Replies: 9 comments 1 reply
|
Part A done — PR #176. Closes #159, #160, #161, one commit per issue:
One thing worth a separate issue, not fixed in this PR: regenerating the bundled ABIs from a fresh Starting on Parts B/C is still blocked on task_240926_16 PRs #171 (Part A) and #173 (Part C) merging — both still open as of now. Will pick up Part A follow-ups or the auditor-side commit-hash-binding issue (Part C's deliverable list) in the meantime if that gap widens. |
|
Heads-up: For this task: nothing to change — this task file and its branches don't reference the old name. Use |
|
Status check (2026-09-28): not closing yet. Part A is done; Parts B and C haven't started. Checked against
The blockers are cleared: task_240926_16's Part A (PR No. 171, merged 2026-09-26) and Part C (PR No. 173, merged 2026-09-27) are both on develop, so @Abidoyesimze, Parts B and C can start now, building on task_16's seed helper and This stays open until the Part B and Part C PRs merge and No. 156 closes. |
|
Yes I'm on it, will raise a PR soon. |
|
Part B done — PR #191 open. Fixes the batch-assignment half of #156's H-2: PoC (
Full suite: 417/417 foundry tests pass, dincli pytest unaffected (180 passed, same 16 pre-existing environment-only failures as a clean Part C (#156's M-1 half — commit-reveal on T1/T2 aggregation submissions) is next. |
|
Part C done — PR #197 open, closes #156. Fixes the aggregation half of #156's M-1: One deliberate hardening past #156's own proposal: the commit hash binds
Full suite: 416/416 foundry tests pass (12 new in That's all three PRs for task_240926_18 now open: #191 (Part B, H-2), #197 (Part C, M-1), plus the already-merged #176/#186 (Part A). #156 closes once #197 lands. |
|
Status check (2026-09-30): all three parts have landed on develop. This task is ready to close. Checked against
Part B deliverables, checked on develop
Part C deliverables, checked on develop
Two deviations from the task file, both deliberate
Follow-ups that outlive this task: No. 192 (auditor-side hash binding), No. 201 (contract size, slash reason for committed-but-unrevealed), BL-26 (seed-lock residuals). Thanks @Abidoyesimze. |
|
@abrahamnash this one is ready for post processing. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
cc @abrahamnash — this one's scoped and ready for your approval / HR-side pre-processing before I formally assign it to @Abidoyesimze.
Full spec:
Developer/tasks/task_240926_18.mdThe task file has the full specification: exact file/line references, the sequencing against Robbert's in-flight work, and the deliverables checklists. This post is the summary and the decisions that need flagging.
Timeline
7 days: Sep 24 – Oct 1, 2026. Part A can start immediately. Parts B and C are gated on Robbert's task_240926_16 Part A and Part C PRs merging (same Sep 24 – Oct 1 window), so if those slip, say so here early rather than building against his branches.
Summary
Similoluwa opened #156, #159, #160 and #161 as follow-throughs on his own July security review (
foundry-src-security-review.md, task_060726_4). None of the four is implemented ondevelopat3e52351. Each issue now has a review comment with the agreed scope. The task is three PRs intodevelop:depositAndMintreverts on a zeromintAmount(review).requestModelRegistrationrefunds overpayment, recordsfeePaid = requiredFee, and gains a transient reentrancy guard (review).setDINTaskAuditorContract, which the issue missed and which bricks the contract on a zero address (review).autoCreateTier1AndTier2andcreateAuditorsBatches.msg.sender, GI, tier and batchId. The issue'skeccak256(cid, salt)lets an aggregator copy a peer's commit hash and reveal the same values.Sequencing with Robbert's work
The four issues were checked against task_240926_16 and task_240926_17 (both Sep 24 – Oct 1). Nothing was cancelled. Where they overlap, this task waits:
updateDinPerEthfrom the deploy script)_shuffleAddressArrayto take a seed and leaves this call site to #156_setGIstate+ submission events in the same functions; its subgraph half regenerates theGIstatesmapping. task_17 Part 3b edits the S2 slash loop.task_17 Part 2's
test_knownGap_tests for shuffle steering get flipped totest_defended_in whichever PR here closes the gap.Decisions to flag, not guess
disputeSeedDelayor add a separate one with the same setter pattern. Say which in the PR.GIstatesordinal. Updatedincli/cli/utils.py's mirrors andDINShared.md§2.1, and post the new ordinal table on PR feat(indexer): implement DIN Protocol subgraph — platform + task-level contracts #29 for Robbert's subgraph. Don't push to his branch.DINTaskAuditoris 22,382 B at3e52351(~2.2 KB under EIP-170) and task_16 adds to it. Putforge build --sizesbefore/after in Parts B and C. If either contract crosses 24,576 B, stop and raise it here rather than splitting the contract.rejectModelnever refundsfeePaid, which is a policy question noted in Part A.Reference material
Developer/tasks/task_240926_18.md: full specDocumentation/technical/audits/foundry-src-security-review.md: H-2, M-1, L-2, L-3, L-6Once assigned: post progress updates, questions, and PR links here, same convention as prior task-tracking discussions. If anything in the spec doesn't feel right, is ambiguous, or needs clarification, comment here and cc @umeradl.
All reactions