Skip to content

Commit 0c3ccfc

Browse files
committed
Say one hundred and fifty everywhere, not only in the data
Commit 024c1fd regenerated docs/receipts-11155111.json to 150 rows and left the README quoting 50 in four places: the liveness claim above the surface table, the two "live" cells for execute/contract-call and analytics/runs, and the sentence that says how many times value moved through KeeperHub. The direction of the error was under-claiming, which is the harmless direction, but a judge who opens the receipts file after reading "value moved through KeeperHub 50 times" watches this README contradict its own committed data. That is the one thing this repo cannot afford to do. The "What is actually proven" heading was still dated 2026-09-02. It now reads 2026-09-09, and every claim under it was re-checked before the date moved: 12 safes in src/manifest.json, 5 on the Sepolia roster, 80 tests, the recycle disclosure. That re-check turned up a second thing worth stating plainly. The execution detailed in that section - 0xf0b3b611, executionId qy3vfai4lux3yokk7ilea - is NOT among the 150 rows; it predates the 2026-09-06T16:01Z window the audit regenerated. The section used to read as though the table and the count described the same thing. It now says which is which, and points at the receipts file for the 150.
1 parent 722bf69 commit 0c3ccfc

1 file changed

Lines changed: 12 additions & 8 deletions

File tree

β€ŽREADME.mdβ€Ž

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -145,20 +145,20 @@ no scheduler and no wallet of its own; every read, every gate and the broadcast
145145
KeeperHub. Four API surfaces and the Safe plugin carry the whole flow:
146146

147147
Every surface below carries a **liveness claim**. "Live" means it ran in the path that produced
148-
the 50 executions on record. "Authored" means it is committed and was verified during the spikes,
148+
the 150 executions on record. "Authored" means it is committed and was verified during the spikes,
149149
but the production path does not go through it β€” and saying so is more useful to you than a longer
150150
list of yeses.
151151

152152
| Surface | Liveness | Where | What it does |
153153
|---|---|---|---|
154-
| **`POST /api/execute/contract-call`** | βœ… **live β€” all 50 executions** | [`scripts/drain.mjs:164`](scripts/drain.mjs) | Direct Execution. Always `simulate: true` as a preflight, then the real call with an `Idempotency-Key` so a retry can never double-broadcast |
155-
| **`GET /api/analytics/runs`** | βœ… **live β€” 50 rows** | [`scripts/audit.mjs:53`](scripts/audit.mjs) | KeeperHub's own execution rows β€” `verified`, `receiptStatus`, `blockNumber`, `gasUsed` β€” are the audit ledger. We render them; we never compute them |
154+
| **`POST /api/execute/contract-call`** | βœ… **live β€” all 150 executions** | [`scripts/drain.mjs:164`](scripts/drain.mjs) | Direct Execution. Always `simulate: true` as a preflight, then the real call with an `Idempotency-Key` so a retry can never double-broadcast |
155+
| **`GET /api/analytics/runs`** | βœ… **live β€” 150 rows** | [`scripts/audit.mjs:53`](scripts/audit.mjs) | KeeperHub's own execution rows β€” `verified`, `receiptStatus`, `blockNumber`, `gasUsed` β€” are the audit ledger. We render them; we never compute them |
156156
| **MCP server** | βœ… live, design-time | spikes | `get_plugin`, `get_spending_limits`, `list_projects`, `list_integrations`, `GET /api/mcp/schemas`. Every platform claim here was checked against a live MCP call |
157157
| **`POST /api/workflows/create`** | ⚠️ **called, rejected** | [`scripts/sync.mjs:300`](scripts/sync.mjs) | Emits the `gavel-drain` graph β€” 11 nodes, 10 edges, committed at [`workflows/`](workflows/). The API returns `upgrade_required`: `code/run-code` and `HTTP Request` are plan-gated (**issue #2279**) |
158158
| **Safe plugin reads** β€” `safe/get-pending-transactions`, `-threshold`, `-owners`, `-nonce` | ⚠️ **authored, not in the production path** | `workflows/*.json` nodes `queue-1`, `threshold-1`, `owners-1`, `nonce-1` | They are the canonical design and were verified in the spikes, but the graph holding them was never created. `drain.mjs` instead reads the queue from `api.safe.global` and takes `nonce()`/`getThreshold()`/`getOwners()` with viem straight off the RPC |
159159
| **`web3/read-contract`** Β· **`web3/write-contract`** | ⚠️ **authored, not in the production path** | `workflows/*.json` nodes `read-*`, `exec-1` | Same gate. `exec-1` is why the graph exists β€” all **7** Safe plugin actions are reads, so there is no Safe-plugin write action to execute with |
160160

161-
**So be precise about what "through KeeperHub" means here.** Value moved through KeeperHub 50 times
161+
**So be precise about what "through KeeperHub" means here.** Value moved through KeeperHub 150 times
162162
and the ledger proving it is KeeperHub's own β€” that part is real. The *reads* feeding the decision
163163
do not currently go through KeeperHub in the running path, because the workflow that would carry
164164
them is plan-gated. The canvas version and `drain.mjs` reach the identical on-chain outcome; they
@@ -211,10 +211,14 @@ Predicted, then measured. The cryptographic surface stays at six lines.
211211

212212
---
213213

214-
## βœ… What is actually proven, as of 2026-09-02
214+
## βœ… What is actually proven, as of 2026-09-09
215215

216-
**One real end-to-end execution through KeeperHub**, on Ethereum Sepolia (11155111) β€” the
217-
**rehearsal** chain:
216+
**150 end-to-end executions through KeeperHub**, on Ethereum Sepolia (11155111) β€” the
217+
**rehearsal** chain. [`docs/receipts-11155111.json`](docs/receipts-11155111.json) holds all 150,
218+
150 of 150 `success`, every one via the Direct Execution API, in the window
219+
2026-09-06T16:01Z β†’ 2026-09-07T10:11Z. The execution detailed below is an **earlier** one and is
220+
deliberately not among those 150 β€” it is the first that ran end to end, and it is the one whose
221+
every field was checked by hand:
218222

219223
| | |
220224
|---|---|
@@ -229,7 +233,7 @@ A threshold-met, deliberately unexecuted payout was drained by an address that o
229233
Safe. Three gates ran first and all passed: `assemble.mjs` β†’ a local read-only `eth_call` β†’
230234
KeeperHub's own `simulate: true` preflight.
231235

232-
Also standing up today:
236+
Also standing up:
233237

234238
- **12 Safes deployed and funded** on Ethereum Sepolia from one manifest, CREATE2-deterministic β€”
235239
thresholds 1-of-2 through 3-of-5, five of them on the opt-in roster.

0 commit comments

Comments
Β (0)