docs: the Sourcify fallback as it actually works - #33
thedavidmeister wants to merge 2 commits into
Conversation
The note said `forge verify-contract --verifier sourcify --chain 4663 ...`. That command does not work, which only showed up when `DecimalFloat` needed it on 2026-09-29. Two things it omits. Unset the etherscan keys and forge refuses to start: it resolves every entry in `[etherscan]` before honouring `--verifier`, and errors on the first name with no value. Set the Robinhood key to anything and forge announces `ETHERSCAN_API_KEY is set, defaulting to Etherscan verifier` and goes to Blockscout regardless of `--verifier sourcify`. Only an EMPTY value reaches Sourcify, with the other keys set to a placeholder so the table resolves. Also records what "failure" looks like when it worked: Sourcify forwards the result to Blockscout (403, Cloudflare) and Etherscan (rate limit) and both fail. Its own record is the verification — `GET /v2/contract/4663/<address>` returned `"match"` for 0xEc632ea4D04A6D72F87E60FEb4C6B6813cda59bd at 11:45:47Z. The Blockscout description is corrected too: it has not merely "rejected non-browser clients", it serves a Cloudflare challenge page, which is why forge reports a JSON deserialization error rather than a refusal. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe Robinhood comments in ChangesRobinhood verification guidance
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to This is a documentation-only update to comments in foundry.toml with no effect on runtime behavior. It is safe to merge. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The empty key, and that Sourcify's own record is the verification. The rest was explanation of forge's internals that a reader does not need to act. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Closing: this documents a manual workaround for a gap that belongs in the workflow.
Fixing it in rainix instead: a chain whose explorer rejects the submission retries through Sourcify, which supports all nine. That removes the need for the note rather than correcting it. |
The note in
foundry.tomlsaid the Robinhood fallback wasforge verify-contract --verifier sourcify --chain 4663 .... That command does not work, which only surfaced whenDecimalFloatactually needed it.Two things it omitted:
[etherscan]before it honours--verifier, and errors on the first name with no value:environment variable CI_DEPLOY_ARBITRUM_ETHERSCAN_API_KEY not found.--verifier sourcify. It reportsETHERSCAN_API_KEY is set, defaulting to Etherscan verifierand goes to Blockscout, which answers with a Cloudflare challenge page, so forge reports a JSON deserialization error.Only an empty value for that one key reaches Sourcify, with the rest of the table set to a placeholder so it resolves.
Also recorded: what success looks like. Sourcify forwards the result onward to Blockscout (403) and Etherscan (rate limit) and both fail, which reads like failure but is not — its own record is the verification.
GET /v2/contract/4663/<address>returned"match"for0xEc632ea4D04A6D72F87E60FEb4C6B6813cda59bdat 11:45:47Z.The Blockscout description is corrected too: it does not merely "reject non-browser clients", it serves a Cloudflare interstitial.
QA
bea50b3e-a07b-4da8-8745-0964bf808790and Sourcify recorded a match.x(goes to Blockscout, Cloudflare 403), empty (reaches Sourcify, match). That is what established which one the note needed.https://sourcify.dev/server/v2/contract/4663/0xEc632ea4D04A6D72F87E60FEb4C6B6813cda59bdreturning"match": "match", and/server/chainsconfirming 4663 is supported.🤖 Generated with Claude Code
Summary by CodeRabbit
GET /v2/contract/4663/<address>should return"match"for a verified contract.