test(vault): exercise sweep/pause/upgrade lifecycle against the admin cool-off (#1125) - #1343
Open
Sam-Rytech wants to merge 1 commit into
Open
Sam-Rytech wants to merge 1 commit into
Sam-Rytech wants to merge 1 commit into
Conversation
… cool-off (CalloraOrg#1125) Adds contracts/vault/src/test_timelock_cooldown.rs (compiled; selected by `cargo test -p callora-vault timelock`): - two matured proposals executed back-to-back in either order (sweep->pause, pause->sweep): the second fails with AdminCooldownActive, moves no funds and keeps its proposal, stays blocked 1s before the boundary, and succeeds exactly at it - execute_upgrade is refused by the same guard - get_last_critical_admin_action reports the right symbol and timestamp after each execution - a failed execution (InsufficientBalance) and the already-paused execute_pause no-op never arm the cool-off - cancel_sweep is idempotent: payload false with nothing pending, true when a proposal exists, false again on repeat; cancelling never arms the cool-off - cancel -> re-propose restarts the timelock and still respects the cool-off Also imports the testutils `Events` trait in test_value_conservation.rs. Without it the whole callora-vault test target failed to compile on main, so no vault test (including these) could run. Import only; no test logic changed. Closes CalloraOrg#1125
|
@Sam-Rytech Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
execute_pause,execute_upgradeandexecute_sweepshareadmin::guard, the only thing stopping an admin key from chaining pause + sweep + upgrade in one block once several proposals have matured. No running test covered back-to-back matured proposals or cancel/re-propose sequences. This PR adds that coverage from the public contract surface.New tests —
contracts/vault/src/test_timelock_cooldown.rsThe module is compiled under
#[cfg(test)]and named*timelock*, socargo test -p callora-vault timelockselects it.…sweep_then_pause_blocked_until_boundaryexecute_sweep, a matured pause fails withAdminCooldownActivein the same block. The vault stays unpaused and the proposal is kept. It is still blocked 1 s before the boundary (admin_cooldown_remaining == 1) and succeeds exactly at it.get_last_critical_admin_actionmoves fromsweeptopausewith correct timestamps.…pause_then_sweep_moves_no_funds_until_boundarysweep.…upgrade_path_is_guarded_tooexecute_upgradeafter a pause is refused by the same guard, which runs before the WASM swap.…failed_execution_does_not_arm_cooldownInsufficientBalanceleavesget_last_critical_admin_action == None, and another action can run immediately.…execute_pause_on_already_paused_vault_does_not_arm_cooldown…cancel_sweep_is_idempotent_with_is_some_payloadcancel_sweepwith nothing pending emitsfalse; with a proposaltrue; repeatedfalse. Cancelling never arms the cool-off, and executing afterwards givesProposalNotFound.…cancel_and_repropose_restarts_timelock_and_respects_cooldownexecute_after(the old deadline now givesTimelockNotExpired), and a matured re-proposal is still blocked by an active cool-off until its boundary.Acceptance criteria → tests
AdminCooldownActiveget_last_critical_admin_actionreports the right symbolNoneafter failed and no-op executionscancel_sweepwith nothing pending emits afalsepayload…cancel_sweep_is_idempotent_with_is_some_payloadRequired one-line fix
test_value_conservation.rscalledenv.events().all()without importing thesoroban_sdk::testutils::Eventstrait. That made the entirecallora-vaulttest target fail to compile onmain, so no vault test could run, including the issue's validation command. This PR adds that import and changes no test logic.Validation
rustfmt --checkpasses on the new file.Note for maintainers
Now that the test target compiles again, the full
cargo test -p callora-vaultshows 2 pre-existing failures intest_value_conservation(*_without_settlement_returns_error_before_mutation). They were hidden by the compile error and are unrelated to the admin cool-off, so they are left for a separate fix.Closes #1125