Skip to content

wallet-cli-4.12.0

Choose a tag to compare

@gummy789j gummy789j released this 19 Aug 06:43
· 196 commits to master since this release
0190dab

Notice

Non-mandatory upgrade

New Features

Change

  1. Chain governance and super-representative operation come to the TypeScript CLI. proposal list / show read chain-parameter proposals and are open to anyone, while proposal create / approve / delete require a registered witness; proposals are expressed in named chain parameters rather than raw numeric keys, and a created proposal's id is resolved from a snapshot taken before submission instead of guessed from the list afterwards. witness create / update / set-brokerage register and operate a super representative. Contract governance follows the same path: contract clear-abi, contract set-origin-energy-limit, contract set-user-resource-percent, and contract create2 for deterministic deployment addresses. Every write goes through the shared transaction pipeline, so --dry-run, --build-only, --sign-only, --permission-id, and multi-sig behave exactly as they do for transfers. (#972, #975)

  2. TRC10 issuance and the protocol-level Bancor exchange are now first-class commands. asset issue / update / participate / unfreeze / info / list cover the life of a TRC10 token (transfers continue to go through tx send), and exchange create / inject / withdraw / trade / show / list drive TRON's on-chain exchange. These reads are fetched and parsed losslessly, so an int64 total_supply or frozen_amount above 2^53 is reported exactly as a decimal string rather than rounded — sampling 1,400 mainnet assets found 252 above that bound. Reads are bound to the id asked for and to the protocol's precision range, and issuance still refuses a supply above 2^53 because java-tron cannot parse a numeric string into that field on the non-visible broadcast path. (#972, #975)

  3. Web3 keystore import and export, with an audit log for what left the machine. import keystore reads a standard Web3 v3 keystore file: the file is read and structurally validated before either password is asked for, so a mistyped path costs no typing, and both passwords — the file's own and the local master password — remain hidden-TTY-only. backup --keystore writes an account out in the same format, and backup --records lists the export audit log, which is preserved rather than overwritten when its contents cannot be read. The codec refuses a dklen below 32, which would leave the MAC's key slice empty and let any password appear to open the file, and compares the MAC as bytes so an uppercase-hex file is accepted instead of being reported as a wrong password. (#975)

  4. The TypeScript CLI now ships as a standalone executable, with no Node.js install required. npm run build:standalone compiles a single self-contained binary, and a GitHub Actions workflow builds and verifies one per platform — Linux x64/arm64, macOS x64/arm64, and Windows x64 — each built on its native runner so the embedded Ledger HID addon matches, checked against a glibc 2.35 baseline on Linux, and smoke-tested before publication. A companion CI workflow runs the architecture check, type-check, tests, and bundle build on every pull request. With this release the TypeScript CLI covers the same TRON feature surface as the Java REPL; the two now differ in how you drive them, not in what they can do. (#977)

Bug Fixes

Change

  1. A broadcast receipt quoted the node's transaction id instead of deriving its own. A TRON txID is the sha256 of the transaction body — derivable from the bytes that were signed, as --sign-only already did — but the broadcast path returned whatever the node echoed back. A dishonest node therefore chose which transaction --wait polled for and which id the receipt named, so a receipt could end up describing someone else's confirmed transaction. The derived id now wins across all three broadcast paths (the pipeline, tx broadcast --file, and the multi-sig relay); a disagreement is reported as a warning rather than an error, because the transaction has already been sent. (#975)

  2. Amounts in a --wait receipt lost precision above 2^53. /wallet/gettransactioninfobyid was still fetched through TronWeb's plain JSON.parse, so realized int64 quantities — unfreeze_amount, withdraw_amount, and the exchange amounts — were already rounded float64 values before the CLI saw them. This endpoint now follows the same lossless fetch and parse as getAccount, getBlock, listwitnesses, and listproposals. (#975)

  3. account activate --address accepted anything non-empty. The address was typed as a plain non-empty string rather than a TRON address, so a malformed value was only rejected once the node saw it. It is now validated locally, like every other address-taking command. Two documentation errors were corrected alongside it: contract deploy --build-only documented unsigned / unsignedHex while the command emits tx / hex, and the pagination inventory listed proposal show, which returns a single proposal, while omitting proposal list, which paginates. (#975)

Integrity Check

All jar files available in this release are signed via this GPG key:

From the download listings below you should see links to the downloadable jar files as well as sig signature files. To verify the authenticity of any jar file, grab the jar and sig files with the same prefix name and then execute the verification process: GPG signature verification