Repository navigation
feat: deploy-script-refs publishes the treasury-movement validator - #32
Merged
Merged
Conversation
heimdall now sources the TM validator from the chain by the hash the Config publishes (#5) and verifies the bytes against it, instead of taking a CBOR string an operator pasted into a config file — a value whose absence let a node pass every startup check, run a whole signing ceremony, and fail only at the mint. But a Plutus script exists on chain only once something uses it, so the bridge's first movement would need the script in order to make the transaction that would publish it. Publishing treasury_movement as a CIP-33 reference output at deployment breaks that circle. It is the one entry in this list published for its existence rather than to shrink a transaction: nothing here spends it, and it must stay published anyway. Re-running the command against an older bridge is the migration, since it already skips whatever is deployed.
Not part of this branch's change, and not a new break: `scalafmtCheck` has been failing on main since at least 2026-08-19 over this file, so every CI run — main's own included — has been red before reaching compile or test. Two docstrings were rewrapped by hand and the formatter was not re-run; this is its output, five lines of comment reflow with no code touched.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Companion to lantr-io/heimdall#77.
heimdall no longer takes the treasury-movement validator as an operator-pasted
cardano.tm_script_cbor. It fetches the script from the chain by the hash the Config publishes (#5) and refuses any bytes that do not hash back to it. That key being unset let a node pass every startup check, run a whole signing ceremony, and fail only at the mint — on the preprod bridge it cost five batch opportunities on 2026-08-20.But a Plutus script exists on chain only once something uses it.
deploy-script-refspublishes nine scripts today and the TM validator is not among them — it is built here only to derivetmNftPolicyforbridge_state. So on a fresh bridge the first movement would need the script in order to make the transaction that would publish it.This adds
treasury_movementto the published set. It is the one entry there published for its existence rather than to shrink a transaction — nothing in binocular spends it, and it must stay published anyway. Re-running the command against an older bridge is the migration path, since it already skips whatever is deployed.Also updates the subcommand's help text, which still described three of the nine scripts it publishes.
sbt compileandsbt test(89 tests) green;scalafmtCheckclean for both touched files.