feat: lp pool, SEP-41 lp token, weighted multisig with governed rotation - #151
Merged
dami-005 merged 1 commit intoSep 30, 2026
Conversation
- multisig: restore source wiped in Zenith-options#150 (from Zenith-options#149, de-duplicated and made consistent on BytesN<32> action ids) - multisig: per-signer weights, initialize_weighted, get_approval_weight; legacy initialize keeps equal weights (Zenith-options#70) - multisig: propose/queue/veto/execute_signer_change with a higher rotation threshold, mandatory delay, single-signer veto, invariant re-validation and epoch-keyed approvals (Zenith-options#69) - lp_token: SEP-41 share token, mint restricted to the pinned lp_pool (Zenith-options#65) - lp_pool: epoch-queued deposits/withdrawals, keeper option writing within series and utilization caps, virtual-share inflation defence (Zenith-options#64) - CI matrices, README and docs updated Closes: Zenith-options#64 Closes: Zenith-options#65 Closes: Zenith-options#69 Closes: Zenith-options#70
|
@Coredevjay Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Map<Address, u32>andthresholdis a total weight. Newinitialize_weightedandget_approval_weight;is_approvedcompares weight against the threshold. The legacyinitializeis kept, with every signer at weight 1. Validation: every weight > 0, overflow-safe sums, threshold ≤ total weight. A single key that can reach quorum alone is allowed but emits asingle_key_quorumevent (documented policy).propose_signer_change→queue_signer_change→execute_signer_change, plusveto_signer_change. A change needsrotation_thresholdweight, which is always abovethresholdor equal to unanimity. After approval there is a mandatoryrotation_delay, and any single signer can veto until execution. At most one signer is added and one removed per change, and weights can change. Invariants are checked both at proposal and at execution. Approvals are keyed by signer epoch, so a rotation invalidates every outstanding vote in O(1). Events:signer_change_proposed,signer_change_vetoed,signers_rotated. The README rationale section is rewritten.lp_token: a full SEP-41token::Interfacewhosemintis restricted to the pinnedlp_pool. Standard events; balances live in persistent storage and allowances in temporary storage with a TTL up toexpiration_ledger. The conformance checklist is indocs/lp_token.md.lp_pool: deposits and withdrawals are queued per epoch. A keeper runswrite_optiononoptions_marketwithin per-series and utilization caps, andprocess_epochonly runs once every position has been reclaimed. Share price = (idle + locked − expected liabilities) / shares. First-depositor inflation is blocked by internal accounting, virtual shares and a minimum deposit. The strategy and risk doc is indocs/lp_pool.md.mainat f95d8d4 (#150) leftmultisig/src/{lib,types,test}.rs, all ofvault/src/{lib,types,events,error,test}.rs,options_market/src/lib.rsandtimelock/src/*empty. The multisig source from #149 was also internally inconsistent: it had duplicated fragments and mixedu64andBytesN<32>ids. This PR restores the multisig from #149, repaired and consistent onBytesN<32>ids, and builds the new features on top. The other gutted crates are out of scope and still fail CI. #150's multisig timelock tiers (is_executable) and__check_authwere never in the committed source, so they are still missing.zenith-common::is_executablehas nothing to call until they're rebuilt; the README now says so.lp_poolcallsoptions_marketthroughinvoke_contractagainst thewrite_option(writer, series_id, contracts, collateral_amount, min_premium) -> u64/reclaim_collateral(writer, position_id)ABI from #147, so it doesn't need that crate's wasm to build. It's tested against a mock market that uses real SAC token transfers, with only the keeper's auth mocked.Closes: #64
Closes: #65
Closes: #69
Closes: #70
Validation
multisig:cargo testpasses all 78 tests, 26 of them new.cargo clippy --all-targets -D warningsandcargo fmt --checkare clean, and the wasm release build succeeds.lp_token:cargo testpasses all 15 tests; clippy, fmt and the wasm build are clean.lp_pool:cargo testpasses all 14 tests; clippy, fmt and the wasm build are clean.