify/pull/1935) > * [@boekkooi-impossiblecloud](https://github.com/boekkooi-impossiblecloud) made their first contribution in [stretchr/testify#1772](https://redirect.github.com/stretchr/testify/pull/1772) > > **Full Changelog**: stretchr/testify@v1.12.0...v1.12.1 ### Commits * [`959dbda`](stretchr/testify@959dbda) Merge pull request [#1935](https://redirect.github.com/stretchr/testify/issues/1935) from harryzcy/yaml-update * [`9bb7176`](stretchr/testify@9bb7176) Update go.yaml.in/yaml/v3 to v3.0.5 * [`0358d0e`](stretchr/testify@0358d0e) change yaml library to go.yaml.in/yaml/v3 * See full diff in [compare view](stretchr/testify@v1.12.0...v1.12.1)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #5984.
The bug
parseV4MapDataForTokenEventscopied ato_muxed_idof typeScvBytesinto a fixed 32-byte buffer:copymovesmin(32, len(val))bytes, so a value shorter than 32 was right-padded with zeroes and a longer one truncated to its first 32. Either way the emitted event reported a muxed id the contract never sent, silently — and a consumer cannot distinguish a genuine 32-byte value from a 4-byte one zero-extended into the same shape.Where it came from
The same three lines appear in
NewMuxedInfoFromMemo(muxed_info.go), where the source is*m.Hash— anxdr.Hash, i.e.[32]byte. There the fixed size is exact and the copy is just a safe array-to-slice conversion.Here the source is an
xdr.ScBytes, which is[]byteand unbounded, so the identical code silently coerces. The 32 was inherited from the classic path, not from the data model:MuxedInfo_Hash.Hashis a[]byte, so nothing downstream requires a fixed width.The fix
Allocate
len(val)instead of32, keeping the defensive copy so nothing aliases the event's XDR buffer.Per CAP-0067, only classic-derived events map
to_muxed_idto bytes, and there it is a 32-byteMEMO_HASH/MEMO_RETURN. A custom SEP-41 contract may put any byte string in that field, so the parser now reports what was emitted and leaves any length policy to the consumer.The issue floated ignoring such events instead. That trades silent corruption for silent loss: callers discard an event whose parse fails rather than surfacing an error (
token_transfer_processor.go), so rejecting would drop the transfer's amount and both addresses over a field carrying no value.Tests
Three cases added to
TestValidContractEventsV4— shorter than 32, longer than 32, and empty. Each was confirmed to fail against the unfixed parser:The existing hash-memo case uses exactly 32 bytes, so neither branch was previously covered.
processors/token_transferpasses;gofmtclean,go vetclean under the flagsgovet.shuses.🤖 Generated with Claude Code