feat(creator-keys): emergency platform pause with 24h timelocked resume (#1000) - #1008
Open
solaawojobi00-bit wants to merge 5 commits into
Open
solaawojobi00-bit wants to merge 5 commits into
solaawojobi00-bit wants to merge 5 commits into
Conversation
…me (accesslayerorg#1000) Add an emergency_pause module letting the global-pause multisig halt all bonding-curve buys and sells in one transaction, resume only after a queued 24h timelock, and pause individual keys independently. Wire the guard into every buy and sell entrypoint, including batch paths.
… halt (accesslayerorg#1000) Move the platform pause event names and payloads into events.rs per the event conventions, and document the multisig platform halt in the emergency pause runbook and event conventions table.
…gency-platform-pause # Conflicts: # creator-keys/src/events.rs
|
@solaawojobi00-bit Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…gency-platform-pause # Conflicts: # creator-keys/src/lib.rs
…gency-platform-pause # Conflicts: # creator-keys/src/lib.rs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Emergency platform pause for a platform-wide trading halt
Problem
There was no way for the multisig admins to halt all bonding-curve trading in one transaction while keeping a deliberate, delayed path back to live trading. The existing #784
global_pause/global_resumetakes two separate transactions to activate, and resume has no delay. The per-keypause_with_expiryis time-boxed and belongs to the creator's own admin set, not the platform.pause_platformcall signed by 2+ adminsglobal_resumetakes effect as soon as the second vote landsresume_platformfails until 24h afterqueue_platform_resumeset_key_pause_overridewith no expiryplat_pau/plat_rescarryactor+timestampSolution
A new
emergency_pausemodule increator-keys, exposed through seven new contract functions:signers: Vec<Address>. It needs at leastGLOBAL_PAUSE_THRESHOLD(2) distinct members of the existing global-pause admin set (set_global_pause_admins), and each of them mustrequire_auth. Reusing that admin set means no new admin configuration.queue_platform_resumerecordsnow + 86_400s.resume_platformfails withTimelockNotElapseduntil that ledger timestamp is reached.assert_trading_allowed(env, key_id)returnsContractError::GlobalTradingHalted(the error trade paths already use for halts). It is placed first in every buy/sell entrypoint and per order in the batch paths.Changes
creator-keys/src/emergency_pause.rs(new)EmergencyPauseError: its own#[contracterror]enum (Unauthorized,InsufficientSigners,DuplicateSigner,AlreadyPaused,NotPaused,ResumeAlreadyQueued,ResumeNotQueued,TimelockNotElapsed,Overflow). It is separate so it adds no variants toContractError.EmergencyPauseDataKey { PlatformPaused, ResumeEta, KeyPaused(Address) }: new keys only.assert_multisigchecks threshold, membership and duplicates beforerequire_auth, so a repeated address is rejected cleanly rather than double-authorised.pause_platform,queue_platform_resume,resume_platform,set_key_pause_override, theis_platform_paused/is_key_paused/resume_etaviews, andassert_trading_allowed.creator-keys/src/lib.rspause_platform,queue_platform_resume,resume_platform,is_paused,get_platform_resume_eta,set_key_pause_override,is_key_paused.emergency_pause::assert_trading_allowed(&env, &creator)?added to:buy_keys_with_referrer(also coversbuy_keys) andbuy_key_with_referrer(also coversbuy_key)sell_keybatch_buy,batch_buy_v2andbatch_sellcreator-keys/src/events.rsplat_pau,plat_rq,plat_resandkey_paunames, payload structs,*_DATA_FIELDSfield-order constants and topic helpers, followingdocs/contract-event-conventions.md.Docs
docs/emergency-pause-runbook.md: new section 9 covering the multisig platform halt, the blocked entrypoints, the timelock and the override semantics.docs/contract-event-conventions.md: event table for the four new events.Regression Tests
creator-keys/src/test_issue_1000.rs: 13 tests.pause_platform_halts_buy_and_sell_on_all_keys(buy_key, buy_keys, sell_key, batch_buy, batch_sell, batch_buy_v2 across two keys)pause_platform_requires_every_signer_to_authorise,pause_platform_rejects_invalid_signer_sets,pause_platform_without_admin_set_is_unauthorized,pause_platform_twice_is_rejectedresume_platform_blocked_until_timelock_elapses(now,eta - 1,eta),resume_platform_requires_queue_and_multisigresume_platform_blocked_until_timelock_elapses(trading halted while paused, restored after resume on both keys)pause_platform_emits_event_with_timestamp_and_actor,resume_platform_emits_event_with_timestamp_and_actorkey_override_halts_only_that_key_while_platform_live,key_override_survives_platform_resume,clearing_key_override_does_not_bypass_platform_pause,key_override_requires_multisigTesting
All 225 test result lines across the workspace are
ok; 0FAILED.Checklist
creator-keystests for every changed behavior, including failure paths for each reachableEmergencyPauseErrorvariant andContractError::GlobalTradingHaltedcargo fmt --all -- --check,cargo clippy --workspace --all-targets -- -D warnings, andcargo test --workspaceEmergencyPauseDataKeyenum). No existing key or layout changes, so no migration needed; an unset flag reads as "not paused"docs/contract-event-conventions.md(lowercasesymbol_short!names inevents.rs, topic 0 = name, topic 1 = primary entity, documented field order); no existing event changedNotes for Reviewers
is_pausedvsget_is_paused: the issue asks foris_paused(), so that name reports this platform halt only. The legacy single-admin protocol pause is still reported byget_is_paused; the runbook calls this out.actorin events is the first entry insigners; every signer's auth is still required.buybackis not guarded. It is a creator repurchase from their own key rather than a user buy/sell. Happy to add the one-line guard if you want it covered too.batch_buy,batch_buy_v2andbatch_sellnever checked the older per-keypause_with_expirystate. The new guard (platform + override) is enforced per order there, but I left the older check untouched to stay in scope.global_pause/global_resumeflow is unchanged and still works alongside this one.Closes #1000