Repository navigation
Conversation
hanzel98
force-pushed
the
feat/metaswap-flexible-settlement-enforcer
branch
5 times, most recently
from
September 3, 2026 13:52
ff660b3 to
7995fa6
Compare
hanzel98
force-pushed
the
feat/metaswap-flexible-settlement-enforcer
branch
2 times, most recently
from
September 25, 2026 03:05
6ac8476 to
4049a6b
Compare
Authorize one open-route MetaSwap settlement with exact input constraints, signed approval flexibility, minimum output, and atomic one-shot consumption.
Fold RedeemerEnforcer, TimestampEnforcer, IdEnforcer, and ERC20/Native balance-change semantics into MetaSwapFlexibleSettlementEnforcer so one MetaSwap-router caveat can settle native or ERC-20 swaps (optional approval) with an allowlisted redeemer. Timestamp bounds of zero disable time checks; id zero keeps hash-based one-shot consumption while a non-zero id uses the per-delegator bitmap for mutual exclusion.
hanzel98
force-pushed
the
feat/metaswap-flexible-settlement-enforcer
branch
from
September 25, 2026 03:39
e40716c to
1455eac
Compare
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
MetaSwapFlexibleSettlementEnforcer: MetaSwap-router caveat for one native/ERC-20 swap (optional approve / reset-approve).ApprovalModepins the batch shape; routeaggregatorId/datastay redeemer-selected.Combined behavior
MetaSwap.swap± approval legs (BATCH_DEFAULT_MODE)tokenOutMin(tokenOut == address(0)→ native)0disables a bound (non-inclusive, likeTimestampEnforcer)0→ hash one-shot(manager, delegationHash); non-zero → bitmap(manager, delegator, id)+ mutual exclusion (hash flag skipped — same id already blocks replay)Native input requires
None; ERC-20 requiresSkipApproval/Approve/ResetApprove. Failed fills roll back one-shot state.Terms
Approve spender / swap token words must be canonical ABI addresses. Swap calldata ≥ 196 bytes.
Security
Trust MetaSwap, adapters, and redeemer-chosen routes. Min output can be met by any balance increase. Residual allowance may remain. Input ≠ output.
Deployment
script/DeployCaveatEnforcers.s.sol· verify viascript/verification/verify-enforcer-contracts.shTest plan
Note
Medium Risk
New settlement path touches approvals, swaps, and balance-based min-output checks with unrestricted routes and known gaming vectors (any balance increase counts); extensive tests mitigate but delegators must understand trust assumptions.
Overview
Adds
MetaSwapFlexibleSettlementEnforcer, a single caveat that authorizes one MetaSwap-router settlement in batch default mode while folding several policies into packedterms.Signed terms pin the router, input amount, output recipient, minimum balance increase (ERC-20 or native when
tokenOut == address(0)), a required redeemer allowlist, and anApprovalModethat fixes batch shape: native-only swap, or ERC-20 swap with skip / approve / reset-approve legs. Swap validation checks target, value, selector, token word, and amount; routeaggregatorId/datastay redeemer-chosen.One-shot consumption is optional:
id == 0marks(delegationManager, delegationHash)inbeforeHook; non-zeroiduses an IdEnforcer-style bitmap per(manager, delegator)so replacement orders sharing an order id are mutually exclusive (hash flag skipped on that path). Optional timestamp bounds mirrorTimestampEnforcer.afterHookcompares recipient balance delta totokenOutMin; failed redemptions revert atomically so consumption state rolls back.Also wires CREATE2 deploy in
DeployCaveatEnforcers.s.sol, documents terms/trust assumptions inCaveatEnforcers.md(plus minor doc table formatting), and adds broad Foundry coverage including end-to-end redemption throughDelegationManager.Reviewed by Cursor Bugbot for commit 1455eac. Bugbot is set up for automated code reviews on this repo. Configure here.