wallet-cli-4.11.0
Notice
Non-mandatory upgrade
New Features
Change
-
Multi-sig is now a first-class workflow in the TypeScript CLI.
permission showandpermission updateread and replace an account's permission structure on chain (the latter burns 100 TRX and warns before an owner lockout); every broadcast command gained--permission-id <n>,--expiration <ms>, and a new--build-onlyearly-exit mode alongside--dry-run/--sign-only.tx signnow takes a transaction hex via--hex/--file, appends exactly one signature while preserving prior ones, and reports how far the accumulated weight is from the threshold — refusing before a key is ever decrypted if the account is not in the permission group (not_authorized) or has already approved (already_signed);--offlinekeeps the air-gapped path.tx approvalsis the read-only companion that shows the permission group, threshold, accumulated weight, approved signers, and expiration without signing. (#963) -
tx multisigadds optional collaboration through the TronLink multi-sig service. Where the on-chain path passes a hex from person to person, the service holds the transaction, accumulates signatures, and pushes notifications: the default mode lists transactions awaiting this account,--createsigns an unsigned hex and opens a collection at1 / N,--sign <txId>co-signs a pending one, and--watchkeeps a WebSocket open and reports only the count awaiting your signature (never transaction content). Once the threshold is reached the service broadcasts. Credentials (tronlinkSecretId/tronlinkSecretKey/tronlinkChannel) are set withconfigand are per-environment; without them the command fails withtronlink_credentials_missing. (#963) -
gasfreebrings gas-less token transfers to the TypeScript CLI.gasfree inforeports your GasFree address, activation status, nonce, and fee schedule;gasfree transfersigns an EIP-712 structured-data transfer and submits it to the GasFree provider, which puts it on chain and charges the fee in the transferred token itself, so no TRX is required;gasfree trace <traceId>follows the provider'sWAITING → INPROGRESS → CONFIRMING → SUCCEED / FAILEDstates. Because submission goes to a provider rather than a node, the receipt carries atraceIdinstead of atxId— follow it with--waitorgasfree trace, nottx status. Credentials aregasfreeApiKey/gasfreeApiSecretviaconfig. (#963) -
New account-lifecycle and local-utility commands.
account activatecreates a not-yet-existing address on chain without transferring any asset, with the payer covering the creation fee;account setwrites the on-chain name or account id (permanent on mainnet, so it is deliberately one-at-a-time). A local contact book —contact add/list/remove, stored0600in the config directory — lets a saved name be used wherever a recipient is expected (tx send --to,gasfree transfer --to).encoding convert <input>auto-detects an input and prints every equivalent representation (TRON base58 / TRON hex / EVM / public key, or hex / Base64 / Base58Check), rejecting secrets outright.address generateproduces a throwaway keypair offline, writing the private key to a0600file rather than the terminal unless--print-secretis passed.current --qrrenders a scannable receive-address QR in text mode without unlocking or touching the network. (#963) -
The Java documentation was split out of
java/README.mdinto a browsablejava/docs/tree. The README shrank from a single ~2,700-line page to an overview with quick links; commands now live underdocs/commands/by domain (wallet, account, transfers, staking, multisig, GasFree, DEX, proposals, contracts, …), withdocs/concepts/,docs/guide/, and a field-by-fielddocs/reference/config.md. Stale planning and QA scratch documents were removed. No Java behavior changed in this release apart from the version constant. (#963)
Bug Fixes
Change
-
A transaction the node rejected could be reported as submitted. TronWeb does not throw on rejection — it hands back the node's response verbatim, and a rejected
/wallet/broadcasttransactioncarries noresultfield at all, so the previousresult === falsecheck never fired and the CLI returned a success envelope with a txId for a transaction that was never accepted. Acceptance is now white-listed (result !== trueis a rejection) on both the object and--hexbroadcast paths, surfacing the node's reason astransaction_rejected. (#963) -
blocklost precision on large int64 fields. Block responses were parsed through JavaScript numbers, so protobuf int64/uint64 values beyondNumber.MAX_SAFE_INTEGERcame back rounded. Blocks are now fetched and parsed losslessly, with out-of-range integers preserved as exact decimal strings. (#963) -
--dry-runreported doomed staking requests as fine.stake freezeandstake unfreezeare rejected by the node at broadcast time when the amount exceeds the available balance or the amount actually staked for that resource, but--dry-runnever reaches the node — so a request that could not possibly succeed previewed cleanly. Both now pre-flight against the chain and fail withinsufficient_balance/insufficient_stake. Relatedly,contract sendnow warns when the supplied--fee-limitis below the energy estimate at the current energy price, and the staked-amount computation was corrected for the node's habit of omitting the defaultBANDWIDTHenum infrozenV2. (#963) -
Chain-controlled text could repaint the terminal. Permission names, token names and symbols, and co-signer labels are written by whoever put them on chain. Terminal control bytes were already stripped, but bidirectional and zero-width formatting characters passed straight through —
U+202Ereverses the display order of everything after it, letting a crafted name change how the address or weight beside it appears, and zero-width characters can make two different names render identically. Text mode now escapes them visibly (<U+202E>) rather than dropping them, so legitimate right-to-left text still displays normally and tampering is obvious. JSON output is never rewritten. (#963) -
Filesystem failures surfaced as raw OS errors.
backupand the atomic config/keystore writers let NodeErrnoExceptions escape, producinginternal_errorand, on a failed write, leaving a truncated or empty file at the destination. Failures are now typed asio_errorwith the partial artifact removed, and the multi-file atomic write reports a rolled-back failure distinctly from one that committed but could not confirm durability. Two new config-file conditions are also reported explicitly:invalid_configwhenconfig.yamlcannot be parsed (the parser detail is withheld, since it quotes the offending line and may carry a credential) andinsecure_configwhen the file holds service credentials but is a symlink or group/world-readable. (#963) -
Positional arguments rejected number-shaped values. Yargs inferred a type for the anonymous positional tail, so a value such as
0xdeadbeefor12345arrived at its string-typed field as a number and was rejected. The tail is now typed as strings so the raw token survives parsing. As a consequence, a field exposed as a positional no longer also accepts its--<field>spelling — this affects the undocumentedconfig --key/--valueandblock --numberforms; the documented positional form is unchanged, and the global--accountflag still works onuse/rename/delete/backup. (#963)
Integrity Check
All jar files available in this release are signed via this GPG key:
- PUB: 1254 F859 D2B1 BD9F 66E7 107D F859 BCB4 4A28 290B
- UID: build@tron.network
From the download listings below you should see links to the downloadable jar files as well as sig signature files. To verify the authenticity of any jar file, grab the jar and sig files with the same prefix name and then execute the verification process: GPG signature verification