Skip to content

Introduce the Sovryn Perimeter Fee on Zero - #10

Open
tjcloa wants to merge 3 commits into
developmentfrom
sovryn-perimeter-fee
Open

Introduce the Sovryn Perimeter Fee on Zero#10
tjcloa wants to merge 3 commits into
developmentfrom
sovryn-perimeter-fee

Conversation

@tjcloa

@tjcloa tjcloa commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Phase 1 of the Sovryn security perimeter (SIP-0094): a minimal exit fee on user-initiated withdrawal surfaces, funding continuous exit monitoring. This is the Zero half of the system; the shared fee rail lives in Sovryn-perimeter and the lending half in Sovryn-smart-contracts#580.

What this carries

  • Exit-fee hooks in BorrowerOperations on collateral withdrawal and trove closure, quoting through the shared ExitFeeController and paying the fee leg to the ExitFeeVault. Every hook fails open: a fee fault forgoes the fee, never blocks a withdrawal.
  • The surplus-claim surface: CollSurplusPool.claimCollWithFee, a BorrowerOperations-only two-leg split that keeps claimColl byte-untouched, with the pool implementation upgrade ordered strictly before the BorrowerOperations upgrade inside SIP-0094 executable part 1.
  • Implementation-only deploy scripts for both contracts (the proxy swaps are governance actions), storage-layout zero-diff guards, and the fee test suite including reentrancy/fail-open matrices and Echidna invariants.

The fee system deploys disabled and is enabled only by governance after post-deployment verification.

Merge timing

This PR is intended to stay open until SIP-0094 has been approved and executed on-chain — mainline follows the chain rather than leading it. The deployment runs from this branch's commit, so no contract file here may change between deploy and execution; the proposal builders compare the live runtime code hash at creation, so a stale implementation produces a refused proposal rather than a silent mismatch.

Phase 1 of the Sovryn security perimeter (SIP-0094): a minimal exit fee on
user-initiated withdrawal surfaces, funding continuous exit monitoring.
This change carries the Zero half of the system:

- exit-fee hooks in BorrowerOperations on collateral withdrawal and trove
  closure, quoting through the shared ExitFeeController (Sovryn-perimeter
  repo) and paying the fee leg to the ExitFeeVault; every hook fails open —
  a fee fault forgoes the fee, never blocks a withdrawal;
- the surplus-claim surface: CollSurplusPool.claimCollWithFee, a BO-only
  two-leg split that keeps claimColl byte-untouched, with the pool
  implementation upgrade ordered strictly before the BO upgrade inside
  SIP-0094 executable part 1;
- impl-only deploy scripts for both contracts (the proxy swaps are
  governance actions), storage-layout zero-diff guards, and the ColFee
  test suite incl. reentrancy/fail-open matrices and Echidna invariants.

The fee system deploys disabled and enables only by governance after
post-deployment verification.
tjcloa added 2 commits August 13, 2026 12:09
Deployed 2026-08-13 by 0x163463b7ddbce853832037a059f5c5e6606bf9c4 (nonces
25-26), both inert until SIP-0094 Part 1 calls setImplementation:

  BorrowerOperations_Implementation  0xcD22ba4b3ED7D7297b40Dcd26d982634A0207885
  CollSurplusPool_Implementation     0x71A605F81a66eB93Ce9b8091014da858bFD4b6dA

Verified after deploy: both hold code; both live proxies still point at
their current implementations (BO 0xD603B4c5…, CSP 0xE9005C36…); the
permit2 immutable baked into the new BO implementation equals the live
proxy's. Runtime codehashes match the fork rehearsal's pins exactly, so
mainnet carries bit-for-bit the code the dress run exercised.

The stale BorrowerOperations_Implementation record was moved aside before
the run: hardhat-deploy's bytecode comparison needs the historical deploy
transaction, which no public RSK endpoint still serves. The prior record
remains in git history.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant