Repository navigation
Vault and ENS: build around the deployed contracts, headless custody and ens, no fixed waits left - #2
Merged
Merged
Conversation
…stody and ens commands, and replace the remaining fixed waits - Recognize deployed Vault builds by runtime hash (current and first committed; a slot for the pre-release build without heldAgent()). An existing Vault may run any known build; a fresh deploy must be the current one. The deposit preflight reads heldAgent() only where it exists, otherwise agentOwner, and simulates the registry deposit before the wallet opens. Vault custom errors decode by name. Reconciliation reports the build instead of treating any code as a Vault. - Custody fixes: re-approve local operators after a redeposit (each deposit starts a new operator epoch), never treat a failed read as "revoked", "no Vault", or "accept", save a fresh Vault's address right after the deploy so a retry reuses it, clear the Vault address when switching to Simple, block a second send while one is in flight, classify ownership read errors by the transport's types, and clear the ownership cache after every custody transaction instead of trusting it for 30 seconds. - Replace the fixed attempt counts with one paced helper: wait for the endpoint to reach the receipt block, look again once per new block with doubling pauses up to the 60 second backoff ceiling, and stop at once on a definitive answer. It covers the post-deploy code check, deposit and withdraw confirmation, operator verification, and the gas estimate, where a revert now surfaces at once and by name. - Add scanLogs: start from each host's learned block range, take the limit an endpoint names or halve on a range refusal, remember it in hosts.json, hand over when an endpoint refuses the depth of history, and say why when none can. The registry transfer scan uses it; the unused discoverVaultedTokens and its unreachable pick-token step are removed. - ENS: reads go through the adaptive transport with cancel-only waits, an unreadable record or resolver is an error instead of "no record", every ENS transaction waits for its receipt (no time limit, cancelable) and records a pending tx, gas is estimated from the signer, Delete clears the agent records before removing the subdomain, and creating a name no longer changes custody or lists the owner as its own operator. - The operator key sends through the adaptive transport (one endpoint per broadcast) with the prepared gas and fees. - New `ethagent custody [--verify]`: Vault, build, holder, Vault-level owner, operators, and eth_call simulations of each permission (exit 4 on a mismatch). - New `ethagent ens`: show the linked name and its records; `ens <name>`, `ens --unlink`, and `ens --set/--clear` preview until --yes, sign ENS transactions in one browser tab or with --operator, refuse unless the signer controls the name, and publish a name change in one owner-signed save. - Document the commands, ETHAGENT_RPC_URL, and ETHAGENT_IPFS_API_URL, correct which history commands go online, and tell agents that previews are theirs to run and --yes is the user's. - Fix the three type errors on the base branch. - Tests: builds and capability preflight, paced checks with mocked time, scanLogs learning a 500-block limit, custody output and simulations, ens previews, diffs, multicall encoding and old-name clearing, signer refusals and exit codes, the local-key sender, runOperatorSave, the paced gas estimate, and the ENS client. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
…racts with forge Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
Reformatting Vault.sol would change the compiled metadata hash, so new deploys would stop matching the recorded current build. The deployed source stays as it is. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
The Base chain client type does not narrow to a plain PublicClient under the lockfile's viem types, which failed typecheck in CI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
…s commands Match the README and help conventions (<ref>, <path>): <name>, <key>=<value>, <key>, and <args> instead of agent.yourname.eth, url=https://example.com, k=v, and ellipses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Covers what the network pass (7169b11) left out. The Solidity is untouched.
Vault builds. Known runtime builds are recognized by hash. An existing Vault may run any known build; a fresh deploy must be the current build. The deposit preflight reads
heldAgent()only on builds that have it, otherwiseagentOwner, and simulates the registry deposit before the wallet opens. Vault custom errors (NotOwner,NotAuthorized, …) now decode by name.Custody fixes:
No fixed waits. One paced helper replaces the fixed loops. It waits for the receipt block, looks again once per new block, and stops at the 60 s backoff ceiling. It covers Vault confirmations, operator verification and the gas estimate; a revert now surfaces at once.
Log scans.
scanLogsuses each host's learned block range and names the limit when one applies, such as mainnet.base.org's 500 blocks. It hands over when an endpoint lacks history and says why. DeaddiscoverVaultedTokensis removed.ENS:
New commands:
ethagent custody [--verify]: read-only, witheth_callpermission simulations; exits 4 on a mismatch.ethagent ens: read-only.ens <name>,ens --unlinkandens --set/--clear: preview until--yes. They sign in the browser or with--operator, refuse unless the signer controls the name, and publish name changes in one owner-signed save.CI. New GitHub Actions workflow:
forge buildandforge testfor the contracts.forge fmt --checkis left out on purpose: reformattingVault.solwould change its metadata hash, so new deploys would stop matching the recorded build.Docs and guidance. README,
--helpand agent guidance are updated.Testing done
npm ci,npm run typecheckis clean andnpm testpasses all 732 tests.heldAgent();scanLogslearning a 500-block limit and handing over;custodyoutput and simulations;enspreviews, multicall encoding and old-name clearing;runOperatorSave;Remaining for testing (unsandboxed agent)
This sandbox has no RPC access, so the live checks below are still open. All are non-destructive; nothing else should be sent.
Pre-release Vault hash (required).
PRE_RELEASE_VAULT_BUILD_HASHinsrc/identity/registry/vault/builds.tsisundefined. Runethagent custody --jsonand takevault.code.hashfrom Vault0x6bdC…51d7: it should be 1,955 bytes and start0xf8f23197. Set the constant to it. Until then, that Vault reads as "not a known Vault build" and re-deposits are refused. The current build (0x97141f0f…) and the first committed build (0xfea7e898…) were reproduced from source with solc 0.8.24.Custody verify.
ethagent custody --verifyon that Vault should show:heldAgent();NotOwner);NotAuthorized); a stranger withdrawing: refused (NotOwner);ENS read.
ethagent ens --jsonformeow.femboi.ethshould show addr = owner, the token and ENSIP-25 records, the link OK, and the operator key able to sign.ENS previews only (no
--yes), viakeychain exec ethagent -- ethagent ens … --operator:ens <new>.femboi.eth --operator;ens --set url=… --operator.Every independent step's simulation should read "would succeed" from the operator.
Deposit preflight. Simulate it against the real Vault. A refusal should decode by name.
One operator save. Run one
keychain operator-saveon this branch's build.🤖 Generated with Claude Code
https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw