BW-187: post-deploy configuration script for Uniswap-venue chains - #28
Merged
Merged
Conversation
SocksNFlops
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
script/ConfigureUniswapFulfillment.s.sol— post-deploy configuration for a chain that fills onUniswap. Reads both address books for the current chain, then, idempotently:
CONSOL_USDX_MAXIMUM_CAPis 0),FULFILLMENT_ROLEand USDX'sIGNORE_CAP_ROLEto theUniswapFulfillmentVault and max-approves every collateral plus USDX to the OrderPool,
PAUSE_ROLEtoADMIN_ADDRESS(default: the deployer) on the GeneralManager,ForfeitedAssetsPool, USDX queue, forfeited-assets queue, OriginationPoolScheduler and every
conversion queue,
KEEPER_ROLEtoKEEPER_ADDRESSon the RolloverVault and the UniswapFulfillmentVault.run()finishes by re-reading all of it from the chain inassertConfigured(), so a silent missfails the run rather than the deploy log.
setUp()refuses to proceed unless the vault named in theperiphery book reports the core book's OrderPool and USDX.
This script was executed against Robinhood Chain mainnet (4663) — 35 transactions, blocks
70914693–70917657 — after a simulation run. It is committed as executed, with two review changes
that leave behaviour identical:
IMaximumCapinterface is replaced by@core'sIConsol. Same selectors, but ahand-rolled copy can drift from core without the compiler noticing.
coreAddressBookPath()/peripheryAddressBookPath(),virtualwith the production paths as their bodies. The core book lives in the sibling corecheckout (
../contracts/addresses/…), which does not exist in this repo's CI, andfoundry.tomlonly grants
readthere — so the alternative was widening that entry toread-writeand havingthe test write into another repo's tracked address book. The override keeps the fixtures inside
this project and leaves an unconfigured run byte-identical to what ran on 4663.
test/script/ConfigureUniswapFulfillment.t.sol— modelled onDeployAllUniswap.t.sol: setsevery env var with
vm.setEnvonBaseTest's core stack and runs atTEST_CHAIN_ID = 4663. Itdeploys a real stack through
DeployRolloverVault.s.solandDeployUniswapFulfillmentVault.s.sol(neither writes an address book) and writes both books as fixtures under
addresses/tests/, whichis gitignored except for a
.gitkeep, with a newread-writefs_permissionsentry.Deliberately not via
DeployAllUniswap.s.sol: itslogAddresses()removes and rewrites thetracked
addresses/addresses-4663.json, andforge testruns suites in parallel, so the windowwhere the file is missing made
DeployAllUniswap.t.sol's own snapshot/restore fail intermittently.Driving the two per-vault scripts means this suite never touches a tracked file.
Coverage: a full
run()configures the stack andassertConfigured()passes; a secondrun()emits no
RoleGranted,ApprovalorMaximumCapSetlogs where the first emits 11/3/1;CONSOL_USDX_MAXIMUM_CAP=0leaves the cap at its prior value; a vault whoseorderPool()orusdx()disagrees with the core book reverts insetUp.addresses/addresses-4663.json— the deployed periphery addresses for 4663: router0xD90E52f001CDa68E1B3a0c4355419edA9493BaFe, rolloverVault0x0ADE37a031530FDE25BF36Be6ED3F3547366f2e0, fulfillmentVault0x5DAaF4cacd8b1EE5Db0715C790c58124c2Dc006f..env.example— a "Post-deploy configuration" section forKEEPER_ADDRESS,CONSOL_USDX_MAXIMUM_CAPandADMIN_ADDRESS. The last two are read withvm.envOr, which fallsback to its default on an empty value, so leaving them blank means "cap unchanged" and "the
deployer" respectively.
The core half of the 4663 address book is buttonwood-protocol/consol#104; this script needs it
present to run in the monorepo.
Testing :
forge test(full suite, withaddresses/addresses-4663.jsonpresent): 129 passed, 0 failed,11 skipped (140 total) across 10 suites.
DeployAllUniswap.t.solis green — 4 passed —including
test_run_deploysStackAndWritesAddresses, which snapshots and restores that file.Re-run three times for stability; the tracked address book is byte-identical afterwards.
ConfigureUniswapFulfillmentScriptTest, 7 passed.PAUSE_ROLEgrant in_grantIfMissingfailstest_run_configuresStack,test_run_secondRunIsIdempotentandtest_run_zeroCapLeavesConsolCapUntouchedwithPAUSE_ROLE missing.forge fmt --checkclean;forge buildandforge build --sizes --skip test --skip scriptsucceed.
src/is untouched, so the solhint and lintspec workflows (both scoped tosrc) see no change.Reviewers:
@SocksNFlops