Repository navigation
feat: timelock tiers, multisig custom account, zenith-common crate, vault escape hatch - #150
Merged
dami-005 merged 2 commits intoSep 29, 2026
Conversation
…ault escape hatch - multisig: per-class timelock (Emergency/Standard/Critical) via is_executable(action_id, class) with threshold_reached_at tracking; CustomAccountInterface::__check_auth for M-of-N ed25519 auth with an optional allowed-contracts policy - common: new zenith-common rlib with require_admin_or_multisig(Auth), pause and admin helpers; every admin fn is a single x_inner shared by both entrypoints; per-crate multisig contractimport clients removed - vault: cumulative-pause escape hatch (emergency_withdraw after max_pause_duration), tag owners and beneficiaries - CI: spec-diff ABI guard + wasm size report; README updated Closes Zenith-options#76 Closes Zenith-options#77 Closes Zenith-options#78 Closes Zenith-options#81
|
@knytcomics-ui Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…-governance-hardening # Conflicts: # .github/workflows/ci.yml # README.md # multisig/src/error.rs # multisig/src/lib.rs # multisig/src/test.rs # multisig/src/types.rs # options_market/src/lib.rs # options_market/src/storage.rs # options_market/src/test.rs # price_oracle/src/lib.rs # vault/src/error.rs # vault/src/events.rs # vault/src/lib.rs # vault/src/test.rs # vault/src/types.rs
dami-005
pushed a commit
that referenced
this pull request
Sep 30, 2026
…ion (#151) - multisig: restore source wiped in #150 (from #149, de-duplicated and made consistent on BytesN<32> action ids) - multisig: per-signer weights, initialize_weighted, get_approval_weight; legacy initialize keeps equal weights (#70) - multisig: propose/queue/veto/execute_signer_change with a higher rotation threshold, mandatory delay, single-signer veto, invariant re-validation and epoch-keyed approvals (#69) - lp_token: SEP-41 share token, mint restricted to the pinned lp_pool (#65) - lp_pool: epoch-queued deposits/withdrawals, keeper option writing within series and utilization caps, virtual-share inflation defence (#64) - CI matrices, README and docs updated Closes: #64 Closes: #65 Closes: #69 Closes: #70
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
threshold_reached_at(set when an approval crosses threshold, cleared on a revoke that drops below it or onreset; if an approval expires during the delay, the timer restarts).is_executable(action_id, class)enforces immutable per-class delays set atinitialize(Emergency= 0,Standard,Critical). Every consumer_via_multisigfn declares its class (pause = Emergency; upgrade/transfer_admin/vault fund moves = Critical; everything else = Standard). The delay table is in the README.__check_auth) #77 Custom account:CustomAccountInterface::__check_authon multisig. It requires M distinct ed25519 signer signatures, sorted strictly ascending (so duplicates, unsorted lists and non-signer keys are rejected), with an optionalallowed_contractspolicy. It works alongside approval mode; the README covers when to use which, plus a CLI signing walkthrough._via_multisigPattern with a Sharedzenith-commonCrate #78zenith-common: new rlib withrequire_admin_or_multisig(env, key, Auth, class, err),enum Auth { Admin, Multisig(..) }, and pause/admin helpers. It defines no#[contract]and exports no spec entries. All 21 twins are nowx_inner(env, Auth, ..)called from both entrypoints. Multisig is called withinvoke_contract, so the per-cratemultisig_client.rsfiles and the multisig wasm build-order dependency are gone.initialize(.., max_pause_duration)(immutable),PausedAtplus cumulative pause accounting (brief unpause/re-pause doesn't reset the clock; only a full unpaused window does), first depositor = tag owner,set_beneficiary(blocked while paused),emergency_withdraw(tag, beneficiary)and anemergency_withdrawnevent.Closes #76
Closes #77
Closes #78
Closes #81
ABI / wasm size (#78)
New CI job
spec-diff(tools/spec-diff/check.sh) diffs each contract's spec against the base branch:price_oracle,options_market: existing ABI preserved, no additions. Wasm 32218 → 30932 B and 62111 → 60261 B.multisig,vault: purely additive, except the intentionalinitializesignature changes (listed intools/spec-diff/allow.txt). Wasm 19291 → 30720 B and 25471 → 33623 B. This growth comes from the new [High] Timelocked Execution Tiers per Action Class #76, [High] Multisig as a Soroban Custom Account (__check_auth) #77 and [High] Beneficiary Escape Hatch After Prolonged Vault Pause #81 entrypoints, not the refactor.Validation
cargo fmt --checkandcargo clippy --all-targets -D warningspass on every crate.cargo testpasses: multisig 45, price_oracle 62, vault 48, options_market 110. The existing tests only needed the newinitializeargs.__check_authwith real ed25519 keys: duplicate, unsorted and non-signer signatures, and the policy.options_marketwithadmin = multisig accountperformsinitialize/set_fee_rate/pause/upgradethrough signed auth entries, with nomock_all_auths.