Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Ogmios: represent 64-bit amounts as bigint with lossless JSON to avoid precision loss

已关闭
#406 1 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

维护者通常 1 天内回复

@emmanuel-musau 已经在做这个了。

开始于 2026年9月28日。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
55/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
冷清
技术栈
typescript
领域
api, backend

调研方向

从 packages/evolution/src/sdk/provider/internal/Ogmios.ts 开始,重点检查受影响的金额类型和 toOgmiosUTxOs,然后检查 HttpUtils.postJson 的请求和响应序列化。跟踪来自 KupmiosEffects.ts 和 KoiosEffect.ts 的 additionalUtxo 路径。完成的标准是回归用例将 2^64-1 和 2^53+1 保留为精确且不带引号的 JSON 数字,并且入站金额解析不会丢失精度。

由索引模型根据 Issue 内容生成。

描述

bug external-review

Summary

The Ogmios provider converts 64-bit Cardano amounts (lovelace and native-token quantities) with Number(...), but a JS number is exact only to 2^53-1. Cardano amounts are uint64, so any value above 2^53 is silently corrupted. Every other provider uses BigInt(...), and the SDK models Coin as Schema.BigInt up to 2^64-1, so this is an inconsistent defect. The corrupted values are sent to Ogmios as the additionalUtxo set during transaction evaluation, producing wrong ex-units/fees and on-chain rejection for transactions involving high-supply tokens. Fail closed: no fund loss, the tx is just rejected.

Affected

packages/evolution/src/sdk/provider/internal/Ogmios.ts: OgmiosAssets type (L128), Value type (L130-132), toOgmiosUTxOs Number(quantity) (L189) and Number(lovelace) (L216), inbound LovelaceAsset schema (L24-26), Delegation rewards/deposit (L118-119)
reached via: KupmiosEffects.ts:380 and KoiosEffect.ts:325 (additionalUtxo for evaluateTransaction)
transport: HttpUtils.postJson (bodyJson -> JSON.stringify on send; response.json -> JSON.parse on receive)
contrast (correct): Koios.ts:292/298, Maestro.ts toBigInt, Blockfrost.ts

Fix

Represent Ogmios amounts as bigint end to end (OgmiosAssets -> Record<string, Record<string, bigint>>, Value.ada.lovelace -> bigint, drop Number(...) in toOgmiosUTxOs).
Important: Ogmios encodes amounts as UNQUOTED JSON numbers (per the Ogmios v6 API, e.g. { "ada": { "lovelace": 1234 } }), so:

  • on send, a bigint cannot go through JSON.stringify; emit it as a bare JSON numeric literal via a lossless serializer (json-bigint style or a replacer that splices the integer), not as a quoted string (Ogmios will reject a string).
  • on receive, response.json uses standard JSON.parse which truncates above 2^53 before the schema, so any inbound amount field that can exceed 2^53 needs a big-int-aware parser, not just a BigInt schema. (The evaluate response is only ex-units, which are small, so the live issue is the send path; fix the receive path too for correctness on amount-bearing Ogmios queries.)

Regression test

  • given: a UTxO with token quantity 2^64-1 and lovelace 2^53+1, run toOgmiosUTxOs([utxo]) and serialize the additionalUtxo body the same way the request does
  • before fix: amounts are corrupted (2^64-1 -> 18446744073709552000, 2^53+1 -> 2^53)
  • after fix: the serialized payload contains the exact integers as unquoted JSON numbers, round-tripping unchanged

Must FAIL on main today and PASS after the fix.

Reference

GHSA-mrqw-3c7x-96mg

主要语言
TypeScript
星标
22
派生
33
平均合并
2 天 12 小时
30 天内合并 PR
36

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

IntersectMBO/evolution-sdk 的其他 Issue

查看 IntersectMBO/evolution-sdk 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。