Description
geev-core has no circuit breaker. AdminContract::admin_withdraw (admin.rs:60) can rescue funds after an incident, but nothing can stop new value from entering or moving while that incident is being handled: create_giveaway, create_giveaway_with_selection, enter_giveaway, donate, claim_prize, and claim_help_request_funds all remain callable. DataKey has no paused flag, and check_admin is the only gate in access.rs.
The result is that the only tool available during an active exploit is draining the contract, which is disruptive to every unaffected giveaway and help request.
User Story
As an Admin,
I want to pause state-changing contract entrypoints during an incident,
so that I can stop an exploit without draining funds from unaffected campaigns.
Requirements and Context
- Files / refs:
contracts/geev-core/src/admin.rs, contracts/geev-core/src/access.rs, contracts/geev-core/src/types.rs, contracts/geev-core/src/giveaway.rs, contracts/geev-core/src/mutual_aid.rs, contracts/geev-core/src/test.rs
- Add a
DataKey::Paused flag in instance storage, defaulting to false
- Add admin-gated
pause(env) / unpause(env) using the existing check_admin helper
- Add a
require_not_paused(&env) guard in access.rs and apply it to value-moving entrypoints
- Emit
ContractPaused / ContractUnpaused events, matching the existing #[contractevent] style
- Escape hatches must stay callable while paused:
admin_withdraw, unpause, and all read-only getters
Suggested Implementation
1. Add DataKey::Paused and a new Error::ContractPaused variant
2. Add pause/unpause to AdminContract, both behind check_admin
3. Add require_not_paused to access.rs
4. Guard create_giveaway, create_giveaway_with_selection, enter_giveaway,
donate, claim_prize, and claim_help_request_funds
5. Test that guarded calls panic while paused, that admin_withdraw and
unpause still work, and that unpausing restores normal operation
Acceptance Criteria
Submission Guidelines
- Branch:
feat/contract-emergency-pause
- Depends on: None
- PR:
feat(admin): add emergency pause circuit breaker
Gap verified against origin/main at 87de441 on 2026-08-27; line references above are from that commit.
Description
geev-corehas no circuit breaker.AdminContract::admin_withdraw(admin.rs:60) can rescue funds after an incident, but nothing can stop new value from entering or moving while that incident is being handled:create_giveaway,create_giveaway_with_selection,enter_giveaway,donate,claim_prize, andclaim_help_request_fundsall remain callable.DataKeyhas no paused flag, andcheck_adminis the only gate inaccess.rs.The result is that the only tool available during an active exploit is draining the contract, which is disruptive to every unaffected giveaway and help request.
User Story
As an Admin,
I want to pause state-changing contract entrypoints during an incident,
so that I can stop an exploit without draining funds from unaffected campaigns.
Requirements and Context
contracts/geev-core/src/admin.rs,contracts/geev-core/src/access.rs,contracts/geev-core/src/types.rs,contracts/geev-core/src/giveaway.rs,contracts/geev-core/src/mutual_aid.rs,contracts/geev-core/src/test.rsDataKey::Pausedflag in instance storage, defaulting tofalsepause(env)/unpause(env)using the existingcheck_adminhelperrequire_not_paused(&env)guard inaccess.rsand apply it to value-moving entrypointsContractPaused/ContractUnpausedevents, matching the existing#[contractevent]styleadmin_withdraw,unpause, and all read-only gettersSuggested Implementation
Acceptance Criteria
admin_withdraw,unpause, and read-only calls still work while pausedSubmission Guidelines
feat/contract-emergency-pausefeat(admin): add emergency pause circuit breakerGap verified against
origin/mainat87de441on 2026-08-27; line references above are from that commit.