Skip to content

js: Use UTF-8 byte length for metadata string prefixes - #859

Merged
joncinque merged 1 commit into
solana-program:mainfrom
ara-stock:js-metadata-utf8-length
Oct 9, 2026
Merged

joncinque merged 1 commit into
solana-program:mainfrom
ara-stock:js-metadata-utf8-length

Conversation

@ara-stock

Copy link
Copy Markdown
Contributor

Problem

updateTokenMetadataInstruction in clients/js writes each borsh string length prefix using the JavaScript string length (UTF-16 code units) but then appends the UTF-8 bytes from TextEncoder. For any name, symbol or URI containing non-ASCII characters (e.g. é, ☀, emoji), the prefix is shorter than the actual byte length, so the program misreads the instruction data. With the name Café Staking ☀ the program reads a garbage length for the next field and aborts:

Error: memory allocation failed, out of memory
Program SVSPxpvHdN29nkVg9rPapPNDddN5DipNLRUFhyjFThE failed: SBF program panicked

This affects both @solana/spl-single-pool and @solana/spl-single-pool-classic, since the legacy client calls the same builder. The Rust update_token_metadata builder uses borsh and is not affected.

Summary of Changes

  • Encode name, symbol and URI to UTF-8 first and use the encoded byte lengths as the length prefixes. Output is unchanged for ASCII-only strings.
  • Add a js-legacy test that updates metadata with a non-ASCII name and symbol and checks both end up in the metadata account. It fails on main with the panic above and passes with this change.

I used an AI assistant (Claude) while preparing this. I reproduced the issue and checked the fix and tests myself.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joncinque

Copy link
Copy Markdown
Contributor

Thanks for finding and fixing this!

@joncinque
joncinque merged commit 46b23a4 into solana-program:main Oct 9, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants