Skip to content

chore(contracts): deploy escrow on testnet and document verifiable on-chain evidence - #84

Merged
TOMOKI977 merged 6 commits into
mainfrom
fix/onchain-evidence-escrow-deploy
Oct 5, 2026
Merged

TOMOKI977 merged 6 commits into
mainfrom
fix/onchain-evidence-escrow-deploy

Conversation

@moises-cisneros

Copy link
Copy Markdown
Contributor

Closes #83

Summary

Deploys the escrow contract to Stellar testnet, registers the 8 demo agents with their payment wallet bound, runs one escrow job and one direct USDC payment, and rewrites the README evidence so every ID and hash can be verified from main.

  • scripts/deploy-escrow-testnet.sh: deploy, USDC allow-list, --test-job, --direct-payment. Identity names only, no key material.
  • scripts/seed-demo-agents.sh: binds each agent's wallet (needed by escrow create_job).
  • contracts/deployments/testnet.json: escrow, test job and direct payment records.
  • README.md, docs/verification/onchain.md, contracts/README.md, contracts/AGENTS.md: evidence tables, verification steps, refreshed layout.
  • openspec/changes/fix-readme-onchain-evidence/: change artifacts.

Acceptance criteria

  • Escrow CBRD7A7MXINM7LREKCL3RMKRQ5UMLGKNHAEYY4JT7MVBBB7R5QV4TPE2 deployed, USDC SAC allow-listed, recorded in testnet.json.
  • agt-001..008 registered as agents 7-14 with wallet bound.
  • Escrow job 3 completed (create, fund, submit, complete) and direct payment for hire 8.
  • Full 56-char IDs and tx hashes with explorer links in the README; verification guide added.

Verification evidence

bash scripts/tests/escrow-deploy.test.sh     passed: 143, failed: 0
bash scripts/tests/seed-preflight.test.sh    passed: 52, failed: 0
Horizon testnet, 9 txs (deploy, allow-list, job 3 x4, direct payment, agt-004, agt-008): successful: true
get_job --job-id 3 -> state 3 (Completed); fee_bps 0; approval_window 86400; total_agents 15

Notes for reviewers

  • Size is about 1,000 changed lines, over the 400-line budget. Requesting size:exception: scripts and tests, docs, and a generated deployment record belong together because the docs quote the real run.
  • The 7 earlier demo agents (ids 0-6) stay on-chain as superseded; the README says so.
  • Escrow jobs 1 and 2 are leftovers from attempts on the same contract: job 1 stopped in Submitted (provider had no USDC trustline), job 2 completed but the script mis-parsed the numeric state (fixed, with a test). Job 3 is the evidence of record. Both are disclosed in the README.
  • The earlier hire-7 payment used a spike-issued PUSDC asset, not Circle USDC; the README now labels it.
  • The WASM hashes in testnet.json are local sha256 values; onchain.md shows how to compare them with stellar contract fetch.
  • Re-seeding was a decision to register 8 new agents rather than align the seed file to the 7 existing ones.
  • Escrow persistent TTL is about 60 days; run extend_ttl to keep the links alive.
  • End-to-end app wiring (server RPC adapter, catalog endpoint, Flutter) is out of scope and planned as follow-up changes.

@moises-cisneros moises-cisneros added area: contracts Soroban smart contracts (Rust) type: chore Maintenance and tooling labels Oct 4, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Deploying puls3 with  Cloudflare Pages  Cloudflare Pages

Latest commit: 6b6e221
Status: ✅  Deploy successful!
Preview URL: https://9f196e2e.puls3-4lw.pages.dev
Branch Preview URL: https://fix-onchain-evidence-escrow.puls3-4lw.pages.dev

View logs

@TOMOKI977 TOMOKI977 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

La documentación y la evidencia on-chain están muy completas, gracias. Antes de mergear, sugiero esperar porque este PR deja deployado el escrow tal como está hoy en main, y el contrato no tiene función de upgrade.

En la revisión del escrow encontramos tres puntos que conviene corregir antes del deploy definitivo:

  • refund_client (escrow/src/lib.rs:899-905) usa transfer directo, sin el fallback try_transfer + Claimable que sí tiene pay_or_defer. Si el cliente no puede recibir el token (por ejemplo, quitó la trustline), reject y claim_refund revierten y los fondos quedan bloqueados.
  • extend_ttl (lib.rs:751-757) solo extiende Job(job_id). Las entradas Claimable(recipient, token) solo se extienden al acreditarse, así que un pago diferido puede archivarse en unos 60 días.
  • create_job (lib.rs:424) valida client != provider, pero permite evaluator == provider. En ese caso el proveedor puede aprobar su propio trabajo y cobrar.

A eso se suma el tope de fee de #94. Propuesta: mergear #94 y los fixes del escrow primero, y después redeployar desde este PR para que el wasm_hash registrado coincida con el código fuente.

Detalle menor: el check scan falla por un falso positivo de gitleaks (la regla S[A-Z2-7]{55} coincide dentro de la dirección muxed MAFUYV5G3…). No es un secreto real; lo corregimos en la regla.

@TOMOKI977

Copy link
Copy Markdown
Contributor

Corrección sobre mi review anterior: el punto de refund_client usando transfer directo no es un bug. Es una decisión documentada en ADR-0005 (docs/adr/0005-…md:84): el cliente siempre puede volver a intentar claim_refund (o que el evaluador haga reject) cuando pueda recibir de nuevo. Descarten ese punto. Siguen vigentes el TTL de Claimable en extend_ttl y la validación evaluator != provider en create_job.

@TOMOKI977

Copy link
Copy Markdown
Contributor

Los dos fixes pendientes del escrow quedaron en #95 (asignado a @moises-cisneros). Este PR queda bloqueado hasta que se mergee, para redeployar con el contrato corregido.

@TOMOKI977 TOMOKI977 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. Revisiting my earlier hold: redeploying on testnet is cheap, so the escrow fixes in #95 don't need to block this. Let's treat this deployment as interim and redeploy once #95 lands.

Before and after merging:

  • scan is red because of our gitleaks rule, not your PR. The pattern S[A-Z2-7]{55} matches inside the muxed address MAFUYV5G3…. I'm fixing the rule in a separate PR; once it's on main, update this branch and the check should pass.
  • Note the interim status in the README / docs/verification/onchain.md. The recorded wasm_hash was built before #94, so it no longer matches the escrow source on main. One line saying "interim deployment, to be redeployed after #95" is enough.
  • After this merges, retarget #86 to main so CI runs on the rest of the stack.

@TOMOKI977

Copy link
Copy Markdown
Contributor

Correction to my approval note: no separate gitleaks PR was needed. The word-boundary fix (\bS[A-Z2-7]{55}\b) was already on main via #70. I updated this branch and scan is green now. Once gate passes and the interim-deployment note is added, this is ready to merge.

@TOMOKI977
TOMOKI977 merged commit 72907ad into main Oct 5, 2026
8 checks passed
moises-cisneros added a commit that referenced this pull request Oct 6, 2026
Archive agent-escrow-payment (#55, PR #78), enforce-max-fee-bps (#79, PR #94)
and address-testnet-deploy-pr-review (PR #84), all merged. Add the
agent-escrow-lifecycle and agent-escrow-administration main specs.
moises-cisneros added a commit that referenced this pull request Oct 6, 2026
…104)

* docs(openspec): archive escrow changes and sync escrow specs

Archive agent-escrow-payment (#55, PR #78), enforce-max-fee-bps (#79, PR #94)
and address-testnet-deploy-pr-review (PR #84), all merged. Add the
agent-escrow-lifecycle and agent-escrow-administration main specs.

* docs(openspec): address review on escrow main specs

- use '### Requirement:' headers in agent-escrow-lifecycle
- drop A8 scenario not present in any delta
@moises-cisneros
moises-cisneros deleted the fix/onchain-evidence-escrow-deploy branch October 8, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: contracts Soroban smart contracts (Rust) type: chore Maintenance and tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(contracts): deploy escrow to testnet and document verifiable on-chain evidence

2 participants