What changed, and why it matters
This commit updates the Stack Wallet app to use a newer version of the underlying Spark library and changes how 'Spark Name' registration fees are calculated. The title says it rejects invalid Spark Name characters, but the actual code diff mainly removes a manual size adjustment for the special name-tag output and updates a dependency. The security relevance is not clearly spelled out in the commit itself, and the change appears to be a partial fix or cleanup rather than a complete, self-contained security patch.
Review the full diff of the updated `flutter_libsparkmobile` dependency at ref `53db5a06a7b7f3df68fe6263f1453f77513bec06` to confirm what changed, especially any Spark Name character validation. Verify that removing `sparkNameFeeScriptSizeDelta` does not cause fee underestimation or transaction malleability. Add or update tests to cover invalid-character rejection and fee-calculation edge cases.
Security signals we found
Dependency update to an external Spark library with an unspecified change set
Removal of manual script-size delta calculation for Spark Name fee outputs
Test updated to check output structure instead of size delta
Commit title implies input validation for Spark Name characters, but no such validation appears in the visible diff
Evidence from the diff
The diff removes the sparkNameFeeScriptSizeDelta accumulator and instead relies on noProofNameTxData!.size for the additional Spark Name transaction size. It also bumps the flutter_libsparkmobile git dependency from ref 171bc186... to 53db5a06..., and updates a test to assert the structure of the tagged output rather than its size delta. The commit title claims invalid Spark Name characters are now rejected, but no validation logic is visible in the diff; that behavior likely lives in the updated dependency. Without the dependency diff, we cannot verify what changed or whether it addresses a security issue.
Changed components
lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dartpubspec.lockscripts/app_config/templates/pubspec.template.yamltest/wallets/spark_name_fee_test.dartExternal dependency: github.com/firoorg/flutter_libsparkmobileInspect captured patch +8 / −9
diff --git a/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart b/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
index bf3e627..fd52362 100644
--- a/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
+++ b/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
@@ -721,7 +721,6 @@ mixin SparkInterface<T extends ElectrumXCurrencyInterface>
final List<InputV2> tempInputs = [];
final List<OutputV2> tempOutputs = [];
- var sparkNameFeeScriptSizeDelta = 0;
for (int i = 0; i < (txData.recipients?.length ?? 0); i++) {
if (txData.recipients![i].amount.raw == BigInt.zero) {
continue;
@@ -742,13 +741,11 @@ mixin SparkInterface<T extends ElectrumXCurrencyInterface>
_bitcoinDartNetwork,
);
if (txData.sparkNameInfo != null) {
- final baseScript = scriptPubKey;
scriptPubKey = sparkNameFeeScript(
baseScript: scriptPubKey,
name: txData.sparkNameInfo!.name,
sparkAddress: txData.sparkNameInfo!.sparkAddress.value,
);
- sparkNameFeeScriptSizeDelta += scriptPubKey.length - baseScript.length;
}
txb.addOutput(
scriptPubKey,
@@ -854,7 +851,7 @@ mixin SparkInterface<T extends ElectrumXCurrencyInterface>
txHash: extractedTx.getHash(),
additionalTxSize: txData.sparkNameInfo == null
? 0
- : noProofNameTxData!.size + sparkNameFeeScriptSizeDelta,
+ : noProofNameTxData!.size,
));
for (final outputScript in spend.outputScripts) {
diff --git a/pubspec.lock b/pubspec.lock
index 1baec63..7518575 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -1028,8 +1028,8 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "171bc186663e3c7a573a6240f28f430e8d6b7d50"
- resolved-ref: "171bc186663e3c7a573a6240f28f430e8d6b7d50"
+ ref: "53db5a06a7b7f3df68fe6263f1453f77513bec06"
+ resolved-ref: "53db5a06a7b7f3df68fe6263f1453f77513bec06"
url: "https://github.com/firoorg/flutter_libsparkmobile.git"
source: git
version: "0.1.0"
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 7ebc0b2..ead1294 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -44,7 +44,7 @@ dependencies:
# flutter_libsparkmobile:
# git:
# url: https://github.com/firoorg/flutter_libsparkmobile.git
-# ref: 171bc186663e3c7a573a6240f28f430e8d6b7d50
+# ref: 53db5a06a7b7f3df68fe6263f1453f77513bec06
# %%END_ENABLE_FIRO%%
# %%ENABLE_EPIC%%
diff --git a/test/wallets/spark_name_fee_test.dart b/test/wallets/spark_name_fee_test.dart
index 442dd3d..745ceff 100644
--- a/test/wallets/spark_name_fee_test.dart
+++ b/test/wallets/spark_name_fee_test.dart
@@ -4,7 +4,7 @@ import 'package:flutter_test/flutter_test.dart';
import 'package:stackwallet/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart';
void main() {
- test('Spark Name fee size includes the tagged output bytes', () {
+ test('Spark Name fee output includes the name and address tag', () {
final baseScript = Uint8List(25);
final feeScript = sparkNameFeeScript(
baseScript: baseScript,
@@ -12,8 +12,10 @@ void main() {
sparkAddress: List.filled(144, 'a').join(),
);
- expect(feeScript.length - baseScript.length, 155);
expect(feeScript.length, 180);
+ expect(feeScript[25], OP_SPARKNAMEID);
+ expect(feeScript[32], OP_DROP);
+ expect(feeScript.last, OP_DROP);
});
test('Spark Name payments never have the miner fee subtracted', () {
Why this scored 45/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.