Skip to content

feat: deploy-script-refs publishes the treasury-movement validator - #32

Merged
rssh merged 2 commits into
mainfrom
feat/publish-tm-validator-ref
Aug 21, 2026
Merged

rssh merged 2 commits into
mainfrom
feat/publish-tm-validator-ref

Conversation

@rssh

@rssh rssh commented Aug 21, 2026

Copy link
Copy Markdown
Collaborator

Companion to lantr-io/heimdall#77.

heimdall no longer takes the treasury-movement validator as an operator-pasted cardano.tm_script_cbor. It fetches the script from the chain by the hash the Config publishes (#5) and refuses any bytes that do not hash back to it. That key being unset let a node pass every startup check, run a whole signing ceremony, and fail only at the mint — on the preprod bridge it cost five batch opportunities on 2026-08-20.

But a Plutus script exists on chain only once something uses it. deploy-script-refs publishes nine scripts today and the TM validator is not among them — it is built here only to derive tmNftPolicy for bridge_state. So on a fresh bridge the first movement would need the script in order to make the transaction that would publish it.

This adds treasury_movement to the published set. It is the one entry there published for its existence rather than to shrink a transaction — nothing in binocular spends it, and it must stay published anyway. Re-running the command against an older bridge is the migration path, since it already skips whatever is deployed.

Also updates the subcommand's help text, which still described three of the nine scripts it publishes.

sbt compile and sbt test (89 tests) green; scalafmtCheck clean for both touched files.

heimdall now sources the TM validator from the chain by the hash the Config
publishes (#5) and verifies the bytes against it, instead of taking a CBOR
string an operator pasted into a config file — a value whose absence let a node
pass every startup check, run a whole signing ceremony, and fail only at the
mint. But a Plutus script exists on chain only once something uses it, so the
bridge's first movement would need the script in order to make the transaction
that would publish it.

Publishing treasury_movement as a CIP-33 reference output at deployment breaks
that circle. It is the one entry in this list published for its existence
rather than to shrink a transaction: nothing here spends it, and it must stay
published anyway. Re-running the command against an older bridge is the
migration, since it already skips whatever is deployed.
Not part of this branch's change, and not a new break: `scalafmtCheck` has been
failing on main since at least 2026-08-19 over this file, so every CI run —
main's own included — has been red before reaching compile or test. Two
docstrings were rewrapped by hand and the formatter was not re-run; this is its
output, five lines of comment reflow with no code touched.
@rssh
rssh merged commit b6ade91 into main Aug 21, 2026
1 check failed
@rssh
rssh deleted the feat/publish-tm-validator-ref branch August 21, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant