Skip to content

BW-187: post-deploy configuration script for Uniswap-venue chains - #28

Merged
SocksNFlops merged 2 commits into
mainfrom
bw-187-configure-uniswap-fulfillment
Sep 24, 2026
Merged

SocksNFlops merged 2 commits into
mainfrom
bw-187-configure-uniswap-fulfillment

Conversation

@0xGumpy

@0xGumpy 0xGumpy commented Sep 24, 2026

Copy link
Copy Markdown

Changes

script/ConfigureUniswapFulfillment.s.sol — post-deploy configuration for a chain that fills on
Uniswap. Reads both address books for the current chain, then, idempotently:

  • sets the Consol USDX maximum cap (skipped when CONSOL_USDX_MAXIMUM_CAP is 0),
  • grants the OrderPool's FULFILLMENT_ROLE and USDX's IGNORE_CAP_ROLE to the
    UniswapFulfillmentVault and max-approves every collateral plus USDX to the OrderPool,
  • grants PAUSE_ROLE to ADMIN_ADDRESS (default: the deployer) on the GeneralManager,
    ForfeitedAssetsPool, USDX queue, forfeited-assets queue, OriginationPoolScheduler and every
    conversion queue,
  • grants KEEPER_ROLE to KEEPER_ADDRESS on the RolloverVault and the UniswapFulfillmentVault.

run() finishes by re-reading all of it from the chain in assertConfigured(), so a silent miss
fails the run rather than the deploy log. setUp() refuses to proceed unless the vault named in the
periphery book reports the core book's OrderPool and USDX.

This script was executed against Robinhood Chain mainnet (4663) — 35 transactions, blocks
70914693–70917657 — after a simulation run. It is committed as executed, with two review changes
that leave behaviour identical:

  • the ad-hoc IMaximumCap interface is replaced by @core's IConsol. Same selectors, but a
    hand-rolled copy can drift from core without the compiler noticing.
  • the two address-book paths move behind coreAddressBookPath() / peripheryAddressBookPath(),
    virtual with the production paths as their bodies. The core book lives in the sibling core
    checkout (../contracts/addresses/…), which does not exist in this repo's CI, and foundry.toml
    only grants read there — so the alternative was widening that entry to read-write and having
    the test write into another repo's tracked address book. The override keeps the fixtures inside
    this project and leaves an unconfigured run byte-identical to what ran on 4663.

test/script/ConfigureUniswapFulfillment.t.sol — modelled on DeployAllUniswap.t.sol: sets
every env var with vm.setEnv on BaseTest's core stack and runs at TEST_CHAIN_ID = 4663. It
deploys a real stack through DeployRolloverVault.s.sol and DeployUniswapFulfillmentVault.s.sol
(neither writes an address book) and writes both books as fixtures under addresses/tests/, which
is gitignored except for a .gitkeep, with a new read-write fs_permissions entry.

Deliberately not via DeployAllUniswap.s.sol: its logAddresses() removes and rewrites the
tracked addresses/addresses-4663.json, and forge test runs suites in parallel, so the window
where the file is missing made DeployAllUniswap.t.sol's own snapshot/restore fail intermittently.
Driving the two per-vault scripts means this suite never touches a tracked file.

Coverage: a full run() configures the stack and assertConfigured() passes; a second run()
emits no RoleGranted, Approval or MaximumCapSet logs where the first emits 11/3/1;
CONSOL_USDX_MAXIMUM_CAP=0 leaves the cap at its prior value; a vault whose orderPool() or
usdx() disagrees with the core book reverts in setUp.

addresses/addresses-4663.json — the deployed periphery addresses for 4663: router
0xD90E52f001CDa68E1B3a0c4355419edA9493BaFe, rolloverVault
0x0ADE37a031530FDE25BF36Be6ED3F3547366f2e0, fulfillmentVault
0x5DAaF4cacd8b1EE5Db0715C790c58124c2Dc006f.

.env.example — a "Post-deploy configuration" section for KEEPER_ADDRESS,
CONSOL_USDX_MAXIMUM_CAP and ADMIN_ADDRESS. The last two are read with vm.envOr, which falls
back to its default on an empty value, so leaving them blank means "cap unchanged" and "the
deployer" respectively.

The core half of the 4663 address book is buttonwood-protocol/consol#104; this script needs it
present to run in the monorepo.

Testing :

  • forge test (full suite, with addresses/addresses-4663.json present): 129 passed, 0 failed,
    11 skipped (140 total)
    across 10 suites. DeployAllUniswap.t.sol is green — 4 passed —
    including test_run_deploysStackAndWritesAddresses, which snapshots and restores that file.
    Re-run three times for stability; the tracked address book is byte-identical afterwards.
  • New suite: ConfigureUniswapFulfillmentScriptTest, 7 passed.
  • Mutation check: suppressing the PAUSE_ROLE grant in _grantIfMissing fails
    test_run_configuresStack, test_run_secondRunIsIdempotent and
    test_run_zeroCapLeavesConsolCapUntouched with PAUSE_ROLE missing.
  • forge fmt --check clean; forge build and forge build --sizes --skip test --skip script
    succeed.
  • src/ is untouched, so the solhint and lintspec workflows (both scoped to src) see no change.

Reviewers:

@SocksNFlops

@SocksNFlops
SocksNFlops merged commit d97325e into main Sep 24, 2026
8 checks passed
@SocksNFlops
SocksNFlops deleted the bw-187-configure-uniswap-fulfillment branch September 24, 2026 01:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants