Repository navigation
feat(contracts): MCMS-governed LinkTokenAdmin for registry-issued LINK - #1113
Open
JohnChangUK wants to merge 2 commits into
Open
JohnChangUK wants to merge 2 commits into
JohnChangUK wants to merge 2 commits into
Conversation
…TokenAdmin Standalone dev-only package (link stays 2.1.0, untouched) holding the MCMS-governed admin surface for registry-issued LINK: Approve/Execute mint, burn, transfer and allocate, plus SetPaused/SetObservers. Execute* takes the live admin contract id and re-checks it: the fetched admin must match the authorization's ccipOwner, adminInstanceId and instrumentId, and must not be paused. SetPaused/SetObservers rotate the admin cid, so a stale cid fails the fetch and the operator must supply the current one. Pause stops outstanding authorizations, not just new approvals. link appears in the test package only, as the factory/holding double. Daml tests cover the entrypoint paths, failure paths and pause enforcement (18 scripts). MCMS wire fix for Decimal params: amount and maxAmount fields are encoded with MCMS encodeDecimal (sign byte plus 10^10-shifted magnitude) via the DecimalFields codegen hint. The hint is name-keyed, so regenerated bindings for other packages gain inert hex:"decimal" tags on their own Decimal amount fields. No existing consumer hex-encodes those structs.
…egistry Integration test driving the governed lifecycle on a one-party CTF network: MCMS bypasser dispatch of ApproveMint, ApproveBurn, SetPaused and SetObservers; ExecuteMint one-step BurnMintFactory_BurnMint on the bootstrap registry AllocationFactory, both to the registrar itself and to a third-party recipient (extraActors path), asserting the resulting registry Holding's owner and amount; ExecuteBurn round-trips both holdings; and the Execute* pause enforcement: a stale admin cid fails at fetch, a paused admin fails the pause assert, unpausing restores execution.
|
👋 JohnChangUK, thanks for creating this pull request! To help reviewers, please consider creating future PRs as drafts first. This allows you to self-review and make any final changes before notifying the team. Once you're ready, you can mark it as "Ready for review" to request feedback. Thanks! |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves privileged LINK operations (mint, burn, transfer, allocate) behind MCMS governance as a standalone dev-only
link-token-admin1.0.0 package.linkstays at 2.1.0 untouched, so vetting this does not keep the customLink.Tokentemplates alive (the NONEVM-5947 migration goal) and no factory re-release is needed on link bumps.Design
MCMS exercises
MCMSReceiver_EntrypointonLinkTokenAdminto create an authorization fixing the economics (recipient, amount, instrument, validity window). The operator then exercisesExecuteon the authorization, supplying only plumbing (factory CID, input holding CIDs, registry choice context, disclosures). It cannot alter what was approved.Executefetches the live admin contract and re-checks ccipOwner, instanceId and instrumentId, and rejects when the admin is paused.SetPausedandSetObserversarchive and recreate the admin, so a stale CID fails the fetch and the operator must supply the current one. Pause is therefore a stop on outstanding authorizations, not just new approvals.linkappears in the test package only, as the factory and holding double.MCMS wire fix for Decimal params
amountandmaxAmountparams fields are now encoded with MCMSencodeDecimal(sign byte plus 10^10-shifted magnitude) via theDecimalFieldscodegen hint. Plain text encoding failed the Daml decode withE_INVALID_PARAMS. The hint is name-keyed, so a few regenerated bindings gain inerthex:"decimal"tags on their own Decimal amount fields. No existing consumer hex-encodes those structs.Tests
integration-tests/mcms/link_token_admin_registry_test.go) against a real DA Registry bootstrap on a CTF network:BurnMintFactory_BurnMinton the registry AllocationFactory, both to the registrar itself and to a third-party recipient (the extraActors path). The created registry Holding's owner and amount are asserted in both cases.CONTRACT_NOT_FOUND), paused admin fails the pause assert, unpausing restores execution.Release
Dev-only in this PR. The
link-token-admin1.0.0 released DAR follows in a dedicated release PR.Follow-ups (deployment changesets, operator Execute tooling, EDS kill switch, forged-holdings check) are tracked as NONEVM-5947 follow-ups.