Solidity sources for the EVM network driver (Approach 2), built with Foundry.
src/StateDelta.sol — the FROZEN StateDelta/OutputToken structs. Field names, types, and order
mirror the Go types (../statedelta) and the EIP-712 type (../eip712) byte-for-byte; do not
reorder or retype without a re-freeze.src/EIP712.sol — domain separator, type hashes, hashStruct, digest. Byte-for-byte mirror of the
Go eip712 package.src/EndorsementVerifier.sol — the authorized endorser set + threshold; verifies a quorum of
EIP-712 signatures over a digest (ecrecover, low-s, v ∈ {27,28}, signer uniqueness, strict
all-provided-valid semantics).src/TokenState.sol - stores token state and applies endorsed StateDeltas: verifies signatures,
checks the public-parameters version, enforces spent/existence per the graphHiding flag, then
applies the transition. Deployed per TMS as an EIP-1167 clone; the shared implementation is locked.src/Clones.sol - minimal EIP-1167 proxy deployment for the per-TMS TokenState clones.script/Deploy.s.sol - deploys the verifier, the TokenState implementation, and an initialized
clone for one TMS (endorsers, threshold, PP v0, and graphHiding come from the environment). This is
the admin bootstrap the NWO topology automates.test/statedelta_digest_fixture.json carries two golden vectors produced by the Go side and
independently validated against ethers v6 (test/eip712_check.js):
stateDelta — transfer-shaped (non-empty arrays), digest 0xc9326b72…setupDelta — PP-update-shaped (empty arrays, isSetup, setupParameters), digest 0xdca9a011…test/EIP712.t.sol asserts the Solidity library reproduces every expected value. Go, ethers, and
Solidity agreeing on both shapes is the gate everything else builds on. If you change any frozen
type, the fixture must be regenerated by the Go side, re-validated against ethers, and this suite
re-run — never edit expected values by hand.
# one-time: fetch forge-std (vendored as a git submodule, pinned by foundry.lock)
git submodule update --init --recursive
forge build
forge test
forge fmt --check
# optional: independent ethers validation of the fixture
npm install ethers@6 && node test/eip712_check.js test/statedelta_digest_fixture.json
Nothing in the Go driver may link go-ethereum (license; enforced by ../depguard_test.go). Tooling
here (forge/anvil) is for contract build and test only, never linked into the driver binary.