Skip to main content

sui_protocol_config/
lib.rs

1// Copyright (c) Mysten Labs, Inc.
2// SPDX-License-Identifier: Apache-2.0
3
4use std::{
5    collections::{BTreeMap, BTreeSet},
6    sync::{
7        Arc, LazyLock,
8        atomic::{AtomicBool, Ordering},
9    },
10};
11
12use std::sync::Mutex;
13
14use clap::*;
15use fastcrypto::encoding::{Base58, Encoding, Hex};
16use move_binary_format::{
17    binary_config::{BinaryConfig, TableConfig},
18    file_format_common::VERSION_1,
19};
20use move_core_types::account_address::AccountAddress;
21use move_vm_config::verifier::VerifierConfig;
22use mysten_common::in_integration_test;
23use serde::{Deserialize, Serialize};
24use serde_with::skip_serializing_none;
25use sui_protocol_config_macros::{
26    ProtocolConfigAccessors, ProtocolConfigFeatureFlagsGetters, ProtocolConfigOverride,
27};
28use tracing::{info, warn};
29
30pub mod reachability;
31
32// Re-exported so that `assert_reachable_gated!` expands without requiring callers to depend on
33// the antithesis sdk or mysten-common directly.
34#[doc(hidden)]
35pub use antithesis_sdk::linkme;
36#[doc(hidden)]
37pub use mysten_common::assert_reachable_simtest;
38
39/// The minimum and maximum protocol versions supported by this build.
40const MIN_PROTOCOL_VERSION: u64 = 1;
41const MAX_PROTOCOL_VERSION: u64 = 138;
42
43const TESTNET_USDC: &str =
44    "0xa1ec7fc00a6f40db9693ad1415d0c193ad3906494428cf252621037bd7117e29::usdc::USDC";
45
46const MAINNET_USDC: &str =
47    "0xdba34672e30cb065b1f93e3ab55318768fd6fef66c15942c9f7cb846e2f900e7::usdc::USDC";
48const MAINNET_USDSUI: &str =
49    "0x44f838219cf67b058f3b37907b655f226153c18e33dfcd0da559a844fea9b1c1::usdsui::USDSUI";
50const MAINNET_SUI_USDE: &str =
51    "0x41d587e5336f1c86cad50d38a7136db99333bb9bda91cea4ba69115defeb1402::sui_usde::SUI_USDE";
52const MAINNET_USDY: &str =
53    "0x960b531667636f39e85867775f52f6b1f220a058c4de786905bdf761e06a56bb::usdy::USDY";
54const MAINNET_FDUSD: &str =
55    "0xf16e6b723f242ec745dfd7634ad072c42d5c1d9ac9d62a39c381303eaa57693a::fdusd::FDUSD";
56const MAINNET_AUSD: &str =
57    "0x2053d08c1e2bd02791056171aab0fd12bd7cd7efad2ab8f6b9c8902f14df2ff2::ausd::AUSD";
58const MAINNET_USDB: &str =
59    "0xe14726c336e81b32328e92afc37345d159f5b550b09fa92bd43640cfdd0a0cfd::usdb::USDB";
60
61// Record history of protocol version allocations here:
62//
63// Version 1: Original version.
64// Version 2: Framework changes, including advancing epoch_start_time in safemode.
65// Version 3: gas model v2, including all sui conservation fixes. Fix for loaded child object
66//            changes, enable package upgrades, add limits on `max_size_written_objects`,
67//            `max_size_written_objects_system_tx`
68// Version 4: New reward slashing rate. Framework changes to skip stake susbidy when the epoch
69//            length is short.
70// Version 5: Package upgrade compatibility error fix. New gas cost table. New scoring decision
71//            mechanism that includes up to f scoring authorities.
72// Version 6: Change to how bytes are charged in the gas meter, increase buffer stake to 0.5f
73// Version 7: Disallow adding new abilities to types during package upgrades,
74//            disable_invariant_violation_check_in_swap_loc,
75//            disable init functions becoming entry,
76//            hash module bytes individually before computing package digest.
77// Version 8: Disallow changing abilities and type constraints for type parameters in structs
78//            during upgrades.
79// Version 9: Limit the length of Move idenfitiers to 128.
80//            Disallow extraneous module bytes,
81//            advance_to_highest_supported_protocol_version,
82// Version 10:increase bytecode verifier `max_verifier_meter_ticks_per_function` and
83//            `max_meter_ticks_per_module` limits each from 6_000_000 to 16_000_000. sui-system
84//            framework changes.
85// Version 11: Introduce `std::type_name::get_with_original_ids` to the system frameworks. Bound max depth of values within the VM.
86// Version 12: Changes to deepbook in framework to add API for querying marketplace.
87//             Change NW Batch to use versioned metadata field.
88//             Changes to sui-system package to add PTB-friendly unstake function, and minor cleanup.
89// Version 13: System package change deprecating `0xdee9::clob` and `0xdee9::custodian`, replaced by
90//             `0xdee9::clob_v2` and `0xdee9::custodian_v2`.
91// Version 14: Introduce a config variable to allow charging of computation to be either
92//             bucket base or rounding up. The presence of `gas_rounding_step` (or `None`)
93//             decides whether rounding is applied or not.
94// Version 15: Add reordering of user transactions by gas price after consensus.
95//             Add `sui::table_vec::drop` to the framework via a system package upgrade.
96// Version 16: Enabled simplified_unwrap_then_delete feature flag, which allows the execution engine
97//             to no longer consult the object store when generating unwrapped_then_deleted in the
98//             effects; this also allows us to stop including wrapped tombstones in accumulator.
99//             Add self-matching prevention for deepbook.
100// Version 17: Enable upgraded multisig support.
101// Version 18: Introduce execution layer versioning, preserve all existing behaviour in v0.
102//             Gas minimum charges moved to be a multiplier over the reference gas price. In this
103//             protocol version the multiplier is the same as the lowest bucket of computation
104//             such that the minimum transaction cost is the same as the minimum computation
105//             bucket.
106//             Add a feature flag to indicate the changes semantics of `base_tx_cost_fixed`.
107// Version 19: Changes to sui-system package to enable liquid staking.
108//             Add limit for total size of events.
109//             Increase limit for number of events emitted to 1024.
110// Version 20: Enables the flag `narwhal_new_leader_election_schedule` for the new narwhal leader
111//             schedule algorithm for enhanced fault tolerance and sets the bad node stake threshold
112//             value. Both values are set for all the environments except mainnet.
113// Version 21: ZKLogin known providers.
114// Version 22: Child object format change.
115// Version 23: Enabling the flag `narwhal_new_leader_election_schedule` for the new narwhal leader
116//             schedule algorithm for enhanced fault tolerance and sets the bad node stake threshold
117//             value for mainnet.
118// Version 24: Re-enable simple gas conservation checks.
119//             Package publish/upgrade number in a single transaction limited.
120//             JWK / authenticator state flags.
121// Version 25: Add sui::table_vec::swap and sui::table_vec::swap_remove to system packages.
122// Version 26: New gas model version.
123//             Add support for receiving objects off of other objects in devnet only.
124// Version 28: Add sui::zklogin::verify_zklogin_id and related functions to sui framework.
125//             Enable transaction effects v2 in devnet.
126// Version 29: Add verify_legacy_zklogin_address flag to sui framework, this add ability to verify
127//             transactions from a legacy zklogin address.
128// Version 30: Enable Narwhal CertificateV2
129//             Add support for random beacon.
130//             Enable transaction effects v2 in testnet.
131//             Deprecate supported oauth providers from protocol config and rely on node config
132//             instead.
133//             In execution, has_public_transfer is recomputed when loading the object.
134//             Add support for shared obj deletion and receiving objects off of other objects in devnet only.
135// Version 31: Add support for shared object deletion in devnet only.
136//             Add support for getting object ID referenced by receiving object in sui framework.
137//             Create new execution layer version, and preserve previous behavior in v1.
138//             Update semantics of `sui::transfer::receive` and add `sui::transfer::public_receive`.
139// Version 32: Add delete functions for VerifiedID and VerifiedIssuer.
140//             Add sui::token module to sui framework.
141//             Enable transfer to object in testnet.
142//             Enable Narwhal CertificateV2 on mainnet
143//             Make critbit tree and order getters public in deepbook.
144// Version 33: Add support for `receiving_object_id` function in framework
145//             Hardened OTW check.
146//             Enable transfer-to-object in mainnet.
147//             Enable shared object deletion in testnet.
148//             Enable effects v2 in mainnet.
149// Version 34: Framework changes for random beacon.
150// Version 35: Add poseidon hash function.
151//             Enable coin deny list.
152// Version 36: Enable group operations native functions in devnet.
153//             Enable shared object deletion in mainnet.
154//             Set the consensus accepted transaction size and the included transactions size in the proposed block.
155// Version 37: Reject entry functions with mutable Random.
156// Version 38: Introduce limits for binary tables size.
157// Version 39: Allow skipped epochs for randomness updates.
158//             Extra version to fix `test_upgrade_compatibility` simtest.
159// Version 40:
160// Version 41: Enable group operations native functions in testnet and mainnet (without msm).
161// Version 42: Migrate sui framework and related code to Move 2024
162// Version 43: Introduce the upper bound delta config for a zklogin signature's max epoch.
163//             Introduce an explicit parameter for the tick limit per package (previously this was
164//             represented by the parameter for the tick limit per module).
165// Version 44: Enable consensus fork detection on mainnet.
166//             Switch between Narwhal and Mysticeti consensus in tests, devnet and testnet.
167// Version 45: Use tonic networking for Mysticeti consensus.
168//             Set min Move binary format version to 6.
169//             Enable transactions to be signed with zkLogin inside multisig signature.
170//             Add native bridge.
171//             Enable native bridge in devnet
172//             Enable Leader Scoring & Schedule Change for Mysticeti consensus on testnet.
173// Version 46: Enable native bridge in testnet
174//             Enable resharing at the same initial shared version.
175// Version 47: Deepbook changes (framework update)
176// Version 48: Use tonic networking for Mysticeti.
177//             Resolve Move abort locations to the package id instead of the runtime module ID.
178//             Enable random beacon in testnet.
179//             Use new VM when verifying framework packages.
180// Version 49: Enable Move enums on devnet.
181//             Enable VDF in devnet
182//             Enable consensus commit prologue V3 in devnet.
183//             Run Mysticeti consensus by default.
184// Version 50: Add update_node_url to native bridge,
185//             New Move stdlib integer modules
186//             Enable checkpoint batching in testnet.
187//             Prepose consensus commit prologue in checkpoints.
188//             Set number of leaders per round for Mysticeti commits.
189// Version 51: Switch to DKG V1.
190//             Enable deny list v2 on devnet.
191// Version 52: Emit `CommitteeMemberUrlUpdateEvent` when updating bridge node url.
192//             std::config native functions.
193//             Modified sui-system package to enable withdrawal of stake before it becomes active.
194//             Enable soft bundle in devnet and testnet.
195//             Core macro visibility in sui core framework.
196//             Enable checkpoint batching in mainnet.
197//             Enable Mysticeti on mainnet.
198//             Enable Leader Scoring & Schedule Change for Mysticeti consensus on mainnet.
199//             Turn on count based shared object congestion control in devnet.
200//             Enable consensus commit prologue V3 in testnet.
201//             Enable enums on testnet.
202//             Add support for passkey in devnet.
203//             Enable deny list v2 on testnet and mainnet.
204// Version 53: Add feature flag to decide whether to attempt to finalize bridge committee
205//             Enable consensus commit prologue V3 on testnet.
206//             Turn on shared object congestion control in testnet.
207//             Update stdlib natives costs
208// Version 54: Enable random beacon on mainnet.
209//             Enable soft bundle on mainnet.
210// Version 55: Enable enums on mainnet.
211//             Rethrow serialization type layout errors instead of converting them.
212// Version 56: Enable bridge on mainnet.
213//             Note: do not use version 56 for any new features.
214// Version 57: Reduce minimum number of random beacon shares.
215// Version 58: Optimize boolean binops
216//             Finalize bridge committee on mainnet.
217//             Switch to distributed vote scoring in consensus in devnet
218// Version 59: Enable round prober in consensus.
219// Version 60: Validation of public inputs for Groth16 verification.
220//             Enable configuration of maximum number of type nodes in a type layout.
221// Version 61: Switch to distributed vote scoring in consensus in testnet
222//             Further reduce minimum number of random beacon shares.
223//             Add feature flag for Mysticeti fastpath.
224// Version 62: Makes the event's sending module package upgrade-aware.
225// Version 63: Enable gas based congestion control in consensus commit.
226// Version 64: Revert congestion control change.
227// Version 65: Enable distributed vote scoring in mainnet.
228// Version 66: Revert distributed vote scoring in mainnet.
229//             Framework fix for fungible staking book-keeping.
230// Version 67: Re-enable distributed vote scoring in mainnet.
231// Version 68: Add G1Uncompressed group to group ops.
232//             Update to Move stdlib.
233//             Enable gas based congestion control with overage.
234//             Further reduce minimum number of random beacon shares.
235//             Disallow adding new modules in `deps-only` packages.
236// Version 69: Sets number of rounds allowed for fastpath voting in consensus.
237//             Enable smart ancestor selection in devnet.
238//             Enable G1Uncompressed group in testnet.
239// Version 70: Enable smart ancestor selection in testnet.
240//             Enable probing for accepted rounds in round prober in testnet
241//             Add new gas model version to update charging of native functions.
242//             Add std::uq64_64 module to Move stdlib.
243//             Improve gas/wall time efficiency of some Move stdlib vector functions
244// Version 71: [SIP-45] Enable consensus amplification.
245// Version 72: Fix issue where `convert_type_argument_error` wasn't being used in all cases.
246//             Max gas budget moved to 50_000 SUI
247//             Max gas price moved to 50 SUI
248//             Variants as type nodes.
249// Version 73: Enable new marker table version.
250//             Enable consensus garbage collection and new commit rule for devnet.
251//             Enable zstd compression for consensus tonic network in testnet.
252//             Enable smart ancestor selection in mainnet.
253//             Enable probing for accepted rounds in round prober in mainnet
254// Version 74: Enable load_nitro_attestation move function in sui framework in devnet.
255//             Enable all gas costs for load_nitro_attestation.
256//             Enable zstd compression for consensus tonic network in mainnet.
257//             Enable the new commit rule for devnet.
258// Version 75: Enable passkey auth in testnet.
259// Version 76: Deprecate Deepbook V2 order placement and deposit.
260//             Removes unnecessary child object mutations
261//             Enable passkey auth in multisig for testnet.
262// Version 77: Enable uncompressed point group ops on mainnet.
263//             Enable consensus garbage collection for testnet
264//             Enable the new consensus commit rule for testnet.
265// Version 78: Make `TxContext` Move API native
266//             Enable execution time estimate mode for congestion control on testnet.
267// Version 79: Enable median based commit timestamp in consensus on testnet.
268//             Increase threshold for bad nodes that won't be considered leaders in consensus in testnet
269//             Enable load_nitro_attestation move function in sui framework in testnet.
270//             Enable consensus garbage collection for mainnet
271//             Enable the new consensus commit rule for mainnet.
272// Version 80: Bound size of values created in the adapter.
273// Version 81: Enable median based commit timestamp in consensus on mainnet.
274//             Enforce checkpoint timestamps are non-decreasing for testnet and mainnet.
275//             Increase threshold for bad nodes that won't be considered leaders in consensus in mainnet
276// Version 82: Relax bounding of size of values created in the adapter.
277// Version 83: Resolve `TypeInput` IDs to defining ID when converting to `TypeTag`s in the adapter.
278//             Enable execution time estimate mode for congestion control on mainnet.
279//             Enable nitro attestation upgraded parsing and mainnet.
280// Version 84: Limit number of stored execution time observations between epochs.
281// Version 85: Enable party transfer in devnet.
282// Version 86: Use type tags in the object runtime and adapter instead of `Type`s.
283//             Make variant count limit explicit in protocol config.
284//             Enable party transfer in testnet.
285// Version 87: Enable better type resolution errors in the adapter.
286// Version 88: Update `sui-system` package to use `calculate_rewards` function.
287//             Define the cost for the native Move function `rgp`.
288//             Ignore execution time observations after validator stops accepting certs.
289// Version 89: Add additional signature checks
290//             Add additional linkage checks
291// Version 90: Standard library improvements.
292//             Enable `debug_fatal` on Move invariant violations.
293//             Enable passkey and passkey inside multisig for mainnet.
294// Version 91: Minor changes in Sui Framework. Include CheckpointDigest in consensus dedup key for checkpoint signatures (V2).
295// Version 92: Disable checking shared object transfer restrictions per command = false
296// Version 93: Enable CheckpointDigest in consensus dedup key for checkpoint signatures.
297// Version 94: Decrease stored observations limit by 10% to stay within system object size limit.
298//             Enable party transfer on mainnet.
299// Version 95: Change type name id base cost to 52, increase max transactions per checkpoint to 20000.
300// Version 96: Enable authority capabilities v2.
301//             Fix bug where MFP transaction shared inputs' debts were not loaded
302//             Create Coin Registry object
303//             Enable checkpoint artifacts digest in devnet.
304// Version 97: Enable additional borrow checks
305// Version 98: Add authenticated event streams support via emit_authenticated function.
306//             Add better error messages to the loader.
307// Version 99: Enable new commit handler.
308// Version 100: Framework update
309// Version 101: Framework update
310//              Set max updates per settlement txn to 100.
311// Version 103: Framework update: internal Coin methods
312// Version 104: Framework update: CoinRegistry follow up for Coin methods
313//              Enable all non-zero PCRs parsing for nitro attestation native function in Devnet and Testnet.
314// Version 105: Framework update: address aliases
315//              Enable multi-epoch transaction expiration.
316//              Enable always include required PCRs (0-4 & 8) parsing even if they are zeros for
317//              nitro attestation native function in Devnet and Testnet.
318// Version 106: Framework update: accumulator storage fund calculations
319//              Enable address balances on devnet
320// Version 108: Enable new digit based gas rounding.
321//              Support TxContext in all parameter positions.
322//              Disable entry point signature check.
323//              Enable address aliases on testnet.
324//              Enable poseidon_bn254 on mainnet.
325// Version 109: Update where we set bounds for some binary tables to be a bit more idiomatic.
326// Version 110: Enable parsing on all nonzero custom pcrs in nitro attestation parsing native
327//              function on mainnet.
328//              split_checkpoints_in_consensus_handler in devnet
329//              Enable additional validation on zkLogin public identifier.
330// Version 111: Validator metadata
331// Version 112: Enable Ristretto255 in devnet.
332// Version 113: Validate gas price >= RGP at signing for address balance gas payments.
333// Version 114: Gate seeded test overrides for checkpoint tx limit behind feature flag.
334// Version 115: Gasless transaction drop safety.
335//              Enable address aliases on mainnet.
336//              Relax ValidDuring requirement for transactions with owned inputs.
337// Version 116: Enable Display Registry.
338//              Disable defer_unpaid_amplification (debugging).
339// Version 117: Update Sui System metadata handling.
340// Version 118: Adds `transfer_migration_cap` to display registry
341// Version 119: Enable the new VM.
342// Version 120: Disallow unused jump tables
343// Version 121: Re-enable defer_unpaid_amplification (devnet + testnet).
344// Version 122: Framework update: vector::empty is deprecated.
345//              Enable bulletproofs verification on devnet.
346//              Enable defer_unpaid_amplification on mainnet.
347// Version 123: Gas accounting refresh (gas_model v13).
348// Version 124: Add timestamp_based_epoch_close feature flag and enable in tests.
349//              Fix native call double-pop in gas meter stack height tracking (gas_model v14).
350//              Limit public inputs in groth16::prepare_verifying_key.
351//              Enable address balances, free tier (gasless), and coin reservations on mainnet.
352//              Enables enable_accumulators, enable_address_balance_gas_payments,
353//              enable_authenticated_event_streams, enable_coin_reservation_obj_refs,
354//              enable_object_funds_withdraw, convert_withdrawal_compatibility_ptb_arguments,
355//              split_checkpoints_in_consensus_handler, include_checkpoint_artifacts_digest_in_summary,
356//              and enable_gasless on mainnet to bring it in line with testnet.
357//              Configure mainnet gasless allowlist with stablecoin types and $0.01 minimum
358//              transfer per stable.
359// Version 125: Enable granular_post_execution_checks.
360//              Enable timestamp_based_epoch_close on testnet.
361// Version 126: Enable early_exit_on_iffw (gates the gas-underflow fix
362//              shipped to mainnet out-of-band in #26816).
363// Version 127: Enable always_advance_dkg_to_resolution.
364//              Update gas prices for range proofs and ristretto group operations.
365//              Enable Ristretto255 group operations and bulletproofs verification on testnet.
366//              Enable init functions for newly introduced modules during package upgrade.
367//              Enable timestamp_based_epoch_close on mainnet.
368// Version 128: Make some additional bounds to binary tables explicit.
369// Version 129: Add `insert_before` and `insert_after` to `sui::linked_table`
370//              Enable unified linkage in PTBs
371// Version 130: Record unsettled object-funds withdraws using per-account net amounts
372//              from transaction effects instead of running-max withdraw amounts.
373//              Add the `sui::scratch` per-transaction ephemeral store and its native costs.
374//              Enable zklogin v2 verify (with v1 fallback) for devnet only.
375//              Add an epoch close deadline failsafe for deferred transactions.
376// Version 131: Enable sharing transaction deny configs between validators via consensus.
377//              Enable tx_context_restrictions_verifier: reject system-package
378//              function signatures with `&mut TxContext` + any `&mut _` return
379//              that have no non-`TxContext` `&mut U` parameter.
380// Version 132: Enable defer_owned_object_double_spend on devnet.
381//              Add the `object::record_new_uid_from_hash` native and its cost, tracking the
382//              root version of hash-derived UIDs (`new_uid_from_hash`).
383//              Create the ForwardingAddressRegistry system object on devnet.
384//              Make upgrade-init linkage checks independent of PTB command order.
385// Version 133: Include function signatures in type-node limits.
386//              Bound type nodes in accumulators.
387// Version 134: Add `package::original_package_id` and its native costs.
388//              Reduce the consensus block transaction count and payload limits.
389//              (Both gated to non-mainnet chains.)
390//              Disable defer_unpaid_amplification on mainnet.
391// Version 135: Apply the v134 config changes on mainnet.
392//              Disable defer_unpaid_amplification everywhere.
393// Version 136: Enable ptb_tx_context_restrictions: `TxContext` may appear in a
394//              PTB Move call signature at most once mutably or any number of
395//              times immutably (never by value), and never in return position.
396//              Enable allowed_proposers on devnet.
397//              Add limits for references used by programmable transactions.
398//              Add additional linkage invariant hardening/invariant checks in PTBs.
399//              Add package_arena_size_in_bytes.
400// Version 137: Lower the per-bit cost of bulletproofs range proof verification, and raise the
401//              bound on batch size * range bits from 512 to 1024.
402//              Enable allowances.
403//              Enable fix_ptb_generated_reads.
404//              Charge `LdConst` for the abstract value size of the constant instead of its
405//              serialized byte length.
406//              Enable check_object_funds_withdraw_in_execution on devnet and charge for reads.
407//              Enable allowed_proposers on testnet and mainnet.
408//              Validate PTB indices at signing time.
409//              Enable memory_safety_invariant_check_v2.
410// Version 138: Enable BumpOnly
411
412#[derive(Copy, Clone, Debug, Hash, Serialize, Deserialize, PartialEq, Eq, PartialOrd, Ord)]
413pub struct ProtocolVersion(u64);
414
415impl ProtocolVersion {
416    // The minimum and maximum protocol version supported by this binary. Counterintuitively, this constant may
417    // change over time as support for old protocol versions is removed from the source. This
418    // ensures that when a new network (such as a testnet) is created, its genesis committee will
419    // use a protocol version that is actually supported by the binary.
420    pub const MIN: Self = Self(MIN_PROTOCOL_VERSION);
421
422    pub const MAX: Self = Self(MAX_PROTOCOL_VERSION);
423
424    #[cfg(not(msim))]
425    pub const MAX_ALLOWED: Self = Self::MAX;
426
427    // We create one additional "fake" version in simulator builds so that we can test upgrades.
428    #[cfg(msim)]
429    pub const MAX_ALLOWED: Self = Self(MAX_PROTOCOL_VERSION + 1);
430
431    pub fn new(v: u64) -> Self {
432        Self(v)
433    }
434
435    pub const fn as_u64(&self) -> u64 {
436        self.0
437    }
438
439    // For serde deserialization - we don't define a Default impl because there isn't a single
440    // universally appropriate default value.
441    pub fn max() -> Self {
442        Self::MAX
443    }
444
445    pub fn prev(self) -> Self {
446        Self(self.0.checked_sub(1).unwrap())
447    }
448}
449
450impl From<u64> for ProtocolVersion {
451    fn from(v: u64) -> Self {
452        Self::new(v)
453    }
454}
455
456impl std::ops::Sub<u64> for ProtocolVersion {
457    type Output = Self;
458    fn sub(self, rhs: u64) -> Self::Output {
459        Self::new(self.0 - rhs)
460    }
461}
462
463impl std::ops::Add<u64> for ProtocolVersion {
464    type Output = Self;
465    fn add(self, rhs: u64) -> Self::Output {
466        Self::new(self.0 + rhs)
467    }
468}
469
470#[derive(
471    Clone, Serialize, Deserialize, Debug, Default, PartialEq, Copy, PartialOrd, Ord, Eq, ValueEnum,
472)]
473pub enum Chain {
474    Mainnet,
475    Testnet,
476    #[default]
477    Unknown,
478}
479
480impl Chain {
481    pub fn as_str(self) -> &'static str {
482        match self {
483            Chain::Mainnet => "mainnet",
484            Chain::Testnet => "testnet",
485            Chain::Unknown => "unknown",
486        }
487    }
488}
489
490pub struct Error(pub String);
491
492// TODO: There are quite a few non boolean values in the feature flags. We should move them out.
493/// Records on/off feature flags that may vary at each protocol version.
494#[derive(Default, Clone, Serialize, Deserialize, Debug, ProtocolConfigFeatureFlagsGetters)]
495struct FeatureFlags {
496    // Add feature flags here, e.g.:
497    // new_protocol_feature: bool,
498    #[serde(skip_serializing_if = "is_false")]
499    package_upgrades: bool,
500    // If true, validators will commit to the root state digest
501    // in end of epoch checkpoint proposals
502    #[serde(skip_serializing_if = "is_false")]
503    commit_root_state_digest: bool,
504    // Pass epoch start time to advance_epoch safe mode function.
505    #[serde(skip_serializing_if = "is_false")]
506    advance_epoch_start_time_in_safe_mode: bool,
507    // If true, apply the fix to correctly capturing loaded child object versions in execution's
508    // object runtime.
509    #[serde(skip_serializing_if = "is_false")]
510    loaded_child_objects_fixed: bool,
511    // If true, treat missing types in the upgraded modules when creating an upgraded package as a
512    // compatibility error.
513    #[serde(skip_serializing_if = "is_false")]
514    missing_type_is_compatibility_error: bool,
515    // If true, then the scoring decision mechanism will not get disabled when we do have more than
516    // f low scoring authorities, but it will simply flag as low scoring only up to f authorities.
517    #[serde(skip_serializing_if = "is_false")]
518    scoring_decision_with_validity_cutoff: bool,
519
520    // DEPRECATED: this was an ephemeral feature flag only used by consensus handler, which has now
521    // been deployed everywhere.
522    #[serde(skip_serializing_if = "is_false")]
523    consensus_order_end_of_epoch_last: bool,
524
525    // If true, validators emit slim (ancestor-compressed) blocks on the consensus block
526    // subscription stream, framed in a block envelope. Gates the wire framing on both
527    // ends of the stream.
528    #[serde(skip_serializing_if = "is_false")]
529    consensus_slim_block_propagation: bool,
530
531    // Disallow adding abilities to types during package upgrades.
532    #[serde(skip_serializing_if = "is_false")]
533    disallow_adding_abilities_on_upgrade: bool,
534    // Disables unnecessary invariant check in the Move VM when swapping the value out of a local
535    #[serde(skip_serializing_if = "is_false")]
536    disable_invariant_violation_check_in_swap_loc: bool,
537    // advance to highest supported protocol version at epoch change, instead of the next consecutive
538    // protocol version.
539    #[serde(skip_serializing_if = "is_false")]
540    advance_to_highest_supported_protocol_version: bool,
541    // If true, disallow entry modifiers on entry functions
542    #[serde(skip_serializing_if = "is_false")]
543    ban_entry_init: bool,
544    // If true, hash module bytes individually when calculating package digests for upgrades
545    #[serde(skip_serializing_if = "is_false")]
546    package_digest_hash_module: bool,
547    // If true, disallow changing struct type parameters during package upgrades
548    #[serde(skip_serializing_if = "is_false")]
549    disallow_change_struct_type_params_on_upgrade: bool,
550    // If true, checks no extra bytes in a compiled module
551    #[serde(skip_serializing_if = "is_false")]
552    no_extraneous_module_bytes: bool,
553    // If true, then use the versioned metadata format in narwhal entities.
554    #[serde(skip_serializing_if = "is_false")]
555    narwhal_versioned_metadata: bool,
556
557    // Enable zklogin auth
558    #[serde(skip_serializing_if = "is_false")]
559    zklogin_auth: bool,
560    // zkLogin circuit verify mode: 0 = accept v1 circuit proofs only, 1 = try the v2
561    // circuit first and fall back to v1 (migration phase), 2 = accept v2 circuit proofs only.
562    #[serde(skip_serializing_if = "is_zero")]
563    zklogin_circuit_mode: u64,
564    // How we order transactions coming out of consensus before sending to execution.
565    #[serde(skip_serializing_if = "ConsensusTransactionOrdering::is_none")]
566    consensus_transaction_ordering: ConsensusTransactionOrdering,
567
568    // Previously, the unwrapped_then_deleted field in TransactionEffects makes a distinction between
569    // whether an object has existed in the store previously (i.e. whether there is a tombstone).
570    // Such dependency makes effects generation inefficient, and requires us to include wrapped
571    // tombstone in state root hash.
572    // To prepare for effects V2, with this flag set to true, we simplify the definition of
573    // unwrapped_then_deleted to always include unwrapped then deleted objects,
574    // regardless of their previous state in the store.
575    #[serde(skip_serializing_if = "is_false")]
576    simplified_unwrap_then_delete: bool,
577    // Enable upgraded multisig support
578    #[serde(skip_serializing_if = "is_false")]
579    upgraded_multisig_supported: bool,
580    // If true minimum txn charge is a multiplier of the gas price
581    #[serde(skip_serializing_if = "is_false")]
582    txn_base_cost_as_multiplier: bool,
583
584    // If true, the ability to delete shared objects is in effect
585    #[serde(skip_serializing_if = "is_false")]
586    shared_object_deletion: bool,
587
588    // If true, then the new algorithm for the leader election schedule will be used
589    #[serde(skip_serializing_if = "is_false")]
590    narwhal_new_leader_election_schedule: bool,
591
592    // A list of supported OIDC providers that can be used for zklogin.
593    #[serde(skip_serializing_if = "is_empty")]
594    zklogin_supported_providers: BTreeSet<String>,
595
596    // If true, use the new child object format
597    #[serde(skip_serializing_if = "is_false")]
598    loaded_child_object_format: bool,
599
600    #[serde(skip_serializing_if = "is_false")]
601    #[skip_protocol_config_accessor]
602    enable_jwk_consensus_updates: bool,
603
604    #[serde(skip_serializing_if = "is_false")]
605    #[skip_protocol_config_accessor]
606    end_of_epoch_transaction_supported: bool,
607
608    // Perform simple conservation checks keeping into account out of gas scenarios
609    // while charging for storage.
610    #[serde(skip_serializing_if = "is_false")]
611    simple_conservation_checks: bool,
612
613    // If true, use the new child object format type logging
614    #[serde(skip_serializing_if = "is_false")]
615    loaded_child_object_format_type: bool,
616
617    // Enable receiving sent objects
618    #[serde(skip_serializing_if = "is_false")]
619    receive_objects: bool,
620
621    // If true, include CheckpointDigest in consensus dedup key for checkpoint signatures (V2).
622    #[serde(skip_serializing_if = "is_false")]
623    consensus_checkpoint_signature_key_includes_digest: bool,
624
625    // Enable random beacon protocol
626    #[serde(skip_serializing_if = "is_false")]
627    random_beacon: bool,
628
629    // Enable bridge protocol
630    #[serde(skip_serializing_if = "is_false")]
631    #[skip_protocol_config_accessor]
632    bridge: bool,
633
634    #[serde(skip_serializing_if = "is_false")]
635    enable_effects_v2: bool,
636
637    // If true, then use CertificateV2 in narwhal.
638    #[serde(skip_serializing_if = "is_false")]
639    narwhal_certificate_v2: bool,
640
641    // If true, allow verify with legacy zklogin address
642    #[serde(skip_serializing_if = "is_false")]
643    verify_legacy_zklogin_address: bool,
644
645    // Enable throughput aware consensus submission
646    #[serde(skip_serializing_if = "is_false")]
647    throughput_aware_consensus_submission: bool,
648
649    // If true, recompute has_public_transfer from the type instead of what is stored in the object
650    #[serde(skip_serializing_if = "is_false")]
651    recompute_has_public_transfer_in_execution: bool,
652
653    // If true, multisig containing zkLogin sig is accepted.
654    #[serde(skip_serializing_if = "is_false")]
655    accept_zklogin_in_multisig: bool,
656
657    // If true, multisig containing passkey sig is accepted.
658    #[serde(skip_serializing_if = "is_false")]
659    accept_passkey_in_multisig: bool,
660
661    // If true, additional zkLogin public identifier structure is validated.
662    #[serde(skip_serializing_if = "is_false")]
663    validate_zklogin_public_identifier: bool,
664
665    // If true, consensus prologue transaction also includes the consensus output digest.
666    // It can be used to detect consensus output folk.
667    #[serde(skip_serializing_if = "is_false")]
668    include_consensus_digest_in_prologue: bool,
669
670    // If true, use the hardened OTW check
671    #[serde(skip_serializing_if = "is_false")]
672    hardened_otw_check: bool,
673
674    // If true allow calling receiving_object_id function
675    #[serde(skip_serializing_if = "is_false")]
676    allow_receiving_object_id: bool,
677
678    // Enable the poseidon hash function
679    #[serde(skip_serializing_if = "is_false")]
680    enable_poseidon: bool,
681
682    // If true, enable the coin deny list.
683    #[serde(skip_serializing_if = "is_false")]
684    enable_coin_deny_list: bool,
685
686    // Enable native functions for group operations.
687    #[serde(skip_serializing_if = "is_false")]
688    enable_group_ops_native_functions: bool,
689
690    // Enable native function for msm.
691    #[serde(skip_serializing_if = "is_false")]
692    enable_group_ops_native_function_msm: bool,
693
694    // Enable group operations for Ristretto255
695    #[serde(skip_serializing_if = "is_false")]
696    enable_ristretto255_group_ops: bool,
697
698    // Enable native functions for group operations.
699    #[serde(skip_serializing_if = "is_false")]
700    enable_verify_bulletproofs_ristretto255: bool,
701
702    // Enable nitro attestation.
703    #[serde(skip_serializing_if = "is_false")]
704    enable_nitro_attestation: bool,
705
706    // Enable upgraded parsing of nitro attestation that interprets pcrs as a map.
707    #[serde(skip_serializing_if = "is_false")]
708    enable_nitro_attestation_upgraded_parsing: bool,
709
710    // Enable upgraded parsing of nitro attestation containing all nonzero PCRs.
711    #[serde(skip_serializing_if = "is_false")]
712    enable_nitro_attestation_all_nonzero_pcrs_parsing: bool,
713
714    // Enable upgraded parsing of nitro attestation to always include required PCRs, even when all zeros.
715    #[serde(skip_serializing_if = "is_false")]
716    enable_nitro_attestation_always_include_required_pcrs_parsing: bool,
717
718    // Reject functions with mutable Random.
719    #[serde(skip_serializing_if = "is_false")]
720    reject_mutable_random_on_entry_functions: bool,
721
722    // Controls the behavior of per object congestion control in consensus handler.
723    #[serde(skip_serializing_if = "PerObjectCongestionControlMode::is_none")]
724    per_object_congestion_control_mode: PerObjectCongestionControlMode,
725
726    // The consensus protocol to be used for the epoch.
727    #[serde(skip_serializing_if = "ConsensusChoice::is_narwhal")]
728    consensus_choice: ConsensusChoice,
729
730    // Consensus network to use.
731    #[serde(skip_serializing_if = "ConsensusNetwork::is_anemo")]
732    consensus_network: ConsensusNetwork,
733
734    // If true, use the correct (<=) comparison for max_gas_payment_objects instead of (<)
735    #[serde(skip_serializing_if = "is_false")]
736    correct_gas_payment_limit_check: bool,
737
738    // Set the upper bound allowed for max_epoch in zklogin signature.
739    #[serde(skip_serializing_if = "Option::is_none")]
740    zklogin_max_epoch_upper_bound_delta: Option<u64>,
741
742    // Controls leader scoring & schedule change in Mysticeti consensus.
743    #[serde(skip_serializing_if = "is_false")]
744    mysticeti_leader_scoring_and_schedule: bool,
745
746    // Enable resharing of shared objects using the same initial shared version
747    #[serde(skip_serializing_if = "is_false")]
748    reshare_at_same_initial_version: bool,
749
750    // Resolve Move abort locations to the package id instead of the runtime module ID.
751    #[serde(skip_serializing_if = "is_false")]
752    resolve_abort_locations_to_package_id: bool,
753
754    // Enables the use of the Mysticeti committed sub dag digest to the `ConsensusCommitInfo` in checkpoints.
755    // When disabled the default digest is used instead. It's important to have this guarded behind
756    // a flag as it will lead to checkpoint forks.
757    #[serde(skip_serializing_if = "is_false")]
758    mysticeti_use_committed_subdag_digest: bool,
759
760    // Enable VDF
761    #[serde(skip_serializing_if = "is_false")]
762    enable_vdf: bool,
763
764    // Controls whether consensus handler should record consensus determined shared object version
765    // assignments in consensus commit prologue transaction.
766    // The purpose of doing this is to enable replaying transaction without transaction effects.
767    #[serde(skip_serializing_if = "is_false")]
768    record_consensus_determined_version_assignments_in_prologue: bool,
769    // V2 also records initial shared versions for consensus objects.
770    // Deprecated: must always be set to `true`.
771    #[serde(skip_serializing_if = "is_false")]
772    record_consensus_determined_version_assignments_in_prologue_v2: bool,
773
774    // Run verification of framework upgrades using a new/fresh VM.
775    #[serde(skip_serializing_if = "is_false")]
776    fresh_vm_on_framework_upgrade: bool,
777
778    // When set to true, the consensus commit prologue transaction will be placed first
779    // in a consensus commit in checkpoints.
780    // If a checkpoint contains multiple consensus commit, say [cm1][cm2]. The each commit's
781    // consensus commit prologue will be the first transaction in each segment:
782    //     [ccp1, rest cm1][ccp2, rest cm2]
783    // The reason to prepose the prologue transaction is to provide information for transaction
784    // cancellation.
785    #[serde(skip_serializing_if = "is_false")]
786    prepend_prologue_tx_in_consensus_commit_in_checkpoints: bool,
787
788    // Set number of leaders per round for Mysticeti commits.
789    #[serde(skip_serializing_if = "Option::is_none")]
790    mysticeti_num_leaders_per_round: Option<usize>,
791
792    // Enable Soft Bundle (SIP-19).
793    #[serde(skip_serializing_if = "is_false")]
794    soft_bundle: bool,
795
796    // If true, enable the coin deny list V2.
797    #[serde(skip_serializing_if = "is_false")]
798    enable_coin_deny_list_v2: bool,
799
800    // Enable passkey auth (SIP-9)
801    #[serde(skip_serializing_if = "is_false")]
802    passkey_auth: bool,
803
804    // Use AuthorityCapabilitiesV2
805    #[serde(skip_serializing_if = "is_false")]
806    authority_capabilities_v2: bool,
807
808    // Rethrow type layout errors during serialization instead of trying to convert them.
809    #[serde(skip_serializing_if = "is_false")]
810    rethrow_serialization_type_layout_errors: bool,
811
812    // Use distributed vote leader scoring strategy in consensus.
813    #[serde(skip_serializing_if = "is_false")]
814    consensus_distributed_vote_scoring_strategy: bool,
815
816    // Probe rounds received by peers from every authority.
817    #[serde(skip_serializing_if = "is_false")]
818    consensus_round_prober: bool,
819
820    // Validate identifier inputs separately
821    #[serde(skip_serializing_if = "is_false")]
822    validate_identifier_inputs: bool,
823
824    // Disallow self identifier
825    #[serde(skip_serializing_if = "is_false")]
826    disallow_self_identifier: bool,
827
828    // Enables Mysticeti fastpath.
829    #[serde(skip_serializing_if = "is_false")]
830    mysticeti_fastpath: bool,
831
832    // If true, disable pre-consensus locking for owned objects.
833    // All transactions go through consensus, and owned object conflict detection
834    // happens post-consensus via lock acquisition.
835    #[serde(skip_serializing_if = "is_false")]
836    disable_preconsensus_locking: bool,
837
838    // Makes the event's sending module version-aware.
839    #[serde(skip_serializing_if = "is_false")]
840    relocate_event_module: bool,
841
842    // Enable uncompressed group elements in BLS123-81 G1
843    #[serde(skip_serializing_if = "is_false")]
844    uncompressed_g1_group_elements: bool,
845
846    #[serde(skip_serializing_if = "is_false")]
847    disallow_new_modules_in_deps_only_packages: bool,
848
849    // Use smart ancestor selection in consensus.
850    #[serde(skip_serializing_if = "is_false")]
851    consensus_smart_ancestor_selection: bool,
852
853    // Probe accepted rounds in round prober.
854    #[serde(skip_serializing_if = "is_false")]
855    consensus_round_prober_probe_accepted_rounds: bool,
856
857    // Enable v2 native charging for natives.
858    #[serde(skip_serializing_if = "is_false")]
859    native_charging_v2: bool,
860
861    // Enables the new logic for collecting the subdag in the consensus linearizer. The new logic does not stop the recursion at the highest
862    // committed round for each authority, but allows to commit uncommitted blocks up to gc round (excluded) for that authority.
863    #[serde(skip_serializing_if = "is_false")]
864    #[skip_protocol_config_accessor]
865    consensus_linearize_subdag_v2: bool,
866
867    // Properly convert certain type argument errors in the execution layer.
868    #[serde(skip_serializing_if = "is_false")]
869    convert_type_argument_error: bool,
870
871    // Variants count as nodes
872    #[serde(skip_serializing_if = "is_false")]
873    variant_nodes: bool,
874
875    // If true, enable zstd compression for consensus tonic network.
876    #[serde(skip_serializing_if = "is_false")]
877    consensus_zstd_compression: bool,
878
879    // If true, enables the optimizations for child object mutations, removing unnecessary mutations
880    #[serde(skip_serializing_if = "is_false")]
881    minimize_child_object_mutations: bool,
882
883    // If true, record the additional state digest in the consensus commit prologue.
884    // Deprecated: must always be set to `true`.
885    #[serde(skip_serializing_if = "is_false")]
886    record_additional_state_digest_in_prologue: bool,
887
888    // If true, enable `TxContext` Move API to go native.
889    #[serde(skip_serializing_if = "is_false")]
890    move_native_context: bool,
891
892    // If true, then it (1) will not enforce monotonicity checks for a block's ancestors and (2) calculates the commit's timestamp based on the
893    // weighted by stake median timestamp of the leader's ancestors.
894    #[serde(skip_serializing_if = "is_false")]
895    #[skip_protocol_config_accessor]
896    consensus_median_based_commit_timestamp: bool,
897
898    // If true, enables the normalization of PTB arguments but does not yet enable splatting
899    // `Result`s of length not equal to 1
900    #[serde(skip_serializing_if = "is_false")]
901    normalize_ptb_arguments: bool,
902
903    // If true, enabled batched block sync in consensus.
904    #[serde(skip_serializing_if = "is_false")]
905    consensus_batched_block_sync: bool,
906
907    // If true, enforces checkpoint timestamps are non-decreasing.
908    #[serde(skip_serializing_if = "is_false")]
909    enforce_checkpoint_timestamp_monotonicity: bool,
910
911    // If true, enables better errors and bounds for max ptb values
912    #[serde(skip_serializing_if = "is_false")]
913    max_ptb_value_size_v2: bool,
914
915    // If true, resolves all type input ids to be defining ID based in the adapter
916    #[serde(skip_serializing_if = "is_false")]
917    resolve_type_input_ids_to_defining_id: bool,
918
919    // Enable native function for party transfer
920    #[serde(skip_serializing_if = "is_false")]
921    enable_party_transfer: bool,
922
923    // Allow objects created or mutated in system transactions to exceed the max object size limit.
924    #[serde(skip_serializing_if = "is_false")]
925    allow_unbounded_system_objects: bool,
926
927    // Signifies the cut-over of using type tags instead of `Type`s in the object runtime.
928    #[serde(skip_serializing_if = "is_false")]
929    type_tags_in_object_runtime: bool,
930
931    // Enable accumulators
932    #[serde(skip_serializing_if = "is_false")]
933    enable_accumulators: bool,
934
935    // Enable coin reservation
936    #[serde(skip_serializing_if = "is_false")]
937    #[skip_protocol_config_accessor]
938    enable_coin_reservation_obj_refs: bool,
939
940    // If true, create the root accumulator object in the change epoch transaction.
941    // This must be enabled and shipped before `enable_accumulators` is set to true.
942    #[serde(skip_serializing_if = "is_false")]
943    create_root_accumulator_object: bool,
944
945    // Enable authenticated event streams
946    #[serde(skip_serializing_if = "is_false")]
947    #[skip_protocol_config_accessor]
948    enable_authenticated_event_streams: bool,
949
950    // Enable address balance gas payments
951    #[serde(skip_serializing_if = "is_false")]
952    enable_address_balance_gas_payments: bool,
953
954    // Validate gas price >= RGP at signing for address balance gas payments
955    #[serde(skip_serializing_if = "is_false")]
956    address_balance_gas_check_rgp_at_signing: bool,
957
958    #[serde(skip_serializing_if = "is_false")]
959    address_balance_gas_reject_gas_coin_arg: bool,
960
961    // Enable multi-epoch transaction expiration (max 1 epoch difference)
962    #[serde(skip_serializing_if = "is_false")]
963    enable_multi_epoch_transaction_expiration: bool,
964
965    // Relax ValidDuring expiration requirement for transactions with owned inputs
966    #[serde(skip_serializing_if = "is_false")]
967    relax_valid_during_for_owned_inputs: bool,
968
969    // Enable statically type checked ptb execution
970    #[serde(skip_serializing_if = "is_false")]
971    enable_ptb_execution_v2: bool,
972
973    // Provide better type resolution errors in the adapter.
974    #[serde(skip_serializing_if = "is_false")]
975    better_adapter_type_resolution_errors: bool,
976
977    // If true, record the time estimate processed in the consensus commit prologue.
978    #[serde(skip_serializing_if = "is_false")]
979    record_time_estimate_processed: bool,
980
981    // If true enable additional linkage checks.
982    #[serde(skip_serializing_if = "is_false")]
983    dependency_linkage_error: bool,
984
985    // If true enable additional multisig checks.
986    #[serde(skip_serializing_if = "is_false")]
987    additional_multisig_checks: bool,
988
989    // If true, ignore execution time observations after certs are closed.
990    #[serde(skip_serializing_if = "is_false")]
991    ignore_execution_time_observations_after_certs_closed: bool,
992
993    // If true use `debug_fatal` to report invariant violations.
994    // `debug_fatal` panics in debug builds and breaks tests/behavior based on older
995    // protocol versions (see make_vec_non_existent_type_v71.move)
996    #[serde(skip_serializing_if = "is_false")]
997    debug_fatal_on_move_invariant_violation: bool,
998
999    // DO NOT ENABLE THIS FOR PRODUCTION NETWORKS. used for testing only.
1000    // Allow private accumulator entrypoints
1001    #[serde(skip_serializing_if = "is_false")]
1002    allow_private_accumulator_entrypoints: bool,
1003
1004    // If true, include indirect state in the additional consensus digest.
1005    // Deprecated: must always be set to `true`.
1006    #[serde(skip_serializing_if = "is_false")]
1007    additional_consensus_digest_indirect_state: bool,
1008
1009    // Check for `init` for new modules to a package on upgrade.
1010    #[serde(skip_serializing_if = "is_false")]
1011    check_for_init_during_upgrade: bool,
1012
1013    // If true, run `init` for newly introduced modules during package upgrade.
1014    #[serde(skip_serializing_if = "is_false")]
1015    enable_init_on_upgrade: bool,
1016
1017    // If true, analyze upgrade-init linkage after all other PTB linkage constraints.
1018    #[serde(skip_serializing_if = "is_false")]
1019    enable_order_independent_upgrade_init_linkage: bool,
1020
1021    // If true, adds additional hardening and checks to upgrade-init linkage entries, and adds
1022    // additional linkage invariant checks around linkage.
1023    #[serde(skip_serializing_if = "is_false")]
1024    harden_linkage_consistency: bool,
1025
1026    // Check shared object transfer restrictions per command.
1027    #[serde(skip_serializing_if = "is_false")]
1028    per_command_shared_object_transfer_rules: bool,
1029
1030    // Validate PTB input and result indices before signing.
1031    #[serde(skip_serializing_if = "is_false")]
1032    validate_ptb_argument_indices: bool,
1033
1034    // Enable including checkpoint artifacts digest in the summary.
1035    #[serde(skip_serializing_if = "is_false")]
1036    include_checkpoint_artifacts_digest_in_summary: bool,
1037
1038    // If true, use MFP txns in load initial object debts.
1039    #[serde(skip_serializing_if = "is_false")]
1040    use_mfp_txns_in_load_initial_object_debts: bool,
1041
1042    // If true, cancel randomness-using txns when DKG has failed *before* doing other congestion checks.
1043    #[serde(skip_serializing_if = "is_false")]
1044    cancel_for_failed_dkg_early: bool,
1045
1046    // If true, keep advancing the DKG state machine while DKG is pending.
1047    #[serde(skip_serializing_if = "is_false")]
1048    always_advance_dkg_to_resolution: bool,
1049
1050    // Enable coin registry protocol
1051    #[serde(skip_serializing_if = "is_false")]
1052    enable_coin_registry: bool,
1053
1054    // Use abstract size in the object runtime instead the legacy value size.
1055    #[serde(skip_serializing_if = "is_false")]
1056    abstract_size_in_object_runtime: bool,
1057
1058    // If true charge for loads into the cache (i.e., fetches from storage) in the object runtime.
1059    #[serde(skip_serializing_if = "is_false")]
1060    object_runtime_charge_cache_load_gas: bool,
1061
1062    // If true, perform additional borrow checks
1063    #[serde(skip_serializing_if = "is_false")]
1064    additional_borrow_checks: bool,
1065
1066    // If true, use the new commit handler.
1067    #[serde(skip_serializing_if = "is_false")]
1068    use_new_commit_handler: bool,
1069
1070    // If true return a better error message when we encounter a loader error.
1071    #[serde(skip_serializing_if = "is_false")]
1072    better_loader_errors: bool,
1073
1074    // If true generate layouts for dynamic fields
1075    #[serde(skip_serializing_if = "is_false")]
1076    generate_df_type_layouts: bool,
1077
1078    // If true, allow Move functions called in PTBs to return references
1079    #[serde(skip_serializing_if = "is_false")]
1080    allow_references_in_ptbs: bool,
1081
1082    // If true, the tx_context_restrictions_verifier pass runs at Move module
1083    // publish time and rejects system-package signatures with `&mut TxContext`
1084    // + any `&mut _` return that have no non-`TxContext` `&mut U` parameter.
1085    // User packages are exempt: they can express the same shape through
1086    // generic instantiation, so PTB arity and auto-injection checks are the
1087    // safety mechanism there.
1088    #[serde(skip_serializing_if = "is_false")]
1089    framework_tx_context_mut_restrictions: bool,
1090
1091    // Count function and local signatures towards type-node budgets.
1092    #[serde(skip_serializing_if = "is_false")]
1093    include_function_signatures_in_instantiation_limits: bool,
1094
1095    // If true, the static PTB verifier restricts `TxContext` in Move call
1096    // signatures: it may appear at most once as `&mut TxContext`, or any
1097    // number of times as `&TxContext`, never by value, and never in return
1098    // position (it can never become a PTB result).
1099    #[serde(skip_serializing_if = "is_false")]
1100    ptb_tx_context_restrictions: bool,
1101
1102    // Enable display registry protocol
1103    #[serde(skip_serializing_if = "is_false")]
1104    enable_display_registry: bool,
1105
1106    // If true, enable private generics verifier v2
1107    #[serde(skip_serializing_if = "is_false")]
1108    private_generics_verifier_v2: bool,
1109
1110    // If true, deprecate global storage ops during Move module deserialization
1111    #[serde(skip_serializing_if = "is_false")]
1112    deprecate_global_storage_ops_during_deserialization: bool,
1113
1114    // If true, enable non-exclusive writes for user transactions.
1115    // DO NOT ENABLE outside of the transaction test runner.
1116    #[serde(skip_serializing_if = "is_false")]
1117    enable_non_exclusive_writes: bool,
1118
1119    // If true, deprecate global storage ops everywhere.
1120    #[serde(skip_serializing_if = "is_false")]
1121    deprecate_global_storage_ops: bool,
1122
1123    // If true, normalize depth formula to not be empty for zero depth.
1124    #[serde(skip_serializing_if = "is_false")]
1125    normalize_depth_formula: bool,
1126
1127    // If true, `LdConst` charges for the abstract value size of the constant instead of its
1128    // serialized byte length.
1129    #[serde(skip_serializing_if = "is_false")]
1130    charge_ld_const_abstract_size: bool,
1131
1132    // If true, skip GC'ed accept votes in CommitFinalizer.
1133    #[serde(skip_serializing_if = "is_false")]
1134    consensus_skip_gced_accept_votes: bool,
1135
1136    // If true, include cancelled randomness txns in the consensus commit prologue.
1137    // Deprecated: must always be set to `true`.
1138    #[serde(skip_serializing_if = "is_false")]
1139    include_cancelled_randomness_txns_in_prologue: bool,
1140
1141    // Enables address aliases.
1142    #[serde(skip_serializing_if = "is_false")]
1143    #[skip_protocol_config_accessor]
1144    address_aliases: bool,
1145
1146    // If true, create the forwarding address registry object in the change epoch transaction.
1147    #[serde(skip_serializing_if = "is_false")]
1148    create_forwarding_address_registry: bool,
1149
1150    // Corrects signature-to-signer mapping in CheckpointContentsV2.
1151    // Deprecated: must always be set to `true`.
1152    #[serde(skip_serializing_if = "is_false")]
1153    fix_checkpoint_signature_mapping: bool,
1154
1155    // If true, enable object funds withdraw.
1156    #[serde(skip_serializing_if = "is_false")]
1157    enable_object_funds_withdraw: bool,
1158
1159    // If true, unsettled object-funds withdraws are recorded using per-account net
1160    // amounts from transaction effects, instead of running-max withdraw amounts.
1161    #[serde(skip_serializing_if = "is_false")]
1162    record_net_unsettled_object_withdraws: bool,
1163
1164    // If true, skip GC'ed blocks in direct finalization.
1165    #[serde(skip_serializing_if = "is_false")]
1166    consensus_skip_gced_blocks_in_direct_finalization: bool,
1167
1168    // If true, uses a new rounding mechanism for gas calculations, replacing the step-based one
1169    #[serde(skip_serializing_if = "is_false")]
1170    gas_rounding_halve_digits: bool,
1171
1172    // If true, enable tx contexts in all argument positions
1173    #[serde(skip_serializing_if = "is_false")]
1174    flexible_tx_context_positions: bool,
1175
1176    // If true, disable entry point signature check.
1177    #[serde(skip_serializing_if = "is_false")]
1178    disable_entry_point_signature_check: bool,
1179
1180    // If true, convert withdrawal compatibility PTB arguments to coins at the start of the PTB.
1181    #[serde(skip_serializing_if = "is_false")]
1182    convert_withdrawal_compatibility_ptb_arguments: bool,
1183
1184    // If true, additional restrictions for hot or not entry functions are enforced.
1185    #[serde(skip_serializing_if = "is_false")]
1186    restrict_hot_or_not_entry_functions: bool,
1187
1188    // If true, split checkpoints in consensus handler.
1189    #[serde(skip_serializing_if = "is_false")]
1190    split_checkpoints_in_consensus_handler: bool,
1191
1192    // If true, always accept committed system transactions.
1193    #[serde(skip_serializing_if = "is_false")]
1194    consensus_always_accept_system_transactions: bool,
1195
1196    // If true perform consistent verification of metadata
1197    #[serde(skip_serializing_if = "is_false")]
1198    validator_metadata_verify_v2: bool,
1199
1200    // If true, defer transactions with unpaid consensus amplification
1201    // (where duplicate count exceeds gas_price / RGP + 1)
1202    #[serde(skip_serializing_if = "is_false")]
1203    defer_unpaid_amplification: bool,
1204
1205    // If true, defer transactions that won an owned object lock when other transactions
1206    // in the same commit attempted to lock the same object (double-spend attempt).
1207    #[serde(skip_serializing_if = "is_false")]
1208    defer_owned_object_double_spend: bool,
1209
1210    // If true, `TransactionExpiration::Validity` is accepted, allowing a transaction to
1211    // restrict which validators may propose it in consensus.
1212    #[serde(skip_serializing_if = "is_false")]
1213    allowed_proposers: bool,
1214
1215    #[serde(skip_serializing_if = "is_false")]
1216    randomize_checkpoint_tx_limit_in_tests: bool,
1217
1218    // If true, mark the gas coin as uninitialized in drop safety when there is no gas coin.
1219    #[serde(skip_serializing_if = "is_false")]
1220    gasless_transaction_drop_safety: bool,
1221
1222    // When split-checkpoints enabled, merge randomness and non-randomness schedulables together.
1223    // Deprecated: must always be set to `true`.
1224    #[serde(skip_serializing_if = "is_false")]
1225    merge_randomness_into_checkpoint: bool,
1226
1227    // If true, use coin party owner information.
1228    #[serde(skip_serializing_if = "is_false")]
1229    use_coin_party_owner: bool,
1230
1231    #[serde(skip_serializing_if = "is_false")]
1232    enable_gasless: bool,
1233
1234    #[serde(skip_serializing_if = "is_false")]
1235    gasless_verify_remaining_balance: bool,
1236
1237    #[serde(skip_serializing_if = "is_false")]
1238    disallow_jump_orphans: bool,
1239
1240    // If true, return early on type mismatch in receive_object.
1241    #[serde(skip_serializing_if = "is_false")]
1242    early_return_receive_object_mismatched_type: bool,
1243
1244    // If true, use consensus commit timestamps to determine epoch close instead of EndOfPublish voting.
1245    // Each validator transitions from AcceptAllCerts to RejectAllCerts when the consensus commit
1246    // timestamp exceeds the reconfiguration timestamp. EndOfPublish quorum still works as a
1247    // fallback for manual epoch close.
1248    #[serde(skip_serializing_if = "is_false")]
1249    timestamp_based_epoch_close: bool,
1250
1251    // If true, groth16::prepare_verifying_key checks that the verifying key has no more than
1252    // MAX_PUBLIC_INPUTS public inputs.
1253    #[serde(skip_serializing_if = "is_false")]
1254    limit_groth16_pvk_inputs: bool,
1255
1256    // If true, the funds-accumulator address-balance change invariant
1257    // (`TemporaryStore::check_address_balance_changes`) is enforced as a consensus check —
1258    // violations abort the tx via the conservation-recovery flow. When false, the check still
1259    // runs but a violation panics so unexpected violations surface during rollout.
1260    #[serde(skip_serializing_if = "is_false")]
1261    enforce_address_balance_change_invariant: bool,
1262
1263    // If true, validators may broadcast `UpdateTransactionDenyConfig` consensus messages.
1264    #[serde(skip_serializing_if = "is_false")]
1265    share_transaction_deny_config_in_consensus: bool,
1266
1267    // Enables more granular post-execution checks.
1268    #[serde(skip_serializing_if = "is_false")]
1269    granular_post_execution_checks: bool,
1270
1271    // If true, exit early for IFWW transactions.
1272    #[serde(skip_serializing_if = "is_false")]
1273    early_exit_on_iffw: bool,
1274
1275    // If true enable unified linkage
1276    #[serde(skip_serializing_if = "is_false")]
1277    enable_unified_linkage: bool,
1278
1279    // Enable allowance-sourced funds withdrawals (`WithdrawFrom::SenderAllowance`).
1280    // Requires `enable_accumulators`.
1281    #[serde(skip_serializing_if = "is_false")]
1282    #[skip_protocol_config_accessor]
1283    enable_allowances: bool,
1284
1285    // Fixes last-use scoping and live-reference metering for generated `Read` PTB arguments.
1286    #[serde(skip_serializing_if = "is_false")]
1287    fix_ptb_generated_reads: bool,
1288
1289    #[serde(skip_serializing_if = "is_false")]
1290    check_object_funds_withdraw_in_execution: bool,
1291    // If true, use the bitset implementation for PTB memory safety invariant check.
1292    #[serde(skip_serializing_if = "is_false")]
1293    memory_safety_invariant_check_v2: bool,
1294}
1295
1296fn is_false(b: &bool) -> bool {
1297    !b
1298}
1299
1300fn is_empty(b: &BTreeSet<String>) -> bool {
1301    b.is_empty()
1302}
1303
1304fn is_zero(val: &u64) -> bool {
1305    *val == 0
1306}
1307
1308/// Ordering mechanism for transactions in one Narwhal consensus output.
1309#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1310pub enum ConsensusTransactionOrdering {
1311    /// No ordering. Transactions are processed in the order they appear in the consensus output.
1312    #[default]
1313    None,
1314    /// Order transactions by gas price, highest first.
1315    ByGasPrice,
1316}
1317
1318impl ConsensusTransactionOrdering {
1319    pub fn is_none(&self) -> bool {
1320        matches!(self, ConsensusTransactionOrdering::None)
1321    }
1322}
1323
1324#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1325pub struct ExecutionTimeEstimateParams {
1326    // Targeted per-object utilization as an integer percentage (1-100).
1327    pub target_utilization: u64,
1328    // Schedule up to this much extra work (in microseconds) per object,
1329    // but don't allow more than a single transaction to exceed this
1330    // burst limit.
1331    pub allowed_txn_cost_overage_burst_limit_us: u64,
1332
1333    // For separate budget for randomness-using tx, the above limits are
1334    // used with this integer-percentage scaling factor (1-100).
1335    pub randomness_scalar: u64,
1336
1337    // Absolute maximum allowed transaction duration estimate (in microseconds).
1338    pub max_estimate_us: u64,
1339
1340    // Number of the final checkpoints in an epoch whose observations should be
1341    // stored for use in the next epoch.
1342    pub stored_observations_num_included_checkpoints: u64,
1343
1344    // Absolute limit on the number of saved observations at end of epoch.
1345    pub stored_observations_limit: u64,
1346
1347    // Requires observations from at least this amount of stake in order to use
1348    // observation-based execution time estimates instead of the default.
1349    #[serde(skip_serializing_if = "is_zero")]
1350    pub stake_weighted_median_threshold: u64,
1351
1352    // For backwards compatibility with old behavior we use a zero default duration when adding
1353    // new execution time observation keys and a zero generation when loading stored observations.
1354    // This can be removed once set to "true" on mainnet.
1355    #[serde(skip_serializing_if = "is_false")]
1356    pub default_none_duration_for_new_keys: bool,
1357
1358    // Number of observations per chunk. When None, chunking is disabled.
1359    #[serde(skip_serializing_if = "Option::is_none")]
1360    pub observations_chunk_size: Option<u64>,
1361}
1362
1363// The config for per object congestion control in consensus handler.
1364#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1365pub enum PerObjectCongestionControlMode {
1366    #[default]
1367    None, // Deprecated.
1368    TotalGasBudget,                                     // Deprecated.
1369    TotalTxCount,                                       // Deprecated.
1370    TotalGasBudgetWithCap,                              // Deprecated.
1371    ExecutionTimeEstimate(ExecutionTimeEstimateParams), // Use execution time estimate as execution cost.
1372}
1373
1374impl PerObjectCongestionControlMode {
1375    pub fn is_none(&self) -> bool {
1376        matches!(self, PerObjectCongestionControlMode::None)
1377    }
1378}
1379
1380// Configuration options for consensus algorithm.
1381#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1382pub enum ConsensusChoice {
1383    #[default]
1384    Narwhal,
1385    SwapEachEpoch,
1386    Mysticeti,
1387}
1388
1389impl ConsensusChoice {
1390    pub fn is_narwhal(&self) -> bool {
1391        matches!(self, ConsensusChoice::Narwhal)
1392    }
1393}
1394
1395// Configuration options for consensus network.
1396#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1397pub enum ConsensusNetwork {
1398    #[default]
1399    Anemo,
1400    Tonic,
1401}
1402
1403impl ConsensusNetwork {
1404    pub fn is_anemo(&self) -> bool {
1405        matches!(self, ConsensusNetwork::Anemo)
1406    }
1407}
1408
1409/// Constants that change the behavior of the protocol.
1410///
1411/// The value of each constant here must be fixed for a given protocol version. To change the value
1412/// of a constant, advance the protocol version, and add support for it in `get_for_version` under
1413/// the new version number.
1414/// (below).
1415///
1416/// To add a new field to this struct, use the following procedure:
1417/// - Advance the protocol version.
1418/// - Add the field as a private `Option<T>` to the struct.
1419/// - Initialize the field to `None` in prior protocol versions.
1420/// - Initialize the field to `Some(val)` for your new protocol version.
1421/// - Add a public getter that simply unwraps the field.
1422/// - Two public getters of the form `field(&self) -> field_type`
1423///     and `field_as_option(&self) -> Option<field_type>` will be automatically generated for you.
1424/// Example for a field: `new_constant: Option<u64>`
1425/// ```rust,ignore
1426///      pub fn new_constant(&self) -> u64 {
1427///         self.new_constant.expect(Self::CONSTANT_ERR_MSG)
1428///     }
1429///      pub fn new_constant_as_option(&self) -> Option<u64> {
1430///         self.new_constant.expect(Self::CONSTANT_ERR_MSG)
1431///     }
1432/// ```
1433/// With `pub fn new_constant(&self) -> u64`, if the constant is accessed in a protocol version
1434/// in which it is not defined, the validator will crash. (Crashing is necessary because
1435/// this type of error would almost always result in forking if not prevented here).
1436/// If you don't want the validator to crash, you can use the
1437/// `pub fn new_constant_as_option(&self) -> Option<u64>` getter, which will
1438/// return `None` if the field is not defined at that version.
1439/// - If you want a customized getter, you can add a method in the impl.
1440#[skip_serializing_none]
1441#[derive(Clone, Serialize, Debug, ProtocolConfigAccessors, ProtocolConfigOverride)]
1442pub struct ProtocolConfig {
1443    pub version: ProtocolVersion,
1444
1445    /// The chain this config was instantiated for. Unlike the other fields, this is not a
1446    /// versioned protocol constant: it identifies the network rather than describing protocol
1447    /// behavior, so it is intentionally excluded from serialization (and from the config
1448    /// snapshots) and is populated directly from the chain passed to `get_for_version`.
1449    #[serde(skip)]
1450    chain: Chain,
1451
1452    feature_flags: FeatureFlags,
1453
1454    // ==== Transaction input limits ====
1455    /// Maximum serialized size of a transaction (in bytes).
1456    max_tx_size_bytes: Option<u64>,
1457
1458    /// Maximum number of input objects to a transaction. Enforced by the transaction input checker
1459    max_input_objects: Option<u64>,
1460
1461    /// Max size of objects a transaction can write to disk after completion. Enforce by the Sui adapter.
1462    /// This is the sum of the serialized size of all objects written to disk.
1463    /// The max size of individual objects on the other hand is `max_move_object_size`.
1464    max_size_written_objects: Option<u64>,
1465    /// Max size of objects a system transaction can write to disk after completion. Enforce by the Sui adapter.
1466    /// Similar to `max_size_written_objects` but for system transactions.
1467    max_size_written_objects_system_tx: Option<u64>,
1468
1469    /// Maximum size of serialized transaction effects.
1470    max_serialized_tx_effects_size_bytes: Option<u64>,
1471
1472    /// Maximum size of serialized transaction effects for system transactions.
1473    max_serialized_tx_effects_size_bytes_system_tx: Option<u64>,
1474
1475    /// Maximum number of gas payment objects for a transaction.
1476    max_gas_payment_objects: Option<u32>,
1477
1478    /// Maximum number of modules in a Publish transaction.
1479    max_modules_in_publish: Option<u32>,
1480
1481    /// Maximum number of transitive dependencies in a package when publishing.
1482    max_package_dependencies: Option<u32>,
1483
1484    /// Maximum number of arguments in a move call or a ProgrammableTransaction's
1485    /// TransferObjects command.
1486    max_arguments: Option<u32>,
1487
1488    /// Maximum number of total type arguments, computed recursively.
1489    max_type_arguments: Option<u32>,
1490
1491    /// Maximum depth of an individual type argument.
1492    max_type_argument_depth: Option<u32>,
1493
1494    /// Maximum size of a Pure CallArg.
1495    max_pure_argument_size: Option<u32>,
1496
1497    /// Maximum number of Commands in a ProgrammableTransaction.
1498    max_programmable_tx_commands: Option<u32>,
1499
1500    // ==== Move VM, Move bytecode verifier, and execution limits ===
1501    /// Maximum Move bytecode version the VM understands. All older versions are accepted.
1502    move_binary_format_version: Option<u32>,
1503    min_move_binary_format_version: Option<u32>,
1504
1505    /// Configuration controlling binary tables size.
1506    binary_module_handles: Option<u16>,
1507    binary_struct_handles: Option<u16>,
1508    binary_function_handles: Option<u16>,
1509    binary_function_instantiations: Option<u16>,
1510    binary_signatures: Option<u16>,
1511    binary_constant_pool: Option<u16>,
1512    binary_identifiers: Option<u16>,
1513    binary_address_identifiers: Option<u16>,
1514    binary_struct_defs: Option<u16>,
1515    binary_struct_def_instantiations: Option<u16>,
1516    binary_function_defs: Option<u16>,
1517    binary_field_handles: Option<u16>,
1518    binary_field_instantiations: Option<u16>,
1519    binary_friend_decls: Option<u16>,
1520    binary_enum_defs: Option<u16>,
1521    binary_enum_def_instantiations: Option<u16>,
1522    binary_variant_handles: Option<u16>,
1523    binary_variant_instantiation_handles: Option<u16>,
1524
1525    /// Maximum size of the `contents` part of an object, in bytes. Enforced by the Sui adapter when effects are produced.
1526    max_move_object_size: Option<u64>,
1527
1528    // TODO: Option<increase to 500 KB. currently, publishing a package > 500 KB exceeds the max computation gas cost
1529    /// Maximum size of a Move package object, in bytes. Enforced by the Sui adapter at the end of a publish transaction.
1530    max_move_package_size: Option<u64>,
1531
1532    /// Max number of publish or upgrade commands allowed in a programmable transaction block.
1533    max_publish_or_upgrade_per_ptb: Option<u64>,
1534
1535    /// Maximum gas budget in MIST that a transaction can use.
1536    max_tx_gas: Option<u64>,
1537
1538    /// Maximum amount of the proposed gas price in MIST (defined in the transaction).
1539    max_gas_price: Option<u64>,
1540
1541    /// For aborted txns, we cap the gas price at a factor of RGP. This lowers risk of setting higher priority gas price
1542    /// if there's a chance the txn will abort.
1543    max_gas_price_rgp_factor_for_aborted_transactions: Option<u64>,
1544
1545    /// The max computation bucket for gas. This is the max that can be charged for computation.
1546    max_gas_computation_bucket: Option<u64>,
1547
1548    // Define the value used to round up computation gas charges
1549    gas_rounding_step: Option<u64>,
1550
1551    /// Maximum number of nested loops. Enforced by the Move bytecode verifier.
1552    max_loop_depth: Option<u64>,
1553
1554    /// Maximum number of type arguments that can be bound to generic type parameters. Enforced by the Move bytecode verifier.
1555    max_generic_instantiation_length: Option<u64>,
1556
1557    /// Maximum number of parameters that a Move function can have. Enforced by the Move bytecode verifier.
1558    max_function_parameters: Option<u64>,
1559
1560    /// Maximum number of basic blocks that a Move function can have. Enforced by the Move bytecode verifier.
1561    max_basic_blocks: Option<u64>,
1562
1563    /// Maximum stack size value. Enforced by the Move bytecode verifier.
1564    max_value_stack_size: Option<u64>,
1565
1566    /// Maximum number of "type nodes", a metric for how big a SignatureToken will be when expanded into a fully qualified type. Enforced by the Move bytecode verifier.
1567    max_type_nodes: Option<u64>,
1568
1569    /// Maximum number of "type nodes" that can be instantiated in a single function.
1570    max_generic_instantiation_type_nodes_per_function: Option<u64>,
1571
1572    /// Maximum number of "type nodes" that can be instantiated in a module.
1573    max_generic_instantiation_type_nodes_per_module: Option<u64>,
1574
1575    /// Maximum number of "type nodes" allowed in an accumulator.
1576    max_accumulator_type_nodes: Option<u64>,
1577
1578    /// Maximum number of push instructions in one function. Enforced by the Move bytecode verifier.
1579    max_push_size: Option<u64>,
1580
1581    /// Maximum number of struct definitions in a module. Enforced by the Move bytecode verifier.
1582    max_struct_definitions: Option<u64>,
1583
1584    /// Maximum number of function definitions in a module. Enforced by the Move bytecode verifier.
1585    max_function_definitions: Option<u64>,
1586
1587    /// Maximum number of fields allowed in a struct definition. Enforced by the Move bytecode verifier.
1588    max_fields_in_struct: Option<u64>,
1589
1590    /// Maximum dependency depth. Enforced by the Move linker when loading dependent modules.
1591    max_dependency_depth: Option<u64>,
1592
1593    /// Maximum number of Move events that a single transaction can emit. Enforced by the VM during execution.
1594    max_num_event_emit: Option<u64>,
1595
1596    /// Maximum number of new IDs that a single transaction can create. Enforced by the VM during execution.
1597    max_num_new_move_object_ids: Option<u64>,
1598
1599    /// Maximum number of new IDs that a single system transaction can create. Enforced by the VM during execution.
1600    max_num_new_move_object_ids_system_tx: Option<u64>,
1601
1602    /// Maximum number of IDs that a single transaction can delete. Enforced by the VM during execution.
1603    max_num_deleted_move_object_ids: Option<u64>,
1604
1605    /// Maximum number of IDs that a single system transaction can delete. Enforced by the VM during execution.
1606    max_num_deleted_move_object_ids_system_tx: Option<u64>,
1607
1608    /// Maximum number of IDs that a single transaction can transfer. Enforced by the VM during execution.
1609    max_num_transferred_move_object_ids: Option<u64>,
1610
1611    /// Maximum number of IDs that a single system transaction can transfer. Enforced by the VM during execution.
1612    max_num_transferred_move_object_ids_system_tx: Option<u64>,
1613
1614    /// Maximum size of a Move user event. Enforced by the VM during execution.
1615    max_event_emit_size: Option<u64>,
1616
1617    /// Maximum size of a Move user event. Enforced by the VM during execution.
1618    max_event_emit_size_total: Option<u64>,
1619
1620    /// Maximum length of a vector in Move. Enforced by the VM during execution, and for constants, by the verifier.
1621    max_move_vector_len: Option<u64>,
1622
1623    /// Maximum length of an `Identifier` in Move. Enforced by the bytecode verifier at signing.
1624    max_move_identifier_len: Option<u64>,
1625
1626    /// Maximum depth of a Move value within the VM.
1627    max_move_value_depth: Option<u64>,
1628
1629    /// Maximum number of bytes a single package's arena may allocate when the package is loaded
1630    /// into the VM. If unset, the VM uses its built-in default.
1631    package_arena_size_in_bytes: Option<u64>,
1632
1633    /// Maximum number of variants in an enum. Enforced by the bytecode verifier at signing.
1634    max_move_enum_variants: Option<u64>,
1635
1636    /// Maximum number of back edges in Move function. Enforced by the bytecode verifier at signing.
1637    max_back_edges_per_function: Option<u64>,
1638
1639    /// Maximum number of back edges in Move module. Enforced by the bytecode verifier at signing.
1640    max_back_edges_per_module: Option<u64>,
1641
1642    /// Maximum number of meter `ticks` spent verifying a Move function. Enforced by the bytecode verifier at signing.
1643    max_verifier_meter_ticks_per_function: Option<u64>,
1644
1645    /// Maximum number of meter `ticks` spent verifying a Move module. Enforced by the bytecode verifier at signing.
1646    max_meter_ticks_per_module: Option<u64>,
1647
1648    /// Maximum number of meter `ticks` spent verifying a Move package. Enforced by the bytecode verifier at signing.
1649    max_meter_ticks_per_package: Option<u64>,
1650
1651    // === Object runtime internal operation limits ====
1652    // These affect dynamic fields
1653    /// Maximum number of cached objects in the object runtime ObjectStore. Enforced by object runtime during execution
1654    object_runtime_max_num_cached_objects: Option<u64>,
1655
1656    /// Maximum number of cached objects in the object runtime ObjectStore in system transaction. Enforced by object runtime during execution
1657    object_runtime_max_num_cached_objects_system_tx: Option<u64>,
1658
1659    /// Maximum number of stored objects accessed by object runtime ObjectStore. Enforced by object runtime during execution
1660    object_runtime_max_num_store_entries: Option<u64>,
1661
1662    /// Maximum number of stored objects accessed by object runtime ObjectStore in system transaction. Enforced by object runtime during execution
1663    object_runtime_max_num_store_entries_system_tx: Option<u64>,
1664
1665    // === Execution gas costs ====
1666    /// Base cost for any Sui transaction
1667    base_tx_cost_fixed: Option<u64>,
1668
1669    /// Additional cost for a transaction that publishes a package
1670    /// i.e., the base cost of such a transaction is base_tx_cost_fixed + package_publish_cost_fixed
1671    package_publish_cost_fixed: Option<u64>,
1672
1673    /// Cost per byte of a Move call transaction
1674    /// i.e., the cost of such a transaction is base_cost + (base_tx_cost_per_byte * size)
1675    base_tx_cost_per_byte: Option<u64>,
1676
1677    /// Cost per byte for a transaction that publishes a package
1678    package_publish_cost_per_byte: Option<u64>,
1679
1680    // Per-byte cost of reading an object during transaction execution
1681    obj_access_cost_read_per_byte: Option<u64>,
1682
1683    // Per-byte cost of writing an object during transaction execution
1684    obj_access_cost_mutate_per_byte: Option<u64>,
1685
1686    // Per-byte cost of deleting an object during transaction execution
1687    obj_access_cost_delete_per_byte: Option<u64>,
1688
1689    /// Per-byte cost charged for each input object to a transaction.
1690    /// Meant to approximate the cost of checking locks for each object
1691    // TODO: Option<I'm not sure that this cost makes sense. Checking locks is "free"
1692    // in the sense that an invalid tx that can never be committed/pay gas can
1693    // force validators to check an arbitrary number of locks. If those checks are
1694    // "free" for invalid transactions, why charge for them in valid transactions
1695    // TODO: Option<if we keep this, I think we probably want it to be a fixed cost rather
1696    // than a per-byte cost. checking an object lock should not require loading an
1697    // entire object, just consulting an ID -> tx digest map
1698    obj_access_cost_verify_per_byte: Option<u64>,
1699
1700    // Maximal nodes which are allowed when converting to a type layout.
1701    max_type_to_layout_nodes: Option<u64>,
1702
1703    // Maximal size in bytes that a PTB value can be
1704    max_ptb_value_size: Option<u64>,
1705
1706    // === Gas version. gas model ===
1707    /// Gas model version, what code we are using to charge gas
1708    gas_model_version: Option<u64>,
1709
1710    // === Storage gas costs ===
1711    /// Per-byte cost of storing an object in the Sui global object store. Some of this cost may be refundable if the object is later freed
1712    obj_data_cost_refundable: Option<u64>,
1713
1714    // Per-byte cost of storing an object in the Sui transaction log (e.g., in CertifiedTransactionEffects)
1715    // This depends on the size of various fields including the effects
1716    // TODO: Option<I don't fully understand this^ and more details would be useful
1717    obj_metadata_cost_non_refundable: Option<u64>,
1718
1719    // === Tokenomics ===
1720
1721    // TODO: Option<this should be changed to u64.
1722    /// Sender of a txn that touches an object will get this percent of the storage rebate back.
1723    /// In basis point.
1724    storage_rebate_rate: Option<u64>,
1725
1726    /// 5% of the storage fund's share of rewards are reinvested into the storage fund.
1727    /// In basis point.
1728    storage_fund_reinvest_rate: Option<u64>,
1729
1730    /// The share of rewards that will be slashed and redistributed is 50%.
1731    /// In basis point.
1732    reward_slashing_rate: Option<u64>,
1733
1734    /// Unit gas price, Mist per internal gas unit.
1735    storage_gas_price: Option<u64>,
1736
1737    /// Per-object storage cost for accumulator objects, used during end-of-epoch accounting.
1738    accumulator_object_storage_cost: Option<u64>,
1739
1740    // === Core Protocol ===
1741    /// Max number of transactions per checkpoint.
1742    /// Note that this is a protocol constant and not a config as validators must have this set to
1743    /// the same value, otherwise they *will* fork.
1744    max_transactions_per_checkpoint: Option<u64>,
1745
1746    /// Max size of a checkpoint in bytes.
1747    /// Note that this is a protocol constant and not a config as validators must have this set to
1748    /// the same value, otherwise they *will* fork.
1749    max_checkpoint_size_bytes: Option<u64>,
1750
1751    /// A protocol upgrade always requires 2f+1 stake to agree. We support a buffer of additional
1752    /// stake (as a fraction of f, expressed in basis points) that is required before an upgrade
1753    /// can happen automatically. 10000bps would indicate that complete unanimity is required (all
1754    /// 3f+1 must vote), while 0bps would indicate that 2f+1 is sufficient.
1755    buffer_stake_for_protocol_upgrade_bps: Option<u64>,
1756
1757    // === Native Function Costs ===
1758
1759    // `address` module
1760    // Cost params for the Move native function `address::from_bytes(bytes: vector<u8>)`
1761    address_from_bytes_cost_base: Option<u64>,
1762    // Cost params for the Move native function `address::to_u256(address): u256`
1763    address_to_u256_cost_base: Option<u64>,
1764    // Cost params for the Move native function `address::from_u256(u256): address`
1765    address_from_u256_cost_base: Option<u64>,
1766
1767    // `config` module
1768    // Cost params for the Move native function `read_setting_impl<Name: copy + drop + store,
1769    // SettingValue: key + store, SettingDataValue: store, Value: copy + drop + store,
1770    // >(config: address, name: address, current_epoch: u64): Option<Value>`
1771    config_read_setting_impl_cost_base: Option<u64>,
1772    config_read_setting_impl_cost_per_byte: Option<u64>,
1773
1774    package_original_package_id_impl_cost_base: Option<u64>,
1775    package_original_package_id_impl_cost_per_byte: Option<u64>,
1776
1777    // `dynamic_field` module
1778    // Cost params for the Move native function `hash_type_and_key<K: copy + drop + store>(parent: address, k: K): address`
1779    dynamic_field_hash_type_and_key_cost_base: Option<u64>,
1780    dynamic_field_hash_type_and_key_type_cost_per_byte: Option<u64>,
1781    dynamic_field_hash_type_and_key_value_cost_per_byte: Option<u64>,
1782    dynamic_field_hash_type_and_key_type_tag_cost_per_byte: Option<u64>,
1783    // Cost params for the Move native function `add_child_object<Child: key>(parent: address, child: Child)`
1784    dynamic_field_add_child_object_cost_base: Option<u64>,
1785    dynamic_field_add_child_object_type_cost_per_byte: Option<u64>,
1786    dynamic_field_add_child_object_value_cost_per_byte: Option<u64>,
1787    dynamic_field_add_child_object_struct_tag_cost_per_byte: Option<u64>,
1788    // Cost params for the Move native function `borrow_child_object_mut<Child: key>(parent: &mut UID, id: address): &mut Child`
1789    dynamic_field_borrow_child_object_cost_base: Option<u64>,
1790    dynamic_field_borrow_child_object_child_ref_cost_per_byte: Option<u64>,
1791    dynamic_field_borrow_child_object_type_cost_per_byte: Option<u64>,
1792    // Cost params for the Move native function `remove_child_object<Child: key>(parent: address, id: address): Child`
1793    dynamic_field_remove_child_object_cost_base: Option<u64>,
1794    dynamic_field_remove_child_object_child_cost_per_byte: Option<u64>,
1795    dynamic_field_remove_child_object_type_cost_per_byte: Option<u64>,
1796    // Cost params for the Move native function `has_child_object(parent: address, id: address): bool`
1797    dynamic_field_has_child_object_cost_base: Option<u64>,
1798    // Cost params for the Move native function `has_child_object_with_ty<Child: key>(parent: address, id: address): bool`
1799    dynamic_field_has_child_object_with_ty_cost_base: Option<u64>,
1800    dynamic_field_has_child_object_with_ty_type_cost_per_byte: Option<u64>,
1801    dynamic_field_has_child_object_with_ty_type_tag_cost_per_byte: Option<u64>,
1802
1803    // `scratch` module
1804    // Cost params for the Move native function `add_impl<V: drop>(key: address, value: V)`
1805    scratch_add_cost_base: Option<u64>,
1806    // Cost params for the Move native function `read_impl<V: copy + drop>(key: address): V`
1807    scratch_read_cost_base: Option<u64>,
1808    scratch_read_value_cost: Option<u64>,
1809    // Cost params for the Move native function `remove_impl<V: drop>(key: address): V`
1810    scratch_remove_cost_base: Option<u64>,
1811    // Cost params for the Move native function `exists_impl(key: address): bool`
1812    scratch_exists_cost_base: Option<u64>,
1813    // Cost params for the Move native function `exists_with_type_impl<V: drop>(key: address): bool`
1814    scratch_exists_with_type_cost_base: Option<u64>,
1815    scratch_exists_with_type_type_cost: Option<u64>,
1816    // Maximum number of entries in the per-transaction `sui::scratch` store.
1817    max_scratch_pad_size: Option<u64>,
1818
1819    // `event` module
1820    // Cost params for the Move native function `event::emit<T: copy + drop>(event: T)`
1821    event_emit_cost_base: Option<u64>,
1822    event_emit_value_size_derivation_cost_per_byte: Option<u64>,
1823    event_emit_tag_size_derivation_cost_per_byte: Option<u64>,
1824    event_emit_output_cost_per_byte: Option<u64>,
1825    event_emit_auth_stream_cost: Option<u64>,
1826
1827    // `funds_accumulator` module
1828    // Base cost for reserving object funds for withdrawal.
1829    reserve_object_funds_for_withdrawal_cost_base: Option<u64>,
1830    // Cost of loading an object's settled balance on the first withdrawal for an owner and type.
1831    reserve_object_funds_for_withdrawal_cold_read_cost: Option<u64>,
1832
1833    //  `object` module
1834    // Cost params for the Move native function `borrow_uid<T: key>(obj: &T): &UID`
1835    object_borrow_uid_cost_base: Option<u64>,
1836    // Cost params for the Move native function `delete_impl(id: address)`
1837    object_delete_impl_cost_base: Option<u64>,
1838    // Cost params for the Move native function `record_new_uid(id: address)`
1839    object_record_new_uid_cost_base: Option<u64>,
1840    // Cost params for the Move native function
1841    // `record_new_uid_from_hash(parent: address, bytes: address)`
1842    object_record_new_uid_from_hash_cost_base: Option<u64>,
1843
1844    // Transfer
1845    // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
1846    transfer_transfer_internal_cost_base: Option<u64>,
1847    // Cost params for the Move native function `party_transfer_impl<T: key>(obj: T, party_members: vector<address>)`
1848    transfer_party_transfer_internal_cost_base: Option<u64>,
1849    // Cost params for the Move native function `freeze_object<T: key>(obj: T)`
1850    transfer_freeze_object_cost_base: Option<u64>,
1851    // Cost params for the Move native function `share_object<T: key>(obj: T)`
1852    transfer_share_object_cost_base: Option<u64>,
1853    // Cost params for the Move native function
1854    // `receive_object<T: key>(p: &mut UID, recv: Receiving<T>T)`
1855    transfer_receive_object_cost_base: Option<u64>,
1856    transfer_receive_object_cost_per_byte: Option<u64>,
1857    transfer_receive_object_type_cost_per_byte: Option<u64>,
1858
1859    // TxContext
1860    // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
1861    tx_context_derive_id_cost_base: Option<u64>,
1862    tx_context_fresh_id_cost_base: Option<u64>,
1863    tx_context_sender_cost_base: Option<u64>,
1864    tx_context_epoch_cost_base: Option<u64>,
1865    tx_context_epoch_timestamp_ms_cost_base: Option<u64>,
1866    tx_context_sponsor_cost_base: Option<u64>,
1867    tx_context_rgp_cost_base: Option<u64>,
1868    tx_context_gas_price_cost_base: Option<u64>,
1869    tx_context_gas_budget_cost_base: Option<u64>,
1870    tx_context_ids_created_cost_base: Option<u64>,
1871    tx_context_replace_cost_base: Option<u64>,
1872
1873    // Types
1874    // Cost params for the Move native function `is_one_time_witness<T: drop>(_: &T): bool`
1875    types_is_one_time_witness_cost_base: Option<u64>,
1876    types_is_one_time_witness_type_tag_cost_per_byte: Option<u64>,
1877    types_is_one_time_witness_type_cost_per_byte: Option<u64>,
1878
1879    // Validator
1880    // Cost params for the Move native function `validate_metadata_bcs(metadata: vector<u8>)`
1881    validator_validate_metadata_cost_base: Option<u64>,
1882    validator_validate_metadata_data_cost_per_byte: Option<u64>,
1883
1884    // Crypto natives
1885    crypto_invalid_arguments_cost: Option<u64>,
1886    // bls12381::bls12381_min_sig_verify
1887    bls12381_bls12381_min_sig_verify_cost_base: Option<u64>,
1888    bls12381_bls12381_min_sig_verify_msg_cost_per_byte: Option<u64>,
1889    bls12381_bls12381_min_sig_verify_msg_cost_per_block: Option<u64>,
1890
1891    // bls12381::bls12381_min_pk_verify
1892    bls12381_bls12381_min_pk_verify_cost_base: Option<u64>,
1893    bls12381_bls12381_min_pk_verify_msg_cost_per_byte: Option<u64>,
1894    bls12381_bls12381_min_pk_verify_msg_cost_per_block: Option<u64>,
1895
1896    // ecdsa_k1::ecrecover
1897    ecdsa_k1_ecrecover_keccak256_cost_base: Option<u64>,
1898    ecdsa_k1_ecrecover_keccak256_msg_cost_per_byte: Option<u64>,
1899    ecdsa_k1_ecrecover_keccak256_msg_cost_per_block: Option<u64>,
1900    ecdsa_k1_ecrecover_sha256_cost_base: Option<u64>,
1901    ecdsa_k1_ecrecover_sha256_msg_cost_per_byte: Option<u64>,
1902    ecdsa_k1_ecrecover_sha256_msg_cost_per_block: Option<u64>,
1903
1904    // ecdsa_k1::decompress_pubkey
1905    ecdsa_k1_decompress_pubkey_cost_base: Option<u64>,
1906
1907    // ecdsa_k1::secp256k1_verify
1908    ecdsa_k1_secp256k1_verify_keccak256_cost_base: Option<u64>,
1909    ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_byte: Option<u64>,
1910    ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_block: Option<u64>,
1911    ecdsa_k1_secp256k1_verify_sha256_cost_base: Option<u64>,
1912    ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_byte: Option<u64>,
1913    ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_block: Option<u64>,
1914
1915    // ecdsa_r1::ecrecover
1916    ecdsa_r1_ecrecover_keccak256_cost_base: Option<u64>,
1917    ecdsa_r1_ecrecover_keccak256_msg_cost_per_byte: Option<u64>,
1918    ecdsa_r1_ecrecover_keccak256_msg_cost_per_block: Option<u64>,
1919    ecdsa_r1_ecrecover_sha256_cost_base: Option<u64>,
1920    ecdsa_r1_ecrecover_sha256_msg_cost_per_byte: Option<u64>,
1921    ecdsa_r1_ecrecover_sha256_msg_cost_per_block: Option<u64>,
1922
1923    // ecdsa_r1::secp256k1_verify
1924    ecdsa_r1_secp256r1_verify_keccak256_cost_base: Option<u64>,
1925    ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_byte: Option<u64>,
1926    ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_block: Option<u64>,
1927    ecdsa_r1_secp256r1_verify_sha256_cost_base: Option<u64>,
1928    ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_byte: Option<u64>,
1929    ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_block: Option<u64>,
1930
1931    // ecvrf::verify
1932    ecvrf_ecvrf_verify_cost_base: Option<u64>,
1933    ecvrf_ecvrf_verify_alpha_string_cost_per_byte: Option<u64>,
1934    ecvrf_ecvrf_verify_alpha_string_cost_per_block: Option<u64>,
1935
1936    // ed25519
1937    ed25519_ed25519_verify_cost_base: Option<u64>,
1938    ed25519_ed25519_verify_msg_cost_per_byte: Option<u64>,
1939    ed25519_ed25519_verify_msg_cost_per_block: Option<u64>,
1940
1941    // groth16::prepare_verifying_key
1942    groth16_prepare_verifying_key_bls12381_cost_base: Option<u64>,
1943    groth16_prepare_verifying_key_bn254_cost_base: Option<u64>,
1944
1945    // groth16::verify_groth16_proof_internal
1946    groth16_verify_groth16_proof_internal_bls12381_cost_base: Option<u64>,
1947    groth16_verify_groth16_proof_internal_bls12381_cost_per_public_input: Option<u64>,
1948    groth16_verify_groth16_proof_internal_bn254_cost_base: Option<u64>,
1949    groth16_verify_groth16_proof_internal_bn254_cost_per_public_input: Option<u64>,
1950    groth16_verify_groth16_proof_internal_public_input_cost_per_byte: Option<u64>,
1951
1952    // hash::blake2b256
1953    hash_blake2b256_cost_base: Option<u64>,
1954    hash_blake2b256_data_cost_per_byte: Option<u64>,
1955    hash_blake2b256_data_cost_per_block: Option<u64>,
1956
1957    // hash::keccak256
1958    hash_keccak256_cost_base: Option<u64>,
1959    hash_keccak256_data_cost_per_byte: Option<u64>,
1960    hash_keccak256_data_cost_per_block: Option<u64>,
1961
1962    // poseidon::poseidon_bn254
1963    poseidon_bn254_cost_base: Option<u64>,
1964    poseidon_bn254_cost_per_block: Option<u64>,
1965
1966    // group_ops
1967    group_ops_bls12381_decode_scalar_cost: Option<u64>,
1968    group_ops_bls12381_decode_g1_cost: Option<u64>,
1969    group_ops_bls12381_decode_g2_cost: Option<u64>,
1970    group_ops_bls12381_decode_gt_cost: Option<u64>,
1971    group_ops_bls12381_scalar_add_cost: Option<u64>,
1972    group_ops_bls12381_g1_add_cost: Option<u64>,
1973    group_ops_bls12381_g2_add_cost: Option<u64>,
1974    group_ops_bls12381_gt_add_cost: Option<u64>,
1975    group_ops_bls12381_scalar_sub_cost: Option<u64>,
1976    group_ops_bls12381_g1_sub_cost: Option<u64>,
1977    group_ops_bls12381_g2_sub_cost: Option<u64>,
1978    group_ops_bls12381_gt_sub_cost: Option<u64>,
1979    group_ops_bls12381_scalar_mul_cost: Option<u64>,
1980    group_ops_bls12381_g1_mul_cost: Option<u64>,
1981    group_ops_bls12381_g2_mul_cost: Option<u64>,
1982    group_ops_bls12381_gt_mul_cost: Option<u64>,
1983    group_ops_bls12381_scalar_div_cost: Option<u64>,
1984    group_ops_bls12381_g1_div_cost: Option<u64>,
1985    group_ops_bls12381_g2_div_cost: Option<u64>,
1986    group_ops_bls12381_gt_div_cost: Option<u64>,
1987    group_ops_bls12381_g1_hash_to_base_cost: Option<u64>,
1988    group_ops_bls12381_g2_hash_to_base_cost: Option<u64>,
1989    group_ops_bls12381_g1_hash_to_cost_per_byte: Option<u64>,
1990    group_ops_bls12381_g2_hash_to_cost_per_byte: Option<u64>,
1991    group_ops_bls12381_g1_msm_base_cost: Option<u64>,
1992    group_ops_bls12381_g2_msm_base_cost: Option<u64>,
1993    group_ops_bls12381_g1_msm_base_cost_per_input: Option<u64>,
1994    group_ops_bls12381_g2_msm_base_cost_per_input: Option<u64>,
1995    group_ops_bls12381_msm_max_len: Option<u32>,
1996    group_ops_bls12381_pairing_cost: Option<u64>,
1997    group_ops_bls12381_g1_to_uncompressed_g1_cost: Option<u64>,
1998    group_ops_bls12381_uncompressed_g1_to_g1_cost: Option<u64>,
1999    group_ops_bls12381_uncompressed_g1_sum_base_cost: Option<u64>,
2000    group_ops_bls12381_uncompressed_g1_sum_cost_per_term: Option<u64>,
2001    group_ops_bls12381_uncompressed_g1_sum_max_terms: Option<u64>,
2002
2003    group_ops_ristretto_decode_scalar_cost: Option<u64>,
2004    group_ops_ristretto_decode_point_cost: Option<u64>,
2005    group_ops_ristretto_scalar_add_cost: Option<u64>,
2006    group_ops_ristretto_point_add_cost: Option<u64>,
2007    group_ops_ristretto_scalar_sub_cost: Option<u64>,
2008    group_ops_ristretto_point_sub_cost: Option<u64>,
2009    group_ops_ristretto_scalar_mul_cost: Option<u64>,
2010    group_ops_ristretto_point_mul_cost: Option<u64>,
2011    group_ops_ristretto_scalar_div_cost: Option<u64>,
2012    group_ops_ristretto_point_div_cost: Option<u64>,
2013
2014    verify_bulletproofs_ristretto255_base_cost: Option<u64>,
2015    verify_bulletproofs_ristretto255_cost_per_bit_and_commitment: Option<u64>,
2016    // Upper bound on batch size * range in bits for a bulletproofs range proof. Defaults to 512
2017    // when unset.
2018    max_bulletproofs_total_bits: Option<u64>,
2019
2020    // hmac::hmac_sha3_256
2021    hmac_hmac_sha3_256_cost_base: Option<u64>,
2022    hmac_hmac_sha3_256_input_cost_per_byte: Option<u64>,
2023    hmac_hmac_sha3_256_input_cost_per_block: Option<u64>,
2024
2025    // zklogin::check_zklogin_id
2026    check_zklogin_id_cost_base: Option<u64>,
2027    // zklogin::check_zklogin_issuer
2028    check_zklogin_issuer_cost_base: Option<u64>,
2029
2030    vdf_verify_vdf_cost: Option<u64>,
2031    vdf_hash_to_input_cost: Option<u64>,
2032
2033    // nitro_attestation::load_nitro_attestation
2034    nitro_attestation_parse_base_cost: Option<u64>,
2035    nitro_attestation_parse_cost_per_byte: Option<u64>,
2036    nitro_attestation_verify_base_cost: Option<u64>,
2037    nitro_attestation_verify_cost_per_cert: Option<u64>,
2038
2039    // Stdlib costs
2040    bcs_per_byte_serialized_cost: Option<u64>,
2041    bcs_legacy_min_output_size_cost: Option<u64>,
2042    bcs_failure_cost: Option<u64>,
2043
2044    hash_sha2_256_base_cost: Option<u64>,
2045    hash_sha2_256_per_byte_cost: Option<u64>,
2046    hash_sha2_256_legacy_min_input_len_cost: Option<u64>,
2047    hash_sha3_256_base_cost: Option<u64>,
2048    hash_sha3_256_per_byte_cost: Option<u64>,
2049    hash_sha3_256_legacy_min_input_len_cost: Option<u64>,
2050    type_name_get_base_cost: Option<u64>,
2051    type_name_get_per_byte_cost: Option<u64>,
2052    type_name_id_base_cost: Option<u64>,
2053
2054    string_check_utf8_base_cost: Option<u64>,
2055    string_check_utf8_per_byte_cost: Option<u64>,
2056    string_is_char_boundary_base_cost: Option<u64>,
2057    string_sub_string_base_cost: Option<u64>,
2058    string_sub_string_per_byte_cost: Option<u64>,
2059    string_index_of_base_cost: Option<u64>,
2060    string_index_of_per_byte_pattern_cost: Option<u64>,
2061    string_index_of_per_byte_searched_cost: Option<u64>,
2062
2063    vector_empty_base_cost: Option<u64>,
2064    vector_length_base_cost: Option<u64>,
2065    vector_push_back_base_cost: Option<u64>,
2066    vector_push_back_legacy_per_abstract_memory_unit_cost: Option<u64>,
2067    vector_borrow_base_cost: Option<u64>,
2068    vector_pop_back_base_cost: Option<u64>,
2069    vector_destroy_empty_base_cost: Option<u64>,
2070    vector_swap_base_cost: Option<u64>,
2071    debug_print_base_cost: Option<u64>,
2072    debug_print_stack_trace_base_cost: Option<u64>,
2073
2074    // ==== Ephemeral (consensus only) params deleted ====
2075    //
2076    // Const params for consensus scoring decision
2077    // The scaling factor property for the MED outlier detection
2078    // scoring_decision_mad_divisor: Option<f64>,
2079    // The cutoff value for the MED outlier detection
2080    // scoring_decision_cutoff_value: Option<f64>,
2081    /// === Execution Version ===
2082    // custom_setter: see `set_execution_version_for_testing`, which forbids downgrades.
2083    #[custom_setter]
2084    execution_version: Option<u64>,
2085
2086    // Dictates the threshold (percentage of stake) that is used to calculate the "bad" nodes to be
2087    // swapped when creating the consensus schedule. The values should be of the range [0 - 33]. Anything
2088    // above 33 (f) will not be allowed.
2089    consensus_bad_nodes_stake_threshold: Option<u64>,
2090
2091    max_jwk_votes_per_validator_per_epoch: Option<u64>,
2092    // The maximum age of a JWK in epochs before it is removed from the AuthenticatorState object.
2093    // Applied at the end of an epoch as a delta from the new epoch value, so setting this to 1
2094    // will cause the new epoch to start with JWKs from the previous epoch still valid.
2095    max_age_of_jwk_in_epochs: Option<u64>,
2096
2097    // === random beacon ===
2098    /// Maximum allowed precision loss when reducing voting weights for the random beacon
2099    /// protocol.
2100    random_beacon_reduction_allowed_delta: Option<u16>,
2101
2102    /// Minimum number of shares below which voting weights will not be reduced for the
2103    /// random beacon protocol.
2104    random_beacon_reduction_lower_bound: Option<u32>,
2105
2106    /// Consensus Round after which DKG should be aborted and randomness disabled for
2107    /// the epoch, if it hasn't already completed.
2108    random_beacon_dkg_timeout_round: Option<u32>,
2109
2110    /// Minimum interval between consecutive rounds of generated randomness.
2111    random_beacon_min_round_interval_ms: Option<u64>,
2112
2113    /// Version of the random beacon DKG protocol.
2114    /// 0 was deprecated (and currently not supported), 1 is the default version.
2115    random_beacon_dkg_version: Option<u64>,
2116
2117    /// The maximum serialised transaction size (in bytes) accepted by consensus. That should be bigger than the
2118    /// `max_tx_size_bytes` with some additional headroom.
2119    consensus_max_transaction_size_bytes: Option<u64>,
2120    /// The maximum size of transactions included in a consensus block.
2121    consensus_max_transactions_in_block_bytes: Option<u64>,
2122    /// The maximum number of transactions included in a consensus block.
2123    consensus_max_num_transactions_in_block: Option<u64>,
2124
2125    /// The maximum number of rounds where transaction voting is allowed.
2126    consensus_voting_rounds: Option<u32>,
2127
2128    /// DEPRECATED. Do not use.
2129    max_accumulated_txn_cost_per_object_in_narwhal_commit: Option<u64>,
2130
2131    /// The max number of consensus rounds a transaction can be deferred due to shared object congestion.
2132    /// Transactions will be cancelled after this many rounds.
2133    max_deferral_rounds_for_congestion_control: Option<u64>,
2134
2135    /// Time after the scheduled epoch end (`next_reconfiguration_timestamp_ms`) at which epoch
2136    /// close stops waiting for deferred transactions to drain: the epoch is closed even if
2137    /// deferred transactions remain unscheduled. They are abandoned and can be resubmitted in the
2138    /// next epoch. When unset, epoch close waits indefinitely.
2139    epoch_close_deadline_ms: Option<u64>,
2140
2141    /// DEPRECATED. Do not use.
2142    max_txn_cost_overage_per_object_in_commit: Option<u64>,
2143
2144    /// DEPRECATED. Do not use.
2145    allowed_txn_cost_overage_burst_per_object_in_commit: Option<u64>,
2146
2147    /// Minimum interval of commit timestamps between consecutive checkpoints.
2148    min_checkpoint_interval_ms: Option<u64>,
2149
2150    /// Version number to use for version_specific_data in `CheckpointSummary`.
2151    checkpoint_summary_version_specific_data: Option<u64>,
2152
2153    /// The max number of transactions that can be included in a single Soft Bundle.
2154    max_soft_bundle_size: Option<u64>,
2155
2156    /// Whether to try to form bridge committee
2157    // Note: this is not a feature flag because we want to distinguish between
2158    // `None` and `Some(false)`, as committee was already finalized on Testnet.
2159    bridge_should_try_to_finalize_committee: Option<bool>,
2160
2161    /// The max accumulated txn execution cost per object in a mysticeti. Transactions
2162    /// in a commit will be deferred once their touch shared objects hit this limit,
2163    /// unless the selected congestion control mode allows overage.
2164    /// This config plays the same role as `max_accumulated_txn_cost_per_object_in_narwhal_commit`
2165    /// but for mysticeti commits due to that mysticeti has higher commit rate.
2166    max_accumulated_txn_cost_per_object_in_mysticeti_commit: Option<u64>,
2167
2168    /// As above, but separate per-commit budget for transactions that use randomness.
2169    /// If not configured, uses the setting for `max_accumulated_txn_cost_per_object_in_mysticeti_commit`.
2170    max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit: Option<u64>,
2171
2172    /// Configures the garbage collection depth for consensus. When is unset or `0` then the garbage collection
2173    /// is disabled.
2174    consensus_gc_depth: Option<u32>,
2175
2176    /// DEPRECATED. Do not use.
2177    gas_budget_based_txn_cost_cap_factor: Option<u64>,
2178
2179    /// DEPRECATED. Do not use.
2180    gas_budget_based_txn_cost_absolute_cap_commit_count: Option<u64>,
2181
2182    /// SIP-45: K in the formula `amplification_factor = max(0, gas_price / reference_gas_price - K)`.
2183    /// This is the threshold for activating consensus amplification.
2184    sip_45_consensus_amplification_threshold: Option<u64>,
2185
2186    /// DEPRECATED: this was an ephemeral feature flag only used in per-epoch tables, which has now
2187    /// been deployed everywhere.
2188    use_object_per_epoch_marker_table_v2: Option<bool>,
2189
2190    /// The number of commits to consider when computing a deterministic commit rate.
2191    consensus_commit_rate_estimation_window_size: Option<u32>,
2192
2193    /// A list of effective AliasedAddress.
2194    /// For each pair, `aliased` is allowed to act as `original` for any of the transaction digests
2195    /// listed in `tx_digests`
2196    #[serde(skip_serializing_if = "Vec::is_empty")]
2197    aliased_addresses: Vec<AliasedAddress>,
2198
2199    /// The base charge for each command in a programmable transaction. This is a fixed cost to
2200    /// account for the overhead of processing each command.
2201    translation_per_command_base_charge: Option<u64>,
2202
2203    /// The base charge for each input in a programmable transaction regardless of if it is used or
2204    /// not, or a pure/object/funds withdrawal input.
2205    translation_per_input_base_charge: Option<u64>,
2206
2207    /// The base charge for each byte of pure input in a programmable transaction.
2208    translation_pure_input_per_byte_charge: Option<u64>,
2209
2210    /// The multiplier for the number of type nodes when charging for type loading.
2211    /// This is multiplied by the number of type nodes to get the total cost.
2212    /// This should be a small number to avoid excessive gas costs for loading types.
2213    translation_per_type_node_charge: Option<u64>,
2214
2215    /// The multiplier for the number of type references when charging for type checking and reference
2216    /// checking.
2217    translation_per_reference_node_charge: Option<u64>,
2218
2219    /// The multiplier for each linkage entry when charging for linkage tables that we have
2220    /// created.
2221    translation_per_linkage_entry_charge: Option<u64>,
2222
2223    /// The maximum number of updates per settlement transaction.
2224    max_updates_per_settlement_txn: Option<u32>,
2225
2226    /// Maximum computation units allowed for a gasless transaction.
2227    gasless_max_computation_units: Option<u64>,
2228
2229    /// Allowed token types for gasless transactions, with minimum transfer sizes per token.
2230    gasless_allowed_token_types: Option<Vec<(String, u64)>>,
2231
2232    /// Maximum number of unused Pure inputs allowed in a gasless transaction.
2233    /// Object and FundsWithdrawal inputs must always be used.
2234    /// When None, there is no limit (effectively unlimited).
2235    gasless_max_unused_inputs: Option<u64>,
2236
2237    /// Maximum size in bytes of each Pure input in a gasless transaction.
2238    /// When None, there is no limit (effectively unlimited).
2239    gasless_max_pure_input_bytes: Option<u64>,
2240
2241    /// Max tps for gasless transactions. Unlimited when unset, zero when set to zero.
2242    gasless_max_tps: Option<u64>,
2243
2244    #[serde(skip_serializing_if = "Option::is_none")]
2245    #[skip_accessor]
2246    include_special_package_amendments: Option<Arc<Amendments>>,
2247
2248    /// Maximum serialized size in bytes of a gasless transaction (SenderSignedData).
2249    /// Bounds the persistent storage impact of each admitted gasless transaction.
2250    gasless_max_tx_size_bytes: Option<u64>,
2251
2252    /// The multiplier for each live reference charging per-command. Only used when
2253    /// `allow_references_in_ptbs` is enabled.
2254    translation_per_live_reference_charge: Option<u64>,
2255
2256    /// The maximum number of live references while checking a command. Only used when
2257    /// `allow_references_in_ptbs` is enabled.
2258    max_ptb_live_references: Option<u64>,
2259
2260    /// The maximum number of references returned by a command. Only used when
2261    /// `allow_references_in_ptbs` is enabled.
2262    max_ptb_returned_references: Option<u64>,
2263
2264    /// The maximum number of references returned over the course of the transaction. Only used
2265    /// when `allow_references_in_ptbs` is enabled.
2266    max_ptb_total_returned_references: Option<u64>,
2267}
2268
2269/// An aliased address.
2270#[derive(Clone, Serialize, Deserialize, Debug)]
2271pub struct AliasedAddress {
2272    /// The original address.
2273    pub original: [u8; 32],
2274    /// An aliased address which is allowed to act as the original address.
2275    pub aliased: [u8; 32],
2276    /// A list of transaction digests for which the aliasing is allowed to be in effect.
2277    pub allowed_tx_digests: Vec<[u8; 32]>,
2278}
2279
2280// feature flags
2281impl ProtocolConfig {
2282    /// The chain this config was instantiated for (see the `chain` field).
2283    pub fn chain(&self) -> Chain {
2284        self.chain
2285    }
2286
2287    // Add checks for feature flag support here, e.g.:
2288    // pub fn check_new_protocol_feature_supported(&self) -> Result<(), Error> {
2289    //     if self.feature_flags.new_protocol_feature_supported {
2290    //         Ok(())
2291    //     } else {
2292    //         Err(Error(format!(
2293    //             "new_protocol_feature is not supported at {:?}",
2294    //             self.version
2295    //         )))
2296    //     }
2297    // }
2298
2299    pub fn check_package_upgrades_supported(&self) -> Result<(), Error> {
2300        if self.feature_flags.package_upgrades {
2301            Ok(())
2302        } else {
2303            Err(Error(format!(
2304                "package upgrades are not supported at {:?}",
2305                self.version
2306            )))
2307        }
2308    }
2309
2310    pub fn zklogin_supported_providers(&self) -> &BTreeSet<String> {
2311        &self.feature_flags.zklogin_supported_providers
2312    }
2313
2314    /// zkLogin circuit verify mode: 0 = v1 circuit only, 1 = v2 circuit with
2315    /// fallback to v1, 2 = v2 circuit only.
2316    pub fn zklogin_circuit_mode(&self) -> u64 {
2317        self.feature_flags.zklogin_circuit_mode
2318    }
2319
2320    pub fn consensus_transaction_ordering(&self) -> ConsensusTransactionOrdering {
2321        self.feature_flags.consensus_transaction_ordering
2322    }
2323
2324    pub fn enable_jwk_consensus_updates(&self) -> bool {
2325        let ret = self.feature_flags.enable_jwk_consensus_updates;
2326        if ret {
2327            // jwk updates required end-of-epoch transactions
2328            assert!(self.feature_flags.end_of_epoch_transaction_supported);
2329        }
2330        ret
2331    }
2332
2333    pub fn end_of_epoch_transaction_supported(&self) -> bool {
2334        let ret = self.feature_flags.end_of_epoch_transaction_supported;
2335        if !ret {
2336            // jwk updates required end-of-epoch transactions
2337            assert!(!self.feature_flags.enable_jwk_consensus_updates);
2338        }
2339        ret
2340    }
2341
2342    pub fn dkg_version(&self) -> u64 {
2343        // Version 0 was deprecated and removed, the default is 1 if not set.
2344        self.random_beacon_dkg_version.unwrap_or(1)
2345    }
2346
2347    pub fn bridge(&self) -> bool {
2348        let ret = self.feature_flags.bridge;
2349        if ret {
2350            // bridge required end-of-epoch transactions
2351            assert!(self.feature_flags.end_of_epoch_transaction_supported);
2352        }
2353        ret
2354    }
2355
2356    pub fn should_try_to_finalize_bridge_committee(&self) -> bool {
2357        if !self.bridge() {
2358            return false;
2359        }
2360        // In the older protocol version, always try to finalize the committee.
2361        self.bridge_should_try_to_finalize_committee.unwrap_or(true)
2362    }
2363
2364    pub fn zklogin_max_epoch_upper_bound_delta(&self) -> Option<u64> {
2365        self.feature_flags.zklogin_max_epoch_upper_bound_delta
2366    }
2367
2368    pub fn enable_allowances(&self) -> bool {
2369        self.feature_flags.enable_allowances && self.enable_accumulators()
2370    }
2371
2372    pub fn enable_coin_reservation_obj_refs(&self) -> bool {
2373        self.new_vm_enabled() && self.feature_flags.enable_coin_reservation_obj_refs
2374    }
2375
2376    pub fn enable_authenticated_event_streams(&self) -> bool {
2377        self.feature_flags.enable_authenticated_event_streams && self.enable_accumulators()
2378    }
2379
2380    pub fn per_object_congestion_control_mode(&self) -> PerObjectCongestionControlMode {
2381        self.feature_flags.per_object_congestion_control_mode
2382    }
2383
2384    pub fn consensus_choice(&self) -> ConsensusChoice {
2385        self.feature_flags.consensus_choice
2386    }
2387
2388    pub fn consensus_network(&self) -> ConsensusNetwork {
2389        self.feature_flags.consensus_network
2390    }
2391
2392    pub fn mysticeti_num_leaders_per_round(&self) -> Option<usize> {
2393        self.feature_flags.mysticeti_num_leaders_per_round
2394    }
2395
2396    pub fn max_transaction_size_bytes(&self) -> u64 {
2397        // Provide a default value if protocol config version is too low.
2398        self.consensus_max_transaction_size_bytes
2399            .unwrap_or(256 * 1024)
2400    }
2401
2402    pub fn max_transactions_in_block_bytes(&self) -> u64 {
2403        if cfg!(msim) {
2404            256 * 1024
2405        } else {
2406            self.consensus_max_transactions_in_block_bytes
2407                .unwrap_or(512 * 1024)
2408        }
2409    }
2410
2411    pub fn max_num_transactions_in_block(&self) -> u64 {
2412        if cfg!(msim) {
2413            8
2414        } else {
2415            self.consensus_max_num_transactions_in_block.unwrap_or(512)
2416        }
2417    }
2418
2419    pub fn gc_depth(&self) -> u32 {
2420        self.consensus_gc_depth.unwrap_or(0)
2421    }
2422
2423    pub fn consensus_linearize_subdag_v2(&self) -> bool {
2424        let res = self.feature_flags.consensus_linearize_subdag_v2;
2425        assert!(
2426            !res || self.gc_depth() > 0,
2427            "The consensus linearize sub dag V2 requires GC to be enabled"
2428        );
2429        res
2430    }
2431
2432    pub fn consensus_median_based_commit_timestamp(&self) -> bool {
2433        let res = self.feature_flags.consensus_median_based_commit_timestamp;
2434        assert!(
2435            !res || self.gc_depth() > 0,
2436            "The consensus median based commit timestamp requires GC to be enabled"
2437        );
2438        res
2439    }
2440
2441    pub fn get_consensus_commit_rate_estimation_window_size(&self) -> u32 {
2442        self.consensus_commit_rate_estimation_window_size
2443            .unwrap_or(0)
2444    }
2445
2446    pub fn consensus_num_requested_prior_commits_at_startup(&self) -> u32 {
2447        // Currently there is only one parameter driving this value. If there are multiple
2448        // things computed from prior consensus commits, this function must return the max
2449        // of all of them.
2450        let window_size = self.get_consensus_commit_rate_estimation_window_size();
2451        // Ensure we are not using past commits without recording a state digest in the prologue.
2452        assert!(window_size == 0 || self.record_additional_state_digest_in_prologue());
2453        window_size
2454    }
2455
2456    pub fn address_aliases(&self) -> bool {
2457        let address_aliases = self.feature_flags.address_aliases;
2458        assert!(
2459            !address_aliases || self.mysticeti_fastpath(),
2460            "Address aliases requires Mysticeti fastpath to be enabled"
2461        );
2462        if address_aliases {
2463            assert!(
2464                self.feature_flags.disable_preconsensus_locking,
2465                "Address aliases requires CertifiedTransaction to be disabled"
2466            );
2467        }
2468        address_aliases
2469    }
2470
2471    pub fn new_vm_enabled(&self) -> bool {
2472        self.execution_version.is_some_and(|v| v >= 4)
2473    }
2474
2475    pub fn gasless_allowed_token_types(&self) -> &[(String, u64)] {
2476        debug_assert!(self.gasless_allowed_token_types.is_some());
2477        self.gasless_allowed_token_types.as_deref().unwrap_or(&[])
2478    }
2479
2480    pub fn get_gasless_max_unused_inputs(&self) -> u64 {
2481        self.gasless_max_unused_inputs.unwrap_or(u64::MAX)
2482    }
2483
2484    pub fn get_gasless_max_pure_input_bytes(&self) -> u64 {
2485        self.gasless_max_pure_input_bytes.unwrap_or(u64::MAX)
2486    }
2487
2488    pub fn get_gasless_max_tx_size_bytes(&self) -> u64 {
2489        self.gasless_max_tx_size_bytes.unwrap_or(u64::MAX)
2490    }
2491
2492    pub fn include_special_package_amendments_as_option(&self) -> &Option<Arc<Amendments>> {
2493        &self.include_special_package_amendments
2494    }
2495}
2496
2497static POISON_VERSION_METHODS: AtomicBool = AtomicBool::new(false);
2498
2499// Instantiations for each protocol version.
2500impl ProtocolConfig {
2501    /// Get the value ProtocolConfig that are in effect during the given protocol version.
2502    pub fn get_for_version(version: ProtocolVersion, chain: Chain) -> Self {
2503        // ProtocolVersion can be deserialized so we need to check it here as well.
2504        assert!(
2505            version >= ProtocolVersion::MIN,
2506            "Network protocol version is {:?}, but the minimum supported version by the binary is {:?}. Please upgrade the binary.",
2507            version,
2508            ProtocolVersion::MIN.0,
2509        );
2510        assert!(
2511            version <= ProtocolVersion::MAX_ALLOWED,
2512            "Network protocol version is {:?}, but the maximum supported version by the binary is {:?}. Please upgrade the binary.",
2513            version,
2514            ProtocolVersion::MAX_ALLOWED.0,
2515        );
2516
2517        let mut ret = Self::get_for_version_impl(version, chain);
2518        ret.version = version;
2519        ret.chain = chain;
2520
2521        ret = Self::apply_config_override(version, ret);
2522
2523        if std::env::var("SUI_PROTOCOL_CONFIG_OVERRIDE_ENABLE").is_ok() {
2524            warn!(
2525                "overriding ProtocolConfig settings with custom settings; this may break non-local networks"
2526            );
2527            let overrides: ProtocolConfigOptional =
2528                serde_env::from_env_with_prefix("SUI_PROTOCOL_CONFIG_OVERRIDE")
2529                    .expect("failed to parse ProtocolConfig override env variables");
2530            overrides.apply_to(&mut ret);
2531        }
2532
2533        ret
2534    }
2535
2536    /// Get the value ProtocolConfig that are in effect during the given protocol version.
2537    /// Or none if the version is not supported.
2538    pub fn get_for_version_if_supported(version: ProtocolVersion, chain: Chain) -> Option<Self> {
2539        if version.0 >= ProtocolVersion::MIN.0 && version.0 <= ProtocolVersion::MAX_ALLOWED.0 {
2540            let mut ret = Self::get_for_version_impl(version, chain);
2541            ret.version = version;
2542            ret.chain = chain;
2543            ret = Self::apply_config_override(version, ret);
2544            Some(ret)
2545        } else {
2546            None
2547        }
2548    }
2549
2550    pub fn poison_get_for_min_version() {
2551        POISON_VERSION_METHODS.store(true, Ordering::Relaxed);
2552    }
2553
2554    fn load_poison_get_for_min_version() -> bool {
2555        POISON_VERSION_METHODS.load(Ordering::Relaxed)
2556    }
2557
2558    /// Convenience to get the constants at the current minimum supported version.
2559    /// Mainly used by client code that may not yet be protocol-version aware.
2560    pub fn get_for_min_version() -> Self {
2561        if Self::load_poison_get_for_min_version() {
2562            panic!("get_for_min_version called on validator");
2563        }
2564        ProtocolConfig::get_for_version(ProtocolVersion::MIN, Chain::Unknown)
2565    }
2566
2567    /// CAREFUL! - You probably want to use `get_for_version` instead.
2568    ///
2569    /// Convenience to get the constants at the current maximum supported version.
2570    /// Mainly used by genesis. Note well that this function uses the max version
2571    /// supported locally by the node, which is not necessarily the current version
2572    /// of the network. ALSO, this function disregards chain specific config (by
2573    /// using Chain::Unknown), thereby potentially returning a protocol config that
2574    /// is incorrect for some feature flags. Definitely safe for testing and for
2575    /// protocol version 11 and prior.
2576    #[allow(non_snake_case)]
2577    pub fn get_for_max_version_UNSAFE() -> Self {
2578        if Self::load_poison_get_for_min_version() {
2579            panic!("get_for_max_version_UNSAFE called on validator");
2580        }
2581        ProtocolConfig::get_for_version(ProtocolVersion::MAX, Chain::Unknown)
2582    }
2583
2584    fn get_for_version_impl(version: ProtocolVersion, chain: Chain) -> Self {
2585        #[cfg(msim)]
2586        {
2587            // populate the fake simulator version # with a different base tx cost.
2588            if version == ProtocolVersion::MAX_ALLOWED {
2589                let mut config = Self::get_for_version_impl(version - 1, Chain::Unknown);
2590                config.base_tx_cost_fixed = Some(config.base_tx_cost_fixed() + 1000);
2591                return config;
2592            }
2593        }
2594
2595        // IMPORTANT: Never modify the value of any constant for a pre-existing protocol version.
2596        // To change the values here you must create a new protocol version with the new values!
2597        let mut cfg = Self {
2598            // will be overwritten before being returned
2599            version,
2600            chain,
2601
2602            // All flags are disabled in V1
2603            feature_flags: Default::default(),
2604
2605            max_tx_size_bytes: Some(128 * 1024),
2606            // We need this number to be at least 100x less than `max_serialized_tx_effects_size_bytes`otherwise effects can be huge
2607            max_input_objects: Some(2048),
2608            max_serialized_tx_effects_size_bytes: Some(512 * 1024),
2609            max_serialized_tx_effects_size_bytes_system_tx: Some(512 * 1024 * 16),
2610            max_gas_payment_objects: Some(256),
2611            max_modules_in_publish: Some(128),
2612            max_package_dependencies: None,
2613            max_arguments: Some(512),
2614            max_type_arguments: Some(16),
2615            max_type_argument_depth: Some(16),
2616            max_pure_argument_size: Some(16 * 1024),
2617            max_programmable_tx_commands: Some(1024),
2618            move_binary_format_version: Some(6),
2619            min_move_binary_format_version: None,
2620            binary_module_handles: None,
2621            binary_struct_handles: None,
2622            binary_function_handles: None,
2623            binary_function_instantiations: None,
2624            binary_signatures: None,
2625            binary_constant_pool: None,
2626            binary_identifiers: None,
2627            binary_address_identifiers: None,
2628            binary_struct_defs: None,
2629            binary_struct_def_instantiations: None,
2630            binary_function_defs: None,
2631            binary_field_handles: None,
2632            binary_field_instantiations: None,
2633            binary_friend_decls: None,
2634            binary_enum_defs: None,
2635            binary_enum_def_instantiations: None,
2636            binary_variant_handles: None,
2637            binary_variant_instantiation_handles: None,
2638            max_move_object_size: Some(250 * 1024),
2639            max_move_package_size: Some(100 * 1024),
2640            max_publish_or_upgrade_per_ptb: None,
2641            max_tx_gas: Some(10_000_000_000),
2642            max_gas_price: Some(100_000),
2643            max_gas_price_rgp_factor_for_aborted_transactions: None,
2644            max_gas_computation_bucket: Some(5_000_000),
2645            max_loop_depth: Some(5),
2646            max_generic_instantiation_length: Some(32),
2647            max_function_parameters: Some(128),
2648            max_basic_blocks: Some(1024),
2649            max_value_stack_size: Some(1024),
2650            max_type_nodes: Some(256),
2651            max_generic_instantiation_type_nodes_per_function: None,
2652            max_generic_instantiation_type_nodes_per_module: None,
2653            max_accumulator_type_nodes: None,
2654            max_push_size: Some(10000),
2655            max_struct_definitions: Some(200),
2656            max_function_definitions: Some(1000),
2657            max_fields_in_struct: Some(32),
2658            max_dependency_depth: Some(100),
2659            max_num_event_emit: Some(256),
2660            max_num_new_move_object_ids: Some(2048),
2661            max_num_new_move_object_ids_system_tx: Some(2048 * 16),
2662            max_num_deleted_move_object_ids: Some(2048),
2663            max_num_deleted_move_object_ids_system_tx: Some(2048 * 16),
2664            max_num_transferred_move_object_ids: Some(2048),
2665            max_num_transferred_move_object_ids_system_tx: Some(2048 * 16),
2666            max_event_emit_size: Some(250 * 1024),
2667            max_move_vector_len: Some(256 * 1024),
2668            max_type_to_layout_nodes: None,
2669            max_ptb_value_size: None,
2670
2671            max_back_edges_per_function: Some(10_000),
2672            max_back_edges_per_module: Some(10_000),
2673            max_verifier_meter_ticks_per_function: Some(6_000_000),
2674            max_meter_ticks_per_module: Some(6_000_000),
2675            max_meter_ticks_per_package: None,
2676
2677            object_runtime_max_num_cached_objects: Some(1000),
2678            object_runtime_max_num_cached_objects_system_tx: Some(1000 * 16),
2679            object_runtime_max_num_store_entries: Some(1000),
2680            object_runtime_max_num_store_entries_system_tx: Some(1000 * 16),
2681            base_tx_cost_fixed: Some(110_000),
2682            package_publish_cost_fixed: Some(1_000),
2683            base_tx_cost_per_byte: Some(0),
2684            package_publish_cost_per_byte: Some(80),
2685            obj_access_cost_read_per_byte: Some(15),
2686            obj_access_cost_mutate_per_byte: Some(40),
2687            obj_access_cost_delete_per_byte: Some(40),
2688            obj_access_cost_verify_per_byte: Some(200),
2689            obj_data_cost_refundable: Some(100),
2690            obj_metadata_cost_non_refundable: Some(50),
2691            gas_model_version: Some(1),
2692            storage_rebate_rate: Some(9900),
2693            storage_fund_reinvest_rate: Some(500),
2694            reward_slashing_rate: Some(5000),
2695            storage_gas_price: Some(1),
2696            accumulator_object_storage_cost: None,
2697            max_transactions_per_checkpoint: Some(10_000),
2698            max_checkpoint_size_bytes: Some(30 * 1024 * 1024),
2699
2700            // For now, perform upgrades with a bare quorum of validators.
2701            // MUSTFIX: This number should be increased to at least 2000 (20%) for mainnet.
2702            buffer_stake_for_protocol_upgrade_bps: Some(0),
2703
2704            // === Native Function Costs ===
2705            // `address` module
2706            // Cost params for the Move native function `address::from_bytes(bytes: vector<u8>)`
2707            address_from_bytes_cost_base: Some(52),
2708            // Cost params for the Move native function `address::to_u256(address): u256`
2709            address_to_u256_cost_base: Some(52),
2710            // Cost params for the Move native function `address::from_u256(u256): address`
2711            address_from_u256_cost_base: Some(52),
2712
2713            // `config` module
2714            // Cost params for the Move native function `read_setting_impl``
2715            config_read_setting_impl_cost_base: None,
2716            config_read_setting_impl_cost_per_byte: None,
2717
2718            package_original_package_id_impl_cost_base: None,
2719            package_original_package_id_impl_cost_per_byte: None,
2720
2721            // `dynamic_field` module
2722            // Cost params for the Move native function `hash_type_and_key<K: copy + drop + store>(parent: address, k: K): address`
2723            dynamic_field_hash_type_and_key_cost_base: Some(100),
2724            dynamic_field_hash_type_and_key_type_cost_per_byte: Some(2),
2725            dynamic_field_hash_type_and_key_value_cost_per_byte: Some(2),
2726            dynamic_field_hash_type_and_key_type_tag_cost_per_byte: Some(2),
2727            // Cost params for the Move native function `add_child_object<Child: key>(parent: address, child: Child)`
2728            dynamic_field_add_child_object_cost_base: Some(100),
2729            dynamic_field_add_child_object_type_cost_per_byte: Some(10),
2730            dynamic_field_add_child_object_value_cost_per_byte: Some(10),
2731            dynamic_field_add_child_object_struct_tag_cost_per_byte: Some(10),
2732            // Cost params for the Move native function `borrow_child_object_mut<Child: key>(parent: &mut UID, id: address): &mut Child`
2733            dynamic_field_borrow_child_object_cost_base: Some(100),
2734            dynamic_field_borrow_child_object_child_ref_cost_per_byte: Some(10),
2735            dynamic_field_borrow_child_object_type_cost_per_byte: Some(10),
2736            // Cost params for the Move native function `remove_child_object<Child: key>(parent: address, id: address): Child`
2737            dynamic_field_remove_child_object_cost_base: Some(100),
2738            dynamic_field_remove_child_object_child_cost_per_byte: Some(2),
2739            dynamic_field_remove_child_object_type_cost_per_byte: Some(2),
2740            // Cost params for the Move native function `has_child_object(parent: address, id: address): bool`
2741            dynamic_field_has_child_object_cost_base: Some(100),
2742            // Cost params for the Move native function `has_child_object_with_ty<Child: key>(parent: address, id: address): bool`
2743            dynamic_field_has_child_object_with_ty_cost_base: Some(100),
2744            dynamic_field_has_child_object_with_ty_type_cost_per_byte: Some(2),
2745            dynamic_field_has_child_object_with_ty_type_tag_cost_per_byte: Some(2),
2746
2747            // `scratch` module: introduced in protocol version 130
2748            scratch_add_cost_base: None,
2749            scratch_read_cost_base: None,
2750            scratch_read_value_cost: None,
2751            scratch_remove_cost_base: None,
2752            scratch_exists_cost_base: None,
2753            scratch_exists_with_type_cost_base: None,
2754            scratch_exists_with_type_type_cost: None,
2755            max_scratch_pad_size: None,
2756
2757            // `event` module
2758            // Cost params for the Move native function `event::emit<T: copy + drop>(event: T)`
2759            event_emit_cost_base: Some(52),
2760            event_emit_value_size_derivation_cost_per_byte: Some(2),
2761            event_emit_tag_size_derivation_cost_per_byte: Some(5),
2762            event_emit_output_cost_per_byte: Some(10),
2763            event_emit_auth_stream_cost: None,
2764
2765            // `funds_accumulator` module: introduced in protocol version 137.
2766            reserve_object_funds_for_withdrawal_cost_base: None,
2767            reserve_object_funds_for_withdrawal_cold_read_cost: None,
2768
2769            //  `object` module
2770            // Cost params for the Move native function `borrow_uid<T: key>(obj: &T): &UID`
2771            object_borrow_uid_cost_base: Some(52),
2772            // Cost params for the Move native function `delete_impl(id: address)`
2773            object_delete_impl_cost_base: Some(52),
2774            // Cost params for the Move native function `record_new_uid(id: address)`
2775            object_record_new_uid_cost_base: Some(52),
2776            // Cost params for the Move native function
2777            // `record_new_uid_from_hash(parent: address, bytes: address)`. Introduced in v131.
2778            object_record_new_uid_from_hash_cost_base: None,
2779
2780            // `transfer` module
2781            // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
2782            transfer_transfer_internal_cost_base: Some(52),
2783            // Cost params for the Move native function `party_transfer_impl<T: key>(obj: T, party_members: vector<address>)`
2784            transfer_party_transfer_internal_cost_base: None,
2785            // Cost params for the Move native function `freeze_object<T: key>(obj: T)`
2786            transfer_freeze_object_cost_base: Some(52),
2787            // Cost params for the Move native function `share_object<T: key>(obj: T)`
2788            transfer_share_object_cost_base: Some(52),
2789            transfer_receive_object_cost_base: None,
2790            transfer_receive_object_type_cost_per_byte: None,
2791            transfer_receive_object_cost_per_byte: None,
2792
2793            // `tx_context` module
2794            // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
2795            tx_context_derive_id_cost_base: Some(52),
2796            tx_context_fresh_id_cost_base: None,
2797            tx_context_sender_cost_base: None,
2798            tx_context_epoch_cost_base: None,
2799            tx_context_epoch_timestamp_ms_cost_base: None,
2800            tx_context_sponsor_cost_base: None,
2801            tx_context_rgp_cost_base: None,
2802            tx_context_gas_price_cost_base: None,
2803            tx_context_gas_budget_cost_base: None,
2804            tx_context_ids_created_cost_base: None,
2805            tx_context_replace_cost_base: None,
2806
2807            // `types` module
2808            // Cost params for the Move native function `is_one_time_witness<T: drop>(_: &T): bool`
2809            types_is_one_time_witness_cost_base: Some(52),
2810            types_is_one_time_witness_type_tag_cost_per_byte: Some(2),
2811            types_is_one_time_witness_type_cost_per_byte: Some(2),
2812
2813            // `validator` module
2814            // Cost params for the Move native function `validate_metadata_bcs(metadata: vector<u8>)`
2815            validator_validate_metadata_cost_base: Some(52),
2816            validator_validate_metadata_data_cost_per_byte: Some(2),
2817
2818            // Crypto
2819            crypto_invalid_arguments_cost: Some(100),
2820            // bls12381::bls12381_min_pk_verify
2821            bls12381_bls12381_min_sig_verify_cost_base: Some(52),
2822            bls12381_bls12381_min_sig_verify_msg_cost_per_byte: Some(2),
2823            bls12381_bls12381_min_sig_verify_msg_cost_per_block: Some(2),
2824
2825            // bls12381::bls12381_min_pk_verify
2826            bls12381_bls12381_min_pk_verify_cost_base: Some(52),
2827            bls12381_bls12381_min_pk_verify_msg_cost_per_byte: Some(2),
2828            bls12381_bls12381_min_pk_verify_msg_cost_per_block: Some(2),
2829
2830            // ecdsa_k1::ecrecover
2831            ecdsa_k1_ecrecover_keccak256_cost_base: Some(52),
2832            ecdsa_k1_ecrecover_keccak256_msg_cost_per_byte: Some(2),
2833            ecdsa_k1_ecrecover_keccak256_msg_cost_per_block: Some(2),
2834            ecdsa_k1_ecrecover_sha256_cost_base: Some(52),
2835            ecdsa_k1_ecrecover_sha256_msg_cost_per_byte: Some(2),
2836            ecdsa_k1_ecrecover_sha256_msg_cost_per_block: Some(2),
2837
2838            // ecdsa_k1::decompress_pubkey
2839            ecdsa_k1_decompress_pubkey_cost_base: Some(52),
2840
2841            // ecdsa_k1::secp256k1_verify
2842            ecdsa_k1_secp256k1_verify_keccak256_cost_base: Some(52),
2843            ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_byte: Some(2),
2844            ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_block: Some(2),
2845            ecdsa_k1_secp256k1_verify_sha256_cost_base: Some(52),
2846            ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_byte: Some(2),
2847            ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_block: Some(2),
2848
2849            // ecdsa_r1::ecrecover
2850            ecdsa_r1_ecrecover_keccak256_cost_base: Some(52),
2851            ecdsa_r1_ecrecover_keccak256_msg_cost_per_byte: Some(2),
2852            ecdsa_r1_ecrecover_keccak256_msg_cost_per_block: Some(2),
2853            ecdsa_r1_ecrecover_sha256_cost_base: Some(52),
2854            ecdsa_r1_ecrecover_sha256_msg_cost_per_byte: Some(2),
2855            ecdsa_r1_ecrecover_sha256_msg_cost_per_block: Some(2),
2856
2857            // ecdsa_r1::secp256k1_verify
2858            ecdsa_r1_secp256r1_verify_keccak256_cost_base: Some(52),
2859            ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_byte: Some(2),
2860            ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_block: Some(2),
2861            ecdsa_r1_secp256r1_verify_sha256_cost_base: Some(52),
2862            ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_byte: Some(2),
2863            ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_block: Some(2),
2864
2865            // ecvrf::verify
2866            ecvrf_ecvrf_verify_cost_base: Some(52),
2867            ecvrf_ecvrf_verify_alpha_string_cost_per_byte: Some(2),
2868            ecvrf_ecvrf_verify_alpha_string_cost_per_block: Some(2),
2869
2870            // ed25519
2871            ed25519_ed25519_verify_cost_base: Some(52),
2872            ed25519_ed25519_verify_msg_cost_per_byte: Some(2),
2873            ed25519_ed25519_verify_msg_cost_per_block: Some(2),
2874
2875            // groth16::prepare_verifying_key
2876            groth16_prepare_verifying_key_bls12381_cost_base: Some(52),
2877            groth16_prepare_verifying_key_bn254_cost_base: Some(52),
2878
2879            // groth16::verify_groth16_proof_internal
2880            groth16_verify_groth16_proof_internal_bls12381_cost_base: Some(52),
2881            groth16_verify_groth16_proof_internal_bls12381_cost_per_public_input: Some(2),
2882            groth16_verify_groth16_proof_internal_bn254_cost_base: Some(52),
2883            groth16_verify_groth16_proof_internal_bn254_cost_per_public_input: Some(2),
2884            groth16_verify_groth16_proof_internal_public_input_cost_per_byte: Some(2),
2885
2886            // hash::blake2b256
2887            hash_blake2b256_cost_base: Some(52),
2888            hash_blake2b256_data_cost_per_byte: Some(2),
2889            hash_blake2b256_data_cost_per_block: Some(2),
2890
2891            // hash::keccak256
2892            hash_keccak256_cost_base: Some(52),
2893            hash_keccak256_data_cost_per_byte: Some(2),
2894            hash_keccak256_data_cost_per_block: Some(2),
2895
2896            poseidon_bn254_cost_base: None,
2897            poseidon_bn254_cost_per_block: None,
2898
2899            // hmac::hmac_sha3_256
2900            hmac_hmac_sha3_256_cost_base: Some(52),
2901            hmac_hmac_sha3_256_input_cost_per_byte: Some(2),
2902            hmac_hmac_sha3_256_input_cost_per_block: Some(2),
2903
2904            // group ops
2905            group_ops_bls12381_decode_scalar_cost: None,
2906            group_ops_bls12381_decode_g1_cost: None,
2907            group_ops_bls12381_decode_g2_cost: None,
2908            group_ops_bls12381_decode_gt_cost: None,
2909            group_ops_bls12381_scalar_add_cost: None,
2910            group_ops_bls12381_g1_add_cost: None,
2911            group_ops_bls12381_g2_add_cost: None,
2912            group_ops_bls12381_gt_add_cost: None,
2913            group_ops_bls12381_scalar_sub_cost: None,
2914            group_ops_bls12381_g1_sub_cost: None,
2915            group_ops_bls12381_g2_sub_cost: None,
2916            group_ops_bls12381_gt_sub_cost: None,
2917            group_ops_bls12381_scalar_mul_cost: None,
2918            group_ops_bls12381_g1_mul_cost: None,
2919            group_ops_bls12381_g2_mul_cost: None,
2920            group_ops_bls12381_gt_mul_cost: None,
2921            group_ops_bls12381_scalar_div_cost: None,
2922            group_ops_bls12381_g1_div_cost: None,
2923            group_ops_bls12381_g2_div_cost: None,
2924            group_ops_bls12381_gt_div_cost: None,
2925            group_ops_bls12381_g1_hash_to_base_cost: None,
2926            group_ops_bls12381_g2_hash_to_base_cost: None,
2927            group_ops_bls12381_g1_hash_to_cost_per_byte: None,
2928            group_ops_bls12381_g2_hash_to_cost_per_byte: None,
2929            group_ops_bls12381_g1_msm_base_cost: None,
2930            group_ops_bls12381_g2_msm_base_cost: None,
2931            group_ops_bls12381_g1_msm_base_cost_per_input: None,
2932            group_ops_bls12381_g2_msm_base_cost_per_input: None,
2933            group_ops_bls12381_msm_max_len: None,
2934            group_ops_bls12381_pairing_cost: None,
2935            group_ops_bls12381_g1_to_uncompressed_g1_cost: None,
2936            group_ops_bls12381_uncompressed_g1_to_g1_cost: None,
2937            group_ops_bls12381_uncompressed_g1_sum_base_cost: None,
2938            group_ops_bls12381_uncompressed_g1_sum_cost_per_term: None,
2939            group_ops_bls12381_uncompressed_g1_sum_max_terms: None,
2940
2941            group_ops_ristretto_decode_scalar_cost: None,
2942            group_ops_ristretto_decode_point_cost: None,
2943            group_ops_ristretto_scalar_add_cost: None,
2944            group_ops_ristretto_point_add_cost: None,
2945            group_ops_ristretto_scalar_sub_cost: None,
2946            group_ops_ristretto_point_sub_cost: None,
2947            group_ops_ristretto_scalar_mul_cost: None,
2948            group_ops_ristretto_point_mul_cost: None,
2949            group_ops_ristretto_scalar_div_cost: None,
2950            group_ops_ristretto_point_div_cost: None,
2951
2952            verify_bulletproofs_ristretto255_base_cost: None,
2953            verify_bulletproofs_ristretto255_cost_per_bit_and_commitment: None,
2954            max_bulletproofs_total_bits: None,
2955
2956            // zklogin::check_zklogin_id
2957            check_zklogin_id_cost_base: None,
2958            // zklogin::check_zklogin_issuer
2959            check_zklogin_issuer_cost_base: None,
2960
2961            vdf_verify_vdf_cost: None,
2962            vdf_hash_to_input_cost: None,
2963
2964            // nitro_attestation::verify_nitro_attestation
2965            nitro_attestation_parse_base_cost: None,
2966            nitro_attestation_parse_cost_per_byte: None,
2967            nitro_attestation_verify_base_cost: None,
2968            nitro_attestation_verify_cost_per_cert: None,
2969
2970            bcs_per_byte_serialized_cost: None,
2971            bcs_legacy_min_output_size_cost: None,
2972            bcs_failure_cost: None,
2973            hash_sha2_256_base_cost: None,
2974            hash_sha2_256_per_byte_cost: None,
2975            hash_sha2_256_legacy_min_input_len_cost: None,
2976            hash_sha3_256_base_cost: None,
2977            hash_sha3_256_per_byte_cost: None,
2978            hash_sha3_256_legacy_min_input_len_cost: None,
2979            type_name_get_base_cost: None,
2980            type_name_get_per_byte_cost: None,
2981            type_name_id_base_cost: None,
2982            string_check_utf8_base_cost: None,
2983            string_check_utf8_per_byte_cost: None,
2984            string_is_char_boundary_base_cost: None,
2985            string_sub_string_base_cost: None,
2986            string_sub_string_per_byte_cost: None,
2987            string_index_of_base_cost: None,
2988            string_index_of_per_byte_pattern_cost: None,
2989            string_index_of_per_byte_searched_cost: None,
2990            vector_empty_base_cost: None,
2991            vector_length_base_cost: None,
2992            vector_push_back_base_cost: None,
2993            vector_push_back_legacy_per_abstract_memory_unit_cost: None,
2994            vector_borrow_base_cost: None,
2995            vector_pop_back_base_cost: None,
2996            vector_destroy_empty_base_cost: None,
2997            vector_swap_base_cost: None,
2998            debug_print_base_cost: None,
2999            debug_print_stack_trace_base_cost: None,
3000
3001            max_size_written_objects: None,
3002            max_size_written_objects_system_tx: None,
3003
3004            // ==== Ephemeral (consensus only) params deleted ====
3005            // Const params for consensus scoring decision
3006            // scoring_decision_mad_divisor: None,
3007            // scoring_decision_cutoff_value: None,
3008
3009            // Limits the length of a Move identifier
3010            max_move_identifier_len: None,
3011            max_move_value_depth: None,
3012            package_arena_size_in_bytes: None,
3013            max_move_enum_variants: None,
3014
3015            gas_rounding_step: None,
3016
3017            execution_version: None,
3018
3019            max_event_emit_size_total: None,
3020
3021            consensus_bad_nodes_stake_threshold: None,
3022
3023            max_jwk_votes_per_validator_per_epoch: None,
3024
3025            max_age_of_jwk_in_epochs: None,
3026
3027            random_beacon_reduction_allowed_delta: None,
3028
3029            random_beacon_reduction_lower_bound: None,
3030
3031            random_beacon_dkg_timeout_round: None,
3032
3033            random_beacon_min_round_interval_ms: None,
3034
3035            random_beacon_dkg_version: None,
3036
3037            consensus_max_transaction_size_bytes: None,
3038
3039            consensus_max_transactions_in_block_bytes: None,
3040
3041            consensus_max_num_transactions_in_block: None,
3042
3043            consensus_voting_rounds: None,
3044
3045            max_accumulated_txn_cost_per_object_in_narwhal_commit: None,
3046
3047            max_deferral_rounds_for_congestion_control: None,
3048
3049            epoch_close_deadline_ms: None,
3050
3051            max_txn_cost_overage_per_object_in_commit: None,
3052
3053            allowed_txn_cost_overage_burst_per_object_in_commit: None,
3054
3055            min_checkpoint_interval_ms: None,
3056
3057            checkpoint_summary_version_specific_data: None,
3058
3059            max_soft_bundle_size: None,
3060
3061            bridge_should_try_to_finalize_committee: None,
3062
3063            max_accumulated_txn_cost_per_object_in_mysticeti_commit: None,
3064
3065            max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit: None,
3066
3067            consensus_gc_depth: None,
3068
3069            gas_budget_based_txn_cost_cap_factor: None,
3070
3071            gas_budget_based_txn_cost_absolute_cap_commit_count: None,
3072
3073            sip_45_consensus_amplification_threshold: None,
3074
3075            use_object_per_epoch_marker_table_v2: None,
3076
3077            consensus_commit_rate_estimation_window_size: None,
3078
3079            aliased_addresses: vec![],
3080
3081            translation_per_command_base_charge: None,
3082            translation_per_input_base_charge: None,
3083            translation_pure_input_per_byte_charge: None,
3084            translation_per_type_node_charge: None,
3085            translation_per_reference_node_charge: None,
3086            translation_per_linkage_entry_charge: None,
3087            translation_per_live_reference_charge: None,
3088            max_ptb_live_references: None,
3089            max_ptb_returned_references: None,
3090            max_ptb_total_returned_references: None,
3091
3092            max_updates_per_settlement_txn: None,
3093
3094            gasless_max_computation_units: None,
3095            gasless_allowed_token_types: None,
3096            gasless_max_unused_inputs: None,
3097            gasless_max_pure_input_bytes: None,
3098            gasless_max_tps: None,
3099            include_special_package_amendments: None,
3100            gasless_max_tx_size_bytes: None,
3101            // When adding a new constant, set it to None in the earliest version, like this:
3102            // new_constant: None,
3103        };
3104        for cur in 2..=version.0 {
3105            match cur {
3106                1 => unreachable!(),
3107                2 => {
3108                    cfg.feature_flags.advance_epoch_start_time_in_safe_mode = true;
3109                }
3110                3 => {
3111                    // changes for gas model
3112                    cfg.gas_model_version = Some(2);
3113                    // max gas budget is in MIST and an absolute value 50SUI
3114                    cfg.max_tx_gas = Some(50_000_000_000);
3115                    // min gas budget is in MIST and an absolute value 2000MIST or 0.000002SUI
3116                    cfg.base_tx_cost_fixed = Some(2_000);
3117                    // storage gas price multiplier
3118                    cfg.storage_gas_price = Some(76);
3119                    cfg.feature_flags.loaded_child_objects_fixed = true;
3120                    // max size of written objects during a TXn
3121                    // this is a sum of all objects written during a TXn
3122                    cfg.max_size_written_objects = Some(5 * 1000 * 1000);
3123                    // max size of written objects during a system TXn to allow for larger writes
3124                    // akin to `max_size_written_objects` but for system TXns
3125                    cfg.max_size_written_objects_system_tx = Some(50 * 1000 * 1000);
3126                    cfg.feature_flags.package_upgrades = true;
3127                }
3128                // This is the first protocol version currently possible.
3129                // Mainnet starts with version 4. Previous versions are pre mainnet and have
3130                // all been wiped out.
3131                // Every other chain is after version 4.
3132                4 => {
3133                    // Change reward slashing rate to 100%.
3134                    cfg.reward_slashing_rate = Some(10000);
3135                    // protect old and new lookup for object version
3136                    cfg.gas_model_version = Some(3);
3137                }
3138                5 => {
3139                    cfg.feature_flags.missing_type_is_compatibility_error = true;
3140                    cfg.gas_model_version = Some(4);
3141                    cfg.feature_flags.scoring_decision_with_validity_cutoff = true;
3142                    // ==== Ephemeral (consensus only) params deleted ====
3143                    // cfg.scoring_decision_mad_divisor = Some(2.3);
3144                    // cfg.scoring_decision_cutoff_value = Some(2.5);
3145                }
3146                6 => {
3147                    cfg.gas_model_version = Some(5);
3148                    cfg.buffer_stake_for_protocol_upgrade_bps = Some(5000);
3149                    cfg.feature_flags.consensus_order_end_of_epoch_last = true;
3150                }
3151                7 => {
3152                    cfg.feature_flags.disallow_adding_abilities_on_upgrade = true;
3153                    cfg.feature_flags
3154                        .disable_invariant_violation_check_in_swap_loc = true;
3155                    cfg.feature_flags.ban_entry_init = true;
3156                    cfg.feature_flags.package_digest_hash_module = true;
3157                }
3158                8 => {
3159                    cfg.feature_flags
3160                        .disallow_change_struct_type_params_on_upgrade = true;
3161                }
3162                9 => {
3163                    // Limits the length of a Move identifier
3164                    cfg.max_move_identifier_len = Some(128);
3165                    cfg.feature_flags.no_extraneous_module_bytes = true;
3166                    cfg.feature_flags
3167                        .advance_to_highest_supported_protocol_version = true;
3168                }
3169                10 => {
3170                    cfg.max_verifier_meter_ticks_per_function = Some(16_000_000);
3171                    cfg.max_meter_ticks_per_module = Some(16_000_000);
3172                }
3173                11 => {
3174                    cfg.max_move_value_depth = Some(128);
3175                }
3176                12 => {
3177                    cfg.feature_flags.narwhal_versioned_metadata = true;
3178                    if chain != Chain::Mainnet {
3179                        cfg.feature_flags.commit_root_state_digest = true;
3180                    }
3181
3182                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3183                        cfg.feature_flags.zklogin_auth = true;
3184                    }
3185                }
3186                13 => {}
3187                14 => {
3188                    cfg.gas_rounding_step = Some(1_000);
3189                    cfg.gas_model_version = Some(6);
3190                }
3191                15 => {
3192                    cfg.feature_flags.consensus_transaction_ordering =
3193                        ConsensusTransactionOrdering::ByGasPrice;
3194                }
3195                16 => {
3196                    cfg.feature_flags.simplified_unwrap_then_delete = true;
3197                }
3198                17 => {
3199                    cfg.feature_flags.upgraded_multisig_supported = true;
3200                }
3201                18 => {
3202                    cfg.execution_version = Some(1);
3203                    // Following flags are implied by this execution version.  Once support for earlier
3204                    // protocol versions is dropped, these flags can be removed:
3205                    // cfg.feature_flags.package_upgrades = true;
3206                    // cfg.feature_flags.disallow_adding_abilities_on_upgrade = true;
3207                    // cfg.feature_flags.disallow_change_struct_type_params_on_upgrade = true;
3208                    // cfg.feature_flags.loaded_child_objects_fixed = true;
3209                    // cfg.feature_flags.ban_entry_init = true;
3210                    // cfg.feature_flags.pack_digest_hash_modules = true;
3211                    cfg.feature_flags.txn_base_cost_as_multiplier = true;
3212                    // this is a multiplier of the gas price
3213                    cfg.base_tx_cost_fixed = Some(1_000);
3214                }
3215                19 => {
3216                    cfg.max_num_event_emit = Some(1024);
3217                    // We maintain the same total size limit for events, but increase the number of
3218                    // events that can be emitted.
3219                    cfg.max_event_emit_size_total = Some(
3220                        256 /* former event count limit */ * 250 * 1024, /* size limit per event */
3221                    );
3222                }
3223                20 => {
3224                    cfg.feature_flags.commit_root_state_digest = true;
3225
3226                    if chain != Chain::Mainnet {
3227                        cfg.feature_flags.narwhal_new_leader_election_schedule = true;
3228                        cfg.consensus_bad_nodes_stake_threshold = Some(20);
3229                    }
3230                }
3231
3232                21 => {
3233                    if chain != Chain::Mainnet {
3234                        cfg.feature_flags.zklogin_supported_providers = BTreeSet::from([
3235                            "Google".to_string(),
3236                            "Facebook".to_string(),
3237                            "Twitch".to_string(),
3238                        ]);
3239                    }
3240                }
3241                22 => {
3242                    cfg.feature_flags.loaded_child_object_format = true;
3243                }
3244                23 => {
3245                    cfg.feature_flags.loaded_child_object_format_type = true;
3246                    cfg.feature_flags.narwhal_new_leader_election_schedule = true;
3247                    // Taking a baby step approach, we consider only 20% by stake as bad nodes so we
3248                    // have a 80% by stake of nodes participating in the leader committee. That allow
3249                    // us for more redundancy in case we have validators under performing - since the
3250                    // responsibility is shared amongst more nodes. We can increase that once we do have
3251                    // higher confidence.
3252                    cfg.consensus_bad_nodes_stake_threshold = Some(20);
3253                }
3254                24 => {
3255                    cfg.feature_flags.simple_conservation_checks = true;
3256                    cfg.max_publish_or_upgrade_per_ptb = Some(5);
3257
3258                    cfg.feature_flags.end_of_epoch_transaction_supported = true;
3259
3260                    if chain != Chain::Mainnet {
3261                        cfg.feature_flags.enable_jwk_consensus_updates = true;
3262                        // Max of 10 votes per hour
3263                        cfg.max_jwk_votes_per_validator_per_epoch = Some(240);
3264                        cfg.max_age_of_jwk_in_epochs = Some(1);
3265                    }
3266                }
3267                25 => {
3268                    // Enable zkLogin for all providers in all networks.
3269                    cfg.feature_flags.zklogin_supported_providers = BTreeSet::from([
3270                        "Google".to_string(),
3271                        "Facebook".to_string(),
3272                        "Twitch".to_string(),
3273                    ]);
3274                    cfg.feature_flags.zklogin_auth = true;
3275
3276                    // Enable jwk consensus updates
3277                    cfg.feature_flags.enable_jwk_consensus_updates = true;
3278                    cfg.max_jwk_votes_per_validator_per_epoch = Some(240);
3279                    cfg.max_age_of_jwk_in_epochs = Some(1);
3280                }
3281                26 => {
3282                    cfg.gas_model_version = Some(7);
3283                    // Only enable receiving objects in devnet
3284                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3285                        cfg.transfer_receive_object_cost_base = Some(52);
3286                        cfg.feature_flags.receive_objects = true;
3287                    }
3288                }
3289                27 => {
3290                    cfg.gas_model_version = Some(8);
3291                }
3292                28 => {
3293                    // zklogin::check_zklogin_id
3294                    cfg.check_zklogin_id_cost_base = Some(200);
3295                    // zklogin::check_zklogin_issuer
3296                    cfg.check_zklogin_issuer_cost_base = Some(200);
3297
3298                    // Only enable effects v2 on devnet.
3299                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3300                        cfg.feature_flags.enable_effects_v2 = true;
3301                    }
3302                }
3303                29 => {
3304                    cfg.feature_flags.verify_legacy_zklogin_address = true;
3305                }
3306                30 => {
3307                    // Only enable nw certificate v2 on testnet.
3308                    if chain != Chain::Mainnet {
3309                        cfg.feature_flags.narwhal_certificate_v2 = true;
3310                    }
3311
3312                    cfg.random_beacon_reduction_allowed_delta = Some(800);
3313                    // Only enable effects v2 on devnet and testnet.
3314                    if chain != Chain::Mainnet {
3315                        cfg.feature_flags.enable_effects_v2 = true;
3316                    }
3317
3318                    // zklogin_supported_providers config is deprecated, zklogin
3319                    // signature verifier will use the fetched jwk map to determine
3320                    // whether the provider is supported based on node config.
3321                    cfg.feature_flags.zklogin_supported_providers = BTreeSet::default();
3322
3323                    cfg.feature_flags.recompute_has_public_transfer_in_execution = true;
3324                }
3325                31 => {
3326                    cfg.execution_version = Some(2);
3327                    // Only enable shared object deletion on devnet
3328                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3329                        cfg.feature_flags.shared_object_deletion = true;
3330                    }
3331                }
3332                32 => {
3333                    // enable zklogin in multisig in devnet and testnet
3334                    if chain != Chain::Mainnet {
3335                        cfg.feature_flags.accept_zklogin_in_multisig = true;
3336                    }
3337                    // enable receiving objects in devnet and testnet
3338                    if chain != Chain::Mainnet {
3339                        cfg.transfer_receive_object_cost_base = Some(52);
3340                        cfg.feature_flags.receive_objects = true;
3341                    }
3342                    // Only enable random beacon on devnet
3343                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3344                        cfg.feature_flags.random_beacon = true;
3345                        cfg.random_beacon_reduction_lower_bound = Some(1600);
3346                        cfg.random_beacon_dkg_timeout_round = Some(3000);
3347                        cfg.random_beacon_min_round_interval_ms = Some(150);
3348                    }
3349                    // Only enable consensus digest in consensus commit prologue in devnet.
3350                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3351                        cfg.feature_flags.include_consensus_digest_in_prologue = true;
3352                    }
3353
3354                    // enable nw cert v2 on mainnet
3355                    cfg.feature_flags.narwhal_certificate_v2 = true;
3356                }
3357                33 => {
3358                    cfg.feature_flags.hardened_otw_check = true;
3359                    cfg.feature_flags.allow_receiving_object_id = true;
3360
3361                    // Enable transfer-to-object in mainnet
3362                    cfg.transfer_receive_object_cost_base = Some(52);
3363                    cfg.feature_flags.receive_objects = true;
3364
3365                    // Enable shared object deletion in testnet and devnet
3366                    if chain != Chain::Mainnet {
3367                        cfg.feature_flags.shared_object_deletion = true;
3368                    }
3369
3370                    cfg.feature_flags.enable_effects_v2 = true;
3371                }
3372                34 => {}
3373                35 => {
3374                    // Add costs for poseidon::poseidon_bn254
3375                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3376                        cfg.feature_flags.enable_poseidon = true;
3377                        cfg.poseidon_bn254_cost_base = Some(260);
3378                        cfg.poseidon_bn254_cost_per_block = Some(10);
3379                    }
3380
3381                    cfg.feature_flags.enable_coin_deny_list = true;
3382                }
3383                36 => {
3384                    // Only enable group ops on devnet
3385                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3386                        cfg.feature_flags.enable_group_ops_native_functions = true;
3387                        cfg.feature_flags.enable_group_ops_native_function_msm = true;
3388                        // Next values are arbitrary in a similar way as the other crypto native functions.
3389                        cfg.group_ops_bls12381_decode_scalar_cost = Some(52);
3390                        cfg.group_ops_bls12381_decode_g1_cost = Some(52);
3391                        cfg.group_ops_bls12381_decode_g2_cost = Some(52);
3392                        cfg.group_ops_bls12381_decode_gt_cost = Some(52);
3393                        cfg.group_ops_bls12381_scalar_add_cost = Some(52);
3394                        cfg.group_ops_bls12381_g1_add_cost = Some(52);
3395                        cfg.group_ops_bls12381_g2_add_cost = Some(52);
3396                        cfg.group_ops_bls12381_gt_add_cost = Some(52);
3397                        cfg.group_ops_bls12381_scalar_sub_cost = Some(52);
3398                        cfg.group_ops_bls12381_g1_sub_cost = Some(52);
3399                        cfg.group_ops_bls12381_g2_sub_cost = Some(52);
3400                        cfg.group_ops_bls12381_gt_sub_cost = Some(52);
3401                        cfg.group_ops_bls12381_scalar_mul_cost = Some(52);
3402                        cfg.group_ops_bls12381_g1_mul_cost = Some(52);
3403                        cfg.group_ops_bls12381_g2_mul_cost = Some(52);
3404                        cfg.group_ops_bls12381_gt_mul_cost = Some(52);
3405                        cfg.group_ops_bls12381_scalar_div_cost = Some(52);
3406                        cfg.group_ops_bls12381_g1_div_cost = Some(52);
3407                        cfg.group_ops_bls12381_g2_div_cost = Some(52);
3408                        cfg.group_ops_bls12381_gt_div_cost = Some(52);
3409                        cfg.group_ops_bls12381_g1_hash_to_base_cost = Some(52);
3410                        cfg.group_ops_bls12381_g2_hash_to_base_cost = Some(52);
3411                        cfg.group_ops_bls12381_g1_hash_to_cost_per_byte = Some(2);
3412                        cfg.group_ops_bls12381_g2_hash_to_cost_per_byte = Some(2);
3413                        cfg.group_ops_bls12381_g1_msm_base_cost = Some(52);
3414                        cfg.group_ops_bls12381_g2_msm_base_cost = Some(52);
3415                        cfg.group_ops_bls12381_g1_msm_base_cost_per_input = Some(52);
3416                        cfg.group_ops_bls12381_g2_msm_base_cost_per_input = Some(52);
3417                        cfg.group_ops_bls12381_msm_max_len = Some(32);
3418                        cfg.group_ops_bls12381_pairing_cost = Some(52);
3419                    }
3420                    // Enable shared object deletion on all networks.
3421                    cfg.feature_flags.shared_object_deletion = true;
3422
3423                    cfg.consensus_max_transaction_size_bytes = Some(256 * 1024); // 256KB
3424                    cfg.consensus_max_transactions_in_block_bytes = Some(6 * 1_024 * 1024);
3425                    // 6 MB
3426                }
3427                37 => {
3428                    cfg.feature_flags.reject_mutable_random_on_entry_functions = true;
3429
3430                    // Enable consensus digest in consensus commit prologue in testnet and devnet.
3431                    if chain != Chain::Mainnet {
3432                        cfg.feature_flags.include_consensus_digest_in_prologue = true;
3433                    }
3434                }
3435                38 => {
3436                    cfg.binary_module_handles = Some(100);
3437                    cfg.binary_struct_handles = Some(300);
3438                    cfg.binary_function_handles = Some(1500);
3439                    cfg.binary_function_instantiations = Some(750);
3440                    cfg.binary_signatures = Some(1000);
3441                    // constants and identifiers are proportional to the binary size,
3442                    // and they vastly depend on the code, so we are leaving them
3443                    // reasonably high
3444                    cfg.binary_constant_pool = Some(4000);
3445                    cfg.binary_identifiers = Some(10000);
3446                    cfg.binary_address_identifiers = Some(100);
3447                    cfg.binary_struct_defs = Some(200);
3448                    cfg.binary_struct_def_instantiations = Some(100);
3449                    cfg.binary_function_defs = Some(1000);
3450                    cfg.binary_field_handles = Some(500);
3451                    cfg.binary_field_instantiations = Some(250);
3452                    cfg.binary_friend_decls = Some(100);
3453                    // reduce dependencies maximum
3454                    cfg.max_package_dependencies = Some(32);
3455                    cfg.max_modules_in_publish = Some(64);
3456                    // bump execution version
3457                    cfg.execution_version = Some(3);
3458                }
3459                39 => {
3460                    // It is important that we keep this protocol version blank due to an issue with random.move.
3461                }
3462                40 => {}
3463                41 => {
3464                    // Enable group ops and all networks (but not msm)
3465                    cfg.feature_flags.enable_group_ops_native_functions = true;
3466                    // Next values are arbitrary in a similar way as the other crypto native functions.
3467                    cfg.group_ops_bls12381_decode_scalar_cost = Some(52);
3468                    cfg.group_ops_bls12381_decode_g1_cost = Some(52);
3469                    cfg.group_ops_bls12381_decode_g2_cost = Some(52);
3470                    cfg.group_ops_bls12381_decode_gt_cost = Some(52);
3471                    cfg.group_ops_bls12381_scalar_add_cost = Some(52);
3472                    cfg.group_ops_bls12381_g1_add_cost = Some(52);
3473                    cfg.group_ops_bls12381_g2_add_cost = Some(52);
3474                    cfg.group_ops_bls12381_gt_add_cost = Some(52);
3475                    cfg.group_ops_bls12381_scalar_sub_cost = Some(52);
3476                    cfg.group_ops_bls12381_g1_sub_cost = Some(52);
3477                    cfg.group_ops_bls12381_g2_sub_cost = Some(52);
3478                    cfg.group_ops_bls12381_gt_sub_cost = Some(52);
3479                    cfg.group_ops_bls12381_scalar_mul_cost = Some(52);
3480                    cfg.group_ops_bls12381_g1_mul_cost = Some(52);
3481                    cfg.group_ops_bls12381_g2_mul_cost = Some(52);
3482                    cfg.group_ops_bls12381_gt_mul_cost = Some(52);
3483                    cfg.group_ops_bls12381_scalar_div_cost = Some(52);
3484                    cfg.group_ops_bls12381_g1_div_cost = Some(52);
3485                    cfg.group_ops_bls12381_g2_div_cost = Some(52);
3486                    cfg.group_ops_bls12381_gt_div_cost = Some(52);
3487                    cfg.group_ops_bls12381_g1_hash_to_base_cost = Some(52);
3488                    cfg.group_ops_bls12381_g2_hash_to_base_cost = Some(52);
3489                    cfg.group_ops_bls12381_g1_hash_to_cost_per_byte = Some(2);
3490                    cfg.group_ops_bls12381_g2_hash_to_cost_per_byte = Some(2);
3491                    cfg.group_ops_bls12381_g1_msm_base_cost = Some(52);
3492                    cfg.group_ops_bls12381_g2_msm_base_cost = Some(52);
3493                    cfg.group_ops_bls12381_g1_msm_base_cost_per_input = Some(52);
3494                    cfg.group_ops_bls12381_g2_msm_base_cost_per_input = Some(52);
3495                    cfg.group_ops_bls12381_msm_max_len = Some(32);
3496                    cfg.group_ops_bls12381_pairing_cost = Some(52);
3497                }
3498                42 => {}
3499                43 => {
3500                    cfg.feature_flags.zklogin_max_epoch_upper_bound_delta = Some(30);
3501                    cfg.max_meter_ticks_per_package = Some(16_000_000);
3502                }
3503                44 => {
3504                    // Enable consensus digest in consensus commit prologue on all networks..
3505                    cfg.feature_flags.include_consensus_digest_in_prologue = true;
3506                    // Switch between Narwhal and Mysticeti per epoch in tests, devnet and testnet.
3507                    if chain != Chain::Mainnet {
3508                        cfg.feature_flags.consensus_choice = ConsensusChoice::SwapEachEpoch;
3509                    }
3510                }
3511                45 => {
3512                    // Use tonic networking for consensus, in tests and devnet.
3513                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3514                        cfg.feature_flags.consensus_network = ConsensusNetwork::Tonic;
3515                    }
3516
3517                    if chain != Chain::Mainnet {
3518                        // Enable leader scoring & schedule change on testnet for mysticeti.
3519                        cfg.feature_flags.mysticeti_leader_scoring_and_schedule = true;
3520                    }
3521                    cfg.min_move_binary_format_version = Some(6);
3522                    cfg.feature_flags.accept_zklogin_in_multisig = true;
3523
3524                    // Also bumps framework snapshot to fix binop issue.
3525
3526                    // enable bridge in devnet
3527                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3528                        cfg.feature_flags.bridge = true;
3529                    }
3530                }
3531                46 => {
3532                    // enable bridge in devnet and testnet
3533                    if chain != Chain::Mainnet {
3534                        cfg.feature_flags.bridge = true;
3535                    }
3536
3537                    // Enable resharing at same initial version
3538                    cfg.feature_flags.reshare_at_same_initial_version = true;
3539                }
3540                47 => {}
3541                48 => {
3542                    // Use tonic networking for Mysticeti.
3543                    cfg.feature_flags.consensus_network = ConsensusNetwork::Tonic;
3544
3545                    // Enable resolving abort code IDs to package ID instead of runtime module ID
3546                    cfg.feature_flags.resolve_abort_locations_to_package_id = true;
3547
3548                    // Enable random beacon on testnet.
3549                    if chain != Chain::Mainnet {
3550                        cfg.feature_flags.random_beacon = true;
3551                        cfg.random_beacon_reduction_lower_bound = Some(1600);
3552                        cfg.random_beacon_dkg_timeout_round = Some(3000);
3553                        cfg.random_beacon_min_round_interval_ms = Some(200);
3554                    }
3555
3556                    // Enable the committed sub dag digest inclusion on the commit output
3557                    cfg.feature_flags.mysticeti_use_committed_subdag_digest = true;
3558                }
3559                49 => {
3560                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3561                        cfg.move_binary_format_version = Some(7);
3562                    }
3563
3564                    // enable vdf in devnet
3565                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3566                        cfg.feature_flags.enable_vdf = true;
3567                        // Set to 30x and 2x the cost of a signature verification for now. This
3568                        // should be updated along with other native crypto functions.
3569                        cfg.vdf_verify_vdf_cost = Some(1500);
3570                        cfg.vdf_hash_to_input_cost = Some(100);
3571                    }
3572
3573                    // Only enable consensus commit prologue V3 in devnet.
3574                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3575                        cfg.feature_flags
3576                            .record_consensus_determined_version_assignments_in_prologue = true;
3577                    }
3578
3579                    // Run Mysticeti consensus in testnet.
3580                    if chain != Chain::Mainnet {
3581                        cfg.feature_flags.consensus_choice = ConsensusChoice::Mysticeti;
3582                    }
3583
3584                    // Run Move verification on framework upgrades in its own VM
3585                    cfg.feature_flags.fresh_vm_on_framework_upgrade = true;
3586                }
3587                50 => {
3588                    // Enable checkpoint batching in testnet.
3589                    if chain != Chain::Mainnet {
3590                        cfg.checkpoint_summary_version_specific_data = Some(1);
3591                        cfg.min_checkpoint_interval_ms = Some(200);
3592                    }
3593
3594                    // Only enable prepose consensus commit prologue in checkpoints in devnet.
3595                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3596                        cfg.feature_flags
3597                            .prepend_prologue_tx_in_consensus_commit_in_checkpoints = true;
3598                    }
3599
3600                    cfg.feature_flags.mysticeti_num_leaders_per_round = Some(1);
3601
3602                    // Set max transaction deferral to 10 consensus rounds.
3603                    cfg.max_deferral_rounds_for_congestion_control = Some(10);
3604                }
3605                51 => {
3606                    cfg.random_beacon_dkg_version = Some(1);
3607
3608                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3609                        cfg.feature_flags.enable_coin_deny_list_v2 = true;
3610                    }
3611                }
3612                52 => {
3613                    if chain != Chain::Mainnet {
3614                        cfg.feature_flags.soft_bundle = true;
3615                        cfg.max_soft_bundle_size = Some(5);
3616                    }
3617
3618                    cfg.config_read_setting_impl_cost_base = Some(100);
3619                    cfg.config_read_setting_impl_cost_per_byte = Some(40);
3620
3621                    // Turn on shared object congestion control in devnet.
3622                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3623                        cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(100);
3624                        cfg.feature_flags.per_object_congestion_control_mode =
3625                            PerObjectCongestionControlMode::TotalTxCount;
3626                    }
3627
3628                    // Enable Mysticeti on mainnet.
3629                    cfg.feature_flags.consensus_choice = ConsensusChoice::Mysticeti;
3630
3631                    // Enable leader scoring & schedule change on mainnet for mysticeti.
3632                    cfg.feature_flags.mysticeti_leader_scoring_and_schedule = true;
3633
3634                    // Enable checkpoint batching on mainnet.
3635                    cfg.checkpoint_summary_version_specific_data = Some(1);
3636                    cfg.min_checkpoint_interval_ms = Some(200);
3637
3638                    // Enable consensus commit prologue V3 in testnet.
3639                    if chain != Chain::Mainnet {
3640                        cfg.feature_flags
3641                            .record_consensus_determined_version_assignments_in_prologue = true;
3642                        cfg.feature_flags
3643                            .prepend_prologue_tx_in_consensus_commit_in_checkpoints = true;
3644                    }
3645                    // Turn on enums in testnet and devnet
3646                    if chain != Chain::Mainnet {
3647                        cfg.move_binary_format_version = Some(7);
3648                    }
3649
3650                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3651                        cfg.feature_flags.passkey_auth = true;
3652                    }
3653                    cfg.feature_flags.enable_coin_deny_list_v2 = true;
3654                }
3655                53 => {
3656                    // Do not allow bridge committee to finalize on mainnet.
3657                    cfg.bridge_should_try_to_finalize_committee = Some(chain != Chain::Mainnet);
3658
3659                    // Enable consensus commit prologue V3 on mainnet.
3660                    cfg.feature_flags
3661                        .record_consensus_determined_version_assignments_in_prologue = true;
3662                    cfg.feature_flags
3663                        .prepend_prologue_tx_in_consensus_commit_in_checkpoints = true;
3664
3665                    if chain == Chain::Unknown {
3666                        cfg.feature_flags.authority_capabilities_v2 = true;
3667                    }
3668
3669                    // Turns on shared object congestion control on testnet.
3670                    if chain != Chain::Mainnet {
3671                        cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(100);
3672                        cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(10);
3673                        cfg.feature_flags.per_object_congestion_control_mode =
3674                            PerObjectCongestionControlMode::TotalTxCount;
3675                    }
3676
3677                    // Adjust stdlib gas costs
3678                    cfg.bcs_per_byte_serialized_cost = Some(2);
3679                    cfg.bcs_legacy_min_output_size_cost = Some(1);
3680                    cfg.bcs_failure_cost = Some(52);
3681                    cfg.debug_print_base_cost = Some(52);
3682                    cfg.debug_print_stack_trace_base_cost = Some(52);
3683                    cfg.hash_sha2_256_base_cost = Some(52);
3684                    cfg.hash_sha2_256_per_byte_cost = Some(2);
3685                    cfg.hash_sha2_256_legacy_min_input_len_cost = Some(1);
3686                    cfg.hash_sha3_256_base_cost = Some(52);
3687                    cfg.hash_sha3_256_per_byte_cost = Some(2);
3688                    cfg.hash_sha3_256_legacy_min_input_len_cost = Some(1);
3689                    cfg.type_name_get_base_cost = Some(52);
3690                    cfg.type_name_get_per_byte_cost = Some(2);
3691                    cfg.string_check_utf8_base_cost = Some(52);
3692                    cfg.string_check_utf8_per_byte_cost = Some(2);
3693                    cfg.string_is_char_boundary_base_cost = Some(52);
3694                    cfg.string_sub_string_base_cost = Some(52);
3695                    cfg.string_sub_string_per_byte_cost = Some(2);
3696                    cfg.string_index_of_base_cost = Some(52);
3697                    cfg.string_index_of_per_byte_pattern_cost = Some(2);
3698                    cfg.string_index_of_per_byte_searched_cost = Some(2);
3699                    cfg.vector_empty_base_cost = Some(52);
3700                    cfg.vector_length_base_cost = Some(52);
3701                    cfg.vector_push_back_base_cost = Some(52);
3702                    cfg.vector_push_back_legacy_per_abstract_memory_unit_cost = Some(2);
3703                    cfg.vector_borrow_base_cost = Some(52);
3704                    cfg.vector_pop_back_base_cost = Some(52);
3705                    cfg.vector_destroy_empty_base_cost = Some(52);
3706                    cfg.vector_swap_base_cost = Some(52);
3707                }
3708                54 => {
3709                    // Enable random beacon on mainnet.
3710                    cfg.feature_flags.random_beacon = true;
3711                    cfg.random_beacon_reduction_lower_bound = Some(1000);
3712                    cfg.random_beacon_dkg_timeout_round = Some(3000);
3713                    cfg.random_beacon_min_round_interval_ms = Some(500);
3714
3715                    // Turns on shared object congestion control on mainnet.
3716                    cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(100);
3717                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(10);
3718                    cfg.feature_flags.per_object_congestion_control_mode =
3719                        PerObjectCongestionControlMode::TotalTxCount;
3720
3721                    // Enable soft bundle on mainnet.
3722                    cfg.feature_flags.soft_bundle = true;
3723                    cfg.max_soft_bundle_size = Some(5);
3724                }
3725                55 => {
3726                    // Turn on enums mainnet
3727                    cfg.move_binary_format_version = Some(7);
3728
3729                    // Assume 1KB per transaction and 500 transactions per block.
3730                    cfg.consensus_max_transactions_in_block_bytes = Some(512 * 1024);
3731                    // Assume 20_000 TPS * 5% max stake per validator / (minimum) 4 blocks per round = 250 transactions per block maximum
3732                    // Using a higher limit that is 512, to account for bursty traffic and system transactions.
3733                    cfg.consensus_max_num_transactions_in_block = Some(512);
3734
3735                    cfg.feature_flags.rethrow_serialization_type_layout_errors = true;
3736                }
3737                56 => {
3738                    if chain == Chain::Mainnet {
3739                        cfg.feature_flags.bridge = true;
3740                    }
3741                }
3742                57 => {
3743                    // Reduce minimum number of random beacon shares.
3744                    cfg.random_beacon_reduction_lower_bound = Some(800);
3745                }
3746                58 => {
3747                    if chain == Chain::Mainnet {
3748                        cfg.bridge_should_try_to_finalize_committee = Some(true);
3749                    }
3750
3751                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3752                        // Enable distributed vote scoring for devnet
3753                        cfg.feature_flags
3754                            .consensus_distributed_vote_scoring_strategy = true;
3755                    }
3756                }
3757                59 => {
3758                    // Enable round prober in consensus.
3759                    cfg.feature_flags.consensus_round_prober = true;
3760                }
3761                60 => {
3762                    cfg.max_type_to_layout_nodes = Some(512);
3763                    cfg.feature_flags.validate_identifier_inputs = true;
3764                }
3765                61 => {
3766                    if chain != Chain::Mainnet {
3767                        // Enable distributed vote scoring for testnet
3768                        cfg.feature_flags
3769                            .consensus_distributed_vote_scoring_strategy = true;
3770                    }
3771                    // Further reduce minimum number of random beacon shares.
3772                    cfg.random_beacon_reduction_lower_bound = Some(700);
3773
3774                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3775                        // Enable Mysticeti fastpath for devnet
3776                        cfg.feature_flags.mysticeti_fastpath = true;
3777                    }
3778                }
3779                62 => {
3780                    cfg.feature_flags.relocate_event_module = true;
3781                }
3782                63 => {
3783                    cfg.feature_flags.per_object_congestion_control_mode =
3784                        PerObjectCongestionControlMode::TotalGasBudgetWithCap;
3785                    cfg.gas_budget_based_txn_cost_cap_factor = Some(400_000);
3786                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(18_500_000);
3787                    cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(240_000_000);
3788                }
3789                64 => {
3790                    cfg.feature_flags.per_object_congestion_control_mode =
3791                        PerObjectCongestionControlMode::TotalTxCount;
3792                    cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(40);
3793                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(3);
3794                }
3795                65 => {
3796                    // Enable distributed vote scoring for mainnet
3797                    cfg.feature_flags
3798                        .consensus_distributed_vote_scoring_strategy = true;
3799                }
3800                66 => {
3801                    if chain == Chain::Mainnet {
3802                        // Revert the distributed vote scoring for mainnet (for one protocol upgrade)
3803                        cfg.feature_flags
3804                            .consensus_distributed_vote_scoring_strategy = false;
3805                    }
3806                }
3807                67 => {
3808                    // Enable it once again.
3809                    cfg.feature_flags
3810                        .consensus_distributed_vote_scoring_strategy = true;
3811                }
3812                68 => {
3813                    cfg.group_ops_bls12381_g1_to_uncompressed_g1_cost = Some(26);
3814                    cfg.group_ops_bls12381_uncompressed_g1_to_g1_cost = Some(52);
3815                    cfg.group_ops_bls12381_uncompressed_g1_sum_base_cost = Some(26);
3816                    cfg.group_ops_bls12381_uncompressed_g1_sum_cost_per_term = Some(13);
3817                    cfg.group_ops_bls12381_uncompressed_g1_sum_max_terms = Some(2000);
3818
3819                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3820                        cfg.feature_flags.uncompressed_g1_group_elements = true;
3821                    }
3822
3823                    cfg.feature_flags.per_object_congestion_control_mode =
3824                        PerObjectCongestionControlMode::TotalGasBudgetWithCap;
3825                    cfg.gas_budget_based_txn_cost_cap_factor = Some(400_000);
3826                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(18_500_000);
3827                    cfg.max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit =
3828                        Some(3_700_000); // 20% of above
3829                    cfg.max_txn_cost_overage_per_object_in_commit = Some(u64::MAX);
3830                    cfg.gas_budget_based_txn_cost_absolute_cap_commit_count = Some(50);
3831
3832                    // Further reduce minimum number of random beacon shares.
3833                    cfg.random_beacon_reduction_lower_bound = Some(500);
3834
3835                    cfg.feature_flags.disallow_new_modules_in_deps_only_packages = true;
3836                }
3837                69 => {
3838                    // Sets number of rounds allowed for fastpath voting in consensus.
3839                    cfg.consensus_voting_rounds = Some(40);
3840
3841                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3842                        // Enable smart ancestor selection for devnet
3843                        cfg.feature_flags.consensus_smart_ancestor_selection = true;
3844                    }
3845
3846                    if chain != Chain::Mainnet {
3847                        cfg.feature_flags.uncompressed_g1_group_elements = true;
3848                    }
3849                }
3850                70 => {
3851                    if chain != Chain::Mainnet {
3852                        // Enable smart ancestor selection for testnet
3853                        cfg.feature_flags.consensus_smart_ancestor_selection = true;
3854                        // Enable probing for accepted rounds in round prober for testnet
3855                        cfg.feature_flags
3856                            .consensus_round_prober_probe_accepted_rounds = true;
3857                    }
3858
3859                    cfg.poseidon_bn254_cost_per_block = Some(388);
3860
3861                    cfg.gas_model_version = Some(9);
3862                    cfg.feature_flags.native_charging_v2 = true;
3863                    cfg.bls12381_bls12381_min_sig_verify_cost_base = Some(44064);
3864                    cfg.bls12381_bls12381_min_pk_verify_cost_base = Some(49282);
3865                    cfg.ecdsa_k1_secp256k1_verify_keccak256_cost_base = Some(1470);
3866                    cfg.ecdsa_k1_secp256k1_verify_sha256_cost_base = Some(1470);
3867                    cfg.ecdsa_r1_secp256r1_verify_sha256_cost_base = Some(4225);
3868                    cfg.ecdsa_r1_secp256r1_verify_keccak256_cost_base = Some(4225);
3869                    cfg.ecvrf_ecvrf_verify_cost_base = Some(4848);
3870                    cfg.ed25519_ed25519_verify_cost_base = Some(1802);
3871
3872                    // Manually changed to be "under cost"
3873                    cfg.ecdsa_r1_ecrecover_keccak256_cost_base = Some(1173);
3874                    cfg.ecdsa_r1_ecrecover_sha256_cost_base = Some(1173);
3875                    cfg.ecdsa_k1_ecrecover_keccak256_cost_base = Some(500);
3876                    cfg.ecdsa_k1_ecrecover_sha256_cost_base = Some(500);
3877
3878                    cfg.groth16_prepare_verifying_key_bls12381_cost_base = Some(53838);
3879                    cfg.groth16_prepare_verifying_key_bn254_cost_base = Some(82010);
3880                    cfg.groth16_verify_groth16_proof_internal_bls12381_cost_base = Some(72090);
3881                    cfg.groth16_verify_groth16_proof_internal_bls12381_cost_per_public_input =
3882                        Some(8213);
3883                    cfg.groth16_verify_groth16_proof_internal_bn254_cost_base = Some(115502);
3884                    cfg.groth16_verify_groth16_proof_internal_bn254_cost_per_public_input =
3885                        Some(9484);
3886
3887                    cfg.hash_keccak256_cost_base = Some(10);
3888                    cfg.hash_blake2b256_cost_base = Some(10);
3889
3890                    // group ops
3891                    cfg.group_ops_bls12381_decode_scalar_cost = Some(7);
3892                    cfg.group_ops_bls12381_decode_g1_cost = Some(2848);
3893                    cfg.group_ops_bls12381_decode_g2_cost = Some(3770);
3894                    cfg.group_ops_bls12381_decode_gt_cost = Some(3068);
3895
3896                    cfg.group_ops_bls12381_scalar_add_cost = Some(10);
3897                    cfg.group_ops_bls12381_g1_add_cost = Some(1556);
3898                    cfg.group_ops_bls12381_g2_add_cost = Some(3048);
3899                    cfg.group_ops_bls12381_gt_add_cost = Some(188);
3900
3901                    cfg.group_ops_bls12381_scalar_sub_cost = Some(10);
3902                    cfg.group_ops_bls12381_g1_sub_cost = Some(1550);
3903                    cfg.group_ops_bls12381_g2_sub_cost = Some(3019);
3904                    cfg.group_ops_bls12381_gt_sub_cost = Some(497);
3905
3906                    cfg.group_ops_bls12381_scalar_mul_cost = Some(11);
3907                    cfg.group_ops_bls12381_g1_mul_cost = Some(4842);
3908                    cfg.group_ops_bls12381_g2_mul_cost = Some(9108);
3909                    cfg.group_ops_bls12381_gt_mul_cost = Some(27490);
3910
3911                    cfg.group_ops_bls12381_scalar_div_cost = Some(91);
3912                    cfg.group_ops_bls12381_g1_div_cost = Some(5091);
3913                    cfg.group_ops_bls12381_g2_div_cost = Some(9206);
3914                    cfg.group_ops_bls12381_gt_div_cost = Some(27804);
3915
3916                    cfg.group_ops_bls12381_g1_hash_to_base_cost = Some(2962);
3917                    cfg.group_ops_bls12381_g2_hash_to_base_cost = Some(8688);
3918
3919                    cfg.group_ops_bls12381_g1_msm_base_cost = Some(62648);
3920                    cfg.group_ops_bls12381_g2_msm_base_cost = Some(131192);
3921                    cfg.group_ops_bls12381_g1_msm_base_cost_per_input = Some(1333);
3922                    cfg.group_ops_bls12381_g2_msm_base_cost_per_input = Some(3216);
3923
3924                    cfg.group_ops_bls12381_uncompressed_g1_to_g1_cost = Some(677);
3925                    cfg.group_ops_bls12381_g1_to_uncompressed_g1_cost = Some(2099);
3926                    cfg.group_ops_bls12381_uncompressed_g1_sum_base_cost = Some(77);
3927                    cfg.group_ops_bls12381_uncompressed_g1_sum_cost_per_term = Some(26);
3928
3929                    cfg.group_ops_bls12381_pairing_cost = Some(26897);
3930                    cfg.group_ops_bls12381_uncompressed_g1_sum_max_terms = Some(1200);
3931
3932                    cfg.validator_validate_metadata_cost_base = Some(20000);
3933                }
3934                71 => {
3935                    cfg.sip_45_consensus_amplification_threshold = Some(5);
3936
3937                    // Enable bursts for congestion control. (10x the per-commit budget)
3938                    cfg.allowed_txn_cost_overage_burst_per_object_in_commit = Some(185_000_000);
3939                }
3940                72 => {
3941                    cfg.feature_flags.convert_type_argument_error = true;
3942
3943                    // Invariant: max_gas_price * base_tx_cost_fixed <= max_tx_gas
3944                    // max gas budget is in MIST and an absolute value 50_000 SUI
3945                    cfg.max_tx_gas = Some(50_000_000_000_000);
3946                    // max gas price is in MIST and an absolute value 50 SUI
3947                    cfg.max_gas_price = Some(50_000_000_000);
3948
3949                    cfg.feature_flags.variant_nodes = true;
3950                }
3951                73 => {
3952                    // Enable new marker table version.
3953                    cfg.use_object_per_epoch_marker_table_v2 = Some(true);
3954
3955                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3956                        // Assuming a round rate of max 15/sec, then using a gc depth of 60 allow blocks within a window of ~4 seconds
3957                        // to be included before be considered garbage collected.
3958                        cfg.consensus_gc_depth = Some(60);
3959                    }
3960
3961                    if chain != Chain::Mainnet {
3962                        // Enable zstd compression for consensus in testnet
3963                        cfg.feature_flags.consensus_zstd_compression = true;
3964                    }
3965
3966                    // Enable smart ancestor selection for mainnet
3967                    cfg.feature_flags.consensus_smart_ancestor_selection = true;
3968                    // Enable probing for accepted rounds in round prober for mainnet
3969                    cfg.feature_flags
3970                        .consensus_round_prober_probe_accepted_rounds = true;
3971
3972                    // Increase congestion control budget.
3973                    cfg.feature_flags.per_object_congestion_control_mode =
3974                        PerObjectCongestionControlMode::TotalGasBudgetWithCap;
3975                    cfg.gas_budget_based_txn_cost_cap_factor = Some(400_000);
3976                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(37_000_000);
3977                    cfg.max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit =
3978                        Some(7_400_000); // 20% of above
3979                    cfg.max_txn_cost_overage_per_object_in_commit = Some(u64::MAX);
3980                    cfg.gas_budget_based_txn_cost_absolute_cap_commit_count = Some(50);
3981                    cfg.allowed_txn_cost_overage_burst_per_object_in_commit = Some(370_000_000);
3982                }
3983                74 => {
3984                    // Enable nitro attestation verify native move function for devnet
3985                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3986                        cfg.feature_flags.enable_nitro_attestation = true;
3987                    }
3988                    cfg.nitro_attestation_parse_base_cost = Some(53 * 50);
3989                    cfg.nitro_attestation_parse_cost_per_byte = Some(50);
3990                    cfg.nitro_attestation_verify_base_cost = Some(49632 * 50);
3991                    cfg.nitro_attestation_verify_cost_per_cert = Some(52369 * 50);
3992
3993                    // Enable zstd compression for consensus in mainnet
3994                    cfg.feature_flags.consensus_zstd_compression = true;
3995
3996                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3997                        cfg.feature_flags.consensus_linearize_subdag_v2 = true;
3998                    }
3999                }
4000                75 => {
4001                    if chain != Chain::Mainnet {
4002                        cfg.feature_flags.passkey_auth = true;
4003                    }
4004                }
4005                76 => {
4006                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4007                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4008                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4009                    }
4010                    cfg.feature_flags.minimize_child_object_mutations = true;
4011
4012                    if chain != Chain::Mainnet {
4013                        cfg.feature_flags.accept_passkey_in_multisig = true;
4014                    }
4015                }
4016                77 => {
4017                    cfg.feature_flags.uncompressed_g1_group_elements = true;
4018
4019                    if chain != Chain::Mainnet {
4020                        cfg.consensus_gc_depth = Some(60);
4021                        cfg.feature_flags.consensus_linearize_subdag_v2 = true;
4022                    }
4023                }
4024                78 => {
4025                    cfg.feature_flags.move_native_context = true;
4026                    cfg.tx_context_fresh_id_cost_base = Some(52);
4027                    cfg.tx_context_sender_cost_base = Some(30);
4028                    cfg.tx_context_epoch_cost_base = Some(30);
4029                    cfg.tx_context_epoch_timestamp_ms_cost_base = Some(30);
4030                    cfg.tx_context_sponsor_cost_base = Some(30);
4031                    cfg.tx_context_gas_price_cost_base = Some(30);
4032                    cfg.tx_context_gas_budget_cost_base = Some(30);
4033                    cfg.tx_context_ids_created_cost_base = Some(30);
4034                    cfg.tx_context_replace_cost_base = Some(30);
4035                    cfg.gas_model_version = Some(10);
4036
4037                    if chain != Chain::Mainnet {
4038                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4039                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4040
4041                        // Enable execution time estimate mode for congestion control on testnet.
4042                        cfg.feature_flags.per_object_congestion_control_mode =
4043                            PerObjectCongestionControlMode::ExecutionTimeEstimate(
4044                                ExecutionTimeEstimateParams {
4045                                    target_utilization: 30,
4046                                    allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4047                                    randomness_scalar: 20,
4048                                    max_estimate_us: 1_500_000, // 1.5s
4049                                    stored_observations_num_included_checkpoints: 10,
4050                                    stored_observations_limit: u64::MAX,
4051                                    stake_weighted_median_threshold: 0,
4052                                    default_none_duration_for_new_keys: false,
4053                                    observations_chunk_size: None,
4054                                },
4055                            );
4056                    }
4057                }
4058                79 => {
4059                    if chain != Chain::Mainnet {
4060                        cfg.feature_flags.consensus_median_based_commit_timestamp = true;
4061
4062                        // Increase threshold for bad nodes that won't be considered
4063                        // leaders in consensus in testnet
4064                        cfg.consensus_bad_nodes_stake_threshold = Some(30);
4065
4066                        cfg.feature_flags.consensus_batched_block_sync = true;
4067
4068                        // Enable verify nitro attestation in testnet.
4069                        cfg.feature_flags.enable_nitro_attestation = true
4070                    }
4071                    cfg.feature_flags.normalize_ptb_arguments = true;
4072
4073                    cfg.consensus_gc_depth = Some(60);
4074                    cfg.feature_flags.consensus_linearize_subdag_v2 = true;
4075                }
4076                80 => {
4077                    cfg.max_ptb_value_size = Some(1024 * 1024);
4078                }
4079                81 => {
4080                    cfg.feature_flags.consensus_median_based_commit_timestamp = true;
4081                    cfg.feature_flags.enforce_checkpoint_timestamp_monotonicity = true;
4082                    cfg.consensus_bad_nodes_stake_threshold = Some(30)
4083                }
4084                82 => {
4085                    cfg.feature_flags.max_ptb_value_size_v2 = true;
4086                }
4087                83 => {
4088                    if chain == Chain::Mainnet {
4089                        // The address that will sign the recovery transaction.
4090                        let aliased: [u8; 32] = Hex::decode(
4091                            "0x0b2da327ba6a4cacbe75dddd50e6e8bbf81d6496e92d66af9154c61c77f7332f",
4092                        )
4093                        .unwrap()
4094                        .try_into()
4095                        .unwrap();
4096
4097                        // Allow aliasing for the two addresses that contain stolen funds.
4098                        cfg.aliased_addresses.push(AliasedAddress {
4099                            original: Hex::decode("0xcd8962dad278d8b50fa0f9eb0186bfa4cbdecc6d59377214c88d0286a0ac9562").unwrap().try_into().unwrap(),
4100                            aliased,
4101                            allowed_tx_digests: vec![
4102                                Base58::decode("B2eGLFoMHgj93Ni8dAJBfqGzo8EWSTLBesZzhEpTPA4").unwrap().try_into().unwrap(),
4103                            ],
4104                        });
4105
4106                        cfg.aliased_addresses.push(AliasedAddress {
4107                            original: Hex::decode("0xe28b50cef1d633ea43d3296a3f6b67ff0312a5f1a99f0af753c85b8b5de8ff06").unwrap().try_into().unwrap(),
4108                            aliased,
4109                            allowed_tx_digests: vec![
4110                                Base58::decode("J4QqSAgp7VrQtQpMy5wDX4QGsCSEZu3U5KuDAkbESAge").unwrap().try_into().unwrap(),
4111                            ],
4112                        });
4113                    }
4114
4115                    // These features had to be deferred to v84 for mainnet in order to ship the recovery protocol
4116                    // upgrade as a patch to 1.48
4117                    if chain != Chain::Mainnet {
4118                        cfg.feature_flags.resolve_type_input_ids_to_defining_id = true;
4119                        cfg.transfer_party_transfer_internal_cost_base = Some(52);
4120
4121                        // Enable execution time estimate mode for congestion control on mainnet.
4122                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4123                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4124                        cfg.feature_flags.per_object_congestion_control_mode =
4125                            PerObjectCongestionControlMode::ExecutionTimeEstimate(
4126                                ExecutionTimeEstimateParams {
4127                                    target_utilization: 30,
4128                                    allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4129                                    randomness_scalar: 20,
4130                                    max_estimate_us: 1_500_000, // 1.5s
4131                                    stored_observations_num_included_checkpoints: 10,
4132                                    stored_observations_limit: u64::MAX,
4133                                    stake_weighted_median_threshold: 0,
4134                                    default_none_duration_for_new_keys: false,
4135                                    observations_chunk_size: None,
4136                                },
4137                            );
4138
4139                        // Enable the new depth-first block sync logic.
4140                        cfg.feature_flags.consensus_batched_block_sync = true;
4141
4142                        // Enable nitro attestation upgraded parsing logic and enable the
4143                        // native function on mainnet.
4144                        cfg.feature_flags.enable_nitro_attestation_upgraded_parsing = true;
4145                        cfg.feature_flags.enable_nitro_attestation = true;
4146                    }
4147                }
4148                84 => {
4149                    if chain == Chain::Mainnet {
4150                        cfg.feature_flags.resolve_type_input_ids_to_defining_id = true;
4151                        cfg.transfer_party_transfer_internal_cost_base = Some(52);
4152
4153                        // Enable execution time estimate mode for congestion control on mainnet.
4154                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4155                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4156                        cfg.feature_flags.per_object_congestion_control_mode =
4157                            PerObjectCongestionControlMode::ExecutionTimeEstimate(
4158                                ExecutionTimeEstimateParams {
4159                                    target_utilization: 30,
4160                                    allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4161                                    randomness_scalar: 20,
4162                                    max_estimate_us: 1_500_000, // 1.5s
4163                                    stored_observations_num_included_checkpoints: 10,
4164                                    stored_observations_limit: u64::MAX,
4165                                    stake_weighted_median_threshold: 0,
4166                                    default_none_duration_for_new_keys: false,
4167                                    observations_chunk_size: None,
4168                                },
4169                            );
4170
4171                        // Enable the new depth-first block sync logic.
4172                        cfg.feature_flags.consensus_batched_block_sync = true;
4173
4174                        // Enable nitro attestation upgraded parsing logic and enable the
4175                        // native function on mainnet.
4176                        cfg.feature_flags.enable_nitro_attestation_upgraded_parsing = true;
4177                        cfg.feature_flags.enable_nitro_attestation = true;
4178                    }
4179
4180                    // Limit the number of stored execution time observations at end of epoch.
4181                    cfg.feature_flags.per_object_congestion_control_mode =
4182                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4183                            ExecutionTimeEstimateParams {
4184                                target_utilization: 30,
4185                                allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4186                                randomness_scalar: 20,
4187                                max_estimate_us: 1_500_000, // 1.5s
4188                                stored_observations_num_included_checkpoints: 10,
4189                                stored_observations_limit: 20,
4190                                stake_weighted_median_threshold: 0,
4191                                default_none_duration_for_new_keys: false,
4192                                observations_chunk_size: None,
4193                            },
4194                        );
4195                    cfg.feature_flags.allow_unbounded_system_objects = true;
4196                }
4197                85 => {
4198                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4199                        cfg.feature_flags.enable_party_transfer = true;
4200                    }
4201
4202                    cfg.feature_flags
4203                        .record_consensus_determined_version_assignments_in_prologue_v2 = true;
4204                    cfg.feature_flags.disallow_self_identifier = true;
4205                    cfg.feature_flags.per_object_congestion_control_mode =
4206                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4207                            ExecutionTimeEstimateParams {
4208                                target_utilization: 50,
4209                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4210                                randomness_scalar: 20,
4211                                max_estimate_us: 1_500_000, // 1.5s
4212                                stored_observations_num_included_checkpoints: 10,
4213                                stored_observations_limit: 20,
4214                                stake_weighted_median_threshold: 0,
4215                                default_none_duration_for_new_keys: false,
4216                                observations_chunk_size: None,
4217                            },
4218                        );
4219                }
4220                86 => {
4221                    cfg.feature_flags.type_tags_in_object_runtime = true;
4222                    cfg.max_move_enum_variants = Some(move_core_types::VARIANT_COUNT_MAX);
4223
4224                    // Set a stake_weighted_median_threshold for congestion control.
4225                    cfg.feature_flags.per_object_congestion_control_mode =
4226                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4227                            ExecutionTimeEstimateParams {
4228                                target_utilization: 50,
4229                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4230                                randomness_scalar: 20,
4231                                max_estimate_us: 1_500_000, // 1.5s
4232                                stored_observations_num_included_checkpoints: 10,
4233                                stored_observations_limit: 20,
4234                                stake_weighted_median_threshold: 3334,
4235                                default_none_duration_for_new_keys: false,
4236                                observations_chunk_size: None,
4237                            },
4238                        );
4239                    // Enable party transfer for testnet.
4240                    if chain != Chain::Mainnet {
4241                        cfg.feature_flags.enable_party_transfer = true;
4242                    }
4243                }
4244                87 => {
4245                    if chain == Chain::Mainnet {
4246                        cfg.feature_flags.record_time_estimate_processed = true;
4247                    }
4248                    cfg.feature_flags.better_adapter_type_resolution_errors = true;
4249                }
4250                88 => {
4251                    cfg.feature_flags.record_time_estimate_processed = true;
4252                    cfg.tx_context_rgp_cost_base = Some(30);
4253                    cfg.feature_flags
4254                        .ignore_execution_time_observations_after_certs_closed = true;
4255
4256                    // Disable backwards compatible behavior in execution time estimator for
4257                    // new protocol version.
4258                    cfg.feature_flags.per_object_congestion_control_mode =
4259                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4260                            ExecutionTimeEstimateParams {
4261                                target_utilization: 50,
4262                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4263                                randomness_scalar: 20,
4264                                max_estimate_us: 1_500_000, // 1.5s
4265                                stored_observations_num_included_checkpoints: 10,
4266                                stored_observations_limit: 20,
4267                                stake_weighted_median_threshold: 3334,
4268                                default_none_duration_for_new_keys: true,
4269                                observations_chunk_size: None,
4270                            },
4271                        );
4272                }
4273                89 => {
4274                    cfg.feature_flags.dependency_linkage_error = true;
4275                    cfg.feature_flags.additional_multisig_checks = true;
4276                }
4277                90 => {
4278                    // 100x RGP
4279                    cfg.max_gas_price_rgp_factor_for_aborted_transactions = Some(100);
4280                    cfg.feature_flags.debug_fatal_on_move_invariant_violation = true;
4281                    cfg.feature_flags.additional_consensus_digest_indirect_state = true;
4282                    cfg.feature_flags.accept_passkey_in_multisig = true;
4283                    cfg.feature_flags.passkey_auth = true;
4284                    cfg.feature_flags.check_for_init_during_upgrade = true;
4285
4286                    // Enable Mysticeti fastpath handlers on testnet.
4287                    if chain != Chain::Mainnet {
4288                        cfg.feature_flags.mysticeti_fastpath = true;
4289                    }
4290                }
4291                91 => {
4292                    cfg.feature_flags.per_command_shared_object_transfer_rules = true;
4293                }
4294                92 => {
4295                    cfg.feature_flags.per_command_shared_object_transfer_rules = false;
4296                }
4297                93 => {
4298                    cfg.feature_flags
4299                        .consensus_checkpoint_signature_key_includes_digest = true;
4300                }
4301                94 => {
4302                    // Decrease stored observations limit 20->18 to stay within system object size limit.
4303                    cfg.feature_flags.per_object_congestion_control_mode =
4304                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4305                            ExecutionTimeEstimateParams {
4306                                target_utilization: 50,
4307                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4308                                randomness_scalar: 20,
4309                                max_estimate_us: 1_500_000, // 1.5s
4310                                stored_observations_num_included_checkpoints: 10,
4311                                stored_observations_limit: 18,
4312                                stake_weighted_median_threshold: 3334,
4313                                default_none_duration_for_new_keys: true,
4314                                observations_chunk_size: None,
4315                            },
4316                        );
4317
4318                    // Enable party transfer on mainnet.
4319                    cfg.feature_flags.enable_party_transfer = true;
4320                }
4321                95 => {
4322                    cfg.type_name_id_base_cost = Some(52);
4323
4324                    // Reduce the frequency of checkpoint splitting under high TPS.
4325                    cfg.max_transactions_per_checkpoint = Some(20_000);
4326                }
4327                96 => {
4328                    // Enable artifacts digest in devnet.
4329                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4330                        cfg.feature_flags
4331                            .include_checkpoint_artifacts_digest_in_summary = true;
4332                    }
4333                    cfg.feature_flags.correct_gas_payment_limit_check = true;
4334                    cfg.feature_flags.authority_capabilities_v2 = true;
4335                    cfg.feature_flags.use_mfp_txns_in_load_initial_object_debts = true;
4336                    cfg.feature_flags.cancel_for_failed_dkg_early = true;
4337                    cfg.feature_flags.enable_coin_registry = true;
4338
4339                    // Enable Mysticeti fastpath handlers on mainnet.
4340                    cfg.feature_flags.mysticeti_fastpath = true;
4341                }
4342                97 => {
4343                    cfg.feature_flags.additional_borrow_checks = true;
4344                }
4345                98 => {
4346                    cfg.event_emit_auth_stream_cost = Some(52);
4347                    cfg.feature_flags.better_loader_errors = true;
4348                    cfg.feature_flags.generate_df_type_layouts = true;
4349                }
4350                99 => {
4351                    cfg.feature_flags.use_new_commit_handler = true;
4352                }
4353                100 => {
4354                    cfg.feature_flags.private_generics_verifier_v2 = true;
4355                }
4356                101 => {
4357                    cfg.feature_flags.create_root_accumulator_object = true;
4358                    cfg.max_updates_per_settlement_txn = Some(100);
4359                    if chain != Chain::Mainnet {
4360                        cfg.feature_flags.enable_poseidon = true;
4361                    }
4362                }
4363                102 => {
4364                    // Enable execution time observation chunking and increase limit to 180.
4365                    // max_move_object_size is 250 KB, we've experientially determined that fits ~ 18 estimates
4366                    // so if we have 10 chunks, that's 2.5MB, < 8MB max_serialized_tx_effects_size_bytes_system_tx
4367                    cfg.feature_flags.per_object_congestion_control_mode =
4368                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4369                            ExecutionTimeEstimateParams {
4370                                target_utilization: 50,
4371                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4372                                randomness_scalar: 20,
4373                                max_estimate_us: 1_500_000, // 1.5s
4374                                stored_observations_num_included_checkpoints: 10,
4375                                stored_observations_limit: 180,
4376                                stake_weighted_median_threshold: 3334,
4377                                default_none_duration_for_new_keys: true,
4378                                observations_chunk_size: Some(18),
4379                            },
4380                        );
4381                    cfg.feature_flags.deprecate_global_storage_ops = true;
4382                }
4383                103 => {}
4384                104 => {
4385                    cfg.translation_per_command_base_charge = Some(1);
4386                    cfg.translation_per_input_base_charge = Some(1);
4387                    cfg.translation_pure_input_per_byte_charge = Some(1);
4388                    cfg.translation_per_type_node_charge = Some(1);
4389                    cfg.translation_per_reference_node_charge = Some(1);
4390                    cfg.translation_per_linkage_entry_charge = Some(10);
4391                    cfg.gas_model_version = Some(11);
4392                    cfg.feature_flags.abstract_size_in_object_runtime = true;
4393                    cfg.feature_flags.object_runtime_charge_cache_load_gas = true;
4394                    cfg.dynamic_field_hash_type_and_key_cost_base = Some(52);
4395                    cfg.dynamic_field_add_child_object_cost_base = Some(52);
4396                    cfg.dynamic_field_add_child_object_value_cost_per_byte = Some(1);
4397                    cfg.dynamic_field_borrow_child_object_cost_base = Some(52);
4398                    cfg.dynamic_field_borrow_child_object_child_ref_cost_per_byte = Some(1);
4399                    cfg.dynamic_field_remove_child_object_cost_base = Some(52);
4400                    cfg.dynamic_field_remove_child_object_child_cost_per_byte = Some(1);
4401                    cfg.dynamic_field_has_child_object_cost_base = Some(52);
4402                    cfg.dynamic_field_has_child_object_with_ty_cost_base = Some(52);
4403                    cfg.feature_flags.enable_ptb_execution_v2 = true;
4404
4405                    cfg.poseidon_bn254_cost_base = Some(260);
4406
4407                    cfg.feature_flags.consensus_skip_gced_accept_votes = true;
4408
4409                    if chain != Chain::Mainnet {
4410                        cfg.feature_flags
4411                            .enable_nitro_attestation_all_nonzero_pcrs_parsing = true;
4412                    }
4413
4414                    cfg.feature_flags
4415                        .include_cancelled_randomness_txns_in_prologue = true;
4416                }
4417                105 => {
4418                    cfg.feature_flags.enable_multi_epoch_transaction_expiration = true;
4419                    cfg.feature_flags.disable_preconsensus_locking = true;
4420
4421                    if chain != Chain::Mainnet {
4422                        cfg.feature_flags
4423                            .enable_nitro_attestation_always_include_required_pcrs_parsing = true;
4424                    }
4425                }
4426                106 => {
4427                    // est. 100 bytes per object * 76 (storage_gas_price)
4428                    cfg.accumulator_object_storage_cost = Some(7600);
4429
4430                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4431                        cfg.feature_flags.enable_accumulators = true;
4432                        cfg.feature_flags.enable_address_balance_gas_payments = true;
4433                        cfg.feature_flags.enable_authenticated_event_streams = true;
4434                        cfg.feature_flags.enable_object_funds_withdraw = true;
4435                    }
4436                }
4437                107 => {
4438                    cfg.feature_flags
4439                        .consensus_skip_gced_blocks_in_direct_finalization = true;
4440
4441                    // Trigger edge cases more often in integration tests.
4442                    if in_integration_test() {
4443                        cfg.consensus_gc_depth = Some(6);
4444                        cfg.consensus_max_num_transactions_in_block = Some(8);
4445                    }
4446                }
4447                108 => {
4448                    cfg.feature_flags.gas_rounding_halve_digits = true;
4449                    cfg.feature_flags.flexible_tx_context_positions = true;
4450                    cfg.feature_flags.disable_entry_point_signature_check = true;
4451
4452                    if chain != Chain::Mainnet {
4453                        cfg.feature_flags.address_aliases = true;
4454
4455                        cfg.feature_flags.enable_accumulators = true;
4456                        cfg.feature_flags.enable_address_balance_gas_payments = true;
4457                    }
4458
4459                    cfg.feature_flags.enable_poseidon = true;
4460                }
4461                109 => {
4462                    cfg.binary_variant_handles = Some(1024);
4463                    cfg.binary_variant_instantiation_handles = Some(1024);
4464                    cfg.feature_flags.restrict_hot_or_not_entry_functions = true;
4465                }
4466                110 => {
4467                    cfg.feature_flags
4468                        .enable_nitro_attestation_all_nonzero_pcrs_parsing = true;
4469                    cfg.feature_flags
4470                        .enable_nitro_attestation_always_include_required_pcrs_parsing = true;
4471                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4472                        cfg.feature_flags.split_checkpoints_in_consensus_handler = true;
4473                    }
4474                    cfg.feature_flags.validate_zklogin_public_identifier = true;
4475                    cfg.feature_flags.fix_checkpoint_signature_mapping = true;
4476                    cfg.feature_flags
4477                        .consensus_always_accept_system_transactions = true;
4478                    if chain != Chain::Mainnet {
4479                        cfg.feature_flags.enable_object_funds_withdraw = true;
4480                    }
4481                }
4482                111 => {
4483                    cfg.feature_flags.validator_metadata_verify_v2 = true;
4484                }
4485                112 => {
4486                    cfg.group_ops_ristretto_decode_scalar_cost = Some(7);
4487                    cfg.group_ops_ristretto_decode_point_cost = Some(200);
4488                    cfg.group_ops_ristretto_scalar_add_cost = Some(10);
4489                    cfg.group_ops_ristretto_point_add_cost = Some(500);
4490                    cfg.group_ops_ristretto_scalar_sub_cost = Some(10);
4491                    cfg.group_ops_ristretto_point_sub_cost = Some(500);
4492                    cfg.group_ops_ristretto_scalar_mul_cost = Some(11);
4493                    cfg.group_ops_ristretto_point_mul_cost = Some(1200);
4494                    cfg.group_ops_ristretto_scalar_div_cost = Some(151);
4495                    cfg.group_ops_ristretto_point_div_cost = Some(2500);
4496
4497                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4498                        cfg.feature_flags.enable_ristretto255_group_ops = true;
4499                    }
4500                }
4501                113 => {
4502                    cfg.feature_flags.address_balance_gas_check_rgp_at_signing = true;
4503                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4504                        cfg.feature_flags.defer_unpaid_amplification = true;
4505                    }
4506                }
4507                114 => {
4508                    cfg.feature_flags.randomize_checkpoint_tx_limit_in_tests = true;
4509                    cfg.feature_flags.address_balance_gas_reject_gas_coin_arg = true;
4510                    if chain != Chain::Mainnet {
4511                        cfg.feature_flags.split_checkpoints_in_consensus_handler = true;
4512                        cfg.feature_flags.enable_authenticated_event_streams = true;
4513                        cfg.feature_flags
4514                            .include_checkpoint_artifacts_digest_in_summary = true;
4515                    }
4516                }
4517                115 => {
4518                    cfg.feature_flags.normalize_depth_formula = true;
4519                }
4520                116 => {
4521                    cfg.feature_flags.gasless_transaction_drop_safety = true;
4522                    cfg.feature_flags.address_aliases = true;
4523                    cfg.feature_flags.relax_valid_during_for_owned_inputs = true;
4524                    // Disabled while debugging
4525                    cfg.feature_flags.defer_unpaid_amplification = false;
4526                    cfg.feature_flags.enable_display_registry = true;
4527                }
4528                117 => {}
4529                118 => {
4530                    cfg.feature_flags.use_coin_party_owner = true;
4531                }
4532                119 => {
4533                    // Enable new VM.
4534                    cfg.execution_version = Some(4);
4535                    cfg.feature_flags.address_balance_gas_reject_gas_coin_arg = false;
4536                    cfg.feature_flags.merge_randomness_into_checkpoint = true;
4537                    if chain != Chain::Mainnet {
4538                        cfg.feature_flags.enable_gasless = true;
4539                        cfg.gasless_max_computation_units = Some(50_000);
4540                        cfg.gasless_allowed_token_types = Some(vec![]);
4541                        cfg.feature_flags.enable_coin_reservation_obj_refs = true;
4542                        cfg.feature_flags
4543                            .convert_withdrawal_compatibility_ptb_arguments = true;
4544                    }
4545                    cfg.gasless_max_unused_inputs = Some(1);
4546                    cfg.gasless_max_pure_input_bytes = Some(32);
4547                    if chain == Chain::Testnet {
4548                        cfg.gasless_allowed_token_types = Some(vec![(TESTNET_USDC.to_string(), 0)]);
4549                    }
4550                    cfg.transfer_receive_object_cost_per_byte = Some(1);
4551                    cfg.transfer_receive_object_type_cost_per_byte = Some(2);
4552                }
4553                120 => {
4554                    cfg.feature_flags.disallow_jump_orphans = true;
4555                }
4556                121 => {
4557                    // Re-enable unpaid amplification deferral protection (testnet + devnet)
4558                    if chain != Chain::Mainnet {
4559                        cfg.feature_flags.defer_unpaid_amplification = true;
4560                        cfg.gasless_max_tps = Some(50);
4561                    }
4562                    cfg.feature_flags
4563                        .early_return_receive_object_mismatched_type = true;
4564                }
4565                122 => {
4566                    // Enable unpaid amplification deferral on mainnet
4567                    cfg.feature_flags.defer_unpaid_amplification = true;
4568                    // Enable bulletproofs range proofs on devnet
4569                    cfg.verify_bulletproofs_ristretto255_base_cost = Some(30000);
4570                    cfg.verify_bulletproofs_ristretto255_cost_per_bit_and_commitment = Some(6500);
4571                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4572                        cfg.feature_flags.enable_verify_bulletproofs_ristretto255 = true;
4573                    }
4574                    cfg.feature_flags.gasless_verify_remaining_balance = true;
4575                    cfg.include_special_package_amendments = match chain {
4576                        Chain::Mainnet => Some(MAINNET_LINKAGE_AMENDMENTS.clone()),
4577                        Chain::Testnet => Some(TESTNET_LINKAGE_AMENDMENTS.clone()),
4578                        Chain::Unknown => None,
4579                    };
4580                    cfg.gasless_max_tx_size_bytes = Some(16 * 1024);
4581                    cfg.gasless_max_tps = Some(300);
4582                    cfg.gasless_max_computation_units = Some(5_000);
4583                }
4584                123 => {
4585                    cfg.gas_model_version = Some(13);
4586                }
4587                124 => {
4588                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4589                        cfg.feature_flags.timestamp_based_epoch_close = true;
4590                    }
4591                    cfg.gas_model_version = Some(14);
4592                    cfg.feature_flags.limit_groth16_pvk_inputs = true;
4593
4594                    // Bring mainnet in line with testnet: enable address balances, the
4595                    // gasless "free tier", coin reservations, and the rest of the
4596                    // accumulator/withdraw stack. These are all already enabled on
4597                    // testnet and devnet, so setting them unconditionally is a no-op
4598                    // there.
4599                    cfg.feature_flags.enable_accumulators = true;
4600                    cfg.feature_flags.enable_address_balance_gas_payments = true;
4601                    cfg.feature_flags.enable_authenticated_event_streams = true;
4602                    cfg.feature_flags.enable_coin_reservation_obj_refs = true;
4603                    cfg.feature_flags.enable_object_funds_withdraw = true;
4604                    cfg.feature_flags
4605                        .convert_withdrawal_compatibility_ptb_arguments = true;
4606                    cfg.feature_flags.split_checkpoints_in_consensus_handler = true;
4607                    cfg.feature_flags
4608                        .include_checkpoint_artifacts_digest_in_summary = true;
4609                    cfg.feature_flags.enable_gasless = true;
4610
4611                    // Set the mainnet allow-list. Testnet already has its USDC entry
4612                    // from v119, so only set this on mainnet to avoid clobbering the
4613                    // testnet value. $0.01 minimum transfer per stable; all listed
4614                    // tokens have 6 decimals.
4615                    if chain == Chain::Mainnet {
4616                        cfg.gasless_allowed_token_types = Some(vec![
4617                            (MAINNET_USDC.to_string(), 10_000),
4618                            (MAINNET_USDSUI.to_string(), 10_000),
4619                            (MAINNET_SUI_USDE.to_string(), 10_000),
4620                            (MAINNET_USDY.to_string(), 10_000),
4621                            (MAINNET_FDUSD.to_string(), 10_000),
4622                            (MAINNET_AUSD.to_string(), 10_000),
4623                            (MAINNET_USDB.to_string(), 10_000),
4624                        ]);
4625                    }
4626                }
4627                125 => {
4628                    cfg.feature_flags.granular_post_execution_checks = true;
4629                    if chain != Chain::Mainnet {
4630                        cfg.feature_flags.timestamp_based_epoch_close = true;
4631                    }
4632                }
4633                126 => {
4634                    cfg.feature_flags.early_exit_on_iffw = true;
4635                }
4636                127 => {
4637                    cfg.feature_flags.always_advance_dkg_to_resolution = true;
4638
4639                    cfg.verify_bulletproofs_ristretto255_base_cost = Some(23866);
4640                    cfg.verify_bulletproofs_ristretto255_cost_per_bit_and_commitment = Some(1324);
4641                    cfg.group_ops_ristretto_decode_scalar_cost = Some(5);
4642                    cfg.group_ops_ristretto_decode_point_cost = Some(216);
4643                    cfg.group_ops_ristretto_scalar_add_cost = Some(2);
4644                    cfg.group_ops_ristretto_point_add_cost = Some(8);
4645                    cfg.group_ops_ristretto_scalar_sub_cost = Some(2);
4646                    cfg.group_ops_ristretto_point_sub_cost = Some(8);
4647                    cfg.group_ops_ristretto_scalar_mul_cost = Some(5);
4648                    cfg.group_ops_ristretto_point_mul_cost = Some(1763);
4649                    cfg.group_ops_ristretto_scalar_div_cost = Some(557);
4650                    cfg.group_ops_ristretto_point_div_cost = Some(2244);
4651
4652                    if chain != Chain::Mainnet {
4653                        cfg.feature_flags.enable_ristretto255_group_ops = true;
4654                        cfg.feature_flags.enable_verify_bulletproofs_ristretto255 = true;
4655                    }
4656
4657                    cfg.feature_flags.timestamp_based_epoch_close = true;
4658                }
4659                128 => {
4660                    cfg.max_generic_instantiation_type_nodes_per_function = Some(10_000);
4661                    cfg.max_generic_instantiation_type_nodes_per_module = Some(500_000);
4662                    cfg.binary_enum_defs = Some(200);
4663                    cfg.binary_enum_def_instantiations = Some(100);
4664                }
4665                129 => {
4666                    cfg.feature_flags.enable_unified_linkage = true;
4667                }
4668                130 => {
4669                    cfg.feature_flags.record_net_unsettled_object_withdraws = true;
4670                    cfg.feature_flags.enable_init_on_upgrade = true;
4671                    cfg.epoch_close_deadline_ms = Some(120_000);
4672                    cfg.scratch_add_cost_base = Some(13);
4673                    cfg.scratch_read_cost_base = Some(13);
4674                    cfg.scratch_read_value_cost = Some(1);
4675                    cfg.scratch_remove_cost_base = Some(13);
4676                    cfg.scratch_exists_cost_base = Some(13);
4677                    cfg.scratch_exists_with_type_cost_base = Some(13);
4678                    cfg.scratch_exists_with_type_type_cost = Some(1);
4679                    let max_commands = cfg.max_programmable_tx_commands() as u64;
4680                    cfg.max_scratch_pad_size = Some(16 * max_commands);
4681                    // Verify with the v2 then v1 for devnet.
4682                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4683                        cfg.feature_flags.zklogin_circuit_mode = 1;
4684                    }
4685                }
4686                131 => {
4687                    cfg.feature_flags.share_transaction_deny_config_in_consensus = true;
4688                    cfg.feature_flags.framework_tx_context_mut_restrictions = true;
4689                }
4690                132 => {
4691                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4692                        cfg.feature_flags.defer_owned_object_double_spend = true;
4693                        cfg.feature_flags.create_forwarding_address_registry = true;
4694                    }
4695                    cfg.object_record_new_uid_from_hash_cost_base = Some(1);
4696                    cfg.feature_flags
4697                        .enable_order_independent_upgrade_init_linkage = true;
4698                }
4699                133 => {
4700                    cfg.feature_flags
4701                        .include_function_signatures_in_instantiation_limits = true;
4702                    cfg.max_accumulator_type_nodes = Some(16);
4703                }
4704                134 => {
4705                    // v134 was released to testnet with this content before the 1.77
4706                    // branch backfilled its own v134 to disable defer_unpaid_amplification
4707                    // on mainnet. To keep (v134, Mainnet) identical across the 1.77 and
4708                    // 1.78 branches, the original v134 content is gated off mainnet here
4709                    // (it applies to mainnet in v135 instead), and mainnet's v134 carries
4710                    // only the deferral disable.
4711                    if chain != Chain::Mainnet {
4712                        cfg.package_original_package_id_impl_cost_base = Some(52);
4713                        let package_read_cost_per_byte = cfg.obj_access_cost_read_per_byte();
4714                        cfg.package_original_package_id_impl_cost_per_byte =
4715                            Some(package_read_cost_per_byte);
4716
4717                        cfg.consensus_max_transactions_in_block_bytes = Some(288 * 1024);
4718                        cfg.consensus_max_num_transactions_in_block = Some(128);
4719                    }
4720
4721                    if chain == Chain::Mainnet {
4722                        cfg.feature_flags.defer_unpaid_amplification = false;
4723                    }
4724                }
4725                135 => {
4726                    // Apply the original v134 content on mainnet (no-op re-assignment on
4727                    // chains that already applied it in v134).
4728                    cfg.package_original_package_id_impl_cost_base = Some(52);
4729                    let package_read_cost_per_byte = cfg.obj_access_cost_read_per_byte();
4730                    cfg.package_original_package_id_impl_cost_per_byte =
4731                        Some(package_read_cost_per_byte);
4732
4733                    cfg.consensus_max_transactions_in_block_bytes = Some(288 * 1024);
4734                    cfg.consensus_max_num_transactions_in_block = Some(128);
4735
4736                    cfg.feature_flags.defer_unpaid_amplification = false;
4737                }
4738                136 => {
4739                    cfg.feature_flags.ptb_tx_context_restrictions = true;
4740
4741                    cfg.translation_per_live_reference_charge = Some(1);
4742                    cfg.max_ptb_live_references = Some(64);
4743                    cfg.max_ptb_returned_references = Some(16);
4744                    cfg.max_ptb_total_returned_references = Some(256);
4745
4746                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4747                        cfg.feature_flags.allowed_proposers = true;
4748                    }
4749                    cfg.feature_flags.harden_linkage_consistency = true;
4750
4751                    cfg.package_arena_size_in_bytes = Some(10_000_000);
4752                }
4753                137 => {
4754                    cfg.verify_bulletproofs_ristretto255_cost_per_bit_and_commitment = Some(621);
4755                    cfg.max_bulletproofs_total_bits = Some(1024);
4756
4757                    cfg.feature_flags.enable_allowances = true;
4758                    cfg.feature_flags.fix_ptb_generated_reads = true;
4759                    cfg.feature_flags.charge_ld_const_abstract_size = true;
4760                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4761                        cfg.feature_flags.check_object_funds_withdraw_in_execution = true;
4762                    }
4763                    cfg.reserve_object_funds_for_withdrawal_cost_base = Some(52);
4764                    // Equivalent to the fixed portion of a dynamic-field lookup (52 + 52) plus
4765                    // loading the 80-byte accumulator field contents at one gas unit per byte.
4766                    cfg.reserve_object_funds_for_withdrawal_cold_read_cost = Some(184);
4767
4768                    cfg.feature_flags.allowed_proposers = true;
4769
4770                    cfg.feature_flags.validate_ptb_argument_indices = true;
4771                    cfg.feature_flags.memory_safety_invariant_check_v2 = true;
4772                }
4773                138 => {
4774                    cfg.gas_model_version = Some(15);
4775                }
4776                // Use this template when making changes:
4777                //
4778                //     // modify an existing constant.
4779                //     move_binary_format_version: Some(7),
4780                //
4781                //     // Add a new constant (which is set to None in prior versions).
4782                //     new_constant: Some(new_value),
4783                //
4784                //     // Remove a constant (ensure that it is never accessed during this version).
4785                //     max_move_object_size: None,
4786                _ => panic!("unsupported version {:?}", version),
4787            }
4788        }
4789
4790        cfg
4791    }
4792
4793    pub fn apply_seeded_test_overrides(&mut self, seed: &[u8; 32]) {
4794        if !self.feature_flags.randomize_checkpoint_tx_limit_in_tests
4795            || !self.feature_flags.split_checkpoints_in_consensus_handler
4796        {
4797            return;
4798        }
4799
4800        if !mysten_common::in_test_configuration() {
4801            return;
4802        }
4803
4804        use rand::{Rng, SeedableRng, rngs::StdRng};
4805        let mut rng = StdRng::from_seed(*seed);
4806        let max_txns = rng.gen_range(10..=100u64);
4807        info!("seeded test override: max_transactions_per_checkpoint = {max_txns}");
4808        self.max_transactions_per_checkpoint = Some(max_txns);
4809    }
4810
4811    // Extract the bytecode verifier config from this protocol config.
4812    // If used during signing, `signing_limits` should be set.
4813    // The third limit configures`sanity_check_with_regex_reference_safety`,
4814    // which runs the new regex-based reference safety check to check that it is strictly more
4815    // permissive than the current implementation.
4816    pub fn verifier_config(&self, signing_limits: Option<(usize, usize, usize)>) -> VerifierConfig {
4817        let (
4818            max_back_edges_per_function,
4819            max_back_edges_per_module,
4820            sanity_check_with_regex_reference_safety,
4821        ) = if let Some((
4822            max_back_edges_per_function,
4823            max_back_edges_per_module,
4824            sanity_check_with_regex_reference_safety,
4825        )) = signing_limits
4826        {
4827            (
4828                Some(max_back_edges_per_function),
4829                Some(max_back_edges_per_module),
4830                Some(sanity_check_with_regex_reference_safety),
4831            )
4832        } else {
4833            (None, None, None)
4834        };
4835
4836        let additional_borrow_checks = if signing_limits.is_some() {
4837            // always turn on additional borrow checks during signing
4838            true
4839        } else {
4840            self.additional_borrow_checks()
4841        };
4842        let deprecate_global_storage_ops = if signing_limits.is_some() {
4843            // always turn on additional vector borrow checks during signing
4844            true
4845        } else {
4846            self.deprecate_global_storage_ops()
4847        };
4848
4849        VerifierConfig {
4850            max_loop_depth: Some(self.max_loop_depth() as usize),
4851            max_generic_instantiation_length: Some(self.max_generic_instantiation_length() as usize),
4852            max_function_parameters: Some(self.max_function_parameters() as usize),
4853            max_basic_blocks: Some(self.max_basic_blocks() as usize),
4854            max_value_stack_size: self.max_value_stack_size() as usize,
4855            max_type_nodes: Some(self.max_type_nodes() as usize),
4856            max_generic_instantiation_type_nodes_per_function: self
4857                .max_generic_instantiation_type_nodes_per_function_as_option()
4858                .map(|v| v as usize),
4859            max_generic_instantiation_type_nodes_per_module: self
4860                .max_generic_instantiation_type_nodes_per_module_as_option()
4861                .map(|v| v as usize),
4862            include_function_signatures_in_instantiation_limits: self
4863                .include_function_signatures_in_instantiation_limits(),
4864            max_push_size: Some(self.max_push_size() as usize),
4865            max_dependency_depth: Some(self.max_dependency_depth() as usize),
4866            max_fields_in_struct: Some(self.max_fields_in_struct() as usize),
4867            max_function_definitions: Some(self.max_function_definitions() as usize),
4868            max_data_definitions: Some(self.max_struct_definitions() as usize),
4869            max_constant_vector_len: Some(self.max_move_vector_len()),
4870            max_back_edges_per_function,
4871            max_back_edges_per_module,
4872            max_basic_blocks_in_script: None,
4873            max_identifier_len: self.max_move_identifier_len_as_option(), // Before protocol version 9, there was no limit
4874            disallow_self_identifier: self.feature_flags.disallow_self_identifier,
4875            allow_receiving_object_id: self.allow_receiving_object_id(),
4876            reject_mutable_random_on_entry_functions: self
4877                .reject_mutable_random_on_entry_functions(),
4878            bytecode_version: self.move_binary_format_version(),
4879            max_variants_in_enum: self.max_move_enum_variants_as_option(),
4880            additional_borrow_checks,
4881            better_loader_errors: self.better_loader_errors(),
4882            private_generics_verifier_v2: self.private_generics_verifier_v2(),
4883            sanity_check_with_regex_reference_safety: sanity_check_with_regex_reference_safety
4884                .map(|limit| limit as u128),
4885            deprecate_global_storage_ops,
4886            disable_entry_point_signature_check: self.disable_entry_point_signature_check(),
4887            switch_to_regex_reference_safety: false,
4888            framework_tx_context_mut_restrictions: self.framework_tx_context_mut_restrictions(),
4889            disallow_jump_orphans: self.disallow_jump_orphans(),
4890        }
4891    }
4892
4893    pub fn binary_config(
4894        &self,
4895        override_deprecate_global_storage_ops_during_deserialization: Option<bool>,
4896    ) -> BinaryConfig {
4897        let deprecate_global_storage_ops =
4898            override_deprecate_global_storage_ops_during_deserialization
4899                .unwrap_or_else(|| self.deprecate_global_storage_ops());
4900        BinaryConfig::new(
4901            self.move_binary_format_version(),
4902            self.min_move_binary_format_version_as_option()
4903                .unwrap_or(VERSION_1),
4904            self.no_extraneous_module_bytes(),
4905            deprecate_global_storage_ops,
4906            TableConfig {
4907                module_handles: self.binary_module_handles_as_option().unwrap_or(u16::MAX),
4908                datatype_handles: self.binary_struct_handles_as_option().unwrap_or(u16::MAX),
4909                function_handles: self.binary_function_handles_as_option().unwrap_or(u16::MAX),
4910                function_instantiations: self
4911                    .binary_function_instantiations_as_option()
4912                    .unwrap_or(u16::MAX),
4913                signatures: self.binary_signatures_as_option().unwrap_or(u16::MAX),
4914                constant_pool: self.binary_constant_pool_as_option().unwrap_or(u16::MAX),
4915                identifiers: self.binary_identifiers_as_option().unwrap_or(u16::MAX),
4916                address_identifiers: self
4917                    .binary_address_identifiers_as_option()
4918                    .unwrap_or(u16::MAX),
4919                struct_defs: self.binary_struct_defs_as_option().unwrap_or(u16::MAX),
4920                struct_def_instantiations: self
4921                    .binary_struct_def_instantiations_as_option()
4922                    .unwrap_or(u16::MAX),
4923                function_defs: self.binary_function_defs_as_option().unwrap_or(u16::MAX),
4924                field_handles: self.binary_field_handles_as_option().unwrap_or(u16::MAX),
4925                field_instantiations: self
4926                    .binary_field_instantiations_as_option()
4927                    .unwrap_or(u16::MAX),
4928                friend_decls: self.binary_friend_decls_as_option().unwrap_or(u16::MAX),
4929                enum_defs: self.binary_enum_defs_as_option().unwrap_or(u16::MAX),
4930                enum_def_instantiations: self
4931                    .binary_enum_def_instantiations_as_option()
4932                    .unwrap_or(u16::MAX),
4933                variant_handles: self.binary_variant_handles_as_option().unwrap_or(u16::MAX),
4934                variant_instantiation_handles: self
4935                    .binary_variant_instantiation_handles_as_option()
4936                    .unwrap_or(u16::MAX),
4937            },
4938        )
4939    }
4940
4941    /// Override one or more settings in the config, for testing.
4942    /// This must be called at the beginning of the test, before get_for_(min|max)_version is
4943    /// called, since those functions cache their return value.
4944    pub fn apply_overrides_for_testing(
4945        override_fn: impl Fn(ProtocolVersion, Self) -> Self + Send + Sync + 'static,
4946    ) -> OverrideGuard {
4947        let mut cur = CONFIG_OVERRIDE.lock().unwrap();
4948        assert!(cur.is_none(), "config override already present");
4949        *cur = Some(Box::new(override_fn));
4950        OverrideGuard
4951    }
4952
4953    fn apply_config_override(version: ProtocolVersion, mut ret: Self) -> Self {
4954        if let Some(override_fn) = CONFIG_OVERRIDE.lock().unwrap().as_ref() {
4955            warn!(
4956                "overriding ProtocolConfig settings with custom settings (you should not see this log outside of tests)"
4957            );
4958            ret = override_fn(version, ret);
4959        }
4960        ret
4961    }
4962}
4963
4964// Setters for tests.
4965// This is only needed for feature_flags. Please suffix each setter with `_for_testing`.
4966// Non-feature_flags should already have test setters defined through macros.
4967impl ProtocolConfig {
4968    // Hand-written (the field is marked #[custom_setter]) to forbid downgrades: an executor
4969    // older than the config's protocol version can't link the frameworks of later versions —
4970    // its natives tables are frozen. Upgrades are allowed for replay's executor override.
4971    pub fn set_execution_version_for_testing(&mut self, val: u64) {
4972        let current = self.execution_version.unwrap_or(0);
4973        assert!(
4974            val >= current,
4975            "cannot downgrade execution_version from {current} to {val}: running an old \
4976             executor against a newer protocol config/framework is unsupported. To test \
4977             frozen executor behavior, start from the last protocol version of that executor \
4978             instead, so genesis loads the matching framework snapshot (see \
4979             test_address_balance_gas_v3_accumulator_sign)."
4980        );
4981        self.execution_version = Some(val);
4982    }
4983
4984    // Not generated by the feature-flags derive because zklogin_circuit_mode is a u64
4985    // flag (the macro only generates setters for bool flags).
4986    pub fn set_zklogin_circuit_mode_for_testing(&mut self, val: u64) {
4987        self.feature_flags.zklogin_circuit_mode = val
4988    }
4989
4990    pub fn set_per_object_congestion_control_mode_for_testing(
4991        &mut self,
4992        val: PerObjectCongestionControlMode,
4993    ) {
4994        self.feature_flags.per_object_congestion_control_mode = val;
4995    }
4996
4997    pub fn set_consensus_choice_for_testing(&mut self, val: ConsensusChoice) {
4998        self.feature_flags.consensus_choice = val;
4999    }
5000
5001    pub fn set_consensus_network_for_testing(&mut self, val: ConsensusNetwork) {
5002        self.feature_flags.consensus_network = val;
5003    }
5004
5005    pub fn set_zklogin_max_epoch_upper_bound_delta_for_testing(&mut self, val: Option<u64>) {
5006        self.feature_flags.zklogin_max_epoch_upper_bound_delta = val
5007    }
5008
5009    pub fn set_mysticeti_num_leaders_per_round_for_testing(&mut self, val: Option<usize>) {
5010        self.feature_flags.mysticeti_num_leaders_per_round = val;
5011    }
5012
5013    pub fn disable_accumulators_for_testing(&mut self) {
5014        self.feature_flags.enable_accumulators = false;
5015        self.feature_flags.enable_address_balance_gas_payments = false;
5016    }
5017
5018    pub fn enable_coin_reservation_for_testing(&mut self) {
5019        self.feature_flags.enable_coin_reservation_obj_refs = true;
5020        self.feature_flags
5021            .convert_withdrawal_compatibility_ptb_arguments = true;
5022        // Ensure execution_version >= 4 so new_vm_enabled() returns true,
5023        // which is required for enable_coin_reservation_obj_refs() to return true.
5024        self.execution_version = Some(self.execution_version.map_or(4, |v| v.max(4)));
5025    }
5026
5027    pub fn disable_coin_reservation_for_testing(&mut self) {
5028        self.feature_flags.enable_coin_reservation_obj_refs = false;
5029        self.feature_flags
5030            .convert_withdrawal_compatibility_ptb_arguments = false;
5031    }
5032
5033    pub fn enable_address_balance_gas_payments_for_testing(&mut self) {
5034        self.feature_flags.enable_accumulators = true;
5035        self.feature_flags.allow_private_accumulator_entrypoints = true;
5036        self.feature_flags.enable_address_balance_gas_payments = true;
5037        self.feature_flags.address_balance_gas_check_rgp_at_signing = true;
5038        self.feature_flags.address_balance_gas_reject_gas_coin_arg = false;
5039        self.execution_version = Some(self.execution_version.map_or(4, |v| v.max(4)))
5040    }
5041
5042    pub fn enable_gasless_for_testing(&mut self) {
5043        self.enable_address_balance_gas_payments_for_testing();
5044        self.feature_flags.enable_gasless = true;
5045        self.feature_flags.gasless_verify_remaining_balance = true;
5046        self.gasless_max_computation_units = Some(5_000);
5047        self.gasless_allowed_token_types = Some(vec![]);
5048        self.gasless_max_tps = Some(1000);
5049        self.gasless_max_tx_size_bytes = Some(16 * 1024);
5050    }
5051
5052    pub fn disable_gasless_for_testing(&mut self) {
5053        self.feature_flags.enable_gasless = false;
5054        self.gasless_max_computation_units = None;
5055        self.gasless_allowed_token_types = None;
5056    }
5057
5058    pub fn enable_authenticated_event_streams_for_testing(&mut self) {
5059        self.feature_flags.enable_accumulators = true;
5060        self.feature_flags.enable_authenticated_event_streams = true;
5061        self.feature_flags
5062            .include_checkpoint_artifacts_digest_in_summary = true;
5063        self.feature_flags.split_checkpoints_in_consensus_handler = true;
5064    }
5065}
5066
5067type OverrideFn = dyn Fn(ProtocolVersion, ProtocolConfig) -> ProtocolConfig + Send + Sync;
5068
5069static CONFIG_OVERRIDE: Mutex<Option<Box<OverrideFn>>> = Mutex::new(None);
5070
5071#[must_use]
5072pub struct OverrideGuard;
5073
5074impl Drop for OverrideGuard {
5075    fn drop(&mut self) {
5076        info!("restoring override fn");
5077        *CONFIG_OVERRIDE.lock().unwrap() = None;
5078    }
5079}
5080
5081/// Defines which limit got crossed.
5082/// The value which crossed the limit and value of the limit crossed are embedded
5083#[derive(PartialEq, Eq)]
5084pub enum LimitThresholdCrossed {
5085    None,
5086    Soft(u128, u128),
5087    Hard(u128, u128),
5088}
5089
5090/// Convenience function for comparing limit ranges
5091/// V::MAX must be at >= U::MAX and T::MAX
5092pub fn check_limit_in_range<T: Into<V>, U: Into<V>, V: PartialOrd + Into<u128>>(
5093    x: T,
5094    soft_limit: U,
5095    hard_limit: V,
5096) -> LimitThresholdCrossed {
5097    let x: V = x.into();
5098    let soft_limit: V = soft_limit.into();
5099
5100    debug_assert!(soft_limit <= hard_limit);
5101
5102    // It is important to preserve this comparison order because if soft_limit == hard_limit
5103    // we want LimitThresholdCrossed::Hard
5104    if x >= hard_limit {
5105        LimitThresholdCrossed::Hard(x.into(), hard_limit.into())
5106    } else if x < soft_limit {
5107        LimitThresholdCrossed::None
5108    } else {
5109        LimitThresholdCrossed::Soft(x.into(), soft_limit.into())
5110    }
5111}
5112
5113#[macro_export]
5114macro_rules! check_limit {
5115    ($x:expr, $hard:expr) => {
5116        check_limit!($x, $hard, $hard)
5117    };
5118    ($x:expr, $soft:expr, $hard:expr) => {
5119        check_limit_in_range($x as u64, $soft, $hard)
5120    };
5121}
5122
5123/// Used to check which limits were crossed if the TX is metered (not system tx)
5124/// Args are: is_metered, value_to_check, metered_limit, unmetered_limit
5125/// metered_limit is always less than or equal to unmetered_hard_limit
5126#[macro_export]
5127macro_rules! check_limit_by_meter {
5128    ($is_metered:expr, $x:expr, $metered_limit:expr, $unmetered_hard_limit:expr, $metric:expr) => {{
5129        // If this is metered, we use the metered_limit limit as the upper bound
5130        let (h, metered_str) = if $is_metered {
5131            ($metered_limit, "metered")
5132        } else {
5133            // Unmetered gets more headroom
5134            ($unmetered_hard_limit, "unmetered")
5135        };
5136        use sui_protocol_config::check_limit_in_range;
5137        let result = check_limit_in_range($x as u64, $metered_limit, h);
5138        match result {
5139            LimitThresholdCrossed::None => {}
5140            LimitThresholdCrossed::Soft(_, _) => {
5141                $metric.with_label_values(&[metered_str, "soft"]).inc();
5142            }
5143            LimitThresholdCrossed::Hard(_, _) => {
5144                $metric.with_label_values(&[metered_str, "hard"]).inc();
5145            }
5146        };
5147        result
5148    }};
5149}
5150
5151// Amendments tables
5152
5153pub type Amendments = BTreeMap<AccountAddress, BTreeMap<AccountAddress, AccountAddress>>;
5154
5155static MAINNET_LINKAGE_AMENDMENTS: LazyLock<Arc<Amendments>> =
5156    LazyLock::new(|| parse_amendments(include_str!("mainnet_amendments.json")));
5157
5158static TESTNET_LINKAGE_AMENDMENTS: LazyLock<Arc<Amendments>> =
5159    LazyLock::new(|| parse_amendments(include_str!("testnet_amendments.json")));
5160
5161fn parse_amendments(json: &str) -> Arc<Amendments> {
5162    #[derive(serde::Deserialize)]
5163    struct AmendmentEntry {
5164        root: String,
5165        deps: Vec<DepEntry>,
5166    }
5167
5168    #[derive(serde::Deserialize)]
5169    struct DepEntry {
5170        original_id: String,
5171        version_id: String,
5172    }
5173
5174    let entries: Vec<AmendmentEntry> =
5175        serde_json::from_str(json).expect("Failed to parse amendments JSON");
5176    let mut amendments = BTreeMap::new();
5177    for entry in entries {
5178        let root_id = AccountAddress::from_hex_literal(&entry.root).unwrap();
5179        let mut dep_ids = BTreeMap::new();
5180        for dep in entry.deps {
5181            let orig_id = AccountAddress::from_hex_literal(&dep.original_id).unwrap();
5182            let upgraded_id = AccountAddress::from_hex_literal(&dep.version_id).unwrap();
5183            assert!(
5184                dep_ids.insert(orig_id, upgraded_id).is_none(),
5185                "Duplicate original ID in amendments table"
5186            );
5187        }
5188        assert!(
5189            amendments.insert(root_id, dep_ids).is_none(),
5190            "Duplicate root ID in amendments table"
5191        );
5192    }
5193    Arc::new(amendments)
5194}
5195
5196#[cfg(all(test, not(msim)))]
5197mod test {
5198    use insta::assert_yaml_snapshot;
5199
5200    use super::*;
5201
5202    #[test]
5203    fn snapshot_tests() {
5204        println!("\n============================================================================");
5205        println!("!                                                                          !");
5206        println!("! IMPORTANT: never update snapshots from this test. only add new versions! !");
5207        println!("!                                                                          !");
5208        println!("============================================================================\n");
5209        for chain_id in &[Chain::Unknown, Chain::Mainnet, Chain::Testnet] {
5210            // make Chain::Unknown snapshots compatible with pre-chain-id snapshots so that we
5211            // don't break the release-time compatibility tests. Once Chain Id configs have been
5212            // released everywhere, we can remove this and only test Mainnet and Testnet
5213            let chain_str = match chain_id {
5214                Chain::Unknown => "".to_string(),
5215                _ => format!("{:?}_", chain_id),
5216            };
5217            for i in MIN_PROTOCOL_VERSION..=MAX_PROTOCOL_VERSION {
5218                let cur = ProtocolVersion::new(i);
5219                assert_yaml_snapshot!(
5220                    format!("{}version_{}", chain_str, cur.as_u64()),
5221                    ProtocolConfig::get_for_version(cur, *chain_id)
5222                );
5223            }
5224        }
5225    }
5226
5227    #[test]
5228    fn test_getters() {
5229        let prot: ProtocolConfig =
5230            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5231        assert_eq!(
5232            prot.max_arguments(),
5233            prot.max_arguments_as_option().unwrap()
5234        );
5235    }
5236
5237    #[test]
5238    fn test_setters() {
5239        let mut prot: ProtocolConfig =
5240            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5241        prot.set_max_arguments_for_testing(123);
5242        assert_eq!(prot.max_arguments(), 123);
5243
5244        prot.set_max_arguments_from_str_for_testing("321".to_string());
5245        assert_eq!(prot.max_arguments(), 321);
5246
5247        prot.disable_max_arguments_for_testing();
5248        assert_eq!(prot.max_arguments_as_option(), None);
5249
5250        prot.set_attr_for_testing("max_arguments".to_string(), "456".to_string());
5251        assert_eq!(prot.max_arguments(), 456);
5252    }
5253
5254    #[test]
5255    fn test_execution_version_setter_allows_upgrade() {
5256        let mut prot = ProtocolConfig::get_for_max_version_UNSAFE();
5257        let current = prot.execution_version();
5258        prot.set_execution_version_for_testing(current);
5259        prot.set_execution_version_for_testing(current + 1);
5260        assert_eq!(prot.execution_version(), current + 1);
5261    }
5262
5263    #[test]
5264    #[should_panic(expected = "cannot downgrade execution_version")]
5265    fn test_execution_version_setter_panics_on_downgrade() {
5266        let mut prot = ProtocolConfig::get_for_max_version_UNSAFE();
5267        let current = prot.execution_version();
5268        prot.set_execution_version_for_testing(current - 1);
5269    }
5270
5271    #[test]
5272    fn test_feature_flag_setter_by_string() {
5273        let mut prot: ProtocolConfig =
5274            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5275        assert!(!prot.zklogin_auth());
5276        prot.set_feature_flag_for_testing("zklogin_auth".to_string(), true);
5277        assert!(prot.zklogin_auth());
5278        prot.set_feature_flag_for_testing("zklogin_auth".to_string(), false);
5279        assert!(!prot.zklogin_auth());
5280    }
5281
5282    #[test]
5283    #[should_panic(expected = "unknown feature flag")]
5284    fn test_feature_flag_setter_unknown_flag() {
5285        let mut prot: ProtocolConfig =
5286            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5287        prot.set_feature_flag_for_testing("some random string".to_string(), true);
5288    }
5289
5290    #[test]
5291    fn test_get_for_version_if_supported_applies_test_overrides() {
5292        let before =
5293            ProtocolConfig::get_for_version_if_supported(ProtocolVersion::new(1), Chain::Unknown)
5294                .unwrap();
5295
5296        assert!(!before.enable_coin_reservation_obj_refs());
5297
5298        let _guard = ProtocolConfig::apply_overrides_for_testing(|_, mut cfg| {
5299            cfg.enable_coin_reservation_for_testing();
5300            cfg
5301        });
5302
5303        let after =
5304            ProtocolConfig::get_for_version_if_supported(ProtocolVersion::new(1), Chain::Unknown)
5305                .unwrap();
5306
5307        assert!(after.enable_coin_reservation_obj_refs());
5308    }
5309
5310    #[test]
5311    #[should_panic(expected = "unsupported version")]
5312    fn max_version_test() {
5313        // When this does not panic, version higher than MAX_PROTOCOL_VERSION exists.
5314        // To fix, bump MAX_PROTOCOL_VERSION or disable this check for the version.
5315        let _ = ProtocolConfig::get_for_version_impl(
5316            ProtocolVersion::new(MAX_PROTOCOL_VERSION + 1),
5317            Chain::Unknown,
5318        );
5319    }
5320
5321    #[test]
5322    fn lookup_by_string_test() {
5323        let prot: ProtocolConfig =
5324            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5325        // Does not exist
5326        assert!(prot.lookup_attr("some random string".to_string()).is_none());
5327
5328        assert!(
5329            prot.lookup_attr("max_arguments".to_string())
5330                == Some(ProtocolConfigValue::u32(prot.max_arguments())),
5331        );
5332
5333        // We didnt have this in version 1
5334        assert!(
5335            prot.lookup_attr("max_move_identifier_len".to_string())
5336                .is_none()
5337        );
5338
5339        // But we did in version 9
5340        let prot: ProtocolConfig =
5341            ProtocolConfig::get_for_version(ProtocolVersion::new(9), Chain::Unknown);
5342        assert!(
5343            prot.lookup_attr("max_move_identifier_len".to_string())
5344                == Some(ProtocolConfigValue::u64(prot.max_move_identifier_len()))
5345        );
5346
5347        let prot: ProtocolConfig =
5348            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5349        // We didnt have this in version 1
5350        assert!(
5351            prot.attr_map()
5352                .get("max_move_identifier_len")
5353                .unwrap()
5354                .is_none()
5355        );
5356        // We had this in version 1
5357        assert!(
5358            prot.attr_map().get("max_arguments").unwrap()
5359                == &Some(ProtocolConfigValue::u32(prot.max_arguments()))
5360        );
5361
5362        // Check feature flags
5363        let prot: ProtocolConfig =
5364            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5365        // Does not exist
5366        assert!(
5367            prot.feature_flags
5368                .lookup_attr("some random string".to_owned())
5369                .is_none()
5370        );
5371        assert!(
5372            !prot
5373                .feature_flags
5374                .attr_map()
5375                .contains_key("some random string")
5376        );
5377
5378        // Was false in v1
5379        assert!(
5380            prot.feature_flags
5381                .lookup_attr("package_upgrades".to_owned())
5382                == Some(false)
5383        );
5384        assert!(
5385            prot.feature_flags
5386                .attr_map()
5387                .get("package_upgrades")
5388                .unwrap()
5389                == &false
5390        );
5391        let prot: ProtocolConfig =
5392            ProtocolConfig::get_for_version(ProtocolVersion::new(4), Chain::Unknown);
5393        // Was true from v3 and up
5394        assert!(
5395            prot.feature_flags
5396                .lookup_attr("package_upgrades".to_owned())
5397                == Some(true)
5398        );
5399        assert!(
5400            prot.feature_flags
5401                .attr_map()
5402                .get("package_upgrades")
5403                .unwrap()
5404                == &true
5405        );
5406    }
5407
5408    #[test]
5409    fn limit_range_fn_test() {
5410        let low = 100u32;
5411        let high = 10000u64;
5412
5413        assert!(check_limit!(1u8, low, high) == LimitThresholdCrossed::None);
5414        assert!(matches!(
5415            check_limit!(255u16, low, high),
5416            LimitThresholdCrossed::Soft(255u128, 100)
5417        ));
5418        // This wont compile because lossy
5419        //assert!(check_limit!(100000000u128, low, high) == LimitThresholdCrossed::None);
5420        // This wont compile because lossy
5421        //assert!(check_limit!(100000000usize, low, high) == LimitThresholdCrossed::None);
5422
5423        assert!(matches!(
5424            check_limit!(2550000u64, low, high),
5425            LimitThresholdCrossed::Hard(2550000, 10000)
5426        ));
5427
5428        assert!(matches!(
5429            check_limit!(2550000u64, high, high),
5430            LimitThresholdCrossed::Hard(2550000, 10000)
5431        ));
5432
5433        assert!(matches!(
5434            check_limit!(1u8, high),
5435            LimitThresholdCrossed::None
5436        ));
5437
5438        assert!(check_limit!(255u16, high) == LimitThresholdCrossed::None);
5439
5440        assert!(matches!(
5441            check_limit!(2550000u64, high),
5442            LimitThresholdCrossed::Hard(2550000, 10000)
5443        ));
5444    }
5445
5446    #[test]
5447    fn linkage_amendments_load() {
5448        let mainnet = LazyLock::force(&MAINNET_LINKAGE_AMENDMENTS);
5449        let testnet = LazyLock::force(&TESTNET_LINKAGE_AMENDMENTS);
5450        assert!(!mainnet.is_empty(), "mainnet amendments must not be empty");
5451        assert!(!testnet.is_empty(), "testnet amendments must not be empty");
5452    }
5453
5454    #[test]
5455    fn render_scalar_fields_use_precision_safe_encoding() {
5456        use mysten_common::rpc_format::Unmetered;
5457
5458        let config = ProtocolConfig::get_for_max_version_UNSAFE();
5459        let rendered = config
5460            .render::<serde_json::Value>(&mut Unmetered)
5461            .expect("render should succeed");
5462
5463        let max_args = rendered
5464            .get("max_arguments")
5465            .expect("max_arguments set at max version");
5466        assert!(
5467            max_args.is_number(),
5468            "u32 should render as number, got {max_args:?}",
5469        );
5470
5471        let max_tx_size = rendered
5472            .get("max_tx_size_bytes")
5473            .expect("max_tx_size_bytes set at max version");
5474        assert!(
5475            max_tx_size.is_string(),
5476            "u64 should render as string, got {max_tx_size:?}",
5477        );
5478    }
5479
5480    #[test]
5481    fn render_includes_non_scalar_gasless_allowlist_as_json() {
5482        use mysten_common::rpc_format::Unmetered;
5483        use serde_json::json;
5484
5485        let mut config = ProtocolConfig::get_for_max_version_UNSAFE();
5486        config.set_gasless_allowed_token_types_for_testing(vec![
5487            ("0xa::usdc::USDC".to_string(), 10_000),
5488            ("0xb::usdt::USDT".to_string(), 0),
5489        ]);
5490
5491        let rendered = config
5492            .render::<serde_json::Value>(&mut Unmetered)
5493            .expect("render should succeed under Unmetered budget");
5494        let allowlist = rendered
5495            .get("gasless_allowed_token_types")
5496            .expect("entry should be present after the testing setter");
5497
5498        // u64 values render as strings to preserve JS precision; the tuple becomes a 2-element
5499        // JSON array.
5500        assert_eq!(
5501            allowlist,
5502            &json!([["0xa::usdc::USDC", "10000"], ["0xb::usdt::USDT", "0"],]),
5503        );
5504    }
5505
5506    #[test]
5507    fn render_targets_prost_value_for_grpc() {
5508        use mysten_common::rpc_format::Unmetered;
5509        use prost_types::value::Kind;
5510
5511        let mut config = ProtocolConfig::get_for_max_version_UNSAFE();
5512        config.set_gasless_allowed_token_types_for_testing(vec![(
5513            "0xa::usdc::USDC".to_string(),
5514            10_000,
5515        )]);
5516
5517        let rendered = config
5518            .render::<prost_types::Value>(&mut Unmetered)
5519            .expect("render to prost Value should succeed");
5520        let allowlist = rendered
5521            .get("gasless_allowed_token_types")
5522            .expect("entry should be present after the testing setter");
5523
5524        // Outer ListValue with one inner ListValue carrying [coin_type_string, amount_string].
5525        let Some(Kind::ListValue(outer)) = &allowlist.kind else {
5526            panic!(
5527                "expected ListValue at the top level, got {:?}",
5528                allowlist.kind
5529            );
5530        };
5531        assert_eq!(outer.values.len(), 1, "one allowlisted entry");
5532        let Some(Kind::ListValue(entry)) = &outer.values[0].kind else {
5533            panic!("expected each entry to be a ListValue");
5534        };
5535        assert_eq!(entry.values.len(), 2, "entry has (coin_type, amount)");
5536
5537        let Some(Kind::StringValue(coin_type)) = &entry.values[0].kind else {
5538            panic!("expected coin_type as StringValue");
5539        };
5540        assert_eq!(coin_type, "0xa::usdc::USDC");
5541
5542        // u64 amount renders as a string, not a NumberValue — this is the precision-safe path.
5543        let Some(Kind::StringValue(amount)) = &entry.values[1].kind else {
5544            panic!(
5545                "expected minimum_transfer_amount as StringValue (precision-safe u64); got {:?}",
5546                entry.values[1].kind,
5547            );
5548        };
5549        assert_eq!(amount, "10000");
5550    }
5551
5552    #[test]
5553    fn render_emits_null_for_unset_protocol_versions() {
5554        use mysten_common::rpc_format::Unmetered;
5555
5556        let config = ProtocolConfig::get_for_version(1.into(), Chain::Unknown);
5557        let rendered = config
5558            .render::<serde_json::Value>(&mut Unmetered)
5559            .expect("render should succeed");
5560        // The gasless allowlist key is present in every version's keyset, but renders as JSON
5561        // `null` for versions that predate the feature. This keeps the keyset stable across
5562        // protocol versions so clients can distinguish "unknown key" from "present but unset".
5563        let entry = rendered
5564            .get("gasless_allowed_token_types")
5565            .expect("key should be present for every protocol version");
5566        assert!(
5567            entry.is_null(),
5568            "value should be null for pre-feature protocol version, got {entry:?}",
5569        );
5570    }
5571}