Conversation
|
Thanks for the contribution! We reviewed this PR while merging the open queue and couldn't merge it yet. Here's what needs fixing:
This branch also has merge conflicts with |
…e-payment-real-semantics Resolves merge conflicts against CalloraOrg/Callora-Contracts@2730f2d (90 commit(s) behind) so the PR is mergeable.
…real transfer semantics - Restore contracts/revenue_pool/src/lib.rs and events.rs, which this branch had deleted, so the crate manifest resolves and the workspace builds again. - receive_payment now rejects non-positive amounts, restricts the caller to the configured vault/settlement address, pulls USDC into the pool with token.transfer, and emits the event only after the transfer succeeds. - Add set_vault/get_vault to configure the authorized caller and add RevenuePoolError::UnauthorizedCaller (code 26) with docs + tests. - Re-point the stale receive_payment/balance assertions and document the new event semantics in EVENT_SCHEMA.md.
|
@greatest0fallt1me — thanks for the review. I've brought the branch up to date with What was wrong. This branch deleted What the PR does now
Verification (local, real toolchain)
Heads-up on the checks that will still be red. |
Overview
This PR gives
RevenuePool::receive_paymentreal semantics: it now validates the amount, pulls USDC from the caller viatoken.transfer, restricts the caller to the configured vault/settlement address, and emits an event whose payload reflects the funds actually moved. Indexers aggregatingreceive_paymentevents will now count real revenue, and the vault can call the entrypoint as the name implies.Related Issue
Changes
💸
receive_paymentsemantics[MODIFY]
contracts/revenue_pool/src/lib.rsreceive_payment(caller, amount, from_vault)now:amount(returns the newInvalidAmounterror).callerto be the configured vault/settlement address (admin-only path removed).token.transfer(caller, contract, amount)so the pool's USDC balance increases by exactlyamount.receive_payment; admin retains config/upgrade powers but no longer bypasses the transfer.[MODIFY]
contracts/revenue_pool/src/errors.rsInvalidAmountfor non-positive amounts andUnauthorizedCallerfor callers other than the configured vault/settlement.[MODIFY]
contracts/revenue_pool/src/events.rsreceive_paymentevent now carries the caller, the transferredamount, and the resulting pool balance so the payload reflects actual funds moved rather than a caller-supplied value.Verification Results
InvalidAmountreturned before any transferamounttoken.transfer(caller, pool, amount)executed on the authorized pathUnauthorizedCallerand covered by testsSecurity and Failure Modes
receive_payment; admin cannot mint fictional revenue events.amount <= 0is rejected before any state change or transfer, preventing zero-value or negative-value events.token.transfersucceeds, so a failed transfer cannot produce a misleading event.deposit_yield.Non-goals
Closes #1161