Repository navigation
fix(deploy): guard ST0X_SIGNER against the deploy key + correct deployer NatSpec - #293
Merged
Merged
Conversation
hardyjosh
marked this pull request as ready for review
August 10, 2026 15:38
Collaborator
Author
This was referenced Aug 10, 2026
Collaborator
Author
Merge activity
|
hardyjosh
changed the base branch from
fix/dia-cross-epoch-skew
to
graphite-base/293
August 10, 2026 16:35
hardyjosh
force-pushed
the
fix/deploy-signer-guard
branch
from
August 10, 2026 16:35
6545b21 to
fe801f5
Compare
hardyjosh
force-pushed
the
graphite-base/293
branch
from
August 10, 2026 16:35
f2678eb to
b4cef4c
Compare
hardyjosh
changed the base branch from
graphite-base/293
to
fix/dia-cross-epoch-skew
August 10, 2026 16:35
hardyjosh
changed the base branch from
fix/dia-cross-epoch-skew
to
graphite-base/293
August 10, 2026 16:36
…yer NatSpec Adversarial-pass findings on the deploy path (mutation-test run @ c371a23). deploy C1 (MED) — deploySignedPriceStack guards ST0X_ADMIN and ST0X_ORACLE_ADMIN against equalling the hot CI deploy key, but not ST0X_SIGNER. updatePrice is permissionless and authorised solely by the signer's EIP-712 signature, so the signer controls every served price even more directly than the two guarded admin roles — a copy-pasted signer == deploy key would ship the feed under CI's control with no other guard catching it. Adds the matching require(signer != deployer). New assertion in testDeployEnvConfigDispatchAndKeySeparation; mutation-verified (removing the guard fails the test). deploy C2 (LOW/doc) — MorphoPairAdapterBeaconSetDeployer NatSpec claimed the central store is 'fixed for the beacon's whole life'. The beacon owner can upgrade to an implementation built with a different central; iCentral() then reports a stale value. NatSpec now frames iCentral() as 'the central at deploy time', a value an owner-authorised beacon upgrade can change — not a live invariant. deploy C3 (LOW/doc) — the Deployment event's NatSpec implied monitoring can trust it to identify the deployer, but minting is permissionless and config-salted (msg.sender excluded), so a front-runner can appear as caller. All three deployers' event docs now direct monitoring to key on the deterministic proxy address and note a front-run mint grants no authority. Comment-only except the one-line signer guard. 190 tests; fmt/slither clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013hi8wq9YkjWPcGACXCEKeL
hardyjosh
force-pushed
the
fix/deploy-signer-guard
branch
from
August 10, 2026 16:37
fe801f5 to
4b5f549
Compare
hardyjosh
added a commit
that referenced
this pull request
Aug 10, 2026
…CDSA doc (#294) Signed-price adversarial findings (mutation-test run @ c371a23). Stacked on [#293](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/293). - **C2 (MED)** — `MorphoPairAdapter.price()` floors the rescale to **0** for very-high-decimal collateral (base > 18 + quote), feeding Morpho a zero collateral price (fail-OPEN) — the exact thing the central store's `PriceZero` guard prevents. Now reverts `PriceRoundsToZero` (fail-closed); mutation-verified. - **C1 (doc)** — `updatePrice` NatSpec now documents that a malformed signature reverts OpenZeppelin's ECDSA errors before `PriceUpdateInvalidSignature`, all fail-closed. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
hardyjosh
added a commit
that referenced
this pull request
Aug 10, 2026
#296) Doc consistency follow-up surfaced by the **post-fix mutation run** (@ `c7c22c3`), which found **no code defects and no coverage gaps** — every non-equivalent mutant is killed by the existing suite — but flagged four doc sites the fix PRs ([#292](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/292)–[#295](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/295)) left contradicting the hardened code: - **README** cross-epoch section still documented `pauseTimeAfter >= maxAge` and called `== maxAge` 'airtight' — a config it calls valid now reverts at init. Rewritten to the strict `> maxAge` rule + forward-skew-margin rationale. - **`maxAge` struct-field NatSpec** said 'MUST be `<= pauseTimeAfter`'; init enforces strict `<`. Corrected. - **`iCentral` immutable comment** still said 'fixed for the beacon's whole life', contradicting the struct doc corrected in [#293](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/293). - Two **test comments** with stale `>=` / 'airtight at equality' phrasing. Doc/comment + README only — **zero code lines changed**. 192 tests; fmt/slither/reuse clean. Last doc loose end before the pre-audit evidence is regenerated over the final tip. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Deploy-path adversarial findings (mutation-test run @ c371a23). Stacked on #292.
deploySignedPriceStackguardedST0X_ADMIN/ST0X_ORACLE_ADMINagainst the hot deploy key but notST0X_SIGNER, which controls every served price more directly (permissionlessupdatePrice). Adds the matchingrequire(signer != deployer), mutation-verified.iCentralNatSpec no longer claims 'fixed for the beacon's whole life' (an owner beacon-upgrade can change it); theDeploymenteventcallerdocs now note minting is permissionless/front-runnable and direct monitoring to the deterministic proxy address.🤖 Generated with Claude Code