Skip to content

feat(framework): add governance-controlled publish allowlist - #431

Closed
rubujubi wants to merge 1 commit into
m1from
feat/publish-allowlist
Closed

rubujubi wants to merge 1 commit into
m1from
feat/publish-allowlist

Conversation

@rubujubi

@rubujubi rubujubi commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds a governance-controlled allowlist that restricts who can publish or upgrade Move packages during the transition period. The change is framework-only (no VM or node changes) and ships through a regular framework upgrade proposal.

  • New module 0x1::publish_allowlist storing PublishAllowlist { enabled, approved_addresses } at @aptos_framework.
  • code::publish_package checks the publisher address before publishing. Every publish path goes through it: publish_package_txn, scripts, upgrades, large_packages chunked publish, and resource_account.
  • object_code_deployment::publish / upgrade check the publishing account instead of the newly created code object address, then call a new friend-only code::publish_package_txn_for_code_object.

Behavior

State Result
Allowlist not initialized Publishing unrestricted (no change from today)
Initialized, enabled = false Publishing unrestricted
enabled = true Only framework reserved addresses (0x1-0xa) and approved addresses may publish or upgrade

Rejected publishes abort with publish_allowlist::EPUBLISHER_NOT_APPROVED (0x50006).

Notes:

  • Removing an address also blocks upgrades of packages it already published.
  • Resource accounts publish under the resource address, so that address must be approved (approving the creator is not enough).
  • For object code deployment, only the publisher needs approval; the object address does not.

Governance API

All mutators require the @aptos_framework signer:

  • initialize(aptos_framework, enabled, approved_addresses)
  • set_enabled(aptos_framework, enabled)
  • add_approved_addresses(aptos_framework, addresses) (aborts if an address is already approved)
  • remove_approved_addresses(aptos_framework, addresses) (aborts if an address is not approved)

Views: is_enabled(), approved_addresses(), is_publisher_allowed(address).

Suggested rollout: framework upgrade, then initialize(..., false, list), then set_enabled(true).

Test plan

  • publish_allowlist Move unit tests (7): lifecycle, duplicate / already-approved / not-approved errors, non-framework signer rejected, unapproved publisher rejected
  • Full aptos-framework Move unit test suite: 673/673 pass
  • New e2e tests (e2e-move-tests/src/tests/publish_allowlist.rs, 4): disabled path, account publish + upgrade, object code deployment + upgrade, resource account
  • Existing e2e suites code_publishing, object_code_deployment, large_package_publishing pass
  • Move prover not run (new specs follow the existing publish_package / publish_package_txn pattern)

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@rubujubi rubujubi closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant