docs: clarify FPI expiration requirements - #3795
Open
partylikeits1983 wants to merge 4 commits into
Open
Conversation
partylikeits1983
marked this pull request as draft
September 2, 2026 13:09
partylikeits1983
commented
Sep 2, 2026
partylikeits1983
marked this pull request as ready for review
September 2, 2026 13:40
mmagician
reviewed
Sep 3, 2026
Comment on lines
+27
to
+30
| Account component procedures can become part of an account's public interface and can be called | ||
| from note scripts, transaction scripts, and foreign accounts through FPI. If such a procedure reads | ||
| mutable security state, it must call `tx::update_expiration_block_delta` in the execution path that | ||
| reads that state. |
Collaborator
There was a problem hiding this comment.
Claude has a tendency to introduce newlines to .md files, but IMO (and keeping in line with our current .md files) we should not artificially split lines here.
May be worth adding a skill that we don't need to respect the 100-char (or whatever) limit in .mds
Contributor
Author
There was a problem hiding this comment.
true about claude, but this is not claude :)
Comment on lines
+198
to
+211
| `execute_foreign_procedure` reads the foreign account's state at the transaction reference block, | ||
| which is chosen by the executor. The foreign account commitment is not a transaction public input | ||
| and is not revalidated against the foreign account's current on-chain state at inclusion, so a | ||
| foreign read may be outdated. | ||
|
|
||
| Any FPI-callable procedure that reads mutable security state must call | ||
| `tx::update_expiration_block_delta` in the execution path that reads that state. This includes | ||
| asset callbacks and procedures that read blocklists, allowlists, pause flags, role maps, active | ||
| policy roots, oracle values, risk parameters, or other mutable data where stale reads can change an | ||
| authorization or pricing decision. | ||
|
|
||
| The call is the foreign account's responsibility because the caller controls which valid reference | ||
| block is used for proving. Procedures may omit the call only when they read immutable data or stale | ||
| data is acceptable. |
Co-authored-by: Marti <marti@miden.team>
mmagician
approved these changes
Sep 3, 2026
| #! | ||
| #! Where: | ||
| #! - block_height_delta is the desired expiration time delta (1 to 0xFFFF). | ||
| #! - block_height_delta is the desired expiration delta (1 to 0xFFFF). |
Collaborator
There was a problem hiding this comment.
let's avoid using HEX values in user-facing docs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
tx::update_expiration_block_deltaCloses #3480