Skip to content

fix(deploy): guard ST0X_SIGNER against the deploy key + correct deployer NatSpec - #293

Merged
hardyjosh merged 1 commit into
mainfrom
fix/deploy-signer-guard
Aug 10, 2026
Merged

hardyjosh merged 1 commit into
mainfrom
fix/deploy-signer-guard

Conversation

@hardyjosh

@hardyjosh hardyjosh commented Aug 10, 2026 •

Copy link
Copy Markdown
Collaborator

Deploy-path adversarial findings (mutation-test run @ c371a23). Stacked on #292.

  • C1 (MED) — deploySignedPriceStack guarded ST0X_ADMIN/ST0X_ORACLE_ADMIN against the hot deploy key but not ST0X_SIGNER, which controls every served price more directly (permissionless updatePrice). Adds the matching require(signer != deployer), mutation-verified.
  • C2/C3 (doc) — iCentral NatSpec no longer claims 'fixed for the beacon's whole life' (an owner beacon-upgrade can change it); the Deployment event caller docs now note minting is permissionless/front-runnable and direct monitoring to the deterministic proxy address.

🤖 Generated with Claude Code

hardyjosh commented Aug 10, 2026 •

Copy link
Copy Markdown
Collaborator Author

Merge activity

  • Aug 10, 4:33 PM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Aug 10, 4:38 PM UTC: Graphite rebased this pull request as part of a merge.
  • Aug 10, 4:38 PM UTC: @hardyjosh merged this pull request with Graphite.

@hardyjosh
hardyjosh changed the base branch from fix/dia-cross-epoch-skew to graphite-base/293 August 10, 2026 16:35
@hardyjosh
hardyjosh force-pushed the fix/deploy-signer-guard branch from 6545b21 to fe801f5 Compare August 10, 2026 16:35
@hardyjosh
hardyjosh changed the base branch from graphite-base/293 to fix/dia-cross-epoch-skew August 10, 2026 16:35
@hardyjosh
hardyjosh changed the base branch from fix/dia-cross-epoch-skew to graphite-base/293 August 10, 2026 16:36
@hardyjosh
hardyjosh changed the base branch from graphite-base/293 to main August 10, 2026 16:36
…yer NatSpec

Adversarial-pass findings on the deploy path (mutation-test run @ c371a23).

deploy C1 (MED) — deploySignedPriceStack guards ST0X_ADMIN and
ST0X_ORACLE_ADMIN against equalling the hot CI deploy key, but not ST0X_SIGNER.
updatePrice is permissionless and authorised solely by the signer's EIP-712
signature, so the signer controls every served price even more directly than
the two guarded admin roles — a copy-pasted signer == deploy key would ship the
feed under CI's control with no other guard catching it. Adds the matching
require(signer != deployer). New assertion in
testDeployEnvConfigDispatchAndKeySeparation; mutation-verified (removing the
guard fails the test).

deploy C2 (LOW/doc) — MorphoPairAdapterBeaconSetDeployer NatSpec claimed the
central store is 'fixed for the beacon's whole life'. The beacon owner can
upgrade to an implementation built with a different central; iCentral() then
reports a stale value. NatSpec now frames iCentral() as 'the central at deploy
time', a value an owner-authorised beacon upgrade can change — not a live
invariant.

deploy C3 (LOW/doc) — the Deployment event's  NatSpec implied
monitoring can trust it to identify the deployer, but minting is permissionless
and config-salted (msg.sender excluded), so a front-runner can appear as
caller. All three deployers' event docs now direct monitoring to key on the
deterministic proxy address and note a front-run mint grants no authority.

Comment-only except the one-line signer guard. 190 tests; fmt/slither clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hi8wq9YkjWPcGACXCEKeL
@hardyjosh
hardyjosh force-pushed the fix/deploy-signer-guard branch from fe801f5 to 4b5f549 Compare August 10, 2026 16:37
@hardyjosh
hardyjosh merged commit 8fc7b86 into main Aug 10, 2026
6 checks passed
hardyjosh added a commit that referenced this pull request Aug 10, 2026
…CDSA doc (#294)

Signed-price adversarial findings (mutation-test run @ c371a23). Stacked on [#293](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/293).

- **C2 (MED)** — `MorphoPairAdapter.price()` floors the rescale to **0** for very-high-decimal collateral (base > 18 + quote), feeding Morpho a zero collateral price (fail-OPEN) — the exact thing the central store's `PriceZero` guard prevents. Now reverts `PriceRoundsToZero` (fail-closed); mutation-verified.
- **C1 (doc)** — `updatePrice` NatSpec now documents that a malformed signature reverts OpenZeppelin's ECDSA errors before `PriceUpdateInvalidSignature`, all fail-closed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
hardyjosh added a commit that referenced this pull request Aug 10, 2026
#296)

Doc consistency follow-up surfaced by the **post-fix mutation run** (@ `c7c22c3`), which found **no code defects and no coverage gaps** — every non-equivalent mutant is killed by the existing suite — but flagged four doc sites the fix PRs ([#292](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/292)–[#295](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/295)) left contradicting the hardened code:

- **README** cross-epoch section still documented `pauseTimeAfter >= maxAge` and called `== maxAge` 'airtight' — a config it calls valid now reverts at init. Rewritten to the strict `> maxAge` rule + forward-skew-margin rationale.
- **`maxAge` struct-field NatSpec** said 'MUST be `<= pauseTimeAfter`'; init enforces strict `<`. Corrected.
- **`iCentral` immutable comment** still said 'fixed for the beacon's whole life', contradicting the struct doc corrected in [#293](https://app.graphite.com/github/pr/ST0x-Technology/st0x.oracle/293).
- Two **test comments** with stale `>=` / 'airtight at equality' phrasing.

Doc/comment + README only — **zero code lines changed**. 192 tests; fmt/slither/reuse clean. Last doc loose end before the pre-audit evidence is regenerated over the final tip.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant