Skip to content

DEVREL-468 feat: add oapp-solana - #1482

Merged
St0rmBr3w merged 18 commits into
mainfrom
oapp-solana
Jun 19, 2025
Merged

DEVREL-468 feat: add oapp-solana#1482
St0rmBr3w merged 18 commits into
mainfrom
oapp-solana

Conversation

@nazreen

@nazreen nazreen commented May 5, 2025

Copy link
Copy Markdown
Contributor

Important: When merging into main, do not squash/rebase merge, since the audit will reference a commit hash in the feature branch. Only use merge commit approach.

Warning: do not use this in production, it is not yet audited. Although, in any case, even if you use this as a starting example for your production use case, you would still need to get your specific OApp implementation audited.

This PR will remain in draft mode until audit is completed.


One-liner

This PR adds a new example for a Solana OApp that interacts with an EVM OApp. The OApps pass strings to each other cross-chain.

Details

  • The EVM OApp is taken from the existing oapp example, with slight modifications (adding in enforced options support)
  • The Solana OApp is deliberately simple. It supports only one account (which acts as the OApp / Peer) per program. This is in contrast to the OFT Program, where one OFT Program can be used for multiple OFTs (The OFT Store addresses are used as the peer addresses when cross-chain transferring)
  • enforced options are implemented for both Solidity OApp and Solana OApp
  • for both the Solidity contract and Solana Program, codecs are introduced

Out of scope

  • Ordered Execution mode
  • implementation of composeMsg/compose_msg is out of scope of this PR

@socket-security

socket-security Bot commented May 5, 2025

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​kinobi-so/​renderers@​0.21.5651006885100
Addedkinobi@​0.21.5741009982100
Added@​kinobi-so/​renderers-js-umi@​0.21.7761008583100
Added@​kinobi-so/​nodes-from-anchor@​0.21.3771008282100
Added@​kinobi-so/​nodes@​0.21.5781009982100

View full report

@socket-security

socket-security Bot commented May 5, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert (click for details)
Warn Medium
@kinobi-so/errors@0.21.5 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/nodes@0.21.5npm/@kinobi-so/nodes-from-anchor@0.21.3npm/@kinobi-so/renderers-js-umi@0.21.7npm/kinobi@0.21.5npm/@kinobi-so/renderers@0.21.5npm/@kinobi-so/errors@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/errors@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/node-types@0.21.5 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/nodes@0.21.5npm/@kinobi-so/nodes-from-anchor@0.21.3npm/@kinobi-so/renderers-js-umi@0.21.7npm/kinobi@0.21.5npm/@kinobi-so/renderers@0.21.5npm/@kinobi-so/node-types@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/node-types@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/nodes-from-anchor@0.21.3 is an Unpopular package.

Location: Package overview

From: examples/oapp-solana/package.jsonnpm/@kinobi-so/nodes-from-anchor@0.21.3

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/nodes-from-anchor@0.21.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/nodes@0.21.5 is an Unpopular package.

Location: Package overview

From: examples/oapp-solana/package.jsonnpm/@kinobi-so/nodes@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/nodes@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/renderers-core@0.21.3 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/renderers-js-umi@0.21.7npm/@kinobi-so/renderers@0.21.5npm/@kinobi-so/renderers-core@0.21.3

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/renderers-core@0.21.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/renderers-js-umi@0.21.7 is an Unpopular package.

Location: Package overview

From: examples/oapp-solana/package.jsonnpm/@kinobi-so/renderers-js-umi@0.21.7

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/renderers-js-umi@0.21.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/renderers-js@0.21.9 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/renderers@0.21.5npm/@kinobi-so/renderers-js@0.21.9

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/renderers-js@0.21.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/renderers-rust@0.21.8 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/renderers@0.21.5npm/@kinobi-so/renderers-rust@0.21.8

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/renderers-rust@0.21.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/renderers@0.21.5 is an Unpopular package.

Location: Package overview

From: examples/oapp-solana/package.jsonnpm/@kinobi-so/renderers@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/renderers@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/validators@0.21.5 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/renderers-js-umi@0.21.7npm/kinobi@0.21.5npm/@kinobi-so/validators@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/validators@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
@kinobi-so/visitors@0.21.5 is an Unpopular package.

Location: Package overview

From: pnpm-lock.yamlnpm/@kinobi-so/nodes-from-anchor@0.21.3npm/kinobi@0.21.5npm/@kinobi-so/visitors@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@kinobi-so/visitors@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
kinobi@0.21.5 is an Unpopular package.

Location: Package overview

From: examples/oapp-solana/package.jsonnpm/kinobi@0.21.5

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/kinobi@0.21.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@St0rmBr3w St0rmBr3w left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nazreen what are your thoughts on removing the counter from the example entirely?

Comment thread examples/oapp-solana/programs/counter/src/instructions/lz_receive.rs Outdated
Comment thread examples/oapp-solana/programs/counter/src/instructions/lz_receive_types.rs Outdated
@nazreen
nazreen marked this pull request as draft May 19, 2025 07:24
Comment thread examples/oapp-solana/programs/my_oapp/src/instructions/lz_compose.rs Outdated
@nazreen
nazreen force-pushed the oapp-solana branch 9 times, most recently from d507c30 to c1a40bc Compare May 21, 2025 02:49
@nazreen
nazreen force-pushed the oapp-solana branch 4 times, most recently from 14ee3ce to dad23e4 Compare May 21, 2025 13:07
Comment thread examples/oapp-solana/programs/my_oapp/src/msg_codec.rs Outdated
Comment thread examples/oapp-solana/programs/my_oapp/src/errors.rs Outdated
Comment thread examples/oapp-solana/programs/my_oapp/src/lib.rs
Comment thread examples/oapp-solana/tasks/solana/skipNonce.ts Outdated
Comment thread examples/oapp-solana/contracts/libs/StringMsgCodec.sol Outdated
Comment thread examples/oapp-solana/contracts/libs/StringMsgCodec.sol Outdated
Comment thread examples/oapp-solana/tasks/solana/retryPayload.ts
Comment thread tests-user/tests/create-lz-oapp.bats
Comment thread examples/oapp-solana/tasks/solana/utils.ts Outdated
@St0rmBr3w St0rmBr3w added ready to review in a state where CI passes and the PR is quite upto date with main and you need reviews and removed do not merge pending_audit labels Jun 18, 2025
@St0rmBr3w St0rmBr3w changed the title feat: add oapp-solana DEVREL-468 feat: add oapp-solana Jun 18, 2025

@St0rmBr3w St0rmBr3w left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given the time crunch I think this looks good. Some minor items, but we can improve rolling forward. Great work!

@nazreen

nazreen commented Jun 18, 2025

Copy link
Copy Markdown
Contributor Author

note: commits after 82a04bc do not change the program/contract code

@nazreen

nazreen commented Jun 19, 2025

Copy link
Copy Markdown
Contributor Author

CI currently failing due to unrelated Ton test

@layerzerolabs/test-devtools-ton#test: command (/app/packages/test-devtools-ton) /usr/local/bin/pnpm run test exited (1)

 Tasks:    87 successful, 105 total
Cached:    58 cached, 105 total
  Time:    12.945s 
Failed:    @layerzerolabs/test-devtools-ton#test

@St0rmBr3w St0rmBr3w left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@ItsAdel ItsAdel left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I only ran the end to end tests. Approving based on that working. Did not get a chance to code review

@St0rmBr3w
St0rmBr3w merged commit 9b2c446 into main Jun 19, 2025
15 of 17 checks passed
@St0rmBr3w
St0rmBr3w deleted the oapp-solana branch June 19, 2025 21:51
shankars99 pushed a commit that referenced this pull request Jul 20, 2025
mattsse pushed a commit to mattsse/devtools that referenced this pull request Aug 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready to review in a state where CI passes and the PR is quite upto date with main and you need reviews

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants