Skip to content

Merge main into release/v3.x-new in order to prepare for v3.6.17 release - #452

Merged
dusan-maksimovic merged 9 commits into
release/v3.x-newfrom
main
Sep 23, 2026
Merged

dusan-maksimovic merged 9 commits into
release/v3.x-newfrom
main

Conversation

@dusan-maksimovic

Copy link
Copy Markdown
Contributor

Description

Closes: #XXXX

Add a description of the changes that this PR introduces and the files that
are the most critical to review.


Author Checklist

All items are required. Please add a note to the item if the item is not applicable and
please add links to any relevant follow up issues.

I have...

  • Targeted the correct branch
  • Included the necessary unit tests
  • Added/adjusted the necessary interchain tests
  • Added necessary migration code for all stores that were adjusted or added
  • Added a changelog entry in .changelog
  • Compiled the contracts by using make compile and included content of the artifacts directory into the PR
  • Regenerated front-end schema by using make schema and included generated files into the PR
  • Updated the relevant documentation or specification
  • Reviewed "Files changed" and left comments if necessary
  • Confirmed all CI checks have passed

dusan-maksimovic and others added 9 commits August 7, 2026 15:11
* reworked script and config for hydro governance hub deployment

* adjust script to instantiate the executive dao as well

* script cleanup
* Add mandatory timeout to SubmitDeployedAmount

SubmitDeployedAmount proposals are executed via DAO DAO with a proposer
and a separate verifier. If the verifier verifies but fails to execute,
the proposal stays executable indefinitely, so a compromised EOA could
execute a very old, stale submission.

The message now carries a required timeout (Unix timestamp in
nanoseconds); execution fails with a new SubmissionExpired error if
env.block.time is past it.

* Add changelog entry for SubmitDeployedAmount timeout
* IBC Eureka Inflow adapter implementation

* adjusted changelog

* Executors must provide fees on their own when initiating IBC Eureka transfers

* Have the relaying quote be specified by the executor

* recompiled contracts
…448)

* Add ability to swap the deposit denom on the Inflow Cosmos Hub vault

* Add changelog entry for deposit denom swap

* Check adapter positions, token info provider and shares denom on deposit denom swap

* Rebuild artifacts and regenerate schemas
@dusan-maksimovic dusan-maksimovic self-assigned this Sep 23, 2026
@dusan-maksimovic
dusan-maksimovic requested a review from a team as a code owner September 23, 2026 14:19
@claude

claude Bot commented Sep 23, 2026

Copy link
Copy Markdown

Review Summary

This PR merges main into release/v3.x-new to prepare the v3.6.17 release. It bundles several already-individually-reviewed PRs (#439, #440, #442, #444, #446, #447, #448, #451). I focused the review on the substantive Rust source changes rather than the generated artifacts/schemas/ts_types.

New IBC Eureka Inflow adapter (contracts/inflow/ibc-eureka-adapter-cosmoshub)

Overall well structured and thoroughly tested (testing_standard_adapter.rs + testing_custom_adapter.rs cover instantiate validation, deposit/withdraw, admin/executor management, denom/destination allowlists, and TransferFunds including the expired-quote and insufficient-balance paths).

A few minor observations, none blocking:

  • error.rs: UnauthorizedExecutor error message reads "only executors or admins can call this function", but validate_executor_caller (validation.rs) only checks the EXECUTORS map — admins are not implicitly treated as executors. Message is slightly misleading; worth aligning wording with actual behavior (or making admins bypass the executor check if that's the intent).
  • execute_register_depositor deserializes capabilities straight from the caller-supplied metadata binary via cosmwasm_std::from_json. Since this call is restricted to admins already (validate_admin_caller), this isn't a security issue, just worth noting there's no test for the malformed-metadata error path.
  • Nice touch documenting the deliberate unit mismatch (seconds vs. nanoseconds) between action_timeout_timestamp and fee_timeout_timestamp in both eureka.rs and at the call site in contract.rs — that kind of thing is easy to silently get wrong later.

SubmitDeployedAmount timeout (control-center)

Clean, minimal fix for the "stale DAO proposal executes an old submission" problem. The boundary test (submit_deployed_amount_timeout_test) correctly confirms block.time == timeout is accepted and block.time > timeout is rejected, matching the > comparison in contract.rs.

SwapDepositDenom (vault-cosmoshub)

Good defensive design — checks vault balance, all registered adapters' bank balances, and adapter-reported deployed positions before allowing the swap, and fails closed if a position query errors out. Test coverage is thorough (success, non-empty withdrawal queue, denom-still-held for vault/tracked/untracked adapters, shares-denom collision, provider-not-supporting-new-denom, position-query-failure, unauthorized, same-denom).

One thing worth double-checking outside the code (can't verify from the diff alone): the doc comment on swap_deposit_denom states a deposit landing "just before the swap" simply makes the swap fail rather than requiring a lock — that's only true if deposits and this execute message can't land ahead of the balance check in a way that races the check itself. Given CosmWasm's atomic per-tx execution this should hold, just flagging the assumption for a second pair of eyes given it's guarding real user funds.

lsm-hub-token-info-provider validator ratio fix

The rewrite of initialize_validator_store/initialize_validator_store_helper changes from "copy round N-1 into round N, repeated per round" to "find the last initialized round once, then stamp its validator set onto every uninitialized round up to the target." This is both a correctness fix and an efficiency win (avoids reloading/rewriting intermediate state per round). The added regression test test_initialize_validator_store_last_initialized_ten_rounds_in_the_past covers exactly the multi-round-gap scenario that looks like the original bug, and correctly asserts every intermediate round is populated.

Other changes

  • marketplace: removing the unused neutron-sdk dependency and Response<NeutronMsg> typing is a reasonable cleanup since the contract doesn't appear to use Neutron-specific messages.
  • hydro/liquid-collateral/ibc-eureka-adapter-cosmoshub migrate.rs: this release's migrate() is a no-op version bump; the previously-active pause/unpause migration helpers are kept around prefixed with _ for reuse in a future migration, consistent with the pattern already established elsewhere in the repo (see CLAUDE.md migration notes).
  • CI workflow (populate-staging-contracts.yml) switches the staging population job from Neutron/Osmosis to Gaia/Cosmos Hub and renames the mnemonic secret — infra-only change, nothing to flag.

Checklist / housekeeping

Artifacts, schemas, and changelog entries (.changelog/v3.6.17/...) are all present and match the merged PRs. Cargo.toml workspace version was bumped to 3.6.17 and the new adapter crate was added to both Cargo.toml members and the Makefile schema/ts-codegen targets.

No security concerns identified beyond the notes above — access control (admin/executor/depositor roles) is checked consistently across the new adapter's execute handlers, and the EVM destination-address allowlist plus role separation (executors can't add new destinations themselves) limits the blast radius of a compromised executor key to funds routed to already-approved addresses.

@dusan-maksimovic
dusan-maksimovic merged commit 727b6c1 into release/v3.x-new Sep 23, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants