-
Notifications
You must be signed in to change notification settings - Fork 13
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Co-authored-by: ksatyarth2 <ksatyarth2@users.noreply.github.com>
- Loading branch information
1 parent
3be1b03
commit 2b5fc42
Showing
6 changed files
with
649 additions
and
1 deletion.
There are no files selected for viewing
48 changes: 48 additions & 0 deletions
48
mainnet-contracts/script/AccessManagerMigrations/05_GenerateValidatorTicketCalldata.s.sol
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,48 @@ | ||
// SPDX-License-Identifier: GPL-3.0 | ||
pragma solidity >=0.8.0 <0.9.0; | ||
|
||
import { Script } from "forge-std/Script.sol"; | ||
import { AccessManager } from "@openzeppelin/contracts/access/manager/AccessManager.sol"; | ||
import { Multicall } from "@openzeppelin/contracts/utils/Multicall.sol"; | ||
import { PUBLIC_ROLE, ROLE_ID_DAO, ROLE_ID_PUFETH_BURNER } from "../../script/Roles.sol"; | ||
import { ValidatorTicket } from "../../src/ValidatorTicket.sol"; | ||
|
||
/** | ||
* @title GenerateValidatorTicketCalldata | ||
* @author Puffer Finance | ||
* @notice Generates the call data to setup the ValidatorTicket contract access | ||
* The returned calldata is queued and executed by the Operations Multisig | ||
* 1. timelock.queueTransaction(address(accessManager), encodedMulticall, 1) | ||
* 2. ... 7 days later ... | ||
* 3. timelock.executeTransaction(address(accessManager), encodedMulticall, 1) | ||
*/ | ||
contract GenerateValidatorTicketCalldata is Script { | ||
function run(address validatorTicketProxy) public pure returns (bytes memory) { | ||
bytes[] memory calldatas = new bytes[](3); | ||
|
||
// Public functions | ||
bytes4[] memory vtPublicSelectors = new bytes4[](4); | ||
vtPublicSelectors[0] = ValidatorTicket.burn.selector; | ||
vtPublicSelectors[1] = ValidatorTicket.purchaseValidatorTicket.selector; | ||
vtPublicSelectors[2] = ValidatorTicket.purchaseValidatorTicketWithPufETH.selector; | ||
vtPublicSelectors[3] = ValidatorTicket.purchaseValidatorTicketWithPufETHAndPermit.selector; | ||
calldatas[0] = abi.encodeWithSelector( | ||
AccessManager.setTargetFunctionRole.selector, validatorTicketProxy, vtPublicSelectors, PUBLIC_ROLE | ||
); | ||
|
||
// DAO-restricted functions | ||
bytes4[] memory vtDaoSelectors = new bytes4[](2); | ||
vtDaoSelectors[0] = ValidatorTicket.setProtocolFeeRate.selector; | ||
vtDaoSelectors[1] = ValidatorTicket.setGuardiansFeeRate.selector; | ||
calldatas[1] = abi.encodeWithSelector( | ||
AccessManager.setTargetFunctionRole.selector, validatorTicketProxy, vtDaoSelectors, ROLE_ID_DAO | ||
); | ||
|
||
// Grant PUFETH_BURNER role to ValidatorTicket | ||
calldatas[2] = | ||
abi.encodeWithSelector(AccessManager.grantRole.selector, ROLE_ID_PUFETH_BURNER, validatorTicketProxy, 0); | ||
|
||
bytes memory encodedMulticall = abi.encodeCall(Multicall.multicall, (calldatas)); | ||
return encodedMulticall; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,64 @@ | ||
// SPDX-License-Identifier: GPL-3.0 | ||
pragma solidity >=0.8.0 <0.9.0; | ||
|
||
import "forge-std/Script.sol"; | ||
import { DeployerHelper } from "./DeployerHelper.s.sol"; | ||
import { ValidatorTicket } from "../src/ValidatorTicket.sol"; | ||
import { GenerateValidatorTicketCalldata } from "./AccessManagerMigrations/05_GenerateValidatorTicketCalldata.s.sol"; | ||
import { IPufferOracle } from "../src/interface/IPufferOracle.sol"; | ||
import { AccessManager } from "@openzeppelin/contracts/access/manager/AccessManager.sol"; | ||
|
||
import { UUPSUpgradeable } from "@openzeppelin/contracts/proxy/utils/UUPSUpgradeable.sol"; | ||
|
||
/** | ||
* forge script script/UpgradeValidatorTicket.s.sol:UpgradeValidatorTicket --rpc-url=$RPC_URL --private-key $PK | ||
* add --slow if deploying to a mainnet fork like tenderly | ||
*/ | ||
contract UpgradeValidatorTicket is DeployerHelper { | ||
ValidatorTicket public validatorTicket; | ||
bytes public upgradeCallData; | ||
bytes public accessManagerCallData; | ||
|
||
function run() public { | ||
GenerateValidatorTicketCalldata calldataGenerator = new GenerateValidatorTicketCalldata(); | ||
|
||
vm.startBroadcast(); | ||
|
||
ValidatorTicket validatorTicketImpl = new ValidatorTicket({ | ||
guardianModule: payable(address(_getGuardianModule())), | ||
treasury: payable(_getTreasury()), | ||
pufferVault: payable(_getPufferVault()), | ||
pufferOracle: IPufferOracle(address(_getPufferOracle())) | ||
}); | ||
|
||
validatorTicket = ValidatorTicket(payable(_getValidatorTicket())); | ||
|
||
vm.label(address(validatorTicket), "ValidatorTicketProxy"); | ||
vm.label(address(validatorTicketImpl), "ValidatorTicketImplementation"); | ||
|
||
// Upgrade on mainnet | ||
upgradeCallData = abi.encodeCall(UUPSUpgradeable.upgradeToAndCall, (address(validatorTicketImpl), "")); | ||
console.log("Queue TX From Timelock to -> ValidatorTicketProxy", _getValidatorTicket()); | ||
console.logBytes(upgradeCallData); | ||
console.log("================================================"); | ||
accessManagerCallData = calldataGenerator.run(address(validatorTicket)); | ||
|
||
console.log("Queue from Timelock -> AccessManager", _getAccessManager()); | ||
console.logBytes(accessManagerCallData); | ||
|
||
// If on testnet, upgrade and execute access control changes directly | ||
if (block.chainid == holesky) { | ||
// upgrade to implementation | ||
AccessManager(_getAccessManager()).execute( | ||
address(validatorTicket), | ||
abi.encodeCall(UUPSUpgradeable.upgradeToAndCall, (address(validatorTicketImpl), "")) | ||
); | ||
|
||
// execute access control changes | ||
(bool success,) = address(_getAccessManager()).call(accessManagerCallData); | ||
console.log("AccessManager.call success", success); | ||
require(success, "AccessManager.call failed"); | ||
} | ||
vm.stopBroadcast(); | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.