Skip to content

Fix SetOpSourceAccount silently ignoring invalid source account errors#5912

Merged
tamirms merged 1 commit intostellar:mainfrom
tamirms:fix-set-op-source-account-error-handling
Feb 24, 2026
Merged

Fix SetOpSourceAccount silently ignoring invalid source account errors#5912
tamirms merged 1 commit intostellar:mainfrom
tamirms:fix-set-op-source-account-error-handling

Conversation

@tamirms
Copy link
Contributor

@tamirms tamirms commented Feb 24, 2026

PR Checklist

PR Structure

  • This PR has reasonably narrow scope (if not, break it down into smaller PRs).
  • This PR avoids mixing refactoring changes with feature changes (split into two PRs
    otherwise).
  • This PR's title starts with name of package that is most changed in the PR, ex.
    services/friendbot, or all or doc if the changes are broad or impact many
    packages.

Thoroughness

  • This PR adds tests for the most critical parts of the new functionality or fixes.
  • I've updated any docs (developer docs, .md
    files, etc... affected by this change). Take a look in the docs folder for a given service,
    like this one.

Release planning

  • I've reviewed the changes in this PR and if I consider them worthwhile for being mentioned on release notes then I have updated the relevant CHANGELOG.md within the component folder structure. For example, if I changed horizon, then I updated (services/horizon/CHANGELOG.md. I add a new line item describing the change and reference to this PR. If I don't update a CHANGELOG, I acknowledge this PR's change may not be mentioned in future release notes.
  • I've decided if this PR requires a new major/minor version according to
    semver, or if it's mainly a patch change. The PR is targeted at the next
    release branch if it's not a patch change.

What

SetOpSourceAccount was discarding the error returned by MuxedAccount.SetAddress, which could produce a partially initialized MuxedAccount that panics on subsequent Address() calls. Return the error instead and check it in all 27 BuildXDR callers.

Known limitations

[N/A]

Copilot AI review requested due to automatic review settings February 24, 2026 21:41
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes txnbuild.SetOpSourceAccount silently discarding invalid muxed/G-address errors by returning an error from SetAddress and propagating it through all BuildXDR() call sites, preventing partially-initialized xdr.MuxedAccount values that can later panic.

Changes:

  • Change SetOpSourceAccount to return an error and wrap invalid address failures.
  • Update all affected BuildXDR() implementations to handle and return SetOpSourceAccount errors.

Reviewed changes

Copilot reviewed 28 out of 28 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
txnbuild/operation.go Make SetOpSourceAccount return errors instead of silently ignoring invalid source accounts.
txnbuild/account_merge.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/allow_trust.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/begin_sponsoring_future_reserves.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/bump_sequence.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/change_trust.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/claim_claimable_balance.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/clawback.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/clawback_claimable_balance.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/create_account.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/create_claimable_balance.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/create_passive_offer.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/end_sponsoring_future_reserves.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/extend_footprint_ttl.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/inflation.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/invoke_host_function.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/liquidity_pool_deposit.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/liquidity_pool_withdraw.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/manage_buy_offer.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/manage_data.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/manage_offer.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/path_payment.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/path_payment_strict_send.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/payment.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/restore_footprint.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/revoke_sponsorship.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/set_options.go Propagate SetOpSourceAccount error in BuildXDR().
txnbuild/set_trust_line_flags.go Propagate SetOpSourceAccount error in BuildXDR().

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

SetOpSourceAccount was discarding the error returned by
MuxedAccount.SetAddress, which could produce a partially initialized
MuxedAccount that panics on subsequent Address() calls. Return the
error instead and check it in all 27 BuildXDR callers.

This is a breaking change: SetOpSourceAccount now returns an error.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@tamirms tamirms force-pushed the fix-set-op-source-account-error-handling branch from 739aec6 to dcb6115 Compare February 24, 2026 22:06
@tamirms tamirms requested a review from Copilot February 24, 2026 22:06
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 30 out of 30 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@tamirms tamirms merged commit 8bc75d7 into stellar:main Feb 24, 2026
15 checks passed
@tamirms tamirms deleted the fix-set-op-source-account-error-handling branch February 24, 2026 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants