Docs menu

SHRIVE docs, for developers

ShriveCollection

Payment release blocked

This source targets the NU6.3 Ironwood pool and a signature claim that keeps the saved code private. The ZEC API is hard closed. Do not send payment. Rust compilation, live Ironwood receipt, reserve and claim integration, host validation and independent review remain UNVERIFIED. See the Zcash advisory.

Local implementation. No production collection address is published. The project owner controls pause and signer changes. The configured signer authorizes Pons buys and ZEC reservations.

Status

Pons buy claim

mintForBuy(address buyer,bytes32 buyRef,uint256 amountIn,uint256 deadline,bytes signature) requires msg.sender == buyer, an EIP-712 signature under domain Shrive Collection version 1, an unused buy reference, a buyer who has never claimed by this path, a minimum buy, and an unexpired deadline. The buyer wallet pays for CREATE2 publication if needed and its own mint. Server relay requests are refused.

ZEC payment and code claim

The browser generates a valid random secp256k1 signing code before payment. It sends only keccak256(20-byte signing address) as the public identifier. An Ironwood watcher source scans post-NU6.3 compact actions and filters decrypted ValuePool::Ironwood outputs. It checks the receiver, amount, exact memo and confirmations. The EVM reserve signer is trusted; chain 4663 does not verify a Zcash proof.

Redemption

reserve(codeHash,amount) is signer only. claimWithCode(bytes32 codeHash,address to,bytes signature) verifies a versioned EIP-712 signature from the code-derived signing address. The domain binds chain and contract; the signed fields bind caller and recipient. The code never enters API payloads or transaction calldata. The identifier, caller, recipient and signature are public. Legacy reservations need a fresh deployment and state rollout.

Operating limits

The ZEC door remains closed until a reviewed watcher, API host and EVM signer are deployed. A fresh verified watcher heartbeat, durable invoice and watcher state, mainnet receiver ownership check, chain 4663 signer check and configured price are required. A stale watcher closes invoices. Public lightwalletd supplies chain data and availability, not a consensus proof. The watcher sees received amounts and memo hashes; timing and network metadata can correlate activity. A reorg after an EVM reserve requires manual incident response because the cross-chain reserve cannot be reversed automatically. Phala attestation is planned and unverified until deployment.

Signer rotation

Only the owner can call setSigner(address next), and the new signer must be nonzero. A successful change emits SignerChanged(oldSigner,newSigner). Pending mint authorizations signed by the old signer then fail. Coordinate the Pons signer and SHRIVE_RESERVE_SIGNER_KEY with the on-chain rotation. The contract currently has one signer role for both paths.