fix(card-spend): disable the retired v2 module when moving a Safe onto v2 - #2589
Merged
Merged
Conversation
…o v2 The Fuse v2 module was redeployed on 2026-09-24 (0xE2d4…7b2B → 0xa98f…A999), but a shipped build kept the old address and moved Safes onto the retired core. The backend reads only the new module, so those cards decline every payment with SAFE_NOT_REGISTERED, while the old lens still tells the app they are set up. Once a build has the new address, those Safes show the enable-spending banner. The set-up and mode-switch batches now also disable any retired v2 core still on the Safe. Disables are computed against the module list as each earlier call leaves it, so v1 and the retired core can come off in one batch without GS103. Retired cores are listed in EXPO_PUBLIC_RETIRED_CASH_MODULE_V2_ADDRESSES, which defaults to 0xE2d4… and never includes the live core. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub. 2 Skipped Deployments
|
Code reviewNo issues found. Checked for bugs and CLAUDE.md compliance. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Wirex card payments are declining with
SAFE_NOT_REGISTEREDfor Safes that moved from v1 to v2.The Fuse
SolidCashModuleV2was redeployed on 2026-09-24:0xE2d4FB3d…7b2B0x34c3…6E320xa98f2D4b…A9990xf21d…3c2cAt least one shipped client still had the retired address in
EXPO_PUBLIC_CASH_MODULE_V2_ADDRESS. Its v1→v2 batch disabled v1 and enabled the retired core. The backend lens reports those Safes as not registered, so every authorization declines. The retired lens still reports them as set up, so the app shows no error, and the backend's registration-confirm step only logs a warning.On-chain as of 2026-09-25:
None of them has debt or escrowed collateral on the retired core.
Fix
ADDRESSES.fuse.retiredCashModulesV2, read fromEXPO_PUBLIC_RETIRED_CASH_MODULE_V2_ADDRESSES(comma-separated). It defaults to0xE2d4…when unset, and never includes the live core.register): whenever the target is v2, the batch now also disables any retired core still on the Safe.switchMode): the same cleanup is added. This is what covers the 6 Safes that have both cores.lib/utils/safeModules.tsworks out eachdisableModulepredecessor against the list as earlier calls leave it. v1 and the retired core are often neighbours, and reading both predecessors off one snapshot reverts with GS103.Stranded Safes need no new UI. With the live address in the build, they read as
awaitingV2(v1 off, live v2 neither enabled nor registered), so the existing "Card spending isn't set up" banner offers setup. It carries over their v1 limits, and the retired core is now removed in the same signature.Disabling the retired core can't trap funds:
withdrawCollateralworks after the module is revoked.Deploy steps (required: this PR alone doesn't fix prod)
EXPO_PUBLIC_CASH_MODULE_V2_ADDRESS=0xa98f2D4b79A465B265F68F745f5048BC369DA999EXPO_PUBLIC_SPEND_LENS_V2_ADDRESS=0xf21d360Ce044e5f28019B4BE09642f05270B3c2cEXPO_PUBLIC_RETIRED_CASH_MODULE_V2_ADDRESSEScan stay unset (it defaults to0xE2d4…).Testing
npx jest lib/utils/__tests__/safeModules.test.ts: 11 passing. Cases covered:tsc --noEmitand eslint are clean on the changed files.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.