Skip to content

docs: the Sourcify fallback as it actually works - #33

Closed
thedavidmeister wants to merge 2 commits into
mainfrom
2026-09-29-sourcify-fallback
Closed

thedavidmeister wants to merge 2 commits into
mainfrom
2026-09-29-sourcify-fallback

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

The note in foundry.toml said the Robinhood fallback was forge verify-contract --verifier sourcify --chain 4663 .... That command does not work, which only surfaced when DecimalFloat actually needed it.

Two things it omitted:

  • Unset the etherscan keys and forge refuses to start. It resolves every entry in [etherscan] before it honours --verifier, and errors on the first name with no value: environment variable CI_DEPLOY_ARBITRUM_ETHERSCAN_API_KEY not found.
  • Set the Robinhood key to anything and forge ignores --verifier sourcify. It reports ETHERSCAN_API_KEY is set, defaulting to Etherscan verifier and goes to Blockscout, which answers with a Cloudflare challenge page, so forge reports a JSON deserialization error.

Only an empty value for that one key reaches Sourcify, with the rest of the table set to a placeholder so it resolves.

Also recorded: what success looks like. Sourcify forwards the result onward to Blockscout (403) and Etherscan (rate limit) and both fail, which reads like failure but is not — its own record is the verification. GET /v2/contract/4663/<address> returned "match" for 0xEc632ea4D04A6D72F87E60FEb4C6B6813cda59bd at 11:45:47Z.

The Blockscout description is corrected too: it does not merely "reject non-browser clients", it serves a Cloudflare interstitial.

QA

  • Discriminating tests: n/a — a comment. The command it documents was run: the old form fails two different ways (shown above), the new form submitted job bea50b3e-a07b-4da8-8745-0964bf808790 and Sourcify recorded a match.
  • Mutations applied: the key value is the mutation, and all three states were exercised against the live explorer — unset (forge will not start), set to x (goes to Blockscout, Cloudflare 403), empty (reaches Sourcify, match). That is what established which one the note needed.
  • Oracle: Sourcify's own record, independent of this repo — https://sourcify.dev/server/v2/contract/4663/0xEc632ea4D04A6D72F87E60FEb4C6B6813cda59bd returning "match": "match", and /server/chains confirming 4663 is supported.
  • Category check: covers the fallback being wrong and the success signal being mistakable for failure. Not covered: making the CI verify workflow do this automatically — it would need the empty-key handling per chain, and one chain's explorer being behind Cloudflare has not yet justified that.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Clarified that Robinhood’s Blockscout Etherscan-compatible endpoint is blocked by a Cloudflare challenge.
    • Documented that the Robinhood API-key setting must be empty to use the Sourcify verifier path.
    • Noted that Sourcify forwarding may fail without affecting verification, and that GET /v2/contract/4663/<address> should return "match" for a verified contract.

The note said `forge verify-contract --verifier sourcify --chain 4663 ...`.
That command does not work, which only showed up when `DecimalFloat` needed
it on 2026-09-29.

Two things it omits. Unset the etherscan keys and forge refuses to start: it
resolves every entry in `[etherscan]` before honouring `--verifier`, and
errors on the first name with no value. Set the Robinhood key to anything
and forge announces `ETHERSCAN_API_KEY is set, defaulting to Etherscan
verifier` and goes to Blockscout regardless of `--verifier sourcify`. Only
an EMPTY value reaches Sourcify, with the other keys set to a placeholder so
the table resolves.

Also records what "failure" looks like when it worked: Sourcify forwards the
result to Blockscout (403, Cloudflare) and Etherscan (rate limit) and both
fail. Its own record is the verification —
`GET /v2/contract/4663/<address>` returned `"match"` for
0xEc632ea4D04A6D72F87E60FEb4C6B6813cda59bd at 11:45:47Z.

The Blockscout description is corrected too: it has not merely "rejected
non-browser clients", it serves a Cloudflare challenge page, which is why
forge reports a JSON deserialization error rather than a refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7e14c428-ed78-4679-a353-fa19bbd1c8a9

📥 Commits

Reviewing files that changed from the base of the PR and between 1579270 and 368b2e7.

📒 Files selected for processing (1)
  • foundry.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The Robinhood comments in foundry.toml describe Blockscout’s Cloudflare challenge, the empty API-key requirement for Sourcify, and how to check Sourcify’s record. The configured endpoint and chain entry are unchanged.

Changes

Robinhood verification guidance

Layer / File(s) Summary
Robinhood verification instructions
foundry.toml
Comments state that the Robinhood API-key variable must be empty for the Sourcify verifier path. They identify GET /v2/contract/4663/<address> as the check for a "match" result, even if Sourcify’s onward pushes fail.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 368b2

This is a documentation-only update to comments in foundry.toml with no effect on runtime behavior. It is safe to merge.

Architecture Summary

Architecture risk: 🔵 Low · up to 368b2

The change affects 1 system.

Changed systems: foundry.toml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — foundry.toml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in foundry.toml: The Robinhood comments replace the brief fallback instruction with details about Blockscout’s 403, the empty-key requirement for reaching Sourcify, a verification command, and how to check Sourcify’s record despite failed explorer forwards. The configured endpoint and chain entry are unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the documentation update for the Sourcify fallback and matches the main change in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The empty key, and that Sourcify's own record is the verification. The rest
was explanation of forge's internals that a reader does not need to act.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

Closing: this documents a manual workaround for a gap that belongs in the workflow.

Manual sol verify fails on 4663 every run, because its Blockscout sits behind a Cloudflare challenge — so verification for this repo can never be green, and the note only tells a human how to finish the job by hand afterwards.

Fixing it in rainix instead: a chain whose explorer rejects the submission retries through Sourcify, which supports all nine. That removes the need for the note rather than correcting it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant