Skip to content

fix(contracts): confirm every local deploy write and the refund manager - #2136

Merged
hmzakhalid merged 6 commits into
mainfrom
fix/local-deploy-wiring-checks
Oct 3, 2026
Merged

hmzakhalid merged 6 commits into
mainfrom
fix/local-deploy-wiring-checks

Conversation

@hmzakhalid

@hmzakhalid hmzakhalid commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

What

Fixes the #2068 items "setRegistry on the ticket token is not awaited" and "The local deployment's wiring check skips the refund manager's references". PR 4 of the Stack 4 stack; base: PR 3.

  • Before: interfoldTicketToken.setRegistry(...) used a bare await, which resolves when the transaction is dispatched, not when it is mined. Fifteen other writes in deployInterfold.ts and two in configureLocalSlashingPolicies.ts called .wait() directly, so a failure did not name the write. The wiring check did not compare the E3RefundManager references or several others, so a mis-wired deployment could print Cross-contract wiring verified. and enable requests.
  • Now: every configuration write in deployInterfold.ts and configureLocalSlashingPolicies.ts goes through send(), which waits for the receipt, rejects a missing receipt or a failed status, and names the write. The wiring check also compares:
    • E3RefundManager.interfold() and treasury();
    • BondingRegistry.ticketToken() and slashedFundsTreasury(), the CiphernodeRegistry DKG fold-attestation verifier, and FOLD's BONDING_REGISTRY;
    • Interfold's feeToken() and its BFV decryption, public-key and ciphertext verifiers (the BFV wrappers with ENABLE_ZK_VERIFICATION, the mocks otherwise), and the ticket token's underlying();
    • on Sepolia, the faucet's fold() and feeToken();
    • the pricing protocol treasury, FOLD's CLAIM_SOURCE(), BondedVotes.votesSource(), and with ENABLE_ZK_VERIFICATION the BFV wrappers' circuitVerifier() and the decryption wrapper's ciphernodeRegistry();
    • the authorizations: the BondingRegistry reward distributor, the FOLD transfer whitelist (BondingRegistry, and the faucet on Sepolia), the initial E3 program, and the fee-token admission.
  • agent/invariants/04_BUILD_CONFIG.md states the rule (every reference and authorization that the script sets is read back before requests are enabled) and one gap: the proxies' ERC-1967 implementation and admin slots are not read. It and 00_INDEX.md no longer list the two old gaps.

Verification

No unit test can tell send() from .wait() on an auto-mining node; the deploy runs in CI's integration jobs. On the test host, against a private anvil:

  • clean mock, ZK and Sepolia-branch deployments pass the wiring check;
  • each injected fault now stops the deploy with the named entry before requests are enabled, while the same fault on main ends with Cross-contract wiring verified.: a wrong E3RefundManager or slashed-funds treasury, the mock public-key verifier on the ZK path, the ticket token as Interfold's fee token, the faucet's FOLD set to the fee token on the Sepolia branch, a wrong pricing treasury, a wrong claim source, a missing BondingRegistry whitelist, and a revoked fee-token admission. The Codex review re-ran its own fault set (also the BFV wrapper links and the votes source) on mock, ZK and Sepolia paths.

Checklist

  • Verified — the runs above; the full local flow (committee:new with each parameter set) on the stack top; tsc --noEmit -p packages/interfold-contracts; prettier.
  • Harness docs — agent/invariants/04_BUILD_CONFIG.md, agent/invariants/00_INDEX.md.
  • Invariants — one invariant-reviewer pass: no High or Medium finding. One Low (the 04 entry said "every cross-contract reference" while four were not read back) is fixed here.
  • Breaking? — no. Rollout class — none (local deploy script).
  • Review — Claude and Codex (gpt-6-astra, max) reviewed on their own and checked each other's findings with tests. Codex found no defect in the first round; its repro scripts covered a delayed receipt, failures at mining time, and refund-manager mis-wiring. Both agreed on two Low items, both fixed here over four rounds: references that the check did not read back (the first four from the Claude side; the fee token, verifiers, faucet, pricing treasury, claim source, votes source, BFV wrapper links and authorizations from Codex), and the 04 text that claimed full coverage. Each fix was checked with fault injection, and Codex confirmed that removing a read-back makes its regression fail. No committed test covers the wiring faults, because the script runs only against a node; CI's integration jobs run the clean deploy (tests/integration/base.sh).

Summary by CodeRabbit

  • Bug Fixes
    • Deployment and slashing-policy updates now wait for transaction confirmation and stop if a transaction fails.
    • Deployment checks now cover additional contract connections and permissions, reporting configuration mismatches and preventing deployment from continuing when checks fail.
    • The known-issues list no longer includes the deployment transaction confirmation issue; the CLI secrets issue remains listed.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (3)
agent/RULES.md — configured
agent/CONTEXT.md — configured
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: theinterfold/interfold/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 19bf2f3e-0ea0-4ed6-bbe6-cf379f6d7ff4
📥 Commits

Reviewing files that changed from the base of the PR and between b4f2c4f and f79055b.

📒 Files selected for processing (4)
  • agent/invariants/00_INDEX.md
  • agent/invariants/04_BUILD_CONFIG.md
  • packages/interfold-contracts/scripts/configureLocalSlashingPolicies.ts
  • packages/interfold-contracts/scripts/deployInterfold.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Deployment and slashing-policy scripts now submit configuration transactions through send(). Deployment verification checks additional contract references and authorization flags, including conditional checks for deployed faucet and BFV verifier contracts.

Changes

Deployment configuration

Layer / File(s) Summary
Await configuration transactions
agent/invariants/00_INDEX.md, agent/invariants/04_BUILD_CONFIG.md, packages/interfold-contracts/scripts/configureLocalSlashingPolicies.ts, packages/interfold-contracts/scripts/deployInterfold.ts
Both slashing-policy loops and deployment configuration calls use send() with operation labels. The build-config requirements describe receipt-waiting behavior, and the open-issue list no longer includes the deployment setter/receipt concern.
Track deployed contracts and verifier targets
packages/interfold-contracts/scripts/deployInterfold.ts
The script retains faucet and BFV verifier references, sets expected verifier addresses, and uses send() for verifier and DKG attestation updates.
Verify deployment wiring and authorizations
agent/invariants/04_BUILD_CONFIG.md, packages/interfold-contracts/scripts/deployInterfold.ts
Wiring checks cover additional contract references and authorization flags. The script collects named mismatches and aborts before enabling requests.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Suggested reviewers: ctrlc03

Merge Risk: ⚪ Minimal · up to f7905

No actionable merge-blocking issue remains; merge after normal checks.

Architecture Summary

Architecture risk: 🟡 Medium · up to f7905

The change affects 2 systems.

Changed systems: packages/interfold-contracts, agent

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — packages/interfold-contracts (library) was modified; 2 changed files map to changed impact.
  • observed — agent (service) was modified; 2 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in agent/invariants/00_INDEX.md: The open-issue entry no longer includes the deployment setter/receipt concern; it retains the CLI argv-secrets concern.
  • observed — Modified behavior in agent/invariants/04_BUILD_CONFIG.md: The required send() path now applies to configuration transactions in both deployInterfold.ts and configureLocalSlashingPolicies.ts. The previous gaps noting a bare setRegistry send and direct .wait() calls are removed; the stated receipt, status, and error-cause behavior of send() remains.
  • observed — Modified behavior in agent/invariants/04_BUILD_CONFIG.md: The deployment read-back requirement expands from specified cross-contract references and one reward-distributor authorization to references set through constructor and initializer arguments or setters, including token, treasury, FOLD claim source, BFV verifier bindings, and conditional BFV wrapper circuit verifiers. It additionally checks BondingRegistry reward-distributor, FOLD transfer whitelist, initial E3 program, and fee-token admission authorizations, and throws with all mismatches before enabling requests. The text excludes owners/admins and configuration values, notes that committee thresholds are checked by the integration test, and retains the gap for unchecked ERC-1967 implementation/admin slots on reused or later-upgrad
  • observed — Modified behavior in packages/interfold-contracts/scripts/configureLocalSlashingPolicies.ts: The script now imports send from ./utils.

Reliability and maintainability

  • inferred — Risk-relevant change factors for packages/interfold-contracts: blast_radius_1; direct_dependents_1
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the receipt-confirmed deployment writes and names the refund manager wiring check, both central parts of the changes.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (2 skipped: 2 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

packages/interfold-contracts/scripts/configureLocalSlashingPolicies.ts

ESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.

packages/interfold-contracts/scripts/deployInterfold.ts

ESLint skipped: the matched ESLint configuration already failed (missing-dependency).


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
crisp Ready Ready Preview Oct 3, 2026 7:08pm UTC
interfold-dashboard Ready Ready Preview Oct 3, 2026 7:08pm UTC
interfold-docs Ready Ready Preview Oct 3, 2026 7:08pm UTC

Request Review

@hmzakhalid
hmzakhalid added this pull request to stack #2138 October 3, 2026 15:26
@hmzakhalid
hmzakhalid removed this pull request from stack #2138 October 3, 2026 15:56
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-wiring-checks branch from a53e04d to b9c7cd4 Compare October 3, 2026 16:30
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-committee-sizes branch from 9619942 to 06b23ab Compare October 3, 2026 16:30
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-wiring-checks branch from b9c7cd4 to 730e728 Compare October 3, 2026 16:46
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-committee-sizes branch from 06b23ab to 2f1c6a9 Compare October 3, 2026 16:46
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-wiring-checks branch from 6a02a9c to d08b0ca Compare October 3, 2026 17:38
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-committee-sizes branch from 2f1c6a9 to 1cd5ab0 Compare October 3, 2026 17:38
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-committee-sizes branch from 1cd5ab0 to 0c5088e Compare October 3, 2026 17:55
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-wiring-checks branch from d08b0ca to dc74d4b Compare October 3, 2026 17:55
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-wiring-checks branch from dc74d4b to 309f1f4 Compare October 3, 2026 18:49
@hmzakhalid
hmzakhalid force-pushed the fix/local-deploy-committee-sizes branch from 0c5088e to ef9b46d Compare October 3, 2026 18:49
deployInterfold.ts sent interfoldTicketToken.setRegistry with a bare
await, which resolves when the transaction is dispatched, not when it is
mined. Several other writes called .wait() directly, so a failure carried
no label. The wiring check also did not read back the references that
E3RefundManager receives in its initializer.

Every configuration write in deployInterfold.ts and
configureLocalSlashingPolicies.ts now goes through send(), which waits for
the receipt, rejects a missing receipt or a failed status, and names the
write. The wiring table reads back E3RefundManager.interfold() and
treasury(). With a deliberately wrong treasury, the local deployment now
stops with "e3RefundManager.treasury: expected <deployer>, got 0x...01".

agent/invariants/04_BUILD_CONFIG.md and 00_INDEX.md no longer list the two
gaps.

Refs #2068
The wiring check did not read back four references that the deploy sets:
BondingRegistry.ticketToken and slashedFundsTreasury, the
CiphernodeRegistry DKG fold-attestation verifier, and FOLD's
BONDING_REGISTRY. With the gap note removed, 04_BUILD_CONFIG.md said the
check covered every reference.

The table now reads all four, and the invariant names them. With the
BondingRegistry slashed-funds treasury deployed as address(1) on the test
host, the deploy stops with "bondingRegistry.slashedFundsTreasury:
expected <deployer>, got 0x...01"; before, it printed "Cross-contract
wiring verified."
…ring check

The wiring check did not compare Interfold's fee token, the ticket
token's underlying token, the final BFV decryption, public-key and
ciphertext verifiers, or the Sepolia faucet's FOLD and fee token. A ZK
deployment that registered the mock public-key verifier, or a deployment
with the wrong fee token, printed "Cross-contract wiring verified." and
enabled requests.

The check now reads all of them. The expected verifiers are the BFV
wrappers with ENABLE_ZK_VERIFICATION and the mocks otherwise; the
ciphertext verifier is always the mock. On the test host each fault now
stops the deploy with the named reference:
- ZK path with the mock PK verifier: "interfold.pkVerifiers(BFV)";
- the ticket token as the fee token: "interfold.feeToken";
- the Sepolia branch with the faucet's FOLD set to the fee token:
  "faucet.fold".
Clean mock, ZK and Sepolia deployments pass. 04_BUILD_CONFIG.md lists
every compared reference.
The wiring check still skipped references that the deploy sets: the
pricing protocol treasury, FOLD's claim source, BondedVotes' votes source
and, with ZK verification, the BFV wrappers' circuit verifiers and the
decryption wrapper's registry. It also checked one authorization only
(the reward distributor), not the FOLD transfer whitelist or the initial
E3 program registration.

The table now compares all of them, and an authorization list checks the
reward distributor, the FOLD transfer whitelist of the BondingRegistry
(and of the faucet on Sepolia), and the initial E3 program. Every row is
created where the table is built, so a failed read cannot surface early as
an unhandled rejection. 04_BUILD_CONFIG.md states the rule (every
reference and authorization that the script sets) instead of a list.

On the test host, clean mock, ZK and Sepolia deployments pass, and each
fault stops the deploy with the named entry: a wrong pricing treasury
("interfold.pricing.protocolTreasury"), a wrong claim source
("interfoldToken.CLAIM_SOURCE"), and a missing BondingRegistry
whitelist ("interfoldToken.transferWhitelist(bondingRegistry): not
granted").
The wiring rule covers references set through constructor arguments, but
the check does not compare a proxy's ERC-1967 implementation and admin
slots with the implementation that the deploy helper created. Each
deployAndSave helper deploys the implementation and passes it to the
proxy constructor in the same function, so only a helper bug can make
them disagree. State this as a gap instead of claiming full coverage.
setFeeAssetConfig admits the fee token (_feeTokenAllowed), but the wiring
check compared only feeToken(). A deployment whose fee token lost its
admission before verification printed "Cross-contract wiring verified."
and enabled requests that then failed with FeeTokenNotAllowed. The
authorization list now reads isFeeTokenAllowed(feeToken); with the
admission revoked on the test host, the deploy stops with
"interfold.isFeeTokenAllowed(feeToken): not granted".

The 04 gap note claimed that only a helper bug could make a proxy's
implementation slot disagree. That holds for fresh deployments only: a
helper can reuse a proxy from the deployment record, and its admin can
upgrade it later. The note now says so.
@hmzakhalid

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@hmzakhalid
hmzakhalid merged commit e2e5304 into main Oct 3, 2026
39 checks passed

This branch was successfully deployed

3 active deployments
Preview – interfold-docs — f79055b4 Deployed Oct 3, 2026 by vercel[bot]
Preview – interfold-dashboard — f79055b4 Deployed Oct 3, 2026 by vercel[bot]
Preview – crisp — f79055b4 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant