Skip to content

feat(solver_registry): timelocked two-step admin transfer (#385 #393 #395 #396) - #447

Open
techisigu wants to merge 2 commits into
stellar-vortex-protocol:mainfrom
techisigu:fix/385-393-395-396
Open

techisigu wants to merge 2 commits into
stellar-vortex-protocol:mainfrom
techisigu:fix/385-393-395-396

Conversation

@techisigu

Copy link
Copy Markdown

solver_registry: timelocked two-step admin transfer (#393)

This PR delivers one acceptance-criteria item from #393. #385, #395 and #396 are referenced so that they close with this PR, but nothing from them is implemented here.

#393 Admin transfer, pause, and bond-token safety for solver_registry

What existed: the registry had no way to change its admin at all. The address set in initialize was permanent.

Done (AC1):

  • propose_admin(new_admin): admin only. Stores (new_admin, eta) with eta = now + ADMIN_TIMELOCK_DELAY (48 h, matching intent_settlement) and emits admin_transfer_proposed(new_admin, eta). A new proposal replaces the pending one and resets the timer.
  • accept_admin(new_admin): two-step. It must be the proposed address (Unauthorized otherwise), runs only once now >= eta (AdminTimelockNotElapsed), and new_admin must sign, so the role can't be handed to an address nobody controls. Emits admin_transferred(old, new).
  • cancel_admin_transfer(): admin only. NoPendingAdminTransfer if nothing is pending. Emits admin_transfer_cancelled.
  • get_pending_admin() -> Option<(Address, u64)>.
  • New errors AdminTimelockNotElapsed = 16 and NoPendingAdminTransfer = 17. Codes 13–15 are claimed by open PRs feat(solver_registry): exactly-once settlement writes per intent (#387 #388 #390 #391) #445 and feat(solver_registry): timelocked writer rotation (#380 #384 #386 #389) #446 (and feat(solver_registry): timelocked writer rotation (#380 #384 #386 #389) #446 uses the name TimelockNotElapsed), so both the codes and the names were chosen not to collide on merge.
  • docs/solver-registry-interface.md admin table and error table updated.
  • 6 new tests:
    • handover waits for the timelock (1 s early rejected; exactly at the eta the new admin's signature is the one recorded, and later admin-only calls authenticate against the new admin);
    • wrong accepter rejected; accept without the new admin's signature rejected;
    • re-proposal replaces the old one and resets the timer; cancel;
    • propose/cancel require the current admin.

Not done in this PR:

  • pause with a guardian role for stake/register/writer calls, with exits kept open (AC2).
  • rescue_tokens excluding the bond token (AC3).
  • Events for those (AC4).

#385 Versioned v2 proof payload

Not done in this PR:

  • The v2 layout with params_hash and a 32-byte src_user, v1/v2 migration in the registry, and settlement params_hash verification.

#395 Batch tier and eligibility views

Not done in this PR:

  • Batch views, paginated list_solvers, settlement tier caching, and resource measurements.

#396 Permissionless, soulbound reputation badges

Not done in this PR:

  • sync_badge, removal or timelocking of admin mint/burn, and the badge_of / tier_since / history reads with badge_changed events.

Verification

In solver_registry:

  • cargo test: 29 passed, 0 failed (23 existing + 6 new).
  • cargo fmt --check: no findings on lines this PR adds. main already has fmt drift in these files, left untouched.
  • cargo clippy --all-targets -- -D warnings: fails on main with current stable clippy (manual_range_contains in set_tier_threshold, pre-existing). There are no findings on lines this PR adds.

Closes #385
Closes #393
Closes #395
Closes #396

@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@techisigu Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment