fix(vault): drop unimplemented capability bits, add entrypoint-mappin… - #1335
Merged
greatest0fallt1me merged 2 commits intoOct 1, 2026
Merged
greatest0fallt1me merged 2 commits into
greatest0fallt1me merged 2 commits into
Conversation
…g tests, update docs (CalloraOrg#1116) Resolves CalloraOrg#1116. The capability bitmap previously advertised six bits for features that have no vault entrypoint today: Bit 6 CAP_OFFERING_METADATA – no entrypoint Bit 7 CAP_PRICE_REGISTRY – no entrypoint Bit 12 CAP_REVENUE_POOL – no entrypoint Bit 13 CAP_RATE_LIMIT – no entrypoint Bit 14 CAP_ADMIN_BROADCAST – no entrypoint Bit 16 CAP_SLIPPAGE_GUARD – no entrypoint Changes: * capabilities.rs - Reserved-bit constants (CAP_OFFERING_METADATA, CAP_PRICE_REGISTRY, CAP_REVENUE_POOL, CAP_RATE_LIMIT, CAP_ADMIN_BROADCAST, CAP_SLIPPAGE_GUARD) are retained as named sentinels so their bit positions can never be accidentally reused, but ALL_CAPABILITIES no longer ORs them in. - ALL_CAPABILITIES is now 0x0000_0000_0002_8F3F, covering only the 12 bits (0-5, 8-11, 15, 17) that have callable vault entrypoints. - Updated all doc-comments to reflect reserved-and-cleared semantics. * test_capabilities.rs (new, 29 tests) - Asserts the exact hex mask (EXPECTED_EXACT_MASK = 0x0000_0000_0002_8F3F). - Asserts each of the 12 supported bits IS set. - Asserts each of the 6 reserved bits IS cleared. - every_set_capability_maps_to_callable_vault_entrypoint: calls the real client method for every set bit, proving no bit is orphaned. - reserved_bits_are_zero / all_reserved_bits_are_cleared_in_all_capabilities: double-check the reserved set is always 0 in ALL_CAPABILITIES. - bit_positions_are_stable: locks down all 18 constant hex values so accidental re-numbering is caught immediately. * lib.rs - Added mod test_capabilities; declaration so the new test module is compiled and run under cargo test. * test_value_conservation.rs - Added missing Events as _ import (unused-import warning fix). * docs/CAPABILITIES.md - Updated active mask from stale value to 0x0000_0000_0002_8F3F. - Marked bits 6, 7, 12, 13, 14, 16 as reserved (cleared) in the bit-registry table and TypeScript constant block. - Added Stability guarantee section documenting the reserved-bit contract. All 29 capability tests pass (cargo test -p callora-vault capabilities).
|
@Anadudev Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # contracts/vault/src/lib.rs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1116
Drop unimplemented features from vault capabilities
Summary
capabilities.rspreviously advertised six bits for features that haveno vault entrypoint today. Integrators that feature-detect via
capabilities()would receive1for a missing entrypoint, leading toruntime failures and eroding trust in the capability contract (bits must
be stable and truthful).
This PR audits every bit against
CalloraVault's public functions,clears bits for missing features (keeping their positions permanently
reserved so they are never reassigned), adds a comprehensive test suite
that maps every set bit to at least one existing client method, and
updates
docs/CAPABILITIES.mdto match.Affected modules
contracts/vault/src/capabilities.rsALL_CAPABILITIESconstantcontracts/vault/src/test_capabilities.rscontracts/vault/src/lib.rsmod test_capabilities;declarationcontracts/vault/src/test_value_conservation.rsEvents as _importdocs/CAPABILITIES.mdWhat changed and why
capabilities.rsThe six reserved-bit constants are kept as named sentinels so their
bit positions can never be accidentally reused in a future version:
ALL_CAPABILITIESnow ORs together only the 12 bits thatcorrespond to callable vault entrypoints:
All doc-comments on reserved constants explicitly state:
0incapabilities()test_capabilities.rs(new - 29 tests)capabilities_equals_exact_expected_mask,capabilities_equals_all_capabilities_constantcap_deposit_is_set,cap_withdraw_is_set, ...cap_upgrade_is_setcap_offering_metadata_is_cleared,cap_price_registry_is_cleared, ...cap_slippage_guard_is_clearedbit_positions_are_stable- locks every constant to its hex valueevery_set_capability_maps_to_callable_vault_entrypoint- calls the real client method for every set bitcapabilities_is_idempotent,capabilities_available_before_init,reserved_bits_are_zero,all_reserved_bits_are_cleared_in_all_capabilities,all_supported_bits_match_all_capabilities_decomposition,all_capabilities_bits_are_power_of_two_distinctlib.rsAdded the
#[cfg(test)] mod test_capabilities;declaration so the newmodule is compiled and exercised by
cargo test.docs/CAPABILITIES.md0x0000_0000_0002_8F3F.*(reserved)* - no entrypoint implementedwith statusreserved (cleared).// Reserved (cleared).Criteria mapping
every_set_capability_maps_to_callable_vault_entrypointtest;ALL_CAPABILITIESdefinitioncapabilities.rsdoc-comments;CAPABILITIES.mdbit-registry tabletest_capabilities.rscompiles and asserts the exact maskcapabilities_equals_exact_expected_mask+EXPECTED_EXACT_MASK = 0x0000_0000_0002_8F3FCAPABILITIES.mdmatches the mask0x28F3FSecurity and failure-mode analysis
ALL_CAPABILITIESwill immediately fail theall_reserved_bits_are_cleared_in_all_capabilitiestest.capabilities()is a pure view. It reads a compile-time constant; no state, auth, or external calls are involved. There is no surface for reentrancy, front-running, or access-control bypass.1for a reserved bit and attempted to call a non-existent entrypoint would already have encountered a runtime trap. Clearing the bit is strictly safer: a0tells integrators the feature is absent before they attempt the call.Test run
Non-goals