Skip to main content

sui_protocol_config/
lib.rs

1// Copyright (c) Mysten Labs, Inc.
2// SPDX-License-Identifier: Apache-2.0
3
4use std::{
5    collections::{BTreeMap, BTreeSet},
6    sync::{
7        Arc, LazyLock,
8        atomic::{AtomicBool, Ordering},
9    },
10};
11
12use std::sync::Mutex;
13
14use clap::*;
15use fastcrypto::encoding::{Base58, Encoding, Hex};
16use move_binary_format::{
17    binary_config::{BinaryConfig, TableConfig},
18    file_format_common::VERSION_1,
19};
20use move_core_types::account_address::AccountAddress;
21use move_vm_config::verifier::VerifierConfig;
22use mysten_common::in_integration_test;
23use serde::{Deserialize, Serialize};
24use serde_with::skip_serializing_none;
25use sui_protocol_config_macros::{
26    ProtocolConfigAccessors, ProtocolConfigFeatureFlagsGetters, ProtocolConfigOverride,
27};
28use tracing::{info, warn};
29
30pub mod reachability;
31
32// Re-exported so that `assert_reachable_gated!` expands without requiring callers to depend on
33// the antithesis sdk or mysten-common directly.
34#[doc(hidden)]
35pub use antithesis_sdk::linkme;
36#[doc(hidden)]
37pub use mysten_common::assert_reachable_simtest;
38
39/// The minimum and maximum protocol versions supported by this build.
40const MIN_PROTOCOL_VERSION: u64 = 1;
41const MAX_PROTOCOL_VERSION: u64 = 140;
42
43const TESTNET_USDC: &str =
44    "0xa1ec7fc00a6f40db9693ad1415d0c193ad3906494428cf252621037bd7117e29::usdc::USDC";
45
46const MAINNET_USDC: &str =
47    "0xdba34672e30cb065b1f93e3ab55318768fd6fef66c15942c9f7cb846e2f900e7::usdc::USDC";
48const MAINNET_USDSUI: &str =
49    "0x44f838219cf67b058f3b37907b655f226153c18e33dfcd0da559a844fea9b1c1::usdsui::USDSUI";
50const MAINNET_SUI_USDE: &str =
51    "0x41d587e5336f1c86cad50d38a7136db99333bb9bda91cea4ba69115defeb1402::sui_usde::SUI_USDE";
52const MAINNET_USDY: &str =
53    "0x960b531667636f39e85867775f52f6b1f220a058c4de786905bdf761e06a56bb::usdy::USDY";
54const MAINNET_FDUSD: &str =
55    "0xf16e6b723f242ec745dfd7634ad072c42d5c1d9ac9d62a39c381303eaa57693a::fdusd::FDUSD";
56const MAINNET_AUSD: &str =
57    "0x2053d08c1e2bd02791056171aab0fd12bd7cd7efad2ab8f6b9c8902f14df2ff2::ausd::AUSD";
58const MAINNET_USDB: &str =
59    "0xe14726c336e81b32328e92afc37345d159f5b550b09fa92bd43640cfdd0a0cfd::usdb::USDB";
60
61// Record history of protocol version allocations here:
62//
63// Version 1: Original version.
64// Version 2: Framework changes, including advancing epoch_start_time in safemode.
65// Version 3: gas model v2, including all sui conservation fixes. Fix for loaded child object
66//            changes, enable package upgrades, add limits on `max_size_written_objects`,
67//            `max_size_written_objects_system_tx`
68// Version 4: New reward slashing rate. Framework changes to skip stake susbidy when the epoch
69//            length is short.
70// Version 5: Package upgrade compatibility error fix. New gas cost table. New scoring decision
71//            mechanism that includes up to f scoring authorities.
72// Version 6: Change to how bytes are charged in the gas meter, increase buffer stake to 0.5f
73// Version 7: Disallow adding new abilities to types during package upgrades,
74//            disable_invariant_violation_check_in_swap_loc,
75//            disable init functions becoming entry,
76//            hash module bytes individually before computing package digest.
77// Version 8: Disallow changing abilities and type constraints for type parameters in structs
78//            during upgrades.
79// Version 9: Limit the length of Move identifiers to 128.
80//            Disallow extraneous module bytes,
81//            advance_to_highest_supported_protocol_version,
82// Version 10:increase bytecode verifier `max_verifier_meter_ticks_per_function` and
83//            `max_meter_ticks_per_module` limits each from 6_000_000 to 16_000_000. sui-system
84//            framework changes.
85// Version 11: Introduce `std::type_name::get_with_original_ids` to the system frameworks. Bound max depth of values within the VM.
86// Version 12: Changes to deepbook in framework to add API for querying marketplace.
87//             Change NW Batch to use versioned metadata field.
88//             Changes to sui-system package to add PTB-friendly unstake function, and minor cleanup.
89// Version 13: System package change deprecating `0xdee9::clob` and `0xdee9::custodian`, replaced by
90//             `0xdee9::clob_v2` and `0xdee9::custodian_v2`.
91// Version 14: Introduce a config variable to allow charging of computation to be either
92//             bucket base or rounding up. The presence of `gas_rounding_step` (or `None`)
93//             decides whether rounding is applied or not.
94// Version 15: Add reordering of user transactions by gas price after consensus.
95//             Add `sui::table_vec::drop` to the framework via a system package upgrade.
96// Version 16: Enabled simplified_unwrap_then_delete feature flag, which allows the execution engine
97//             to no longer consult the object store when generating unwrapped_then_deleted in the
98//             effects; this also allows us to stop including wrapped tombstones in accumulator.
99//             Add self-matching prevention for deepbook.
100// Version 17: Enable upgraded multisig support.
101// Version 18: Introduce execution layer versioning, preserve all existing behaviour in v0.
102//             Gas minimum charges moved to be a multiplier over the reference gas price. In this
103//             protocol version the multiplier is the same as the lowest bucket of computation
104//             such that the minimum transaction cost is the same as the minimum computation
105//             bucket.
106//             Add a feature flag to indicate the changes semantics of `base_tx_cost_fixed`.
107// Version 19: Changes to sui-system package to enable liquid staking.
108//             Add limit for total size of events.
109//             Increase limit for number of events emitted to 1024.
110// Version 20: Enables the flag `narwhal_new_leader_election_schedule` for the new narwhal leader
111//             schedule algorithm for enhanced fault tolerance and sets the bad node stake threshold
112//             value. Both values are set for all the environments except mainnet.
113// Version 21: ZKLogin known providers.
114// Version 22: Child object format change.
115// Version 23: Enabling the flag `narwhal_new_leader_election_schedule` for the new narwhal leader
116//             schedule algorithm for enhanced fault tolerance and sets the bad node stake threshold
117//             value for mainnet.
118// Version 24: Re-enable simple gas conservation checks.
119//             Package publish/upgrade number in a single transaction limited.
120//             JWK / authenticator state flags.
121// Version 25: Add sui::table_vec::swap and sui::table_vec::swap_remove to system packages.
122// Version 26: New gas model version.
123//             Add support for receiving objects off of other objects in devnet only.
124// Version 28: Add sui::zklogin::verify_zklogin_id and related functions to sui framework.
125//             Enable transaction effects v2 in devnet.
126// Version 29: Add verify_legacy_zklogin_address flag to sui framework, this add ability to verify
127//             transactions from a legacy zklogin address.
128// Version 30: Enable Narwhal CertificateV2
129//             Add support for random beacon.
130//             Enable transaction effects v2 in testnet.
131//             Deprecate supported oauth providers from protocol config and rely on node config
132//             instead.
133//             In execution, has_public_transfer is recomputed when loading the object.
134//             Add support for shared obj deletion and receiving objects off of other objects in devnet only.
135// Version 31: Add support for shared object deletion in devnet only.
136//             Add support for getting object ID referenced by receiving object in sui framework.
137//             Create new execution layer version, and preserve previous behavior in v1.
138//             Update semantics of `sui::transfer::receive` and add `sui::transfer::public_receive`.
139// Version 32: Add delete functions for VerifiedID and VerifiedIssuer.
140//             Add sui::token module to sui framework.
141//             Enable transfer to object in testnet.
142//             Enable Narwhal CertificateV2 on mainnet
143//             Make critbit tree and order getters public in deepbook.
144// Version 33: Add support for `receiving_object_id` function in framework
145//             Hardened OTW check.
146//             Enable transfer-to-object in mainnet.
147//             Enable shared object deletion in testnet.
148//             Enable effects v2 in mainnet.
149// Version 34: Framework changes for random beacon.
150// Version 35: Add poseidon hash function.
151//             Enable coin deny list.
152// Version 36: Enable group operations native functions in devnet.
153//             Enable shared object deletion in mainnet.
154//             Set the consensus accepted transaction size and the included transactions size in the proposed block.
155// Version 37: Reject entry functions with mutable Random.
156// Version 38: Introduce limits for binary tables size.
157// Version 39: Allow skipped epochs for randomness updates.
158//             Extra version to fix `test_upgrade_compatibility` simtest.
159// Version 40:
160// Version 41: Enable group operations native functions in testnet and mainnet (without msm).
161// Version 42: Migrate sui framework and related code to Move 2024
162// Version 43: Introduce the upper bound delta config for a zklogin signature's max epoch.
163//             Introduce an explicit parameter for the tick limit per package (previously this was
164//             represented by the parameter for the tick limit per module).
165// Version 44: Enable consensus fork detection on mainnet.
166//             Switch between Narwhal and Mysticeti consensus in tests, devnet and testnet.
167// Version 45: Use tonic networking for Mysticeti consensus.
168//             Set min Move binary format version to 6.
169//             Enable transactions to be signed with zkLogin inside multisig signature.
170//             Add native bridge.
171//             Enable native bridge in devnet
172//             Enable Leader Scoring & Schedule Change for Mysticeti consensus on testnet.
173// Version 46: Enable native bridge in testnet
174//             Enable resharing at the same initial shared version.
175// Version 47: Deepbook changes (framework update)
176// Version 48: Use tonic networking for Mysticeti.
177//             Resolve Move abort locations to the package id instead of the runtime module ID.
178//             Enable random beacon in testnet.
179//             Use new VM when verifying framework packages.
180// Version 49: Enable Move enums on devnet.
181//             Enable VDF in devnet
182//             Enable consensus commit prologue V3 in devnet.
183//             Run Mysticeti consensus by default.
184// Version 50: Add update_node_url to native bridge,
185//             New Move stdlib integer modules
186//             Enable checkpoint batching in testnet.
187//             Prepose consensus commit prologue in checkpoints.
188//             Set number of leaders per round for Mysticeti commits.
189// Version 51: Switch to DKG V1.
190//             Enable deny list v2 on devnet.
191// Version 52: Emit `CommitteeMemberUrlUpdateEvent` when updating bridge node url.
192//             std::config native functions.
193//             Modified sui-system package to enable withdrawal of stake before it becomes active.
194//             Enable soft bundle in devnet and testnet.
195//             Core macro visibility in sui core framework.
196//             Enable checkpoint batching in mainnet.
197//             Enable Mysticeti on mainnet.
198//             Enable Leader Scoring & Schedule Change for Mysticeti consensus on mainnet.
199//             Turn on count based shared object congestion control in devnet.
200//             Enable consensus commit prologue V3 in testnet.
201//             Enable enums on testnet.
202//             Add support for passkey in devnet.
203//             Enable deny list v2 on testnet and mainnet.
204// Version 53: Add feature flag to decide whether to attempt to finalize bridge committee
205//             Enable consensus commit prologue V3 on testnet.
206//             Turn on shared object congestion control in testnet.
207//             Update stdlib natives costs
208// Version 54: Enable random beacon on mainnet.
209//             Enable soft bundle on mainnet.
210// Version 55: Enable enums on mainnet.
211//             Rethrow serialization type layout errors instead of converting them.
212// Version 56: Enable bridge on mainnet.
213//             Note: do not use version 56 for any new features.
214// Version 57: Reduce minimum number of random beacon shares.
215// Version 58: Optimize boolean binops
216//             Finalize bridge committee on mainnet.
217//             Switch to distributed vote scoring in consensus in devnet
218// Version 59: Enable round prober in consensus.
219// Version 60: Validation of public inputs for Groth16 verification.
220//             Enable configuration of maximum number of type nodes in a type layout.
221// Version 61: Switch to distributed vote scoring in consensus in testnet
222//             Further reduce minimum number of random beacon shares.
223//             Add feature flag for Mysticeti fastpath.
224// Version 62: Makes the event's sending module package upgrade-aware.
225// Version 63: Enable gas based congestion control in consensus commit.
226// Version 64: Revert congestion control change.
227// Version 65: Enable distributed vote scoring in mainnet.
228// Version 66: Revert distributed vote scoring in mainnet.
229//             Framework fix for fungible staking book-keeping.
230// Version 67: Re-enable distributed vote scoring in mainnet.
231// Version 68: Add G1Uncompressed group to group ops.
232//             Update to Move stdlib.
233//             Enable gas based congestion control with overage.
234//             Further reduce minimum number of random beacon shares.
235//             Disallow adding new modules in `deps-only` packages.
236// Version 69: Sets number of rounds allowed for fastpath voting in consensus.
237//             Enable smart ancestor selection in devnet.
238//             Enable G1Uncompressed group in testnet.
239// Version 70: Enable smart ancestor selection in testnet.
240//             Enable probing for accepted rounds in round prober in testnet
241//             Add new gas model version to update charging of native functions.
242//             Add std::uq64_64 module to Move stdlib.
243//             Improve gas/wall time efficiency of some Move stdlib vector functions
244// Version 71: [SIP-45] Enable consensus amplification.
245// Version 72: Fix issue where `convert_type_argument_error` wasn't being used in all cases.
246//             Max gas budget moved to 50_000 SUI
247//             Max gas price moved to 50 SUI
248//             Variants as type nodes.
249// Version 73: Enable new marker table version.
250//             Enable consensus garbage collection and new commit rule for devnet.
251//             Enable zstd compression for consensus tonic network in testnet.
252//             Enable smart ancestor selection in mainnet.
253//             Enable probing for accepted rounds in round prober in mainnet
254// Version 74: Enable load_nitro_attestation move function in sui framework in devnet.
255//             Enable all gas costs for load_nitro_attestation.
256//             Enable zstd compression for consensus tonic network in mainnet.
257//             Enable the new commit rule for devnet.
258// Version 75: Enable passkey auth in testnet.
259// Version 76: Deprecate Deepbook V2 order placement and deposit.
260//             Removes unnecessary child object mutations
261//             Enable passkey auth in multisig for testnet.
262// Version 77: Enable uncompressed point group ops on mainnet.
263//             Enable consensus garbage collection for testnet
264//             Enable the new consensus commit rule for testnet.
265// Version 78: Make `TxContext` Move API native
266//             Enable execution time estimate mode for congestion control on testnet.
267// Version 79: Enable median based commit timestamp in consensus on testnet.
268//             Increase threshold for bad nodes that won't be considered leaders in consensus in testnet
269//             Enable load_nitro_attestation move function in sui framework in testnet.
270//             Enable consensus garbage collection for mainnet
271//             Enable the new consensus commit rule for mainnet.
272// Version 80: Bound size of values created in the adapter.
273// Version 81: Enable median based commit timestamp in consensus on mainnet.
274//             Enforce checkpoint timestamps are non-decreasing for testnet and mainnet.
275//             Increase threshold for bad nodes that won't be considered leaders in consensus in mainnet
276// Version 82: Relax bounding of size of values created in the adapter.
277// Version 83: Resolve `TypeInput` IDs to defining ID when converting to `TypeTag`s in the adapter.
278//             Enable execution time estimate mode for congestion control on mainnet.
279//             Enable nitro attestation upgraded parsing and mainnet.
280// Version 84: Limit number of stored execution time observations between epochs.
281// Version 85: Enable party transfer in devnet.
282// Version 86: Use type tags in the object runtime and adapter instead of `Type`s.
283//             Make variant count limit explicit in protocol config.
284//             Enable party transfer in testnet.
285// Version 87: Enable better type resolution errors in the adapter.
286// Version 88: Update `sui-system` package to use `calculate_rewards` function.
287//             Define the cost for the native Move function `rgp`.
288//             Ignore execution time observations after validator stops accepting certs.
289// Version 89: Add additional signature checks
290//             Add additional linkage checks
291// Version 90: Standard library improvements.
292//             Enable `debug_fatal` on Move invariant violations.
293//             Enable passkey and passkey inside multisig for mainnet.
294// Version 91: Minor changes in Sui Framework. Include CheckpointDigest in consensus dedup key for checkpoint signatures (V2).
295// Version 92: Disable checking shared object transfer restrictions per command = false
296// Version 93: Enable CheckpointDigest in consensus dedup key for checkpoint signatures.
297// Version 94: Decrease stored observations limit by 10% to stay within system object size limit.
298//             Enable party transfer on mainnet.
299// Version 95: Change type name id base cost to 52, increase max transactions per checkpoint to 20000.
300// Version 96: Enable authority capabilities v2.
301//             Fix bug where MFP transaction shared inputs' debts were not loaded
302//             Create Coin Registry object
303//             Enable checkpoint artifacts digest in devnet.
304// Version 97: Enable additional borrow checks
305// Version 98: Add authenticated event streams support via emit_authenticated function.
306//             Add better error messages to the loader.
307// Version 99: Enable new commit handler.
308// Version 100: Framework update
309// Version 101: Framework update
310//              Set max updates per settlement txn to 100.
311// Version 103: Framework update: internal Coin methods
312// Version 104: Framework update: CoinRegistry follow up for Coin methods
313//              Enable all non-zero PCRs parsing for nitro attestation native function in Devnet and Testnet.
314// Version 105: Framework update: address aliases
315//              Enable multi-epoch transaction expiration.
316//              Enable always include required PCRs (0-4 & 8) parsing even if they are zeros for
317//              nitro attestation native function in Devnet and Testnet.
318// Version 106: Framework update: accumulator storage fund calculations
319//              Enable address balances on devnet
320// Version 108: Enable new digit based gas rounding.
321//              Support TxContext in all parameter positions.
322//              Disable entry point signature check.
323//              Enable address aliases on testnet.
324//              Enable poseidon_bn254 on mainnet.
325// Version 109: Update where we set bounds for some binary tables to be a bit more idiomatic.
326// Version 110: Enable parsing on all nonzero custom pcrs in nitro attestation parsing native
327//              function on mainnet.
328//              split_checkpoints_in_consensus_handler in devnet
329//              Enable additional validation on zkLogin public identifier.
330// Version 111: Validator metadata
331// Version 112: Enable Ristretto255 in devnet.
332// Version 113: Validate gas price >= RGP at signing for address balance gas payments.
333// Version 114: Gate seeded test overrides for checkpoint tx limit behind feature flag.
334// Version 115: Gasless transaction drop safety.
335//              Enable address aliases on mainnet.
336//              Relax ValidDuring requirement for transactions with owned inputs.
337// Version 116: Enable Display Registry.
338//              Disable defer_unpaid_amplification (debugging).
339// Version 117: Update Sui System metadata handling.
340// Version 118: Adds `transfer_migration_cap` to display registry
341// Version 119: Enable the new VM.
342// Version 120: Disallow unused jump tables
343// Version 121: Re-enable defer_unpaid_amplification (devnet + testnet).
344// Version 122: Framework update: vector::empty is deprecated.
345//              Enable bulletproofs verification on devnet.
346//              Enable defer_unpaid_amplification on mainnet.
347// Version 123: Gas accounting refresh (gas_model v13).
348// Version 124: Add timestamp_based_epoch_close feature flag and enable in tests.
349//              Fix native call double-pop in gas meter stack height tracking (gas_model v14).
350//              Limit public inputs in groth16::prepare_verifying_key.
351//              Enable address balances, free tier (gasless), and coin reservations on mainnet.
352//              Enables enable_accumulators, enable_address_balance_gas_payments,
353//              enable_authenticated_event_streams, enable_coin_reservation_obj_refs,
354//              enable_object_funds_withdraw, convert_withdrawal_compatibility_ptb_arguments,
355//              split_checkpoints_in_consensus_handler, include_checkpoint_artifacts_digest_in_summary,
356//              and enable_gasless on mainnet to bring it in line with testnet.
357//              Configure mainnet gasless allowlist with stablecoin types and $0.01 minimum
358//              transfer per stable.
359// Version 125: Enable granular_post_execution_checks.
360//              Enable timestamp_based_epoch_close on testnet.
361// Version 126: Enable early_exit_on_iffw (gates the gas-underflow fix
362//              shipped to mainnet out-of-band in #26816).
363// Version 127: Enable always_advance_dkg_to_resolution.
364//              Update gas prices for range proofs and ristretto group operations.
365//              Enable Ristretto255 group operations and bulletproofs verification on testnet.
366//              Enable init functions for newly introduced modules during package upgrade.
367//              Enable timestamp_based_epoch_close on mainnet.
368// Version 128: Make some additional bounds to binary tables explicit.
369// Version 129: Add `insert_before` and `insert_after` to `sui::linked_table`
370//              Enable unified linkage in PTBs
371// Version 130: Record unsettled object-funds withdraws using per-account net amounts
372//              from transaction effects instead of running-max withdraw amounts.
373//              Add the `sui::scratch` per-transaction ephemeral store and its native costs.
374//              Enable zklogin v2 verify (with v1 fallback) for devnet only.
375//              Add an epoch close deadline failsafe for deferred transactions.
376// Version 131: Enable sharing transaction deny configs between validators via consensus.
377//              Enable tx_context_restrictions_verifier: reject system-package
378//              function signatures with `&mut TxContext` + any `&mut _` return
379//              that have no non-`TxContext` `&mut U` parameter.
380// Version 132: Enable defer_owned_object_double_spend on devnet.
381//              Add the `object::record_new_uid_from_hash` native and its cost, tracking the
382//              root version of hash-derived UIDs (`new_uid_from_hash`).
383//              Create the ForwardingAddressRegistry system object on devnet.
384//              Make upgrade-init linkage checks independent of PTB command order.
385// Version 133: Include function signatures in type-node limits.
386//              Bound type nodes in accumulators.
387// Version 134: Add `package::original_package_id` and its native costs.
388//              Reduce the consensus block transaction count and payload limits.
389//              (Both gated to non-mainnet chains.)
390//              Disable defer_unpaid_amplification on mainnet.
391// Version 135: Apply the v134 config changes on mainnet.
392//              Disable defer_unpaid_amplification everywhere.
393// Version 136: Enable ptb_tx_context_restrictions: `TxContext` may appear in a
394//              PTB Move call signature at most once mutably or any number of
395//              times immutably (never by value), and never in return position.
396//              Enable allowed_proposers on devnet.
397//              Add limits for references used by programmable transactions.
398//              Add additional linkage invariant hardening/invariant checks in PTBs.
399//              Add package_arena_size_in_bytes.
400// Version 137: Lower the per-bit cost of bulletproofs range proof verification, and raise the
401//              bound on batch size * range bits from 512 to 1024.
402//              Enable allowances on devnet and testnet.
403//              Enable fix_ptb_generated_reads.
404//              Charge `LdConst` for the abstract value size of the constant instead of its
405//              serialized byte length.
406//              Enable check_object_funds_withdraw_in_execution on devnet and charge for reads.
407//              Enable allowed_proposers on testnet and mainnet.
408//              Validate PTB indices at signing time.
409//              Enable memory_safety_invariant_check_v2.
410// Version 138: Enable BumpOnly
411//              Enable check_object_funds_withdraw_in_execution on testnet.
412//              Disable effects transaction dependencies on testnet.
413//              Enable allowances on mainnet.
414//              Merge colliding deferred-transaction entries in the consensus handler
415//              instead of overwriting (which stranded the displaced transactions).
416//              Reduce the non-refundable storage fee from 1% to 0.01% on mainnet.
417// Version 139: Enable forwarding addresses on devnet.
418//              Enable ML-DSA-65 account signatures on devnet.
419//              Reduce the non-refundable storage fee from 1% to 0.01%.
420//              Allow random beacon DKG to complete after its timeout on devnet and testnet.
421//              Charge package inputs 1% of the per-byte object read cost.
422// Version 140: Add native vector bulk operations (keep_range, copy_range, replace_range
423//              and reverse) and their gas costs.
424
425#[derive(Copy, Clone, Debug, Hash, Serialize, Deserialize, PartialEq, Eq, PartialOrd, Ord)]
426pub struct ProtocolVersion(u64);
427
428impl ProtocolVersion {
429    // The minimum and maximum protocol version supported by this binary. Counterintuitively, this constant may
430    // change over time as support for old protocol versions is removed from the source. This
431    // ensures that when a new network (such as a testnet) is created, its genesis committee will
432    // use a protocol version that is actually supported by the binary.
433    pub const MIN: Self = Self(MIN_PROTOCOL_VERSION);
434
435    pub const MAX: Self = Self(MAX_PROTOCOL_VERSION);
436
437    #[cfg(not(msim))]
438    pub const MAX_ALLOWED: Self = Self::MAX;
439
440    // We create one additional "fake" version in simulator builds so that we can test upgrades.
441    #[cfg(msim)]
442    pub const MAX_ALLOWED: Self = Self(MAX_PROTOCOL_VERSION + 1);
443
444    pub fn new(v: u64) -> Self {
445        Self(v)
446    }
447
448    pub const fn as_u64(&self) -> u64 {
449        self.0
450    }
451
452    // For serde deserialization - we don't define a Default impl because there isn't a single
453    // universally appropriate default value.
454    pub fn max() -> Self {
455        Self::MAX
456    }
457
458    pub fn prev(self) -> Self {
459        Self(self.0.checked_sub(1).unwrap())
460    }
461}
462
463impl From<u64> for ProtocolVersion {
464    fn from(v: u64) -> Self {
465        Self::new(v)
466    }
467}
468
469impl std::ops::Sub<u64> for ProtocolVersion {
470    type Output = Self;
471    fn sub(self, rhs: u64) -> Self::Output {
472        Self::new(self.0 - rhs)
473    }
474}
475
476impl std::ops::Add<u64> for ProtocolVersion {
477    type Output = Self;
478    fn add(self, rhs: u64) -> Self::Output {
479        Self::new(self.0 + rhs)
480    }
481}
482
483#[derive(
484    Clone, Serialize, Deserialize, Debug, Default, PartialEq, Copy, PartialOrd, Ord, Eq, ValueEnum,
485)]
486pub enum Chain {
487    Mainnet,
488    Testnet,
489    #[default]
490    Unknown,
491}
492
493impl Chain {
494    pub fn as_str(self) -> &'static str {
495        match self {
496            Chain::Mainnet => "mainnet",
497            Chain::Testnet => "testnet",
498            Chain::Unknown => "unknown",
499        }
500    }
501}
502
503pub struct Error(pub String);
504
505// TODO: There are quite a few non boolean values in the feature flags. We should move them out.
506/// Records on/off feature flags that may vary at each protocol version.
507#[derive(Default, Clone, Serialize, Deserialize, Debug, ProtocolConfigFeatureFlagsGetters)]
508struct FeatureFlags {
509    // Add feature flags here, e.g.:
510    // new_protocol_feature: bool,
511    #[serde(skip_serializing_if = "is_false")]
512    package_upgrades: bool,
513    // If true, validators will commit to the root state digest
514    // in end of epoch checkpoint proposals
515    #[serde(skip_serializing_if = "is_false")]
516    commit_root_state_digest: bool,
517    // Pass epoch start time to advance_epoch safe mode function.
518    #[serde(skip_serializing_if = "is_false")]
519    advance_epoch_start_time_in_safe_mode: bool,
520    // If true, apply the fix to correctly capturing loaded child object versions in execution's
521    // object runtime.
522    #[serde(skip_serializing_if = "is_false")]
523    loaded_child_objects_fixed: bool,
524    // If true, treat missing types in the upgraded modules when creating an upgraded package as a
525    // compatibility error.
526    #[serde(skip_serializing_if = "is_false")]
527    missing_type_is_compatibility_error: bool,
528    // If true, then the scoring decision mechanism will not get disabled when we do have more than
529    // f low scoring authorities, but it will simply flag as low scoring only up to f authorities.
530    #[serde(skip_serializing_if = "is_false")]
531    scoring_decision_with_validity_cutoff: bool,
532
533    // DEPRECATED: this was an ephemeral feature flag only used by consensus handler, which has now
534    // been deployed everywhere.
535    #[serde(skip_serializing_if = "is_false")]
536    consensus_order_end_of_epoch_last: bool,
537
538    // If true, validators emit slim (ancestor-compressed) blocks on the consensus block
539    // subscription stream, framed in a block envelope. Gates the wire framing on both
540    // ends of the stream.
541    #[serde(skip_serializing_if = "is_false")]
542    consensus_slim_block_propagation: bool,
543
544    // Disallow adding abilities to types during package upgrades.
545    #[serde(skip_serializing_if = "is_false")]
546    disallow_adding_abilities_on_upgrade: bool,
547    // Disables unnecessary invariant check in the Move VM when swapping the value out of a local
548    #[serde(skip_serializing_if = "is_false")]
549    disable_invariant_violation_check_in_swap_loc: bool,
550    // advance to highest supported protocol version at epoch change, instead of the next consecutive
551    // protocol version.
552    #[serde(skip_serializing_if = "is_false")]
553    advance_to_highest_supported_protocol_version: bool,
554    // If true, disallow entry modifiers on entry functions
555    #[serde(skip_serializing_if = "is_false")]
556    ban_entry_init: bool,
557    // If true, hash module bytes individually when calculating package digests for upgrades
558    #[serde(skip_serializing_if = "is_false")]
559    package_digest_hash_module: bool,
560    // If true, disallow changing struct type parameters during package upgrades
561    #[serde(skip_serializing_if = "is_false")]
562    disallow_change_struct_type_params_on_upgrade: bool,
563    // If true, checks no extra bytes in a compiled module
564    #[serde(skip_serializing_if = "is_false")]
565    no_extraneous_module_bytes: bool,
566    // If true, then use the versioned metadata format in narwhal entities.
567    #[serde(skip_serializing_if = "is_false")]
568    narwhal_versioned_metadata: bool,
569
570    // Enable zklogin auth
571    #[serde(skip_serializing_if = "is_false")]
572    zklogin_auth: bool,
573    // zkLogin circuit verify mode: 0 = accept v1 circuit proofs only, 1 = try the v2
574    // circuit first and fall back to v1 (migration phase), 2 = accept v2 circuit proofs only.
575    #[serde(skip_serializing_if = "is_zero")]
576    zklogin_circuit_mode: u64,
577    // How we order transactions coming out of consensus before sending to execution.
578    #[serde(skip_serializing_if = "ConsensusTransactionOrdering::is_none")]
579    consensus_transaction_ordering: ConsensusTransactionOrdering,
580
581    // Previously, the unwrapped_then_deleted field in TransactionEffects makes a distinction between
582    // whether an object has existed in the store previously (i.e. whether there is a tombstone).
583    // Such dependency makes effects generation inefficient, and requires us to include wrapped
584    // tombstone in state root hash.
585    // To prepare for effects V2, with this flag set to true, we simplify the definition of
586    // unwrapped_then_deleted to always include unwrapped then deleted objects,
587    // regardless of their previous state in the store.
588    #[serde(skip_serializing_if = "is_false")]
589    simplified_unwrap_then_delete: bool,
590    // Enable upgraded multisig support
591    #[serde(skip_serializing_if = "is_false")]
592    upgraded_multisig_supported: bool,
593    // If true minimum txn charge is a multiplier of the gas price
594    #[serde(skip_serializing_if = "is_false")]
595    txn_base_cost_as_multiplier: bool,
596
597    // If true, the ability to delete shared objects is in effect
598    #[serde(skip_serializing_if = "is_false")]
599    shared_object_deletion: bool,
600
601    // If true, then the new algorithm for the leader election schedule will be used
602    #[serde(skip_serializing_if = "is_false")]
603    narwhal_new_leader_election_schedule: bool,
604
605    // A list of supported OIDC providers that can be used for zklogin.
606    #[serde(skip_serializing_if = "is_empty")]
607    zklogin_supported_providers: BTreeSet<String>,
608
609    // If true, use the new child object format
610    #[serde(skip_serializing_if = "is_false")]
611    loaded_child_object_format: bool,
612
613    #[serde(skip_serializing_if = "is_false")]
614    #[skip_protocol_config_accessor]
615    enable_jwk_consensus_updates: bool,
616
617    #[serde(skip_serializing_if = "is_false")]
618    #[skip_protocol_config_accessor]
619    end_of_epoch_transaction_supported: bool,
620
621    // Perform simple conservation checks keeping into account out of gas scenarios
622    // while charging for storage.
623    #[serde(skip_serializing_if = "is_false")]
624    simple_conservation_checks: bool,
625
626    // If true, use the new child object format type logging
627    #[serde(skip_serializing_if = "is_false")]
628    loaded_child_object_format_type: bool,
629
630    // Enable receiving sent objects
631    #[serde(skip_serializing_if = "is_false")]
632    receive_objects: bool,
633
634    // If true, include CheckpointDigest in consensus dedup key for checkpoint signatures (V2).
635    #[serde(skip_serializing_if = "is_false")]
636    consensus_checkpoint_signature_key_includes_digest: bool,
637
638    // Enable random beacon protocol
639    #[serde(skip_serializing_if = "is_false")]
640    random_beacon: bool,
641
642    // Enable bridge protocol
643    #[serde(skip_serializing_if = "is_false")]
644    #[skip_protocol_config_accessor]
645    bridge: bool,
646
647    #[serde(skip_serializing_if = "is_false")]
648    enable_effects_v2: bool,
649
650    // If true, then use CertificateV2 in narwhal.
651    #[serde(skip_serializing_if = "is_false")]
652    narwhal_certificate_v2: bool,
653
654    // If true, allow verify with legacy zklogin address
655    #[serde(skip_serializing_if = "is_false")]
656    verify_legacy_zklogin_address: bool,
657
658    // Enable throughput aware consensus submission
659    #[serde(skip_serializing_if = "is_false")]
660    throughput_aware_consensus_submission: bool,
661
662    // If true, recompute has_public_transfer from the type instead of what is stored in the object
663    #[serde(skip_serializing_if = "is_false")]
664    recompute_has_public_transfer_in_execution: bool,
665
666    // If true, multisig containing zkLogin sig is accepted.
667    #[serde(skip_serializing_if = "is_false")]
668    accept_zklogin_in_multisig: bool,
669
670    // If true, multisig containing passkey sig is accepted.
671    #[serde(skip_serializing_if = "is_false")]
672    accept_passkey_in_multisig: bool,
673
674    // If true, additional zkLogin public identifier structure is validated.
675    #[serde(skip_serializing_if = "is_false")]
676    validate_zklogin_public_identifier: bool,
677
678    // If true, consensus prologue transaction also includes the consensus output digest.
679    // It can be used to detect consensus output folk.
680    #[serde(skip_serializing_if = "is_false")]
681    include_consensus_digest_in_prologue: bool,
682
683    // If true, use the hardened OTW check
684    #[serde(skip_serializing_if = "is_false")]
685    hardened_otw_check: bool,
686
687    // If true allow calling receiving_object_id function
688    #[serde(skip_serializing_if = "is_false")]
689    allow_receiving_object_id: bool,
690
691    // Enable the poseidon hash function
692    #[serde(skip_serializing_if = "is_false")]
693    enable_poseidon: bool,
694
695    // If true, enable the coin deny list.
696    #[serde(skip_serializing_if = "is_false")]
697    enable_coin_deny_list: bool,
698
699    // Enable native functions for group operations.
700    #[serde(skip_serializing_if = "is_false")]
701    enable_group_ops_native_functions: bool,
702
703    // Enable native function for msm.
704    #[serde(skip_serializing_if = "is_false")]
705    enable_group_ops_native_function_msm: bool,
706
707    // Enable group operations for Ristretto255
708    #[serde(skip_serializing_if = "is_false")]
709    enable_ristretto255_group_ops: bool,
710
711    // Enable native functions for group operations.
712    #[serde(skip_serializing_if = "is_false")]
713    enable_verify_bulletproofs_ristretto255: bool,
714
715    // Enable nitro attestation.
716    #[serde(skip_serializing_if = "is_false")]
717    enable_nitro_attestation: bool,
718
719    // Enable upgraded parsing of nitro attestation that interprets pcrs as a map.
720    #[serde(skip_serializing_if = "is_false")]
721    enable_nitro_attestation_upgraded_parsing: bool,
722
723    // Enable upgraded parsing of nitro attestation containing all nonzero PCRs.
724    #[serde(skip_serializing_if = "is_false")]
725    enable_nitro_attestation_all_nonzero_pcrs_parsing: bool,
726
727    // Enable upgraded parsing of nitro attestation to always include required PCRs, even when all zeros.
728    #[serde(skip_serializing_if = "is_false")]
729    enable_nitro_attestation_always_include_required_pcrs_parsing: bool,
730
731    // Reject functions with mutable Random.
732    #[serde(skip_serializing_if = "is_false")]
733    reject_mutable_random_on_entry_functions: bool,
734
735    // Controls the behavior of per object congestion control in consensus handler.
736    #[serde(skip_serializing_if = "PerObjectCongestionControlMode::is_none")]
737    per_object_congestion_control_mode: PerObjectCongestionControlMode,
738
739    // The consensus protocol to be used for the epoch.
740    #[serde(skip_serializing_if = "ConsensusChoice::is_narwhal")]
741    consensus_choice: ConsensusChoice,
742
743    // Consensus network to use.
744    #[serde(skip_serializing_if = "ConsensusNetwork::is_anemo")]
745    consensus_network: ConsensusNetwork,
746
747    // If true, use the correct (<=) comparison for max_gas_payment_objects instead of (<)
748    #[serde(skip_serializing_if = "is_false")]
749    correct_gas_payment_limit_check: bool,
750
751    // Set the upper bound allowed for max_epoch in zklogin signature.
752    #[serde(skip_serializing_if = "Option::is_none")]
753    zklogin_max_epoch_upper_bound_delta: Option<u64>,
754
755    // Controls leader scoring & schedule change in Mysticeti consensus.
756    #[serde(skip_serializing_if = "is_false")]
757    mysticeti_leader_scoring_and_schedule: bool,
758
759    // Enable resharing of shared objects using the same initial shared version
760    #[serde(skip_serializing_if = "is_false")]
761    reshare_at_same_initial_version: bool,
762
763    // Resolve Move abort locations to the package id instead of the runtime module ID.
764    #[serde(skip_serializing_if = "is_false")]
765    resolve_abort_locations_to_package_id: bool,
766
767    // Enables the use of the Mysticeti committed sub dag digest to the `ConsensusCommitInfo` in checkpoints.
768    // When disabled the default digest is used instead. It's important to have this guarded behind
769    // a flag as it will lead to checkpoint forks.
770    #[serde(skip_serializing_if = "is_false")]
771    mysticeti_use_committed_subdag_digest: bool,
772
773    // Enable VDF
774    #[serde(skip_serializing_if = "is_false")]
775    enable_vdf: bool,
776
777    // Controls whether consensus handler should record consensus determined shared object version
778    // assignments in consensus commit prologue transaction.
779    // The purpose of doing this is to enable replaying transaction without transaction effects.
780    #[serde(skip_serializing_if = "is_false")]
781    record_consensus_determined_version_assignments_in_prologue: bool,
782    // V2 also records initial shared versions for consensus objects.
783    // Deprecated: must always be set to `true`.
784    #[serde(skip_serializing_if = "is_false")]
785    record_consensus_determined_version_assignments_in_prologue_v2: bool,
786
787    // Run verification of framework upgrades using a new/fresh VM.
788    #[serde(skip_serializing_if = "is_false")]
789    fresh_vm_on_framework_upgrade: bool,
790
791    // When set to true, the consensus commit prologue transaction will be placed first
792    // in a consensus commit in checkpoints.
793    // If a checkpoint contains multiple consensus commit, say [cm1][cm2]. The each commit's
794    // consensus commit prologue will be the first transaction in each segment:
795    //     [ccp1, rest cm1][ccp2, rest cm2]
796    // The reason to prepose the prologue transaction is to provide information for transaction
797    // cancellation.
798    #[serde(skip_serializing_if = "is_false")]
799    prepend_prologue_tx_in_consensus_commit_in_checkpoints: bool,
800
801    // Set number of leaders per round for Mysticeti commits.
802    #[serde(skip_serializing_if = "Option::is_none")]
803    mysticeti_num_leaders_per_round: Option<usize>,
804
805    // Enable Soft Bundle (SIP-19).
806    #[serde(skip_serializing_if = "is_false")]
807    soft_bundle: bool,
808
809    // If true, enable the coin deny list V2.
810    #[serde(skip_serializing_if = "is_false")]
811    enable_coin_deny_list_v2: bool,
812
813    // Enable passkey auth (SIP-9)
814    #[serde(skip_serializing_if = "is_false")]
815    passkey_auth: bool,
816
817    // Enable ML-DSA-65 (FIPS 204) account signatures, standalone and as
818    // multisig members. Kept out of the generated accessors, and with them out
819    // of the protocol-config listings, until the scheme's RPC surface lands;
820    // `mldsa65_auth()` and its test setter are hand-written.
821    #[serde(skip_serializing_if = "is_false")]
822    #[skip_accessor]
823    mldsa65_auth: bool,
824
825    // Use AuthorityCapabilitiesV2
826    #[serde(skip_serializing_if = "is_false")]
827    authority_capabilities_v2: bool,
828
829    // Rethrow type layout errors during serialization instead of trying to convert them.
830    #[serde(skip_serializing_if = "is_false")]
831    rethrow_serialization_type_layout_errors: bool,
832
833    // Use distributed vote leader scoring strategy in consensus.
834    #[serde(skip_serializing_if = "is_false")]
835    consensus_distributed_vote_scoring_strategy: bool,
836
837    // Probe rounds received by peers from every authority.
838    #[serde(skip_serializing_if = "is_false")]
839    consensus_round_prober: bool,
840
841    // Validate identifier inputs separately
842    #[serde(skip_serializing_if = "is_false")]
843    validate_identifier_inputs: bool,
844
845    // Disallow self identifier
846    #[serde(skip_serializing_if = "is_false")]
847    disallow_self_identifier: bool,
848
849    // Enables Mysticeti fastpath.
850    #[serde(skip_serializing_if = "is_false")]
851    mysticeti_fastpath: bool,
852
853    // If true, disable pre-consensus locking for owned objects.
854    // All transactions go through consensus, and owned object conflict detection
855    // happens post-consensus via lock acquisition.
856    #[serde(skip_serializing_if = "is_false")]
857    disable_preconsensus_locking: bool,
858
859    // Makes the event's sending module version-aware.
860    #[serde(skip_serializing_if = "is_false")]
861    relocate_event_module: bool,
862
863    // Enable uncompressed group elements in BLS123-81 G1
864    #[serde(skip_serializing_if = "is_false")]
865    uncompressed_g1_group_elements: bool,
866
867    #[serde(skip_serializing_if = "is_false")]
868    disallow_new_modules_in_deps_only_packages: bool,
869
870    // Use smart ancestor selection in consensus.
871    #[serde(skip_serializing_if = "is_false")]
872    consensus_smart_ancestor_selection: bool,
873
874    // Probe accepted rounds in round prober.
875    #[serde(skip_serializing_if = "is_false")]
876    consensus_round_prober_probe_accepted_rounds: bool,
877
878    // Enable v2 native charging for natives.
879    #[serde(skip_serializing_if = "is_false")]
880    native_charging_v2: bool,
881
882    // Enables the new logic for collecting the subdag in the consensus linearizer. The new logic does not stop the recursion at the highest
883    // committed round for each authority, but allows to commit uncommitted blocks up to gc round (excluded) for that authority.
884    #[serde(skip_serializing_if = "is_false")]
885    #[skip_protocol_config_accessor]
886    consensus_linearize_subdag_v2: bool,
887
888    // Properly convert certain type argument errors in the execution layer.
889    #[serde(skip_serializing_if = "is_false")]
890    convert_type_argument_error: bool,
891
892    // Variants count as nodes
893    #[serde(skip_serializing_if = "is_false")]
894    variant_nodes: bool,
895
896    // If true, enable zstd compression for consensus tonic network.
897    #[serde(skip_serializing_if = "is_false")]
898    consensus_zstd_compression: bool,
899
900    // If true, enables the optimizations for child object mutations, removing unnecessary mutations
901    #[serde(skip_serializing_if = "is_false")]
902    minimize_child_object_mutations: bool,
903
904    // If true, record the additional state digest in the consensus commit prologue.
905    // Deprecated: must always be set to `true`.
906    #[serde(skip_serializing_if = "is_false")]
907    record_additional_state_digest_in_prologue: bool,
908
909    // If true, enable `TxContext` Move API to go native.
910    #[serde(skip_serializing_if = "is_false")]
911    move_native_context: bool,
912
913    // If true, then it (1) will not enforce monotonicity checks for a block's ancestors and (2) calculates the commit's timestamp based on the
914    // weighted by stake median timestamp of the leader's ancestors.
915    #[serde(skip_serializing_if = "is_false")]
916    #[skip_protocol_config_accessor]
917    consensus_median_based_commit_timestamp: bool,
918
919    // If true, enables the normalization of PTB arguments but does not yet enable splatting
920    // `Result`s of length not equal to 1
921    #[serde(skip_serializing_if = "is_false")]
922    normalize_ptb_arguments: bool,
923
924    // If true, enabled batched block sync in consensus.
925    #[serde(skip_serializing_if = "is_false")]
926    consensus_batched_block_sync: bool,
927
928    // If true, enforces checkpoint timestamps are non-decreasing.
929    #[serde(skip_serializing_if = "is_false")]
930    enforce_checkpoint_timestamp_monotonicity: bool,
931
932    // If true, enables better errors and bounds for max ptb values
933    #[serde(skip_serializing_if = "is_false")]
934    max_ptb_value_size_v2: bool,
935
936    // If true, resolves all type input ids to be defining ID based in the adapter
937    #[serde(skip_serializing_if = "is_false")]
938    resolve_type_input_ids_to_defining_id: bool,
939
940    // Enable native function for party transfer
941    #[serde(skip_serializing_if = "is_false")]
942    enable_party_transfer: bool,
943
944    // Allow objects created or mutated in system transactions to exceed the max object size limit.
945    #[serde(skip_serializing_if = "is_false")]
946    allow_unbounded_system_objects: bool,
947
948    // Signifies the cut-over of using type tags instead of `Type`s in the object runtime.
949    #[serde(skip_serializing_if = "is_false")]
950    type_tags_in_object_runtime: bool,
951
952    // Enable accumulators
953    #[serde(skip_serializing_if = "is_false")]
954    enable_accumulators: bool,
955
956    // Enable coin reservation
957    #[serde(skip_serializing_if = "is_false")]
958    #[skip_protocol_config_accessor]
959    enable_coin_reservation_obj_refs: bool,
960
961    // If true, create the root accumulator object in the change epoch transaction.
962    // This must be enabled and shipped before `enable_accumulators` is set to true.
963    #[serde(skip_serializing_if = "is_false")]
964    create_root_accumulator_object: bool,
965
966    // Enable authenticated event streams
967    #[serde(skip_serializing_if = "is_false")]
968    #[skip_protocol_config_accessor]
969    enable_authenticated_event_streams: bool,
970
971    // Enable address balance gas payments
972    #[serde(skip_serializing_if = "is_false")]
973    enable_address_balance_gas_payments: bool,
974
975    // Validate gas price >= RGP at signing for address balance gas payments
976    #[serde(skip_serializing_if = "is_false")]
977    address_balance_gas_check_rgp_at_signing: bool,
978
979    #[serde(skip_serializing_if = "is_false")]
980    address_balance_gas_reject_gas_coin_arg: bool,
981
982    // Enable multi-epoch transaction expiration (max 1 epoch difference)
983    #[serde(skip_serializing_if = "is_false")]
984    enable_multi_epoch_transaction_expiration: bool,
985
986    // Relax ValidDuring expiration requirement for transactions with owned inputs
987    #[serde(skip_serializing_if = "is_false")]
988    relax_valid_during_for_owned_inputs: bool,
989
990    // Enable statically type checked ptb execution
991    #[serde(skip_serializing_if = "is_false")]
992    enable_ptb_execution_v2: bool,
993
994    // Provide better type resolution errors in the adapter.
995    #[serde(skip_serializing_if = "is_false")]
996    better_adapter_type_resolution_errors: bool,
997
998    // If true, record the time estimate processed in the consensus commit prologue.
999    #[serde(skip_serializing_if = "is_false")]
1000    record_time_estimate_processed: bool,
1001
1002    // If true enable additional linkage checks.
1003    #[serde(skip_serializing_if = "is_false")]
1004    dependency_linkage_error: bool,
1005
1006    // If true enable additional multisig checks.
1007    #[serde(skip_serializing_if = "is_false")]
1008    additional_multisig_checks: bool,
1009
1010    // If true, ignore execution time observations after certs are closed.
1011    #[serde(skip_serializing_if = "is_false")]
1012    ignore_execution_time_observations_after_certs_closed: bool,
1013
1014    // If true use `debug_fatal` to report invariant violations.
1015    // `debug_fatal` panics in debug builds and breaks tests/behavior based on older
1016    // protocol versions (see make_vec_non_existent_type_v71.move)
1017    #[serde(skip_serializing_if = "is_false")]
1018    debug_fatal_on_move_invariant_violation: bool,
1019
1020    // DO NOT ENABLE THIS FOR PRODUCTION NETWORKS. used for testing only.
1021    // Allow private accumulator entrypoints
1022    #[serde(skip_serializing_if = "is_false")]
1023    allow_private_accumulator_entrypoints: bool,
1024
1025    // If true, include indirect state in the additional consensus digest.
1026    // Deprecated: must always be set to `true`.
1027    #[serde(skip_serializing_if = "is_false")]
1028    additional_consensus_digest_indirect_state: bool,
1029
1030    // Check for `init` for new modules to a package on upgrade.
1031    #[serde(skip_serializing_if = "is_false")]
1032    check_for_init_during_upgrade: bool,
1033
1034    // If true, run `init` for newly introduced modules during package upgrade.
1035    #[serde(skip_serializing_if = "is_false")]
1036    enable_init_on_upgrade: bool,
1037
1038    // If true, analyze upgrade-init linkage after all other PTB linkage constraints.
1039    #[serde(skip_serializing_if = "is_false")]
1040    enable_order_independent_upgrade_init_linkage: bool,
1041
1042    // If true, adds additional hardening and checks to upgrade-init linkage entries, and adds
1043    // additional linkage invariant checks around linkage.
1044    #[serde(skip_serializing_if = "is_false")]
1045    harden_linkage_consistency: bool,
1046
1047    // Check shared object transfer restrictions per command.
1048    #[serde(skip_serializing_if = "is_false")]
1049    per_command_shared_object_transfer_rules: bool,
1050
1051    // Validate PTB input and result indices before signing.
1052    #[serde(skip_serializing_if = "is_false")]
1053    validate_ptb_argument_indices: bool,
1054
1055    // Enable including checkpoint artifacts digest in the summary.
1056    #[serde(skip_serializing_if = "is_false")]
1057    include_checkpoint_artifacts_digest_in_summary: bool,
1058
1059    // If true, use MFP txns in load initial object debts.
1060    #[serde(skip_serializing_if = "is_false")]
1061    use_mfp_txns_in_load_initial_object_debts: bool,
1062
1063    // If true, cancel randomness-using txns when DKG has failed *before* doing other congestion checks.
1064    #[serde(skip_serializing_if = "is_false")]
1065    cancel_for_failed_dkg_early: bool,
1066
1067    // If true, keep advancing the DKG state machine while DKG is pending.
1068    #[serde(skip_serializing_if = "is_false")]
1069    always_advance_dkg_to_resolution: bool,
1070
1071    // If true, keep DKG pending after its timeout so that it can complete later in the epoch.
1072    #[serde(skip_serializing_if = "is_false")]
1073    allow_dkg_completion_after_timeout: bool,
1074
1075    // Enable coin registry protocol
1076    #[serde(skip_serializing_if = "is_false")]
1077    enable_coin_registry: bool,
1078
1079    // Use abstract size in the object runtime instead the legacy value size.
1080    #[serde(skip_serializing_if = "is_false")]
1081    abstract_size_in_object_runtime: bool,
1082
1083    // If true charge for loads into the cache (i.e., fetches from storage) in the object runtime.
1084    #[serde(skip_serializing_if = "is_false")]
1085    object_runtime_charge_cache_load_gas: bool,
1086
1087    // If true, perform additional borrow checks
1088    #[serde(skip_serializing_if = "is_false")]
1089    additional_borrow_checks: bool,
1090
1091    // If true, use the new commit handler.
1092    #[serde(skip_serializing_if = "is_false")]
1093    use_new_commit_handler: bool,
1094
1095    // If true return a better error message when we encounter a loader error.
1096    #[serde(skip_serializing_if = "is_false")]
1097    better_loader_errors: bool,
1098
1099    // If true generate layouts for dynamic fields
1100    #[serde(skip_serializing_if = "is_false")]
1101    generate_df_type_layouts: bool,
1102
1103    // If true, allow Move functions called in PTBs to return references
1104    #[serde(skip_serializing_if = "is_false")]
1105    allow_references_in_ptbs: bool,
1106
1107    // If true, the tx_context_restrictions_verifier pass runs at Move module
1108    // publish time and rejects system-package signatures with `&mut TxContext`
1109    // + any `&mut _` return that have no non-`TxContext` `&mut U` parameter.
1110    // User packages are exempt: they can express the same shape through
1111    // generic instantiation, so PTB arity and auto-injection checks are the
1112    // safety mechanism there.
1113    #[serde(skip_serializing_if = "is_false")]
1114    framework_tx_context_mut_restrictions: bool,
1115
1116    // Count function and local signatures towards type-node budgets.
1117    #[serde(skip_serializing_if = "is_false")]
1118    include_function_signatures_in_instantiation_limits: bool,
1119
1120    // If true, the static PTB verifier restricts `TxContext` in Move call
1121    // signatures: it may appear at most once as `&mut TxContext`, or any
1122    // number of times as `&TxContext`, never by value, and never in return
1123    // position (it can never become a PTB result).
1124    #[serde(skip_serializing_if = "is_false")]
1125    ptb_tx_context_restrictions: bool,
1126
1127    // Enable display registry protocol
1128    #[serde(skip_serializing_if = "is_false")]
1129    enable_display_registry: bool,
1130
1131    // If true, enable private generics verifier v2
1132    #[serde(skip_serializing_if = "is_false")]
1133    private_generics_verifier_v2: bool,
1134
1135    // If true, deprecate global storage ops during Move module deserialization
1136    #[serde(skip_serializing_if = "is_false")]
1137    deprecate_global_storage_ops_during_deserialization: bool,
1138
1139    // If true, enable non-exclusive writes for user transactions.
1140    // DO NOT ENABLE outside of the transaction test runner.
1141    #[serde(skip_serializing_if = "is_false")]
1142    enable_non_exclusive_writes: bool,
1143
1144    // If true, deprecate global storage ops everywhere.
1145    #[serde(skip_serializing_if = "is_false")]
1146    deprecate_global_storage_ops: bool,
1147
1148    // If true, normalize depth formula to not be empty for zero depth.
1149    #[serde(skip_serializing_if = "is_false")]
1150    normalize_depth_formula: bool,
1151
1152    // If true, `LdConst` charges for the abstract value size of the constant instead of its
1153    // serialized byte length.
1154    #[serde(skip_serializing_if = "is_false")]
1155    charge_ld_const_abstract_size: bool,
1156
1157    // If true, skip GC'ed accept votes in CommitFinalizer.
1158    #[serde(skip_serializing_if = "is_false")]
1159    consensus_skip_gced_accept_votes: bool,
1160
1161    // If true, include cancelled randomness txns in the consensus commit prologue.
1162    // Deprecated: must always be set to `true`.
1163    #[serde(skip_serializing_if = "is_false")]
1164    include_cancelled_randomness_txns_in_prologue: bool,
1165
1166    // Enables address aliases.
1167    #[serde(skip_serializing_if = "is_false")]
1168    #[skip_protocol_config_accessor]
1169    address_aliases: bool,
1170
1171    // If true, create the forwarding address registry object in the change epoch transaction.
1172    #[serde(skip_serializing_if = "is_false")]
1173    create_forwarding_address_registry: bool,
1174
1175    // If true, resolve forwarding addresses through the forwarding address registry.
1176    #[serde(skip_serializing_if = "is_false")]
1177    enable_forwarding_addresses: bool,
1178
1179    // Corrects signature-to-signer mapping in CheckpointContentsV2.
1180    // Deprecated: must always be set to `true`.
1181    #[serde(skip_serializing_if = "is_false")]
1182    fix_checkpoint_signature_mapping: bool,
1183
1184    // If true, enable object funds withdraw.
1185    #[serde(skip_serializing_if = "is_false")]
1186    enable_object_funds_withdraw: bool,
1187
1188    // If true, unsettled object-funds withdraws are recorded using per-account net
1189    // amounts from transaction effects, instead of running-max withdraw amounts.
1190    #[serde(skip_serializing_if = "is_false")]
1191    record_net_unsettled_object_withdraws: bool,
1192
1193    // If true, skip GC'ed blocks in direct finalization.
1194    #[serde(skip_serializing_if = "is_false")]
1195    consensus_skip_gced_blocks_in_direct_finalization: bool,
1196
1197    // If true, uses a new rounding mechanism for gas calculations, replacing the step-based one
1198    #[serde(skip_serializing_if = "is_false")]
1199    gas_rounding_halve_digits: bool,
1200
1201    // If true, enable tx contexts in all argument positions
1202    #[serde(skip_serializing_if = "is_false")]
1203    flexible_tx_context_positions: bool,
1204
1205    // If true, disable entry point signature check.
1206    #[serde(skip_serializing_if = "is_false")]
1207    disable_entry_point_signature_check: bool,
1208
1209    // If true, convert withdrawal compatibility PTB arguments to coins at the start of the PTB.
1210    #[serde(skip_serializing_if = "is_false")]
1211    convert_withdrawal_compatibility_ptb_arguments: bool,
1212
1213    // If true, additional restrictions for hot or not entry functions are enforced.
1214    #[serde(skip_serializing_if = "is_false")]
1215    restrict_hot_or_not_entry_functions: bool,
1216
1217    // If true, split checkpoints in consensus handler.
1218    #[serde(skip_serializing_if = "is_false")]
1219    split_checkpoints_in_consensus_handler: bool,
1220
1221    // If true, always accept committed system transactions.
1222    #[serde(skip_serializing_if = "is_false")]
1223    consensus_always_accept_system_transactions: bool,
1224
1225    // If true perform consistent verification of metadata
1226    #[serde(skip_serializing_if = "is_false")]
1227    validator_metadata_verify_v2: bool,
1228
1229    // If true, defer transactions with unpaid consensus amplification
1230    // (where duplicate count exceeds gas_price / RGP + 1)
1231    #[serde(skip_serializing_if = "is_false")]
1232    defer_unpaid_amplification: bool,
1233
1234    // If true, defer transactions that won an owned object lock when other transactions
1235    // in the same commit attempted to lock the same object (double-spend attempt).
1236    #[serde(skip_serializing_if = "is_false")]
1237    defer_owned_object_double_spend: bool,
1238
1239    // If true, `TransactionExpiration::Validity` is accepted, allowing a transaction to
1240    // restrict which validators may propose it in consensus.
1241    #[serde(skip_serializing_if = "is_false")]
1242    allowed_proposers: bool,
1243
1244    #[serde(skip_serializing_if = "is_false")]
1245    randomize_checkpoint_tx_limit_in_tests: bool,
1246
1247    // If true, mark the gas coin as uninitialized in drop safety when there is no gas coin.
1248    #[serde(skip_serializing_if = "is_false")]
1249    gasless_transaction_drop_safety: bool,
1250
1251    // When split-checkpoints enabled, merge randomness and non-randomness schedulables together.
1252    // Deprecated: must always be set to `true`.
1253    #[serde(skip_serializing_if = "is_false")]
1254    merge_randomness_into_checkpoint: bool,
1255
1256    // If true, use coin party owner information.
1257    #[serde(skip_serializing_if = "is_false")]
1258    use_coin_party_owner: bool,
1259
1260    #[serde(skip_serializing_if = "is_false")]
1261    enable_gasless: bool,
1262
1263    #[serde(skip_serializing_if = "is_false")]
1264    gasless_verify_remaining_balance: bool,
1265
1266    #[serde(skip_serializing_if = "is_false")]
1267    disallow_jump_orphans: bool,
1268
1269    // If true, return early on type mismatch in receive_object.
1270    #[serde(skip_serializing_if = "is_false")]
1271    early_return_receive_object_mismatched_type: bool,
1272
1273    // If true, use consensus commit timestamps to determine epoch close instead of EndOfPublish voting.
1274    // Each validator transitions from AcceptAllCerts to RejectAllCerts when the consensus commit
1275    // timestamp exceeds the reconfiguration timestamp. EndOfPublish quorum still works as a
1276    // fallback for manual epoch close.
1277    #[serde(skip_serializing_if = "is_false")]
1278    timestamp_based_epoch_close: bool,
1279
1280    // If true, groth16::prepare_verifying_key checks that the verifying key has no more than
1281    // MAX_PUBLIC_INPUTS public inputs.
1282    #[serde(skip_serializing_if = "is_false")]
1283    limit_groth16_pvk_inputs: bool,
1284
1285    // If true, the funds-accumulator address-balance change invariant
1286    // (`TemporaryStore::check_address_balance_changes`) is enforced as a consensus check —
1287    // violations abort the tx via the conservation-recovery flow. When false, the check still
1288    // runs but a violation panics so unexpected violations surface during rollout.
1289    #[serde(skip_serializing_if = "is_false")]
1290    enforce_address_balance_change_invariant: bool,
1291
1292    // If true, validators may broadcast `UpdateTransactionDenyConfig` consensus messages.
1293    #[serde(skip_serializing_if = "is_false")]
1294    share_transaction_deny_config_in_consensus: bool,
1295
1296    // Enables more granular post-execution checks.
1297    #[serde(skip_serializing_if = "is_false")]
1298    granular_post_execution_checks: bool,
1299
1300    // If true, exit early for IFWW transactions.
1301    #[serde(skip_serializing_if = "is_false")]
1302    early_exit_on_iffw: bool,
1303
1304    // If true enable unified linkage
1305    #[serde(skip_serializing_if = "is_false")]
1306    enable_unified_linkage: bool,
1307
1308    // Enable allowance-sourced funds withdrawals (`WithdrawFrom::SenderAllowance`).
1309    // Requires `enable_accumulators`.
1310    #[serde(skip_serializing_if = "is_false")]
1311    #[skip_protocol_config_accessor]
1312    enable_allowances: bool,
1313
1314    // Fixes last-use scoping and live-reference metering for generated `Read` PTB arguments.
1315    #[serde(skip_serializing_if = "is_false")]
1316    fix_ptb_generated_reads: bool,
1317
1318    #[serde(skip_serializing_if = "is_false")]
1319    check_object_funds_withdraw_in_execution: bool,
1320    // If true, use the bitset implementation for PTB memory safety invariant check.
1321    #[serde(skip_serializing_if = "is_false")]
1322    memory_safety_invariant_check_v2: bool,
1323
1324    // Keep the effects wire representation, but stop collecting transaction dependencies.
1325    #[serde(skip_serializing_if = "is_false")]
1326    disable_effects_tx_dependencies: bool,
1327
1328    // If true, a deferred-transaction key collision in the consensus commit handler
1329    // merges the colliding entries instead of overwriting the existing one, which
1330    // silently dropped the displaced (finalized) transactions.
1331    #[serde(skip_serializing_if = "is_false")]
1332    merge_colliding_deferrals: bool,
1333}
1334
1335fn is_false(b: &bool) -> bool {
1336    !b
1337}
1338
1339fn is_empty(b: &BTreeSet<String>) -> bool {
1340    b.is_empty()
1341}
1342
1343fn is_zero(val: &u64) -> bool {
1344    *val == 0
1345}
1346
1347/// Ordering mechanism for transactions in one Narwhal consensus output.
1348#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1349pub enum ConsensusTransactionOrdering {
1350    /// No ordering. Transactions are processed in the order they appear in the consensus output.
1351    #[default]
1352    None,
1353    /// Order transactions by gas price, highest first.
1354    ByGasPrice,
1355}
1356
1357impl ConsensusTransactionOrdering {
1358    pub fn is_none(&self) -> bool {
1359        matches!(self, ConsensusTransactionOrdering::None)
1360    }
1361}
1362
1363#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1364pub struct ExecutionTimeEstimateParams {
1365    // Targeted per-object utilization as an integer percentage (1-100).
1366    pub target_utilization: u64,
1367    // Schedule up to this much extra work (in microseconds) per object,
1368    // but don't allow more than a single transaction to exceed this
1369    // burst limit.
1370    pub allowed_txn_cost_overage_burst_limit_us: u64,
1371
1372    // For separate budget for randomness-using tx, the above limits are
1373    // used with this integer-percentage scaling factor (1-100).
1374    pub randomness_scalar: u64,
1375
1376    // Absolute maximum allowed transaction duration estimate (in microseconds).
1377    pub max_estimate_us: u64,
1378
1379    // Number of the final checkpoints in an epoch whose observations should be
1380    // stored for use in the next epoch.
1381    pub stored_observations_num_included_checkpoints: u64,
1382
1383    // Absolute limit on the number of saved observations at end of epoch.
1384    pub stored_observations_limit: u64,
1385
1386    // Requires observations from at least this amount of stake in order to use
1387    // observation-based execution time estimates instead of the default.
1388    #[serde(skip_serializing_if = "is_zero")]
1389    pub stake_weighted_median_threshold: u64,
1390
1391    // For backwards compatibility with old behavior we use a zero default duration when adding
1392    // new execution time observation keys and a zero generation when loading stored observations.
1393    // This can be removed once set to "true" on mainnet.
1394    #[serde(skip_serializing_if = "is_false")]
1395    pub default_none_duration_for_new_keys: bool,
1396
1397    // Number of observations per chunk. When None, chunking is disabled.
1398    #[serde(skip_serializing_if = "Option::is_none")]
1399    pub observations_chunk_size: Option<u64>,
1400}
1401
1402// The config for per object congestion control in consensus handler.
1403#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1404pub enum PerObjectCongestionControlMode {
1405    #[default]
1406    None, // Deprecated.
1407    TotalGasBudget,                                     // Deprecated.
1408    TotalTxCount,                                       // Deprecated.
1409    TotalGasBudgetWithCap,                              // Deprecated.
1410    ExecutionTimeEstimate(ExecutionTimeEstimateParams), // Use execution time estimate as execution cost.
1411}
1412
1413impl PerObjectCongestionControlMode {
1414    pub fn is_none(&self) -> bool {
1415        matches!(self, PerObjectCongestionControlMode::None)
1416    }
1417}
1418
1419// Configuration options for consensus algorithm.
1420#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1421pub enum ConsensusChoice {
1422    #[default]
1423    Narwhal,
1424    SwapEachEpoch,
1425    Mysticeti,
1426}
1427
1428impl ConsensusChoice {
1429    pub fn is_narwhal(&self) -> bool {
1430        matches!(self, ConsensusChoice::Narwhal)
1431    }
1432}
1433
1434// Configuration options for consensus network.
1435#[derive(Default, Copy, Clone, PartialEq, Eq, Serialize, Deserialize, Debug)]
1436pub enum ConsensusNetwork {
1437    #[default]
1438    Anemo,
1439    Tonic,
1440}
1441
1442impl ConsensusNetwork {
1443    pub fn is_anemo(&self) -> bool {
1444        matches!(self, ConsensusNetwork::Anemo)
1445    }
1446}
1447
1448/// Constants that change the behavior of the protocol.
1449///
1450/// The value of each constant here must be fixed for a given protocol version. To change the value
1451/// of a constant, advance the protocol version, and add support for it in `get_for_version` under
1452/// the new version number.
1453/// (below).
1454///
1455/// To add a new field to this struct, use the following procedure:
1456/// - Advance the protocol version.
1457/// - Add the field as a private `Option<T>` to the struct.
1458/// - Initialize the field to `None` in prior protocol versions.
1459/// - Initialize the field to `Some(val)` for your new protocol version.
1460/// - Add a public getter that simply unwraps the field.
1461/// - Two public getters of the form `field(&self) -> field_type`
1462///     and `field_as_option(&self) -> Option<field_type>` will be automatically generated for you.
1463/// Example for a field: `new_constant: Option<u64>`
1464/// ```rust,ignore
1465///      pub fn new_constant(&self) -> u64 {
1466///         self.new_constant.expect(Self::CONSTANT_ERR_MSG)
1467///     }
1468///      pub fn new_constant_as_option(&self) -> Option<u64> {
1469///         self.new_constant.expect(Self::CONSTANT_ERR_MSG)
1470///     }
1471/// ```
1472/// With `pub fn new_constant(&self) -> u64`, if the constant is accessed in a protocol version
1473/// in which it is not defined, the validator will crash. (Crashing is necessary because
1474/// this type of error would almost always result in forking if not prevented here).
1475/// If you don't want the validator to crash, you can use the
1476/// `pub fn new_constant_as_option(&self) -> Option<u64>` getter, which will
1477/// return `None` if the field is not defined at that version.
1478/// - If you want a customized getter, you can add a method in the impl.
1479#[skip_serializing_none]
1480#[derive(Clone, Serialize, Debug, ProtocolConfigAccessors, ProtocolConfigOverride)]
1481pub struct ProtocolConfig {
1482    pub version: ProtocolVersion,
1483
1484    /// The chain this config was instantiated for. Unlike the other fields, this is not a
1485    /// versioned protocol constant: it identifies the network rather than describing protocol
1486    /// behavior, so it is intentionally excluded from serialization (and from the config
1487    /// snapshots) and is populated directly from the chain passed to `get_for_version`.
1488    #[serde(skip)]
1489    chain: Chain,
1490
1491    feature_flags: FeatureFlags,
1492
1493    // ==== Transaction input limits ====
1494    /// Maximum serialized size of a transaction (in bytes).
1495    max_tx_size_bytes: Option<u64>,
1496
1497    /// Maximum number of input objects to a transaction. Enforced by the transaction input checker
1498    max_input_objects: Option<u64>,
1499
1500    /// Max size of objects a transaction can write to disk after completion. Enforce by the Sui adapter.
1501    /// This is the sum of the serialized size of all objects written to disk.
1502    /// The max size of individual objects on the other hand is `max_move_object_size`.
1503    max_size_written_objects: Option<u64>,
1504    /// Max size of objects a system transaction can write to disk after completion. Enforce by the Sui adapter.
1505    /// Similar to `max_size_written_objects` but for system transactions.
1506    max_size_written_objects_system_tx: Option<u64>,
1507
1508    /// Maximum size of serialized transaction effects.
1509    max_serialized_tx_effects_size_bytes: Option<u64>,
1510
1511    /// Maximum size of serialized transaction effects for system transactions.
1512    max_serialized_tx_effects_size_bytes_system_tx: Option<u64>,
1513
1514    /// Maximum number of gas payment objects for a transaction.
1515    max_gas_payment_objects: Option<u32>,
1516
1517    /// Maximum number of modules in a Publish transaction.
1518    max_modules_in_publish: Option<u32>,
1519
1520    /// Maximum number of transitive dependencies in a package when publishing.
1521    max_package_dependencies: Option<u32>,
1522
1523    /// Maximum number of arguments in a move call or a ProgrammableTransaction's
1524    /// TransferObjects command.
1525    max_arguments: Option<u32>,
1526
1527    /// Maximum number of total type arguments, computed recursively.
1528    max_type_arguments: Option<u32>,
1529
1530    /// Maximum depth of an individual type argument.
1531    max_type_argument_depth: Option<u32>,
1532
1533    /// Maximum size of a Pure CallArg.
1534    max_pure_argument_size: Option<u32>,
1535
1536    /// Maximum number of Commands in a ProgrammableTransaction.
1537    max_programmable_tx_commands: Option<u32>,
1538
1539    // ==== Move VM, Move bytecode verifier, and execution limits ===
1540    /// Maximum Move bytecode version the VM understands. All older versions are accepted.
1541    move_binary_format_version: Option<u32>,
1542    min_move_binary_format_version: Option<u32>,
1543
1544    /// Configuration controlling binary tables size.
1545    binary_module_handles: Option<u16>,
1546    binary_struct_handles: Option<u16>,
1547    binary_function_handles: Option<u16>,
1548    binary_function_instantiations: Option<u16>,
1549    binary_signatures: Option<u16>,
1550    binary_constant_pool: Option<u16>,
1551    binary_identifiers: Option<u16>,
1552    binary_address_identifiers: Option<u16>,
1553    binary_struct_defs: Option<u16>,
1554    binary_struct_def_instantiations: Option<u16>,
1555    binary_function_defs: Option<u16>,
1556    binary_field_handles: Option<u16>,
1557    binary_field_instantiations: Option<u16>,
1558    binary_friend_decls: Option<u16>,
1559    binary_enum_defs: Option<u16>,
1560    binary_enum_def_instantiations: Option<u16>,
1561    binary_variant_handles: Option<u16>,
1562    binary_variant_instantiation_handles: Option<u16>,
1563
1564    /// Maximum size of the `contents` part of an object, in bytes. Enforced by the Sui adapter when effects are produced.
1565    max_move_object_size: Option<u64>,
1566
1567    // TODO: Option<increase to 500 KB. currently, publishing a package > 500 KB exceeds the max computation gas cost
1568    /// Maximum size of a Move package object, in bytes. Enforced by the Sui adapter at the end of a publish transaction.
1569    max_move_package_size: Option<u64>,
1570
1571    /// Max number of publish or upgrade commands allowed in a programmable transaction block.
1572    max_publish_or_upgrade_per_ptb: Option<u64>,
1573
1574    /// Maximum gas budget in MIST that a transaction can use.
1575    max_tx_gas: Option<u64>,
1576
1577    /// Maximum amount of the proposed gas price in MIST (defined in the transaction).
1578    max_gas_price: Option<u64>,
1579
1580    /// For aborted txns, we cap the gas price at a factor of RGP. This lowers risk of setting higher priority gas price
1581    /// if there's a chance the txn will abort.
1582    max_gas_price_rgp_factor_for_aborted_transactions: Option<u64>,
1583
1584    /// The max computation bucket for gas. This is the max that can be charged for computation.
1585    max_gas_computation_bucket: Option<u64>,
1586
1587    // Define the value used to round up computation gas charges
1588    gas_rounding_step: Option<u64>,
1589
1590    /// Maximum number of nested loops. Enforced by the Move bytecode verifier.
1591    max_loop_depth: Option<u64>,
1592
1593    /// Maximum number of type arguments that can be bound to generic type parameters. Enforced by the Move bytecode verifier.
1594    max_generic_instantiation_length: Option<u64>,
1595
1596    /// Maximum number of parameters that a Move function can have. Enforced by the Move bytecode verifier.
1597    max_function_parameters: Option<u64>,
1598
1599    /// Maximum number of basic blocks that a Move function can have. Enforced by the Move bytecode verifier.
1600    max_basic_blocks: Option<u64>,
1601
1602    /// Maximum stack size value. Enforced by the Move bytecode verifier.
1603    max_value_stack_size: Option<u64>,
1604
1605    /// Maximum number of "type nodes", a metric for how big a SignatureToken will be when expanded into a fully qualified type. Enforced by the Move bytecode verifier.
1606    max_type_nodes: Option<u64>,
1607
1608    /// Maximum number of "type nodes" that can be instantiated in a single function.
1609    max_generic_instantiation_type_nodes_per_function: Option<u64>,
1610
1611    /// Maximum number of "type nodes" that can be instantiated in a module.
1612    max_generic_instantiation_type_nodes_per_module: Option<u64>,
1613
1614    /// Maximum number of "type nodes" allowed in an accumulator.
1615    max_accumulator_type_nodes: Option<u64>,
1616
1617    /// Maximum number of push instructions in one function. Enforced by the Move bytecode verifier.
1618    max_push_size: Option<u64>,
1619
1620    /// Maximum number of struct definitions in a module. Enforced by the Move bytecode verifier.
1621    max_struct_definitions: Option<u64>,
1622
1623    /// Maximum number of function definitions in a module. Enforced by the Move bytecode verifier.
1624    max_function_definitions: Option<u64>,
1625
1626    /// Maximum number of fields allowed in a struct definition. Enforced by the Move bytecode verifier.
1627    max_fields_in_struct: Option<u64>,
1628
1629    /// Maximum dependency depth. Enforced by the Move linker when loading dependent modules.
1630    max_dependency_depth: Option<u64>,
1631
1632    /// Maximum number of Move events that a single transaction can emit. Enforced by the VM during execution.
1633    max_num_event_emit: Option<u64>,
1634
1635    /// Maximum number of new IDs that a single transaction can create. Enforced by the VM during execution.
1636    max_num_new_move_object_ids: Option<u64>,
1637
1638    /// Maximum number of new IDs that a single system transaction can create. Enforced by the VM during execution.
1639    max_num_new_move_object_ids_system_tx: Option<u64>,
1640
1641    /// Maximum number of IDs that a single transaction can delete. Enforced by the VM during execution.
1642    max_num_deleted_move_object_ids: Option<u64>,
1643
1644    /// Maximum number of IDs that a single system transaction can delete. Enforced by the VM during execution.
1645    max_num_deleted_move_object_ids_system_tx: Option<u64>,
1646
1647    /// Maximum number of IDs that a single transaction can transfer. Enforced by the VM during execution.
1648    max_num_transferred_move_object_ids: Option<u64>,
1649
1650    /// Maximum number of IDs that a single system transaction can transfer. Enforced by the VM during execution.
1651    max_num_transferred_move_object_ids_system_tx: Option<u64>,
1652
1653    /// Maximum size of a Move user event. Enforced by the VM during execution.
1654    max_event_emit_size: Option<u64>,
1655
1656    /// Maximum size of a Move user event. Enforced by the VM during execution.
1657    max_event_emit_size_total: Option<u64>,
1658
1659    /// Maximum length of a vector in Move. Enforced by the VM during execution, and for constants, by the verifier.
1660    max_move_vector_len: Option<u64>,
1661
1662    /// Maximum length of an `Identifier` in Move. Enforced by the bytecode verifier at signing.
1663    max_move_identifier_len: Option<u64>,
1664
1665    /// Maximum depth of a Move value within the VM.
1666    max_move_value_depth: Option<u64>,
1667
1668    /// Maximum number of bytes a single package's arena may allocate when the package is loaded
1669    /// into the VM. If unset, the VM uses its built-in default.
1670    package_arena_size_in_bytes: Option<u64>,
1671
1672    /// Maximum number of variants in an enum. Enforced by the bytecode verifier at signing.
1673    max_move_enum_variants: Option<u64>,
1674
1675    /// Maximum number of back edges in Move function. Enforced by the bytecode verifier at signing.
1676    max_back_edges_per_function: Option<u64>,
1677
1678    /// Maximum number of back edges in Move module. Enforced by the bytecode verifier at signing.
1679    max_back_edges_per_module: Option<u64>,
1680
1681    /// Maximum number of meter `ticks` spent verifying a Move function. Enforced by the bytecode verifier at signing.
1682    max_verifier_meter_ticks_per_function: Option<u64>,
1683
1684    /// Maximum number of meter `ticks` spent verifying a Move module. Enforced by the bytecode verifier at signing.
1685    max_meter_ticks_per_module: Option<u64>,
1686
1687    /// Maximum number of meter `ticks` spent verifying a Move package. Enforced by the bytecode verifier at signing.
1688    max_meter_ticks_per_package: Option<u64>,
1689
1690    // === Object runtime internal operation limits ====
1691    // These affect dynamic fields
1692    /// Maximum number of cached objects in the object runtime ObjectStore. Enforced by object runtime during execution
1693    object_runtime_max_num_cached_objects: Option<u64>,
1694
1695    /// Maximum number of cached objects in the object runtime ObjectStore in system transaction. Enforced by object runtime during execution
1696    object_runtime_max_num_cached_objects_system_tx: Option<u64>,
1697
1698    /// Maximum number of stored objects accessed by object runtime ObjectStore. Enforced by object runtime during execution
1699    object_runtime_max_num_store_entries: Option<u64>,
1700
1701    /// Maximum number of stored objects accessed by object runtime ObjectStore in system transaction. Enforced by object runtime during execution
1702    object_runtime_max_num_store_entries_system_tx: Option<u64>,
1703
1704    // === Execution gas costs ====
1705    /// Base cost for any Sui transaction
1706    base_tx_cost_fixed: Option<u64>,
1707
1708    /// Additional cost for a transaction that publishes a package
1709    /// i.e., the base cost of such a transaction is base_tx_cost_fixed + package_publish_cost_fixed
1710    package_publish_cost_fixed: Option<u64>,
1711
1712    /// Cost per byte of a Move call transaction
1713    /// i.e., the cost of such a transaction is base_cost + (base_tx_cost_per_byte * size)
1714    base_tx_cost_per_byte: Option<u64>,
1715
1716    /// Cost per byte for a transaction that publishes a package
1717    package_publish_cost_per_byte: Option<u64>,
1718
1719    // Per-byte cost of reading an object during transaction execution
1720    obj_access_cost_read_per_byte: Option<u64>,
1721
1722    // Cost per KiB (1,024 bytes) of reading a non-system package input. When unset, packages are
1723    // charged `obj_access_cost_read_per_byte` like other input objects.
1724    obj_access_cost_read_per_package_kb: Option<u64>,
1725
1726    // Per-byte cost of writing an object during transaction execution
1727    obj_access_cost_mutate_per_byte: Option<u64>,
1728
1729    // Per-byte cost of deleting an object during transaction execution
1730    obj_access_cost_delete_per_byte: Option<u64>,
1731
1732    /// Per-byte cost charged for each input object to a transaction.
1733    /// Meant to approximate the cost of checking locks for each object
1734    // TODO: Option<I'm not sure that this cost makes sense. Checking locks is "free"
1735    // in the sense that an invalid tx that can never be committed/pay gas can
1736    // force validators to check an arbitrary number of locks. If those checks are
1737    // "free" for invalid transactions, why charge for them in valid transactions
1738    // TODO: Option<if we keep this, I think we probably want it to be a fixed cost rather
1739    // than a per-byte cost. checking an object lock should not require loading an
1740    // entire object, just consulting an ID -> tx digest map
1741    obj_access_cost_verify_per_byte: Option<u64>,
1742
1743    // Maximal nodes which are allowed when converting to a type layout.
1744    max_type_to_layout_nodes: Option<u64>,
1745
1746    // Maximal size in bytes that a PTB value can be
1747    max_ptb_value_size: Option<u64>,
1748
1749    // === Gas version. gas model ===
1750    /// Gas model version, what code we are using to charge gas
1751    gas_model_version: Option<u64>,
1752
1753    // === Storage gas costs ===
1754    /// Per-byte cost of storing an object in the Sui global object store. Some of this cost may be refundable if the object is later freed
1755    obj_data_cost_refundable: Option<u64>,
1756
1757    // Per-byte cost of storing an object in the Sui transaction log (e.g., in CertifiedTransactionEffects)
1758    // This depends on the size of various fields including the effects
1759    // TODO: Option<I don't fully understand this^ and more details would be useful
1760    obj_metadata_cost_non_refundable: Option<u64>,
1761
1762    // === Tokenomics ===
1763
1764    // TODO: Option<this should be changed to u64.
1765    /// Sender of a txn that touches an object will get this percent of the storage rebate back.
1766    /// In basis point.
1767    storage_rebate_rate: Option<u64>,
1768
1769    /// 5% of the storage fund's share of rewards are reinvested into the storage fund.
1770    /// In basis point.
1771    storage_fund_reinvest_rate: Option<u64>,
1772
1773    /// The share of rewards that will be slashed and redistributed is 50%.
1774    /// In basis point.
1775    reward_slashing_rate: Option<u64>,
1776
1777    /// Unit gas price, Mist per internal gas unit.
1778    storage_gas_price: Option<u64>,
1779
1780    /// Per-object storage cost for accumulator objects, used during end-of-epoch accounting.
1781    accumulator_object_storage_cost: Option<u64>,
1782
1783    // === Core Protocol ===
1784    /// Max number of transactions per checkpoint.
1785    /// Note that this is a protocol constant and not a config as validators must have this set to
1786    /// the same value, otherwise they *will* fork.
1787    max_transactions_per_checkpoint: Option<u64>,
1788
1789    /// Max size of a checkpoint in bytes.
1790    /// Note that this is a protocol constant and not a config as validators must have this set to
1791    /// the same value, otherwise they *will* fork.
1792    max_checkpoint_size_bytes: Option<u64>,
1793
1794    /// A protocol upgrade always requires 2f+1 stake to agree. We support a buffer of additional
1795    /// stake (as a fraction of f, expressed in basis points) that is required before an upgrade
1796    /// can happen automatically. 10000bps would indicate that complete unanimity is required (all
1797    /// 3f+1 must vote), while 0bps would indicate that 2f+1 is sufficient.
1798    buffer_stake_for_protocol_upgrade_bps: Option<u64>,
1799
1800    // === Native Function Costs ===
1801
1802    // `address` module
1803    // Cost params for the Move native function `address::from_bytes(bytes: vector<u8>)`
1804    address_from_bytes_cost_base: Option<u64>,
1805    // Cost params for the Move native function `address::to_u256(address): u256`
1806    address_to_u256_cost_base: Option<u64>,
1807    // Cost params for the Move native function `address::from_u256(u256): address`
1808    address_from_u256_cost_base: Option<u64>,
1809
1810    // `config` module
1811    // Cost params for the Move native function `read_setting_impl<Name: copy + drop + store,
1812    // SettingValue: key + store, SettingDataValue: store, Value: copy + drop + store,
1813    // >(config: address, name: address, current_epoch: u64): Option<Value>`
1814    config_read_setting_impl_cost_base: Option<u64>,
1815    config_read_setting_impl_cost_per_byte: Option<u64>,
1816
1817    package_original_package_id_impl_cost_base: Option<u64>,
1818    package_original_package_id_impl_cost_per_byte: Option<u64>,
1819
1820    // `dynamic_field` module
1821    // Cost params for the Move native function `hash_type_and_key<K: copy + drop + store>(parent: address, k: K): address`
1822    dynamic_field_hash_type_and_key_cost_base: Option<u64>,
1823    dynamic_field_hash_type_and_key_type_cost_per_byte: Option<u64>,
1824    dynamic_field_hash_type_and_key_value_cost_per_byte: Option<u64>,
1825    dynamic_field_hash_type_and_key_type_tag_cost_per_byte: Option<u64>,
1826    // Cost params for the Move native function `add_child_object<Child: key>(parent: address, child: Child)`
1827    dynamic_field_add_child_object_cost_base: Option<u64>,
1828    dynamic_field_add_child_object_type_cost_per_byte: Option<u64>,
1829    dynamic_field_add_child_object_value_cost_per_byte: Option<u64>,
1830    dynamic_field_add_child_object_struct_tag_cost_per_byte: Option<u64>,
1831    // Cost params for the Move native function `borrow_child_object_mut<Child: key>(parent: &mut UID, id: address): &mut Child`
1832    dynamic_field_borrow_child_object_cost_base: Option<u64>,
1833    dynamic_field_borrow_child_object_child_ref_cost_per_byte: Option<u64>,
1834    dynamic_field_borrow_child_object_type_cost_per_byte: Option<u64>,
1835    // Cost params for the Move native function `remove_child_object<Child: key>(parent: address, id: address): Child`
1836    dynamic_field_remove_child_object_cost_base: Option<u64>,
1837    dynamic_field_remove_child_object_child_cost_per_byte: Option<u64>,
1838    dynamic_field_remove_child_object_type_cost_per_byte: Option<u64>,
1839    // Cost params for the Move native function `has_child_object(parent: address, id: address): bool`
1840    dynamic_field_has_child_object_cost_base: Option<u64>,
1841    // Cost params for the Move native function `has_child_object_with_ty<Child: key>(parent: address, id: address): bool`
1842    dynamic_field_has_child_object_with_ty_cost_base: Option<u64>,
1843    dynamic_field_has_child_object_with_ty_type_cost_per_byte: Option<u64>,
1844    dynamic_field_has_child_object_with_ty_type_tag_cost_per_byte: Option<u64>,
1845
1846    // `scratch` module
1847    // Cost params for the Move native function `add_impl<V: drop>(key: address, value: V)`
1848    scratch_add_cost_base: Option<u64>,
1849    // Cost params for the Move native function `read_impl<V: copy + drop>(key: address): V`
1850    scratch_read_cost_base: Option<u64>,
1851    scratch_read_value_cost: Option<u64>,
1852    // Cost params for the Move native function `remove_impl<V: drop>(key: address): V`
1853    scratch_remove_cost_base: Option<u64>,
1854    // Cost params for the Move native function `exists_impl(key: address): bool`
1855    scratch_exists_cost_base: Option<u64>,
1856    // Cost params for the Move native function `exists_with_type_impl<V: drop>(key: address): bool`
1857    scratch_exists_with_type_cost_base: Option<u64>,
1858    scratch_exists_with_type_type_cost: Option<u64>,
1859    // Maximum number of entries in the per-transaction `sui::scratch` store.
1860    max_scratch_pad_size: Option<u64>,
1861
1862    // `event` module
1863    // Cost params for the Move native function `event::emit<T: copy + drop>(event: T)`
1864    event_emit_cost_base: Option<u64>,
1865    event_emit_value_size_derivation_cost_per_byte: Option<u64>,
1866    event_emit_tag_size_derivation_cost_per_byte: Option<u64>,
1867    event_emit_output_cost_per_byte: Option<u64>,
1868    event_emit_auth_stream_cost: Option<u64>,
1869
1870    // `funds_accumulator` module
1871    // Base cost for reserving object funds for withdrawal.
1872    reserve_object_funds_for_withdrawal_cost_base: Option<u64>,
1873    // Cost of loading an object's settled balance on the first withdrawal for an owner and type.
1874    reserve_object_funds_for_withdrawal_cold_read_cost: Option<u64>,
1875
1876    //  `object` module
1877    // Cost params for the Move native function `borrow_uid<T: key>(obj: &T): &UID`
1878    object_borrow_uid_cost_base: Option<u64>,
1879    // Cost params for the Move native function `delete_impl(id: address)`
1880    object_delete_impl_cost_base: Option<u64>,
1881    // Cost params for the Move native function `record_new_uid(id: address)`
1882    object_record_new_uid_cost_base: Option<u64>,
1883    // Cost params for the Move native function
1884    // `record_new_uid_from_hash(parent: address, bytes: address)`
1885    object_record_new_uid_from_hash_cost_base: Option<u64>,
1886
1887    // Transfer
1888    // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
1889    transfer_transfer_internal_cost_base: Option<u64>,
1890    // Cost params for the Move native function `party_transfer_impl<T: key>(obj: T, party_members: vector<address>)`
1891    transfer_party_transfer_internal_cost_base: Option<u64>,
1892    // Cost params for the Move native function `freeze_object<T: key>(obj: T)`
1893    transfer_freeze_object_cost_base: Option<u64>,
1894    // Cost params for the Move native function `share_object<T: key>(obj: T)`
1895    transfer_share_object_cost_base: Option<u64>,
1896    // Cost params for the Move native function
1897    // `receive_object<T: key>(p: &mut UID, recv: Receiving<T>T)`
1898    transfer_receive_object_cost_base: Option<u64>,
1899    transfer_receive_object_cost_per_byte: Option<u64>,
1900    transfer_receive_object_type_cost_per_byte: Option<u64>,
1901
1902    // TxContext
1903    // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
1904    tx_context_derive_id_cost_base: Option<u64>,
1905    tx_context_fresh_id_cost_base: Option<u64>,
1906    tx_context_sender_cost_base: Option<u64>,
1907    tx_context_epoch_cost_base: Option<u64>,
1908    tx_context_epoch_timestamp_ms_cost_base: Option<u64>,
1909    tx_context_sponsor_cost_base: Option<u64>,
1910    tx_context_rgp_cost_base: Option<u64>,
1911    tx_context_gas_price_cost_base: Option<u64>,
1912    tx_context_gas_budget_cost_base: Option<u64>,
1913    tx_context_ids_created_cost_base: Option<u64>,
1914    tx_context_replace_cost_base: Option<u64>,
1915
1916    // Types
1917    // Cost params for the Move native function `is_one_time_witness<T: drop>(_: &T): bool`
1918    types_is_one_time_witness_cost_base: Option<u64>,
1919    types_is_one_time_witness_type_tag_cost_per_byte: Option<u64>,
1920    types_is_one_time_witness_type_cost_per_byte: Option<u64>,
1921
1922    // Validator
1923    // Cost params for the Move native function `validate_metadata_bcs(metadata: vector<u8>)`
1924    validator_validate_metadata_cost_base: Option<u64>,
1925    validator_validate_metadata_data_cost_per_byte: Option<u64>,
1926
1927    // Crypto natives
1928    crypto_invalid_arguments_cost: Option<u64>,
1929    // bls12381::bls12381_min_sig_verify
1930    bls12381_bls12381_min_sig_verify_cost_base: Option<u64>,
1931    bls12381_bls12381_min_sig_verify_msg_cost_per_byte: Option<u64>,
1932    bls12381_bls12381_min_sig_verify_msg_cost_per_block: Option<u64>,
1933
1934    // bls12381::bls12381_min_pk_verify
1935    bls12381_bls12381_min_pk_verify_cost_base: Option<u64>,
1936    bls12381_bls12381_min_pk_verify_msg_cost_per_byte: Option<u64>,
1937    bls12381_bls12381_min_pk_verify_msg_cost_per_block: Option<u64>,
1938
1939    // ecdsa_k1::ecrecover
1940    ecdsa_k1_ecrecover_keccak256_cost_base: Option<u64>,
1941    ecdsa_k1_ecrecover_keccak256_msg_cost_per_byte: Option<u64>,
1942    ecdsa_k1_ecrecover_keccak256_msg_cost_per_block: Option<u64>,
1943    ecdsa_k1_ecrecover_sha256_cost_base: Option<u64>,
1944    ecdsa_k1_ecrecover_sha256_msg_cost_per_byte: Option<u64>,
1945    ecdsa_k1_ecrecover_sha256_msg_cost_per_block: Option<u64>,
1946
1947    // ecdsa_k1::decompress_pubkey
1948    ecdsa_k1_decompress_pubkey_cost_base: Option<u64>,
1949
1950    // ecdsa_k1::secp256k1_verify
1951    ecdsa_k1_secp256k1_verify_keccak256_cost_base: Option<u64>,
1952    ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_byte: Option<u64>,
1953    ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_block: Option<u64>,
1954    ecdsa_k1_secp256k1_verify_sha256_cost_base: Option<u64>,
1955    ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_byte: Option<u64>,
1956    ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_block: Option<u64>,
1957
1958    // ecdsa_r1::ecrecover
1959    ecdsa_r1_ecrecover_keccak256_cost_base: Option<u64>,
1960    ecdsa_r1_ecrecover_keccak256_msg_cost_per_byte: Option<u64>,
1961    ecdsa_r1_ecrecover_keccak256_msg_cost_per_block: Option<u64>,
1962    ecdsa_r1_ecrecover_sha256_cost_base: Option<u64>,
1963    ecdsa_r1_ecrecover_sha256_msg_cost_per_byte: Option<u64>,
1964    ecdsa_r1_ecrecover_sha256_msg_cost_per_block: Option<u64>,
1965
1966    // ecdsa_r1::secp256k1_verify
1967    ecdsa_r1_secp256r1_verify_keccak256_cost_base: Option<u64>,
1968    ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_byte: Option<u64>,
1969    ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_block: Option<u64>,
1970    ecdsa_r1_secp256r1_verify_sha256_cost_base: Option<u64>,
1971    ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_byte: Option<u64>,
1972    ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_block: Option<u64>,
1973
1974    // ecvrf::verify
1975    ecvrf_ecvrf_verify_cost_base: Option<u64>,
1976    ecvrf_ecvrf_verify_alpha_string_cost_per_byte: Option<u64>,
1977    ecvrf_ecvrf_verify_alpha_string_cost_per_block: Option<u64>,
1978
1979    // ed25519
1980    ed25519_ed25519_verify_cost_base: Option<u64>,
1981    ed25519_ed25519_verify_msg_cost_per_byte: Option<u64>,
1982    ed25519_ed25519_verify_msg_cost_per_block: Option<u64>,
1983
1984    // groth16::prepare_verifying_key
1985    groth16_prepare_verifying_key_bls12381_cost_base: Option<u64>,
1986    groth16_prepare_verifying_key_bn254_cost_base: Option<u64>,
1987
1988    // groth16::verify_groth16_proof_internal
1989    groth16_verify_groth16_proof_internal_bls12381_cost_base: Option<u64>,
1990    groth16_verify_groth16_proof_internal_bls12381_cost_per_public_input: Option<u64>,
1991    groth16_verify_groth16_proof_internal_bn254_cost_base: Option<u64>,
1992    groth16_verify_groth16_proof_internal_bn254_cost_per_public_input: Option<u64>,
1993    groth16_verify_groth16_proof_internal_public_input_cost_per_byte: Option<u64>,
1994
1995    // hash::blake2b256
1996    hash_blake2b256_cost_base: Option<u64>,
1997    hash_blake2b256_data_cost_per_byte: Option<u64>,
1998    hash_blake2b256_data_cost_per_block: Option<u64>,
1999
2000    // hash::keccak256
2001    hash_keccak256_cost_base: Option<u64>,
2002    hash_keccak256_data_cost_per_byte: Option<u64>,
2003    hash_keccak256_data_cost_per_block: Option<u64>,
2004
2005    // poseidon::poseidon_bn254
2006    poseidon_bn254_cost_base: Option<u64>,
2007    poseidon_bn254_cost_per_block: Option<u64>,
2008
2009    // group_ops
2010    group_ops_bls12381_decode_scalar_cost: Option<u64>,
2011    group_ops_bls12381_decode_g1_cost: Option<u64>,
2012    group_ops_bls12381_decode_g2_cost: Option<u64>,
2013    group_ops_bls12381_decode_gt_cost: Option<u64>,
2014    group_ops_bls12381_scalar_add_cost: Option<u64>,
2015    group_ops_bls12381_g1_add_cost: Option<u64>,
2016    group_ops_bls12381_g2_add_cost: Option<u64>,
2017    group_ops_bls12381_gt_add_cost: Option<u64>,
2018    group_ops_bls12381_scalar_sub_cost: Option<u64>,
2019    group_ops_bls12381_g1_sub_cost: Option<u64>,
2020    group_ops_bls12381_g2_sub_cost: Option<u64>,
2021    group_ops_bls12381_gt_sub_cost: Option<u64>,
2022    group_ops_bls12381_scalar_mul_cost: Option<u64>,
2023    group_ops_bls12381_g1_mul_cost: Option<u64>,
2024    group_ops_bls12381_g2_mul_cost: Option<u64>,
2025    group_ops_bls12381_gt_mul_cost: Option<u64>,
2026    group_ops_bls12381_scalar_div_cost: Option<u64>,
2027    group_ops_bls12381_g1_div_cost: Option<u64>,
2028    group_ops_bls12381_g2_div_cost: Option<u64>,
2029    group_ops_bls12381_gt_div_cost: Option<u64>,
2030    group_ops_bls12381_g1_hash_to_base_cost: Option<u64>,
2031    group_ops_bls12381_g2_hash_to_base_cost: Option<u64>,
2032    group_ops_bls12381_g1_hash_to_cost_per_byte: Option<u64>,
2033    group_ops_bls12381_g2_hash_to_cost_per_byte: Option<u64>,
2034    group_ops_bls12381_g1_msm_base_cost: Option<u64>,
2035    group_ops_bls12381_g2_msm_base_cost: Option<u64>,
2036    group_ops_bls12381_g1_msm_base_cost_per_input: Option<u64>,
2037    group_ops_bls12381_g2_msm_base_cost_per_input: Option<u64>,
2038    group_ops_bls12381_msm_max_len: Option<u32>,
2039    group_ops_bls12381_pairing_cost: Option<u64>,
2040    group_ops_bls12381_g1_to_uncompressed_g1_cost: Option<u64>,
2041    group_ops_bls12381_uncompressed_g1_to_g1_cost: Option<u64>,
2042    group_ops_bls12381_uncompressed_g1_sum_base_cost: Option<u64>,
2043    group_ops_bls12381_uncompressed_g1_sum_cost_per_term: Option<u64>,
2044    group_ops_bls12381_uncompressed_g1_sum_max_terms: Option<u64>,
2045
2046    group_ops_ristretto_decode_scalar_cost: Option<u64>,
2047    group_ops_ristretto_decode_point_cost: Option<u64>,
2048    group_ops_ristretto_scalar_add_cost: Option<u64>,
2049    group_ops_ristretto_point_add_cost: Option<u64>,
2050    group_ops_ristretto_scalar_sub_cost: Option<u64>,
2051    group_ops_ristretto_point_sub_cost: Option<u64>,
2052    group_ops_ristretto_scalar_mul_cost: Option<u64>,
2053    group_ops_ristretto_point_mul_cost: Option<u64>,
2054    group_ops_ristretto_scalar_div_cost: Option<u64>,
2055    group_ops_ristretto_point_div_cost: Option<u64>,
2056
2057    verify_bulletproofs_ristretto255_base_cost: Option<u64>,
2058    verify_bulletproofs_ristretto255_cost_per_bit_and_commitment: Option<u64>,
2059    // Upper bound on batch size * range in bits for a bulletproofs range proof. Defaults to 512
2060    // when unset.
2061    max_bulletproofs_total_bits: Option<u64>,
2062
2063    // hmac::hmac_sha3_256
2064    hmac_hmac_sha3_256_cost_base: Option<u64>,
2065    hmac_hmac_sha3_256_input_cost_per_byte: Option<u64>,
2066    hmac_hmac_sha3_256_input_cost_per_block: Option<u64>,
2067
2068    // zklogin::check_zklogin_id
2069    check_zklogin_id_cost_base: Option<u64>,
2070    // zklogin::check_zklogin_issuer
2071    check_zklogin_issuer_cost_base: Option<u64>,
2072
2073    vdf_verify_vdf_cost: Option<u64>,
2074    vdf_hash_to_input_cost: Option<u64>,
2075
2076    // nitro_attestation::load_nitro_attestation
2077    nitro_attestation_parse_base_cost: Option<u64>,
2078    nitro_attestation_parse_cost_per_byte: Option<u64>,
2079    nitro_attestation_verify_base_cost: Option<u64>,
2080    nitro_attestation_verify_cost_per_cert: Option<u64>,
2081
2082    // Stdlib costs
2083    bcs_per_byte_serialized_cost: Option<u64>,
2084    bcs_legacy_min_output_size_cost: Option<u64>,
2085    bcs_failure_cost: Option<u64>,
2086
2087    hash_sha2_256_base_cost: Option<u64>,
2088    hash_sha2_256_per_byte_cost: Option<u64>,
2089    hash_sha2_256_legacy_min_input_len_cost: Option<u64>,
2090    hash_sha3_256_base_cost: Option<u64>,
2091    hash_sha3_256_per_byte_cost: Option<u64>,
2092    hash_sha3_256_legacy_min_input_len_cost: Option<u64>,
2093    type_name_get_base_cost: Option<u64>,
2094    type_name_get_per_byte_cost: Option<u64>,
2095    type_name_id_base_cost: Option<u64>,
2096
2097    string_check_utf8_base_cost: Option<u64>,
2098    string_check_utf8_per_byte_cost: Option<u64>,
2099    string_is_char_boundary_base_cost: Option<u64>,
2100    string_sub_string_base_cost: Option<u64>,
2101    string_sub_string_per_byte_cost: Option<u64>,
2102    string_index_of_base_cost: Option<u64>,
2103    string_index_of_per_byte_pattern_cost: Option<u64>,
2104    string_index_of_per_byte_searched_cost: Option<u64>,
2105
2106    vector_empty_base_cost: Option<u64>,
2107    vector_length_base_cost: Option<u64>,
2108    vector_push_back_base_cost: Option<u64>,
2109    vector_push_back_legacy_per_abstract_memory_unit_cost: Option<u64>,
2110    vector_borrow_base_cost: Option<u64>,
2111    vector_pop_back_base_cost: Option<u64>,
2112    vector_destroy_empty_base_cost: Option<u64>,
2113    vector_swap_base_cost: Option<u64>,
2114    vector_reverse_base_cost: Option<u64>,
2115    vector_reverse_per_elem_cost: Option<u64>,
2116    vector_keep_range_base_cost: Option<u64>,
2117    vector_keep_range_per_dropped_elem_cost: Option<u64>,
2118    vector_keep_range_per_moved_elem_cost: Option<u64>,
2119    vector_copy_range_base_cost: Option<u64>,
2120    vector_replace_range_base_cost: Option<u64>,
2121    vector_replace_range_per_elem_cost: Option<u64>,
2122    debug_print_base_cost: Option<u64>,
2123    debug_print_stack_trace_base_cost: Option<u64>,
2124
2125    // ==== Ephemeral (consensus only) params deleted ====
2126    //
2127    // Const params for consensus scoring decision
2128    // The scaling factor property for the MED outlier detection
2129    // scoring_decision_mad_divisor: Option<f64>,
2130    // The cutoff value for the MED outlier detection
2131    // scoring_decision_cutoff_value: Option<f64>,
2132    /// === Execution Version ===
2133    // custom_setter: see `set_execution_version_for_testing`, which forbids downgrades.
2134    #[custom_setter]
2135    execution_version: Option<u64>,
2136
2137    // Dictates the threshold (percentage of stake) that is used to calculate the "bad" nodes to be
2138    // swapped when creating the consensus schedule. The values should be of the range [0 - 33]. Anything
2139    // above 33 (f) will not be allowed.
2140    consensus_bad_nodes_stake_threshold: Option<u64>,
2141
2142    max_jwk_votes_per_validator_per_epoch: Option<u64>,
2143    // The maximum age of a JWK in epochs before it is removed from the AuthenticatorState object.
2144    // Applied at the end of an epoch as a delta from the new epoch value, so setting this to 1
2145    // will cause the new epoch to start with JWKs from the previous epoch still valid.
2146    max_age_of_jwk_in_epochs: Option<u64>,
2147
2148    // === random beacon ===
2149    /// Maximum allowed precision loss when reducing voting weights for the random beacon
2150    /// protocol.
2151    random_beacon_reduction_allowed_delta: Option<u16>,
2152
2153    /// Minimum number of shares below which voting weights will not be reduced for the
2154    /// random beacon protocol.
2155    random_beacon_reduction_lower_bound: Option<u32>,
2156
2157    /// Consensus Round after which DKG should be aborted and randomness disabled for
2158    /// the epoch, if it hasn't already completed.
2159    random_beacon_dkg_timeout_round: Option<u32>,
2160
2161    /// Minimum interval between consecutive rounds of generated randomness.
2162    random_beacon_min_round_interval_ms: Option<u64>,
2163
2164    /// Version of the random beacon DKG protocol.
2165    /// 0 was deprecated (and currently not supported), 1 is the default version.
2166    random_beacon_dkg_version: Option<u64>,
2167
2168    /// The maximum serialised transaction size (in bytes) accepted by consensus. That should be bigger than the
2169    /// `max_tx_size_bytes` with some additional headroom.
2170    consensus_max_transaction_size_bytes: Option<u64>,
2171    /// The maximum size of transactions included in a consensus block.
2172    consensus_max_transactions_in_block_bytes: Option<u64>,
2173    /// The maximum number of transactions included in a consensus block.
2174    consensus_max_num_transactions_in_block: Option<u64>,
2175
2176    /// The maximum number of rounds where transaction voting is allowed.
2177    consensus_voting_rounds: Option<u32>,
2178
2179    /// DEPRECATED. Do not use.
2180    max_accumulated_txn_cost_per_object_in_narwhal_commit: Option<u64>,
2181
2182    /// The max number of consensus rounds a transaction can be deferred due to shared object congestion.
2183    /// Transactions will be cancelled after this many rounds.
2184    max_deferral_rounds_for_congestion_control: Option<u64>,
2185
2186    /// Time after the scheduled epoch end (`next_reconfiguration_timestamp_ms`) at which epoch
2187    /// close stops waiting for deferred transactions to drain: the epoch is closed even if
2188    /// deferred transactions remain unscheduled. They are abandoned and can be resubmitted in the
2189    /// next epoch. When unset, epoch close waits indefinitely.
2190    epoch_close_deadline_ms: Option<u64>,
2191
2192    /// DEPRECATED. Do not use.
2193    max_txn_cost_overage_per_object_in_commit: Option<u64>,
2194
2195    /// DEPRECATED. Do not use.
2196    allowed_txn_cost_overage_burst_per_object_in_commit: Option<u64>,
2197
2198    /// Minimum interval of commit timestamps between consecutive checkpoints.
2199    min_checkpoint_interval_ms: Option<u64>,
2200
2201    /// Version number to use for version_specific_data in `CheckpointSummary`.
2202    checkpoint_summary_version_specific_data: Option<u64>,
2203
2204    /// The max number of transactions that can be included in a single Soft Bundle.
2205    max_soft_bundle_size: Option<u64>,
2206
2207    /// Whether to try to form bridge committee
2208    // Note: this is not a feature flag because we want to distinguish between
2209    // `None` and `Some(false)`, as committee was already finalized on Testnet.
2210    bridge_should_try_to_finalize_committee: Option<bool>,
2211
2212    /// The max accumulated txn execution cost per object in a mysticeti. Transactions
2213    /// in a commit will be deferred once their touch shared objects hit this limit,
2214    /// unless the selected congestion control mode allows overage.
2215    /// This config plays the same role as `max_accumulated_txn_cost_per_object_in_narwhal_commit`
2216    /// but for mysticeti commits due to that mysticeti has higher commit rate.
2217    max_accumulated_txn_cost_per_object_in_mysticeti_commit: Option<u64>,
2218
2219    /// As above, but separate per-commit budget for transactions that use randomness.
2220    /// If not configured, uses the setting for `max_accumulated_txn_cost_per_object_in_mysticeti_commit`.
2221    max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit: Option<u64>,
2222
2223    /// Configures the garbage collection depth for consensus. When is unset or `0` then the garbage collection
2224    /// is disabled.
2225    consensus_gc_depth: Option<u32>,
2226
2227    /// DEPRECATED. Do not use.
2228    gas_budget_based_txn_cost_cap_factor: Option<u64>,
2229
2230    /// DEPRECATED. Do not use.
2231    gas_budget_based_txn_cost_absolute_cap_commit_count: Option<u64>,
2232
2233    /// SIP-45: K in the formula `amplification_factor = max(0, gas_price / reference_gas_price - K)`.
2234    /// This is the threshold for activating consensus amplification.
2235    sip_45_consensus_amplification_threshold: Option<u64>,
2236
2237    /// DEPRECATED: this was an ephemeral feature flag only used in per-epoch tables, which has now
2238    /// been deployed everywhere.
2239    use_object_per_epoch_marker_table_v2: Option<bool>,
2240
2241    /// The number of commits to consider when computing a deterministic commit rate.
2242    consensus_commit_rate_estimation_window_size: Option<u32>,
2243
2244    /// A list of effective AliasedAddress.
2245    /// For each pair, `aliased` is allowed to act as `original` for any of the transaction digests
2246    /// listed in `tx_digests`
2247    #[serde(skip_serializing_if = "Vec::is_empty")]
2248    aliased_addresses: Vec<AliasedAddress>,
2249
2250    /// The base charge for each command in a programmable transaction. This is a fixed cost to
2251    /// account for the overhead of processing each command.
2252    translation_per_command_base_charge: Option<u64>,
2253
2254    /// The base charge for each input in a programmable transaction regardless of if it is used or
2255    /// not, or a pure/object/funds withdrawal input.
2256    translation_per_input_base_charge: Option<u64>,
2257
2258    /// The base charge for each byte of pure input in a programmable transaction.
2259    translation_pure_input_per_byte_charge: Option<u64>,
2260
2261    /// The multiplier for the number of type nodes when charging for type loading.
2262    /// This is multiplied by the number of type nodes to get the total cost.
2263    /// This should be a small number to avoid excessive gas costs for loading types.
2264    translation_per_type_node_charge: Option<u64>,
2265
2266    /// The multiplier for the number of type references when charging for type checking and reference
2267    /// checking.
2268    translation_per_reference_node_charge: Option<u64>,
2269
2270    /// The multiplier for each linkage entry when charging for linkage tables that we have
2271    /// created.
2272    translation_per_linkage_entry_charge: Option<u64>,
2273
2274    /// The maximum number of updates per settlement transaction.
2275    max_updates_per_settlement_txn: Option<u32>,
2276
2277    /// Maximum computation units allowed for a gasless transaction.
2278    gasless_max_computation_units: Option<u64>,
2279
2280    /// Allowed token types for gasless transactions, with minimum transfer sizes per token.
2281    gasless_allowed_token_types: Option<Vec<(String, u64)>>,
2282
2283    /// Maximum number of unused Pure inputs allowed in a gasless transaction.
2284    /// Object and FundsWithdrawal inputs must always be used.
2285    /// When None, there is no limit (effectively unlimited).
2286    gasless_max_unused_inputs: Option<u64>,
2287
2288    /// Maximum size in bytes of each Pure input in a gasless transaction.
2289    /// When None, there is no limit (effectively unlimited).
2290    gasless_max_pure_input_bytes: Option<u64>,
2291
2292    /// Max tps for gasless transactions. Unlimited when unset, zero when set to zero.
2293    gasless_max_tps: Option<u64>,
2294
2295    #[serde(skip_serializing_if = "Option::is_none")]
2296    #[skip_accessor]
2297    include_special_package_amendments: Option<Arc<Amendments>>,
2298
2299    /// Maximum serialized size in bytes of a gasless transaction (SenderSignedData).
2300    /// Bounds the persistent storage impact of each admitted gasless transaction.
2301    gasless_max_tx_size_bytes: Option<u64>,
2302
2303    /// The multiplier for each live reference charging per-command. Only used when
2304    /// `allow_references_in_ptbs` is enabled.
2305    translation_per_live_reference_charge: Option<u64>,
2306
2307    /// The maximum number of live references while checking a command. Only used when
2308    /// `allow_references_in_ptbs` is enabled.
2309    max_ptb_live_references: Option<u64>,
2310
2311    /// The maximum number of references returned by a command. Only used when
2312    /// `allow_references_in_ptbs` is enabled.
2313    max_ptb_returned_references: Option<u64>,
2314
2315    /// The maximum number of references returned over the course of the transaction. Only used
2316    /// when `allow_references_in_ptbs` is enabled.
2317    max_ptb_total_returned_references: Option<u64>,
2318}
2319
2320/// An aliased address.
2321#[derive(Clone, Serialize, Deserialize, Debug)]
2322pub struct AliasedAddress {
2323    /// The original address.
2324    pub original: [u8; 32],
2325    /// An aliased address which is allowed to act as the original address.
2326    pub aliased: [u8; 32],
2327    /// A list of transaction digests for which the aliasing is allowed to be in effect.
2328    pub allowed_tx_digests: Vec<[u8; 32]>,
2329}
2330
2331// feature flags
2332impl ProtocolConfig {
2333    /// The chain this config was instantiated for (see the `chain` field).
2334    pub fn chain(&self) -> Chain {
2335        self.chain
2336    }
2337
2338    // Add checks for feature flag support here, e.g.:
2339    // pub fn check_new_protocol_feature_supported(&self) -> Result<(), Error> {
2340    //     if self.feature_flags.new_protocol_feature_supported {
2341    //         Ok(())
2342    //     } else {
2343    //         Err(Error(format!(
2344    //             "new_protocol_feature is not supported at {:?}",
2345    //             self.version
2346    //         )))
2347    //     }
2348    // }
2349
2350    pub fn check_package_upgrades_supported(&self) -> Result<(), Error> {
2351        if self.feature_flags.package_upgrades {
2352            Ok(())
2353        } else {
2354            Err(Error(format!(
2355                "package upgrades are not supported at {:?}",
2356                self.version
2357            )))
2358        }
2359    }
2360
2361    pub fn zklogin_supported_providers(&self) -> &BTreeSet<String> {
2362        &self.feature_flags.zklogin_supported_providers
2363    }
2364
2365    /// zkLogin circuit verify mode: 0 = v1 circuit only, 1 = v2 circuit with
2366    /// fallback to v1, 2 = v2 circuit only.
2367    pub fn zklogin_circuit_mode(&self) -> u64 {
2368        self.feature_flags.zklogin_circuit_mode
2369    }
2370
2371    pub fn consensus_transaction_ordering(&self) -> ConsensusTransactionOrdering {
2372        self.feature_flags.consensus_transaction_ordering
2373    }
2374
2375    // Hand-written because the field is `#[skip_accessor]`; see FeatureFlags.
2376    pub fn mldsa65_auth(&self) -> bool {
2377        self.feature_flags.mldsa65_auth
2378    }
2379
2380    pub fn set_mldsa65_auth_for_testing(&mut self, val: bool) {
2381        self.feature_flags.mldsa65_auth = val;
2382    }
2383
2384    pub fn enable_jwk_consensus_updates(&self) -> bool {
2385        let ret = self.feature_flags.enable_jwk_consensus_updates;
2386        if ret {
2387            // jwk updates required end-of-epoch transactions
2388            assert!(self.feature_flags.end_of_epoch_transaction_supported);
2389        }
2390        ret
2391    }
2392
2393    pub fn end_of_epoch_transaction_supported(&self) -> bool {
2394        let ret = self.feature_flags.end_of_epoch_transaction_supported;
2395        if !ret {
2396            // jwk updates required end-of-epoch transactions
2397            assert!(!self.feature_flags.enable_jwk_consensus_updates);
2398        }
2399        ret
2400    }
2401
2402    pub fn dkg_version(&self) -> u64 {
2403        // Version 0 was deprecated and removed, the default is 1 if not set.
2404        self.random_beacon_dkg_version.unwrap_or(1)
2405    }
2406
2407    pub fn bridge(&self) -> bool {
2408        let ret = self.feature_flags.bridge;
2409        if ret {
2410            // bridge required end-of-epoch transactions
2411            assert!(self.feature_flags.end_of_epoch_transaction_supported);
2412        }
2413        ret
2414    }
2415
2416    pub fn should_try_to_finalize_bridge_committee(&self) -> bool {
2417        if !self.bridge() {
2418            return false;
2419        }
2420        // In the older protocol version, always try to finalize the committee.
2421        self.bridge_should_try_to_finalize_committee.unwrap_or(true)
2422    }
2423
2424    pub fn zklogin_max_epoch_upper_bound_delta(&self) -> Option<u64> {
2425        self.feature_flags.zklogin_max_epoch_upper_bound_delta
2426    }
2427
2428    pub fn enable_allowances(&self) -> bool {
2429        self.feature_flags.enable_allowances && self.enable_accumulators()
2430    }
2431
2432    pub fn enable_coin_reservation_obj_refs(&self) -> bool {
2433        self.new_vm_enabled() && self.feature_flags.enable_coin_reservation_obj_refs
2434    }
2435
2436    pub fn enable_authenticated_event_streams(&self) -> bool {
2437        self.feature_flags.enable_authenticated_event_streams && self.enable_accumulators()
2438    }
2439
2440    pub fn per_object_congestion_control_mode(&self) -> PerObjectCongestionControlMode {
2441        self.feature_flags.per_object_congestion_control_mode
2442    }
2443
2444    pub fn consensus_choice(&self) -> ConsensusChoice {
2445        self.feature_flags.consensus_choice
2446    }
2447
2448    pub fn consensus_network(&self) -> ConsensusNetwork {
2449        self.feature_flags.consensus_network
2450    }
2451
2452    pub fn mysticeti_num_leaders_per_round(&self) -> Option<usize> {
2453        self.feature_flags.mysticeti_num_leaders_per_round
2454    }
2455
2456    pub fn max_transaction_size_bytes(&self) -> u64 {
2457        // Provide a default value if protocol config version is too low.
2458        self.consensus_max_transaction_size_bytes
2459            .unwrap_or(256 * 1024)
2460    }
2461
2462    pub fn max_transactions_in_block_bytes(&self) -> u64 {
2463        if cfg!(msim) {
2464            256 * 1024
2465        } else {
2466            self.consensus_max_transactions_in_block_bytes
2467                .unwrap_or(512 * 1024)
2468        }
2469    }
2470
2471    pub fn max_num_transactions_in_block(&self) -> u64 {
2472        if cfg!(msim) {
2473            8
2474        } else {
2475            self.consensus_max_num_transactions_in_block.unwrap_or(512)
2476        }
2477    }
2478
2479    pub fn gc_depth(&self) -> u32 {
2480        self.consensus_gc_depth.unwrap_or(0)
2481    }
2482
2483    pub fn consensus_linearize_subdag_v2(&self) -> bool {
2484        let res = self.feature_flags.consensus_linearize_subdag_v2;
2485        assert!(
2486            !res || self.gc_depth() > 0,
2487            "The consensus linearize sub dag V2 requires GC to be enabled"
2488        );
2489        res
2490    }
2491
2492    pub fn consensus_median_based_commit_timestamp(&self) -> bool {
2493        let res = self.feature_flags.consensus_median_based_commit_timestamp;
2494        assert!(
2495            !res || self.gc_depth() > 0,
2496            "The consensus median based commit timestamp requires GC to be enabled"
2497        );
2498        res
2499    }
2500
2501    pub fn get_consensus_commit_rate_estimation_window_size(&self) -> u32 {
2502        self.consensus_commit_rate_estimation_window_size
2503            .unwrap_or(0)
2504    }
2505
2506    pub fn consensus_num_requested_prior_commits_at_startup(&self) -> u32 {
2507        // Currently there is only one parameter driving this value. If there are multiple
2508        // things computed from prior consensus commits, this function must return the max
2509        // of all of them.
2510        let window_size = self.get_consensus_commit_rate_estimation_window_size();
2511        // Ensure we are not using past commits without recording a state digest in the prologue.
2512        assert!(window_size == 0 || self.record_additional_state_digest_in_prologue());
2513        window_size
2514    }
2515
2516    pub fn address_aliases(&self) -> bool {
2517        let address_aliases = self.feature_flags.address_aliases;
2518        assert!(
2519            !address_aliases || self.mysticeti_fastpath(),
2520            "Address aliases requires Mysticeti fastpath to be enabled"
2521        );
2522        if address_aliases {
2523            assert!(
2524                self.feature_flags.disable_preconsensus_locking,
2525                "Address aliases requires CertifiedTransaction to be disabled"
2526            );
2527        }
2528        address_aliases
2529    }
2530
2531    pub fn new_vm_enabled(&self) -> bool {
2532        self.execution_version.is_some_and(|v| v >= 4)
2533    }
2534
2535    pub fn gasless_allowed_token_types(&self) -> &[(String, u64)] {
2536        debug_assert!(self.gasless_allowed_token_types.is_some());
2537        self.gasless_allowed_token_types.as_deref().unwrap_or(&[])
2538    }
2539
2540    pub fn get_gasless_max_unused_inputs(&self) -> u64 {
2541        self.gasless_max_unused_inputs.unwrap_or(u64::MAX)
2542    }
2543
2544    pub fn get_gasless_max_pure_input_bytes(&self) -> u64 {
2545        self.gasless_max_pure_input_bytes.unwrap_or(u64::MAX)
2546    }
2547
2548    pub fn get_gasless_max_tx_size_bytes(&self) -> u64 {
2549        self.gasless_max_tx_size_bytes.unwrap_or(u64::MAX)
2550    }
2551
2552    pub fn include_special_package_amendments_as_option(&self) -> &Option<Arc<Amendments>> {
2553        &self.include_special_package_amendments
2554    }
2555}
2556
2557static POISON_VERSION_METHODS: AtomicBool = AtomicBool::new(false);
2558
2559// Instantiations for each protocol version.
2560impl ProtocolConfig {
2561    /// Get the value ProtocolConfig that are in effect during the given protocol version.
2562    pub fn get_for_version(version: ProtocolVersion, chain: Chain) -> Self {
2563        // ProtocolVersion can be deserialized so we need to check it here as well.
2564        assert!(
2565            version >= ProtocolVersion::MIN,
2566            "Network protocol version is {:?}, but the minimum supported version by the binary is {:?}. Please upgrade the binary.",
2567            version,
2568            ProtocolVersion::MIN.0,
2569        );
2570        assert!(
2571            version <= ProtocolVersion::MAX_ALLOWED,
2572            "Network protocol version is {:?}, but the maximum supported version by the binary is {:?}. Please upgrade the binary.",
2573            version,
2574            ProtocolVersion::MAX_ALLOWED.0,
2575        );
2576
2577        let mut ret = Self::get_for_version_impl(version, chain);
2578        ret.version = version;
2579        ret.chain = chain;
2580
2581        ret = Self::apply_config_override(version, ret);
2582
2583        if std::env::var("SUI_PROTOCOL_CONFIG_OVERRIDE_ENABLE").is_ok() {
2584            warn!(
2585                "overriding ProtocolConfig settings with custom settings; this may break non-local networks"
2586            );
2587            let overrides: ProtocolConfigOptional =
2588                serde_env::from_env_with_prefix("SUI_PROTOCOL_CONFIG_OVERRIDE")
2589                    .expect("failed to parse ProtocolConfig override env variables");
2590            overrides.apply_to(&mut ret);
2591        }
2592
2593        ret
2594    }
2595
2596    /// Get the value ProtocolConfig that are in effect during the given protocol version.
2597    /// Or none if the version is not supported.
2598    pub fn get_for_version_if_supported(version: ProtocolVersion, chain: Chain) -> Option<Self> {
2599        if version.0 >= ProtocolVersion::MIN.0 && version.0 <= ProtocolVersion::MAX_ALLOWED.0 {
2600            let mut ret = Self::get_for_version_impl(version, chain);
2601            ret.version = version;
2602            ret.chain = chain;
2603            ret = Self::apply_config_override(version, ret);
2604            Some(ret)
2605        } else {
2606            None
2607        }
2608    }
2609
2610    pub fn poison_get_for_min_version() {
2611        POISON_VERSION_METHODS.store(true, Ordering::Relaxed);
2612    }
2613
2614    fn load_poison_get_for_min_version() -> bool {
2615        POISON_VERSION_METHODS.load(Ordering::Relaxed)
2616    }
2617
2618    /// Convenience to get the constants at the current minimum supported version.
2619    /// Mainly used by client code that may not yet be protocol-version aware.
2620    pub fn get_for_min_version() -> Self {
2621        if Self::load_poison_get_for_min_version() {
2622            panic!("get_for_min_version called on validator");
2623        }
2624        ProtocolConfig::get_for_version(ProtocolVersion::MIN, Chain::Unknown)
2625    }
2626
2627    /// CAREFUL! - You probably want to use `get_for_version` instead.
2628    ///
2629    /// Convenience to get the constants at the current maximum supported version.
2630    /// Mainly used by genesis. Note well that this function uses the max version
2631    /// supported locally by the node, which is not necessarily the current version
2632    /// of the network. ALSO, this function disregards chain specific config (by
2633    /// using Chain::Unknown), thereby potentially returning a protocol config that
2634    /// is incorrect for some feature flags. Definitely safe for testing and for
2635    /// protocol version 11 and prior.
2636    #[allow(non_snake_case)]
2637    pub fn get_for_max_version_UNSAFE() -> Self {
2638        if Self::load_poison_get_for_min_version() {
2639            panic!("get_for_max_version_UNSAFE called on validator");
2640        }
2641        ProtocolConfig::get_for_version(ProtocolVersion::MAX, Chain::Unknown)
2642    }
2643
2644    fn get_for_version_impl(version: ProtocolVersion, chain: Chain) -> Self {
2645        #[cfg(msim)]
2646        {
2647            // populate the fake simulator version # with a different base tx cost.
2648            if version == ProtocolVersion::MAX_ALLOWED {
2649                let mut config = Self::get_for_version_impl(version - 1, Chain::Unknown);
2650                config.base_tx_cost_fixed = Some(config.base_tx_cost_fixed() + 1000);
2651                return config;
2652            }
2653        }
2654
2655        // IMPORTANT: Never modify the value of any constant for a pre-existing protocol version.
2656        // To change the values here you must create a new protocol version with the new values!
2657        let mut cfg = Self {
2658            // will be overwritten before being returned
2659            version,
2660            chain,
2661
2662            // All flags are disabled in V1
2663            feature_flags: Default::default(),
2664
2665            max_tx_size_bytes: Some(128 * 1024),
2666            // We need this number to be at least 100x less than `max_serialized_tx_effects_size_bytes`otherwise effects can be huge
2667            max_input_objects: Some(2048),
2668            max_serialized_tx_effects_size_bytes: Some(512 * 1024),
2669            max_serialized_tx_effects_size_bytes_system_tx: Some(512 * 1024 * 16),
2670            max_gas_payment_objects: Some(256),
2671            max_modules_in_publish: Some(128),
2672            max_package_dependencies: None,
2673            max_arguments: Some(512),
2674            max_type_arguments: Some(16),
2675            max_type_argument_depth: Some(16),
2676            max_pure_argument_size: Some(16 * 1024),
2677            max_programmable_tx_commands: Some(1024),
2678            move_binary_format_version: Some(6),
2679            min_move_binary_format_version: None,
2680            binary_module_handles: None,
2681            binary_struct_handles: None,
2682            binary_function_handles: None,
2683            binary_function_instantiations: None,
2684            binary_signatures: None,
2685            binary_constant_pool: None,
2686            binary_identifiers: None,
2687            binary_address_identifiers: None,
2688            binary_struct_defs: None,
2689            binary_struct_def_instantiations: None,
2690            binary_function_defs: None,
2691            binary_field_handles: None,
2692            binary_field_instantiations: None,
2693            binary_friend_decls: None,
2694            binary_enum_defs: None,
2695            binary_enum_def_instantiations: None,
2696            binary_variant_handles: None,
2697            binary_variant_instantiation_handles: None,
2698            max_move_object_size: Some(250 * 1024),
2699            max_move_package_size: Some(100 * 1024),
2700            max_publish_or_upgrade_per_ptb: None,
2701            max_tx_gas: Some(10_000_000_000),
2702            max_gas_price: Some(100_000),
2703            max_gas_price_rgp_factor_for_aborted_transactions: None,
2704            max_gas_computation_bucket: Some(5_000_000),
2705            max_loop_depth: Some(5),
2706            max_generic_instantiation_length: Some(32),
2707            max_function_parameters: Some(128),
2708            max_basic_blocks: Some(1024),
2709            max_value_stack_size: Some(1024),
2710            max_type_nodes: Some(256),
2711            max_generic_instantiation_type_nodes_per_function: None,
2712            max_generic_instantiation_type_nodes_per_module: None,
2713            max_accumulator_type_nodes: None,
2714            max_push_size: Some(10000),
2715            max_struct_definitions: Some(200),
2716            max_function_definitions: Some(1000),
2717            max_fields_in_struct: Some(32),
2718            max_dependency_depth: Some(100),
2719            max_num_event_emit: Some(256),
2720            max_num_new_move_object_ids: Some(2048),
2721            max_num_new_move_object_ids_system_tx: Some(2048 * 16),
2722            max_num_deleted_move_object_ids: Some(2048),
2723            max_num_deleted_move_object_ids_system_tx: Some(2048 * 16),
2724            max_num_transferred_move_object_ids: Some(2048),
2725            max_num_transferred_move_object_ids_system_tx: Some(2048 * 16),
2726            max_event_emit_size: Some(250 * 1024),
2727            max_move_vector_len: Some(256 * 1024),
2728            max_type_to_layout_nodes: None,
2729            max_ptb_value_size: None,
2730
2731            max_back_edges_per_function: Some(10_000),
2732            max_back_edges_per_module: Some(10_000),
2733            max_verifier_meter_ticks_per_function: Some(6_000_000),
2734            max_meter_ticks_per_module: Some(6_000_000),
2735            max_meter_ticks_per_package: None,
2736
2737            object_runtime_max_num_cached_objects: Some(1000),
2738            object_runtime_max_num_cached_objects_system_tx: Some(1000 * 16),
2739            object_runtime_max_num_store_entries: Some(1000),
2740            object_runtime_max_num_store_entries_system_tx: Some(1000 * 16),
2741            base_tx_cost_fixed: Some(110_000),
2742            package_publish_cost_fixed: Some(1_000),
2743            base_tx_cost_per_byte: Some(0),
2744            package_publish_cost_per_byte: Some(80),
2745            obj_access_cost_read_per_byte: Some(15),
2746            obj_access_cost_read_per_package_kb: None,
2747            obj_access_cost_mutate_per_byte: Some(40),
2748            obj_access_cost_delete_per_byte: Some(40),
2749            obj_access_cost_verify_per_byte: Some(200),
2750            obj_data_cost_refundable: Some(100),
2751            obj_metadata_cost_non_refundable: Some(50),
2752            gas_model_version: Some(1),
2753            storage_rebate_rate: Some(9900),
2754            storage_fund_reinvest_rate: Some(500),
2755            reward_slashing_rate: Some(5000),
2756            storage_gas_price: Some(1),
2757            accumulator_object_storage_cost: None,
2758            max_transactions_per_checkpoint: Some(10_000),
2759            max_checkpoint_size_bytes: Some(30 * 1024 * 1024),
2760
2761            // For now, perform upgrades with a bare quorum of validators.
2762            // MUSTFIX: This number should be increased to at least 2000 (20%) for mainnet.
2763            buffer_stake_for_protocol_upgrade_bps: Some(0),
2764
2765            // === Native Function Costs ===
2766            // `address` module
2767            // Cost params for the Move native function `address::from_bytes(bytes: vector<u8>)`
2768            address_from_bytes_cost_base: Some(52),
2769            // Cost params for the Move native function `address::to_u256(address): u256`
2770            address_to_u256_cost_base: Some(52),
2771            // Cost params for the Move native function `address::from_u256(u256): address`
2772            address_from_u256_cost_base: Some(52),
2773
2774            // `config` module
2775            // Cost params for the Move native function `read_setting_impl``
2776            config_read_setting_impl_cost_base: None,
2777            config_read_setting_impl_cost_per_byte: None,
2778
2779            package_original_package_id_impl_cost_base: None,
2780            package_original_package_id_impl_cost_per_byte: None,
2781
2782            // `dynamic_field` module
2783            // Cost params for the Move native function `hash_type_and_key<K: copy + drop + store>(parent: address, k: K): address`
2784            dynamic_field_hash_type_and_key_cost_base: Some(100),
2785            dynamic_field_hash_type_and_key_type_cost_per_byte: Some(2),
2786            dynamic_field_hash_type_and_key_value_cost_per_byte: Some(2),
2787            dynamic_field_hash_type_and_key_type_tag_cost_per_byte: Some(2),
2788            // Cost params for the Move native function `add_child_object<Child: key>(parent: address, child: Child)`
2789            dynamic_field_add_child_object_cost_base: Some(100),
2790            dynamic_field_add_child_object_type_cost_per_byte: Some(10),
2791            dynamic_field_add_child_object_value_cost_per_byte: Some(10),
2792            dynamic_field_add_child_object_struct_tag_cost_per_byte: Some(10),
2793            // Cost params for the Move native function `borrow_child_object_mut<Child: key>(parent: &mut UID, id: address): &mut Child`
2794            dynamic_field_borrow_child_object_cost_base: Some(100),
2795            dynamic_field_borrow_child_object_child_ref_cost_per_byte: Some(10),
2796            dynamic_field_borrow_child_object_type_cost_per_byte: Some(10),
2797            // Cost params for the Move native function `remove_child_object<Child: key>(parent: address, id: address): Child`
2798            dynamic_field_remove_child_object_cost_base: Some(100),
2799            dynamic_field_remove_child_object_child_cost_per_byte: Some(2),
2800            dynamic_field_remove_child_object_type_cost_per_byte: Some(2),
2801            // Cost params for the Move native function `has_child_object(parent: address, id: address): bool`
2802            dynamic_field_has_child_object_cost_base: Some(100),
2803            // Cost params for the Move native function `has_child_object_with_ty<Child: key>(parent: address, id: address): bool`
2804            dynamic_field_has_child_object_with_ty_cost_base: Some(100),
2805            dynamic_field_has_child_object_with_ty_type_cost_per_byte: Some(2),
2806            dynamic_field_has_child_object_with_ty_type_tag_cost_per_byte: Some(2),
2807
2808            // `scratch` module: introduced in protocol version 130
2809            scratch_add_cost_base: None,
2810            scratch_read_cost_base: None,
2811            scratch_read_value_cost: None,
2812            scratch_remove_cost_base: None,
2813            scratch_exists_cost_base: None,
2814            scratch_exists_with_type_cost_base: None,
2815            scratch_exists_with_type_type_cost: None,
2816            max_scratch_pad_size: None,
2817
2818            // `event` module
2819            // Cost params for the Move native function `event::emit<T: copy + drop>(event: T)`
2820            event_emit_cost_base: Some(52),
2821            event_emit_value_size_derivation_cost_per_byte: Some(2),
2822            event_emit_tag_size_derivation_cost_per_byte: Some(5),
2823            event_emit_output_cost_per_byte: Some(10),
2824            event_emit_auth_stream_cost: None,
2825
2826            // `funds_accumulator` module: introduced in protocol version 137.
2827            reserve_object_funds_for_withdrawal_cost_base: None,
2828            reserve_object_funds_for_withdrawal_cold_read_cost: None,
2829
2830            //  `object` module
2831            // Cost params for the Move native function `borrow_uid<T: key>(obj: &T): &UID`
2832            object_borrow_uid_cost_base: Some(52),
2833            // Cost params for the Move native function `delete_impl(id: address)`
2834            object_delete_impl_cost_base: Some(52),
2835            // Cost params for the Move native function `record_new_uid(id: address)`
2836            object_record_new_uid_cost_base: Some(52),
2837            // Cost params for the Move native function
2838            // `record_new_uid_from_hash(parent: address, bytes: address)`. Introduced in v131.
2839            object_record_new_uid_from_hash_cost_base: None,
2840
2841            // `transfer` module
2842            // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
2843            transfer_transfer_internal_cost_base: Some(52),
2844            // Cost params for the Move native function `party_transfer_impl<T: key>(obj: T, party_members: vector<address>)`
2845            transfer_party_transfer_internal_cost_base: None,
2846            // Cost params for the Move native function `freeze_object<T: key>(obj: T)`
2847            transfer_freeze_object_cost_base: Some(52),
2848            // Cost params for the Move native function `share_object<T: key>(obj: T)`
2849            transfer_share_object_cost_base: Some(52),
2850            transfer_receive_object_cost_base: None,
2851            transfer_receive_object_type_cost_per_byte: None,
2852            transfer_receive_object_cost_per_byte: None,
2853
2854            // `tx_context` module
2855            // Cost params for the Move native function `transfer_impl<T: key>(obj: T, recipient: address)`
2856            tx_context_derive_id_cost_base: Some(52),
2857            tx_context_fresh_id_cost_base: None,
2858            tx_context_sender_cost_base: None,
2859            tx_context_epoch_cost_base: None,
2860            tx_context_epoch_timestamp_ms_cost_base: None,
2861            tx_context_sponsor_cost_base: None,
2862            tx_context_rgp_cost_base: None,
2863            tx_context_gas_price_cost_base: None,
2864            tx_context_gas_budget_cost_base: None,
2865            tx_context_ids_created_cost_base: None,
2866            tx_context_replace_cost_base: None,
2867
2868            // `types` module
2869            // Cost params for the Move native function `is_one_time_witness<T: drop>(_: &T): bool`
2870            types_is_one_time_witness_cost_base: Some(52),
2871            types_is_one_time_witness_type_tag_cost_per_byte: Some(2),
2872            types_is_one_time_witness_type_cost_per_byte: Some(2),
2873
2874            // `validator` module
2875            // Cost params for the Move native function `validate_metadata_bcs(metadata: vector<u8>)`
2876            validator_validate_metadata_cost_base: Some(52),
2877            validator_validate_metadata_data_cost_per_byte: Some(2),
2878
2879            // Crypto
2880            crypto_invalid_arguments_cost: Some(100),
2881            // bls12381::bls12381_min_pk_verify
2882            bls12381_bls12381_min_sig_verify_cost_base: Some(52),
2883            bls12381_bls12381_min_sig_verify_msg_cost_per_byte: Some(2),
2884            bls12381_bls12381_min_sig_verify_msg_cost_per_block: Some(2),
2885
2886            // bls12381::bls12381_min_pk_verify
2887            bls12381_bls12381_min_pk_verify_cost_base: Some(52),
2888            bls12381_bls12381_min_pk_verify_msg_cost_per_byte: Some(2),
2889            bls12381_bls12381_min_pk_verify_msg_cost_per_block: Some(2),
2890
2891            // ecdsa_k1::ecrecover
2892            ecdsa_k1_ecrecover_keccak256_cost_base: Some(52),
2893            ecdsa_k1_ecrecover_keccak256_msg_cost_per_byte: Some(2),
2894            ecdsa_k1_ecrecover_keccak256_msg_cost_per_block: Some(2),
2895            ecdsa_k1_ecrecover_sha256_cost_base: Some(52),
2896            ecdsa_k1_ecrecover_sha256_msg_cost_per_byte: Some(2),
2897            ecdsa_k1_ecrecover_sha256_msg_cost_per_block: Some(2),
2898
2899            // ecdsa_k1::decompress_pubkey
2900            ecdsa_k1_decompress_pubkey_cost_base: Some(52),
2901
2902            // ecdsa_k1::secp256k1_verify
2903            ecdsa_k1_secp256k1_verify_keccak256_cost_base: Some(52),
2904            ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_byte: Some(2),
2905            ecdsa_k1_secp256k1_verify_keccak256_msg_cost_per_block: Some(2),
2906            ecdsa_k1_secp256k1_verify_sha256_cost_base: Some(52),
2907            ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_byte: Some(2),
2908            ecdsa_k1_secp256k1_verify_sha256_msg_cost_per_block: Some(2),
2909
2910            // ecdsa_r1::ecrecover
2911            ecdsa_r1_ecrecover_keccak256_cost_base: Some(52),
2912            ecdsa_r1_ecrecover_keccak256_msg_cost_per_byte: Some(2),
2913            ecdsa_r1_ecrecover_keccak256_msg_cost_per_block: Some(2),
2914            ecdsa_r1_ecrecover_sha256_cost_base: Some(52),
2915            ecdsa_r1_ecrecover_sha256_msg_cost_per_byte: Some(2),
2916            ecdsa_r1_ecrecover_sha256_msg_cost_per_block: Some(2),
2917
2918            // ecdsa_r1::secp256k1_verify
2919            ecdsa_r1_secp256r1_verify_keccak256_cost_base: Some(52),
2920            ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_byte: Some(2),
2921            ecdsa_r1_secp256r1_verify_keccak256_msg_cost_per_block: Some(2),
2922            ecdsa_r1_secp256r1_verify_sha256_cost_base: Some(52),
2923            ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_byte: Some(2),
2924            ecdsa_r1_secp256r1_verify_sha256_msg_cost_per_block: Some(2),
2925
2926            // ecvrf::verify
2927            ecvrf_ecvrf_verify_cost_base: Some(52),
2928            ecvrf_ecvrf_verify_alpha_string_cost_per_byte: Some(2),
2929            ecvrf_ecvrf_verify_alpha_string_cost_per_block: Some(2),
2930
2931            // ed25519
2932            ed25519_ed25519_verify_cost_base: Some(52),
2933            ed25519_ed25519_verify_msg_cost_per_byte: Some(2),
2934            ed25519_ed25519_verify_msg_cost_per_block: Some(2),
2935
2936            // groth16::prepare_verifying_key
2937            groth16_prepare_verifying_key_bls12381_cost_base: Some(52),
2938            groth16_prepare_verifying_key_bn254_cost_base: Some(52),
2939
2940            // groth16::verify_groth16_proof_internal
2941            groth16_verify_groth16_proof_internal_bls12381_cost_base: Some(52),
2942            groth16_verify_groth16_proof_internal_bls12381_cost_per_public_input: Some(2),
2943            groth16_verify_groth16_proof_internal_bn254_cost_base: Some(52),
2944            groth16_verify_groth16_proof_internal_bn254_cost_per_public_input: Some(2),
2945            groth16_verify_groth16_proof_internal_public_input_cost_per_byte: Some(2),
2946
2947            // hash::blake2b256
2948            hash_blake2b256_cost_base: Some(52),
2949            hash_blake2b256_data_cost_per_byte: Some(2),
2950            hash_blake2b256_data_cost_per_block: Some(2),
2951
2952            // hash::keccak256
2953            hash_keccak256_cost_base: Some(52),
2954            hash_keccak256_data_cost_per_byte: Some(2),
2955            hash_keccak256_data_cost_per_block: Some(2),
2956
2957            poseidon_bn254_cost_base: None,
2958            poseidon_bn254_cost_per_block: None,
2959
2960            // hmac::hmac_sha3_256
2961            hmac_hmac_sha3_256_cost_base: Some(52),
2962            hmac_hmac_sha3_256_input_cost_per_byte: Some(2),
2963            hmac_hmac_sha3_256_input_cost_per_block: Some(2),
2964
2965            // group ops
2966            group_ops_bls12381_decode_scalar_cost: None,
2967            group_ops_bls12381_decode_g1_cost: None,
2968            group_ops_bls12381_decode_g2_cost: None,
2969            group_ops_bls12381_decode_gt_cost: None,
2970            group_ops_bls12381_scalar_add_cost: None,
2971            group_ops_bls12381_g1_add_cost: None,
2972            group_ops_bls12381_g2_add_cost: None,
2973            group_ops_bls12381_gt_add_cost: None,
2974            group_ops_bls12381_scalar_sub_cost: None,
2975            group_ops_bls12381_g1_sub_cost: None,
2976            group_ops_bls12381_g2_sub_cost: None,
2977            group_ops_bls12381_gt_sub_cost: None,
2978            group_ops_bls12381_scalar_mul_cost: None,
2979            group_ops_bls12381_g1_mul_cost: None,
2980            group_ops_bls12381_g2_mul_cost: None,
2981            group_ops_bls12381_gt_mul_cost: None,
2982            group_ops_bls12381_scalar_div_cost: None,
2983            group_ops_bls12381_g1_div_cost: None,
2984            group_ops_bls12381_g2_div_cost: None,
2985            group_ops_bls12381_gt_div_cost: None,
2986            group_ops_bls12381_g1_hash_to_base_cost: None,
2987            group_ops_bls12381_g2_hash_to_base_cost: None,
2988            group_ops_bls12381_g1_hash_to_cost_per_byte: None,
2989            group_ops_bls12381_g2_hash_to_cost_per_byte: None,
2990            group_ops_bls12381_g1_msm_base_cost: None,
2991            group_ops_bls12381_g2_msm_base_cost: None,
2992            group_ops_bls12381_g1_msm_base_cost_per_input: None,
2993            group_ops_bls12381_g2_msm_base_cost_per_input: None,
2994            group_ops_bls12381_msm_max_len: None,
2995            group_ops_bls12381_pairing_cost: None,
2996            group_ops_bls12381_g1_to_uncompressed_g1_cost: None,
2997            group_ops_bls12381_uncompressed_g1_to_g1_cost: None,
2998            group_ops_bls12381_uncompressed_g1_sum_base_cost: None,
2999            group_ops_bls12381_uncompressed_g1_sum_cost_per_term: None,
3000            group_ops_bls12381_uncompressed_g1_sum_max_terms: None,
3001
3002            group_ops_ristretto_decode_scalar_cost: None,
3003            group_ops_ristretto_decode_point_cost: None,
3004            group_ops_ristretto_scalar_add_cost: None,
3005            group_ops_ristretto_point_add_cost: None,
3006            group_ops_ristretto_scalar_sub_cost: None,
3007            group_ops_ristretto_point_sub_cost: None,
3008            group_ops_ristretto_scalar_mul_cost: None,
3009            group_ops_ristretto_point_mul_cost: None,
3010            group_ops_ristretto_scalar_div_cost: None,
3011            group_ops_ristretto_point_div_cost: None,
3012
3013            verify_bulletproofs_ristretto255_base_cost: None,
3014            verify_bulletproofs_ristretto255_cost_per_bit_and_commitment: None,
3015            max_bulletproofs_total_bits: None,
3016
3017            // zklogin::check_zklogin_id
3018            check_zklogin_id_cost_base: None,
3019            // zklogin::check_zklogin_issuer
3020            check_zklogin_issuer_cost_base: None,
3021
3022            vdf_verify_vdf_cost: None,
3023            vdf_hash_to_input_cost: None,
3024
3025            // nitro_attestation::verify_nitro_attestation
3026            nitro_attestation_parse_base_cost: None,
3027            nitro_attestation_parse_cost_per_byte: None,
3028            nitro_attestation_verify_base_cost: None,
3029            nitro_attestation_verify_cost_per_cert: None,
3030
3031            bcs_per_byte_serialized_cost: None,
3032            bcs_legacy_min_output_size_cost: None,
3033            bcs_failure_cost: None,
3034            hash_sha2_256_base_cost: None,
3035            hash_sha2_256_per_byte_cost: None,
3036            hash_sha2_256_legacy_min_input_len_cost: None,
3037            hash_sha3_256_base_cost: None,
3038            hash_sha3_256_per_byte_cost: None,
3039            hash_sha3_256_legacy_min_input_len_cost: None,
3040            type_name_get_base_cost: None,
3041            type_name_get_per_byte_cost: None,
3042            type_name_id_base_cost: None,
3043            string_check_utf8_base_cost: None,
3044            string_check_utf8_per_byte_cost: None,
3045            string_is_char_boundary_base_cost: None,
3046            string_sub_string_base_cost: None,
3047            string_sub_string_per_byte_cost: None,
3048            string_index_of_base_cost: None,
3049            string_index_of_per_byte_pattern_cost: None,
3050            string_index_of_per_byte_searched_cost: None,
3051            vector_empty_base_cost: None,
3052            vector_length_base_cost: None,
3053            vector_push_back_base_cost: None,
3054            vector_push_back_legacy_per_abstract_memory_unit_cost: None,
3055            vector_borrow_base_cost: None,
3056            vector_pop_back_base_cost: None,
3057            vector_destroy_empty_base_cost: None,
3058            vector_swap_base_cost: None,
3059            vector_reverse_base_cost: None,
3060            vector_reverse_per_elem_cost: None,
3061            vector_keep_range_base_cost: None,
3062            vector_keep_range_per_dropped_elem_cost: None,
3063            vector_keep_range_per_moved_elem_cost: None,
3064            vector_copy_range_base_cost: None,
3065            vector_replace_range_base_cost: None,
3066            vector_replace_range_per_elem_cost: None,
3067            debug_print_base_cost: None,
3068            debug_print_stack_trace_base_cost: None,
3069
3070            max_size_written_objects: None,
3071            max_size_written_objects_system_tx: None,
3072
3073            // ==== Ephemeral (consensus only) params deleted ====
3074            // Const params for consensus scoring decision
3075            // scoring_decision_mad_divisor: None,
3076            // scoring_decision_cutoff_value: None,
3077
3078            // Limits the length of a Move identifier
3079            max_move_identifier_len: None,
3080            max_move_value_depth: None,
3081            package_arena_size_in_bytes: None,
3082            max_move_enum_variants: None,
3083
3084            gas_rounding_step: None,
3085
3086            execution_version: None,
3087
3088            max_event_emit_size_total: None,
3089
3090            consensus_bad_nodes_stake_threshold: None,
3091
3092            max_jwk_votes_per_validator_per_epoch: None,
3093
3094            max_age_of_jwk_in_epochs: None,
3095
3096            random_beacon_reduction_allowed_delta: None,
3097
3098            random_beacon_reduction_lower_bound: None,
3099
3100            random_beacon_dkg_timeout_round: None,
3101
3102            random_beacon_min_round_interval_ms: None,
3103
3104            random_beacon_dkg_version: None,
3105
3106            consensus_max_transaction_size_bytes: None,
3107
3108            consensus_max_transactions_in_block_bytes: None,
3109
3110            consensus_max_num_transactions_in_block: None,
3111
3112            consensus_voting_rounds: None,
3113
3114            max_accumulated_txn_cost_per_object_in_narwhal_commit: None,
3115
3116            max_deferral_rounds_for_congestion_control: None,
3117
3118            epoch_close_deadline_ms: None,
3119
3120            max_txn_cost_overage_per_object_in_commit: None,
3121
3122            allowed_txn_cost_overage_burst_per_object_in_commit: None,
3123
3124            min_checkpoint_interval_ms: None,
3125
3126            checkpoint_summary_version_specific_data: None,
3127
3128            max_soft_bundle_size: None,
3129
3130            bridge_should_try_to_finalize_committee: None,
3131
3132            max_accumulated_txn_cost_per_object_in_mysticeti_commit: None,
3133
3134            max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit: None,
3135
3136            consensus_gc_depth: None,
3137
3138            gas_budget_based_txn_cost_cap_factor: None,
3139
3140            gas_budget_based_txn_cost_absolute_cap_commit_count: None,
3141
3142            sip_45_consensus_amplification_threshold: None,
3143
3144            use_object_per_epoch_marker_table_v2: None,
3145
3146            consensus_commit_rate_estimation_window_size: None,
3147
3148            aliased_addresses: vec![],
3149
3150            translation_per_command_base_charge: None,
3151            translation_per_input_base_charge: None,
3152            translation_pure_input_per_byte_charge: None,
3153            translation_per_type_node_charge: None,
3154            translation_per_reference_node_charge: None,
3155            translation_per_linkage_entry_charge: None,
3156            translation_per_live_reference_charge: None,
3157            max_ptb_live_references: None,
3158            max_ptb_returned_references: None,
3159            max_ptb_total_returned_references: None,
3160
3161            max_updates_per_settlement_txn: None,
3162
3163            gasless_max_computation_units: None,
3164            gasless_allowed_token_types: None,
3165            gasless_max_unused_inputs: None,
3166            gasless_max_pure_input_bytes: None,
3167            gasless_max_tps: None,
3168            include_special_package_amendments: None,
3169            gasless_max_tx_size_bytes: None,
3170            // When adding a new constant, set it to None in the earliest version, like this:
3171            // new_constant: None,
3172        };
3173        for cur in 2..=version.0 {
3174            match cur {
3175                1 => unreachable!(),
3176                2 => {
3177                    cfg.feature_flags.advance_epoch_start_time_in_safe_mode = true;
3178                }
3179                3 => {
3180                    // changes for gas model
3181                    cfg.gas_model_version = Some(2);
3182                    // max gas budget is in MIST and an absolute value 50SUI
3183                    cfg.max_tx_gas = Some(50_000_000_000);
3184                    // min gas budget is in MIST and an absolute value 2000MIST or 0.000002SUI
3185                    cfg.base_tx_cost_fixed = Some(2_000);
3186                    // storage gas price multiplier
3187                    cfg.storage_gas_price = Some(76);
3188                    cfg.feature_flags.loaded_child_objects_fixed = true;
3189                    // max size of written objects during a TXn
3190                    // this is a sum of all objects written during a TXn
3191                    cfg.max_size_written_objects = Some(5 * 1000 * 1000);
3192                    // max size of written objects during a system TXn to allow for larger writes
3193                    // akin to `max_size_written_objects` but for system TXns
3194                    cfg.max_size_written_objects_system_tx = Some(50 * 1000 * 1000);
3195                    cfg.feature_flags.package_upgrades = true;
3196                }
3197                // This is the first protocol version currently possible.
3198                // Mainnet starts with version 4. Previous versions are pre mainnet and have
3199                // all been wiped out.
3200                // Every other chain is after version 4.
3201                4 => {
3202                    // Change reward slashing rate to 100%.
3203                    cfg.reward_slashing_rate = Some(10000);
3204                    // protect old and new lookup for object version
3205                    cfg.gas_model_version = Some(3);
3206                }
3207                5 => {
3208                    cfg.feature_flags.missing_type_is_compatibility_error = true;
3209                    cfg.gas_model_version = Some(4);
3210                    cfg.feature_flags.scoring_decision_with_validity_cutoff = true;
3211                    // ==== Ephemeral (consensus only) params deleted ====
3212                    // cfg.scoring_decision_mad_divisor = Some(2.3);
3213                    // cfg.scoring_decision_cutoff_value = Some(2.5);
3214                }
3215                6 => {
3216                    cfg.gas_model_version = Some(5);
3217                    cfg.buffer_stake_for_protocol_upgrade_bps = Some(5000);
3218                    cfg.feature_flags.consensus_order_end_of_epoch_last = true;
3219                }
3220                7 => {
3221                    cfg.feature_flags.disallow_adding_abilities_on_upgrade = true;
3222                    cfg.feature_flags
3223                        .disable_invariant_violation_check_in_swap_loc = true;
3224                    cfg.feature_flags.ban_entry_init = true;
3225                    cfg.feature_flags.package_digest_hash_module = true;
3226                }
3227                8 => {
3228                    cfg.feature_flags
3229                        .disallow_change_struct_type_params_on_upgrade = true;
3230                }
3231                9 => {
3232                    // Limits the length of a Move identifier
3233                    cfg.max_move_identifier_len = Some(128);
3234                    cfg.feature_flags.no_extraneous_module_bytes = true;
3235                    cfg.feature_flags
3236                        .advance_to_highest_supported_protocol_version = true;
3237                }
3238                10 => {
3239                    cfg.max_verifier_meter_ticks_per_function = Some(16_000_000);
3240                    cfg.max_meter_ticks_per_module = Some(16_000_000);
3241                }
3242                11 => {
3243                    cfg.max_move_value_depth = Some(128);
3244                }
3245                12 => {
3246                    cfg.feature_flags.narwhal_versioned_metadata = true;
3247                    if chain != Chain::Mainnet {
3248                        cfg.feature_flags.commit_root_state_digest = true;
3249                    }
3250
3251                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3252                        cfg.feature_flags.zklogin_auth = true;
3253                    }
3254                }
3255                13 => {}
3256                14 => {
3257                    cfg.gas_rounding_step = Some(1_000);
3258                    cfg.gas_model_version = Some(6);
3259                }
3260                15 => {
3261                    cfg.feature_flags.consensus_transaction_ordering =
3262                        ConsensusTransactionOrdering::ByGasPrice;
3263                }
3264                16 => {
3265                    cfg.feature_flags.simplified_unwrap_then_delete = true;
3266                }
3267                17 => {
3268                    cfg.feature_flags.upgraded_multisig_supported = true;
3269                }
3270                18 => {
3271                    cfg.execution_version = Some(1);
3272                    // Following flags are implied by this execution version.  Once support for earlier
3273                    // protocol versions is dropped, these flags can be removed:
3274                    // cfg.feature_flags.package_upgrades = true;
3275                    // cfg.feature_flags.disallow_adding_abilities_on_upgrade = true;
3276                    // cfg.feature_flags.disallow_change_struct_type_params_on_upgrade = true;
3277                    // cfg.feature_flags.loaded_child_objects_fixed = true;
3278                    // cfg.feature_flags.ban_entry_init = true;
3279                    // cfg.feature_flags.pack_digest_hash_modules = true;
3280                    cfg.feature_flags.txn_base_cost_as_multiplier = true;
3281                    // this is a multiplier of the gas price
3282                    cfg.base_tx_cost_fixed = Some(1_000);
3283                }
3284                19 => {
3285                    cfg.max_num_event_emit = Some(1024);
3286                    // We maintain the same total size limit for events, but increase the number of
3287                    // events that can be emitted.
3288                    cfg.max_event_emit_size_total = Some(
3289                        256 /* former event count limit */ * 250 * 1024, /* size limit per event */
3290                    );
3291                }
3292                20 => {
3293                    cfg.feature_flags.commit_root_state_digest = true;
3294
3295                    if chain != Chain::Mainnet {
3296                        cfg.feature_flags.narwhal_new_leader_election_schedule = true;
3297                        cfg.consensus_bad_nodes_stake_threshold = Some(20);
3298                    }
3299                }
3300
3301                21 => {
3302                    if chain != Chain::Mainnet {
3303                        cfg.feature_flags.zklogin_supported_providers = BTreeSet::from([
3304                            "Google".to_string(),
3305                            "Facebook".to_string(),
3306                            "Twitch".to_string(),
3307                        ]);
3308                    }
3309                }
3310                22 => {
3311                    cfg.feature_flags.loaded_child_object_format = true;
3312                }
3313                23 => {
3314                    cfg.feature_flags.loaded_child_object_format_type = true;
3315                    cfg.feature_flags.narwhal_new_leader_election_schedule = true;
3316                    // Taking a baby step approach, we consider only 20% by stake as bad nodes so we
3317                    // have a 80% by stake of nodes participating in the leader committee. That allow
3318                    // us for more redundancy in case we have validators under performing - since the
3319                    // responsibility is shared amongst more nodes. We can increase that once we do have
3320                    // higher confidence.
3321                    cfg.consensus_bad_nodes_stake_threshold = Some(20);
3322                }
3323                24 => {
3324                    cfg.feature_flags.simple_conservation_checks = true;
3325                    cfg.max_publish_or_upgrade_per_ptb = Some(5);
3326
3327                    cfg.feature_flags.end_of_epoch_transaction_supported = true;
3328
3329                    if chain != Chain::Mainnet {
3330                        cfg.feature_flags.enable_jwk_consensus_updates = true;
3331                        // Max of 10 votes per hour
3332                        cfg.max_jwk_votes_per_validator_per_epoch = Some(240);
3333                        cfg.max_age_of_jwk_in_epochs = Some(1);
3334                    }
3335                }
3336                25 => {
3337                    // Enable zkLogin for all providers in all networks.
3338                    cfg.feature_flags.zklogin_supported_providers = BTreeSet::from([
3339                        "Google".to_string(),
3340                        "Facebook".to_string(),
3341                        "Twitch".to_string(),
3342                    ]);
3343                    cfg.feature_flags.zklogin_auth = true;
3344
3345                    // Enable jwk consensus updates
3346                    cfg.feature_flags.enable_jwk_consensus_updates = true;
3347                    cfg.max_jwk_votes_per_validator_per_epoch = Some(240);
3348                    cfg.max_age_of_jwk_in_epochs = Some(1);
3349                }
3350                26 => {
3351                    cfg.gas_model_version = Some(7);
3352                    // Only enable receiving objects in devnet
3353                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3354                        cfg.transfer_receive_object_cost_base = Some(52);
3355                        cfg.feature_flags.receive_objects = true;
3356                    }
3357                }
3358                27 => {
3359                    cfg.gas_model_version = Some(8);
3360                }
3361                28 => {
3362                    // zklogin::check_zklogin_id
3363                    cfg.check_zklogin_id_cost_base = Some(200);
3364                    // zklogin::check_zklogin_issuer
3365                    cfg.check_zklogin_issuer_cost_base = Some(200);
3366
3367                    // Only enable effects v2 on devnet.
3368                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3369                        cfg.feature_flags.enable_effects_v2 = true;
3370                    }
3371                }
3372                29 => {
3373                    cfg.feature_flags.verify_legacy_zklogin_address = true;
3374                }
3375                30 => {
3376                    // Only enable nw certificate v2 on testnet.
3377                    if chain != Chain::Mainnet {
3378                        cfg.feature_flags.narwhal_certificate_v2 = true;
3379                    }
3380
3381                    cfg.random_beacon_reduction_allowed_delta = Some(800);
3382                    // Only enable effects v2 on devnet and testnet.
3383                    if chain != Chain::Mainnet {
3384                        cfg.feature_flags.enable_effects_v2 = true;
3385                    }
3386
3387                    // zklogin_supported_providers config is deprecated, zklogin
3388                    // signature verifier will use the fetched jwk map to determine
3389                    // whether the provider is supported based on node config.
3390                    cfg.feature_flags.zklogin_supported_providers = BTreeSet::default();
3391
3392                    cfg.feature_flags.recompute_has_public_transfer_in_execution = true;
3393                }
3394                31 => {
3395                    cfg.execution_version = Some(2);
3396                    // Only enable shared object deletion on devnet
3397                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3398                        cfg.feature_flags.shared_object_deletion = true;
3399                    }
3400                }
3401                32 => {
3402                    // enable zklogin in multisig in devnet and testnet
3403                    if chain != Chain::Mainnet {
3404                        cfg.feature_flags.accept_zklogin_in_multisig = true;
3405                    }
3406                    // enable receiving objects in devnet and testnet
3407                    if chain != Chain::Mainnet {
3408                        cfg.transfer_receive_object_cost_base = Some(52);
3409                        cfg.feature_flags.receive_objects = true;
3410                    }
3411                    // Only enable random beacon on devnet
3412                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3413                        cfg.feature_flags.random_beacon = true;
3414                        cfg.random_beacon_reduction_lower_bound = Some(1600);
3415                        cfg.random_beacon_dkg_timeout_round = Some(3000);
3416                        cfg.random_beacon_min_round_interval_ms = Some(150);
3417                    }
3418                    // Only enable consensus digest in consensus commit prologue in devnet.
3419                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3420                        cfg.feature_flags.include_consensus_digest_in_prologue = true;
3421                    }
3422
3423                    // enable nw cert v2 on mainnet
3424                    cfg.feature_flags.narwhal_certificate_v2 = true;
3425                }
3426                33 => {
3427                    cfg.feature_flags.hardened_otw_check = true;
3428                    cfg.feature_flags.allow_receiving_object_id = true;
3429
3430                    // Enable transfer-to-object in mainnet
3431                    cfg.transfer_receive_object_cost_base = Some(52);
3432                    cfg.feature_flags.receive_objects = true;
3433
3434                    // Enable shared object deletion in testnet and devnet
3435                    if chain != Chain::Mainnet {
3436                        cfg.feature_flags.shared_object_deletion = true;
3437                    }
3438
3439                    cfg.feature_flags.enable_effects_v2 = true;
3440                }
3441                34 => {}
3442                35 => {
3443                    // Add costs for poseidon::poseidon_bn254
3444                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3445                        cfg.feature_flags.enable_poseidon = true;
3446                        cfg.poseidon_bn254_cost_base = Some(260);
3447                        cfg.poseidon_bn254_cost_per_block = Some(10);
3448                    }
3449
3450                    cfg.feature_flags.enable_coin_deny_list = true;
3451                }
3452                36 => {
3453                    // Only enable group ops on devnet
3454                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3455                        cfg.feature_flags.enable_group_ops_native_functions = true;
3456                        cfg.feature_flags.enable_group_ops_native_function_msm = true;
3457                        // Next values are arbitrary in a similar way as the other crypto native functions.
3458                        cfg.group_ops_bls12381_decode_scalar_cost = Some(52);
3459                        cfg.group_ops_bls12381_decode_g1_cost = Some(52);
3460                        cfg.group_ops_bls12381_decode_g2_cost = Some(52);
3461                        cfg.group_ops_bls12381_decode_gt_cost = Some(52);
3462                        cfg.group_ops_bls12381_scalar_add_cost = Some(52);
3463                        cfg.group_ops_bls12381_g1_add_cost = Some(52);
3464                        cfg.group_ops_bls12381_g2_add_cost = Some(52);
3465                        cfg.group_ops_bls12381_gt_add_cost = Some(52);
3466                        cfg.group_ops_bls12381_scalar_sub_cost = Some(52);
3467                        cfg.group_ops_bls12381_g1_sub_cost = Some(52);
3468                        cfg.group_ops_bls12381_g2_sub_cost = Some(52);
3469                        cfg.group_ops_bls12381_gt_sub_cost = Some(52);
3470                        cfg.group_ops_bls12381_scalar_mul_cost = Some(52);
3471                        cfg.group_ops_bls12381_g1_mul_cost = Some(52);
3472                        cfg.group_ops_bls12381_g2_mul_cost = Some(52);
3473                        cfg.group_ops_bls12381_gt_mul_cost = Some(52);
3474                        cfg.group_ops_bls12381_scalar_div_cost = Some(52);
3475                        cfg.group_ops_bls12381_g1_div_cost = Some(52);
3476                        cfg.group_ops_bls12381_g2_div_cost = Some(52);
3477                        cfg.group_ops_bls12381_gt_div_cost = Some(52);
3478                        cfg.group_ops_bls12381_g1_hash_to_base_cost = Some(52);
3479                        cfg.group_ops_bls12381_g2_hash_to_base_cost = Some(52);
3480                        cfg.group_ops_bls12381_g1_hash_to_cost_per_byte = Some(2);
3481                        cfg.group_ops_bls12381_g2_hash_to_cost_per_byte = Some(2);
3482                        cfg.group_ops_bls12381_g1_msm_base_cost = Some(52);
3483                        cfg.group_ops_bls12381_g2_msm_base_cost = Some(52);
3484                        cfg.group_ops_bls12381_g1_msm_base_cost_per_input = Some(52);
3485                        cfg.group_ops_bls12381_g2_msm_base_cost_per_input = Some(52);
3486                        cfg.group_ops_bls12381_msm_max_len = Some(32);
3487                        cfg.group_ops_bls12381_pairing_cost = Some(52);
3488                    }
3489                    // Enable shared object deletion on all networks.
3490                    cfg.feature_flags.shared_object_deletion = true;
3491
3492                    cfg.consensus_max_transaction_size_bytes = Some(256 * 1024); // 256KB
3493                    cfg.consensus_max_transactions_in_block_bytes = Some(6 * 1_024 * 1024);
3494                    // 6 MB
3495                }
3496                37 => {
3497                    cfg.feature_flags.reject_mutable_random_on_entry_functions = true;
3498
3499                    // Enable consensus digest in consensus commit prologue in testnet and devnet.
3500                    if chain != Chain::Mainnet {
3501                        cfg.feature_flags.include_consensus_digest_in_prologue = true;
3502                    }
3503                }
3504                38 => {
3505                    cfg.binary_module_handles = Some(100);
3506                    cfg.binary_struct_handles = Some(300);
3507                    cfg.binary_function_handles = Some(1500);
3508                    cfg.binary_function_instantiations = Some(750);
3509                    cfg.binary_signatures = Some(1000);
3510                    // constants and identifiers are proportional to the binary size,
3511                    // and they vastly depend on the code, so we are leaving them
3512                    // reasonably high
3513                    cfg.binary_constant_pool = Some(4000);
3514                    cfg.binary_identifiers = Some(10000);
3515                    cfg.binary_address_identifiers = Some(100);
3516                    cfg.binary_struct_defs = Some(200);
3517                    cfg.binary_struct_def_instantiations = Some(100);
3518                    cfg.binary_function_defs = Some(1000);
3519                    cfg.binary_field_handles = Some(500);
3520                    cfg.binary_field_instantiations = Some(250);
3521                    cfg.binary_friend_decls = Some(100);
3522                    // reduce dependencies maximum
3523                    cfg.max_package_dependencies = Some(32);
3524                    cfg.max_modules_in_publish = Some(64);
3525                    // bump execution version
3526                    cfg.execution_version = Some(3);
3527                }
3528                39 => {
3529                    // It is important that we keep this protocol version blank due to an issue with random.move.
3530                }
3531                40 => {}
3532                41 => {
3533                    // Enable group ops and all networks (but not msm)
3534                    cfg.feature_flags.enable_group_ops_native_functions = true;
3535                    // Next values are arbitrary in a similar way as the other crypto native functions.
3536                    cfg.group_ops_bls12381_decode_scalar_cost = Some(52);
3537                    cfg.group_ops_bls12381_decode_g1_cost = Some(52);
3538                    cfg.group_ops_bls12381_decode_g2_cost = Some(52);
3539                    cfg.group_ops_bls12381_decode_gt_cost = Some(52);
3540                    cfg.group_ops_bls12381_scalar_add_cost = Some(52);
3541                    cfg.group_ops_bls12381_g1_add_cost = Some(52);
3542                    cfg.group_ops_bls12381_g2_add_cost = Some(52);
3543                    cfg.group_ops_bls12381_gt_add_cost = Some(52);
3544                    cfg.group_ops_bls12381_scalar_sub_cost = Some(52);
3545                    cfg.group_ops_bls12381_g1_sub_cost = Some(52);
3546                    cfg.group_ops_bls12381_g2_sub_cost = Some(52);
3547                    cfg.group_ops_bls12381_gt_sub_cost = Some(52);
3548                    cfg.group_ops_bls12381_scalar_mul_cost = Some(52);
3549                    cfg.group_ops_bls12381_g1_mul_cost = Some(52);
3550                    cfg.group_ops_bls12381_g2_mul_cost = Some(52);
3551                    cfg.group_ops_bls12381_gt_mul_cost = Some(52);
3552                    cfg.group_ops_bls12381_scalar_div_cost = Some(52);
3553                    cfg.group_ops_bls12381_g1_div_cost = Some(52);
3554                    cfg.group_ops_bls12381_g2_div_cost = Some(52);
3555                    cfg.group_ops_bls12381_gt_div_cost = Some(52);
3556                    cfg.group_ops_bls12381_g1_hash_to_base_cost = Some(52);
3557                    cfg.group_ops_bls12381_g2_hash_to_base_cost = Some(52);
3558                    cfg.group_ops_bls12381_g1_hash_to_cost_per_byte = Some(2);
3559                    cfg.group_ops_bls12381_g2_hash_to_cost_per_byte = Some(2);
3560                    cfg.group_ops_bls12381_g1_msm_base_cost = Some(52);
3561                    cfg.group_ops_bls12381_g2_msm_base_cost = Some(52);
3562                    cfg.group_ops_bls12381_g1_msm_base_cost_per_input = Some(52);
3563                    cfg.group_ops_bls12381_g2_msm_base_cost_per_input = Some(52);
3564                    cfg.group_ops_bls12381_msm_max_len = Some(32);
3565                    cfg.group_ops_bls12381_pairing_cost = Some(52);
3566                }
3567                42 => {}
3568                43 => {
3569                    cfg.feature_flags.zklogin_max_epoch_upper_bound_delta = Some(30);
3570                    cfg.max_meter_ticks_per_package = Some(16_000_000);
3571                }
3572                44 => {
3573                    // Enable consensus digest in consensus commit prologue on all networks..
3574                    cfg.feature_flags.include_consensus_digest_in_prologue = true;
3575                    // Switch between Narwhal and Mysticeti per epoch in tests, devnet and testnet.
3576                    if chain != Chain::Mainnet {
3577                        cfg.feature_flags.consensus_choice = ConsensusChoice::SwapEachEpoch;
3578                    }
3579                }
3580                45 => {
3581                    // Use tonic networking for consensus, in tests and devnet.
3582                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3583                        cfg.feature_flags.consensus_network = ConsensusNetwork::Tonic;
3584                    }
3585
3586                    if chain != Chain::Mainnet {
3587                        // Enable leader scoring & schedule change on testnet for mysticeti.
3588                        cfg.feature_flags.mysticeti_leader_scoring_and_schedule = true;
3589                    }
3590                    cfg.min_move_binary_format_version = Some(6);
3591                    cfg.feature_flags.accept_zklogin_in_multisig = true;
3592
3593                    // Also bumps framework snapshot to fix binop issue.
3594
3595                    // enable bridge in devnet
3596                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3597                        cfg.feature_flags.bridge = true;
3598                    }
3599                }
3600                46 => {
3601                    // enable bridge in devnet and testnet
3602                    if chain != Chain::Mainnet {
3603                        cfg.feature_flags.bridge = true;
3604                    }
3605
3606                    // Enable resharing at same initial version
3607                    cfg.feature_flags.reshare_at_same_initial_version = true;
3608                }
3609                47 => {}
3610                48 => {
3611                    // Use tonic networking for Mysticeti.
3612                    cfg.feature_flags.consensus_network = ConsensusNetwork::Tonic;
3613
3614                    // Enable resolving abort code IDs to package ID instead of runtime module ID
3615                    cfg.feature_flags.resolve_abort_locations_to_package_id = true;
3616
3617                    // Enable random beacon on testnet.
3618                    if chain != Chain::Mainnet {
3619                        cfg.feature_flags.random_beacon = true;
3620                        cfg.random_beacon_reduction_lower_bound = Some(1600);
3621                        cfg.random_beacon_dkg_timeout_round = Some(3000);
3622                        cfg.random_beacon_min_round_interval_ms = Some(200);
3623                    }
3624
3625                    // Enable the committed sub dag digest inclusion on the commit output
3626                    cfg.feature_flags.mysticeti_use_committed_subdag_digest = true;
3627                }
3628                49 => {
3629                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3630                        cfg.move_binary_format_version = Some(7);
3631                    }
3632
3633                    // enable vdf in devnet
3634                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3635                        cfg.feature_flags.enable_vdf = true;
3636                        // Set to 30x and 2x the cost of a signature verification for now. This
3637                        // should be updated along with other native crypto functions.
3638                        cfg.vdf_verify_vdf_cost = Some(1500);
3639                        cfg.vdf_hash_to_input_cost = Some(100);
3640                    }
3641
3642                    // Only enable consensus commit prologue V3 in devnet.
3643                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3644                        cfg.feature_flags
3645                            .record_consensus_determined_version_assignments_in_prologue = true;
3646                    }
3647
3648                    // Run Mysticeti consensus in testnet.
3649                    if chain != Chain::Mainnet {
3650                        cfg.feature_flags.consensus_choice = ConsensusChoice::Mysticeti;
3651                    }
3652
3653                    // Run Move verification on framework upgrades in its own VM
3654                    cfg.feature_flags.fresh_vm_on_framework_upgrade = true;
3655                }
3656                50 => {
3657                    // Enable checkpoint batching in testnet.
3658                    if chain != Chain::Mainnet {
3659                        cfg.checkpoint_summary_version_specific_data = Some(1);
3660                        cfg.min_checkpoint_interval_ms = Some(200);
3661                    }
3662
3663                    // Only enable prepose consensus commit prologue in checkpoints in devnet.
3664                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3665                        cfg.feature_flags
3666                            .prepend_prologue_tx_in_consensus_commit_in_checkpoints = true;
3667                    }
3668
3669                    cfg.feature_flags.mysticeti_num_leaders_per_round = Some(1);
3670
3671                    // Set max transaction deferral to 10 consensus rounds.
3672                    cfg.max_deferral_rounds_for_congestion_control = Some(10);
3673                }
3674                51 => {
3675                    cfg.random_beacon_dkg_version = Some(1);
3676
3677                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3678                        cfg.feature_flags.enable_coin_deny_list_v2 = true;
3679                    }
3680                }
3681                52 => {
3682                    if chain != Chain::Mainnet {
3683                        cfg.feature_flags.soft_bundle = true;
3684                        cfg.max_soft_bundle_size = Some(5);
3685                    }
3686
3687                    cfg.config_read_setting_impl_cost_base = Some(100);
3688                    cfg.config_read_setting_impl_cost_per_byte = Some(40);
3689
3690                    // Turn on shared object congestion control in devnet.
3691                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3692                        cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(100);
3693                        cfg.feature_flags.per_object_congestion_control_mode =
3694                            PerObjectCongestionControlMode::TotalTxCount;
3695                    }
3696
3697                    // Enable Mysticeti on mainnet.
3698                    cfg.feature_flags.consensus_choice = ConsensusChoice::Mysticeti;
3699
3700                    // Enable leader scoring & schedule change on mainnet for mysticeti.
3701                    cfg.feature_flags.mysticeti_leader_scoring_and_schedule = true;
3702
3703                    // Enable checkpoint batching on mainnet.
3704                    cfg.checkpoint_summary_version_specific_data = Some(1);
3705                    cfg.min_checkpoint_interval_ms = Some(200);
3706
3707                    // Enable consensus commit prologue V3 in testnet.
3708                    if chain != Chain::Mainnet {
3709                        cfg.feature_flags
3710                            .record_consensus_determined_version_assignments_in_prologue = true;
3711                        cfg.feature_flags
3712                            .prepend_prologue_tx_in_consensus_commit_in_checkpoints = true;
3713                    }
3714                    // Turn on enums in testnet and devnet
3715                    if chain != Chain::Mainnet {
3716                        cfg.move_binary_format_version = Some(7);
3717                    }
3718
3719                    if chain != Chain::Testnet && chain != Chain::Mainnet {
3720                        cfg.feature_flags.passkey_auth = true;
3721                    }
3722                    cfg.feature_flags.enable_coin_deny_list_v2 = true;
3723                }
3724                53 => {
3725                    // Do not allow bridge committee to finalize on mainnet.
3726                    cfg.bridge_should_try_to_finalize_committee = Some(chain != Chain::Mainnet);
3727
3728                    // Enable consensus commit prologue V3 on mainnet.
3729                    cfg.feature_flags
3730                        .record_consensus_determined_version_assignments_in_prologue = true;
3731                    cfg.feature_flags
3732                        .prepend_prologue_tx_in_consensus_commit_in_checkpoints = true;
3733
3734                    if chain == Chain::Unknown {
3735                        cfg.feature_flags.authority_capabilities_v2 = true;
3736                    }
3737
3738                    // Turns on shared object congestion control on testnet.
3739                    if chain != Chain::Mainnet {
3740                        cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(100);
3741                        cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(10);
3742                        cfg.feature_flags.per_object_congestion_control_mode =
3743                            PerObjectCongestionControlMode::TotalTxCount;
3744                    }
3745
3746                    // Adjust stdlib gas costs
3747                    cfg.bcs_per_byte_serialized_cost = Some(2);
3748                    cfg.bcs_legacy_min_output_size_cost = Some(1);
3749                    cfg.bcs_failure_cost = Some(52);
3750                    cfg.debug_print_base_cost = Some(52);
3751                    cfg.debug_print_stack_trace_base_cost = Some(52);
3752                    cfg.hash_sha2_256_base_cost = Some(52);
3753                    cfg.hash_sha2_256_per_byte_cost = Some(2);
3754                    cfg.hash_sha2_256_legacy_min_input_len_cost = Some(1);
3755                    cfg.hash_sha3_256_base_cost = Some(52);
3756                    cfg.hash_sha3_256_per_byte_cost = Some(2);
3757                    cfg.hash_sha3_256_legacy_min_input_len_cost = Some(1);
3758                    cfg.type_name_get_base_cost = Some(52);
3759                    cfg.type_name_get_per_byte_cost = Some(2);
3760                    cfg.string_check_utf8_base_cost = Some(52);
3761                    cfg.string_check_utf8_per_byte_cost = Some(2);
3762                    cfg.string_is_char_boundary_base_cost = Some(52);
3763                    cfg.string_sub_string_base_cost = Some(52);
3764                    cfg.string_sub_string_per_byte_cost = Some(2);
3765                    cfg.string_index_of_base_cost = Some(52);
3766                    cfg.string_index_of_per_byte_pattern_cost = Some(2);
3767                    cfg.string_index_of_per_byte_searched_cost = Some(2);
3768                    cfg.vector_empty_base_cost = Some(52);
3769                    cfg.vector_length_base_cost = Some(52);
3770                    cfg.vector_push_back_base_cost = Some(52);
3771                    cfg.vector_push_back_legacy_per_abstract_memory_unit_cost = Some(2);
3772                    cfg.vector_borrow_base_cost = Some(52);
3773                    cfg.vector_pop_back_base_cost = Some(52);
3774                    cfg.vector_destroy_empty_base_cost = Some(52);
3775                    cfg.vector_swap_base_cost = Some(52);
3776                }
3777                54 => {
3778                    // Enable random beacon on mainnet.
3779                    cfg.feature_flags.random_beacon = true;
3780                    cfg.random_beacon_reduction_lower_bound = Some(1000);
3781                    cfg.random_beacon_dkg_timeout_round = Some(3000);
3782                    cfg.random_beacon_min_round_interval_ms = Some(500);
3783
3784                    // Turns on shared object congestion control on mainnet.
3785                    cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(100);
3786                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(10);
3787                    cfg.feature_flags.per_object_congestion_control_mode =
3788                        PerObjectCongestionControlMode::TotalTxCount;
3789
3790                    // Enable soft bundle on mainnet.
3791                    cfg.feature_flags.soft_bundle = true;
3792                    cfg.max_soft_bundle_size = Some(5);
3793                }
3794                55 => {
3795                    // Turn on enums mainnet
3796                    cfg.move_binary_format_version = Some(7);
3797
3798                    // Assume 1KB per transaction and 500 transactions per block.
3799                    cfg.consensus_max_transactions_in_block_bytes = Some(512 * 1024);
3800                    // Assume 20_000 TPS * 5% max stake per validator / (minimum) 4 blocks per round = 250 transactions per block maximum
3801                    // Using a higher limit that is 512, to account for bursty traffic and system transactions.
3802                    cfg.consensus_max_num_transactions_in_block = Some(512);
3803
3804                    cfg.feature_flags.rethrow_serialization_type_layout_errors = true;
3805                }
3806                56 => {
3807                    if chain == Chain::Mainnet {
3808                        cfg.feature_flags.bridge = true;
3809                    }
3810                }
3811                57 => {
3812                    // Reduce minimum number of random beacon shares.
3813                    cfg.random_beacon_reduction_lower_bound = Some(800);
3814                }
3815                58 => {
3816                    if chain == Chain::Mainnet {
3817                        cfg.bridge_should_try_to_finalize_committee = Some(true);
3818                    }
3819
3820                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3821                        // Enable distributed vote scoring for devnet
3822                        cfg.feature_flags
3823                            .consensus_distributed_vote_scoring_strategy = true;
3824                    }
3825                }
3826                59 => {
3827                    // Enable round prober in consensus.
3828                    cfg.feature_flags.consensus_round_prober = true;
3829                }
3830                60 => {
3831                    cfg.max_type_to_layout_nodes = Some(512);
3832                    cfg.feature_flags.validate_identifier_inputs = true;
3833                }
3834                61 => {
3835                    if chain != Chain::Mainnet {
3836                        // Enable distributed vote scoring for testnet
3837                        cfg.feature_flags
3838                            .consensus_distributed_vote_scoring_strategy = true;
3839                    }
3840                    // Further reduce minimum number of random beacon shares.
3841                    cfg.random_beacon_reduction_lower_bound = Some(700);
3842
3843                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3844                        // Enable Mysticeti fastpath for devnet
3845                        cfg.feature_flags.mysticeti_fastpath = true;
3846                    }
3847                }
3848                62 => {
3849                    cfg.feature_flags.relocate_event_module = true;
3850                }
3851                63 => {
3852                    cfg.feature_flags.per_object_congestion_control_mode =
3853                        PerObjectCongestionControlMode::TotalGasBudgetWithCap;
3854                    cfg.gas_budget_based_txn_cost_cap_factor = Some(400_000);
3855                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(18_500_000);
3856                    cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(240_000_000);
3857                }
3858                64 => {
3859                    cfg.feature_flags.per_object_congestion_control_mode =
3860                        PerObjectCongestionControlMode::TotalTxCount;
3861                    cfg.max_accumulated_txn_cost_per_object_in_narwhal_commit = Some(40);
3862                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(3);
3863                }
3864                65 => {
3865                    // Enable distributed vote scoring for mainnet
3866                    cfg.feature_flags
3867                        .consensus_distributed_vote_scoring_strategy = true;
3868                }
3869                66 => {
3870                    if chain == Chain::Mainnet {
3871                        // Revert the distributed vote scoring for mainnet (for one protocol upgrade)
3872                        cfg.feature_flags
3873                            .consensus_distributed_vote_scoring_strategy = false;
3874                    }
3875                }
3876                67 => {
3877                    // Enable it once again.
3878                    cfg.feature_flags
3879                        .consensus_distributed_vote_scoring_strategy = true;
3880                }
3881                68 => {
3882                    cfg.group_ops_bls12381_g1_to_uncompressed_g1_cost = Some(26);
3883                    cfg.group_ops_bls12381_uncompressed_g1_to_g1_cost = Some(52);
3884                    cfg.group_ops_bls12381_uncompressed_g1_sum_base_cost = Some(26);
3885                    cfg.group_ops_bls12381_uncompressed_g1_sum_cost_per_term = Some(13);
3886                    cfg.group_ops_bls12381_uncompressed_g1_sum_max_terms = Some(2000);
3887
3888                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3889                        cfg.feature_flags.uncompressed_g1_group_elements = true;
3890                    }
3891
3892                    cfg.feature_flags.per_object_congestion_control_mode =
3893                        PerObjectCongestionControlMode::TotalGasBudgetWithCap;
3894                    cfg.gas_budget_based_txn_cost_cap_factor = Some(400_000);
3895                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(18_500_000);
3896                    cfg.max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit =
3897                        Some(3_700_000); // 20% of above
3898                    cfg.max_txn_cost_overage_per_object_in_commit = Some(u64::MAX);
3899                    cfg.gas_budget_based_txn_cost_absolute_cap_commit_count = Some(50);
3900
3901                    // Further reduce minimum number of random beacon shares.
3902                    cfg.random_beacon_reduction_lower_bound = Some(500);
3903
3904                    cfg.feature_flags.disallow_new_modules_in_deps_only_packages = true;
3905                }
3906                69 => {
3907                    // Sets number of rounds allowed for fastpath voting in consensus.
3908                    cfg.consensus_voting_rounds = Some(40);
3909
3910                    if chain != Chain::Mainnet && chain != Chain::Testnet {
3911                        // Enable smart ancestor selection for devnet
3912                        cfg.feature_flags.consensus_smart_ancestor_selection = true;
3913                    }
3914
3915                    if chain != Chain::Mainnet {
3916                        cfg.feature_flags.uncompressed_g1_group_elements = true;
3917                    }
3918                }
3919                70 => {
3920                    if chain != Chain::Mainnet {
3921                        // Enable smart ancestor selection for testnet
3922                        cfg.feature_flags.consensus_smart_ancestor_selection = true;
3923                        // Enable probing for accepted rounds in round prober for testnet
3924                        cfg.feature_flags
3925                            .consensus_round_prober_probe_accepted_rounds = true;
3926                    }
3927
3928                    cfg.poseidon_bn254_cost_per_block = Some(388);
3929
3930                    cfg.gas_model_version = Some(9);
3931                    cfg.feature_flags.native_charging_v2 = true;
3932                    cfg.bls12381_bls12381_min_sig_verify_cost_base = Some(44064);
3933                    cfg.bls12381_bls12381_min_pk_verify_cost_base = Some(49282);
3934                    cfg.ecdsa_k1_secp256k1_verify_keccak256_cost_base = Some(1470);
3935                    cfg.ecdsa_k1_secp256k1_verify_sha256_cost_base = Some(1470);
3936                    cfg.ecdsa_r1_secp256r1_verify_sha256_cost_base = Some(4225);
3937                    cfg.ecdsa_r1_secp256r1_verify_keccak256_cost_base = Some(4225);
3938                    cfg.ecvrf_ecvrf_verify_cost_base = Some(4848);
3939                    cfg.ed25519_ed25519_verify_cost_base = Some(1802);
3940
3941                    // Manually changed to be "under cost"
3942                    cfg.ecdsa_r1_ecrecover_keccak256_cost_base = Some(1173);
3943                    cfg.ecdsa_r1_ecrecover_sha256_cost_base = Some(1173);
3944                    cfg.ecdsa_k1_ecrecover_keccak256_cost_base = Some(500);
3945                    cfg.ecdsa_k1_ecrecover_sha256_cost_base = Some(500);
3946
3947                    cfg.groth16_prepare_verifying_key_bls12381_cost_base = Some(53838);
3948                    cfg.groth16_prepare_verifying_key_bn254_cost_base = Some(82010);
3949                    cfg.groth16_verify_groth16_proof_internal_bls12381_cost_base = Some(72090);
3950                    cfg.groth16_verify_groth16_proof_internal_bls12381_cost_per_public_input =
3951                        Some(8213);
3952                    cfg.groth16_verify_groth16_proof_internal_bn254_cost_base = Some(115502);
3953                    cfg.groth16_verify_groth16_proof_internal_bn254_cost_per_public_input =
3954                        Some(9484);
3955
3956                    cfg.hash_keccak256_cost_base = Some(10);
3957                    cfg.hash_blake2b256_cost_base = Some(10);
3958
3959                    // group ops
3960                    cfg.group_ops_bls12381_decode_scalar_cost = Some(7);
3961                    cfg.group_ops_bls12381_decode_g1_cost = Some(2848);
3962                    cfg.group_ops_bls12381_decode_g2_cost = Some(3770);
3963                    cfg.group_ops_bls12381_decode_gt_cost = Some(3068);
3964
3965                    cfg.group_ops_bls12381_scalar_add_cost = Some(10);
3966                    cfg.group_ops_bls12381_g1_add_cost = Some(1556);
3967                    cfg.group_ops_bls12381_g2_add_cost = Some(3048);
3968                    cfg.group_ops_bls12381_gt_add_cost = Some(188);
3969
3970                    cfg.group_ops_bls12381_scalar_sub_cost = Some(10);
3971                    cfg.group_ops_bls12381_g1_sub_cost = Some(1550);
3972                    cfg.group_ops_bls12381_g2_sub_cost = Some(3019);
3973                    cfg.group_ops_bls12381_gt_sub_cost = Some(497);
3974
3975                    cfg.group_ops_bls12381_scalar_mul_cost = Some(11);
3976                    cfg.group_ops_bls12381_g1_mul_cost = Some(4842);
3977                    cfg.group_ops_bls12381_g2_mul_cost = Some(9108);
3978                    cfg.group_ops_bls12381_gt_mul_cost = Some(27490);
3979
3980                    cfg.group_ops_bls12381_scalar_div_cost = Some(91);
3981                    cfg.group_ops_bls12381_g1_div_cost = Some(5091);
3982                    cfg.group_ops_bls12381_g2_div_cost = Some(9206);
3983                    cfg.group_ops_bls12381_gt_div_cost = Some(27804);
3984
3985                    cfg.group_ops_bls12381_g1_hash_to_base_cost = Some(2962);
3986                    cfg.group_ops_bls12381_g2_hash_to_base_cost = Some(8688);
3987
3988                    cfg.group_ops_bls12381_g1_msm_base_cost = Some(62648);
3989                    cfg.group_ops_bls12381_g2_msm_base_cost = Some(131192);
3990                    cfg.group_ops_bls12381_g1_msm_base_cost_per_input = Some(1333);
3991                    cfg.group_ops_bls12381_g2_msm_base_cost_per_input = Some(3216);
3992
3993                    cfg.group_ops_bls12381_uncompressed_g1_to_g1_cost = Some(677);
3994                    cfg.group_ops_bls12381_g1_to_uncompressed_g1_cost = Some(2099);
3995                    cfg.group_ops_bls12381_uncompressed_g1_sum_base_cost = Some(77);
3996                    cfg.group_ops_bls12381_uncompressed_g1_sum_cost_per_term = Some(26);
3997
3998                    cfg.group_ops_bls12381_pairing_cost = Some(26897);
3999                    cfg.group_ops_bls12381_uncompressed_g1_sum_max_terms = Some(1200);
4000
4001                    cfg.validator_validate_metadata_cost_base = Some(20000);
4002                }
4003                71 => {
4004                    cfg.sip_45_consensus_amplification_threshold = Some(5);
4005
4006                    // Enable bursts for congestion control. (10x the per-commit budget)
4007                    cfg.allowed_txn_cost_overage_burst_per_object_in_commit = Some(185_000_000);
4008                }
4009                72 => {
4010                    cfg.feature_flags.convert_type_argument_error = true;
4011
4012                    // Invariant: max_gas_price * base_tx_cost_fixed <= max_tx_gas
4013                    // max gas budget is in MIST and an absolute value 50_000 SUI
4014                    cfg.max_tx_gas = Some(50_000_000_000_000);
4015                    // max gas price is in MIST and an absolute value 50 SUI
4016                    cfg.max_gas_price = Some(50_000_000_000);
4017
4018                    cfg.feature_flags.variant_nodes = true;
4019                }
4020                73 => {
4021                    // Enable new marker table version.
4022                    cfg.use_object_per_epoch_marker_table_v2 = Some(true);
4023
4024                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4025                        // Assuming a round rate of max 15/sec, then using a gc depth of 60 allow blocks within a window of ~4 seconds
4026                        // to be included before be considered garbage collected.
4027                        cfg.consensus_gc_depth = Some(60);
4028                    }
4029
4030                    if chain != Chain::Mainnet {
4031                        // Enable zstd compression for consensus in testnet
4032                        cfg.feature_flags.consensus_zstd_compression = true;
4033                    }
4034
4035                    // Enable smart ancestor selection for mainnet
4036                    cfg.feature_flags.consensus_smart_ancestor_selection = true;
4037                    // Enable probing for accepted rounds in round prober for mainnet
4038                    cfg.feature_flags
4039                        .consensus_round_prober_probe_accepted_rounds = true;
4040
4041                    // Increase congestion control budget.
4042                    cfg.feature_flags.per_object_congestion_control_mode =
4043                        PerObjectCongestionControlMode::TotalGasBudgetWithCap;
4044                    cfg.gas_budget_based_txn_cost_cap_factor = Some(400_000);
4045                    cfg.max_accumulated_txn_cost_per_object_in_mysticeti_commit = Some(37_000_000);
4046                    cfg.max_accumulated_randomness_txn_cost_per_object_in_mysticeti_commit =
4047                        Some(7_400_000); // 20% of above
4048                    cfg.max_txn_cost_overage_per_object_in_commit = Some(u64::MAX);
4049                    cfg.gas_budget_based_txn_cost_absolute_cap_commit_count = Some(50);
4050                    cfg.allowed_txn_cost_overage_burst_per_object_in_commit = Some(370_000_000);
4051                }
4052                74 => {
4053                    // Enable nitro attestation verify native move function for devnet
4054                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4055                        cfg.feature_flags.enable_nitro_attestation = true;
4056                    }
4057                    cfg.nitro_attestation_parse_base_cost = Some(53 * 50);
4058                    cfg.nitro_attestation_parse_cost_per_byte = Some(50);
4059                    cfg.nitro_attestation_verify_base_cost = Some(49632 * 50);
4060                    cfg.nitro_attestation_verify_cost_per_cert = Some(52369 * 50);
4061
4062                    // Enable zstd compression for consensus in mainnet
4063                    cfg.feature_flags.consensus_zstd_compression = true;
4064
4065                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4066                        cfg.feature_flags.consensus_linearize_subdag_v2 = true;
4067                    }
4068                }
4069                75 => {
4070                    if chain != Chain::Mainnet {
4071                        cfg.feature_flags.passkey_auth = true;
4072                    }
4073                }
4074                76 => {
4075                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4076                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4077                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4078                    }
4079                    cfg.feature_flags.minimize_child_object_mutations = true;
4080
4081                    if chain != Chain::Mainnet {
4082                        cfg.feature_flags.accept_passkey_in_multisig = true;
4083                    }
4084                }
4085                77 => {
4086                    cfg.feature_flags.uncompressed_g1_group_elements = true;
4087
4088                    if chain != Chain::Mainnet {
4089                        cfg.consensus_gc_depth = Some(60);
4090                        cfg.feature_flags.consensus_linearize_subdag_v2 = true;
4091                    }
4092                }
4093                78 => {
4094                    cfg.feature_flags.move_native_context = true;
4095                    cfg.tx_context_fresh_id_cost_base = Some(52);
4096                    cfg.tx_context_sender_cost_base = Some(30);
4097                    cfg.tx_context_epoch_cost_base = Some(30);
4098                    cfg.tx_context_epoch_timestamp_ms_cost_base = Some(30);
4099                    cfg.tx_context_sponsor_cost_base = Some(30);
4100                    cfg.tx_context_gas_price_cost_base = Some(30);
4101                    cfg.tx_context_gas_budget_cost_base = Some(30);
4102                    cfg.tx_context_ids_created_cost_base = Some(30);
4103                    cfg.tx_context_replace_cost_base = Some(30);
4104                    cfg.gas_model_version = Some(10);
4105
4106                    if chain != Chain::Mainnet {
4107                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4108                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4109
4110                        // Enable execution time estimate mode for congestion control on testnet.
4111                        cfg.feature_flags.per_object_congestion_control_mode =
4112                            PerObjectCongestionControlMode::ExecutionTimeEstimate(
4113                                ExecutionTimeEstimateParams {
4114                                    target_utilization: 30,
4115                                    allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4116                                    randomness_scalar: 20,
4117                                    max_estimate_us: 1_500_000, // 1.5s
4118                                    stored_observations_num_included_checkpoints: 10,
4119                                    stored_observations_limit: u64::MAX,
4120                                    stake_weighted_median_threshold: 0,
4121                                    default_none_duration_for_new_keys: false,
4122                                    observations_chunk_size: None,
4123                                },
4124                            );
4125                    }
4126                }
4127                79 => {
4128                    if chain != Chain::Mainnet {
4129                        cfg.feature_flags.consensus_median_based_commit_timestamp = true;
4130
4131                        // Increase threshold for bad nodes that won't be considered
4132                        // leaders in consensus in testnet
4133                        cfg.consensus_bad_nodes_stake_threshold = Some(30);
4134
4135                        cfg.feature_flags.consensus_batched_block_sync = true;
4136
4137                        // Enable verify nitro attestation in testnet.
4138                        cfg.feature_flags.enable_nitro_attestation = true
4139                    }
4140                    cfg.feature_flags.normalize_ptb_arguments = true;
4141
4142                    cfg.consensus_gc_depth = Some(60);
4143                    cfg.feature_flags.consensus_linearize_subdag_v2 = true;
4144                }
4145                80 => {
4146                    cfg.max_ptb_value_size = Some(1024 * 1024);
4147                }
4148                81 => {
4149                    cfg.feature_flags.consensus_median_based_commit_timestamp = true;
4150                    cfg.feature_flags.enforce_checkpoint_timestamp_monotonicity = true;
4151                    cfg.consensus_bad_nodes_stake_threshold = Some(30)
4152                }
4153                82 => {
4154                    cfg.feature_flags.max_ptb_value_size_v2 = true;
4155                }
4156                83 => {
4157                    if chain == Chain::Mainnet {
4158                        // The address that will sign the recovery transaction.
4159                        let aliased: [u8; 32] = Hex::decode(
4160                            "0x0b2da327ba6a4cacbe75dddd50e6e8bbf81d6496e92d66af9154c61c77f7332f",
4161                        )
4162                        .unwrap()
4163                        .try_into()
4164                        .unwrap();
4165
4166                        // Allow aliasing for the two addresses that contain stolen funds.
4167                        cfg.aliased_addresses.push(AliasedAddress {
4168                            original: Hex::decode("0xcd8962dad278d8b50fa0f9eb0186bfa4cbdecc6d59377214c88d0286a0ac9562").unwrap().try_into().unwrap(),
4169                            aliased,
4170                            allowed_tx_digests: vec![
4171                                Base58::decode("B2eGLFoMHgj93Ni8dAJBfqGzo8EWSTLBesZzhEpTPA4").unwrap().try_into().unwrap(),
4172                            ],
4173                        });
4174
4175                        cfg.aliased_addresses.push(AliasedAddress {
4176                            original: Hex::decode("0xe28b50cef1d633ea43d3296a3f6b67ff0312a5f1a99f0af753c85b8b5de8ff06").unwrap().try_into().unwrap(),
4177                            aliased,
4178                            allowed_tx_digests: vec![
4179                                Base58::decode("J4QqSAgp7VrQtQpMy5wDX4QGsCSEZu3U5KuDAkbESAge").unwrap().try_into().unwrap(),
4180                            ],
4181                        });
4182                    }
4183
4184                    // These features had to be deferred to v84 for mainnet in order to ship the recovery protocol
4185                    // upgrade as a patch to 1.48
4186                    if chain != Chain::Mainnet {
4187                        cfg.feature_flags.resolve_type_input_ids_to_defining_id = true;
4188                        cfg.transfer_party_transfer_internal_cost_base = Some(52);
4189
4190                        // Enable execution time estimate mode for congestion control on mainnet.
4191                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4192                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4193                        cfg.feature_flags.per_object_congestion_control_mode =
4194                            PerObjectCongestionControlMode::ExecutionTimeEstimate(
4195                                ExecutionTimeEstimateParams {
4196                                    target_utilization: 30,
4197                                    allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4198                                    randomness_scalar: 20,
4199                                    max_estimate_us: 1_500_000, // 1.5s
4200                                    stored_observations_num_included_checkpoints: 10,
4201                                    stored_observations_limit: u64::MAX,
4202                                    stake_weighted_median_threshold: 0,
4203                                    default_none_duration_for_new_keys: false,
4204                                    observations_chunk_size: None,
4205                                },
4206                            );
4207
4208                        // Enable the new depth-first block sync logic.
4209                        cfg.feature_flags.consensus_batched_block_sync = true;
4210
4211                        // Enable nitro attestation upgraded parsing logic and enable the
4212                        // native function on mainnet.
4213                        cfg.feature_flags.enable_nitro_attestation_upgraded_parsing = true;
4214                        cfg.feature_flags.enable_nitro_attestation = true;
4215                    }
4216                }
4217                84 => {
4218                    if chain == Chain::Mainnet {
4219                        cfg.feature_flags.resolve_type_input_ids_to_defining_id = true;
4220                        cfg.transfer_party_transfer_internal_cost_base = Some(52);
4221
4222                        // Enable execution time estimate mode for congestion control on mainnet.
4223                        cfg.feature_flags.record_additional_state_digest_in_prologue = true;
4224                        cfg.consensus_commit_rate_estimation_window_size = Some(10);
4225                        cfg.feature_flags.per_object_congestion_control_mode =
4226                            PerObjectCongestionControlMode::ExecutionTimeEstimate(
4227                                ExecutionTimeEstimateParams {
4228                                    target_utilization: 30,
4229                                    allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4230                                    randomness_scalar: 20,
4231                                    max_estimate_us: 1_500_000, // 1.5s
4232                                    stored_observations_num_included_checkpoints: 10,
4233                                    stored_observations_limit: u64::MAX,
4234                                    stake_weighted_median_threshold: 0,
4235                                    default_none_duration_for_new_keys: false,
4236                                    observations_chunk_size: None,
4237                                },
4238                            );
4239
4240                        // Enable the new depth-first block sync logic.
4241                        cfg.feature_flags.consensus_batched_block_sync = true;
4242
4243                        // Enable nitro attestation upgraded parsing logic and enable the
4244                        // native function on mainnet.
4245                        cfg.feature_flags.enable_nitro_attestation_upgraded_parsing = true;
4246                        cfg.feature_flags.enable_nitro_attestation = true;
4247                    }
4248
4249                    // Limit the number of stored execution time observations at end of epoch.
4250                    cfg.feature_flags.per_object_congestion_control_mode =
4251                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4252                            ExecutionTimeEstimateParams {
4253                                target_utilization: 30,
4254                                allowed_txn_cost_overage_burst_limit_us: 100_000, // 100 ms
4255                                randomness_scalar: 20,
4256                                max_estimate_us: 1_500_000, // 1.5s
4257                                stored_observations_num_included_checkpoints: 10,
4258                                stored_observations_limit: 20,
4259                                stake_weighted_median_threshold: 0,
4260                                default_none_duration_for_new_keys: false,
4261                                observations_chunk_size: None,
4262                            },
4263                        );
4264                    cfg.feature_flags.allow_unbounded_system_objects = true;
4265                }
4266                85 => {
4267                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4268                        cfg.feature_flags.enable_party_transfer = true;
4269                    }
4270
4271                    cfg.feature_flags
4272                        .record_consensus_determined_version_assignments_in_prologue_v2 = true;
4273                    cfg.feature_flags.disallow_self_identifier = true;
4274                    cfg.feature_flags.per_object_congestion_control_mode =
4275                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4276                            ExecutionTimeEstimateParams {
4277                                target_utilization: 50,
4278                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4279                                randomness_scalar: 20,
4280                                max_estimate_us: 1_500_000, // 1.5s
4281                                stored_observations_num_included_checkpoints: 10,
4282                                stored_observations_limit: 20,
4283                                stake_weighted_median_threshold: 0,
4284                                default_none_duration_for_new_keys: false,
4285                                observations_chunk_size: None,
4286                            },
4287                        );
4288                }
4289                86 => {
4290                    cfg.feature_flags.type_tags_in_object_runtime = true;
4291                    cfg.max_move_enum_variants = Some(move_core_types::VARIANT_COUNT_MAX);
4292
4293                    // Set a stake_weighted_median_threshold for congestion control.
4294                    cfg.feature_flags.per_object_congestion_control_mode =
4295                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4296                            ExecutionTimeEstimateParams {
4297                                target_utilization: 50,
4298                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4299                                randomness_scalar: 20,
4300                                max_estimate_us: 1_500_000, // 1.5s
4301                                stored_observations_num_included_checkpoints: 10,
4302                                stored_observations_limit: 20,
4303                                stake_weighted_median_threshold: 3334,
4304                                default_none_duration_for_new_keys: false,
4305                                observations_chunk_size: None,
4306                            },
4307                        );
4308                    // Enable party transfer for testnet.
4309                    if chain != Chain::Mainnet {
4310                        cfg.feature_flags.enable_party_transfer = true;
4311                    }
4312                }
4313                87 => {
4314                    if chain == Chain::Mainnet {
4315                        cfg.feature_flags.record_time_estimate_processed = true;
4316                    }
4317                    cfg.feature_flags.better_adapter_type_resolution_errors = true;
4318                }
4319                88 => {
4320                    cfg.feature_flags.record_time_estimate_processed = true;
4321                    cfg.tx_context_rgp_cost_base = Some(30);
4322                    cfg.feature_flags
4323                        .ignore_execution_time_observations_after_certs_closed = true;
4324
4325                    // Disable backwards compatible behavior in execution time estimator for
4326                    // new protocol version.
4327                    cfg.feature_flags.per_object_congestion_control_mode =
4328                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4329                            ExecutionTimeEstimateParams {
4330                                target_utilization: 50,
4331                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4332                                randomness_scalar: 20,
4333                                max_estimate_us: 1_500_000, // 1.5s
4334                                stored_observations_num_included_checkpoints: 10,
4335                                stored_observations_limit: 20,
4336                                stake_weighted_median_threshold: 3334,
4337                                default_none_duration_for_new_keys: true,
4338                                observations_chunk_size: None,
4339                            },
4340                        );
4341                }
4342                89 => {
4343                    cfg.feature_flags.dependency_linkage_error = true;
4344                    cfg.feature_flags.additional_multisig_checks = true;
4345                }
4346                90 => {
4347                    // 100x RGP
4348                    cfg.max_gas_price_rgp_factor_for_aborted_transactions = Some(100);
4349                    cfg.feature_flags.debug_fatal_on_move_invariant_violation = true;
4350                    cfg.feature_flags.additional_consensus_digest_indirect_state = true;
4351                    cfg.feature_flags.accept_passkey_in_multisig = true;
4352                    cfg.feature_flags.passkey_auth = true;
4353                    cfg.feature_flags.check_for_init_during_upgrade = true;
4354
4355                    // Enable Mysticeti fastpath handlers on testnet.
4356                    if chain != Chain::Mainnet {
4357                        cfg.feature_flags.mysticeti_fastpath = true;
4358                    }
4359                }
4360                91 => {
4361                    cfg.feature_flags.per_command_shared_object_transfer_rules = true;
4362                }
4363                92 => {
4364                    cfg.feature_flags.per_command_shared_object_transfer_rules = false;
4365                }
4366                93 => {
4367                    cfg.feature_flags
4368                        .consensus_checkpoint_signature_key_includes_digest = true;
4369                }
4370                94 => {
4371                    // Decrease stored observations limit 20->18 to stay within system object size limit.
4372                    cfg.feature_flags.per_object_congestion_control_mode =
4373                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4374                            ExecutionTimeEstimateParams {
4375                                target_utilization: 50,
4376                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4377                                randomness_scalar: 20,
4378                                max_estimate_us: 1_500_000, // 1.5s
4379                                stored_observations_num_included_checkpoints: 10,
4380                                stored_observations_limit: 18,
4381                                stake_weighted_median_threshold: 3334,
4382                                default_none_duration_for_new_keys: true,
4383                                observations_chunk_size: None,
4384                            },
4385                        );
4386
4387                    // Enable party transfer on mainnet.
4388                    cfg.feature_flags.enable_party_transfer = true;
4389                }
4390                95 => {
4391                    cfg.type_name_id_base_cost = Some(52);
4392
4393                    // Reduce the frequency of checkpoint splitting under high TPS.
4394                    cfg.max_transactions_per_checkpoint = Some(20_000);
4395                }
4396                96 => {
4397                    // Enable artifacts digest in devnet.
4398                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4399                        cfg.feature_flags
4400                            .include_checkpoint_artifacts_digest_in_summary = true;
4401                    }
4402                    cfg.feature_flags.correct_gas_payment_limit_check = true;
4403                    cfg.feature_flags.authority_capabilities_v2 = true;
4404                    cfg.feature_flags.use_mfp_txns_in_load_initial_object_debts = true;
4405                    cfg.feature_flags.cancel_for_failed_dkg_early = true;
4406                    cfg.feature_flags.enable_coin_registry = true;
4407
4408                    // Enable Mysticeti fastpath handlers on mainnet.
4409                    cfg.feature_flags.mysticeti_fastpath = true;
4410                }
4411                97 => {
4412                    cfg.feature_flags.additional_borrow_checks = true;
4413                }
4414                98 => {
4415                    cfg.event_emit_auth_stream_cost = Some(52);
4416                    cfg.feature_flags.better_loader_errors = true;
4417                    cfg.feature_flags.generate_df_type_layouts = true;
4418                }
4419                99 => {
4420                    cfg.feature_flags.use_new_commit_handler = true;
4421                }
4422                100 => {
4423                    cfg.feature_flags.private_generics_verifier_v2 = true;
4424                }
4425                101 => {
4426                    cfg.feature_flags.create_root_accumulator_object = true;
4427                    cfg.max_updates_per_settlement_txn = Some(100);
4428                    if chain != Chain::Mainnet {
4429                        cfg.feature_flags.enable_poseidon = true;
4430                    }
4431                }
4432                102 => {
4433                    // Enable execution time observation chunking and increase limit to 180.
4434                    // max_move_object_size is 250 KB, we've experientially determined that fits ~ 18 estimates
4435                    // so if we have 10 chunks, that's 2.5MB, < 8MB max_serialized_tx_effects_size_bytes_system_tx
4436                    cfg.feature_flags.per_object_congestion_control_mode =
4437                        PerObjectCongestionControlMode::ExecutionTimeEstimate(
4438                            ExecutionTimeEstimateParams {
4439                                target_utilization: 50,
4440                                allowed_txn_cost_overage_burst_limit_us: 500_000, // 500 ms
4441                                randomness_scalar: 20,
4442                                max_estimate_us: 1_500_000, // 1.5s
4443                                stored_observations_num_included_checkpoints: 10,
4444                                stored_observations_limit: 180,
4445                                stake_weighted_median_threshold: 3334,
4446                                default_none_duration_for_new_keys: true,
4447                                observations_chunk_size: Some(18),
4448                            },
4449                        );
4450                    cfg.feature_flags.deprecate_global_storage_ops = true;
4451                }
4452                103 => {}
4453                104 => {
4454                    cfg.translation_per_command_base_charge = Some(1);
4455                    cfg.translation_per_input_base_charge = Some(1);
4456                    cfg.translation_pure_input_per_byte_charge = Some(1);
4457                    cfg.translation_per_type_node_charge = Some(1);
4458                    cfg.translation_per_reference_node_charge = Some(1);
4459                    cfg.translation_per_linkage_entry_charge = Some(10);
4460                    cfg.gas_model_version = Some(11);
4461                    cfg.feature_flags.abstract_size_in_object_runtime = true;
4462                    cfg.feature_flags.object_runtime_charge_cache_load_gas = true;
4463                    cfg.dynamic_field_hash_type_and_key_cost_base = Some(52);
4464                    cfg.dynamic_field_add_child_object_cost_base = Some(52);
4465                    cfg.dynamic_field_add_child_object_value_cost_per_byte = Some(1);
4466                    cfg.dynamic_field_borrow_child_object_cost_base = Some(52);
4467                    cfg.dynamic_field_borrow_child_object_child_ref_cost_per_byte = Some(1);
4468                    cfg.dynamic_field_remove_child_object_cost_base = Some(52);
4469                    cfg.dynamic_field_remove_child_object_child_cost_per_byte = Some(1);
4470                    cfg.dynamic_field_has_child_object_cost_base = Some(52);
4471                    cfg.dynamic_field_has_child_object_with_ty_cost_base = Some(52);
4472                    cfg.feature_flags.enable_ptb_execution_v2 = true;
4473
4474                    cfg.poseidon_bn254_cost_base = Some(260);
4475
4476                    cfg.feature_flags.consensus_skip_gced_accept_votes = true;
4477
4478                    if chain != Chain::Mainnet {
4479                        cfg.feature_flags
4480                            .enable_nitro_attestation_all_nonzero_pcrs_parsing = true;
4481                    }
4482
4483                    cfg.feature_flags
4484                        .include_cancelled_randomness_txns_in_prologue = true;
4485                }
4486                105 => {
4487                    cfg.feature_flags.enable_multi_epoch_transaction_expiration = true;
4488                    cfg.feature_flags.disable_preconsensus_locking = true;
4489
4490                    if chain != Chain::Mainnet {
4491                        cfg.feature_flags
4492                            .enable_nitro_attestation_always_include_required_pcrs_parsing = true;
4493                    }
4494                }
4495                106 => {
4496                    // est. 100 bytes per object * 76 (storage_gas_price)
4497                    cfg.accumulator_object_storage_cost = Some(7600);
4498
4499                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4500                        cfg.feature_flags.enable_accumulators = true;
4501                        cfg.feature_flags.enable_address_balance_gas_payments = true;
4502                        cfg.feature_flags.enable_authenticated_event_streams = true;
4503                        cfg.feature_flags.enable_object_funds_withdraw = true;
4504                    }
4505                }
4506                107 => {
4507                    cfg.feature_flags
4508                        .consensus_skip_gced_blocks_in_direct_finalization = true;
4509
4510                    // Trigger edge cases more often in integration tests.
4511                    if in_integration_test() {
4512                        cfg.consensus_gc_depth = Some(6);
4513                        cfg.consensus_max_num_transactions_in_block = Some(8);
4514                    }
4515                }
4516                108 => {
4517                    cfg.feature_flags.gas_rounding_halve_digits = true;
4518                    cfg.feature_flags.flexible_tx_context_positions = true;
4519                    cfg.feature_flags.disable_entry_point_signature_check = true;
4520
4521                    if chain != Chain::Mainnet {
4522                        cfg.feature_flags.address_aliases = true;
4523
4524                        cfg.feature_flags.enable_accumulators = true;
4525                        cfg.feature_flags.enable_address_balance_gas_payments = true;
4526                    }
4527
4528                    cfg.feature_flags.enable_poseidon = true;
4529                }
4530                109 => {
4531                    cfg.binary_variant_handles = Some(1024);
4532                    cfg.binary_variant_instantiation_handles = Some(1024);
4533                    cfg.feature_flags.restrict_hot_or_not_entry_functions = true;
4534                }
4535                110 => {
4536                    cfg.feature_flags
4537                        .enable_nitro_attestation_all_nonzero_pcrs_parsing = true;
4538                    cfg.feature_flags
4539                        .enable_nitro_attestation_always_include_required_pcrs_parsing = true;
4540                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4541                        cfg.feature_flags.split_checkpoints_in_consensus_handler = true;
4542                    }
4543                    cfg.feature_flags.validate_zklogin_public_identifier = true;
4544                    cfg.feature_flags.fix_checkpoint_signature_mapping = true;
4545                    cfg.feature_flags
4546                        .consensus_always_accept_system_transactions = true;
4547                    if chain != Chain::Mainnet {
4548                        cfg.feature_flags.enable_object_funds_withdraw = true;
4549                    }
4550                }
4551                111 => {
4552                    cfg.feature_flags.validator_metadata_verify_v2 = true;
4553                }
4554                112 => {
4555                    cfg.group_ops_ristretto_decode_scalar_cost = Some(7);
4556                    cfg.group_ops_ristretto_decode_point_cost = Some(200);
4557                    cfg.group_ops_ristretto_scalar_add_cost = Some(10);
4558                    cfg.group_ops_ristretto_point_add_cost = Some(500);
4559                    cfg.group_ops_ristretto_scalar_sub_cost = Some(10);
4560                    cfg.group_ops_ristretto_point_sub_cost = Some(500);
4561                    cfg.group_ops_ristretto_scalar_mul_cost = Some(11);
4562                    cfg.group_ops_ristretto_point_mul_cost = Some(1200);
4563                    cfg.group_ops_ristretto_scalar_div_cost = Some(151);
4564                    cfg.group_ops_ristretto_point_div_cost = Some(2500);
4565
4566                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4567                        cfg.feature_flags.enable_ristretto255_group_ops = true;
4568                    }
4569                }
4570                113 => {
4571                    cfg.feature_flags.address_balance_gas_check_rgp_at_signing = true;
4572                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4573                        cfg.feature_flags.defer_unpaid_amplification = true;
4574                    }
4575                }
4576                114 => {
4577                    cfg.feature_flags.randomize_checkpoint_tx_limit_in_tests = true;
4578                    cfg.feature_flags.address_balance_gas_reject_gas_coin_arg = true;
4579                    if chain != Chain::Mainnet {
4580                        cfg.feature_flags.split_checkpoints_in_consensus_handler = true;
4581                        cfg.feature_flags.enable_authenticated_event_streams = true;
4582                        cfg.feature_flags
4583                            .include_checkpoint_artifacts_digest_in_summary = true;
4584                    }
4585                }
4586                115 => {
4587                    cfg.feature_flags.normalize_depth_formula = true;
4588                }
4589                116 => {
4590                    cfg.feature_flags.gasless_transaction_drop_safety = true;
4591                    cfg.feature_flags.address_aliases = true;
4592                    cfg.feature_flags.relax_valid_during_for_owned_inputs = true;
4593                    // Disabled while debugging
4594                    cfg.feature_flags.defer_unpaid_amplification = false;
4595                    cfg.feature_flags.enable_display_registry = true;
4596                }
4597                117 => {}
4598                118 => {
4599                    cfg.feature_flags.use_coin_party_owner = true;
4600                }
4601                119 => {
4602                    // Enable new VM.
4603                    cfg.execution_version = Some(4);
4604                    cfg.feature_flags.address_balance_gas_reject_gas_coin_arg = false;
4605                    cfg.feature_flags.merge_randomness_into_checkpoint = true;
4606                    if chain != Chain::Mainnet {
4607                        cfg.feature_flags.enable_gasless = true;
4608                        cfg.gasless_max_computation_units = Some(50_000);
4609                        cfg.gasless_allowed_token_types = Some(vec![]);
4610                        cfg.feature_flags.enable_coin_reservation_obj_refs = true;
4611                        cfg.feature_flags
4612                            .convert_withdrawal_compatibility_ptb_arguments = true;
4613                    }
4614                    cfg.gasless_max_unused_inputs = Some(1);
4615                    cfg.gasless_max_pure_input_bytes = Some(32);
4616                    if chain == Chain::Testnet {
4617                        cfg.gasless_allowed_token_types = Some(vec![(TESTNET_USDC.to_string(), 0)]);
4618                    }
4619                    cfg.transfer_receive_object_cost_per_byte = Some(1);
4620                    cfg.transfer_receive_object_type_cost_per_byte = Some(2);
4621                }
4622                120 => {
4623                    cfg.feature_flags.disallow_jump_orphans = true;
4624                }
4625                121 => {
4626                    // Re-enable unpaid amplification deferral protection (testnet + devnet)
4627                    if chain != Chain::Mainnet {
4628                        cfg.feature_flags.defer_unpaid_amplification = true;
4629                        cfg.gasless_max_tps = Some(50);
4630                    }
4631                    cfg.feature_flags
4632                        .early_return_receive_object_mismatched_type = true;
4633                }
4634                122 => {
4635                    // Enable unpaid amplification deferral on mainnet
4636                    cfg.feature_flags.defer_unpaid_amplification = true;
4637                    // Enable bulletproofs range proofs on devnet
4638                    cfg.verify_bulletproofs_ristretto255_base_cost = Some(30000);
4639                    cfg.verify_bulletproofs_ristretto255_cost_per_bit_and_commitment = Some(6500);
4640                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4641                        cfg.feature_flags.enable_verify_bulletproofs_ristretto255 = true;
4642                    }
4643                    cfg.feature_flags.gasless_verify_remaining_balance = true;
4644                    cfg.include_special_package_amendments = match chain {
4645                        Chain::Mainnet => Some(MAINNET_LINKAGE_AMENDMENTS.clone()),
4646                        Chain::Testnet => Some(TESTNET_LINKAGE_AMENDMENTS.clone()),
4647                        Chain::Unknown => None,
4648                    };
4649                    cfg.gasless_max_tx_size_bytes = Some(16 * 1024);
4650                    cfg.gasless_max_tps = Some(300);
4651                    cfg.gasless_max_computation_units = Some(5_000);
4652                }
4653                123 => {
4654                    cfg.gas_model_version = Some(13);
4655                }
4656                124 => {
4657                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4658                        cfg.feature_flags.timestamp_based_epoch_close = true;
4659                    }
4660                    cfg.gas_model_version = Some(14);
4661                    cfg.feature_flags.limit_groth16_pvk_inputs = true;
4662
4663                    // Bring mainnet in line with testnet: enable address balances, the
4664                    // gasless "free tier", coin reservations, and the rest of the
4665                    // accumulator/withdraw stack. These are all already enabled on
4666                    // testnet and devnet, so setting them unconditionally is a no-op
4667                    // there.
4668                    cfg.feature_flags.enable_accumulators = true;
4669                    cfg.feature_flags.enable_address_balance_gas_payments = true;
4670                    cfg.feature_flags.enable_authenticated_event_streams = true;
4671                    cfg.feature_flags.enable_coin_reservation_obj_refs = true;
4672                    cfg.feature_flags.enable_object_funds_withdraw = true;
4673                    cfg.feature_flags
4674                        .convert_withdrawal_compatibility_ptb_arguments = true;
4675                    cfg.feature_flags.split_checkpoints_in_consensus_handler = true;
4676                    cfg.feature_flags
4677                        .include_checkpoint_artifacts_digest_in_summary = true;
4678                    cfg.feature_flags.enable_gasless = true;
4679
4680                    // Set the mainnet allow-list. Testnet already has its USDC entry
4681                    // from v119, so only set this on mainnet to avoid clobbering the
4682                    // testnet value. $0.01 minimum transfer per stable; all listed
4683                    // tokens have 6 decimals.
4684                    if chain == Chain::Mainnet {
4685                        cfg.gasless_allowed_token_types = Some(vec![
4686                            (MAINNET_USDC.to_string(), 10_000),
4687                            (MAINNET_USDSUI.to_string(), 10_000),
4688                            (MAINNET_SUI_USDE.to_string(), 10_000),
4689                            (MAINNET_USDY.to_string(), 10_000),
4690                            (MAINNET_FDUSD.to_string(), 10_000),
4691                            (MAINNET_AUSD.to_string(), 10_000),
4692                            (MAINNET_USDB.to_string(), 10_000),
4693                        ]);
4694                    }
4695                }
4696                125 => {
4697                    cfg.feature_flags.granular_post_execution_checks = true;
4698                    if chain != Chain::Mainnet {
4699                        cfg.feature_flags.timestamp_based_epoch_close = true;
4700                    }
4701                }
4702                126 => {
4703                    cfg.feature_flags.early_exit_on_iffw = true;
4704                }
4705                127 => {
4706                    cfg.feature_flags.always_advance_dkg_to_resolution = true;
4707
4708                    cfg.verify_bulletproofs_ristretto255_base_cost = Some(23866);
4709                    cfg.verify_bulletproofs_ristretto255_cost_per_bit_and_commitment = Some(1324);
4710                    cfg.group_ops_ristretto_decode_scalar_cost = Some(5);
4711                    cfg.group_ops_ristretto_decode_point_cost = Some(216);
4712                    cfg.group_ops_ristretto_scalar_add_cost = Some(2);
4713                    cfg.group_ops_ristretto_point_add_cost = Some(8);
4714                    cfg.group_ops_ristretto_scalar_sub_cost = Some(2);
4715                    cfg.group_ops_ristretto_point_sub_cost = Some(8);
4716                    cfg.group_ops_ristretto_scalar_mul_cost = Some(5);
4717                    cfg.group_ops_ristretto_point_mul_cost = Some(1763);
4718                    cfg.group_ops_ristretto_scalar_div_cost = Some(557);
4719                    cfg.group_ops_ristretto_point_div_cost = Some(2244);
4720
4721                    if chain != Chain::Mainnet {
4722                        cfg.feature_flags.enable_ristretto255_group_ops = true;
4723                        cfg.feature_flags.enable_verify_bulletproofs_ristretto255 = true;
4724                    }
4725
4726                    cfg.feature_flags.timestamp_based_epoch_close = true;
4727                }
4728                128 => {
4729                    cfg.max_generic_instantiation_type_nodes_per_function = Some(10_000);
4730                    cfg.max_generic_instantiation_type_nodes_per_module = Some(500_000);
4731                    cfg.binary_enum_defs = Some(200);
4732                    cfg.binary_enum_def_instantiations = Some(100);
4733                }
4734                129 => {
4735                    cfg.feature_flags.enable_unified_linkage = true;
4736                }
4737                130 => {
4738                    cfg.feature_flags.record_net_unsettled_object_withdraws = true;
4739                    cfg.feature_flags.enable_init_on_upgrade = true;
4740                    cfg.epoch_close_deadline_ms = Some(120_000);
4741                    cfg.scratch_add_cost_base = Some(13);
4742                    cfg.scratch_read_cost_base = Some(13);
4743                    cfg.scratch_read_value_cost = Some(1);
4744                    cfg.scratch_remove_cost_base = Some(13);
4745                    cfg.scratch_exists_cost_base = Some(13);
4746                    cfg.scratch_exists_with_type_cost_base = Some(13);
4747                    cfg.scratch_exists_with_type_type_cost = Some(1);
4748                    let max_commands = cfg.max_programmable_tx_commands() as u64;
4749                    cfg.max_scratch_pad_size = Some(16 * max_commands);
4750                    // Verify with the v2 then v1 for devnet.
4751                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4752                        cfg.feature_flags.zklogin_circuit_mode = 1;
4753                    }
4754                }
4755                131 => {
4756                    cfg.feature_flags.share_transaction_deny_config_in_consensus = true;
4757                    cfg.feature_flags.framework_tx_context_mut_restrictions = true;
4758                }
4759                132 => {
4760                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4761                        cfg.feature_flags.defer_owned_object_double_spend = true;
4762                        cfg.feature_flags.create_forwarding_address_registry = true;
4763                    }
4764                    cfg.object_record_new_uid_from_hash_cost_base = Some(1);
4765                    cfg.feature_flags
4766                        .enable_order_independent_upgrade_init_linkage = true;
4767                }
4768                133 => {
4769                    cfg.feature_flags
4770                        .include_function_signatures_in_instantiation_limits = true;
4771                    cfg.max_accumulator_type_nodes = Some(16);
4772                }
4773                134 => {
4774                    // v134 was released to testnet with this content before the 1.77
4775                    // branch backfilled its own v134 to disable defer_unpaid_amplification
4776                    // on mainnet. To keep (v134, Mainnet) identical across the 1.77 and
4777                    // 1.78 branches, the original v134 content is gated off mainnet here
4778                    // (it applies to mainnet in v135 instead), and mainnet's v134 carries
4779                    // only the deferral disable.
4780                    if chain != Chain::Mainnet {
4781                        cfg.package_original_package_id_impl_cost_base = Some(52);
4782                        let package_read_cost_per_byte = cfg.obj_access_cost_read_per_byte();
4783                        cfg.package_original_package_id_impl_cost_per_byte =
4784                            Some(package_read_cost_per_byte);
4785
4786                        cfg.consensus_max_transactions_in_block_bytes = Some(288 * 1024);
4787                        cfg.consensus_max_num_transactions_in_block = Some(128);
4788                    }
4789
4790                    if chain == Chain::Mainnet {
4791                        cfg.feature_flags.defer_unpaid_amplification = false;
4792                    }
4793                }
4794                135 => {
4795                    // Apply the original v134 content on mainnet (no-op re-assignment on
4796                    // chains that already applied it in v134).
4797                    cfg.package_original_package_id_impl_cost_base = Some(52);
4798                    let package_read_cost_per_byte = cfg.obj_access_cost_read_per_byte();
4799                    cfg.package_original_package_id_impl_cost_per_byte =
4800                        Some(package_read_cost_per_byte);
4801
4802                    cfg.consensus_max_transactions_in_block_bytes = Some(288 * 1024);
4803                    cfg.consensus_max_num_transactions_in_block = Some(128);
4804
4805                    cfg.feature_flags.defer_unpaid_amplification = false;
4806                }
4807                136 => {
4808                    cfg.feature_flags.ptb_tx_context_restrictions = true;
4809
4810                    cfg.translation_per_live_reference_charge = Some(1);
4811                    cfg.max_ptb_live_references = Some(64);
4812                    cfg.max_ptb_returned_references = Some(16);
4813                    cfg.max_ptb_total_returned_references = Some(256);
4814
4815                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4816                        cfg.feature_flags.allowed_proposers = true;
4817                    }
4818                    cfg.feature_flags.harden_linkage_consistency = true;
4819
4820                    cfg.package_arena_size_in_bytes = Some(10_000_000);
4821                }
4822                137 => {
4823                    cfg.verify_bulletproofs_ristretto255_cost_per_bit_and_commitment = Some(621);
4824                    cfg.max_bulletproofs_total_bits = Some(1024);
4825
4826                    if chain != Chain::Mainnet {
4827                        cfg.feature_flags.enable_allowances = true;
4828                    }
4829                    cfg.feature_flags.fix_ptb_generated_reads = true;
4830                    cfg.feature_flags.charge_ld_const_abstract_size = true;
4831                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4832                        cfg.feature_flags.check_object_funds_withdraw_in_execution = true;
4833                    }
4834                    cfg.reserve_object_funds_for_withdrawal_cost_base = Some(52);
4835                    // Equivalent to the fixed portion of a dynamic-field lookup (52 + 52) plus
4836                    // loading the 80-byte accumulator field contents at one gas unit per byte.
4837                    cfg.reserve_object_funds_for_withdrawal_cold_read_cost = Some(184);
4838
4839                    cfg.feature_flags.allowed_proposers = true;
4840
4841                    cfg.feature_flags.validate_ptb_argument_indices = true;
4842                    cfg.feature_flags.memory_safety_invariant_check_v2 = true;
4843                }
4844                138 => {
4845                    cfg.gas_model_version = Some(15);
4846                    cfg.feature_flags.enable_allowances = true;
4847                    if chain != Chain::Mainnet {
4848                        cfg.feature_flags.check_object_funds_withdraw_in_execution = true;
4849                        cfg.feature_flags.disable_effects_tx_dependencies = true;
4850                    }
4851                    cfg.feature_flags.merge_colliding_deferrals = true;
4852                    // Testnet already runs version 138, so it gets this change in version 139.
4853                    if chain == Chain::Mainnet {
4854                        cfg.storage_rebate_rate = Some(9999);
4855                    }
4856                }
4857                139 => {
4858                    if chain != Chain::Mainnet && chain != Chain::Testnet {
4859                        cfg.feature_flags.enable_forwarding_addresses = true;
4860                        cfg.feature_flags.mldsa65_auth = true;
4861                    }
4862                    cfg.storage_rebate_rate = Some(9999);
4863                    if chain != Chain::Mainnet {
4864                        cfg.feature_flags.allow_dkg_completion_after_timeout = true;
4865                    }
4866                    // Validators cache packages, so reading one costs far less than reading an object.
4867                    cfg.obj_access_cost_read_per_package_kb = Some(154);
4868                }
4869                140 => {
4870                    cfg.vector_reverse_base_cost = Some(52);
4871                    cfg.vector_reverse_per_elem_cost = Some(8);
4872                    cfg.vector_keep_range_base_cost = Some(52);
4873                    cfg.vector_keep_range_per_dropped_elem_cost = Some(1);
4874                    cfg.vector_keep_range_per_moved_elem_cost = Some(8);
4875                    cfg.vector_copy_range_base_cost = Some(52);
4876                    cfg.vector_replace_range_base_cost = Some(52);
4877                    cfg.vector_replace_range_per_elem_cost = Some(8);
4878                }
4879                // Use this template when making changes:
4880                //
4881                //     // modify an existing constant.
4882                //     move_binary_format_version: Some(7),
4883                //
4884                //     // Add a new constant (which is set to None in prior versions).
4885                //     new_constant: Some(new_value),
4886                //
4887                //     // Remove a constant (ensure that it is never accessed during this version).
4888                //     max_move_object_size: None,
4889                _ => panic!("unsupported version {:?}", version),
4890            }
4891        }
4892
4893        cfg
4894    }
4895
4896    pub fn apply_seeded_test_overrides(&mut self, seed: &[u8; 32]) {
4897        if !self.feature_flags.randomize_checkpoint_tx_limit_in_tests
4898            || !self.feature_flags.split_checkpoints_in_consensus_handler
4899        {
4900            return;
4901        }
4902
4903        if !mysten_common::in_test_configuration() {
4904            return;
4905        }
4906
4907        use rand::{Rng, SeedableRng, rngs::StdRng};
4908        let mut rng = StdRng::from_seed(*seed);
4909        let max_txns = rng.gen_range(10..=100u64);
4910        info!("seeded test override: max_transactions_per_checkpoint = {max_txns}");
4911        self.max_transactions_per_checkpoint = Some(max_txns);
4912    }
4913
4914    // Extract the bytecode verifier config from this protocol config.
4915    // If used during signing, `signing_limits` should be set.
4916    // The third limit configures`sanity_check_with_regex_reference_safety`,
4917    // which runs the new regex-based reference safety check to check that it is strictly more
4918    // permissive than the current implementation.
4919    pub fn verifier_config(&self, signing_limits: Option<(usize, usize, usize)>) -> VerifierConfig {
4920        let (
4921            max_back_edges_per_function,
4922            max_back_edges_per_module,
4923            sanity_check_with_regex_reference_safety,
4924        ) = if let Some((
4925            max_back_edges_per_function,
4926            max_back_edges_per_module,
4927            sanity_check_with_regex_reference_safety,
4928        )) = signing_limits
4929        {
4930            (
4931                Some(max_back_edges_per_function),
4932                Some(max_back_edges_per_module),
4933                Some(sanity_check_with_regex_reference_safety),
4934            )
4935        } else {
4936            (None, None, None)
4937        };
4938
4939        let additional_borrow_checks = if signing_limits.is_some() {
4940            // always turn on additional borrow checks during signing
4941            true
4942        } else {
4943            self.additional_borrow_checks()
4944        };
4945        let deprecate_global_storage_ops = if signing_limits.is_some() {
4946            // always turn on additional vector borrow checks during signing
4947            true
4948        } else {
4949            self.deprecate_global_storage_ops()
4950        };
4951
4952        VerifierConfig {
4953            max_loop_depth: Some(self.max_loop_depth() as usize),
4954            max_generic_instantiation_length: Some(self.max_generic_instantiation_length() as usize),
4955            max_function_parameters: Some(self.max_function_parameters() as usize),
4956            max_basic_blocks: Some(self.max_basic_blocks() as usize),
4957            max_value_stack_size: self.max_value_stack_size() as usize,
4958            max_type_nodes: Some(self.max_type_nodes() as usize),
4959            max_generic_instantiation_type_nodes_per_function: self
4960                .max_generic_instantiation_type_nodes_per_function_as_option()
4961                .map(|v| v as usize),
4962            max_generic_instantiation_type_nodes_per_module: self
4963                .max_generic_instantiation_type_nodes_per_module_as_option()
4964                .map(|v| v as usize),
4965            include_function_signatures_in_instantiation_limits: self
4966                .include_function_signatures_in_instantiation_limits(),
4967            max_push_size: Some(self.max_push_size() as usize),
4968            max_dependency_depth: Some(self.max_dependency_depth() as usize),
4969            max_fields_in_struct: Some(self.max_fields_in_struct() as usize),
4970            max_function_definitions: Some(self.max_function_definitions() as usize),
4971            max_data_definitions: Some(self.max_struct_definitions() as usize),
4972            max_constant_vector_len: Some(self.max_move_vector_len()),
4973            max_back_edges_per_function,
4974            max_back_edges_per_module,
4975            max_basic_blocks_in_script: None,
4976            max_identifier_len: self.max_move_identifier_len_as_option(), // Before protocol version 9, there was no limit
4977            disallow_self_identifier: self.feature_flags.disallow_self_identifier,
4978            allow_receiving_object_id: self.allow_receiving_object_id(),
4979            reject_mutable_random_on_entry_functions: self
4980                .reject_mutable_random_on_entry_functions(),
4981            bytecode_version: self.move_binary_format_version(),
4982            max_variants_in_enum: self.max_move_enum_variants_as_option(),
4983            additional_borrow_checks,
4984            better_loader_errors: self.better_loader_errors(),
4985            private_generics_verifier_v2: self.private_generics_verifier_v2(),
4986            sanity_check_with_regex_reference_safety: sanity_check_with_regex_reference_safety
4987                .map(|limit| limit as u128),
4988            deprecate_global_storage_ops,
4989            disable_entry_point_signature_check: self.disable_entry_point_signature_check(),
4990            switch_to_regex_reference_safety: false,
4991            framework_tx_context_mut_restrictions: self.framework_tx_context_mut_restrictions(),
4992            disallow_jump_orphans: self.disallow_jump_orphans(),
4993        }
4994    }
4995
4996    pub fn binary_config(
4997        &self,
4998        override_deprecate_global_storage_ops_during_deserialization: Option<bool>,
4999    ) -> BinaryConfig {
5000        let deprecate_global_storage_ops =
5001            override_deprecate_global_storage_ops_during_deserialization
5002                .unwrap_or_else(|| self.deprecate_global_storage_ops());
5003        BinaryConfig::new(
5004            self.move_binary_format_version(),
5005            self.min_move_binary_format_version_as_option()
5006                .unwrap_or(VERSION_1),
5007            self.no_extraneous_module_bytes(),
5008            deprecate_global_storage_ops,
5009            TableConfig {
5010                module_handles: self.binary_module_handles_as_option().unwrap_or(u16::MAX),
5011                datatype_handles: self.binary_struct_handles_as_option().unwrap_or(u16::MAX),
5012                function_handles: self.binary_function_handles_as_option().unwrap_or(u16::MAX),
5013                function_instantiations: self
5014                    .binary_function_instantiations_as_option()
5015                    .unwrap_or(u16::MAX),
5016                signatures: self.binary_signatures_as_option().unwrap_or(u16::MAX),
5017                constant_pool: self.binary_constant_pool_as_option().unwrap_or(u16::MAX),
5018                identifiers: self.binary_identifiers_as_option().unwrap_or(u16::MAX),
5019                address_identifiers: self
5020                    .binary_address_identifiers_as_option()
5021                    .unwrap_or(u16::MAX),
5022                struct_defs: self.binary_struct_defs_as_option().unwrap_or(u16::MAX),
5023                struct_def_instantiations: self
5024                    .binary_struct_def_instantiations_as_option()
5025                    .unwrap_or(u16::MAX),
5026                function_defs: self.binary_function_defs_as_option().unwrap_or(u16::MAX),
5027                field_handles: self.binary_field_handles_as_option().unwrap_or(u16::MAX),
5028                field_instantiations: self
5029                    .binary_field_instantiations_as_option()
5030                    .unwrap_or(u16::MAX),
5031                friend_decls: self.binary_friend_decls_as_option().unwrap_or(u16::MAX),
5032                enum_defs: self.binary_enum_defs_as_option().unwrap_or(u16::MAX),
5033                enum_def_instantiations: self
5034                    .binary_enum_def_instantiations_as_option()
5035                    .unwrap_or(u16::MAX),
5036                variant_handles: self.binary_variant_handles_as_option().unwrap_or(u16::MAX),
5037                variant_instantiation_handles: self
5038                    .binary_variant_instantiation_handles_as_option()
5039                    .unwrap_or(u16::MAX),
5040            },
5041        )
5042    }
5043
5044    /// Override one or more settings in the config, for testing.
5045    /// This must be called at the beginning of the test, before get_for_(min|max)_version is
5046    /// called, since those functions cache their return value.
5047    pub fn apply_overrides_for_testing(
5048        override_fn: impl Fn(ProtocolVersion, Self) -> Self + Send + Sync + 'static,
5049    ) -> OverrideGuard {
5050        let mut cur = CONFIG_OVERRIDE.lock().unwrap();
5051        assert!(cur.is_none(), "config override already present");
5052        *cur = Some(Box::new(override_fn));
5053        OverrideGuard
5054    }
5055
5056    fn apply_config_override(version: ProtocolVersion, mut ret: Self) -> Self {
5057        if let Some(override_fn) = CONFIG_OVERRIDE.lock().unwrap().as_ref() {
5058            warn!(
5059                "overriding ProtocolConfig settings with custom settings (you should not see this log outside of tests)"
5060            );
5061            ret = override_fn(version, ret);
5062        }
5063        ret
5064    }
5065}
5066
5067// Setters for tests.
5068// This is only needed for feature_flags. Please suffix each setter with `_for_testing`.
5069// Non-feature_flags should already have test setters defined through macros.
5070impl ProtocolConfig {
5071    // Hand-written (the field is marked #[custom_setter]) to forbid downgrades: an executor
5072    // older than the config's protocol version can't link the frameworks of later versions —
5073    // its natives tables are frozen. Upgrades are allowed for replay's executor override.
5074    pub fn set_execution_version_for_testing(&mut self, val: u64) {
5075        let current = self.execution_version.unwrap_or(0);
5076        assert!(
5077            val >= current,
5078            "cannot downgrade execution_version from {current} to {val}: running an old \
5079             executor against a newer protocol config/framework is unsupported. To test \
5080             frozen executor behavior, start from the last protocol version of that executor \
5081             instead, so genesis loads the matching framework snapshot (see \
5082             test_address_balance_gas_v3_accumulator_sign)."
5083        );
5084        self.execution_version = Some(val);
5085    }
5086
5087    // Not generated by the feature-flags derive because zklogin_circuit_mode is a u64
5088    // flag (the macro only generates setters for bool flags).
5089    pub fn set_zklogin_circuit_mode_for_testing(&mut self, val: u64) {
5090        self.feature_flags.zklogin_circuit_mode = val
5091    }
5092
5093    pub fn set_per_object_congestion_control_mode_for_testing(
5094        &mut self,
5095        val: PerObjectCongestionControlMode,
5096    ) {
5097        self.feature_flags.per_object_congestion_control_mode = val;
5098    }
5099
5100    pub fn set_consensus_choice_for_testing(&mut self, val: ConsensusChoice) {
5101        self.feature_flags.consensus_choice = val;
5102    }
5103
5104    pub fn set_consensus_network_for_testing(&mut self, val: ConsensusNetwork) {
5105        self.feature_flags.consensus_network = val;
5106    }
5107
5108    pub fn set_zklogin_max_epoch_upper_bound_delta_for_testing(&mut self, val: Option<u64>) {
5109        self.feature_flags.zklogin_max_epoch_upper_bound_delta = val
5110    }
5111
5112    pub fn set_mysticeti_num_leaders_per_round_for_testing(&mut self, val: Option<usize>) {
5113        self.feature_flags.mysticeti_num_leaders_per_round = val;
5114    }
5115
5116    pub fn disable_accumulators_for_testing(&mut self) {
5117        self.feature_flags.enable_accumulators = false;
5118        self.feature_flags.enable_address_balance_gas_payments = false;
5119    }
5120
5121    pub fn enable_coin_reservation_for_testing(&mut self) {
5122        self.feature_flags.enable_coin_reservation_obj_refs = true;
5123        self.feature_flags
5124            .convert_withdrawal_compatibility_ptb_arguments = true;
5125        // Ensure execution_version >= 4 so new_vm_enabled() returns true,
5126        // which is required for enable_coin_reservation_obj_refs() to return true.
5127        self.execution_version = Some(self.execution_version.map_or(4, |v| v.max(4)));
5128    }
5129
5130    pub fn disable_coin_reservation_for_testing(&mut self) {
5131        self.feature_flags.enable_coin_reservation_obj_refs = false;
5132        self.feature_flags
5133            .convert_withdrawal_compatibility_ptb_arguments = false;
5134    }
5135
5136    pub fn enable_address_balance_gas_payments_for_testing(&mut self) {
5137        self.feature_flags.enable_accumulators = true;
5138        self.feature_flags.allow_private_accumulator_entrypoints = true;
5139        self.feature_flags.enable_address_balance_gas_payments = true;
5140        self.feature_flags.address_balance_gas_check_rgp_at_signing = true;
5141        self.feature_flags.address_balance_gas_reject_gas_coin_arg = false;
5142        self.execution_version = Some(self.execution_version.map_or(4, |v| v.max(4)))
5143    }
5144
5145    pub fn enable_gasless_for_testing(&mut self) {
5146        self.enable_address_balance_gas_payments_for_testing();
5147        self.feature_flags.enable_gasless = true;
5148        self.feature_flags.gasless_verify_remaining_balance = true;
5149        self.gasless_max_computation_units = Some(5_000);
5150        self.gasless_allowed_token_types = Some(vec![]);
5151        self.gasless_max_tps = Some(1000);
5152        self.gasless_max_tx_size_bytes = Some(16 * 1024);
5153    }
5154
5155    pub fn disable_gasless_for_testing(&mut self) {
5156        self.feature_flags.enable_gasless = false;
5157        self.gasless_max_computation_units = None;
5158        self.gasless_allowed_token_types = None;
5159    }
5160
5161    pub fn enable_authenticated_event_streams_for_testing(&mut self) {
5162        self.feature_flags.enable_accumulators = true;
5163        self.feature_flags.enable_authenticated_event_streams = true;
5164        self.feature_flags
5165            .include_checkpoint_artifacts_digest_in_summary = true;
5166        self.feature_flags.split_checkpoints_in_consensus_handler = true;
5167    }
5168}
5169
5170type OverrideFn = dyn Fn(ProtocolVersion, ProtocolConfig) -> ProtocolConfig + Send + Sync;
5171
5172static CONFIG_OVERRIDE: Mutex<Option<Box<OverrideFn>>> = Mutex::new(None);
5173
5174#[must_use]
5175pub struct OverrideGuard;
5176
5177impl Drop for OverrideGuard {
5178    fn drop(&mut self) {
5179        info!("restoring override fn");
5180        *CONFIG_OVERRIDE.lock().unwrap() = None;
5181    }
5182}
5183
5184/// Defines which limit got crossed.
5185/// The value which crossed the limit and value of the limit crossed are embedded
5186#[derive(PartialEq, Eq)]
5187pub enum LimitThresholdCrossed {
5188    None,
5189    Soft(u128, u128),
5190    Hard(u128, u128),
5191}
5192
5193/// Convenience function for comparing limit ranges
5194/// V::MAX must be at >= U::MAX and T::MAX
5195pub fn check_limit_in_range<T: Into<V>, U: Into<V>, V: PartialOrd + Into<u128>>(
5196    x: T,
5197    soft_limit: U,
5198    hard_limit: V,
5199) -> LimitThresholdCrossed {
5200    let x: V = x.into();
5201    let soft_limit: V = soft_limit.into();
5202
5203    debug_assert!(soft_limit <= hard_limit);
5204
5205    // It is important to preserve this comparison order because if soft_limit == hard_limit
5206    // we want LimitThresholdCrossed::Hard
5207    if x >= hard_limit {
5208        LimitThresholdCrossed::Hard(x.into(), hard_limit.into())
5209    } else if x < soft_limit {
5210        LimitThresholdCrossed::None
5211    } else {
5212        LimitThresholdCrossed::Soft(x.into(), soft_limit.into())
5213    }
5214}
5215
5216#[macro_export]
5217macro_rules! check_limit {
5218    ($x:expr, $hard:expr) => {
5219        check_limit!($x, $hard, $hard)
5220    };
5221    ($x:expr, $soft:expr, $hard:expr) => {
5222        check_limit_in_range($x as u64, $soft, $hard)
5223    };
5224}
5225
5226/// Used to check which limits were crossed if the TX is metered (not system tx)
5227/// Args are: is_metered, value_to_check, metered_limit, unmetered_limit
5228/// metered_limit is always less than or equal to unmetered_hard_limit
5229#[macro_export]
5230macro_rules! check_limit_by_meter {
5231    ($is_metered:expr, $x:expr, $metered_limit:expr, $unmetered_hard_limit:expr, $metric:expr) => {{
5232        // If this is metered, we use the metered_limit limit as the upper bound
5233        let (h, metered_str) = if $is_metered {
5234            ($metered_limit, "metered")
5235        } else {
5236            // Unmetered gets more headroom
5237            ($unmetered_hard_limit, "unmetered")
5238        };
5239        use sui_protocol_config::check_limit_in_range;
5240        let result = check_limit_in_range($x as u64, $metered_limit, h);
5241        match result {
5242            LimitThresholdCrossed::None => {}
5243            LimitThresholdCrossed::Soft(_, _) => {
5244                $metric.with_label_values(&[metered_str, "soft"]).inc();
5245            }
5246            LimitThresholdCrossed::Hard(_, _) => {
5247                $metric.with_label_values(&[metered_str, "hard"]).inc();
5248            }
5249        };
5250        result
5251    }};
5252}
5253
5254// Amendments tables
5255
5256pub type Amendments = BTreeMap<AccountAddress, BTreeMap<AccountAddress, AccountAddress>>;
5257
5258static MAINNET_LINKAGE_AMENDMENTS: LazyLock<Arc<Amendments>> =
5259    LazyLock::new(|| parse_amendments(include_str!("mainnet_amendments.json")));
5260
5261static TESTNET_LINKAGE_AMENDMENTS: LazyLock<Arc<Amendments>> =
5262    LazyLock::new(|| parse_amendments(include_str!("testnet_amendments.json")));
5263
5264fn parse_amendments(json: &str) -> Arc<Amendments> {
5265    #[derive(serde::Deserialize)]
5266    struct AmendmentEntry {
5267        root: String,
5268        deps: Vec<DepEntry>,
5269    }
5270
5271    #[derive(serde::Deserialize)]
5272    struct DepEntry {
5273        original_id: String,
5274        version_id: String,
5275    }
5276
5277    let entries: Vec<AmendmentEntry> =
5278        serde_json::from_str(json).expect("Failed to parse amendments JSON");
5279    let mut amendments = BTreeMap::new();
5280    for entry in entries {
5281        let root_id = AccountAddress::from_hex_literal(&entry.root).unwrap();
5282        let mut dep_ids = BTreeMap::new();
5283        for dep in entry.deps {
5284            let orig_id = AccountAddress::from_hex_literal(&dep.original_id).unwrap();
5285            let upgraded_id = AccountAddress::from_hex_literal(&dep.version_id).unwrap();
5286            assert!(
5287                dep_ids.insert(orig_id, upgraded_id).is_none(),
5288                "Duplicate original ID in amendments table"
5289            );
5290        }
5291        assert!(
5292            amendments.insert(root_id, dep_ids).is_none(),
5293            "Duplicate root ID in amendments table"
5294        );
5295    }
5296    Arc::new(amendments)
5297}
5298
5299#[cfg(all(test, not(msim)))]
5300mod test {
5301    use insta::assert_yaml_snapshot;
5302
5303    use super::*;
5304
5305    #[test]
5306    fn snapshot_tests() {
5307        println!("\n============================================================================");
5308        println!("!                                                                          !");
5309        println!("! IMPORTANT: never update snapshots from this test. only add new versions! !");
5310        println!("!                                                                          !");
5311        println!("============================================================================\n");
5312        for chain_id in &[Chain::Unknown, Chain::Mainnet, Chain::Testnet] {
5313            // make Chain::Unknown snapshots compatible with pre-chain-id snapshots so that we
5314            // don't break the release-time compatibility tests. Once Chain Id configs have been
5315            // released everywhere, we can remove this and only test Mainnet and Testnet
5316            let chain_str = match chain_id {
5317                Chain::Unknown => "".to_string(),
5318                _ => format!("{:?}_", chain_id),
5319            };
5320            for i in MIN_PROTOCOL_VERSION..=MAX_PROTOCOL_VERSION {
5321                let cur = ProtocolVersion::new(i);
5322                assert_yaml_snapshot!(
5323                    format!("{}version_{}", chain_str, cur.as_u64()),
5324                    ProtocolConfig::get_for_version(cur, *chain_id)
5325                );
5326            }
5327        }
5328    }
5329
5330    #[test]
5331    fn test_getters() {
5332        let prot: ProtocolConfig =
5333            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5334        assert_eq!(
5335            prot.max_arguments(),
5336            prot.max_arguments_as_option().unwrap()
5337        );
5338    }
5339
5340    #[test]
5341    fn vector_bulk_native_gas_costs_start_at_version_140() {
5342        for chain in [Chain::Unknown, Chain::Mainnet, Chain::Testnet] {
5343            let before = ProtocolConfig::get_for_version(ProtocolVersion::new(139), chain);
5344            assert_eq!(before.vector_reverse_base_cost_as_option(), None);
5345            assert_eq!(before.vector_reverse_per_elem_cost_as_option(), None);
5346            assert_eq!(before.vector_keep_range_base_cost_as_option(), None);
5347            assert_eq!(
5348                before.vector_keep_range_per_dropped_elem_cost_as_option(),
5349                None
5350            );
5351            assert_eq!(
5352                before.vector_keep_range_per_moved_elem_cost_as_option(),
5353                None
5354            );
5355            assert_eq!(before.vector_copy_range_base_cost_as_option(), None);
5356            assert_eq!(before.vector_replace_range_base_cost_as_option(), None);
5357            assert_eq!(before.vector_replace_range_per_elem_cost_as_option(), None);
5358
5359            let active = ProtocolConfig::get_for_version(ProtocolVersion::new(140), chain);
5360            assert_eq!(active.vector_reverse_base_cost_as_option(), Some(52));
5361            assert_eq!(active.vector_reverse_per_elem_cost_as_option(), Some(8));
5362            assert_eq!(active.vector_keep_range_base_cost_as_option(), Some(52));
5363            assert_eq!(
5364                active.vector_keep_range_per_dropped_elem_cost_as_option(),
5365                Some(1)
5366            );
5367            assert_eq!(
5368                active.vector_keep_range_per_moved_elem_cost_as_option(),
5369                Some(8)
5370            );
5371            assert_eq!(active.vector_copy_range_base_cost_as_option(), Some(52));
5372            assert_eq!(active.vector_replace_range_base_cost_as_option(), Some(52));
5373            assert_eq!(
5374                active.vector_replace_range_per_elem_cost_as_option(),
5375                Some(8)
5376            );
5377        }
5378    }
5379
5380    #[test]
5381    fn test_setters() {
5382        let mut prot: ProtocolConfig =
5383            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5384        prot.set_max_arguments_for_testing(123);
5385        assert_eq!(prot.max_arguments(), 123);
5386
5387        prot.set_max_arguments_from_str_for_testing("321".to_string());
5388        assert_eq!(prot.max_arguments(), 321);
5389
5390        prot.disable_max_arguments_for_testing();
5391        assert_eq!(prot.max_arguments_as_option(), None);
5392
5393        prot.set_attr_for_testing("max_arguments".to_string(), "456".to_string());
5394        assert_eq!(prot.max_arguments(), 456);
5395    }
5396
5397    #[test]
5398    fn test_execution_version_setter_allows_upgrade() {
5399        let mut prot = ProtocolConfig::get_for_max_version_UNSAFE();
5400        let current = prot.execution_version();
5401        prot.set_execution_version_for_testing(current);
5402        prot.set_execution_version_for_testing(current + 1);
5403        assert_eq!(prot.execution_version(), current + 1);
5404    }
5405
5406    #[test]
5407    #[should_panic(expected = "cannot downgrade execution_version")]
5408    fn test_execution_version_setter_panics_on_downgrade() {
5409        let mut prot = ProtocolConfig::get_for_max_version_UNSAFE();
5410        let current = prot.execution_version();
5411        prot.set_execution_version_for_testing(current - 1);
5412    }
5413
5414    #[test]
5415    fn test_feature_flag_setter_by_string() {
5416        let mut prot: ProtocolConfig =
5417            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5418        assert!(!prot.zklogin_auth());
5419        prot.set_feature_flag_for_testing("zklogin_auth".to_string(), true);
5420        assert!(prot.zklogin_auth());
5421        prot.set_feature_flag_for_testing("zklogin_auth".to_string(), false);
5422        assert!(!prot.zklogin_auth());
5423    }
5424
5425    #[test]
5426    #[should_panic(expected = "unknown feature flag")]
5427    fn test_feature_flag_setter_unknown_flag() {
5428        let mut prot: ProtocolConfig =
5429            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5430        prot.set_feature_flag_for_testing("some random string".to_string(), true);
5431    }
5432
5433    #[test]
5434    fn test_get_for_version_if_supported_applies_test_overrides() {
5435        let before =
5436            ProtocolConfig::get_for_version_if_supported(ProtocolVersion::new(1), Chain::Unknown)
5437                .unwrap();
5438
5439        assert!(!before.enable_coin_reservation_obj_refs());
5440
5441        let _guard = ProtocolConfig::apply_overrides_for_testing(|_, mut cfg| {
5442            cfg.enable_coin_reservation_for_testing();
5443            cfg
5444        });
5445
5446        let after =
5447            ProtocolConfig::get_for_version_if_supported(ProtocolVersion::new(1), Chain::Unknown)
5448                .unwrap();
5449
5450        assert!(after.enable_coin_reservation_obj_refs());
5451    }
5452
5453    #[test]
5454    #[should_panic(expected = "unsupported version")]
5455    fn max_version_test() {
5456        // When this does not panic, version higher than MAX_PROTOCOL_VERSION exists.
5457        // To fix, bump MAX_PROTOCOL_VERSION or disable this check for the version.
5458        let _ = ProtocolConfig::get_for_version_impl(
5459            ProtocolVersion::new(MAX_PROTOCOL_VERSION + 1),
5460            Chain::Unknown,
5461        );
5462    }
5463
5464    #[test]
5465    fn lookup_by_string_test() {
5466        let prot: ProtocolConfig =
5467            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5468        // Does not exist
5469        assert!(prot.lookup_attr("some random string".to_string()).is_none());
5470
5471        assert!(
5472            prot.lookup_attr("max_arguments".to_string())
5473                == Some(ProtocolConfigValue::u32(prot.max_arguments())),
5474        );
5475
5476        // We didnt have this in version 1
5477        assert!(
5478            prot.lookup_attr("max_move_identifier_len".to_string())
5479                .is_none()
5480        );
5481
5482        // But we did in version 9
5483        let prot: ProtocolConfig =
5484            ProtocolConfig::get_for_version(ProtocolVersion::new(9), Chain::Unknown);
5485        assert!(
5486            prot.lookup_attr("max_move_identifier_len".to_string())
5487                == Some(ProtocolConfigValue::u64(prot.max_move_identifier_len()))
5488        );
5489
5490        let prot: ProtocolConfig =
5491            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5492        // We didnt have this in version 1
5493        assert!(
5494            prot.attr_map()
5495                .get("max_move_identifier_len")
5496                .unwrap()
5497                .is_none()
5498        );
5499        // We had this in version 1
5500        assert!(
5501            prot.attr_map().get("max_arguments").unwrap()
5502                == &Some(ProtocolConfigValue::u32(prot.max_arguments()))
5503        );
5504
5505        // Check feature flags
5506        let prot: ProtocolConfig =
5507            ProtocolConfig::get_for_version(ProtocolVersion::new(1), Chain::Unknown);
5508        // Does not exist
5509        assert!(
5510            prot.feature_flags
5511                .lookup_attr("some random string".to_owned())
5512                .is_none()
5513        );
5514        assert!(
5515            !prot
5516                .feature_flags
5517                .attr_map()
5518                .contains_key("some random string")
5519        );
5520
5521        // Was false in v1
5522        assert!(
5523            prot.feature_flags
5524                .lookup_attr("package_upgrades".to_owned())
5525                == Some(false)
5526        );
5527        assert!(
5528            prot.feature_flags
5529                .attr_map()
5530                .get("package_upgrades")
5531                .unwrap()
5532                == &false
5533        );
5534        let prot: ProtocolConfig =
5535            ProtocolConfig::get_for_version(ProtocolVersion::new(4), Chain::Unknown);
5536        // Was true from v3 and up
5537        assert!(
5538            prot.feature_flags
5539                .lookup_attr("package_upgrades".to_owned())
5540                == Some(true)
5541        );
5542        assert!(
5543            prot.feature_flags
5544                .attr_map()
5545                .get("package_upgrades")
5546                .unwrap()
5547                == &true
5548        );
5549    }
5550
5551    #[test]
5552    fn limit_range_fn_test() {
5553        let low = 100u32;
5554        let high = 10000u64;
5555
5556        assert!(check_limit!(1u8, low, high) == LimitThresholdCrossed::None);
5557        assert!(matches!(
5558            check_limit!(255u16, low, high),
5559            LimitThresholdCrossed::Soft(255u128, 100)
5560        ));
5561        // This wont compile because lossy
5562        //assert!(check_limit!(100000000u128, low, high) == LimitThresholdCrossed::None);
5563        // This wont compile because lossy
5564        //assert!(check_limit!(100000000usize, low, high) == LimitThresholdCrossed::None);
5565
5566        assert!(matches!(
5567            check_limit!(2550000u64, low, high),
5568            LimitThresholdCrossed::Hard(2550000, 10000)
5569        ));
5570
5571        assert!(matches!(
5572            check_limit!(2550000u64, high, high),
5573            LimitThresholdCrossed::Hard(2550000, 10000)
5574        ));
5575
5576        assert!(matches!(
5577            check_limit!(1u8, high),
5578            LimitThresholdCrossed::None
5579        ));
5580
5581        assert!(check_limit!(255u16, high) == LimitThresholdCrossed::None);
5582
5583        assert!(matches!(
5584            check_limit!(2550000u64, high),
5585            LimitThresholdCrossed::Hard(2550000, 10000)
5586        ));
5587    }
5588
5589    #[test]
5590    fn linkage_amendments_load() {
5591        let mainnet = LazyLock::force(&MAINNET_LINKAGE_AMENDMENTS);
5592        let testnet = LazyLock::force(&TESTNET_LINKAGE_AMENDMENTS);
5593        assert!(!mainnet.is_empty(), "mainnet amendments must not be empty");
5594        assert!(!testnet.is_empty(), "testnet amendments must not be empty");
5595    }
5596
5597    #[test]
5598    fn render_scalar_fields_use_precision_safe_encoding() {
5599        use mysten_common::rpc_format::Unmetered;
5600
5601        let config = ProtocolConfig::get_for_max_version_UNSAFE();
5602        let rendered = config
5603            .render::<serde_json::Value>(&mut Unmetered)
5604            .expect("render should succeed");
5605
5606        let max_args = rendered
5607            .get("max_arguments")
5608            .expect("max_arguments set at max version");
5609        assert!(
5610            max_args.is_number(),
5611            "u32 should render as number, got {max_args:?}",
5612        );
5613
5614        let max_tx_size = rendered
5615            .get("max_tx_size_bytes")
5616            .expect("max_tx_size_bytes set at max version");
5617        assert!(
5618            max_tx_size.is_string(),
5619            "u64 should render as string, got {max_tx_size:?}",
5620        );
5621    }
5622
5623    #[test]
5624    fn render_includes_non_scalar_gasless_allowlist_as_json() {
5625        use mysten_common::rpc_format::Unmetered;
5626        use serde_json::json;
5627
5628        let mut config = ProtocolConfig::get_for_max_version_UNSAFE();
5629        config.set_gasless_allowed_token_types_for_testing(vec![
5630            ("0xa::usdc::USDC".to_string(), 10_000),
5631            ("0xb::usdt::USDT".to_string(), 0),
5632        ]);
5633
5634        let rendered = config
5635            .render::<serde_json::Value>(&mut Unmetered)
5636            .expect("render should succeed under Unmetered budget");
5637        let allowlist = rendered
5638            .get("gasless_allowed_token_types")
5639            .expect("entry should be present after the testing setter");
5640
5641        // u64 values render as strings to preserve JS precision; the tuple becomes a 2-element
5642        // JSON array.
5643        assert_eq!(
5644            allowlist,
5645            &json!([["0xa::usdc::USDC", "10000"], ["0xb::usdt::USDT", "0"],]),
5646        );
5647    }
5648
5649    #[test]
5650    fn render_targets_prost_value_for_grpc() {
5651        use mysten_common::rpc_format::Unmetered;
5652        use prost_types::value::Kind;
5653
5654        let mut config = ProtocolConfig::get_for_max_version_UNSAFE();
5655        config.set_gasless_allowed_token_types_for_testing(vec![(
5656            "0xa::usdc::USDC".to_string(),
5657            10_000,
5658        )]);
5659
5660        let rendered = config
5661            .render::<prost_types::Value>(&mut Unmetered)
5662            .expect("render to prost Value should succeed");
5663        let allowlist = rendered
5664            .get("gasless_allowed_token_types")
5665            .expect("entry should be present after the testing setter");
5666
5667        // Outer ListValue with one inner ListValue carrying [coin_type_string, amount_string].
5668        let Some(Kind::ListValue(outer)) = &allowlist.kind else {
5669            panic!(
5670                "expected ListValue at the top level, got {:?}",
5671                allowlist.kind
5672            );
5673        };
5674        assert_eq!(outer.values.len(), 1, "one allowlisted entry");
5675        let Some(Kind::ListValue(entry)) = &outer.values[0].kind else {
5676            panic!("expected each entry to be a ListValue");
5677        };
5678        assert_eq!(entry.values.len(), 2, "entry has (coin_type, amount)");
5679
5680        let Some(Kind::StringValue(coin_type)) = &entry.values[0].kind else {
5681            panic!("expected coin_type as StringValue");
5682        };
5683        assert_eq!(coin_type, "0xa::usdc::USDC");
5684
5685        // u64 amount renders as a string, not a NumberValue — this is the precision-safe path.
5686        let Some(Kind::StringValue(amount)) = &entry.values[1].kind else {
5687            panic!(
5688                "expected minimum_transfer_amount as StringValue (precision-safe u64); got {:?}",
5689                entry.values[1].kind,
5690            );
5691        };
5692        assert_eq!(amount, "10000");
5693    }
5694
5695    #[test]
5696    fn render_emits_null_for_unset_protocol_versions() {
5697        use mysten_common::rpc_format::Unmetered;
5698
5699        let config = ProtocolConfig::get_for_version(1.into(), Chain::Unknown);
5700        let rendered = config
5701            .render::<serde_json::Value>(&mut Unmetered)
5702            .expect("render should succeed");
5703        // The gasless allowlist key is present in every version's keyset, but renders as JSON
5704        // `null` for versions that predate the feature. This keeps the keyset stable across
5705        // protocol versions so clients can distinguish "unknown key" from "present but unset".
5706        let entry = rendered
5707            .get("gasless_allowed_token_types")
5708            .expect("key should be present for every protocol version");
5709        assert!(
5710            entry.is_null(),
5711            "value should be null for pre-feature protocol version, got {entry:?}",
5712        );
5713    }
5714}