fix(txe): authorize sync_state utility calls in inlined contexts - #25034
Merged
Merged
Conversation
nchamo
commented
Jul 28, 2026
| scopes, | ||
| simulator, | ||
| utilityExecutor: this.utilityExecutorForContractSync(anchorBlock), | ||
| hooks: this.buildExecutionHooks(), |
Contributor
Author
There was a problem hiding this comment.
This was the actual bug, we weren't building hooks here
nchamo
marked this pull request as ready for review
July 28, 2026 19:26
rangozd
pushed a commit
to rangozd/aztec-packages
that referenced
this pull request
Aug 5, 2026
BEGIN_COMMIT_OVERRIDE fix(pxe): validate a BoundedVec against its storage array on deserialization (AztecProtocol#25035) chore: add disclaimers on poc contracts (AztecProtocol#24975) chore: begin nr constant cleanup (AztecProtocol#25014) fix(txe): authorize sync_state utility calls in inlined contexts (AztecProtocol#25034) refactor(stdlib): a function's return type is a single optional AbiType (AztecProtocol#25066) feat(pxe): hash-pinned node read cache (AztecProtocol#24969) feat(noir-projects): publish compiled protocol artifacts to npm (AztecProtocol#25075) fix(ci): trim GitHub commit API response in upload_benchmarks to avoid E2BIG on large merge commits (AztecProtocol#25077) END_COMMIT_OVERRIDE
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
TestEnvironmentOptions::with_all_utility_call_targets_authorized()did not apply to utility calls made from a contract'ssync_state: the TXE session's contract-sync executor built itsUtilityExecutionOraclewithout thehooksobject carrying the authorization callback, so any cross-contract utility call made during sync was denied with "No authorizeUtilityCall hook configured" regardless of the option. The other oracle construction sites (top-level flows and the inlined contexts' own oracles) passed the hook correctly.The scenario was also unreachable from inlined contexts: the RPC translator never implemented
aztec_utl_callUtilityFunction, so a cross-contract utility call fromenv.private_context/env.utility_contextfailed with "Unknown oracle" (an error TXE itself flags as "unexpected, please report it").Fix
aztec_utl_callUtilityFunctionmethod to TXE's RPC translator, so inlined contexts support cross-contract utility calls.buildExecutionHooks()helper onTXESessionand use it at every oracle construction site, including the contract-sync executor, so session options apply on all execution paths.custom_sync_statehook onNestedUtilitythat records its cross-contract call's result, plus tests for sync-time calls from both inlined contexts (authorized and default-denied).