Replies: 1 comment
|
Closing — both parts delivered. Part 1 — security review: Part 2 — Filecoin provider recommendation: posted as a comment on Discussion #18 — hands-on retrieval verification for Storacha and Lighthouse, a clear recommendation (Storacha Forge), and an FVM-native assessment (Filecoin Onchain Cloud's PDP proofs + Filecoin Pay cover what custom escrow/SLA logic would have built from scratch). The Storacha integration work that followed on Discussion #18 is new scope from that follow-up ask, not part of this task's original checklist — tracked there, not a reason to keep this one open. |
Uh oh!
There was an error while loading. Please reload this page.
cc @Abidoyesimze
Trial task assigned for Jul 7–13, 2026 (deadline Monday, July 13). Full spec:
Developer/tasks/task_060726_4.mdSummary
Two independent parts:
Part 1 — Security review of all 7 contracts in
foundry/src/(Days 1–3), pinned to commitd136ff3. Severity-tagged findings report covering the usual classes (access control, reentrancy, unchecked calls, gas-DoS) plus proxy-specific checks for the 4 upgradeable platform contracts (initializer protection, storage layout, upgrade-path access control). Findings-only — no API/storage/behavior changes; Foundry PoC tests encouraged.Part 2 — Filecoin provider recommendation, Discussion #18 (Days 4–5). Hands-on third-party retrieval verification per candidate provider, an FVM-native assessment, a written recommendation posted on #18, and best-effort provider credits/grant leads. Context: PR #16's Lighthouse adapter finding (upload works, retrieval payment-gated).
Reference material for the security audit
Documentation/technical/upgradable-contracts/has been updated in commit805ce9d. These docs refer to the code in PR #13 for the hardhat contracts and tests — and those hardhat contracts are identical to thefoundry/src/contracts ondevelopthat you're reviewing. All of this documentation (proxy pattern rationale, deployment architecture, design decisions) should be a helpful companion for the security audit.Questions, pushback, or anything ambiguous in the task spec — raise it here.
All reactions