Skip to content

fix(ismp): decode the relayer account, and cover the inbound path - #149

Merged
nol4lej merged 4 commits into
mainfrom
test/ismp-inbound-coverage
Sep 15, 2026
Merged

nol4lej merged 4 commits into
mainfrom
test/ismp-inbound-coverage

Conversation

@nol4lej

@nol4lej nol4lej commented Sep 15, 2026

Copy link
Copy Markdown
Member

Two commits, kept separate because one changes consensus and the other does not.

1 · fix(ismp): decode the relayer account from its SCALE-encoded receipt value

DeliveryConfirmed.relayer published the receipt's stored bytes verbatim. pallet-ismp writes that receipt with child::put (child_trie.rs:154), which encodes, so a 32-byte account is stored as 33 bytes: a compact length prefix (0x80) followed by the account. Observed live as 0x8022b6e6…9763, where the account is 0x22b6e6…9763.

Not cosmetic: the published relayer matched no account anyone could look up. on_response now SCALE-decodes before emitting, and a value that fails to decode emits nothing — the receipt's presence is already the proof of delivery, so the account answers who, not whether.

The existing tests passed with unencoded data, so they would have stayed green with the bug in place. They now store what the chain actually stores, and one asserts the 33-byte width explicitly.

spec_version 15. No migration, no storage change, no weight change. transaction_version stays at 3 — no call signature moved. RUNTIME_VERSIONS.md also marks spec 14 as released (2026-09-13, v0.1.0-rc.25, live from block 829906) and records this defect against it: events indexed while spec 14 was live keep the 33-byte shape.

2 · test(ismp): cover the inbound path and the runtime router that feeds it

AcceptedSources has been populated on testnet (KUSAMA-4009, EVM-97) since spec 14, but no inbound message has ever arrived — InboundCount is still 0. Every inbound behaviour is unexercised on the live chain, so a regression would surface as a message silently lost rather than as a failing test.

Eleven tests pin what the first real arrival will hit: attribution of an event to the message that caused it, data messages alongside pings, oversized bodies rejected before decoding, rejections that still name what they refused, source acceptance as the gate that opens the door, repeated arrivals each getting their own row, and a body an EVM caller would build.

One runtime test covers a step nothing else does: the pallet's own tests call IsmpModuleCallback directly, so nothing proved the real router resolves our module id and hands it a PostRequest — exactly the path a message from Hyperbridge takes.

Tests only: no runtime change, no spec_version bump.

Verification

Command Result
cargo test -p pallet-ismp-messaging 65 passed
cargo test -p orbinum-runtime --lib configs::ismp 17 passed
cargo check -p orbinum-runtime clean

@nol4lej
nol4lej merged commit 74ce17f into main Sep 15, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant