Skip to content

deploy-bridge publishes the federation one-shot at Config #12 - #31

Merged
rssh merged 2 commits into
mainfrom
feat/wi-090-config-federation-one-shot
Aug 14, 2026
Merged

rssh merged 2 commits into
mainfrom
feat/wi-090-config-federation-one-shot

Conversation

@rssh

@rssh rssh commented Aug 14, 2026

Copy link
Copy Markdown
Collaborator

Depends on FluidTokens/ft-bifrost-bridge#45 (the datum field).

The three federation policy ids the Config publishes are all functions of one compile parameter, the federation one-shot outpoint, and until now that outpoint reached each operator by hand out of deploy-bridge's terminal output.

deploy-bridge now writes it as ConfigDatum #12, and deploy-script-refs takes it from the deployed Config instead of bridge.federation-one-shot-ref. That matters more than it sounds: the SPO half — spos_registry, spo_bans and the three fault verifiers — used to be conditional on an operator having set a local key that reference.conf leaves unset. So a default deployment published no registry reference script at all, and every SPO deployed and paid ~55 ADA for their own copy.

The retired key is still parsed when present, and a disagreement with #12 is refused rather than ignored — silently preferring the chain would hide a real dispute about which bridge this is.

Re-vendored blueprint. Taking ft's current bytes moves bitcoin/config, whose hash is the config NFT policy id, so all five contract pins and the four federation pins cascade — exactly as the rev-5.4 widening did.

RebuildDrift is now empty. It existed because ft's plutus.json did not reproduce from its own source. Measured today: a pristine rebuild at the pinned compiler = "v1.1.23" (local v1.1.23+8949565, the version CI installs) reproduces the committed blueprint byte for byte, and only the edited validator moves. The re-vendor absorbs treasury_info's pre-existing drift, which is free here because treasury_info is parameterized by the config policy that moves anyway — not a precedent for absorbing drift cheaply.

180 tests pass, including the CEK suites that execute the real validators.

The three federation policy ids the Config already publishes are all functions
of one compile parameter, the federation one-shot outpoint, and until now that
outpoint reached each operator by hand out of deploy-bridge's terminal output.
Publishing it as ConfigDatum #12 removes the copy: deploy-script-refs now takes
it from the deployed Config instead of bridge.federation-one-shot-ref, so the
SPO half — spos_registry, spo_bans and the three DKG fault verifiers — is no
longer conditional on an operator having set a local key that defaults to unset.
Before this, a default deployment published no registry reference script at all
and every SPO deployed and paid for their own copy. The retired key is still
parsed when present and a disagreement with #12 is refused rather than ignored,
since silently preferring the chain would hide a real dispute about which bridge
this is.

The vendored min-blueprint is re-taken from ft, which moves bitcoin/config —
whose hash IS the config NFT policy id — so all five contract pins and the four
federation pins cascade, exactly as the rev-5.4 widening did. The re-vendor also
absorbs treasury_info's pre-existing build drift, which costs nothing here
because treasury_info is parameterized by the config policy that moves anyway;
that lets RebuildDrift go empty, as its own comment asked, now that ft's
blueprint reproduces byte-for-byte at its pinned compiler version.
@rssh
rssh merged commit de63661 into main Aug 14, 2026
1 check passed
@rssh
rssh deleted the feat/wi-090-config-federation-one-shot branch August 14, 2026 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant