Component
Store
Priority
P0
Summary
StoreFactory is the only non-upgradeable authority in the system (plain Ownable, contracts/store/StoreFactory.sol:28), yet it permanently holds:
- Ownership of both store beacons: created in its constructor with no ownership-transfer path, so every futurec
LabelStore/UserStore implementation upgrade depends forever on this one contract and its owner key. A lost or renounced key bricks the whole store fleet, unrecoverably.
- The permanent user-to-store directory (
_labelStores/_userStores): write-once, not migratable. Re-pointing the STORE_FACTORY registry key to a fresh factory would silently break label lookups and zero out transfer fees for all existing names.
Requirement: every R1 contract must have an owner-operated path to R2; StoreFactory currently does not.
Proposal
Convert StoreFactory to the same UUPS pattern as the other twelve contracts. The factory is then upgraded in place: bindings stay behind the proxy, beacon ownership sits with upgradeable logic, and both failure modes disappear.
Main requirements:
Initializable + UUPSUpgradeable + OwnableUpgradeable, onlyOwner _authorizeUpgrade, __gap
- Beacons created in initialize, owned by the proxy; beacon addresses and
protocolRegistry in storage instead of immutables
- Deploy pipeline switches the factory to the UUPS deploy path; verification and
DEPLOYMENTS.md updated
Acceptance criteria
Component
Store
Priority
P0
Summary
StoreFactoryis the only non-upgradeable authority in the system (plainOwnable,contracts/store/StoreFactory.sol:28), yet it permanently holds:LabelStore/UserStoreimplementation upgrade depends forever on this one contract and its owner key. A lost or renounced key bricks the whole store fleet, unrecoverably._labelStores/_userStores): write-once, not migratable. Re-pointing theSTORE_FACTORYregistry key to a fresh factory would silently break label lookups and zero out transfer fees for all existing names.Requirement: every R1 contract must have an owner-operated path to R2;
StoreFactorycurrently does not.Proposal
Convert
StoreFactoryto the same UUPS pattern as the other twelve contracts. The factory is then upgraded in place: bindings stay behind the proxy, beacon ownership sits with upgradeable logic, and both failure modes disappear.Main requirements:
Initializable+UUPSUpgradeable+OwnableUpgradeable,onlyOwner_authorizeUpgrade,__gapprotocolRegistryin storage instead of immutablesDEPLOYMENTS.mdupdatedAcceptance criteria
StoreFactorybehind an ERC1967 proxy, upgrade gatedonlyOwner