Description:
Settlement calls the proof registry, the solver registry, and token contracts, and will soon call an oracle, a policy contract, and hooks. When one of them traps or is paused, is that failure swallowed (fail-open) or propagated (fail-closed)? Nothing currently defines this. Write a policy table and implement it consistently, using try_ invocations where fail-open is chosen.
Problem Statement & Context:
An inconsistent failure policy creates both DoS vectors (a paused registry blocks all fills) and safety holes (a trapping oracle skips the check). Auditors will ask for this table.
Scope & Acceptance Criteria:
- A policy table in
docs/ listing each call site, its dependency, the chosen policy, and the rationale.
- Implementation, using
env.try_invoke_contract for fail-open sites with event emission.
- Tests that make each dependency trap or pause and assert the chosen behaviour.
- Out of scope: new dependencies.
Implementation Guidelines:
- Key Files/Modules:
intent_settlement/src/lib.rs, a new docs/dependency-failure-policy.md.
- Design/Architecture: Make slashing fail-open with respect to the registry, so a registry failure can't prevent a slash. Make proof verification fail-closed.
- Edge Cases/Constraints: A
try_ call still consumes budget, and a trapping token transfer can't be made fail-open safely.
- Testing: A trap-injection mock for each dependency.
Definition of "Done":
- Doc plus implementation plus tests.
- Reviewed and approved.
Resources:
Complexity: High (200 points)
Description:
Settlement calls the proof registry, the solver registry, and token contracts, and will soon call an oracle, a policy contract, and hooks. When one of them traps or is paused, is that failure swallowed (fail-open) or propagated (fail-closed)? Nothing currently defines this. Write a policy table and implement it consistently, using
try_invocations where fail-open is chosen.Problem Statement & Context:
An inconsistent failure policy creates both DoS vectors (a paused registry blocks all fills) and safety holes (a trapping oracle skips the check). Auditors will ask for this table.
Scope & Acceptance Criteria:
docs/listing each call site, its dependency, the chosen policy, and the rationale.env.try_invoke_contractfor fail-open sites with event emission.Implementation Guidelines:
intent_settlement/src/lib.rs, a newdocs/dependency-failure-policy.md.try_call still consumes budget, and a trapping token transfer can't be made fail-open safely.Definition of "Done":
Resources:
accept_intentandslash_solver#197Complexity: High (200 points)