Repository navigation
deploy-bridge publishes the federation one-shot at Config #12 - #31
Merged
Merged
Conversation
The three federation policy ids the Config already publishes are all functions of one compile parameter, the federation one-shot outpoint, and until now that outpoint reached each operator by hand out of deploy-bridge's terminal output. Publishing it as ConfigDatum #12 removes the copy: deploy-script-refs now takes it from the deployed Config instead of bridge.federation-one-shot-ref, so the SPO half — spos_registry, spo_bans and the three DKG fault verifiers — is no longer conditional on an operator having set a local key that defaults to unset. Before this, a default deployment published no registry reference script at all and every SPO deployed and paid for their own copy. The retired key is still parsed when present and a disagreement with #12 is refused rather than ignored, since silently preferring the chain would hide a real dispute about which bridge this is. The vendored min-blueprint is re-taken from ft, which moves bitcoin/config — whose hash IS the config NFT policy id — so all five contract pins and the four federation pins cascade, exactly as the rev-5.4 widening did. The re-vendor also absorbs treasury_info's pre-existing build drift, which costs nothing here because treasury_info is parameterized by the config policy that moves anyway; that lets RebuildDrift go empty, as its own comment asked, now that ft's blueprint reproduces byte-for-byte at its pinned compiler version.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on FluidTokens/ft-bifrost-bridge#45 (the datum field).
The three federation policy ids the Config publishes are all functions of one compile parameter, the federation one-shot outpoint, and until now that outpoint reached each operator by hand out of
deploy-bridge's terminal output.deploy-bridgenow writes it asConfigDatum#12, anddeploy-script-refstakes it from the deployed Config instead ofbridge.federation-one-shot-ref. That matters more than it sounds: the SPO half —spos_registry,spo_bansand the three fault verifiers — used to be conditional on an operator having set a local key thatreference.confleaves unset. So a default deployment published no registry reference script at all, and every SPO deployed and paid ~55 ADA for their own copy.The retired key is still parsed when present, and a disagreement with #12 is refused rather than ignored — silently preferring the chain would hide a real dispute about which bridge this is.
Re-vendored blueprint. Taking ft's current bytes moves
bitcoin/config, whose hash is the config NFT policy id, so all five contract pins and the four federation pins cascade — exactly as the rev-5.4 widening did.RebuildDriftis now empty. It existed because ft'splutus.jsondid not reproduce from its own source. Measured today: a pristine rebuild at the pinnedcompiler = "v1.1.23"(localv1.1.23+8949565, the version CI installs) reproduces the committed blueprint byte for byte, and only the edited validator moves. The re-vendor absorbstreasury_info's pre-existing drift, which is free here becausetreasury_infois parameterized by the config policy that moves anyway — not a precedent for absorbing drift cheaply.180 tests pass, including the CEK suites that execute the real validators.