Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions agent/invariants/00_INDEX.md
Original file line number Diff line number Diff line change
Expand Up @@ -96,8 +96,7 @@ item in code before you rely on it.
lifecycle snapshot, not in the event log. — `03_ACTOR_RUNTIME.md` §Durability, persistence, replay
- Circuit artifacts: a node installs a downloaded archive without `checksums.json`. —
`02_CRYPTO_CIRCUITS.md` §Noir / Barretenberg compatibility
- Deployment and CLI: `deployInterfold.ts` sends one setter without waiting for its receipt, and the
CLI accepts secrets on argv. — `04_BUILD_CONFIG.md`
- CLI: the CLI accepts secrets on argv. — `04_BUILD_CONFIG.md`
- CLI `activate` calls `register` and reverts for registered operators. —
`crates/cli/src/ciphernode/lifecycle.rs`
- EventBus fan-out waits for each subscriber to accept the event within a timeout, but a timeout is
Expand Down
29 changes: 17 additions & 12 deletions agent/invariants/04_BUILD_CONFIG.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,19 +62,24 @@ every section.
(`crates/cli/src/password.rs`, `crates/cli/src/wallet.rs`), and `deploy/local/nodes.sh` uses them.
— `flow-trace/00`, `01`
- **Deployment writes must be mined, not only sent.** Every configuration transaction in
`scripts/deployInterfold.ts` goes through the `send()` helper in `scripts/utils.ts`, which awaits
the receipt and fails on a missing receipt or a non-success status. `send()` also labels a
rejection from the send or the mining stage and keeps the original error as its `cause`. A bare
`await contract.setX(...)` resolves when the transaction is dispatched, not when it is mined.
**Gap:** `deployInterfold.ts` still sends `interfoldTicketToken.setRegistry(...)` with a bare
`await`, and several other writes call `.wait()` directly instead of `send()`.
`scripts/deployInterfold.ts` and `scripts/configureLocalSlashingPolicies.ts` goes through the
`send()` helper in `scripts/utils.ts`, which awaits the receipt and fails on a missing receipt or
a non-success status. `send()` also labels a rejection from the send or the mining stage and keeps
the original error as its `cause`. A bare `await contract.setX(...)` resolves when the transaction
is dispatched, not when it is mined.
- **A deployment must end with a verified wiring graph.** After configuration, `deployInterfold.ts`
reads back every cross-contract reference (Interfold, CiphernodeRegistry, BondingRegistry,
InterfoldTicketToken, SlashingManager, E3RefundManager, FOLD as the BondingRegistry ciphernode
bond token) plus the BondingRegistry reward-distributor authorization for Interfold, and throws
with the full list of mismatches. Add a read-back for each new cross-contract setter and each
initializer reference. **Gap:** the check does not read back the references that `E3RefundManager`
receives in its initializer.
reads back every reference that it sets to another contract, a token, a treasury, or the FOLD
claim source (constructor and initializer arguments and setter values, including the BFV verifier
bindings and, with ZK verification, the BFV wrappers' circuit verifiers), and every authorization
that it grants (the BondingRegistry reward distributor, the FOLD transfer whitelist, the initial
E3 program, the fee-token admission). It throws with the full list of mismatches before it enables
requests. Owners and admins (the deployer) and configuration values (committee thresholds,
parameter sets, slash policies, the node release, timing and pricing amounts) are not references;
the integration check in `tests/integration/base.sh` covers the committee thresholds. Add a
read-back for each new reference or authorization. **Gap:** the check does not read the ERC-1967
implementation and admin slots of the proxies. A fresh deployment passes each new implementation
to the proxy constructor in the same `deployAndSave` helper, but a proxy that a helper reuses from
the deployment record, or that its admin upgraded later, is not checked.
- **A deployment must also enable bonded voting.** `protocol/deployContracts` deploys
`BondedCheckpoints` (bound to the BondingRegistry **proxy**, not the implementation) and the
governance batch calls `setBondedCheckpoints` after `initialize`. `BondedVotes` comes later, from
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ import {
DKG_PROOF_TYPES,
slashReasonForProofType,
} from "./protocol/slashPolicies";
import { getDeploymentChain, readDeploymentArgs } from "./utils";
import { getDeploymentChain, readDeploymentArgs, send } from "./utils";

/** `IInterfold.FailureReason.InsufficientCommitteeMembers` */
const FAILURE_REASON_INSUFFICIENT_COMMITTEE_MEMBERS = 2;
Expand Down Expand Up @@ -69,27 +69,31 @@ export async function configureLocalSlashingPolicies(

for (const proofType of DKG_PROOF_TYPES) {
const reason = slashReasonForProofType(proofType);
const tx = await contract.setSlashPolicy(
reason,
localAttestationSlashPolicy(
ethers,
FAILURE_REASON_INSUFFICIENT_COMMITTEE_MEMBERS,
await send(
contract.setSlashPolicy(
reason,
localAttestationSlashPolicy(
ethers,
FAILURE_REASON_INSUFFICIENT_COMMITTEE_MEMBERS,
),
),
`slashingManager.setSlashPolicy(${reason})`,
);
await tx.wait();
console.log(` proofType ${proofType} (DKG) -> ${reason}`);
}

for (const proofType of DECRYPTION_PROOF_TYPES) {
const reason = slashReasonForProofType(proofType);
const tx = await contract.setSlashPolicy(
reason,
localAttestationSlashPolicy(
ethers,
FAILURE_REASON_INSUFFICIENT_COMMITTEE_MEMBERS,
await send(
contract.setSlashPolicy(
reason,
localAttestationSlashPolicy(
ethers,
FAILURE_REASON_INSUFFICIENT_COMMITTEE_MEMBERS,
),
),
`slashingManager.setSlashPolicy(${reason})`,
);
await tx.wait();
console.log(` proofType ${proofType} (decryption) -> ${reason}`);
}

Expand Down
Loading
Loading