Commit fb6ea60
committed
The canvas ran: one drain, two refusals, and two things sync.mjs got wrong
First workflow on the KeeperHub canvas (7v0qwhcp5gcex58gjugyg), the day the
Pro trial unblocked code/run-code and HTTP Request. Execution
hq4av5dbacb1i5z9bxfs0 drained VOL_1 on Sepolia:
0x188addfb861b79c7d300966680fe3edc02140e58515425bfef358b4329b95a5c,
verified, 102503 gas, from a wallet that owns nothing on that Safe.
Before it, the same graph refused VOL_2 (not-next-nonce, two proposals at
nonce 37) and VOL_3 (refund-requested, gasPrice=1) — same assemble.mjs,
same decisions drain.mjs makes.
Two generator bugs, both only findable by running:
- gate-addr used matchesRegex. The docs list it; the runtime condition
validator bans `new RegExp`, has no `test` in ALLOWED_METHODS, and
rejects any `[` after a word char even inside a quoted string. Replaced
with startsWith + length; the strict ADDRESS_RE check lives in assemble().
- The Code node substitutes templates as JSON values, so wrapping the nonce
and threshold templates in quotes produced ""37"" and a syntax error.
Unquoted now.
Both graphs regenerated from the fixed generator.1 parent 80fc5b1 commit fb6ea60
3 files changed
Lines changed: 21 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
125 | 125 | | |
126 | 126 | | |
127 | 127 | | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
128 | 132 | | |
129 | | - | |
130 | | - | |
| 133 | + | |
| 134 | + | |
131 | 135 | | |
132 | | - | |
133 | | - | |
| 136 | + | |
| 137 | + | |
134 | 138 | | |
135 | 139 | | |
136 | 140 | | |
| |||
188 | 192 | | |
189 | 193 | | |
190 | 194 | | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
191 | 203 | | |
192 | 204 | | |
193 | | - | |
| 205 | + | |
194 | 206 | | |
195 | 207 | | |
196 | 208 | | |
| |||
0 commit comments