Repository navigation
chore(contracts): deploy escrow on testnet and document verifiable on-chain evidence - #84
Conversation
Deploying puls3 with
|
| Latest commit: |
6b6e221
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://9f196e2e.puls3-4lw.pages.dev |
| Branch Preview URL: | https://fix-onchain-evidence-escrow.puls3-4lw.pages.dev |
TOMOKI977
left a comment
There was a problem hiding this comment.
La documentación y la evidencia on-chain están muy completas, gracias. Antes de mergear, sugiero esperar porque este PR deja deployado el escrow tal como está hoy en main, y el contrato no tiene función de upgrade.
En la revisión del escrow encontramos tres puntos que conviene corregir antes del deploy definitivo:
refund_client(escrow/src/lib.rs:899-905) usatransferdirecto, sin el fallbacktry_transfer+Claimableque sí tienepay_or_defer. Si el cliente no puede recibir el token (por ejemplo, quitó la trustline),rejectyclaim_refundrevierten y los fondos quedan bloqueados.extend_ttl(lib.rs:751-757) solo extiendeJob(job_id). Las entradasClaimable(recipient, token)solo se extienden al acreditarse, así que un pago diferido puede archivarse en unos 60 días.create_job(lib.rs:424) validaclient != provider, pero permiteevaluator == provider. En ese caso el proveedor puede aprobar su propio trabajo y cobrar.
A eso se suma el tope de fee de #94. Propuesta: mergear #94 y los fixes del escrow primero, y después redeployar desde este PR para que el wasm_hash registrado coincida con el código fuente.
Detalle menor: el check scan falla por un falso positivo de gitleaks (la regla S[A-Z2-7]{55} coincide dentro de la dirección muxed MAFUYV5G3…). No es un secreto real; lo corregimos en la regla.
|
Corrección sobre mi review anterior: el punto de |
|
Los dos fixes pendientes del escrow quedaron en #95 (asignado a @moises-cisneros). Este PR queda bloqueado hasta que se mergee, para redeployar con el contrato corregido. |
TOMOKI977
left a comment
There was a problem hiding this comment.
Approving. Revisiting my earlier hold: redeploying on testnet is cheap, so the escrow fixes in #95 don't need to block this. Let's treat this deployment as interim and redeploy once #95 lands.
Before and after merging:
scanis red because of our gitleaks rule, not your PR. The patternS[A-Z2-7]{55}matches inside the muxed addressMAFUYV5G3…. I'm fixing the rule in a separate PR; once it's onmain, update this branch and the check should pass.- Note the interim status in the README /
docs/verification/onchain.md. The recordedwasm_hashwas built before #94, so it no longer matches the escrow source onmain. One line saying "interim deployment, to be redeployed after #95" is enough. - After this merges, retarget #86 to
mainso CI runs on the rest of the stack.
|
Correction to my approval note: no separate gitleaks PR was needed. The word-boundary fix ( |
…104) * docs(openspec): archive escrow changes and sync escrow specs Archive agent-escrow-payment (#55, PR #78), enforce-max-fee-bps (#79, PR #94) and address-testnet-deploy-pr-review (PR #84), all merged. Add the agent-escrow-lifecycle and agent-escrow-administration main specs. * docs(openspec): address review on escrow main specs - use '### Requirement:' headers in agent-escrow-lifecycle - drop A8 scenario not present in any delta
Closes #83
Summary
Deploys the escrow contract to Stellar testnet, registers the 8 demo agents with their payment wallet bound, runs one escrow job and one direct USDC payment, and rewrites the README evidence so every ID and hash can be verified from main.
scripts/deploy-escrow-testnet.sh: deploy, USDC allow-list,--test-job,--direct-payment. Identity names only, no key material.scripts/seed-demo-agents.sh: binds each agent's wallet (needed by escrowcreate_job).contracts/deployments/testnet.json: escrow, test job and direct payment records.README.md,docs/verification/onchain.md,contracts/README.md,contracts/AGENTS.md: evidence tables, verification steps, refreshed layout.openspec/changes/fix-readme-onchain-evidence/: change artifacts.Acceptance criteria
CBRD7A7MXINM7LREKCL3RMKRQ5UMLGKNHAEYY4JT7MVBBB7R5QV4TPE2deployed, USDC SAC allow-listed, recorded intestnet.json.agt-001..008registered as agents 7-14 with wallet bound.Verification evidence
Notes for reviewers
size:exception: scripts and tests, docs, and a generated deployment record belong together because the docs quote the real run.testnet.jsonare local sha256 values;onchain.mdshows how to compare them withstellar contract fetch.extend_ttlto keep the links alive.