Skip to content

wallet-cli-4.10.0

Choose a tag to compare

@gummy789j gummy789j released this 28 Jul 07:08
· 255 commits to master since this release
db60105

Notice

Non-mandatory upgrade

New Features

Change

  1. Add standalone signing commands to the TypeScript CLI: tx sign and typed-data sign. tx sign signs a transaction built elsewhere and prints the signed payload without broadcasting, so the signed result can be handed to tx broadcast later; because it appends to an existing signature array rather than replacing it, a partially signed transaction can be passed from signer to signer until a TRON multi-sig permission threshold is met. typed-data sign signs EIP-712 / TIP-712 structured data and returns the signature, the digest that was signed, and the resolved primary type; it accommodates real-world payloads by ignoring EIP712Domain in types, accepting value as an alias for message and accepting TRON base58 addresses in address fields, while rejecting a declared primaryType that is not the message root, since a nested type can never be what gets signed. Both commands are offline for software accounts (--network is optional) and both work with Ledger accounts. (#957)

  2. Enforce TRON transaction payload integrity before any signature is produced, in the software strategy and on Ledger alike. A TRON transaction states its content three times — raw_data (what a caller reads), raw_data_hex (what the node executes) and txID (the only thing actually signed) — and nothing in the format forces the three to agree, so a payload that displays a harmless raw_data can carry the hash and bytes of a different transaction. Signing now refuses (tx_integrity) unless txID is the sha256 of raw_data_hex, the contract types encoded in raw_data_hex match those raw_data declares, and raw_data re-encodes to exactly those bytes wherever the contract type can be encoded. The checks reject nothing a correct transaction builder produces. (#957)

  3. Make Ledger failures actionable rather than opaque. APDU statuses that previously surfaced as UNKNOWN_ERROR (0x6a8c) are now mapped to typed errors that name the fix: ledger_setting_required for the TRON app's "Sign by Hash", "Transactions data" and "Custom contracts" settings, and ledger_unsupported when the app version does not implement the instruction. Device signing also honours an abort signal, closing the transport immediately instead of holding the native handle until the timeout expires. (#957)

Bug Fixes

Change

  1. Fail closed on invalid global flag values in the TypeScript CLI. An out-of-range or non-matching value for a global flag (for example --timeout 0 or an unrecognized --output) silently fell back to the flag's default and the command ran under settings the caller never asked for. Such a value is now reported as invalid_value before any command dispatch, so no RPC is attempted. (#957)

  2. Reject operations that cannot succeed instead of returning misleading results. contract info on an address with no deployed contract returned a valid-but-empty contract normalized from TronWeb's empty response, and now fails as not found. stake withdraw with nothing withdrawable passed the node's broadcast-time checks but never confirmed, leaving a phantom txid; the withdrawable amount is now queried up front and the command fails with nothing_to_withdraw. (#957)

Integrity Check

All jar files available in this release are signed via this GPG key:

From the download listings below you should see links to the downloadable jar files as well as sig signature files. To verify the authenticity of any jar file, grab the jar and sig files with the same prefix name and then execute the verification process: GPG signature verification