Skip to content

[Feat]: Make StoreFactory upgradeable (UUPS) so beacon ownership and user store bindings survive into R2 #297

Description

@re-gius

Component

Store

Priority

P0

Summary

StoreFactory is the only non-upgradeable authority in the system (plain Ownable, contracts/store/StoreFactory.sol:28), yet it permanently holds:

  1. Ownership of both store beacons: created in its constructor with no ownership-transfer path, so every futurecLabelStore/UserStore implementation upgrade depends forever on this one contract and its owner key. A lost or renounced key bricks the whole store fleet, unrecoverably.
  2. The permanent user-to-store directory (_labelStores/_userStores): write-once, not migratable. Re-pointing the STORE_FACTORY registry key to a fresh factory would silently break label lookups and zero out transfer fees for all existing names.

Requirement: every R1 contract must have an owner-operated path to R2; StoreFactory currently does not.

Proposal

Convert StoreFactory to the same UUPS pattern as the other twelve contracts. The factory is then upgraded in place: bindings stay behind the proxy, beacon ownership sits with upgradeable logic, and both failure modes disappear.

Main requirements:

  • Initializable + UUPSUpgradeable + OwnableUpgradeable, onlyOwner _authorizeUpgrade, __gap
  • Beacons created in initialize, owned by the proxy; beacon addresses and protocolRegistry in storage instead of immutables
  • Deploy pipeline switches the factory to the UUPS deploy path; verification and DEPLOYMENTS.md updated

Acceptance criteria

  • StoreFactory behind an ERC1967 proxy, upgrade gated onlyOwner
  • Both beacons owned by the proxy
  • Existing behaviour unchanged (store deploy auth, claim, one-store-per-user)
  • OZ upgrade-safety validation passes; deploy pipeline and docs updated

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions