Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 42 additions & 0 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
FROM mcr.microsoft.com/devcontainers/rust:1.78

# Install system dependencies required by Stellar CLI and other tools
RUN apt-get update && apt-get install -y --no-install-recommends \
make \
pkg-config \
libssl-dev \
&& rm -rf /var/lib/apt/lists/*

# Install wasm32-unknown-unknown target
RUN rustup target add wasm32-unknown-unknown

# Install Stellar CLI with optimization features
# The --features opt flag enables additional tooling optimizations
RUN cargo install --locked stellar-cli --features opt

# Install cargo-audit for dependency vulnerability scanning
RUN cargo install --locked cargo-audit

# Install just for task running (alternative to make)
RUN cargo install --locked just

# Create setup script that runs on container creation
RUN echo '#!/bin/bash\n\
set -e\n\
echo "Vortex Contracts devcontainer setup..."\n\
\n\
# Verify toolchain versions\n\
echo "Rust version: $(rustc --version)"\n\
echo "Stellar CLI version: $(stellar --version 2>&1 || echo \"stellar command ready\")"\n\
\n\
# Pre-fetch dependencies to speed up first build\n\
echo "Pre-fetching cargo dependencies..."\n\
cd /workspaces/vortex-contracts && cargo fetch --locked 2>/dev/null || true\n\
\n\
echo "✓ Devcontainer setup complete"\n\
echo ""\n\
echo "Run \"make all\" or \"just all\" to build and test both contracts"\n\
' > /tmp/devcontainer-setup.sh && chmod +x /tmp/devcontainer-setup.sh

# Set working directory
WORKDIR /workspaces/vortex-contracts
35 changes: 35 additions & 0 deletions .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
{
"name": "Vortex Contracts",
"build": {
"dockerfile": "Dockerfile"
},
"features": {
"ghcr.io/devcontainers/features/github-cli:1": {}
},
"remoteUser": "vscode",
"customizations": {
"vscode": {
"extensions": [
"rust-lang.rust-analyzer",
"tamasfe.even-better-toml",
"serayuzgur.crates"
],
"settings": {
"rust-analyzer.checkOnSave.command": "clippy",
"rust-analyzer.checkOnSave.extraArgs": ["--all-targets", "--all-features"],
"[rust]": {
"editor.formatOnSave": true,
"editor.defaultFormatter": "rust-lang.rust-analyzer"
}
}
}
},
"onCreateCommand": "bash /tmp/devcontainer-setup.sh",
"forwardPorts": [],
"mounts": [
"source=${localEnv:HOME}${localEnv:USERPROFILE}/.cargo/registry,target=/usr/local/cargo/registry,type=volume"
],
"containerEnv": {
"RUST_BACKTRACE": "1"
}
}
35 changes: 35 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -291,6 +291,41 @@ jobs:
- name: Run mutation tests
run: cargo mutants --copy-target=false

view-calls-sync:
name: Check view-calls collection sync (Issue #290)
runs-on: ubuntu-latest
# Needs: contents: read (checkout only). This job just runs a shell script
# to verify the Postman collection is in sync with contract view functions.
# Inherits workflow-level minimum.
steps:
- uses: actions/checkout@v4
- name: Check Postman collection sync
run: scripts/check-view-calls-sync.sh
shell: bash

risk-aware-solver-bot-tests:
name: Test risk_aware_solver_bot.py (Issue #293)
runs-on: ubuntu-latest
# Needs: contents: read (checkout only). Pytest runs in-process, no network calls.
# Inherits workflow-level minimum.
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: "3.9"
- name: Install dependencies
run: pip install pytest pytest-cov
- name: Run pytest suite
run: pytest examples/tests/ -v --cov=examples --cov-report=term-missing
- name: Upload coverage
if: always()
uses: codecov/codecov-action@v3
with:
files: ./coverage.xml
flags: examples
fail_ci_if_error: false

coverage:
name: Code coverage
runs-on: ubuntu-latest
Expand Down
140 changes: 140 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,140 @@
name: Release

on:
push:
tags:
- 'v*'

permissions:
contents: write

jobs:
# Ensure CI checks pass before releasing
ci:
uses: ./.github/workflows/ci.yml
permissions:
contents: read

build-and-release:
name: Build release artifacts and publish
runs-on: ubuntu-latest
needs: ci
steps:
- uses: actions/checkout@v4

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@master
with:
toolchain: "1.78.0"
targets: wasm32-unknown-unknown

- uses: Swatinem/rust-cache@v2
with:
workspaces: intent_settlement,proof_registry

# Build intent_settlement release wasm
- name: Build intent_settlement release wasm
run: cd intent_settlement && cargo build --target wasm32-unknown-unknown --release

# Build proof_registry release wasm
- name: Build proof_registry release wasm
run: cd proof_registry && cargo build --target wasm32-unknown-unknown --release

# Compute checksums for both wasm binaries
- name: Compute checksums
run: |
set -e

# Paths to wasm binaries
INTENT_WASM="intent_settlement/target/wasm32-unknown-unknown/release/vortex_intent_settlement.wasm"
PROOF_WASM="proof_registry/target/wasm32-unknown-unknown/release/vortex_proof_registry.wasm"

# Compute SHA-256 for each
if command -v sha256sum &>/dev/null; then
SHA_CMD="sha256sum"
else
SHA_CMD="shasum -a 256"
fi

$SHA_CMD "$INTENT_WASM" | awk '{print $1}' > intent_settlement.wasm.sha256
$SHA_CMD "$PROOF_WASM" | awk '{print $1}' > proof_registry.wasm.sha256

# Create combined SHASUMS256.txt
echo "SHA256 checksums for release ${{ github.ref_name }}" > SHASUMS256.txt
echo "" >> SHASUMS256.txt
echo "intent_settlement.wasm:" >> SHASUMS256.txt
cat intent_settlement.wasm.sha256 >> SHASUMS256.txt
echo "" >> SHASUMS256.txt
echo "proof_registry.wasm:" >> SHASUMS256.txt
cat proof_registry.wasm.sha256 >> SHASUMS256.txt

# Display for verification
echo "=== Checksums ==="
cat SHASUMS256.txt

# Extract release notes from CHANGELOG.md
- name: Extract release notes
id: release_notes
run: |
# Extract version from tag (e.g., v1.2.3 -> 1.2.3)
VERSION="${{ github.ref_name }}"
VERSION="${VERSION#v}"

# Try to find and extract the section for this version from CHANGELOG.md
# Look for ## [VERSION] or ## version pattern
RELEASE_NOTES=$(awk "
/^## \[?$VERSION\]?/ {found=1; next}
found && /^## / {exit}
found {print}
" CHANGELOG.md | sed '/^$/d' | head -n -1)

if [ -z "$RELEASE_NOTES" ]; then
RELEASE_NOTES="See CHANGELOG.md for details about this release."
fi

# Use environment file to handle multiline content safely
{
echo 'RELEASE_NOTES<<EOF'
echo "$RELEASE_NOTES"
echo 'EOF'
} >> $GITHUB_ENV

# Create GitHub Release with artifacts
- name: Create GitHub Release
uses: softprops/action-gh-release@v1
with:
files: |
intent_settlement/target/wasm32-unknown-unknown/release/vortex_intent_settlement.wasm
proof_registry/target/wasm32-unknown-unknown/release/vortex_proof_registry.wasm
SHASUMS256.txt
body: ${{ env.RELEASE_NOTES }}
draft: false
prerelease: false
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

# Post checksums to job summary for verification
- name: Post verification summary
if: success()
run: |
cat >> $GITHUB_STEP_SUMMARY <<'EOF'
## Release Artifacts

✓ Successfully built and published release ${{ github.ref_name }}

### Artifacts
- `vortex_intent_settlement.wasm`
- `vortex_proof_registry.wasm`
- `SHASUMS256.txt`

### Verification
Download the `.wasm` files from the release and verify checksums:

```bash
# Download SHASUMS256.txt from the release
sha256sum -c SHASUMS256.txt
```

Both checksums should print `OK`. These signed artifacts are reproducible
and match the ones generated by `./verify-build.sh` run locally with Rust 1.78.0.
EOF
20 changes: 19 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,25 @@ the org-wide

## Toolchain Setup

### Rust
### Quick start via devcontainer (recommended for new contributors)

If you have [Docker](https://docs.docker.com/get-docker/) and [VS Code](https://code.visualstudio.com/) installed:

1. Install the [Dev Containers extension](https://marketplace.visualstudio.com/items?itemName=ms-vscode-remote.remote-containers) for VS Code
2. Clone this repository
3. Open it in VS Code, then run the **Dev Containers: Reopen in Container** command (Ctrl+Shift+P / Cmd+Shift+P)
4. VS Code will build the devcontainer and install all dependencies automatically
5. Once ready, run `make all` or `just all` in the terminal to verify the build

This approach ensures a reproducible setup matching the pinned Rust 1.78 toolchain used in CI, with zero manual configuration steps.

Alternatively, use GitHub Codespaces: click the green "Code" button → "Codespaces" tab → "Create codespace on main". The devcontainer will bootstrap automatically.

### Manual setup (Rust, wasm32 target, Stellar CLI, cargo-audit)

If you prefer not to use devcontainers, follow these steps manually:

#### Rust

Install Rust via [rustup](https://rustup.rs/):

Expand Down
20 changes: 20 additions & 0 deletions docs/mainnet-deployment-runbook.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,26 @@ deployment:
sha256sum target/wasm32-unknown-unknown/release/vortex_intent_settlement.wasm
```

### Alternative: Download from GitHub Release

For reproducible verification without rebuilding, download the verified `.wasm`
binary and `SHASUMS256.txt` from the [GitHub Release](https://github.com/stellar-vortex-protocol/vortex-contracts/releases)
corresponding to the version tag you're deploying:

```bash
# Download SHASUMS256.txt from the release
curl -L https://github.com/stellar-vortex-protocol/vortex-contracts/releases/download/v1.0.0/SHASUMS256.txt -o SHASUMS256.txt

# Download the wasm binary
curl -L https://github.com/stellar-vortex-protocol/vortex-contracts/releases/download/v1.0.0/vortex_intent_settlement.wasm -o vortex_intent_settlement.wasm

# Verify checksum
sha256sum -c SHASUMS256.txt
```

This binary is built deterministically using Rust 1.78.0 and can be independently
verified to match the source code at that tag — no local build required.

---

## Deploy the Contract
Expand Down
Binary file not shown.
Loading
Loading