Skip to content

fix(txe): authorize sync_state utility calls in inlined contexts - #25034

Merged
nchamo merged 1 commit into
merge-train/fairiesfrom
nchamo/hooks-fix
Jul 30, 2026
Merged

nchamo merged 1 commit into
merge-train/fairiesfrom
nchamo/hooks-fix

Conversation

@nchamo

@nchamo nchamo commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Problem

TestEnvironmentOptions::with_all_utility_call_targets_authorized() did not apply to utility calls made from a contract's sync_state: the TXE session's contract-sync executor built its UtilityExecutionOracle without the hooks object carrying the authorization callback, so any cross-contract utility call made during sync was denied with "No authorizeUtilityCall hook configured" regardless of the option. The other oracle construction sites (top-level flows and the inlined contexts' own oracles) passed the hook correctly.

The scenario was also unreachable from inlined contexts: the RPC translator never implemented aztec_utl_callUtilityFunction, so a cross-contract utility call from env.private_context / env.utility_context failed with "Unknown oracle" (an error TXE itself flags as "unexpected, please report it").

Fix

  • Add the missing aztec_utl_callUtilityFunction method to TXE's RPC translator, so inlined contexts support cross-contract utility calls.
  • Factor a buildExecutionHooks() helper on TXESession and use it at every oracle construction site, including the contract-sync executor, so session options apply on all execution paths.
  • Cover it with a capsule-gated custom_sync_state hook on NestedUtility that records its cross-contract call's result, plus tests for sync-time calls from both inlined contexts (authorized and default-denied).

@nchamo nchamo self-assigned this Jul 28, 2026
@nchamo nchamo added ci-draft Run CI on draft PRs. ci-no-fail-fast Sets NO_FAIL_FAST in the CI so the run is not aborted on the first failure labels Jul 28, 2026
scopes,
simulator,
utilityExecutor: this.utilityExecutorForContractSync(anchorBlock),
hooks: this.buildExecutionHooks(),

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was the actual bug, we weren't building hooks here

@nchamo
nchamo marked this pull request as ready for review July 28, 2026 19:26
@nchamo
nchamo requested a review from vezenovm July 28, 2026 19:26

@vezenovm vezenovm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good

@nchamo
nchamo merged commit 322b948 into merge-train/fairies Jul 30, 2026
43 of 47 checks passed
@nchamo
nchamo deleted the nchamo/hooks-fix branch July 30, 2026 19:31
rangozd pushed a commit to rangozd/aztec-packages that referenced this pull request Aug 5, 2026
BEGIN_COMMIT_OVERRIDE
fix(pxe): validate a BoundedVec against its storage array on
deserialization (AztecProtocol#25035)
chore: add disclaimers on poc contracts (AztecProtocol#24975)
chore: begin nr constant cleanup (AztecProtocol#25014)
fix(txe): authorize sync_state utility calls in inlined contexts
(AztecProtocol#25034)
refactor(stdlib): a function's return type is a single optional AbiType
(AztecProtocol#25066)
feat(pxe): hash-pinned node read cache (AztecProtocol#24969)
feat(noir-projects): publish compiled protocol artifacts to npm (AztecProtocol#25075)
fix(ci): trim GitHub commit API response in upload_benchmarks to avoid
E2BIG on large merge commits (AztecProtocol#25077)
END_COMMIT_OVERRIDE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-draft Run CI on draft PRs. ci-no-fail-fast Sets NO_FAIL_FAST in the CI so the run is not aborted on the first failure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants