Retire bundle: signer's direct vault roles, after the burn-in - #336
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
650f281 to
bd86161
Compare
a94712a to
2f96db0
Compare
20260831-retire-direct-signer-roles (run-script registry): the second half of the enable/retire split of the old cutover bundle, per review - the enable bundle grants the orchestrator path while LEAVING the signer's direct DEPOSIT/WITHDRAW as a parallel emergency fallback; this bundle revokes them once the orchestrator has proven itself. The burn-in gate (OrchestratorPathNotEnabled) refuses to author unless the orchestrator holds both vault roles AND the signer holds MINT/BURN on it - the retirement can never strand a chain without a working mint path. Self-scoping; already-retired refuses; post-sim proves the signer's CERTIFY and every other canonical row survive; n+1 proves the Safe can restore the fallback under the live threshold. Own deadline 2026-10-15 - two weeks after the enable/fleet deadline, honouring the burn-in window by construction. 7 unit tests + 3-state prod walk per chain. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KbsbYN4C4YDa8pu9DdudoX
bd86161 to
43d7b34
Compare

Top of stack: #324 (enable) → #325 (fleet) → #334 (governed beacon set) → this.
The retire half of the enable/retire split:
20260831-retire-direct-signer-roles(run-scriptregistry, per chain) revokes the service signer's directDEPOSIT/WITHDRAWonce the orchestrator has proven itself — closing the parallel burn-in window #324 deliberately opens.OrchestratorPathNotEnabled): refuses to author unless the orchestrator holds both vault roles AND the signer holdsMINT/BURNon it — retirement can never strand a chain without a working mint path.CERTIFYand the Safe's break-glass action roles.verify(), Fireblocks-style post-execution pin lifecycle.Unit 7/7, prod walk 3/3 (today every chain pins the world/enable-pending refusals).
🤖 Generated with Claude Code
https://claude.ai/code/session_01KbsbYN4C4YDa8pu9DdudoX