diff --git a/.github/actions/detect-solidity-file-changes/action.yml b/.github/actions/detect-solidity-file-changes/action.yml
index 37cb871d68d..b86c91dbb4d 100644
--- a/.github/actions/detect-solidity-file-changes/action.yml
+++ b/.github/actions/detect-solidity-file-changes/action.yml
@@ -1,5 +1,5 @@
-name: 'Detect Changes Composite Action'
-description: 'Detects changes in solidity files and fails if read-only files are modified.'
+name: 'Detect Solidity File Changes Composite Action'
+description: 'Detects changes in solidity files and outputs the result.'
outputs:
changes:
description: 'Whether or not changes were detected'
@@ -19,18 +19,3 @@ runs:
- '.github/workflows/solidity.yml'
- '.github/workflows/solidity-foundry.yml'
- '.github/workflows/solidity-wrappers.yml'
- read_only_sol:
- - 'contracts/src/v0.8/interfaces/**/*'
- - 'contracts/src/v0.8/automation/v1_2/**/*'
- - 'contracts/src/v0.8/automation/v1_3/**/*'
- - 'contracts/src/v0.8/automation/v2_0/**/*'
-
- - name: Fail if read-only files have changed
- if: ${{ steps.changed_files.outputs.read_only_sol == 'true' }}
- shell: bash
- run: |
- echo "One or more read-only Solidity file(s) has changed."
- for file in ${{ steps.changed_files.outputs.read_only_sol_files }}; do
- echo "$file was changed"
- done
- exit 1
diff --git a/.github/actions/detect-solidity-readonly-file-changes/action.yml b/.github/actions/detect-solidity-readonly-file-changes/action.yml
new file mode 100644
index 00000000000..faca16d53f0
--- /dev/null
+++ b/.github/actions/detect-solidity-readonly-file-changes/action.yml
@@ -0,0 +1,31 @@
+name: 'Detect Solidity Readonly Files Changes Composite Action'
+description: 'Detects changes in readonly solidity files and fails if they are modified.'
+outputs:
+ changes:
+ description: 'Whether or not changes were detected'
+ value: ${{ steps.changed_files.outputs.src }}
+runs:
+ using: 'composite'
+ steps:
+
+ - name: Filter paths
+ uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2
+ id: changed_files
+ with:
+ list-files: 'csv'
+ filters: |
+ read_only_sol:
+ - 'contracts/src/v0.8/interfaces/**/*'
+ - 'contracts/src/v0.8/automation/v1_2/**/*'
+ - 'contracts/src/v0.8/automation/v1_3/**/*'
+ - 'contracts/src/v0.8/automation/v2_0/**/*'
+
+ - name: Fail if read-only files have changed
+ if: ${{ steps.changed_files.outputs.read_only_sol == 'true' }}
+ shell: bash
+ run: |
+ echo "One or more read-only Solidity file(s) has changed."
+ for file in ${{ steps.changed_files.outputs.read_only_sol_files }}; do
+ echo "$file was changed"
+ done
+ exit 1
diff --git a/.github/workflows/solidity-foundry.yml b/.github/workflows/solidity-foundry.yml
index a7ced0f5653..4ec9e424471 100644
--- a/.github/workflows/solidity-foundry.yml
+++ b/.github/workflows/solidity-foundry.yml
@@ -3,6 +3,8 @@ on: [pull_request]
env:
FOUNDRY_PROFILE: ci
+ # Has to match the `make foundry` version in `contracts/GNUmakefile`
+ FOUNDRY_VERSION: nightly-de33b6af53005037b463318d2628b5cfcaf39916
jobs:
changes:
@@ -27,7 +29,7 @@ jobs:
strategy:
fail-fast: false
matrix:
- product: [automation, functions, keystone, l2ep, llo-feeds, operatorforwarder, shared, vrf]
+ product: [automation, ccip, functions, keystone, l2ep, liquiditymanager, llo-feeds, operatorforwarder, shared, vrf]
needs: [changes]
name: Foundry Tests ${{ matrix.product }}
# See https://github.com/foundry-rs/foundry/issues/3827
@@ -52,8 +54,7 @@ jobs:
if: needs.changes.outputs.changes == 'true'
uses: foundry-rs/foundry-toolchain@8f1998e9878d786675189ef566a2e4bf24869773 # v1.2.0
with:
- # Has to match the `make foundry` version.
- version: nightly-de33b6af53005037b463318d2628b5cfcaf39916
+ version: ${{ env.FOUNDRY_VERSION }}
- name: Run Forge build
if: needs.changes.outputs.changes == 'true'
@@ -77,12 +78,36 @@ jobs:
- name: Run Forge snapshot
if: ${{ !contains(fromJson('["vrf"]'), matrix.product) && !contains(fromJson('["automation"]'), matrix.product) && !contains(fromJson('["keystone"]'), matrix.product) && needs.changes.outputs.changes == 'true' }}
run: |
- forge snapshot --nmt "testFuzz_\w{1,}?" --check gas-snapshots/${{ matrix.product }}.gas-snapshot
+ forge snapshot --nmt "test_?Fuzz_\w{1,}?" --check gas-snapshots/${{ matrix.product }}.gas-snapshot
id: snapshot
working-directory: contracts
env:
FOUNDRY_PROFILE: ${{ matrix.product }}
+ - name: Run coverage
+ if: ${{ contains(fromJson('["ccip"]'), matrix.product) && needs.changes.outputs.changes == 'true' }}
+ working-directory: contracts
+ run: forge coverage --report lcov
+ env:
+ FOUNDRY_PROFILE: ${{ matrix.product }}
+
+ - name: Prune report
+ if: ${{ contains(fromJson('["ccip"]'), matrix.product) && needs.changes.outputs.changes == 'true' }}
+ run: |
+ sudo apt-get install lcov
+ ./contracts/scripts/ccip_lcov_prune ./contracts/lcov.info ./lcov.info.pruned
+
+ - name: Report code coverage
+ if: ${{ contains(fromJson('["ccip"]'), matrix.product) && needs.changes.outputs.changes == 'true' }}
+ uses: zgosalvez/github-actions-report-lcov@a546f89a65a0cdcd82a92ae8d65e74d450ff3fbc # v4.1.4
+ with:
+ update-comment: true
+ coverage-files: lcov.info.pruned
+ minimum-coverage: 98.5
+ artifact-name: code-coverage-report
+ working-directory: ./contracts
+ github-token: ${{ secrets.GITHUB_TOKEN }}
+
- name: Collect Metrics
if: needs.changes.outputs.changes == 'true'
id: collect-gha-metrics
@@ -94,3 +119,55 @@ jobs:
hostname: ${{ secrets.GRAFANA_INTERNAL_HOST }}
this-job-name: Foundry Tests ${{ matrix.product }}
continue-on-error: true
+
+ solidity-forge-fmt:
+ strategy:
+ fail-fast: false
+ matrix:
+ product: [ ccip ]
+ needs: [ changes ]
+ name: Forge fmt ${{ matrix.product }}
+ # See https://github.com/foundry-rs/foundry/issues/3827
+ runs-on: ubuntu-22.04
+
+ # The if statements for steps after checkout repo is workaround for
+ # passing required check for PRs that don't have filtered changes.
+ steps:
+ - name: Checkout the repo
+ uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
+ with:
+ submodules: recursive
+
+ # Only needed because we use the NPM versions of packages
+ # and not native Foundry. This is to make sure the dependencies
+ # stay in sync.
+ - name: Setup NodeJS
+ if: needs.changes.outputs.changes == 'true'
+ uses: ./.github/actions/setup-nodejs
+
+ - name: Install Foundry
+ if: needs.changes.outputs.changes == 'true'
+ uses: foundry-rs/foundry-toolchain@8f1998e9878d786675189ef566a2e4bf24869773 # v1.2.0
+ with:
+ version: ${{ env.FOUNDRY_VERSION }}
+
+ - name: Run Forge fmt
+ if: needs.changes.outputs.changes == 'true'
+ run: |
+ forge fmt --check
+ id: fmt
+ working-directory: contracts
+ env:
+ FOUNDRY_PROFILE: ${{ matrix.product }}
+
+ - name: Collect Metrics
+ if: needs.changes.outputs.changes == 'true'
+ id: collect-gha-metrics
+ uses: smartcontractkit/push-gha-metrics-action@dea9b546553cb4ca936607c2267a09c004e4ab3f # v3.0.0
+ with:
+ id: solidity-forge-fmt
+ org-id: ${{ secrets.GRAFANA_INTERNAL_TENANT_ID }}
+ basic-auth: ${{ secrets.GRAFANA_INTERNAL_BASIC_AUTH }}
+ hostname: ${{ secrets.GRAFANA_INTERNAL_HOST }}
+ this-job-name: Foundry Tests ${{ matrix.product }}
+ continue-on-error: true
diff --git a/.github/workflows/solidity-hardhat.yml b/.github/workflows/solidity-hardhat.yml
index fb6ba6fef43..f28cf499072 100644
--- a/.github/workflows/solidity-hardhat.yml
+++ b/.github/workflows/solidity-hardhat.yml
@@ -25,7 +25,7 @@ jobs:
with:
filters: |
src:
- - 'contracts/src/!(v0.8/(ccip|functions|keystone|l2ep|llo-feeds|transmission|vrf)/**)/**/*'
+ - 'contracts/src/!(v0.8/(ccip|functions|keystone|l2ep|liquiditymanager|llo-feeds|transmission|vrf)/**)/**/*'
- 'contracts/test/**/*'
- 'contracts/package.json'
- 'contracts/pnpm-lock.yaml'
diff --git a/.github/workflows/solidity.yml b/.github/workflows/solidity.yml
index dff35b3cc93..10193bfc2ec 100644
--- a/.github/workflows/solidity.yml
+++ b/.github/workflows/solidity.yml
@@ -9,6 +9,18 @@ defaults:
shell: bash
jobs:
+ readonly_changes:
+ name: Detect readonly solidity file changes
+ runs-on: ubuntu-latest
+ outputs:
+ changes: ${{ steps.ch.outputs.changes }}
+ steps:
+ - name: Checkout the repo
+ uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
+ - name: Detect readonly solidity file changes
+ id: ch
+ uses: ./.github/actions/detect-solidity-readonly-file-changes
+
changes:
name: Detect changes
runs-on: ubuntu-latest
@@ -31,15 +43,15 @@ jobs:
release-version: ${{ steps.release-tag-check.outputs.release-version }}
pre-release-version: ${{ steps.release-tag-check.outputs.pre-release-version }}
steps:
- - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
+ - uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
- name: Check release tag
id: release-tag-check
- uses: smartcontractkit/chainlink-github-actions/release/release-tag-check@2031e56eb4edb8115ce8ba07cbbfb457149d865d # v2.3.8
+ uses: smartcontractkit/chainlink-github-actions/release/release-tag-check@5dd916d08c03cb5f9a97304f4f174820421bb946 # v2.3.11
env:
# Match semver git tags with a "contracts-" prefix.
RELEASE_REGEX: '^contracts-v[0-9]+\.[0-9]+\.[0-9]+$'
PRE_RELEASE_REGEX: '^contracts-v[0-9]+\.[0-9]+\.[0-9]+-(.+)$'
- # Get the version by stripping the "contracts-v" prefix.
+ # Get the version by stripping the "contracts-v" prefix.
VERSION_PREFIX: 'contracts-v'
prepublish-test:
@@ -171,7 +183,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout the repo
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
+ uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
- name: Setup NodeJS
uses: ./.github/actions/setup-nodejs
@@ -211,7 +223,7 @@ jobs:
contents: write
steps:
- name: Checkout the repo
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
+ uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
- name: Setup NodeJS
uses: ./.github/actions/setup-nodejs
diff --git a/LICENSE b/LICENSE
index 1fa3822f510..9723bc8be9a 100644
--- a/LICENSE
+++ b/LICENSE
@@ -1,6 +1,8 @@
-The MIT License (MIT)
+Copyright (c) 2018 SmartContract ChainLink Limited SEZC
+
+Portions of this software are licensed as follows:
-Copyright (c) 2018 SmartContract ChainLink, Ltd.
+The MIT License (MIT)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
@@ -19,3 +21,12 @@ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
+
+
+*All content residing under (1) “/contracts/src/v0.8/ccip”; (2)
+“/core/services/ocr2/plugins/ccip” are licensed under “Business Source
+License 1.1” with a Change Date of May 23, 2027 and Change License to
+ “MIT License”
+
+* Content outside of the above mentioned directories or restrictions
+above is available under the "MIT" license as defined above.
\ No newline at end of file
diff --git a/contracts/.changeset/three-stingrays-compete.md b/contracts/.changeset/three-stingrays-compete.md
new file mode 100644
index 00000000000..613b2784657
--- /dev/null
+++ b/contracts/.changeset/three-stingrays-compete.md
@@ -0,0 +1,5 @@
+---
+'@chainlink/contracts': minor
+---
+
+add ccip contracts to the repo
diff --git a/contracts/.prettierignore b/contracts/.prettierignore
index 7c3131db424..440cf95afa2 100644
--- a/contracts/.prettierignore
+++ b/contracts/.prettierignore
@@ -21,6 +21,7 @@ solc
LinkToken.json
typechain
**/vendor
+src/v0.8/ccip/**
# Ignore TS definition and map files
**/**.d.ts
@@ -35,4 +36,4 @@ venv/
.solhint.json
src/v0.8/mocks/FunctionsOracleEventsMock.sol
-src/v0.8/mocks/FunctionsBillingRegistryEventsMock.sol
\ No newline at end of file
+src/v0.8/mocks/FunctionsBillingRegistryEventsMock.sol
diff --git a/contracts/.prettierrc.js b/contracts/.prettierrc.js
index 774a5e964e8..17662841223 100644
--- a/contracts/.prettierrc.js
+++ b/contracts/.prettierrc.js
@@ -5,6 +5,7 @@ module.exports = {
endOfLine: 'auto',
tabWidth: 2,
trailingComma: 'all',
+ plugins: ['prettier-plugin-solidity'],
overrides: [
{
files: '*.sol',
diff --git a/contracts/.solhintignore b/contracts/.solhintignore
index bab41a57940..bad1935442b 100644
--- a/contracts/.solhintignore
+++ b/contracts/.solhintignore
@@ -1,6 +1,3 @@
-# 344 warnings
-#./src/v0.8/automation
-
# Ignore frozen Automation code
./src/v0.8/automation/v1_2
./src/v0.8/automation/interfaces/v1_2
@@ -39,6 +36,7 @@
./src/v0.8/llo-feeds/test
./src/v0.8/vrf/testhelpers
./src/v0.8/functions/tests
+./src/v0.8/ccip/test
# Always ignore vendor
./src/v0.8/vendor
diff --git a/contracts/GNUmakefile b/contracts/GNUmakefile
index c3e69464698..0ebad8446e5 100644
--- a/contracts/GNUmakefile
+++ b/contracts/GNUmakefile
@@ -1,6 +1,6 @@
# ALL_FOUNDRY_PRODUCTS contains a list of all products that have a foundry
-# profile defined and use the Foundry snapshots.
-ALL_FOUNDRY_PRODUCTS = functions keystone l2ep llo-feeds operatorforwarder shared transmission
+# profile defined and use the Foundry snapshots.
+ALL_FOUNDRY_PRODUCTS = ccip functions keystone l2ep liquiditymanager llo-feeds operatorforwarder shared transmission
# To make a snapshot for a specific product, either set the `FOUNDRY_PROFILE` env var
# or call the target with `FOUNDRY_PROFILE=product`
@@ -16,11 +16,11 @@ ALL_FOUNDRY_PRODUCTS = functions keystone l2ep llo-feeds operatorforwarder share
# a static fuzz seed by default, flaky gas results per platform are still observed.
.PHONY: snapshot
snapshot: ## Make a snapshot for a specific product.
- export FOUNDRY_PROFILE=$(FOUNDRY_PROFILE) && forge snapshot --nmt "testFuzz_\w{1,}?" --snap gas-snapshots/$(FOUNDRY_PROFILE).gas-snapshot
+ export FOUNDRY_PROFILE=$(FOUNDRY_PROFILE) && forge snapshot --nmt "test_?Fuzz_\w{1,}?" --snap gas-snapshots/$(FOUNDRY_PROFILE).gas-snapshot
.PHONY: snapshot-diff
snapshot-diff: ## Make a snapshot for a specific product.
- export FOUNDRY_PROFILE=$(FOUNDRY_PROFILE) && forge snapshot --nmt "testFuzz_\w{1,}?" --diff gas-snapshots/$(FOUNDRY_PROFILE).gas-snapshot
+ export FOUNDRY_PROFILE=$(FOUNDRY_PROFILE) && forge snapshot --nmt "test_?Fuzz_\w{1,}?" --diff gas-snapshots/$(FOUNDRY_PROFILE).gas-snapshot
.PHONY: snapshot-all
@@ -50,6 +50,21 @@ foundry-refresh: foundry
git submodule deinit -f .
git submodule update --init --recursive
+ccip-precommit: export FOUNDRY_PROFILE=ccip
+.PHONY: ccip-precommit
+ccip-precommit:
+ forge test
+ make snapshot
+ forge fmt
+ pnpm solhint
+
+ccip-lcov: export FOUNDRY_PROFILE=ccip
+.PHONY: ccip-lcov
+ccip-lcov:
+ forge coverage --report lcov
+ ../tools/ci/ccip_lcov_prune ./lcov.info ./lcov.info.pruned
+ genhtml -o report lcov.info.pruned --branch-coverage
+
# To generate gethwrappers for a specific product, either set the `FOUNDRY_PROFILE`
# env var or call the target with `FOUNDRY_PROFILE=product`
# This uses FOUNDRY_PROFILE, even though it does support non-foundry products. This
diff --git a/contracts/README.md b/contracts/README.md
index 26b0a823298..182891ceef7 100644
--- a/contracts/README.md
+++ b/contracts/README.md
@@ -67,5 +67,9 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## License
+Most of the contracts are licensed under the [MIT](https://choosealicense.com/licenses/mit/) license.
+An exception to this is the ccip folder, which defaults to be licensed under the [BUSL-1.1](./src/v0.8/ccip/LICENSE.md) license, however, there are a few exceptions
-[MIT](https://choosealicense.com/licenses/mit/)
+- `src/v0.8/ccip/applications/*` is licensed under the [MIT](./src/v0.8/ccip/LICENSE-MIT.md) license
+- `src/v0.8/ccip/interfaces/*` is licensed under the [MIT](./src/v0.8/ccip/LICENSE-MIT.md) license
+- `src/v0.8/ccip/libraries/{Client.sol, Internal.sol}` is licensed under the [MIT](./src/v0.8/ccip/LICENSE-MIT.md) license
\ No newline at end of file
diff --git a/contracts/STYLE_GUIDE.md b/contracts/STYLE_GUIDE.md
index b9294de5765..c5dc20abeab 100644
--- a/contracts/STYLE_GUIDE.md
+++ b/contracts/STYLE_GUIDE.md
@@ -1,7 +1,7 @@
# Structure
-This guide is split into two sections: [Guidelines](#guidelines) and [Rules](#rules).
-Guidelines are recommendations that should be followed but are hard to enforce in an automated way.
+This guide is split into two sections: [Guidelines](#guidelines) and [Rules](#rules).
+Guidelines are recommendations that should be followed but are hard to enforce in an automated way.
Rules are all enforced through CI, this can be through Solhint rules or other tools.
## Background
@@ -76,11 +76,11 @@ uint256 networkFeeUSDCents; // good
struct FeeTokenConfigArgs {
address token; // ────────────╮ Token address
uint32 networkFeeUSD; // │ Flat network fee to charge for messages, multiples of 0.01 USD
- // │ multiline comments should work like this. More fee info
+ // │ multiline comments should work like this. More fee info
uint64 gasMultiplier; // ─────╯ Price multiplier for gas costs, 1e18 based so 11e17 = 10% extra cost
uint64 premiumMultiplier; // ─╮ Multiplier for fee-token-specific premiums
bool enabled; // ─────────────╯ Whether this fee token is enabled
- uint256 fee; // The flat fee the user pays in juels
+ uint256 fee; // The flat fee the user pays in juels
}
```
## Functions
@@ -132,7 +132,7 @@ assembly {
// call and return whether we succeeded. ignore return data
// call(gas,addr,value,argsOffset,argsLength,retOffset,retLength)
success := call(gasLimit, target, 0, add(payload, 0x20), mload(payload), 0, 0)
-
+
// limit our copy to maxReturnBytes bytes
let toCopy := returndatasize()
if gt(toCopy, maxReturnBytes) {
@@ -242,7 +242,7 @@ contract AccessControlledFoo is Foo {
contract OffchainAggregator is ITypeAndVersion {
string public constant override typeAndVersion = "OffchainAggregator 1.0.0";
-
+
function getData() public returns(uint256) {
return 4;
}
@@ -310,8 +310,8 @@ import {IPool} from "../interfaces/pools/IPool.sol";
import {AggregateRateLimiter} from "../AggregateRateLimiter.sol";
import {Client} from "../libraries/Client.sol";
-import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.0/contracts/token/ERC20/utils/SafeERC20.sol";
-import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.0/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
```
## Variables
diff --git a/contracts/foundry.toml b/contracts/foundry.toml
index 08940b4e9ff..c755ba6437b 100644
--- a/contracts/foundry.toml
+++ b/contracts/foundry.toml
@@ -16,6 +16,19 @@ gas_price = 1
block_timestamp = 1234567890
block_number = 12345
+[fmt]
+tab_width = 2
+multiline_func_header = "params_first"
+sort_imports = true
+single_line_statement_blocks = "preserve"
+
+[profile.ccip]
+solc_version = '0.8.24'
+src = 'src/v0.8/ccip'
+test = 'src/v0.8/ccip/test'
+optimizer_runs = 3_600
+evm_version = 'paris'
+
[profile.functions]
solc_version = '0.8.19'
src = 'src/v0.8/functions/dev/v1_X'
@@ -52,6 +65,13 @@ src = 'src/v0.8/llo-feeds'
test = 'src/v0.8/llo-feeds/test'
solc_version = '0.8.19'
+[profile.liquiditymanager]
+optimizer_runs = 1000000
+src = 'src/v0.8/liquiditymanager'
+test = 'src/v0.8/liquiditymanager/test'
+solc_version = '0.8.24'
+evm_version = 'paris'
+
[profile.keystone]
optimizer_runs = 1_000_000
solc_version = '0.8.24'
diff --git a/contracts/gas-snapshots/ccip.gas-snapshot b/contracts/gas-snapshots/ccip.gas-snapshot
new file mode 100644
index 00000000000..5fc99a9a409
--- /dev/null
+++ b/contracts/gas-snapshots/ccip.gas-snapshot
@@ -0,0 +1,943 @@
+ARMProxyStandaloneTest:test_ARMCallEmptyContractRevert() (gas: 19600)
+ARMProxyStandaloneTest:test_Constructor() (gas: 374544)
+ARMProxyStandaloneTest:test_SetARM() (gas: 16494)
+ARMProxyStandaloneTest:test_SetARMzero() (gas: 11216)
+ARMProxyTest:test_ARMCallRevertReasonForwarded() (gas: 47793)
+ARMProxyTest:test_ARMIsBlessed_Success() (gas: 36269)
+ARMProxyTest:test_ARMIsCursed_Success() (gas: 49740)
+AggregateTokenLimiter_constructor:test_Constructor_Success() (gas: 26920)
+AggregateTokenLimiter_getTokenBucket:test_GetTokenBucket_Success() (gas: 19691)
+AggregateTokenLimiter_getTokenBucket:test_Refill_Success() (gas: 40911)
+AggregateTokenLimiter_getTokenBucket:test_TimeUnderflow_Revert() (gas: 15368)
+AggregateTokenLimiter_getTokenLimitAdmin:test_GetTokenLimitAdmin_Success() (gas: 10531)
+AggregateTokenLimiter_getTokenValue:test_GetTokenValue_Success() (gas: 19696)
+AggregateTokenLimiter_getTokenValue:test_NoTokenPrice_Reverts() (gas: 21281)
+AggregateTokenLimiter_rateLimitValue:test_AggregateValueMaxCapacityExceeded_Revert() (gas: 16418)
+AggregateTokenLimiter_rateLimitValue:test_RateLimitValueSuccess_gas() (gas: 18306)
+AggregateTokenLimiter_setAdmin:test_OnlyOwnerOrAdmin_Revert() (gas: 13047)
+AggregateTokenLimiter_setAdmin:test_Owner_Success() (gas: 18989)
+AggregateTokenLimiter_setRateLimiterConfig:test_OnlyOnlyCallableByAdminOrOwner_Revert() (gas: 17479)
+AggregateTokenLimiter_setRateLimiterConfig:test_Owner_Success() (gas: 30062)
+AggregateTokenLimiter_setRateLimiterConfig:test_TokenLimitAdmin_Success() (gas: 32071)
+BurnFromMintTokenPool_lockOrBurn:test_ChainNotAllowed_Revert() (gas: 28675)
+BurnFromMintTokenPool_lockOrBurn:test_PoolBurnRevertNotHealthy_Revert() (gas: 55158)
+BurnFromMintTokenPool_lockOrBurn:test_PoolBurn_Success() (gas: 243525)
+BurnFromMintTokenPool_lockOrBurn:test_Setup_Success() (gas: 23907)
+BurnMintTokenPool_lockOrBurn:test_ChainNotAllowed_Revert() (gas: 27565)
+BurnMintTokenPool_lockOrBurn:test_PoolBurnRevertNotHealthy_Revert() (gas: 55158)
+BurnMintTokenPool_lockOrBurn:test_PoolBurn_Success() (gas: 241416)
+BurnMintTokenPool_lockOrBurn:test_Setup_Success() (gas: 17633)
+BurnMintTokenPool_releaseOrMint:test_ChainNotAllowed_Revert() (gas: 28537)
+BurnMintTokenPool_releaseOrMint:test_PoolMintNotHealthy_Revert() (gas: 55991)
+BurnMintTokenPool_releaseOrMint:test_PoolMint_Success() (gas: 110657)
+BurnWithFromMintTokenPool_lockOrBurn:test_ChainNotAllowed_Revert() (gas: 28675)
+BurnWithFromMintTokenPool_lockOrBurn:test_PoolBurnRevertNotHealthy_Revert() (gas: 55158)
+BurnWithFromMintTokenPool_lockOrBurn:test_PoolBurn_Success() (gas: 243552)
+BurnWithFromMintTokenPool_lockOrBurn:test_Setup_Success() (gas: 24260)
+CCIPClientExample_sanity:test_ImmutableExamples_Success() (gas: 2131281)
+CCIPConfigSetup:test_getCapabilityConfiguration_Success() (gas: 9495)
+CCIPConfig_ConfigStateMachine:test__computeConfigDigest_Success() (gas: 70755)
+CCIPConfig_ConfigStateMachine:test__computeNewConfigWithMeta_InitToRunning_Success() (gas: 363647)
+CCIPConfig_ConfigStateMachine:test__computeNewConfigWithMeta_RunningToStaging_Success() (gas: 488774)
+CCIPConfig_ConfigStateMachine:test__computeNewConfigWithMeta_StagingToRunning_Success() (gas: 453384)
+CCIPConfig_ConfigStateMachine:test__groupByPluginType_TooManyOCR3Configs_Reverts() (gas: 37027)
+CCIPConfig_ConfigStateMachine:test__groupByPluginType_threeCommitConfigs_Reverts() (gas: 61043)
+CCIPConfig_ConfigStateMachine:test__groupByPluginType_threeExecutionConfigs_Reverts() (gas: 60963)
+CCIPConfig_ConfigStateMachine:test__stateFromConfigLength_Success() (gas: 11764)
+CCIPConfig_ConfigStateMachine:test__validateConfigStateTransition_Success() (gas: 8765)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_InitToRunning_Success() (gas: 311991)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_InitToRunning_WrongConfigCount_Reverts() (gas: 49663)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_NonExistentConfigTransition_Reverts() (gas: 32275)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_RunningToStaging_Success() (gas: 376576)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_RunningToStaging_WrongConfigCount_Reverts() (gas: 120943)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_RunningToStaging_WrongConfigDigestBlueGreen_Reverts() (gas: 157105)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_StagingToRunning_Success() (gas: 376352)
+CCIPConfig_ConfigStateMachine:test__validateConfigTransition_StagingToRunning_WrongConfigDigest_Reverts() (gas: 157172)
+CCIPConfig_ConfigStateMachine:test_getCapabilityConfiguration_Success() (gas: 9583)
+CCIPConfig__updatePluginConfig:test__updatePluginConfig_InitToRunning_Success() (gas: 1057393)
+CCIPConfig__updatePluginConfig:test__updatePluginConfig_InvalidConfigLength_Reverts() (gas: 27539)
+CCIPConfig__updatePluginConfig:test__updatePluginConfig_InvalidConfigStateTransition_Reverts() (gas: 23105)
+CCIPConfig__updatePluginConfig:test__updatePluginConfig_RunningToStaging_Success() (gas: 2009309)
+CCIPConfig__updatePluginConfig:test__updatePluginConfig_StagingToRunning_Success() (gas: 2616177)
+CCIPConfig__updatePluginConfig:test_getCapabilityConfiguration_Success() (gas: 9583)
+CCIPConfig_beforeCapabilityConfigSet:test_beforeCapabilityConfigSet_CommitAndExecConfig_Success() (gas: 1851188)
+CCIPConfig_beforeCapabilityConfigSet:test_beforeCapabilityConfigSet_CommitConfigOnly_Success() (gas: 1068362)
+CCIPConfig_beforeCapabilityConfigSet:test_beforeCapabilityConfigSet_ExecConfigOnly_Success() (gas: 1068393)
+CCIPConfig_beforeCapabilityConfigSet:test_beforeCapabilityConfigSet_OnlyCapabilitiesRegistryCanCall_Reverts() (gas: 9599)
+CCIPConfig_beforeCapabilityConfigSet:test_beforeCapabilityConfigSet_ZeroLengthConfig_Success() (gas: 16070)
+CCIPConfig_beforeCapabilityConfigSet:test_getCapabilityConfiguration_Success() (gas: 9583)
+CCIPConfig_chainConfig:test__applyChainConfigUpdates_FChainNotPositive_Reverts() (gas: 184703)
+CCIPConfig_chainConfig:test_applyChainConfigUpdates_addChainConfigs_Success() (gas: 344332)
+CCIPConfig_chainConfig:test_applyChainConfigUpdates_nodeNotInRegistry_Reverts() (gas: 20258)
+CCIPConfig_chainConfig:test_applyChainConfigUpdates_removeChainConfigs_Success() (gas: 267558)
+CCIPConfig_chainConfig:test_applyChainConfigUpdates_selectorNotFound_Reverts() (gas: 14829)
+CCIPConfig_chainConfig:test_getCapabilityConfiguration_Success() (gas: 9626)
+CCIPConfig_validateConfig:test__validateConfig_BootstrapP2PIdsHasDuplicates_Reverts() (gas: 294893)
+CCIPConfig_validateConfig:test__validateConfig_BootstrapP2PIdsNotASubsetOfP2PIds_Reverts() (gas: 298325)
+CCIPConfig_validateConfig:test__validateConfig_BootstrapP2PIdsNotSorted_Reverts() (gas: 295038)
+CCIPConfig_validateConfig:test__validateConfig_ChainSelectorNotFound_Reverts() (gas: 294357)
+CCIPConfig_validateConfig:test__validateConfig_ChainSelectorNotSet_Reverts() (gas: 291431)
+CCIPConfig_validateConfig:test__validateConfig_FMustBePositive_Reverts() (gas: 292396)
+CCIPConfig_validateConfig:test__validateConfig_FTooHigh_Reverts() (gas: 292540)
+CCIPConfig_validateConfig:test__validateConfig_NodeNotInRegistry_Reverts() (gas: 299420)
+CCIPConfig_validateConfig:test__validateConfig_NotEnoughTransmitters_Reverts() (gas: 1160094)
+CCIPConfig_validateConfig:test__validateConfig_OfframpAddressCannotBeZero_Reverts() (gas: 291260)
+CCIPConfig_validateConfig:test__validateConfig_P2PIdsHasDuplicates_Reverts() (gas: 295907)
+CCIPConfig_validateConfig:test__validateConfig_P2PIdsLengthNotMatching_Reverts() (gas: 293229)
+CCIPConfig_validateConfig:test__validateConfig_P2PIdsNotSorted_Reverts() (gas: 295623)
+CCIPConfig_validateConfig:test__validateConfig_Success() (gas: 302186)
+CCIPConfig_validateConfig:test__validateConfig_TooManyBootstrapP2PIds_Reverts() (gas: 294539)
+CCIPConfig_validateConfig:test__validateConfig_TooManySigners_Reverts() (gas: 1215861)
+CCIPConfig_validateConfig:test__validateConfig_TooManyTransmitters_Reverts() (gas: 1214264)
+CCIPConfig_validateConfig:test_getCapabilityConfiguration_Success() (gas: 9562)
+CommitStore_constructor:test_Constructor_Success() (gas: 3091326)
+CommitStore_isUnpausedAndRMNHealthy:test_RMN_Success() (gas: 73420)
+CommitStore_report:test_InvalidIntervalMinLargerThanMax_Revert() (gas: 28670)
+CommitStore_report:test_InvalidInterval_Revert() (gas: 28610)
+CommitStore_report:test_InvalidRootRevert() (gas: 27843)
+CommitStore_report:test_OnlyGasPriceUpdates_Success() (gas: 53253)
+CommitStore_report:test_OnlyPriceUpdateStaleReport_Revert() (gas: 59049)
+CommitStore_report:test_OnlyTokenPriceUpdates_Success() (gas: 53251)
+CommitStore_report:test_Paused_Revert() (gas: 21259)
+CommitStore_report:test_ReportAndPriceUpdate_Success() (gas: 84242)
+CommitStore_report:test_ReportOnlyRootSuccess_gas() (gas: 56313)
+CommitStore_report:test_RootAlreadyCommitted_Revert() (gas: 63969)
+CommitStore_report:test_StaleReportWithRoot_Success() (gas: 119420)
+CommitStore_report:test_Unhealthy_Revert() (gas: 44751)
+CommitStore_report:test_ValidPriceUpdateThenStaleReportWithRoot_Success() (gas: 100758)
+CommitStore_report:test_ZeroEpochAndRound_Revert() (gas: 27626)
+CommitStore_resetUnblessedRoots:test_OnlyOwner_Revert() (gas: 11325)
+CommitStore_resetUnblessedRoots:test_ResetUnblessedRoots_Success() (gas: 143718)
+CommitStore_setDynamicConfig:test_InvalidCommitStoreConfig_Revert() (gas: 37263)
+CommitStore_setDynamicConfig:test_OnlyOwner_Revert() (gas: 37399)
+CommitStore_setDynamicConfig:test_PriceEpochCleared_Success() (gas: 129098)
+CommitStore_setLatestPriceEpochAndRound:test_OnlyOwner_Revert() (gas: 11047)
+CommitStore_setLatestPriceEpochAndRound:test_SetLatestPriceEpochAndRound_Success() (gas: 20642)
+CommitStore_setMinSeqNr:test_OnlyOwner_Revert() (gas: 11046)
+CommitStore_verify:test_Blessed_Success() (gas: 96389)
+CommitStore_verify:test_NotBlessed_Success() (gas: 61374)
+CommitStore_verify:test_Paused_Revert() (gas: 18496)
+CommitStore_verify:test_TooManyLeaves_Revert() (gas: 36785)
+DefensiveExampleTest:test_HappyPath_Success() (gas: 200018)
+DefensiveExampleTest:test_Recovery() (gas: 424253)
+E2E:test_E2E_3MessagesSuccess_gas() (gas: 1103438)
+EVM2EVMMultiOffRamp__releaseOrMintSingleToken:test__releaseOrMintSingleToken_NotACompatiblePool_Revert() (gas: 38157)
+EVM2EVMMultiOffRamp__releaseOrMintSingleToken:test__releaseOrMintSingleToken_Success() (gas: 108343)
+EVM2EVMMultiOffRamp__releaseOrMintSingleToken:test__releaseOrMintSingleToken_TokenHandlingError_revert_Revert() (gas: 116811)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_AddMultipleChains_Success() (gas: 460560)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_AddNewChain_Success() (gas: 95542)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_ApplyZeroUpdates_Success() (gas: 12463)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_ReplaceExistingChainOnRamp_Revert() (gas: 90385)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_ReplaceExistingChain_Success() (gas: 105586)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_ZeroOnRampAddress_Revert() (gas: 15719)
+EVM2EVMMultiOffRamp_applySourceChainConfigUpdates:test_ZeroSourceChainSelector_Revert() (gas: 13057)
+EVM2EVMMultiOffRamp_batchExecute:test_MultipleReportsDifferentChains_Success() (gas: 298564)
+EVM2EVMMultiOffRamp_batchExecute:test_MultipleReportsSameChain_Success() (gas: 239899)
+EVM2EVMMultiOffRamp_batchExecute:test_MultipleReportsSkipDuplicate_Success() (gas: 158863)
+EVM2EVMMultiOffRamp_batchExecute:test_OutOfBoundsGasLimitsAccess_Revert() (gas: 189303)
+EVM2EVMMultiOffRamp_batchExecute:test_SingleReport_Success() (gas: 147582)
+EVM2EVMMultiOffRamp_batchExecute:test_Unhealthy_Revert() (gas: 521508)
+EVM2EVMMultiOffRamp_batchExecute:test_ZeroReports_Revert() (gas: 10459)
+EVM2EVMMultiOffRamp_ccipReceive:test_Reverts() (gas: 15662)
+EVM2EVMMultiOffRamp_commit:test_InvalidIntervalMinLargerThanMax_Revert() (gas: 67195)
+EVM2EVMMultiOffRamp_commit:test_InvalidInterval_Revert() (gas: 59698)
+EVM2EVMMultiOffRamp_commit:test_InvalidRootRevert() (gas: 58778)
+EVM2EVMMultiOffRamp_commit:test_NoConfigWithOtherConfigPresent_Revert() (gas: 6394741)
+EVM2EVMMultiOffRamp_commit:test_NoConfig_Revert() (gas: 5977968)
+EVM2EVMMultiOffRamp_commit:test_OnlyGasPriceUpdates_Success() (gas: 106229)
+EVM2EVMMultiOffRamp_commit:test_OnlyPriceUpdateStaleReport_Revert() (gas: 116228)
+EVM2EVMMultiOffRamp_commit:test_OnlyTokenPriceUpdates_Success() (gas: 106272)
+EVM2EVMMultiOffRamp_commit:test_PriceSequenceNumberCleared_Success() (gas: 351414)
+EVM2EVMMultiOffRamp_commit:test_ReportAndPriceUpdate_Success() (gas: 159132)
+EVM2EVMMultiOffRamp_commit:test_ReportOnlyRootSuccess_gas() (gas: 136253)
+EVM2EVMMultiOffRamp_commit:test_RootAlreadyCommitted_Revert() (gas: 136831)
+EVM2EVMMultiOffRamp_commit:test_SourceChainNotEnabled_Revert() (gas: 59046)
+EVM2EVMMultiOffRamp_commit:test_StaleReportWithRoot_Success() (gas: 227807)
+EVM2EVMMultiOffRamp_commit:test_UnauthorizedTransmitter_Revert() (gas: 117527)
+EVM2EVMMultiOffRamp_commit:test_Unhealthy_Revert() (gas: 77605)
+EVM2EVMMultiOffRamp_commit:test_ValidPriceUpdateThenStaleReportWithRoot_Success() (gas: 207057)
+EVM2EVMMultiOffRamp_commit:test_WrongConfigWithoutSigners_Revert() (gas: 6389130)
+EVM2EVMMultiOffRamp_commit:test_ZeroEpochAndRound_Revert() (gas: 47785)
+EVM2EVMMultiOffRamp_constructor:test_Constructor_Success() (gas: 5981174)
+EVM2EVMMultiOffRamp_constructor:test_SourceChainSelector_Revert() (gas: 157326)
+EVM2EVMMultiOffRamp_constructor:test_ZeroChainSelector_Revert() (gas: 103815)
+EVM2EVMMultiOffRamp_constructor:test_ZeroNonceManager_Revert() (gas: 101686)
+EVM2EVMMultiOffRamp_constructor:test_ZeroOnRampAddress_Revert() (gas: 159832)
+EVM2EVMMultiOffRamp_constructor:test_ZeroRMNProxy_Revert() (gas: 101585)
+EVM2EVMMultiOffRamp_constructor:test_ZeroTokenAdminRegistry_Revert() (gas: 101652)
+EVM2EVMMultiOffRamp_execute:test_IncorrectArrayType_Revert() (gas: 17280)
+EVM2EVMMultiOffRamp_execute:test_LargeBatch_Success() (gas: 1559406)
+EVM2EVMMultiOffRamp_execute:test_MultipleReportsWithPartialValidationFailures_Success() (gas: 342924)
+EVM2EVMMultiOffRamp_execute:test_MultipleReports_Success() (gas: 260178)
+EVM2EVMMultiOffRamp_execute:test_NoConfigWithOtherConfigPresent_Revert() (gas: 6445247)
+EVM2EVMMultiOffRamp_execute:test_NoConfig_Revert() (gas: 6028193)
+EVM2EVMMultiOffRamp_execute:test_NonArray_Revert() (gas: 27681)
+EVM2EVMMultiOffRamp_execute:test_SingleReport_Success() (gas: 165181)
+EVM2EVMMultiOffRamp_execute:test_UnauthorizedTransmitter_Revert() (gas: 149137)
+EVM2EVMMultiOffRamp_execute:test_WrongConfigWithSigners_Revert() (gas: 6807322)
+EVM2EVMMultiOffRamp_execute:test_ZeroReports_Revert() (gas: 17154)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_MessageSender_Revert() (gas: 18413)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_NonContractWithTokens_Success() (gas: 249368)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_NonContract_Success() (gas: 20672)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_TokenHandlingError_Revert() (gas: 201673)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_ZeroGasDONExecution_Revert() (gas: 48860)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_executeSingleMessage_NoTokens_Success() (gas: 48381)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_executeSingleMessage_WithFailingValidationNoRouterCall_Revert() (gas: 232798)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_executeSingleMessage_WithFailingValidation_Revert() (gas: 89392)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_executeSingleMessage_WithTokens_Success() (gas: 278146)
+EVM2EVMMultiOffRamp_executeSingleMessage:test_executeSingleMessage_WithValidation_Success() (gas: 93615)
+EVM2EVMMultiOffRamp_executeSingleReport:test_DisabledSourceChain_Revert() (gas: 35083)
+EVM2EVMMultiOffRamp_executeSingleReport:test_EmptyReport_Revert() (gas: 23907)
+EVM2EVMMultiOffRamp_executeSingleReport:test_InvalidSourcePoolAddress_Success() (gas: 451358)
+EVM2EVMMultiOffRamp_executeSingleReport:test_ManualExecutionNotYetEnabled_Revert() (gas: 54475)
+EVM2EVMMultiOffRamp_executeSingleReport:test_MismatchingDestChainSelector_Revert() (gas: 35917)
+EVM2EVMMultiOffRamp_executeSingleReport:test_MismatchingOnRampRoot_Revert() (gas: 154369)
+EVM2EVMMultiOffRamp_executeSingleReport:test_NonExistingSourceChain_Revert() (gas: 35317)
+EVM2EVMMultiOffRamp_executeSingleReport:test_ReceiverError_Success() (gas: 181353)
+EVM2EVMMultiOffRamp_executeSingleReport:test_RetryFailedMessageWithoutManualExecution_Revert() (gas: 190627)
+EVM2EVMMultiOffRamp_executeSingleReport:test_RootNotCommitted_Revert() (gas: 48053)
+EVM2EVMMultiOffRamp_executeSingleReport:test_RouterYULCall_Revert() (gas: 443030)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SingleMessageNoTokensOtherChain_Success() (gas: 251770)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SingleMessageNoTokensUnordered_Success() (gas: 173962)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SingleMessageNoTokens_Success() (gas: 193657)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SingleMessageToNonCCIPReceiver_Success() (gas: 259648)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SingleMessagesNoTokensSuccess_gas() (gas: 129585)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SkippedIncorrectNonceStillExecutes_Success() (gas: 391710)
+EVM2EVMMultiOffRamp_executeSingleReport:test_SkippedIncorrectNonce_Success() (gas: 65899)
+EVM2EVMMultiOffRamp_executeSingleReport:test_TokenDataMismatch_Revert() (gas: 80955)
+EVM2EVMMultiOffRamp_executeSingleReport:test_TwoMessagesWithTokensAndGE_Success() (gas: 535429)
+EVM2EVMMultiOffRamp_executeSingleReport:test_TwoMessagesWithTokensSuccess_gas() (gas: 480345)
+EVM2EVMMultiOffRamp_executeSingleReport:test_UnexpectedTokenData_Revert() (gas: 35763)
+EVM2EVMMultiOffRamp_executeSingleReport:test_UnhealthySingleChainCurse_Revert() (gas: 520344)
+EVM2EVMMultiOffRamp_executeSingleReport:test_Unhealthy_Revert() (gas: 517712)
+EVM2EVMMultiOffRamp_executeSingleReport:test_WithCurseOnAnotherSourceChain_Success() (gas: 487848)
+EVM2EVMMultiOffRamp_executeSingleReport:test__execute_SkippedAlreadyExecutedMessageUnordered_Success() (gas: 127921)
+EVM2EVMMultiOffRamp_executeSingleReport:test__execute_SkippedAlreadyExecutedMessage_Success() (gas: 157144)
+EVM2EVMMultiOffRamp_getExecutionState:test_FillExecutionState_Success() (gas: 3655340)
+EVM2EVMMultiOffRamp_getExecutionState:test_GetDifferentChainExecutionState_Success() (gas: 118224)
+EVM2EVMMultiOffRamp_getExecutionState:test_GetExecutionState_Success() (gas: 87461)
+EVM2EVMMultiOffRamp_manuallyExecute:test_ManualExecGasLimitMismatchSingleReport_Revert() (gas: 75600)
+EVM2EVMMultiOffRamp_manuallyExecute:test_ManualExecInvalidGasLimit_Revert() (gas: 26461)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_DoesNotRevertIfUntouched_Success() (gas: 163081)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_FailedTx_Revert() (gas: 207379)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_ForkedChain_Revert() (gas: 26004)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_GasLimitMismatchMultipleReports_Revert() (gas: 152867)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_LowGasLimit_Success() (gas: 507480)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_ReentrancyFails() (gas: 2307925)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_Success() (gas: 209633)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_WithGasOverride_Success() (gas: 210210)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_WithMultiReportGasOverride_Success() (gas: 668610)
+EVM2EVMMultiOffRamp_manuallyExecute:test_manuallyExecute_WithPartialMessages_Success() (gas: 299477)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test_TokenHandlingError_Reverts() (gas: 160598)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test__releaseOrMintTokens_PoolIsNotAPool_Reverts() (gas: 24131)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test_releaseOrMintTokens_InvalidDataLengthReturnData_Revert() (gas: 59105)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test_releaseOrMintTokens_InvalidEVMAddress_Revert() (gas: 40405)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test_releaseOrMintTokens_PoolDoesNotSupportDest_Reverts() (gas: 76130)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test_releaseOrMintTokens_Success() (gas: 178951)
+EVM2EVMMultiOffRamp_releaseOrMintTokens:test_releaseOrMintTokens_destDenominatedDecimals_Success() (gas: 278805)
+EVM2EVMMultiOffRamp_resetUnblessedRoots:test_OnlyOwner_Revert() (gas: 11379)
+EVM2EVMMultiOffRamp_resetUnblessedRoots:test_ResetUnblessedRoots_Success() (gas: 215406)
+EVM2EVMMultiOffRamp_setDynamicConfig:test_NonOwner_Revert() (gas: 14374)
+EVM2EVMMultiOffRamp_setDynamicConfig:test_PriceRegistryZeroAddress_Revert() (gas: 11898)
+EVM2EVMMultiOffRamp_setDynamicConfig:test_RouterZeroAddress_Revert() (gas: 14054)
+EVM2EVMMultiOffRamp_setDynamicConfig:test_SetDynamicConfigWithValidator_Success() (gas: 55771)
+EVM2EVMMultiOffRamp_setDynamicConfig:test_SetDynamicConfig_Success() (gas: 33781)
+EVM2EVMMultiOffRamp_trialExecute:test_RateLimitError_Success() (gas: 238004)
+EVM2EVMMultiOffRamp_trialExecute:test_TokenHandlingErrorIsCaught_Success() (gas: 246667)
+EVM2EVMMultiOffRamp_trialExecute:test_TokenPoolIsNotAContract_Success() (gas: 299499)
+EVM2EVMMultiOffRamp_trialExecute:test_trialExecute_Success() (gas: 280579)
+EVM2EVMMultiOffRamp_verify:test_Blessed_Success() (gas: 176604)
+EVM2EVMMultiOffRamp_verify:test_NotBlessedWrongChainSelector_Success() (gas: 178672)
+EVM2EVMMultiOffRamp_verify:test_NotBlessed_Success() (gas: 141533)
+EVM2EVMMultiOffRamp_verify:test_TooManyLeaves_Revert() (gas: 51508)
+EVM2EVMMultiOnRamp_constructor:test_Constructor_InvalidConfigChainSelectorEqZero_Revert() (gas: 94528)
+EVM2EVMMultiOnRamp_constructor:test_Constructor_InvalidConfigNonceManagerEqAddressZero_Revert() (gas: 92480)
+EVM2EVMMultiOnRamp_constructor:test_Constructor_InvalidConfigRMNProxyEqAddressZero_Revert() (gas: 97483)
+EVM2EVMMultiOnRamp_constructor:test_Constructor_InvalidConfigTokenAdminRegistryEqAddressZero_Revert() (gas: 92538)
+EVM2EVMMultiOnRamp_constructor:test_Constructor_Success() (gas: 2260144)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_CannotSendZeroTokens_Revert() (gas: 90987)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ForwardFromRouterExtraArgsV2AllowOutOfOrderTrue_Success() (gas: 130983)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ForwardFromRouterExtraArgsV2_Success() (gas: 161753)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ForwardFromRouterSuccessCustomExtraArgs() (gas: 161306)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ForwardFromRouterSuccessEmptyExtraArgs() (gas: 159506)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ForwardFromRouterSuccessLegacyExtraArgs() (gas: 161536)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ForwardFromRouter_Success() (gas: 160928)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_InvalidExtraArgsTag_Revert() (gas: 26206)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_MessageValidationError_Revert() (gas: 134082)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_MesssageFeeTooHigh_Revert() (gas: 24272)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_OriginalSender_Revert() (gas: 12819)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_Paused_Revert() (gas: 30695)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_Permissions_Revert() (gas: 15675)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ShouldIncrementNonceOnlyOnOrdered_Success() (gas: 198276)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ShouldIncrementSeqNumAndNonce_Success() (gas: 224545)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ShouldStoreLinkFees() (gas: 140840)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_ShouldStoreNonLinkFees() (gas: 162262)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_SourceTokenDataTooLarge_Revert() (gas: 3803257)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_UnsupportedToken_Revert() (gas: 127615)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_forwardFromRouter_UnsupportedToken_Revert() (gas: 93044)
+EVM2EVMMultiOnRamp_forwardFromRouter:test_forwardFromRouter_WithValidation_Success() (gas: 282576)
+EVM2EVMMultiOnRamp_getFee:test_EmptyMessage_Success() (gas: 104423)
+EVM2EVMMultiOnRamp_getFee:test_EnforceOutOfOrder_Revert() (gas: 74041)
+EVM2EVMMultiOnRamp_getFee:test_SingleTokenMessage_Success() (gas: 119755)
+EVM2EVMMultiOnRamp_getFee:test_Unhealthy_Revert() (gas: 43657)
+EVM2EVMMultiOnRamp_getSupportedTokens:test_GetSupportedTokens_Revert() (gas: 10438)
+EVM2EVMMultiOnRamp_getTokenPool:test_GetTokenPool_Success() (gas: 35204)
+EVM2EVMMultiOnRamp_setDynamicConfig:test_SetConfigInvalidConfigFeeAggregatorEqAddressZero_Revert() (gas: 11356)
+EVM2EVMMultiOnRamp_setDynamicConfig:test_SetConfigInvalidConfigPriceRegistryEqAddressZero_Revert() (gas: 12956)
+EVM2EVMMultiOnRamp_setDynamicConfig:test_SetConfigInvalidConfig_Revert() (gas: 11313)
+EVM2EVMMultiOnRamp_setDynamicConfig:test_SetConfigOnlyOwner_Revert() (gas: 16287)
+EVM2EVMMultiOnRamp_setDynamicConfig:test_SetDynamicConfig_Success() (gas: 58439)
+EVM2EVMMultiOnRamp_withdrawFeeTokens:test_WithdrawFeeTokens_Success() (gas: 97185)
+EVM2EVMOffRamp__releaseOrMintToken:test__releaseOrMintToken_NotACompatiblePool_Revert() (gas: 38028)
+EVM2EVMOffRamp__releaseOrMintToken:test__releaseOrMintToken_Success() (gas: 108191)
+EVM2EVMOffRamp__releaseOrMintToken:test__releaseOrMintToken_TokenHandlingError_revert_Revert() (gas: 116732)
+EVM2EVMOffRamp__releaseOrMintTokens:test_OverValueWithARLOff_Success() (gas: 391880)
+EVM2EVMOffRamp__releaseOrMintTokens:test_PriceNotFoundForToken_Reverts() (gas: 145379)
+EVM2EVMOffRamp__releaseOrMintTokens:test_RateLimitErrors_Reverts() (gas: 788000)
+EVM2EVMOffRamp__releaseOrMintTokens:test_TokenHandlingError_Reverts() (gas: 176208)
+EVM2EVMOffRamp__releaseOrMintTokens:test__releaseOrMintTokens_NotACompatiblePool_Reverts() (gas: 29700)
+EVM2EVMOffRamp__releaseOrMintTokens:test_releaseOrMintTokens_InvalidDataLengthReturnData_Revert() (gas: 63325)
+EVM2EVMOffRamp__releaseOrMintTokens:test_releaseOrMintTokens_InvalidEVMAddress_Revert() (gas: 44501)
+EVM2EVMOffRamp__releaseOrMintTokens:test_releaseOrMintTokens_Success() (gas: 214151)
+EVM2EVMOffRamp__releaseOrMintTokens:test_releaseOrMintTokens_destDenominatedDecimals_Success() (gas: 306912)
+EVM2EVMOffRamp__report:test_Report_Success() (gas: 127459)
+EVM2EVMOffRamp__trialExecute:test_RateLimitError_Success() (gas: 255047)
+EVM2EVMOffRamp__trialExecute:test_TokenHandlingErrorIsCaught_Success() (gas: 263638)
+EVM2EVMOffRamp__trialExecute:test_TokenPoolIsNotAContract_Success() (gas: 335707)
+EVM2EVMOffRamp__trialExecute:test_trialExecute_Success() (gas: 314443)
+EVM2EVMOffRamp_ccipReceive:test_Reverts() (gas: 17009)
+EVM2EVMOffRamp_constructor:test_CommitStoreAlreadyInUse_Revert() (gas: 153427)
+EVM2EVMOffRamp_constructor:test_Constructor_Success() (gas: 5464875)
+EVM2EVMOffRamp_constructor:test_ZeroOnRampAddress_Revert() (gas: 144183)
+EVM2EVMOffRamp_execute:test_EmptyReport_Revert() (gas: 21345)
+EVM2EVMOffRamp_execute:test_InvalidMessageId_Revert() (gas: 36442)
+EVM2EVMOffRamp_execute:test_InvalidSourceChain_Revert() (gas: 51701)
+EVM2EVMOffRamp_execute:test_InvalidSourcePoolAddress_Success() (gas: 473575)
+EVM2EVMOffRamp_execute:test_ManualExecutionNotYetEnabled_Revert() (gas: 46423)
+EVM2EVMOffRamp_execute:test_MessageTooLarge_Revert() (gas: 152453)
+EVM2EVMOffRamp_execute:test_Paused_Revert() (gas: 101458)
+EVM2EVMOffRamp_execute:test_ReceiverError_Success() (gas: 165036)
+EVM2EVMOffRamp_execute:test_RetryFailedMessageWithoutManualExecution_Revert() (gas: 177824)
+EVM2EVMOffRamp_execute:test_RootNotCommitted_Revert() (gas: 41317)
+EVM2EVMOffRamp_execute:test_RouterYULCall_Revert() (gas: 402506)
+EVM2EVMOffRamp_execute:test_SingleMessageNoTokensUnordered_Success() (gas: 159387)
+EVM2EVMOffRamp_execute:test_SingleMessageNoTokens_Success() (gas: 174622)
+EVM2EVMOffRamp_execute:test_SingleMessageToNonCCIPReceiver_Success() (gas: 248634)
+EVM2EVMOffRamp_execute:test_SingleMessagesNoTokensSuccess_gas() (gas: 115017)
+EVM2EVMOffRamp_execute:test_SkippedIncorrectNonceStillExecutes_Success() (gas: 409338)
+EVM2EVMOffRamp_execute:test_SkippedIncorrectNonce_Success() (gas: 54173)
+EVM2EVMOffRamp_execute:test_StrictUntouchedToSuccess_Success() (gas: 132056)
+EVM2EVMOffRamp_execute:test_TokenDataMismatch_Revert() (gas: 52200)
+EVM2EVMOffRamp_execute:test_TwoMessagesWithTokensAndGE_Success() (gas: 560178)
+EVM2EVMOffRamp_execute:test_TwoMessagesWithTokensSuccess_gas() (gas: 499424)
+EVM2EVMOffRamp_execute:test_UnexpectedTokenData_Revert() (gas: 35442)
+EVM2EVMOffRamp_execute:test_Unhealthy_Revert() (gas: 546987)
+EVM2EVMOffRamp_execute:test_UnsupportedNumberOfTokens_Revert() (gas: 64045)
+EVM2EVMOffRamp_execute:test__execute_SkippedAlreadyExecutedMessageUnordered_Success() (gas: 123223)
+EVM2EVMOffRamp_execute:test__execute_SkippedAlreadyExecutedMessage_Success() (gas: 143388)
+EVM2EVMOffRamp_executeSingleMessage:test_MessageSender_Revert() (gas: 20582)
+EVM2EVMOffRamp_executeSingleMessage:test_NonContractWithTokens_Success() (gas: 281891)
+EVM2EVMOffRamp_executeSingleMessage:test_NonContract_Success() (gas: 20231)
+EVM2EVMOffRamp_executeSingleMessage:test_TokenHandlingError_Revert() (gas: 219228)
+EVM2EVMOffRamp_executeSingleMessage:test_ZeroGasDONExecution_Revert() (gas: 48632)
+EVM2EVMOffRamp_executeSingleMessage:test_executeSingleMessage_NoTokens_Success() (gas: 48120)
+EVM2EVMOffRamp_executeSingleMessage:test_executeSingleMessage_WithTokens_Success() (gas: 316477)
+EVM2EVMOffRamp_executeSingleMessage:test_executeSingleMessage_ZeroGasZeroData_Success() (gas: 72423)
+EVM2EVMOffRamp_execute_upgrade:test_V2NonceNewSenderStartsAtZero_Success() (gas: 231326)
+EVM2EVMOffRamp_execute_upgrade:test_V2NonceStartsAtV1Nonce_Success() (gas: 279867)
+EVM2EVMOffRamp_execute_upgrade:test_V2OffRampNonceSkipsIfMsgInFlight_Success() (gas: 261109)
+EVM2EVMOffRamp_execute_upgrade:test_V2SenderNoncesReadsPreviousRamp_Success() (gas: 229397)
+EVM2EVMOffRamp_execute_upgrade:test_V2_Success() (gas: 131682)
+EVM2EVMOffRamp_getAllRateLimitTokens:test_GetAllRateLimitTokens_Success() (gas: 38408)
+EVM2EVMOffRamp_getExecutionState:test_FillExecutionState_Success() (gas: 3213556)
+EVM2EVMOffRamp_getExecutionState:test_GetExecutionState_Success() (gas: 83091)
+EVM2EVMOffRamp_manuallyExecute:test_LowGasLimitManualExec_Success() (gas: 483328)
+EVM2EVMOffRamp_manuallyExecute:test_ManualExecFailedTx_Revert() (gas: 186413)
+EVM2EVMOffRamp_manuallyExecute:test_ManualExecForkedChain_Revert() (gas: 25824)
+EVM2EVMOffRamp_manuallyExecute:test_ManualExecGasLimitMismatch_Revert() (gas: 43449)
+EVM2EVMOffRamp_manuallyExecute:test_ManualExecInvalidGasLimit_Revert() (gas: 25927)
+EVM2EVMOffRamp_manuallyExecute:test_ManualExecWithGasOverride_Success() (gas: 188518)
+EVM2EVMOffRamp_manuallyExecute:test_ManualExec_Success() (gas: 187965)
+EVM2EVMOffRamp_manuallyExecute:test_ReentrancyManualExecuteFails() (gas: 2027441)
+EVM2EVMOffRamp_manuallyExecute:test_manuallyExecute_DoesNotRevertIfUntouched_Success() (gas: 143803)
+EVM2EVMOffRamp_metadataHash:test_MetadataHash_Success() (gas: 8871)
+EVM2EVMOffRamp_setDynamicConfig:test_NonOwner_Revert() (gas: 40429)
+EVM2EVMOffRamp_setDynamicConfig:test_RouterZeroAddress_Revert() (gas: 38804)
+EVM2EVMOffRamp_setDynamicConfig:test_SetDynamicConfig_Success() (gas: 146790)
+EVM2EVMOffRamp_updateRateLimitTokens:test_updateRateLimitTokens_AddsAndRemoves_Success() (gas: 162464)
+EVM2EVMOffRamp_updateRateLimitTokens:test_updateRateLimitTokens_NonOwner_Revert() (gas: 16667)
+EVM2EVMOffRamp_updateRateLimitTokens:test_updateRateLimitTokens_Success() (gas: 197660)
+EVM2EVMOnRamp_constructor:test_Constructor_Success() (gas: 5619710)
+EVM2EVMOnRamp_forwardFromRouter:test_CannotSendZeroTokens_Revert() (gas: 35778)
+EVM2EVMOnRamp_forwardFromRouter:test_EnforceOutOfOrder_Revert() (gas: 99470)
+EVM2EVMOnRamp_forwardFromRouter:test_ForwardFromRouterExtraArgsV2AllowOutOfOrderTrue_Success() (gas: 114210)
+EVM2EVMOnRamp_forwardFromRouter:test_ForwardFromRouterExtraArgsV2_Success() (gas: 114252)
+EVM2EVMOnRamp_forwardFromRouter:test_ForwardFromRouterSuccessCustomExtraArgs() (gas: 130118)
+EVM2EVMOnRamp_forwardFromRouter:test_ForwardFromRouterSuccessLegacyExtraArgs() (gas: 138650)
+EVM2EVMOnRamp_forwardFromRouter:test_ForwardFromRouter_Success() (gas: 129804)
+EVM2EVMOnRamp_forwardFromRouter:test_InvalidAddressEncodePacked_Revert() (gas: 38254)
+EVM2EVMOnRamp_forwardFromRouter:test_InvalidAddress_Revert() (gas: 38370)
+EVM2EVMOnRamp_forwardFromRouter:test_InvalidChainSelector_Revert() (gas: 25511)
+EVM2EVMOnRamp_forwardFromRouter:test_InvalidExtraArgsTag_Revert() (gas: 25297)
+EVM2EVMOnRamp_forwardFromRouter:test_MaxCapacityExceeded_Revert() (gas: 86041)
+EVM2EVMOnRamp_forwardFromRouter:test_MaxFeeBalanceReached_Revert() (gas: 36457)
+EVM2EVMOnRamp_forwardFromRouter:test_MessageGasLimitTooHigh_Revert() (gas: 29037)
+EVM2EVMOnRamp_forwardFromRouter:test_MessageTooLarge_Revert() (gas: 107526)
+EVM2EVMOnRamp_forwardFromRouter:test_OriginalSender_Revert() (gas: 22635)
+EVM2EVMOnRamp_forwardFromRouter:test_OverValueWithARLOff_Success() (gas: 223665)
+EVM2EVMOnRamp_forwardFromRouter:test_Paused_Revert() (gas: 53935)
+EVM2EVMOnRamp_forwardFromRouter:test_Permissions_Revert() (gas: 25481)
+EVM2EVMOnRamp_forwardFromRouter:test_PriceNotFoundForToken_Revert() (gas: 59303)
+EVM2EVMOnRamp_forwardFromRouter:test_ShouldIncrementNonceOnlyOnOrdered_Success() (gas: 179141)
+EVM2EVMOnRamp_forwardFromRouter:test_ShouldIncrementSeqNumAndNonce_Success() (gas: 177355)
+EVM2EVMOnRamp_forwardFromRouter:test_ShouldStoreNonLinkFees() (gas: 137297)
+EVM2EVMOnRamp_forwardFromRouter:test_SourceTokenDataTooLarge_Revert() (gas: 3731767)
+EVM2EVMOnRamp_forwardFromRouter:test_TooManyTokens_Revert() (gas: 30187)
+EVM2EVMOnRamp_forwardFromRouter:test_Unhealthy_Revert() (gas: 43300)
+EVM2EVMOnRamp_forwardFromRouter:test_UnsupportedToken_Revert() (gas: 109258)
+EVM2EVMOnRamp_forwardFromRouter:test_ZeroAddressReceiver_Revert() (gas: 312351)
+EVM2EVMOnRamp_forwardFromRouter:test_forwardFromRouter_ShouldStoreLinkFees_Success() (gas: 112319)
+EVM2EVMOnRamp_forwardFromRouter:test_forwardFromRouter_UnsupportedToken_Revert() (gas: 72181)
+EVM2EVMOnRamp_forwardFromRouter_upgrade:test_V2NonceNewSenderStartsAtZero_Success() (gas: 147614)
+EVM2EVMOnRamp_forwardFromRouter_upgrade:test_V2NonceStartsAtV1Nonce_Success() (gas: 190454)
+EVM2EVMOnRamp_forwardFromRouter_upgrade:test_V2SenderNoncesReadsPreviousRamp_Success() (gas: 121245)
+EVM2EVMOnRamp_forwardFromRouter_upgrade:test_V2_Success() (gas: 95324)
+EVM2EVMOnRamp_getDataAvailabilityCost:test_EmptyMessageCalculatesDataAvailabilityCost_Success() (gas: 20760)
+EVM2EVMOnRamp_getDataAvailabilityCost:test_SimpleMessageCalculatesDataAvailabilityCost_Success() (gas: 21128)
+EVM2EVMOnRamp_getFee:test_EmptyMessage_Success() (gas: 78242)
+EVM2EVMOnRamp_getFee:test_HighGasMessage_Success() (gas: 234090)
+EVM2EVMOnRamp_getFee:test_MessageGasLimitTooHigh_Revert() (gas: 16715)
+EVM2EVMOnRamp_getFee:test_MessageTooLarge_Revert() (gas: 95271)
+EVM2EVMOnRamp_getFee:test_MessageWithDataAndTokenTransfer_Success() (gas: 159220)
+EVM2EVMOnRamp_getFee:test_NotAFeeToken_Revert() (gas: 24089)
+EVM2EVMOnRamp_getFee:test_SingleTokenMessage_Success() (gas: 117858)
+EVM2EVMOnRamp_getFee:test_TooManyTokens_Revert() (gas: 19902)
+EVM2EVMOnRamp_getFee:test_ZeroDataAvailabilityMultiplier_Success() (gas: 65663)
+EVM2EVMOnRamp_getSupportedTokens:test_GetSupportedTokens_Revert() (gas: 10460)
+EVM2EVMOnRamp_getTokenPool:test_GetTokenPool_Success() (gas: 35195)
+EVM2EVMOnRamp_getTokenTransferCost:test_CustomTokenBpsFee_Success() (gas: 45037)
+EVM2EVMOnRamp_getTokenTransferCost:test_FeeTokenBpsFee_Success() (gas: 33041)
+EVM2EVMOnRamp_getTokenTransferCost:test_LargeTokenTransferChargesMaxFeeAndGas_Success() (gas: 28296)
+EVM2EVMOnRamp_getTokenTransferCost:test_MixedTokenTransferFee_Success() (gas: 130189)
+EVM2EVMOnRamp_getTokenTransferCost:test_NoTokenTransferChargesZeroFee_Success() (gas: 15260)
+EVM2EVMOnRamp_getTokenTransferCost:test_SmallTokenTransferChargesMinFeeAndGas_Success() (gas: 28104)
+EVM2EVMOnRamp_getTokenTransferCost:test_UnsupportedToken_Revert() (gas: 21248)
+EVM2EVMOnRamp_getTokenTransferCost:test_WETHTokenBpsFee_Success() (gas: 38922)
+EVM2EVMOnRamp_getTokenTransferCost:test_ZeroAmountTokenTransferChargesMinFeeAndGas_Success() (gas: 28149)
+EVM2EVMOnRamp_getTokenTransferCost:test_ZeroFeeConfigChargesMinFee_Success() (gas: 38615)
+EVM2EVMOnRamp_getTokenTransferCost:test__getTokenTransferCost_selfServeUsesDefaults_Success() (gas: 29527)
+EVM2EVMOnRamp_linkAvailableForPayment:test_InsufficientLinkBalance_Success() (gas: 32615)
+EVM2EVMOnRamp_linkAvailableForPayment:test_LinkAvailableForPayment_Success() (gas: 134833)
+EVM2EVMOnRamp_payNops:test_AdminPayNops_Success() (gas: 143054)
+EVM2EVMOnRamp_payNops:test_InsufficientBalance_Revert() (gas: 26543)
+EVM2EVMOnRamp_payNops:test_NoFeesToPay_Revert() (gas: 127367)
+EVM2EVMOnRamp_payNops:test_NoNopsToPay_Revert() (gas: 133251)
+EVM2EVMOnRamp_payNops:test_NopPayNops_Success() (gas: 146341)
+EVM2EVMOnRamp_payNops:test_OwnerPayNops_Success() (gas: 140916)
+EVM2EVMOnRamp_payNops:test_PayNopsSuccessAfterSetNops() (gas: 297485)
+EVM2EVMOnRamp_payNops:test_WrongPermissions_Revert() (gas: 15294)
+EVM2EVMOnRamp_setDynamicConfig:test_SetConfigInvalidConfig_Revert() (gas: 43376)
+EVM2EVMOnRamp_setDynamicConfig:test_SetConfigOnlyOwner_Revert() (gas: 21646)
+EVM2EVMOnRamp_setDynamicConfig:test_SetDynamicConfig_Success() (gas: 55086)
+EVM2EVMOnRamp_setFeeTokenConfig:test_OnlyCallableByOwnerOrAdmin_Revert() (gas: 13464)
+EVM2EVMOnRamp_setFeeTokenConfig:test_SetFeeTokenConfigByAdmin_Success() (gas: 16449)
+EVM2EVMOnRamp_setFeeTokenConfig:test_SetFeeTokenConfig_Success() (gas: 13994)
+EVM2EVMOnRamp_setNops:test_AdminCanSetNops_Success() (gas: 61759)
+EVM2EVMOnRamp_setNops:test_IncludesPayment_Success() (gas: 469097)
+EVM2EVMOnRamp_setNops:test_LinkTokenCannotBeNop_Revert() (gas: 57255)
+EVM2EVMOnRamp_setNops:test_NonOwnerOrAdmin_Revert() (gas: 14665)
+EVM2EVMOnRamp_setNops:test_NotEnoughFundsForPayout_Revert() (gas: 84455)
+EVM2EVMOnRamp_setNops:test_SetNopsRemovesOldNopsCompletely_Success() (gas: 60637)
+EVM2EVMOnRamp_setNops:test_SetNops_Success() (gas: 173677)
+EVM2EVMOnRamp_setNops:test_TooManyNops_Revert() (gas: 190338)
+EVM2EVMOnRamp_setNops:test_ZeroAddressCannotBeNop_Revert() (gas: 53596)
+EVM2EVMOnRamp_setTokenTransferFeeConfig:test__setTokenTransferFeeConfig_InvalidDestBytesOverhead_Revert() (gas: 14493)
+EVM2EVMOnRamp_setTokenTransferFeeConfig:test__setTokenTransferFeeConfig_OnlyCallableByOwnerOrAdmin_Revert() (gas: 14277)
+EVM2EVMOnRamp_setTokenTransferFeeConfig:test__setTokenTransferFeeConfig_Success() (gas: 84017)
+EVM2EVMOnRamp_setTokenTransferFeeConfig:test__setTokenTransferFeeConfig_byAdmin_Success() (gas: 17369)
+EVM2EVMOnRamp_withdrawNonLinkFees:test_LinkBalanceNotSettled_Revert() (gas: 82980)
+EVM2EVMOnRamp_withdrawNonLinkFees:test_NonOwnerOrAdmin_Revert() (gas: 15275)
+EVM2EVMOnRamp_withdrawNonLinkFees:test_SettlingBalance_Success() (gas: 272015)
+EVM2EVMOnRamp_withdrawNonLinkFees:test_WithdrawNonLinkFees_Success() (gas: 53446)
+EVM2EVMOnRamp_withdrawNonLinkFees:test_WithdrawToZeroAddress_Revert() (gas: 12830)
+EtherSenderReceiverTest_ccipReceive:test_ccipReceive_fallbackToWethTransfer() (gas: 96729)
+EtherSenderReceiverTest_ccipReceive:test_ccipReceive_happyPath() (gas: 47688)
+EtherSenderReceiverTest_ccipReceive:test_ccipReceive_wrongToken() (gas: 17384)
+EtherSenderReceiverTest_ccipReceive:test_ccipReceive_wrongTokenAmount() (gas: 15677)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_reverts_insufficientFee_feeToken() (gas: 99741)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_reverts_insufficientFee_native() (gas: 76096)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_reverts_insufficientFee_weth() (gas: 99748)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_success_feeToken() (gas: 144569)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_success_native() (gas: 80259)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_success_nativeExcess() (gas: 80446)
+EtherSenderReceiverTest_ccipSend:test_ccipSend_success_weth() (gas: 95713)
+EtherSenderReceiverTest_constructor:test_constructor() (gas: 17511)
+EtherSenderReceiverTest_getFee:test_getFee() (gas: 27289)
+EtherSenderReceiverTest_validateFeeToken:test_validateFeeToken_reverts_feeToken_tokenAmountNotEqualToMsgValue() (gas: 20333)
+EtherSenderReceiverTest_validateFeeToken:test_validateFeeToken_valid_feeToken() (gas: 16715)
+EtherSenderReceiverTest_validateFeeToken:test_validateFeeToken_valid_native() (gas: 16654)
+EtherSenderReceiverTest_validatedMessage:test_validatedMessage_dataOverwrittenToMsgSender() (gas: 25415)
+EtherSenderReceiverTest_validatedMessage:test_validatedMessage_emptyDataOverwrittenToMsgSender() (gas: 25265)
+EtherSenderReceiverTest_validatedMessage:test_validatedMessage_invalidTokenAmounts() (gas: 17895)
+EtherSenderReceiverTest_validatedMessage:test_validatedMessage_tokenOverwrittenToWeth() (gas: 25287)
+EtherSenderReceiverTest_validatedMessage:test_validatedMessage_validMessage_extraArgs() (gas: 26292)
+LockReleaseTokenPoolAndProxy_setRateLimitAdmin:test_SetRateLimitAdmin_Revert() (gas: 11058)
+LockReleaseTokenPoolAndProxy_setRateLimitAdmin:test_SetRateLimitAdmin_Success() (gas: 35097)
+LockReleaseTokenPoolAndProxy_setRebalancer:test_SetRebalancer_Revert() (gas: 10970)
+LockReleaseTokenPoolAndProxy_setRebalancer:test_SetRebalancer_Success() (gas: 18036)
+LockReleaseTokenPoolPoolAndProxy_canAcceptLiquidity:test_CanAcceptLiquidity_Success() (gas: 3313980)
+LockReleaseTokenPoolPoolAndProxy_provideLiquidity:test_LiquidityNotAccepted_Revert() (gas: 3310379)
+LockReleaseTokenPoolPoolAndProxy_provideLiquidity:test_Unauthorized_Revert() (gas: 11380)
+LockReleaseTokenPoolPoolAndProxy_setChainRateLimiterConfig:test_NonExistentChain_Revert() (gas: 17135)
+LockReleaseTokenPoolPoolAndProxy_setChainRateLimiterConfig:test_OnlyOwnerOrRateLimitAdmin_Revert() (gas: 69142)
+LockReleaseTokenPoolPoolAndProxy_setChainRateLimiterConfig:test_OnlyOwner_Revert() (gas: 17319)
+LockReleaseTokenPoolPoolAndProxy_supportsInterface:test_SupportsInterface_Success() (gas: 9977)
+LockReleaseTokenPoolPoolAndProxy_withdrawalLiquidity:test_InsufficientLiquidity_Revert() (gas: 60043)
+LockReleaseTokenPoolPoolAndProxy_withdrawalLiquidity:test_Unauthorized_Revert() (gas: 11355)
+LockReleaseTokenPool_canAcceptLiquidity:test_CanAcceptLiquidity_Success() (gas: 3067883)
+LockReleaseTokenPool_lockOrBurn:test_LockOrBurnWithAllowList_Revert() (gas: 29942)
+LockReleaseTokenPool_lockOrBurn:test_LockOrBurnWithAllowList_Success() (gas: 79844)
+LockReleaseTokenPool_lockOrBurn:test_PoolBurnRevertNotHealthy_Revert() (gas: 59464)
+LockReleaseTokenPool_provideLiquidity:test_LiquidityNotAccepted_Revert() (gas: 3064325)
+LockReleaseTokenPool_provideLiquidity:test_Unauthorized_Revert() (gas: 11380)
+LockReleaseTokenPool_releaseOrMint:test_ChainNotAllowed_Revert() (gas: 72662)
+LockReleaseTokenPool_releaseOrMint:test_PoolMintNotHealthy_Revert() (gas: 56131)
+LockReleaseTokenPool_releaseOrMint:test_ReleaseOrMint_Success() (gas: 238673)
+LockReleaseTokenPool_setChainRateLimiterConfig:test_NonExistentChain_Revert() (gas: 17102)
+LockReleaseTokenPool_setChainRateLimiterConfig:test_OnlyOwnerOrRateLimitAdmin_Revert() (gas: 69075)
+LockReleaseTokenPool_setChainRateLimiterConfig:test_OnlyOwner_Revert() (gas: 17297)
+LockReleaseTokenPool_setRateLimitAdmin:test_SetRateLimitAdmin_Revert() (gas: 11057)
+LockReleaseTokenPool_setRateLimitAdmin:test_SetRateLimitAdmin_Success() (gas: 35140)
+LockReleaseTokenPool_setRebalancer:test_SetRebalancer_Revert() (gas: 10992)
+LockReleaseTokenPool_setRebalancer:test_SetRebalancer_Success() (gas: 17926)
+LockReleaseTokenPool_supportsInterface:test_SupportsInterface_Success() (gas: 9977)
+LockReleaseTokenPool_withdrawalLiquidity:test_InsufficientLiquidity_Revert() (gas: 60043)
+LockReleaseTokenPool_withdrawalLiquidity:test_Unauthorized_Revert() (gas: 11355)
+MerkleMultiProofTest:test_CVE_2023_34459() (gas: 5451)
+MerkleMultiProofTest:test_EmptyLeaf_Revert() (gas: 3552)
+MerkleMultiProofTest:test_MerkleRoot256() (gas: 394876)
+MerkleMultiProofTest:test_MerkleRootSingleLeaf_Success() (gas: 3649)
+MerkleMultiProofTest:test_SpecSync_gas() (gas: 34123)
+MockRouterTest:test_ccipSendWithInsufficientNativeTokens_Revert() (gas: 33965)
+MockRouterTest:test_ccipSendWithInvalidMsgValue_Revert() (gas: 60758)
+MockRouterTest:test_ccipSendWithLinkFeeTokenAndValidMsgValue_Success() (gas: 126294)
+MockRouterTest:test_ccipSendWithLinkFeeTokenbutInsufficientAllowance_Revert() (gas: 63302)
+MockRouterTest:test_ccipSendWithSufficientNativeFeeTokens_Success() (gas: 43853)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_MultipleConfigsBothLanes_Success() (gas: 132031)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_MultipleConfigs_Success() (gas: 312057)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_OnlyCallableByOwner_Revert() (gas: 17717)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_SingleConfigOutbound_Success() (gas: 75784)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_SingleConfig_Success() (gas: 75700)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_UpdateExistingConfigWithNoDifference_Success() (gas: 38133)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_UpdateExistingConfig_Success() (gas: 53092)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_ZeroChainSelector_Revert() (gas: 17019)
+MultiAggregateRateLimiter_applyRateLimiterConfigUpdates:test_ZeroConfigs_Success() (gas: 12295)
+MultiAggregateRateLimiter_constructor:test_ConstructorNoAuthorizedCallers_Success() (gas: 1971805)
+MultiAggregateRateLimiter_constructor:test_Constructor_Success() (gas: 2085252)
+MultiAggregateRateLimiter_getTokenBucket:test_GetTokenBucket_Success() (gas: 30248)
+MultiAggregateRateLimiter_getTokenBucket:test_Refill_Success() (gas: 47358)
+MultiAggregateRateLimiter_getTokenBucket:test_TimeUnderflow_Revert() (gas: 15821)
+MultiAggregateRateLimiter_getTokenValue:test_GetTokenValue_Success() (gas: 19668)
+MultiAggregateRateLimiter_getTokenValue:test_NoTokenPrice_Reverts() (gas: 21253)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageFromUnauthorizedCaller_Revert() (gas: 14527)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithDifferentTokensOnDifferentChains_Success() (gas: 189450)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithDisabledRateLimitToken_Success() (gas: 59927)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithNoTokens_Success() (gas: 17593)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithRateLimitDisabled_Success() (gas: 44895)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithRateLimitExceeded_Revert() (gas: 50598)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithRateLimitReset_Success() (gas: 78780)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithTokensOnDifferentChains_Success() (gas: 263510)
+MultiAggregateRateLimiter_onInboundMessage:test_ValidateMessageWithTokens_Success() (gas: 54784)
+MultiAggregateRateLimiter_onOutboundMessage:test_RateLimitValueDifferentLanes_Success() (gas: 9223372036854754743)
+MultiAggregateRateLimiter_onOutboundMessage:test_ValidateMessageWithNoTokens_Success() (gas: 19104)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageFromUnauthorizedCaller_Revert() (gas: 15778)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithDifferentTokensOnDifferentChains_Success() (gas: 189438)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithDisabledRateLimitToken_Success() (gas: 61662)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithRateLimitDisabled_Success() (gas: 46683)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithRateLimitExceeded_Revert() (gas: 52371)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithRateLimitReset_Success() (gas: 79845)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithTokensOnDifferentChains_Success() (gas: 263724)
+MultiAggregateRateLimiter_onOutboundMessage:test_onOutboundMessage_ValidateMessageWithTokens_Success() (gas: 56541)
+MultiAggregateRateLimiter_setPriceRegistry:test_OnlyOwner_Revert() (gas: 11336)
+MultiAggregateRateLimiter_setPriceRegistry:test_Owner_Success() (gas: 19124)
+MultiAggregateRateLimiter_setPriceRegistry:test_ZeroAddress_Revert() (gas: 10608)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_NonOwner_Revert() (gas: 16085)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_UpdateRateLimitTokensMultipleChains_Success() (gas: 225643)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_UpdateRateLimitTokensSingleChain_Success() (gas: 200192)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_UpdateRateLimitTokens_AddsAndRemoves_Success() (gas: 162053)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_UpdateRateLimitTokens_RemoveNonExistentToken_Success() (gas: 28509)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_ZeroDestToken_Revert() (gas: 17430)
+MultiAggregateRateLimiter_updateRateLimitTokens:test_ZeroSourceToken_Revert() (gas: 17485)
+MultiOCR3Base_setOCR3Configs:test_FMustBePositive_Revert() (gas: 59331)
+MultiOCR3Base_setOCR3Configs:test_FTooHigh_Revert() (gas: 44298)
+MultiOCR3Base_setOCR3Configs:test_RepeatSignerAddress_Revert() (gas: 283711)
+MultiOCR3Base_setOCR3Configs:test_RepeatTransmitterAddress_Revert() (gas: 422848)
+MultiOCR3Base_setOCR3Configs:test_SetConfigIgnoreSigners_Success() (gas: 511694)
+MultiOCR3Base_setOCR3Configs:test_SetConfigWithSigners_Success() (gas: 829593)
+MultiOCR3Base_setOCR3Configs:test_SetConfigWithoutSigners_Success() (gas: 457446)
+MultiOCR3Base_setOCR3Configs:test_SetConfigsZeroInput_Success() (gas: 12376)
+MultiOCR3Base_setOCR3Configs:test_SetMultipleConfigs_Success() (gas: 2143220)
+MultiOCR3Base_setOCR3Configs:test_SignerCannotBeZeroAddress_Revert() (gas: 141744)
+MultiOCR3Base_setOCR3Configs:test_StaticConfigChange_Revert() (gas: 808478)
+MultiOCR3Base_setOCR3Configs:test_TooManySigners_Revert() (gas: 171331)
+MultiOCR3Base_setOCR3Configs:test_TooManyTransmitters_Revert() (gas: 30298)
+MultiOCR3Base_setOCR3Configs:test_TransmitterCannotBeZeroAddress_Revert() (gas: 254454)
+MultiOCR3Base_setOCR3Configs:test_UpdateConfigSigners_Success() (gas: 861521)
+MultiOCR3Base_setOCR3Configs:test_UpdateConfigTransmittersWithoutSigners_Success() (gas: 475825)
+MultiOCR3Base_transmit:test_ConfigDigestMismatch_Revert() (gas: 42837)
+MultiOCR3Base_transmit:test_ForkedChain_Revert() (gas: 48442)
+MultiOCR3Base_transmit:test_InsufficientSignatures_Revert() (gas: 76930)
+MultiOCR3Base_transmit:test_NonUniqueSignature_Revert() (gas: 66127)
+MultiOCR3Base_transmit:test_SignatureOutOfRegistration_Revert() (gas: 33419)
+MultiOCR3Base_transmit:test_TooManySignatures_Revert() (gas: 79521)
+MultiOCR3Base_transmit:test_TransmitSigners_gas_Success() (gas: 34131)
+MultiOCR3Base_transmit:test_TransmitWithExtraCalldataArgs_Revert() (gas: 47114)
+MultiOCR3Base_transmit:test_TransmitWithLessCalldataArgs_Revert() (gas: 25682)
+MultiOCR3Base_transmit:test_TransmitWithoutSignatureVerification_gas_Success() (gas: 18726)
+MultiOCR3Base_transmit:test_UnAuthorizedTransmitter_Revert() (gas: 24191)
+MultiOCR3Base_transmit:test_UnauthorizedSigner_Revert() (gas: 61409)
+MultiOCR3Base_transmit:test_UnconfiguredPlugin_Revert() (gas: 39890)
+MultiOCR3Base_transmit:test_ZeroSignatures_Revert() (gas: 32973)
+MultiOnRampTokenPoolReentrancy:test_OnRampTokenPoolReentrancy_Success() (gas: 412349)
+MultiRampsE2E:test_E2E_3MessagesSuccess_gas() (gas: 1426976)
+NonceManager_NonceIncrementation:test_getIncrementedOutboundNonce_Success() (gas: 37907)
+NonceManager_NonceIncrementation:test_incrementInboundNonce_Skip() (gas: 23694)
+NonceManager_NonceIncrementation:test_incrementInboundNonce_Success() (gas: 38763)
+NonceManager_NonceIncrementation:test_incrementNoncesInboundAndOutbound_Success() (gas: 71847)
+NonceManager_OffRampUpgrade:test_NoPrevOffRampForChain_Success() (gas: 252566)
+NonceManager_OffRampUpgrade:test_UpgradedNonceNewSenderStartsAtZero_Success() (gas: 254866)
+NonceManager_OffRampUpgrade:test_UpgradedNonceStartsAtV1Nonce_Success() (gas: 307885)
+NonceManager_OffRampUpgrade:test_UpgradedOffRampNonceSkipsIfMsgInFlight_Success() (gas: 290962)
+NonceManager_OffRampUpgrade:test_UpgradedSenderNoncesReadsPreviousRampTransitive_Success() (gas: 247990)
+NonceManager_OffRampUpgrade:test_UpgradedSenderNoncesReadsPreviousRamp_Success() (gas: 236024)
+NonceManager_OffRampUpgrade:test_Upgraded_Success() (gas: 144774)
+NonceManager_OnRampUpgrade:test_UpgradeNonceNewSenderStartsAtZero_Success() (gas: 186669)
+NonceManager_OnRampUpgrade:test_UpgradeNonceStartsAtV1Nonce_Success() (gas: 237737)
+NonceManager_OnRampUpgrade:test_UpgradeSenderNoncesReadsPreviousRamp_Success() (gas: 124995)
+NonceManager_OnRampUpgrade:test_Upgrade_Success() (gas: 125923)
+NonceManager_applyPreviousRampsUpdates:test_MultipleRampsUpdates() (gas: 122899)
+NonceManager_applyPreviousRampsUpdates:test_PreviousRampAlreadySetOffRamp_Revert() (gas: 42959)
+NonceManager_applyPreviousRampsUpdates:test_PreviousRampAlreadySetOnRampAndOffRamp_Revert() (gas: 64282)
+NonceManager_applyPreviousRampsUpdates:test_PreviousRampAlreadySetOnRamp_Revert() (gas: 42823)
+NonceManager_applyPreviousRampsUpdates:test_SingleRampUpdate() (gas: 66548)
+NonceManager_applyPreviousRampsUpdates:test_ZeroInput() (gas: 12025)
+OCR2BaseNoChecks_setOCR2Config:test_FMustBePositive_Revert() (gas: 12171)
+OCR2BaseNoChecks_setOCR2Config:test_RepeatAddress_Revert() (gas: 42233)
+OCR2BaseNoChecks_setOCR2Config:test_SetConfigSuccess_gas() (gas: 84124)
+OCR2BaseNoChecks_setOCR2Config:test_TooManyTransmitter_Revert() (gas: 36938)
+OCR2BaseNoChecks_setOCR2Config:test_TransmitterCannotBeZeroAddress_Revert() (gas: 24158)
+OCR2BaseNoChecks_transmit:test_ConfigDigestMismatch_Revert() (gas: 17448)
+OCR2BaseNoChecks_transmit:test_ForkedChain_Revert() (gas: 26726)
+OCR2BaseNoChecks_transmit:test_TransmitSuccess_gas() (gas: 27478)
+OCR2BaseNoChecks_transmit:test_UnAuthorizedTransmitter_Revert() (gas: 21296)
+OCR2Base_setOCR2Config:test_FMustBePositive_Revert() (gas: 12189)
+OCR2Base_setOCR2Config:test_FTooHigh_Revert() (gas: 12345)
+OCR2Base_setOCR2Config:test_OracleOutOfRegister_Revert() (gas: 14892)
+OCR2Base_setOCR2Config:test_RepeatAddress_Revert() (gas: 45442)
+OCR2Base_setOCR2Config:test_SetConfigSuccess_gas() (gas: 155192)
+OCR2Base_setOCR2Config:test_SingerCannotBeZeroAddress_Revert() (gas: 24407)
+OCR2Base_setOCR2Config:test_TooManySigners_Revert() (gas: 20508)
+OCR2Base_setOCR2Config:test_TransmitterCannotBeZeroAddress_Revert() (gas: 47298)
+OCR2Base_transmit:test_ConfigDigestMismatch_Revert() (gas: 19623)
+OCR2Base_transmit:test_ForkedChain_Revert() (gas: 37683)
+OCR2Base_transmit:test_NonUniqueSignature_Revert() (gas: 55309)
+OCR2Base_transmit:test_SignatureOutOfRegistration_Revert() (gas: 20962)
+OCR2Base_transmit:test_Transmit2SignersSuccess_gas() (gas: 51686)
+OCR2Base_transmit:test_UnAuthorizedTransmitter_Revert() (gas: 23484)
+OCR2Base_transmit:test_UnauthorizedSigner_Revert() (gas: 39665)
+OCR2Base_transmit:test_WrongNumberOfSignatures_Revert() (gas: 20557)
+OnRampTokenPoolReentrancy:test_OnRampTokenPoolReentrancy_Success() (gas: 380360)
+PingPong_ccipReceive:test_CcipReceive_Success() (gas: 148380)
+PingPong_plumbing:test_Pausing_Success() (gas: 17803)
+PingPong_startPingPong:test_StartPingPong_Success() (gas: 178340)
+PriceRegistry_applyDestChainConfigUpdates:test_InvalidChainFamilySelector_Revert() (gas: 16719)
+PriceRegistry_applyDestChainConfigUpdates:test_InvalidDestBytesOverhead_Revert() (gas: 16784)
+PriceRegistry_applyDestChainConfigUpdates:test_InvalidDestChainConfigDestChainSelectorEqZero_Revert() (gas: 16611)
+PriceRegistry_applyDestChainConfigUpdates:test_applyDestChainConfigUpdatesDefaultTxGasLimitEqZero_Revert() (gas: 16675)
+PriceRegistry_applyDestChainConfigUpdates:test_applyDestChainConfigUpdatesDefaultTxGasLimitGtMaxPerMessageGasLimit_Revert() (gas: 40953)
+PriceRegistry_applyDestChainConfigUpdates:test_applyDestChainConfigUpdatesZeroIntput_Success() (gas: 12341)
+PriceRegistry_applyDestChainConfigUpdates:test_applyDestChainConfigUpdates_Success() (gas: 139564)
+PriceRegistry_applyFeeTokensUpdates:test_ApplyFeeTokensUpdates_Success() (gas: 80002)
+PriceRegistry_applyFeeTokensUpdates:test_OnlyCallableByOwner_Revert() (gas: 12603)
+PriceRegistry_applyPremiumMultiplierWeiPerEthUpdates:test_OnlyCallableByOwnerOrAdmin_Revert() (gas: 11465)
+PriceRegistry_applyPremiumMultiplierWeiPerEthUpdates:test_applyPremiumMultiplierWeiPerEthUpdatesMultipleTokens_Success() (gas: 54149)
+PriceRegistry_applyPremiumMultiplierWeiPerEthUpdates:test_applyPremiumMultiplierWeiPerEthUpdatesSingleToken_Success() (gas: 44835)
+PriceRegistry_applyPremiumMultiplierWeiPerEthUpdates:test_applyPremiumMultiplierWeiPerEthUpdatesZeroInput() (gas: 12301)
+PriceRegistry_applyTokenTransferFeeConfigUpdates:test_ApplyTokenTransferFeeConfig_Success() (gas: 86826)
+PriceRegistry_applyTokenTransferFeeConfigUpdates:test_ApplyTokenTransferFeeZeroInput() (gas: 13089)
+PriceRegistry_applyTokenTransferFeeConfigUpdates:test_InvalidDestBytesOverhead_Revert() (gas: 17045)
+PriceRegistry_applyTokenTransferFeeConfigUpdates:test_OnlyCallableByOwnerOrAdmin_Revert() (gas: 12240)
+PriceRegistry_constructor:test_InvalidLinkTokenEqZeroAddress_Revert() (gas: 105966)
+PriceRegistry_constructor:test_InvalidMaxFeeJuelsPerMsg_Revert() (gas: 110316)
+PriceRegistry_constructor:test_InvalidStalenessThreshold_Revert() (gas: 110369)
+PriceRegistry_constructor:test_Setup_Success() (gas: 4650895)
+PriceRegistry_convertTokenAmount:test_ConvertTokenAmount_Success() (gas: 72751)
+PriceRegistry_convertTokenAmount:test_LinkTokenNotSupported_Revert() (gas: 30981)
+PriceRegistry_getDataAvailabilityCost:test_EmptyMessageCalculatesDataAvailabilityCost_Success() (gas: 95575)
+PriceRegistry_getDataAvailabilityCost:test_SimpleMessageCalculatesDataAvailabilityCostUnsupportedDestChainSelector_Success() (gas: 14636)
+PriceRegistry_getDataAvailabilityCost:test_SimpleMessageCalculatesDataAvailabilityCost_Success() (gas: 20614)
+PriceRegistry_getTokenAndGasPrices:test_GetFeeTokenAndGasPrices_Success() (gas: 70449)
+PriceRegistry_getTokenAndGasPrices:test_StaleGasPrice_Revert() (gas: 16838)
+PriceRegistry_getTokenAndGasPrices:test_UnsupportedChain_Revert() (gas: 16140)
+PriceRegistry_getTokenAndGasPrices:test_ZeroGasPrice_Success() (gas: 45734)
+PriceRegistry_getTokenPrice:test_GetTokenPriceFromFeed_Success() (gas: 62311)
+PriceRegistry_getTokenPrices:test_GetTokenPrices_Success() (gas: 84774)
+PriceRegistry_getTokenTransferCost:test_CustomTokenBpsFee_Success() (gas: 41283)
+PriceRegistry_getTokenTransferCost:test_FeeTokenBpsFee_Success() (gas: 34733)
+PriceRegistry_getTokenTransferCost:test_LargeTokenTransferChargesMaxFeeAndGas_Success() (gas: 27807)
+PriceRegistry_getTokenTransferCost:test_MixedTokenTransferFee_Success() (gas: 108018)
+PriceRegistry_getTokenTransferCost:test_NoTokenTransferChargesZeroFee_Success() (gas: 20359)
+PriceRegistry_getTokenTransferCost:test_SmallTokenTransferChargesMinFeeAndGas_Success() (gas: 27615)
+PriceRegistry_getTokenTransferCost:test_WETHTokenBpsFee_Success() (gas: 40668)
+PriceRegistry_getTokenTransferCost:test_ZeroAmountTokenTransferChargesMinFeeAndGas_Success() (gas: 27638)
+PriceRegistry_getTokenTransferCost:test_ZeroFeeConfigChargesMinFee_Success() (gas: 40015)
+PriceRegistry_getTokenTransferCost:test_getTokenTransferCost_selfServeUsesDefaults_Success() (gas: 29343)
+PriceRegistry_getValidatedFee:test_DestinationChainNotEnabled_Revert() (gas: 18203)
+PriceRegistry_getValidatedFee:test_EmptyMessage_Success() (gas: 81464)
+PriceRegistry_getValidatedFee:test_EnforceOutOfOrder_Revert() (gas: 55184)
+PriceRegistry_getValidatedFee:test_HighGasMessage_Success() (gas: 237926)
+PriceRegistry_getValidatedFee:test_InvalidEVMAddress_Revert() (gas: 19971)
+PriceRegistry_getValidatedFee:test_MessageGasLimitTooHigh_Revert() (gas: 31775)
+PriceRegistry_getValidatedFee:test_MessageTooLarge_Revert() (gas: 97714)
+PriceRegistry_getValidatedFee:test_MessageWithDataAndTokenTransfer_Success() (gas: 143193)
+PriceRegistry_getValidatedFee:test_NotAFeeToken_Revert() (gas: 29435)
+PriceRegistry_getValidatedFee:test_SingleTokenMessage_Success() (gas: 112283)
+PriceRegistry_getValidatedFee:test_TooManyTokens_Revert() (gas: 20107)
+PriceRegistry_getValidatedFee:test_ZeroDataAvailabilityMultiplier_Success() (gas: 62956)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedErc20Above18Decimals_Success() (gas: 2094532)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedErc20Below18Decimals_Success() (gas: 2094490)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedFeedAt0Decimals_Success() (gas: 2074609)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedFeedAt18Decimals_Success() (gas: 2094264)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedFlippedDecimals_Success() (gas: 2094468)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedMaxInt224Value_Success() (gas: 2094280)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeedOverStalenessPeriod_Success() (gas: 61997)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPriceFromFeed_Success() (gas: 61877)
+PriceRegistry_getValidatedTokenPrice:test_GetValidatedTokenPrice_Success() (gas: 60998)
+PriceRegistry_getValidatedTokenPrice:test_OverflowFeedPrice_Revert() (gas: 2093992)
+PriceRegistry_getValidatedTokenPrice:test_StaleFeeToken_Success() (gas: 61525)
+PriceRegistry_getValidatedTokenPrice:test_TokenNotSupportedFeed_Revert() (gas: 109113)
+PriceRegistry_getValidatedTokenPrice:test_TokenNotSupported_Revert() (gas: 13819)
+PriceRegistry_getValidatedTokenPrice:test_UnderflowFeedPrice_Revert() (gas: 2092670)
+PriceRegistry_parseEVMExtraArgsFromBytes:test_EVMExtraArgsDefault_Success() (gas: 17360)
+PriceRegistry_parseEVMExtraArgsFromBytes:test_EVMExtraArgsEnforceOutOfOrder_Revert() (gas: 21454)
+PriceRegistry_parseEVMExtraArgsFromBytes:test_EVMExtraArgsGasLimitTooHigh_Revert() (gas: 18551)
+PriceRegistry_parseEVMExtraArgsFromBytes:test_EVMExtraArgsInvalidExtraArgsTag_Revert() (gas: 18075)
+PriceRegistry_parseEVMExtraArgsFromBytes:test_EVMExtraArgsV1_Success() (gas: 18452)
+PriceRegistry_parseEVMExtraArgsFromBytes:test_EVMExtraArgsV2_Success() (gas: 18569)
+PriceRegistry_processMessageArgs:test_InvalidExtraArgs_Revert() (gas: 18306)
+PriceRegistry_processMessageArgs:test_MalformedEVMExtraArgs_Revert() (gas: 18852)
+PriceRegistry_processMessageArgs:test_MessageFeeTooHigh_Revert() (gas: 16360)
+PriceRegistry_processMessageArgs:test_WitEVMExtraArgsV2_Success() (gas: 26236)
+PriceRegistry_processMessageArgs:test_WithConvertedTokenAmount_Success() (gas: 32410)
+PriceRegistry_processMessageArgs:test_WithEVMExtraArgsV1_Success() (gas: 25848)
+PriceRegistry_processMessageArgs:test_WithEmptyEVMExtraArgs_Success() (gas: 23663)
+PriceRegistry_processMessageArgs:test_WithLinkTokenAmount_Success() (gas: 17320)
+PriceRegistry_updatePrices:test_OnlyCallableByUpdater_Revert() (gas: 12080)
+PriceRegistry_updatePrices:test_OnlyGasPrice_Success() (gas: 23599)
+PriceRegistry_updatePrices:test_OnlyTokenPrice_Success() (gas: 30637)
+PriceRegistry_updatePrices:test_UpdatableByAuthorizedCaller_Success() (gas: 76043)
+PriceRegistry_updatePrices:test_UpdateMultiplePrices_Success() (gas: 151521)
+PriceRegistry_updateTokenPriceFeeds:test_FeedNotUpdated() (gas: 50699)
+PriceRegistry_updateTokenPriceFeeds:test_FeedUnset_Success() (gas: 63882)
+PriceRegistry_updateTokenPriceFeeds:test_FeedUpdatedByNonOwner_Revert() (gas: 19998)
+PriceRegistry_updateTokenPriceFeeds:test_MultipleFeedUpdate_Success() (gas: 89162)
+PriceRegistry_updateTokenPriceFeeds:test_SingleFeedUpdate_Success() (gas: 50949)
+PriceRegistry_updateTokenPriceFeeds:test_ZeroFeeds_Success() (gas: 12362)
+PriceRegistry_validateDestFamilyAddress:test_InvalidEVMAddressEncodePacked_Revert() (gas: 10572)
+PriceRegistry_validateDestFamilyAddress:test_InvalidEVMAddressPrecompiles_Revert() (gas: 3916546)
+PriceRegistry_validateDestFamilyAddress:test_InvalidEVMAddress_Revert() (gas: 10756)
+PriceRegistry_validateDestFamilyAddress:test_ValidEVMAddress_Success() (gas: 6660)
+PriceRegistry_validateDestFamilyAddress:test_ValidNonEVMAddress_Success() (gas: 6440)
+PriceRegistry_validatePoolReturnData:test_InvalidEVMAddressDestToken_Revert() (gas: 35457)
+PriceRegistry_validatePoolReturnData:test_SourceTokenDataTooLarge_Revert() (gas: 90631)
+PriceRegistry_validatePoolReturnData:test_TokenAmountArraysMismatching_Revert() (gas: 32749)
+PriceRegistry_validatePoolReturnData:test_WithSingleToken_Success() (gas: 31293)
+RMN_constructor:test_Constructor_Success() (gas: 48838)
+RMN_getRecordedCurseRelatedOps:test_OpsPostDeployment() (gas: 19666)
+RMN_lazyVoteToCurseUpdate_Benchmark:test_VoteToCurseLazilyRetain3VotersUponConfigChange_gas() (gas: 152152)
+RMN_ownerUnbless:test_Unbless_Success() (gas: 74699)
+RMN_ownerUnvoteToCurse:test_CanBlessAndCurseAfterGlobalCurseIsLifted() (gas: 470965)
+RMN_ownerUnvoteToCurse:test_IsIdempotent() (gas: 397532)
+RMN_ownerUnvoteToCurse:test_NonOwner_Revert() (gas: 18591)
+RMN_ownerUnvoteToCurse:test_OwnerUnvoteToCurseSuccess_gas() (gas: 357403)
+RMN_ownerUnvoteToCurse:test_UnknownVoter_Revert() (gas: 32980)
+RMN_ownerUnvoteToCurse_Benchmark:test_OwnerUnvoteToCurse_1Voter_LiftsCurse_gas() (gas: 261985)
+RMN_permaBlessing:test_PermaBlessing() (gas: 202686)
+RMN_setConfig:test_BlessVoterIsZeroAddress_Revert() (gas: 15494)
+RMN_setConfig:test_EitherThresholdIsZero_Revert() (gas: 21095)
+RMN_setConfig:test_NonOwner_Revert() (gas: 14713)
+RMN_setConfig:test_RepeatedAddress_Revert() (gas: 18213)
+RMN_setConfig:test_SetConfigSuccess_gas() (gas: 104204)
+RMN_setConfig:test_TotalWeightsSmallerThanEachThreshold_Revert() (gas: 30173)
+RMN_setConfig:test_VoteToBlessByEjectedVoter_Revert() (gas: 130303)
+RMN_setConfig:test_VotersLengthIsZero_Revert() (gas: 12128)
+RMN_setConfig:test_WeightIsZeroAddress_Revert() (gas: 15734)
+RMN_setConfig_Benchmark_1:test_SetConfig_7Voters_gas() (gas: 659123)
+RMN_setConfig_Benchmark_2:test_ResetConfig_7Voters_gas() (gas: 212156)
+RMN_unvoteToCurse:test_InvalidCursesHash() (gas: 26364)
+RMN_unvoteToCurse:test_OwnerSkips() (gas: 33753)
+RMN_unvoteToCurse:test_OwnerSucceeds() (gas: 63909)
+RMN_unvoteToCurse:test_UnauthorizedVoter() (gas: 47478)
+RMN_unvoteToCurse:test_ValidCursesHash() (gas: 61067)
+RMN_unvoteToCurse:test_VotersCantLiftCurseButOwnerCan() (gas: 627750)
+RMN_voteToBless:test_Curse_Revert() (gas: 472823)
+RMN_voteToBless:test_IsAlreadyBlessed_Revert() (gas: 114829)
+RMN_voteToBless:test_RootSuccess() (gas: 555559)
+RMN_voteToBless:test_SenderAlreadyVoted_Revert() (gas: 96730)
+RMN_voteToBless:test_UnauthorizedVoter_Revert() (gas: 17087)
+RMN_voteToBless_Benchmark:test_1RootSuccess_gas() (gas: 44667)
+RMN_voteToBless_Benchmark:test_3RootSuccess_gas() (gas: 98565)
+RMN_voteToBless_Benchmark:test_5RootSuccess_gas() (gas: 152401)
+RMN_voteToBless_Blessed_Benchmark:test_1RootSuccessBecameBlessed_gas() (gas: 29619)
+RMN_voteToBless_Blessed_Benchmark:test_1RootSuccess_gas() (gas: 27565)
+RMN_voteToBless_Blessed_Benchmark:test_3RootSuccess_gas() (gas: 81485)
+RMN_voteToBless_Blessed_Benchmark:test_5RootSuccess_gas() (gas: 135299)
+RMN_voteToCurse:test_CurseOnlyWhenThresholdReached_Success() (gas: 1648701)
+RMN_voteToCurse:test_EmptySubjects_Revert() (gas: 14019)
+RMN_voteToCurse:test_EvenIfAlreadyCursed_Success() (gas: 534332)
+RMN_voteToCurse:test_OwnerCanCurseAndUncurse() (gas: 399001)
+RMN_voteToCurse:test_RepeatedSubject_Revert() (gas: 144225)
+RMN_voteToCurse:test_ReusedCurseId_Revert() (gas: 146738)
+RMN_voteToCurse:test_UnauthorizedVoter_Revert() (gas: 12600)
+RMN_voteToCurse:test_VoteToCurse_NoCurse_Success() (gas: 187244)
+RMN_voteToCurse:test_VoteToCurse_YesCurse_Success() (gas: 472452)
+RMN_voteToCurse_2:test_VotesAreDroppedIfSubjectIsNotCursedDuringConfigChange() (gas: 370468)
+RMN_voteToCurse_2:test_VotesAreRetainedIfSubjectIsCursedDuringConfigChange() (gas: 1151909)
+RMN_voteToCurse_Benchmark_1:test_VoteToCurse_NewSubject_NewVoter_NoCurse_gas() (gas: 140968)
+RMN_voteToCurse_Benchmark_1:test_VoteToCurse_NewSubject_NewVoter_YesCurse_gas() (gas: 165087)
+RMN_voteToCurse_Benchmark_2:test_VoteToCurse_OldSubject_NewVoter_NoCurse_gas() (gas: 121305)
+RMN_voteToCurse_Benchmark_2:test_VoteToCurse_OldSubject_OldVoter_NoCurse_gas() (gas: 98247)
+RMN_voteToCurse_Benchmark_3:test_VoteToCurse_OldSubject_NewVoter_YesCurse_gas() (gas: 145631)
+RateLimiter_constructor:test_Constructor_Success() (gas: 19650)
+RateLimiter_consume:test_AggregateValueMaxCapacityExceeded_Revert() (gas: 15916)
+RateLimiter_consume:test_AggregateValueRateLimitReached_Revert() (gas: 22222)
+RateLimiter_consume:test_ConsumeAggregateValue_Success() (gas: 31353)
+RateLimiter_consume:test_ConsumeTokens_Success() (gas: 20336)
+RateLimiter_consume:test_ConsumeUnlimited_Success() (gas: 40285)
+RateLimiter_consume:test_ConsumingMoreThanUint128_Revert() (gas: 15720)
+RateLimiter_consume:test_RateLimitReachedOverConsecutiveBlocks_Revert() (gas: 25594)
+RateLimiter_consume:test_Refill_Success() (gas: 37222)
+RateLimiter_consume:test_TokenMaxCapacityExceeded_Revert() (gas: 18250)
+RateLimiter_consume:test_TokenRateLimitReached_Revert() (gas: 24706)
+RateLimiter_currentTokenBucketState:test_CurrentTokenBucketState_Success() (gas: 38647)
+RateLimiter_currentTokenBucketState:test_Refill_Success() (gas: 46384)
+RateLimiter_setTokenBucketConfig:test_SetRateLimiterConfig_Success() (gas: 38017)
+RegistryModuleOwnerCustom_constructor:test_constructor_Revert() (gas: 36031)
+RegistryModuleOwnerCustom_registerAdminViaGetCCIPAdmin:test_registerAdminViaGetCCIPAdmin_Revert() (gas: 19637)
+RegistryModuleOwnerCustom_registerAdminViaGetCCIPAdmin:test_registerAdminViaGetCCIPAdmin_Success() (gas: 129918)
+RegistryModuleOwnerCustom_registerAdminViaOwner:test_registerAdminViaOwner_Revert() (gas: 19451)
+RegistryModuleOwnerCustom_registerAdminViaOwner:test_registerAdminViaOwner_Success() (gas: 129731)
+Router_applyRampUpdates:test_OffRampMismatch_Revert() (gas: 89288)
+Router_applyRampUpdates:test_OffRampUpdatesWithRouting() (gas: 10642128)
+Router_applyRampUpdates:test_OnRampDisable() (gas: 55913)
+Router_applyRampUpdates:test_OnlyOwner_Revert() (gas: 12311)
+Router_ccipSend:test_CCIPSendLinkFeeNoTokenSuccess_gas() (gas: 113861)
+Router_ccipSend:test_CCIPSendLinkFeeOneTokenSuccess_gas() (gas: 200634)
+Router_ccipSend:test_CCIPSendNativeFeeNoTokenSuccess_gas() (gas: 128508)
+Router_ccipSend:test_CCIPSendNativeFeeOneTokenSuccess_gas() (gas: 215283)
+Router_ccipSend:test_FeeTokenAmountTooLow_Revert() (gas: 66275)
+Router_ccipSend:test_InvalidMsgValue() (gas: 31963)
+Router_ccipSend:test_NativeFeeTokenInsufficientValue() (gas: 68711)
+Router_ccipSend:test_NativeFeeTokenOverpay_Success() (gas: 173605)
+Router_ccipSend:test_NativeFeeTokenZeroValue() (gas: 56037)
+Router_ccipSend:test_NativeFeeToken_Success() (gas: 172199)
+Router_ccipSend:test_NonLinkFeeToken_Success() (gas: 242707)
+Router_ccipSend:test_UnsupportedDestinationChain_Revert() (gas: 24749)
+Router_ccipSend:test_WhenNotHealthy_Revert() (gas: 44724)
+Router_ccipSend:test_WrappedNativeFeeToken_Success() (gas: 174415)
+Router_ccipSend:test_ZeroFeeAndGasPrice_Success() (gas: 245121)
+Router_constructor:test_Constructor_Success() (gas: 13074)
+Router_getArmProxy:test_getArmProxy() (gas: 10561)
+Router_getFee:test_GetFeeSupportedChain_Success() (gas: 46464)
+Router_getFee:test_UnsupportedDestinationChain_Revert() (gas: 17138)
+Router_getSupportedTokens:test_GetSupportedTokens_Revert() (gas: 10460)
+Router_recoverTokens:test_RecoverTokensInvalidRecipient_Revert() (gas: 11316)
+Router_recoverTokens:test_RecoverTokensNoFunds_Revert() (gas: 17761)
+Router_recoverTokens:test_RecoverTokensNonOwner_Revert() (gas: 11159)
+Router_recoverTokens:test_RecoverTokensValueReceiver_Revert() (gas: 422138)
+Router_recoverTokens:test_RecoverTokens_Success() (gas: 50437)
+Router_routeMessage:test_AutoExec_Success() (gas: 42684)
+Router_routeMessage:test_ExecutionEvent_Success() (gas: 158002)
+Router_routeMessage:test_ManualExec_Success() (gas: 35381)
+Router_routeMessage:test_OnlyOffRamp_Revert() (gas: 25116)
+Router_routeMessage:test_WhenNotHealthy_Revert() (gas: 44724)
+Router_setWrappedNative:test_OnlyOwner_Revert() (gas: 10985)
+SelfFundedPingPong_ccipReceive:test_FundingIfNotANop_Revert() (gas: 53540)
+SelfFundedPingPong_ccipReceive:test_Funding_Success() (gas: 416930)
+SelfFundedPingPong_setCountIncrBeforeFunding:test_setCountIncrBeforeFunding() (gas: 20157)
+TokenAdminRegistry_acceptAdminRole:test_acceptAdminRole_OnlyPendingAdministrator_Revert() (gas: 51085)
+TokenAdminRegistry_acceptAdminRole:test_acceptAdminRole_Success() (gas: 43947)
+TokenAdminRegistry_addRegistryModule:test_addRegistryModule_OnlyOwner_Revert() (gas: 12629)
+TokenAdminRegistry_addRegistryModule:test_addRegistryModule_Success() (gas: 67011)
+TokenAdminRegistry_getAllConfiguredTokens:test_getAllConfiguredTokens_outOfBounds_Success() (gas: 11350)
+TokenAdminRegistry_getPool:test_getPool_Success() (gas: 17581)
+TokenAdminRegistry_getPools:test_getPools_Success() (gas: 39902)
+TokenAdminRegistry_isAdministrator:test_isAdministrator_Success() (gas: 105922)
+TokenAdminRegistry_proposeAdministrator:test_proposeAdministrator_AlreadyRegistered_Revert() (gas: 104001)
+TokenAdminRegistry_proposeAdministrator:test_proposeAdministrator_OnlyRegistryModule_Revert() (gas: 15481)
+TokenAdminRegistry_proposeAdministrator:test_proposeAdministrator_ZeroAddress_Revert() (gas: 15026)
+TokenAdminRegistry_proposeAdministrator:test_proposeAdministrator_module_Success() (gas: 112536)
+TokenAdminRegistry_proposeAdministrator:test_proposeAdministrator_owner_Success() (gas: 107656)
+TokenAdminRegistry_proposeAdministrator:test_proposeAdministrator_reRegisterWhileUnclaimed_Success() (gas: 115686)
+TokenAdminRegistry_removeRegistryModule:test_removeRegistryModule_OnlyOwner_Revert() (gas: 12585)
+TokenAdminRegistry_removeRegistryModule:test_removeRegistryModule_Success() (gas: 54473)
+TokenAdminRegistry_setPool:test_setPool_InvalidTokenPoolToken_Revert() (gas: 19148)
+TokenAdminRegistry_setPool:test_setPool_OnlyAdministrator_Revert() (gas: 18020)
+TokenAdminRegistry_setPool:test_setPool_Success() (gas: 35943)
+TokenAdminRegistry_setPool:test_setPool_ZeroAddressRemovesPool_Success() (gas: 30617)
+TokenAdminRegistry_transferAdminRole:test_transferAdminRole_OnlyAdministrator_Revert() (gas: 18043)
+TokenAdminRegistry_transferAdminRole:test_transferAdminRole_Success() (gas: 49390)
+TokenPoolAndProxy:test_lockOrBurn_burnMint_Success() (gas: 6036775)
+TokenPoolAndProxy:test_lockOrBurn_lockRelease_Success() (gas: 6282531)
+TokenPoolAndProxyMigration:test_tokenPoolMigration_Success_1_2() (gas: 6883397)
+TokenPoolAndProxyMigration:test_tokenPoolMigration_Success_1_4() (gas: 7067512)
+TokenPoolWithAllowList_applyAllowListUpdates:test_AllowListNotEnabled_Revert() (gas: 2169749)
+TokenPoolWithAllowList_applyAllowListUpdates:test_OnlyOwner_Revert() (gas: 12089)
+TokenPoolWithAllowList_applyAllowListUpdates:test_SetAllowListSkipsZero_Success() (gas: 23280)
+TokenPoolWithAllowList_applyAllowListUpdates:test_SetAllowList_Success() (gas: 177516)
+TokenPoolWithAllowList_getAllowList:test_GetAllowList_Success() (gas: 23648)
+TokenPoolWithAllowList_getAllowListEnabled:test_GetAllowListEnabled_Success() (gas: 8363)
+TokenPoolWithAllowList_setRouter:test_SetRouter_Success() (gas: 24765)
+TokenPool_applyChainUpdates:test_applyChainUpdates_DisabledNonZeroRateLimit_Revert() (gas: 271305)
+TokenPool_applyChainUpdates:test_applyChainUpdates_InvalidRateLimitRate_Revert() (gas: 541162)
+TokenPool_applyChainUpdates:test_applyChainUpdates_NonExistentChain_Revert() (gas: 18344)
+TokenPool_applyChainUpdates:test_applyChainUpdates_OnlyCallableByOwner_Revert() (gas: 11385)
+TokenPool_applyChainUpdates:test_applyChainUpdates_Success() (gas: 476472)
+TokenPool_applyChainUpdates:test_applyChainUpdates_ZeroAddressNotAllowed_Revert() (gas: 157074)
+TokenPool_constructor:test_ZeroAddressNotAllowed_Revert() (gas: 70676)
+TokenPool_constructor:test_immutableFields_Success() (gas: 20522)
+TokenPool_getRemotePool:test_getRemotePool_Success() (gas: 273962)
+TokenPool_onlyOffRamp:test_CallerIsNotARampOnRouter_Revert() (gas: 276952)
+TokenPool_onlyOffRamp:test_ChainNotAllowed_Revert() (gas: 289509)
+TokenPool_onlyOffRamp:test_onlyOffRamp_Success() (gas: 349763)
+TokenPool_onlyOnRamp:test_CallerIsNotARampOnRouter_Revert() (gas: 276643)
+TokenPool_onlyOnRamp:test_ChainNotAllowed_Revert() (gas: 253466)
+TokenPool_onlyOnRamp:test_onlyOnRamp_Success() (gas: 304761)
+TokenPool_setChainRateLimiterConfig:test_NonExistentChain_Revert() (gas: 14906)
+TokenPool_setChainRateLimiterConfig:test_OnlyOwner_Revert() (gas: 12565)
+TokenPool_setRemotePool:test_setRemotePool_NonExistentChain_Reverts() (gas: 15598)
+TokenPool_setRemotePool:test_setRemotePool_OnlyOwner_Reverts() (gas: 13173)
+TokenPool_setRemotePool:test_setRemotePool_Success() (gas: 281890)
+TokenProxy_ccipSend:test_CcipSendGasShouldBeZero_Revert() (gas: 17109)
+TokenProxy_ccipSend:test_CcipSendInsufficientAllowance_Revert() (gas: 136351)
+TokenProxy_ccipSend:test_CcipSendInvalidToken_Revert() (gas: 15919)
+TokenProxy_ccipSend:test_CcipSendNative_Success() (gas: 244483)
+TokenProxy_ccipSend:test_CcipSendNoDataAllowed_Revert() (gas: 16303)
+TokenProxy_ccipSend:test_CcipSend_Success() (gas: 261100)
+TokenProxy_constructor:test_Constructor() (gas: 13812)
+TokenProxy_getFee:test_GetFeeGasShouldBeZero_Revert() (gas: 16827)
+TokenProxy_getFee:test_GetFeeInvalidToken_Revert() (gas: 12658)
+TokenProxy_getFee:test_GetFeeNoDataAllowed_Revert() (gas: 15849)
+TokenProxy_getFee:test_GetFee_Success() (gas: 86948)
+USDCTokenPool__validateMessage:test_ValidateInvalidMessage_Revert() (gas: 24960)
+USDCTokenPool_lockOrBurn:test_CallerIsNotARampOnRouter_Revert() (gas: 35312)
+USDCTokenPool_lockOrBurn:test_LockOrBurnWithAllowList_Revert() (gas: 30063)
+USDCTokenPool_lockOrBurn:test_LockOrBurn_Success() (gas: 132864)
+USDCTokenPool_lockOrBurn:test_UnknownDomain_Revert() (gas: 477209)
+USDCTokenPool_lockOrBurn:test_lockOrBurn_InvalidReceiver_Revert() (gas: 52606)
+USDCTokenPool_releaseOrMint:test_ReleaseOrMintRealTx_Success() (gas: 289268)
+USDCTokenPool_releaseOrMint:test_TokenMaxCapacityExceeded_Revert() (gas: 50682)
+USDCTokenPool_releaseOrMint:test_UnlockingUSDCFailed_Revert() (gas: 119185)
+USDCTokenPool_setDomains:test_InvalidDomain_Revert() (gas: 66150)
+USDCTokenPool_setDomains:test_OnlyOwner_Revert() (gas: 11339)
+USDCTokenPool_supportsInterface:test_SupportsInterface_Success() (gas: 9876)
\ No newline at end of file
diff --git a/contracts/gas-snapshots/liquiditymanager.gas-snapshot b/contracts/gas-snapshots/liquiditymanager.gas-snapshot
new file mode 100644
index 00000000000..53483ed6c7c
--- /dev/null
+++ b/contracts/gas-snapshots/liquiditymanager.gas-snapshot
@@ -0,0 +1,48 @@
+LiquidityManager__report:test_EmptyReportReverts() (gas: 11181)
+LiquidityManager_addLiquidity:test_addLiquiditySuccess() (gas: 279154)
+LiquidityManager_rebalanceLiquidity:test_InsufficientLiquidityReverts() (gas: 206745)
+LiquidityManager_rebalanceLiquidity:test_InvalidRemoteChainReverts() (gas: 192319)
+LiquidityManager_rebalanceLiquidity:test_rebalanceBetweenPoolsSuccess() (gas: 9141768)
+LiquidityManager_rebalanceLiquidity:test_rebalanceBetweenPoolsSuccess_AlreadyFinalized() (gas: 8898695)
+LiquidityManager_rebalanceLiquidity:test_rebalanceBetweenPools_MultiStageFinalization() (gas: 8893901)
+LiquidityManager_rebalanceLiquidity:test_rebalanceBetweenPools_NativeRewrap() (gas: 8821699)
+LiquidityManager_rebalanceLiquidity:test_rebalanceLiquiditySuccess() (gas: 382897)
+LiquidityManager_receive:test_receive_success() (gas: 21182)
+LiquidityManager_removeLiquidity:test_InsufficientLiquidityReverts() (gas: 184869)
+LiquidityManager_removeLiquidity:test_OnlyFinanceRoleReverts() (gas: 10872)
+LiquidityManager_removeLiquidity:test_removeLiquiditySuccess() (gas: 236342)
+LiquidityManager_setCrossChainRebalancer:test_OnlyOwnerReverts() (gas: 17005)
+LiquidityManager_setCrossChainRebalancer:test_ZeroAddressReverts() (gas: 21624)
+LiquidityManager_setCrossChainRebalancer:test_ZeroChainSelectorReverts() (gas: 13099)
+LiquidityManager_setCrossChainRebalancer:test_setCrossChainRebalancerSuccess() (gas: 162186)
+LiquidityManager_setFinanceRole:test_OnlyOwnerReverts() (gas: 10987)
+LiquidityManager_setFinanceRole:test_setFinanceRoleSuccess() (gas: 21836)
+LiquidityManager_setLocalLiquidityContainer:test_OnlyOwnerReverts() (gas: 11052)
+LiquidityManager_setLocalLiquidityContainer:test_ReverstWhen_CalledWithTheZeroAddress() (gas: 10643)
+LiquidityManager_setLocalLiquidityContainer:test_setLocalLiquidityContainerSuccess() (gas: 3436651)
+LiquidityManager_setMinimumLiquidity:test_OnlyOwnerReverts() (gas: 10925)
+LiquidityManager_setMinimumLiquidity:test_setMinimumLiquiditySuccess() (gas: 36389)
+LiquidityManager_withdrawERC20:test_withdrawERC20Reverts() (gas: 180359)
+LiquidityManager_withdrawERC20:test_withdrawERC20Success() (gas: 205858)
+LiquidityManager_withdrawNative:test_OnlyFinanceRoleReverts() (gas: 13046)
+LiquidityManager_withdrawNative:test_withdrawNative_success() (gas: 51398)
+OCR3Base_setOCR3Config:testFMustBePositiveReverts() (gas: 12245)
+OCR3Base_setOCR3Config:testFTooHighReverts() (gas: 12429)
+OCR3Base_setOCR3Config:testOracleOutOfRegisterReverts() (gas: 14847)
+OCR3Base_setOCR3Config:testRepeatAddressReverts() (gas: 44932)
+OCR3Base_setOCR3Config:testSetConfigSuccess() (gas: 154642)
+OCR3Base_setOCR3Config:testSignerCannotBeZeroAddressReverts() (gas: 23712)
+OCR3Base_setOCR3Config:testTooManySignersReverts() (gas: 19832)
+OCR3Base_setOCR3Config:testTransmitterCannotBeZeroAddressReverts() (gas: 46539)
+OCR3Base_transmit:testConfigDigestMismatchReverts() (gas: 24827)
+OCR3Base_transmit:testForkedChainReverts() (gas: 42846)
+OCR3Base_transmit:testNonIncreasingSequenceNumberReverts() (gas: 30522)
+OCR3Base_transmit:testNonUniqueSignatureReverts() (gas: 60370)
+OCR3Base_transmit:testSignatureOutOfRegistrationReverts() (gas: 26128)
+OCR3Base_transmit:testTransmit2SignersSuccess_gas() (gas: 56783)
+OCR3Base_transmit:testUnAuthorizedTransmitterReverts() (gas: 28618)
+OCR3Base_transmit:testUnauthorizedSignerReverts() (gas: 44759)
+OCR3Base_transmit:testWrongNumberOfSignaturesReverts() (gas: 25678)
+OptimismL1BridgeAdapter_finalizeWithdrawERC20:testFinalizeWithdrawERC20Reverts() (gas: 12932)
+OptimismL1BridgeAdapter_finalizeWithdrawERC20:testfinalizeWithdrawERC20FinalizeSuccess() (gas: 16972)
+OptimismL1BridgeAdapter_finalizeWithdrawERC20:testfinalizeWithdrawERC20proveWithdrawalSuccess() (gas: 20758)
\ No newline at end of file
diff --git a/contracts/hardhat.config.ts b/contracts/hardhat.config.ts
index 1b2ac1bdf19..73e70081e9a 100644
--- a/contracts/hardhat.config.ts
+++ b/contracts/hardhat.config.ts
@@ -21,7 +21,8 @@ subtask(TASK_COMPILE_SOLIDITY_GET_SOURCE_PATHS).setAction(
async (_, __, runSuper) => {
const paths = await runSuper()
const noTests = paths.filter((p: string) => !p.endsWith('.t.sol'))
- return noTests.filter(
+ const noCCIP = noTests.filter((p: string) => !p.includes('/v0.8/ccip'))
+ return noCCIP.filter(
(p: string) => !p.includes('src/v0.8/vendor/forge-std'),
)
},
diff --git a/contracts/package.json b/contracts/package.json
index 5a13d561f0c..85bae226c43 100644
--- a/contracts/package.json
+++ b/contracts/package.json
@@ -18,7 +18,7 @@
"prepublishOnly": "pnpm compile && ./scripts/prepublish_generate_abi_folder",
"publish-beta": "pnpm publish --tag beta",
"publish-prod": "pnpm publish --tag latest",
- "solhint": "solhint --max-warnings 2 \"./src/v0.8/**/*.sol\""
+ "solhint": "solhint --max-warnings 0 \"./src/v0.8/**/*.sol\""
},
"files": [
"src/v0.8",
@@ -78,6 +78,8 @@
"typescript": "^5.4.5"
},
"dependencies": {
+ "@arbitrum/nitro-contracts": "1.1.1",
+ "@arbitrum/token-bridge-contracts": "1.1.2",
"@changesets/changelog-github": "^0.5.0",
"@changesets/cli": "~2.27.3",
"@eth-optimism/contracts": "0.6.0",
diff --git a/contracts/pnpm-lock.yaml b/contracts/pnpm-lock.yaml
index 4ad8deda991..825715f4160 100644
--- a/contracts/pnpm-lock.yaml
+++ b/contracts/pnpm-lock.yaml
@@ -11,6 +11,12 @@ importers:
.:
dependencies:
+ '@arbitrum/nitro-contracts':
+ specifier: 1.1.1
+ version: 1.1.1
+ '@arbitrum/token-bridge-contracts':
+ specifier: 1.1.2
+ version: 1.1.2
'@changesets/changelog-github':
specifier: ^0.5.0
version: 0.5.0
@@ -50,22 +56,22 @@ importers:
version: 5.7.2
'@nomicfoundation/hardhat-chai-matchers':
specifier: ^1.0.6
- version: 1.0.6(@nomiclabs/hardhat-ethers@2.2.3)(chai@4.4.1)(ethers@5.7.2)(hardhat@2.20.1)
+ version: 1.0.6(@nomiclabs/hardhat-ethers@2.2.3(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)))(chai@4.4.1)(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))
'@nomicfoundation/hardhat-ethers':
specifier: ^3.0.6
- version: 3.0.6(ethers@5.7.2)(hardhat@2.20.1)
+ version: 3.0.6(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))
'@nomicfoundation/hardhat-network-helpers':
specifier: ^1.0.9
- version: 1.0.10(hardhat@2.20.1)
+ version: 1.0.10(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))
'@nomicfoundation/hardhat-verify':
specifier: ^2.0.7
- version: 2.0.7(hardhat@2.20.1)
+ version: 2.0.7(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))
'@typechain/ethers-v5':
specifier: ^7.2.0
- version: 7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2)(typescript@5.4.5)
+ version: 7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2(typescript@5.4.5))(typescript@5.4.5)
'@typechain/hardhat':
specifier: ^7.0.0
- version: 7.0.0(@ethersproject/abi@5.7.0)(@ethersproject/providers@5.7.2)(@typechain/ethers-v5@7.2.0)(ethers@5.7.2)(hardhat@2.20.1)(typechain@8.3.2)
+ version: 7.0.0(@ethersproject/abi@5.7.0)(@ethersproject/providers@5.7.2)(@typechain/ethers-v5@7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2(typescript@5.4.5))(typescript@5.4.5))(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))(typechain@8.3.2(typescript@5.4.5))
'@types/cbor':
specifier: ~5.0.1
version: 5.0.1
@@ -86,7 +92,7 @@ importers:
version: 20.12.12
'@typescript-eslint/eslint-plugin':
specifier: ^7.10.0
- version: 7.10.0(@typescript-eslint/parser@7.10.0)(eslint@8.57.0)(typescript@5.4.5)
+ version: 7.10.0(@typescript-eslint/parser@7.10.0(eslint@8.57.0)(typescript@5.4.5))(eslint@8.57.0)(typescript@5.4.5)
'@typescript-eslint/parser':
specifier: ^7.10.0
version: 7.10.0(eslint@8.57.0)(typescript@5.4.5)
@@ -113,16 +119,16 @@ importers:
version: 9.1.0(eslint@8.57.0)
eslint-plugin-prettier:
specifier: ^5.1.3
- version: 5.1.3(eslint-config-prettier@9.1.0)(eslint@8.57.0)(prettier@3.2.5)
+ version: 5.1.3(eslint-config-prettier@9.1.0(eslint@8.57.0))(eslint@8.57.0)(prettier@3.2.5)
ethers:
specifier: ~5.7.2
version: 5.7.2
hardhat:
specifier: ~2.20.1
- version: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ version: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
hardhat-abi-exporter:
specifier: ^2.10.1
- version: 2.10.1(hardhat@2.20.1)
+ version: 2.10.1(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))
hardhat-ignore-warnings:
specifier: ^0.2.6
version: 0.2.11
@@ -143,7 +149,7 @@ importers:
version: '@chainlink/solhint-plugin-chainlink-solidity@https://codeload.github.com/smartcontractkit/chainlink-solhint-rules/tar.gz/1b4c0c2663fcd983589d4f33a2e73908624ed43c'
solhint-plugin-prettier:
specifier: ^0.1.0
- version: 0.1.0(prettier-plugin-solidity@1.3.1)(prettier@3.2.5)
+ version: 0.1.0(prettier-plugin-solidity@1.3.1(prettier@3.2.5))(prettier@3.2.5)
ts-node:
specifier: ^10.9.2
version: 10.9.2(@types/node@20.12.12)(typescript@5.4.5)
@@ -160,6 +166,12 @@ packages:
resolution: {integrity: sha512-1Yjs2SvM8TflER/OD3cOjhWWOZb58A2t7wpE2S9XfBYTiIl+XFhQG2bjy4Pu1I+EAlCNUzRDYDdFwFYUKvXcIA==}
engines: {node: '>=0.10.0'}
+ '@arbitrum/nitro-contracts@1.1.1':
+ resolution: {integrity: sha512-4Tyk3XVHz+bm8UujUC78LYSw3xAxyYvBCxfEX4z3qE4/ww7Qck/rmce5gbHMzQjArEAzAP2YSfYIFuIFuRXtfg==}
+
+ '@arbitrum/token-bridge-contracts@1.1.2':
+ resolution: {integrity: sha512-k7AZXiB2HFecJ1KfaDBqgOKe3Loo1ttGLC7hUOVB+0YrihIR6cYpJRuqKSKK4YCy+FF21AUDtaG3x57OFM667Q==}
+
'@babel/code-frame@7.18.6':
resolution: {integrity: sha512-TDCmlK5eOvH+eH7cdAFlNXeVJqWIQ7gW9tY1GJIpUtFb6CmjVyq2VM3u71bOyR8CRihcCgMUYoDNyLXao3+70Q==}
engines: {node: '>=6.9.0'}
@@ -178,7 +190,6 @@ packages:
'@chainlink/solhint-plugin-chainlink-solidity@https://codeload.github.com/smartcontractkit/chainlink-solhint-rules/tar.gz/1b4c0c2663fcd983589d4f33a2e73908624ed43c':
resolution: {tarball: https://codeload.github.com/smartcontractkit/chainlink-solhint-rules/tar.gz/1b4c0c2663fcd983589d4f33a2e73908624ed43c}
- name: '@chainlink/solhint-plugin-chainlink-solidity'
version: 1.2.0
'@changesets/apply-release-plan@7.0.1':
@@ -572,12 +583,37 @@ packages:
ethers: ^5.0.0
hardhat: ^2.0.0
+ '@offchainlabs/upgrade-executor@1.1.0-beta.0':
+ resolution: {integrity: sha512-mpn6PHjH/KDDjNX0pXHEKdyv8m6DVGQiI2nGzQn0JbM1nOSHJpWx6fvfjtH7YxHJ6zBZTcsKkqGkFKDtCfoSLw==}
+
+ '@openzeppelin/contracts-upgradeable@4.5.2':
+ resolution: {integrity: sha512-xgWZYaPlrEOQo3cBj97Ufiuv79SPd8Brh4GcFYhPgb6WvAq4ppz8dWKL6h+jLAK01rUqMRp/TS9AdXgAeNvCLA==}
+
+ '@openzeppelin/contracts-upgradeable@4.7.3':
+ resolution: {integrity: sha512-+wuegAMaLcZnLCJIvrVUDzA9z/Wp93f0Dla/4jJvIhijRrPabjQbZe6fWiECLaJyfn5ci9fqf9vTw3xpQOad2A==}
+
+ '@openzeppelin/contracts-upgradeable@4.8.3':
+ resolution: {integrity: sha512-SXDRl7HKpl2WDoJpn7CK/M9U4Z8gNXDHHChAKh0Iz+Wew3wu6CmFYBeie3je8V0GSXZAIYYwUktSrnW/kwVPtg==}
+
'@openzeppelin/contracts-upgradeable@4.9.3':
resolution: {integrity: sha512-jjaHAVRMrE4UuZNfDwjlLGDxTHWIOwTJS2ldnc278a0gevfXfPr8hxKEVBGFBE96kl2G3VHDZhUimw/+G3TG2A==}
+ '@openzeppelin/contracts@4.5.0':
+ resolution: {integrity: sha512-fdkzKPYMjrRiPK6K4y64e6GzULR7R7RwxSigHS8DDp7aWDeoReqsQI+cxHV1UuhAqX69L1lAaWDxenfP+xiqzA==}
+
+ '@openzeppelin/contracts@4.7.3':
+ resolution: {integrity: sha512-dGRS0agJzu8ybo44pCIf3xBaPQN/65AIXNgK8+4gzKd5kbvlqyxryUYVLJv7fK98Seyd2hDZzVEHSWAh0Bt1Yw==}
+
+ '@openzeppelin/contracts@4.8.3':
+ resolution: {integrity: sha512-bQHV8R9Me8IaJoJ2vPG4rXcL7seB7YVuskr4f+f5RyOStSZetwzkWtoqDMl5erkBJy0lDRUnIR2WIkPiC0GJlg==}
+
'@openzeppelin/contracts@4.9.3':
resolution: {integrity: sha512-He3LieZ1pP2TNt5JbkPA4PNT9WC3gOTOlDcFGJW4Le4QKqwmiNJCRt44APfxMxvq7OugU/cqYuPcSBzOw38DAg==}
+ '@openzeppelin/upgrades-core@1.34.4':
+ resolution: {integrity: sha512-iGN3StqYHYVqqSKs8hWY+Gz6VkiEqOkQccBhHl7lHLGBJF91QUZ8wNMZ59SA5Usg1Fstu/HurvZTCEshPJAZ8w==}
+ hasBin: true
+
'@pkgr/core@0.1.1':
resolution: {integrity: sha512-cq8o4cWH0ibXh9VGi5P20Tu9XF/0fFXl9EUinr9QfTM7a7p0oTA4iJRCQWppXR1Pg8dSM0UCItCkPwsk9qWWYA==}
engines: {node: ^12.20.0 || ^14.18.0 || >=16.0.0}
@@ -821,6 +857,9 @@ packages:
'@ungap/structured-clone@1.2.0':
resolution: {integrity: sha512-zuVdFrMJiuCDQUMCzQaD6KL28MjnqqN8XnAqiEq9PNm/hCPTSGfrXCOfwj1ow4LFb/tNymJPwsNbVePc1xFqrQ==}
+ '@yarnpkg/lockfile@1.1.0':
+ resolution: {integrity: sha512-GpSwvyXOcOOlV70vbnzjj4fW5xW/FdUF6nQEt1ENy7m4ZCczi1+/buVUPAqmGfqznsORNFzUMjctTIp8a9tuCQ==}
+
abi-to-sol@0.6.6:
resolution: {integrity: sha512-PRn81rSpv6NXFPYQSw7ujruqIP6UkwZ/XoFldtiqCX8+2kHVc73xVaUVvdbro06vvBVZiwnxhEIGdI4BRMwGHw==}
hasBin: true
@@ -924,10 +963,18 @@ packages:
array-buffer-byte-length@1.0.0:
resolution: {integrity: sha512-LPuwb2P+NrQw3XhxGc36+XSvuBPopovXYTR9Ew++Du9Yb/bx5AzBfrIsBoj0EZUifjQU+sHL21sseZ3jerWO/A==}
+ array-buffer-byte-length@1.0.1:
+ resolution: {integrity: sha512-ahC5W1xgou+KTXix4sAO8Ki12Q+jf4i0+tmk3sC+zgcynshkHxzpXdImBehiUYKKKDwvfFiJl1tZt6ewscS1Mg==}
+ engines: {node: '>= 0.4'}
+
array-union@2.1.0:
resolution: {integrity: sha512-HGyxoOTYUyCM6stUe6EJgnd4EoewAI7zMdfqO+kGjnlZmBDz/cR5pf8r/cR4Wq60sL/p0IkcjUEEPwS3GFrIyw==}
engines: {node: '>=8'}
+ array.prototype.findlast@1.2.5:
+ resolution: {integrity: sha512-CVvd6FHg1Z3POpBLxO6E6zr+rSKEQ9L6rZHAaY7lLfhKsWYUBBOuMs0e9o24oopj6H+geRCX0YJ+TJLBK2eHyQ==}
+ engines: {node: '>= 0.4'}
+
array.prototype.flat@1.3.2:
resolution: {integrity: sha512-djYB+Zx2vLewY8RWlNCUdHjDXs2XOgm602S9E7P/UpHgfeHL00cRiIF+IN/G/aUJ7kGPb6yO/ErDI5V2s8iycA==}
engines: {node: '>= 0.4'}
@@ -936,6 +983,10 @@ packages:
resolution: {integrity: sha512-yMBKppFur/fbHu9/6USUe03bZ4knMYiwFBcyiaXB8Go0qNehwX6inYPzK9U0NeQvGxKthcmHcaR8P5MStSRBAw==}
engines: {node: '>= 0.4'}
+ arraybuffer.prototype.slice@1.0.3:
+ resolution: {integrity: sha512-bMxMKAjg13EBSVscxTaYA4mRc5t1UAXa2kXiGTNfZ079HIWXEkKmkgFrh/nJqamaLSrXO5H4WFFkPEaLJWbs3A==}
+ engines: {node: '>= 0.4'}
+
arrify@1.0.1:
resolution: {integrity: sha512-3CYzex9M9FGQjCGMGyi6/31c8GJbgb0qGyrx5HWxPd0aCwh4cB2YjMb2Xf9UuoogrMrlO9cTqnB5rI5GHZTcUA==}
engines: {node: '>=0.10.0'}
@@ -958,6 +1009,10 @@ packages:
resolution: {integrity: sha512-DMD0KiN46eipeziST1LPP/STfDU0sufISXmjSgvVsoU2tqxctQeASejWcfNtxYKqETM1UxQ8sp2OrSBWpHY6sw==}
engines: {node: '>= 0.4'}
+ available-typed-arrays@1.0.7:
+ resolution: {integrity: sha512-wvUjBtSGN7+7SjNpq/9M2Tg350UZD3q62IFZLbRAR1bSMlCo1ZaeW+BJ+D090e4hIIZLBcTDWe4Mh4jvUDajzQ==}
+ engines: {node: '>= 0.4'}
+
balanced-match@1.0.0:
resolution: {integrity: sha512-9Y0g0Q8rmSt+H33DfKv7FOc3v+iRI+o1lbzt8jGcIosYW37IIW/2XVYq5NPdmaD5NQ59Nk26Kl/vZbwW9Fr8vg==}
@@ -1056,6 +1111,10 @@ packages:
call-bind@1.0.5:
resolution: {integrity: sha512-C3nQxfFZxFRVoJoGKKI8y3MOEo129NQ+FgQ08iye+Mk4zNZZGdjfs06bVTr+DBSlA66Q2VEcMki/cUCP4SercQ==}
+ call-bind@1.0.7:
+ resolution: {integrity: sha512-GHTSNSYICQ7scH7sZ+M2rFopRoLh8t2bLSW6BbgrtLsahOIB5iyAVJf9GjWK3cYTDaMj4XdBpM1cA6pIS0Kv2w==}
+ engines: {node: '>= 0.4'}
+
callsites@3.1.0:
resolution: {integrity: sha512-P8BjAsXvZS+VIDUI11hHCQEv74YT67YUi5JJFNWIqL235sBmjX4+qx9Muvls5ivyNENctx46xQLQ3aTuE7ssaQ==}
engines: {node: '>=6'}
@@ -1083,6 +1142,10 @@ packages:
resolution: {integrity: sha512-DwGjNW9omn6EwP70aXsn7FQJx5kO12tX0bZkaTjzdVFM6/7nhA4t0EENocKGx6D2Bch9PE2KzCUf5SceBdeijg==}
engines: {node: '>=12.19'}
+ cbor@9.0.2:
+ resolution: {integrity: sha512-JPypkxsB10s9QOWwa6zwPzqE1Md3vqpPc+cai4sAecuCsRyAtAl/pMyhPlMbT/xtPnm2dznJZYRLui57qiRhaQ==}
+ engines: {node: '>=16'}
+
chai-as-promised@7.1.1:
resolution: {integrity: sha512-azL6xMoi+uxu6z4rhWQ1jbdUhOMhis2PvscD/xjLqNMkv3BPPp2JyyuTHOrf9BOosGpNQ11v6BKv/g57RXbiaA==}
peerDependencies:
@@ -1183,6 +1246,9 @@ packages:
commander@3.0.2:
resolution: {integrity: sha512-Gar0ASD4BDyKC4hl4DwHqDrmvjoxWKZigVnAbn5H1owvm4CxCPdb0HQDehwNYMJpla5+M2tPmPARzhtYuwpHow==}
+ compare-versions@6.1.1:
+ resolution: {integrity: sha512-4hm4VPpIecmlg59CHXnRDnqGplJFrbLG4aFEl5vl6cK1u76ws3LLvX7ikFnTDl5vo39sjWD6AaDPYodJp/NNHg==}
+
concat-map@0.0.1:
resolution: {integrity: sha512-/Srv4dswyQNBfohGpz9o6Yb3Gz3SrUDqBH5rTuhGR7ahtlbYKnVxw2bCFMRljaA7EXHaXZ8wsHdodFvbkhKmqg==}
@@ -1215,6 +1281,10 @@ packages:
cross-spawn@5.1.0:
resolution: {integrity: sha512-pTgQJ5KC0d2hcY8eyL1IzlBPYjTkyH72XRZPnLyKus2mBfNjQs3klqbJU2VILqZryAZUt9JOb3h/mWMy23/f5A==}
+ cross-spawn@6.0.5:
+ resolution: {integrity: sha512-eTVLrBSt7fjbDygz805pMnstIs2VTBNkRm0qxZd+M7A5XDdxVRWO5MxGBXZhjY4cqLYLdtrGqRf8mBPmzwSpWQ==}
+ engines: {node: '>=4.8'}
+
cross-spawn@7.0.3:
resolution: {integrity: sha512-iRDPJKUPVEND7dHPO8rkbOnPpyDygcDFtWjpeWNCgy8WP2rXcxXL8TskReQl6OrB2G7+UJrags1q15Fudc7G6w==}
engines: {node: '>= 8'}
@@ -1232,6 +1302,18 @@ packages:
resolution: {integrity: sha512-QTaY0XjjhTQOdguARF0lGKm5/mEq9PD9/VhZZegHDIBq2tQwgNpHc3dneD4mGo2iJs+fTKv5Bp0fZ+BRuY3Z0g==}
engines: {node: '>= 0.1.90'}
+ data-view-buffer@1.0.1:
+ resolution: {integrity: sha512-0lht7OugA5x3iJLOWFhWK/5ehONdprk0ISXqVFn/NFrDu+cuc8iADFrGQz5BnRK7LLU3JmkbXSxaqX+/mXYtUA==}
+ engines: {node: '>= 0.4'}
+
+ data-view-byte-length@1.0.1:
+ resolution: {integrity: sha512-4J7wRJD3ABAzr8wP+OcIcqq2dlUKp4DVflx++hs5h5ZKydWMI6/D/fAot+yh6g2tHh8fLFTvNOaVN357NvSrOQ==}
+ engines: {node: '>= 0.4'}
+
+ data-view-byte-offset@1.0.0:
+ resolution: {integrity: sha512-t/Ygsytq+R995EJ5PZlD4Cu56sWa8InXySaViRzw9apusqsOO2bQP+SbYzAhR0pFKoB+43lYy8rWban9JSuXnA==}
+ engines: {node: '>= 0.4'}
+
dataloader@1.4.0:
resolution: {integrity: sha512-68s5jYdlvasItOJnCuI2Q9s4q98g0pCyL3HrcKJu8KNugUl8ahgmZYg38ysLTgQjjXX3H8CJLkAvWrclWfcalw==}
@@ -1285,6 +1367,10 @@ packages:
resolution: {integrity: sha512-E7uGkTzkk1d0ByLeSc6ZsFS79Axg+m1P/VsgYsxHgiuc3tFSj+MjMIwe90FC4lOAZzNBdY7kkO2P2wKdsQ1vgQ==}
engines: {node: '>= 0.4'}
+ define-data-property@1.1.4:
+ resolution: {integrity: sha512-rBMvIzlpA8v6E+SJZoo++HAYqsLrkg7MSfIinMPFhmkorw7X+dOXVJQs+QT69zGkzMyfDnIMN2Wid1+NbL3T+A==}
+ engines: {node: '>= 0.4'}
+
define-properties@1.2.1:
resolution: {integrity: sha512-8QmQKqEASLd5nx0U1B1okLElbUuuttJ/AnYmRXbbbGDWh6uS208EjD4Xqq/I9wK7u0v6O08XhTWnt5XtEbR6Dg==}
engines: {node: '>= 0.4'}
@@ -1349,10 +1435,30 @@ packages:
resolution: {integrity: sha512-eiiY8HQeYfYH2Con2berK+To6GrK2RxbPawDkGq4UiCQQfZHb6wX9qQqkbpPqaxQFcl8d9QzZqo0tGE0VcrdwA==}
engines: {node: '>= 0.4'}
+ es-abstract@1.23.3:
+ resolution: {integrity: sha512-e+HfNH61Bj1X9/jLc5v1owaLYuHdeHHSQlkhCBiTK8rBvKaULl/beGMxwrMXjpYrv4pz22BlY570vVePA2ho4A==}
+ engines: {node: '>= 0.4'}
+
+ es-define-property@1.0.0:
+ resolution: {integrity: sha512-jxayLKShrEqqzJ0eumQbVhTYQM27CfT1T35+gCgDFoL82JLsXqTJ76zv6A0YLOgEnLUMvLzsDsGIrl8NFpT2gQ==}
+ engines: {node: '>= 0.4'}
+
+ es-errors@1.3.0:
+ resolution: {integrity: sha512-Zf5H2Kxt2xjTvbJvP2ZWLEICxA6j+hAmMzIlypy4xcBg1vKVnx89Wy0GbS+kf5cwCVFFzdCFh2XSCFNULS6csw==}
+ engines: {node: '>= 0.4'}
+
+ es-object-atoms@1.0.0:
+ resolution: {integrity: sha512-MZ4iQ6JwHOBQjahnjwaC1ZtIBH+2ohjamzAO3oaHcXYup7qxjF2fixyH+Q71voWHeOkI2q/TnJao/KfXYIZWbw==}
+ engines: {node: '>= 0.4'}
+
es-set-tostringtag@2.0.2:
resolution: {integrity: sha512-BuDyupZt65P9D2D2vA/zqcI3G5xRsklm5N3xCwuiy+/vKy8i0ifdsQP1sLgO4tZDSCaQUSnmC48khknGMV3D2Q==}
engines: {node: '>= 0.4'}
+ es-set-tostringtag@2.0.3:
+ resolution: {integrity: sha512-3T8uNMC3OQTHkFUsFq8r/BwAXLHvU/9O9mE0fBc/MY5iq/8H7ncvO947LmYA6ldWw9Uh8Yhf25zu6n7nML5QWQ==}
+ engines: {node: '>= 0.4'}
+
es-shim-unscopables@1.0.2:
resolution: {integrity: sha512-J3yBRXCzDu4ULnQwxyToo/OjdMx6akgVC7K6few0a7F/0wLtmKKN7I73AH5T2836UuXRqN7Qg+IIUw/+YJksRw==}
@@ -1520,6 +1626,9 @@ packages:
find-yarn-workspace-root2@1.2.16:
resolution: {integrity: sha512-hr6hb1w8ePMpPVUK39S4RlwJzi+xPLuVuG8XlwXU3KD5Yn3qgBWVfy3AzNlDhWvE1EORCE65/Qm26rFQt3VLVA==}
+ find-yarn-workspace-root@2.0.0:
+ resolution: {integrity: sha512-1IMnbjt4KzsQfnhnzNd8wUEgXZ44IzZaZmnLYx7D5FZlaHt2gW20Cri8Q+E/t5tIj4+epTBub+2Zxu/vNILzqQ==}
+
flat-cache@3.2.0:
resolution: {integrity: sha512-CYcENa+FtcUKLmhhqyctpclsq7QF38pKjZHsGNiSQF5r4FtoKDWabFDl3hzaEQMvT1LHEysw5twgLvpYYb4vbw==}
engines: {node: ^10.12.0 || >=12.0.0}
@@ -1592,6 +1701,10 @@ packages:
get-intrinsic@1.2.2:
resolution: {integrity: sha512-0gSo4ml/0j98Y3lngkFEot/zhiCeWsbYIlZ+uZOVgzLyLaUw7wxUL+nCTP0XJvJg1AXulJRI3UJi8GsbDuxdGA==}
+ get-intrinsic@1.2.4:
+ resolution: {integrity: sha512-5uYhsJH8VJBTv7oslg4BznJYhDoRI6waYCxMmCdnTrcCrHA/fCFKoTFz2JKKE0HdDFUF7/oQuhzumXJK7paBRQ==}
+ engines: {node: '>= 0.4'}
+
get-stream@5.1.0:
resolution: {integrity: sha512-EXr1FOzrzTfGeL0gQdeFEvOMm2mzMOglyiOXSTpPC+iAjAKftbr3jpCMWynogwYnM+eSj9sHGc6wjIcDvYiygw==}
engines: {node: '>=8'}
@@ -1604,6 +1717,10 @@ packages:
resolution: {integrity: sha512-2EmdH1YvIQiZpltCNgkuiUnyukzxM/R6NDJX31Ke3BG1Nq5b0S2PhX59UKi9vZpPDQVdqn+1IcaAwnzTT5vCjw==}
engines: {node: '>= 0.4'}
+ get-symbol-description@1.0.2:
+ resolution: {integrity: sha512-g0QYk1dZBxGwk+Ngc+ltRH2IBp2f7zBkBMBJZCDerh6EhlhSR6+9irMCuT/09zD6qkarHUSn529sK/yL4S27mg==}
+ engines: {node: '>= 0.4'}
+
glob-parent@5.1.2:
resolution: {integrity: sha512-AOIgSQCepiJYwP3ARnGx+5VnTu2HBYdzbGP45eLw1vr3zB3vZLeyed1sC9hnbcOc9/SrMyM5RPQrkGz4aS9Zow==}
engines: {node: '>= 6'}
@@ -1692,10 +1809,17 @@ packages:
has-property-descriptors@1.0.0:
resolution: {integrity: sha512-62DVLZGoiEBDHQyqG4w9xCuZ7eJEwNmJRWw2VY84Oedb7WFcA27fiEVe8oUQx9hAUJ4ekurquucTGwsyO1XGdQ==}
+ has-property-descriptors@1.0.2:
+ resolution: {integrity: sha512-55JNKuIW+vq4Ke1BjOTjM2YctQIvCT7GFzHwmfZPGo5wnrgkid0YQtnAleFSqumZm4az3n2BS+erby5ipJdgrg==}
+
has-proto@1.0.1:
resolution: {integrity: sha512-7qE+iP+O+bgF9clE5+UoBFzE65mlBiVj3tKCrlNQ0Ogwm0BjpT/gK4SlLYDMybDh5I3TCTKnPPa0oMG7JDYrhg==}
engines: {node: '>= 0.4'}
+ has-proto@1.0.3:
+ resolution: {integrity: sha512-SJ1amZAJUiZS+PhsVLf5tGydlaVB8EdFpaSO4gmiUKUOxk8qzn5AIy4ZeJUmh22znIdk/uMAUT2pl3FxzVUH+Q==}
+ engines: {node: '>= 0.4'}
+
has-symbols@1.0.3:
resolution: {integrity: sha512-l3LCuF6MgDNwTDKkdYGEihYjt5pRPbEg46rtlmnSPlUbgmB8LOIrKJbYYFBSbnPaJexMKtiPO8hmeRjRz2Td+A==}
engines: {node: '>= 0.4'}
@@ -1704,6 +1828,10 @@ packages:
resolution: {integrity: sha512-kFjcSNhnlGV1kyoGk7OXKSawH5JOb/LzUc5w9B02hOTO0dfFRjbHQKvg1d6cf3HbeUmtU9VbbV3qzZ2Teh97WQ==}
engines: {node: '>= 0.4'}
+ has-tostringtag@1.0.2:
+ resolution: {integrity: sha512-NqADB8VjPFLM2V0VvHUewwwsw0ZWBaIdgo+ieHtK3hasLz4qeCRjYcqfB6AQrBggRKppKF8L52/VqdVsO47Dlw==}
+ engines: {node: '>= 0.4'}
+
has@1.0.3:
resolution: {integrity: sha512-f2dvO0VU6Oej7RkWJGrehjbzMAjFp5/VKPp5tTpWIV4JHHZK1/BxbFRtf/siA2SWTe09caDmVtYYzWEIbBS4zw==}
engines: {node: '>= 0.4.0'}
@@ -1719,6 +1847,10 @@ packages:
resolution: {integrity: sha512-vUptKVTpIJhcczKBbgnS+RtcuYMB8+oNzPK2/Hp3hanz8JmpATdmmgLgSaadVREkDm+e2giHwY3ZRkyjSIDDFA==}
engines: {node: '>= 0.4'}
+ hasown@2.0.2:
+ resolution: {integrity: sha512-0hJU9SCPvmMzIBdZFqNPXWa6dqh7WdH0cII9y+CyS8rG3nL48Bclra9HmKhVVUHyPWNH5Y7xDwAB7bfgSjkUMQ==}
+ engines: {node: '>= 0.4'}
+
he@1.2.0:
resolution: {integrity: sha512-F/1DnUGPopORZi0ni+CvrCgHQ5FyEAHRLSApuYWMmrbSwoN2Mn/7k+Gl38gJnR7yyDZk6WLXwiGod1JOWNDKGw==}
hasBin: true
@@ -1790,12 +1922,20 @@ packages:
resolution: {integrity: sha512-Xj6dv+PsbtwyPpEflsejS+oIZxmMlV44zAhG479uYu89MsjcYOhCFnNyKrkJrihbsiasQyY0afoCl/9BLR65bg==}
engines: {node: '>= 0.4'}
+ internal-slot@1.0.7:
+ resolution: {integrity: sha512-NGnrKwXzSms2qUUih/ILZ5JBqNTSa1+ZmP6flaIp6KmSElgE9qdndzS3cqjrDovwFdmwsGsLdeFgB6suw+1e9g==}
+ engines: {node: '>= 0.4'}
+
io-ts@1.10.4:
resolution: {integrity: sha512-b23PteSnYXSONJ6JQXRAlvJhuw8KOtkqa87W4wDtvMrud/DTJd5X+NpOOI+O/zZwVq6v0VLAaJ+1EDViKEuN9g==}
is-array-buffer@3.0.2:
resolution: {integrity: sha512-y+FyyR/w8vfIRq4eQcM1EYgSTnmHXPqaF+IgzgraytCFq5Xh8lllDVmAZolPJiZttZLeFSINPYMaEJ7/vWUa1w==}
+ is-array-buffer@3.0.4:
+ resolution: {integrity: sha512-wcjaerHw0ydZwfhiKbXJWLDY8A7yV7KhjQOpb83hGgGfId/aQa4TOvwyzn2PuswW2gPCYEL/nEAiSVpdOj1lXw==}
+ engines: {node: '>= 0.4'}
+
is-arrayish@0.2.1:
resolution: {integrity: sha512-zz06S8t0ozoDXMG+ube26zeCTNXcKIPJZJi8hBrF4idCLms4CG9QtK7qBl1boi5ODzFpjswb5JPmHCbMpjaYzg==}
@@ -1814,13 +1954,26 @@ packages:
resolution: {integrity: sha512-1BC0BVFhS/p0qtw6enp8e+8OD0UrK0oFLztSjNzhcKA3WDuJxxAPXzPuPtKkjEY9UUoEWlX/8fgKeu2S8i9JTA==}
engines: {node: '>= 0.4'}
+ is-ci@2.0.0:
+ resolution: {integrity: sha512-YfJT7rkpQB0updsdHLGWrvhBJfcfzNNawYDNIyQXJz0IViGf75O8EBPKSdvw2rF+LGCsX4FZ8tcr3b19LcZq4w==}
+ hasBin: true
+
is-core-module@2.10.0:
resolution: {integrity: sha512-Erxj2n/LDAZ7H8WNJXd9tw38GYM3dv8rk8Zcs+jJuxYTW7sozH+SS8NtrSjVL1/vpLvWi1hxy96IzjJ3EHTJJg==}
+ is-data-view@1.0.1:
+ resolution: {integrity: sha512-AHkaJrsUVW6wq6JS8y3JnM/GJF/9cf+k20+iDzlSaJrinEo5+7vRiteOSwBhHRiAyQATN1AmY4hwzxJKPmYf+w==}
+ engines: {node: '>= 0.4'}
+
is-date-object@1.0.2:
resolution: {integrity: sha512-USlDT524woQ08aoZFzh3/Z6ch9Y/EWXEHQ/AaRN0SkKq4t2Jw2R2339tSXmwuVoY7LLlBCbOIlx2myP/L5zk0g==}
engines: {node: '>= 0.4'}
+ is-docker@2.2.1:
+ resolution: {integrity: sha512-F+i2BKsFrH66iaUFc0woD8sLy8getkwTwtOBjvs56Cx4CgJDeKQeqfz8wAYiSb8JOprWhHH5p77PbmYCvvUuXQ==}
+ engines: {node: '>=8'}
+ hasBin: true
+
is-extglob@2.1.1:
resolution: {integrity: sha512-SbKbANkN603Vi4jEZv49LeVJMn4yGwsbzZworEoyEiutsN3nJYdbO36zfhGJ6QEDpOZIFkDtnq5JRxmvl3jsoQ==}
engines: {node: '>=0.10.0'}
@@ -1844,6 +1997,10 @@ packages:
resolution: {integrity: sha512-dqJvarLawXsFbNDeJW7zAz8ItJ9cd28YufuuFzh0G8pNHjJMnY08Dv7sYX2uF5UpQOwieAeOExEYAWWfu7ZZUA==}
engines: {node: '>= 0.4'}
+ is-negative-zero@2.0.3:
+ resolution: {integrity: sha512-5KoIu2Ngpyek75jXodFvnafB6DJgr3u8uuK0LEZJjrU19DrMD3EVERaR8sjz8CCGgpZvxPl9SuE1GMVPFHx1mw==}
+ engines: {node: '>= 0.4'}
+
is-number-object@1.0.7:
resolution: {integrity: sha512-k1U0IRzLMo7ZlYIfzRu23Oh6MiIFasgpb9X76eqfFZAqwH44UI4KTBvBYIZ1dSL9ZzChTB9ShHfLkR4pdW5krQ==}
engines: {node: '>= 0.4'}
@@ -1871,6 +2028,10 @@ packages:
is-shared-array-buffer@1.0.2:
resolution: {integrity: sha512-sqN2UDu1/0y6uvXyStCOzyhAjCSlHceFoMKJW8W9EU9cvic/QdsZ0kEU93HEy3IUEFZIiH/3w+AH/UQbPHNdhA==}
+ is-shared-array-buffer@1.0.3:
+ resolution: {integrity: sha512-nA2hv5XIhLR3uVzDDfCIknerhx8XUKnstuOERPNNIinXG7v9u+ohXF67vxm4TPTEPU6lm61ZkwP3c9PCB97rhg==}
+ engines: {node: '>= 0.4'}
+
is-string@1.0.7:
resolution: {integrity: sha512-tE2UXzivje6ofPW7l23cjDOMa09gb7xlAqG6jG5ej6uPV32TlWP3NKPigtaGeHNu9fohccRYvIiZMfOOnOYUtg==}
engines: {node: '>= 0.4'}
@@ -1887,6 +2048,10 @@ packages:
resolution: {integrity: sha512-Z14TF2JNG8Lss5/HMqt0//T9JeHXttXy5pH/DBU4vi98ozO2btxzq9MwYDZYnKwU8nRsz/+GVFVRDq3DkVuSPg==}
engines: {node: '>= 0.4'}
+ is-typed-array@1.1.13:
+ resolution: {integrity: sha512-uZ25/bUAlUY5fR4OKT4rZQEBrzQWYV9ZJYGGsUmEJ6thodVJ1HX64ePQ6Z0qPWP+m+Uq6e9UugrE38jeYsDSMw==}
+ engines: {node: '>= 0.4'}
+
is-unicode-supported@0.1.0:
resolution: {integrity: sha512-knxG2q4UC3u8stRGyAVJCOdxFmv5DZiRcdlIaAQXAbSfJya+OhopNotLQrstBhququ4ZpuKbDc/8S6mgXgPFPw==}
engines: {node: '>=10'}
@@ -1901,6 +2066,10 @@ packages:
resolution: {integrity: sha512-eXK1UInq2bPmjyX6e3VHIzMLobc4J94i4AWn+Hpq3OU5KkrRC96OAcR3PRJ/pGu6m8TRnBHP9dkXQVsT/COVIA==}
engines: {node: '>=0.10.0'}
+ is-wsl@2.2.0:
+ resolution: {integrity: sha512-fKzAra0rGJUUBwGBgNkHZuToZcn+TtXHpeCgmkMJMMYx1sQDYaCSyjJBSCa2nH1DGm7s3n1oBnohoVTBaN7Lww==}
+ engines: {node: '>=8'}
+
isarray@2.0.5:
resolution: {integrity: sha512-xHjhDr3cNBK0BzdUJSPXZntQUx/mwMS5Rw4A7lPJ90XGAO6ISP/ePDNuo0vhqOZU+UD5JoodwCAAoZQd3FeAKw==}
@@ -1970,6 +2139,9 @@ packages:
resolution: {integrity: sha512-dcS1ul+9tmeD95T+x28/ehLgd9mENa3LsvDTtzm3vyBEO7RPptvAD+t44WVXaUjTBRcrpFeFlC8WCruUR456hw==}
engines: {node: '>=0.10.0'}
+ klaw-sync@6.0.0:
+ resolution: {integrity: sha512-nIeuVSzdCCs6TDPTqI8w1Yre34sSq7AkZ4B3sfOBbI2CgVSB4Du4aLQijFU2+lhAFCwt9+42Hel6lQNIv6AntQ==}
+
klaw@1.3.1:
resolution: {integrity: sha512-TED5xi9gGQjGpNnvRWknrwAB1eL5GciPfVFOt3Vk1OJCVDQbzuSfrF3hkUQKlsgKrG1F+0t5W0m+Fje1jIt8rw==}
@@ -2170,6 +2342,9 @@ packages:
neodoc@2.0.2:
resolution: {integrity: sha512-NAppJ0YecKWdhSXFYCHbo6RutiX8vOt/Jo3l46mUg6pQlpJNaqc5cGxdrW2jITQm5JIYySbFVPDl3RrREXNyPw==}
+ nice-try@1.0.5:
+ resolution: {integrity: sha512-1nh45deeb5olNY7eX82BkPO7SSxR5SSYJiPTrTdFUVYwAl8CKMA5N9PjTYkHiRjisVcxcQ1HXdLhx2qxxJzLNQ==}
+
no-case@2.3.2:
resolution: {integrity: sha512-rmTZ9kz+f3rCvK2TD1Ue/oZlns7OGoIWP4fc3llxxRXlOkHKoWPPWJOfFYpITabSow43QJbRIoHQXtt10VldyQ==}
@@ -2227,12 +2402,20 @@ packages:
resolution: {integrity: sha512-1mxKf0e58bvyjSCtKYY4sRe9itRk3PJpquJOjeIkz885CczcI4IvJJDLPS72oowuSh+pBxUFROpX+TU++hxhZQ==}
engines: {node: '>= 0.4'}
+ object.assign@4.1.5:
+ resolution: {integrity: sha512-byy+U7gp+FVwmyzKPYhW2h5l3crpmGsxl7X2s8y43IgxvG4g3QZ6CffDtsNQy1WsmZpQbO+ybo0AlW7TY6DcBQ==}
+ engines: {node: '>= 0.4'}
+
obliterator@2.0.4:
resolution: {integrity: sha512-lgHwxlxV1qIg1Eap7LgIeoBWIMFibOjbrYPIPJZcI1mmGAI2m3lNYpK12Y+GBdPQ0U1hRwSord7GIaawz962qQ==}
once@1.4.0:
resolution: {integrity: sha512-lNaJgI+2Q5URQBkccEKHTQOPaXdUxnZZElQTZY0MFUAuaEqe1E+Nyvgdz/aIyNi6Z9MzO5dv1H8n58/GELp3+w==}
+ open@7.4.2:
+ resolution: {integrity: sha512-MVHddDVweXZF3awtlAS+6pgKLlm/JgxZ90+/NBurBoQctVOOB/zDdVjcyPzQ+0laDGbsWgrRkflI65sQeOgT9Q==}
+ engines: {node: '>=8'}
+
optionator@0.9.3:
resolution: {integrity: sha512-JjCoypp+jKn1ttEFExxhetCKeJt9zhAgAve5FXHixTvFDW/5aEktX9bufBKLRRMdU7bNtpLfcGu94B3cdEJgjg==}
engines: {node: '>= 0.8.0'}
@@ -2313,6 +2496,11 @@ packages:
pascal-case@2.0.1:
resolution: {integrity: sha512-qjS4s8rBOJa2Xm0jmxXiyh1+OFf6ekCWOvUaRgAQSktzlTbMotS0nmG9gyYAybCWBcuP4fsBeRCKNwGBnMe2OQ==}
+ patch-package@6.5.1:
+ resolution: {integrity: sha512-I/4Zsalfhc6bphmJTlrLoOcAF87jcxko4q0qsv4bGcurbr8IskEOtdnt9iCmsQVGL1B+iUhSQqweyTLJfCF9rA==}
+ engines: {node: '>=10', npm: '>5'}
+ hasBin: true
+
path-case@2.1.1:
resolution: {integrity: sha512-Ou0N05MioItesaLr9q8TtHVWmJ6fxWdqKB2RohFmNWVyJ+2zeKIeDNWAN6B/Pe7wpzWChhZX6nONYmOnMeJQ/Q==}
@@ -2328,6 +2516,10 @@ packages:
resolution: {integrity: sha512-AVbw3UJ2e9bq64vSaS9Am0fje1Pa8pbGqTTsmXfaIiMpnr5DlDhfJOuLj9Sf95ZPVDAUerDfEk88MPmPe7UCQg==}
engines: {node: '>=0.10.0'}
+ path-key@2.0.1:
+ resolution: {integrity: sha512-fEHGKCSmUSDPv4uoj8AlD+joPlq3peND+HRYyxFz4KPw4z926S/b8rIuFs2FYJg3BwsxJf6A9/3eIdLaYC+9Dw==}
+ engines: {node: '>=4'}
+
path-key@3.1.1:
resolution: {integrity: sha512-ojmeN0qd+y0jszEtoY48r0Peq5dwMEkIlCOu6Q5f41lfkswXuKtYrhgoTpLnyIcHm24Uhqx+5Tqm2InSwLhE6Q==}
engines: {node: '>=8'}
@@ -2366,6 +2558,10 @@ packages:
resolution: {integrity: sha512-Nc3IT5yHzflTfbjgqWcCPpo7DaKy4FnpB0l/zCAW0Tc7jxAiuqSxHasntB3D7887LSrA93kDJ9IXovxJYxyLCA==}
engines: {node: '>=4'}
+ possible-typed-array-names@1.0.0:
+ resolution: {integrity: sha512-d7Uw+eZoloe0EHDIYoe+bQ5WXnGMOpmiZFTuMWCwpjzzkL2nTjcKiAk4hh8TjnGye2TwWOk3UXucZ+3rbmBa8Q==}
+ engines: {node: '>= 0.4'}
+
preferred-pm@3.1.3:
resolution: {integrity: sha512-MkXsENfftWSRpzCzImcp4FRsCc3y1opwB73CfCNWyzMqArju2CrlMHlqB7VexKiPEOjGMbttv1r9fSCn5S610w==}
engines: {node: '>=10'}
@@ -2394,6 +2590,9 @@ packages:
engines: {node: '>=14'}
hasBin: true
+ proper-lockfile@4.1.2:
+ resolution: {integrity: sha512-TjNPblN4BwAWMXU8s9AEz4JmQxnD1NNL7bNOY/AKUzyamc379FWASUhc/K1pL2noVb+XmZKLL68cjzLsiOAMaA==}
+
proto-list@1.2.4:
resolution: {integrity: sha512-vtK/94akxsTMhe0/cbfpR+syPuszcuwhqVjJq26CuNDgFGj682oRBXOP5MJpv2r7JtE8MsiepGIqvvOTBwn2vA==}
@@ -2464,6 +2663,10 @@ packages:
resolution: {integrity: sha512-sy6TXMN+hnP/wMy+ISxg3krXx7BAtWVO4UouuCN/ziM9UEne0euamVNafDfvC83bRNr95y0V5iijeDQFUNpvrg==}
engines: {node: '>= 0.4'}
+ regexp.prototype.flags@1.5.2:
+ resolution: {integrity: sha512-NcDiDkTLuPR+++OCKB0nWafEmhg/Da8aUPLPMQbK+bxKKCm1/S5he+AqYa4PlMCVBalb4/yxIRub6qkEx5yJbw==}
+ engines: {node: '>= 0.4'}
+
registry-auth-token@5.0.2:
resolution: {integrity: sha512-o/3ikDxtXaA59BmZuZrJZDJv8NMDGSj+6j6XaeBmHw8eY1i1qd9+6H+LjVvQXx3HN6aRCGa1cUdJ9RaJZUugnQ==}
engines: {node: '>=14'}
@@ -2504,6 +2707,10 @@ packages:
responselike@2.0.1:
resolution: {integrity: sha512-4gl03wn3hj1HP3yzgdI7d3lCkF95F21Pz4BPGvKHinyQzALR5CapwC8yIi0Rh58DEMQ/SguC03wFj2k0M/mHhw==}
+ retry@0.12.0:
+ resolution: {integrity: sha512-9LkiTwjUh6rT555DtE9rTX+BKByPfrMzEAtnlEtdEwr3Nkffwiihqe2bWADg+OQRjt9gl6ICdmB/ZFDCGAtSow==}
+ engines: {node: '>= 4'}
+
reusify@1.0.4:
resolution: {integrity: sha512-U9nH88a3fc/ekCF1l0/UP1IosiuIjyTh7hBvXVMHYgVcfGvt897Xguj2UOLDeI5BG2m7/uwyaLVT6fbtCwTyzw==}
engines: {iojs: '>=1.0.0', node: '>=0.10.0'}
@@ -2536,6 +2743,10 @@ packages:
resolution: {integrity: sha512-6XbUAseYE2KtOuGueyeobCySj9L4+66Tn6KQMOPQJrAJEowYKW/YR/MGJZl7FdydUdaFu4LYyDZjxf4/Nmo23Q==}
engines: {node: '>=0.4'}
+ safe-array-concat@1.1.2:
+ resolution: {integrity: sha512-vj6RsCsWBCf19jIeHEfkRMw8DPiBb+DMXklQ/1SGDHOMlHdPUkZXFQ2YdplS23zESTijAcurb1aSgJA3AgMu1Q==}
+ engines: {node: '>=0.4'}
+
safe-buffer@5.1.2:
resolution: {integrity: sha512-Gd2UZBJDkXlY7GbJxfsE8/nvKkUEU1G38c1siN6QP6a9PT9MmHB8GnpscSmMJSoF8LOIrt8ud/wPtojys4G6+g==}
@@ -2545,6 +2756,10 @@ packages:
safe-regex-test@1.0.0:
resolution: {integrity: sha512-JBUUzyOgEwXQY1NuPtvcj/qcBDbDmEvWufhlnXZIm75DEHp+afM1r1ujJpJsV/gSM4t59tpDyPi1sd6ZaPFfsA==}
+ safe-regex-test@1.0.3:
+ resolution: {integrity: sha512-CdASjNJPvRa7roO6Ra/gLYBTzYzzPyyBXxIMdGW3USQLyjWEls2RgW5UBTXaQVp+OrpeCK3bLem8smtmheoRuw==}
+ engines: {node: '>= 0.4'}
+
safer-buffer@2.1.2:
resolution: {integrity: sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==}
@@ -2581,6 +2796,10 @@ packages:
resolution: {integrity: sha512-VoaqjbBJKiWtg4yRcKBQ7g7wnGnLV3M8oLvVWwOk2PdYY6PEFegR1vezXR0tw6fZGF9csVakIRjrJiy2veSBFQ==}
engines: {node: '>= 0.4'}
+ set-function-length@1.2.2:
+ resolution: {integrity: sha512-pgRc4hJ4/sNjWCSS9AmnS40x3bNMDTknHgL5UaMBTMyJnU90EgWh1Rz+MC9eFu4BuN/UwZjKQuY/1v3rM7HMfg==}
+ engines: {node: '>= 0.4'}
+
set-function-name@2.0.1:
resolution: {integrity: sha512-tMNCiqYVkXIZgc2Hnoy2IvC/f8ezc5koaRFkCjrpWzGpCd3qbZXPzVy9MAZzK1ch/X0jvSkojys3oqJN0qCmdA==}
engines: {node: '>= 0.4'}
@@ -2620,6 +2839,10 @@ packages:
signal-exit@3.0.7:
resolution: {integrity: sha512-wnD2ZE+l+SPC/uoS0vXeE9L1+0wuaMqKlfz9AMUo38JsyLSBWSFcHR1Rri62LZc12vLr1gb3jl7iwQhgwpAbGQ==}
+ slash@2.0.0:
+ resolution: {integrity: sha512-ZYKh3Wh2z1PpEXWr0MpSBZ0V6mZHAQfYevttO11c51CaWjGTaadiKZ+wVt1PbMlDV5qhMFslpZCemhwOK7C89A==}
+ engines: {node: '>=6'}
+
slash@3.0.0:
resolution: {integrity: sha512-g9Q1haeby36OSStwb4ntCGGGaKsaVSjQ68fBxoQcutl5fS1vuY18H3wSt3jFyFtrkx+Kz0V1G85A4MyAdDMi2Q==}
engines: {node: '>=8'}
@@ -2651,6 +2874,9 @@ packages:
resolution: {integrity: sha512-QeQLS9HGCnIiibt+xiOa/+MuP7BWz9N7C5+Mj9pLHshdkNhuo3AzCpWmjfWVZBUuwIUO3YyCRVIcYLR3YOKGfg==}
hasBin: true
+ solidity-ast@0.4.56:
+ resolution: {integrity: sha512-HgmsA/Gfklm/M8GFbCX/J1qkVH0spXHgALCNZ8fA8x5X+MFdn/8CP2gr5OVyXjXw6RZTPC/Sxl2RUDQOXyNMeA==}
+
solidity-comments-darwin-arm64@0.0.2:
resolution: {integrity: sha512-HidWkVLSh7v+Vu0CA7oI21GWP/ZY7ro8g8OmIxE8oTqyMwgMbE8F1yc58Sj682Hj199HCZsjmtn1BE4PCbLiGA==}
engines: {node: '>= 10'}
@@ -2768,12 +2994,23 @@ packages:
resolution: {integrity: sha512-lfjY4HcixfQXOfaqCvcBuOIapyaroTXhbkfJN3gcB1OtyupngWK4sEET9Knd0cXd28kTUqu/kHoV4HKSJdnjiQ==}
engines: {node: '>= 0.4'}
+ string.prototype.trim@1.2.9:
+ resolution: {integrity: sha512-klHuCNxiMZ8MlsOihJhJEBJAiMVqU3Z2nEXWfWnIqjN0gEFS9J9+IxKozWWtQGcgoa1WUZzLjKPTr4ZHNFTFxw==}
+ engines: {node: '>= 0.4'}
+
string.prototype.trimend@1.0.7:
resolution: {integrity: sha512-Ni79DqeB72ZFq1uH/L6zJ+DKZTkOtPIHovb3YZHQViE+HDouuU4mBrLOLDn5Dde3RF8qw5qVETEjhu9locMLvA==}
+ string.prototype.trimend@1.0.8:
+ resolution: {integrity: sha512-p73uL5VCHCO2BZZ6krwwQE3kCzM7NKmis8S//xEC6fQonchbum4eP6kR4DLEjQFO3Wnj3Fuo8NM0kOSjVdHjZQ==}
+
string.prototype.trimstart@1.0.7:
resolution: {integrity: sha512-NGhtDFu3jCEm7B4Fy0DpLewdJQOZcQ0rGbwQ/+stjnrp2i+rlKeCvos9hOIeCmqwratM47OBxY7uFZzjxHXmrg==}
+ string.prototype.trimstart@1.0.8:
+ resolution: {integrity: sha512-UXSH262CSZY1tfu3G3Secr6uGLCFVPMhIqHjlgCUtCCcgihYc/xKs9djMTMUOb2j1mVSeU8EU6NWc/iQKU6Gfg==}
+ engines: {node: '>= 0.4'}
+
string_decoder@1.3.0:
resolution: {integrity: sha512-hkRX8U1WjJFd8LsDJ2yQ/wWWxaopEsABU1XfkM8A+j0+85JAGppt16cr1Whg6KIbb4okU6Mql6BOj+uup/wKeA==}
@@ -2952,17 +3189,33 @@ packages:
resolution: {integrity: sha512-Y8KTSIglk9OZEr8zywiIHG/kmQ7KWyjseXs1CbSo8vC42w7hg2HgYTxSWwP0+is7bWDc1H+Fo026CpHFwm8tkw==}
engines: {node: '>= 0.4'}
+ typed-array-buffer@1.0.2:
+ resolution: {integrity: sha512-gEymJYKZtKXzzBzM4jqa9w6Q1Jjm7x2d+sh19AdsD4wqnMPDYyvwpsIc2Q/835kHuo3BEQ7CjelGhfTsoBb2MQ==}
+ engines: {node: '>= 0.4'}
+
typed-array-byte-length@1.0.0:
resolution: {integrity: sha512-Or/+kvLxNpeQ9DtSydonMxCx+9ZXOswtwJn17SNLvhptaXYDJvkFFP5zbfU/uLmvnBJlI4yrnXRxpdWH/M5tNA==}
engines: {node: '>= 0.4'}
+ typed-array-byte-length@1.0.1:
+ resolution: {integrity: sha512-3iMJ9q0ao7WE9tWcaYKIptkNBuOIcZCCT0d4MRvuuH88fEoEH62IuQe0OtraD3ebQEoTRk8XCBoknUNc1Y67pw==}
+ engines: {node: '>= 0.4'}
+
typed-array-byte-offset@1.0.0:
resolution: {integrity: sha512-RD97prjEt9EL8YgAgpOkf3O4IF9lhJFr9g0htQkm0rchFp/Vx7LW5Q8fSXXub7BXAODyUQohRMyOc3faCPd0hg==}
engines: {node: '>= 0.4'}
+ typed-array-byte-offset@1.0.2:
+ resolution: {integrity: sha512-Ous0vodHa56FviZucS2E63zkgtgrACj7omjwd/8lTEMEPFFyjfixMZ1ZXenpgCFBBt4EC1J2XsyVS2gkG0eTFA==}
+ engines: {node: '>= 0.4'}
+
typed-array-length@1.0.4:
resolution: {integrity: sha512-KjZypGq+I/H7HI5HlOoGHkWUUGq+Q0TPhQurLbyrVrvnKTBgzLhIJ7j6J/XTQOi0d1RjyZ0wdas8bKs2p0x3Ng==}
+ typed-array-length@1.0.6:
+ resolution: {integrity: sha512-/OxDN6OtAk5KBpGb28T+HZc2M+ADtvRxXrKKbUwtsLgdoxgX13hyy7ek6bFRl5+aBs2yZzB0c4CnQfAtVypW/g==}
+ engines: {node: '>= 0.4'}
+
typescript@5.4.5:
resolution: {integrity: sha512-vcI4UpRgg81oIRUFwR0WSIHKt11nJ7SAVlYNIu+QpqeyXP+gpQJy/Z4+F0aGxSE4MqwjyXvW/TzgkLAx2AGHwQ==}
engines: {node: '>=14.17'}
@@ -3050,6 +3303,10 @@ packages:
resolution: {integrity: sha512-P5Nra0qjSncduVPEAr7xhoF5guty49ArDTwzJ/yNuPIbZppyRxFQsRCWrocxIY+CnMVG+qfbU2FmDKyvSGClow==}
engines: {node: '>= 0.4'}
+ which-typed-array@1.1.15:
+ resolution: {integrity: sha512-oV0jmFtUky6CXfkqehVvBP/LSWJ2sy4vWMioiENyJLePrBO/yKyV9OyJySfAKosh+RYkIl5zJCNZ8/4JncrpdA==}
+ engines: {node: '>= 0.4'}
+
which@1.3.1:
resolution: {integrity: sha512-HxJdYWq1MTIQbJ3nw0cqssHoTNU267KlrDuGZ1WYlxDStUtKUhOaJmh112/TZmHxxUfuJqPXSOm7tDyas0OSIQ==}
hasBin: true
@@ -3115,6 +3372,10 @@ packages:
yallist@2.1.2:
resolution: {integrity: sha512-ncTzHV7NvsQZkYe1DW7cbDLm0YpzHmZF5r/iyP3ZnQtMiJ+pjzisCiMNI+Sj+xQF5pXhSHxSB3uDbsBTzY/c2A==}
+ yaml@1.10.2:
+ resolution: {integrity: sha512-r3vXyErRCYJ7wg28yvBY5VSoAF8ZvlcW9/BwUzEtUsjvX/DKs24dIkuwjtuprwJJHsbyUbLApepYTR1BN4uHrg==}
+ engines: {node: '>= 6'}
+
yargs-parser@18.1.3:
resolution: {integrity: sha512-o50j0JeToy/4K6OZcaQmW6lyXXKhq7csREXcDwk2omFPJEwUNOVtJKvmDr9EI1fAJZUyZcRF7kxGBWmRXudrCQ==}
engines: {node: '>=6'}
@@ -3155,6 +3416,24 @@ snapshots:
'@aashutoshrathi/word-wrap@1.2.6': {}
+ '@arbitrum/nitro-contracts@1.1.1':
+ dependencies:
+ '@offchainlabs/upgrade-executor': 1.1.0-beta.0
+ '@openzeppelin/contracts': 4.5.0
+ '@openzeppelin/contracts-upgradeable': 4.5.2
+ patch-package: 6.5.1
+
+ '@arbitrum/token-bridge-contracts@1.1.2':
+ dependencies:
+ '@arbitrum/nitro-contracts': 1.1.1
+ '@offchainlabs/upgrade-executor': 1.1.0-beta.0
+ '@openzeppelin/contracts': 4.8.3
+ '@openzeppelin/contracts-upgradeable': 4.8.3
+ optionalDependencies:
+ '@openzeppelin/upgrades-core': 1.34.4
+ transitivePeerDependencies:
+ - supports-color
+
'@babel/code-frame@7.18.6':
dependencies:
'@babel/highlight': 7.18.6
@@ -3787,11 +4066,12 @@ snapshots:
'@nomicfoundation/ethereumjs-rlp': 5.0.4
'@nomicfoundation/ethereumjs-trie': 6.0.4
'@nomicfoundation/ethereumjs-util': 9.0.4
- '@nomicfoundation/ethereumjs-verkle': 0.0.2
debug: 4.3.4(supports-color@8.1.1)
ethereum-cryptography: 0.1.3
js-sdsl: 4.4.2
lru-cache: 10.2.2
+ optionalDependencies:
+ '@nomicfoundation/ethereumjs-verkle': 0.0.2
transitivePeerDependencies:
- c-kzg
- supports-color
@@ -3846,40 +4126,40 @@ snapshots:
- c-kzg
- supports-color
- '@nomicfoundation/hardhat-chai-matchers@1.0.6(@nomiclabs/hardhat-ethers@2.2.3)(chai@4.4.1)(ethers@5.7.2)(hardhat@2.20.1)':
+ '@nomicfoundation/hardhat-chai-matchers@1.0.6(@nomiclabs/hardhat-ethers@2.2.3(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)))(chai@4.4.1)(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))':
dependencies:
'@ethersproject/abi': 5.7.0
- '@nomiclabs/hardhat-ethers': 2.2.3(ethers@5.7.2)(hardhat@2.20.1)
+ '@nomiclabs/hardhat-ethers': 2.2.3(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))
'@types/chai-as-promised': 7.1.8
chai: 4.4.1
chai-as-promised: 7.1.1(chai@4.4.1)
deep-eql: 4.1.3
ethers: 5.7.2
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
ordinal: 1.0.3
- '@nomicfoundation/hardhat-ethers@3.0.6(ethers@5.7.2)(hardhat@2.20.1)':
+ '@nomicfoundation/hardhat-ethers@3.0.6(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))':
dependencies:
debug: 4.3.4(supports-color@8.1.1)
ethers: 5.7.2
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
lodash.isequal: 4.5.0
transitivePeerDependencies:
- supports-color
- '@nomicfoundation/hardhat-network-helpers@1.0.10(hardhat@2.20.1)':
+ '@nomicfoundation/hardhat-network-helpers@1.0.10(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))':
dependencies:
ethereumjs-util: 7.1.5
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
- '@nomicfoundation/hardhat-verify@2.0.7(hardhat@2.20.1)':
+ '@nomicfoundation/hardhat-verify@2.0.7(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))':
dependencies:
'@ethersproject/abi': 5.7.0
'@ethersproject/address': 5.7.0
cbor: 8.1.0
chalk: 2.4.2
debug: 4.3.4(supports-color@8.1.1)
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
lodash.clonedeep: 4.5.0
semver: 6.3.0
table: 6.8.1
@@ -3930,15 +4210,46 @@ snapshots:
'@nomicfoundation/solidity-analyzer-win32-ia32-msvc': 0.1.0
'@nomicfoundation/solidity-analyzer-win32-x64-msvc': 0.1.0
- '@nomiclabs/hardhat-ethers@2.2.3(ethers@5.7.2)(hardhat@2.20.1)':
+ '@nomiclabs/hardhat-ethers@2.2.3(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))':
dependencies:
ethers: 5.7.2
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
+
+ '@offchainlabs/upgrade-executor@1.1.0-beta.0':
+ dependencies:
+ '@openzeppelin/contracts': 4.7.3
+ '@openzeppelin/contracts-upgradeable': 4.7.3
+
+ '@openzeppelin/contracts-upgradeable@4.5.2': {}
+
+ '@openzeppelin/contracts-upgradeable@4.7.3': {}
+
+ '@openzeppelin/contracts-upgradeable@4.8.3': {}
'@openzeppelin/contracts-upgradeable@4.9.3': {}
+ '@openzeppelin/contracts@4.5.0': {}
+
+ '@openzeppelin/contracts@4.7.3': {}
+
+ '@openzeppelin/contracts@4.8.3': {}
+
'@openzeppelin/contracts@4.9.3': {}
+ '@openzeppelin/upgrades-core@1.34.4':
+ dependencies:
+ cbor: 9.0.2
+ chalk: 4.1.2
+ compare-versions: 6.1.1
+ debug: 4.3.4(supports-color@8.1.1)
+ ethereumjs-util: 7.1.5
+ minimist: 1.2.8
+ proper-lockfile: 4.1.2
+ solidity-ast: 0.4.56
+ transitivePeerDependencies:
+ - supports-color
+ optional: true
+
'@pkgr/core@0.1.1': {}
'@pnpm/config.env-replace@1.1.0': {}
@@ -4052,7 +4363,7 @@ snapshots:
'@tsconfig/node16@1.0.3': {}
- '@typechain/ethers-v5@7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2)(typescript@5.4.5)':
+ '@typechain/ethers-v5@7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2(typescript@5.4.5))(typescript@5.4.5)':
dependencies:
'@ethersproject/abi': 5.7.0
'@ethersproject/bytes': 5.7.0
@@ -4063,14 +4374,14 @@ snapshots:
typechain: 8.3.2(typescript@5.4.5)
typescript: 5.4.5
- '@typechain/hardhat@7.0.0(@ethersproject/abi@5.7.0)(@ethersproject/providers@5.7.2)(@typechain/ethers-v5@7.2.0)(ethers@5.7.2)(hardhat@2.20.1)(typechain@8.3.2)':
+ '@typechain/hardhat@7.0.0(@ethersproject/abi@5.7.0)(@ethersproject/providers@5.7.2)(@typechain/ethers-v5@7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2(typescript@5.4.5))(typescript@5.4.5))(ethers@5.7.2)(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5))(typechain@8.3.2(typescript@5.4.5))':
dependencies:
'@ethersproject/abi': 5.7.0
'@ethersproject/providers': 5.7.2
- '@typechain/ethers-v5': 7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2)(typescript@5.4.5)
+ '@typechain/ethers-v5': 7.2.0(@ethersproject/abi@5.7.0)(@ethersproject/bytes@5.7.0)(@ethersproject/providers@5.7.2)(ethers@5.7.2)(typechain@8.3.2(typescript@5.4.5))(typescript@5.4.5)
ethers: 5.7.2
fs-extra: 9.1.0
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
typechain: 8.3.2(typescript@5.4.5)
'@types/bn.js@4.11.6':
@@ -4147,7 +4458,7 @@ snapshots:
'@types/semver@7.5.0': {}
- '@typescript-eslint/eslint-plugin@7.10.0(@typescript-eslint/parser@7.10.0)(eslint@8.57.0)(typescript@5.4.5)':
+ '@typescript-eslint/eslint-plugin@7.10.0(@typescript-eslint/parser@7.10.0(eslint@8.57.0)(typescript@5.4.5))(eslint@8.57.0)(typescript@5.4.5)':
dependencies:
'@eslint-community/regexpp': 4.10.0
'@typescript-eslint/parser': 7.10.0(eslint@8.57.0)(typescript@5.4.5)
@@ -4160,6 +4471,7 @@ snapshots:
ignore: 5.3.1
natural-compare: 1.4.0
ts-api-utils: 1.3.0(typescript@5.4.5)
+ optionalDependencies:
typescript: 5.4.5
transitivePeerDependencies:
- supports-color
@@ -4172,6 +4484,7 @@ snapshots:
'@typescript-eslint/visitor-keys': 7.10.0
debug: 4.3.4(supports-color@8.1.1)
eslint: 8.57.0
+ optionalDependencies:
typescript: 5.4.5
transitivePeerDependencies:
- supports-color
@@ -4188,6 +4501,7 @@ snapshots:
debug: 4.3.4(supports-color@8.1.1)
eslint: 8.57.0
ts-api-utils: 1.3.0(typescript@5.4.5)
+ optionalDependencies:
typescript: 5.4.5
transitivePeerDependencies:
- supports-color
@@ -4204,6 +4518,7 @@ snapshots:
minimatch: 9.0.4
semver: 7.6.2
ts-api-utils: 1.3.0(typescript@5.4.5)
+ optionalDependencies:
typescript: 5.4.5
transitivePeerDependencies:
- supports-color
@@ -4226,6 +4541,8 @@ snapshots:
'@ungap/structured-clone@1.2.0': {}
+ '@yarnpkg/lockfile@1.1.0': {}
+
abi-to-sol@0.6.6:
dependencies:
'@truffle/abi-utils': 0.3.2
@@ -4328,8 +4645,24 @@ snapshots:
call-bind: 1.0.5
is-array-buffer: 3.0.2
+ array-buffer-byte-length@1.0.1:
+ dependencies:
+ call-bind: 1.0.7
+ is-array-buffer: 3.0.4
+ optional: true
+
array-union@2.1.0: {}
+ array.prototype.findlast@1.2.5:
+ dependencies:
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ es-abstract: 1.23.3
+ es-errors: 1.3.0
+ es-object-atoms: 1.0.0
+ es-shim-unscopables: 1.0.2
+ optional: true
+
array.prototype.flat@1.3.2:
dependencies:
call-bind: 1.0.5
@@ -4347,6 +4680,18 @@ snapshots:
is-array-buffer: 3.0.2
is-shared-array-buffer: 1.0.2
+ arraybuffer.prototype.slice@1.0.3:
+ dependencies:
+ array-buffer-byte-length: 1.0.1
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ es-abstract: 1.23.3
+ es-errors: 1.3.0
+ get-intrinsic: 1.2.4
+ is-array-buffer: 3.0.4
+ is-shared-array-buffer: 1.0.3
+ optional: true
+
arrify@1.0.1: {}
assertion-error@1.1.0: {}
@@ -4359,6 +4704,11 @@ snapshots:
available-typed-arrays@1.0.5: {}
+ available-typed-arrays@1.0.7:
+ dependencies:
+ possible-typed-array-names: 1.0.0
+ optional: true
+
balanced-match@1.0.0: {}
base-x@3.0.9:
@@ -4473,6 +4823,15 @@ snapshots:
get-intrinsic: 1.2.2
set-function-length: 1.1.1
+ call-bind@1.0.7:
+ dependencies:
+ es-define-property: 1.0.0
+ es-errors: 1.3.0
+ function-bind: 1.1.2
+ get-intrinsic: 1.2.4
+ set-function-length: 1.2.2
+ optional: true
+
callsites@3.1.0: {}
camel-case@3.0.0:
@@ -4499,6 +4858,11 @@ snapshots:
dependencies:
nofilter: 3.1.0
+ cbor@9.0.2:
+ dependencies:
+ nofilter: 3.1.0
+ optional: true
+
chai-as-promised@7.1.1(chai@4.4.1):
dependencies:
chai: 4.4.1
@@ -4635,6 +4999,9 @@ snapshots:
commander@3.0.2: {}
+ compare-versions@6.1.1:
+ optional: true
+
concat-map@0.0.1: {}
config-chain@1.1.13:
@@ -4683,6 +5050,14 @@ snapshots:
shebang-command: 1.2.0
which: 1.3.1
+ cross-spawn@6.0.5:
+ dependencies:
+ nice-try: 1.0.5
+ path-key: 2.0.1
+ semver: 5.7.1
+ shebang-command: 1.2.0
+ which: 1.3.1
+
cross-spawn@7.0.3:
dependencies:
path-key: 3.1.1
@@ -4702,11 +5077,33 @@ snapshots:
csv-stringify: 5.6.5
stream-transform: 2.1.3
+ data-view-buffer@1.0.1:
+ dependencies:
+ call-bind: 1.0.7
+ es-errors: 1.3.0
+ is-data-view: 1.0.1
+ optional: true
+
+ data-view-byte-length@1.0.1:
+ dependencies:
+ call-bind: 1.0.7
+ es-errors: 1.3.0
+ is-data-view: 1.0.1
+ optional: true
+
+ data-view-byte-offset@1.0.0:
+ dependencies:
+ call-bind: 1.0.7
+ es-errors: 1.3.0
+ is-data-view: 1.0.1
+ optional: true
+
dataloader@1.4.0: {}
debug@4.3.4(supports-color@8.1.1):
dependencies:
ms: 2.1.2
+ optionalDependencies:
supports-color: 8.1.1
decamelize-keys@1.1.1:
@@ -4747,6 +5144,13 @@ snapshots:
gopd: 1.0.1
has-property-descriptors: 1.0.0
+ define-data-property@1.1.4:
+ dependencies:
+ es-define-property: 1.0.0
+ es-errors: 1.3.0
+ gopd: 1.0.1
+ optional: true
+
define-properties@1.2.1:
dependencies:
define-data-property: 1.1.1
@@ -4850,12 +5254,82 @@ snapshots:
unbox-primitive: 1.0.2
which-typed-array: 1.1.13
+ es-abstract@1.23.3:
+ dependencies:
+ array-buffer-byte-length: 1.0.1
+ arraybuffer.prototype.slice: 1.0.3
+ available-typed-arrays: 1.0.7
+ call-bind: 1.0.7
+ data-view-buffer: 1.0.1
+ data-view-byte-length: 1.0.1
+ data-view-byte-offset: 1.0.0
+ es-define-property: 1.0.0
+ es-errors: 1.3.0
+ es-object-atoms: 1.0.0
+ es-set-tostringtag: 2.0.3
+ es-to-primitive: 1.2.1
+ function.prototype.name: 1.1.6
+ get-intrinsic: 1.2.4
+ get-symbol-description: 1.0.2
+ globalthis: 1.0.3
+ gopd: 1.0.1
+ has-property-descriptors: 1.0.2
+ has-proto: 1.0.3
+ has-symbols: 1.0.3
+ hasown: 2.0.2
+ internal-slot: 1.0.7
+ is-array-buffer: 3.0.4
+ is-callable: 1.2.7
+ is-data-view: 1.0.1
+ is-negative-zero: 2.0.3
+ is-regex: 1.1.4
+ is-shared-array-buffer: 1.0.3
+ is-string: 1.0.7
+ is-typed-array: 1.1.13
+ is-weakref: 1.0.2
+ object-inspect: 1.13.1
+ object-keys: 1.1.1
+ object.assign: 4.1.5
+ regexp.prototype.flags: 1.5.2
+ safe-array-concat: 1.1.2
+ safe-regex-test: 1.0.3
+ string.prototype.trim: 1.2.9
+ string.prototype.trimend: 1.0.8
+ string.prototype.trimstart: 1.0.8
+ typed-array-buffer: 1.0.2
+ typed-array-byte-length: 1.0.1
+ typed-array-byte-offset: 1.0.2
+ typed-array-length: 1.0.6
+ unbox-primitive: 1.0.2
+ which-typed-array: 1.1.15
+ optional: true
+
+ es-define-property@1.0.0:
+ dependencies:
+ get-intrinsic: 1.2.4
+ optional: true
+
+ es-errors@1.3.0:
+ optional: true
+
+ es-object-atoms@1.0.0:
+ dependencies:
+ es-errors: 1.3.0
+ optional: true
+
es-set-tostringtag@2.0.2:
dependencies:
get-intrinsic: 1.2.2
has-tostringtag: 1.0.0
hasown: 2.0.0
+ es-set-tostringtag@2.0.3:
+ dependencies:
+ get-intrinsic: 1.2.4
+ has-tostringtag: 1.0.2
+ hasown: 2.0.2
+ optional: true
+
es-shim-unscopables@1.0.2:
dependencies:
hasown: 2.0.0
@@ -4876,13 +5350,14 @@ snapshots:
dependencies:
eslint: 8.57.0
- eslint-plugin-prettier@5.1.3(eslint-config-prettier@9.1.0)(eslint@8.57.0)(prettier@3.2.5):
+ eslint-plugin-prettier@5.1.3(eslint-config-prettier@9.1.0(eslint@8.57.0))(eslint@8.57.0)(prettier@3.2.5):
dependencies:
eslint: 8.57.0
- eslint-config-prettier: 9.1.0(eslint@8.57.0)
prettier: 3.2.5
prettier-linter-helpers: 1.0.0
synckit: 0.8.8
+ optionalDependencies:
+ eslint-config-prettier: 9.1.0(eslint@8.57.0)
eslint-scope@7.2.2:
dependencies:
@@ -5120,6 +5595,10 @@ snapshots:
micromatch: 4.0.5
pkg-dir: 4.2.0
+ find-yarn-workspace-root@2.0.0:
+ dependencies:
+ micromatch: 4.0.5
+
flat-cache@3.2.0:
dependencies:
flatted: 3.3.1
@@ -5131,7 +5610,7 @@ snapshots:
flatted@3.3.1: {}
follow-redirects@1.15.6(debug@4.3.4):
- dependencies:
+ optionalDependencies:
debug: 4.3.4(supports-color@8.1.1)
for-each@0.3.3:
@@ -5196,6 +5675,15 @@ snapshots:
has-symbols: 1.0.3
hasown: 2.0.0
+ get-intrinsic@1.2.4:
+ dependencies:
+ es-errors: 1.3.0
+ function-bind: 1.1.2
+ has-proto: 1.0.1
+ has-symbols: 1.0.3
+ hasown: 2.0.0
+ optional: true
+
get-stream@5.1.0:
dependencies:
pump: 3.0.0
@@ -5207,6 +5695,13 @@ snapshots:
call-bind: 1.0.5
get-intrinsic: 1.2.2
+ get-symbol-description@1.0.2:
+ dependencies:
+ call-bind: 1.0.7
+ es-errors: 1.3.0
+ get-intrinsic: 1.2.4
+ optional: true
+
glob-parent@5.1.2:
dependencies:
is-glob: 4.0.3
@@ -5295,11 +5790,11 @@ snapshots:
hard-rejection@2.1.0: {}
- hardhat-abi-exporter@2.10.1(hardhat@2.20.1):
+ hardhat-abi-exporter@2.10.1(hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)):
dependencies:
'@ethersproject/abi': 5.7.0
delete-empty: 3.0.0
- hardhat: 2.20.1(ts-node@10.9.2)(typescript@5.4.5)
+ hardhat: 2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5)
hardhat-ignore-warnings@0.2.11:
dependencies:
@@ -5307,7 +5802,7 @@ snapshots:
node-interval-tree: 2.1.2
solidity-comments: 0.0.2
- hardhat@2.20.1(ts-node@10.9.2)(typescript@5.4.5):
+ hardhat@2.20.1(ts-node@10.9.2(@types/node@20.12.12)(typescript@5.4.5))(typescript@5.4.5):
dependencies:
'@ethersproject/abi': 5.7.0
'@metamask/eth-sig-util': 4.0.1
@@ -5355,12 +5850,13 @@ snapshots:
solc: 0.7.3(debug@4.3.4)
source-map-support: 0.5.21
stacktrace-parser: 0.1.10
- ts-node: 10.9.2(@types/node@20.12.12)(typescript@5.4.5)
tsort: 0.0.1
- typescript: 5.4.5
undici: 5.28.4
uuid: 8.3.2
ws: 7.5.9
+ optionalDependencies:
+ ts-node: 10.9.2(@types/node@20.12.12)(typescript@5.4.5)
+ typescript: 5.4.5
transitivePeerDependencies:
- bufferutil
- c-kzg
@@ -5377,14 +5873,27 @@ snapshots:
dependencies:
get-intrinsic: 1.2.2
+ has-property-descriptors@1.0.2:
+ dependencies:
+ es-define-property: 1.0.0
+ optional: true
+
has-proto@1.0.1: {}
+ has-proto@1.0.3:
+ optional: true
+
has-symbols@1.0.3: {}
has-tostringtag@1.0.0:
dependencies:
has-symbols: 1.0.3
+ has-tostringtag@1.0.2:
+ dependencies:
+ has-symbols: 1.0.3
+ optional: true
+
has@1.0.3:
dependencies:
function-bind: 1.1.2
@@ -5404,6 +5913,11 @@ snapshots:
dependencies:
function-bind: 1.1.2
+ hasown@2.0.2:
+ dependencies:
+ function-bind: 1.1.2
+ optional: true
+
he@1.2.0: {}
header-case@1.0.1:
@@ -5477,6 +5991,13 @@ snapshots:
hasown: 2.0.0
side-channel: 1.0.4
+ internal-slot@1.0.7:
+ dependencies:
+ es-errors: 1.3.0
+ hasown: 2.0.2
+ side-channel: 1.0.4
+ optional: true
+
io-ts@1.10.4:
dependencies:
fp-ts: 1.19.3
@@ -5487,6 +6008,12 @@ snapshots:
get-intrinsic: 1.2.2
is-typed-array: 1.1.12
+ is-array-buffer@3.0.4:
+ dependencies:
+ call-bind: 1.0.7
+ get-intrinsic: 1.2.4
+ optional: true
+
is-arrayish@0.2.1: {}
is-bigint@1.0.4:
@@ -5504,12 +6031,23 @@ snapshots:
is-callable@1.2.7: {}
+ is-ci@2.0.0:
+ dependencies:
+ ci-info: 2.0.0
+
is-core-module@2.10.0:
dependencies:
has: 1.0.3
+ is-data-view@1.0.1:
+ dependencies:
+ is-typed-array: 1.1.13
+ optional: true
+
is-date-object@1.0.2: {}
+ is-docker@2.2.1: {}
+
is-extglob@2.1.1: {}
is-fullwidth-code-point@3.0.0: {}
@@ -5526,6 +6064,9 @@ snapshots:
is-negative-zero@2.0.2: {}
+ is-negative-zero@2.0.3:
+ optional: true
+
is-number-object@1.0.7:
dependencies:
has-tostringtag: 1.0.0
@@ -5547,6 +6088,11 @@ snapshots:
dependencies:
call-bind: 1.0.5
+ is-shared-array-buffer@1.0.3:
+ dependencies:
+ call-bind: 1.0.7
+ optional: true
+
is-string@1.0.7:
dependencies:
has-tostringtag: 1.0.0
@@ -5563,6 +6109,11 @@ snapshots:
dependencies:
which-typed-array: 1.1.13
+ is-typed-array@1.1.13:
+ dependencies:
+ which-typed-array: 1.1.15
+ optional: true
+
is-unicode-supported@0.1.0: {}
is-upper-case@1.1.2:
@@ -5575,6 +6126,10 @@ snapshots:
is-windows@1.0.2: {}
+ is-wsl@2.2.0:
+ dependencies:
+ is-docker: 2.2.1
+
isarray@2.0.5: {}
isexe@2.0.0: {}
@@ -5641,6 +6196,10 @@ snapshots:
kind-of@6.0.3: {}
+ klaw-sync@6.0.0:
+ dependencies:
+ graceful-fs: 4.2.10
+
klaw@1.3.1:
optionalDependencies:
graceful-fs: 4.2.10
@@ -5839,6 +6398,8 @@ snapshots:
dependencies:
ansi-regex: 2.1.1
+ nice-try@1.0.5: {}
+
no-case@2.3.2:
dependencies:
lower-case: 1.1.4
@@ -5886,12 +6447,25 @@ snapshots:
has-symbols: 1.0.3
object-keys: 1.1.1
+ object.assign@4.1.5:
+ dependencies:
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ has-symbols: 1.0.3
+ object-keys: 1.1.1
+ optional: true
+
obliterator@2.0.4: {}
once@1.4.0:
dependencies:
wrappy: 1.0.2
+ open@7.4.2:
+ dependencies:
+ is-docker: 2.2.1
+ is-wsl: 2.2.0
+
optionator@0.9.3:
dependencies:
'@aashutoshrathi/word-wrap': 1.2.6
@@ -5974,6 +6548,23 @@ snapshots:
camel-case: 3.0.0
upper-case-first: 1.1.2
+ patch-package@6.5.1:
+ dependencies:
+ '@yarnpkg/lockfile': 1.1.0
+ chalk: 4.1.2
+ cross-spawn: 6.0.5
+ find-yarn-workspace-root: 2.0.0
+ fs-extra: 9.1.0
+ is-ci: 2.0.0
+ klaw-sync: 6.0.0
+ minimist: 1.2.8
+ open: 7.4.2
+ rimraf: 2.7.1
+ semver: 5.7.1
+ slash: 2.0.0
+ tmp: 0.0.33
+ yaml: 1.10.2
+
path-case@2.1.1:
dependencies:
no-case: 2.3.2
@@ -5984,6 +6575,8 @@ snapshots:
path-is-absolute@1.0.1: {}
+ path-key@2.0.1: {}
+
path-key@3.1.1: {}
path-parse@1.0.7: {}
@@ -6012,6 +6605,9 @@ snapshots:
pluralize@8.0.0: {}
+ possible-typed-array-names@1.0.0:
+ optional: true
+
preferred-pm@3.1.3:
dependencies:
find-up: 5.0.0
@@ -6044,6 +6640,13 @@ snapshots:
prettier@3.2.5: {}
+ proper-lockfile@4.1.2:
+ dependencies:
+ graceful-fs: 4.2.10
+ retry: 0.12.0
+ signal-exit: 3.0.7
+ optional: true
+
proto-list@1.2.4: {}
pseudomap@1.0.2: {}
@@ -6124,6 +6727,14 @@ snapshots:
define-properties: 1.2.1
set-function-name: 2.0.1
+ regexp.prototype.flags@1.5.2:
+ dependencies:
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ es-errors: 1.3.0
+ set-function-name: 2.0.1
+ optional: true
+
registry-auth-token@5.0.2:
dependencies:
'@pnpm/npm-conf': 2.2.2
@@ -6158,6 +6769,9 @@ snapshots:
dependencies:
lowercase-keys: 2.0.0
+ retry@0.12.0:
+ optional: true
+
reusify@1.0.4: {}
rimraf@2.7.1:
@@ -6192,6 +6806,14 @@ snapshots:
has-symbols: 1.0.3
isarray: 2.0.5
+ safe-array-concat@1.1.2:
+ dependencies:
+ call-bind: 1.0.7
+ get-intrinsic: 1.2.4
+ has-symbols: 1.0.3
+ isarray: 2.0.5
+ optional: true
+
safe-buffer@5.1.2: {}
safe-buffer@5.2.1: {}
@@ -6202,6 +6824,13 @@ snapshots:
get-intrinsic: 1.2.2
is-regex: 1.1.4
+ safe-regex-test@1.0.3:
+ dependencies:
+ call-bind: 1.0.7
+ es-errors: 1.3.0
+ is-regex: 1.1.4
+ optional: true
+
safer-buffer@2.1.2: {}
scrypt-js@3.0.1: {}
@@ -6236,6 +6865,16 @@ snapshots:
gopd: 1.0.1
has-property-descriptors: 1.0.0
+ set-function-length@1.2.2:
+ dependencies:
+ define-data-property: 1.1.4
+ es-errors: 1.3.0
+ function-bind: 1.1.2
+ get-intrinsic: 1.2.4
+ gopd: 1.0.1
+ has-property-descriptors: 1.0.2
+ optional: true
+
set-function-name@2.0.1:
dependencies:
define-data-property: 1.1.1
@@ -6273,6 +6912,8 @@ snapshots:
signal-exit@3.0.7: {}
+ slash@2.0.0: {}
+
slash@3.0.0: {}
slice-ansi@4.0.0:
@@ -6308,7 +6949,7 @@ snapshots:
transitivePeerDependencies:
- debug
- solhint-plugin-prettier@0.1.0(prettier-plugin-solidity@1.3.1)(prettier@3.2.5):
+ solhint-plugin-prettier@0.1.0(prettier-plugin-solidity@1.3.1(prettier@3.2.5))(prettier@3.2.5):
dependencies:
'@prettier/sync': 0.3.0(prettier@3.2.5)
prettier: 3.2.5
@@ -6338,6 +6979,11 @@ snapshots:
optionalDependencies:
prettier: 2.8.8
+ solidity-ast@0.4.56:
+ dependencies:
+ array.prototype.findlast: 1.2.5
+ optional: true
+
solidity-comments-darwin-arm64@0.0.2:
optional: true
@@ -6439,18 +7085,40 @@ snapshots:
define-properties: 1.2.1
es-abstract: 1.22.3
+ string.prototype.trim@1.2.9:
+ dependencies:
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ es-abstract: 1.23.3
+ es-object-atoms: 1.0.0
+ optional: true
+
string.prototype.trimend@1.0.7:
dependencies:
call-bind: 1.0.5
define-properties: 1.2.1
es-abstract: 1.22.3
+ string.prototype.trimend@1.0.8:
+ dependencies:
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ es-object-atoms: 1.0.0
+ optional: true
+
string.prototype.trimstart@1.0.7:
dependencies:
call-bind: 1.0.5
define-properties: 1.2.1
es-abstract: 1.22.3
+ string.prototype.trimstart@1.0.8:
+ dependencies:
+ call-bind: 1.0.7
+ define-properties: 1.2.1
+ es-object-atoms: 1.0.0
+ optional: true
+
string_decoder@1.3.0:
dependencies:
safe-buffer: 5.2.1
@@ -6628,6 +7296,13 @@ snapshots:
get-intrinsic: 1.2.2
is-typed-array: 1.1.12
+ typed-array-buffer@1.0.2:
+ dependencies:
+ call-bind: 1.0.7
+ es-errors: 1.3.0
+ is-typed-array: 1.1.13
+ optional: true
+
typed-array-byte-length@1.0.0:
dependencies:
call-bind: 1.0.5
@@ -6635,6 +7310,15 @@ snapshots:
has-proto: 1.0.1
is-typed-array: 1.1.12
+ typed-array-byte-length@1.0.1:
+ dependencies:
+ call-bind: 1.0.7
+ for-each: 0.3.3
+ gopd: 1.0.1
+ has-proto: 1.0.3
+ is-typed-array: 1.1.13
+ optional: true
+
typed-array-byte-offset@1.0.0:
dependencies:
available-typed-arrays: 1.0.5
@@ -6643,12 +7327,32 @@ snapshots:
has-proto: 1.0.1
is-typed-array: 1.1.12
+ typed-array-byte-offset@1.0.2:
+ dependencies:
+ available-typed-arrays: 1.0.7
+ call-bind: 1.0.7
+ for-each: 0.3.3
+ gopd: 1.0.1
+ has-proto: 1.0.3
+ is-typed-array: 1.1.13
+ optional: true
+
typed-array-length@1.0.4:
dependencies:
call-bind: 1.0.5
for-each: 0.3.3
is-typed-array: 1.1.12
+ typed-array-length@1.0.6:
+ dependencies:
+ call-bind: 1.0.7
+ for-each: 0.3.3
+ gopd: 1.0.1
+ has-proto: 1.0.3
+ is-typed-array: 1.1.13
+ possible-typed-array-names: 1.0.0
+ optional: true
+
typescript@5.4.5: {}
typical@4.0.0: {}
@@ -6741,6 +7445,15 @@ snapshots:
gopd: 1.0.1
has-tostringtag: 1.0.0
+ which-typed-array@1.1.15:
+ dependencies:
+ available-typed-arrays: 1.0.7
+ call-bind: 1.0.7
+ for-each: 0.3.3
+ gopd: 1.0.1
+ has-tostringtag: 1.0.2
+ optional: true
+
which@1.3.1:
dependencies:
isexe: 2.0.0
@@ -6784,6 +7497,8 @@ snapshots:
yallist@2.1.2: {}
+ yaml@1.10.2: {}
+
yargs-parser@18.1.3:
dependencies:
camelcase: 5.3.1
diff --git a/contracts/remappings.txt b/contracts/remappings.txt
index 1428f50b316..ec64b1b2118 100644
--- a/contracts/remappings.txt
+++ b/contracts/remappings.txt
@@ -1,6 +1,7 @@
forge-std/=src/v0.8/vendor/forge-std/src/
@openzeppelin/=node_modules/@openzeppelin/
+@arbitrum/=node_modules/@arbitrum/
hardhat/=node_modules/hardhat/
@eth-optimism/=node_modules/@eth-optimism/
@scroll-tech/=node_modules/@scroll-tech/
diff --git a/contracts/scripts/ccip_lcov_prune b/contracts/scripts/ccip_lcov_prune
new file mode 100755
index 00000000000..002e5a3f133
--- /dev/null
+++ b/contracts/scripts/ccip_lcov_prune
@@ -0,0 +1,29 @@
+#!/usr/bin/env bash
+
+set -e
+
+# src/v0.8/ccip/libraries/Internal.sol
+# src/v0.8/ccip/libraries/RateLimiter.sol
+# src/v0.8/ccip/libraries/USDPriceWith18Decimals.sol
+# src/v0.8/ccip/libraries/MerkleMultiProof.sol
+# src/v0.8/ccip/libraries/Pool.sol
+# excluded because Foundry doesn't support coverage on library files
+
+# BurnWithFromMintTokenPool is excluded because Forge doesn't seem to
+# register coverage, even though it is 100% covered.
+
+lcov --remove $1 -o $2 \
+ '*/ccip/test/*' \
+ '*/vendor/*' \
+ '*/shared/*' \
+ 'src/v0.8/ccip/ocr/OCR2Abstract.sol' \
+ 'src/v0.8/ccip/libraries/Internal.sol' \
+ 'src/v0.8/ccip/libraries/RateLimiter.sol' \
+ 'src/v0.8/ccip/libraries/USDPriceWith18Decimals.sol' \
+ 'src/v0.8/ccip/libraries/MerkleMultiProof.sol' \
+ 'src/v0.8/ccip/libraries/Pool.sol' \
+ 'src/v0.8/ConfirmedOwnerWithProposal.sol' \
+ 'src/v0.8/tests/MockV3Aggregator.sol' \
+ 'src/v0.8/ccip/applications/CCIPClientExample.sol' \
+ 'src/v0.8/ccip/pools/BurnWithFromMintTokenPool.sol' \
+ --rc lcov_branch_coverage=1
diff --git a/contracts/scripts/native_solc_compile_all b/contracts/scripts/native_solc_compile_all
index 542337a191a..6e9f17561dd 100755
--- a/contracts/scripts/native_solc_compile_all
+++ b/contracts/scripts/native_solc_compile_all
@@ -12,7 +12,7 @@ python3 -m pip install --require-hashes -r $SCRIPTPATH/requirements.txt
# 6 and 7 are legacy contracts, for each other product we have a native_solc_compile_all_$product script
# These scripts can be run individually, or all together with this script.
# To add new CL products, simply write a native_solc_compile_all_$product script and add it to the list below.
-for product in automation events_mock feeds functions keystone llo-feeds logpoller operatorforwarder shared transmission vrf
+for product in automation events_mock feeds functions keystone llo-feeds logpoller operatorforwarder shared transmission vrf ccip liquiditymanager
do
$SCRIPTPATH/native_solc_compile_all_$product
done
diff --git a/contracts/scripts/native_solc_compile_all_ccip b/contracts/scripts/native_solc_compile_all_ccip
new file mode 100755
index 00000000000..1dbb70502d6
--- /dev/null
+++ b/contracts/scripts/native_solc_compile_all_ccip
@@ -0,0 +1,97 @@
+#!/usr/bin/env bash
+
+set -e
+
+echo " ┌──────────────────────────────────────────────┐"
+echo " │ Compiling CCIP contracts... │"
+echo " └──────────────────────────────────────────────┘"
+
+SOLC_VERSION="0.8.24"
+OPTIMIZE_RUNS=26000
+OPTIMIZE_RUNS_OFFRAMP=18000
+OPTIMIZE_RUNS_ONRAMP=4100
+OPTIMIZE_RUNS_MULTI_OFFRAMP=2500
+
+
+SCRIPTPATH="$( cd "$(dirname "$0")" >/dev/null 2>&1 ; pwd -P )"
+python3 -m pip install --require-hashes -r "$SCRIPTPATH"/requirements.txt
+solc-select install $SOLC_VERSION
+solc-select use $SOLC_VERSION
+export SOLC_VERSION=$SOLC_VERSION
+
+ROOT="$( cd "$(dirname "$0")" >/dev/null 2>&1 ; cd ../../ && pwd -P )"
+
+compileContract () {
+ local contract
+ contract=$(basename "$1" ".sol")
+
+ local optimize_runs=$OPTIMIZE_RUNS
+
+ case $1 in
+ "ccip/offRamp/EVM2EVMOffRamp.sol")
+ echo "OffRamp uses $OPTIMIZE_RUNS_OFFRAMP optimizer runs."
+ optimize_runs=$OPTIMIZE_RUNS_OFFRAMP
+ ;;
+ "ccip/offRamp/EVM2EVMMultiOffRamp.sol")
+ echo "MultiOffRamp uses $OPTIMIZE_RUNS_MULTI_OFFRAMP optimizer runs."
+ optimize_runs=$OPTIMIZE_RUNS_MULTI_OFFRAMP
+ ;;
+ "ccip/onRamp/EVM2EVMOnRamp.sol")
+ echo "OnRamp uses $OPTIMIZE_RUNS_ONRAMP optimizer runs."
+ optimize_runs=$OPTIMIZE_RUNS_ONRAMP
+ ;;
+ esac
+
+ solc --overwrite --optimize --optimize-runs $optimize_runs --metadata-hash none \
+ -o "$ROOT"/contracts/solc/v$SOLC_VERSION/"$contract" \
+ --abi --bin --allow-paths "$ROOT"/contracts/src/v0.8 \
+ --evm-version paris \
+ "$ROOT"/contracts/src/v0.8/"$1"
+}
+
+
+# Solc produces and overwrites intermediary contracts.
+# Contracts should be ordered in reverse-import-complexity-order to minimize overwrite risks.
+compileContract ccip/offRamp/EVM2EVMOffRamp.sol
+compileContract ccip/offRamp/EVM2EVMMultiOffRamp.sol
+compileContract ccip/applications/PingPongDemo.sol
+compileContract ccip/applications/SelfFundedPingPong.sol
+compileContract ccip/applications/EtherSenderReceiver.sol
+compileContract ccip/onRamp/EVM2EVMMultiOnRamp.sol
+compileContract ccip/onRamp/EVM2EVMOnRamp.sol
+compileContract ccip/CommitStore.sol
+compileContract ccip/MultiAggregateRateLimiter.sol
+compileContract ccip/Router.sol
+compileContract ccip/PriceRegistry.sol
+compileContract ccip/pools/LockReleaseTokenPool.sol
+compileContract ccip/pools/BurnMintTokenPool.sol
+compileContract ccip/pools/BurnFromMintTokenPool.sol
+compileContract ccip/pools/BurnWithFromMintTokenPool.sol
+compileContract ccip/pools/LockReleaseTokenPoolAndProxy.sol
+compileContract ccip/pools/BurnMintTokenPoolAndProxy.sol
+compileContract ccip/pools/TokenPool.sol
+compileContract shared/token/ERC677/BurnMintERC677.sol
+compileContract ccip/RMN.sol
+compileContract ccip/ARMProxy.sol
+compileContract ccip/tokenAdminRegistry/TokenAdminRegistry.sol
+compileContract ccip/tokenAdminRegistry/RegistryModuleOwnerCustom.sol
+compileContract ccip/capability/CCIPConfig.sol
+compileContract ccip/capability/interfaces/IOCR3ConfigEncoder.sol
+compileContract ccip/NonceManager.sol
+
+# Test helpers
+compileContract ccip/test/helpers/BurnMintERC677Helper.sol
+compileContract ccip/test/helpers/CommitStoreHelper.sol
+compileContract ccip/test/helpers/MessageHasher.sol
+compileContract ccip/test/helpers/ReportCodec.sol
+compileContract ccip/test/helpers/receivers/MaybeRevertMessageReceiver.sol
+compileContract ccip/test/helpers/MultiOCR3Helper.sol
+compileContract ccip/test/mocks/MockRMN1_0.sol
+compileContract ccip/test/mocks/MockE2EUSDCTokenMessenger.sol
+compileContract ccip/test/mocks/MockE2EUSDCTransmitter.sol
+compileContract ccip/test/WETH9.sol
+
+# Customer contracts
+compileContract ccip/pools/USDC/USDCTokenPool.sol
+
+compileContract tests/MockV3Aggregator.sol
diff --git a/contracts/scripts/native_solc_compile_all_liquiditymanager b/contracts/scripts/native_solc_compile_all_liquiditymanager
new file mode 100755
index 00000000000..a29f041c77b
--- /dev/null
+++ b/contracts/scripts/native_solc_compile_all_liquiditymanager
@@ -0,0 +1,67 @@
+#!/usr/bin/env bash
+
+set -e
+
+echo " ┌──────────────────────────────────────────────┐"
+echo " │ Compiling LiquidityManager contracts... │"
+echo " └──────────────────────────────────────────────┘"
+
+SOLC_VERSION="0.8.24"
+OPTIMIZE_RUNS=1000000
+
+
+SCRIPTPATH="$( cd "$(dirname "$0")" >/dev/null 2>&1 ; pwd -P )"
+python3 -m pip install --require-hashes -r "$SCRIPTPATH"/requirements.txt
+solc-select install $SOLC_VERSION
+solc-select use $SOLC_VERSION
+export SOLC_VERSION=$SOLC_VERSION
+
+ROOT="$( cd "$(dirname "$0")" >/dev/null 2>&1 ; cd ../../ && pwd -P )"
+
+compileContract () {
+ local contract
+ contract=$(basename "$1" ".sol")
+
+ solc @arbitrum/="$ROOT"/contracts/node_modules/@arbitrum/ \
+ @eth-optimism/="$ROOT"/contracts/node_modules/@eth-optimism/ \
+ @openzeppelin/="$ROOT"/contracts/node_modules/@openzeppelin/ \
+ --overwrite --optimize --optimize-runs $OPTIMIZE_RUNS --metadata-hash none \
+ -o "$ROOT"/contracts/solc/v$SOLC_VERSION/"$contract" \
+ --abi --bin --allow-paths "$ROOT"/contracts/src/v0.8,"$ROOT"/contracts/node_modules \
+ --evm-version paris \
+ "$ROOT"/contracts/src/v0.8/"$1"
+}
+
+
+# Liquidity Management
+compileContract liquiditymanager/LiquidityManager.sol
+compileContract liquiditymanager/bridge-adapters/ArbitrumL1BridgeAdapter.sol
+compileContract liquiditymanager/bridge-adapters/ArbitrumL2BridgeAdapter.sol
+compileContract liquiditymanager/bridge-adapters/OptimismL1BridgeAdapter.sol
+compileContract liquiditymanager/bridge-adapters/OptimismL2BridgeAdapter.sol
+compileContract liquiditymanager/test/mocks/NoOpOCR3.sol
+compileContract liquiditymanager/test/mocks/MockBridgeAdapter.sol
+compileContract liquiditymanager/test/helpers/ReportEncoder.sol
+
+# Arbitrum helpers
+compileContract liquiditymanager/interfaces/arbitrum/IArbSys.sol
+compileContract liquiditymanager/interfaces/arbitrum/INodeInterface.sol
+compileContract liquiditymanager/interfaces/arbitrum/IL2ArbitrumGateway.sol
+compileContract liquiditymanager/interfaces/arbitrum/IL2ArbitrumMessenger.sol
+compileContract liquiditymanager/interfaces/arbitrum/IArbRollupCore.sol
+compileContract liquiditymanager/interfaces/arbitrum/IArbitrumL1GatewayRouter.sol
+compileContract liquiditymanager/interfaces/arbitrum/IArbitrumInbox.sol
+compileContract liquiditymanager/interfaces/arbitrum/IArbitrumGatewayRouter.sol
+compileContract liquiditymanager/interfaces/arbitrum/IArbitrumTokenGateway.sol
+compileContract liquiditymanager/interfaces/arbitrum/IAbstractArbitrumTokenGateway.sol
+
+# Optimism helpers
+compileContract liquiditymanager/interfaces/optimism/IOptimismPortal.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismL2OutputOracle.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismL2ToL1MessagePasser.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismCrossDomainMessenger.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismPortal2.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismDisputeGameFactory.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismStandardBridge.sol
+compileContract liquiditymanager/interfaces/optimism/IOptimismL1StandardBridge.sol
+compileContract liquiditymanager/encoders/OptimismL1BridgeAdapterEncoder.sol
diff --git a/contracts/src/v0.8/ccip/ARMProxy.sol b/contracts/src/v0.8/ccip/ARMProxy.sol
new file mode 100644
index 00000000000..e9ccde8680b
--- /dev/null
+++ b/contracts/src/v0.8/ccip/ARMProxy.sol
@@ -0,0 +1,74 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../shared/interfaces/ITypeAndVersion.sol";
+
+import {OwnerIsCreator} from "./../shared/access/OwnerIsCreator.sol";
+
+/// @notice The ARMProxy serves to allow CCIP contracts
+/// to point to a static address for ARM queries, which saves gas
+/// since each contract need not store an ARM address in storage. That way
+/// we can add ARM queries along many code paths for increased defense in depth
+/// with minimal additional cost.
+contract ARMProxy is OwnerIsCreator, ITypeAndVersion {
+ error ZeroAddressNotAllowed();
+
+ event ARMSet(address arm);
+
+ // STATIC CONFIG
+ // solhint-disable-next-line chainlink-solidity/all-caps-constant-storage-variables
+ string public constant override typeAndVersion = "ARMProxy 1.0.0";
+
+ // DYNAMIC CONFIG
+ address private s_arm;
+
+ constructor(address arm) {
+ setARM(arm);
+ }
+
+ /// @notice SetARM sets the ARM implementation contract address.
+ /// @param arm The address of the arm implementation contract.
+ function setARM(address arm) public onlyOwner {
+ if (arm == address(0)) revert ZeroAddressNotAllowed();
+ s_arm = arm;
+ emit ARMSet(arm);
+ }
+
+ /// @notice getARM gets the ARM implementation contract address.
+ /// @return arm The address of the arm implementation contract.
+ function getARM() external view returns (address) {
+ return s_arm;
+ }
+
+ // We use a fallback function instead of explicit implementations of the functions
+ // defined in IRMN.sol to preserve compatibility with future additions to the IRMN
+ // interface. Calling IRMN interface methods in ARMProxy should be transparent, i.e.
+ // their input/output behaviour should be identical to calling the proxied s_arm
+ // contract directly. (If s_arm doesn't point to a contract, we always revert.)
+ // solhint-disable-next-line payable-fallback, no-complex-fallback
+ fallback() external {
+ address arm = s_arm;
+ // solhint-disable-next-line no-inline-assembly
+ assembly {
+ // Revert if no contract present at destination address, otherwise call
+ // might succeed unintentionally.
+ if iszero(extcodesize(arm)) { revert(0, 0) }
+ // We use memory starting at zero, overwriting anything that might already
+ // be stored there. This messes with Solidity's expectations around memory
+ // layout, but it's fine because we always exit execution of this contract
+ // inside this assembly block, i.e. we don't cede control to code generated
+ // by the Solidity compiler that might have expectations around memory
+ // layout.
+ // Copy calldatasize() bytes from calldata offset 0 to memory offset 0.
+ calldatacopy(0, 0, calldatasize())
+ // Call the underlying ARM implementation. out and outsize are 0 because
+ // we don't know the size yet. We hardcode value to zero.
+ let success := call(gas(), arm, 0, 0, calldatasize(), 0, 0)
+ // Copy the returned data.
+ returndatacopy(0, 0, returndatasize())
+ // Pass through successful return or revert and associated data.
+ if success { return(0, returndatasize()) }
+ revert(0, returndatasize())
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/AggregateRateLimiter.sol b/contracts/src/v0.8/ccip/AggregateRateLimiter.sol
new file mode 100644
index 00000000000..7401df2ed49
--- /dev/null
+++ b/contracts/src/v0.8/ccip/AggregateRateLimiter.sol
@@ -0,0 +1,92 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPriceRegistry} from "./interfaces/IPriceRegistry.sol";
+
+import {OwnerIsCreator} from "./../shared/access/OwnerIsCreator.sol";
+import {Client} from "./libraries/Client.sol";
+import {RateLimiter} from "./libraries/RateLimiter.sol";
+import {USDPriceWith18Decimals} from "./libraries/USDPriceWith18Decimals.sol";
+
+/// @notice The aggregate rate limiter is a wrapper of the token bucket rate limiter
+/// which permits rate limiting based on the aggregate value of a group of
+/// token transfers, using a price registry to convert to a numeraire asset (e.g. USD).
+contract AggregateRateLimiter is OwnerIsCreator {
+ using RateLimiter for RateLimiter.TokenBucket;
+ using USDPriceWith18Decimals for uint224;
+
+ error PriceNotFoundForToken(address token);
+
+ event AdminSet(address newAdmin);
+
+ // The address of the token limit admin that has the same permissions as the owner.
+ address internal s_admin;
+
+ // The token bucket object that contains the bucket state.
+ RateLimiter.TokenBucket private s_rateLimiter;
+
+ /// @param config The RateLimiter.Config
+ constructor(RateLimiter.Config memory config) {
+ s_rateLimiter = RateLimiter.TokenBucket({
+ rate: config.rate,
+ capacity: config.capacity,
+ tokens: config.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: config.isEnabled
+ });
+ }
+
+ /// @notice Consumes value from the rate limiter bucket based on the token value given.
+ function _rateLimitValue(uint256 value) internal {
+ s_rateLimiter._consume(value, address(0));
+ }
+
+ function _getTokenValue(
+ Client.EVMTokenAmount memory tokenAmount,
+ IPriceRegistry priceRegistry
+ ) internal view returns (uint256) {
+ // not fetching validated price, as price staleness is not important for value-based rate limiting
+ // we only need to verify the price is not 0
+ uint224 pricePerToken = priceRegistry.getTokenPrice(tokenAmount.token).value;
+ if (pricePerToken == 0) revert PriceNotFoundForToken(tokenAmount.token);
+ return pricePerToken._calcUSDValueFromTokenAmount(tokenAmount.amount);
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function currentRateLimiterState() external view returns (RateLimiter.TokenBucket memory) {
+ return s_rateLimiter._currentTokenBucketState();
+ }
+
+ /// @notice Sets the rate limited config.
+ /// @param config The new rate limiter config.
+ /// @dev should only be callable by the owner or token limit admin.
+ function setRateLimiterConfig(RateLimiter.Config memory config) external onlyAdminOrOwner {
+ s_rateLimiter._setTokenBucketConfig(config);
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Gets the token limit admin address.
+ /// @return the token limit admin address.
+ function getTokenLimitAdmin() external view returns (address) {
+ return s_admin;
+ }
+
+ /// @notice Sets the token limit admin address.
+ /// @param newAdmin the address of the new admin.
+ /// @dev setting this to address(0) indicates there is no active admin.
+ function setAdmin(address newAdmin) external onlyAdminOrOwner {
+ s_admin = newAdmin;
+ emit AdminSet(newAdmin);
+ }
+
+ /// @notice a modifier that allows the owner or the s_tokenLimitAdmin call the functions
+ /// it is applied to.
+ modifier onlyAdminOrOwner() {
+ if (msg.sender != owner() && msg.sender != s_admin) revert RateLimiter.OnlyCallableByAdminOrOwner();
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/CommitStore.sol b/contracts/src/v0.8/ccip/CommitStore.sol
new file mode 100644
index 00000000000..27388b6dcc2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/CommitStore.sol
@@ -0,0 +1,314 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../shared/interfaces/ITypeAndVersion.sol";
+import {ICommitStore} from "./interfaces/ICommitStore.sol";
+import {IPriceRegistry} from "./interfaces/IPriceRegistry.sol";
+import {IRMN} from "./interfaces/IRMN.sol";
+
+import {Internal} from "./libraries/Internal.sol";
+import {MerkleMultiProof} from "./libraries/MerkleMultiProof.sol";
+import {OCR2Base} from "./ocr/OCR2Base.sol";
+
+contract CommitStore is ICommitStore, ITypeAndVersion, OCR2Base {
+ error StaleReport();
+ error PausedError();
+ error InvalidInterval(Interval interval);
+ error InvalidRoot();
+ error InvalidCommitStoreConfig();
+ error CursedByRMN();
+ error RootAlreadyCommitted();
+
+ event Paused(address account);
+ event Unpaused(address account);
+ /// @dev RMN depends on this event, if changing, please notify the RMN maintainers.
+ event ReportAccepted(CommitReport report);
+ event ConfigSet(StaticConfig staticConfig, DynamicConfig dynamicConfig);
+ event RootRemoved(bytes32 root);
+ event SequenceNumberSet(uint64 oldSeqNum, uint64 newSeqNum);
+ event LatestPriceEpochAndRoundSet(uint40 oldEpochAndRound, uint40 newEpochAndRound);
+
+ /// @notice Static commit store config
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ //solhint-disable gas-struct-packing
+ struct StaticConfig {
+ uint64 chainSelector; // ───────╮ Destination chainSelector
+ uint64 sourceChainSelector; // ─╯ Source chainSelector
+ address onRamp; // OnRamp address on the source chain
+ address rmnProxy; // RMN proxy address
+ }
+
+ /// @notice Dynamic commit store config
+ struct DynamicConfig {
+ address priceRegistry; // Price registry address on the destination chain
+ }
+
+ /// @notice a sequenceNumber interval
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct Interval {
+ uint64 min; // ───╮ Minimum sequence number, inclusive
+ uint64 max; // ───╯ Maximum sequence number, inclusive
+ }
+
+ /// @notice Report that is committed by the observing DON at the committing phase
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct CommitReport {
+ Internal.PriceUpdates priceUpdates;
+ Interval interval;
+ bytes32 merkleRoot;
+ }
+
+ // STATIC CONFIG
+ string public constant override typeAndVersion = "CommitStore 1.5.0-dev";
+ // Chain ID of this chain
+ uint64 internal immutable i_chainSelector;
+ // Chain ID of the source chain
+ uint64 internal immutable i_sourceChainSelector;
+ // The onRamp address on the source chain
+ address internal immutable i_onRamp;
+ // The address of the rmn proxy
+ address internal immutable i_rmnProxy;
+
+ // DYNAMIC CONFIG
+ // The dynamic commitStore config
+ DynamicConfig internal s_dynamicConfig;
+
+ // STATE
+ // The min sequence number expected for future messages
+ uint64 private s_minSeqNr = 1;
+ /// @dev The epoch and round of the last report
+ uint40 private s_latestPriceEpochAndRound;
+ /// @dev Whether this CommitStore is paused or not
+ bool private s_paused = false;
+ // merkleRoot => timestamp when received
+ mapping(bytes32 merkleRoot => uint256 timestamp) private s_roots;
+
+ /// @param staticConfig Containing the static part of the commitStore config
+ /// @dev When instantiating OCR2Base we set UNIQUE_REPORTS to false, which means
+ /// that we do not require 2f+1 signatures on a report, only f+1 to save gas. 2f+1 is required
+ /// only if one must strictly ensure that for a given round there is only one valid report ever generated by
+ /// the DON. In our case additional valid reports (i.e. approved by >= f+1 oracles) are not a problem, as they will
+ /// will either be ignored (reverted as an invalid interval) or will be accepted as an additional valid price update.
+ constructor(StaticConfig memory staticConfig) OCR2Base(false) {
+ if (
+ staticConfig.onRamp == address(0) || staticConfig.chainSelector == 0 || staticConfig.sourceChainSelector == 0
+ || staticConfig.rmnProxy == address(0)
+ ) revert InvalidCommitStoreConfig();
+
+ i_chainSelector = staticConfig.chainSelector;
+ i_sourceChainSelector = staticConfig.sourceChainSelector;
+ i_onRamp = staticConfig.onRamp;
+ i_rmnProxy = staticConfig.rmnProxy;
+ }
+
+ // ================================================================
+ // │ Verification │
+ // ================================================================
+
+ /// @notice Returns the next expected sequence number.
+ /// @return the next expected sequenceNumber.
+ function getExpectedNextSequenceNumber() external view returns (uint64) {
+ return s_minSeqNr;
+ }
+
+ /// @notice Sets the minimum sequence number.
+ /// @param minSeqNr The new minimum sequence number.
+ function setMinSeqNr(uint64 minSeqNr) external onlyOwner {
+ uint64 oldSeqNum = s_minSeqNr;
+
+ s_minSeqNr = minSeqNr;
+
+ emit SequenceNumberSet(oldSeqNum, minSeqNr);
+ }
+
+ /// @notice Returns the epoch and round of the last price update.
+ /// @return the latest price epoch and round.
+ function getLatestPriceEpochAndRound() external view returns (uint64) {
+ return s_latestPriceEpochAndRound;
+ }
+
+ /// @notice Sets the latest epoch and round for price update.
+ /// @param latestPriceEpochAndRound The new epoch and round for prices.
+ function setLatestPriceEpochAndRound(uint40 latestPriceEpochAndRound) external onlyOwner {
+ uint40 oldEpochAndRound = s_latestPriceEpochAndRound;
+
+ s_latestPriceEpochAndRound = latestPriceEpochAndRound;
+
+ emit LatestPriceEpochAndRoundSet(oldEpochAndRound, latestPriceEpochAndRound);
+ }
+
+ /// @notice Returns the timestamp of a potentially previously committed merkle root.
+ /// If the root was never committed 0 will be returned.
+ /// @param root The merkle root to check the commit status for.
+ /// @return the timestamp of the committed root or zero in the case that it was never
+ /// committed.
+ function getMerkleRoot(bytes32 root) external view returns (uint256) {
+ return s_roots[root];
+ }
+
+ /// @notice Returns if a root is blessed or not.
+ /// @param root The merkle root to check the blessing status for.
+ /// @return whether the root is blessed or not.
+ function isBlessed(bytes32 root) public view returns (bool) {
+ return IRMN(i_rmnProxy).isBlessed(IRMN.TaggedRoot({commitStore: address(this), root: root}));
+ }
+
+ /// @notice Used by the owner in case an invalid sequence of roots has been
+ /// posted and needs to be removed. The interval in the report is trusted.
+ /// @param rootToReset The roots that will be reset. This function will only
+ /// reset roots that are not blessed.
+ function resetUnblessedRoots(bytes32[] calldata rootToReset) external onlyOwner {
+ for (uint256 i = 0; i < rootToReset.length; ++i) {
+ bytes32 root = rootToReset[i];
+ if (!isBlessed(root)) {
+ delete s_roots[root];
+ emit RootRemoved(root);
+ }
+ }
+ }
+
+ /// @inheritdoc ICommitStore
+ function verify(
+ bytes32[] calldata hashedLeaves,
+ bytes32[] calldata proofs,
+ uint256 proofFlagBits
+ ) external view override whenNotPaused returns (uint256 timestamp) {
+ bytes32 root = MerkleMultiProof.merkleRoot(hashedLeaves, proofs, proofFlagBits);
+ // Only return non-zero if present and blessed.
+ if (!isBlessed(root)) {
+ return 0;
+ }
+ return s_roots[root];
+ }
+
+ /// @inheritdoc OCR2Base
+ /// @dev A commitReport can have two distinct parts (batched together to amortize the cost of checking sigs):
+ /// 1. Price updates
+ /// 2. A merkle root and sequence number interval
+ /// Both have their own, separate, staleness checks, with price updates using the epoch and round
+ /// number of the latest price update. The merkle root checks for staleness based on the seqNums.
+ /// They need to be separate because a price report for round t+2 might be included before a report
+ /// containing a merkle root for round t+1. This merkle root report for round t+1 is still valid
+ /// and should not be rejected. When a report with a stale root but valid price updates is submitted,
+ /// we are OK to revert to preserve the invariant that we always revert on invalid sequence number ranges.
+ /// If that happens, prices will be updates in later rounds.
+ function _report(bytes calldata encodedReport, uint40 epochAndRound) internal override whenNotPaused {
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(i_sourceChainSelector)))) revert CursedByRMN();
+
+ CommitReport memory report = abi.decode(encodedReport, (CommitReport));
+
+ // Check if the report contains price updates
+ if (report.priceUpdates.tokenPriceUpdates.length > 0 || report.priceUpdates.gasPriceUpdates.length > 0) {
+ // Check for price staleness based on the epoch and round
+ if (s_latestPriceEpochAndRound < epochAndRound) {
+ // If prices are not stale, update the latest epoch and round
+ s_latestPriceEpochAndRound = epochAndRound;
+ // And update the prices in the price registry
+ IPriceRegistry(s_dynamicConfig.priceRegistry).updatePrices(report.priceUpdates);
+
+ // If there is no root, the report only contained fee updated and
+ // we return to not revert on the empty root check below.
+ if (report.merkleRoot == bytes32(0)) return;
+ } else {
+ // If prices are stale and the report doesn't contain a root, this report
+ // does not have any valid information and we revert.
+ // If it does contain a merkle root, continue to the root checking section.
+ if (report.merkleRoot == bytes32(0)) revert StaleReport();
+ }
+ }
+
+ // If we reached this section, the report should contain a valid root
+ if (s_minSeqNr != report.interval.min || report.interval.min > report.interval.max) {
+ revert InvalidInterval(report.interval);
+ }
+
+ if (report.merkleRoot == bytes32(0)) revert InvalidRoot();
+ // Disallow duplicate roots as that would reset the timestamp and
+ // delay potential manual execution.
+ if (s_roots[report.merkleRoot] != 0) revert RootAlreadyCommitted();
+
+ s_minSeqNr = report.interval.max + 1;
+ s_roots[report.merkleRoot] = block.timestamp;
+ emit ReportAccepted(report);
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Returns the static commit store config.
+ /// @dev RMN depends on this function, if changing, please notify the RMN maintainers.
+ /// @return the configuration.
+ function getStaticConfig() external view returns (StaticConfig memory) {
+ return StaticConfig({
+ chainSelector: i_chainSelector,
+ sourceChainSelector: i_sourceChainSelector,
+ onRamp: i_onRamp,
+ rmnProxy: i_rmnProxy
+ });
+ }
+
+ /// @notice Returns the dynamic commit store config.
+ /// @return the configuration.
+ function getDynamicConfig() external view returns (DynamicConfig memory) {
+ return s_dynamicConfig;
+ }
+
+ /// @notice Sets the dynamic config. This function is called during `setOCR2Config` flow
+ function _beforeSetConfig(bytes memory onchainConfig) internal override {
+ DynamicConfig memory dynamicConfig = abi.decode(onchainConfig, (DynamicConfig));
+
+ if (dynamicConfig.priceRegistry == address(0)) revert InvalidCommitStoreConfig();
+
+ s_dynamicConfig = dynamicConfig;
+ // When the OCR config changes, we reset the price epoch and round
+ // since epoch and rounds are scoped per config digest.
+ // Note that s_minSeqNr/roots do not need to be reset as the roots persist
+ // across reconfigurations and are de-duplicated separately.
+ s_latestPriceEpochAndRound = 0;
+
+ emit ConfigSet(
+ StaticConfig({
+ chainSelector: i_chainSelector,
+ sourceChainSelector: i_sourceChainSelector,
+ onRamp: i_onRamp,
+ rmnProxy: i_rmnProxy
+ }),
+ dynamicConfig
+ );
+ }
+
+ // ================================================================
+ // │ Access and RMN │
+ // ================================================================
+
+ /// @notice Single function to check the status of the commitStore.
+ function isUnpausedAndNotCursed() external view returns (bool) {
+ return !IRMN(i_rmnProxy).isCursed(bytes16(uint128(i_sourceChainSelector))) && !s_paused;
+ }
+
+ /// @notice Modifier to make a function callable only when the contract is not paused.
+ modifier whenNotPaused() {
+ if (paused()) revert PausedError();
+ _;
+ }
+
+ /// @notice Returns true if the contract is paused, and false otherwise.
+ function paused() public view returns (bool) {
+ return s_paused;
+ }
+
+ /// @notice Pause the contract
+ /// @dev only callable by the owner
+ function pause() external onlyOwner {
+ s_paused = true;
+ emit Paused(msg.sender);
+ }
+
+ /// @notice Unpause the contract
+ /// @dev only callable by the owner
+ function unpause() external onlyOwner {
+ s_paused = false;
+ emit Unpaused(msg.sender);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/LICENSE-MIT.md b/contracts/src/v0.8/ccip/LICENSE-MIT.md
new file mode 100644
index 00000000000..812debd8e9b
--- /dev/null
+++ b/contracts/src/v0.8/ccip/LICENSE-MIT.md
@@ -0,0 +1,21 @@
+The MIT License (MIT)
+
+Copyright (c) 2018 SmartContract ChainLink, Ltd.
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in
+all copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
+THE SOFTWARE.
\ No newline at end of file
diff --git a/contracts/src/v0.8/ccip/LICENSE.md b/contracts/src/v0.8/ccip/LICENSE.md
new file mode 100644
index 00000000000..5f2783f7a34
--- /dev/null
+++ b/contracts/src/v0.8/ccip/LICENSE.md
@@ -0,0 +1,56 @@
+Business Source License 1.1
+
+License text copyright (c) 2017 MariaDB Corporation Ab, All Rights Reserved.
+"Business Source License" is a trademark of MariaDB Corporation Ab.
+
+-----------------------------------------------------------------------------
+
+Parameters
+
+Licensor: SmartContract Chainlink Limited SEZC
+
+Licensed Work: Cross-Chain Interoperability Protocol v1.4
+The Licensed Work is (c) 2023 SmartContract Chainlink Limited SEZC
+
+Additional Use Grant: Any uses listed and defined at [v1.4-CCIP-License-grants](
+./v1.4-CCIP-License-grants)
+
+Change Date: May 23, 2027
+
+Change License: MIT
+
+-----------------------------------------------------------------------------
+
+Terms
+
+The Licensor hereby grants you the right to copy, modify, create derivative works, redistribute, and make non-production use of the Licensed Work. The Licensor may make an Additional Use Grant, above, permitting limited production use.
+
+Effective on the Change Date, or the fourth anniversary of the first publicly available distribution of a specific version of the Licensed Work under this License, whichever comes first, the Licensor hereby grants you rights under the terms of the Change License, and the rights granted in the paragraph above terminate.
+
+If your use of the Licensed Work does not comply with the requirements currently in effect as described in this License, you must purchase a commercial license from the Licensor, its affiliated entities, or authorized resellers, or you must refrain from using the Licensed Work.
+
+All copies of the original and modified Licensed Work, and derivative works of the Licensed Work, are subject to this License. This License applies separately for each version of the Licensed Work and the Change Date may vary for each version of the Licensed Work released by Licensor.
+
+You must conspicuously display this License on each original or modified copy of the Licensed Work. If you receive the Licensed Work in original or modified form from a third party, the terms and conditions set forth in this License apply to your use of that work.
+
+Any use of the Licensed Work in violation of this License will automatically terminate your rights under this License for the current and all other versions of the Licensed Work.
+
+This License does not grant you any right in any trademark or logo of Licensor or its affiliates (provided that you may use a trademark or logo of Licensor as expressly required by this License).
+
+TO THE EXTENT PERMITTED BY APPLICABLE LAW, THE LICENSED WORK IS PROVIDED ON AN "AS IS" BASIS. LICENSOR HEREBY DISCLAIMS ALL WARRANTIES AND CONDITIONS, EXPRESS OR IMPLIED, INCLUDING (WITHOUT LIMITATION) WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND TITLE.
+
+MariaDB hereby grants you permission to use this License’s text to license your works, and to refer to it using the trademark "Business Source License", as long as you comply with the Covenants of Licensor below.
+
+-----------------------------------------------------------------------------
+
+Covenants of Licensor
+
+In consideration of the right to use this License’s text and the "Business Source License" name and trademark, Licensor covenants to MariaDB, and to all other recipients of the licensed work to be provided by Licensor:
+
+1. To specify as the Change License the GPL Version 2.0 or any later version, or a license that is compatible with GPL Version 2.0 or a later version, where "compatible" means that software provided under the Change License can be included in a program with software provided under GPL Version 2.0 or a later version. Licensor may specify additional Change Licenses without limitation.
+
+2. To either: (a) specify an additional grant of rights to use that does not impose any additional restriction on the right granted in this License, as the Additional Use Grant; or (b) insert the text "None".
+
+3. To specify a Change Date.
+
+4. Not to modify this License in any other way.
\ No newline at end of file
diff --git a/contracts/src/v0.8/ccip/MultiAggregateRateLimiter.sol b/contracts/src/v0.8/ccip/MultiAggregateRateLimiter.sol
new file mode 100644
index 00000000000..2a9d087a26c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/MultiAggregateRateLimiter.sol
@@ -0,0 +1,272 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IMessageInterceptor} from "./interfaces/IMessageInterceptor.sol";
+import {IPriceRegistry} from "./interfaces/IPriceRegistry.sol";
+
+import {AuthorizedCallers} from "../shared/access/AuthorizedCallers.sol";
+import {EnumerableMapAddresses} from "./../shared/enumerable/EnumerableMapAddresses.sol";
+import {Client} from "./libraries/Client.sol";
+import {RateLimiter} from "./libraries/RateLimiter.sol";
+import {USDPriceWith18Decimals} from "./libraries/USDPriceWith18Decimals.sol";
+
+import {EnumerableSet} from "./../vendor/openzeppelin-solidity/v4.7.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice The aggregate rate limiter is a wrapper of the token bucket rate limiter
+/// which permits rate limiting based on the aggregate value of a group of
+/// token transfers, using a price registry to convert to a numeraire asset (e.g. USD).
+/// The contract is a standalone multi-lane message validator contract, which can be called by authorized
+/// ramp contracts to apply rate limit changes to lanes, and revert when the rate limits get breached.
+contract MultiAggregateRateLimiter is IMessageInterceptor, AuthorizedCallers {
+ using RateLimiter for RateLimiter.TokenBucket;
+ using USDPriceWith18Decimals for uint224;
+ using EnumerableMapAddresses for EnumerableMapAddresses.AddressToBytes32Map;
+ using EnumerableSet for EnumerableSet.AddressSet;
+
+ error PriceNotFoundForToken(address token);
+ error ZeroChainSelectorNotAllowed();
+
+ event RateLimiterConfigUpdated(uint64 indexed remoteChainSelector, bool isOutboundLane, RateLimiter.Config config);
+ event PriceRegistrySet(address newPriceRegistry);
+ event TokenAggregateRateLimitAdded(uint64 remoteChainSelector, bytes32 remoteToken, address localToken);
+ event TokenAggregateRateLimitRemoved(uint64 remoteChainSelector, address localToken);
+
+ /// @notice RemoteRateLimitToken struct containing the local token address with the chain selector
+ /// The struct is used for removals and updates, since the local -> remote token mappings are scoped per-chain
+ struct LocalRateLimitToken {
+ uint64 remoteChainSelector; // ────╮ Remote chain selector for which to update the rate limit token mapping
+ address localToken; // ────────────╯ Token on the chain on which the multi-ARL is deployed
+ }
+
+ /// @notice RateLimitToken struct containing both the local and remote token addresses
+ struct RateLimitTokenArgs {
+ LocalRateLimitToken localTokenArgs; // Local token update args scoped to one remote chain
+ bytes32 remoteToken; // Token on the remote chain (for OnRamp - dest, of OffRamp - source)
+ }
+
+ /// @notice Update args for a single rate limiter config update
+ struct RateLimiterConfigArgs {
+ uint64 remoteChainSelector; // ────╮ Chain selector to set config for
+ bool isOutboundLane; // ───────────╯ If set to true, represents the outbound message lane (OnRamp), and the inbound message lane otherwise (OffRamp)
+ RateLimiter.Config rateLimiterConfig; // Rate limiter config to set
+ }
+
+ /// @notice Struct to store rate limit token buckets for both lane directions
+ struct RateLimiterBuckets {
+ RateLimiter.TokenBucket inboundLaneBucket; // Bucket for the inbound lane (remote -> local)
+ RateLimiter.TokenBucket outboundLaneBucket; // Bucket for the outbound lane (local -> remote)
+ }
+
+ /// @dev Tokens that should be included in Aggregate Rate Limiting (from local chain (this chain) -> remote),
+ /// grouped per-remote chain.
+ mapping(uint64 remoteChainSelector => EnumerableMapAddresses.AddressToBytes32Map tokensLocalToRemote) internal
+ s_rateLimitedTokensLocalToRemote;
+
+ /// @notice The address of the PriceRegistry used to query token values for ratelimiting
+ address internal s_priceRegistry;
+
+ /// @notice Rate limiter token bucket states per chain, with separate buckets for inbound and outbound lanes.
+ mapping(uint64 remoteChainSelector => RateLimiterBuckets buckets) internal s_rateLimitersByChainSelector;
+
+ /// @param priceRegistry the price registry to set
+ /// @param authorizedCallers the authorized callers to set
+ constructor(address priceRegistry, address[] memory authorizedCallers) AuthorizedCallers(authorizedCallers) {
+ _setPriceRegistry(priceRegistry);
+ }
+
+ /// @inheritdoc IMessageInterceptor
+ function onInboundMessage(Client.Any2EVMMessage memory message) external onlyAuthorizedCallers {
+ _applyRateLimit(message.sourceChainSelector, message.destTokenAmounts, false);
+ }
+
+ /// @inheritdoc IMessageInterceptor
+ function onOutboundMessage(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external onlyAuthorizedCallers {
+ _applyRateLimit(destChainSelector, message.tokenAmounts, true);
+ }
+
+ /// @notice Applies the rate limit to the token bucket if enabled
+ /// @param remoteChainSelector The remote chain selector
+ /// @param tokenAmounts The tokens and amounts to rate limit
+ /// @param isOutgoingLane if set to true, fetches the bucket for the outgoing message lane (OnRamp).
+ function _applyRateLimit(
+ uint64 remoteChainSelector,
+ Client.EVMTokenAmount[] memory tokenAmounts,
+ bool isOutgoingLane
+ ) private {
+ RateLimiter.TokenBucket storage tokenBucket = _getTokenBucket(remoteChainSelector, isOutgoingLane);
+
+ // Skip rate limiting if it is disabled
+ if (tokenBucket.isEnabled) {
+ uint256 value;
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ if (s_rateLimitedTokensLocalToRemote[remoteChainSelector].contains(tokenAmounts[i].token)) {
+ value += _getTokenValue(tokenAmounts[i]);
+ }
+ }
+ // Rate limit on aggregated token value
+ if (value > 0) tokenBucket._consume(value, address(0));
+ }
+ }
+
+ /// @param remoteChainSelector chain selector to retrieve token bucket for
+ /// @param isOutboundLane if set to true, fetches the bucket for the outbound message lane (OnRamp).
+ /// Otherwise fetches for the inbound message lane (OffRamp).
+ /// @return bucket Storage pointer to the token bucket representing a specific lane
+ function _getTokenBucket(
+ uint64 remoteChainSelector,
+ bool isOutboundLane
+ ) internal view returns (RateLimiter.TokenBucket storage) {
+ RateLimiterBuckets storage rateLimiterBuckets = s_rateLimitersByChainSelector[remoteChainSelector];
+ if (isOutboundLane) {
+ return rateLimiterBuckets.outboundLaneBucket;
+ } else {
+ return rateLimiterBuckets.inboundLaneBucket;
+ }
+ }
+
+ /// @notice Retrieves the token value for a token using the PriceRegistry
+ /// @return tokenValue USD value in 18 decimals
+ function _getTokenValue(Client.EVMTokenAmount memory tokenAmount) internal view returns (uint256) {
+ // not fetching validated price, as price staleness is not important for value-based rate limiting
+ // we only need to verify the price is not 0
+ uint224 pricePerToken = IPriceRegistry(s_priceRegistry).getTokenPrice(tokenAmount.token).value;
+ if (pricePerToken == 0) revert PriceNotFoundForToken(tokenAmount.token);
+ return pricePerToken._calcUSDValueFromTokenAmount(tokenAmount.amount);
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @param remoteChainSelector chain selector to retrieve state for
+ /// @param isOutboundLane if set to true, fetches the rate limit state for the outbound message lane (OnRamp).
+ /// Otherwise fetches for the inbound message lane (OffRamp).
+ /// The outbound and inbound message rate limit state is completely separated.
+ /// @return The token bucket.
+ function currentRateLimiterState(
+ uint64 remoteChainSelector,
+ bool isOutboundLane
+ ) external view returns (RateLimiter.TokenBucket memory) {
+ return _getTokenBucket(remoteChainSelector, isOutboundLane)._currentTokenBucketState();
+ }
+
+ /// @notice Applies the provided rate limiter config updates.
+ /// @param rateLimiterUpdates Rate limiter updates
+ /// @dev should only be callable by the owner
+ function applyRateLimiterConfigUpdates(RateLimiterConfigArgs[] memory rateLimiterUpdates) external onlyOwner {
+ for (uint256 i = 0; i < rateLimiterUpdates.length; ++i) {
+ RateLimiterConfigArgs memory updateArgs = rateLimiterUpdates[i];
+ RateLimiter.Config memory configUpdate = updateArgs.rateLimiterConfig;
+ uint64 remoteChainSelector = updateArgs.remoteChainSelector;
+
+ if (remoteChainSelector == 0) {
+ revert ZeroChainSelectorNotAllowed();
+ }
+
+ bool isOutboundLane = updateArgs.isOutboundLane;
+
+ RateLimiter.TokenBucket storage tokenBucket = _getTokenBucket(remoteChainSelector, isOutboundLane);
+
+ if (tokenBucket.lastUpdated == 0) {
+ // Token bucket needs to be newly added
+ RateLimiter.TokenBucket memory newTokenBucket = RateLimiter.TokenBucket({
+ rate: configUpdate.rate,
+ capacity: configUpdate.capacity,
+ tokens: configUpdate.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: configUpdate.isEnabled
+ });
+
+ if (isOutboundLane) {
+ s_rateLimitersByChainSelector[remoteChainSelector].outboundLaneBucket = newTokenBucket;
+ } else {
+ s_rateLimitersByChainSelector[remoteChainSelector].inboundLaneBucket = newTokenBucket;
+ }
+ } else {
+ tokenBucket._setTokenBucketConfig(configUpdate);
+ }
+ emit RateLimiterConfigUpdated(remoteChainSelector, isOutboundLane, configUpdate);
+ }
+ }
+
+ /// @notice Get all tokens which are included in Aggregate Rate Limiting.
+ /// @param remoteChainSelector chain selector to get rate limit tokens for
+ /// @return localTokens The local chain representation of the tokens that are rate limited.
+ /// @return remoteTokens The remote representation of the tokens that are rate limited.
+ /// @dev the order of IDs in the list is **not guaranteed**, therefore, if ordering matters when
+ /// making successive calls, one should keep the block height constant to ensure a consistent result.
+ function getAllRateLimitTokens(uint64 remoteChainSelector)
+ external
+ view
+ returns (address[] memory localTokens, bytes32[] memory remoteTokens)
+ {
+ uint256 tokenCount = s_rateLimitedTokensLocalToRemote[remoteChainSelector].length();
+
+ localTokens = new address[](tokenCount);
+ remoteTokens = new bytes32[](tokenCount);
+
+ for (uint256 i = 0; i < tokenCount; ++i) {
+ (address localToken, bytes32 remoteToken) = s_rateLimitedTokensLocalToRemote[remoteChainSelector].at(i);
+ localTokens[i] = localToken;
+ remoteTokens[i] = remoteToken;
+ }
+ return (localTokens, remoteTokens);
+ }
+
+ /// @notice Adds or removes tokens from being used in Aggregate Rate Limiting.
+ /// @param removes - A list of one or more tokens to be removed.
+ /// @param adds - A list of one or more tokens to be added.
+ function updateRateLimitTokens(
+ LocalRateLimitToken[] memory removes,
+ RateLimitTokenArgs[] memory adds
+ ) external onlyOwner {
+ for (uint256 i = 0; i < removes.length; ++i) {
+ address localToken = removes[i].localToken;
+ uint64 remoteChainSelector = removes[i].remoteChainSelector;
+
+ if (s_rateLimitedTokensLocalToRemote[remoteChainSelector].remove(localToken)) {
+ emit TokenAggregateRateLimitRemoved(remoteChainSelector, localToken);
+ }
+ }
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ LocalRateLimitToken memory localTokenArgs = adds[i].localTokenArgs;
+ bytes32 remoteToken = adds[i].remoteToken;
+ address localToken = localTokenArgs.localToken;
+
+ if (localToken == address(0) || remoteToken == bytes32("")) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ uint64 remoteChainSelector = localTokenArgs.remoteChainSelector;
+
+ if (s_rateLimitedTokensLocalToRemote[remoteChainSelector].set(localToken, remoteToken)) {
+ emit TokenAggregateRateLimitAdded(remoteChainSelector, remoteToken, localToken);
+ }
+ }
+ }
+
+ /// @return priceRegistry The configured PriceRegistry address
+ function getPriceRegistry() external view returns (address) {
+ return s_priceRegistry;
+ }
+
+ /// @notice Sets the Price Registry address
+ /// @param newPriceRegistry the address of the new PriceRegistry
+ /// @dev precondition The address must be a non-zero address
+ function setPriceRegistry(address newPriceRegistry) external onlyOwner {
+ _setPriceRegistry(newPriceRegistry);
+ }
+
+ /// @notice Sets the Price Registry address
+ /// @param newPriceRegistry the address of the new PriceRegistry
+ /// @dev precondition The address must be a non-zero address
+ function _setPriceRegistry(address newPriceRegistry) internal {
+ if (newPriceRegistry == address(0)) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ s_priceRegistry = newPriceRegistry;
+ emit PriceRegistrySet(newPriceRegistry);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/NonceManager.sol b/contracts/src/v0.8/ccip/NonceManager.sol
new file mode 100644
index 00000000000..2cfcbbe9e2b
--- /dev/null
+++ b/contracts/src/v0.8/ccip/NonceManager.sol
@@ -0,0 +1,147 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IEVM2AnyOnRamp} from "./interfaces/IEVM2AnyOnRamp.sol";
+import {INonceManager} from "./interfaces/INonceManager.sol";
+
+import {AuthorizedCallers} from "../shared/access/AuthorizedCallers.sol";
+
+/// @title NonceManager
+/// @notice NonceManager contract that manages sender nonces for the on/off ramps
+contract NonceManager is INonceManager, AuthorizedCallers {
+ error PreviousRampAlreadySet();
+
+ event PreviousRampsUpdated(uint64 indexed remoteChainSelector, PreviousRamps prevRamp);
+ event SkippedIncorrectNonce(uint64 sourceChainSelector, uint64 nonce, bytes sender);
+
+ /// @dev Struct that contains the previous on/off ramp addresses
+ struct PreviousRamps {
+ address prevOnRamp; // Previous onRamp
+ address prevOffRamp; // Previous offRamp
+ }
+
+ /// @dev Struct that contains the chain selector and the previous on/off ramps, same as PreviousRamps but with the chain selector
+ /// so that an array of these can be passed to the applyPreviousRampsUpdates function
+ struct PreviousRampsArgs {
+ uint64 remoteChainSelector; // Chain selector
+ PreviousRamps prevRamps; // Previous on/off ramps
+ }
+
+ /// @dev previous ramps
+ mapping(uint64 chainSelector => PreviousRamps previousRamps) private s_previousRamps;
+ /// @dev The current outbound nonce per sender used on the onramp
+ mapping(uint64 destChainSelector => mapping(address sender => uint64 outboundNonce)) private s_outboundNonces;
+ /// @dev The current inbound nonce per sender used on the offramp
+ /// Eventually in sync with the outbound nonce in the remote source chain NonceManager, used to enforce that messages are
+ /// executed in the same order they are sent (assuming they are DON)
+ mapping(uint64 sourceChainSelector => mapping(bytes sender => uint64 inboundNonce)) private s_inboundNonces;
+
+ constructor(address[] memory authorizedCallers) AuthorizedCallers(authorizedCallers) {}
+
+ /// @inheritdoc INonceManager
+ function getIncrementedOutboundNonce(
+ uint64 destChainSelector,
+ address sender
+ ) external onlyAuthorizedCallers returns (uint64) {
+ uint64 outboundNonce = _getOutboundNonce(destChainSelector, sender) + 1;
+ s_outboundNonces[destChainSelector][sender] = outboundNonce;
+
+ return outboundNonce;
+ }
+
+ /// @notice Returns the outbound nonce for a given sender on a given destination chain
+ /// @param destChainSelector The destination chain selector
+ /// @param sender The sender address
+ /// @return The outbound nonce
+ function getOutboundNonce(uint64 destChainSelector, address sender) external view returns (uint64) {
+ return _getOutboundNonce(destChainSelector, sender);
+ }
+
+ function _getOutboundNonce(uint64 destChainSelector, address sender) private view returns (uint64) {
+ uint64 outboundNonce = s_outboundNonces[destChainSelector][sender];
+
+ // When introducing the NonceManager with existing lanes, we still want to have sequential nonces.
+ // Referencing the old onRamp preserves sequencing between updates.
+ if (outboundNonce == 0) {
+ address prevOnRamp = s_previousRamps[destChainSelector].prevOnRamp;
+ if (prevOnRamp != address(0)) {
+ return IEVM2AnyOnRamp(prevOnRamp).getSenderNonce(sender);
+ }
+ }
+
+ return outboundNonce;
+ }
+
+ /// @inheritdoc INonceManager
+ function incrementInboundNonce(
+ uint64 sourceChainSelector,
+ uint64 expectedNonce,
+ bytes calldata sender
+ ) external onlyAuthorizedCallers returns (bool) {
+ uint64 inboundNonce = _getInboundNonce(sourceChainSelector, sender) + 1;
+
+ if (inboundNonce != expectedNonce) {
+ // If the nonce is not the expected one, this means that there are still messages in flight so we skip
+ // the nonce increment
+ emit SkippedIncorrectNonce(sourceChainSelector, expectedNonce, sender);
+ return false;
+ }
+
+ s_inboundNonces[sourceChainSelector][sender] = inboundNonce;
+
+ return true;
+ }
+
+ /// @notice Returns the inbound nonce for a given sender on a given source chain
+ /// @param sourceChainSelector The source chain selector
+ /// @param sender The encoded sender address
+ /// @return The inbound nonce
+ function getInboundNonce(uint64 sourceChainSelector, bytes calldata sender) external view returns (uint64) {
+ return _getInboundNonce(sourceChainSelector, sender);
+ }
+
+ function _getInboundNonce(uint64 sourceChainSelector, bytes calldata sender) private view returns (uint64) {
+ uint64 inboundNonce = s_inboundNonces[sourceChainSelector][sender];
+
+ // When introducing the NonceManager with existing lanes, we still want to have sequential nonces.
+ // Referencing the old offRamp to check the expected nonce if none is set for a
+ // given sender allows us to skip the current message in the current offRamp if it would not be the next according
+ // to the old offRamp. This preserves sequencing between updates.
+ if (inboundNonce == 0) {
+ address prevOffRamp = s_previousRamps[sourceChainSelector].prevOffRamp;
+ if (prevOffRamp != address(0)) {
+ // We only expect EVM previous offRamps here so we can safely decode the sender
+ return IEVM2AnyOnRamp(prevOffRamp).getSenderNonce(abi.decode(sender, (address)));
+ }
+ }
+
+ return inboundNonce;
+ }
+
+ /// @notice Updates the previous ramps addresses
+ /// @param previousRampsArgs The previous on/off ramps addresses
+ function applyPreviousRampsUpdates(PreviousRampsArgs[] calldata previousRampsArgs) external onlyOwner {
+ for (uint256 i = 0; i < previousRampsArgs.length; ++i) {
+ PreviousRampsArgs calldata previousRampsArg = previousRampsArgs[i];
+
+ PreviousRamps storage prevRamps = s_previousRamps[previousRampsArg.remoteChainSelector];
+
+ // If the previous ramps are already set then they should not be updated
+ if (prevRamps.prevOnRamp != address(0) || prevRamps.prevOffRamp != address(0)) {
+ revert PreviousRampAlreadySet();
+ }
+
+ prevRamps.prevOnRamp = previousRampsArg.prevRamps.prevOnRamp;
+ prevRamps.prevOffRamp = previousRampsArg.prevRamps.prevOffRamp;
+
+ emit PreviousRampsUpdated(previousRampsArg.remoteChainSelector, previousRampsArg.prevRamps);
+ }
+ }
+
+ /// @notice Gets the previous onRamp address for the given chain selector
+ /// @param chainSelector The chain selector
+ /// @return The previous onRamp address
+ function getPreviousRamps(uint64 chainSelector) external view returns (PreviousRamps memory) {
+ return s_previousRamps[chainSelector];
+ }
+}
diff --git a/contracts/src/v0.8/ccip/PriceRegistry.sol b/contracts/src/v0.8/ccip/PriceRegistry.sol
new file mode 100644
index 00000000000..f15232271e9
--- /dev/null
+++ b/contracts/src/v0.8/ccip/PriceRegistry.sol
@@ -0,0 +1,888 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../shared/interfaces/ITypeAndVersion.sol";
+import {IPriceRegistry} from "./interfaces/IPriceRegistry.sol";
+
+import {AuthorizedCallers} from "../shared/access/AuthorizedCallers.sol";
+import {AggregatorV3Interface} from "./../shared/interfaces/AggregatorV3Interface.sol";
+import {Client} from "./libraries/Client.sol";
+import {Internal} from "./libraries/Internal.sol";
+import {Pool} from "./libraries/Pool.sol";
+import {USDPriceWith18Decimals} from "./libraries/USDPriceWith18Decimals.sol";
+
+import {EnumerableSet} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice The PriceRegistry contract responsibility is to store the current gas price in USD for a given destination chain,
+/// and the price of a token in USD allowing the owner or priceUpdater to update this value.
+/// The authorized callers in the contract represent the fee price updaters.
+contract PriceRegistry is AuthorizedCallers, IPriceRegistry, ITypeAndVersion {
+ using EnumerableSet for EnumerableSet.AddressSet;
+ using USDPriceWith18Decimals for uint224;
+
+ /// @notice Token price data feed update
+ struct TokenPriceFeedUpdate {
+ address sourceToken; // Source token to update feed for
+ IPriceRegistry.TokenPriceFeedConfig feedConfig; // Feed config update data
+ }
+
+ /// @dev Struct that contains the static configuration
+ /// RMN depends on this struct, if changing, please notify the RMN maintainers.
+ // solhint-disable-next-line gas-struct-packing
+ struct StaticConfig {
+ uint96 maxFeeJuelsPerMsg; // ─╮ Maximum fee that can be charged for a message
+ address linkToken; // ────────╯ LINK token address
+ uint32 stalenessThreshold; // The amount of time a gas price can be stale before it is considered invalid.
+ }
+
+ error TokenNotSupported(address token);
+ error ChainNotSupported(uint64 chain);
+ error StaleGasPrice(uint64 destChainSelector, uint256 threshold, uint256 timePassed);
+ error DataFeedValueOutOfUint224Range();
+ error InvalidDestBytesOverhead(address token, uint32 destBytesOverhead);
+ error MessageGasLimitTooHigh();
+ error DestinationChainNotEnabled(uint64 destChainSelector);
+ error ExtraArgOutOfOrderExecutionMustBeTrue();
+ error InvalidExtraArgsTag();
+ error SourceTokenDataTooLarge(address token);
+ error InvalidDestChainConfig(uint64 destChainSelector);
+ error MessageFeeTooHigh(uint256 msgFeeJuels, uint256 maxFeeJuelsPerMsg);
+ error InvalidStaticConfig();
+ error MessageTooLarge(uint256 maxSize, uint256 actualSize);
+ error UnsupportedNumberOfTokens();
+
+ event PriceUpdaterSet(address indexed priceUpdater);
+ event PriceUpdaterRemoved(address indexed priceUpdater);
+ event FeeTokenAdded(address indexed feeToken);
+ event FeeTokenRemoved(address indexed feeToken);
+ event UsdPerUnitGasUpdated(uint64 indexed destChain, uint256 value, uint256 timestamp);
+ event UsdPerTokenUpdated(address indexed token, uint256 value, uint256 timestamp);
+ event PriceFeedPerTokenUpdated(address indexed token, IPriceRegistry.TokenPriceFeedConfig priceFeedConfig);
+
+ event TokenTransferFeeConfigUpdated(
+ uint64 indexed destChainSelector, address indexed token, TokenTransferFeeConfig tokenTransferFeeConfig
+ );
+ event TokenTransferFeeConfigDeleted(uint64 indexed destChainSelector, address indexed token);
+ event PremiumMultiplierWeiPerEthUpdated(address indexed token, uint64 premiumMultiplierWeiPerEth);
+ event DestChainConfigUpdated(uint64 indexed destChainSelector, DestChainConfig destChainConfig);
+ event DestChainAdded(uint64 indexed destChainSelector, DestChainConfig destChainConfig);
+
+ /// @dev Struct to hold the fee & validation configs for a destination chain
+ struct DestChainConfig {
+ bool isEnabled; // ──────────────────────────╮ Whether this destination chain is enabled
+ uint16 maxNumberOfTokensPerMsg; // │ Maximum number of distinct ERC20 token transferred per message
+ uint32 maxDataBytes; // │ Maximum payload data size in bytes
+ uint32 maxPerMsgGasLimit; // │ Maximum gas limit for messages targeting EVMs
+ uint32 destGasOverhead; // │ Gas charged on top of the gasLimit to cover destination chain costs
+ uint16 destGasPerPayloadByte; // │ Destination chain gas charged for passing each byte of `data` payload to receiver
+ uint32 destDataAvailabilityOverheadGas; // | Extra data availability gas charged on top of the message, e.g. for OCR
+ uint16 destGasPerDataAvailabilityByte; // | Amount of gas to charge per byte of message data that needs availability
+ uint16 destDataAvailabilityMultiplierBps; // │ Multiplier for data availability gas, multiples of bps, or 0.0001
+ // The following three properties are defaults, they can be overridden by setting the TokenTransferFeeConfig for a token
+ uint16 defaultTokenFeeUSDCents; // │ Default token fee charged per token transfer
+ uint32 defaultTokenDestGasOverhead; // ──────╯ Default gas charged to execute the token transfer on the destination chain
+ uint32 defaultTokenDestBytesOverhead; // ────╮ Default extra data availability bytes charged per token transfer
+ uint32 defaultTxGasLimit; // │ Default gas limit for a tx
+ uint64 gasMultiplierWeiPerEth; // │ Multiplier for gas costs, 1e18 based so 11e17 = 10% extra cost.
+ uint32 networkFeeUSDCents; // │ Flat network fee to charge for messages, multiples of 0.01 USD
+ bool enforceOutOfOrder; // │ Whether to enforce the allowOutOfOrderExecution extraArg value to be true.
+ bytes4 chainFamilySelector; // ──────────────╯ Selector that identifies the destination chain's family. Used to determine the correct validations to perform for the dest chain.
+ }
+
+ /// @dev Struct to hold the configs and its destination chain selector
+ /// Same as DestChainConfig but with the destChainSelector so that an array of these
+ /// can be passed in the constructor and the applyDestChainConfigUpdates function
+ //solhint-disable gas-struct-packing
+ struct DestChainConfigArgs {
+ uint64 destChainSelector; // Destination chain selector
+ DestChainConfig destChainConfig; // Config to update for the chain selector
+ }
+
+ /// @dev Struct to hold the transfer fee configuration for token transfers
+ struct TokenTransferFeeConfig {
+ uint32 minFeeUSDCents; // ──────────╮ Minimum fee to charge per token transfer, multiples of 0.01 USD
+ uint32 maxFeeUSDCents; // │ Maximum fee to charge per token transfer, multiples of 0.01 USD
+ uint16 deciBps; // │ Basis points charged on token transfers, multiples of 0.1bps, or 1e-5
+ uint32 destGasOverhead; // │ Gas charged to execute the token transfer on the destination chain
+ // │ Extra data availability bytes that are returned from the source pool and sent
+ uint32 destBytesOverhead; // │ to the destination pool. Must be >= Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES
+ bool isEnabled; // ─────────────────╯ Whether this token has custom transfer fees
+ }
+
+ /// @dev Struct to hold the token transfer fee configurations for a token, same as TokenTransferFeeConfig but with the token address included so
+ /// that an array of these can be passed in the TokenTransferFeeConfigArgs struct to set the mapping
+ struct TokenTransferFeeConfigSingleTokenArgs {
+ address token; // Token address
+ TokenTransferFeeConfig tokenTransferFeeConfig; // struct to hold the transfer fee configuration for token transfers
+ }
+
+ /// @dev Struct to hold the token transfer fee configurations for a destination chain and a set of tokens. Same as TokenTransferFeeConfigSingleTokenArgs
+ /// but with the destChainSelector and an array of TokenTransferFeeConfigSingleTokenArgs included so that an array of these can be passed in the constructor
+ /// and the applyTokenTransferFeeConfigUpdates function
+ struct TokenTransferFeeConfigArgs {
+ uint64 destChainSelector; // Destination chain selector
+ TokenTransferFeeConfigSingleTokenArgs[] tokenTransferFeeConfigs; // Array of token transfer fee configurations
+ }
+
+ /// @dev Struct to hold a pair of destination chain selector and token address so that an array of these can be passed in the
+ /// applyTokenTransferFeeConfigUpdates function to remove the token transfer fee configuration for a token
+ struct TokenTransferFeeConfigRemoveArgs {
+ uint64 destChainSelector; // ─╮ Destination chain selector
+ address token; // ────────────╯ Token address
+ }
+
+ /// @dev Struct to hold the fee token configuration for a token, same as the s_premiumMultiplierWeiPerEth but with
+ /// the token address included so that an array of these can be passed in the constructor and
+ /// applyPremiumMultiplierWeiPerEthUpdates to set the mapping
+ struct PremiumMultiplierWeiPerEthArgs {
+ address token; // // ───────────────────╮ Token address
+ uint64 premiumMultiplierWeiPerEth; // ──╯ Multiplier for destination chain specific premiums. Should never be 0 so can be used as an isEnabled flag
+ }
+
+ string public constant override typeAndVersion = "PriceRegistry 1.6.0-dev";
+
+ /// @dev The gas price per unit of gas for a given destination chain, in USD with 18 decimals.
+ /// Multiple gas prices can be encoded into the same value. Each price takes {Internal.GAS_PRICE_BITS} bits.
+ /// For example, if Optimism is the destination chain, gas price can include L1 base fee and L2 gas price.
+ /// Logic to parse the price components is chain-specific, and should live in OnRamp.
+ /// @dev Price of 1e18 is 1 USD. Examples:
+ /// Very Expensive: 1 unit of gas costs 1 USD -> 1e18
+ /// Expensive: 1 unit of gas costs 0.1 USD -> 1e17
+ /// Cheap: 1 unit of gas costs 0.000001 USD -> 1e12
+ mapping(uint64 destChainSelector => Internal.TimestampedPackedUint224 price) private
+ s_usdPerUnitGasByDestChainSelector;
+
+ /// @dev The price, in USD with 18 decimals, per 1e18 of the smallest token denomination.
+ /// @dev Price of 1e18 represents 1 USD per 1e18 token amount.
+ /// 1 USDC = 1.00 USD per full token, each full token is 1e6 units -> 1 * 1e18 * 1e18 / 1e6 = 1e30
+ /// 1 ETH = 2,000 USD per full token, each full token is 1e18 units -> 2000 * 1e18 * 1e18 / 1e18 = 2_000e18
+ /// 1 LINK = 5.00 USD per full token, each full token is 1e18 units -> 5 * 1e18 * 1e18 / 1e18 = 5e18
+ mapping(address token => Internal.TimestampedPackedUint224 price) private s_usdPerToken;
+
+ /// @dev Stores the price data feed configurations per token.
+ mapping(address token => IPriceRegistry.TokenPriceFeedConfig dataFeedAddress) private s_usdPriceFeedsPerToken;
+
+ /// @dev The multiplier for destination chain specific premiums that can be set by the owner or fee admin
+ /// This should never be 0 once set, so it can be used as an isEnabled flag
+ mapping(address token => uint64 premiumMultiplierWeiPerEth) internal s_premiumMultiplierWeiPerEth;
+
+ /// @dev The destination chain specific fee configs
+ mapping(uint64 destChainSelector => DestChainConfig destChainConfig) internal s_destChainConfigs;
+
+ /// @dev The token transfer fee config that can be set by the owner or fee admin
+ mapping(uint64 destChainSelector => mapping(address token => TokenTransferFeeConfig tranferFeeConfig)) internal
+ s_tokenTransferFeeConfig;
+
+ /// @dev Maximum fee that can be charged for a message. This is a guard to prevent massively overcharging due to misconfiguation.
+ uint96 internal immutable i_maxFeeJuelsPerMsg;
+ /// @dev The link token address
+ address internal immutable i_linkToken;
+
+ // Price updaters are allowed to update the prices.
+ EnumerableSet.AddressSet private s_priceUpdaters;
+ // Subset of tokens which prices tracked by this registry which are fee tokens.
+ EnumerableSet.AddressSet private s_feeTokens;
+ // The amount of time a gas price can be stale before it is considered invalid.
+ uint32 private immutable i_stalenessThreshold;
+
+ constructor(
+ StaticConfig memory staticConfig,
+ address[] memory priceUpdaters,
+ address[] memory feeTokens,
+ TokenPriceFeedUpdate[] memory tokenPriceFeeds,
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs,
+ DestChainConfigArgs[] memory destChainConfigArgs
+ ) AuthorizedCallers(priceUpdaters) {
+ if (
+ staticConfig.linkToken == address(0) || staticConfig.maxFeeJuelsPerMsg == 0
+ || staticConfig.stalenessThreshold == 0
+ ) {
+ revert InvalidStaticConfig();
+ }
+
+ i_linkToken = staticConfig.linkToken;
+ i_maxFeeJuelsPerMsg = staticConfig.maxFeeJuelsPerMsg;
+ i_stalenessThreshold = staticConfig.stalenessThreshold;
+
+ _applyFeeTokensUpdates(feeTokens, new address[](0));
+ _updateTokenPriceFeeds(tokenPriceFeeds);
+ _applyDestChainConfigUpdates(destChainConfigArgs);
+ _applyPremiumMultiplierWeiPerEthUpdates(premiumMultiplierWeiPerEthArgs);
+ _applyTokenTransferFeeConfigUpdates(tokenTransferFeeConfigArgs, new TokenTransferFeeConfigRemoveArgs[](0));
+ }
+
+ // ================================================================
+ // │ Price calculations │
+ // ================================================================
+
+ /// @inheritdoc IPriceRegistry
+ function getTokenPrice(address token) public view override returns (Internal.TimestampedPackedUint224 memory) {
+ IPriceRegistry.TokenPriceFeedConfig memory priceFeedConfig = s_usdPriceFeedsPerToken[token];
+ if (priceFeedConfig.dataFeedAddress == address(0)) {
+ return s_usdPerToken[token];
+ }
+
+ return _getTokenPriceFromDataFeed(priceFeedConfig);
+ }
+
+ /// @inheritdoc IPriceRegistry
+ function getValidatedTokenPrice(address token) external view override returns (uint224) {
+ return _getValidatedTokenPrice(token);
+ }
+
+ /// @inheritdoc IPriceRegistry
+ function getTokenPrices(address[] calldata tokens)
+ external
+ view
+ override
+ returns (Internal.TimestampedPackedUint224[] memory)
+ {
+ uint256 length = tokens.length;
+ Internal.TimestampedPackedUint224[] memory tokenPrices = new Internal.TimestampedPackedUint224[](length);
+ for (uint256 i = 0; i < length; ++i) {
+ tokenPrices[i] = getTokenPrice(tokens[i]);
+ }
+ return tokenPrices;
+ }
+
+ /// @inheritdoc IPriceRegistry
+ function getTokenPriceFeedConfig(address token)
+ external
+ view
+ override
+ returns (IPriceRegistry.TokenPriceFeedConfig memory)
+ {
+ return s_usdPriceFeedsPerToken[token];
+ }
+
+ /// @inheritdoc IPriceRegistry
+ function getDestinationChainGasPrice(uint64 destChainSelector)
+ external
+ view
+ override
+ returns (Internal.TimestampedPackedUint224 memory)
+ {
+ return s_usdPerUnitGasByDestChainSelector[destChainSelector];
+ }
+
+ /// @inheritdoc IPriceRegistry
+ function getTokenAndGasPrices(
+ address token,
+ uint64 destChainSelector
+ ) public view override returns (uint224 tokenPrice, uint224 gasPriceValue) {
+ Internal.TimestampedPackedUint224 memory gasPrice = s_usdPerUnitGasByDestChainSelector[destChainSelector];
+ // We do allow a gas price of 0, but no stale or unset gas prices
+ if (gasPrice.timestamp == 0) revert ChainNotSupported(destChainSelector);
+ uint256 timePassed = block.timestamp - gasPrice.timestamp;
+ if (timePassed > i_stalenessThreshold) revert StaleGasPrice(destChainSelector, i_stalenessThreshold, timePassed);
+
+ return (_getValidatedTokenPrice(token), gasPrice.value);
+ }
+
+ /// @inheritdoc IPriceRegistry
+ /// @dev this function assumes that no more than 1e59 dollars are sent as payment.
+ /// If more is sent, the multiplication of feeTokenAmount and feeTokenValue will overflow.
+ /// Since there isn't even close to 1e59 dollars in the world economy this is safe.
+ function convertTokenAmount(
+ address fromToken,
+ uint256 fromTokenAmount,
+ address toToken
+ ) public view override returns (uint256) {
+ /// Example:
+ /// fromTokenAmount: 1e18 // 1 ETH
+ /// ETH: 2_000e18
+ /// LINK: 5e18
+ /// return: 1e18 * 2_000e18 / 5e18 = 400e18 (400 LINK)
+ return (fromTokenAmount * _getValidatedTokenPrice(fromToken)) / _getValidatedTokenPrice(toToken);
+ }
+
+ /// @notice Gets the token price for a given token and revert if the token is not supported
+ /// @param token The address of the token to get the price for
+ /// @return the token price
+ function _getValidatedTokenPrice(address token) internal view returns (uint224) {
+ Internal.TimestampedPackedUint224 memory tokenPrice = getTokenPrice(token);
+ // Token price must be set at least once
+ if (tokenPrice.timestamp == 0 || tokenPrice.value == 0) revert TokenNotSupported(token);
+ return tokenPrice.value;
+ }
+
+ /// @notice Gets the token price from a data feed address, rebased to the same units as s_usdPerToken
+ /// @param priceFeedConfig token data feed configuration with valid data feed address (used to retrieve price & timestamp)
+ /// @return tokenPrice data feed price answer rebased to s_usdPerToken units, with latest block timestamp
+ function _getTokenPriceFromDataFeed(IPriceRegistry.TokenPriceFeedConfig memory priceFeedConfig)
+ internal
+ view
+ returns (Internal.TimestampedPackedUint224 memory tokenPrice)
+ {
+ AggregatorV3Interface dataFeedContract = AggregatorV3Interface(priceFeedConfig.dataFeedAddress);
+ (
+ /* uint80 roundID */
+ ,
+ int256 dataFeedAnswer,
+ /* uint startedAt */
+ ,
+ /* uint256 updatedAt */
+ ,
+ /* uint80 answeredInRound */
+ ) = dataFeedContract.latestRoundData();
+
+ if (dataFeedAnswer < 0) {
+ revert DataFeedValueOutOfUint224Range();
+ }
+ uint256 rebasedValue = uint256(dataFeedAnswer);
+
+ // Rebase formula for units in smallest token denomination: usdValue * (1e18 * 1e18) / 1eTokenDecimals
+ // feedValue * (10 ** (18 - feedDecimals)) * (10 ** (18 - erc20Decimals))
+ // feedValue * (10 ** ((18 - feedDecimals) + (18 - erc20Decimals)))
+ // feedValue * (10 ** (36 - feedDecimals - erc20Decimals))
+ // feedValue * (10 ** (36 - (feedDecimals + erc20Decimals)))
+ // feedValue * (10 ** (36 - excessDecimals))
+ // If excessDecimals > 36 => flip it to feedValue / (10 ** (excessDecimals - 36))
+
+ uint8 excessDecimals = dataFeedContract.decimals() + priceFeedConfig.tokenDecimals;
+
+ if (excessDecimals > 36) {
+ rebasedValue /= 10 ** (excessDecimals - 36);
+ } else {
+ rebasedValue *= 10 ** (36 - excessDecimals);
+ }
+
+ if (rebasedValue > type(uint224).max) {
+ revert DataFeedValueOutOfUint224Range();
+ }
+
+ // Data feed staleness is unchecked to decouple the PriceRegistry from data feed delay issues
+ return Internal.TimestampedPackedUint224({value: uint224(rebasedValue), timestamp: uint32(block.timestamp)});
+ }
+
+ // ================================================================
+ // │ Fee tokens │
+ // ================================================================
+
+ /// @inheritdoc IPriceRegistry
+ function getFeeTokens() external view returns (address[] memory) {
+ return s_feeTokens.values();
+ }
+
+ /// @notice Add and remove tokens from feeTokens set.
+ /// @param feeTokensToAdd The addresses of the tokens which are now considered fee tokens
+ /// and can be used to calculate fees.
+ /// @param feeTokensToRemove The addresses of the tokens which are no longer considered feeTokens.
+ function applyFeeTokensUpdates(
+ address[] memory feeTokensToAdd,
+ address[] memory feeTokensToRemove
+ ) external onlyOwner {
+ _applyFeeTokensUpdates(feeTokensToAdd, feeTokensToRemove);
+ }
+
+ /// @notice Add and remove tokens from feeTokens set.
+ /// @param feeTokensToAdd The addresses of the tokens which are now considered fee tokens
+ /// and can be used to calculate fees.
+ /// @param feeTokensToRemove The addresses of the tokens which are no longer considered feeTokens.
+ function _applyFeeTokensUpdates(address[] memory feeTokensToAdd, address[] memory feeTokensToRemove) private {
+ for (uint256 i = 0; i < feeTokensToAdd.length; ++i) {
+ if (s_feeTokens.add(feeTokensToAdd[i])) {
+ emit FeeTokenAdded(feeTokensToAdd[i]);
+ }
+ }
+ for (uint256 i = 0; i < feeTokensToRemove.length; ++i) {
+ if (s_feeTokens.remove(feeTokensToRemove[i])) {
+ emit FeeTokenRemoved(feeTokensToRemove[i]);
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Price updates │
+ // ================================================================
+
+ /// @inheritdoc IPriceRegistry
+ function updatePrices(Internal.PriceUpdates calldata priceUpdates) external override {
+ // The caller must be the fee updater
+ _validateCaller();
+
+ uint256 tokenUpdatesLength = priceUpdates.tokenPriceUpdates.length;
+
+ for (uint256 i = 0; i < tokenUpdatesLength; ++i) {
+ Internal.TokenPriceUpdate memory update = priceUpdates.tokenPriceUpdates[i];
+ s_usdPerToken[update.sourceToken] =
+ Internal.TimestampedPackedUint224({value: update.usdPerToken, timestamp: uint32(block.timestamp)});
+ emit UsdPerTokenUpdated(update.sourceToken, update.usdPerToken, block.timestamp);
+ }
+
+ uint256 gasUpdatesLength = priceUpdates.gasPriceUpdates.length;
+
+ for (uint256 i = 0; i < gasUpdatesLength; ++i) {
+ Internal.GasPriceUpdate memory update = priceUpdates.gasPriceUpdates[i];
+ s_usdPerUnitGasByDestChainSelector[update.destChainSelector] =
+ Internal.TimestampedPackedUint224({value: update.usdPerUnitGas, timestamp: uint32(block.timestamp)});
+ emit UsdPerUnitGasUpdated(update.destChainSelector, update.usdPerUnitGas, block.timestamp);
+ }
+ }
+
+ /// @notice Updates the USD token price feeds for given tokens
+ /// @param tokenPriceFeedUpdates Token price feed updates to apply
+ function updateTokenPriceFeeds(TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates) external onlyOwner {
+ _updateTokenPriceFeeds(tokenPriceFeedUpdates);
+ }
+
+ /// @notice Updates the USD token price feeds for given tokens
+ /// @param tokenPriceFeedUpdates Token price feed updates to apply
+ function _updateTokenPriceFeeds(TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates) private {
+ for (uint256 i; i < tokenPriceFeedUpdates.length; ++i) {
+ TokenPriceFeedUpdate memory update = tokenPriceFeedUpdates[i];
+ address sourceToken = update.sourceToken;
+ IPriceRegistry.TokenPriceFeedConfig memory tokenPriceFeedConfig = update.feedConfig;
+
+ s_usdPriceFeedsPerToken[sourceToken] = tokenPriceFeedConfig;
+ emit PriceFeedPerTokenUpdated(sourceToken, tokenPriceFeedConfig);
+ }
+ }
+
+ // ================================================================
+ // │ Fee quoting │
+ // ================================================================
+
+ /// @inheritdoc IPriceRegistry
+ /// @dev The function should always validate message.extraArgs, message.receiver and family-specific configs
+ function getValidatedFee(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external view returns (uint256 feeTokenAmount) {
+ DestChainConfig memory destChainConfig = s_destChainConfigs[destChainSelector];
+ if (!destChainConfig.isEnabled) revert DestinationChainNotEnabled(destChainSelector);
+
+ uint256 numberOfTokens = message.tokenAmounts.length;
+ _validateMessage(destChainConfig, message.data.length, numberOfTokens, message.receiver);
+
+ uint64 premiumMultiplierWeiPerEth = s_premiumMultiplierWeiPerEth[message.feeToken];
+
+ // The below call asserts that feeToken is a supported token
+ (uint224 feeTokenPrice, uint224 packedGasPrice) = getTokenAndGasPrices(message.feeToken, destChainSelector);
+
+ // Calculate premiumFee in USD with 18 decimals precision first.
+ // If message-only and no token transfers, a flat network fee is charged.
+ // If there are token transfers, premiumFee is calculated from token transfer fee.
+ // If there are both token transfers and message, premiumFee is only calculated from token transfer fee.
+ uint256 premiumFee = 0;
+ uint32 tokenTransferGas = 0;
+ uint32 tokenTransferBytesOverhead = 0;
+ if (numberOfTokens > 0) {
+ (premiumFee, tokenTransferGas, tokenTransferBytesOverhead) =
+ _getTokenTransferCost(destChainConfig, destChainSelector, message.feeToken, feeTokenPrice, message.tokenAmounts);
+ } else {
+ // Convert USD cents with 2 decimals to 18 decimals.
+ premiumFee = uint256(destChainConfig.networkFeeUSDCents) * 1e16;
+ }
+
+ // Calculate data availability cost in USD with 36 decimals. Data availability cost exists on rollups that need to post
+ // transaction calldata onto another storage layer, e.g. Eth mainnet, incurring additional storage gas costs.
+ uint256 dataAvailabilityCost = 0;
+
+ // Only calculate data availability cost if data availability multiplier is non-zero.
+ // The multiplier should be set to 0 if destination chain does not charge data availability cost.
+ if (destChainConfig.destDataAvailabilityMultiplierBps > 0) {
+ dataAvailabilityCost = _getDataAvailabilityCost(
+ destChainConfig,
+ // Parse the data availability gas price stored in the higher-order 112 bits of the encoded gas price.
+ uint112(packedGasPrice >> Internal.GAS_PRICE_BITS),
+ message.data.length,
+ numberOfTokens,
+ tokenTransferBytesOverhead
+ );
+ }
+
+ // Calculate execution gas fee on destination chain in USD with 36 decimals.
+ // We add the message gas limit, the overhead gas, the gas of passing message data to receiver, and token transfer gas together.
+ // We then multiply this gas total with the gas multiplier and gas price, converting it into USD with 36 decimals.
+ // uint112(packedGasPrice) = executionGasPrice
+
+ // NOTE: when supporting non-EVM chains, revisit how generic this fee logic can be
+ // NOTE: revisit parsing non-EVM args
+
+ uint256 executionCost = uint112(packedGasPrice)
+ * (
+ destChainConfig.destGasOverhead + (message.data.length * destChainConfig.destGasPerPayloadByte) + tokenTransferGas
+ + _parseEVMExtraArgsFromBytes(message.extraArgs, destChainConfig).gasLimit
+ ) * destChainConfig.gasMultiplierWeiPerEth;
+
+ // Calculate number of fee tokens to charge.
+ // Total USD fee is in 36 decimals, feeTokenPrice is in 18 decimals USD for 1e18 smallest token denominations.
+ // Result of the division is the number of smallest token denominations.
+ return ((premiumFee * premiumMultiplierWeiPerEth) + executionCost + dataAvailabilityCost) / feeTokenPrice;
+ }
+
+ /// @notice Sets the fee configuration for a token
+ /// @param premiumMultiplierWeiPerEthArgs Array of PremiumMultiplierWeiPerEthArgs structs.
+ function applyPremiumMultiplierWeiPerEthUpdates(
+ PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs
+ ) external onlyOwner {
+ _applyPremiumMultiplierWeiPerEthUpdates(premiumMultiplierWeiPerEthArgs);
+ }
+
+ /// @dev Set the fee config.
+ /// @param premiumMultiplierWeiPerEthArgs The multiplier for destination chain specific premiums.
+ function _applyPremiumMultiplierWeiPerEthUpdates(
+ PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs
+ ) internal {
+ for (uint256 i = 0; i < premiumMultiplierWeiPerEthArgs.length; ++i) {
+ address token = premiumMultiplierWeiPerEthArgs[i].token;
+ uint64 premiumMultiplierWeiPerEth = premiumMultiplierWeiPerEthArgs[i].premiumMultiplierWeiPerEth;
+ s_premiumMultiplierWeiPerEth[token] = premiumMultiplierWeiPerEth;
+
+ emit PremiumMultiplierWeiPerEthUpdated(token, premiumMultiplierWeiPerEth);
+ }
+ }
+
+ /// @notice Gets the fee configuration for a token.
+ /// @param token The token to get the fee configuration for.
+ /// @return premiumMultiplierWeiPerEth The multiplier for destination chain specific premiums.
+ function getPremiumMultiplierWeiPerEth(address token) external view returns (uint64 premiumMultiplierWeiPerEth) {
+ return s_premiumMultiplierWeiPerEth[token];
+ }
+
+ /// @notice Returns the token transfer cost parameters.
+ /// A basis point fee is calculated from the USD value of each token transfer.
+ /// For each individual transfer, this fee is between [minFeeUSD, maxFeeUSD].
+ /// Total transfer fee is the sum of each individual token transfer fee.
+ /// @dev Assumes that tokenAmounts are validated to be listed tokens elsewhere.
+ /// @dev Splitting one token transfer into multiple transfers is discouraged,
+ /// as it will result in a transferFee equal or greater than the same amount aggregated/de-duped.
+ /// @param destChainConfig the config configured for the destination chain selector.
+ /// @param destChainSelector the destination chain selector.
+ /// @param feeToken address of the feeToken.
+ /// @param feeTokenPrice price of feeToken in USD with 18 decimals.
+ /// @param tokenAmounts token transfers in the message.
+ /// @return tokenTransferFeeUSDWei total token transfer bps fee in USD with 18 decimals.
+ /// @return tokenTransferGas total execution gas of the token transfers.
+ /// @return tokenTransferBytesOverhead additional token transfer data passed to destination, e.g. USDC attestation.
+ function _getTokenTransferCost(
+ DestChainConfig memory destChainConfig,
+ uint64 destChainSelector,
+ address feeToken,
+ uint224 feeTokenPrice,
+ Client.EVMTokenAmount[] calldata tokenAmounts
+ ) internal view returns (uint256 tokenTransferFeeUSDWei, uint32 tokenTransferGas, uint32 tokenTransferBytesOverhead) {
+ uint256 numberOfTokens = tokenAmounts.length;
+
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ Client.EVMTokenAmount memory tokenAmount = tokenAmounts[i];
+ TokenTransferFeeConfig memory transferFeeConfig = s_tokenTransferFeeConfig[destChainSelector][tokenAmount.token];
+
+ // If the token has no specific overrides configured, we use the global defaults.
+ if (!transferFeeConfig.isEnabled) {
+ tokenTransferFeeUSDWei += uint256(destChainConfig.defaultTokenFeeUSDCents) * 1e16;
+ tokenTransferGas += destChainConfig.defaultTokenDestGasOverhead;
+ tokenTransferBytesOverhead += destChainConfig.defaultTokenDestBytesOverhead;
+ continue;
+ }
+
+ uint256 bpsFeeUSDWei = 0;
+ // Only calculate bps fee if ratio is greater than 0. Ratio of 0 means no bps fee for a token.
+ // Useful for when the PriceRegistry cannot return a valid price for the token.
+ if (transferFeeConfig.deciBps > 0) {
+ uint224 tokenPrice = 0;
+ if (tokenAmount.token != feeToken) {
+ tokenPrice = _getValidatedTokenPrice(tokenAmount.token);
+ } else {
+ tokenPrice = feeTokenPrice;
+ }
+
+ // Calculate token transfer value, then apply fee ratio
+ // ratio represents multiples of 0.1bps, or 1e-5
+ bpsFeeUSDWei = (tokenPrice._calcUSDValueFromTokenAmount(tokenAmount.amount) * transferFeeConfig.deciBps) / 1e5;
+ }
+
+ tokenTransferGas += transferFeeConfig.destGasOverhead;
+ tokenTransferBytesOverhead += transferFeeConfig.destBytesOverhead;
+
+ // Bps fees should be kept within range of [minFeeUSD, maxFeeUSD].
+ // Convert USD values with 2 decimals to 18 decimals.
+ uint256 minFeeUSDWei = uint256(transferFeeConfig.minFeeUSDCents) * 1e16;
+ if (bpsFeeUSDWei < minFeeUSDWei) {
+ tokenTransferFeeUSDWei += minFeeUSDWei;
+ continue;
+ }
+
+ uint256 maxFeeUSDWei = uint256(transferFeeConfig.maxFeeUSDCents) * 1e16;
+ if (bpsFeeUSDWei > maxFeeUSDWei) {
+ tokenTransferFeeUSDWei += maxFeeUSDWei;
+ continue;
+ }
+
+ tokenTransferFeeUSDWei += bpsFeeUSDWei;
+ }
+
+ return (tokenTransferFeeUSDWei, tokenTransferGas, tokenTransferBytesOverhead);
+ }
+
+ /// @notice Returns the estimated data availability cost of the message.
+ /// @dev To save on gas, we use a single destGasPerDataAvailabilityByte value for both zero and non-zero bytes.
+ /// @param destChainConfig the config configured for the destination chain selector.
+ /// @param dataAvailabilityGasPrice USD per data availability gas in 18 decimals.
+ /// @param messageDataLength length of the data field in the message.
+ /// @param numberOfTokens number of distinct token transfers in the message.
+ /// @param tokenTransferBytesOverhead additional token transfer data passed to destination, e.g. USDC attestation.
+ /// @return dataAvailabilityCostUSD36Decimal total data availability cost in USD with 36 decimals.
+ function _getDataAvailabilityCost(
+ DestChainConfig memory destChainConfig,
+ uint112 dataAvailabilityGasPrice,
+ uint256 messageDataLength,
+ uint256 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) internal pure returns (uint256 dataAvailabilityCostUSD36Decimal) {
+ // dataAvailabilityLengthBytes sums up byte lengths of fixed message fields and dynamic message fields.
+ // Fixed message fields do account for the offset and length slot of the dynamic fields.
+ uint256 dataAvailabilityLengthBytes = Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES + messageDataLength
+ + (numberOfTokens * Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES_PER_TOKEN) + tokenTransferBytesOverhead;
+
+ // destDataAvailabilityOverheadGas is a separate config value for flexibility to be updated independently of message cost.
+ // Its value is determined by CCIP lane implementation, e.g. the overhead data posted for OCR.
+ uint256 dataAvailabilityGas = (dataAvailabilityLengthBytes * destChainConfig.destGasPerDataAvailabilityByte)
+ + destChainConfig.destDataAvailabilityOverheadGas;
+
+ // dataAvailabilityGasPrice is in 18 decimals, destDataAvailabilityMultiplierBps is in 4 decimals
+ // We pad 14 decimals to bring the result to 36 decimals, in line with token bps and execution fee.
+ return ((dataAvailabilityGas * dataAvailabilityGasPrice) * destChainConfig.destDataAvailabilityMultiplierBps) * 1e14;
+ }
+
+ /// @notice Gets the transfer fee config for a given token.
+ /// @param destChainSelector The destination chain selector.
+ /// @param token The token address.
+ function getTokenTransferFeeConfig(
+ uint64 destChainSelector,
+ address token
+ ) external view returns (TokenTransferFeeConfig memory tokenTransferFeeConfig) {
+ return s_tokenTransferFeeConfig[destChainSelector][token];
+ }
+
+ /// @notice Sets the transfer fee config.
+ /// @dev only callable by the owner or admin.
+ function applyTokenTransferFeeConfigUpdates(
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ TokenTransferFeeConfigRemoveArgs[] memory tokensToUseDefaultFeeConfigs
+ ) external onlyOwner {
+ _applyTokenTransferFeeConfigUpdates(tokenTransferFeeConfigArgs, tokensToUseDefaultFeeConfigs);
+ }
+
+ /// @notice internal helper to set the token transfer fee config.
+ function _applyTokenTransferFeeConfigUpdates(
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ TokenTransferFeeConfigRemoveArgs[] memory tokensToUseDefaultFeeConfigs
+ ) internal {
+ for (uint256 i = 0; i < tokenTransferFeeConfigArgs.length; ++i) {
+ TokenTransferFeeConfigArgs memory tokenTransferFeeConfigArg = tokenTransferFeeConfigArgs[i];
+ uint64 destChainSelector = tokenTransferFeeConfigArg.destChainSelector;
+
+ for (uint256 j = 0; j < tokenTransferFeeConfigArg.tokenTransferFeeConfigs.length; ++j) {
+ TokenTransferFeeConfig memory tokenTransferFeeConfig =
+ tokenTransferFeeConfigArg.tokenTransferFeeConfigs[j].tokenTransferFeeConfig;
+ address token = tokenTransferFeeConfigArg.tokenTransferFeeConfigs[j].token;
+
+ if (tokenTransferFeeConfig.destBytesOverhead < Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) {
+ revert InvalidDestBytesOverhead(token, tokenTransferFeeConfig.destBytesOverhead);
+ }
+
+ s_tokenTransferFeeConfig[destChainSelector][token] = tokenTransferFeeConfig;
+
+ emit TokenTransferFeeConfigUpdated(destChainSelector, token, tokenTransferFeeConfig);
+ }
+ }
+
+ // Remove the custom fee configs for the tokens that are in the tokensToUseDefaultFeeConfigs array
+ for (uint256 i = 0; i < tokensToUseDefaultFeeConfigs.length; ++i) {
+ uint64 destChainSelector = tokensToUseDefaultFeeConfigs[i].destChainSelector;
+ address token = tokensToUseDefaultFeeConfigs[i].token;
+ delete s_tokenTransferFeeConfig[destChainSelector][token];
+ emit TokenTransferFeeConfigDeleted(destChainSelector, token);
+ }
+ }
+
+ // ================================================================
+ // │ Validations & message processing │
+ // ================================================================
+
+ /// @notice Validates that the destAddress matches the expected format of the family.
+ /// @param chainFamilySelector Tag to identify the target family
+ /// @param destAddress Dest address to validate
+ /// @dev precondition - assumes the family tag is correct and validated
+ function _validateDestFamilyAddress(bytes4 chainFamilySelector, bytes memory destAddress) internal pure {
+ if (chainFamilySelector == Internal.CHAIN_FAMILY_SELECTOR_EVM) {
+ Internal._validateEVMAddress(destAddress);
+ }
+ }
+
+ /// @dev Convert the extra args bytes into a struct with validations against the dest chain config
+ /// @param extraArgs The extra args bytes
+ /// @param destChainConfig Dest chain config to validate against
+ /// @return EVMExtraArgs the extra args struct (latest version)
+ function _parseEVMExtraArgsFromBytes(
+ bytes calldata extraArgs,
+ DestChainConfig memory destChainConfig
+ ) internal pure returns (Client.EVMExtraArgsV2 memory) {
+ Client.EVMExtraArgsV2 memory evmExtraArgs =
+ _parseUnvalidatedEVMExtraArgsFromBytes(extraArgs, destChainConfig.defaultTxGasLimit);
+
+ if (evmExtraArgs.gasLimit > uint256(destChainConfig.maxPerMsgGasLimit)) revert MessageGasLimitTooHigh();
+ if (destChainConfig.enforceOutOfOrder && !evmExtraArgs.allowOutOfOrderExecution) {
+ revert ExtraArgOutOfOrderExecutionMustBeTrue();
+ }
+
+ return evmExtraArgs;
+ }
+
+ /// @dev Convert the extra args bytes into a struct
+ /// @param extraArgs The extra args bytes
+ /// @param defaultTxGasLimit default tx gas limit to use in the absence of extra args
+ /// @return EVMExtraArgs the extra args struct (latest version)
+ function _parseUnvalidatedEVMExtraArgsFromBytes(
+ bytes calldata extraArgs,
+ uint64 defaultTxGasLimit
+ ) private pure returns (Client.EVMExtraArgsV2 memory) {
+ if (extraArgs.length == 0) {
+ // If extra args are empty, generate default values
+ return Client.EVMExtraArgsV2({gasLimit: defaultTxGasLimit, allowOutOfOrderExecution: false});
+ }
+
+ bytes4 extraArgsTag = bytes4(extraArgs);
+ bytes memory argsData = extraArgs[4:];
+
+ if (extraArgsTag == Client.EVM_EXTRA_ARGS_V2_TAG) {
+ return abi.decode(argsData, (Client.EVMExtraArgsV2));
+ } else if (extraArgsTag == Client.EVM_EXTRA_ARGS_V1_TAG) {
+ // EVMExtraArgsV1 originally included a second boolean (strict) field which has been deprecated.
+ // Clients may still include it but it will be ignored.
+ return Client.EVMExtraArgsV2({gasLimit: abi.decode(argsData, (uint256)), allowOutOfOrderExecution: false});
+ }
+
+ revert InvalidExtraArgsTag();
+ }
+
+ /// @notice Validate the forwarded message to ensure it matches the configuration limits (message length, number of tokens)
+ /// and family-specific expectations (address format)
+ /// @param destChainConfig Dest chain config
+ /// @param dataLength The length of the data field of the message.
+ /// @param numberOfTokens The number of tokens to be sent.
+ /// @param receiver Message receiver on the dest chain
+ function _validateMessage(
+ DestChainConfig memory destChainConfig,
+ uint256 dataLength,
+ uint256 numberOfTokens,
+ bytes memory receiver
+ ) internal pure {
+ // Check that payload is formed correctly
+ if (dataLength > uint256(destChainConfig.maxDataBytes)) {
+ revert MessageTooLarge(uint256(destChainConfig.maxDataBytes), dataLength);
+ }
+ if (numberOfTokens > uint256(destChainConfig.maxNumberOfTokensPerMsg)) revert UnsupportedNumberOfTokens();
+ _validateDestFamilyAddress(destChainConfig.chainFamilySelector, receiver);
+ }
+
+ /// @inheritdoc IPriceRegistry
+ function processMessageArgs(
+ uint64 destChainSelector,
+ address feeToken,
+ uint256 feeTokenAmount,
+ bytes calldata extraArgs
+ ) external view returns (uint256 msgFeeJuels, bool isOutOfOrderExecution, bytes memory convertedExtraArgs) {
+ // Convert feeToken to link if not already in link
+ if (feeToken == i_linkToken) {
+ msgFeeJuels = feeTokenAmount;
+ } else {
+ msgFeeJuels = convertTokenAmount(feeToken, feeTokenAmount, i_linkToken);
+ }
+
+ if (msgFeeJuels > i_maxFeeJuelsPerMsg) revert MessageFeeTooHigh(msgFeeJuels, i_maxFeeJuelsPerMsg);
+
+ uint64 defaultTxGasLimit = s_destChainConfigs[destChainSelector].defaultTxGasLimit;
+ // NOTE: when supporting non-EVM chains, revisit this and parse non-EVM args.
+ // We can parse unvalidated args since this message is called after getFee (which will already validate the params)
+ Client.EVMExtraArgsV2 memory parsedExtraArgs = _parseUnvalidatedEVMExtraArgsFromBytes(extraArgs, defaultTxGasLimit);
+ isOutOfOrderExecution = parsedExtraArgs.allowOutOfOrderExecution;
+
+ return (msgFeeJuels, isOutOfOrderExecution, Client._argsToBytes(parsedExtraArgs));
+ }
+
+ /// @inheritdoc IPriceRegistry
+ /// @dev precondition - rampTokenAmounts and sourceTokenAmounts lengths must be equal
+ function validatePoolReturnData(
+ uint64 destChainSelector,
+ Internal.RampTokenAmount[] calldata rampTokenAmounts,
+ Client.EVMTokenAmount[] calldata sourceTokenAmounts
+ ) external view {
+ bytes4 chainFamilySelector = s_destChainConfigs[destChainSelector].chainFamilySelector;
+
+ for (uint256 i = 0; i < rampTokenAmounts.length; ++i) {
+ address sourceToken = sourceTokenAmounts[i].token;
+
+ // Since the DON has to pay for the extraData to be included on the destination chain, we cap the length of the
+ // extraData. This prevents gas bomb attacks on the NOPs. As destBytesOverhead accounts for both
+ // extraData and offchainData, this caps the worst case abuse to the number of bytes reserved for offchainData.
+ uint256 destPoolDataLength = rampTokenAmounts[i].extraData.length;
+ if (destPoolDataLength > Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) {
+ if (destPoolDataLength > s_tokenTransferFeeConfig[destChainSelector][sourceToken].destBytesOverhead) {
+ revert SourceTokenDataTooLarge(sourceToken);
+ }
+ }
+
+ _validateDestFamilyAddress(chainFamilySelector, rampTokenAmounts[i].destTokenAddress);
+ }
+ }
+
+ // ================================================================
+ // │ Configs │
+ // ================================================================
+
+ /// @notice Returns the configured config for the dest chain selector
+ /// @param destChainSelector destination chain selector to fetch config for
+ /// @return destChainConfig config for the dest chain
+ function getDestChainConfig(uint64 destChainSelector) external view returns (DestChainConfig memory) {
+ return s_destChainConfigs[destChainSelector];
+ }
+
+ /// @notice Updates the destination chain specific config.
+ /// @param destChainConfigArgs Array of source chain specific configs.
+ function applyDestChainConfigUpdates(DestChainConfigArgs[] memory destChainConfigArgs) external onlyOwner {
+ _applyDestChainConfigUpdates(destChainConfigArgs);
+ }
+
+ /// @notice Internal version of applyDestChainConfigUpdates.
+ function _applyDestChainConfigUpdates(DestChainConfigArgs[] memory destChainConfigArgs) internal {
+ for (uint256 i = 0; i < destChainConfigArgs.length; ++i) {
+ DestChainConfigArgs memory destChainConfigArg = destChainConfigArgs[i];
+ uint64 destChainSelector = destChainConfigArgs[i].destChainSelector;
+ DestChainConfig memory destChainConfig = destChainConfigArg.destChainConfig;
+
+ // NOTE: when supporting non-EVM chains, update chainFamilySelector validations
+ if (
+ destChainSelector == 0 || destChainConfig.defaultTxGasLimit == 0
+ || destChainConfig.chainFamilySelector != Internal.CHAIN_FAMILY_SELECTOR_EVM
+ || destChainConfig.defaultTokenDestBytesOverhead < Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES
+ || destChainConfig.defaultTxGasLimit > destChainConfig.maxPerMsgGasLimit
+ ) {
+ revert InvalidDestChainConfig(destChainSelector);
+ }
+
+ // The chain family selector cannot be zero - indicates that it is a new chain
+ if (s_destChainConfigs[destChainSelector].chainFamilySelector == 0) {
+ emit DestChainAdded(destChainSelector, destChainConfig);
+ } else {
+ emit DestChainConfigUpdated(destChainSelector, destChainConfig);
+ }
+
+ s_destChainConfigs[destChainSelector] = destChainConfig;
+ }
+ }
+
+ /// @notice Returns the static PriceRegistry config.
+ /// @dev RMN depends on this function, if changing, please notify the RMN maintainers.
+ /// @return the configuration.
+ function getStaticConfig() external view returns (StaticConfig memory) {
+ return StaticConfig({
+ maxFeeJuelsPerMsg: i_maxFeeJuelsPerMsg,
+ linkToken: i_linkToken,
+ stalenessThreshold: i_stalenessThreshold
+ });
+ }
+}
diff --git a/contracts/src/v0.8/ccip/RMN.sol b/contracts/src/v0.8/ccip/RMN.sol
new file mode 100644
index 00000000000..424aad8fa57
--- /dev/null
+++ b/contracts/src/v0.8/ccip/RMN.sol
@@ -0,0 +1,964 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../shared/interfaces/ITypeAndVersion.sol";
+import {IRMN} from "./interfaces/IRMN.sol";
+
+import {OwnerIsCreator} from "./../shared/access/OwnerIsCreator.sol";
+
+import {EnumerableSet} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+// An active curse on this subject will cause isCursed() to return true. Use this subject if there is an issue with a
+// remote chain, for which there exists a legacy lane contract deployed on the same chain as this RMN contract is
+// deployed, relying on isCursed().
+bytes16 constant LEGACY_CURSE_SUBJECT = 0x01000000000000000000000000000000;
+
+// An active curse on this subject will cause isCursed() and isCursed(bytes32) to return true. Use this subject for
+// issues affecting all of CCIP chains, or pertaining to the chain that this contract is deployed on, instead of using
+// the local chain selector as a subject.
+bytes16 constant GLOBAL_CURSE_SUBJECT = 0x01000000000000000000000000000001;
+
+// The curse vote address representing the owner in data structures, events and recorded votes. Remains constant, even
+// if the owner changes.
+address constant OWNER_CURSE_VOTE_ADDR = address(~uint160(0)); // 0xff...ff
+
+// The curse vote address used in an OwnerUnvoteToCurseRequest to lift a curse, if there is no active curse votes for
+// the subject that we are able to unvote, but the conditions for an active curse no longer hold.
+address constant LIFT_CURSE_VOTE_ADDR = address(0);
+
+/// @dev This contract is owned by RMN, if changing, please notify the RMN maintainers.
+// solhint-disable chainlink-solidity/explicit-returns
+contract RMN is IRMN, OwnerIsCreator, ITypeAndVersion {
+ using EnumerableSet for EnumerableSet.AddressSet;
+
+ // STATIC CONFIG
+ string public constant override typeAndVersion = "RMN 1.5.0-dev";
+
+ uint256 private constant MAX_NUM_VOTERS = 16;
+
+ // MAGIC VALUES
+ bytes28 private constant NO_VOTES_CURSES_HASH = bytes28(0);
+
+ // DYNAMIC CONFIG
+ /// @notice blessVoteAddr and curseVoteAddr can't be 0. Additionally curseVoteAddr can't be LIFT_CURSE_VOTE_ADDR or
+ /// OWNER_CURSE_VOTE_ADDR. At least one of blessWeight & curseWeight must be non-zero, i.e., a voter could only vote
+ /// to bless, or only vote to curse, or both vote to bless and vote to curse.
+ struct Voter {
+ // This is the address the voter should use to call voteToBless.
+ address blessVoteAddr;
+ // This is the address the voter should use to call voteToCurse.
+ address curseVoteAddr;
+ // The weight of this voter's vote for blessing.
+ uint8 blessWeight;
+ // The weight of this voter's vote for cursing.
+ uint8 curseWeight;
+ }
+
+ struct Config {
+ Voter[] voters;
+ // When the total weight of voters that have voted to bless a tagged root reaches
+ // or exceeds blessWeightThreshold, the tagged root becomes blessed.
+ uint16 blessWeightThreshold;
+ // When the total weight of voters that have voted to curse a subject reaches or
+ // exceeds curseWeightThreshold, the subject becomes cursed.
+ uint16 curseWeightThreshold;
+ }
+
+ struct VersionedConfig {
+ Config config;
+ // The version is incremented every time the config changes.
+ // The initial configuration on the contract will have configVersion == 1.
+ uint32 configVersion;
+ // The block number at which the config was last set. Helps the offchain
+ // code check that the config was set in a stable block or double-check
+ // that it has the correct config by querying logs at that block number.
+ uint32 blockNumber;
+ }
+
+ VersionedConfig private s_versionedConfig;
+
+ // STATE
+ struct BlesserRecord {
+ // The config version at which this BlesserRecord was last set. A blesser
+ // is considered active iff this configVersion equals
+ // s_versionedConfig.configVersion.
+ uint32 configVersion;
+ uint8 weight;
+ uint8 index;
+ }
+
+ mapping(address blessVoteAddr => BlesserRecord blesserRecord) private s_blesserRecords;
+
+ struct BlessVoteProgress {
+ // This particular ordering saves us ~400 gas per voteToBless call, compared to the bool being at the bottom, even
+ // though the size of the struct is the same.
+ bool weightThresholdMet;
+ // A BlessVoteProgress is considered invalid if weightThresholdMet is false when
+ // s_versionedConfig.configVersion changes. we don't want old in-progress
+ // votes to continue when we set a new config!
+ // The config version at which the bless vote for a tagged root was initiated.
+ uint32 configVersion;
+ uint16 accumulatedWeight;
+ // Care must be taken that the bitmap has at least as many bits as MAX_NUM_VOTERS.
+ // uint200 is much larger than we need, but it saves us ~100 gas per voteToBless call to fill the word instead of
+ // using a smaller type.
+ // _bitmapGet(voterBitmap, i) = true indicates that the i-th voter has voted to bless
+ uint200 voterBitmap;
+ }
+
+ mapping(bytes32 taggedRootHash => BlessVoteProgress blessVoteProgress) private s_blessVoteProgressByTaggedRootHash;
+
+ // Any tagged root with a commit store included in s_permaBlessedCommitStores will be considered automatically
+ // blessed.
+ EnumerableSet.AddressSet private s_permaBlessedCommitStores;
+
+ struct CurserRecord {
+ bool active;
+ uint8 weight;
+ mapping(bytes16 curseId => bool used) usedCurseIds; // retained across config changes
+ }
+
+ mapping(address curseVoteAddr => CurserRecord curserRecord) private s_curserRecords;
+
+ struct ConfigVersionAndCursesHash {
+ uint32 configVersion; // configVersion != s_versionedConfig.configVersion means no active vote
+ bytes28 cursesHash; // bytes28(0) means no active vote; truncated so that ConfigVersionAndCursesHash fits in a word
+ }
+
+ struct CurseVoteProgress {
+ uint32 configVersion; // upon config change, lazy set to new config version
+ uint16 curseWeightThreshold; // upon config change, lazy set to new config value
+ uint16 accumulatedWeight; // upon config change, lazy set to 0
+ // A curse becomes active after either:
+ // - sum([voter.weight for voter who voted in current config]) >= curseWeightThreshold
+ // - ownerCurse is invoked
+ // Once a curse is active, only the owner can lift it.
+ bool curseActive; // retained across config changes
+ mapping(address => ConfigVersionAndCursesHash) latestVoteToCurseByCurseVoteAddr; // retained across config changes
+ }
+
+ mapping(bytes16 subject => CurseVoteProgress curseVoteProgress) private
+ s_potentiallyOutdatedCurseVoteProgressBySubject;
+
+ // We intentionally use a struct here, even though it contains a single field, to make it obvious to future editors
+ // that there is space for more fields.
+ struct CurseHotVars {
+ uint64 numSubjectsCursed; // incremented by voteToCurse, ownerCurse; decremented by ownerUnvoteToCurse
+ }
+
+ CurseHotVars private s_curseHotVars;
+
+ enum RecordedCurseRelatedOpTag {
+ // A vote to curse, through either voteToCurse or ownerCurse.
+ VoteToCurse,
+ // An unvote to curse, through unvoteToCurse.
+ UnvoteToCurse,
+ // An unvote to curse, through ownerUnvoteToCurse, which was not forced (forceUnvote=false).
+ OwnerUnvoteToCurseUnforced,
+ // An unvote to curse, through ownerUnvoteToCurse, which was forced (forceUnvote=true).
+ OwnerUnvoteToCurseForced,
+ // A configuration change.
+ //
+ // For subjects that are not cursed when this happens, past votes do not get accounted for in the new configuration.
+ // If a voter votes during the new configuration, their curses hash will restart from NO_VOTES_CURSES_HASH.
+ //
+ // For subjects that are cursed when this happens, past votes get accounted for.
+ // If a voter votes during the new configuration, their curses hash will continue from its old value.
+ SetConfig
+ }
+
+ /// @notice Provides the ability to quickly reconstruct the curse-related state of the contract offchain, without
+ /// having to replay all past events. Replaying past events often takes long, and in some cases might even be
+ /// infeasible due to log pruning.
+ ///
+ /// @dev We could save some gas by omitting some fields and instead using them as mapping keys, but we would lose the
+ /// cross-voter ordering, or cross-subject ordering, or cross-vote/unvote ordering.
+ struct RecordedCurseRelatedOp {
+ RecordedCurseRelatedOpTag tag;
+ uint64 blockTimestamp;
+ bool cursed; // whether the subject is cursed after this op; if tag in {SetConfig}, will be false
+ address curseVoteAddr; // if tag in {SetConfig}, will be address(0)
+ bytes16 subject; // if tag in {SetConfig}, will be bytes16(0)
+ bytes16 curseId; // if tag in {SetConfig, UnvoteToCurse, OwnerUnvoteToCurseUnforced, OwnerUnvoteToCurseForced}, will be bytes16(0)
+ }
+
+ RecordedCurseRelatedOp[] private s_recordedCurseRelatedOps;
+
+ /// @dev This function is to _ONLY_ be called in order to determine if a curse should become active upon a
+ /// vote-to-curse, or a curse should be deactivated upon an owner-unvote-to-curse.
+ /// Other reasons for a curse to be active, which are not covered here:
+ /// 1. Cursedness is retained from a prior config.
+ /// 2. The curse weight threshold was met at some point, which activated a curse, and enough voters unvoted to curse
+ /// such that the curse weight threshold is no longer met.
+ function _shouldCurseBeActive(CurseVoteProgress storage sptr_upToDateCurseVoteProgress) internal view returns (bool) {
+ return sptr_upToDateCurseVoteProgress.latestVoteToCurseByCurseVoteAddr[OWNER_CURSE_VOTE_ADDR].cursesHash
+ != NO_VOTES_CURSES_HASH
+ || sptr_upToDateCurseVoteProgress.accumulatedWeight >= sptr_upToDateCurseVoteProgress.curseWeightThreshold;
+ }
+
+ /// @dev It might be the case that due to the lazy update of curseVoteProgress, a curse is active even though
+ /// _shouldCurseBeActive(curseVoteProgress) is false, i.e., the owner has no active vote to curse and the curse
+ /// weight threshold has not been met.
+ function _getUpToDateCurseVoteProgress(
+ uint32 configVersion,
+ bytes16 subject
+ ) internal returns (CurseVoteProgress storage) {
+ CurseVoteProgress storage sptr_curseVoteProgress = s_potentiallyOutdatedCurseVoteProgressBySubject[subject];
+ if (configVersion != sptr_curseVoteProgress.configVersion) {
+ sptr_curseVoteProgress.configVersion = configVersion;
+ sptr_curseVoteProgress.curseWeightThreshold = s_versionedConfig.config.curseWeightThreshold;
+ sptr_curseVoteProgress.accumulatedWeight = 0;
+
+ if (sptr_curseVoteProgress.curseActive) {
+ // If a curse was active, count past votes to curse and retain the curses hash for cursers who are part of the
+ // new config.
+ Config storage sptr_config = s_versionedConfig.config;
+ for (uint256 i = 0; i < sptr_config.voters.length; ++i) {
+ Voter storage sptr_voter = sptr_config.voters[i];
+ ConfigVersionAndCursesHash storage sptr_cvch =
+ sptr_curseVoteProgress.latestVoteToCurseByCurseVoteAddr[sptr_voter.curseVoteAddr];
+ if (sptr_cvch.configVersion < configVersion && sptr_cvch.cursesHash != NO_VOTES_CURSES_HASH) {
+ // `< configVersion` instead of `== configVersion-1`, because there might have been multiple config changes
+ // without a lazy update of our subject. This has the side effect of retaining votes from very old configs
+ // that we might not really intend to retain, but these can be removed by the owner later.
+ sptr_cvch.configVersion = configVersion;
+ sptr_curseVoteProgress.accumulatedWeight += sptr_voter.curseWeight;
+ }
+ }
+ // We don't need to think about OWNER_CURSE_VOTE_ADDR here, because its ConfigVersionAndCursesHash counts even
+ // if the configVersion is not the current config version, in contrast to regular voters.
+ // It's an irregularity, but it saves us > 5k gas (if the owner had previously voted) for the unlucky voter who
+ // enters this branch.
+ } else {
+ // If a curse was not active, we don't count past votes to curse for voters who are part of the new config.
+ // Their curses hash will be restart from NO_VOTES_CURSES_HASH when they vote to curse again.
+ // We expect that the offchain code will revote to curse in case it voted to curse, and the vote to curse was
+ // lost due to any reason, including a config change when the curse was not yet active.
+ }
+ }
+ return sptr_curseVoteProgress;
+ }
+
+ // EVENTS, ERRORS
+
+ event ConfigSet(uint32 indexed configVersion, Config config);
+
+ error InvalidConfig();
+
+ event TaggedRootBlessed(uint32 indexed configVersion, IRMN.TaggedRoot taggedRoot, uint16 accumulatedWeight);
+ event TaggedRootBlessVotesReset(uint32 indexed configVersion, IRMN.TaggedRoot taggedRoot, bool wasBlessed);
+ event VotedToBless(uint32 indexed configVersion, address indexed voter, IRMN.TaggedRoot taggedRoot, uint8 weight);
+
+ event VotedToCurse(
+ uint32 indexed configVersion,
+ address indexed voter,
+ bytes16 subject,
+ bytes16 curseId,
+ uint8 weight,
+ uint64 blockTimestamp,
+ bytes28 cursesHash,
+ uint16 accumulatedWeight
+ );
+ event UnvotedToCurse(
+ uint32 indexed configVersion,
+ address indexed voter,
+ bytes16 subject,
+ uint8 weight,
+ bytes28 cursesHash,
+ uint16 remainingAccumulatedWeight
+ );
+ event SkippedUnvoteToCurse(address indexed voter, bytes16 subject, bytes28 onchainCursesHash, bytes28 cursesHash);
+ event Cursed(uint32 indexed configVersion, bytes16 subject, uint64 blockTimestamp);
+ event CurseLifted(bytes16 subject);
+
+ // These events make it easier for offchain logic to discover that it performs
+ // the same actions multiple times.
+ event AlreadyVotedToBless(uint32 indexed configVersion, address indexed voter, IRMN.TaggedRoot taggedRoot);
+ event AlreadyBlessed(uint32 indexed configVersion, address indexed voter, IRMN.TaggedRoot taggedRoot);
+
+ // Emitted by ownerRemoveThenAddPermaBlessedCommitStores.
+ event PermaBlessedCommitStoreAdded(address commitStore);
+ event PermaBlessedCommitStoreRemoved(address commitStore);
+
+ error ReusedCurseId(address voter, bytes16 curseId);
+ error UnauthorizedVoter(address voter);
+ error VoteToBlessNoop();
+ error VoteToCurseNoop();
+ error UnvoteToCurseNoop();
+ error VoteToBlessForbiddenDuringActiveGlobalCurse();
+
+ /// @notice Thrown when subjects are not a strictly increasing monotone sequence.
+ // Prevents a subject from receiving multiple votes to curse with the same curse id.
+ error SubjectsMustBeStrictlyIncreasing();
+
+ constructor(Config memory config) {
+ {
+ // Ensure that the bitmap is large enough to hold MAX_NUM_VOTERS.
+ // We do this in the constructor because MAX_NUM_VOTERS is constant.
+ BlessVoteProgress memory vp = BlessVoteProgress({
+ configVersion: 0,
+ voterBitmap: type(uint200).max, // will not compile if it doesn't fit
+ accumulatedWeight: 0,
+ weightThresholdMet: false
+ });
+ assert(vp.voterBitmap >> (MAX_NUM_VOTERS - 1) >= 1);
+ }
+ _setConfig(config);
+ }
+
+ function _bitmapGet(uint200 bitmap, uint8 index) internal pure returns (bool) {
+ assert(index < MAX_NUM_VOTERS);
+ return bitmap & (uint200(1) << index) != 0;
+ }
+
+ function _bitmapSet(uint200 bitmap, uint8 index) internal pure returns (uint200) {
+ assert(index < MAX_NUM_VOTERS);
+ return bitmap | (uint200(1) << index);
+ }
+
+ function _bitmapCount(uint200 bitmap) internal pure returns (uint8 oneBits) {
+ assert(bitmap < 1 << MAX_NUM_VOTERS);
+ // https://graphics.stanford.edu/~seander/bithacks.html#CountBitsSetKernighan
+ for (; bitmap != 0; ++oneBits) {
+ bitmap &= bitmap - 1;
+ }
+ }
+
+ function _taggedRootHash(IRMN.TaggedRoot memory taggedRoot) internal pure returns (bytes32) {
+ return keccak256(abi.encode(taggedRoot.commitStore, taggedRoot.root));
+ }
+
+ function _cursesHash(bytes28 prevCursesHash, bytes16 curseId) internal pure returns (bytes28) {
+ return bytes28(keccak256(abi.encode(prevCursesHash, curseId)));
+ }
+
+ function _blockTimestamp() internal view returns (uint64) {
+ return uint64(block.timestamp);
+ }
+
+ /// @param taggedRoots A tagged root is hashed as `keccak256(abi.encode(taggedRoot.commitStore
+ /// /* address */, taggedRoot.root /* bytes32 */))`.
+ /// @notice Tagged roots which are already (voted to be) blessed are skipped and emit corresponding events. In case
+ /// the call has no effect, i.e., all passed tagged roots are skipped, the function reverts with a `VoteToBlessNoop`.
+ function voteToBless(IRMN.TaggedRoot[] calldata taggedRoots) external {
+ // If we have an active global curse, something is really wrong. Let's err on the
+ // side of caution and not accept further blessings during this time of
+ // uncertainty.
+ if (isCursed(GLOBAL_CURSE_SUBJECT)) revert VoteToBlessForbiddenDuringActiveGlobalCurse();
+
+ uint32 configVersion = s_versionedConfig.configVersion;
+ BlesserRecord memory blesserRecord = s_blesserRecords[msg.sender];
+ if (blesserRecord.configVersion != configVersion) revert UnauthorizedVoter(msg.sender);
+
+ bool noop = true;
+ for (uint256 i = 0; i < taggedRoots.length; ++i) {
+ IRMN.TaggedRoot memory taggedRoot = taggedRoots[i];
+ bytes32 taggedRootHash = _taggedRootHash(taggedRoot);
+ BlessVoteProgress memory voteProgress = s_blessVoteProgressByTaggedRootHash[taggedRootHash];
+ if (voteProgress.weightThresholdMet) {
+ // We don't revert here because it's unreasonable to expect from the
+ // voter to know exactly when to stop voting. Most likely when they
+ // voted they didn't realize the threshold would be reached by the time
+ // their vote was counted.
+ // Additionally, there might be other tagged roots for which votes might
+ // count, and we want to allow that to happen.
+ emit AlreadyBlessed(configVersion, msg.sender, taggedRoot);
+ continue;
+ } else if (voteProgress.configVersion != configVersion) {
+ // Note that voteProgress.weightThresholdMet must be false at this point
+
+ // If votes were received while an older config was in effect,
+ // invalidate them and start from scratch.
+ // If votes were never received, set the current config version.
+ voteProgress = BlessVoteProgress({
+ configVersion: configVersion,
+ voterBitmap: 0,
+ accumulatedWeight: 0,
+ weightThresholdMet: false
+ });
+ } else if (_bitmapGet(voteProgress.voterBitmap, blesserRecord.index)) {
+ // We don't revert here because there might be other tagged roots for
+ // which votes might count, and we want to allow that to happen.
+ emit AlreadyVotedToBless(configVersion, msg.sender, taggedRoot);
+ continue;
+ }
+ noop = false;
+ voteProgress.voterBitmap = _bitmapSet(voteProgress.voterBitmap, blesserRecord.index);
+ voteProgress.accumulatedWeight += blesserRecord.weight;
+ emit VotedToBless(configVersion, msg.sender, taggedRoot, blesserRecord.weight);
+ if (voteProgress.accumulatedWeight >= s_versionedConfig.config.blessWeightThreshold) {
+ voteProgress.weightThresholdMet = true;
+ emit TaggedRootBlessed(configVersion, taggedRoot, voteProgress.accumulatedWeight);
+ }
+ s_blessVoteProgressByTaggedRootHash[taggedRootHash] = voteProgress;
+ }
+
+ if (noop) {
+ revert VoteToBlessNoop();
+ }
+ }
+
+ /// @notice Can be called by the owner to remove unintentionally voted or even blessed tagged roots in a recovery
+ /// scenario. The owner must ensure that there are no in-flight transactions by RMN nodes voting for any of the
+ /// taggedRoots before calling this function, as such in-flight transactions could lead to the roots becoming
+ /// re-blessed shortly after the call to this function, contrary to the original intention.
+ function ownerResetBlessVotes(IRMN.TaggedRoot[] calldata taggedRoots) external onlyOwner {
+ uint32 configVersion = s_versionedConfig.configVersion;
+ for (uint256 i = 0; i < taggedRoots.length; ++i) {
+ IRMN.TaggedRoot memory taggedRoot = taggedRoots[i];
+ bytes32 taggedRootHash = _taggedRootHash(taggedRoot);
+ BlessVoteProgress memory voteProgress = s_blessVoteProgressByTaggedRootHash[taggedRootHash];
+ delete s_blessVoteProgressByTaggedRootHash[taggedRootHash];
+ bool wasBlessed = voteProgress.weightThresholdMet;
+ if (voteProgress.configVersion == configVersion || wasBlessed) {
+ emit TaggedRootBlessVotesReset(configVersion, taggedRoot, wasBlessed);
+ }
+ }
+ }
+
+ struct UnvoteToCurseRequest {
+ bytes16 subject;
+ bytes28 cursesHash;
+ }
+
+ // For use in internal calls.
+ enum Privilege {
+ Owner,
+ Voter
+ }
+
+ function _authorizedUnvoteToCurse(
+ Privilege priv, // Privilege.Owner during an ownerUnvoteToCurse call, Privilege.Voter during a unvoteToCurse call
+ uint32 configVersion,
+ address curseVoteAddr,
+ UnvoteToCurseRequest memory req,
+ bool forceUnvote, // true only during an ownerUnvoteToCurse call, when OwnerUnvoteToCurseRequest.forceUnvote is true
+ CurserRecord storage sptr_curserRecord,
+ CurseVoteProgress storage sptr_curseVoteProgress
+ ) internal returns (bool unvoted, bool curseLifted) {
+ {
+ assert(priv == Privilege.Voter || priv == Privilege.Owner); // sanity check
+ // Check that the supplied arguments are feasible for our privilege.
+ if (forceUnvote || curseVoteAddr == OWNER_CURSE_VOTE_ADDR || curseVoteAddr == LIFT_CURSE_VOTE_ADDR) {
+ assert(priv == Privilege.Owner);
+ }
+ }
+
+ ConfigVersionAndCursesHash memory cvch = sptr_curseVoteProgress.latestVoteToCurseByCurseVoteAddr[curseVoteAddr];
+
+ // First, try to unvote.
+ if (
+ sptr_curserRecord.active && (curseVoteAddr == OWNER_CURSE_VOTE_ADDR || cvch.configVersion == configVersion)
+ && cvch.cursesHash != NO_VOTES_CURSES_HASH && (cvch.cursesHash == req.cursesHash || forceUnvote)
+ ) {
+ unvoted = true;
+ delete sptr_curseVoteProgress.latestVoteToCurseByCurseVoteAddr[curseVoteAddr];
+ // Assumes: s_curserRecords[OWNER_CURSE_VOTE_ADDR].weight == 0, enforced by _setConfig
+ sptr_curseVoteProgress.accumulatedWeight -= sptr_curserRecord.weight;
+
+ emit UnvotedToCurse(
+ configVersion,
+ curseVoteAddr,
+ req.subject,
+ sptr_curserRecord.weight,
+ req.cursesHash,
+ sptr_curseVoteProgress.accumulatedWeight
+ );
+ }
+
+ // If we have owner privilege, and the conditions for the curse to be active no longer hold, we are able to lift the
+ // curse.
+ bool shouldTryToLiftCurse = priv == Privilege.Owner && (unvoted || curseVoteAddr == LIFT_CURSE_VOTE_ADDR);
+
+ if (shouldTryToLiftCurse && sptr_curseVoteProgress.curseActive && !_shouldCurseBeActive(sptr_curseVoteProgress)) {
+ curseLifted = true;
+ sptr_curseVoteProgress.curseActive = false;
+ --s_curseHotVars.numSubjectsCursed;
+ emit CurseLifted(req.subject);
+ }
+
+ if (unvoted || curseLifted) {
+ RecordedCurseRelatedOpTag tag;
+ if (priv == Privilege.Owner) {
+ if (forceUnvote) {
+ tag = RecordedCurseRelatedOpTag.OwnerUnvoteToCurseForced;
+ } else {
+ tag = RecordedCurseRelatedOpTag.OwnerUnvoteToCurseUnforced;
+ }
+ } else if (priv == Privilege.Voter) {
+ tag = RecordedCurseRelatedOpTag.UnvoteToCurse;
+ } else {
+ // solhint-disable-next-line gas-custom-errors, reason-string
+ revert(); // assumption violation
+ }
+ s_recordedCurseRelatedOps.push(
+ RecordedCurseRelatedOp({
+ tag: tag,
+ cursed: sptr_curseVoteProgress.curseActive,
+ curseVoteAddr: curseVoteAddr,
+ curseId: bytes16(0),
+ subject: req.subject,
+ blockTimestamp: _blockTimestamp()
+ })
+ );
+ } else {
+ emit SkippedUnvoteToCurse(curseVoteAddr, req.subject, cvch.cursesHash, req.cursesHash);
+ }
+ }
+
+ /// @notice Can be called by a curser to remove unintentional votes to curse.
+ /// We expect this to be called very rarely, e.g. in case of a bug in the
+ /// offchain code causing false voteToCurse calls.
+ /// @notice Should be called from curser's corresponding curseVoteAddr.
+ function unvoteToCurse(UnvoteToCurseRequest[] memory unvoteToCurseRequests) external {
+ address curseVoteAddr = msg.sender;
+ CurserRecord storage sptr_curserRecord = s_curserRecords[curseVoteAddr];
+
+ if (!sptr_curserRecord.active) revert UnauthorizedVoter(curseVoteAddr);
+
+ uint32 configVersion = s_versionedConfig.configVersion;
+ bool anyVoteWasUnvoted = false;
+ for (uint256 i = 0; i < unvoteToCurseRequests.length; ++i) {
+ UnvoteToCurseRequest memory req = unvoteToCurseRequests[i];
+ CurseVoteProgress storage sptr_curseVoteProgress = _getUpToDateCurseVoteProgress(configVersion, req.subject);
+ (bool unvoted, bool curseLifted) = _authorizedUnvoteToCurse(
+ Privilege.Voter, configVersion, curseVoteAddr, req, false, sptr_curserRecord, sptr_curseVoteProgress
+ );
+ assert(!curseLifted); // assumption violation: voters can't lift curses
+ anyVoteWasUnvoted = anyVoteWasUnvoted || unvoted;
+ }
+
+ if (!anyVoteWasUnvoted) {
+ revert UnvoteToCurseNoop();
+ }
+ }
+
+ /// @notice A vote to curse is appropriate during unhealthy blockchain conditions
+ /// (eg. finality violations).
+ function voteToCurse(bytes16 curseId, bytes16[] memory subjects) external {
+ address curseVoteAddr = msg.sender;
+ assert(curseVoteAddr != OWNER_CURSE_VOTE_ADDR);
+ CurserRecord storage sptr_curserRecord = s_curserRecords[curseVoteAddr];
+ if (!sptr_curserRecord.active) revert UnauthorizedVoter(curseVoteAddr);
+ _authorizedVoteToCurse(curseVoteAddr, curseId, subjects, sptr_curserRecord);
+ }
+
+ function _authorizedVoteToCurse(
+ address curseVoteAddr,
+ bytes16 curseId,
+ bytes16[] memory subjects,
+ CurserRecord storage sptr_curserRecord
+ ) internal {
+ if (subjects.length == 0) revert VoteToCurseNoop();
+
+ if (sptr_curserRecord.usedCurseIds[curseId]) revert ReusedCurseId(curseVoteAddr, curseId);
+ sptr_curserRecord.usedCurseIds[curseId] = true;
+
+ // NOTE: We could pack configVersion into CurserRecord that we already load in the beginning of this function to
+ // avoid the following extra storage read for it, but since voteToCurse is not on the hot path we'd rather keep
+ // things simple.
+ uint32 configVersion = s_versionedConfig.configVersion;
+ for (uint256 i = 0; i < subjects.length; ++i) {
+ if (i >= 1 && !(subjects[i - 1] < subjects[i])) {
+ // Prevents a subject from receiving multiple votes to curse with the same curse id.
+ revert SubjectsMustBeStrictlyIncreasing();
+ }
+
+ bytes16 subject = subjects[i];
+ CurseVoteProgress storage sptr_curseVoteProgress = _getUpToDateCurseVoteProgress(configVersion, subject);
+ ConfigVersionAndCursesHash memory cvch = sptr_curseVoteProgress.latestVoteToCurseByCurseVoteAddr[curseVoteAddr];
+ bytes28 prevCursesHash;
+ if (
+ (curseVoteAddr != OWNER_CURSE_VOTE_ADDR && cvch.configVersion < configVersion)
+ || cvch.cursesHash == NO_VOTES_CURSES_HASH
+ ) {
+ // if owner's first vote, or if voter's first vote in this config version
+ prevCursesHash = NO_VOTES_CURSES_HASH; // start hashchain from scratch, explicit
+ sptr_curseVoteProgress.accumulatedWeight += sptr_curserRecord.weight;
+ } else {
+ // we've already accounted for the weight
+ prevCursesHash = cvch.cursesHash;
+ }
+ sptr_curseVoteProgress.latestVoteToCurseByCurseVoteAddr[curseVoteAddr] = cvch =
+ ConfigVersionAndCursesHash({configVersion: configVersion, cursesHash: _cursesHash(prevCursesHash, curseId)});
+ emit VotedToCurse(
+ configVersion,
+ curseVoteAddr,
+ subject,
+ curseId,
+ sptr_curserRecord.weight,
+ _blockTimestamp(),
+ cvch.cursesHash,
+ sptr_curseVoteProgress.accumulatedWeight
+ );
+
+ if (
+ prevCursesHash == NO_VOTES_CURSES_HASH && !sptr_curseVoteProgress.curseActive
+ && _shouldCurseBeActive(sptr_curseVoteProgress)
+ ) {
+ sptr_curseVoteProgress.curseActive = true;
+ ++s_curseHotVars.numSubjectsCursed;
+ emit Cursed(configVersion, subject, _blockTimestamp());
+ }
+
+ s_recordedCurseRelatedOps.push(
+ RecordedCurseRelatedOp({
+ tag: RecordedCurseRelatedOpTag.VoteToCurse,
+ cursed: sptr_curseVoteProgress.curseActive,
+ curseVoteAddr: curseVoteAddr,
+ curseId: curseId,
+ subject: subject,
+ blockTimestamp: _blockTimestamp()
+ })
+ );
+ }
+ }
+
+ /// @notice Enables the owner to immediately have the system enter the cursed state.
+ function ownerCurse(bytes16 curseId, bytes16[] memory subjects) external onlyOwner {
+ address curseVoteAddr = OWNER_CURSE_VOTE_ADDR;
+ CurserRecord storage sptr_curserRecord = s_curserRecords[curseVoteAddr];
+ // no need to check if sptr_curserRecord.active, we must have the onlyOwner modifier
+ _authorizedVoteToCurse(curseVoteAddr, curseId, subjects, sptr_curserRecord);
+ }
+
+ // Set curseVoteAddr=LIFT_CURSE_VOTE_ADDR, cursesHash=bytes28(0), to reset curseActive if it can be reset. Useful if
+ // all voters have unvoted to curse on their own and the curse can now be lifted without any individual votes that can
+ // be unvoted.
+ // solhint-disable-next-line gas-struct-packing
+ struct OwnerUnvoteToCurseRequest {
+ address curseVoteAddr;
+ UnvoteToCurseRequest unit;
+ bool forceUnvote;
+ }
+
+ /// @notice Enables the owner to remove curse votes. After the curse votes are removed,
+ /// this function will check whether the curse is still valid and restore the uncursed state if possible.
+ /// This function also enables the owner to lift a curse created through ownerCurse.
+ function ownerUnvoteToCurse(OwnerUnvoteToCurseRequest[] memory ownerUnvoteToCurseRequests) external onlyOwner {
+ bool anyCurseWasLifted = false;
+ bool anyVoteWasUnvoted = false;
+ uint32 configVersion = s_versionedConfig.configVersion;
+ for (uint256 i = 0; i < ownerUnvoteToCurseRequests.length; ++i) {
+ OwnerUnvoteToCurseRequest memory req = ownerUnvoteToCurseRequests[i];
+ CurseVoteProgress storage sptr_curseVoteProgress = _getUpToDateCurseVoteProgress(configVersion, req.unit.subject);
+ (bool unvoted, bool curseLifted) = _authorizedUnvoteToCurse(
+ Privilege.Owner,
+ configVersion,
+ req.curseVoteAddr,
+ req.unit,
+ req.forceUnvote,
+ s_curserRecords[req.curseVoteAddr],
+ sptr_curseVoteProgress
+ );
+ anyVoteWasUnvoted = anyVoteWasUnvoted || unvoted;
+ anyCurseWasLifted = anyCurseWasLifted || curseLifted;
+ }
+
+ if (anyCurseWasLifted) {
+ // Invalidate all in-progress votes to bless or curse by bumping the config version.
+ // They might have been based on false information about the source chain
+ // (e.g. in case of a finality violation).
+ _setConfig(s_versionedConfig.config);
+ }
+
+ if (!(anyVoteWasUnvoted || anyCurseWasLifted)) {
+ revert UnvoteToCurseNoop();
+ }
+ }
+
+ function setConfig(Config memory config) external onlyOwner {
+ _setConfig(config);
+ }
+
+ /// @notice Any tagged root with a commit store included in this array will be considered automatically blessed.
+ function getPermaBlessedCommitStores() external view returns (address[] memory) {
+ return s_permaBlessedCommitStores.values();
+ }
+
+ /// @notice The ordering of parameters is important. First come the commit stores to remove, then the commit stores to
+ /// add.
+ function ownerRemoveThenAddPermaBlessedCommitStores(
+ address[] memory removes,
+ address[] memory adds
+ ) external onlyOwner {
+ for (uint256 i = 0; i < removes.length; ++i) {
+ if (s_permaBlessedCommitStores.remove(removes[i])) {
+ emit PermaBlessedCommitStoreRemoved(removes[i]);
+ }
+ }
+ for (uint256 i = 0; i < adds.length; ++i) {
+ if (s_permaBlessedCommitStores.add(adds[i])) {
+ emit PermaBlessedCommitStoreAdded(adds[i]);
+ }
+ }
+ }
+
+ /// @inheritdoc IRMN
+ function isBlessed(IRMN.TaggedRoot calldata taggedRoot) external view returns (bool) {
+ return s_blessVoteProgressByTaggedRootHash[_taggedRootHash(taggedRoot)].weightThresholdMet
+ || s_permaBlessedCommitStores.contains(taggedRoot.commitStore);
+ }
+
+ /// @inheritdoc IRMN
+ function isCursed() external view returns (bool) {
+ if (s_curseHotVars.numSubjectsCursed == 0) {
+ return false; // happy path costs a single SLOAD
+ } else {
+ return s_potentiallyOutdatedCurseVoteProgressBySubject[GLOBAL_CURSE_SUBJECT].curseActive
+ || s_potentiallyOutdatedCurseVoteProgressBySubject[LEGACY_CURSE_SUBJECT].curseActive;
+ }
+ }
+
+ /// @inheritdoc IRMN
+ function isCursed(bytes16 subject) public view returns (bool) {
+ if (s_curseHotVars.numSubjectsCursed == 0) {
+ return false; // happy path costs a single SLOAD
+ } else {
+ return s_potentiallyOutdatedCurseVoteProgressBySubject[GLOBAL_CURSE_SUBJECT].curseActive
+ || s_potentiallyOutdatedCurseVoteProgressBySubject[subject].curseActive;
+ }
+ }
+
+ /// @notice Config version might be incremented for many reasons, including
+ /// the lifting of a curse, or a regular config change.
+ function getConfigDetails() external view returns (uint32 version, uint32 blockNumber, Config memory config) {
+ version = s_versionedConfig.configVersion;
+ blockNumber = s_versionedConfig.blockNumber;
+ config = s_versionedConfig.config;
+ }
+
+ /// @return blessVoteAddrs addresses of voters, will be empty if voting took place with an older config version
+ /// @return accumulatedWeight sum of weights of voters, will be zero if voting took place with an older config version
+ /// @return blessed will be accurate regardless of when voting took place
+ /// @dev This is a helper method for offchain code so efficiency is not really a concern.
+ function getBlessProgress(IRMN.TaggedRoot calldata taggedRoot)
+ external
+ view
+ returns (address[] memory blessVoteAddrs, uint16 accumulatedWeight, bool blessed)
+ {
+ bytes32 taggedRootHash = _taggedRootHash(taggedRoot);
+ BlessVoteProgress memory progress = s_blessVoteProgressByTaggedRootHash[taggedRootHash];
+ blessed = progress.weightThresholdMet;
+ if (progress.configVersion == s_versionedConfig.configVersion) {
+ accumulatedWeight = progress.accumulatedWeight;
+ uint200 bitmap = progress.voterBitmap;
+ blessVoteAddrs = new address[](_bitmapCount(bitmap));
+ Voter[] memory voters = s_versionedConfig.config.voters;
+ uint256 j = 0;
+ for (uint8 i = 0; i < voters.length; ++i) {
+ if (_bitmapGet(bitmap, i)) {
+ blessVoteAddrs[j] = voters[i].blessVoteAddr;
+ ++j;
+ }
+ }
+ }
+ }
+
+ /// @return curseVoteAddrs the curseVoteAddr of each voter with an active vote to curse
+ /// @return cursesHashes the i-th value is the curses hash of curseVoteAddrs[i]
+ /// @return accumulatedWeight the accumulated weight of all voters with an active vote to curse who are part of the
+ /// current config
+ /// @return cursed might be true even if the owner has no active vote and accumulatedWeight < curseWeightThreshold,
+ /// due to a retained curse from a prior config
+ /// @dev This is a helper method for offchain code so efficiency is not really a concern.
+ function getCurseProgress(bytes16 subject)
+ external
+ view
+ returns (address[] memory curseVoteAddrs, bytes28[] memory cursesHashes, uint16 accumulatedWeight, bool cursed)
+ {
+ uint32 configVersion = s_versionedConfig.configVersion;
+ Config memory config = s_versionedConfig.config;
+ // Can't use _getUpToDateCurseVoteProgress here because we can't call a non-view function from within a view.
+ // So we get to repeat some accounting.
+ CurseVoteProgress storage outdatedCurseVoteProgress = s_potentiallyOutdatedCurseVoteProgressBySubject[subject];
+
+ cursed = outdatedCurseVoteProgress.curseActive;
+
+ // See _getUpToDateCurseVoteProgress for more context.
+ bool shouldCountVotesFromOlderConfigs = outdatedCurseVoteProgress.configVersion < configVersion && cursed;
+
+ // A play in two acts, because we can't push to arrays in memory, so we need to precompute the array's length.
+ // First act: we count the number of cursers, i.e., voters with active vote.
+ // Second act: push the cursers to the arrays, sum their weights.
+
+ uint256 numCursers = 0; // we reuse this variable for writing to perserve stack space
+ accumulatedWeight = 0;
+ for (uint256 act = 1; act <= 2; ++act) {
+ uint256 i = config.voters.length; // not config.voters.length-1 to account for the owner
+ while (true) {
+ address curseVoteAddr;
+ uint8 weight;
+ if (i < config.voters.length) {
+ curseVoteAddr = config.voters[i].curseVoteAddr;
+ weight = config.voters[i].curseWeight;
+ } else {
+ // Allows us to include the owner's vote and curses hash in the result.
+ curseVoteAddr = OWNER_CURSE_VOTE_ADDR;
+ weight = 0;
+ }
+
+ ConfigVersionAndCursesHash memory cvch =
+ outdatedCurseVoteProgress.latestVoteToCurseByCurseVoteAddr[curseVoteAddr];
+ bool hasActiveVote = (
+ shouldCountVotesFromOlderConfigs || cvch.configVersion == configVersion
+ || curseVoteAddr == OWNER_CURSE_VOTE_ADDR
+ ) && cvch.cursesHash != NO_VOTES_CURSES_HASH;
+ if (hasActiveVote) {
+ if (act == 1) {
+ ++numCursers;
+ } else if (act == 2) {
+ accumulatedWeight += weight;
+ --numCursers;
+ curseVoteAddrs[numCursers] = curseVoteAddr;
+ cursesHashes[numCursers] = cvch.cursesHash;
+ } else {
+ // solhint-disable-next-line gas-custom-errors, reason-string
+ revert(); // assumption violation
+ }
+ }
+
+ if (i > 0) {
+ --i;
+ } else {
+ break;
+ }
+ }
+
+ if (act == 1) {
+ // We are done counting at this point, initialize the arrays for the second act that follows immediately after.
+ curseVoteAddrs = new address[](numCursers);
+ cursesHashes = new bytes28[](numCursers);
+ }
+ }
+ }
+
+ /// @notice Returns the number of subjects that are currently cursed.
+ function getCursedSubjectsCount() external view returns (uint256) {
+ return s_curseHotVars.numSubjectsCursed;
+ }
+
+ /// @dev This is a helper method for offchain code to know what arguments to use for getRecordedCurseRelatedOps.
+ function getRecordedCurseRelatedOpsCount() external view returns (uint256) {
+ return s_recordedCurseRelatedOps.length;
+ }
+
+ /// @dev This is a helper method for offchain code so efficiency is not really a concern.
+ /// @dev Returns s_recordedCurseRelatedOps[offset:offset+limit].
+ function getRecordedCurseRelatedOps(
+ uint256 offset,
+ uint256 limit
+ ) external view returns (RecordedCurseRelatedOp[] memory) {
+ uint256 pageLen;
+ if (offset + limit <= s_recordedCurseRelatedOps.length) {
+ pageLen = limit;
+ } else if (offset < s_recordedCurseRelatedOps.length) {
+ pageLen = s_recordedCurseRelatedOps.length - offset;
+ } else {
+ pageLen = 0;
+ }
+ RecordedCurseRelatedOp[] memory page = new RecordedCurseRelatedOp[](pageLen);
+ for (uint256 i = 0; i < pageLen; ++i) {
+ page[i] = s_recordedCurseRelatedOps[offset + i];
+ }
+ return page;
+ }
+
+ function _validateConfig(Config memory config) internal pure returns (bool) {
+ if (
+ config.voters.length == 0 || config.voters.length > MAX_NUM_VOTERS || config.blessWeightThreshold == 0
+ || config.curseWeightThreshold == 0
+ ) {
+ return false;
+ }
+
+ uint256 totalBlessWeight = 0;
+ uint256 totalCurseWeight = 0;
+ address[] memory allAddrs = new address[](2 * config.voters.length);
+ for (uint256 i = 0; i < config.voters.length; ++i) {
+ Voter memory voter = config.voters[i];
+ // The owner can always curse using the ownerCurse method, and is not supposed to be included in the voters list.
+ // Even though the intent is for the actual owner address to NOT be included in the voters list, we don't
+ // explicitly disallow curseVoteAddr == owner() here. Even if we did, the owner could transfer ownership of the
+ // contract, and so we couldn't guarantee that the owner is not eventually included in the voters list.
+ if (
+ voter.blessVoteAddr == address(0) || voter.curseVoteAddr == address(0)
+ || voter.curseVoteAddr == LIFT_CURSE_VOTE_ADDR || voter.curseVoteAddr == OWNER_CURSE_VOTE_ADDR
+ || (voter.blessWeight == 0 && voter.curseWeight == 0)
+ ) {
+ return false;
+ }
+ allAddrs[2 * i + 0] = voter.blessVoteAddr;
+ allAddrs[2 * i + 1] = voter.curseVoteAddr;
+ totalBlessWeight += voter.blessWeight;
+ totalCurseWeight += voter.curseWeight;
+ }
+ for (uint256 i = 0; i < allAddrs.length; ++i) {
+ address allAddrs_i = allAddrs[i];
+ for (uint256 j = i + 1; j < allAddrs.length; ++j) {
+ if (allAddrs_i == allAddrs[j]) {
+ return false;
+ }
+ }
+ }
+
+ return totalBlessWeight >= config.blessWeightThreshold && totalCurseWeight >= config.curseWeightThreshold;
+ }
+
+ function _setConfig(Config memory config) private {
+ if (!_validateConfig(config)) revert InvalidConfig();
+
+ // We can't directly assign s_versionedConfig.config to config
+ // because copying a memory array into storage is not supported.
+ {
+ s_versionedConfig.config.blessWeightThreshold = config.blessWeightThreshold;
+ s_versionedConfig.config.curseWeightThreshold = config.curseWeightThreshold;
+ while (s_versionedConfig.config.voters.length != 0) {
+ Voter memory voter = s_versionedConfig.config.voters[s_versionedConfig.config.voters.length - 1];
+ delete s_blesserRecords[voter.blessVoteAddr];
+ delete s_curserRecords[voter.curseVoteAddr]; // usedCurseIds mapping is retained, as intended
+ s_versionedConfig.config.voters.pop();
+ }
+ for (uint256 i = 0; i < config.voters.length; ++i) {
+ s_versionedConfig.config.voters.push(config.voters[i]);
+ }
+ }
+
+ ++s_versionedConfig.configVersion;
+ uint32 configVersion = s_versionedConfig.configVersion;
+
+ for (uint8 i = 0; i < config.voters.length; ++i) {
+ Voter memory voter = config.voters[i];
+ s_blesserRecords[voter.blessVoteAddr] =
+ BlesserRecord({configVersion: configVersion, index: i, weight: voter.blessWeight});
+ {
+ CurserRecord storage sptr_curserRecord = s_curserRecords[voter.curseVoteAddr];
+ // Solidity will not let us initialize as CurserRecord({...}) due to the nested mapping
+ sptr_curserRecord.active = true;
+ sptr_curserRecord.weight = voter.curseWeight;
+ }
+ }
+ {
+ // Initialize the owner's CurserRecord
+ // We could in principle perform this initialization once in the constructor instead, and save a small bit of gas.
+ // But configuration changes are relatively infrequent, and keeping the initialization here makes the contract's
+ // correctness easier to reason about.
+ CurserRecord storage sptr_ownerCurserRecord = s_curserRecords[OWNER_CURSE_VOTE_ADDR];
+ sptr_ownerCurserRecord.active = true; // Assumed by vote/unvote-to-curse logic
+ sptr_ownerCurserRecord.weight = 0; // Assumed by vote/unvote-to-curse logic
+ }
+ s_versionedConfig.blockNumber = uint32(block.number);
+ emit ConfigSet(configVersion, config);
+
+ s_recordedCurseRelatedOps.push(
+ RecordedCurseRelatedOp({
+ tag: RecordedCurseRelatedOpTag.SetConfig,
+ blockTimestamp: _blockTimestamp(),
+ cursed: false,
+ curseVoteAddr: address(0),
+ curseId: bytes16(0),
+ subject: bytes16(0)
+ })
+ );
+ }
+}
diff --git a/contracts/src/v0.8/ccip/Router.sol b/contracts/src/v0.8/ccip/Router.sol
new file mode 100644
index 00000000000..e50651bc5ba
--- /dev/null
+++ b/contracts/src/v0.8/ccip/Router.sol
@@ -0,0 +1,290 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../shared/interfaces/ITypeAndVersion.sol";
+import {IAny2EVMMessageReceiver} from "./interfaces/IAny2EVMMessageReceiver.sol";
+import {IEVM2AnyOnRamp} from "./interfaces/IEVM2AnyOnRamp.sol";
+import {IRMN} from "./interfaces/IRMN.sol";
+import {IRouter} from "./interfaces/IRouter.sol";
+import {IRouterClient} from "./interfaces/IRouterClient.sol";
+import {IWrappedNative} from "./interfaces/IWrappedNative.sol";
+
+import {OwnerIsCreator} from "../shared/access/OwnerIsCreator.sol";
+import {CallWithExactGas} from "../shared/call/CallWithExactGas.sol";
+import {Client} from "./libraries/Client.sol";
+import {Internal} from "./libraries/Internal.sol";
+
+import {IERC20} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+import {EnumerableSet} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @title Router
+/// @notice This is the entry point for the end user wishing to send data across chains.
+/// @dev This contract is used as a router for both on-ramps and off-ramps
+contract Router is IRouter, IRouterClient, ITypeAndVersion, OwnerIsCreator {
+ using SafeERC20 for IERC20;
+ using EnumerableSet for EnumerableSet.UintSet;
+
+ error FailedToSendValue();
+ error InvalidRecipientAddress(address to);
+ error OffRampMismatch(uint64 chainSelector, address offRamp);
+ error BadARMSignal();
+
+ event OnRampSet(uint64 indexed destChainSelector, address onRamp);
+ event OffRampAdded(uint64 indexed sourceChainSelector, address offRamp);
+ event OffRampRemoved(uint64 indexed sourceChainSelector, address offRamp);
+ event MessageExecuted(bytes32 messageId, uint64 sourceChainSelector, address offRamp, bytes32 calldataHash);
+
+ struct OnRamp {
+ uint64 destChainSelector;
+ address onRamp;
+ }
+
+ struct OffRamp {
+ uint64 sourceChainSelector;
+ address offRamp;
+ }
+
+ string public constant override typeAndVersion = "Router 1.2.0";
+ // We limit return data to a selector plus 4 words. This is to avoid
+ // malicious contracts from returning large amounts of data and causing
+ // repeated out-of-gas scenarios.
+ uint16 public constant MAX_RET_BYTES = 4 + 4 * 32;
+ // STATIC CONFIG
+ // Address of RMN proxy contract (formerly known as ARM)
+ address private immutable i_armProxy;
+
+ // DYNAMIC CONFIG
+ address private s_wrappedNative;
+ // destChainSelector => onRamp address
+ // Only ever one onRamp enabled at a time for a given destChainSelector.
+ mapping(uint256 destChainSelector => address onRamp) private s_onRamps;
+ // Stores [sourceChainSelector << 160 + offramp] as a pair to allow for
+ // lookups for specific chain/offramp pairs.
+ EnumerableSet.UintSet private s_chainSelectorAndOffRamps;
+
+ constructor(address wrappedNative, address armProxy) {
+ // Zero address indicates unsupported auto-wrapping, therefore, unsupported
+ // native fee token payments.
+ s_wrappedNative = wrappedNative;
+ i_armProxy = armProxy;
+ }
+
+ // ================================================================
+ // │ Message sending │
+ // ================================================================
+
+ /// @inheritdoc IRouterClient
+ function getFee(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage memory message
+ ) external view returns (uint256 fee) {
+ if (message.feeToken == address(0)) {
+ // For empty feeToken return native quote.
+ message.feeToken = address(s_wrappedNative);
+ }
+ address onRamp = s_onRamps[destinationChainSelector];
+ if (onRamp == address(0)) revert UnsupportedDestinationChain(destinationChainSelector);
+ return IEVM2AnyOnRamp(onRamp).getFee(destinationChainSelector, message);
+ }
+
+ /// @notice This functionality has been removed and will revert when called.
+ function getSupportedTokens(uint64 chainSelector) external view returns (address[] memory) {
+ if (!isChainSupported(chainSelector)) {
+ return new address[](0);
+ }
+ return IEVM2AnyOnRamp(s_onRamps[uint256(chainSelector)]).getSupportedTokens(chainSelector);
+ }
+
+ /// @inheritdoc IRouterClient
+ function isChainSupported(uint64 chainSelector) public view returns (bool) {
+ return s_onRamps[chainSelector] != address(0);
+ }
+
+ /// @inheritdoc IRouterClient
+ function ccipSend(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage memory message
+ ) external payable whenNotCursed returns (bytes32) {
+ address onRamp = s_onRamps[destinationChainSelector];
+ if (onRamp == address(0)) revert UnsupportedDestinationChain(destinationChainSelector);
+ uint256 feeTokenAmount;
+ // address(0) signals payment in true native
+ if (message.feeToken == address(0)) {
+ // for fee calculation we check the wrapped native price as we wrap
+ // as part of the native fee coin payment.
+ message.feeToken = s_wrappedNative;
+ // We rely on getFee to validate that the feeToken is whitelisted.
+ feeTokenAmount = IEVM2AnyOnRamp(onRamp).getFee(destinationChainSelector, message);
+ // Ensure sufficient native.
+ if (msg.value < feeTokenAmount) revert InsufficientFeeTokenAmount();
+ // Wrap and send native payment.
+ // Note we take the whole msg.value regardless if its larger.
+ feeTokenAmount = msg.value;
+ IWrappedNative(message.feeToken).deposit{value: feeTokenAmount}();
+ IERC20(message.feeToken).safeTransfer(onRamp, feeTokenAmount);
+ } else {
+ if (msg.value > 0) revert InvalidMsgValue();
+ // We rely on getFee to validate that the feeToken is whitelisted.
+ feeTokenAmount = IEVM2AnyOnRamp(onRamp).getFee(destinationChainSelector, message);
+ IERC20(message.feeToken).safeTransferFrom(msg.sender, onRamp, feeTokenAmount);
+ }
+
+ // Transfer the tokens to the token pools.
+ for (uint256 i = 0; i < message.tokenAmounts.length; ++i) {
+ IERC20 token = IERC20(message.tokenAmounts[i].token);
+ // We rely on getPoolBySourceToken to validate that the token is whitelisted.
+ token.safeTransferFrom(
+ msg.sender,
+ address(IEVM2AnyOnRamp(onRamp).getPoolBySourceToken(destinationChainSelector, token)),
+ message.tokenAmounts[i].amount
+ );
+ }
+
+ return IEVM2AnyOnRamp(onRamp).forwardFromRouter(destinationChainSelector, message, feeTokenAmount, msg.sender);
+ }
+
+ // ================================================================
+ // │ Message execution │
+ // ================================================================
+
+ /// @inheritdoc IRouter
+ /// @dev _callWithExactGas protects against return data bombs by capping the return data size at MAX_RET_BYTES.
+ function routeMessage(
+ Client.Any2EVMMessage calldata message,
+ uint16 gasForCallExactCheck,
+ uint256 gasLimit,
+ address receiver
+ ) external override whenNotCursed returns (bool success, bytes memory retData, uint256 gasUsed) {
+ // We only permit offRamps to call this function.
+ if (!isOffRamp(message.sourceChainSelector, msg.sender)) revert OnlyOffRamp();
+
+ // We encode here instead of the offRamps to constrain specifically what functions
+ // can be called from the router.
+ bytes memory data = abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message);
+
+ (success, retData, gasUsed) = CallWithExactGas._callWithExactGasSafeReturnData(
+ data, receiver, gasLimit, gasForCallExactCheck, Internal.MAX_RET_BYTES
+ );
+
+ emit MessageExecuted(message.messageId, message.sourceChainSelector, msg.sender, keccak256(data));
+ return (success, retData, gasUsed);
+ }
+
+ // @notice Merges a chain selector and offRamp address into a single uint256 by shifting the
+ // chain selector 160 bits to the left.
+ function _mergeChainSelectorAndOffRamp(
+ uint64 sourceChainSelector,
+ address offRampAddress
+ ) internal pure returns (uint256) {
+ return (uint256(sourceChainSelector) << 160) + uint160(offRampAddress);
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Gets the wrapped representation of the native fee coin.
+ /// @return The address of the ERC20 wrapped native.
+ function getWrappedNative() external view returns (address) {
+ return s_wrappedNative;
+ }
+
+ /// @notice Sets a new wrapped native token.
+ /// @param wrappedNative The address of the new wrapped native ERC20 token.
+ function setWrappedNative(address wrappedNative) external onlyOwner {
+ s_wrappedNative = wrappedNative;
+ }
+
+ /// @notice Gets the RMN address, formerly known as ARM
+ /// @return The address of the RMN proxy contract, formerly known as ARM
+ function getArmProxy() external view returns (address) {
+ return i_armProxy;
+ }
+
+ /// @inheritdoc IRouter
+ function getOnRamp(uint64 destChainSelector) external view returns (address) {
+ return s_onRamps[destChainSelector];
+ }
+
+ function getOffRamps() external view returns (OffRamp[] memory) {
+ uint256[] memory encodedOffRamps = s_chainSelectorAndOffRamps.values();
+ OffRamp[] memory offRamps = new OffRamp[](encodedOffRamps.length);
+ for (uint256 i = 0; i < encodedOffRamps.length; ++i) {
+ uint256 encodedOffRamp = encodedOffRamps[i];
+ offRamps[i] =
+ OffRamp({sourceChainSelector: uint64(encodedOffRamp >> 160), offRamp: address(uint160(encodedOffRamp))});
+ }
+ return offRamps;
+ }
+
+ /// @inheritdoc IRouter
+ function isOffRamp(uint64 sourceChainSelector, address offRamp) public view returns (bool) {
+ // We have to encode the sourceChainSelector and offRamp into a uint256 to use as a key in the set.
+ return s_chainSelectorAndOffRamps.contains(_mergeChainSelectorAndOffRamp(sourceChainSelector, offRamp));
+ }
+
+ /// @notice applyRampUpdates applies a set of ramp changes which provides
+ /// the ability to add new chains and upgrade ramps.
+ function applyRampUpdates(
+ OnRamp[] calldata onRampUpdates,
+ OffRamp[] calldata offRampRemoves,
+ OffRamp[] calldata offRampAdds
+ ) external onlyOwner {
+ // Apply egress updates.
+ // We permit zero address as way to disable egress.
+ for (uint256 i = 0; i < onRampUpdates.length; ++i) {
+ OnRamp memory onRampUpdate = onRampUpdates[i];
+ s_onRamps[onRampUpdate.destChainSelector] = onRampUpdate.onRamp;
+ emit OnRampSet(onRampUpdate.destChainSelector, onRampUpdate.onRamp);
+ }
+
+ // Apply ingress updates.
+ for (uint256 i = 0; i < offRampRemoves.length; ++i) {
+ uint64 sourceChainSelector = offRampRemoves[i].sourceChainSelector;
+ address offRampAddress = offRampRemoves[i].offRamp;
+
+ // If the selector-offRamp pair does not exist, revert.
+ if (!s_chainSelectorAndOffRamps.remove(_mergeChainSelectorAndOffRamp(sourceChainSelector, offRampAddress))) {
+ revert OffRampMismatch(sourceChainSelector, offRampAddress);
+ }
+
+ emit OffRampRemoved(sourceChainSelector, offRampAddress);
+ }
+
+ for (uint256 i = 0; i < offRampAdds.length; ++i) {
+ uint64 sourceChainSelector = offRampAdds[i].sourceChainSelector;
+ address offRampAddress = offRampAdds[i].offRamp;
+
+ if (s_chainSelectorAndOffRamps.add(_mergeChainSelectorAndOffRamp(sourceChainSelector, offRampAddress))) {
+ emit OffRampAdded(sourceChainSelector, offRampAddress);
+ }
+ }
+ }
+
+ /// @notice Provides the ability for the owner to recover any tokens accidentally
+ /// sent to this contract.
+ /// @dev Must be onlyOwner to avoid malicious token contract calls.
+ /// @param tokenAddress ERC20-token to recover
+ /// @param to Destination address to send the tokens to.
+ function recoverTokens(address tokenAddress, address to, uint256 amount) external onlyOwner {
+ if (to == address(0)) revert InvalidRecipientAddress(to);
+
+ if (tokenAddress == address(0)) {
+ (bool success,) = to.call{value: amount}("");
+ if (!success) revert FailedToSendValue();
+ return;
+ }
+ IERC20(tokenAddress).safeTransfer(to, amount);
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Ensure that the RMN has not cursed the network.
+ modifier whenNotCursed() {
+ if (IRMN(i_armProxy).isCursed()) revert BadARMSignal();
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/CCIPClientExample.sol b/contracts/src/v0.8/ccip/applications/CCIPClientExample.sol
new file mode 100644
index 00000000000..b105cf8b00f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/CCIPClientExample.sol
@@ -0,0 +1,173 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IRouterClient} from "../interfaces/IRouterClient.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {Client} from "../libraries/Client.sol";
+import {CCIPReceiver} from "./CCIPReceiver.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+// @notice Example of a client which supports EVM/non-EVM chains
+// @dev If chain specific logic is required for different chain families (e.g. particular
+// decoding the bytes sender for authorization checks), it may be required to point to a helper
+// authorization contract unless all chain families are known up front.
+// @dev If contract does not implement IAny2EVMMessageReceiver and IERC165,
+// and tokens are sent to it, ccipReceive will not be called but tokens will be transferred.
+// @dev If the client is upgradeable you have significantly more flexibility and
+// can avoid storage based options like the below contract uses. However it's
+// worth carefully considering how the trust assumptions of your client dapp will
+// change if you introduce upgradeability. An immutable dapp building on top of CCIP
+// like the example below will inherit the trust properties of CCIP (i.e. the oracle network).
+// @dev The receiver's are encoded offchain and passed as direct arguments to permit supporting
+// new chain family receivers (e.g. a Solana encoded receiver address) without upgrading.
+contract CCIPClientExample is CCIPReceiver, OwnerIsCreator {
+ error InvalidChain(uint64 chainSelector);
+
+ event MessageSent(bytes32 messageId);
+ event MessageReceived(bytes32 messageId);
+
+ // Current feeToken
+ IERC20 public s_feeToken;
+ // Below is a simplistic example (same params for all messages) of using storage to allow for new options without
+ // upgrading the dapp. Note that extra args are chain family specific (e.g. gasLimit is EVM specific etc.).
+ // and will always be backwards compatible i.e. upgrades are opt-in.
+ // Offchain we can compute the V1 extraArgs:
+ // Client.EVMExtraArgsV1 memory extraArgs = Client.EVMExtraArgsV1({gasLimit: 300_000});
+ // bytes memory encodedV1ExtraArgs = Client._argsToBytes(extraArgs);
+ // Then later compute V2 extraArgs, for example if a refund feature was added:
+ // Client.EVMExtraArgsV2 memory extraArgs = Client.EVMExtraArgsV2({gasLimit: 300_000, destRefundAddress: 0x1234});
+ // bytes memory encodedV2ExtraArgs = Client._argsToBytes(extraArgs);
+ // and update storage with the new args.
+ // If different options are required for different messages, for example different gas limits,
+ // one can simply key based on (chainSelector, messageType) instead of only chainSelector.
+ mapping(uint64 destChainSelector => bytes extraArgsBytes) public s_chains;
+
+ constructor(IRouterClient router, IERC20 feeToken) CCIPReceiver(address(router)) {
+ s_feeToken = feeToken;
+ s_feeToken.approve(address(router), type(uint256).max);
+ }
+
+ function enableChain(uint64 chainSelector, bytes memory extraArgs) external onlyOwner {
+ s_chains[chainSelector] = extraArgs;
+ }
+
+ function disableChain(uint64 chainSelector) external onlyOwner {
+ delete s_chains[chainSelector];
+ }
+
+ function ccipReceive(Client.Any2EVMMessage calldata message)
+ external
+ virtual
+ override
+ onlyRouter
+ validChain(message.sourceChainSelector)
+ {
+ // Extremely important to ensure only router calls this.
+ // Tokens in message if any will be transferred to this contract
+ // TODO: Validate sender/origin chain and process message and/or tokens.
+ _ccipReceive(message);
+ }
+
+ function _ccipReceive(Client.Any2EVMMessage memory message) internal override {
+ emit MessageReceived(message.messageId);
+ }
+
+ /// @notice sends data to receiver on dest chain. Assumes address(this) has sufficient native asset.
+ function sendDataPayNative(
+ uint64 destChainSelector,
+ bytes memory receiver,
+ bytes memory data
+ ) external validChain(destChainSelector) {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](0);
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: receiver,
+ data: data,
+ tokenAmounts: tokenAmounts,
+ extraArgs: s_chains[destChainSelector],
+ feeToken: address(0) // We leave the feeToken empty indicating we'll pay raw native.
+ });
+ bytes32 messageId = IRouterClient(i_ccipRouter).ccipSend{
+ value: IRouterClient(i_ccipRouter).getFee(destChainSelector, message)
+ }(destChainSelector, message);
+ emit MessageSent(messageId);
+ }
+
+ /// @notice sends data to receiver on dest chain. Assumes address(this) has sufficient feeToken.
+ function sendDataPayFeeToken(
+ uint64 destChainSelector,
+ bytes memory receiver,
+ bytes memory data
+ ) external validChain(destChainSelector) {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](0);
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: receiver,
+ data: data,
+ tokenAmounts: tokenAmounts,
+ extraArgs: s_chains[destChainSelector],
+ feeToken: address(s_feeToken)
+ });
+ // Optional uint256 fee = i_ccipRouter.getFee(destChainSelector, message);
+ // Can decide if fee is acceptable.
+ // address(this) must have sufficient feeToken or the send will revert.
+ bytes32 messageId = IRouterClient(i_ccipRouter).ccipSend(destChainSelector, message);
+ emit MessageSent(messageId);
+ }
+
+ /// @notice sends data to receiver on dest chain. Assumes address(this) has sufficient native token.
+ function sendDataAndTokens(
+ uint64 destChainSelector,
+ bytes memory receiver,
+ bytes memory data,
+ Client.EVMTokenAmount[] memory tokenAmounts
+ ) external validChain(destChainSelector) {
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ IERC20(tokenAmounts[i].token).transferFrom(msg.sender, address(this), tokenAmounts[i].amount);
+ IERC20(tokenAmounts[i].token).approve(i_ccipRouter, tokenAmounts[i].amount);
+ }
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: receiver,
+ data: data,
+ tokenAmounts: tokenAmounts,
+ extraArgs: s_chains[destChainSelector],
+ feeToken: address(s_feeToken)
+ });
+ // Optional uint256 fee = i_ccipRouter.getFee(destChainSelector, message);
+ // Can decide if fee is acceptable.
+ // address(this) must have sufficient feeToken or the send will revert.
+ bytes32 messageId = IRouterClient(i_ccipRouter).ccipSend(destChainSelector, message);
+ emit MessageSent(messageId);
+ }
+
+ // @notice user sends tokens to a receiver
+ // Approvals can be optimized with a whitelist of tokens and inf approvals if desired.
+ function sendTokens(
+ uint64 destChainSelector,
+ bytes memory receiver,
+ Client.EVMTokenAmount[] memory tokenAmounts
+ ) external validChain(destChainSelector) {
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ IERC20(tokenAmounts[i].token).transferFrom(msg.sender, address(this), tokenAmounts[i].amount);
+ IERC20(tokenAmounts[i].token).approve(i_ccipRouter, tokenAmounts[i].amount);
+ }
+ bytes memory data;
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: receiver,
+ data: data,
+ tokenAmounts: tokenAmounts,
+ extraArgs: s_chains[destChainSelector],
+ feeToken: address(s_feeToken)
+ });
+ // Optional uint256 fee = i_ccipRouter.getFee(destChainSelector, message);
+ // Can decide if fee is acceptable.
+ // address(this) must have sufficient feeToken or the send will revert.
+ bytes32 messageId = IRouterClient(i_ccipRouter).ccipSend(destChainSelector, message);
+ emit MessageSent(messageId);
+ }
+
+ modifier validChain(uint64 chainSelector) {
+ if (s_chains[chainSelector].length == 0) revert InvalidChain(chainSelector);
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/CCIPReceiver.sol b/contracts/src/v0.8/ccip/applications/CCIPReceiver.sol
new file mode 100644
index 00000000000..7011f814de7
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/CCIPReceiver.sol
@@ -0,0 +1,59 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IAny2EVMMessageReceiver} from "../interfaces/IAny2EVMMessageReceiver.sol";
+
+import {Client} from "../libraries/Client.sol";
+
+import {IERC165} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+
+/// @title CCIPReceiver - Base contract for CCIP applications that can receive messages.
+abstract contract CCIPReceiver is IAny2EVMMessageReceiver, IERC165 {
+ address internal immutable i_ccipRouter;
+
+ constructor(address router) {
+ if (router == address(0)) revert InvalidRouter(address(0));
+ i_ccipRouter = router;
+ }
+
+ /// @notice IERC165 supports an interfaceId
+ /// @param interfaceId The interfaceId to check
+ /// @return true if the interfaceId is supported
+ /// @dev Should indicate whether the contract implements IAny2EVMMessageReceiver
+ /// e.g. return interfaceId == type(IAny2EVMMessageReceiver).interfaceId || interfaceId == type(IERC165).interfaceId
+ /// This allows CCIP to check if ccipReceive is available before calling it.
+ /// If this returns false or reverts, only tokens are transferred to the receiver.
+ /// If this returns true, tokens are transferred and ccipReceive is called atomically.
+ /// Additionally, if the receiver address does not have code associated with
+ /// it at the time of execution (EXTCODESIZE returns 0), only tokens will be transferred.
+ function supportsInterface(bytes4 interfaceId) public view virtual override returns (bool) {
+ return interfaceId == type(IAny2EVMMessageReceiver).interfaceId || interfaceId == type(IERC165).interfaceId;
+ }
+
+ /// @inheritdoc IAny2EVMMessageReceiver
+ function ccipReceive(Client.Any2EVMMessage calldata message) external virtual override onlyRouter {
+ _ccipReceive(message);
+ }
+
+ /// @notice Override this function in your implementation.
+ /// @param message Any2EVMMessage
+ function _ccipReceive(Client.Any2EVMMessage memory message) internal virtual;
+
+ /////////////////////////////////////////////////////////////////////
+ // Plumbing
+ /////////////////////////////////////////////////////////////////////
+
+ /// @notice Return the current router
+ /// @return CCIP router address
+ function getRouter() public view virtual returns (address) {
+ return address(i_ccipRouter);
+ }
+
+ error InvalidRouter(address router);
+
+ /// @dev only calls from the set router are accepted.
+ modifier onlyRouter() {
+ if (msg.sender != getRouter()) revert InvalidRouter(msg.sender);
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/DefensiveExample.sol b/contracts/src/v0.8/ccip/applications/DefensiveExample.sol
new file mode 100644
index 00000000000..54e1e809465
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/DefensiveExample.sol
@@ -0,0 +1,117 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IRouterClient} from "../interfaces/IRouterClient.sol";
+
+import {Client} from "../libraries/Client.sol";
+import {CCIPClientExample} from "./CCIPClientExample.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+import {EnumerableMap} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableMap.sol";
+
+contract DefensiveExample is CCIPClientExample {
+ using EnumerableMap for EnumerableMap.Bytes32ToUintMap;
+ using SafeERC20 for IERC20;
+
+ error OnlySelf();
+ error ErrorCase();
+ error MessageNotFailed(bytes32 messageId);
+
+ event MessageFailed(bytes32 indexed messageId, bytes reason);
+ event MessageSucceeded(bytes32 indexed messageId);
+ event MessageRecovered(bytes32 indexed messageId);
+
+ // Example error code, could have many different error codes.
+ enum ErrorCode {
+ // RESOLVED is first so that the default value is resolved.
+ RESOLVED,
+ // Could have any number of error codes here.
+ BASIC
+ }
+
+ // The message contents of failed messages are stored here.
+ mapping(bytes32 messageId => Client.Any2EVMMessage contents) public s_messageContents;
+
+ // Contains failed messages and their state.
+ EnumerableMap.Bytes32ToUintMap internal s_failedMessages;
+
+ // This is used to simulate a revert in the processMessage function.
+ bool internal s_simRevert = false;
+
+ constructor(IRouterClient router, IERC20 feeToken) CCIPClientExample(router, feeToken) {}
+
+ /// @notice The entrypoint for the CCIP router to call. This function should
+ /// never revert, all errors should be handled internally in this contract.
+ /// @param message The message to process.
+ /// @dev Extremely important to ensure only router calls this.
+ function ccipReceive(Client.Any2EVMMessage calldata message)
+ external
+ override
+ onlyRouter
+ validChain(message.sourceChainSelector)
+ {
+ try this.processMessage(message) {}
+ catch (bytes memory err) {
+ // Could set different error codes based on the caught error. Each could be
+ // handled differently.
+ s_failedMessages.set(message.messageId, uint256(ErrorCode.BASIC));
+ s_messageContents[message.messageId] = message;
+ // Don't revert so CCIP doesn't revert. Emit event instead.
+ // The message can be retried later without having to do manual execution of CCIP.
+ emit MessageFailed(message.messageId, err);
+ return;
+ }
+ emit MessageSucceeded(message.messageId);
+ }
+
+ /// @notice This function the entrypoint for this contract to process messages.
+ /// @param message The message to process.
+ /// @dev This example just sends the tokens to the owner of this contracts. More
+ /// interesting functions could be implemented.
+ /// @dev It has to be external because of the try/catch.
+ function processMessage(Client.Any2EVMMessage calldata message)
+ external
+ onlySelf
+ validChain(message.sourceChainSelector)
+ {
+ // Simulate a revert
+ if (s_simRevert) revert ErrorCase();
+
+ // Send tokens to the owner
+ for (uint256 i = 0; i < message.destTokenAmounts.length; ++i) {
+ IERC20(message.destTokenAmounts[i].token).safeTransfer(owner(), message.destTokenAmounts[i].amount);
+ }
+ // Do other things that might revert
+ }
+
+ /// @notice This function is callable by the owner when a message has failed
+ /// to unblock the tokens that are associated with that message.
+ /// @dev This function is only callable by the owner.
+ function retryFailedMessage(bytes32 messageId, address tokenReceiver) external onlyOwner {
+ if (s_failedMessages.get(messageId) != uint256(ErrorCode.BASIC)) revert MessageNotFailed(messageId);
+ // Set the error code to 0 to disallow reentry and retry the same failed message
+ // multiple times.
+ s_failedMessages.set(messageId, uint256(ErrorCode.RESOLVED));
+
+ // Do stuff to retry message, potentially just releasing the associated tokens
+ Client.Any2EVMMessage memory message = s_messageContents[messageId];
+
+ // send the tokens to the receiver as escape hatch
+ for (uint256 i = 0; i < message.destTokenAmounts.length; ++i) {
+ IERC20(message.destTokenAmounts[i].token).safeTransfer(tokenReceiver, message.destTokenAmounts[i].amount);
+ }
+
+ emit MessageRecovered(messageId);
+ }
+
+ // An example function to demonstrate recovery
+ function setSimRevert(bool simRevert) external onlyOwner {
+ s_simRevert = simRevert;
+ }
+
+ modifier onlySelf() {
+ if (msg.sender != address(this)) revert OnlySelf();
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/EtherSenderReceiver.sol b/contracts/src/v0.8/ccip/applications/EtherSenderReceiver.sol
new file mode 100644
index 00000000000..ce8ed1ff7a0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/EtherSenderReceiver.sol
@@ -0,0 +1,180 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+
+import {IRouterClient} from "../interfaces/IRouterClient.sol";
+import {IWrappedNative} from "../interfaces/IWrappedNative.sol";
+
+import {Client} from "./../libraries/Client.sol";
+import {CCIPReceiver} from "./CCIPReceiver.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+//solhint-disable interface-starts-with-i
+interface CCIPRouter {
+ function getWrappedNative() external view returns (address);
+}
+
+/// @notice A contract that can send raw ether cross-chain using CCIP.
+/// Since CCIP only supports ERC-20 token transfers, this contract accepts
+/// normal ether, wraps it, and uses CCIP to send it cross-chain.
+/// On the receiving side, the wrapped ether is unwrapped and sent to the final receiver.
+/// @notice This contract only supports chains where the wrapped native contract
+/// is the WETH contract (i.e not WMATIC, or WAVAX, etc.). This is because the
+/// receiving contract will always unwrap the ether using it's local wrapped native contract.
+/// @dev This contract is both a sender and a receiver. This same contract can be
+/// deployed on source and destination chains to facilitate cross-chain ether transfers
+/// and act as a sender and a receiver.
+/// @dev This contract is intentionally ownerless and permissionless. This contract
+/// will never hold any excess funds, native or otherwise, when used correctly.
+contract EtherSenderReceiver is CCIPReceiver, ITypeAndVersion {
+ using SafeERC20 for IERC20;
+
+ error InvalidTokenAmounts(uint256 gotAmounts);
+ error InvalidToken(address gotToken, address expectedToken);
+ error TokenAmountNotEqualToMsgValue(uint256 gotAmount, uint256 msgValue);
+
+ string public constant override typeAndVersion = "EtherSenderReceiver 1.5.0";
+
+ /// @notice The wrapped native token address.
+ /// @dev If the wrapped native token address changes on the router, this contract will need to be redeployed.
+ IWrappedNative public immutable i_weth;
+
+ /// @param router The CCIP router address.
+ constructor(address router) CCIPReceiver(router) {
+ i_weth = IWrappedNative(CCIPRouter(router).getWrappedNative());
+ i_weth.approve(router, type(uint256).max);
+ }
+
+ /// @notice Need this in order to unwrap correctly.
+ receive() external payable {}
+
+ /// @notice Get the fee for sending a message to a destination chain.
+ /// This is mirrored from the router for convenience, construct the appropriate
+ /// message and get it's fee.
+ /// @param destinationChainSelector The destination chainSelector
+ /// @param message The cross-chain CCIP message including data and/or tokens
+ /// @return fee returns execution fee for the message
+ /// delivery to destination chain, denominated in the feeToken specified in the message.
+ /// @dev Reverts with appropriate reason upon invalid message.
+ function getFee(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external view returns (uint256 fee) {
+ Client.EVM2AnyMessage memory validatedMessage = _validatedMessage(message);
+
+ return IRouterClient(getRouter()).getFee(destinationChainSelector, validatedMessage);
+ }
+
+ /// @notice Send raw native tokens cross-chain.
+ /// @param destinationChainSelector The destination chain selector.
+ /// @param message The CCIP message with the following fields correctly set:
+ /// - bytes receiver: The _contract_ address on the destination chain that will receive the wrapped ether.
+ /// The caller must ensure that this contract address is correct, otherwise funds may be lost forever.
+ /// - address feeToken: The fee token address. Must be address(0) for native tokens, or a supported CCIP fee token otherwise (i.e, LINK token).
+ /// In the event a feeToken is set, we will transferFrom the caller the fee amount before sending the message, in order to forward them to the router.
+ /// - EVMTokenAmount[] tokenAmounts: The tokenAmounts array must contain a single element with the following fields:
+ /// - uint256 amount: The amount of ether to send.
+ /// There are a couple of cases here that depend on the fee token specified:
+ /// 1. If feeToken == address(0), the fee must be included in msg.value. Therefore tokenAmounts[0].amount must be less than msg.value,
+ /// and the difference will be used as the fee.
+ /// 2. If feeToken != address(0), the fee is not included in msg.value, and tokenAmounts[0].amount must be equal to msg.value.
+ /// these fees to the CCIP router.
+ /// @return messageId The CCIP message ID.
+ function ccipSend(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external payable returns (bytes32) {
+ _validateFeeToken(message);
+ Client.EVM2AnyMessage memory validatedMessage = _validatedMessage(message);
+
+ i_weth.deposit{value: validatedMessage.tokenAmounts[0].amount}();
+
+ uint256 fee = IRouterClient(getRouter()).getFee(destinationChainSelector, validatedMessage);
+ if (validatedMessage.feeToken != address(0)) {
+ // If the fee token is not native, we need to transfer the fee to this contract and re-approve it to the router.
+ // Its not possible to have any leftover tokens in this path because we transferFrom the exact fee that CCIP
+ // requires from the caller.
+ IERC20(validatedMessage.feeToken).safeTransferFrom(msg.sender, address(this), fee);
+
+ // We gave an infinite approval of weth to the router in the constructor.
+ if (validatedMessage.feeToken != address(i_weth)) {
+ IERC20(validatedMessage.feeToken).approve(getRouter(), fee);
+ }
+
+ return IRouterClient(getRouter()).ccipSend(destinationChainSelector, validatedMessage);
+ }
+
+ // We don't want to keep any excess ether in this contract, so we send over the entire address(this).balance as the fee.
+ // CCIP will revert if the fee is insufficient, so we don't need to check here.
+ return IRouterClient(getRouter()).ccipSend{value: address(this).balance}(destinationChainSelector, validatedMessage);
+ }
+
+ /// @notice Validate the message content.
+ /// @dev Only allows a single token to be sent. Always overwritten to be address(i_weth)
+ /// and receiver is always msg.sender.
+ function _validatedMessage(Client.EVM2AnyMessage calldata message)
+ internal
+ view
+ returns (Client.EVM2AnyMessage memory)
+ {
+ Client.EVM2AnyMessage memory validatedMessage = message;
+
+ if (validatedMessage.tokenAmounts.length != 1) {
+ revert InvalidTokenAmounts(validatedMessage.tokenAmounts.length);
+ }
+
+ validatedMessage.data = abi.encode(msg.sender);
+ validatedMessage.tokenAmounts[0].token = address(i_weth);
+
+ return validatedMessage;
+ }
+
+ function _validateFeeToken(Client.EVM2AnyMessage calldata message) internal view {
+ uint256 tokenAmount = message.tokenAmounts[0].amount;
+
+ if (message.feeToken != address(0)) {
+ // If the fee token is NOT native, then the token amount must be equal to msg.value.
+ // This is done to ensure that there is no leftover ether in this contract.
+ if (msg.value != tokenAmount) {
+ revert TokenAmountNotEqualToMsgValue(tokenAmount, msg.value);
+ }
+ }
+ }
+
+ /// @notice Receive the wrapped ether, unwrap it, and send it to the specified EOA in the data field.
+ /// @param message The CCIP message containing the wrapped ether amount and the final receiver.
+ /// @dev The code below should never revert if the message being is valid according
+ /// to the above _validatedMessage and _validateFeeToken functions.
+ function _ccipReceive(Client.Any2EVMMessage memory message) internal override {
+ address receiver = abi.decode(message.data, (address));
+
+ if (message.destTokenAmounts.length != 1) {
+ revert InvalidTokenAmounts(message.destTokenAmounts.length);
+ }
+
+ if (message.destTokenAmounts[0].token != address(i_weth)) {
+ revert InvalidToken(message.destTokenAmounts[0].token, address(i_weth));
+ }
+
+ uint256 tokenAmount = message.destTokenAmounts[0].amount;
+ i_weth.withdraw(tokenAmount);
+
+ // it is possible that the below call may fail if receiver.code.length > 0 and the contract
+ // doesn't e.g have a receive() or a fallback() function.
+ (bool success,) = payable(receiver).call{value: tokenAmount}("");
+ if (!success) {
+ // We have a few options here:
+ // 1. Revert: this is bad generally because it may mean that these tokens are stuck.
+ // 2. Store the tokens in a mapping and allow the user to withdraw them with another tx.
+ // 3. Send WETH to the receiver address.
+ // We opt for (3) here because at least the receiver will have the funds and can unwrap them if needed.
+ // However it is worth noting that if receiver is actually a contract AND the contract _cannot_ withdraw
+ // the WETH, then the WETH will be stuck in this contract.
+ i_weth.deposit{value: tokenAmount}();
+ i_weth.transfer(receiver, tokenAmount);
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/PingPongDemo.sol b/contracts/src/v0.8/ccip/applications/PingPongDemo.sol
new file mode 100644
index 00000000000..423fdc45467
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/PingPongDemo.sol
@@ -0,0 +1,102 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IRouterClient} from "../interfaces/IRouterClient.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {Client} from "../libraries/Client.sol";
+import {CCIPReceiver} from "./CCIPReceiver.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+/// @title PingPongDemo - A simple ping-pong contract for demonstrating cross-chain communication
+contract PingPongDemo is CCIPReceiver, OwnerIsCreator, ITypeAndVersion {
+ event Ping(uint256 pingPongCount);
+ event Pong(uint256 pingPongCount);
+
+ // The chain ID of the counterpart ping pong contract
+ uint64 internal s_counterpartChainSelector;
+ // The contract address of the counterpart ping pong contract
+ address internal s_counterpartAddress;
+ // Pause ping-ponging
+ bool private s_isPaused;
+ // The fee token used to pay for CCIP transactions
+ IERC20 internal s_feeToken;
+
+ constructor(address router, IERC20 feeToken) CCIPReceiver(router) {
+ s_isPaused = false;
+ s_feeToken = feeToken;
+ s_feeToken.approve(address(router), type(uint256).max);
+ }
+
+ function typeAndVersion() external pure virtual returns (string memory) {
+ return "PingPongDemo 1.2.0";
+ }
+
+ function setCounterpart(uint64 counterpartChainSelector, address counterpartAddress) external onlyOwner {
+ s_counterpartChainSelector = counterpartChainSelector;
+ s_counterpartAddress = counterpartAddress;
+ }
+
+ function startPingPong() external onlyOwner {
+ s_isPaused = false;
+ _respond(1);
+ }
+
+ function _respond(uint256 pingPongCount) internal virtual {
+ if (pingPongCount & 1 == 1) {
+ emit Ping(pingPongCount);
+ } else {
+ emit Pong(pingPongCount);
+ }
+ bytes memory data = abi.encode(pingPongCount);
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(s_counterpartAddress),
+ data: data,
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ extraArgs: "",
+ feeToken: address(s_feeToken)
+ });
+ IRouterClient(getRouter()).ccipSend(s_counterpartChainSelector, message);
+ }
+
+ function _ccipReceive(Client.Any2EVMMessage memory message) internal override {
+ uint256 pingPongCount = abi.decode(message.data, (uint256));
+ if (!s_isPaused) {
+ _respond(pingPongCount + 1);
+ }
+ }
+
+ /////////////////////////////////////////////////////////////////////
+ // Plumbing
+ /////////////////////////////////////////////////////////////////////
+
+ function getCounterpartChainSelector() external view returns (uint64) {
+ return s_counterpartChainSelector;
+ }
+
+ function setCounterpartChainSelector(uint64 chainSelector) external onlyOwner {
+ s_counterpartChainSelector = chainSelector;
+ }
+
+ function getCounterpartAddress() external view returns (address) {
+ return s_counterpartAddress;
+ }
+
+ function getFeeToken() external view returns (IERC20) {
+ return s_feeToken;
+ }
+
+ function setCounterpartAddress(address addr) external onlyOwner {
+ s_counterpartAddress = addr;
+ }
+
+ function isPaused() external view returns (bool) {
+ return s_isPaused;
+ }
+
+ function setPaused(bool pause) external onlyOwner {
+ s_isPaused = pause;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/SelfFundedPingPong.sol b/contracts/src/v0.8/ccip/applications/SelfFundedPingPong.sol
new file mode 100644
index 00000000000..80bc7bb24ab
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/SelfFundedPingPong.sol
@@ -0,0 +1,67 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Router} from "../Router.sol";
+import {Client} from "../libraries/Client.sol";
+import {EVM2EVMOnRamp} from "../onRamp/EVM2EVMOnRamp.sol";
+import {PingPongDemo} from "./PingPongDemo.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract SelfFundedPingPong is PingPongDemo {
+ string public constant override typeAndVersion = "SelfFundedPingPong 1.2.0";
+
+ event Funded();
+ event CountIncrBeforeFundingSet(uint8 countIncrBeforeFunding);
+
+ // Defines the increase in ping pong count before self-funding is attempted.
+ // Set to 0 to disable auto-funding, auto-funding only works for ping-pongs that are set as NOPs in the onRamp.
+ uint8 private s_countIncrBeforeFunding;
+
+ constructor(address router, IERC20 feeToken, uint8 roundTripsBeforeFunding) PingPongDemo(router, feeToken) {
+ // PingPong count increases by 2 for each round trip.
+ s_countIncrBeforeFunding = roundTripsBeforeFunding * 2;
+ }
+
+ function _respond(uint256 pingPongCount) internal override {
+ if (pingPongCount & 1 == 1) {
+ emit Ping(pingPongCount);
+ } else {
+ emit Pong(pingPongCount);
+ }
+
+ fundPingPong(pingPongCount);
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(s_counterpartAddress),
+ data: abi.encode(pingPongCount),
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ extraArgs: "",
+ feeToken: address(s_feeToken)
+ });
+ Router(getRouter()).ccipSend(s_counterpartChainSelector, message);
+ }
+
+ /// @notice A function that is responsible for funding this contract.
+ /// The contract can only be funded if it is set as a nop in the target onRamp.
+ /// In case your contract is not a nop you can prevent this function from being called by setting s_countIncrBeforeFunding=0.
+ function fundPingPong(uint256 pingPongCount) public {
+ // If selfFunding is disabled, or ping pong count has not reached s_countIncrPerFunding, do not attempt funding.
+ if (s_countIncrBeforeFunding == 0 || pingPongCount < s_countIncrBeforeFunding) return;
+
+ // Ping pong on one side will always be even, one side will always to odd.
+ if (pingPongCount % s_countIncrBeforeFunding <= 1) {
+ EVM2EVMOnRamp(Router(getRouter()).getOnRamp(s_counterpartChainSelector)).payNops();
+ emit Funded();
+ }
+ }
+
+ function getCountIncrBeforeFunding() external view returns (uint8) {
+ return s_countIncrBeforeFunding;
+ }
+
+ function setCountIncrBeforeFunding(uint8 countIncrBeforeFunding) external onlyOwner {
+ s_countIncrBeforeFunding = countIncrBeforeFunding;
+ emit CountIncrBeforeFundingSet(countIncrBeforeFunding);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/applications/TokenProxy.sol b/contracts/src/v0.8/ccip/applications/TokenProxy.sol
new file mode 100644
index 00000000000..6fd26c076bc
--- /dev/null
+++ b/contracts/src/v0.8/ccip/applications/TokenProxy.sol
@@ -0,0 +1,87 @@
+// SPDX-License-Identifier: MIT
+pragma solidity 0.8.24;
+
+import {IRouterClient} from "../interfaces/IRouterClient.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {Client} from "../libraries/Client.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+contract TokenProxy is OwnerIsCreator {
+ using SafeERC20 for IERC20;
+
+ error InvalidToken();
+ error NoDataAllowed();
+ error GasShouldBeZero();
+
+ /// @notice The CCIP router contract
+ IRouterClient internal immutable i_ccipRouter;
+ /// @notice Only this token is allowed to be sent using this proxy
+ address internal immutable i_token;
+
+ constructor(address router, address token) OwnerIsCreator() {
+ i_ccipRouter = IRouterClient(router);
+ i_token = token;
+ // Approve the router to spend an unlimited amount of tokens to reduce
+ // gas cost per tx.
+ IERC20(token).approve(router, type(uint256).max);
+ }
+
+ /// @notice Simply forwards the request to the CCIP router and returns the result.
+ /// @param destinationChainSelector The destination chainSelector
+ /// @param message The cross-chain CCIP message including data and/or tokens
+ /// @return fee returns execution fee for the message delivery to destination chain,
+ /// denominated in the feeToken specified in the message.
+ /// @dev Reverts with appropriate reason upon invalid message.
+ function getFee(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external view returns (uint256 fee) {
+ _validateMessage(message);
+ return i_ccipRouter.getFee(destinationChainSelector, message);
+ }
+
+ /// @notice Validates the message content, forwards it to the CCIP router and returns the result.
+ function ccipSend(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external payable returns (bytes32 messageId) {
+ _validateMessage(message);
+ if (message.feeToken != address(0)) {
+ // This path is probably warmed up already so the extra cost isn't too bad.
+ uint256 feeAmount = i_ccipRouter.getFee(destinationChainSelector, message);
+ IERC20(message.feeToken).safeTransferFrom(msg.sender, address(this), feeAmount);
+ IERC20(message.feeToken).approve(address(i_ccipRouter), feeAmount);
+ }
+
+ // Transfer the tokens from the sender to this contract.
+ IERC20(message.tokenAmounts[0].token).transferFrom(msg.sender, address(this), message.tokenAmounts[0].amount);
+
+ return i_ccipRouter.ccipSend{value: msg.value}(destinationChainSelector, message);
+ }
+
+ /// @notice Validates the message content.
+ /// @dev Only allows a single token to be sent, and no data.
+ function _validateMessage(Client.EVM2AnyMessage calldata message) internal view {
+ if (message.tokenAmounts.length != 1 || message.tokenAmounts[0].token != i_token) revert InvalidToken();
+ if (message.data.length > 0) revert NoDataAllowed();
+
+ if (message.extraArgs.length == 0 || bytes4(message.extraArgs) != Client.EVM_EXTRA_ARGS_V1_TAG) {
+ revert GasShouldBeZero();
+ }
+
+ if (abi.decode(message.extraArgs[4:], (Client.EVMExtraArgsV1)).gasLimit != 0) revert GasShouldBeZero();
+ }
+
+ /// @notice Returns the CCIP router contract.
+ function getRouter() external view returns (IRouterClient) {
+ return i_ccipRouter;
+ }
+
+ /// @notice Returns the token that this proxy is allowed to send.
+ function getToken() external view returns (address) {
+ return i_token;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/capability/CCIPConfig.sol b/contracts/src/v0.8/ccip/capability/CCIPConfig.sol
new file mode 100644
index 00000000000..40b7a4a2f93
--- /dev/null
+++ b/contracts/src/v0.8/ccip/capability/CCIPConfig.sol
@@ -0,0 +1,476 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ICapabilityConfiguration} from "../../keystone/interfaces/ICapabilityConfiguration.sol";
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {ICapabilitiesRegistry} from "./interfaces/ICapabilitiesRegistry.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+
+import {SortedSetValidationUtil} from "../../shared/util/SortedSetValidationUtil.sol";
+import {Internal} from "../libraries/Internal.sol";
+import {CCIPConfigTypes} from "./libraries/CCIPConfigTypes.sol";
+
+import {IERC165} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/interfaces/IERC165.sol";
+import {EnumerableSet} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice CCIPConfig stores the configuration for the CCIP capability.
+/// We have two classes of configuration: chain configuration and DON (in the CapabilitiesRegistry sense) configuration.
+/// Each chain will have a single configuration which includes information like the router address.
+/// Each CR DON will have up to four configurations: for each of (commit, exec), one blue and one green configuration.
+/// This is done in order to achieve "blue-green" deployments.
+contract CCIPConfig is ITypeAndVersion, ICapabilityConfiguration, OwnerIsCreator, IERC165 {
+ using EnumerableSet for EnumerableSet.UintSet;
+
+ /// @notice Emitted when a chain's configuration is set.
+ /// @param chainSelector The chain selector.
+ /// @param chainConfig The chain configuration.
+ event ChainConfigSet(uint64 chainSelector, CCIPConfigTypes.ChainConfig chainConfig);
+
+ /// @notice Emitted when a chain's configuration is removed.
+ /// @param chainSelector The chain selector.
+ event ChainConfigRemoved(uint64 chainSelector);
+
+ error ChainConfigNotSetForChain(uint64 chainSelector);
+ error NodeNotInRegistry(bytes32 p2pId);
+ error OnlyCapabilitiesRegistryCanCall();
+ error ChainSelectorNotFound(uint64 chainSelector);
+ error ChainSelectorNotSet();
+ error TooManyOCR3Configs();
+ error TooManySigners();
+ error TooManyTransmitters();
+ error TooManyBootstrapP2PIds();
+ error P2PIdsLengthNotMatching(uint256 p2pIdsLength, uint256 signersLength, uint256 transmittersLength);
+ error NotEnoughTransmitters(uint256 got, uint256 minimum);
+ error FMustBePositive();
+ error FChainMustBePositive();
+ error FTooHigh();
+ error InvalidPluginType();
+ error OfframpAddressCannotBeZero();
+ error InvalidConfigLength(uint256 length);
+ error InvalidConfigStateTransition(
+ CCIPConfigTypes.ConfigState currentState, CCIPConfigTypes.ConfigState proposedState
+ );
+ error NonExistentConfigTransition();
+ error WrongConfigCount(uint64 got, uint64 expected);
+ error WrongConfigDigest(bytes32 got, bytes32 expected);
+ error WrongConfigDigestBlueGreen(bytes32 got, bytes32 expected);
+
+ /// @notice Type and version override.
+ string public constant override typeAndVersion = "CCIPConfig 1.6.0-dev";
+
+ /// @notice The canonical capabilities registry address.
+ address internal immutable i_capabilitiesRegistry;
+
+ /// @notice chain configuration for each chain that CCIP is deployed on.
+ mapping(uint64 chainSelector => CCIPConfigTypes.ChainConfig chainConfig) internal s_chainConfigurations;
+
+ /// @notice All chains that are configured.
+ EnumerableSet.UintSet internal s_remoteChainSelectors;
+
+ /// @notice OCR3 configurations for each DON.
+ /// Each CR DON will have a commit and execution configuration.
+ /// This means that a DON can have up to 4 configurations, since we are implementing blue/green deployments.
+ mapping(
+ uint32 donId => mapping(Internal.OCRPluginType pluginType => CCIPConfigTypes.OCR3ConfigWithMeta[] ocr3Configs)
+ ) internal s_ocr3Configs;
+
+ /// @notice The DONs that have been configured.
+ EnumerableSet.UintSet internal s_donIds;
+
+ uint8 internal constant MAX_OCR3_CONFIGS_PER_PLUGIN = 2;
+ uint8 internal constant MAX_OCR3_CONFIGS_PER_DON = 4;
+ uint8 internal constant MAX_NUM_ORACLES = 31;
+
+ /// @param capabilitiesRegistry the canonical capabilities registry address.
+ constructor(address capabilitiesRegistry) {
+ i_capabilitiesRegistry = capabilitiesRegistry;
+ }
+
+ /// @inheritdoc IERC165
+ function supportsInterface(bytes4 interfaceId) external pure override returns (bool) {
+ return interfaceId == type(ICapabilityConfiguration).interfaceId || interfaceId == type(IERC165).interfaceId;
+ }
+
+ // ================================================================
+ // │ Config Getters │
+ // ================================================================
+
+ /// @notice Returns all the chain configurations.
+ /// @return The chain configurations.
+ // TODO: will this eventually hit the RPC max response size limit?
+ function getAllChainConfigs() external view returns (CCIPConfigTypes.ChainConfigInfo[] memory) {
+ uint256[] memory chainSelectors = s_remoteChainSelectors.values();
+ CCIPConfigTypes.ChainConfigInfo[] memory chainConfigs =
+ new CCIPConfigTypes.ChainConfigInfo[](s_remoteChainSelectors.length());
+ for (uint256 i = 0; i < chainSelectors.length; ++i) {
+ uint64 chainSelector = uint64(chainSelectors[i]);
+ chainConfigs[i] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: chainSelector,
+ chainConfig: s_chainConfigurations[chainSelector]
+ });
+ }
+ return chainConfigs;
+ }
+
+ /// @notice Returns the OCR configuration for the given don ID and plugin type.
+ /// @param donId The DON ID.
+ /// @param pluginType The plugin type.
+ /// @return The OCR3 configurations, up to 2 (blue and green).
+ function getOCRConfig(
+ uint32 donId,
+ Internal.OCRPluginType pluginType
+ ) external view returns (CCIPConfigTypes.OCR3ConfigWithMeta[] memory) {
+ return s_ocr3Configs[donId][pluginType];
+ }
+
+ // ================================================================
+ // │ Capability Configuration │
+ // ================================================================
+
+ /// @inheritdoc ICapabilityConfiguration
+ /// @dev The CCIP capability will fetch the configuration needed directly from this contract.
+ /// The offchain syncer will call this function, however, so its important that it doesn't revert.
+ function getCapabilityConfiguration(uint32 /* donId */ ) external pure override returns (bytes memory configuration) {
+ return bytes("");
+ }
+
+ /// @notice Called by the registry prior to the config being set for a particular DON.
+ function beforeCapabilityConfigSet(
+ bytes32[] calldata, /* nodes */
+ bytes calldata config,
+ uint64, /* configCount */
+ uint32 donId
+ ) external override {
+ if (msg.sender != i_capabilitiesRegistry) {
+ revert OnlyCapabilitiesRegistryCanCall();
+ }
+
+ CCIPConfigTypes.OCR3Config[] memory ocr3Configs = abi.decode(config, (CCIPConfigTypes.OCR3Config[]));
+ (CCIPConfigTypes.OCR3Config[] memory commitConfigs, CCIPConfigTypes.OCR3Config[] memory execConfigs) =
+ _groupByPluginType(ocr3Configs);
+ if (commitConfigs.length > 0) {
+ _updatePluginConfig(donId, Internal.OCRPluginType.Commit, commitConfigs);
+ }
+ if (execConfigs.length > 0) {
+ _updatePluginConfig(donId, Internal.OCRPluginType.Execution, execConfigs);
+ }
+ }
+
+ function _updatePluginConfig(
+ uint32 donId,
+ Internal.OCRPluginType pluginType,
+ CCIPConfigTypes.OCR3Config[] memory newConfig
+ ) internal {
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = s_ocr3Configs[donId][pluginType];
+
+ // Validate the state transition being proposed, which is implicitly defined by the combination
+ // of lengths of the current and new configurations.
+ CCIPConfigTypes.ConfigState currentState = _stateFromConfigLength(currentConfig.length);
+ CCIPConfigTypes.ConfigState proposedState = _stateFromConfigLength(newConfig.length);
+ _validateConfigStateTransition(currentState, proposedState);
+
+ // Build the new configuration with metadata and validate that the transition is valid.
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta =
+ _computeNewConfigWithMeta(donId, currentConfig, newConfig, currentState, proposedState);
+ _validateConfigTransition(currentConfig, newConfigWithMeta);
+
+ // Update contract state with new configuration if its valid.
+ // We won't run out of gas from this delete since the array is at most 2 elements long.
+ delete s_ocr3Configs[donId][pluginType];
+ for (uint256 i = 0; i < newConfigWithMeta.length; ++i) {
+ s_ocr3Configs[donId][pluginType].push(newConfigWithMeta[i]);
+ }
+ }
+
+ // ================================================================
+ // │ Config State Machine │
+ // ================================================================
+
+ /// @notice Determine the config state of the configuration from the length of the config.
+ /// @param configLen The length of the configuration.
+ /// @return The config state.
+ function _stateFromConfigLength(uint256 configLen) internal pure returns (CCIPConfigTypes.ConfigState) {
+ if (configLen > 2) {
+ revert InvalidConfigLength(configLen);
+ }
+ return CCIPConfigTypes.ConfigState(configLen);
+ }
+
+ // the only valid state transitions are the following:
+ // init -> running (first ever config)
+ // running -> staging (blue/green proposal)
+ // staging -> running (promotion)
+ // everything else is invalid and should revert.
+ function _validateConfigStateTransition(
+ CCIPConfigTypes.ConfigState currentState,
+ CCIPConfigTypes.ConfigState newState
+ ) internal pure {
+ // Calculate the difference between the new state and the current state
+ int256 stateDiff = int256(uint256(newState)) - int256(uint256(currentState));
+
+ // Check if the state transition is valid:
+ // Valid transitions:
+ // 1. currentState -> newState (where stateDiff == 1)
+ // e.g., init -> running or running -> staging
+ // 2. staging -> running (where stateDiff == -1)
+ if (stateDiff == 1 || (stateDiff == -1 && currentState == CCIPConfigTypes.ConfigState.Staging)) {
+ return;
+ }
+ revert InvalidConfigStateTransition(currentState, newState);
+ }
+
+ function _validateConfigTransition(
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig,
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta
+ ) internal pure {
+ uint256 currentConfigLen = currentConfig.length;
+ uint256 newConfigLen = newConfigWithMeta.length;
+ if (currentConfigLen == 0 && newConfigLen == 1) {
+ // Config counts always must start at 1 for the first ever config.
+ if (newConfigWithMeta[0].configCount != 1) {
+ revert WrongConfigCount(newConfigWithMeta[0].configCount, 1);
+ }
+ return;
+ }
+
+ if (currentConfigLen == 1 && newConfigLen == 2) {
+ // On a blue/green proposal:
+ // * the config digest of the blue config must remain unchanged.
+ // * the green config count must be the blue config count + 1.
+ if (newConfigWithMeta[0].configDigest != currentConfig[0].configDigest) {
+ revert WrongConfigDigestBlueGreen(newConfigWithMeta[0].configDigest, currentConfig[0].configDigest);
+ }
+ if (newConfigWithMeta[1].configCount != currentConfig[0].configCount + 1) {
+ revert WrongConfigCount(newConfigWithMeta[1].configCount, currentConfig[0].configCount + 1);
+ }
+ return;
+ }
+
+ if (currentConfigLen == 2 && newConfigLen == 1) {
+ // On a promotion, the green config digest must become the blue config digest.
+ if (newConfigWithMeta[0].configDigest != currentConfig[1].configDigest) {
+ revert WrongConfigDigest(newConfigWithMeta[0].configDigest, currentConfig[1].configDigest);
+ }
+ return;
+ }
+
+ revert NonExistentConfigTransition();
+ }
+
+ /// @notice Computes a new configuration with metadata based on the current configuration and the new configuration.
+ /// @param donId The DON ID.
+ /// @param currentConfig The current configuration, including metadata.
+ /// @param newConfig The new configuration, without metadata.
+ /// @param currentState The current state of the configuration.
+ /// @param newState The new state of the configuration.
+ /// @return The new configuration with metadata.
+ function _computeNewConfigWithMeta(
+ uint32 donId,
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig,
+ CCIPConfigTypes.OCR3Config[] memory newConfig,
+ CCIPConfigTypes.ConfigState currentState,
+ CCIPConfigTypes.ConfigState newState
+ ) internal view returns (CCIPConfigTypes.OCR3ConfigWithMeta[] memory) {
+ uint64[] memory configCounts = new uint64[](newConfig.length);
+
+ // Set config counts based on the only valid state transitions.
+ // Init -> Running (first ever config)
+ // Running -> Staging (blue/green proposal)
+ // Staging -> Running (promotion)
+ if (currentState == CCIPConfigTypes.ConfigState.Init && newState == CCIPConfigTypes.ConfigState.Running) {
+ // First ever config starts with config count == 1.
+ configCounts[0] = 1;
+ } else if (currentState == CCIPConfigTypes.ConfigState.Running && newState == CCIPConfigTypes.ConfigState.Staging) {
+ // On a blue/green proposal, the config count of the green config is the blue config count + 1.
+ configCounts[0] = currentConfig[0].configCount;
+ configCounts[1] = currentConfig[0].configCount + 1;
+ } else if (currentState == CCIPConfigTypes.ConfigState.Staging && newState == CCIPConfigTypes.ConfigState.Running) {
+ // On a promotion, the config count of the green config becomes the blue config count.
+ configCounts[0] = currentConfig[1].configCount;
+ } else {
+ revert InvalidConfigStateTransition(currentState, newState);
+ }
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta =
+ new CCIPConfigTypes.OCR3ConfigWithMeta[](newConfig.length);
+ for (uint256 i = 0; i < configCounts.length; ++i) {
+ _validateConfig(newConfig[i]);
+ newConfigWithMeta[i] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ config: newConfig[i],
+ configCount: configCounts[i],
+ configDigest: _computeConfigDigest(donId, configCounts[i], newConfig[i])
+ });
+ }
+
+ return newConfigWithMeta;
+ }
+
+ /// @notice Group the OCR3 configurations by plugin type for further processing.
+ /// @param ocr3Configs The OCR3 configurations to group.
+ function _groupByPluginType(CCIPConfigTypes.OCR3Config[] memory ocr3Configs)
+ internal
+ pure
+ returns (CCIPConfigTypes.OCR3Config[] memory commitConfigs, CCIPConfigTypes.OCR3Config[] memory execConfigs)
+ {
+ if (ocr3Configs.length > MAX_OCR3_CONFIGS_PER_DON) {
+ revert TooManyOCR3Configs();
+ }
+
+ // Declare with size 2 since we have a maximum of two configs per plugin type (blue, green).
+ // If we have less we will adjust the length later using mstore.
+ // If the caller provides more than 2 configs per plugin type, we will revert due to out of bounds
+ // access in the for loop below.
+ commitConfigs = new CCIPConfigTypes.OCR3Config[](MAX_OCR3_CONFIGS_PER_PLUGIN);
+ execConfigs = new CCIPConfigTypes.OCR3Config[](MAX_OCR3_CONFIGS_PER_PLUGIN);
+ uint256 commitCount;
+ uint256 execCount;
+ for (uint256 i = 0; i < ocr3Configs.length; ++i) {
+ if (ocr3Configs[i].pluginType == Internal.OCRPluginType.Commit) {
+ commitConfigs[commitCount] = ocr3Configs[i];
+ ++commitCount;
+ } else {
+ execConfigs[execCount] = ocr3Configs[i];
+ ++execCount;
+ }
+ }
+
+ // Adjust the length of the arrays to the actual number of configs.
+ assembly {
+ mstore(commitConfigs, commitCount)
+ mstore(execConfigs, execCount)
+ }
+
+ return (commitConfigs, execConfigs);
+ }
+
+ function _validateConfig(CCIPConfigTypes.OCR3Config memory cfg) internal view {
+ if (cfg.chainSelector == 0) revert ChainSelectorNotSet();
+ if (cfg.pluginType != Internal.OCRPluginType.Commit && cfg.pluginType != Internal.OCRPluginType.Execution) {
+ revert InvalidPluginType();
+ }
+ // TODO: can we do more sophisticated validation than this?
+ if (cfg.offrampAddress.length == 0) revert OfframpAddressCannotBeZero();
+ if (!s_remoteChainSelectors.contains(cfg.chainSelector)) revert ChainSelectorNotFound(cfg.chainSelector);
+
+ // Some of these checks below are done in OCR2/3Base config validation, so we do them again here.
+ // Role DON OCR configs will have all the Role DON signers but only a subset of transmitters.
+ if (cfg.signers.length > MAX_NUM_ORACLES) revert TooManySigners();
+ if (cfg.transmitters.length > MAX_NUM_ORACLES) revert TooManyTransmitters();
+
+ // We check for chain config presence above, so fChain here must be non-zero.
+ uint256 minTransmittersLength = 3 * s_chainConfigurations[cfg.chainSelector].fChain + 1;
+ if (cfg.transmitters.length < minTransmittersLength) {
+ revert NotEnoughTransmitters(cfg.transmitters.length, minTransmittersLength);
+ }
+ if (cfg.F == 0) revert FMustBePositive();
+ if (cfg.signers.length <= 3 * cfg.F) revert FTooHigh();
+
+ if (cfg.p2pIds.length != cfg.signers.length || cfg.p2pIds.length != cfg.transmitters.length) {
+ revert P2PIdsLengthNotMatching(cfg.p2pIds.length, cfg.signers.length, cfg.transmitters.length);
+ }
+ if (cfg.bootstrapP2PIds.length > cfg.p2pIds.length) revert TooManyBootstrapP2PIds();
+
+ // check for duplicate p2p ids and bootstrapP2PIds.
+ // check that p2p ids in cfg.bootstrapP2PIds are included in cfg.p2pIds.
+ SortedSetValidationUtil._checkIsValidUniqueSubset(cfg.bootstrapP2PIds, cfg.p2pIds);
+
+ // Check that the readers are in the capabilities registry.
+ for (uint256 i = 0; i < cfg.signers.length; ++i) {
+ _ensureInRegistry(cfg.p2pIds[i]);
+ }
+ }
+
+ /// @notice Computes the digest of the provided configuration.
+ /// @dev In traditional OCR config digest computation, block.chainid and address(this) are used
+ /// in order to further domain separate the digest. We can't do that here since the digest will
+ /// be used on remote chains; so we use the chain selector instead of block.chainid. The don ID
+ /// replaces the address(this) in the traditional computation.
+ /// @param donId The DON ID.
+ /// @param configCount The configuration count.
+ /// @param ocr3Config The OCR3 configuration.
+ /// @return The computed digest.
+ function _computeConfigDigest(
+ uint32 donId,
+ uint64 configCount,
+ CCIPConfigTypes.OCR3Config memory ocr3Config
+ ) internal pure returns (bytes32) {
+ uint256 h = uint256(
+ keccak256(
+ abi.encode(
+ ocr3Config.chainSelector,
+ donId,
+ ocr3Config.pluginType,
+ ocr3Config.offrampAddress,
+ configCount,
+ ocr3Config.bootstrapP2PIds,
+ ocr3Config.p2pIds,
+ ocr3Config.signers,
+ ocr3Config.transmitters,
+ ocr3Config.F,
+ ocr3Config.offchainConfigVersion,
+ ocr3Config.offchainConfig
+ )
+ )
+ );
+ uint256 prefixMask = type(uint256).max << (256 - 16); // 0xFFFF00..00
+ uint256 prefix = 0x000a << (256 - 16); // 0x000a00..00
+ return bytes32((prefix & prefixMask) | (h & ~prefixMask));
+ }
+
+ // ================================================================
+ // │ Chain Configuration │
+ // ================================================================
+
+ /// @notice Sets and/or removes chain configurations.
+ /// @param chainSelectorRemoves The chain configurations to remove.
+ /// @param chainConfigAdds The chain configurations to add.
+ function applyChainConfigUpdates(
+ uint64[] calldata chainSelectorRemoves,
+ CCIPConfigTypes.ChainConfigInfo[] calldata chainConfigAdds
+ ) external onlyOwner {
+ // Process removals first.
+ for (uint256 i = 0; i < chainSelectorRemoves.length; ++i) {
+ // check if the chain selector is in s_remoteChainSelectors first.
+ if (!s_remoteChainSelectors.contains(chainSelectorRemoves[i])) {
+ revert ChainSelectorNotFound(chainSelectorRemoves[i]);
+ }
+
+ delete s_chainConfigurations[chainSelectorRemoves[i]];
+ s_remoteChainSelectors.remove(chainSelectorRemoves[i]);
+
+ emit ChainConfigRemoved(chainSelectorRemoves[i]);
+ }
+
+ // Process additions next.
+ for (uint256 i = 0; i < chainConfigAdds.length; ++i) {
+ CCIPConfigTypes.ChainConfig memory chainConfig = chainConfigAdds[i].chainConfig;
+ bytes32[] memory readers = chainConfig.readers;
+ uint64 chainSelector = chainConfigAdds[i].chainSelector;
+
+ // Verify that the provided readers are present in the capabilities registry.
+ for (uint256 j = 0; j < readers.length; j++) {
+ _ensureInRegistry(readers[j]);
+ }
+
+ // Verify that fChain is positive.
+ if (chainConfig.fChain == 0) {
+ revert FChainMustBePositive();
+ }
+
+ s_chainConfigurations[chainSelector] = chainConfig;
+ s_remoteChainSelectors.add(chainSelector);
+
+ emit ChainConfigSet(chainSelector, chainConfig);
+ }
+ }
+
+ /// @notice Helper function to ensure that a node is in the capabilities registry.
+ /// @param p2pId The P2P ID of the node to check.
+ function _ensureInRegistry(bytes32 p2pId) internal view {
+ ICapabilitiesRegistry.NodeInfo memory node = ICapabilitiesRegistry(i_capabilitiesRegistry).getNode(p2pId);
+ if (node.p2pId == bytes32("")) {
+ revert NodeNotInRegistry(p2pId);
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/capability/interfaces/ICapabilitiesRegistry.sol b/contracts/src/v0.8/ccip/capability/interfaces/ICapabilitiesRegistry.sol
new file mode 100644
index 00000000000..621c3686cfa
--- /dev/null
+++ b/contracts/src/v0.8/ccip/capability/interfaces/ICapabilitiesRegistry.sol
@@ -0,0 +1,31 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.24;
+
+interface ICapabilitiesRegistry {
+ struct NodeInfo {
+ /// @notice The id of the node operator that manages this node
+ uint32 nodeOperatorId;
+ /// @notice The number of times the node's configuration has been updated
+ uint32 configCount;
+ /// @notice The ID of the Workflow DON that the node belongs to. A node can
+ /// only belong to one DON that accepts Workflows.
+ uint32 workflowDONId;
+ /// @notice The signer address for application-layer message verification.
+ bytes32 signer;
+ /// @notice This is an Ed25519 public key that is used to identify a node.
+ /// This key is guaranteed to be unique in the CapabilitiesRegistry. It is
+ /// used to identify a node in the the P2P network.
+ bytes32 p2pId;
+ /// @notice The list of hashed capability IDs supported by the node
+ bytes32[] hashedCapabilityIds;
+ /// @notice The list of capabilities DON Ids supported by the node. A node
+ /// can belong to multiple capabilities DONs. This list does not include a
+ /// Workflow DON id if the node belongs to one.
+ uint256[] capabilitiesDONIds;
+ }
+
+ /// @notice Gets a node's data
+ /// @param p2pId The P2P ID of the node to query for
+ /// @return NodeInfo The node data
+ function getNode(bytes32 p2pId) external view returns (NodeInfo memory);
+}
diff --git a/contracts/src/v0.8/ccip/capability/interfaces/IOCR3ConfigEncoder.sol b/contracts/src/v0.8/ccip/capability/interfaces/IOCR3ConfigEncoder.sol
new file mode 100644
index 00000000000..6d0b0f72a5a
--- /dev/null
+++ b/contracts/src/v0.8/ccip/capability/interfaces/IOCR3ConfigEncoder.sol
@@ -0,0 +1,11 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {CCIPConfigTypes} from "../libraries/CCIPConfigTypes.sol";
+
+/// @dev This is so that we can generate gethwrappers and easily encode/decode OCR3Config
+/// in the offchain integration tests.
+interface IOCR3ConfigEncoder {
+ /// @dev Encodes an array of OCR3Config into a bytes array. For test usage only.
+ function exposeOCR3Config(CCIPConfigTypes.OCR3Config[] calldata config) external view returns (bytes memory);
+}
diff --git a/contracts/src/v0.8/ccip/capability/libraries/CCIPConfigTypes.sol b/contracts/src/v0.8/ccip/capability/libraries/CCIPConfigTypes.sol
new file mode 100644
index 00000000000..99adef84b10
--- /dev/null
+++ b/contracts/src/v0.8/ccip/capability/libraries/CCIPConfigTypes.sol
@@ -0,0 +1,57 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {Internal} from "../../libraries/Internal.sol";
+
+library CCIPConfigTypes {
+ /// @notice ConfigState indicates the state of the configuration.
+ /// A DON's configuration always starts out in the "Init" state - this is the starting state.
+ /// The only valid transition from "Init" is to the "Running" state - this is the first ever configuration.
+ /// The only valid transition from "Running" is to the "Staging" state - this is a blue/green proposal.
+ /// The only valid transition from "Staging" is back to the "Running" state - this is a promotion.
+ /// TODO: explain rollbacks?
+ enum ConfigState {
+ Init,
+ Running,
+ Staging
+ }
+
+ /// @notice Chain configuration.
+ /// Changes to chain configuration are detected out-of-band in plugins and decoded offchain.
+ struct ChainConfig {
+ bytes32[] readers; // The P2P IDs of the readers for the chain. These IDs must be registered in the capabilities registry.
+ uint8 fChain; // The fault tolerance parameter of the chain.
+ bytes config; // The chain configuration. This is kept intentionally opaque so as to add fields in the future if needed.
+ }
+
+ /// @notice Chain configuration information struct used in applyChainConfigUpdates and getAllChainConfigs.
+ struct ChainConfigInfo {
+ uint64 chainSelector;
+ ChainConfig chainConfig;
+ }
+
+ /// @notice OCR3 configuration.
+ struct OCR3Config {
+ Internal.OCRPluginType pluginType; // ────────╮ The plugin that the configuration is for.
+ uint64 chainSelector; // | The (remote) chain that the configuration is for.
+ uint8 F; // | The "big F" parameter for the role DON.
+ uint64 offchainConfigVersion; // ─────────────╯ The version of the offchain configuration.
+ bytes offrampAddress; // The remote chain offramp address.
+ // NOTE: bootstrapP2PIds and p2pIds should be sent as sorted sets
+ bytes32[] bootstrapP2PIds; // The bootstrap P2P IDs of the oracles that are part of the role DON.
+ // len(p2pIds) == len(signers) == len(transmitters) == 3 * F + 1
+ // NOTE: indexes matter here! The p2p ID at index i corresponds to the signer at index i and the transmitter at index i.
+ // This is crucial in order to build the oracle ID <-> peer ID mapping offchain.
+ bytes32[] p2pIds; // The P2P IDs of the oracles that are part of the role DON.
+ bytes[] signers; // The onchain signing keys of nodes in the don.
+ bytes[] transmitters; // The onchain transmitter keys of nodes in the don.
+ bytes offchainConfig; // The offchain configuration for the OCR3 protocol. Protobuf encoded.
+ }
+
+ /// @notice OCR3 configuration with metadata, specifically the config count and the config digest.
+ struct OCR3ConfigWithMeta {
+ OCR3Config config; // The OCR3 configuration.
+ uint64 configCount; // The config count used to compute the config digest.
+ bytes32 configDigest; // The config digest of the OCR3 configuration.
+ }
+}
diff --git a/contracts/src/v0.8/ccip/docs/multi-chain-overview-ocr3.png b/contracts/src/v0.8/ccip/docs/multi-chain-overview-ocr3.png
new file mode 100644
index 00000000000..39302619cb4
Binary files /dev/null and b/contracts/src/v0.8/ccip/docs/multi-chain-overview-ocr3.png differ
diff --git a/contracts/src/v0.8/ccip/docs/multi-chain-overview.drawio b/contracts/src/v0.8/ccip/docs/multi-chain-overview.drawio
new file mode 100644
index 00000000000..5743bf5182e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/docs/multi-chain-overview.drawio
@@ -0,0 +1,2060 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/contracts/src/v0.8/ccip/interfaces/IAny2EVMMessageReceiver.sol b/contracts/src/v0.8/ccip/interfaces/IAny2EVMMessageReceiver.sol
new file mode 100644
index 00000000000..6305311050d
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IAny2EVMMessageReceiver.sol
@@ -0,0 +1,15 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Client} from "../libraries/Client.sol";
+
+/// @notice Application contracts that intend to receive messages from
+/// the router should implement this interface.
+interface IAny2EVMMessageReceiver {
+ /// @notice Called by the Router to deliver a message.
+ /// If this reverts, any token transfers also revert. The message
+ /// will move to a FAILED state and become available for manual execution.
+ /// @param message CCIP Message
+ /// @dev Note ensure you check the msg.sender is the OffRampRouter
+ function ccipReceive(Client.Any2EVMMessage calldata message) external;
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IAny2EVMOffRamp.sol b/contracts/src/v0.8/ccip/interfaces/IAny2EVMOffRamp.sol
new file mode 100644
index 00000000000..1881dede2ee
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IAny2EVMOffRamp.sol
@@ -0,0 +1,9 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+interface IAny2EVMOffRamp {
+ /// @notice Returns the the current nonce for a receiver.
+ /// @param sender The sender address
+ /// @return nonce The nonce value belonging to the sender address.
+ function getSenderNonce(address sender) external view returns (uint64 nonce);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/ICommitStore.sol b/contracts/src/v0.8/ccip/interfaces/ICommitStore.sol
new file mode 100644
index 00000000000..1183eb277b8
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/ICommitStore.sol
@@ -0,0 +1,17 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+interface ICommitStore {
+ /// @notice Returns timestamp of when root was accepted or 0 if verification fails.
+ /// @dev This method uses a merkle tree within a merkle tree, with the hashedLeaves,
+ /// proofs and proofFlagBits being used to get the root of the inner tree.
+ /// This root is then used as the singular leaf of the outer tree.
+ function verify(
+ bytes32[] calldata hashedLeaves,
+ bytes32[] calldata proofs,
+ uint256 proofFlagBits
+ ) external view returns (uint256 timestamp);
+
+ /// @notice Returns the expected next sequence number
+ function getExpectedNextSequenceNumber() external view returns (uint64 sequenceNumber);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IEVM2AnyOnRamp.sol b/contracts/src/v0.8/ccip/interfaces/IEVM2AnyOnRamp.sol
new file mode 100644
index 00000000000..d657e148cb2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IEVM2AnyOnRamp.sol
@@ -0,0 +1,15 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IEVM2AnyOnRampClient} from "./IEVM2AnyOnRampClient.sol";
+
+interface IEVM2AnyOnRamp is IEVM2AnyOnRampClient {
+ /// @notice Gets the next sequence number to be used in the onRamp
+ /// @return the next sequence number to be used
+ function getExpectedNextSequenceNumber() external view returns (uint64);
+
+ /// @notice Get the next nonce for a given sender
+ /// @param sender The sender to get the nonce for
+ /// @return nonce The next nonce for the sender
+ function getSenderNonce(address sender) external view returns (uint64 nonce);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IEVM2AnyOnRampClient.sol b/contracts/src/v0.8/ccip/interfaces/IEVM2AnyOnRampClient.sol
new file mode 100644
index 00000000000..1744d6c2295
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IEVM2AnyOnRampClient.sol
@@ -0,0 +1,42 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IPoolV1} from "./IPool.sol";
+
+import {Client} from "../libraries/Client.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+interface IEVM2AnyOnRampClient {
+ /// @notice Get the fee for a given ccip message
+ /// @param destChainSelector The destination chain selector
+ /// @param message The message to calculate the cost for
+ /// @return fee The calculated fee
+ function getFee(uint64 destChainSelector, Client.EVM2AnyMessage calldata message) external view returns (uint256 fee);
+
+ /// @notice Get the pool for a specific token
+ /// @param destChainSelector The destination chain selector
+ /// @param sourceToken The source chain token to get the pool for
+ /// @return pool Token pool
+ function getPoolBySourceToken(uint64 destChainSelector, IERC20 sourceToken) external view returns (IPoolV1);
+
+ /// @notice Gets a list of all supported source chain tokens.
+ /// @param destChainSelector The destination chain selector
+ /// @return tokens The addresses of all tokens that this onRamp supports the given destination chain
+ function getSupportedTokens(uint64 destChainSelector) external view returns (address[] memory tokens);
+
+ /// @notice Send a message to the remote chain
+ /// @dev only callable by the Router
+ /// @dev approve() must have already been called on the token using the this ramp address as the spender.
+ /// @dev if the contract is paused, this function will revert.
+ /// @param destChainSelector The destination chain selector
+ /// @param message Message struct to send
+ /// @param feeTokenAmount Amount of fee tokens for payment
+ /// @param originalSender The original initiator of the CCIP request
+ function forwardFromRouter(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage memory message,
+ uint256 feeTokenAmount,
+ address originalSender
+ ) external returns (bytes32);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IGetCCIPAdmin.sol b/contracts/src/v0.8/ccip/interfaces/IGetCCIPAdmin.sol
new file mode 100644
index 00000000000..d83a1f34e89
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IGetCCIPAdmin.sol
@@ -0,0 +1,8 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+interface IGetCCIPAdmin {
+ /// @notice Returns the admin of the token.
+ /// @dev This method is named to never conflict with existing methods.
+ function getCCIPAdmin() external view returns (address);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IMessageInterceptor.sol b/contracts/src/v0.8/ccip/interfaces/IMessageInterceptor.sol
new file mode 100644
index 00000000000..c2b432426b6
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IMessageInterceptor.sol
@@ -0,0 +1,22 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Client} from "../libraries/Client.sol";
+
+/// @notice Interface for plug-in message hook contracts that intercept OffRamp & OnRamp messages
+/// and perform validations / state changes on top of the messages. The interceptor functions are expected to
+/// revert on validation failures.
+interface IMessageInterceptor {
+ /// @notice Common error that can be thrown on validation failures and used by consumers
+ /// @param errorReason abi encoded revert reason
+ error MessageValidationError(bytes errorReason);
+
+ /// @notice Intercepts & validates the given OffRamp message. Reverts on validation failure
+ /// @param message to validate
+ function onInboundMessage(Client.Any2EVMMessage memory message) external;
+
+ /// @notice Intercepts & validates the given OnRamp message. Reverts on validation failure
+ /// @param destChainSelector remote destination chain selector where the message is being sent to
+ /// @param message to validate
+ function onOutboundMessage(uint64 destChainSelector, Client.EVM2AnyMessage memory message) external;
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/INonceManager.sol b/contracts/src/v0.8/ccip/interfaces/INonceManager.sol
new file mode 100644
index 00000000000..52408ae4f57
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/INonceManager.sol
@@ -0,0 +1,23 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+/// @notice Contract interface that allows managing sender nonces
+interface INonceManager {
+ /// @notice Increments the outbound nonce for a given sender on a given destination chain
+ /// @param destChainSelector The destination chain selector
+ /// @param sender The sender address
+ /// @return The new outbound nonce
+ function getIncrementedOutboundNonce(uint64 destChainSelector, address sender) external returns (uint64);
+
+ /// @notice Increments the inbound nonce for a given sender on a given source chain
+ /// @notice The increment is only applied if the resulting nonce matches the expectedNonce
+ /// @param sourceChainSelector The destination chain selector
+ /// @param expectedNonce The expected inbound nonce
+ /// @param sender The encoded sender address
+ /// @return True if the nonce was incremented, false otherwise
+ function incrementInboundNonce(
+ uint64 sourceChainSelector,
+ uint64 expectedNonce,
+ bytes calldata sender
+ ) external returns (bool);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IOwner.sol b/contracts/src/v0.8/ccip/interfaces/IOwner.sol
new file mode 100644
index 00000000000..ccb1039e555
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IOwner.sol
@@ -0,0 +1,8 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+interface IOwner {
+ /// @notice Returns the owner of the contract.
+ /// @dev This method is named to match with the OpenZeppelin Ownable contract.
+ function owner() external view returns (address);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IPool.sol b/contracts/src/v0.8/ccip/interfaces/IPool.sol
new file mode 100644
index 00000000000..5d5c95e03c7
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IPool.sol
@@ -0,0 +1,35 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Pool} from "../libraries/Pool.sol";
+
+import {IERC165} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+
+/// @notice Shared public interface for multiple V1 pool types.
+/// Each pool type handles a different child token model (lock/unlock, mint/burn.)
+interface IPoolV1 is IERC165 {
+ /// @notice Lock tokens into the pool or burn the tokens.
+ /// @param lockOrBurnIn Encoded data fields for the processing of tokens on the source chain.
+ /// @return lockOrBurnOut Encoded data fields for the processing of tokens on the destination chain.
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ returns (Pool.LockOrBurnOutV1 memory lockOrBurnOut);
+
+ /// @notice Releases or mints tokens to the receiver address.
+ /// @param releaseOrMintIn All data required to release or mint tokens.
+ /// @return releaseOrMintOut The amount of tokens released or minted on the local chain, denominated
+ /// in the local token's decimals.
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ returns (Pool.ReleaseOrMintOutV1 memory);
+
+ /// @notice Checks whether a remote chain is supported in the token pool.
+ /// @param remoteChainSelector The selector of the remote chain.
+ /// @return true if the given chain is a permissioned remote chain.
+ function isSupportedChain(uint64 remoteChainSelector) external view returns (bool);
+
+ /// @notice Returns if the token pool supports the given token.
+ /// @param token The address of the token.
+ /// @return true if the token is supported by the pool.
+ function isSupportedToken(address token) external view returns (bool);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IPoolPriorTo1_5.sol b/contracts/src/v0.8/ccip/interfaces/IPoolPriorTo1_5.sol
new file mode 100644
index 00000000000..d8a2f15fd29
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IPoolPriorTo1_5.sol
@@ -0,0 +1,46 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+// Shared public interface for multiple pool types.
+// Each pool type handles a different child token model (lock/unlock, mint/burn.)
+interface IPoolPriorTo1_5 {
+ /// @notice Lock tokens into the pool or burn the tokens.
+ /// @param originalSender Original sender of the tokens.
+ /// @param receiver Receiver of the tokens on destination chain.
+ /// @param amount Amount to lock or burn.
+ /// @param remoteChainSelector Destination chain Id.
+ /// @param extraArgs Additional data passed in by sender for lockOrBurn processing
+ /// in custom pools on source chain.
+ /// @return retData Optional field that contains bytes. Unused for now but already
+ /// implemented to allow future upgrades while preserving the interface.
+ function lockOrBurn(
+ address originalSender,
+ bytes calldata receiver,
+ uint256 amount,
+ uint64 remoteChainSelector,
+ bytes calldata extraArgs
+ ) external returns (bytes memory);
+
+ /// @notice Releases or mints tokens to the receiver address.
+ /// @param originalSender Original sender of the tokens.
+ /// @param receiver Receiver of the tokens.
+ /// @param amount Amount to release or mint.
+ /// @param remoteChainSelector Source chain Id.
+ /// @param extraData Additional data supplied offchain for releaseOrMint processing in
+ /// custom pools on dest chain. This could be an attestation that was retrieved through a
+ /// third party API.
+ /// @dev offchainData can come from any untrusted source.
+ function releaseOrMint(
+ bytes memory originalSender,
+ address receiver,
+ uint256 amount,
+ uint64 remoteChainSelector,
+ bytes memory extraData
+ ) external;
+
+ /// @notice Gets the IERC20 token that this pool can lock or burn.
+ /// @return token The IERC20 token representation.
+ function getToken() external view returns (IERC20 token);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IPriceRegistry.sol b/contracts/src/v0.8/ccip/interfaces/IPriceRegistry.sol
new file mode 100644
index 00000000000..8a20299371f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IPriceRegistry.sol
@@ -0,0 +1,109 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Client} from "../libraries/Client.sol";
+import {Internal} from "../libraries/Internal.sol";
+
+interface IPriceRegistry {
+ /// @notice Token price data feed configuration
+ struct TokenPriceFeedConfig {
+ address dataFeedAddress; // ──╮ AggregatorV3Interface contract (0 - feed is unset)
+ uint8 tokenDecimals; // ──────╯ Decimals of the token that the feed represents
+ }
+
+ /// @notice Update the price for given tokens and gas prices for given chains.
+ /// @param priceUpdates The price updates to apply.
+ function updatePrices(Internal.PriceUpdates memory priceUpdates) external;
+
+ /// @notice Get the `tokenPrice` for a given token.
+ /// @param token The token to get the price for.
+ /// @return tokenPrice The tokenPrice for the given token.
+ function getTokenPrice(address token) external view returns (Internal.TimestampedPackedUint224 memory);
+
+ /// @notice Get the `tokenPrice` for a given token, checks if the price is valid.
+ /// @param token The token to get the price for.
+ /// @return tokenPrice The tokenPrice for the given token if it exists and is valid.
+ function getValidatedTokenPrice(address token) external view returns (uint224);
+
+ /// @notice Get the `tokenPrice` for an array of tokens.
+ /// @param tokens The tokens to get prices for.
+ /// @return tokenPrices The tokenPrices for the given tokens.
+ function getTokenPrices(address[] calldata tokens) external view returns (Internal.TimestampedPackedUint224[] memory);
+
+ /// @notice Returns the token price data feed configuration
+ /// @param token The token to retrieve the feed config for
+ /// @return dataFeedAddress The token price data feed config (if feed address is 0, the feed config is disabled)
+ function getTokenPriceFeedConfig(address token) external view returns (TokenPriceFeedConfig memory);
+
+ /// @notice Get an encoded `gasPrice` for a given destination chain ID.
+ /// The 224-bit result encodes necessary gas price components.
+ /// On L1 chains like Ethereum or Avax, the only component is the gas price.
+ /// On Optimistic Rollups, there are two components - the L2 gas price, and L1 base fee for data availability.
+ /// On future chains, there could be more or differing price components.
+ /// PriceRegistry does not contain chain-specific logic to parse destination chain price components.
+ /// @param destChainSelector The destination chain to get the price for.
+ /// @return gasPrice The encoded gasPrice for the given destination chain ID.
+ function getDestinationChainGasPrice(uint64 destChainSelector)
+ external
+ view
+ returns (Internal.TimestampedPackedUint224 memory);
+
+ /// @notice Gets the fee token price and the gas price, both denominated in dollars.
+ /// @param token The source token to get the price for.
+ /// @param destChainSelector The destination chain to get the gas price for.
+ /// @return tokenPrice The price of the feeToken in 1e18 dollars per base unit.
+ /// @return gasPrice The price of gas in 1e18 dollars per base unit.
+ function getTokenAndGasPrices(
+ address token,
+ uint64 destChainSelector
+ ) external view returns (uint224 tokenPrice, uint224 gasPrice);
+
+ /// @notice Convert a given token amount to target token amount.
+ /// @param fromToken The given token address.
+ /// @param fromTokenAmount The given token amount.
+ /// @param toToken The target token address.
+ /// @return toTokenAmount The target token amount.
+ function convertTokenAmount(
+ address fromToken,
+ uint256 fromTokenAmount,
+ address toToken
+ ) external view returns (uint256 toTokenAmount);
+
+ /// @notice Get the list of fee tokens.
+ /// @return The tokens set as fee tokens.
+ function getFeeTokens() external view returns (address[] memory);
+
+ /// @notice Validates the ccip message & returns the fee
+ /// @param destChainSelector The destination chain selector.
+ /// @param message The message to get quote for.
+ /// @return feeTokenAmount The amount of fee token needed for the fee, in smallest denomination of the fee token.
+ function getValidatedFee(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external view returns (uint256 feeTokenAmount);
+
+ /// @notice Converts the extraArgs to the latest version and returns the converted message fee in juels
+ /// @param destChainSelector destination chain selector to process
+ /// @param feeToken Fee token address used to pay for message fees
+ /// @param feeTokenAmount Fee token amount
+ /// @param extraArgs Message extra args that were passed in by the client
+ /// @return msgFeeJuels message fee in juels
+ /// @return isOutOfOrderExecution true if the message should be executed out of order
+ /// @return convertedExtraArgs extra args converted to the latest family-specific args version
+ function processMessageArgs(
+ uint64 destChainSelector,
+ address feeToken,
+ uint256 feeTokenAmount,
+ bytes memory extraArgs
+ ) external view returns (uint256 msgFeeJuels, bool isOutOfOrderExecution, bytes memory convertedExtraArgs);
+
+ /// @notice Validates pool return data
+ /// @param destChainSelector Destination chain selector to which the token amounts are sent to
+ /// @param rampTokenAmounts Token amounts with populated pool return data
+ /// @param sourceTokenAmounts Token amounts originally sent in a Client.EVM2AnyMessage message
+ function validatePoolReturnData(
+ uint64 destChainSelector,
+ Internal.RampTokenAmount[] calldata rampTokenAmounts,
+ Client.EVMTokenAmount[] calldata sourceTokenAmounts
+ ) external view;
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IRMN.sol b/contracts/src/v0.8/ccip/interfaces/IRMN.sol
new file mode 100644
index 00000000000..a409731549f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IRMN.sol
@@ -0,0 +1,21 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+/// @notice This interface contains the only RMN-related functions that might be used on-chain by other CCIP contracts.
+interface IRMN {
+ /// @notice A Merkle root tagged with the address of the commit store contract it is destined for.
+ struct TaggedRoot {
+ address commitStore;
+ bytes32 root;
+ }
+
+ /// @notice Callers MUST NOT cache the return value as a blessed tagged root could become unblessed.
+ function isBlessed(TaggedRoot calldata taggedRoot) external view returns (bool);
+
+ /// @notice Iff there is an active global or legacy curse, this function returns true.
+ function isCursed() external view returns (bool);
+
+ /// @notice Iff there is an active global curse, or an active curse for `subject`, this function returns true.
+ /// @param subject To check whether a particular chain is cursed, set to bytes16(uint128(chainSelector)).
+ function isCursed(bytes16 subject) external view returns (bool);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IRouter.sol b/contracts/src/v0.8/ccip/interfaces/IRouter.sol
new file mode 100644
index 00000000000..7f4544fd0fa
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IRouter.sol
@@ -0,0 +1,35 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Client} from "../libraries/Client.sol";
+
+interface IRouter {
+ error OnlyOffRamp();
+
+ /// @notice Route the message to its intended receiver contract.
+ /// @param message Client.Any2EVMMessage struct.
+ /// @param gasForCallExactCheck of params for exec
+ /// @param gasLimit set of params for exec
+ /// @param receiver set of params for exec
+ /// @dev if the receiver is a contracts that signals support for CCIP execution through EIP-165.
+ /// the contract is called. If not, only tokens are transferred.
+ /// @return success A boolean value indicating whether the ccip message was received without errors.
+ /// @return retBytes A bytes array containing return data form CCIP receiver.
+ /// @return gasUsed the gas used by the external customer call. Does not include any overhead.
+ function routeMessage(
+ Client.Any2EVMMessage calldata message,
+ uint16 gasForCallExactCheck,
+ uint256 gasLimit,
+ address receiver
+ ) external returns (bool success, bytes memory retBytes, uint256 gasUsed);
+
+ /// @notice Returns the configured onramp for a specific destination chain.
+ /// @param destChainSelector The destination chain Id to get the onRamp for.
+ /// @return onRampAddress The address of the onRamp.
+ function getOnRamp(uint64 destChainSelector) external view returns (address onRampAddress);
+
+ /// @notice Return true if the given offRamp is a configured offRamp for the given source chain.
+ /// @param sourceChainSelector The source chain selector to check.
+ /// @param offRamp The address of the offRamp to check.
+ function isOffRamp(uint64 sourceChainSelector, address offRamp) external view returns (bool isOffRamp);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IRouterClient.sol b/contracts/src/v0.8/ccip/interfaces/IRouterClient.sol
new file mode 100644
index 00000000000..9805a41bbdc
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IRouterClient.sol
@@ -0,0 +1,37 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Client} from "../libraries/Client.sol";
+
+interface IRouterClient {
+ error UnsupportedDestinationChain(uint64 destChainSelector);
+ error InsufficientFeeTokenAmount();
+ error InvalidMsgValue();
+
+ /// @notice Checks if the given chain ID is supported for sending/receiving.
+ /// @param destChainSelector The chain to check.
+ /// @return supported is true if it is supported, false if not.
+ function isChainSupported(uint64 destChainSelector) external view returns (bool supported);
+
+ /// @param destinationChainSelector The destination chainSelector
+ /// @param message The cross-chain CCIP message including data and/or tokens
+ /// @return fee returns execution fee for the message
+ /// delivery to destination chain, denominated in the feeToken specified in the message.
+ /// @dev Reverts with appropriate reason upon invalid message.
+ function getFee(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage memory message
+ ) external view returns (uint256 fee);
+
+ /// @notice Request a message to be sent to the destination chain
+ /// @param destinationChainSelector The destination chain ID
+ /// @param message The cross-chain CCIP message including data and/or tokens
+ /// @return messageId The message ID
+ /// @dev Note if msg.value is larger than the required fee (from getFee) we accept
+ /// the overpayment with no refund.
+ /// @dev Reverts with appropriate reason upon invalid message.
+ function ccipSend(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external payable returns (bytes32);
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/ITokenAdminRegistry.sol b/contracts/src/v0.8/ccip/interfaces/ITokenAdminRegistry.sol
new file mode 100644
index 00000000000..0e441229011
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/ITokenAdminRegistry.sol
@@ -0,0 +1,12 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+interface ITokenAdminRegistry {
+ /// @notice Returns the pool for the given token.
+ function getPool(address token) external view returns (address);
+
+ /// @notice Proposes an administrator for the given token as pending administrator.
+ /// @param localToken The token to register the administrator for.
+ /// @param administrator The administrator to register.
+ function proposeAdministrator(address localToken, address administrator) external;
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/IWrappedNative.sol b/contracts/src/v0.8/ccip/interfaces/IWrappedNative.sol
new file mode 100644
index 00000000000..4225827a612
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/IWrappedNative.sol
@@ -0,0 +1,10 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+interface IWrappedNative is IERC20 {
+ function deposit() external payable;
+
+ function withdraw(uint256 wad) external;
+}
diff --git a/contracts/src/v0.8/ccip/interfaces/automation/ILinkAvailable.sol b/contracts/src/v0.8/ccip/interfaces/automation/ILinkAvailable.sol
new file mode 100644
index 00000000000..b0dad9a5e70
--- /dev/null
+++ b/contracts/src/v0.8/ccip/interfaces/automation/ILinkAvailable.sol
@@ -0,0 +1,8 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+/// @notice Implement this contract so that a keeper-compatible contract can monitor
+/// and fund the implementation contract with LINK if it falls below a defined threshold.
+interface ILinkAvailable {
+ function linkAvailableForPayment() external view returns (int256 availableBalance);
+}
diff --git a/contracts/src/v0.8/ccip/libraries/Client.sol b/contracts/src/v0.8/ccip/libraries/Client.sol
new file mode 100644
index 00000000000..a985371bef1
--- /dev/null
+++ b/contracts/src/v0.8/ccip/libraries/Client.sol
@@ -0,0 +1,55 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+// End consumer library.
+library Client {
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct EVMTokenAmount {
+ address token; // token address on the local chain.
+ uint256 amount; // Amount of tokens.
+ }
+
+ struct Any2EVMMessage {
+ bytes32 messageId; // MessageId corresponding to ccipSend on source.
+ uint64 sourceChainSelector; // Source chain selector.
+ bytes sender; // abi.decode(sender) if coming from an EVM chain.
+ bytes data; // payload sent in original message.
+ EVMTokenAmount[] destTokenAmounts; // Tokens and their amounts in their destination chain representation.
+ }
+
+ // If extraArgs is empty bytes, the default is 200k gas limit.
+ struct EVM2AnyMessage {
+ bytes receiver; // abi.encode(receiver address) for dest EVM chains
+ bytes data; // Data payload
+ EVMTokenAmount[] tokenAmounts; // Token transfers
+ address feeToken; // Address of feeToken. address(0) means you will send msg.value.
+ bytes extraArgs; // Populate this with _argsToBytes(EVMExtraArgsV2)
+ }
+
+ // bytes4(keccak256("CCIP EVMExtraArgsV1"));
+ bytes4 public constant EVM_EXTRA_ARGS_V1_TAG = 0x97a657c9;
+
+ struct EVMExtraArgsV1 {
+ uint256 gasLimit;
+ }
+
+ function _argsToBytes(EVMExtraArgsV1 memory extraArgs) internal pure returns (bytes memory bts) {
+ return abi.encodeWithSelector(EVM_EXTRA_ARGS_V1_TAG, extraArgs);
+ }
+
+ // bytes4(keccak256("CCIP EVMExtraArgsV2"));
+ bytes4 public constant EVM_EXTRA_ARGS_V2_TAG = 0x181dcf10;
+
+ /// @param gasLimit: gas limit for the callback on the destination chain.
+ /// @param allowOutOfOrderExecution: if true, it indicates that the message can be executed in any order relative to other messages from the same sender.
+ /// This value's default varies by chain. On some chains, a particular value is enforced, meaning if the expected value
+ /// is not set, the message request will revert.
+ struct EVMExtraArgsV2 {
+ uint256 gasLimit;
+ bool allowOutOfOrderExecution;
+ }
+
+ function _argsToBytes(EVMExtraArgsV2 memory extraArgs) internal pure returns (bytes memory bts) {
+ return abi.encodeWithSelector(EVM_EXTRA_ARGS_V2_TAG, extraArgs);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/libraries/Internal.sol b/contracts/src/v0.8/ccip/libraries/Internal.sol
new file mode 100644
index 00000000000..db2bc05ee53
--- /dev/null
+++ b/contracts/src/v0.8/ccip/libraries/Internal.sol
@@ -0,0 +1,319 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {MerkleMultiProof} from "../libraries/MerkleMultiProof.sol";
+import {Client} from "./Client.sol";
+
+// Library for CCIP internal definitions common to multiple contracts.
+library Internal {
+ error InvalidEVMAddress(bytes encodedAddress);
+
+ /// @dev The minimum amount of gas to perform the call with exact gas.
+ /// We include this in the offramp so that we can redeploy to adjust it
+ /// should a hardfork change the gas costs of relevant opcodes in callWithExactGas.
+ uint16 internal constant GAS_FOR_CALL_EXACT_CHECK = 5_000;
+ // @dev We limit return data to a selector plus 4 words. This is to avoid
+ // malicious contracts from returning large amounts of data and causing
+ // repeated out-of-gas scenarios.
+ uint16 internal constant MAX_RET_BYTES = 4 + 4 * 32;
+
+ /// @notice A collection of token price and gas price updates.
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct PriceUpdates {
+ TokenPriceUpdate[] tokenPriceUpdates;
+ GasPriceUpdate[] gasPriceUpdates;
+ }
+
+ /// @notice Token price in USD.
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct TokenPriceUpdate {
+ address sourceToken; // Source token
+ uint224 usdPerToken; // 1e18 USD per 1e18 of the smallest token denomination.
+ }
+
+ /// @notice Gas price for a given chain in USD, its value may contain tightly packed fields.
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct GasPriceUpdate {
+ uint64 destChainSelector; // Destination chain selector
+ uint224 usdPerUnitGas; // 1e18 USD per smallest unit (e.g. wei) of destination chain gas
+ }
+
+ /// @notice A timestamped uint224 value that can contain several tightly packed fields.
+ struct TimestampedPackedUint224 {
+ uint224 value; // ───────╮ Value in uint224, packed.
+ uint32 timestamp; // ────╯ Timestamp of the most recent price update.
+ }
+
+ /// @dev Gas price is stored in 112-bit unsigned int. uint224 can pack 2 prices.
+ /// When packing L1 and L2 gas prices, L1 gas price is left-shifted to the higher-order bits.
+ /// Using uint8 type, which cannot be higher than other bit shift operands, to avoid shift operand type warning.
+ uint8 public constant GAS_PRICE_BITS = 112;
+
+ struct PoolUpdate {
+ address token; // The IERC20 token address
+ address pool; // The token pool address
+ }
+
+ struct SourceTokenData {
+ // The source pool address, abi encoded. This value is trusted as it was obtained through the onRamp. It can be
+ // relied upon by the destination pool to validate the source pool.
+ bytes sourcePoolAddress;
+ // The address of the destination token, abi encoded in the case of EVM chains
+ // This value is UNTRUSTED as any pool owner can return whatever value they want.
+ bytes destTokenAddress;
+ // Optional pool data to be transferred to the destination chain. Be default this is capped at
+ // CCIP_LOCK_OR_BURN_V1_RET_BYTES bytes. If more data is required, the TokenTransferFeeConfig.destBytesOverhead
+ // has to be set for the specific token.
+ bytes extraData;
+ }
+
+ /// @notice Report that is submitted by the execution DON at the execution phase. (including chain selector data)
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct ExecutionReportSingleChain {
+ uint64 sourceChainSelector; // Source chain selector for which the report is submitted
+ Any2EVMRampMessage[] messages;
+ // Contains a bytes array for each message, each inner bytes array contains bytes per transferred token
+ bytes[][] offchainTokenData;
+ bytes32[] proofs;
+ uint256 proofFlagBits;
+ }
+
+ /// @notice Report that is submitted by the execution DON at the execution phase.
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct ExecutionReport {
+ EVM2EVMMessage[] messages;
+ // Contains a bytes array for each message, each inner bytes array contains bytes per transferred token
+ bytes[][] offchainTokenData;
+ bytes32[] proofs;
+ uint256 proofFlagBits;
+ }
+
+ /// @notice The cross chain message that gets committed to EVM chains.
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct EVM2EVMMessage {
+ uint64 sourceChainSelector; // ───────────╮ the chain selector of the source chain, note: not chainId
+ address sender; // ───────────────────────╯ sender address on the source chain
+ address receiver; // ─────────────────────╮ receiver address on the destination chain
+ uint64 sequenceNumber; // ────────────────╯ sequence number, not unique across lanes
+ uint256 gasLimit; // user supplied maximum gas amount available for dest chain execution
+ bool strict; // ──────────────────────────╮ DEPRECATED
+ uint64 nonce; // │ nonce for this lane for this sender, not unique across senders/lanes
+ address feeToken; // ─────────────────────╯ fee token
+ uint256 feeTokenAmount; // fee token amount
+ bytes data; // arbitrary data payload supplied by the message sender
+ Client.EVMTokenAmount[] tokenAmounts; // array of tokens and amounts to transfer
+ bytes[] sourceTokenData; // array of token data, one per token
+ bytes32 messageId; // a hash of the message data
+ }
+
+ /// @dev EVM2EVMMessage struct has 13 fields, including 3 variable arrays.
+ /// Each variable array takes 1 more slot to store its length.
+ /// When abi encoded, excluding array contents,
+ /// EVM2EVMMessage takes up a fixed number of 16 lots, 32 bytes each.
+ /// For structs that contain arrays, 1 more slot is added to the front, reaching a total of 17.
+ uint256 public constant MESSAGE_FIXED_BYTES = 32 * 17;
+
+ /// @dev Each token transfer adds 1 EVMTokenAmount and 1 bytes.
+ /// When abiEncoded, each EVMTokenAmount takes 2 slots, each bytes takes 2 slots, excl bytes contents
+ uint256 public constant MESSAGE_FIXED_BYTES_PER_TOKEN = 32 * 4;
+
+ /// @dev Any2EVMRampMessage struct has 10 fields, including 3 variable unnested arrays (data, receiver and tokenAmounts).
+ /// Each variable array takes 1 more slot to store its length.
+ /// When abi encoded, excluding array contents,
+ /// Any2EVMMessage takes up a fixed number of 13 slots, 32 bytes each.
+ /// For structs that contain arrays, 1 more slot is added to the front, reaching a total of 14.
+ /// The fixed bytes does not cover struct data (this is represented by ANY_2_EVM_MESSAGE_FIXED_BYTES_PER_TOKEN)
+ uint256 public constant ANY_2_EVM_MESSAGE_FIXED_BYTES = 32 * 14;
+
+ /// @dev Each token transfer adds 1 RampTokenAmount
+ /// RampTokenAmount has 4 fields, including 3 bytes.
+ /// Each bytes takes 1 more slot to store its length.
+ /// When abi encoded, each token transfer takes up 7 slots, excl bytes contents.
+ uint256 public constant ANY_2_EVM_MESSAGE_FIXED_BYTES_PER_TOKEN = 32 * 7;
+
+ bytes32 internal constant EVM_2_EVM_MESSAGE_HASH = keccak256("EVM2EVMMessageHashV2");
+
+ /// @dev Used to hash messages for single-lane ramps.
+ /// OnRamp hash(EVM2EVMMessage) = OffRamp hash(EVM2EVMMessage)
+ /// The EVM2EVMMessage's messageId is expected to be the output of this hash function
+ /// @param original Message to hash
+ /// @param metadataHash Immutable metadata hash representing a lane with a fixed OnRamp
+ /// @return hashedMessage hashed message as a keccak256
+ function _hash(EVM2EVMMessage memory original, bytes32 metadataHash) internal pure returns (bytes32) {
+ // Fixed-size message fields are included in nested hash to reduce stack pressure.
+ // This hashing scheme is also used by RMN. If changing it, please notify the RMN maintainers.
+ return keccak256(
+ abi.encode(
+ MerkleMultiProof.LEAF_DOMAIN_SEPARATOR,
+ metadataHash,
+ keccak256(
+ abi.encode(
+ original.sender,
+ original.receiver,
+ original.sequenceNumber,
+ original.gasLimit,
+ original.strict,
+ original.nonce,
+ original.feeToken,
+ original.feeTokenAmount
+ )
+ ),
+ keccak256(original.data),
+ keccak256(abi.encode(original.tokenAmounts)),
+ keccak256(abi.encode(original.sourceTokenData))
+ )
+ );
+ }
+
+ bytes32 internal constant ANY_2_EVM_MESSAGE_HASH = keccak256("Any2EVMMessageHashV1");
+ bytes32 internal constant EVM_2_ANY_MESSAGE_HASH = keccak256("EVM2AnyMessageHashV1");
+
+ /// @dev Used to hash messages for multi-lane family-agnostic OffRamps.
+ /// OnRamp hash(EVM2AnyMessage) != Any2EVMRampMessage.messageId
+ /// OnRamp hash(EVM2AnyMessage) != OffRamp hash(Any2EVMRampMessage)
+ /// @param original OffRamp message to hash
+ /// @param onRamp OnRamp to hash the message with - used to compute the metadataHash
+ /// @return hashedMessage hashed message as a keccak256
+ function _hash(Any2EVMRampMessage memory original, bytes memory onRamp) internal pure returns (bytes32) {
+ // Fixed-size message fields are included in nested hash to reduce stack pressure.
+ // This hashing scheme is also used by RMN. If changing it, please notify the RMN maintainers.
+ return keccak256(
+ abi.encode(
+ MerkleMultiProof.LEAF_DOMAIN_SEPARATOR,
+ // Implicit metadata hash
+ keccak256(
+ abi.encode(
+ ANY_2_EVM_MESSAGE_HASH, original.header.sourceChainSelector, original.header.destChainSelector, onRamp
+ )
+ ),
+ keccak256(
+ abi.encode(
+ original.header.messageId,
+ original.sender,
+ original.receiver,
+ original.header.sequenceNumber,
+ original.gasLimit,
+ original.header.nonce
+ )
+ ),
+ keccak256(original.data),
+ keccak256(abi.encode(original.tokenAmounts))
+ )
+ );
+ }
+
+ function _hash(EVM2AnyRampMessage memory original, bytes32 metadataHash) internal pure returns (bytes32) {
+ // Fixed-size message fields are included in nested hash to reduce stack pressure.
+ // This hashing scheme is also used by RMN. If changing it, please notify the RMN maintainers.
+ return keccak256(
+ abi.encode(
+ MerkleMultiProof.LEAF_DOMAIN_SEPARATOR,
+ metadataHash,
+ keccak256(
+ abi.encode(
+ original.sender,
+ original.receiver,
+ original.header.sequenceNumber,
+ original.header.nonce,
+ original.feeToken,
+ original.feeTokenAmount
+ )
+ ),
+ keccak256(original.data),
+ keccak256(abi.encode(original.tokenAmounts)),
+ keccak256(original.extraArgs)
+ )
+ );
+ }
+
+ /// @dev We disallow the first 1024 addresses to never allow calling precompiles. It is extremely unlikely that
+ /// anyone would ever be able to generate an address in this range.
+ uint256 public constant PRECOMPILE_SPACE = 1024;
+
+ /// @notice This methods provides validation for parsing abi encoded addresses by ensuring the
+ /// address is within the EVM address space. If it isn't it will revert with an InvalidEVMAddress error, which
+ /// we can catch and handle more gracefully than a revert from abi.decode.
+ /// @return The address if it is valid, the function will revert otherwise.
+ function _validateEVMAddress(bytes memory encodedAddress) internal pure returns (address) {
+ if (encodedAddress.length != 32) revert InvalidEVMAddress(encodedAddress);
+ uint256 encodedAddressUint = abi.decode(encodedAddress, (uint256));
+ if (encodedAddressUint > type(uint160).max || encodedAddressUint < PRECOMPILE_SPACE) {
+ revert InvalidEVMAddress(encodedAddress);
+ }
+ return address(uint160(encodedAddressUint));
+ }
+
+ /// @notice Enum listing the possible message execution states within
+ /// the offRamp contract.
+ /// UNTOUCHED never executed
+ /// IN_PROGRESS currently being executed, used a replay protection
+ /// SUCCESS successfully executed. End state
+ /// FAILURE unsuccessfully executed, manual execution is now enabled.
+ /// @dev RMN depends on this enum, if changing, please notify the RMN maintainers.
+ enum MessageExecutionState {
+ UNTOUCHED,
+ IN_PROGRESS,
+ SUCCESS,
+ FAILURE
+ }
+
+ /// @notice CCIP OCR plugin type, used to separate execution & commit transmissions and configs
+ enum OCRPluginType {
+ Commit,
+ Execution
+ }
+
+ /// @notice Family-agnostic token amounts used for both OnRamp & OffRamp messages
+ struct RampTokenAmount {
+ // The source pool address, abi encoded. This value is trusted as it was obtained through the onRamp. It can be
+ // relied upon by the destination pool to validate the source pool.
+ bytes sourcePoolAddress;
+ // The address of the destination token, abi encoded in the case of EVM chains
+ // This value is UNTRUSTED as any pool owner can return whatever value they want.
+ bytes destTokenAddress;
+ // Optional pool data to be transferred to the destination chain. Be default this is capped at
+ // CCIP_LOCK_OR_BURN_V1_RET_BYTES bytes. If more data is required, the TokenTransferFeeConfig.destBytesOverhead
+ // has to be set for the specific token.
+ bytes extraData;
+ uint256 amount; // Amount of tokens.
+ }
+
+ /// @notice Family-agnostic header for OnRamp & OffRamp messages.
+ /// The messageId is not expected to match hash(message), since it may originate from another ramp family
+ struct RampMessageHeader {
+ bytes32 messageId; // Unique identifier for the message, generated with the source chain's encoding scheme (i.e. not necessarily abi.encoded)
+ uint64 sourceChainSelector; // ───────╮ the chain selector of the source chain, note: not chainId
+ uint64 destChainSelector; // | the chain selector of the destination chain, note: not chainId
+ uint64 sequenceNumber; // │ sequence number, not unique across lanes
+ uint64 nonce; // ─────────────────────╯ nonce for this lane for this sender, not unique across senders/lanes
+ }
+
+ /// @notice Family-agnostic message routed to an OffRamp
+ /// Note: hash(Any2EVMRampMessage) != hash(EVM2AnyRampMessage), hash(Any2EVMRampMessage) != messageId
+ /// due to encoding & parameter differences
+ struct Any2EVMRampMessage {
+ RampMessageHeader header; // Message header
+ bytes sender; // sender address on the source chain
+ bytes data; // arbitrary data payload supplied by the message sender
+ address receiver; // receiver address on the destination chain
+ uint256 gasLimit; // user supplied maximum gas amount available for dest chain execution
+ RampTokenAmount[] tokenAmounts; // array of tokens and amounts to transfer
+ }
+
+ /// @notice Family-agnostic message emitted from the OnRamp
+ /// Note: hash(Any2EVMRampMessage) != hash(EVM2AnyRampMessage) due to encoding & parameter differences
+ /// messageId = hash(EVM2AnyRampMessage) using the source EVM chain's encoding format
+ struct EVM2AnyRampMessage {
+ RampMessageHeader header; // Message header
+ address sender; // sender address on the source chain
+ bytes data; // arbitrary data payload supplied by the message sender
+ bytes receiver; // receiver address on the destination chain
+ bytes extraArgs; // destination-chain specific extra args, such as the gasLimit for EVM chains
+ address feeToken; // fee token
+ uint256 feeTokenAmount; // fee token amount
+ RampTokenAmount[] tokenAmounts; // array of tokens and amounts to transfer
+ }
+
+ // bytes4(keccak256("CCIP ChainFamilySelector EVM"))
+ bytes4 public constant CHAIN_FAMILY_SELECTOR_EVM = 0x2812d52c;
+}
diff --git a/contracts/src/v0.8/ccip/libraries/MerkleMultiProof.sol b/contracts/src/v0.8/ccip/libraries/MerkleMultiProof.sol
new file mode 100644
index 00000000000..fed8a1165bb
--- /dev/null
+++ b/contracts/src/v0.8/ccip/libraries/MerkleMultiProof.sol
@@ -0,0 +1,113 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+library MerkleMultiProof {
+ /// @notice Leaf domain separator, should be used as the first 32 bytes of a leaf's preimage.
+ bytes32 internal constant LEAF_DOMAIN_SEPARATOR = 0x0000000000000000000000000000000000000000000000000000000000000000;
+ /// @notice Internal domain separator, should be used as the first 32 bytes of an internal node's preiimage.
+ bytes32 internal constant INTERNAL_DOMAIN_SEPARATOR =
+ 0x0000000000000000000000000000000000000000000000000000000000000001;
+
+ uint256 internal constant MAX_NUM_HASHES = 256;
+
+ error InvalidProof();
+ error LeavesCannotBeEmpty();
+
+ /// @notice Computes the root based on provided pre-hashed leaf nodes in
+ /// leaves, internal nodes in proofs, and using proofFlagBits' i-th bit to
+ /// determine if an element of proofs or one of the previously computed leafs
+ /// or internal nodes will be used for the i-th hash.
+ /// @param leaves Should be pre-hashed and the first 32 bytes of a leaf's
+ /// preimage should match LEAF_DOMAIN_SEPARATOR.
+ /// @param proofs The hashes to be used instead of a leaf hash when the proofFlagBits
+ /// indicates a proof should be used.
+ /// @param proofFlagBits A single uint256 of which each bit indicates whether a leaf or
+ /// a proof needs to be used in a hash operation.
+ /// @dev the maximum number of hash operations it set to 256. Any input that would require
+ /// more than 256 hashes to get to a root will revert.
+ /// @dev For given input `leaves` = [a,b,c] `proofs` = [D] and `proofFlagBits` = 5
+ /// totalHashes = 3 + 1 - 1 = 3
+ /// ** round 1 **
+ /// proofFlagBits = (5 >> 0) & 1 = true
+ /// hashes[0] = hashPair(a, b)
+ /// (leafPos, hashPos, proofPos) = (2, 0, 0);
+ ///
+ /// ** round 2 **
+ /// proofFlagBits = (5 >> 1) & 1 = false
+ /// hashes[1] = hashPair(D, c)
+ /// (leafPos, hashPos, proofPos) = (3, 0, 1);
+ ///
+ /// ** round 3 **
+ /// proofFlagBits = (5 >> 2) & 1 = true
+ /// hashes[2] = hashPair(hashes[0], hashes[1])
+ /// (leafPos, hashPos, proofPos) = (3, 2, 1);
+ ///
+ /// i = 3 and no longer < totalHashes. The algorithm is done
+ /// return hashes[totalHashes - 1] = hashes[2]; the last hash we computed.
+ // We mark this function as internal to force it to be inlined in contracts
+ // that use it, but semantically it is public.
+ // solhint-disable-next-line chainlink-solidity/prefix-internal-functions-with-underscore
+ function merkleRoot(
+ bytes32[] memory leaves,
+ bytes32[] memory proofs,
+ uint256 proofFlagBits
+ ) internal pure returns (bytes32) {
+ unchecked {
+ uint256 leavesLen = leaves.length;
+ uint256 proofsLen = proofs.length;
+ if (leavesLen == 0) revert LeavesCannotBeEmpty();
+ if (!(leavesLen <= MAX_NUM_HASHES + 1 && proofsLen <= MAX_NUM_HASHES + 1)) revert InvalidProof();
+ uint256 totalHashes = leavesLen + proofsLen - 1;
+ if (!(totalHashes <= MAX_NUM_HASHES)) revert InvalidProof();
+ if (totalHashes == 0) {
+ return leaves[0];
+ }
+ bytes32[] memory hashes = new bytes32[](totalHashes);
+ (uint256 leafPos, uint256 hashPos, uint256 proofPos) = (0, 0, 0);
+
+ for (uint256 i = 0; i < totalHashes; ++i) {
+ // Checks if the bit flag signals the use of a supplied proof or a leaf/previous hash.
+ bytes32 a;
+ if (proofFlagBits & (1 << i) == (1 << i)) {
+ // Use a leaf or a previously computed hash.
+ if (leafPos < leavesLen) {
+ a = leaves[leafPos++];
+ } else {
+ a = hashes[hashPos++];
+ }
+ } else {
+ // Use a supplied proof.
+ a = proofs[proofPos++];
+ }
+
+ // The second part of the hashed pair is never a proof as hashing two proofs would result in a
+ // hash that can already be computed offchain.
+ bytes32 b;
+ if (leafPos < leavesLen) {
+ b = leaves[leafPos++];
+ } else {
+ b = hashes[hashPos++];
+ }
+
+ if (!(hashPos <= i)) revert InvalidProof();
+
+ hashes[i] = _hashPair(a, b);
+ }
+ if (!(hashPos == totalHashes - 1 && leafPos == leavesLen && proofPos == proofsLen)) revert InvalidProof();
+ // Return the last hash.
+ return hashes[totalHashes - 1];
+ }
+ }
+
+ /// @notice Hashes two bytes32 objects in their given order, prepended by the
+ /// INTERNAL_DOMAIN_SEPARATOR.
+ function _hashInternalNode(bytes32 left, bytes32 right) private pure returns (bytes32 hash) {
+ return keccak256(abi.encode(INTERNAL_DOMAIN_SEPARATOR, left, right));
+ }
+
+ /// @notice Hashes two bytes32 objects. The order is taken into account,
+ /// using the lower value first.
+ function _hashPair(bytes32 a, bytes32 b) private pure returns (bytes32) {
+ return a < b ? _hashInternalNode(a, b) : _hashInternalNode(b, a);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/libraries/Pool.sol b/contracts/src/v0.8/ccip/libraries/Pool.sol
new file mode 100644
index 00000000000..3f1895dcf5a
--- /dev/null
+++ b/contracts/src/v0.8/ccip/libraries/Pool.sol
@@ -0,0 +1,58 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+/// @notice This library contains various token pool functions to aid constructing the return data.
+library Pool {
+ // The tag used to signal support for the pool v1 standard
+ // bytes4(keccak256("CCIP_POOL_V1"))
+ bytes4 public constant CCIP_POOL_V1 = 0xaff2afbf;
+
+ // The number of bytes in the return data for a pool v1 releaseOrMint call.
+ // This should match the size of the ReleaseOrMintOutV1 struct.
+ uint16 public constant CCIP_POOL_V1_RET_BYTES = 32;
+
+ // The default max number of bytes in the return data for a pool v1 lockOrBurn call.
+ // This data can be used to send information to the destination chain token pool. Can be overwritten
+ // in the TokenTransferFeeConfig.destBytesOverhead if more data is required.
+ uint256 public constant CCIP_LOCK_OR_BURN_V1_RET_BYTES = 32;
+
+ struct LockOrBurnInV1 {
+ bytes receiver; // The recipient of the tokens on the destination chain, abi encoded
+ uint64 remoteChainSelector; // ─╮ The chain ID of the destination chain
+ address originalSender; // ─────╯ The original sender of the tx on the source chain
+ uint256 amount; // The amount of tokens to lock or burn, denominated in the source token's decimals
+ address localToken; // The address on this chain of the token to lock or burn
+ }
+
+ struct LockOrBurnOutV1 {
+ // The address of the destination token pool, abi encoded in the case of EVM chains
+ // This value is UNTRUSTED as any pool owner can return whatever value they want.
+ bytes destTokenAddress;
+ // Optional pool data to be transferred to the destination chain. Be default this is capped at
+ // CCIP_LOCK_OR_BURN_V1_RET_BYTES bytes. If more data is required, the TokenTransferFeeConfig.destBytesOverhead
+ // has to be set for the specific token.
+ bytes destPoolData;
+ }
+
+ struct ReleaseOrMintInV1 {
+ bytes originalSender; // The original sender of the tx on the source chain
+ uint64 remoteChainSelector; // ─╮ The chain ID of the source chain
+ address receiver; // ───────────╯ The recipient of the tokens on the destination chain. This is *NOT* the address to
+ // send the tokens to, but the address that will receive the tokens via the offRamp.
+ uint256 amount; // The amount of tokens to release or mint, denominated in the source token's decimals
+ address localToken; // The address on this chain of the token to release or mint
+ /// @dev WARNING: sourcePoolAddress should be checked prior to any processing of funds. Make sure it matches the
+ /// expected pool address for the given remoteChainSelector.
+ bytes sourcePoolAddress; // The address of the source pool, abi encoded in the case of EVM chains
+ bytes sourcePoolData; // The data received from the source pool to process the release or mint
+ /// @dev WARNING: offchainTokenData is untrusted data.
+ bytes offchainTokenData; // The offchain data to process the release or mint
+ }
+
+ struct ReleaseOrMintOutV1 {
+ // The number of tokens released or minted on the destination chain, denominated in the local token's decimals.
+ // This value is expected to be equal to the ReleaseOrMintInV1.amount in the case where the source and destination
+ // chain have the same number of decimals.
+ uint256 destinationAmount;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/libraries/RateLimiter.sol b/contracts/src/v0.8/ccip/libraries/RateLimiter.sol
new file mode 100644
index 00000000000..40ac3ca213e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/libraries/RateLimiter.sol
@@ -0,0 +1,157 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+/// @notice Implements Token Bucket rate limiting.
+/// @dev uint128 is safe for rate limiter state.
+/// For USD value rate limiting, it can adequately store USD value in 18 decimals.
+/// For ERC20 token amount rate limiting, all tokens that will be listed will have at most
+/// a supply of uint128.max tokens, and it will therefore not overflow the bucket.
+/// In exceptional scenarios where tokens consumed may be larger than uint128,
+/// e.g. compromised issuer, an enabled RateLimiter will check and revert.
+library RateLimiter {
+ error BucketOverfilled();
+ error OnlyCallableByAdminOrOwner();
+ error TokenMaxCapacityExceeded(uint256 capacity, uint256 requested, address tokenAddress);
+ error TokenRateLimitReached(uint256 minWaitInSeconds, uint256 available, address tokenAddress);
+ error AggregateValueMaxCapacityExceeded(uint256 capacity, uint256 requested);
+ error AggregateValueRateLimitReached(uint256 minWaitInSeconds, uint256 available);
+ error InvalidRateLimitRate(Config rateLimiterConfig);
+ error DisabledNonZeroRateLimit(Config config);
+ error RateLimitMustBeDisabled();
+
+ event TokensConsumed(uint256 tokens);
+ event ConfigChanged(Config config);
+
+ struct TokenBucket {
+ uint128 tokens; // ──────╮ Current number of tokens that are in the bucket.
+ uint32 lastUpdated; // │ Timestamp in seconds of the last token refill, good for 100+ years.
+ bool isEnabled; // ──────╯ Indication whether the rate limiting is enabled or not
+ uint128 capacity; // ────╮ Maximum number of tokens that can be in the bucket.
+ uint128 rate; // ────────╯ Number of tokens per second that the bucket is refilled.
+ }
+
+ struct Config {
+ bool isEnabled; // Indication whether the rate limiting should be enabled
+ uint128 capacity; // ────╮ Specifies the capacity of the rate limiter
+ uint128 rate; // ───────╯ Specifies the rate of the rate limiter
+ }
+
+ /// @notice _consume removes the given tokens from the pool, lowering the
+ /// rate tokens allowed to be consumed for subsequent calls.
+ /// @param requestTokens The total tokens to be consumed from the bucket.
+ /// @param tokenAddress The token to consume capacity for, use 0x0 to indicate aggregate value capacity.
+ /// @dev Reverts when requestTokens exceeds bucket capacity or available tokens in the bucket
+ /// @dev emits removal of requestTokens if requestTokens is > 0
+ function _consume(TokenBucket storage s_bucket, uint256 requestTokens, address tokenAddress) internal {
+ // If there is no value to remove or rate limiting is turned off, skip this step to reduce gas usage
+ if (!s_bucket.isEnabled || requestTokens == 0) {
+ return;
+ }
+
+ uint256 tokens = s_bucket.tokens;
+ uint256 capacity = s_bucket.capacity;
+ uint256 timeDiff = block.timestamp - s_bucket.lastUpdated;
+
+ if (timeDiff != 0) {
+ if (tokens > capacity) revert BucketOverfilled();
+
+ // Refill tokens when arriving at a new block time
+ tokens = _calculateRefill(capacity, tokens, timeDiff, s_bucket.rate);
+
+ s_bucket.lastUpdated = uint32(block.timestamp);
+ }
+
+ if (capacity < requestTokens) {
+ // Token address 0 indicates consuming aggregate value rate limit capacity.
+ if (tokenAddress == address(0)) revert AggregateValueMaxCapacityExceeded(capacity, requestTokens);
+ revert TokenMaxCapacityExceeded(capacity, requestTokens, tokenAddress);
+ }
+ if (tokens < requestTokens) {
+ uint256 rate = s_bucket.rate;
+ // Wait required until the bucket is refilled enough to accept this value, round up to next higher second
+ // Consume is not guaranteed to succeed after wait time passes if there is competing traffic.
+ // This acts as a lower bound of wait time.
+ uint256 minWaitInSeconds = ((requestTokens - tokens) + (rate - 1)) / rate;
+
+ if (tokenAddress == address(0)) revert AggregateValueRateLimitReached(minWaitInSeconds, tokens);
+ revert TokenRateLimitReached(minWaitInSeconds, tokens, tokenAddress);
+ }
+ tokens -= requestTokens;
+
+ // Downcast is safe here, as tokens is not larger than capacity
+ s_bucket.tokens = uint128(tokens);
+ emit TokensConsumed(requestTokens);
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function _currentTokenBucketState(TokenBucket memory bucket) internal view returns (TokenBucket memory) {
+ // We update the bucket to reflect the status at the exact time of the
+ // call. This means we might need to refill a part of the bucket based
+ // on the time that has passed since the last update.
+ bucket.tokens =
+ uint128(_calculateRefill(bucket.capacity, bucket.tokens, block.timestamp - bucket.lastUpdated, bucket.rate));
+ bucket.lastUpdated = uint32(block.timestamp);
+ return bucket;
+ }
+
+ /// @notice Sets the rate limited config.
+ /// @param s_bucket The token bucket
+ /// @param config The new config
+ function _setTokenBucketConfig(TokenBucket storage s_bucket, Config memory config) internal {
+ // First update the bucket to make sure the proper rate is used for all the time
+ // up until the config change.
+ uint256 timeDiff = block.timestamp - s_bucket.lastUpdated;
+ if (timeDiff != 0) {
+ s_bucket.tokens = uint128(_calculateRefill(s_bucket.capacity, s_bucket.tokens, timeDiff, s_bucket.rate));
+
+ s_bucket.lastUpdated = uint32(block.timestamp);
+ }
+
+ s_bucket.tokens = uint128(_min(config.capacity, s_bucket.tokens));
+ s_bucket.isEnabled = config.isEnabled;
+ s_bucket.capacity = config.capacity;
+ s_bucket.rate = config.rate;
+
+ emit ConfigChanged(config);
+ }
+
+ /// @notice Validates the token bucket config
+ function _validateTokenBucketConfig(Config memory config, bool mustBeDisabled) internal pure {
+ if (config.isEnabled) {
+ if (config.rate >= config.capacity || config.rate == 0) {
+ revert InvalidRateLimitRate(config);
+ }
+ if (mustBeDisabled) {
+ revert RateLimitMustBeDisabled();
+ }
+ } else {
+ if (config.rate != 0 || config.capacity != 0) {
+ revert DisabledNonZeroRateLimit(config);
+ }
+ }
+ }
+
+ /// @notice Calculate refilled tokens
+ /// @param capacity bucket capacity
+ /// @param tokens current bucket tokens
+ /// @param timeDiff block time difference since last refill
+ /// @param rate bucket refill rate
+ /// @return the value of tokens after refill
+ function _calculateRefill(
+ uint256 capacity,
+ uint256 tokens,
+ uint256 timeDiff,
+ uint256 rate
+ ) private pure returns (uint256) {
+ return _min(capacity, tokens + timeDiff * rate);
+ }
+
+ /// @notice Return the smallest of two integers
+ /// @param a first int
+ /// @param b second int
+ /// @return smallest
+ function _min(uint256 a, uint256 b) internal pure returns (uint256) {
+ return a < b ? a : b;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/libraries/USDPriceWith18Decimals.sol b/contracts/src/v0.8/ccip/libraries/USDPriceWith18Decimals.sol
new file mode 100644
index 00000000000..3508276d769
--- /dev/null
+++ b/contracts/src/v0.8/ccip/libraries/USDPriceWith18Decimals.sol
@@ -0,0 +1,45 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+library USDPriceWith18Decimals {
+ /// @notice Takes a price in USD, with 18 decimals per 1e18 token amount,
+ /// and amount of the smallest token denomination,
+ /// calculates the value in USD with 18 decimals.
+ /// @param tokenPrice The USD price of the token.
+ /// @param tokenAmount Amount of the smallest token denomination.
+ /// @return USD value with 18 decimals.
+ /// @dev this function assumes that no more than 1e59 US dollar worth of token is passed in.
+ /// If more is sent, this function will overflow and revert.
+ /// Since there isn't even close to 1e59 dollars, this is ok for all legit tokens.
+ function _calcUSDValueFromTokenAmount(uint224 tokenPrice, uint256 tokenAmount) internal pure returns (uint256) {
+ /// LINK Example:
+ /// tokenPrice: 8e18 -> $8/LINK, as 1e18 token amount is 1 LINK, worth 8 USD, or 8e18 with 18 decimals
+ /// tokenAmount: 2e18 -> 2 LINK
+ /// result: 8e18 * 2e18 / 1e18 -> 16e18 with 18 decimals = $16
+
+ /// USDC Example:
+ /// tokenPrice: 1e30 -> $1/USDC, as 1e18 token amount is 1e12 USDC, worth 1e12 USD, or 1e30 with 18 decimals
+ /// tokenAmount: 5e6 -> 5 USDC
+ /// result: 1e30 * 5e6 / 1e18 -> 5e18 with 18 decimals = $5
+ return (tokenPrice * tokenAmount) / 1e18;
+ }
+
+ /// @notice Takes a price in USD, with 18 decimals per 1e18 token amount,
+ /// and USD value with 18 decimals,
+ /// calculates amount of the smallest token denomination.
+ /// @param tokenPrice The USD price of the token.
+ /// @param usdValue USD value with 18 decimals.
+ /// @return Amount of the smallest token denomination.
+ function _calcTokenAmountFromUSDValue(uint224 tokenPrice, uint256 usdValue) internal pure returns (uint256) {
+ /// LINK Example:
+ /// tokenPrice: 8e18 -> $8/LINK, as 1e18 token amount is 1 LINK, worth 8 USD, or 8e18 with 18 decimals
+ /// usdValue: 16e18 -> $16
+ /// result: 16e18 * 1e18 / 8e18 -> 2e18 = 2 LINK
+
+ /// USDC Example:
+ /// tokenPrice: 1e30 -> $1/USDC, as 1e18 token amount is 1e12 USDC, worth 1e12 USD, or 1e30 with 18 decimals
+ /// usdValue: 5e18 -> $5
+ /// result: 5e18 * 1e18 / 1e30 -> 5e6 = 5 USDC
+ return (usdValue * 1e18) / tokenPrice;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/ocr/MultiOCR3Base.sol b/contracts/src/v0.8/ccip/ocr/MultiOCR3Base.sol
new file mode 100644
index 00000000000..1872ae276ce
--- /dev/null
+++ b/contracts/src/v0.8/ccip/ocr/MultiOCR3Base.sol
@@ -0,0 +1,323 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+
+/// @notice Onchain verification of reports from the offchain reporting protocol
+/// with multiple OCR plugin support.
+abstract contract MultiOCR3Base is ITypeAndVersion, OwnerIsCreator {
+ // Maximum number of oracles the offchain reporting protocol is designed for
+ uint256 internal constant MAX_NUM_ORACLES = 31;
+
+ /// @notice triggers a new run of the offchain reporting protocol
+ /// @param ocrPluginType OCR plugin type for which the config was set
+ /// @param configDigest configDigest of this configuration
+ /// @param signers ith element is address ith oracle uses to sign a report
+ /// @param transmitters ith element is address ith oracle uses to transmit a report via the transmit method
+ /// @param F maximum number of faulty/dishonest oracles the protocol can tolerate while still working correctly
+ event ConfigSet(uint8 ocrPluginType, bytes32 configDigest, address[] signers, address[] transmitters, uint8 F);
+
+ /// @notice optionally emitted to indicate the latest configDigest and sequence number
+ /// for which a report was successfully transmitted. Alternatively, the contract may
+ /// use latestConfigDigestAndEpoch with scanLogs set to false.
+ event Transmitted(uint8 indexed ocrPluginType, bytes32 configDigest, uint64 sequenceNumber);
+
+ enum InvalidConfigErrorType {
+ F_MUST_BE_POSITIVE,
+ TOO_MANY_TRANSMITTERS,
+ TOO_MANY_SIGNERS,
+ F_TOO_HIGH,
+ REPEATED_ORACLE_ADDRESS
+ }
+
+ error InvalidConfig(InvalidConfigErrorType errorType);
+ error WrongMessageLength(uint256 expected, uint256 actual);
+ error ConfigDigestMismatch(bytes32 expected, bytes32 actual);
+ error ForkedChain(uint256 expected, uint256 actual);
+ error WrongNumberOfSignatures();
+ error SignaturesOutOfRegistration();
+ error UnauthorizedTransmitter();
+ error UnauthorizedSigner();
+ error NonUniqueSignatures();
+ error OracleCannotBeZeroAddress();
+ error StaticConfigCannotBeChanged(uint8 ocrPluginType);
+
+ /// @dev Packing these fields used on the hot path in a ConfigInfo variable reduces the
+ /// retrieval of all of them to a minimum number of SLOADs.
+ struct ConfigInfo {
+ bytes32 configDigest;
+ uint8 F; // ──────────────────────────────╮ maximum number of faulty/dishonest oracles the system can tolerate
+ uint8 n; // │ number of signers / transmitters
+ bool isSignatureVerificationEnabled; // ──╯ if true, requires signers and verifies signatures on transmission verification
+ }
+
+ /// @notice Used for s_oracles[a].role, where a is an address, to track the purpose
+ /// of the address, or to indicate that the address is unset.
+ enum Role {
+ // No oracle role has been set for address a
+ Unset,
+ // Signing address for the s_oracles[a].index'th oracle. I.e., report
+ // signatures from this oracle should ecrecover back to address a.
+ Signer,
+ // Transmission address for the s_oracles[a].index'th oracle. I.e., if a
+ // report is received by OCR2Aggregator.transmit in which msg.sender is
+ // a, it is attributed to the s_oracles[a].index'th oracle.
+ Transmitter
+ }
+
+ struct Oracle {
+ uint8 index; // ───╮ Index of oracle in s_signers/s_transmitters
+ Role role; // ─────╯ Role of the address which mapped to this struct
+ }
+
+ /// @notice OCR configuration for a single OCR plugin within a DON
+ struct OCRConfig {
+ ConfigInfo configInfo; // latest OCR config
+ address[] signers; // addresses oracles use to sign the reports
+ address[] transmitters; // addresses oracles use to transmit the reports
+ }
+
+ /// @notice Args to update an OCR Config
+ struct OCRConfigArgs {
+ bytes32 configDigest; // Config digest to update to
+ uint8 ocrPluginType; // ──────────────────╮ OCR plugin type to update config for
+ uint8 F; // │ maximum number of faulty/dishonest oracles
+ bool isSignatureVerificationEnabled; // ──╯ if true, requires signers and verifies signatures on transmission verification
+ address[] signers; // signing address of each oracle
+ address[] transmitters; // transmission address of each oracle (i.e. the address the oracle actually sends transactions to the contract from)
+ }
+
+ /// @notice mapping of OCR plugin type -> DON config
+ mapping(uint8 ocrPluginType => OCRConfig config) internal s_ocrConfigs;
+
+ /// @notice OCR plugin type => signer OR transmitter address mapping
+ mapping(uint8 ocrPluginType => mapping(address signerOrTransmiter => Oracle oracle)) internal s_oracles;
+
+ // Constant-length components of the msg.data sent to transmit.
+ // See the "If we wanted to call sam" example on for example reasoning
+ // https://solidity.readthedocs.io/en/v0.7.2/abi-spec.html
+
+ /// @notice constant length component for transmit functions with no signatures.
+ /// The signatures are expected to match transmitPlugin(reportContext, report)
+ uint16 private constant TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT_NO_SIGNATURES = 4 // function selector
+ + 3 * 32 // 3 words containing reportContext
+ + 32 // word containing start location of abiencoded report value
+ + 32; // word containing length of report
+
+ /// @notice extra constant length component for transmit functions with signatures (relative to no signatures)
+ /// The signatures are expected to match transmitPlugin(reportContext, report, rs, ss, rawVs)
+ uint16 private constant TRANSMIT_MSGDATA_EXTRA_CONSTANT_LENGTH_COMPONENT_FOR_SIGNATURES = 32 // word containing location start of abiencoded rs value
+ + 32 // word containing start location of abiencoded ss value
+ + 32 // rawVs value
+ + 32 // word containing length rs
+ + 32; // word containing length of ss
+
+ uint256 internal immutable i_chainID;
+
+ constructor() {
+ i_chainID = block.chainid;
+ }
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles
+ /// NOTE: The OCR3 config must be sanity-checked against the home-chain registry configuration, to ensure
+ /// home-chain and remote-chain parity!
+ /// @param ocrConfigArgs OCR config update args
+ function setOCR3Configs(OCRConfigArgs[] memory ocrConfigArgs) external onlyOwner {
+ for (uint256 i; i < ocrConfigArgs.length; ++i) {
+ _setOCR3Config(ocrConfigArgs[i]);
+ }
+ }
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles for a single OCR plugin type
+ /// @param ocrConfigArgs OCR config update args
+ function _setOCR3Config(OCRConfigArgs memory ocrConfigArgs) internal {
+ if (ocrConfigArgs.F == 0) revert InvalidConfig(InvalidConfigErrorType.F_MUST_BE_POSITIVE);
+
+ uint8 ocrPluginType = ocrConfigArgs.ocrPluginType;
+ OCRConfig storage ocrConfig = s_ocrConfigs[ocrPluginType];
+ ConfigInfo storage configInfo = ocrConfig.configInfo;
+
+ // If F is 0, then the config is not yet set
+ if (configInfo.F == 0) {
+ configInfo.isSignatureVerificationEnabled = ocrConfigArgs.isSignatureVerificationEnabled;
+ } else if (configInfo.isSignatureVerificationEnabled != ocrConfigArgs.isSignatureVerificationEnabled) {
+ revert StaticConfigCannotBeChanged(ocrPluginType);
+ }
+
+ address[] memory transmitters = ocrConfigArgs.transmitters;
+ // Transmitters are expected to never exceed 255 (since this is bounded by MAX_NUM_ORACLES)
+ uint8 newTransmittersLength = uint8(transmitters.length);
+
+ if (newTransmittersLength > MAX_NUM_ORACLES) revert InvalidConfig(InvalidConfigErrorType.TOO_MANY_TRANSMITTERS);
+
+ _clearOracleRoles(ocrPluginType, ocrConfig.transmitters);
+
+ if (ocrConfigArgs.isSignatureVerificationEnabled) {
+ _clearOracleRoles(ocrPluginType, ocrConfig.signers);
+
+ address[] memory signers = ocrConfigArgs.signers;
+ ocrConfig.signers = signers;
+
+ uint8 signersLength = uint8(signers.length);
+ configInfo.n = signersLength;
+
+ if (signersLength > MAX_NUM_ORACLES) revert InvalidConfig(InvalidConfigErrorType.TOO_MANY_SIGNERS);
+ if (signersLength <= 3 * ocrConfigArgs.F) revert InvalidConfig(InvalidConfigErrorType.F_TOO_HIGH);
+
+ _assignOracleRoles(ocrPluginType, signers, Role.Signer);
+ }
+
+ _assignOracleRoles(ocrPluginType, transmitters, Role.Transmitter);
+
+ ocrConfig.transmitters = transmitters;
+ configInfo.F = ocrConfigArgs.F;
+ configInfo.configDigest = ocrConfigArgs.configDigest;
+
+ emit ConfigSet(
+ ocrPluginType, ocrConfigArgs.configDigest, ocrConfig.signers, ocrConfigArgs.transmitters, ocrConfigArgs.F
+ );
+ _afterOCR3ConfigSet(ocrPluginType);
+ }
+
+ /// @notice Hook that is called after a plugin's OCR3 config changes
+ /// @param ocrPluginType Plugin type for which the config changed
+ function _afterOCR3ConfigSet(uint8 ocrPluginType) internal virtual;
+
+ /// @notice Clears oracle roles for the provided oracle addresses
+ /// @param ocrPluginType OCR plugin type to clear roles for
+ /// @param oracleAddresses Oracle addresses to clear roles for
+ function _clearOracleRoles(uint8 ocrPluginType, address[] memory oracleAddresses) internal {
+ for (uint256 i = 0; i < oracleAddresses.length; ++i) {
+ delete s_oracles[ocrPluginType][oracleAddresses[i]];
+ }
+ }
+
+ /// @notice Assigns oracles roles for the provided oracle addresses with uniqueness verification
+ /// @param ocrPluginType OCR plugin type to assign roles for
+ /// @param oracleAddresses Oracle addresses to assign roles to
+ /// @param role Role to assign
+ function _assignOracleRoles(uint8 ocrPluginType, address[] memory oracleAddresses, Role role) internal {
+ for (uint8 i = 0; i < oracleAddresses.length; ++i) {
+ address oracle = oracleAddresses[i];
+ if (s_oracles[ocrPluginType][oracle].role != Role.Unset) {
+ revert InvalidConfig(InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS);
+ }
+ if (oracle == address(0)) revert OracleCannotBeZeroAddress();
+ s_oracles[ocrPluginType][oracle] = Oracle(i, role);
+ }
+ }
+
+ /// @notice _transmit is called to post a new report to the contract.
+ /// The function should be called after the per-DON reporting logic is completed.
+ /// @param ocrPluginType OCR plugin type to transmit report for
+ /// @param report serialized report, which the signatures are signing.
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param rawVs ith element is the the V component of the ith signature
+ function _transmit(
+ uint8 ocrPluginType,
+ // NOTE: If these parameters are changed, expectedMsgDataLength and/or
+ // TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT need to be changed accordingly
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] memory rs,
+ bytes32[] memory ss,
+ bytes32 rawVs // signatures
+ ) internal {
+ // reportContext consists of:
+ // reportContext[0]: ConfigDigest
+ // reportContext[1]: 24 byte padding, 8 byte sequence number
+ // reportContext[2]: ExtraHash
+ ConfigInfo memory configInfo = s_ocrConfigs[ocrPluginType].configInfo;
+ bytes32 configDigest = reportContext[0];
+
+ // Scoping this reduces stack pressure and gas usage
+ {
+ uint256 expectedDataLength = uint256(TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT_NO_SIGNATURES) + report.length; // one byte pure entry in _report
+
+ if (configInfo.isSignatureVerificationEnabled) {
+ expectedDataLength += TRANSMIT_MSGDATA_EXTRA_CONSTANT_LENGTH_COMPONENT_FOR_SIGNATURES + rs.length * 32 // 32 bytes per entry in _rs
+ + ss.length * 32; // 32 bytes per entry in _ss)
+ }
+
+ if (msg.data.length != expectedDataLength) revert WrongMessageLength(expectedDataLength, msg.data.length);
+ }
+
+ if (configInfo.configDigest != configDigest) {
+ revert ConfigDigestMismatch(configInfo.configDigest, configDigest);
+ }
+ // If the cached chainID at time of deployment doesn't match the current chainID, we reject all signed reports.
+ // This avoids a (rare) scenario where chain A forks into chain A and A', A' still has configDigest
+ // calculated from chain A and so OCR reports will be valid on both forks.
+ _whenChainNotForked();
+
+ // Scoping this reduces stack pressure and gas usage
+ {
+ Oracle memory transmitter = s_oracles[ocrPluginType][msg.sender];
+ // Check that sender is authorized to report
+ if (
+ !(
+ transmitter.role == Role.Transmitter
+ && msg.sender == s_ocrConfigs[ocrPluginType].transmitters[transmitter.index]
+ )
+ ) {
+ revert UnauthorizedTransmitter();
+ }
+ }
+
+ if (configInfo.isSignatureVerificationEnabled) {
+ // Scoping to reduce stack pressure
+ {
+ if (rs.length != configInfo.F + 1) revert WrongNumberOfSignatures();
+ if (rs.length != ss.length) revert SignaturesOutOfRegistration();
+ }
+
+ bytes32 h = keccak256(abi.encodePacked(keccak256(report), reportContext));
+ _verifySignatures(ocrPluginType, h, rs, ss, rawVs);
+ }
+
+ emit Transmitted(ocrPluginType, configDigest, uint64(uint256(reportContext[1])));
+ }
+
+ /// @notice verifies the signatures of a hashed report value for one OCR plugin type
+ /// @param ocrPluginType OCR plugin type to transmit report for
+ /// @param hashedReport hashed encoded packing of report + reportContext
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param rawVs ith element is the the V component of the ith signature
+ function _verifySignatures(
+ uint8 ocrPluginType,
+ bytes32 hashedReport,
+ bytes32[] memory rs,
+ bytes32[] memory ss,
+ bytes32 rawVs // signatures
+ ) internal view {
+ // Verify signatures attached to report
+ bool[MAX_NUM_ORACLES] memory signed;
+
+ uint256 numberOfSignatures = rs.length;
+ for (uint256 i; i < numberOfSignatures; ++i) {
+ // Safe from ECDSA malleability here since we check for duplicate signers.
+ address signer = ecrecover(hashedReport, uint8(rawVs[i]) + 27, rs[i], ss[i]);
+ // Since we disallow address(0) as a valid signer address, it can
+ // never have a signer role.
+ Oracle memory oracle = s_oracles[ocrPluginType][signer];
+ if (oracle.role != Role.Signer) revert UnauthorizedSigner();
+ if (signed[oracle.index]) revert NonUniqueSignatures();
+ signed[oracle.index] = true;
+ }
+ }
+
+ /// @notice Validates that the chain ID has not diverged after deployment. Reverts if the chain IDs do not match
+ function _whenChainNotForked() internal view {
+ if (i_chainID != block.chainid) revert ForkedChain(i_chainID, block.chainid);
+ }
+
+ /// @notice information about current offchain reporting protocol configuration
+ /// @param ocrPluginType OCR plugin type to return config details for
+ /// @return ocrConfig OCR config for the plugin type
+ function latestConfigDetails(uint8 ocrPluginType) external view returns (OCRConfig memory ocrConfig) {
+ return s_ocrConfigs[ocrPluginType];
+ }
+}
diff --git a/contracts/src/v0.8/ccip/ocr/OCR2Abstract.sol b/contracts/src/v0.8/ccip/ocr/OCR2Abstract.sol
new file mode 100644
index 00000000000..741433bd5ad
--- /dev/null
+++ b/contracts/src/v0.8/ccip/ocr/OCR2Abstract.sol
@@ -0,0 +1,122 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+
+abstract contract OCR2Abstract is ITypeAndVersion {
+ // Maximum number of oracles the offchain reporting protocol is designed for
+ uint256 internal constant MAX_NUM_ORACLES = 31;
+
+ /// @notice triggers a new run of the offchain reporting protocol
+ /// @param previousConfigBlockNumber block in which the previous config was set, to simplify historic analysis
+ /// @param configDigest configDigest of this configuration
+ /// @param configCount ordinal number of this config setting among all config settings over the life of this contract
+ /// @param signers ith element is address ith oracle uses to sign a report
+ /// @param transmitters ith element is address ith oracle uses to transmit a report via the transmit method
+ /// @param f maximum number of faulty/dishonest oracles the protocol can tolerate while still working correctly
+ /// @param onchainConfig serialized configuration used by the contract (and possibly oracles)
+ /// @param offchainConfigVersion version of the serialization format used for "offchainConfig" parameter
+ /// @param offchainConfig serialized configuration used by the oracles exclusively and only passed through the contract
+ event ConfigSet(
+ uint32 previousConfigBlockNumber,
+ bytes32 configDigest,
+ uint64 configCount,
+ address[] signers,
+ address[] transmitters,
+ uint8 f,
+ bytes onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes offchainConfig
+ );
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles
+ /// @param signers addresses with which oracles sign the reports
+ /// @param transmitters addresses oracles use to transmit the reports
+ /// @param f number of faulty oracles the system can tolerate
+ /// @param onchainConfig serialized configuration used by the contract (and possibly oracles)
+ /// @param offchainConfigVersion version number for offchainEncoding schema
+ /// @param offchainConfig serialized configuration used by the oracles exclusively and only passed through the contract
+ function setOCR2Config(
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) external virtual;
+
+ /// @notice information about current offchain reporting protocol configuration
+ /// @return configCount ordinal number of current config, out of all configs applied to this contract so far
+ /// @return blockNumber block at which this config was set
+ /// @return configDigest domain-separation tag for current config (see _configDigestFromConfigData)
+ function latestConfigDetails()
+ external
+ view
+ virtual
+ returns (uint32 configCount, uint32 blockNumber, bytes32 configDigest);
+
+ function _configDigestFromConfigData(
+ uint256 chainId,
+ address contractAddress,
+ uint64 configCount,
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) internal pure returns (bytes32) {
+ uint256 h = uint256(
+ keccak256(
+ abi.encode(
+ chainId,
+ contractAddress,
+ configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ )
+ )
+ );
+ uint256 prefixMask = type(uint256).max << (256 - 16); // 0xFFFF00..00
+ uint256 prefix = 0x0001 << (256 - 16); // 0x000100..00
+ return bytes32((prefix & prefixMask) | (h & ~prefixMask));
+ }
+
+ /// @notice optionally emitted to indicate the latest configDigest and epoch for
+ /// which a report was successfully transmitted. Alternatively, the contract may
+ /// use latestConfigDigestAndEpoch with scanLogs set to false.
+ event Transmitted(bytes32 configDigest, uint32 epoch);
+
+ /// @notice optionally returns the latest configDigest and epoch for which a
+ /// report was successfully transmitted. Alternatively, the contract may return
+ /// scanLogs set to true and use Transmitted events to provide this information
+ /// to offchain watchers.
+ /// @return scanLogs indicates whether to rely on the configDigest and epoch
+ /// returned or whether to scan logs for the Transmitted event instead.
+ /// @return configDigest
+ /// @return epoch
+ function latestConfigDigestAndEpoch()
+ external
+ view
+ virtual
+ returns (bool scanLogs, bytes32 configDigest, uint32 epoch);
+
+ /// @notice transmit is called to post a new report to the contract
+ /// @param report serialized report, which the signatures are signing.
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param rawVs ith element is the the V component of the ith signature
+ function transmit(
+ // NOTE: If these parameters are changed, expectedMsgDataLength and/or
+ // TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT need to be changed accordingly
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 rawVs // signatures
+ ) external virtual;
+}
diff --git a/contracts/src/v0.8/ccip/ocr/OCR2Base.sol b/contracts/src/v0.8/ccip/ocr/OCR2Base.sol
new file mode 100644
index 00000000000..52a6df2f3a2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/ocr/OCR2Base.sol
@@ -0,0 +1,291 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {OCR2Abstract} from "./OCR2Abstract.sol";
+
+/// @notice Onchain verification of reports from the offchain reporting protocol
+/// @dev For details on its operation, see the offchain reporting protocol design
+/// doc, which refers to this contract as simply the "contract".
+abstract contract OCR2Base is OwnerIsCreator, OCR2Abstract {
+ error InvalidConfig(InvalidConfigErrorType errorType);
+ error WrongMessageLength(uint256 expected, uint256 actual);
+ error ConfigDigestMismatch(bytes32 expected, bytes32 actual);
+ error ForkedChain(uint256 expected, uint256 actual);
+ error WrongNumberOfSignatures();
+ error SignaturesOutOfRegistration();
+ error UnauthorizedTransmitter();
+ error UnauthorizedSigner();
+ error NonUniqueSignatures();
+ error OracleCannotBeZeroAddress();
+
+ enum InvalidConfigErrorType {
+ F_MUST_BE_POSITIVE,
+ TOO_MANY_SIGNERS,
+ F_TOO_HIGH,
+ REPEATED_ORACLE_ADDRESS,
+ NUM_SIGNERS_NOT_NUM_TRANSMITTERS
+ }
+
+ // Packing these fields used on the hot path in a ConfigInfo variable reduces the
+ // retrieval of all of them to a minimum number of SLOADs.
+ struct ConfigInfo {
+ bytes32 latestConfigDigest;
+ uint8 f;
+ uint8 n;
+ }
+
+ // Used for s_oracles[a].role, where a is an address, to track the purpose
+ // of the address, or to indicate that the address is unset.
+ enum Role {
+ // No oracle role has been set for address a
+ Unset,
+ // Signing address for the s_oracles[a].index'th oracle. I.e., report
+ // signatures from this oracle should ecrecover back to address a.
+ Signer,
+ // Transmission address for the s_oracles[a].index'th oracle. I.e., if a
+ // report is received by OCR2Aggregator.transmit in which msg.sender is
+ // a, it is attributed to the s_oracles[a].index'th oracle.
+ Transmitter
+ }
+
+ struct Oracle {
+ uint8 index; // Index of oracle in s_signers/s_transmitters
+ Role role; // Role of the address which mapped to this struct
+ }
+
+ // The current config
+ ConfigInfo internal s_configInfo;
+
+ // incremented each time a new config is posted. This count is incorporated
+ // into the config digest, to prevent replay attacks.
+ uint32 internal s_configCount;
+ // makes it easier for offchain systems to extract config from logs.
+ uint32 internal s_latestConfigBlockNumber;
+
+ // signer OR transmitter address
+ mapping(address signerOrTransmitter => Oracle oracle) internal s_oracles;
+
+ // s_signers contains the signing address of each oracle
+ address[] internal s_signers;
+
+ // s_transmitters contains the transmission address of each oracle,
+ // i.e. the address the oracle actually sends transactions to the contract from
+ address[] internal s_transmitters;
+
+ // The constant-length components of the msg.data sent to transmit.
+ // See the "If we wanted to call sam" example on for example reasoning
+ // https://solidity.readthedocs.io/en/v0.7.2/abi-spec.html
+ uint16 private constant TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT = 4 // function selector
+ + 32 * 3 // 3 words containing reportContext
+ + 32 // word containing start location of abiencoded report value
+ + 32 // word containing location start of abiencoded rs value
+ + 32 // word containing start location of abiencoded ss value
+ + 32 // rawVs value
+ + 32 // word containing length of report
+ + 32 // word containing length rs
+ + 32; // word containing length of ss
+
+ bool internal immutable i_uniqueReports;
+ uint256 internal immutable i_chainID;
+
+ constructor(bool uniqueReports) {
+ i_uniqueReports = uniqueReports;
+ i_chainID = block.chainid;
+ }
+
+ // Reverts transaction if config args are invalid
+ modifier checkConfigValid(uint256 numSigners, uint256 numTransmitters, uint256 f) {
+ if (numSigners > MAX_NUM_ORACLES) revert InvalidConfig(InvalidConfigErrorType.TOO_MANY_SIGNERS);
+ if (f == 0) revert InvalidConfig(InvalidConfigErrorType.F_MUST_BE_POSITIVE);
+ if (numSigners != numTransmitters) revert InvalidConfig(InvalidConfigErrorType.NUM_SIGNERS_NOT_NUM_TRANSMITTERS);
+ if (numSigners <= 3 * f) revert InvalidConfig(InvalidConfigErrorType.F_TOO_HIGH);
+ _;
+ }
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles
+ /// @param signers addresses with which oracles sign the reports
+ /// @param transmitters addresses oracles use to transmit the reports
+ /// @param f number of faulty oracles the system can tolerate
+ /// @param onchainConfig encoded on-chain contract configuration
+ /// @param offchainConfigVersion version number for offchainEncoding schema
+ /// @param offchainConfig encoded off-chain oracle configuration
+ function setOCR2Config(
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) external override checkConfigValid(signers.length, transmitters.length, f) onlyOwner {
+ _beforeSetConfig(onchainConfig);
+ uint256 oldSignerLength = s_signers.length;
+ for (uint256 i = 0; i < oldSignerLength; ++i) {
+ delete s_oracles[s_signers[i]];
+ delete s_oracles[s_transmitters[i]];
+ }
+
+ uint256 newSignersLength = signers.length;
+ for (uint256 i = 0; i < newSignersLength; ++i) {
+ // add new signer/transmitter addresses
+ address signer = signers[i];
+ if (s_oracles[signer].role != Role.Unset) revert InvalidConfig(InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS);
+ if (signer == address(0)) revert OracleCannotBeZeroAddress();
+ s_oracles[signer] = Oracle(uint8(i), Role.Signer);
+
+ address transmitter = transmitters[i];
+ if (s_oracles[transmitter].role != Role.Unset) {
+ revert InvalidConfig(InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS);
+ }
+ if (transmitter == address(0)) revert OracleCannotBeZeroAddress();
+ s_oracles[transmitter] = Oracle(uint8(i), Role.Transmitter);
+ }
+
+ s_signers = signers;
+ s_transmitters = transmitters;
+
+ s_configInfo.f = f;
+ s_configInfo.n = uint8(newSignersLength);
+ s_configInfo.latestConfigDigest = _configDigestFromConfigData(
+ block.chainid,
+ address(this),
+ ++s_configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+
+ uint32 previousConfigBlockNumber = s_latestConfigBlockNumber;
+ s_latestConfigBlockNumber = uint32(block.number);
+
+ emit ConfigSet(
+ previousConfigBlockNumber,
+ s_configInfo.latestConfigDigest,
+ s_configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+ }
+
+ /// @dev Hook that is run from setOCR2Config() right after validating configuration.
+ /// Empty by default, please provide an implementation in a child contract if you need additional configuration processing
+ function _beforeSetConfig(bytes memory _onchainConfig) internal virtual;
+
+ /// @return list of addresses permitted to transmit reports to this contract
+ /// @dev The list will match the order used to specify the transmitter during setConfig
+ function getTransmitters() external view returns (address[] memory) {
+ return s_transmitters;
+ }
+
+ /// @notice transmit is called to post a new report to the contract
+ /// @param report serialized report, which the signatures are signing.
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param rawVs ith element is the the V component of the ith signature
+ function transmit(
+ // NOTE: If these parameters are changed, expectedMsgDataLength and/or
+ // TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT need to be changed accordingly
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 rawVs // signatures
+ ) external override {
+ // Scoping this reduces stack pressure and gas usage
+ {
+ // report and epochAndRound
+ _report(report, uint40(uint256(reportContext[1])));
+ }
+
+ // reportContext consists of:
+ // reportContext[0]: ConfigDigest
+ // reportContext[1]: 27 byte padding, 4-byte epoch and 1-byte round
+ // reportContext[2]: ExtraHash
+ bytes32 configDigest = reportContext[0];
+ ConfigInfo memory configInfo = s_configInfo;
+
+ if (configInfo.latestConfigDigest != configDigest) {
+ revert ConfigDigestMismatch(configInfo.latestConfigDigest, configDigest);
+ }
+ // If the cached chainID at time of deployment doesn't match the current chainID, we reject all signed reports.
+ // This avoids a (rare) scenario where chain A forks into chain A and A', A' still has configDigest
+ // calculated from chain A and so OCR reports will be valid on both forks.
+ if (i_chainID != block.chainid) revert ForkedChain(i_chainID, block.chainid);
+
+ emit Transmitted(configDigest, uint32(uint256(reportContext[1]) >> 8));
+
+ uint256 expectedNumSignatures;
+ if (i_uniqueReports) {
+ expectedNumSignatures = (configInfo.n + configInfo.f) / 2 + 1;
+ } else {
+ expectedNumSignatures = configInfo.f + 1;
+ }
+ if (rs.length != expectedNumSignatures) revert WrongNumberOfSignatures();
+ if (rs.length != ss.length) revert SignaturesOutOfRegistration();
+
+ // Scoping this reduces stack pressure and gas usage
+ {
+ Oracle memory transmitter = s_oracles[msg.sender];
+ // Check that sender is authorized to report
+ if (!(transmitter.role == Role.Transmitter && msg.sender == s_transmitters[transmitter.index])) {
+ revert UnauthorizedTransmitter();
+ }
+ }
+ // Scoping this reduces stack pressure and gas usage
+ {
+ uint256 expectedDataLength = uint256(TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT) + report.length // one byte pure entry in _report
+ + rs.length * 32 // 32 bytes per entry in _rs
+ + ss.length * 32; // 32 bytes per entry in _ss)
+ if (msg.data.length != expectedDataLength) revert WrongMessageLength(expectedDataLength, msg.data.length);
+ }
+
+ // Verify signatures attached to report
+ bytes32 h = keccak256(abi.encodePacked(keccak256(report), reportContext));
+ bool[MAX_NUM_ORACLES] memory signed;
+
+ uint256 numberOfSignatures = rs.length;
+ for (uint256 i = 0; i < numberOfSignatures; ++i) {
+ // Safe from ECDSA malleability here since we check for duplicate signers.
+ address signer = ecrecover(h, uint8(rawVs[i]) + 27, rs[i], ss[i]);
+ // Since we disallow address(0) as a valid signer address, it can
+ // never have a signer role.
+ Oracle memory oracle = s_oracles[signer];
+ if (oracle.role != Role.Signer) revert UnauthorizedSigner();
+ if (signed[oracle.index]) revert NonUniqueSignatures();
+ signed[oracle.index] = true;
+ }
+ }
+
+ /// @notice information about current offchain reporting protocol configuration
+ /// @return configCount ordinal number of current config, out of all configs applied to this contract so far
+ /// @return blockNumber block at which this config was set
+ /// @return configDigest domain-separation tag for current config (see _configDigestFromConfigData)
+ function latestConfigDetails()
+ external
+ view
+ override
+ returns (uint32 configCount, uint32 blockNumber, bytes32 configDigest)
+ {
+ return (s_configCount, s_latestConfigBlockNumber, s_configInfo.latestConfigDigest);
+ }
+
+ /// @inheritdoc OCR2Abstract
+ function latestConfigDigestAndEpoch()
+ external
+ view
+ virtual
+ override
+ returns (bool scanLogs, bytes32 configDigest, uint32 epoch)
+ {
+ return (true, bytes32(0), uint32(0));
+ }
+
+ function _report(bytes calldata report, uint40 epochAndRound) internal virtual;
+}
diff --git a/contracts/src/v0.8/ccip/ocr/OCR2BaseNoChecks.sol b/contracts/src/v0.8/ccip/ocr/OCR2BaseNoChecks.sol
new file mode 100644
index 00000000000..a79df8d589a
--- /dev/null
+++ b/contracts/src/v0.8/ccip/ocr/OCR2BaseNoChecks.sol
@@ -0,0 +1,242 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {OCR2Abstract} from "./OCR2Abstract.sol";
+
+/// @notice Onchain verification of reports from the offchain reporting protocol
+/// @dev For details on its operation, see the offchain reporting protocol design
+/// doc, which refers to this contract as simply the "contract".
+/// @dev This contract does ***NOT*** check the supplied signatures on `transmit`
+/// This is intentional.
+abstract contract OCR2BaseNoChecks is OwnerIsCreator, OCR2Abstract {
+ error InvalidConfig(InvalidConfigErrorType errorType);
+ error WrongMessageLength(uint256 expected, uint256 actual);
+ error ConfigDigestMismatch(bytes32 expected, bytes32 actual);
+ error ForkedChain(uint256 expected, uint256 actual);
+ error UnauthorizedTransmitter();
+ error OracleCannotBeZeroAddress();
+
+ enum InvalidConfigErrorType {
+ F_MUST_BE_POSITIVE,
+ TOO_MANY_TRANSMITTERS,
+ REPEATED_ORACLE_ADDRESS
+ }
+
+ // Packing these fields used on the hot path in a ConfigInfo variable reduces the
+ // retrieval of all of them to a minimum number of SLOADs.
+ struct ConfigInfo {
+ bytes32 latestConfigDigest;
+ uint8 f;
+ uint8 n;
+ }
+
+ // Used for s_oracles[a].role, where a is an address, to track the purpose
+ // of the address, or to indicate that the address is unset.
+ enum Role {
+ // No oracle role has been set for address a
+ Unset,
+ // Unused
+ Signer,
+ // Transmission address for the s_oracles[a].index'th oracle. I.e., if a
+ // report is received by OCR2Aggregator.transmit in which msg.sender is
+ // a, it is attributed to the s_oracles[a].index'th oracle.
+ Transmitter
+ }
+
+ struct Oracle {
+ uint8 index; // Index of oracle in s_transmitters
+ Role role; // Role of the address which mapped to this struct
+ }
+
+ // The current config
+ ConfigInfo internal s_configInfo;
+
+ // incremented each time a new config is posted. This count is incorporated
+ // into the config digest, to prevent replay attacks.
+ uint32 internal s_configCount;
+ // makes it easier for offchain systems to extract config from logs.
+ uint32 internal s_latestConfigBlockNumber;
+
+ // Transmitter address
+ mapping(address transmitter => Oracle oracle) internal s_oracles;
+
+ // s_transmitters contains the transmission address of each oracle,
+ // i.e. the address the oracle actually sends transactions to the contract from
+ address[] internal s_transmitters;
+
+ // The constant-length components of the msg.data sent to transmit.
+ // See the "If we wanted to call sam" example on for example reasoning
+ // https://solidity.readthedocs.io/en/v0.7.2/abi-spec.html
+ uint16 private constant TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT = 4 // function selector
+ + 32 * 3 // 3 words containing reportContext
+ + 32 // word containing start location of abiencoded report value
+ + 32 // word containing location start of abiencoded rs value
+ + 32 // word containing start location of abiencoded ss value
+ + 32 // rawVs value
+ + 32 // word containing length of report
+ + 32 // word containing length rs
+ + 32; // word containing length of ss
+
+ uint256 internal immutable i_chainID;
+
+ // Reverts transaction if config args are invalid
+ modifier checkConfigValid(uint256 numTransmitters, uint256 f) {
+ if (numTransmitters > MAX_NUM_ORACLES) revert InvalidConfig(InvalidConfigErrorType.TOO_MANY_TRANSMITTERS);
+ if (f == 0) revert InvalidConfig(InvalidConfigErrorType.F_MUST_BE_POSITIVE);
+ _;
+ }
+
+ constructor() {
+ i_chainID = block.chainid;
+ }
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles
+ /// @param signers addresses with which oracles sign the reports
+ /// @param transmitters addresses oracles use to transmit the reports
+ /// @param f number of faulty oracles the system can tolerate
+ /// @param onchainConfig encoded on-chain contract configuration
+ /// @param offchainConfigVersion version number for offchainEncoding schema
+ /// @param offchainConfig encoded off-chain oracle configuration
+ function setOCR2Config(
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) external override checkConfigValid(transmitters.length, f) onlyOwner {
+ _beforeSetConfig(onchainConfig);
+ // Scoped to reduce contract size
+ {
+ uint256 oldTransmitterLength = s_transmitters.length;
+ for (uint256 i = 0; i < oldTransmitterLength; ++i) {
+ delete s_oracles[s_transmitters[i]];
+ }
+ }
+ uint256 newTransmitterLength = transmitters.length;
+ for (uint256 i = 0; i < newTransmitterLength; ++i) {
+ address transmitter = transmitters[i];
+ if (s_oracles[transmitter].role != Role.Unset) {
+ revert InvalidConfig(InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS);
+ }
+ if (transmitter == address(0)) revert OracleCannotBeZeroAddress();
+ s_oracles[transmitter] = Oracle(uint8(i), Role.Transmitter);
+ }
+
+ s_transmitters = transmitters;
+
+ s_configInfo.f = f;
+ s_configInfo.n = uint8(newTransmitterLength);
+ s_configInfo.latestConfigDigest = _configDigestFromConfigData(
+ block.chainid,
+ address(this),
+ ++s_configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+
+ uint32 previousConfigBlockNumber = s_latestConfigBlockNumber;
+ s_latestConfigBlockNumber = uint32(block.number);
+
+ emit ConfigSet(
+ previousConfigBlockNumber,
+ s_configInfo.latestConfigDigest,
+ s_configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+ }
+
+ /// @dev Hook that is run from setOCR2Config() right after validating configuration.
+ /// Empty by default, please provide an implementation in a child contract if you need additional configuration processing
+ function _beforeSetConfig(bytes memory _onchainConfig) internal virtual;
+
+ /// @return list of addresses permitted to transmit reports to this contract
+ /// @dev The list will match the order used to specify the transmitter during setConfig
+ function getTransmitters() external view returns (address[] memory) {
+ return s_transmitters;
+ }
+
+ /// @notice transmit is called to post a new report to the contract
+ /// @param report serialized report, which the signatures are signing.
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ function transmit(
+ // NOTE: If these parameters are changed, expectedMsgDataLength and/or
+ // TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT need to be changed accordingly
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 // signatures
+ ) external override {
+ _report(report);
+
+ // reportContext consists of:
+ // reportContext[0]: ConfigDigest
+ // reportContext[1]: 27 byte padding, 4-byte epoch and 1-byte round
+ // reportContext[2]: ExtraHash
+ bytes32 configDigest = reportContext[0];
+ bytes32 latestConfigDigest = s_configInfo.latestConfigDigest;
+ if (latestConfigDigest != configDigest) revert ConfigDigestMismatch(latestConfigDigest, configDigest);
+ _checkChainForked();
+
+ emit Transmitted(configDigest, uint32(uint256(reportContext[1]) >> 8));
+
+ // Scoping this reduces stack pressure and gas usage
+ {
+ Oracle memory transmitter = s_oracles[msg.sender];
+ // Check that sender is authorized to report
+ if (!(transmitter.role == Role.Transmitter && msg.sender == s_transmitters[transmitter.index])) {
+ revert UnauthorizedTransmitter();
+ }
+ }
+
+ uint256 expectedDataLength = uint256(TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT) + report.length // one byte pure entry in _report
+ + rs.length * 32 // 32 bytes per entry in _rs
+ + ss.length * 32; // 32 bytes per entry in _ss)
+ if (msg.data.length != expectedDataLength) revert WrongMessageLength(expectedDataLength, msg.data.length);
+ }
+
+ function _checkChainForked() internal view {
+ // If the cached chainID at time of deployment doesn't match the current chainID, we reject all signed reports.
+ // This avoids a (rare) scenario where chain A forks into chain A and A', A' still has configDigest
+ // calculated from chain A and so OCR reports will be valid on both forks.
+ if (i_chainID != block.chainid) revert ForkedChain(i_chainID, block.chainid);
+ }
+
+ /// @notice information about current offchain reporting protocol configuration
+ /// @return configCount ordinal number of current config, out of all configs applied to this contract so far
+ /// @return blockNumber block at which this config was set
+ /// @return configDigest domain-separation tag for current config (see _configDigestFromConfigData)
+ function latestConfigDetails()
+ external
+ view
+ override
+ returns (uint32 configCount, uint32 blockNumber, bytes32 configDigest)
+ {
+ return (s_configCount, s_latestConfigBlockNumber, s_configInfo.latestConfigDigest);
+ }
+
+ /// @inheritdoc OCR2Abstract
+ function latestConfigDigestAndEpoch()
+ external
+ view
+ virtual
+ override
+ returns (bool scanLogs, bytes32 configDigest, uint32 epoch)
+ {
+ return (true, bytes32(0), uint32(0));
+ }
+
+ function _report(bytes calldata report) internal virtual;
+}
diff --git a/contracts/src/v0.8/ccip/offRamp/EVM2EVMMultiOffRamp.sol b/contracts/src/v0.8/ccip/offRamp/EVM2EVMMultiOffRamp.sol
new file mode 100644
index 00000000000..809e4e22a4e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/offRamp/EVM2EVMMultiOffRamp.sol
@@ -0,0 +1,914 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IAny2EVMMessageReceiver} from "../interfaces/IAny2EVMMessageReceiver.sol";
+import {IMessageInterceptor} from "../interfaces/IMessageInterceptor.sol";
+import {INonceManager} from "../interfaces/INonceManager.sol";
+import {IPoolV1} from "../interfaces/IPool.sol";
+import {IPriceRegistry} from "../interfaces/IPriceRegistry.sol";
+import {IRMN} from "../interfaces/IRMN.sol";
+import {IRouter} from "../interfaces/IRouter.sol";
+import {ITokenAdminRegistry} from "../interfaces/ITokenAdminRegistry.sol";
+
+import {CallWithExactGas} from "../../shared/call/CallWithExactGas.sol";
+import {EnumerableMapAddresses} from "../../shared/enumerable/EnumerableMapAddresses.sol";
+import {Client} from "../libraries/Client.sol";
+import {Internal} from "../libraries/Internal.sol";
+import {MerkleMultiProof} from "../libraries/MerkleMultiProof.sol";
+import {Pool} from "../libraries/Pool.sol";
+import {MultiOCR3Base} from "../ocr/MultiOCR3Base.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {ERC165Checker} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol";
+
+/// @notice EVM2EVMOffRamp enables OCR networks to execute multiple messages
+/// in an OffRamp in a single transaction.
+/// @dev The EVM2EVMMultiOnRamp and EVM2EVMMultiOffRamp form an xchain upgradeable unit. Any change to one of them
+/// results an onchain upgrade of both contracts.
+/// @dev MultiOCR3Base is used to store multiple OCR configs for both the OffRamp and the CommitStore.
+/// The execution plugin type has to be configured without signature verification, and the commit
+/// plugin type with verification.
+contract EVM2EVMMultiOffRamp is ITypeAndVersion, MultiOCR3Base {
+ using ERC165Checker for address;
+ using EnumerableMapAddresses for EnumerableMapAddresses.AddressToAddressMap;
+
+ error AlreadyAttempted(uint64 sourceChainSelector, uint64 sequenceNumber);
+ error AlreadyExecuted(uint64 sourceChainSelector, uint64 sequenceNumber);
+ error ZeroChainSelectorNotAllowed();
+ error ExecutionError(bytes32 messageId, bytes err);
+ error SourceChainNotEnabled(uint64 sourceChainSelector);
+ error TokenDataMismatch(uint64 sourceChainSelector, uint64 sequenceNumber);
+ error UnexpectedTokenData();
+ error ManualExecutionNotYetEnabled(uint64 sourceChainSelector);
+ error ManualExecutionGasLimitMismatch();
+ error InvalidManualExecutionGasLimit(uint64 sourceChainSelector, uint256 index, uint256 newLimit);
+ error RootNotCommitted(uint64 sourceChainSelector);
+ error RootAlreadyCommitted(uint64 sourceChainSelector, bytes32 merkleRoot);
+ error InvalidRoot();
+ error CanOnlySelfCall();
+ error ReceiverError(bytes err);
+ error TokenHandlingError(bytes err);
+ error EmptyReport();
+ error CursedByRMN(uint64 sourceChainSelector);
+ error NotACompatiblePool(address notPool);
+ error InvalidDataLength(uint256 expected, uint256 got);
+ error InvalidNewState(uint64 sourceChainSelector, uint64 sequenceNumber, Internal.MessageExecutionState newState);
+ error InvalidStaticConfig(uint64 sourceChainSelector);
+ error StaleCommitReport();
+ error InvalidInterval(uint64 sourceChainSelector, Interval interval);
+ error ZeroAddressNotAllowed();
+ error InvalidMessageDestChainSelector(uint64 messageDestChainSelector);
+
+ /// @dev Atlas depends on this event, if changing, please notify Atlas.
+ event StaticConfigSet(StaticConfig staticConfig);
+ event DynamicConfigSet(DynamicConfig dynamicConfig);
+ /// @dev RMN depends on this event, if changing, please notify the RMN maintainers.
+ event ExecutionStateChanged(
+ uint64 indexed sourceChainSelector,
+ uint64 indexed sequenceNumber,
+ bytes32 indexed messageId,
+ Internal.MessageExecutionState state,
+ bytes returnData
+ );
+ event SourceChainSelectorAdded(uint64 sourceChainSelector);
+ event SourceChainConfigSet(uint64 indexed sourceChainSelector, SourceChainConfig sourceConfig);
+ event SkippedAlreadyExecutedMessage(uint64 sourceChainSelector, uint64 sequenceNumber);
+ /// @dev RMN depends on this event, if changing, please notify the RMN maintainers.
+ event CommitReportAccepted(CommitReport report);
+ event RootRemoved(bytes32 root);
+
+ /// @notice Static offRamp config
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct StaticConfig {
+ uint64 chainSelector; // ───╮ Destination chainSelector
+ address rmnProxy; // ───────╯ RMN proxy address
+ address tokenAdminRegistry; // Token admin registry address
+ address nonceManager; // Address of the nonce manager
+ }
+
+ /// @notice Per-chain source config (defining a lane from a Source Chain -> Dest OffRamp)
+ struct SourceChainConfig {
+ bool isEnabled; // ──────────╮ Flag whether the source chain is enabled or not
+ uint64 minSeqNr; // ─────────╯ The min sequence number expected for future messages
+ bytes onRamp; // OnRamp address on the source chain
+ }
+
+ /// @notice SourceChainConfig update args scoped to one source chain
+ struct SourceChainConfigArgs {
+ uint64 sourceChainSelector; // ───╮ Source chain selector of the config to update
+ bool isEnabled; // ────────────────╯ Flag whether the source chain is enabled or not
+ bytes onRamp; // OnRamp address on the source chain
+ }
+
+ /// @notice Dynamic offRamp config
+ /// @dev since OffRampConfig is part of OffRampConfigChanged event, if changing it, we should update the ABI on Atlas
+ struct DynamicConfig {
+ address router; // ─────────────────────────────────╮ Router address
+ uint32 permissionLessExecutionThresholdSeconds; // │ Waiting time before manual execution is enabled
+ uint32 maxTokenTransferGas; // │ Maximum amount of gas passed on to token `transfer` call
+ uint32 maxPoolReleaseOrMintGas; // ─────────────────╯ Maximum amount of gas passed on to token pool when calling releaseOrMint
+ address messageValidator; // Optional message validator to validate incoming messages (zero address = no validator)
+ address priceRegistry; // Price registry address on the local chain
+ }
+
+ /// @notice a sequenceNumber interval
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct Interval {
+ uint64 min; // ───╮ Minimum sequence number, inclusive
+ uint64 max; // ───╯ Maximum sequence number, inclusive
+ }
+
+ /// @dev Struct to hold a merkle root and an interval for a source chain so that an array of these can be passed in the CommitReport.
+ struct MerkleRoot {
+ uint64 sourceChainSelector; // Remote source chain selector that the Merkle Root is scoped to
+ Interval interval; // Report interval of the merkle root
+ bytes32 merkleRoot; // Merkle root covering the interval & source chain messages
+ }
+
+ /// @notice Report that is committed by the observing DON at the committing phase
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ struct CommitReport {
+ Internal.PriceUpdates priceUpdates; // Collection of gas and price updates to commit
+ MerkleRoot[] merkleRoots; // Collection of merkle roots per source chain to commit
+ }
+
+ /// @dev Struct to hold a merkle root for a source chain so that an array of these can be passed in the resetUblessedRoots function.
+ struct UnblessedRoot {
+ uint64 sourceChainSelector; // Remote source chain selector that the Merkle Root is scoped to
+ bytes32 merkleRoot; // Merkle root of a single remote source chain
+ }
+
+ // STATIC CONFIG
+ string public constant override typeAndVersion = "EVM2EVMMultiOffRamp 1.6.0-dev";
+ /// @dev ChainSelector of this chain
+ uint64 internal immutable i_chainSelector;
+ /// @dev The address of the RMN proxy
+ address internal immutable i_rmnProxy;
+ /// @dev The address of the token admin registry
+ address internal immutable i_tokenAdminRegistry;
+ /// @dev The address of the nonce manager
+ address internal immutable i_nonceManager;
+
+ // DYNAMIC CONFIG
+ DynamicConfig internal s_dynamicConfig;
+
+ /// @notice SourceConfig per chain
+ /// (forms lane configurations from sourceChainSelector => StaticConfig.chainSelector)
+ mapping(uint64 sourceChainSelector => SourceChainConfig sourceChainConfig) internal s_sourceChainConfigs;
+
+ // STATE
+ /// @dev A mapping of sequence numbers (per source chain) to execution state using a bitmap with each execution
+ /// state only taking up 2 bits of the uint256, packing 128 states into a single slot.
+ /// Message state is tracked to ensure message can only be executed successfully once.
+ mapping(uint64 sourceChainSelector => mapping(uint64 seqNum => uint256 executionStateBitmap)) internal
+ s_executionStates;
+
+ // sourceChainSelector => merkleRoot => timestamp when received
+ mapping(uint64 sourceChainSelector => mapping(bytes32 merkleRoot => uint256 timestamp)) internal s_roots;
+ /// @dev The sequence number of the last price update
+ uint64 private s_latestPriceSequenceNumber;
+
+ constructor(
+ StaticConfig memory staticConfig,
+ DynamicConfig memory dynamicConfig,
+ SourceChainConfigArgs[] memory sourceChainConfigs
+ ) MultiOCR3Base() {
+ if (
+ staticConfig.rmnProxy == address(0) || staticConfig.tokenAdminRegistry == address(0)
+ || staticConfig.nonceManager == address(0)
+ ) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ if (staticConfig.chainSelector == 0) {
+ revert ZeroChainSelectorNotAllowed();
+ }
+
+ i_chainSelector = staticConfig.chainSelector;
+ i_rmnProxy = staticConfig.rmnProxy;
+ i_tokenAdminRegistry = staticConfig.tokenAdminRegistry;
+ i_nonceManager = staticConfig.nonceManager;
+ emit StaticConfigSet(staticConfig);
+
+ _setDynamicConfig(dynamicConfig);
+ _applySourceChainConfigUpdates(sourceChainConfigs);
+ }
+
+ // ================================================================
+ // │ Messaging │
+ // ================================================================
+
+ // The size of the execution state in bits
+ uint256 private constant MESSAGE_EXECUTION_STATE_BIT_WIDTH = 2;
+ // The mask for the execution state bits
+ uint256 private constant MESSAGE_EXECUTION_STATE_MASK = (1 << MESSAGE_EXECUTION_STATE_BIT_WIDTH) - 1;
+
+ // ================================================================
+ // │ Execution │
+ // ================================================================
+
+ /// @notice Returns the current execution state of a message based on its sequenceNumber.
+ /// @param sourceChainSelector The source chain to get the execution state for
+ /// @param sequenceNumber The sequence number of the message to get the execution state for.
+ /// @return The current execution state of the message.
+ /// @dev we use the literal number 128 because using a constant increased gas usage.
+ function getExecutionState(
+ uint64 sourceChainSelector,
+ uint64 sequenceNumber
+ ) public view returns (Internal.MessageExecutionState) {
+ return Internal.MessageExecutionState(
+ (
+ _getSequenceNumberBitmap(sourceChainSelector, sequenceNumber)
+ >> ((sequenceNumber % 128) * MESSAGE_EXECUTION_STATE_BIT_WIDTH)
+ ) & MESSAGE_EXECUTION_STATE_MASK
+ );
+ }
+
+ /// @notice Sets a new execution state for a given sequence number. It will overwrite any existing state.
+ /// @param sourceChainSelector The source chain to set the execution state for
+ /// @param sequenceNumber The sequence number for which the state will be saved.
+ /// @param newState The new value the state will be in after this function is called.
+ /// @dev we use the literal number 128 because using a constant increased gas usage.
+ function _setExecutionState(
+ uint64 sourceChainSelector,
+ uint64 sequenceNumber,
+ Internal.MessageExecutionState newState
+ ) internal {
+ uint256 offset = (sequenceNumber % 128) * MESSAGE_EXECUTION_STATE_BIT_WIDTH;
+ uint256 bitmap = _getSequenceNumberBitmap(sourceChainSelector, sequenceNumber);
+ // to unset any potential existing state we zero the bits of the section the state occupies,
+ // then we do an AND operation to blank out any existing state for the section.
+ bitmap &= ~(MESSAGE_EXECUTION_STATE_MASK << offset);
+ // Set the new state
+ bitmap |= uint256(newState) << offset;
+
+ s_executionStates[sourceChainSelector][sequenceNumber / 128] = bitmap;
+ }
+
+ /// @param sourceChainSelector remote source chain selector to get sequence number bitmap for
+ /// @param sequenceNumber sequence number to get bitmap for
+ /// @return bitmap Bitmap of the given sequence number for the provided source chain selector. One bitmap represents 128 sequence numbers
+ function _getSequenceNumberBitmap(
+ uint64 sourceChainSelector,
+ uint64 sequenceNumber
+ ) internal view returns (uint256 bitmap) {
+ return s_executionStates[sourceChainSelector][sequenceNumber / 128];
+ }
+
+ /// @notice Manually executes a set of reports.
+ /// @param reports Internal.ExecutionReportSingleChain[] - list of reports to execute
+ /// @param gasLimitOverrides New gasLimit for each message per report
+ // The outer array represents each report, inner array represents each message in the report.
+ // i.e. gasLimitOverrides[report1][report1Message1] -> access message1 from report1
+ /// @dev We permit gas limit overrides so that users may manually execute messages which failed due to
+ /// insufficient gas provided.
+ /// The reports do not have to contain all the messages (they can be omitted). Multiple reports can be passed in simultaneously.
+ function manuallyExecute(
+ Internal.ExecutionReportSingleChain[] memory reports,
+ uint256[][] memory gasLimitOverrides
+ ) external {
+ // We do this here because the other _execute path is already covered by MultiOCR3Base.
+ _whenChainNotForked();
+
+ uint256 numReports = reports.length;
+ if (numReports != gasLimitOverrides.length) revert ManualExecutionGasLimitMismatch();
+
+ for (uint256 reportIndex = 0; reportIndex < numReports; ++reportIndex) {
+ Internal.ExecutionReportSingleChain memory report = reports[reportIndex];
+
+ uint256 numMsgs = report.messages.length;
+ uint256[] memory msgGasLimitOverrides = gasLimitOverrides[reportIndex];
+ if (numMsgs != msgGasLimitOverrides.length) revert ManualExecutionGasLimitMismatch();
+
+ for (uint256 msgIndex = 0; msgIndex < numMsgs; ++msgIndex) {
+ uint256 newLimit = msgGasLimitOverrides[msgIndex];
+ // Checks to ensure message cannot be executed with less gas than specified.
+ if (newLimit != 0) {
+ if (newLimit < report.messages[msgIndex].gasLimit) {
+ revert InvalidManualExecutionGasLimit(report.sourceChainSelector, msgIndex, newLimit);
+ }
+ }
+ }
+ }
+
+ _batchExecute(reports, gasLimitOverrides);
+ }
+
+ /// @notice Transmit function for execution reports. The function takes no signatures,
+ /// and expects the exec plugin type to be configured with no signatures.
+ /// @param report serialized execution report
+ function execute(bytes32[3] calldata reportContext, bytes calldata report) external {
+ _batchExecute(abi.decode(report, (Internal.ExecutionReportSingleChain[])), new uint256[][](0));
+
+ bytes32[] memory emptySigs = new bytes32[](0);
+ _transmit(uint8(Internal.OCRPluginType.Execution), reportContext, report, emptySigs, emptySigs, bytes32(""));
+ }
+
+ /// @notice Batch executes a set of reports, each report matching one single source chain
+ /// @param reports Set of execution reports (one per chain) containing the messages and proofs
+ /// @param manualExecGasLimits An array of gas limits to use for manual execution
+ // The outer array represents each report, inner array represents each message in the report.
+ // i.e. gasLimitOverrides[report1][report1Message1] -> access message1 from report1
+ /// @dev The manualExecGasLimits array should either be empty, or match the length of the reports array
+ /// @dev If called from manual execution, each inner array's length has to match the number of messages.
+ function _batchExecute(
+ Internal.ExecutionReportSingleChain[] memory reports,
+ uint256[][] memory manualExecGasLimits
+ ) internal {
+ if (reports.length == 0) revert EmptyReport();
+
+ bool areManualGasLimitsEmpty = manualExecGasLimits.length == 0;
+ // Cache array for gas savings in the loop's condition
+ uint256[] memory emptyGasLimits = new uint256[](0);
+
+ for (uint256 i = 0; i < reports.length; ++i) {
+ _executeSingleReport(reports[i], areManualGasLimitsEmpty ? emptyGasLimits : manualExecGasLimits[i]);
+ }
+ }
+
+ /// @notice Executes a report, executing each message in order.
+ /// @param report The execution report containing the messages and proofs.
+ /// @param manualExecGasLimits An array of gas limits to use for manual execution.
+ /// @dev If called from the DON, this array is always empty.
+ /// @dev If called from manual execution, this array is always same length as messages.
+ function _executeSingleReport(
+ Internal.ExecutionReportSingleChain memory report,
+ uint256[] memory manualExecGasLimits
+ ) internal {
+ uint64 sourceChainSelector = report.sourceChainSelector;
+ _whenNotCursed(sourceChainSelector);
+
+ SourceChainConfig storage sourceChainConfig = _getEnabledSourceChainConfig(sourceChainSelector);
+
+ uint256 numMsgs = report.messages.length;
+ if (numMsgs == 0) revert EmptyReport();
+ if (numMsgs != report.offchainTokenData.length) revert UnexpectedTokenData();
+
+ bytes32[] memory hashedLeaves = new bytes32[](numMsgs);
+
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ Internal.Any2EVMRampMessage memory message = report.messages[i];
+
+ // Commits do not verify the destChainSelector in the message, since only the root is committed,
+ // so we have to check it explicitly
+ if (message.header.destChainSelector != i_chainSelector) {
+ revert InvalidMessageDestChainSelector(message.header.destChainSelector);
+ }
+
+ // We do this hash here instead of in _verifyMessages to avoid two separate loops
+ // over the same data, which increases gas cost.
+ // Hashing all of the message fields ensures that the message being executed is correct and not tampered with.
+ // Including the known OnRamp ensures that the message originates from the correct on ramp version
+ hashedLeaves[i] = Internal._hash(message, sourceChainConfig.onRamp);
+ }
+
+ // SECURITY CRITICAL CHECK
+ // NOTE: This check also verifies that all messages match the report's sourceChainSelector
+ uint256 timestampCommitted = _verify(sourceChainSelector, hashedLeaves, report.proofs, report.proofFlagBits);
+ if (timestampCommitted == 0) revert RootNotCommitted(sourceChainSelector);
+
+ // Execute messages
+ bool manualExecution = manualExecGasLimits.length != 0;
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ Internal.Any2EVMRampMessage memory message = report.messages[i];
+
+ Internal.MessageExecutionState originalState =
+ getExecutionState(sourceChainSelector, message.header.sequenceNumber);
+ if (originalState == Internal.MessageExecutionState.SUCCESS) {
+ // If the message has already been executed, we skip it. We want to not revert on race conditions between
+ // executing parties. This will allow us to open up manual exec while also attempting with the DON, without
+ // reverting an entire DON batch when a user manually executes while the tx is inflight.
+ emit SkippedAlreadyExecutedMessage(sourceChainSelector, message.header.sequenceNumber);
+ continue;
+ }
+ // Two valid cases here, we either have never touched this message before, or we tried to execute
+ // and failed. This check protects against reentry and re-execution because the other state is
+ // IN_PROGRESS which should not be allowed to execute.
+ if (
+ !(
+ originalState == Internal.MessageExecutionState.UNTOUCHED
+ || originalState == Internal.MessageExecutionState.FAILURE
+ )
+ ) revert AlreadyExecuted(sourceChainSelector, message.header.sequenceNumber);
+
+ if (manualExecution) {
+ bool isOldCommitReport =
+ (block.timestamp - timestampCommitted) > s_dynamicConfig.permissionLessExecutionThresholdSeconds;
+ // Manually execution is fine if we previously failed or if the commit report is just too old
+ // Acceptable state transitions: FAILURE->SUCCESS, UNTOUCHED->SUCCESS, FAILURE->FAILURE
+ if (!(isOldCommitReport || originalState == Internal.MessageExecutionState.FAILURE)) {
+ revert ManualExecutionNotYetEnabled(sourceChainSelector);
+ }
+
+ // Manual execution gas limit can override gas limit specified in the message. Value of 0 indicates no override.
+ if (manualExecGasLimits[i] != 0) {
+ message.gasLimit = manualExecGasLimits[i];
+ }
+ } else {
+ // DON can only execute a message once
+ // Acceptable state transitions: UNTOUCHED->SUCCESS, UNTOUCHED->FAILURE
+ if (originalState != Internal.MessageExecutionState.UNTOUCHED) {
+ revert AlreadyAttempted(sourceChainSelector, message.header.sequenceNumber);
+ }
+ }
+
+ // Nonce changes per state transition (these only apply for ordered messages):
+ // UNTOUCHED -> FAILURE nonce bump
+ // UNTOUCHED -> SUCCESS nonce bump
+ // FAILURE -> FAILURE no nonce bump
+ // FAILURE -> SUCCESS no nonce bump
+ // UNTOUCHED messages MUST be executed in order always
+ if (message.header.nonce != 0) {
+ if (originalState == Internal.MessageExecutionState.UNTOUCHED) {
+ // If a nonce is not incremented, that means it was skipped, and we can ignore the message
+ if (
+ !INonceManager(i_nonceManager).incrementInboundNonce(
+ sourceChainSelector, message.header.nonce, message.sender
+ )
+ ) continue;
+ }
+ }
+
+ // Although we expect only valid messages will be committed, we check again
+ // when executing as a defense in depth measure.
+ bytes[] memory offchainTokenData = report.offchainTokenData[i];
+ if (message.tokenAmounts.length != offchainTokenData.length) {
+ revert TokenDataMismatch(sourceChainSelector, message.header.sequenceNumber);
+ }
+
+ _setExecutionState(sourceChainSelector, message.header.sequenceNumber, Internal.MessageExecutionState.IN_PROGRESS);
+
+ (Internal.MessageExecutionState newState, bytes memory returnData) = _trialExecute(message, offchainTokenData);
+ _setExecutionState(sourceChainSelector, message.header.sequenceNumber, newState);
+
+ // Since it's hard to estimate whether manual execution will succeed, we
+ // revert the entire transaction if it fails. This will show the user if
+ // their manual exec will fail before they submit it.
+ if (manualExecution) {
+ if (newState == Internal.MessageExecutionState.FAILURE) {
+ if (originalState != Internal.MessageExecutionState.UNTOUCHED) {
+ // If manual execution fails, we revert the entire transaction, unless the originalState is UNTOUCHED as we
+ // would still be making progress by changing the state from UNTOUCHED to FAILURE.
+ revert ExecutionError(message.header.messageId, returnData);
+ }
+ }
+ }
+
+ // The only valid prior states are UNTOUCHED and FAILURE (checked above)
+ // The only valid post states are FAILURE and SUCCESS (checked below)
+ if (newState != Internal.MessageExecutionState.SUCCESS) {
+ if (newState != Internal.MessageExecutionState.FAILURE) {
+ revert InvalidNewState(sourceChainSelector, message.header.sequenceNumber, newState);
+ }
+ }
+
+ emit ExecutionStateChanged(
+ sourceChainSelector, message.header.sequenceNumber, message.header.messageId, newState, returnData
+ );
+ }
+ }
+
+ /// @notice Try executing a message.
+ /// @param message Internal.Any2EVMRampMessage memory message.
+ /// @param offchainTokenData Data provided by the DON for token transfers.
+ /// @return the new state of the message, being either SUCCESS or FAILURE.
+ /// @return revert data in bytes if CCIP receiver reverted during execution.
+ function _trialExecute(
+ Internal.Any2EVMRampMessage memory message,
+ bytes[] memory offchainTokenData
+ ) internal returns (Internal.MessageExecutionState, bytes memory) {
+ try this.executeSingleMessage(message, offchainTokenData) {}
+ catch (bytes memory err) {
+ // return the message execution state as FAILURE and the revert data
+ // Max length of revert data is Router.MAX_RET_BYTES, max length of err is 4 + Router.MAX_RET_BYTES
+ return (Internal.MessageExecutionState.FAILURE, err);
+ }
+ // If message execution succeeded, no CCIP receiver return data is expected, return with empty bytes.
+ return (Internal.MessageExecutionState.SUCCESS, "");
+ }
+
+ /// @notice Execute a single message.
+ /// @param message The message that will be executed.
+ /// @param offchainTokenData Token transfer data to be passed to TokenPool.
+ /// @dev We make this external and callable by the contract itself, in order to try/catch
+ /// its execution and enforce atomicity among successful message processing and token transfer.
+ /// @dev We use ERC-165 to check for the ccipReceive interface to permit sending tokens to contracts
+ /// (for example smart contract wallets) without an associated message.
+ function executeSingleMessage(Internal.Any2EVMRampMessage memory message, bytes[] memory offchainTokenData) external {
+ if (msg.sender != address(this)) revert CanOnlySelfCall();
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](0);
+ if (message.tokenAmounts.length > 0) {
+ destTokenAmounts = _releaseOrMintTokens(
+ message.tokenAmounts, message.sender, message.receiver, message.header.sourceChainSelector, offchainTokenData
+ );
+ }
+
+ Client.Any2EVMMessage memory any2EvmMessage = Client.Any2EVMMessage({
+ messageId: message.header.messageId,
+ sourceChainSelector: message.header.sourceChainSelector,
+ sender: abi.encode(message.sender),
+ data: message.data,
+ destTokenAmounts: destTokenAmounts
+ });
+
+ address messageValidator = s_dynamicConfig.messageValidator;
+ if (messageValidator != address(0)) {
+ try IMessageInterceptor(messageValidator).onInboundMessage(any2EvmMessage) {}
+ catch (bytes memory err) {
+ revert IMessageInterceptor.MessageValidationError(err);
+ }
+ }
+
+ // There are three cases in which we skip calling the receiver:
+ // 1. If the message data is empty AND the gas limit is 0.
+ // This indicates a message that only transfers tokens. It is valid to only send tokens to a contract
+ // that supports the IAny2EVMMessageReceiver interface, but without this first check we would call the
+ // receiver without any gas, which would revert the transaction.
+ // 2. If the receiver is not a contract.
+ // 3. If the receiver is a contract but it does not support the IAny2EVMMessageReceiver interface.
+ //
+ // The ordering of these checks is important, as the first check is the cheapest to execute.
+ if (
+ (message.data.length == 0 && message.gasLimit == 0) || message.receiver.code.length == 0
+ || !message.receiver.supportsInterface(type(IAny2EVMMessageReceiver).interfaceId)
+ ) return;
+
+ (bool success, bytes memory returnData,) = IRouter(s_dynamicConfig.router).routeMessage(
+ any2EvmMessage, Internal.GAS_FOR_CALL_EXACT_CHECK, message.gasLimit, message.receiver
+ );
+ // If CCIP receiver execution is not successful, revert the call including token transfers
+ if (!success) revert ReceiverError(returnData);
+ }
+
+ // ================================================================
+ // │ Commit │
+ // ================================================================
+
+ /// @notice Transmit function for commit reports. The function requires signatures,
+ /// and expects the commit plugin type to be configured with signatures.
+ /// @param report serialized commit report
+ /// @dev A commitReport can have two distinct parts (batched together to amortize the cost of checking sigs):
+ /// 1. Price updates
+ /// 2. A batch of merkle root and sequence number intervals (per-source)
+ /// Both have their own, separate, staleness checks, with price updates using the epoch and round
+ /// number of the latest price update. The merkle root checks for staleness based on the seqNums.
+ /// They need to be separate because a price report for round t+2 might be included before a report
+ /// containing a merkle root for round t+1. This merkle root report for round t+1 is still valid
+ /// and should not be rejected. When a report with a stale root but valid price updates is submitted,
+ /// we are OK to revert to preserve the invariant that we always revert on invalid sequence number ranges.
+ /// If that happens, prices will be updates in later rounds.
+ function commit(
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 rawVs // signatures
+ ) external {
+ CommitReport memory commitReport = abi.decode(report, (CommitReport));
+
+ // Check if the report contains price updates
+ if (commitReport.priceUpdates.tokenPriceUpdates.length > 0 || commitReport.priceUpdates.gasPriceUpdates.length > 0)
+ {
+ uint64 sequenceNumber = uint64(uint256(reportContext[1]));
+
+ // Check for price staleness based on the epoch and round
+ if (s_latestPriceSequenceNumber < sequenceNumber) {
+ // If prices are not stale, update the latest epoch and round
+ s_latestPriceSequenceNumber = sequenceNumber;
+ // And update the prices in the price registry
+ IPriceRegistry(s_dynamicConfig.priceRegistry).updatePrices(commitReport.priceUpdates);
+ } else {
+ // If prices are stale and the report doesn't contain a root, this report
+ // does not have any valid information and we revert.
+ // If it does contain a merkle root, continue to the root checking section.
+ if (commitReport.merkleRoots.length == 0) revert StaleCommitReport();
+ }
+ }
+
+ for (uint256 i = 0; i < commitReport.merkleRoots.length; ++i) {
+ MerkleRoot memory root = commitReport.merkleRoots[i];
+ uint64 sourceChainSelector = root.sourceChainSelector;
+
+ _whenNotCursed(sourceChainSelector);
+ SourceChainConfig storage sourceChainConfig = _getEnabledSourceChainConfig(sourceChainSelector);
+
+ // If we reached this section, the report should contain a valid root
+ if (sourceChainConfig.minSeqNr != root.interval.min || root.interval.min > root.interval.max) {
+ revert InvalidInterval(root.sourceChainSelector, root.interval);
+ }
+
+ // TODO: confirm how RMN offchain blessing impacts commit report
+ bytes32 merkleRoot = root.merkleRoot;
+ if (merkleRoot == bytes32(0)) revert InvalidRoot();
+ // Disallow duplicate roots as that would reset the timestamp and
+ // delay potential manual execution.
+ if (s_roots[root.sourceChainSelector][merkleRoot] != 0) {
+ revert RootAlreadyCommitted(root.sourceChainSelector, merkleRoot);
+ }
+
+ sourceChainConfig.minSeqNr = root.interval.max + 1;
+ s_roots[root.sourceChainSelector][merkleRoot] = block.timestamp;
+ }
+
+ emit CommitReportAccepted(commitReport);
+
+ _transmit(uint8(Internal.OCRPluginType.Commit), reportContext, report, rs, ss, rawVs);
+ }
+
+ /// @notice Returns the sequence number of the last price update.
+ /// @return the latest price update sequence number.
+ function getLatestPriceSequenceNumber() public view returns (uint64) {
+ return s_latestPriceSequenceNumber;
+ }
+
+ /// @notice Returns the timestamp of a potentially previously committed merkle root.
+ /// If the root was never committed 0 will be returned.
+ /// @param sourceChainSelector The source chain selector.
+ /// @param root The merkle root to check the commit status for.
+ /// @return the timestamp of the committed root or zero in the case that it was never
+ /// committed.
+ function getMerkleRoot(uint64 sourceChainSelector, bytes32 root) external view returns (uint256) {
+ return s_roots[sourceChainSelector][root];
+ }
+
+ /// @notice Returns if a root is blessed or not.
+ /// @param root The merkle root to check the blessing status for.
+ /// @return whether the root is blessed or not.
+ function isBlessed(bytes32 root) public view returns (bool) {
+ // TODO: update RMN to also consider the source chain selector for blessing
+ return IRMN(i_rmnProxy).isBlessed(IRMN.TaggedRoot({commitStore: address(this), root: root}));
+ }
+
+ /// @notice Used by the owner in case an invalid sequence of roots has been
+ /// posted and needs to be removed. The interval in the report is trusted.
+ /// @param rootToReset The roots that will be reset. This function will only
+ /// reset roots that are not blessed.
+ function resetUnblessedRoots(UnblessedRoot[] calldata rootToReset) external onlyOwner {
+ for (uint256 i = 0; i < rootToReset.length; ++i) {
+ UnblessedRoot memory root = rootToReset[i];
+ if (!isBlessed(root.merkleRoot)) {
+ delete s_roots[root.sourceChainSelector][root.merkleRoot];
+ emit RootRemoved(root.merkleRoot);
+ }
+ }
+ }
+
+ /// @notice Returns timestamp of when root was accepted or 0 if verification fails.
+ /// @dev This method uses a merkle tree within a merkle tree, with the hashedLeaves,
+ /// proofs and proofFlagBits being used to get the root of the inner tree.
+ /// This root is then used as the singular leaf of the outer tree.
+ function _verify(
+ uint64 sourceChainSelector,
+ bytes32[] memory hashedLeaves,
+ bytes32[] memory proofs,
+ uint256 proofFlagBits
+ ) internal view virtual returns (uint256 timestamp) {
+ bytes32 root = MerkleMultiProof.merkleRoot(hashedLeaves, proofs, proofFlagBits);
+ // Only return non-zero if present and blessed.
+ if (!isBlessed(root)) {
+ return 0;
+ }
+ return s_roots[sourceChainSelector][root];
+ }
+
+ /// @inheritdoc MultiOCR3Base
+ function _afterOCR3ConfigSet(uint8 ocrPluginType) internal override {
+ if (ocrPluginType == uint8(Internal.OCRPluginType.Commit)) {
+ // When the OCR config changes, we reset the sequence number
+ // since it is scoped per config digest.
+ // Note that s_minSeqNr/roots do not need to be reset as the roots persist
+ // across reconfigurations and are de-duplicated separately.
+ s_latestPriceSequenceNumber = 0;
+ }
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Returns the static config.
+ /// @dev This function will always return the same struct as the contents is static and can never change.
+ /// RMN depends on this function, if changing, please notify the RMN maintainers.
+ function getStaticConfig() external view returns (StaticConfig memory) {
+ return StaticConfig({
+ chainSelector: i_chainSelector,
+ rmnProxy: i_rmnProxy,
+ tokenAdminRegistry: i_tokenAdminRegistry,
+ nonceManager: i_nonceManager
+ });
+ }
+
+ /// @notice Returns the current dynamic config.
+ /// @return The current config.
+ function getDynamicConfig() external view returns (DynamicConfig memory) {
+ return s_dynamicConfig;
+ }
+
+ /// @notice Returns the source chain config for the provided source chain selector
+ /// @param sourceChainSelector chain to retrieve configuration for
+ /// @return SourceChainConfig config for the source chain
+ function getSourceChainConfig(uint64 sourceChainSelector) external view returns (SourceChainConfig memory) {
+ return s_sourceChainConfigs[sourceChainSelector];
+ }
+
+ /// @notice Updates source configs
+ /// @param sourceChainConfigUpdates Source chain configs
+ function applySourceChainConfigUpdates(SourceChainConfigArgs[] memory sourceChainConfigUpdates) external onlyOwner {
+ _applySourceChainConfigUpdates(sourceChainConfigUpdates);
+ }
+
+ /// @notice Updates source configs
+ /// @param sourceChainConfigUpdates Source chain configs
+ function _applySourceChainConfigUpdates(SourceChainConfigArgs[] memory sourceChainConfigUpdates) internal {
+ for (uint256 i = 0; i < sourceChainConfigUpdates.length; ++i) {
+ SourceChainConfigArgs memory sourceConfigUpdate = sourceChainConfigUpdates[i];
+ uint64 sourceChainSelector = sourceConfigUpdate.sourceChainSelector;
+
+ if (sourceChainSelector == 0) {
+ revert ZeroChainSelectorNotAllowed();
+ }
+
+ SourceChainConfig storage currentConfig = s_sourceChainConfigs[sourceChainSelector];
+ bytes memory currentOnRamp = currentConfig.onRamp;
+ bytes memory newOnRamp = sourceConfigUpdate.onRamp;
+
+ // OnRamp can never be zero - if it is, then the source chain has been added for the first time
+ if (currentOnRamp.length == 0) {
+ if (newOnRamp.length == 0) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ currentConfig.onRamp = newOnRamp;
+ currentConfig.minSeqNr = 1;
+ emit SourceChainSelectorAdded(sourceChainSelector);
+ } else if (keccak256(currentOnRamp) != keccak256(newOnRamp)) {
+ revert InvalidStaticConfig(sourceChainSelector);
+ }
+
+ // The only dynamic config is the isEnabled flag
+ currentConfig.isEnabled = sourceConfigUpdate.isEnabled;
+ emit SourceChainConfigSet(sourceChainSelector, currentConfig);
+ }
+ }
+
+ /// @notice Sets the dynamic config.
+ /// @param dynamicConfig The new dynamic config.
+ function setDynamicConfig(DynamicConfig memory dynamicConfig) external onlyOwner {
+ _setDynamicConfig(dynamicConfig);
+ }
+
+ /// @notice Sets the dynamic config.
+ /// @param dynamicConfig The dynamic config.
+ function _setDynamicConfig(DynamicConfig memory dynamicConfig) internal {
+ if (dynamicConfig.priceRegistry == address(0) || dynamicConfig.router == address(0)) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ s_dynamicConfig = dynamicConfig;
+
+ emit DynamicConfigSet(dynamicConfig);
+ }
+
+ /// @notice Returns a source chain config with a check that the config is enabled
+ /// @param sourceChainSelector Source chain selector to check for cursing
+ /// @return sourceChainConfig Source chain config
+ function _getEnabledSourceChainConfig(uint64 sourceChainSelector) internal view returns (SourceChainConfig storage) {
+ SourceChainConfig storage sourceChainConfig = s_sourceChainConfigs[sourceChainSelector];
+ if (!sourceChainConfig.isEnabled) {
+ revert SourceChainNotEnabled(sourceChainSelector);
+ }
+
+ return sourceChainConfig;
+ }
+
+ // ================================================================
+ // │ Tokens and pools │
+ // ================================================================
+
+ /// @notice Uses a pool to release or mint a token to a receiver address in two steps. First, the pool is called
+ /// to release the tokens to the offRamp, then the offRamp calls the token contract to transfer the tokens to the
+ /// receiver. This is done to ensure the exact number of tokens, the pool claims to release are actually transferred.
+ /// @dev The local token address is validated through the TokenAdminRegistry. If, due to some misconfiguration, the
+ /// token is unknown to the registry, the offRamp will revert. The tx, and the tokens, can be retrieved by
+ /// registering the token on this chain, and re-trying the msg.
+ /// @param sourceTokenAmount Amount and source data of the token to be released/minted.
+ /// @param originalSender The message sender on the source chain.
+ /// @param receiver The address that will receive the tokens.
+ /// @param sourceChainSelector The remote source chain selector
+ /// @param offchainTokenData Data fetched offchain by the DON.
+ /// @return destTokenAmount local token address with amount
+ function _releaseOrMintSingleToken(
+ Internal.RampTokenAmount memory sourceTokenAmount,
+ bytes memory originalSender,
+ address receiver,
+ uint64 sourceChainSelector,
+ bytes memory offchainTokenData
+ ) internal returns (Client.EVMTokenAmount memory destTokenAmount) {
+ // We need to safely decode the token address from the sourceTokenData, as it could be wrong,
+ // in which case it doesn't have to be a valid EVM address.
+ address localToken = Internal._validateEVMAddress(sourceTokenAmount.destTokenAddress);
+ // We check with the token admin registry if the token has a pool on this chain.
+ address localPoolAddress = ITokenAdminRegistry(i_tokenAdminRegistry).getPool(localToken);
+ // This will call the supportsInterface through the ERC165Checker, and not directly on the pool address.
+ // This is done to prevent a pool from reverting the entire transaction if it doesn't support the interface.
+ // The call gets a max or 30k gas per instance, of which there are three. This means gas estimations should
+ // account for 90k gas overhead due to the interface check.
+ if (localPoolAddress == address(0) || !localPoolAddress.supportsInterface(Pool.CCIP_POOL_V1)) {
+ revert NotACompatiblePool(localPoolAddress);
+ }
+
+ // We determined that the pool address is a valid EVM address, but that does not mean the code at this
+ // address is a (compatible) pool contract. _callWithExactGasSafeReturnData will check if the location
+ // contains a contract. If it doesn't it reverts with a known error, which we catch gracefully.
+ // We call the pool with exact gas to increase resistance against malicious tokens or token pools.
+ // We protects against return data bombs by capping the return data size at MAX_RET_BYTES.
+ (bool success, bytes memory returnData,) = CallWithExactGas._callWithExactGasSafeReturnData(
+ abi.encodeCall(
+ IPoolV1.releaseOrMint,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: receiver,
+ amount: sourceTokenAmount.amount,
+ localToken: localToken,
+ remoteChainSelector: sourceChainSelector,
+ sourcePoolAddress: sourceTokenAmount.sourcePoolAddress,
+ sourcePoolData: sourceTokenAmount.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ ),
+ localPoolAddress,
+ s_dynamicConfig.maxPoolReleaseOrMintGas,
+ Internal.GAS_FOR_CALL_EXACT_CHECK,
+ Internal.MAX_RET_BYTES
+ );
+
+ // wrap and rethrow the error so we can catch it lower in the stack
+ if (!success) revert TokenHandlingError(returnData);
+
+ // If the call was successful, the returnData should be the local token address.
+ if (returnData.length != Pool.CCIP_POOL_V1_RET_BYTES) {
+ revert InvalidDataLength(Pool.CCIP_POOL_V1_RET_BYTES, returnData.length);
+ }
+ uint256 localAmount = abi.decode(returnData, (uint256));
+ // Since token pools send the tokens to the msg.sender, which is this offRamp, we need to
+ // transfer them to the final receiver. We use the _callWithExactGasSafeReturnData function because
+ // the token contracts are not considered trusted.
+ (success, returnData,) = CallWithExactGas._callWithExactGasSafeReturnData(
+ abi.encodeCall(IERC20.transfer, (receiver, localAmount)),
+ localToken,
+ s_dynamicConfig.maxTokenTransferGas,
+ Internal.GAS_FOR_CALL_EXACT_CHECK,
+ Internal.MAX_RET_BYTES
+ );
+
+ if (!success) revert TokenHandlingError(returnData);
+
+ return Client.EVMTokenAmount({token: localToken, amount: localAmount});
+ }
+
+ /// @notice Uses pools to release or mint a number of different tokens to a receiver address.
+ /// @param sourceTokenAmounts List of token amounts with source data of the tokens to be released/minted.
+ /// @param originalSender The message sender on the source chain.
+ /// @param receiver The address that will receive the tokens.
+ /// @param sourceChainSelector The remote source chain selector
+ /// @param offchainTokenData Array of token data fetched offchain by the DON.
+ /// @return destTokenAmounts local token addresses with amounts
+ /// @dev This function wrappes the token pool call in a try catch block to gracefully handle
+ /// any non-rate limiting errors that may occur. If we encounter a rate limiting related error
+ /// we bubble it up. If we encounter a non-rate limiting error we wrap it in a TokenHandlingError.
+ function _releaseOrMintTokens(
+ Internal.RampTokenAmount[] memory sourceTokenAmounts,
+ bytes memory originalSender,
+ address receiver,
+ uint64 sourceChainSelector,
+ bytes[] memory offchainTokenData
+ ) internal returns (Client.EVMTokenAmount[] memory destTokenAmounts) {
+ destTokenAmounts = new Client.EVMTokenAmount[](sourceTokenAmounts.length);
+ for (uint256 i = 0; i < sourceTokenAmounts.length; ++i) {
+ destTokenAmounts[i] = _releaseOrMintSingleToken(
+ sourceTokenAmounts[i], originalSender, receiver, sourceChainSelector, offchainTokenData[i]
+ );
+ }
+
+ return destTokenAmounts;
+ }
+
+ // ================================================================
+ // │ Access and RMN │
+ // ================================================================
+
+ /// @notice Reverts as this contract should not access CCIP messages
+ function ccipReceive(Client.Any2EVMMessage calldata) external pure {
+ // solhint-disable-next-line
+ revert();
+ }
+
+ /// @notice Validates that the source chain -> this chain lane, and reverts if it is cursed
+ /// @param sourceChainSelector Source chain selector to check for cursing
+ function _whenNotCursed(uint64 sourceChainSelector) internal view {
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(sourceChainSelector)))) {
+ revert CursedByRMN(sourceChainSelector);
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/offRamp/EVM2EVMOffRamp.sol b/contracts/src/v0.8/ccip/offRamp/EVM2EVMOffRamp.sol
new file mode 100644
index 00000000000..1aec436ef8c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/offRamp/EVM2EVMOffRamp.sol
@@ -0,0 +1,721 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IAny2EVMMessageReceiver} from "../interfaces/IAny2EVMMessageReceiver.sol";
+import {IAny2EVMOffRamp} from "../interfaces/IAny2EVMOffRamp.sol";
+import {ICommitStore} from "../interfaces/ICommitStore.sol";
+import {IPoolV1} from "../interfaces/IPool.sol";
+import {IPriceRegistry} from "../interfaces/IPriceRegistry.sol";
+import {IRMN} from "../interfaces/IRMN.sol";
+import {IRouter} from "../interfaces/IRouter.sol";
+import {ITokenAdminRegistry} from "../interfaces/ITokenAdminRegistry.sol";
+
+import {CallWithExactGas} from "../../shared/call/CallWithExactGas.sol";
+import {EnumerableMapAddresses} from "../../shared/enumerable/EnumerableMapAddresses.sol";
+import {AggregateRateLimiter} from "../AggregateRateLimiter.sol";
+import {Client} from "../libraries/Client.sol";
+import {Internal} from "../libraries/Internal.sol";
+import {Pool} from "../libraries/Pool.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+import {OCR2BaseNoChecks} from "../ocr/OCR2BaseNoChecks.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {ERC165Checker} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol";
+
+/// @notice EVM2EVMOffRamp enables OCR networks to execute multiple messages
+/// in an OffRamp in a single transaction.
+/// @dev The EVM2EVMOnRamp, CommitStore and EVM2EVMOffRamp form an xchain upgradeable unit. Any change to one of them
+/// results an onchain upgrade of all 3.
+/// @dev OCR2BaseNoChecks is used to save gas, signatures are not required as the offramp can only execute
+/// messages which are committed in the commitStore. We still make use of OCR2 as an executor whitelist
+/// and turn-taking mechanism.
+contract EVM2EVMOffRamp is IAny2EVMOffRamp, AggregateRateLimiter, ITypeAndVersion, OCR2BaseNoChecks {
+ using ERC165Checker for address;
+ using EnumerableMapAddresses for EnumerableMapAddresses.AddressToAddressMap;
+
+ error AlreadyAttempted(uint64 sequenceNumber);
+ error AlreadyExecuted(uint64 sequenceNumber);
+ error ZeroAddressNotAllowed();
+ error CommitStoreAlreadyInUse();
+ error ExecutionError(bytes err);
+ error InvalidSourceChain(uint64 sourceChainSelector);
+ error MessageTooLarge(uint256 maxSize, uint256 actualSize);
+ error TokenDataMismatch(uint64 sequenceNumber);
+ error UnexpectedTokenData();
+ error UnsupportedNumberOfTokens(uint64 sequenceNumber);
+ error ManualExecutionNotYetEnabled();
+ error ManualExecutionGasLimitMismatch();
+ error InvalidManualExecutionGasLimit(uint256 index, uint256 newLimit);
+ error RootNotCommitted();
+ error CanOnlySelfCall();
+ error ReceiverError(bytes err);
+ error TokenHandlingError(bytes err);
+ error EmptyReport();
+ error CursedByRMN();
+ error InvalidMessageId();
+ error NotACompatiblePool(address notPool);
+ error InvalidDataLength(uint256 expected, uint256 got);
+ error InvalidNewState(uint64 sequenceNumber, Internal.MessageExecutionState newState);
+
+ /// @dev Atlas depends on this event, if changing, please notify Atlas.
+ event ConfigSet(StaticConfig staticConfig, DynamicConfig dynamicConfig);
+ event SkippedIncorrectNonce(uint64 indexed nonce, address indexed sender);
+ event SkippedSenderWithPreviousRampMessageInflight(uint64 indexed nonce, address indexed sender);
+ /// @dev RMN depends on this event, if changing, please notify the RMN maintainers.
+ event ExecutionStateChanged(
+ uint64 indexed sequenceNumber, bytes32 indexed messageId, Internal.MessageExecutionState state, bytes returnData
+ );
+ event TokenAggregateRateLimitAdded(address sourceToken, address destToken);
+ event TokenAggregateRateLimitRemoved(address sourceToken, address destToken);
+ event SkippedAlreadyExecutedMessage(uint64 indexed sequenceNumber);
+
+ /// @notice Static offRamp config
+ /// @dev RMN depends on this struct, if changing, please notify the RMN maintainers.
+ //solhint-disable gas-struct-packing
+ struct StaticConfig {
+ address commitStore; // ────────╮ CommitStore address on the destination chain
+ uint64 chainSelector; // ───────╯ Destination chainSelector
+ uint64 sourceChainSelector; // ─╮ Source chainSelector
+ address onRamp; // ─────────────╯ OnRamp address on the source chain
+ address prevOffRamp; // Address of previous-version OffRamp
+ address rmnProxy; // RMN proxy address
+ address tokenAdminRegistry; // Token admin registry address
+ }
+
+ /// @notice Dynamic offRamp config
+ /// @dev since OffRampConfig is part of OffRampConfigChanged event, if changing it, we should update the ABI on Atlas
+ struct DynamicConfig {
+ uint32 permissionLessExecutionThresholdSeconds; // ─╮ Waiting time before manual execution is enabled
+ uint32 maxDataBytes; // │ Maximum payload data size in bytes
+ uint16 maxNumberOfTokensPerMsg; // │ Maximum number of ERC20 token transfers that can be included per message
+ address router; // ─────────────────────────────────╯ Router address
+ address priceRegistry; // ──────────╮ Price registry address
+ uint32 maxPoolReleaseOrMintGas; // │ Maximum amount of gas passed on to token pool `releaseOrMint` call
+ uint32 maxTokenTransferGas; // ─────╯ Maximum amount of gas passed on to token `transfer` call
+ }
+
+ /// @notice RateLimitToken struct containing both the source and destination token addresses
+ struct RateLimitToken {
+ address sourceToken;
+ address destToken;
+ }
+
+ // STATIC CONFIG
+ string public constant override typeAndVersion = "EVM2EVMOffRamp 1.5.0-dev";
+
+ /// @dev Commit store address on the destination chain
+ address internal immutable i_commitStore;
+ /// @dev ChainSelector of the source chain
+ uint64 internal immutable i_sourceChainSelector;
+ /// @dev ChainSelector of this chain
+ uint64 internal immutable i_chainSelector;
+ /// @dev OnRamp address on the source chain
+ address internal immutable i_onRamp;
+ /// @dev metadataHash is a lane-specific prefix for a message hash preimage which ensures global uniqueness.
+ /// Ensures that 2 identical messages sent to 2 different lanes will have a distinct hash.
+ /// Must match the metadataHash used in computing leaf hashes offchain for the root committed in
+ /// the commitStore and i_metadataHash in the onRamp.
+ bytes32 internal immutable i_metadataHash;
+ /// @dev The address of previous-version OffRamp for this lane.
+ /// Used to be able to provide sequencing continuity during a zero downtime upgrade.
+ address internal immutable i_prevOffRamp;
+ /// @dev The address of the RMN proxy
+ address internal immutable i_rmnProxy;
+ /// @dev The address of the token admin registry
+ address internal immutable i_tokenAdminRegistry;
+
+ // DYNAMIC CONFIG
+ DynamicConfig internal s_dynamicConfig;
+ /// @dev Tokens that should be included in Aggregate Rate Limiting
+ /// An (address => address) map is used for backwards compatability of offchain code
+ EnumerableMapAddresses.AddressToAddressMap internal s_rateLimitedTokensDestToSource;
+
+ // STATE
+ /// @dev The expected nonce for a given sender.
+ /// Corresponds to s_senderNonce in the OnRamp, used to enforce that messages are
+ /// executed in the same order they are sent (assuming they are DON). Note that re-execution
+ /// of FAILED messages however, can be out of order.
+ mapping(address sender => uint64 nonce) internal s_senderNonce;
+ /// @dev A mapping of sequence numbers to execution state using a bitmap with each execution
+ /// state only taking up 2 bits of the uint256, packing 128 states into a single slot.
+ /// Message state is tracked to ensure message can only be executed successfully once.
+ mapping(uint64 seqNum => uint256 executionStateBitmap) internal s_executionStates;
+
+ constructor(
+ StaticConfig memory staticConfig,
+ RateLimiter.Config memory rateLimiterConfig
+ ) OCR2BaseNoChecks() AggregateRateLimiter(rateLimiterConfig) {
+ if (
+ staticConfig.onRamp == address(0) || staticConfig.commitStore == address(0)
+ || staticConfig.tokenAdminRegistry == address(0)
+ ) revert ZeroAddressNotAllowed();
+ // Ensures we can never deploy a new offRamp that points to a commitStore that
+ // already has roots committed.
+ if (ICommitStore(staticConfig.commitStore).getExpectedNextSequenceNumber() != 1) revert CommitStoreAlreadyInUse();
+
+ i_commitStore = staticConfig.commitStore;
+ i_sourceChainSelector = staticConfig.sourceChainSelector;
+ i_chainSelector = staticConfig.chainSelector;
+ i_onRamp = staticConfig.onRamp;
+ i_prevOffRamp = staticConfig.prevOffRamp;
+ i_rmnProxy = staticConfig.rmnProxy;
+ i_tokenAdminRegistry = staticConfig.tokenAdminRegistry;
+
+ i_metadataHash = _metadataHash(Internal.EVM_2_EVM_MESSAGE_HASH);
+ }
+
+ // ================================================================
+ // │ Messaging │
+ // ================================================================
+
+ // The size of the execution state in bits
+ uint256 private constant MESSAGE_EXECUTION_STATE_BIT_WIDTH = 2;
+ // The mask for the execution state bits
+ uint256 private constant MESSAGE_EXECUTION_STATE_MASK = (1 << MESSAGE_EXECUTION_STATE_BIT_WIDTH) - 1;
+
+ /// @notice Returns the current execution state of a message based on its sequenceNumber.
+ /// @param sequenceNumber The sequence number of the message to get the execution state for.
+ /// @return The current execution state of the message.
+ /// @dev we use the literal number 128 because using a constant increased gas usage.
+ function getExecutionState(uint64 sequenceNumber) public view returns (Internal.MessageExecutionState) {
+ return Internal.MessageExecutionState(
+ (s_executionStates[sequenceNumber / 128] >> ((sequenceNumber % 128) * MESSAGE_EXECUTION_STATE_BIT_WIDTH))
+ & MESSAGE_EXECUTION_STATE_MASK
+ );
+ }
+
+ /// @notice Sets a new execution state for a given sequence number. It will overwrite any existing state.
+ /// @param sequenceNumber The sequence number for which the state will be saved.
+ /// @param newState The new value the state will be in after this function is called.
+ /// @dev we use the literal number 128 because using a constant increased gas usage.
+ function _setExecutionState(uint64 sequenceNumber, Internal.MessageExecutionState newState) internal {
+ uint256 offset = (sequenceNumber % 128) * MESSAGE_EXECUTION_STATE_BIT_WIDTH;
+ uint256 bitmap = s_executionStates[sequenceNumber / 128];
+ // to unset any potential existing state we zero the bits of the section the state occupies,
+ // then we do an AND operation to blank out any existing state for the section.
+ bitmap &= ~(MESSAGE_EXECUTION_STATE_MASK << offset);
+ // Set the new state
+ bitmap |= uint256(newState) << offset;
+
+ s_executionStates[sequenceNumber / 128] = bitmap;
+ }
+
+ /// @inheritdoc IAny2EVMOffRamp
+ function getSenderNonce(address sender) external view returns (uint64 nonce) {
+ uint256 senderNonce = s_senderNonce[sender];
+
+ if (senderNonce == 0) {
+ if (i_prevOffRamp != address(0)) {
+ // If OffRamp was upgraded, check if sender has a nonce from the previous OffRamp.
+ return IAny2EVMOffRamp(i_prevOffRamp).getSenderNonce(sender);
+ }
+ }
+ return uint64(senderNonce);
+ }
+
+ /// @notice Manually execute a message.
+ /// @param report Internal.ExecutionReport.
+ /// @param gasLimitOverrides New gasLimit for each message in the report.
+ /// @dev We permit gas limit overrides so that users may manually execute messages which failed due to
+ /// insufficient gas provided.
+ function manuallyExecute(Internal.ExecutionReport memory report, uint256[] memory gasLimitOverrides) external {
+ // We do this here because the other _execute path is already covered OCR2BaseXXX.
+ _checkChainForked();
+
+ uint256 numMsgs = report.messages.length;
+ if (numMsgs != gasLimitOverrides.length) revert ManualExecutionGasLimitMismatch();
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ uint256 newLimit = gasLimitOverrides[i];
+ // Checks to ensure message cannot be executed with less gas than specified.
+ if (newLimit != 0) {
+ if (newLimit < report.messages[i].gasLimit) {
+ revert InvalidManualExecutionGasLimit(i, newLimit);
+ }
+ }
+ }
+
+ _execute(report, gasLimitOverrides);
+ }
+
+ /// @notice Entrypoint for execution, called by the OCR network
+ /// @dev Expects an encoded ExecutionReport
+ function _report(bytes calldata report) internal override {
+ _execute(abi.decode(report, (Internal.ExecutionReport)), new uint256[](0));
+ }
+
+ /// @notice Executes a report, executing each message in order.
+ /// @param report The execution report containing the messages and proofs.
+ /// @param manualExecGasLimits An array of gas limits to use for manual execution.
+ /// @dev If called from the DON, this array is always empty.
+ /// @dev If called from manual execution, this array is always same length as messages.
+ function _execute(Internal.ExecutionReport memory report, uint256[] memory manualExecGasLimits) internal {
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(i_sourceChainSelector)))) revert CursedByRMN();
+
+ uint256 numMsgs = report.messages.length;
+ if (numMsgs == 0) revert EmptyReport();
+ if (numMsgs != report.offchainTokenData.length) revert UnexpectedTokenData();
+
+ bytes32[] memory hashedLeaves = new bytes32[](numMsgs);
+
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ Internal.EVM2EVMMessage memory message = report.messages[i];
+ // We do this hash here instead of in _verifyMessages to avoid two separate loops
+ // over the same data, which increases gas cost
+ hashedLeaves[i] = Internal._hash(message, i_metadataHash);
+ // For EVM2EVM offramps, the messageID is the leaf hash.
+ // Asserting that this is true ensures we don't accidentally commit and then execute
+ // a message with an unexpected hash.
+ if (hashedLeaves[i] != message.messageId) revert InvalidMessageId();
+ }
+
+ // SECURITY CRITICAL CHECK
+ uint256 timestampCommitted = ICommitStore(i_commitStore).verify(hashedLeaves, report.proofs, report.proofFlagBits);
+ if (timestampCommitted == 0) revert RootNotCommitted();
+
+ // Execute messages
+ bool manualExecution = manualExecGasLimits.length != 0;
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ Internal.EVM2EVMMessage memory message = report.messages[i];
+ Internal.MessageExecutionState originalState = getExecutionState(message.sequenceNumber);
+ if (originalState == Internal.MessageExecutionState.SUCCESS) {
+ // If the message has already been executed, we skip it. We want to not revert on race conditions between
+ // executing parties. This will allow us to open up manual exec while also attempting with the DON, without
+ // reverting an entire DON batch when a user manually executes while the tx is inflight.
+ emit SkippedAlreadyExecutedMessage(message.sequenceNumber);
+ continue;
+ }
+ // Two valid cases here, we either have never touched this message before, or we tried to execute
+ // and failed. This check protects against reentry and re-execution because the other state is
+ // IN_PROGRESS which should not be allowed to execute.
+ if (
+ !(
+ originalState == Internal.MessageExecutionState.UNTOUCHED
+ || originalState == Internal.MessageExecutionState.FAILURE
+ )
+ ) revert AlreadyExecuted(message.sequenceNumber);
+
+ if (manualExecution) {
+ bool isOldCommitReport =
+ (block.timestamp - timestampCommitted) > s_dynamicConfig.permissionLessExecutionThresholdSeconds;
+ // Manually execution is fine if we previously failed or if the commit report is just too old
+ // Acceptable state transitions: FAILURE->SUCCESS, UNTOUCHED->SUCCESS, FAILURE->FAILURE
+ if (!(isOldCommitReport || originalState == Internal.MessageExecutionState.FAILURE)) {
+ revert ManualExecutionNotYetEnabled();
+ }
+
+ // Manual execution gas limit can override gas limit specified in the message. Value of 0 indicates no override.
+ if (manualExecGasLimits[i] != 0) {
+ message.gasLimit = manualExecGasLimits[i];
+ }
+ } else {
+ // DON can only execute a message once
+ // Acceptable state transitions: UNTOUCHED->SUCCESS, UNTOUCHED->FAILURE
+ if (originalState != Internal.MessageExecutionState.UNTOUCHED) revert AlreadyAttempted(message.sequenceNumber);
+ }
+
+ if (message.nonce != 0) {
+ // In the scenario where we upgrade offRamps, we still want to have sequential nonces.
+ // Referencing the old offRamp to check the expected nonce if none is set for a
+ // given sender allows us to skip the current message if it would not be the next according
+ // to the old offRamp. This preserves sequencing between updates.
+ uint64 prevNonce = s_senderNonce[message.sender];
+ if (prevNonce == 0) {
+ if (i_prevOffRamp != address(0)) {
+ prevNonce = IAny2EVMOffRamp(i_prevOffRamp).getSenderNonce(message.sender);
+ if (prevNonce + 1 != message.nonce) {
+ // the starting v2 onramp nonce, i.e. the 1st message nonce v2 offramp is expected to receive,
+ // is guaranteed to equal (largest v1 onramp nonce + 1).
+ // if this message's nonce isn't (v1 offramp nonce + 1), then v1 offramp nonce != largest v1 onramp nonce,
+ // it tells us there are still messages inflight for v1 offramp
+ emit SkippedSenderWithPreviousRampMessageInflight(message.nonce, message.sender);
+ continue;
+ }
+ // Otherwise this nonce is indeed the "transitional nonce", that is
+ // all messages sent to v1 ramp have been executed by the DON and the sequence can resume in V2.
+ // Note if first time user in V2, then prevNonce will be 0, and message.nonce = 1, so this will be a no-op.
+ s_senderNonce[message.sender] = prevNonce;
+ }
+ }
+
+ // UNTOUCHED messages MUST be executed in order always IF message.nonce > 0.
+ if (originalState == Internal.MessageExecutionState.UNTOUCHED) {
+ if (prevNonce + 1 != message.nonce) {
+ // We skip the message if the nonce is incorrect, since message.nonce > 0.
+ emit SkippedIncorrectNonce(message.nonce, message.sender);
+ continue;
+ }
+ }
+ }
+
+ // Although we expect only valid messages will be committed, we check again
+ // when executing as a defense in depth measure.
+ bytes[] memory offchainTokenData = report.offchainTokenData[i];
+ _isWellFormed(
+ message.sequenceNumber,
+ message.sourceChainSelector,
+ message.tokenAmounts.length,
+ message.data.length,
+ offchainTokenData.length
+ );
+
+ _setExecutionState(message.sequenceNumber, Internal.MessageExecutionState.IN_PROGRESS);
+ (Internal.MessageExecutionState newState, bytes memory returnData) = _trialExecute(message, offchainTokenData);
+ _setExecutionState(message.sequenceNumber, newState);
+
+ // Since it's hard to estimate whether manual execution will succeed, we
+ // revert the entire transaction if it fails. This will show the user if
+ // their manual exec will fail before they submit it.
+ if (manualExecution) {
+ if (newState == Internal.MessageExecutionState.FAILURE) {
+ if (originalState != Internal.MessageExecutionState.UNTOUCHED) {
+ // If manual execution fails, we revert the entire transaction, unless the originalState is UNTOUCHED as we
+ // would still be making progress by changing the state from UNTOUCHED to FAILURE.
+ revert ExecutionError(returnData);
+ }
+ }
+ }
+
+ // The only valid prior states are UNTOUCHED and FAILURE (checked above)
+ // The only valid post states are SUCCESS and FAILURE (checked below)
+ if (newState != Internal.MessageExecutionState.SUCCESS) {
+ if (newState != Internal.MessageExecutionState.FAILURE) {
+ revert InvalidNewState(message.sequenceNumber, newState);
+ }
+ }
+
+ // Nonce changes per state transition.
+ // These only apply for ordered messages.
+ // UNTOUCHED -> FAILURE nonce bump
+ // UNTOUCHED -> SUCCESS nonce bump
+ // FAILURE -> FAILURE no nonce bump
+ // FAILURE -> SUCCESS no nonce bump
+ if (message.nonce != 0) {
+ if (originalState == Internal.MessageExecutionState.UNTOUCHED) {
+ s_senderNonce[message.sender]++;
+ }
+ }
+
+ emit ExecutionStateChanged(message.sequenceNumber, message.messageId, newState, returnData);
+ }
+ }
+
+ /// @notice Does basic message validation. Should never fail.
+ /// @param sequenceNumber Sequence number of the message.
+ /// @param sourceChainSelector SourceChainSelector of the message.
+ /// @param numberOfTokens Length of tokenAmounts array in the message.
+ /// @param dataLength Length of data field in the message.
+ /// @param offchainTokenDataLength Length of offchainTokenData array.
+ /// @dev reverts on validation failures.
+ function _isWellFormed(
+ uint64 sequenceNumber,
+ uint64 sourceChainSelector,
+ uint256 numberOfTokens,
+ uint256 dataLength,
+ uint256 offchainTokenDataLength
+ ) private view {
+ if (sourceChainSelector != i_sourceChainSelector) revert InvalidSourceChain(sourceChainSelector);
+ if (numberOfTokens > uint256(s_dynamicConfig.maxNumberOfTokensPerMsg)) {
+ revert UnsupportedNumberOfTokens(sequenceNumber);
+ }
+ if (numberOfTokens != offchainTokenDataLength) revert TokenDataMismatch(sequenceNumber);
+ if (dataLength > uint256(s_dynamicConfig.maxDataBytes)) {
+ revert MessageTooLarge(uint256(s_dynamicConfig.maxDataBytes), dataLength);
+ }
+ }
+
+ /// @notice Try executing a message.
+ /// @param message Internal.EVM2EVMMessage memory message.
+ /// @param offchainTokenData Data provided by the DON for token transfers.
+ /// @return the new state of the message, being either SUCCESS or FAILURE.
+ /// @return revert data in bytes if CCIP receiver reverted during execution.
+ function _trialExecute(
+ Internal.EVM2EVMMessage memory message,
+ bytes[] memory offchainTokenData
+ ) internal returns (Internal.MessageExecutionState, bytes memory) {
+ try this.executeSingleMessage(message, offchainTokenData) {}
+ catch (bytes memory err) {
+ if (
+ ReceiverError.selector == bytes4(err) || TokenHandlingError.selector == bytes4(err)
+ || Internal.InvalidEVMAddress.selector == bytes4(err) || InvalidDataLength.selector == bytes4(err)
+ || CallWithExactGas.NoContract.selector == bytes4(err) || NotACompatiblePool.selector == bytes4(err)
+ ) {
+ // If CCIP receiver execution is not successful, bubble up receiver revert data,
+ // prepended by the 4 bytes of ReceiverError.selector, TokenHandlingError.selector or InvalidPoolAddress.selector.
+ // Max length of revert data is Router.MAX_RET_BYTES, max length of err is 4 + Router.MAX_RET_BYTES
+ return (Internal.MessageExecutionState.FAILURE, err);
+ }
+ // If revert is not caused by CCIP receiver, it is unexpected, bubble up the revert.
+ revert ExecutionError(err);
+ }
+ // If message execution succeeded, no CCIP receiver return data is expected, return with empty bytes.
+ return (Internal.MessageExecutionState.SUCCESS, "");
+ }
+
+ /// @notice Execute a single message.
+ /// @param message The message that will be executed.
+ /// @param offchainTokenData Token transfer data to be passed to TokenPool.
+ /// @dev We make this external and callable by the contract itself, in order to try/catch
+ /// its execution and enforce atomicity among successful message processing and token transfer.
+ /// @dev We use ERC-165 to check for the ccipReceive interface to permit sending tokens to contracts
+ /// (for example smart contract wallets) without an associated message.
+ function executeSingleMessage(Internal.EVM2EVMMessage memory message, bytes[] memory offchainTokenData) external {
+ if (msg.sender != address(this)) revert CanOnlySelfCall();
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](0);
+ if (message.tokenAmounts.length > 0) {
+ destTokenAmounts = _releaseOrMintTokens(
+ message.tokenAmounts, abi.encode(message.sender), message.receiver, message.sourceTokenData, offchainTokenData
+ );
+ }
+ // There are three cases in which we skip calling the receiver:
+ // 1. If the message data is empty AND the gas limit is 0.
+ // This indicates a message that only transfers tokens. It is valid to only send tokens to a contract
+ // that supports the IAny2EVMMessageReceiver interface, but without this first check we would call the
+ // receiver without any gas, which would revert the transaction.
+ // 2. If the receiver is not a contract.
+ // 3. If the receiver is a contract but it does not support the IAny2EVMMessageReceiver interface.
+ //
+ // The ordering of these checks is important, as the first check is the cheapest to execute.
+ if (
+ (message.data.length == 0 && message.gasLimit == 0) || message.receiver.code.length == 0
+ || !message.receiver.supportsInterface(type(IAny2EVMMessageReceiver).interfaceId)
+ ) return;
+
+ (bool success, bytes memory returnData,) = IRouter(s_dynamicConfig.router).routeMessage(
+ Client.Any2EVMMessage({
+ messageId: message.messageId,
+ sourceChainSelector: message.sourceChainSelector,
+ sender: abi.encode(message.sender),
+ data: message.data,
+ destTokenAmounts: destTokenAmounts
+ }),
+ Internal.GAS_FOR_CALL_EXACT_CHECK,
+ message.gasLimit,
+ message.receiver
+ );
+ // If CCIP receiver execution is not successful, revert the call including token transfers
+ if (!success) revert ReceiverError(returnData);
+ }
+
+ /// @notice creates a unique hash to be used in message hashing.
+ function _metadataHash(bytes32 prefix) internal view returns (bytes32) {
+ return keccak256(abi.encode(prefix, i_sourceChainSelector, i_chainSelector, i_onRamp));
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Returns the static config.
+ /// @dev This function will always return the same struct as the contents is static and can never change.
+ /// RMN depends on this function, if changing, please notify the RMN maintainers.
+ function getStaticConfig() external view returns (StaticConfig memory) {
+ return StaticConfig({
+ commitStore: i_commitStore,
+ chainSelector: i_chainSelector,
+ sourceChainSelector: i_sourceChainSelector,
+ onRamp: i_onRamp,
+ prevOffRamp: i_prevOffRamp,
+ rmnProxy: i_rmnProxy,
+ tokenAdminRegistry: i_tokenAdminRegistry
+ });
+ }
+
+ /// @notice Returns the current dynamic config.
+ /// @return The current config.
+ function getDynamicConfig() external view returns (DynamicConfig memory) {
+ return s_dynamicConfig;
+ }
+
+ /// @notice Sets the dynamic config. This function is called during `setOCR2Config` flow
+ function _beforeSetConfig(bytes memory onchainConfig) internal override {
+ DynamicConfig memory dynamicConfig = abi.decode(onchainConfig, (DynamicConfig));
+
+ if (dynamicConfig.router == address(0)) revert ZeroAddressNotAllowed();
+
+ s_dynamicConfig = dynamicConfig;
+
+ emit ConfigSet(
+ StaticConfig({
+ commitStore: i_commitStore,
+ chainSelector: i_chainSelector,
+ sourceChainSelector: i_sourceChainSelector,
+ onRamp: i_onRamp,
+ prevOffRamp: i_prevOffRamp,
+ rmnProxy: i_rmnProxy,
+ tokenAdminRegistry: i_tokenAdminRegistry
+ }),
+ dynamicConfig
+ );
+ }
+
+ /// @notice Get all tokens which are included in Aggregate Rate Limiting.
+ /// @return sourceTokens The source representation of the tokens that are rate limited.
+ /// @return destTokens The destination representation of the tokens that are rate limited.
+ /// @dev the order of IDs in the list is **not guaranteed**, therefore, if ordering matters when
+ /// making successive calls, one should keep the block height constant to ensure a consistent result.
+ function getAllRateLimitTokens() external view returns (address[] memory sourceTokens, address[] memory destTokens) {
+ uint256 numRateLimitedTokens = s_rateLimitedTokensDestToSource.length();
+ sourceTokens = new address[](numRateLimitedTokens);
+ destTokens = new address[](numRateLimitedTokens);
+
+ for (uint256 i = 0; i < numRateLimitedTokens; ++i) {
+ (address destToken, address sourceToken) = s_rateLimitedTokensDestToSource.at(i);
+ sourceTokens[i] = sourceToken;
+ destTokens[i] = destToken;
+ }
+ return (sourceTokens, destTokens);
+ }
+
+ /// @notice Adds or removes tokens from being used in Aggregate Rate Limiting.
+ /// @param removes - A list of one or more tokens to be removed.
+ /// @param adds - A list of one or more tokens to be added.
+ function updateRateLimitTokens(RateLimitToken[] memory removes, RateLimitToken[] memory adds) external onlyOwner {
+ for (uint256 i = 0; i < removes.length; ++i) {
+ if (s_rateLimitedTokensDestToSource.remove(removes[i].destToken)) {
+ emit TokenAggregateRateLimitRemoved(removes[i].sourceToken, removes[i].destToken);
+ }
+ }
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ if (s_rateLimitedTokensDestToSource.set(adds[i].destToken, adds[i].sourceToken)) {
+ emit TokenAggregateRateLimitAdded(adds[i].sourceToken, adds[i].destToken);
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Tokens and pools │
+ // ================================================================
+
+ /// @notice Uses a pool to release or mint a token to a receiver address in two steps. First, the pool is called
+ /// to release the tokens to the offRamp, then the offRamp calls the token contract to transfer the tokens to the
+ /// receiver. This is done to ensure the exact number of tokens, the pool claims to release are actually transferred.
+ /// @dev The local token address is validated through the TokenAdminRegistry. If, due to some misconfiguration, the
+ /// token is unknown to the registry, the offRamp will revert. The tx, and the tokens, can be retrieved by
+ /// registering the token on this chain, and re-trying the msg.
+ /// @param sourceAmount The amount of tokens to be released/minted.
+ /// @param originalSender The message sender on the source chain.
+ /// @param receiver The address that will receive the tokens.
+ /// @param sourceTokenData A struct containing the local token address, the source pool address and optional data
+ /// returned from the source pool.
+ /// @param offchainTokenData Data fetched offchain by the DON.
+ function _releaseOrMintToken(
+ uint256 sourceAmount,
+ bytes memory originalSender,
+ address receiver,
+ Internal.SourceTokenData memory sourceTokenData,
+ bytes memory offchainTokenData
+ ) internal returns (Client.EVMTokenAmount memory destTokenAmount) {
+ // We need to safely decode the token address from the sourceTokenData, as it could be wrong,
+ // in which case it doesn't have to be a valid EVM address.
+ address localToken = Internal._validateEVMAddress(sourceTokenData.destTokenAddress);
+ // We check with the token admin registry if the token has a pool on this chain.
+ address localPoolAddress = ITokenAdminRegistry(i_tokenAdminRegistry).getPool(localToken);
+ // This will call the supportsInterface through the ERC165Checker, and not directly on the pool address.
+ // This is done to prevent a pool from reverting the entire transaction if it doesn't support the interface.
+ // The call gets a max or 30k gas per instance, of which there are three. This means gas estimations should
+ // account for 90k gas overhead due to the interface check.
+ if (localPoolAddress == address(0) || !localPoolAddress.supportsInterface(Pool.CCIP_POOL_V1)) {
+ revert NotACompatiblePool(localPoolAddress);
+ }
+
+ // We determined that the pool address is a valid EVM address, but that does not mean the code at this
+ // address is a (compatible) pool contract. _callWithExactGasSafeReturnData will check if the location
+ // contains a contract. If it doesn't it reverts with a known error, which we catch gracefully.
+ // We call the pool with exact gas to increase resistance against malicious tokens or token pools.
+ // We protects against return data bombs by capping the return data size at MAX_RET_BYTES.
+ (bool success, bytes memory returnData,) = CallWithExactGas._callWithExactGasSafeReturnData(
+ abi.encodeCall(
+ IPoolV1.releaseOrMint,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: receiver,
+ amount: sourceAmount,
+ localToken: localToken,
+ remoteChainSelector: i_sourceChainSelector,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ ),
+ localPoolAddress,
+ s_dynamicConfig.maxPoolReleaseOrMintGas,
+ Internal.GAS_FOR_CALL_EXACT_CHECK,
+ Internal.MAX_RET_BYTES
+ );
+
+ // wrap and rethrow the error so we can catch it lower in the stack
+ if (!success) revert TokenHandlingError(returnData);
+
+ // If the call was successful, the returnData should contain only the local token amount.
+ if (returnData.length != Pool.CCIP_POOL_V1_RET_BYTES) {
+ revert InvalidDataLength(Pool.CCIP_POOL_V1_RET_BYTES, returnData.length);
+ }
+ uint256 localAmount = abi.decode(returnData, (uint256));
+ // Since token pools send the tokens to the msg.sender, which is this offRamp, we need to
+ // transfer them to the final receiver. We use the _callWithExactGasSafeReturnData function because
+ // the token contracts are not considered trusted.
+ (success, returnData,) = CallWithExactGas._callWithExactGasSafeReturnData(
+ abi.encodeCall(IERC20.transfer, (receiver, localAmount)),
+ localToken,
+ s_dynamicConfig.maxTokenTransferGas,
+ Internal.GAS_FOR_CALL_EXACT_CHECK,
+ Internal.MAX_RET_BYTES
+ );
+
+ if (!success) revert TokenHandlingError(returnData);
+
+ return Client.EVMTokenAmount({token: localToken, amount: localAmount});
+ }
+
+ /// @notice Uses pools to release or mint a number of different tokens to a receiver address.
+ /// @param sourceTokenAmounts List of tokens and amount values to be released/minted.
+ /// @param originalSender The message sender.
+ /// @param receiver The address that will receive the tokens.
+ /// @param encodedSourceTokenData Array of token data returned by token pools on the source chain.
+ /// @param offchainTokenData Array of token data fetched offchain by the DON.
+ /// @dev This function wrappes the token pool call in a try catch block to gracefully handle
+ /// any non-rate limiting errors that may occur. If we encounter a rate limiting related error
+ /// we bubble it up. If we encounter a non-rate limiting error we wrap it in a TokenHandlingError.
+ function _releaseOrMintTokens(
+ Client.EVMTokenAmount[] memory sourceTokenAmounts,
+ bytes memory originalSender,
+ address receiver,
+ bytes[] memory encodedSourceTokenData,
+ bytes[] memory offchainTokenData
+ ) internal returns (Client.EVMTokenAmount[] memory destTokenAmounts) {
+ // Creating a copy is more gas efficient than initializing a new array.
+ destTokenAmounts = sourceTokenAmounts;
+ uint256 value = 0;
+ for (uint256 i = 0; i < sourceTokenAmounts.length; ++i) {
+ destTokenAmounts[i] = _releaseOrMintToken(
+ sourceTokenAmounts[i].amount,
+ originalSender,
+ receiver,
+ // This should never revert as the onRamp encodes the sourceTokenData struct. Only the inner components from
+ // this struct come from untrusted sources.
+ abi.decode(encodedSourceTokenData[i], (Internal.SourceTokenData)),
+ offchainTokenData[i]
+ );
+
+ if (s_rateLimitedTokensDestToSource.contains(destTokenAmounts[i].token)) {
+ value += _getTokenValue(destTokenAmounts[i], IPriceRegistry(s_dynamicConfig.priceRegistry));
+ }
+ }
+
+ if (value > 0) _rateLimitValue(value);
+
+ return destTokenAmounts;
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Reverts as this contract should not access CCIP messages
+ function ccipReceive(Client.Any2EVMMessage calldata) external pure {
+ // solhint-disable-next-line
+ revert();
+ }
+}
diff --git a/contracts/src/v0.8/ccip/onRamp/EVM2EVMMultiOnRamp.sol b/contracts/src/v0.8/ccip/onRamp/EVM2EVMMultiOnRamp.sol
new file mode 100644
index 00000000000..fc455cc869e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/onRamp/EVM2EVMMultiOnRamp.sol
@@ -0,0 +1,339 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IEVM2AnyOnRampClient} from "../interfaces/IEVM2AnyOnRampClient.sol";
+import {IMessageInterceptor} from "../interfaces/IMessageInterceptor.sol";
+import {INonceManager} from "../interfaces/INonceManager.sol";
+import {IPoolV1} from "../interfaces/IPool.sol";
+import {IPriceRegistry} from "../interfaces/IPriceRegistry.sol";
+import {IRMN} from "../interfaces/IRMN.sol";
+import {ITokenAdminRegistry} from "../interfaces/ITokenAdminRegistry.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {Client} from "../libraries/Client.sol";
+import {Internal} from "../libraries/Internal.sol";
+import {Pool} from "../libraries/Pool.sol";
+import {USDPriceWith18Decimals} from "../libraries/USDPriceWith18Decimals.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice The EVM2EVMMultiOnRamp is a contract that handles lane-specific fee logic
+/// @dev The EVM2EVMMultiOnRamp, MultiCommitStore and EVM2EVMMultiOffRamp form an xchain upgradeable unit. Any change to one of them
+/// results an onchain upgrade of all 3.
+contract EVM2EVMMultiOnRamp is IEVM2AnyOnRampClient, ITypeAndVersion, OwnerIsCreator {
+ using SafeERC20 for IERC20;
+ using USDPriceWith18Decimals for uint224;
+
+ error CannotSendZeroTokens();
+ error InvalidExtraArgsTag();
+ error ExtraArgOutOfOrderExecutionMustBeTrue();
+ error OnlyCallableByOwnerOrAdmin();
+ error MessageGasLimitTooHigh();
+ error UnsupportedToken(address token);
+ error MustBeCalledByRouter();
+ error RouterMustSetOriginalSender();
+ error InvalidConfig();
+ error CursedByRMN(uint64 sourceChainSelector);
+ error GetSupportedTokensFunctionalityRemovedCheckAdminRegistry();
+
+ event AdminSet(address newAdmin);
+ event ConfigSet(StaticConfig staticConfig, DynamicConfig dynamicConfig);
+ event FeePaid(address indexed feeToken, uint256 feeValueJuels);
+ event FeeTokenWithdrawn(address indexed feeAggregator, address indexed feeToken, uint256 amount);
+ /// RMN depends on this event, if changing, please notify the RMN maintainers.
+ event CCIPSendRequested(uint64 indexed destChainSelector, Internal.EVM2AnyRampMessage message);
+
+ /// @dev Struct that contains the static configuration
+ /// RMN depends on this struct, if changing, please notify the RMN maintainers.
+ // solhint-disable-next-line gas-struct-packing
+ struct StaticConfig {
+ uint64 chainSelector; // ─────╮ Source chainSelector
+ address rmnProxy; // ─────────╯ Address of RMN proxy
+ address nonceManager; // Address of the nonce manager
+ address tokenAdminRegistry; // Token admin registry address
+ }
+
+ /// @dev Struct to contains the dynamic configuration
+ // solhint-disable-next-line gas-struct-packing
+ struct DynamicConfig {
+ address router; // Router address
+ address priceRegistry; // Price registry address
+ address messageValidator; // Optional message validator to validate outbound messages (zero address = no validator)
+ address feeAggregator; // Fee aggregator address
+ }
+
+ // STATIC CONFIG
+ string public constant override typeAndVersion = "EVM2EVMMultiOnRamp 1.6.0-dev";
+ /// @dev The chain ID of the source chain that this contract is deployed to
+ uint64 internal immutable i_chainSelector;
+ /// @dev The address of the rmn proxy
+ address internal immutable i_rmnProxy;
+ /// @dev The address of the nonce manager
+ address internal immutable i_nonceManager;
+ /// @dev The address of the token admin registry
+ address internal immutable i_tokenAdminRegistry;
+ /// @dev the maximum number of nops that can be configured at the same time.
+ /// Used to bound gas for loops over nops.
+ uint256 private constant MAX_NUMBER_OF_NOPS = 64;
+
+ // DYNAMIC CONFIG
+ /// @dev The config for the onRamp
+ DynamicConfig internal s_dynamicConfig;
+
+ /// @dev Last used sequence number per destination chain.
+ /// This is zero in the case where no messages have been sent yet.
+ /// 0 is not a valid sequence number for any real transaction.
+ mapping(uint64 destChainSelector => uint64 sequenceNumber) internal s_destChainSequenceNumbers;
+
+ // STATE
+ /// @dev The amount of LINK available to pay NOPS
+ uint96 internal s_nopFeesJuels;
+ /// @dev The combined weight of all NOPs weights
+ uint32 internal s_nopWeightsTotal;
+
+ constructor(StaticConfig memory staticConfig, DynamicConfig memory dynamicConfig) {
+ if (
+ staticConfig.chainSelector == 0 || staticConfig.rmnProxy == address(0) || staticConfig.nonceManager == address(0)
+ || staticConfig.tokenAdminRegistry == address(0)
+ ) {
+ revert InvalidConfig();
+ }
+
+ i_chainSelector = staticConfig.chainSelector;
+ i_rmnProxy = staticConfig.rmnProxy;
+ i_nonceManager = staticConfig.nonceManager;
+ i_tokenAdminRegistry = staticConfig.tokenAdminRegistry;
+
+ _setDynamicConfig(dynamicConfig);
+ }
+
+ // ================================================================
+ // │ Messaging │
+ // ================================================================
+
+ /// @notice Gets the next sequence number to be used in the onRamp
+ /// @param destChainSelector The destination chain selector
+ /// @return the next sequence number to be used
+ function getExpectedNextSequenceNumber(uint64 destChainSelector) external view returns (uint64) {
+ return s_destChainSequenceNumbers[destChainSelector] + 1;
+ }
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ function forwardFromRouter(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message,
+ uint256 feeTokenAmount,
+ address originalSender
+ ) external returns (bytes32) {
+ // NOTE: assumes the message has already been validated through the getFee call
+ // Validate message sender is set and allowed. Not validated in `getFee` since it is not user-driven.
+ if (originalSender == address(0)) revert RouterMustSetOriginalSender();
+ // Router address may be zero intentionally to pause.
+ if (msg.sender != s_dynamicConfig.router) revert MustBeCalledByRouter();
+
+ address messageValidator = s_dynamicConfig.messageValidator;
+ if (messageValidator != address(0)) {
+ IMessageInterceptor(messageValidator).onOutboundMessage(destChainSelector, message);
+ }
+
+ // Convert message fee to juels and retrieve converted args
+ (uint256 msgFeeJuels, bool isOutOfOrderExecution, bytes memory convertedExtraArgs) = IPriceRegistry(
+ s_dynamicConfig.priceRegistry
+ ).processMessageArgs(destChainSelector, message.feeToken, feeTokenAmount, message.extraArgs);
+
+ emit FeePaid(message.feeToken, msgFeeJuels);
+
+ Internal.EVM2AnyRampMessage memory newMessage = Internal.EVM2AnyRampMessage({
+ header: Internal.RampMessageHeader({
+ // Should be generated after the message is complete
+ messageId: "",
+ sourceChainSelector: i_chainSelector,
+ destChainSelector: destChainSelector,
+ // We need the next available sequence number so we increment before we use the value
+ sequenceNumber: ++s_destChainSequenceNumbers[destChainSelector],
+ // Only bump nonce for messages that specify allowOutOfOrderExecution == false. Otherwise, we
+ // may block ordered message nonces, which is not what we want.
+ nonce: isOutOfOrderExecution
+ ? 0
+ : INonceManager(i_nonceManager).getIncrementedOutboundNonce(destChainSelector, originalSender)
+ }),
+ sender: originalSender,
+ data: message.data,
+ extraArgs: message.extraArgs,
+ receiver: message.receiver,
+ feeToken: message.feeToken,
+ feeTokenAmount: feeTokenAmount,
+ // Should be populated via lock / burn pool calls
+ tokenAmounts: new Internal.RampTokenAmount[](message.tokenAmounts.length)
+ });
+
+ // Lock the tokens as last step. TokenPools may not always be trusted.
+ // There should be no state changes after external call to TokenPools.
+ for (uint256 i = 0; i < message.tokenAmounts.length; ++i) {
+ newMessage.tokenAmounts[i] =
+ _lockOrBurnSingleToken(message.tokenAmounts[i], destChainSelector, message.receiver, originalSender);
+ }
+
+ // Validate pool return data after it is populated (view function - no state changes)
+ IPriceRegistry(s_dynamicConfig.priceRegistry).validatePoolReturnData(
+ destChainSelector, newMessage.tokenAmounts, message.tokenAmounts
+ );
+
+ // Override extraArgs with latest version
+ newMessage.extraArgs = convertedExtraArgs;
+
+ // Hash only after all fields have been set
+ newMessage.header.messageId = Internal._hash(
+ newMessage,
+ // Metadata hash preimage to ensure global uniqueness, ensuring 2 identical messages sent to 2 different
+ // lanes will have a distinct hash.
+ keccak256(abi.encode(Internal.EVM_2_ANY_MESSAGE_HASH, i_chainSelector, destChainSelector, address(this)))
+ );
+
+ // Emit message request
+ // This must happen after any pool events as some tokens (e.g. USDC) emit events that we expect to precede this
+ // event in the offchain code.
+ emit CCIPSendRequested(destChainSelector, newMessage);
+ return newMessage.header.messageId;
+ }
+
+ /// @notice Uses a pool to lock or burn a token
+ /// @param tokenAndAmount Token address and amount to lock or burn
+ /// @param destChainSelector Target dest chain selector of the message
+ /// @param receiver Message receiver
+ /// @param originalSender Message sender
+ /// @return rampTokenAndAmount Ramp token and amount data
+ function _lockOrBurnSingleToken(
+ Client.EVMTokenAmount memory tokenAndAmount,
+ uint64 destChainSelector,
+ bytes memory receiver,
+ address originalSender
+ ) internal returns (Internal.RampTokenAmount memory) {
+ if (tokenAndAmount.amount == 0) revert CannotSendZeroTokens();
+
+ IPoolV1 sourcePool = getPoolBySourceToken(destChainSelector, IERC20(tokenAndAmount.token));
+ // We don't have to check if it supports the pool version in a non-reverting way here because
+ // if we revert here, there is no effect on CCIP. Therefore we directly call the supportsInterface
+ // function and not through the ERC165Checker.
+ if (address(sourcePool) == address(0) || !sourcePool.supportsInterface(Pool.CCIP_POOL_V1)) {
+ revert UnsupportedToken(tokenAndAmount.token);
+ }
+
+ Pool.LockOrBurnOutV1 memory poolReturnData = sourcePool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ receiver: receiver,
+ remoteChainSelector: destChainSelector,
+ originalSender: originalSender,
+ amount: tokenAndAmount.amount,
+ localToken: tokenAndAmount.token
+ })
+ );
+
+ // NOTE: pool data validations are outsourced to the PriceRegistry to handle family-specific logic handling
+
+ return Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(sourcePool),
+ destTokenAddress: poolReturnData.destTokenAddress,
+ extraData: poolReturnData.destPoolData,
+ amount: tokenAndAmount.amount
+ });
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Returns the static onRamp config.
+ /// @dev RMN depends on this function, if changing, please notify the RMN maintainers.
+ /// @return the configuration.
+ function getStaticConfig() external view returns (StaticConfig memory) {
+ return StaticConfig({
+ chainSelector: i_chainSelector,
+ rmnProxy: i_rmnProxy,
+ nonceManager: i_nonceManager,
+ tokenAdminRegistry: i_tokenAdminRegistry
+ });
+ }
+
+ /// @notice Returns the dynamic onRamp config.
+ /// @return dynamicConfig the configuration.
+ function getDynamicConfig() external view returns (DynamicConfig memory dynamicConfig) {
+ return s_dynamicConfig;
+ }
+
+ /// @notice Sets the dynamic configuration.
+ /// @param dynamicConfig The configuration.
+ function setDynamicConfig(DynamicConfig memory dynamicConfig) external onlyOwner {
+ _setDynamicConfig(dynamicConfig);
+ }
+
+ /// @notice Internal version of setDynamicConfig to allow for reuse in the constructor.
+ function _setDynamicConfig(DynamicConfig memory dynamicConfig) internal {
+ // We permit router to be set to zero as a way to pause the contract.
+ if (dynamicConfig.priceRegistry == address(0) || dynamicConfig.feeAggregator == address(0)) revert InvalidConfig();
+
+ s_dynamicConfig = dynamicConfig;
+
+ emit ConfigSet(
+ StaticConfig({
+ chainSelector: i_chainSelector,
+ rmnProxy: i_rmnProxy,
+ nonceManager: i_nonceManager,
+ tokenAdminRegistry: i_tokenAdminRegistry
+ }),
+ dynamicConfig
+ );
+ }
+
+ // ================================================================
+ // │ Tokens and pools │
+ // ================================================================
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ function getPoolBySourceToken(uint64, /*destChainSelector*/ IERC20 sourceToken) public view returns (IPoolV1) {
+ return IPoolV1(ITokenAdminRegistry(i_tokenAdminRegistry).getPool(address(sourceToken)));
+ }
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ function getSupportedTokens(uint64 /*destChainSelector*/ ) external pure returns (address[] memory) {
+ revert GetSupportedTokensFunctionalityRemovedCheckAdminRegistry();
+ }
+
+ // ================================================================
+ // │ Fees │
+ // ================================================================
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ /// @dev getFee MUST revert if the feeToken is not listed in the fee token config, as the router assumes it does.
+ /// @param destChainSelector The destination chain selector.
+ /// @param message The message to get quote for.
+ /// @return feeTokenAmount The amount of fee token needed for the fee, in smallest denomination of the fee token.
+ function getFee(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external view returns (uint256 feeTokenAmount) {
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(destChainSelector)))) revert CursedByRMN(destChainSelector);
+
+ return IPriceRegistry(s_dynamicConfig.priceRegistry).getValidatedFee(destChainSelector, message);
+ }
+
+ /// @notice Withdraws the outstanding fee token balances to the fee aggregator.
+ /// @dev This function can be permissionless as it only transfers accepted fee tokens to the fee aggregator which is a trusted address.
+ function withdrawFeeTokens() external {
+ address[] memory feeTokens = IPriceRegistry(s_dynamicConfig.priceRegistry).getFeeTokens();
+ address feeAggregator = s_dynamicConfig.feeAggregator;
+
+ for (uint256 i = 0; i < feeTokens.length; ++i) {
+ IERC20 feeToken = IERC20(feeTokens[i]);
+ uint256 feeTokenBalance = feeToken.balanceOf(address(this));
+
+ if (feeTokenBalance > 0) {
+ feeToken.safeTransfer(feeAggregator, feeTokenBalance);
+
+ emit FeeTokenWithdrawn(feeAggregator, address(feeToken), feeTokenBalance);
+ }
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/onRamp/EVM2EVMOnRamp.sol b/contracts/src/v0.8/ccip/onRamp/EVM2EVMOnRamp.sol
new file mode 100644
index 00000000000..0e978596e4c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/onRamp/EVM2EVMOnRamp.sol
@@ -0,0 +1,916 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IEVM2AnyOnRamp} from "../interfaces/IEVM2AnyOnRamp.sol";
+import {IEVM2AnyOnRampClient} from "../interfaces/IEVM2AnyOnRampClient.sol";
+import {IPoolV1} from "../interfaces/IPool.sol";
+import {IPriceRegistry} from "../interfaces/IPriceRegistry.sol";
+import {IRMN} from "../interfaces/IRMN.sol";
+import {ITokenAdminRegistry} from "../interfaces/ITokenAdminRegistry.sol";
+import {ILinkAvailable} from "../interfaces/automation/ILinkAvailable.sol";
+
+import {AggregateRateLimiter} from "../AggregateRateLimiter.sol";
+import {Client} from "../libraries/Client.sol";
+import {Internal} from "../libraries/Internal.sol";
+import {Pool} from "../libraries/Pool.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+import {USDPriceWith18Decimals} from "../libraries/USDPriceWith18Decimals.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+import {EnumerableMap} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableMap.sol";
+
+/// @notice The onRamp is a contract that handles lane-specific fee logic, NOP payments and
+/// bridgeable token support.
+/// @dev The EVM2EVMOnRamp, CommitStore and EVM2EVMOffRamp form an xchain upgradeable unit. Any change to one of them
+/// results an onchain upgrade of all 3.
+contract EVM2EVMOnRamp is IEVM2AnyOnRamp, ILinkAvailable, AggregateRateLimiter, ITypeAndVersion {
+ using SafeERC20 for IERC20;
+ using EnumerableMap for EnumerableMap.AddressToUintMap;
+ using USDPriceWith18Decimals for uint224;
+
+ error InvalidExtraArgsTag();
+ error ExtraArgOutOfOrderExecutionMustBeTrue();
+ error OnlyCallableByOwnerOrAdmin();
+ error OnlyCallableByOwnerOrAdminOrNop();
+ error InvalidWithdrawParams();
+ error NoFeesToPay();
+ error NoNopsToPay();
+ error InsufficientBalance();
+ error TooManyNops();
+ error MaxFeeBalanceReached();
+ error MessageTooLarge(uint256 maxSize, uint256 actualSize);
+ error MessageGasLimitTooHigh();
+ error UnsupportedNumberOfTokens();
+ error UnsupportedToken(address token);
+ error MustBeCalledByRouter();
+ error RouterMustSetOriginalSender();
+ error InvalidConfig();
+ error CursedByRMN();
+ error LinkBalanceNotSettled();
+ error InvalidNopAddress(address nop);
+ error NotAFeeToken(address token);
+ error CannotSendZeroTokens();
+ error SourceTokenDataTooLarge(address token);
+ error InvalidChainSelector(uint64 chainSelector);
+ error GetSupportedTokensFunctionalityRemovedCheckAdminRegistry();
+ error InvalidDestBytesOverhead(address token, uint32 destBytesOverhead);
+
+ event ConfigSet(StaticConfig staticConfig, DynamicConfig dynamicConfig);
+ event NopPaid(address indexed nop, uint256 amount);
+ event FeeConfigSet(FeeTokenConfigArgs[] feeConfig);
+ event TokenTransferFeeConfigSet(TokenTransferFeeConfigArgs[] transferFeeConfig);
+ event TokenTransferFeeConfigDeleted(address[] tokens);
+ /// RMN depends on this event, if changing, please notify the RMN maintainers.
+ event CCIPSendRequested(Internal.EVM2EVMMessage message);
+ event NopsSet(uint256 nopWeightsTotal, NopAndWeight[] nopsAndWeights);
+
+ /// @dev Struct that contains the static configuration
+ /// RMN depends on this struct, if changing, please notify the RMN maintainers.
+ //solhint-disable gas-struct-packing
+ struct StaticConfig {
+ address linkToken; // ────────╮ Link token address
+ uint64 chainSelector; // ─────╯ Source chainSelector
+ uint64 destChainSelector; // ─╮ Destination chainSelector
+ uint64 defaultTxGasLimit; // │ Default gas limit for a tx
+ uint96 maxNopFeesJuels; // ───╯ Max nop fee balance onramp can have
+ address prevOnRamp; // Address of previous-version OnRamp
+ address rmnProxy; // Address of RMN proxy
+ address tokenAdminRegistry; // Address of the token admin registry
+ }
+
+ /// @dev Struct to contains the dynamic configuration
+ struct DynamicConfig {
+ address router; // ──────────────────────────╮ Router address
+ uint16 maxNumberOfTokensPerMsg; // │ Maximum number of distinct ERC20 token transferred per message
+ uint32 destGasOverhead; // │ Gas charged on top of the gasLimit to cover destination chain costs
+ uint16 destGasPerPayloadByte; // │ Destination chain gas charged for passing each byte of `data` payload to receiver
+ uint32 destDataAvailabilityOverheadGas; // ──╯ Extra data availability gas charged on top of the message, e.g. for OCR
+ uint16 destGasPerDataAvailabilityByte; // ───╮ Amount of gas to charge per byte of message data that needs availability
+ uint16 destDataAvailabilityMultiplierBps; // │ Multiplier for data availability gas, multiples of bps, or 0.0001
+ address priceRegistry; // │ Price registry address
+ uint32 maxDataBytes; // │ Maximum payload data size in bytes
+ uint32 maxPerMsgGasLimit; // ────────────────╯ Maximum gas limit for messages targeting EVMs
+ // │
+ // The following three properties are defaults, they can be overridden by setting the TokenTransferFeeConfig for a token
+ uint16 defaultTokenFeeUSDCents; // ──────────╮ Default token fee charged per token transfer
+ uint32 defaultTokenDestGasOverhead; // │ Default gas charged to execute the token transfer on the destination chain
+ // │ Default data availability bytes that are returned from the source pool and sent
+ uint32 defaultTokenDestBytesOverhead; // | to the destination pool. Must be >= Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES
+ bool enforceOutOfOrder; // ──────────────────╯ Whether to enforce the allowOutOfOrderExecution extraArg value to be true.
+ }
+
+ /// @dev Struct to hold the execution fee configuration for a fee token
+ struct FeeTokenConfig {
+ uint32 networkFeeUSDCents; // ─────────╮ Flat network fee to charge for messages, multiples of 0.01 USD
+ uint64 gasMultiplierWeiPerEth; // │ Multiplier for gas costs, 1e18 based so 11e17 = 10% extra cost.
+ uint64 premiumMultiplierWeiPerEth; // │ Multiplier for fee-token-specific premiums
+ bool enabled; // ──────────────────────╯ Whether this fee token is enabled
+ }
+
+ /// @dev Struct to hold the fee configuration for a fee token, same as the FeeTokenConfig but with
+ /// token included so that an array of these can be passed in to setFeeTokenConfig to set the mapping
+ struct FeeTokenConfigArgs {
+ address token; // ─────────────────────╮ Token address
+ uint32 networkFeeUSDCents; // │ Flat network fee to charge for messages, multiples of 0.01 USD
+ uint64 gasMultiplierWeiPerEth; // ─────╯ Multiplier for gas costs, 1e18 based so 11e17 = 10% extra cost
+ uint64 premiumMultiplierWeiPerEth; // ─╮ Multiplier for fee-token-specific premiums, 1e18 based
+ bool enabled; // ──────────────────────╯ Whether this fee token is enabled
+ }
+
+ /// @dev Struct to hold the transfer fee configuration for token transfers
+ struct TokenTransferFeeConfig {
+ uint32 minFeeUSDCents; // ──────────╮ Minimum fee to charge per token transfer, multiples of 0.01 USD
+ uint32 maxFeeUSDCents; // │ Maximum fee to charge per token transfer, multiples of 0.01 USD
+ uint16 deciBps; // │ Basis points charged on token transfers, multiples of 0.1bps, or 1e-5
+ uint32 destGasOverhead; // │ Gas charged to execute the token transfer on the destination chain
+ // │ Extra data availability bytes that are returned from the source pool and sent
+ uint32 destBytesOverhead; // │ to the destination pool. Must be >= Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES
+ bool aggregateRateLimitEnabled; // │ Whether this transfer token is to be included in Aggregate Rate Limiting
+ bool isEnabled; // ─────────────────╯ Whether this token has custom transfer fees
+ }
+
+ /// @dev Same as TokenTransferFeeConfig
+ /// token included so that an array of these can be passed in to setTokenTransferFeeConfig
+ struct TokenTransferFeeConfigArgs {
+ address token; // ──────────────────╮ Token address
+ uint32 minFeeUSDCents; // │ Minimum fee to charge per token transfer, multiples of 0.01 USD
+ uint32 maxFeeUSDCents; // │ Maximum fee to charge per token transfer, multiples of 0.01 USD
+ uint16 deciBps; // ─────────────────╯ Basis points charged on token transfers, multiples of 0.1bps, or 1e-5
+ uint32 destGasOverhead; // ─────────╮ Gas charged to execute the token transfer on the destination chain
+ // │ Extra data availability bytes that are returned from the source pool and sent
+ uint32 destBytesOverhead; // │ to the destination pool. Must be >= Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES
+ bool aggregateRateLimitEnabled; // ─╯ Whether this transfer token is to be included in Aggregate Rate Limiting
+ }
+
+ /// @dev Nop address and weight, used to set the nops and their weights
+ struct NopAndWeight {
+ address nop; // ────╮ Address of the node operator
+ uint16 weight; // ──╯ Weight for nop rewards
+ }
+
+ // STATIC CONFIG
+ string public constant override typeAndVersion = "EVM2EVMOnRamp 1.5.0-dev";
+ /// @dev metadataHash is a lane-specific prefix for a message hash preimage which ensures global uniqueness
+ /// Ensures that 2 identical messages sent to 2 different lanes will have a distinct hash.
+ /// Must match the metadataHash used in computing leaf hashes offchain for the root committed in
+ /// the commitStore and i_metadataHash in the offRamp.
+ bytes32 internal immutable i_metadataHash;
+ /// @dev Default gas limit for a transactions that did not specify
+ /// a gas limit in the extraArgs.
+ uint64 internal immutable i_defaultTxGasLimit;
+ /// @dev Maximum nop fee that can accumulate in this onramp
+ uint96 internal immutable i_maxNopFeesJuels;
+ /// @dev The link token address - known to pay nops for their work
+ address internal immutable i_linkToken;
+ /// @dev The chain ID of the source chain that this contract is deployed to
+ uint64 internal immutable i_chainSelector;
+ /// @dev The chain ID of the destination chain
+ uint64 internal immutable i_destChainSelector;
+ /// @dev The address of previous-version OnRamp for this lane
+ /// Used to be able to provide sequencing continuity during a zero downtime upgrade.
+ address internal immutable i_prevOnRamp;
+ /// @dev The address of the RMN proxy
+ address internal immutable i_rmnProxy;
+ /// @dev The address of the token admin registry
+ address internal immutable i_tokenAdminRegistry;
+ /// @dev the maximum number of nops that can be configured at the same time.
+ /// Used to bound gas for loops over nops.
+ uint256 private constant MAX_NUMBER_OF_NOPS = 64;
+
+ // DYNAMIC CONFIG
+ /// @dev The config for the onRamp
+ DynamicConfig internal s_dynamicConfig;
+ /// @dev (address nop => uint256 weight)
+ EnumerableMap.AddressToUintMap internal s_nops;
+
+ /// @dev The execution fee token config that can be set by the owner or fee admin
+ mapping(address token => FeeTokenConfig feeTokenConfig) internal s_feeTokenConfig;
+ /// @dev The token transfer fee config that can be set by the owner or fee admin
+ mapping(address token => TokenTransferFeeConfig tranferFeeConfig) internal s_tokenTransferFeeConfig;
+
+ // STATE
+ /// @dev The current nonce per sender.
+ /// The offramp has a corresponding s_senderNonce mapping to ensure messages
+ /// are executed in the same order they are sent.
+ mapping(address sender => uint64 nonce) internal s_senderNonce;
+ /// @dev The amount of LINK available to pay NOPS
+ uint96 internal s_nopFeesJuels;
+ /// @dev The combined weight of all NOPs weights
+ uint32 internal s_nopWeightsTotal;
+ /// @dev The last used sequence number. This is zero in the case where no
+ /// messages has been sent yet. 0 is not a valid sequence number for any
+ /// real transaction.
+ uint64 internal s_sequenceNumber;
+
+ constructor(
+ StaticConfig memory staticConfig,
+ DynamicConfig memory dynamicConfig,
+ RateLimiter.Config memory rateLimiterConfig,
+ FeeTokenConfigArgs[] memory feeTokenConfigs,
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ NopAndWeight[] memory nopsAndWeights
+ ) AggregateRateLimiter(rateLimiterConfig) {
+ if (
+ staticConfig.linkToken == address(0) || staticConfig.chainSelector == 0 || staticConfig.destChainSelector == 0
+ || staticConfig.defaultTxGasLimit == 0 || staticConfig.rmnProxy == address(0)
+ || staticConfig.tokenAdminRegistry == address(0)
+ ) revert InvalidConfig();
+
+ i_metadataHash = keccak256(
+ abi.encode(
+ Internal.EVM_2_EVM_MESSAGE_HASH, staticConfig.chainSelector, staticConfig.destChainSelector, address(this)
+ )
+ );
+ i_linkToken = staticConfig.linkToken;
+ i_chainSelector = staticConfig.chainSelector;
+ i_destChainSelector = staticConfig.destChainSelector;
+ i_defaultTxGasLimit = staticConfig.defaultTxGasLimit;
+ i_maxNopFeesJuels = staticConfig.maxNopFeesJuels;
+ i_prevOnRamp = staticConfig.prevOnRamp;
+ i_rmnProxy = staticConfig.rmnProxy;
+ i_tokenAdminRegistry = staticConfig.tokenAdminRegistry;
+
+ _setDynamicConfig(dynamicConfig);
+ _setFeeTokenConfig(feeTokenConfigs);
+ _setTokenTransferFeeConfig(tokenTransferFeeConfigArgs, new address[](0));
+ _setNops(nopsAndWeights);
+ }
+
+ // ================================================================
+ // │ Messaging │
+ // ================================================================
+
+ /// @inheritdoc IEVM2AnyOnRamp
+ function getExpectedNextSequenceNumber() external view returns (uint64) {
+ return s_sequenceNumber + 1;
+ }
+
+ /// @inheritdoc IEVM2AnyOnRamp
+ function getSenderNonce(address sender) external view returns (uint64) {
+ uint256 senderNonce = s_senderNonce[sender];
+
+ if (i_prevOnRamp != address(0)) {
+ if (senderNonce == 0) {
+ // If OnRamp was upgraded, check if sender has a nonce from the previous OnRamp.
+ return IEVM2AnyOnRamp(i_prevOnRamp).getSenderNonce(sender);
+ }
+ }
+ return uint64(senderNonce);
+ }
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ function forwardFromRouter(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message,
+ uint256 feeTokenAmount,
+ address originalSender
+ ) external returns (bytes32) {
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(destChainSelector)))) revert CursedByRMN();
+ // Validate message sender is set and allowed. Not validated in `getFee` since it is not user-driven.
+ if (originalSender == address(0)) revert RouterMustSetOriginalSender();
+ // Router address may be zero intentionally to pause.
+ if (msg.sender != s_dynamicConfig.router) revert MustBeCalledByRouter();
+ if (destChainSelector != i_destChainSelector) revert InvalidChainSelector(destChainSelector);
+
+ Client.EVMExtraArgsV2 memory extraArgs = _fromBytes(message.extraArgs);
+ // Validate the message with various checks
+ uint256 numberOfTokens = message.tokenAmounts.length;
+ _validateMessage(message.data.length, extraArgs.gasLimit, numberOfTokens, extraArgs.allowOutOfOrderExecution);
+
+ // Only check token value if there are tokens
+ if (numberOfTokens > 0) {
+ uint256 value;
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ if (message.tokenAmounts[i].amount == 0) revert CannotSendZeroTokens();
+ if (s_tokenTransferFeeConfig[message.tokenAmounts[i].token].aggregateRateLimitEnabled) {
+ value += _getTokenValue(message.tokenAmounts[i], IPriceRegistry(s_dynamicConfig.priceRegistry));
+ }
+ }
+ // Rate limit on aggregated token value
+ if (value > 0) _rateLimitValue(value);
+ }
+
+ // Convert feeToken to link if not already in link
+ if (message.feeToken == i_linkToken) {
+ // Since there is only 1b link this is safe
+ s_nopFeesJuels += uint96(feeTokenAmount);
+ } else {
+ // the cast from uint256 to uint96 is considered safe, uint96 can store more than max supply of link token
+ s_nopFeesJuels += uint96(
+ IPriceRegistry(s_dynamicConfig.priceRegistry).convertTokenAmount(message.feeToken, feeTokenAmount, i_linkToken)
+ );
+ }
+ if (s_nopFeesJuels > i_maxNopFeesJuels) revert MaxFeeBalanceReached();
+
+ if (i_prevOnRamp != address(0)) {
+ if (s_senderNonce[originalSender] == 0) {
+ // If this is first time send for a sender in new OnRamp, check if they have a nonce
+ // from the previous OnRamp and start from there instead of zero.
+ s_senderNonce[originalSender] = IEVM2AnyOnRamp(i_prevOnRamp).getSenderNonce(originalSender);
+ }
+ }
+
+ // We need the next available sequence number so we increment before we use the value
+ Internal.EVM2EVMMessage memory newMessage = Internal.EVM2EVMMessage({
+ sourceChainSelector: i_chainSelector,
+ sender: originalSender,
+ // EVM destination addresses should be abi encoded and therefore always 32 bytes long
+ // Not duplicately validated in `getFee`. Invalid address is uncommon, gas cost outweighs UX gain.
+ receiver: Internal._validateEVMAddress(message.receiver),
+ sequenceNumber: ++s_sequenceNumber,
+ gasLimit: extraArgs.gasLimit,
+ strict: false,
+ // Only bump nonce for messages that specify allowOutOfOrderExecution == false. Otherwise, we
+ // may block ordered message nonces, which is not what we want.
+ nonce: extraArgs.allowOutOfOrderExecution ? 0 : ++s_senderNonce[originalSender],
+ feeToken: message.feeToken,
+ feeTokenAmount: feeTokenAmount,
+ data: message.data,
+ tokenAmounts: message.tokenAmounts,
+ sourceTokenData: new bytes[](numberOfTokens), // will be populated below
+ messageId: ""
+ });
+
+ // Lock the tokens as last step. TokenPools may not always be trusted.
+ // There should be no state changes after external call to TokenPools.
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ Client.EVMTokenAmount memory tokenAndAmount = message.tokenAmounts[i];
+ IPoolV1 sourcePool = getPoolBySourceToken(destChainSelector, IERC20(tokenAndAmount.token));
+ // We don't have to check if it supports the pool version in a non-reverting way here because
+ // if we revert here, there is no effect on CCIP. Therefore we directly call the supportsInterface
+ // function and not through the ERC165Checker.
+ if (address(sourcePool) == address(0) || !sourcePool.supportsInterface(Pool.CCIP_POOL_V1)) {
+ revert UnsupportedToken(tokenAndAmount.token);
+ }
+
+ Pool.LockOrBurnOutV1 memory poolReturnData = sourcePool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ receiver: message.receiver,
+ remoteChainSelector: i_destChainSelector,
+ originalSender: originalSender,
+ amount: tokenAndAmount.amount,
+ localToken: tokenAndAmount.token
+ })
+ );
+
+ // Since the DON has to pay for the extraData to be included on the destination chain, we cap the length of the
+ // extraData. This prevents gas bomb attacks on the NOPs. As destBytesOverhead accounts for both
+ // extraData and offchainData, this caps the worst case abuse to the number of bytes reserved for offchainData.
+ if (poolReturnData.destPoolData.length > Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) {
+ if (poolReturnData.destPoolData.length > s_tokenTransferFeeConfig[tokenAndAmount.token].destBytesOverhead) {
+ revert SourceTokenDataTooLarge(tokenAndAmount.token);
+ }
+ }
+ // We validate the token address to ensure it is a valid EVM address
+ Internal._validateEVMAddress(poolReturnData.destTokenAddress);
+
+ newMessage.sourceTokenData[i] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(sourcePool),
+ destTokenAddress: poolReturnData.destTokenAddress,
+ extraData: poolReturnData.destPoolData
+ })
+ );
+ }
+
+ // Hash only after the sourceTokenData has been set
+ newMessage.messageId = Internal._hash(newMessage, i_metadataHash);
+
+ // Emit message request
+ // This must happen after any pool events as some tokens (e.g. USDC) emit events that we expect to precede this
+ // event in the offchain code.
+ emit CCIPSendRequested(newMessage);
+ return newMessage.messageId;
+ }
+
+ /// @dev Convert the extra args bytes into a struct
+ /// @param extraArgs The extra args bytes
+ /// @return The extra args struct
+ function _fromBytes(bytes calldata extraArgs) internal view returns (Client.EVMExtraArgsV2 memory) {
+ if (extraArgs.length == 0) {
+ return Client.EVMExtraArgsV2({gasLimit: i_defaultTxGasLimit, allowOutOfOrderExecution: false});
+ }
+
+ bytes4 extraArgsTag = bytes4(extraArgs);
+ if (extraArgsTag == Client.EVM_EXTRA_ARGS_V2_TAG) {
+ return abi.decode(extraArgs[4:], (Client.EVMExtraArgsV2));
+ } else if (extraArgsTag == Client.EVM_EXTRA_ARGS_V1_TAG) {
+ // EVMExtraArgsV1 originally included a second boolean (strict) field which has been deprecated.
+ // Clients may still include it but it will be ignored.
+ return Client.EVMExtraArgsV2({gasLimit: abi.decode(extraArgs[4:], (uint256)), allowOutOfOrderExecution: false});
+ }
+
+ revert InvalidExtraArgsTag();
+ }
+
+ /// @notice Validate the forwarded message with various checks.
+ /// @dev This function can be called multiple times during a CCIPSend,
+ /// only common user-driven mistakes are validated here to minimize duplicate validation cost.
+ /// @param dataLength The length of the data field of the message.
+ /// @param gasLimit The gasLimit set in message for destination execution.
+ /// @param numberOfTokens The number of tokens to be sent.
+ function _validateMessage(
+ uint256 dataLength,
+ uint256 gasLimit,
+ uint256 numberOfTokens,
+ bool allowOutOfOrderExecution
+ ) internal view {
+ uint256 maxDataBytes = uint256(s_dynamicConfig.maxDataBytes);
+ if (dataLength > maxDataBytes) revert MessageTooLarge(maxDataBytes, dataLength);
+ if (gasLimit > uint256(s_dynamicConfig.maxPerMsgGasLimit)) revert MessageGasLimitTooHigh();
+ if (numberOfTokens > uint256(s_dynamicConfig.maxNumberOfTokensPerMsg)) revert UnsupportedNumberOfTokens();
+ if (!allowOutOfOrderExecution) {
+ if (s_dynamicConfig.enforceOutOfOrder) {
+ revert ExtraArgOutOfOrderExecutionMustBeTrue();
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Returns the static onRamp config.
+ /// @dev RMN depends on this function, if changing, please notify the RMN maintainers.
+ /// @return the configuration.
+ function getStaticConfig() external view returns (StaticConfig memory) {
+ return StaticConfig({
+ linkToken: i_linkToken,
+ chainSelector: i_chainSelector,
+ destChainSelector: i_destChainSelector,
+ defaultTxGasLimit: i_defaultTxGasLimit,
+ maxNopFeesJuels: i_maxNopFeesJuels,
+ prevOnRamp: i_prevOnRamp,
+ rmnProxy: i_rmnProxy,
+ tokenAdminRegistry: i_tokenAdminRegistry
+ });
+ }
+
+ /// @notice Returns the dynamic onRamp config.
+ /// @return dynamicConfig the configuration.
+ function getDynamicConfig() external view returns (DynamicConfig memory dynamicConfig) {
+ return s_dynamicConfig;
+ }
+
+ /// @notice Sets the dynamic configuration.
+ /// @param dynamicConfig The configuration.
+ function setDynamicConfig(DynamicConfig memory dynamicConfig) external onlyOwner {
+ _setDynamicConfig(dynamicConfig);
+ }
+
+ /// @notice Internal version of setDynamicConfig to allow for reuse in the constructor.
+ function _setDynamicConfig(DynamicConfig memory dynamicConfig) internal {
+ // We permit router to be set to zero as a way to pause the contract.
+ if (dynamicConfig.priceRegistry == address(0)) revert InvalidConfig();
+ if (dynamicConfig.defaultTokenDestBytesOverhead < Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) {
+ revert InvalidDestBytesOverhead(address(0), dynamicConfig.defaultTokenDestBytesOverhead);
+ }
+
+ s_dynamicConfig = dynamicConfig;
+
+ emit ConfigSet(
+ StaticConfig({
+ linkToken: i_linkToken,
+ chainSelector: i_chainSelector,
+ destChainSelector: i_destChainSelector,
+ defaultTxGasLimit: i_defaultTxGasLimit,
+ maxNopFeesJuels: i_maxNopFeesJuels,
+ prevOnRamp: i_prevOnRamp,
+ rmnProxy: i_rmnProxy,
+ tokenAdminRegistry: i_tokenAdminRegistry
+ }),
+ dynamicConfig
+ );
+ }
+
+ // ================================================================
+ // │ Tokens and pools │
+ // ================================================================
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ function getPoolBySourceToken(uint64, /*destChainSelector*/ IERC20 sourceToken) public view returns (IPoolV1) {
+ return IPoolV1(ITokenAdminRegistry(i_tokenAdminRegistry).getPool(address(sourceToken)));
+ }
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ function getSupportedTokens(uint64) external pure returns (address[] memory) {
+ revert GetSupportedTokensFunctionalityRemovedCheckAdminRegistry();
+ }
+
+ // ================================================================
+ // │ Fees │
+ // ================================================================
+
+ /// @inheritdoc IEVM2AnyOnRampClient
+ /// @dev getFee MUST revert if the feeToken is not listed in the fee token config, as the router assumes it does.
+ /// @param destChainSelector The destination chain selector.
+ /// @param message The message to get quote for.
+ /// @return feeTokenAmount The amount of fee token needed for the fee, in smallest denomination of the fee token.
+ function getFee(
+ uint64 destChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external view returns (uint256 feeTokenAmount) {
+ if (destChainSelector != i_destChainSelector) revert InvalidChainSelector(destChainSelector);
+
+ Client.EVMExtraArgsV2 memory extraArgs = _fromBytes(message.extraArgs);
+ // Validate the message with various checks
+ _validateMessage(
+ message.data.length, extraArgs.gasLimit, message.tokenAmounts.length, extraArgs.allowOutOfOrderExecution
+ );
+
+ FeeTokenConfig memory feeTokenConfig = s_feeTokenConfig[message.feeToken];
+ if (!feeTokenConfig.enabled) revert NotAFeeToken(message.feeToken);
+
+ (uint224 feeTokenPrice, uint224 packedGasPrice) =
+ IPriceRegistry(s_dynamicConfig.priceRegistry).getTokenAndGasPrices(message.feeToken, destChainSelector);
+
+ // Calculate premiumFee in USD with 18 decimals precision first.
+ // If message-only and no token transfers, a flat network fee is charged.
+ // If there are token transfers, premiumFee is calculated from token transfer fee.
+ // If there are both token transfers and message, premiumFee is only calculated from token transfer fee.
+ uint256 premiumFee = 0;
+ uint32 tokenTransferGas = 0;
+ uint32 tokenTransferBytesOverhead = 0;
+ if (message.tokenAmounts.length > 0) {
+ (premiumFee, tokenTransferGas, tokenTransferBytesOverhead) =
+ _getTokenTransferCost(message.feeToken, feeTokenPrice, message.tokenAmounts);
+ } else {
+ // Convert USD cents with 2 decimals to 18 decimals.
+ premiumFee = uint256(feeTokenConfig.networkFeeUSDCents) * 1e16;
+ }
+
+ // Calculate data availability cost in USD with 36 decimals. Data availability cost exists on rollups that need to post
+ // transaction calldata onto another storage layer, e.g. Eth mainnet, incurring additional storage gas costs.
+ uint256 dataAvailabilityCost = 0;
+ // Only calculate data availability cost if data availability multiplier is non-zero.
+ // The multiplier should be set to 0 if destination chain does not charge data availability cost.
+ if (s_dynamicConfig.destDataAvailabilityMultiplierBps > 0) {
+ dataAvailabilityCost = _getDataAvailabilityCost(
+ // Parse the data availability gas price stored in the higher-order 112 bits of the encoded gas price.
+ uint112(packedGasPrice >> Internal.GAS_PRICE_BITS),
+ message.data.length,
+ message.tokenAmounts.length,
+ tokenTransferBytesOverhead
+ );
+ }
+
+ // Calculate execution gas fee on destination chain in USD with 36 decimals.
+ // We add the message gas limit, the overhead gas, the gas of passing message data to receiver, and token transfer gas together.
+ // We then multiply this gas total with the gas multiplier and gas price, converting it into USD with 36 decimals.
+ // uint112(packedGasPrice) = executionGasPrice
+ uint256 executionCost = uint112(packedGasPrice)
+ * (
+ extraArgs.gasLimit + s_dynamicConfig.destGasOverhead
+ + (message.data.length * s_dynamicConfig.destGasPerPayloadByte) + tokenTransferGas
+ ) * feeTokenConfig.gasMultiplierWeiPerEth;
+
+ // Calculate number of fee tokens to charge.
+ // Total USD fee is in 36 decimals, feeTokenPrice is in 18 decimals USD for 1e18 smallest token denominations.
+ // Result of the division is the number of smallest token denominations.
+ return
+ ((premiumFee * feeTokenConfig.premiumMultiplierWeiPerEth) + executionCost + dataAvailabilityCost) / feeTokenPrice;
+ }
+
+ /// @notice Returns the estimated data availability cost of the message.
+ /// @dev To save on gas, we use a single destGasPerDataAvailabilityByte value for both zero and non-zero bytes.
+ /// @param dataAvailabilityGasPrice USD per data availability gas in 18 decimals.
+ /// @param messageDataLength length of the data field in the message.
+ /// @param numberOfTokens number of distinct token transfers in the message.
+ /// @param tokenTransferBytesOverhead additional token transfer data passed to destination, e.g. USDC attestation.
+ /// @return dataAvailabilityCostUSD36Decimal total data availability cost in USD with 36 decimals.
+ function _getDataAvailabilityCost(
+ uint112 dataAvailabilityGasPrice,
+ uint256 messageDataLength,
+ uint256 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) internal view returns (uint256 dataAvailabilityCostUSD36Decimal) {
+ // dataAvailabilityLengthBytes sums up byte lengths of fixed message fields and dynamic message fields.
+ // Fixed message fields do account for the offset and length slot of the dynamic fields.
+ uint256 dataAvailabilityLengthBytes = Internal.MESSAGE_FIXED_BYTES + messageDataLength
+ + (numberOfTokens * Internal.MESSAGE_FIXED_BYTES_PER_TOKEN) + tokenTransferBytesOverhead;
+
+ // destDataAvailabilityOverheadGas is a separate config value for flexibility to be updated independently of message cost.
+ // Its value is determined by CCIP lane implementation, e.g. the overhead data posted for OCR.
+ uint256 dataAvailabilityGas = (dataAvailabilityLengthBytes * s_dynamicConfig.destGasPerDataAvailabilityByte)
+ + s_dynamicConfig.destDataAvailabilityOverheadGas;
+
+ // dataAvailabilityGasPrice is in 18 decimals, destDataAvailabilityMultiplierBps is in 4 decimals
+ // We pad 14 decimals to bring the result to 36 decimals, in line with token bps and execution fee.
+ return ((dataAvailabilityGas * dataAvailabilityGasPrice) * s_dynamicConfig.destDataAvailabilityMultiplierBps) * 1e14;
+ }
+
+ /// @notice Returns the token transfer cost parameters.
+ /// A basis point fee is calculated from the USD value of each token transfer.
+ /// For each individual transfer, this fee is between [minFeeUSD, maxFeeUSD].
+ /// Total transfer fee is the sum of each individual token transfer fee.
+ /// @dev Assumes that tokenAmounts are validated to be listed tokens elsewhere.
+ /// @dev Splitting one token transfer into multiple transfers is discouraged,
+ /// as it will result in a transferFee equal or greater than the same amount aggregated/de-duped.
+ /// @param feeToken address of the feeToken.
+ /// @param feeTokenPrice price of feeToken in USD with 18 decimals.
+ /// @param tokenAmounts token transfers in the message.
+ /// @return tokenTransferFeeUSDWei total token transfer bps fee in USD with 18 decimals.
+ /// @return tokenTransferGas total execution gas of the token transfers.
+ /// @return tokenTransferBytesOverhead additional token transfer data passed to destination, e.g. USDC attestation.
+ function _getTokenTransferCost(
+ address feeToken,
+ uint224 feeTokenPrice,
+ Client.EVMTokenAmount[] calldata tokenAmounts
+ ) internal view returns (uint256 tokenTransferFeeUSDWei, uint32 tokenTransferGas, uint32 tokenTransferBytesOverhead) {
+ uint256 numberOfTokens = tokenAmounts.length;
+
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ Client.EVMTokenAmount memory tokenAmount = tokenAmounts[i];
+
+ // Validate if the token is supported, do not calculate fee for unsupported tokens.
+ if (address(getPoolBySourceToken(i_destChainSelector, IERC20(tokenAmount.token))) == address(0)) {
+ revert UnsupportedToken(tokenAmount.token);
+ }
+
+ TokenTransferFeeConfig memory transferFeeConfig = s_tokenTransferFeeConfig[tokenAmount.token];
+
+ // If the token has no specific overrides configured, we use the global defaults.
+ if (!transferFeeConfig.isEnabled) {
+ tokenTransferFeeUSDWei += uint256(s_dynamicConfig.defaultTokenFeeUSDCents) * 1e16;
+ tokenTransferGas += s_dynamicConfig.defaultTokenDestGasOverhead;
+ tokenTransferBytesOverhead += s_dynamicConfig.defaultTokenDestBytesOverhead;
+ continue;
+ }
+
+ uint256 bpsFeeUSDWei = 0;
+ // Only calculate bps fee if ratio is greater than 0. Ratio of 0 means no bps fee for a token.
+ // Useful for when the PriceRegistry cannot return a valid price for the token.
+ if (transferFeeConfig.deciBps > 0) {
+ uint224 tokenPrice = 0;
+ if (tokenAmount.token != feeToken) {
+ tokenPrice = IPriceRegistry(s_dynamicConfig.priceRegistry).getValidatedTokenPrice(tokenAmount.token);
+ } else {
+ tokenPrice = feeTokenPrice;
+ }
+
+ // Calculate token transfer value, then apply fee ratio
+ // ratio represents multiples of 0.1bps, or 1e-5
+ bpsFeeUSDWei = (tokenPrice._calcUSDValueFromTokenAmount(tokenAmount.amount) * transferFeeConfig.deciBps) / 1e5;
+ }
+
+ tokenTransferGas += transferFeeConfig.destGasOverhead;
+ tokenTransferBytesOverhead += transferFeeConfig.destBytesOverhead;
+
+ // Bps fees should be kept within range of [minFeeUSD, maxFeeUSD].
+ // Convert USD values with 2 decimals to 18 decimals.
+ uint256 minFeeUSDWei = uint256(transferFeeConfig.minFeeUSDCents) * 1e16;
+ if (bpsFeeUSDWei < minFeeUSDWei) {
+ tokenTransferFeeUSDWei += minFeeUSDWei;
+ continue;
+ }
+
+ uint256 maxFeeUSDWei = uint256(transferFeeConfig.maxFeeUSDCents) * 1e16;
+ if (bpsFeeUSDWei > maxFeeUSDWei) {
+ tokenTransferFeeUSDWei += maxFeeUSDWei;
+ continue;
+ }
+
+ tokenTransferFeeUSDWei += bpsFeeUSDWei;
+ }
+
+ return (tokenTransferFeeUSDWei, tokenTransferGas, tokenTransferBytesOverhead);
+ }
+
+ /// @notice Gets the fee configuration for a token
+ /// @param token The token to get the fee configuration for
+ /// @return feeTokenConfig FeeTokenConfig struct
+ function getFeeTokenConfig(address token) external view returns (FeeTokenConfig memory feeTokenConfig) {
+ return s_feeTokenConfig[token];
+ }
+
+ /// @notice Sets the fee configuration for a token
+ /// @param feeTokenConfigArgs Array of FeeTokenConfigArgs structs.
+ function setFeeTokenConfig(FeeTokenConfigArgs[] memory feeTokenConfigArgs) external {
+ _onlyOwnerOrAdmin();
+ _setFeeTokenConfig(feeTokenConfigArgs);
+ }
+
+ /// @dev Set the fee config
+ /// @param feeTokenConfigArgs The fee token configs.
+ function _setFeeTokenConfig(FeeTokenConfigArgs[] memory feeTokenConfigArgs) internal {
+ for (uint256 i = 0; i < feeTokenConfigArgs.length; ++i) {
+ FeeTokenConfigArgs memory configArg = feeTokenConfigArgs[i];
+
+ s_feeTokenConfig[configArg.token] = FeeTokenConfig({
+ networkFeeUSDCents: configArg.networkFeeUSDCents,
+ gasMultiplierWeiPerEth: configArg.gasMultiplierWeiPerEth,
+ premiumMultiplierWeiPerEth: configArg.premiumMultiplierWeiPerEth,
+ enabled: configArg.enabled
+ });
+ }
+ emit FeeConfigSet(feeTokenConfigArgs);
+ }
+
+ /// @notice Gets the transfer fee config for a given token.
+ function getTokenTransferFeeConfig(address token)
+ external
+ view
+ returns (TokenTransferFeeConfig memory tokenTransferFeeConfig)
+ {
+ return s_tokenTransferFeeConfig[token];
+ }
+
+ /// @notice Sets the transfer fee config.
+ /// @dev only callable by the owner or admin.
+ function setTokenTransferFeeConfig(
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ address[] memory tokensToUseDefaultFeeConfigs
+ ) external {
+ _onlyOwnerOrAdmin();
+ _setTokenTransferFeeConfig(tokenTransferFeeConfigArgs, tokensToUseDefaultFeeConfigs);
+ }
+
+ /// @notice internal helper to set the token transfer fee config.
+ function _setTokenTransferFeeConfig(
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ address[] memory tokensToUseDefaultFeeConfigs
+ ) internal {
+ for (uint256 i = 0; i < tokenTransferFeeConfigArgs.length; ++i) {
+ TokenTransferFeeConfigArgs memory configArg = tokenTransferFeeConfigArgs[i];
+
+ if (configArg.destBytesOverhead < Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) {
+ revert InvalidDestBytesOverhead(configArg.token, configArg.destBytesOverhead);
+ }
+
+ s_tokenTransferFeeConfig[configArg.token] = TokenTransferFeeConfig({
+ minFeeUSDCents: configArg.minFeeUSDCents,
+ maxFeeUSDCents: configArg.maxFeeUSDCents,
+ deciBps: configArg.deciBps,
+ destGasOverhead: configArg.destGasOverhead,
+ destBytesOverhead: configArg.destBytesOverhead,
+ aggregateRateLimitEnabled: configArg.aggregateRateLimitEnabled,
+ isEnabled: true
+ });
+ }
+ emit TokenTransferFeeConfigSet(tokenTransferFeeConfigArgs);
+
+ // Remove the custom fee configs for the tokens that are in the tokensToUseDefaultFeeConfigs array
+ for (uint256 i = 0; i < tokensToUseDefaultFeeConfigs.length; ++i) {
+ delete s_tokenTransferFeeConfig[tokensToUseDefaultFeeConfigs[i]];
+ }
+ if (tokensToUseDefaultFeeConfigs.length > 0) {
+ emit TokenTransferFeeConfigDeleted(tokensToUseDefaultFeeConfigs);
+ }
+ }
+
+ // ================================================================
+ // │ NOP payments │
+ // ================================================================
+
+ /// @notice Get the total amount of fees to be paid to the Nops (in LINK)
+ /// @return totalNopFees
+ function getNopFeesJuels() external view returns (uint96) {
+ return s_nopFeesJuels;
+ }
+
+ /// @notice Gets the Nops and their weights
+ /// @return nopsAndWeights Array of NopAndWeight structs
+ /// @return weightsTotal The sum weight of all Nops
+ function getNops() external view returns (NopAndWeight[] memory nopsAndWeights, uint256 weightsTotal) {
+ uint256 length = s_nops.length();
+ nopsAndWeights = new NopAndWeight[](length);
+ for (uint256 i = 0; i < length; ++i) {
+ (address nopAddress, uint256 nopWeight) = s_nops.at(i);
+ nopsAndWeights[i] = NopAndWeight({nop: nopAddress, weight: uint16(nopWeight)});
+ }
+ weightsTotal = s_nopWeightsTotal;
+ return (nopsAndWeights, weightsTotal);
+ }
+
+ /// @notice Sets the Nops and their weights
+ /// @param nopsAndWeights Array of NopAndWeight structs
+ function setNops(NopAndWeight[] calldata nopsAndWeights) external {
+ _onlyOwnerOrAdmin();
+ _setNops(nopsAndWeights);
+ }
+
+ /// @param nopsAndWeights New set of nops and weights
+ /// @dev Clears existing nops, sets new nops and weights
+ /// @dev We permit fees to accrue before nops are configured, in which case
+ /// they will go to the first set of configured nops.
+ function _setNops(NopAndWeight[] memory nopsAndWeights) internal {
+ uint256 numberOfNops = nopsAndWeights.length;
+ if (numberOfNops > MAX_NUMBER_OF_NOPS) revert TooManyNops();
+
+ // Make sure all nops have been paid before removing nops
+ // We only have to pay when there are nops and there is enough
+ // outstanding NOP balance to trigger a payment.
+ if (s_nopWeightsTotal > 0) {
+ if (s_nopFeesJuels >= s_nopWeightsTotal) {
+ payNops();
+ }
+ }
+
+ // Remove all previous nops, move from end to start to avoid shifting
+ for (uint256 i = s_nops.length(); i > 0; --i) {
+ (address nop,) = s_nops.at(i - 1);
+ s_nops.remove(nop);
+ }
+
+ // Add new
+ uint32 nopWeightsTotal = 0;
+ // nopWeightsTotal is bounded by the MAX_NUMBER_OF_NOPS and the weight of
+ // a single nop being of type uint16. This ensures nopWeightsTotal will
+ // always fit into the uint32 type.
+ for (uint256 i = 0; i < numberOfNops; ++i) {
+ // Make sure the LINK token is not a nop because the link token doesn't allow
+ // self transfers. If set as nop, payNops would always revert. Since setNops
+ // calls payNops, we can never remove the LINK token as a nop.
+ address nop = nopsAndWeights[i].nop;
+ uint16 weight = nopsAndWeights[i].weight;
+ if (nop == i_linkToken || nop == address(0)) revert InvalidNopAddress(nop);
+ s_nops.set(nop, weight);
+ nopWeightsTotal += weight;
+ }
+ s_nopWeightsTotal = nopWeightsTotal;
+ emit NopsSet(nopWeightsTotal, nopsAndWeights);
+ }
+
+ /// @notice Pays the Node Ops their outstanding balances.
+ /// @dev some balance can remain after payments are done. This is at most the sum
+ /// of the weight of all nops. Since nop weights are uint16s and we can have at
+ /// most MAX_NUMBER_OF_NOPS NOPs, the highest possible value is 2**22 or 0.04 gjuels.
+ function payNops() public {
+ if (msg.sender != owner()) {
+ if (msg.sender != s_admin) {
+ if (!s_nops.contains(msg.sender)) {
+ revert OnlyCallableByOwnerOrAdminOrNop();
+ }
+ }
+ }
+ uint256 weightsTotal = s_nopWeightsTotal;
+ if (weightsTotal == 0) revert NoNopsToPay();
+
+ uint96 totalFeesToPay = s_nopFeesJuels;
+ if (totalFeesToPay < weightsTotal) revert NoFeesToPay();
+ if (linkAvailableForPayment() < 0) revert InsufficientBalance();
+
+ uint96 fundsLeft = totalFeesToPay;
+ uint256 numberOfNops = s_nops.length();
+ for (uint256 i = 0; i < numberOfNops; ++i) {
+ (address nop, uint256 weight) = s_nops.at(i);
+ // amount can never be higher than totalFeesToPay so the cast to uint96 is safe
+ uint96 amount = uint96((totalFeesToPay * weight) / weightsTotal);
+ fundsLeft -= amount;
+ IERC20(i_linkToken).safeTransfer(nop, amount);
+ emit NopPaid(nop, amount);
+ }
+ // Some funds can remain, since this is an incredibly small
+ // amount we consider this OK.
+ s_nopFeesJuels = fundsLeft;
+ }
+
+ /// @notice Allows the owner to withdraw any ERC20 token from the contract.
+ /// The NOP link balance is not withdrawable.
+ /// @param feeToken The token to withdraw
+ /// @param to The address to send the tokens to
+ function withdrawNonLinkFees(address feeToken, address to) external {
+ _onlyOwnerOrAdmin();
+ if (to == address(0)) revert InvalidWithdrawParams();
+
+ // We require the link balance to be settled before allowing withdrawal of non-link fees.
+ int256 linkAfterNopFees = linkAvailableForPayment();
+ if (linkAfterNopFees < 0) revert LinkBalanceNotSettled();
+
+ if (feeToken == i_linkToken) {
+ // Withdraw only the left over link balance
+ IERC20(feeToken).safeTransfer(to, uint256(linkAfterNopFees));
+ } else {
+ // Withdrawal all non-link tokens in the contract
+ IERC20(feeToken).safeTransfer(to, IERC20(feeToken).balanceOf(address(this)));
+ }
+ }
+
+ // ================================================================
+ // │ Link monitoring │
+ // ================================================================
+
+ /// @notice Calculate remaining LINK balance after paying nops
+ /// @dev Allow keeper to monitor funds available for paying nops
+ /// @return balance if nops were to be paid
+ function linkAvailableForPayment() public view returns (int256) {
+ // Since LINK caps at uint96, casting to int256 is safe
+ return int256(IERC20(i_linkToken).balanceOf(address(this))) - int256(uint256(s_nopFeesJuels));
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @dev Require that the sender is the owner or the fee admin
+ /// Not a modifier to save on contract size
+ function _onlyOwnerOrAdmin() internal view {
+ if (msg.sender != owner()) {
+ if (msg.sender != s_admin) {
+ revert OnlyCallableByOwnerOrAdmin();
+ }
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/BurnFromMintTokenPool.sol b/contracts/src/v0.8/ccip/pools/BurnFromMintTokenPool.sol
new file mode 100644
index 00000000000..de68b18a302
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/BurnFromMintTokenPool.sol
@@ -0,0 +1,38 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IBurnMintERC20} from "../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {BurnMintTokenPoolAbstract} from "./BurnMintTokenPoolAbstract.sol";
+import {TokenPool} from "./TokenPool.sol";
+
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice This pool mints and burns a 3rd-party token.
+/// @dev Pool whitelisting mode is set in the constructor and cannot be modified later.
+/// It either accepts any address as originalSender, or only accepts whitelisted originalSender.
+/// The only way to change whitelisting mode is to deploy a new pool.
+/// If that is expected, please make sure the token's burner/minter roles are adjustable.
+/// @dev This contract is a variant of BurnMintTokenPool that uses `burnFrom(from, amount)`.
+contract BurnFromMintTokenPool is BurnMintTokenPoolAbstract, ITypeAndVersion {
+ using SafeERC20 for IBurnMintERC20;
+
+ string public constant override typeAndVersion = "BurnFromMintTokenPool 1.5.0-dev";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {
+ // Some tokens allow burning from the sender without approval, but not all do.
+ // To be safe, we approve the pool to burn from the pool.
+ token.safeIncreaseAllowance(address(this), type(uint256).max);
+ }
+
+ /// @inheritdoc BurnMintTokenPoolAbstract
+ function _burn(uint256 amount) internal virtual override {
+ IBurnMintERC20(address(i_token)).burnFrom(address(this), amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/BurnMintTokenPool.sol b/contracts/src/v0.8/ccip/pools/BurnMintTokenPool.sol
new file mode 100644
index 00000000000..a8562ae4d36
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/BurnMintTokenPool.sol
@@ -0,0 +1,30 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IBurnMintERC20} from "../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {BurnMintTokenPoolAbstract} from "./BurnMintTokenPoolAbstract.sol";
+import {TokenPool} from "./TokenPool.sol";
+
+/// @notice This pool mints and burns a 3rd-party token.
+/// @dev Pool whitelisting mode is set in the constructor and cannot be modified later.
+/// It either accepts any address as originalSender, or only accepts whitelisted originalSender.
+/// The only way to change whitelisting mode is to deploy a new pool.
+/// If that is expected, please make sure the token's burner/minter roles are adjustable.
+/// @dev This contract is a variant of BurnMintTokenPool that uses `burn(amount)`.
+contract BurnMintTokenPool is BurnMintTokenPoolAbstract, ITypeAndVersion {
+ string public constant override typeAndVersion = "BurnMintTokenPool 1.5.0-dev";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {}
+
+ /// @inheritdoc BurnMintTokenPoolAbstract
+ function _burn(uint256 amount) internal virtual override {
+ IBurnMintERC20(address(i_token)).burn(amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/BurnMintTokenPoolAbstract.sol b/contracts/src/v0.8/ccip/pools/BurnMintTokenPoolAbstract.sol
new file mode 100644
index 00000000000..2085c9427b0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/BurnMintTokenPoolAbstract.sol
@@ -0,0 +1,49 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBurnMintERC20} from "../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {Pool} from "../libraries/Pool.sol";
+import {TokenPool} from "./TokenPool.sol";
+
+abstract contract BurnMintTokenPoolAbstract is TokenPool {
+ /// @notice Contains the specific burn call for a pool.
+ /// @dev overriding this method allows us to create pools with different burn signatures
+ /// without duplicating the underlying logic.
+ function _burn(uint256 amount) internal virtual;
+
+ /// @notice Burn the token in the pool
+ /// @dev The _validateLockOrBurn check is an essential security check
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ _burn(lockOrBurnIn.amount);
+
+ emit Burned(msg.sender, lockOrBurnIn.amount);
+
+ return Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ /// @notice Mint tokens from the pool to the recipient
+ /// @dev The _validateReleaseOrMint check is an essential security check
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ virtual
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+
+ // Mint to the offRamp, which forwards it to the recipient
+ IBurnMintERC20(address(i_token)).mint(msg.sender, releaseOrMintIn.amount);
+
+ emit Minted(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/BurnMintTokenPoolAndProxy.sol b/contracts/src/v0.8/ccip/pools/BurnMintTokenPoolAndProxy.sol
new file mode 100644
index 00000000000..a3a7e082cc7
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/BurnMintTokenPoolAndProxy.sol
@@ -0,0 +1,62 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IBurnMintERC20} from "../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {Pool} from "../libraries/Pool.sol";
+import {LegacyPoolWrapper} from "./LegacyPoolWrapper.sol";
+
+contract BurnMintTokenPoolAndProxy is ITypeAndVersion, LegacyPoolWrapper {
+ string public constant override typeAndVersion = "BurnMintTokenPoolAndProxy 1.5.0-dev";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) LegacyPoolWrapper(token, allowlist, rmnProxy, router) {}
+
+ /// @notice Burn the token in the pool
+ /// @dev The _validateLockOrBurn check is an essential security check
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ if (!_hasLegacyPool()) {
+ IBurnMintERC20(address(i_token)).burn(lockOrBurnIn.amount);
+ } else {
+ _lockOrBurnLegacy(lockOrBurnIn);
+ }
+
+ emit Burned(msg.sender, lockOrBurnIn.amount);
+
+ return Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ /// @notice Mint tokens from the pool to the recipient
+ /// @dev The _validateReleaseOrMint check is an essential security check
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ virtual
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+
+ if (!_hasLegacyPool()) {
+ // Mint to the offRamp, which forwards it to the recipient
+ IBurnMintERC20(address(i_token)).mint(msg.sender, releaseOrMintIn.amount);
+ } else {
+ _releaseOrMintLegacy(releaseOrMintIn);
+ }
+
+ emit Minted(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/BurnWithFromMintTokenPool.sol b/contracts/src/v0.8/ccip/pools/BurnWithFromMintTokenPool.sol
new file mode 100644
index 00000000000..33f6c43c5b0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/BurnWithFromMintTokenPool.sol
@@ -0,0 +1,38 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IBurnMintERC20} from "../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {BurnMintTokenPoolAbstract} from "./BurnMintTokenPoolAbstract.sol";
+import {TokenPool} from "./TokenPool.sol";
+
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice This pool mints and burns a 3rd-party token.
+/// @dev Pool whitelisting mode is set in the constructor and cannot be modified later.
+/// It either accepts any address as originalSender, or only accepts whitelisted originalSender.
+/// The only way to change whitelisting mode is to deploy a new pool.
+/// If that is expected, please make sure the token's burner/minter roles are adjustable.
+/// @dev This contract is a variant of BurnMintTokenPool that uses `burn(from, amount)`.
+contract BurnWithFromMintTokenPool is BurnMintTokenPoolAbstract, ITypeAndVersion {
+ using SafeERC20 for IBurnMintERC20;
+
+ string public constant override typeAndVersion = "BurnWithFromMintTokenPool 1.5.0-dev";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {
+ // Some tokens allow burning from the sender without approval, but not all do.
+ // To be safe, we approve the pool to burn from the pool.
+ token.safeIncreaseAllowance(address(this), type(uint256).max);
+ }
+
+ /// @inheritdoc BurnMintTokenPoolAbstract
+ function _burn(uint256 amount) internal virtual override {
+ IBurnMintERC20(address(i_token)).burn(address(this), amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/LegacyPoolWrapper.sol b/contracts/src/v0.8/ccip/pools/LegacyPoolWrapper.sol
new file mode 100644
index 00000000000..125a3a28ee4
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/LegacyPoolWrapper.sol
@@ -0,0 +1,81 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IPoolPriorTo1_5} from "../interfaces/IPoolPriorTo1_5.sol";
+
+import {Pool} from "../libraries/Pool.sol";
+import {TokenPool} from "./TokenPool.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+abstract contract LegacyPoolWrapper is TokenPool {
+ using SafeERC20 for IERC20;
+
+ event LegacyPoolChanged(IPoolPriorTo1_5 oldPool, IPoolPriorTo1_5 newPool);
+
+ /// @dev The previous pool, if there is any. This is a property to make the older 1.0-1.4 pools
+ /// compatible with the current 1.5 pool. To achieve this, we set the previous pool address to the
+ /// currently deployed legacy pool. Then we configure this new pool as onRamp and offRamp on the legacy pools.
+ /// In the case of a 1.4 pool, this new pool contract has to be set to the Router as well, as it validates
+ /// who can call it through the router calls. This contract will always return itself as the only allowed ramp.
+ /// @dev Can be address(0), this would indicate that this pool is operating as a normal pool as opposed to
+ /// a proxy pool.
+ IPoolPriorTo1_5 internal s_previousPool;
+
+ constructor(
+ IERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {}
+
+ // ================================================================
+ // │ Legacy Fallbacks │
+ // ================================================================
+ // Legacy fallbacks for older token pools that do not implement the new interface.
+
+ /// @notice Legacy fallback for the 1.4 token pools.
+ function getOnRamp(uint64) external view returns (address onRampAddress) {
+ return address(this);
+ }
+
+ /// @notice Return true if the given offRamp is a configured offRamp for the given source chain.
+ function isOffRamp(uint64 sourceChainSelector, address offRamp) external view returns (bool) {
+ return offRamp == address(this) || s_router.isOffRamp(sourceChainSelector, offRamp);
+ }
+
+ /// @notice Configures the legacy fallback option. If the previous pool is set, this pool will act as a proxy for
+ /// the legacy pool.
+ /// @param prevPool The address of the previous pool.
+ function setPreviousPool(IPoolPriorTo1_5 prevPool) external onlyOwner {
+ IPoolPriorTo1_5 oldPrevPool = s_previousPool;
+ s_previousPool = prevPool;
+
+ emit LegacyPoolChanged(oldPrevPool, prevPool);
+ }
+
+ function _hasLegacyPool() internal view returns (bool) {
+ return address(s_previousPool) != address(0);
+ }
+
+ function _lockOrBurnLegacy(Pool.LockOrBurnInV1 memory lockOrBurnIn) internal {
+ i_token.safeTransfer(address(s_previousPool), lockOrBurnIn.amount);
+ s_previousPool.lockOrBurn(
+ lockOrBurnIn.originalSender, lockOrBurnIn.receiver, lockOrBurnIn.amount, lockOrBurnIn.remoteChainSelector, ""
+ );
+ }
+
+ /// @notice This call converts the arguments from a >=1.5 pool call to those of a <1.5 pool call, and uses these
+ /// to call the previous pool.
+ /// @param releaseOrMintIn The 1.5 style release or mint arguments.
+ /// @dev Overwrites the receiver so the previous pool sends the tokens to the sender of this call, which is the
+ /// offRamp. This is due to the older pools sending funds directly to the receiver, while the new pools do a hop
+ /// through the offRamp to ensure the correct tokens are sent.
+ /// @dev Since extraData has never been used in LockRelease or MintBurn token pools, we can safely ignore it.
+ function _releaseOrMintLegacy(Pool.ReleaseOrMintInV1 memory releaseOrMintIn) internal {
+ s_previousPool.releaseOrMint(
+ releaseOrMintIn.originalSender, msg.sender, releaseOrMintIn.amount, releaseOrMintIn.remoteChainSelector, ""
+ );
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/LockReleaseTokenPool.sol b/contracts/src/v0.8/ccip/pools/LockReleaseTokenPool.sol
new file mode 100644
index 00000000000..5716777fb5e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/LockReleaseTokenPool.sol
@@ -0,0 +1,151 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ILiquidityContainer} from "../../liquiditymanager/interfaces/ILiquidityContainer.sol";
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+
+import {Pool} from "../libraries/Pool.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+import {TokenPool} from "./TokenPool.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice Token pool used for tokens on their native chain. This uses a lock and release mechanism.
+/// Because of lock/unlock requiring liquidity, this pool contract also has function to add and remove
+/// liquidity. This allows for proper bookkeeping for both user and liquidity provider balances.
+/// @dev One token per LockReleaseTokenPool.
+contract LockReleaseTokenPool is TokenPool, ILiquidityContainer, ITypeAndVersion {
+ using SafeERC20 for IERC20;
+
+ error InsufficientLiquidity();
+ error LiquidityNotAccepted();
+ error Unauthorized(address caller);
+
+ string public constant override typeAndVersion = "LockReleaseTokenPool 1.5.0-dev";
+
+ /// @dev Whether or not the pool accepts liquidity.
+ /// External liquidity is not required when there is one canonical token deployed to a chain,
+ /// and CCIP is facilitating mint/burn on all the other chains, in which case the invariant
+ /// balanceOf(pool) on home chain == sum(totalSupply(mint/burn "wrapped" token) on all remote chains) should always hold
+ bool internal immutable i_acceptLiquidity;
+ /// @notice The address of the rebalancer.
+ address internal s_rebalancer;
+ /// @notice The address of the rate limiter admin.
+ /// @dev Can be address(0) if none is configured.
+ address internal s_rateLimitAdmin;
+
+ constructor(
+ IERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ bool acceptLiquidity,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {
+ i_acceptLiquidity = acceptLiquidity;
+ }
+
+ /// @notice Locks the token in the pool
+ /// @dev The _validateLockOrBurn check is an essential security check
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ emit Locked(msg.sender, lockOrBurnIn.amount);
+
+ return Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ /// @notice Release tokens from the pool to the recipient
+ /// @dev The _validateReleaseOrMint check is an essential security check
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ virtual
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+
+ // Release to the offRamp, which forwards it to the recipient
+ getToken().safeTransfer(msg.sender, releaseOrMintIn.amount);
+
+ emit Released(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+
+ // @inheritdoc IERC165
+ function supportsInterface(bytes4 interfaceId) public pure virtual override returns (bool) {
+ return interfaceId == type(ILiquidityContainer).interfaceId || super.supportsInterface(interfaceId);
+ }
+
+ /// @notice Gets LiquidityManager, can be address(0) if none is configured.
+ /// @return The current liquidity manager.
+ function getRebalancer() external view returns (address) {
+ return s_rebalancer;
+ }
+
+ /// @notice Sets the LiquidityManager address.
+ /// @dev Only callable by the owner.
+ function setRebalancer(address rebalancer) external onlyOwner {
+ s_rebalancer = rebalancer;
+ }
+
+ /// @notice Sets the rate limiter admin address.
+ /// @dev Only callable by the owner.
+ /// @param rateLimitAdmin The new rate limiter admin address.
+ function setRateLimitAdmin(address rateLimitAdmin) external onlyOwner {
+ s_rateLimitAdmin = rateLimitAdmin;
+ }
+
+ /// @notice Gets the rate limiter admin address.
+ function getRateLimitAdmin() external view returns (address) {
+ return s_rateLimitAdmin;
+ }
+
+ /// @notice Checks if the pool can accept liquidity.
+ /// @return true if the pool can accept liquidity, false otherwise.
+ function canAcceptLiquidity() external view returns (bool) {
+ return i_acceptLiquidity;
+ }
+
+ /// @notice Adds liquidity to the pool. The tokens should be approved first.
+ /// @param amount The amount of liquidity to provide.
+ function provideLiquidity(uint256 amount) external {
+ if (!i_acceptLiquidity) revert LiquidityNotAccepted();
+ if (s_rebalancer != msg.sender) revert Unauthorized(msg.sender);
+
+ i_token.safeTransferFrom(msg.sender, address(this), amount);
+ emit LiquidityAdded(msg.sender, amount);
+ }
+
+ /// @notice Removed liquidity to the pool. The tokens will be sent to msg.sender.
+ /// @param amount The amount of liquidity to remove.
+ function withdrawLiquidity(uint256 amount) external {
+ if (s_rebalancer != msg.sender) revert Unauthorized(msg.sender);
+
+ if (i_token.balanceOf(address(this)) < amount) revert InsufficientLiquidity();
+ i_token.safeTransfer(msg.sender, amount);
+ emit LiquidityRemoved(msg.sender, amount);
+ }
+
+ /// @notice Sets the rate limiter admin address.
+ /// @dev Only callable by the owner or the rate limiter admin. NOTE: overwrites the normal
+ /// onlyAdmin check in the base implementation to also allow the rate limiter admin.
+ /// @param remoteChainSelector The remote chain selector for which the rate limits apply.
+ /// @param outboundConfig The new outbound rate limiter config.
+ /// @param inboundConfig The new inbound rate limiter config.
+ function setChainRateLimiterConfig(
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) external override {
+ if (msg.sender != s_rateLimitAdmin && msg.sender != owner()) revert Unauthorized(msg.sender);
+
+ _setRateLimitConfig(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/LockReleaseTokenPoolAndProxy.sol b/contracts/src/v0.8/ccip/pools/LockReleaseTokenPoolAndProxy.sol
new file mode 100644
index 00000000000..91766d5f26a
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/LockReleaseTokenPoolAndProxy.sol
@@ -0,0 +1,159 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ILiquidityContainer} from "../../liquiditymanager/interfaces/ILiquidityContainer.sol";
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+
+import {Pool} from "../libraries/Pool.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+import {LegacyPoolWrapper} from "./LegacyPoolWrapper.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice Token pool used for tokens on their native chain. This uses a lock and release mechanism.
+/// Because of lock/unlock requiring liquidity, this pool contract also has function to add and remove
+/// liquidity. This allows for proper bookkeeping for both user and liquidity provider balances.
+/// @dev One token per LockReleaseTokenPool.
+contract LockReleaseTokenPoolAndProxy is LegacyPoolWrapper, ILiquidityContainer, ITypeAndVersion {
+ using SafeERC20 for IERC20;
+
+ error InsufficientLiquidity();
+ error LiquidityNotAccepted();
+ error Unauthorized(address caller);
+
+ string public constant override typeAndVersion = "LockReleaseTokenPoolAndProxy 1.5.0-dev";
+
+ /// @dev Whether or not the pool accepts liquidity.
+ /// External liquidity is not required when there is one canonical token deployed to a chain,
+ /// and CCIP is facilitating mint/burn on all the other chains, in which case the invariant
+ /// balanceOf(pool) on home chain == sum(totalSupply(mint/burn "wrapped" token) on all remote chains) should always hold
+ bool internal immutable i_acceptLiquidity;
+ /// @notice The address of the rebalancer.
+ address internal s_rebalancer;
+ /// @notice The address of the rate limiter admin.
+ /// @dev Can be address(0) if none is configured.
+ address internal s_rateLimitAdmin;
+
+ constructor(
+ IERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ bool acceptLiquidity,
+ address router
+ ) LegacyPoolWrapper(token, allowlist, rmnProxy, router) {
+ i_acceptLiquidity = acceptLiquidity;
+ }
+
+ /// @notice Locks the token in the pool
+ /// @dev The _validateLockOrBurn check is an essential security check
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ if (_hasLegacyPool()) {
+ _lockOrBurnLegacy(lockOrBurnIn);
+ }
+
+ emit Locked(msg.sender, lockOrBurnIn.amount);
+
+ return Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ /// @notice Release tokens from the pool to the recipient
+ /// @dev The _validateReleaseOrMint check is an essential security check
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ virtual
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+
+ if (!_hasLegacyPool()) {
+ // Release to the offRamp, which forwards it to the recipient
+ getToken().safeTransfer(msg.sender, releaseOrMintIn.amount);
+ } else {
+ _releaseOrMintLegacy(releaseOrMintIn);
+ }
+
+ emit Released(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+
+ // @inheritdoc IERC165
+ function supportsInterface(bytes4 interfaceId) public pure virtual override returns (bool) {
+ return interfaceId == type(ILiquidityContainer).interfaceId || super.supportsInterface(interfaceId);
+ }
+
+ /// @notice Gets LiquidityManager, can be address(0) if none is configured.
+ /// @return The current liquidity manager.
+ function getRebalancer() external view returns (address) {
+ return s_rebalancer;
+ }
+
+ /// @notice Sets the LiquidityManager address.
+ /// @dev Only callable by the owner.
+ function setRebalancer(address rebalancer) external onlyOwner {
+ s_rebalancer = rebalancer;
+ }
+
+ /// @notice Sets the rate limiter admin address.
+ /// @dev Only callable by the owner.
+ /// @param rateLimitAdmin The new rate limiter admin address.
+ function setRateLimitAdmin(address rateLimitAdmin) external onlyOwner {
+ s_rateLimitAdmin = rateLimitAdmin;
+ }
+
+ /// @notice Gets the rate limiter admin address.
+ function getRateLimitAdmin() external view returns (address) {
+ return s_rateLimitAdmin;
+ }
+
+ /// @notice Checks if the pool can accept liquidity.
+ /// @return true if the pool can accept liquidity, false otherwise.
+ function canAcceptLiquidity() external view returns (bool) {
+ return i_acceptLiquidity;
+ }
+
+ /// @notice Adds liquidity to the pool. The tokens should be approved first.
+ /// @param amount The amount of liquidity to provide.
+ function provideLiquidity(uint256 amount) external {
+ if (!i_acceptLiquidity) revert LiquidityNotAccepted();
+ if (s_rebalancer != msg.sender) revert Unauthorized(msg.sender);
+
+ i_token.safeTransferFrom(msg.sender, address(this), amount);
+ emit LiquidityAdded(msg.sender, amount);
+ }
+
+ /// @notice Removed liquidity to the pool. The tokens will be sent to msg.sender.
+ /// @param amount The amount of liquidity to remove.
+ function withdrawLiquidity(uint256 amount) external {
+ if (s_rebalancer != msg.sender) revert Unauthorized(msg.sender);
+
+ if (i_token.balanceOf(address(this)) < amount) revert InsufficientLiquidity();
+ i_token.safeTransfer(msg.sender, amount);
+ emit LiquidityRemoved(msg.sender, amount);
+ }
+
+ /// @notice Sets the rate limiter admin address.
+ /// @dev Only callable by the owner or the rate limiter admin. NOTE: overwrites the normal
+ /// onlyAdmin check in the base implementation to also allow the rate limiter admin.
+ /// @param remoteChainSelector The remote chain selector for which the rate limits apply.
+ /// @param outboundConfig The new outbound rate limiter config.
+ /// @param inboundConfig The new inbound rate limiter config.
+ function setChainRateLimiterConfig(
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) external override {
+ if (msg.sender != s_rateLimitAdmin && msg.sender != owner()) revert Unauthorized(msg.sender);
+
+ _setRateLimitConfig(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/TokenPool.sol b/contracts/src/v0.8/ccip/pools/TokenPool.sol
new file mode 100644
index 00000000000..fb1f8c49e6f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/TokenPool.sol
@@ -0,0 +1,424 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../interfaces/IPool.sol";
+import {IRMN} from "../interfaces/IRMN.sol";
+import {IRouter} from "../interfaces/IRouter.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {Pool} from "../libraries/Pool.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {IERC165} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+import {EnumerableSet} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice Base abstract class with common functions for all token pools.
+/// A token pool serves as isolated place for holding tokens and token specific logic
+/// that may execute as tokens move across the bridge.
+abstract contract TokenPool is IPoolV1, OwnerIsCreator {
+ using EnumerableSet for EnumerableSet.AddressSet;
+ using EnumerableSet for EnumerableSet.UintSet;
+ using RateLimiter for RateLimiter.TokenBucket;
+
+ error CallerIsNotARampOnRouter(address caller);
+ error ZeroAddressNotAllowed();
+ error SenderNotAllowed(address sender);
+ error AllowListNotEnabled();
+ error NonExistentChain(uint64 remoteChainSelector);
+ error ChainNotAllowed(uint64 remoteChainSelector);
+ error CursedByRMN();
+ error ChainAlreadyExists(uint64 chainSelector);
+ error InvalidSourcePoolAddress(bytes sourcePoolAddress);
+ error InvalidToken(address token);
+
+ event Locked(address indexed sender, uint256 amount);
+ event Burned(address indexed sender, uint256 amount);
+ event Released(address indexed sender, address indexed recipient, uint256 amount);
+ event Minted(address indexed sender, address indexed recipient, uint256 amount);
+ event ChainAdded(
+ uint64 remoteChainSelector,
+ bytes remoteToken,
+ RateLimiter.Config outboundRateLimiterConfig,
+ RateLimiter.Config inboundRateLimiterConfig
+ );
+ event ChainConfigured(
+ uint64 remoteChainSelector,
+ RateLimiter.Config outboundRateLimiterConfig,
+ RateLimiter.Config inboundRateLimiterConfig
+ );
+ event ChainRemoved(uint64 remoteChainSelector);
+ event RemotePoolSet(uint64 indexed remoteChainSelector, bytes previousPoolAddress, bytes remotePoolAddress);
+ event AllowListAdd(address sender);
+ event AllowListRemove(address sender);
+ event RouterUpdated(address oldRouter, address newRouter);
+
+ struct ChainUpdate {
+ uint64 remoteChainSelector; // ──╮ Remote chain selector
+ bool allowed; // ────────────────╯ Whether the chain should be enabled
+ bytes remotePoolAddress; // Address of the remote pool, ABI encoded in the case of a remove EVM chain.
+ bytes remoteTokenAddress; // Address of the remote token, ABI encoded in the case of a remote EVM chain.
+ RateLimiter.Config outboundRateLimiterConfig; // Outbound rate limited config, meaning the rate limits for all of the onRamps for the given chain
+ RateLimiter.Config inboundRateLimiterConfig; // Inbound rate limited config, meaning the rate limits for all of the offRamps for the given chain
+ }
+
+ struct RemoteChainConfig {
+ RateLimiter.TokenBucket outboundRateLimiterConfig; // Outbound rate limited config, meaning the rate limits for all of the onRamps for the given chain
+ RateLimiter.TokenBucket inboundRateLimiterConfig; // Inbound rate limited config, meaning the rate limits for all of the offRamps for the given chain
+ bytes remotePoolAddress; // Address of the remote pool, ABI encoded in the case of a remote EVM chain.
+ bytes remoteTokenAddress; // Address of the remote token, ABI encoded in the case of a remote EVM chain.
+ }
+
+ /// @dev The bridgeable token that is managed by this pool.
+ IERC20 internal immutable i_token;
+ /// @dev The address of the RMN proxy
+ address internal immutable i_rmnProxy;
+ /// @dev The immutable flag that indicates if the pool is access-controlled.
+ bool internal immutable i_allowlistEnabled;
+ /// @dev A set of addresses allowed to trigger lockOrBurn as original senders.
+ /// Only takes effect if i_allowlistEnabled is true.
+ /// This can be used to ensure only token-issuer specified addresses can
+ /// move tokens.
+ EnumerableSet.AddressSet internal s_allowList;
+ /// @dev The address of the router
+ IRouter internal s_router;
+ /// @dev A set of allowed chain selectors. We want the allowlist to be enumerable to
+ /// be able to quickly determine (without parsing logs) who can access the pool.
+ /// @dev The chain selectors are in uint256 format because of the EnumerableSet implementation.
+ EnumerableSet.UintSet internal s_remoteChainSelectors;
+ mapping(uint64 remoteChainSelector => RemoteChainConfig) internal s_remoteChainConfigs;
+
+ constructor(IERC20 token, address[] memory allowlist, address rmnProxy, address router) {
+ if (address(token) == address(0) || router == address(0) || rmnProxy == address(0)) revert ZeroAddressNotAllowed();
+ i_token = token;
+ i_rmnProxy = rmnProxy;
+ s_router = IRouter(router);
+
+ // Pool can be set as permissioned or permissionless at deployment time only to save hot-path gas.
+ i_allowlistEnabled = allowlist.length > 0;
+ if (i_allowlistEnabled) {
+ _applyAllowListUpdates(new address[](0), allowlist);
+ }
+ }
+
+ /// @notice Get RMN proxy address
+ /// @return rmnProxy Address of RMN proxy
+ function getRmnProxy() public view returns (address rmnProxy) {
+ return i_rmnProxy;
+ }
+
+ /// @inheritdoc IPoolV1
+ function isSupportedToken(address token) public view virtual returns (bool) {
+ return token == address(i_token);
+ }
+
+ /// @notice Gets the IERC20 token that this pool can lock or burn.
+ /// @return token The IERC20 token representation.
+ function getToken() public view returns (IERC20 token) {
+ return i_token;
+ }
+
+ /// @notice Gets the pool's Router
+ /// @return router The pool's Router
+ function getRouter() public view returns (address router) {
+ return address(s_router);
+ }
+
+ /// @notice Sets the pool's Router
+ /// @param newRouter The new Router
+ function setRouter(address newRouter) public onlyOwner {
+ if (newRouter == address(0)) revert ZeroAddressNotAllowed();
+ address oldRouter = address(s_router);
+ s_router = IRouter(newRouter);
+
+ emit RouterUpdated(oldRouter, newRouter);
+ }
+
+ /// @notice Signals which version of the pool interface is supported
+ function supportsInterface(bytes4 interfaceId) public pure virtual override returns (bool) {
+ return interfaceId == Pool.CCIP_POOL_V1 || interfaceId == type(IPoolV1).interfaceId
+ || interfaceId == type(IERC165).interfaceId;
+ }
+
+ // ================================================================
+ // │ Validation │
+ // ================================================================
+
+ /// @notice Validates the lock or burn input for correctness on
+ /// - token to be locked or burned
+ /// - RMN curse status
+ /// - allowlist status
+ /// - if the sender is a valid onRamp
+ /// - rate limit status
+ /// @param lockOrBurnIn The input to validate.
+ /// @dev This function should always be called before executing a lock or burn. Not doing so would allow
+ /// for various exploits.
+ function _validateLockOrBurn(Pool.LockOrBurnInV1 memory lockOrBurnIn) internal {
+ if (!isSupportedToken(lockOrBurnIn.localToken)) revert InvalidToken(lockOrBurnIn.localToken);
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(lockOrBurnIn.remoteChainSelector)))) revert CursedByRMN();
+ _checkAllowList(lockOrBurnIn.originalSender);
+
+ _onlyOnRamp(lockOrBurnIn.remoteChainSelector);
+ _consumeOutboundRateLimit(lockOrBurnIn.remoteChainSelector, lockOrBurnIn.amount);
+ }
+
+ /// @notice Validates the release or mint input for correctness on
+ /// - token to be released or minted
+ /// - RMN curse status
+ /// - if the sender is a valid offRamp
+ /// - if the source pool is valid
+ /// - rate limit status
+ /// @param releaseOrMintIn The input to validate.
+ /// @dev This function should always be called before executing a lock or burn. Not doing so would allow
+ /// for various exploits.
+ function _validateReleaseOrMint(Pool.ReleaseOrMintInV1 memory releaseOrMintIn) internal {
+ if (!isSupportedToken(releaseOrMintIn.localToken)) revert InvalidToken(releaseOrMintIn.localToken);
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(releaseOrMintIn.remoteChainSelector)))) revert CursedByRMN();
+ _onlyOffRamp(releaseOrMintIn.remoteChainSelector);
+
+ // Validates that the source pool address is configured on this pool.
+ bytes memory configuredRemotePool = getRemotePool(releaseOrMintIn.remoteChainSelector);
+ if (
+ configuredRemotePool.length == 0
+ || keccak256(releaseOrMintIn.sourcePoolAddress) != keccak256(configuredRemotePool)
+ ) {
+ revert InvalidSourcePoolAddress(releaseOrMintIn.sourcePoolAddress);
+ }
+ _consumeInboundRateLimit(releaseOrMintIn.remoteChainSelector, releaseOrMintIn.amount);
+ }
+
+ // ================================================================
+ // │ Chain permissions │
+ // ================================================================
+
+ /// @notice Gets the pool address on the remote chain.
+ /// @param remoteChainSelector Remote chain selector.
+ /// @dev To support non-evm chains, this value is encoded into bytes
+ function getRemotePool(uint64 remoteChainSelector) public view returns (bytes memory) {
+ return s_remoteChainConfigs[remoteChainSelector].remotePoolAddress;
+ }
+
+ /// @notice Gets the token address on the remote chain.
+ /// @param remoteChainSelector Remote chain selector.
+ /// @dev To support non-evm chains, this value is encoded into bytes
+ function getRemoteToken(uint64 remoteChainSelector) public view returns (bytes memory) {
+ return s_remoteChainConfigs[remoteChainSelector].remoteTokenAddress;
+ }
+
+ /// @notice Sets the remote pool address for a given chain selector.
+ /// @param remoteChainSelector The remote chain selector for which the remote pool address is being set.
+ /// @param remotePoolAddress The address of the remote pool.
+ function setRemotePool(uint64 remoteChainSelector, bytes calldata remotePoolAddress) external onlyOwner {
+ if (!isSupportedChain(remoteChainSelector)) revert NonExistentChain(remoteChainSelector);
+
+ bytes memory prevAddress = s_remoteChainConfigs[remoteChainSelector].remotePoolAddress;
+ s_remoteChainConfigs[remoteChainSelector].remotePoolAddress = remotePoolAddress;
+
+ emit RemotePoolSet(remoteChainSelector, prevAddress, remotePoolAddress);
+ }
+
+ /// @inheritdoc IPoolV1
+ function isSupportedChain(uint64 remoteChainSelector) public view returns (bool) {
+ return s_remoteChainSelectors.contains(remoteChainSelector);
+ }
+
+ /// @notice Get list of allowed chains
+ /// @return list of chains.
+ function getSupportedChains() public view returns (uint64[] memory) {
+ uint256[] memory uint256ChainSelectors = s_remoteChainSelectors.values();
+ uint64[] memory chainSelectors = new uint64[](uint256ChainSelectors.length);
+ for (uint256 i = 0; i < uint256ChainSelectors.length; ++i) {
+ chainSelectors[i] = uint64(uint256ChainSelectors[i]);
+ }
+
+ return chainSelectors;
+ }
+
+ /// @notice Sets the permissions for a list of chains selectors. Actual senders for these chains
+ /// need to be allowed on the Router to interact with this pool.
+ /// @dev Only callable by the owner
+ /// @param chains A list of chains and their new permission status & rate limits. Rate limits
+ /// are only used when the chain is being added through `allowed` being true.
+ function applyChainUpdates(ChainUpdate[] calldata chains) external virtual onlyOwner {
+ for (uint256 i = 0; i < chains.length; ++i) {
+ ChainUpdate memory update = chains[i];
+ RateLimiter._validateTokenBucketConfig(update.outboundRateLimiterConfig, !update.allowed);
+ RateLimiter._validateTokenBucketConfig(update.inboundRateLimiterConfig, !update.allowed);
+
+ if (update.allowed) {
+ // If the chain already exists, revert
+ if (!s_remoteChainSelectors.add(update.remoteChainSelector)) {
+ revert ChainAlreadyExists(update.remoteChainSelector);
+ }
+
+ if (update.remotePoolAddress.length == 0 || update.remoteTokenAddress.length == 0) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ s_remoteChainConfigs[update.remoteChainSelector] = RemoteChainConfig({
+ outboundRateLimiterConfig: RateLimiter.TokenBucket({
+ rate: update.outboundRateLimiterConfig.rate,
+ capacity: update.outboundRateLimiterConfig.capacity,
+ tokens: update.outboundRateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.outboundRateLimiterConfig.isEnabled
+ }),
+ inboundRateLimiterConfig: RateLimiter.TokenBucket({
+ rate: update.inboundRateLimiterConfig.rate,
+ capacity: update.inboundRateLimiterConfig.capacity,
+ tokens: update.inboundRateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.inboundRateLimiterConfig.isEnabled
+ }),
+ remotePoolAddress: update.remotePoolAddress,
+ remoteTokenAddress: update.remoteTokenAddress
+ });
+
+ emit ChainAdded(
+ update.remoteChainSelector,
+ update.remoteTokenAddress,
+ update.outboundRateLimiterConfig,
+ update.inboundRateLimiterConfig
+ );
+ } else {
+ // If the chain doesn't exist, revert
+ if (!s_remoteChainSelectors.remove(update.remoteChainSelector)) {
+ revert NonExistentChain(update.remoteChainSelector);
+ }
+
+ delete s_remoteChainConfigs[update.remoteChainSelector];
+
+ emit ChainRemoved(update.remoteChainSelector);
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Rate limiting │
+ // ================================================================
+
+ /// @notice Consumes outbound rate limiting capacity in this pool
+ function _consumeOutboundRateLimit(uint64 remoteChainSelector, uint256 amount) internal {
+ s_remoteChainConfigs[remoteChainSelector].outboundRateLimiterConfig._consume(amount, address(i_token));
+ }
+
+ /// @notice Consumes inbound rate limiting capacity in this pool
+ function _consumeInboundRateLimit(uint64 remoteChainSelector, uint256 amount) internal {
+ s_remoteChainConfigs[remoteChainSelector].inboundRateLimiterConfig._consume(amount, address(i_token));
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function getCurrentOutboundRateLimiterState(uint64 remoteChainSelector)
+ external
+ view
+ returns (RateLimiter.TokenBucket memory)
+ {
+ return s_remoteChainConfigs[remoteChainSelector].outboundRateLimiterConfig._currentTokenBucketState();
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function getCurrentInboundRateLimiterState(uint64 remoteChainSelector)
+ external
+ view
+ returns (RateLimiter.TokenBucket memory)
+ {
+ return s_remoteChainConfigs[remoteChainSelector].inboundRateLimiterConfig._currentTokenBucketState();
+ }
+
+ /// @notice Sets the chain rate limiter config.
+ /// @param remoteChainSelector The remote chain selector for which the rate limits apply.
+ /// @param outboundConfig The new outbound rate limiter config, meaning the onRamp rate limits for the given chain.
+ /// @param inboundConfig The new inbound rate limiter config, meaning the offRamp rate limits for the given chain.
+ function setChainRateLimiterConfig(
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) external virtual onlyOwner {
+ _setRateLimitConfig(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+
+ function _setRateLimitConfig(
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) internal {
+ if (!isSupportedChain(remoteChainSelector)) revert NonExistentChain(remoteChainSelector);
+ RateLimiter._validateTokenBucketConfig(outboundConfig, false);
+ s_remoteChainConfigs[remoteChainSelector].outboundRateLimiterConfig._setTokenBucketConfig(outboundConfig);
+ RateLimiter._validateTokenBucketConfig(inboundConfig, false);
+ s_remoteChainConfigs[remoteChainSelector].inboundRateLimiterConfig._setTokenBucketConfig(inboundConfig);
+ emit ChainConfigured(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Checks whether remote chain selector is configured on this contract, and if the msg.sender
+ /// is a permissioned onRamp for the given chain on the Router.
+ function _onlyOnRamp(uint64 remoteChainSelector) internal view {
+ if (!isSupportedChain(remoteChainSelector)) revert ChainNotAllowed(remoteChainSelector);
+ if (!(msg.sender == s_router.getOnRamp(remoteChainSelector))) revert CallerIsNotARampOnRouter(msg.sender);
+ }
+
+ /// @notice Checks whether remote chain selector is configured on this contract, and if the msg.sender
+ /// is a permissioned offRamp for the given chain on the Router.
+ function _onlyOffRamp(uint64 remoteChainSelector) internal view {
+ if (!isSupportedChain(remoteChainSelector)) revert ChainNotAllowed(remoteChainSelector);
+ if (!s_router.isOffRamp(remoteChainSelector, msg.sender)) revert CallerIsNotARampOnRouter(msg.sender);
+ }
+
+ // ================================================================
+ // │ Allowlist │
+ // ================================================================
+
+ function _checkAllowList(address sender) internal view {
+ if (i_allowlistEnabled) {
+ if (!s_allowList.contains(sender)) {
+ revert SenderNotAllowed(sender);
+ }
+ }
+ }
+
+ /// @notice Gets whether the allowList functionality is enabled.
+ /// @return true is enabled, false if not.
+ function getAllowListEnabled() external view returns (bool) {
+ return i_allowlistEnabled;
+ }
+
+ /// @notice Gets the allowed addresses.
+ /// @return The allowed addresses.
+ function getAllowList() external view returns (address[] memory) {
+ return s_allowList.values();
+ }
+
+ /// @notice Apply updates to the allow list.
+ /// @param removes The addresses to be removed.
+ /// @param adds The addresses to be added.
+ function applyAllowListUpdates(address[] calldata removes, address[] calldata adds) external onlyOwner {
+ _applyAllowListUpdates(removes, adds);
+ }
+
+ /// @notice Internal version of applyAllowListUpdates to allow for reuse in the constructor.
+ function _applyAllowListUpdates(address[] memory removes, address[] memory adds) internal {
+ if (!i_allowlistEnabled) revert AllowListNotEnabled();
+
+ for (uint256 i = 0; i < removes.length; ++i) {
+ address toRemove = removes[i];
+ if (s_allowList.remove(toRemove)) {
+ emit AllowListRemove(toRemove);
+ }
+ }
+ for (uint256 i = 0; i < adds.length; ++i) {
+ address toAdd = adds[i];
+ if (toAdd == address(0)) {
+ continue;
+ }
+ if (s_allowList.add(toAdd)) {
+ emit AllowListAdd(toAdd);
+ }
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/pools/USDC/IMessageTransmitter.sol b/contracts/src/v0.8/ccip/pools/USDC/IMessageTransmitter.sol
new file mode 100644
index 00000000000..1b2a0f90210
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/USDC/IMessageTransmitter.sol
@@ -0,0 +1,46 @@
+/*
+ * Copyright (c) 2022, Circle Internet Financial Limited.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+pragma solidity ^0.8.0;
+
+interface IMessageTransmitter {
+ /// @notice Unlocks USDC tokens on the destination chain
+ /// @param message The original message on the source chain
+ /// * Message format:
+ /// * Field Bytes Type Index
+ /// * version 4 uint32 0
+ /// * sourceDomain 4 uint32 4
+ /// * destinationDomain 4 uint32 8
+ /// * nonce 8 uint64 12
+ /// * sender 32 bytes32 20
+ /// * recipient 32 bytes32 52
+ /// * destinationCaller 32 bytes32 84
+ /// * messageBody dynamic bytes 116
+ /// param attestation A valid attestation is the concatenated 65-byte signature(s) of
+ /// exactly `thresholdSignature` signatures, in increasing order of attester address.
+ /// ***If the attester addresses recovered from signatures are not in increasing order,
+ /// signature verification will fail.***
+ /// If incorrect number of signatures or duplicate signatures are supplied,
+ /// signature verification will fail.
+ function receiveMessage(bytes calldata message, bytes calldata attestation) external returns (bool success);
+
+ /// Returns domain of chain on which the contract is deployed.
+ /// @dev immutable
+ function localDomain() external view returns (uint32);
+
+ /// Returns message format version.
+ /// @dev immutable
+ function version() external view returns (uint32);
+}
diff --git a/contracts/src/v0.8/ccip/pools/USDC/ITokenMessenger.sol b/contracts/src/v0.8/ccip/pools/USDC/ITokenMessenger.sol
new file mode 100644
index 00000000000..ce5923cfdcd
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/USDC/ITokenMessenger.sol
@@ -0,0 +1,65 @@
+/*
+ * Copyright (c) 2022, Circle Internet Financial Limited.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+pragma solidity ^0.8.0;
+
+interface ITokenMessenger {
+ /// @notice Emitted when a DepositForBurn message is sent
+ /// @param nonce Unique nonce reserved by message
+ /// @param burnToken Address of token burnt on source domain
+ /// @param amount Deposit amount
+ /// @param depositor Address where deposit is transferred from
+ /// @param mintRecipient Address receiving minted tokens on destination domain as bytes32
+ /// @param destinationDomain Destination domain
+ /// @param destinationTokenMessenger Address of TokenMessenger on destination domain as bytes32
+ /// @param destinationCaller Authorized caller as bytes32 of receiveMessage() on destination domain,
+ /// if not equal to bytes32(0). If equal to bytes32(0), any address can call receiveMessage().
+ event DepositForBurn(
+ uint64 indexed nonce,
+ address indexed burnToken,
+ uint256 amount,
+ address indexed depositor,
+ bytes32 mintRecipient,
+ uint32 destinationDomain,
+ bytes32 destinationTokenMessenger,
+ bytes32 destinationCaller
+ );
+
+ /// @notice Burns the tokens on the source side to produce a nonce through
+ /// Circles Cross Chain Transfer Protocol.
+ /// @param amount Amount of tokens to deposit and burn.
+ /// @param destinationDomain Destination domain identifier.
+ /// @param mintRecipient Address of mint recipient on destination domain.
+ /// @param burnToken Address of contract to burn deposited tokens, on local domain.
+ /// @param destinationCaller Caller on the destination domain, as bytes32.
+ /// @return nonce The unique nonce used in unlocking the funds on the destination chain.
+ /// @dev emits DepositForBurn
+ function depositForBurnWithCaller(
+ uint256 amount,
+ uint32 destinationDomain,
+ bytes32 mintRecipient,
+ address burnToken,
+ bytes32 destinationCaller
+ ) external returns (uint64 nonce);
+
+ /// Returns the version of the message body format.
+ /// @dev immutable
+ function messageBodyVersion() external view returns (uint32);
+
+ /// Returns local Message Transmitter responsible for sending and receiving messages
+ /// to/from remote domainsmessage transmitter for this token messenger.
+ /// @dev immutable
+ function localMessageTransmitter() external view returns (address);
+}
diff --git a/contracts/src/v0.8/ccip/pools/USDC/USDCTokenPool.sol b/contracts/src/v0.8/ccip/pools/USDC/USDCTokenPool.sol
new file mode 100644
index 00000000000..339ed09992f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/pools/USDC/USDCTokenPool.sol
@@ -0,0 +1,241 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../../shared/interfaces/ITypeAndVersion.sol";
+import {IMessageTransmitter} from "./IMessageTransmitter.sol";
+import {ITokenMessenger} from "./ITokenMessenger.sol";
+
+import {Pool} from "../../libraries/Pool.sol";
+import {TokenPool} from "../TokenPool.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice This pool mints and burns USDC tokens through the Cross Chain Transfer
+/// Protocol (CCTP).
+contract USDCTokenPool is TokenPool, ITypeAndVersion {
+ using SafeERC20 for IERC20;
+
+ event DomainsSet(DomainUpdate[]);
+ event ConfigSet(address tokenMessenger);
+
+ error UnknownDomain(uint64 domain);
+ error UnlockingUSDCFailed();
+ error InvalidConfig();
+ error InvalidDomain(DomainUpdate domain);
+ error InvalidMessageVersion(uint32 version);
+ error InvalidTokenMessengerVersion(uint32 version);
+ error InvalidNonce(uint64 expected, uint64 got);
+ error InvalidSourceDomain(uint32 expected, uint32 got);
+ error InvalidDestinationDomain(uint32 expected, uint32 got);
+ error InvalidReceiver(bytes receiver);
+
+ // This data is supplied from offchain and contains everything needed
+ // to receive the USDC tokens.
+ struct MessageAndAttestation {
+ bytes message;
+ bytes attestation;
+ }
+
+ // A domain is a USDC representation of a chain.
+ struct DomainUpdate {
+ bytes32 allowedCaller; // Address allowed to mint on the domain
+ uint32 domainIdentifier; // ──╮ Unique domain ID
+ uint64 destChainSelector; // │ The destination chain for this domain
+ bool enabled; // ─────────────╯ Whether the domain is enabled
+ }
+
+ struct SourceTokenDataPayload {
+ uint64 nonce;
+ uint32 sourceDomain;
+ }
+
+ string public constant override typeAndVersion = "USDCTokenPool 1.4.0";
+
+ // We restrict to the first version. New pool may be required for subsequent versions.
+ uint32 public constant SUPPORTED_USDC_VERSION = 0;
+
+ // The local USDC config
+ ITokenMessenger public immutable i_tokenMessenger;
+ IMessageTransmitter public immutable i_messageTransmitter;
+ uint32 public immutable i_localDomainIdentifier;
+
+ /// A domain is a USDC representation of a destination chain.
+ /// @dev Zero is a valid domain identifier.
+ /// @dev The address to mint on the destination chain is the corresponding USDC pool.
+ struct Domain {
+ bytes32 allowedCaller; // Address allowed to mint on the domain
+ uint32 domainIdentifier; // ─╮ Unique domain ID
+ bool enabled; // ────────────╯ Whether the domain is enabled
+ }
+
+ // A mapping of CCIP chain identifiers to destination domains
+ mapping(uint64 chainSelector => Domain CCTPDomain) private s_chainToDomain;
+
+ constructor(
+ ITokenMessenger tokenMessenger,
+ IERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {
+ if (address(tokenMessenger) == address(0)) revert InvalidConfig();
+ IMessageTransmitter transmitter = IMessageTransmitter(tokenMessenger.localMessageTransmitter());
+ uint32 transmitterVersion = transmitter.version();
+ if (transmitterVersion != SUPPORTED_USDC_VERSION) revert InvalidMessageVersion(transmitterVersion);
+ uint32 tokenMessengerVersion = tokenMessenger.messageBodyVersion();
+ if (tokenMessengerVersion != SUPPORTED_USDC_VERSION) revert InvalidTokenMessengerVersion(tokenMessengerVersion);
+
+ i_tokenMessenger = tokenMessenger;
+ i_messageTransmitter = transmitter;
+ i_localDomainIdentifier = transmitter.localDomain();
+ i_token.safeIncreaseAllowance(address(i_tokenMessenger), type(uint256).max);
+ emit ConfigSet(address(tokenMessenger));
+ }
+
+ /// @notice Burn the token in the pool
+ /// @dev Burn is not rate limited at per-pool level. Burn does not contribute to honey pot risk.
+ /// Benefits of rate limiting here does not justify the extra gas cost.
+ /// @dev emits ITokenMessenger.DepositForBurn
+ /// @dev Assumes caller has validated destinationReceiver
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ Domain memory domain = s_chainToDomain[lockOrBurnIn.remoteChainSelector];
+ if (!domain.enabled) revert UnknownDomain(lockOrBurnIn.remoteChainSelector);
+ if (lockOrBurnIn.receiver.length != 32) {
+ revert InvalidReceiver(lockOrBurnIn.receiver);
+ }
+
+ // Since this pool is the msg sender of the CCTP transaction, only this contract
+ // is able to call replaceDepositForBurn. Since this contract does not implement
+ // replaceDepositForBurn, the tokens cannot be maliciously re-routed to another address.
+ uint64 nonce = i_tokenMessenger.depositForBurnWithCaller(
+ // We set the domain.allowedCaller as the receiver of the funds, as this is the token pool. Since 1.5 the
+ // token pools receiver the funds to hop them through the offRamps.
+ lockOrBurnIn.amount,
+ domain.domainIdentifier,
+ domain.allowedCaller,
+ address(i_token),
+ domain.allowedCaller
+ );
+
+ emit Burned(msg.sender, lockOrBurnIn.amount);
+
+ return Pool.LockOrBurnOutV1({
+ destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector),
+ destPoolData: abi.encode(SourceTokenDataPayload({nonce: nonce, sourceDomain: i_localDomainIdentifier}))
+ });
+ }
+
+ /// @notice Mint tokens from the pool to the recipient
+ /// * sourceTokenData is part of the verified message and passed directly from
+ /// the offramp so it is guaranteed to be what the lockOrBurn pool released on the
+ /// source chain. It contains (nonce, sourceDomain) which is guaranteed by CCTP
+ /// to be unique.
+ /// * offchainTokenData is untrusted (can be supplied by manual execution), but we assert
+ /// that (nonce, sourceDomain) is equal to the message's (nonce, sourceDomain) and
+ /// receiveMessage will assert that Attestation contains a valid attestation signature
+ /// for that message, including its (nonce, sourceDomain). This way, the only
+ /// non-reverting offchainTokenData that can be supplied is a valid attestation for the
+ /// specific message that was sent on source.
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+ SourceTokenDataPayload memory sourceTokenDataPayload =
+ abi.decode(releaseOrMintIn.sourcePoolData, (SourceTokenDataPayload));
+ MessageAndAttestation memory msgAndAttestation =
+ abi.decode(releaseOrMintIn.offchainTokenData, (MessageAndAttestation));
+
+ _validateMessage(msgAndAttestation.message, sourceTokenDataPayload);
+
+ if (!i_messageTransmitter.receiveMessage(msgAndAttestation.message, msgAndAttestation.attestation)) {
+ revert UnlockingUSDCFailed();
+ }
+ // Since the tokens are minted to the pool, the pool has to send it to the offRamp
+ getToken().safeTransfer(msg.sender, releaseOrMintIn.amount);
+
+ emit Minted(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+
+ /// @notice Validates the USDC encoded message against the given parameters.
+ /// @param usdcMessage The USDC encoded message
+ /// @param sourceTokenData The expected source chain token data to check against
+ /// @dev Only supports version SUPPORTED_USDC_VERSION of the CCTP message format
+ /// @dev Message format for USDC:
+ /// * Field Bytes Type Index
+ /// * version 4 uint32 0
+ /// * sourceDomain 4 uint32 4
+ /// * destinationDomain 4 uint32 8
+ /// * nonce 8 uint64 12
+ /// * sender 32 bytes32 20
+ /// * recipient 32 bytes32 52
+ /// * destinationCaller 32 bytes32 84
+ /// * messageBody dynamic bytes 116
+ function _validateMessage(bytes memory usdcMessage, SourceTokenDataPayload memory sourceTokenData) internal view {
+ uint32 version;
+ // solhint-disable-next-line no-inline-assembly
+ assembly {
+ // We truncate using the datatype of the version variable, meaning
+ // we will only be left with the first 4 bytes of the message.
+ version := mload(add(usdcMessage, 4)) // 0 + 4 = 4
+ }
+ // This token pool only supports version 0 of the CCTP message format
+ // We check the version prior to loading the rest of the message
+ // to avoid unexpected reverts due to out-of-bounds reads.
+ if (version != SUPPORTED_USDC_VERSION) revert InvalidMessageVersion(version);
+
+ uint32 sourceDomain;
+ uint32 destinationDomain;
+ uint64 nonce;
+
+ // solhint-disable-next-line no-inline-assembly
+ assembly {
+ sourceDomain := mload(add(usdcMessage, 8)) // 4 + 4 = 8
+ destinationDomain := mload(add(usdcMessage, 12)) // 8 + 4 = 12
+ nonce := mload(add(usdcMessage, 20)) // 12 + 8 = 20
+ }
+
+ if (sourceDomain != sourceTokenData.sourceDomain) {
+ revert InvalidSourceDomain(sourceTokenData.sourceDomain, sourceDomain);
+ }
+ if (destinationDomain != i_localDomainIdentifier) {
+ revert InvalidDestinationDomain(i_localDomainIdentifier, destinationDomain);
+ }
+ if (nonce != sourceTokenData.nonce) revert InvalidNonce(sourceTokenData.nonce, nonce);
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ /// @notice Gets the CCTP domain for a given CCIP chain selector.
+ function getDomain(uint64 chainSelector) external view returns (Domain memory) {
+ return s_chainToDomain[chainSelector];
+ }
+
+ /// @notice Sets the CCTP domain for a CCIP chain selector.
+ /// @dev Must verify mapping of selectors -> (domain, caller) offchain.
+ function setDomains(DomainUpdate[] calldata domains) external onlyOwner {
+ for (uint256 i = 0; i < domains.length; ++i) {
+ DomainUpdate memory domain = domains[i];
+ if (domain.allowedCaller == bytes32(0) || domain.destChainSelector == 0) revert InvalidDomain(domain);
+
+ s_chainToDomain[domain.destChainSelector] = Domain({
+ domainIdentifier: domain.domainIdentifier,
+ allowedCaller: domain.allowedCaller,
+ enabled: domain.enabled
+ });
+ }
+ emit DomainsSet(domains);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/BaseTest.t.sol b/contracts/src/v0.8/ccip/test/BaseTest.t.sol
new file mode 100644
index 00000000000..ee3f3e6fd4c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/BaseTest.t.sol
@@ -0,0 +1,125 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+// Imports to any non-library are not allowed due to the significant cascading
+// compile time increase they cause when imported into this base test.
+import {Internal} from "../libraries/Internal.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+import {MockRMN} from "./mocks/MockRMN.sol";
+import {Test} from "forge-std/Test.sol";
+
+contract BaseTest is Test {
+ // Addresses
+ address internal constant OWNER = 0x00007e64E1fB0C487F25dd6D3601ff6aF8d32e4e;
+ address internal constant STRANGER = address(999999);
+ address internal constant DUMMY_CONTRACT_ADDRESS = 0x1111111111111111111111111111111111111112;
+ address internal constant ON_RAMP_ADDRESS = 0x11118e64e1FB0c487f25dD6D3601FF6aF8d32E4e;
+ address internal constant ZERO_ADDRESS = address(0);
+ address internal constant FEE_AGGREGATOR = 0xa33CDB32eAEce34F6affEfF4899cef45744EDea3;
+
+ address internal constant USER_1 = address(1);
+ address internal constant USER_2 = address(2);
+ address internal constant USER_3 = address(3);
+ address internal constant USER_4 = address(4);
+
+ // Message info
+ uint64 internal constant SOURCE_CHAIN_SELECTOR = 1;
+ uint64 internal constant DEST_CHAIN_SELECTOR = 2;
+ uint32 internal constant GAS_LIMIT = 200_000;
+
+ // Timing
+ uint256 internal constant BLOCK_TIME = 1234567890;
+ uint32 internal constant TWELVE_HOURS = 60 * 60 * 12;
+
+ // Onramp
+ uint96 internal constant MAX_NOP_FEES_JUELS = 1e27;
+ uint96 internal constant MAX_MSG_FEES_JUELS = 1e18;
+ uint32 internal constant DEST_GAS_OVERHEAD = 350_000;
+ uint16 internal constant DEST_GAS_PER_PAYLOAD_BYTE = 16;
+
+ uint16 internal constant DEFAULT_TOKEN_FEE_USD_CENTS = 50;
+ uint32 internal constant DEFAULT_TOKEN_DEST_GAS_OVERHEAD = 34_000;
+ uint32 internal constant DEFAULT_TOKEN_BYTES_OVERHEAD = 50;
+
+ bool private s_baseTestInitialized;
+
+ // Use 16 gas per data availability byte in our tests.
+ // This is an overestimation in OP stack, it ignores 4 gas per 0 byte rule.
+ // Arbitrum on the other hand, does always use 16 gas per data availability byte.
+ // This value may be substantially decreased after EIP 4844.
+ uint16 internal constant DEST_GAS_PER_DATA_AVAILABILITY_BYTE = 16;
+
+ // Total L1 data availability overhead estimate is 33_596 gas.
+ // This value includes complete CommitStore and OffRamp call data.
+ uint32 internal constant DEST_DATA_AVAILABILITY_OVERHEAD_GAS = 188 // Fixed data availability overhead in OP stack.
+ + (32 * 31 + 4) * DEST_GAS_PER_DATA_AVAILABILITY_BYTE // CommitStore single-root transmission takes up about 31 slots, plus selector.
+ + (32 * 34 + 4) * DEST_GAS_PER_DATA_AVAILABILITY_BYTE; // OffRamp transmission excluding EVM2EVMMessage takes up about 34 slots, plus selector.
+
+ // Multiples of bps, or 0.0001, use 6840 to be same as OP mainnet compression factor of 0.684.
+ uint16 internal constant DEST_GAS_DATA_AVAILABILITY_MULTIPLIER_BPS = 6840;
+
+ // OffRamp
+ uint32 internal constant MAX_DATA_SIZE = 30_000;
+ uint16 internal constant MAX_TOKENS_LENGTH = 5;
+ uint32 internal constant MAX_TOKEN_POOL_RELEASE_OR_MINT_GAS = 200_000;
+ uint32 internal constant MAX_TOKEN_POOL_TRANSFER_GAS = 50_000;
+ uint16 internal constant GAS_FOR_CALL_EXACT_CHECK = 5000;
+ uint32 internal constant PERMISSION_LESS_EXECUTION_THRESHOLD_SECONDS = 500;
+ uint32 internal constant MAX_GAS_LIMIT = 4_000_000;
+
+ // Rate limiter
+ address internal constant ADMIN = 0x11118e64e1FB0c487f25dD6D3601FF6aF8d32E4e;
+
+ MockRMN internal s_mockRMN;
+
+ function setUp() public virtual {
+ // BaseTest.setUp is often called multiple times from tests' setUp due to inheritance.
+ if (s_baseTestInitialized) return;
+ s_baseTestInitialized = true;
+
+ // Set the sender to OWNER permanently
+ vm.startPrank(OWNER);
+ deal(OWNER, 1e20);
+ vm.label(OWNER, "Owner");
+ vm.label(STRANGER, "Stranger");
+
+ // Set the block time to a constant known value
+ vm.warp(BLOCK_TIME);
+
+ s_mockRMN = new MockRMN();
+ }
+
+ function getOutboundRateLimiterConfig() internal pure returns (RateLimiter.Config memory) {
+ return RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e15});
+ }
+
+ function getInboundRateLimiterConfig() internal pure returns (RateLimiter.Config memory) {
+ return RateLimiter.Config({isEnabled: true, capacity: 222e30, rate: 1e18});
+ }
+
+ function getSingleTokenPriceUpdateStruct(
+ address token,
+ uint224 price
+ ) internal pure returns (Internal.PriceUpdates memory) {
+ Internal.TokenPriceUpdate[] memory tokenPriceUpdates = new Internal.TokenPriceUpdate[](1);
+ tokenPriceUpdates[0] = Internal.TokenPriceUpdate({sourceToken: token, usdPerToken: price});
+
+ Internal.PriceUpdates memory priceUpdates =
+ Internal.PriceUpdates({tokenPriceUpdates: tokenPriceUpdates, gasPriceUpdates: new Internal.GasPriceUpdate[](0)});
+
+ return priceUpdates;
+ }
+
+ function getSingleGasPriceUpdateStruct(
+ uint64 chainSelector,
+ uint224 usdPerUnitGas
+ ) internal pure returns (Internal.PriceUpdates memory) {
+ Internal.GasPriceUpdate[] memory gasPriceUpdates = new Internal.GasPriceUpdate[](1);
+ gasPriceUpdates[0] = Internal.GasPriceUpdate({destChainSelector: chainSelector, usdPerUnitGas: usdPerUnitGas});
+
+ Internal.PriceUpdates memory priceUpdates =
+ Internal.PriceUpdates({tokenPriceUpdates: new Internal.TokenPriceUpdate[](0), gasPriceUpdates: gasPriceUpdates});
+
+ return priceUpdates;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/NonceManager.t.sol b/contracts/src/v0.8/ccip/test/NonceManager.t.sol
new file mode 100644
index 00000000000..75de4db8c5c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/NonceManager.t.sol
@@ -0,0 +1,649 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {NonceManager} from "../NonceManager.sol";
+import {ICommitStore} from "../interfaces/ICommitStore.sol";
+import {Client} from "../libraries/Client.sol";
+import {Internal} from "../libraries/Internal.sol";
+import {Pool} from "../libraries/Pool.sol";
+import {RateLimiter} from "../libraries/RateLimiter.sol";
+import {EVM2EVMMultiOffRamp} from "../offRamp/EVM2EVMMultiOffRamp.sol";
+import {EVM2EVMMultiOnRamp} from "../onRamp/EVM2EVMMultiOnRamp.sol";
+import {EVM2EVMOnRamp} from "../onRamp/EVM2EVMOnRamp.sol";
+
+import {BaseTest} from "./BaseTest.t.sol";
+import {EVM2EVMMultiOnRampHelper} from "./helpers/EVM2EVMMultiOnRampHelper.sol";
+import {EVM2EVMOffRampHelper} from "./helpers/EVM2EVMOffRampHelper.sol";
+import {EVM2EVMOnRampHelper} from "./helpers/EVM2EVMOnRampHelper.sol";
+import {MockCommitStore} from "./mocks/MockCommitStore.sol";
+import {EVM2EVMMultiOffRampSetup} from "./offRamp/EVM2EVMMultiOffRampSetup.t.sol";
+import {EVM2EVMMultiOnRampSetup} from "./onRamp/EVM2EVMMultiOnRampSetup.t.sol";
+
+contract NonceManager_NonceIncrementation is BaseTest {
+ NonceManager private s_nonceManager;
+
+ function setUp() public override {
+ address[] memory authorizedCallers = new address[](1);
+ authorizedCallers[0] = address(this);
+ s_nonceManager = new NonceManager(authorizedCallers);
+ }
+
+ function test_getIncrementedOutboundNonce_Success() public {
+ address sender = address(this);
+
+ assertEq(s_nonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, sender), 0);
+
+ uint64 outboundNonce = s_nonceManager.getIncrementedOutboundNonce(DEST_CHAIN_SELECTOR, sender);
+ assertEq(outboundNonce, 1);
+ }
+
+ function test_incrementInboundNonce_Success() public {
+ address sender = address(this);
+
+ s_nonceManager.incrementInboundNonce(SOURCE_CHAIN_SELECTOR, 1, abi.encode(sender));
+
+ assertEq(s_nonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR, abi.encode(sender)), 1);
+ }
+
+ function test_incrementInboundNonce_Skip() public {
+ address sender = address(this);
+ uint64 expectedNonce = 2;
+
+ vm.expectEmit();
+ emit NonceManager.SkippedIncorrectNonce(SOURCE_CHAIN_SELECTOR, expectedNonce, abi.encode(sender));
+
+ s_nonceManager.incrementInboundNonce(SOURCE_CHAIN_SELECTOR, expectedNonce, abi.encode(sender));
+
+ assertEq(s_nonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR, abi.encode(sender)), 0);
+ }
+
+ function test_incrementNoncesInboundAndOutbound_Success() public {
+ address sender = address(this);
+
+ assertEq(s_nonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, sender), 0);
+ uint64 outboundNonce = s_nonceManager.getIncrementedOutboundNonce(DEST_CHAIN_SELECTOR, sender);
+ assertEq(outboundNonce, 1);
+
+ // Inbound nonce unchanged
+ assertEq(s_nonceManager.getInboundNonce(DEST_CHAIN_SELECTOR, abi.encode(sender)), 0);
+
+ s_nonceManager.incrementInboundNonce(DEST_CHAIN_SELECTOR, 1, abi.encode(sender));
+ assertEq(s_nonceManager.getInboundNonce(DEST_CHAIN_SELECTOR, abi.encode(sender)), 1);
+
+ // Outbound nonce unchanged
+ assertEq(s_nonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, sender), 1);
+ }
+}
+
+contract NonceManager_applyPreviousRampsUpdates is EVM2EVMMultiOnRampSetup {
+ function test_SingleRampUpdate() public {
+ address prevOnRamp = makeAddr("prevOnRamp");
+ address prevOffRamp = makeAddr("prevOffRamp");
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](1);
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(prevOnRamp, prevOffRamp));
+
+ vm.expectEmit();
+ emit NonceManager.PreviousRampsUpdated(DEST_CHAIN_SELECTOR, previousRamps[0].prevRamps);
+
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ _assertPreviousRampsEqual(s_outboundNonceManager.getPreviousRamps(DEST_CHAIN_SELECTOR), previousRamps[0].prevRamps);
+ }
+
+ function test_MultipleRampsUpdates() public {
+ address prevOnRamp1 = makeAddr("prevOnRamp1");
+ address prevOnRamp2 = makeAddr("prevOnRamp2");
+ address prevOffRamp1 = makeAddr("prevOffRamp1");
+ address prevOffRamp2 = makeAddr("prevOffRamp2");
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](2);
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(prevOnRamp1, prevOffRamp1));
+ previousRamps[1] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR + 1, NonceManager.PreviousRamps(prevOnRamp2, prevOffRamp2));
+
+ vm.expectEmit();
+ emit NonceManager.PreviousRampsUpdated(DEST_CHAIN_SELECTOR, previousRamps[0].prevRamps);
+ vm.expectEmit();
+ emit NonceManager.PreviousRampsUpdated(DEST_CHAIN_SELECTOR + 1, previousRamps[1].prevRamps);
+
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ _assertPreviousRampsEqual(s_outboundNonceManager.getPreviousRamps(DEST_CHAIN_SELECTOR), previousRamps[0].prevRamps);
+ _assertPreviousRampsEqual(
+ s_outboundNonceManager.getPreviousRamps(DEST_CHAIN_SELECTOR + 1), previousRamps[1].prevRamps
+ );
+ }
+
+ function test_ZeroInput() public {
+ vm.recordLogs();
+ s_outboundNonceManager.applyPreviousRampsUpdates(new NonceManager.PreviousRampsArgs[](0));
+
+ assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ function test_PreviousRampAlreadySetOnRamp_Revert() public {
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](1);
+ address prevOnRamp = makeAddr("prevOnRamp");
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(prevOnRamp, address(0)));
+
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(prevOnRamp, address(0)));
+
+ vm.expectRevert(NonceManager.PreviousRampAlreadySet.selector);
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+ }
+
+ function test_PreviousRampAlreadySetOffRamp_Revert() public {
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](1);
+ address prevOffRamp = makeAddr("prevOffRamp");
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(address(0), prevOffRamp));
+
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(address(0), prevOffRamp));
+
+ vm.expectRevert(NonceManager.PreviousRampAlreadySet.selector);
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+ }
+
+ function test_PreviousRampAlreadySetOnRampAndOffRamp_Revert() public {
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](1);
+ address prevOnRamp = makeAddr("prevOnRamp");
+ address prevOffRamp = makeAddr("prevOffRamp");
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(prevOnRamp, prevOffRamp));
+
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(prevOnRamp, prevOffRamp));
+
+ vm.expectRevert(NonceManager.PreviousRampAlreadySet.selector);
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+ }
+
+ function _assertPreviousRampsEqual(
+ NonceManager.PreviousRamps memory a,
+ NonceManager.PreviousRamps memory b
+ ) internal pure {
+ assertEq(a.prevOnRamp, b.prevOnRamp);
+ assertEq(a.prevOffRamp, b.prevOffRamp);
+ }
+}
+
+contract NonceManager_OnRampUpgrade is EVM2EVMMultiOnRampSetup {
+ uint256 internal constant FEE_AMOUNT = 1234567890;
+ EVM2EVMOnRampHelper internal s_prevOnRamp;
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] memory feeTokenConfigArgs = new EVM2EVMOnRamp.FeeTokenConfigArgs[](1);
+ feeTokenConfigArgs[0] = EVM2EVMOnRamp.FeeTokenConfigArgs({
+ token: s_sourceFeeToken,
+ networkFeeUSDCents: 1_00, // 1 USD
+ gasMultiplierWeiPerEth: 1e18, // 1x
+ premiumMultiplierWeiPerEth: 5e17, // 0.5x
+ enabled: true
+ });
+
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfig =
+ new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](1);
+
+ tokenTransferFeeConfig[0] = EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: s_sourceFeeToken,
+ minFeeUSDCents: 1_00, // 1 USD
+ maxFeeUSDCents: 1000_00, // 1,000 USD
+ deciBps: 2_5, // 2.5 bps, or 0.025%
+ destGasOverhead: 40_000,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES),
+ aggregateRateLimitEnabled: true
+ });
+
+ s_prevOnRamp = new EVM2EVMOnRampHelper(
+ EVM2EVMOnRamp.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ defaultTxGasLimit: GAS_LIMIT,
+ maxNopFeesJuels: MAX_NOP_FEES_JUELS,
+ prevOnRamp: address(0),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ EVM2EVMOnRamp.DynamicConfig({
+ router: address(s_sourceRouter),
+ maxNumberOfTokensPerMsg: MAX_TOKENS_LENGTH,
+ destGasOverhead: DEST_GAS_OVERHEAD,
+ destGasPerPayloadByte: DEST_GAS_PER_PAYLOAD_BYTE,
+ destDataAvailabilityOverheadGas: DEST_DATA_AVAILABILITY_OVERHEAD_GAS,
+ destGasPerDataAvailabilityByte: DEST_GAS_PER_DATA_AVAILABILITY_BYTE,
+ destDataAvailabilityMultiplierBps: DEST_GAS_DATA_AVAILABILITY_MULTIPLIER_BPS,
+ priceRegistry: address(s_priceRegistry),
+ maxDataBytes: MAX_DATA_SIZE,
+ maxPerMsgGasLimit: MAX_GAS_LIMIT,
+ defaultTokenFeeUSDCents: DEFAULT_TOKEN_FEE_USD_CENTS,
+ defaultTokenDestGasOverhead: DEFAULT_TOKEN_DEST_GAS_OVERHEAD,
+ defaultTokenDestBytesOverhead: DEFAULT_TOKEN_BYTES_OVERHEAD,
+ enforceOutOfOrder: false
+ }),
+ RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e15}),
+ feeTokenConfigArgs,
+ tokenTransferFeeConfig,
+ new EVM2EVMOnRamp.NopAndWeight[](0)
+ );
+
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](1);
+ previousRamps[0] =
+ NonceManager.PreviousRampsArgs(DEST_CHAIN_SELECTOR, NonceManager.PreviousRamps(address(s_prevOnRamp), address(0)));
+ s_outboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ (s_onRamp, s_metadataHash) = _deployOnRamp(
+ SOURCE_CHAIN_SELECTOR, address(s_sourceRouter), address(s_outboundNonceManager), address(s_tokenAdminRegistry)
+ );
+
+ vm.startPrank(address(s_sourceRouter));
+ }
+
+ function test_Upgrade_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, FEE_AMOUNT, OWNER));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+ }
+
+ function test_UpgradeSenderNoncesReadsPreviousRamp_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint64 startNonce = s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER);
+
+ for (uint64 i = 1; i < 4; ++i) {
+ s_prevOnRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ assertEq(startNonce + i, s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER));
+ }
+ }
+
+ function test_UpgradeNonceStartsAtV1Nonce_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint64 startNonce = s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER);
+
+ // send 1 message from previous onramp
+ s_prevOnRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ assertEq(startNonce + 1, s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER));
+
+ // new onramp nonce should start from 2, while sequence number start from 1
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(
+ DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, startNonce + 2, FEE_AMOUNT, OWNER)
+ );
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ assertEq(startNonce + 2, s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER));
+
+ // after another send, nonce should be 3, and sequence number be 2
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(
+ DEST_CHAIN_SELECTOR, _messageToEvent(message, 2, startNonce + 3, FEE_AMOUNT, OWNER)
+ );
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ assertEq(startNonce + 3, s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER));
+ }
+
+ function test_UpgradeNonceNewSenderStartsAtZero_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ // send 1 message from previous onramp from OWNER
+ s_prevOnRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ address newSender = address(1234567);
+ // new onramp nonce should start from 1 for new sender
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(
+ DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, FEE_AMOUNT, newSender)
+ );
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, newSender);
+ }
+}
+
+contract NonceManager_OffRampUpgrade is EVM2EVMMultiOffRampSetup {
+ EVM2EVMOffRampHelper internal s_prevOffRamp;
+ EVM2EVMOffRampHelper[] internal s_nestedPrevOffRamps;
+
+ address internal constant SINGLE_LANE_ON_RAMP_ADDRESS_1 = abi.decode(ON_RAMP_ADDRESS_1, (address));
+ address internal constant SINGLE_LANE_ON_RAMP_ADDRESS_2 = abi.decode(ON_RAMP_ADDRESS_2, (address));
+ address internal constant SINGLE_LANE_ON_RAMP_ADDRESS_3 = abi.decode(ON_RAMP_ADDRESS_3, (address));
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ ICommitStore mockPrevCommitStore = new MockCommitStore();
+ s_prevOffRamp = _deploySingleLaneOffRamp(
+ mockPrevCommitStore, s_destRouter, address(0), SOURCE_CHAIN_SELECTOR_1, SINGLE_LANE_ON_RAMP_ADDRESS_1
+ );
+
+ s_nestedPrevOffRamps = new EVM2EVMOffRampHelper[](2);
+ s_nestedPrevOffRamps[0] = _deploySingleLaneOffRamp(
+ mockPrevCommitStore, s_destRouter, address(0), SOURCE_CHAIN_SELECTOR_2, SINGLE_LANE_ON_RAMP_ADDRESS_2
+ );
+ s_nestedPrevOffRamps[1] = _deploySingleLaneOffRamp(
+ mockPrevCommitStore,
+ s_destRouter,
+ address(s_nestedPrevOffRamps[0]),
+ SOURCE_CHAIN_SELECTOR_2,
+ SINGLE_LANE_ON_RAMP_ADDRESS_2
+ );
+
+ NonceManager.PreviousRampsArgs[] memory previousRamps = new NonceManager.PreviousRampsArgs[](3);
+ previousRamps[0] = NonceManager.PreviousRampsArgs(
+ SOURCE_CHAIN_SELECTOR_1, NonceManager.PreviousRamps(address(0), address(s_prevOffRamp))
+ );
+ previousRamps[1] = NonceManager.PreviousRampsArgs(
+ SOURCE_CHAIN_SELECTOR_2, NonceManager.PreviousRamps(address(0), address(s_nestedPrevOffRamps[1]))
+ );
+ previousRamps[2] = NonceManager.PreviousRampsArgs(
+ SOURCE_CHAIN_SELECTOR_3, NonceManager.PreviousRamps(SINGLE_LANE_ON_RAMP_ADDRESS_3, address(0))
+ );
+ s_inboundNonceManager.applyPreviousRampsUpdates(previousRamps);
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](3);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ isEnabled: true,
+ onRamp: ON_RAMP_ADDRESS_1
+ });
+ sourceChainConfigs[1] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_2,
+ isEnabled: true,
+ onRamp: ON_RAMP_ADDRESS_2
+ });
+ sourceChainConfigs[2] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_3,
+ isEnabled: true,
+ onRamp: ON_RAMP_ADDRESS_3
+ });
+
+ _setupMultipleOffRampsFromConfigs(sourceChainConfigs);
+
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_3, 1);
+ }
+
+ function test_Upgraded_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function test_NoPrevOffRampForChain_Success() public {
+ Internal.EVM2EVMMessage[] memory messages =
+ _generateSingleLaneSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, SINGLE_LANE_ON_RAMP_ADDRESS_1);
+ uint64 startNonceChain3 =
+ s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_3, abi.encode(messages[0].sender));
+ s_prevOffRamp.execute(_generateSingleLaneRampReportFromMessages(messages), new uint256[](0));
+
+ // Nonce unchanged for chain 3
+ assertEq(
+ startNonceChain3, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_3, abi.encode(messages[0].sender))
+ );
+
+ Internal.Any2EVMRampMessage[] memory messagesChain3 =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_3, ON_RAMP_ADDRESS_3);
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_3,
+ messagesChain3[0].header.sequenceNumber,
+ messagesChain3[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_3, messagesChain3), new uint256[](0)
+ );
+ assertEq(
+ startNonceChain3 + 1, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_3, messagesChain3[0].sender)
+ );
+ }
+
+ function test_UpgradedSenderNoncesReadsPreviousRamp_Success() public {
+ Internal.EVM2EVMMessage[] memory messages =
+ _generateSingleLaneSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, SINGLE_LANE_ON_RAMP_ADDRESS_1);
+ uint64 startNonce = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(messages[0].sender));
+
+ for (uint64 i = 1; i < 4; ++i) {
+ s_prevOffRamp.execute(_generateSingleLaneRampReportFromMessages(messages), new uint256[](0));
+
+ // messages contains a single message - update for the next execution
+ messages[0].nonce++;
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_prevOffRamp.metadataHash());
+
+ assertEq(
+ startNonce + i, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(messages[0].sender))
+ );
+ }
+ }
+
+ function test_UpgradedSenderNoncesReadsPreviousRampTransitive_Success() public {
+ Internal.EVM2EVMMessage[] memory messages =
+ _generateSingleLaneSingleBasicMessage(SOURCE_CHAIN_SELECTOR_2, SINGLE_LANE_ON_RAMP_ADDRESS_2);
+ uint64 startNonce = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_2, abi.encode(messages[0].sender));
+
+ for (uint64 i = 1; i < 4; ++i) {
+ s_nestedPrevOffRamps[0].execute(_generateSingleLaneRampReportFromMessages(messages), new uint256[](0));
+
+ // messages contains a single message - update for the next execution
+ messages[0].nonce++;
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_nestedPrevOffRamps[0].metadataHash());
+
+ // Read through prev sender nonce through prevOffRamp -> prevPrevOffRamp
+ assertEq(
+ startNonce + i, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_2, abi.encode(messages[0].sender))
+ );
+ }
+ }
+
+ function test_UpgradedNonceStartsAtV1Nonce_Success() public {
+ Internal.EVM2EVMMessage[] memory messages =
+ _generateSingleLaneSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, SINGLE_LANE_ON_RAMP_ADDRESS_1);
+
+ uint64 startNonce = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(messages[0].sender));
+ s_prevOffRamp.execute(_generateSingleLaneRampReportFromMessages(messages), new uint256[](0));
+
+ assertEq(
+ startNonce + 1, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(messages[0].sender))
+ );
+
+ Internal.Any2EVMRampMessage[] memory messagesMultiRamp =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ messagesMultiRamp[0].header.nonce++;
+ messagesMultiRamp[0].header.messageId = Internal._hash(messagesMultiRamp[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messagesMultiRamp[0].header.sequenceNumber,
+ messagesMultiRamp[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messagesMultiRamp), new uint256[](0)
+ );
+ assertEq(
+ startNonce + 2, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messagesMultiRamp[0].sender)
+ );
+
+ messagesMultiRamp[0].header.nonce++;
+ messagesMultiRamp[0].header.sequenceNumber++;
+ messagesMultiRamp[0].header.messageId = Internal._hash(messagesMultiRamp[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messagesMultiRamp[0].header.sequenceNumber,
+ messagesMultiRamp[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messagesMultiRamp), new uint256[](0)
+ );
+ assertEq(
+ startNonce + 3, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messagesMultiRamp[0].sender)
+ );
+ }
+
+ function test_UpgradedNonceNewSenderStartsAtZero_Success() public {
+ Internal.EVM2EVMMessage[] memory messages =
+ _generateSingleLaneSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, SINGLE_LANE_ON_RAMP_ADDRESS_1);
+
+ s_prevOffRamp.execute(_generateSingleLaneRampReportFromMessages(messages), new uint256[](0));
+
+ Internal.Any2EVMRampMessage[] memory messagesMultiRamp =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ bytes memory newSender = abi.encode(address(1234567));
+ messagesMultiRamp[0].sender = newSender;
+ messagesMultiRamp[0].header.messageId = Internal._hash(messagesMultiRamp[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messagesMultiRamp[0].header.sequenceNumber,
+ messagesMultiRamp[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ // new sender nonce in new offramp should go from 0 -> 1
+ assertEq(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, newSender), 0);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messagesMultiRamp), new uint256[](0)
+ );
+ assertEq(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, newSender), 1);
+ }
+
+ function test_UpgradedOffRampNonceSkipsIfMsgInFlight_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ address newSender = address(1234567);
+ messages[0].sender = abi.encode(newSender);
+ messages[0].header.nonce = 2;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ uint64 startNonce = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender);
+
+ // new offramp sees msg nonce higher than senderNonce
+ // it waits for previous offramp to execute
+ vm.expectEmit();
+ emit NonceManager.SkippedIncorrectNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].header.nonce, messages[0].sender);
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ assertEq(startNonce, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender));
+
+ Internal.EVM2EVMMessage[] memory messagesSingleLane =
+ _generateSingleLaneSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, SINGLE_LANE_ON_RAMP_ADDRESS_1);
+
+ messagesSingleLane[0].nonce = 1;
+ messagesSingleLane[0].sender = newSender;
+ messagesSingleLane[0].messageId = Internal._hash(messagesSingleLane[0], s_prevOffRamp.metadataHash());
+
+ // previous offramp executes msg and increases nonce
+ s_prevOffRamp.execute(_generateSingleLaneRampReportFromMessages(messagesSingleLane), new uint256[](0));
+ assertEq(
+ startNonce + 1,
+ s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(messagesSingleLane[0].sender))
+ );
+
+ messages[0].header.nonce = 2;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ // new offramp is able to execute
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ assertEq(startNonce + 2, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender));
+ }
+
+ function _generateSingleLaneRampReportFromMessages(Internal.EVM2EVMMessage[] memory messages)
+ internal
+ pure
+ returns (Internal.ExecutionReport memory)
+ {
+ bytes[][] memory offchainTokenData = new bytes[][](messages.length);
+
+ for (uint256 i = 0; i < messages.length; ++i) {
+ offchainTokenData[i] = new bytes[](messages[i].tokenAmounts.length);
+ }
+
+ return Internal.ExecutionReport({
+ proofs: new bytes32[](0),
+ proofFlagBits: 2 ** 256 - 1,
+ messages: messages,
+ offchainTokenData: offchainTokenData
+ });
+ }
+
+ function _generateSingleLaneSingleBasicMessage(
+ uint64 sourceChainSelector,
+ address onRamp
+ ) internal view returns (Internal.EVM2EVMMessage[] memory) {
+ Internal.EVM2EVMMessage[] memory messages = new Internal.EVM2EVMMessage[](1);
+
+ bytes memory data = abi.encode(0);
+ messages[0] = Internal.EVM2EVMMessage({
+ sequenceNumber: 1,
+ sender: OWNER,
+ nonce: 1,
+ gasLimit: GAS_LIMIT,
+ strict: false,
+ sourceChainSelector: sourceChainSelector,
+ receiver: address(s_receiver),
+ data: data,
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ sourceTokenData: new bytes[](0),
+ feeToken: s_destFeeToken,
+ feeTokenAmount: uint256(0),
+ messageId: ""
+ });
+
+ messages[0].messageId = Internal._hash(
+ messages[0],
+ keccak256(abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, sourceChainSelector, DEST_CHAIN_SELECTOR, onRamp))
+ );
+
+ return messages;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/README.md b/contracts/src/v0.8/ccip/test/README.md
new file mode 100644
index 00000000000..99223e1a63d
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/README.md
@@ -0,0 +1,89 @@
+# Foundry Test Guidelines
+
+We're using Foundry to test our CCIP smart contracts here. This enables us to test in Solidity. If you need to add tests for anything outside the CCIP contracts, please write them in hardhat (for the time being).
+
+## Directory Structure
+
+The test directory structure mimics the source contract file structure as closely as possible. Example:
+
+`./offRamp/SomeOffRamp.sol` should have a test contract `./test/offRamp/SomeOffRamp.t.sol`.
+
+## Test File Structure
+
+Break the test file down into multiple contracts, each contract testing a specific function inside the source contract.
+
+For Example, here's a source contract `SomeOffRamp`:
+
+```
+contract SomeOffRamp {
+
+ constructor() {
+ ... set some state
+ }
+
+ function firstFunction() public {
+ ...
+ }
+
+ function theNextFunction() public {
+ ...
+ }
+
+ function _anInternalFunction() internal {
+ ...
+ }
+}
+```
+
+Our test file `SomeOffRamp.t.sol` should be structured like this:
+
+```
+contract SomeOffRamp_constructor {
+ // constructor state setup tests here
+}
+
+contract SomeOffRamp_firstFunction {
+ // first function tests here
+}
+
+contract SomeOffRamp_theNextFunction {
+ // tests here too...
+}
+
+contract SomeOffRamp_anInternalFunction {
+ // This function will require a helper contract to expose it.
+}
+```
+
+## Test Structure
+
+Inside each test contract, group tests into `Success` and `Reverts` by starting with all the success cases and then adding a `// Reverts` comments to indicate the failure cases below.
+
+```
+contract SomeOffRamp_firstFunction {
+ function testZeroValueSuccess() public {
+ ...
+ }
+
+ ...
+
+
+ // Reverts
+
+ function testOwnerReverts() public {
+ // test that an ownable function reverts when not called by the owner
+ ...
+ }
+
+ ...
+
+}
+```
+
+Function naming should follow this structure, where the `_fuzz_` section denotes whether it's a fuzz test. Do not write tests that are named `testSuccess`, always include the description of the test, even if it's just the name of the function that is being called.
+
+`test{_fuzz_}{description of test}[Success|Reverts]`
+
+Try to cover all the code paths present in each function being tested. In most cases, this will result in many more failure tests than success tests.
+
+If a test file requires a complicated setUp, or if it requires many helper functions (like `_generateAMessageWithNoTokensStruct()`), create a separate file to perform this setup in. Using the example above, `SomeOffRampSetup.t.sol`. Inherit this and call the setUp function in the test file.
diff --git a/contracts/src/v0.8/ccip/test/TokenSetup.t.sol b/contracts/src/v0.8/ccip/test/TokenSetup.t.sol
new file mode 100644
index 00000000000..182d92c5c94
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/TokenSetup.t.sol
@@ -0,0 +1,179 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../interfaces/IPool.sol";
+
+import {BurnMintERC677} from "../../shared/token/ERC677/BurnMintERC677.sol";
+import {Client} from "../libraries/Client.sol";
+import {BurnMintTokenPool} from "../pools/BurnMintTokenPool.sol";
+import {LockReleaseTokenPool} from "../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../pools/TokenPool.sol";
+import {TokenAdminRegistry} from "../tokenAdminRegistry/TokenAdminRegistry.sol";
+import {MaybeRevertingBurnMintTokenPool} from "./helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {RouterSetup} from "./router/RouterSetup.t.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract TokenSetup is RouterSetup {
+ address[] internal s_sourceTokens;
+ address[] internal s_destTokens;
+
+ address internal s_sourceFeeToken;
+ address internal s_destFeeToken;
+
+ TokenAdminRegistry internal s_tokenAdminRegistry;
+
+ mapping(address sourceToken => address sourcePool) internal s_sourcePoolByToken;
+ mapping(address sourceToken => address destPool) internal s_destPoolBySourceToken;
+ mapping(address destToken => address destPool) internal s_destPoolByToken;
+ mapping(address sourceToken => address destToken) internal s_destTokenBySourceToken;
+
+ function _deploySourceToken(string memory tokenName, uint256 dealAmount, uint8 decimals) internal returns (address) {
+ BurnMintERC677 token = new BurnMintERC677(tokenName, tokenName, decimals, 0);
+ s_sourceTokens.push(address(token));
+ deal(address(token), OWNER, dealAmount);
+ return address(token);
+ }
+
+ function _deployDestToken(string memory tokenName, uint256 dealAmount) internal returns (address) {
+ BurnMintERC677 token = new BurnMintERC677(tokenName, tokenName, 18, 0);
+ s_destTokens.push(address(token));
+ deal(address(token), OWNER, dealAmount);
+ return address(token);
+ }
+
+ function _deployLockReleasePool(address token, bool isSourcePool) internal {
+ address router = address(s_sourceRouter);
+ if (!isSourcePool) {
+ router = address(s_destRouter);
+ }
+
+ LockReleaseTokenPool pool =
+ new LockReleaseTokenPool(IERC20(token), new address[](0), address(s_mockRMN), true, router);
+
+ if (isSourcePool) {
+ s_sourcePoolByToken[address(token)] = address(pool);
+ } else {
+ s_destPoolByToken[address(token)] = address(pool);
+ s_destPoolBySourceToken[s_sourceTokens[s_destTokens.length - 1]] = address(pool);
+ }
+ }
+
+ function _deployTokenAndBurnMintPool(address token, bool isSourcePool) internal {
+ address router = address(s_sourceRouter);
+ if (!isSourcePool) {
+ router = address(s_destRouter);
+ }
+
+ BurnMintTokenPool pool =
+ new MaybeRevertingBurnMintTokenPool(BurnMintERC677(token), new address[](0), address(s_mockRMN), router);
+ BurnMintERC677(token).grantMintAndBurnRoles(address(pool));
+
+ if (isSourcePool) {
+ s_sourcePoolByToken[address(token)] = address(pool);
+ } else {
+ s_destPoolByToken[address(token)] = address(pool);
+ s_destPoolBySourceToken[s_sourceTokens[s_destTokens.length - 1]] = address(pool);
+ }
+ }
+
+ function setUp() public virtual override {
+ RouterSetup.setUp();
+
+ bool isSetup = s_sourceTokens.length != 0;
+ if (isSetup) {
+ return;
+ }
+
+ // Source tokens & pools
+ address sourceLink = _deploySourceToken("sLINK", type(uint256).max, 18);
+ _deployLockReleasePool(sourceLink, true);
+ s_sourceFeeToken = sourceLink;
+
+ address sourceEth = _deploySourceToken("sETH", 2 ** 128, 18);
+ _deployTokenAndBurnMintPool(sourceEth, true);
+
+ // Destination tokens & pools
+ address destLink = _deployDestToken("dLINK", type(uint256).max);
+ _deployLockReleasePool(destLink, false);
+ s_destFeeToken = destLink;
+
+ s_destTokenBySourceToken[sourceLink] = destLink;
+
+ address destEth = _deployDestToken("dETH", 2 ** 128);
+ _deployTokenAndBurnMintPool(destEth, false);
+
+ s_destTokenBySourceToken[sourceEth] = destEth;
+
+ // Float the dest link lock release pool with funds
+ IERC20(destLink).transfer(s_destPoolByToken[destLink], 1000 ether);
+
+ s_tokenAdminRegistry = new TokenAdminRegistry();
+
+ // Set pools in the registry
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ address token = s_sourceTokens[i];
+ address pool = s_sourcePoolByToken[token];
+
+ _setPool(
+ s_tokenAdminRegistry, token, pool, DEST_CHAIN_SELECTOR, s_destPoolByToken[s_destTokens[i]], s_destTokens[i]
+ );
+ }
+
+ for (uint256 i = 0; i < s_destTokens.length; ++i) {
+ address token = s_destTokens[i];
+ address pool = s_destPoolByToken[token];
+ s_tokenAdminRegistry.proposeAdministrator(token, OWNER);
+ s_tokenAdminRegistry.acceptAdminRole(token);
+ s_tokenAdminRegistry.setPool(token, pool);
+
+ _setPool(
+ s_tokenAdminRegistry,
+ token,
+ pool,
+ SOURCE_CHAIN_SELECTOR,
+ s_sourcePoolByToken[s_sourceTokens[i]],
+ s_sourceTokens[i]
+ );
+ }
+ }
+
+ function getCastedSourceEVMTokenAmountsWithZeroAmounts()
+ internal
+ view
+ returns (Client.EVMTokenAmount[] memory tokenAmounts)
+ {
+ tokenAmounts = new Client.EVMTokenAmount[](s_sourceTokens.length);
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ tokenAmounts[i].token = s_sourceTokens[i];
+ }
+ }
+
+ function _setPool(
+ TokenAdminRegistry tokenAdminRegistry,
+ address token,
+ address pool,
+ uint64 remoteChainSelector,
+ address remotePoolAddress,
+ address remoteToken
+ ) internal {
+ if (!tokenAdminRegistry.isAdministrator(token, OWNER)) {
+ tokenAdminRegistry.proposeAdministrator(token, OWNER);
+ tokenAdminRegistry.acceptAdminRole(token);
+ }
+
+ tokenAdminRegistry.setPool(token, pool);
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: remoteChainSelector,
+ remotePoolAddress: abi.encode(remotePoolAddress),
+ remoteTokenAddress: abi.encode(remoteToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ TokenPool(pool).applyChainUpdates(chainUpdates);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/WETH9.sol b/contracts/src/v0.8/ccip/test/WETH9.sol
new file mode 100644
index 00000000000..fbc19ee2c4d
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/WETH9.sol
@@ -0,0 +1,82 @@
+// Submitted for verification at Etherscan.io on 2017-12-12
+
+// Copyright (C) 2015, 2016, 2017 Dapphub
+
+// This program is free software: you can redistribute it and/or modify
+// it under the terms of the GNU General Public License as published by
+// the Free Software Foundation, either version 3 of the License, or
+// (at your option) any later version.
+
+// This program is distributed in the hope that it will be useful,
+// but WITHOUT ANY WARRANTY; without even the implied warranty of
+// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+// GNU General Public License for more details.
+
+// You should have received a copy of the GNU General Public License
+// along with this program. If not, see .
+pragma solidity 0.8.24;
+
+// solhint-disable
+contract WETH9 {
+ string public name = "Wrapped Ether";
+ string public symbol = "WETH";
+ uint8 public decimals = 18;
+
+ event Approval(address indexed src, address indexed guy, uint256 wad);
+ event Transfer(address indexed src, address indexed dst, uint256 wad);
+ event Deposit(address indexed dst, uint256 wad);
+ event Withdrawal(address indexed src, uint256 wad);
+
+ mapping(address => uint256) public balanceOf;
+ mapping(address => mapping(address => uint256)) public allowance;
+
+ receive() external payable {
+ _deposit();
+ }
+
+ function _deposit() internal {
+ balanceOf[msg.sender] += msg.value;
+ emit Deposit(msg.sender, msg.value);
+ }
+
+ function deposit() external payable {
+ _deposit();
+ }
+
+ function withdraw(uint256 wad) external {
+ require(balanceOf[msg.sender] >= wad);
+ balanceOf[msg.sender] -= wad;
+ payable(msg.sender).transfer(wad);
+ emit Withdrawal(msg.sender, wad);
+ }
+
+ function totalSupply() public view returns (uint256) {
+ return address(this).balance;
+ }
+
+ function approve(address guy, uint256 wad) public returns (bool) {
+ allowance[msg.sender][guy] = wad;
+ emit Approval(msg.sender, guy, wad);
+ return true;
+ }
+
+ function transfer(address dst, uint256 wad) public returns (bool) {
+ return transferFrom(msg.sender, dst, wad);
+ }
+
+ function transferFrom(address src, address dst, uint256 wad) public returns (bool) {
+ require(balanceOf[src] >= wad);
+
+ if (src != msg.sender && allowance[src][msg.sender] != type(uint128).max) {
+ require(allowance[src][msg.sender] >= wad);
+ allowance[src][msg.sender] -= wad;
+ }
+
+ balanceOf[src] -= wad;
+ balanceOf[dst] += wad;
+
+ emit Transfer(src, dst, wad);
+
+ return true;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/applications/DefensiveExample.t.sol b/contracts/src/v0.8/ccip/test/applications/DefensiveExample.t.sol
new file mode 100644
index 00000000000..18453f9f525
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/applications/DefensiveExample.t.sol
@@ -0,0 +1,97 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {DefensiveExample} from "../../applications/DefensiveExample.sol";
+import {Client} from "../../libraries/Client.sol";
+import {EVM2EVMOnRampSetup} from "../onRamp/EVM2EVMOnRampSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract DefensiveExampleTest is EVM2EVMOnRampSetup {
+ event MessageFailed(bytes32 indexed messageId, bytes reason);
+ event MessageSucceeded(bytes32 indexed messageId);
+ event MessageRecovered(bytes32 indexed messageId);
+
+ DefensiveExample internal s_receiver;
+ uint64 internal sourceChainSelector = 7331;
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ s_receiver = new DefensiveExample(s_destRouter, IERC20(s_destFeeToken));
+ s_receiver.enableChain(sourceChainSelector, abi.encode(""));
+ }
+
+ function test_Recovery() public {
+ bytes32 messageId = keccak256("messageId");
+ address token = address(s_destFeeToken);
+ uint256 amount = 111333333777;
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](1);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: token, amount: amount});
+
+ // Make sure we give the receiver contract enough tokens like CCIP would.
+ deal(token, address(s_receiver), amount);
+
+ // Make sure the contract call reverts so we can test recovery.
+ s_receiver.setSimRevert(true);
+
+ // The receiver contract will revert if the router is not the sender.
+ vm.startPrank(address(s_destRouter));
+
+ vm.expectEmit();
+ emit MessageFailed(messageId, abi.encodeWithSelector(DefensiveExample.ErrorCase.selector));
+
+ s_receiver.ccipReceive(
+ Client.Any2EVMMessage({
+ messageId: messageId,
+ sourceChainSelector: sourceChainSelector,
+ sender: abi.encode(address(0)), // wrong sender, will revert internally
+ data: "",
+ destTokenAmounts: destTokenAmounts
+ })
+ );
+
+ address tokenReceiver = address(0x000001337);
+ uint256 tokenReceiverBalancePre = IERC20(token).balanceOf(tokenReceiver);
+ uint256 receiverBalancePre = IERC20(token).balanceOf(address(s_receiver));
+
+ // Recovery can only be done by the owner.
+ vm.startPrank(OWNER);
+
+ vm.expectEmit();
+ emit MessageRecovered(messageId);
+
+ s_receiver.retryFailedMessage(messageId, tokenReceiver);
+
+ // Assert the tokens have successfully been rescued from the contract.
+ assertEq(IERC20(token).balanceOf(tokenReceiver), tokenReceiverBalancePre + amount);
+ assertEq(IERC20(token).balanceOf(address(s_receiver)), receiverBalancePre - amount);
+ }
+
+ function test_HappyPath_Success() public {
+ bytes32 messageId = keccak256("messageId");
+ address token = address(s_destFeeToken);
+ uint256 amount = 111333333777;
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](1);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: token, amount: amount});
+
+ // Make sure we give the receiver contract enough tokens like CCIP would.
+ deal(token, address(s_receiver), amount);
+
+ // The receiver contract will revert if the router is not the sender.
+ vm.startPrank(address(s_destRouter));
+
+ vm.expectEmit();
+ emit MessageSucceeded(messageId);
+
+ s_receiver.ccipReceive(
+ Client.Any2EVMMessage({
+ messageId: messageId,
+ sourceChainSelector: sourceChainSelector,
+ sender: abi.encode(address(s_receiver)), // correct sender
+ data: "",
+ destTokenAmounts: destTokenAmounts
+ })
+ );
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/applications/EtherSenderReceiver.t.sol b/contracts/src/v0.8/ccip/test/applications/EtherSenderReceiver.t.sol
new file mode 100644
index 00000000000..cfd402d9106
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/applications/EtherSenderReceiver.t.sol
@@ -0,0 +1,718 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Test} from "forge-std/Test.sol";
+
+import {CCIPRouter} from "../../applications/EtherSenderReceiver.sol";
+
+import {IRouterClient} from "../../interfaces/IRouterClient.sol";
+import {Client} from "../../libraries/Client.sol";
+import {WETH9} from "../WETH9.sol";
+import {EtherSenderReceiverHelper} from "./../helpers/EtherSenderReceiverHelper.sol";
+
+import {ERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/ERC20.sol";
+
+contract EtherSenderReceiverTest is Test {
+ EtherSenderReceiverHelper internal s_etherSenderReceiver;
+ WETH9 internal s_weth;
+ WETH9 internal s_someOtherWeth;
+ ERC20 internal s_linkToken;
+
+ address internal constant OWNER = 0x00007e64E1fB0C487F25dd6D3601ff6aF8d32e4e;
+ address internal constant ROUTER = 0x0F3779ee3a832D10158073ae2F5e61ac7FBBF880;
+ address internal constant XCHAIN_RECEIVER = 0xBd91b2073218AF872BF73b65e2e5950ea356d147;
+
+ function setUp() public {
+ vm.startPrank(OWNER);
+
+ s_linkToken = new ERC20("Chainlink Token", "LINK");
+ s_someOtherWeth = new WETH9();
+ s_weth = new WETH9();
+ vm.mockCall(ROUTER, abi.encodeWithSelector(CCIPRouter.getWrappedNative.selector), abi.encode(address(s_weth)));
+ s_etherSenderReceiver = new EtherSenderReceiverHelper(ROUTER);
+
+ deal(OWNER, 1_000_000 ether);
+ deal(address(s_linkToken), OWNER, 1_000_000 ether);
+
+ // deposit some eth into the weth contract.
+ s_weth.deposit{value: 10 ether}();
+ uint256 wethSupply = s_weth.totalSupply();
+ assertEq(wethSupply, 10 ether, "total weth supply must be 10 ether");
+ }
+}
+
+contract EtherSenderReceiverTest_constructor is EtherSenderReceiverTest {
+ function test_constructor() public view {
+ assertEq(s_etherSenderReceiver.getRouter(), ROUTER, "router must be set correctly");
+ uint256 allowance = s_weth.allowance(address(s_etherSenderReceiver), ROUTER);
+ assertEq(allowance, type(uint256).max, "allowance must be set infinite");
+ }
+}
+
+contract EtherSenderReceiverTest_validateFeeToken is EtherSenderReceiverTest {
+ uint256 internal constant amount = 100;
+
+ error InsufficientMsgValue(uint256 gotAmount, uint256 msgValue);
+ error TokenAmountNotEqualToMsgValue(uint256 gotAmount, uint256 msgValue);
+
+ function test_validateFeeToken_valid_native() public {
+ Client.EVMTokenAmount[] memory tokenAmount = new Client.EVMTokenAmount[](1);
+ tokenAmount[0] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmount,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ s_etherSenderReceiver.validateFeeToken{value: amount + 1}(message);
+ }
+
+ function test_validateFeeToken_valid_feeToken() public {
+ Client.EVMTokenAmount[] memory tokenAmount = new Client.EVMTokenAmount[](1);
+ tokenAmount[0] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmount,
+ feeToken: address(s_weth),
+ extraArgs: ""
+ });
+
+ s_etherSenderReceiver.validateFeeToken{value: amount}(message);
+ }
+
+ function test_validateFeeToken_reverts_feeToken_tokenAmountNotEqualToMsgValue() public {
+ Client.EVMTokenAmount[] memory tokenAmount = new Client.EVMTokenAmount[](1);
+ tokenAmount[0] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmount,
+ feeToken: address(s_weth),
+ extraArgs: ""
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(TokenAmountNotEqualToMsgValue.selector, amount, amount + 1));
+ s_etherSenderReceiver.validateFeeToken{value: amount + 1}(message);
+ }
+}
+
+contract EtherSenderReceiverTest_validatedMessage is EtherSenderReceiverTest {
+ error InvalidDestinationReceiver(bytes destReceiver);
+ error InvalidTokenAmounts(uint256 gotAmounts);
+ error InvalidWethAddress(address want, address got);
+ error GasLimitTooLow(uint256 minLimit, uint256 gotLimit);
+
+ uint256 internal constant amount = 100;
+
+ function test_Fuzz_validatedMessage_msgSenderOverwrite(bytes memory data) public view {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: data,
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+ assertEq(validatedMessage.receiver, abi.encode(XCHAIN_RECEIVER), "receiver must be XCHAIN_RECEIVER");
+ assertEq(validatedMessage.data, abi.encode(OWNER), "data must be msg.sender");
+ assertEq(validatedMessage.tokenAmounts[0].token, address(s_weth), "token must be weth");
+ assertEq(validatedMessage.tokenAmounts[0].amount, amount, "amount must be correct");
+ assertEq(validatedMessage.feeToken, address(0), "feeToken must be 0");
+ assertEq(validatedMessage.extraArgs, bytes(""), "extraArgs must be empty");
+ }
+
+ function test_Fuzz_validatedMessage_tokenAddressOverwrite(address token) public view {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: token, amount: amount});
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+ assertEq(validatedMessage.receiver, abi.encode(XCHAIN_RECEIVER), "receiver must be XCHAIN_RECEIVER");
+ assertEq(validatedMessage.data, abi.encode(OWNER), "data must be msg.sender");
+ assertEq(validatedMessage.tokenAmounts[0].token, address(s_weth), "token must be weth");
+ assertEq(validatedMessage.tokenAmounts[0].amount, amount, "amount must be correct");
+ assertEq(validatedMessage.feeToken, address(0), "feeToken must be 0");
+ assertEq(validatedMessage.extraArgs, bytes(""), "extraArgs must be empty");
+ }
+
+ function test_validatedMessage_emptyDataOverwrittenToMsgSender() public view {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+ assertEq(validatedMessage.receiver, abi.encode(XCHAIN_RECEIVER), "receiver must be XCHAIN_RECEIVER");
+ assertEq(validatedMessage.data, abi.encode(OWNER), "data must be msg.sender");
+ assertEq(validatedMessage.tokenAmounts[0].token, address(s_weth), "token must be weth");
+ assertEq(validatedMessage.tokenAmounts[0].amount, amount, "amount must be correct");
+ assertEq(validatedMessage.feeToken, address(0), "feeToken must be 0");
+ assertEq(validatedMessage.extraArgs, bytes(""), "extraArgs must be empty");
+ }
+
+ function test_validatedMessage_dataOverwrittenToMsgSender() public view {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: abi.encode(address(42)),
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+ assertEq(validatedMessage.receiver, abi.encode(XCHAIN_RECEIVER), "receiver must be XCHAIN_RECEIVER");
+ assertEq(validatedMessage.data, abi.encode(OWNER), "data must be msg.sender");
+ assertEq(validatedMessage.tokenAmounts[0].token, address(s_weth), "token must be weth");
+ assertEq(validatedMessage.tokenAmounts[0].amount, amount, "amount must be correct");
+ assertEq(validatedMessage.feeToken, address(0), "feeToken must be 0");
+ assertEq(validatedMessage.extraArgs, bytes(""), "extraArgs must be empty");
+ }
+
+ function test_validatedMessage_tokenOverwrittenToWeth() public view {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(42), // incorrect token.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+ assertEq(validatedMessage.receiver, abi.encode(XCHAIN_RECEIVER), "receiver must be XCHAIN_RECEIVER");
+ assertEq(validatedMessage.data, abi.encode(OWNER), "data must be msg.sender");
+ assertEq(validatedMessage.tokenAmounts[0].token, address(s_weth), "token must be weth");
+ assertEq(validatedMessage.tokenAmounts[0].amount, amount, "amount must be correct");
+ assertEq(validatedMessage.feeToken, address(0), "feeToken must be 0");
+ assertEq(validatedMessage.extraArgs, bytes(""), "extraArgs must be empty");
+ }
+
+ function test_validatedMessage_validMessage_extraArgs() public view {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 200_000}))
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+ assertEq(validatedMessage.receiver, abi.encode(XCHAIN_RECEIVER), "receiver must be XCHAIN_RECEIVER");
+ assertEq(validatedMessage.data, abi.encode(OWNER), "data must be msg.sender");
+ assertEq(validatedMessage.tokenAmounts[0].token, address(s_weth), "token must be weth");
+ assertEq(validatedMessage.tokenAmounts[0].amount, amount, "amount must be correct");
+ assertEq(validatedMessage.feeToken, address(0), "feeToken must be 0");
+ assertEq(
+ validatedMessage.extraArgs,
+ Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 200_000})),
+ "extraArgs must be correct"
+ );
+ }
+
+ function test_validatedMessage_invalidTokenAmounts() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: address(0), amount: amount});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: address(0), amount: amount});
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(InvalidTokenAmounts.selector, uint256(2)));
+ s_etherSenderReceiver.validatedMessage(message);
+ }
+}
+
+contract EtherSenderReceiverTest_getFee is EtherSenderReceiverTest {
+ uint64 internal constant destinationChainSelector = 424242;
+ uint256 internal constant feeWei = 121212;
+ uint256 internal constant amount = 100;
+
+ function test_getFee() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: address(0), amount: amount});
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeWei)
+ );
+
+ uint256 fee = s_etherSenderReceiver.getFee(destinationChainSelector, message);
+ assertEq(fee, feeWei, "fee must be feeWei");
+ }
+}
+
+contract EtherSenderReceiverTest_ccipReceive is EtherSenderReceiverTest {
+ uint256 internal constant amount = 100;
+ uint64 internal constant sourceChainSelector = 424242;
+ address internal constant XCHAIN_SENDER = 0x9951529C13B01E542f7eE3b6D6665D292e9BA2E0;
+
+ error InvalidTokenAmounts(uint256 gotAmounts);
+ error InvalidToken(address gotToken, address expectedToken);
+
+ function test_Fuzz_ccipReceive(uint256 tokenAmount) public {
+ // cap to 10 ether because OWNER only has 10 ether.
+ if (tokenAmount > 10 ether) {
+ return;
+ }
+
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](1);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: address(s_weth), amount: tokenAmount});
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: keccak256(abi.encode("ccip send")),
+ sourceChainSelector: sourceChainSelector,
+ sender: abi.encode(XCHAIN_SENDER),
+ data: abi.encode(OWNER),
+ destTokenAmounts: destTokenAmounts
+ });
+
+ // simulate a cross-chain token transfer, just transfer the weth to s_etherSenderReceiver.
+ s_weth.transfer(address(s_etherSenderReceiver), tokenAmount);
+
+ uint256 balanceBefore = OWNER.balance;
+ s_etherSenderReceiver.publicCcipReceive(message);
+ uint256 balanceAfter = OWNER.balance;
+ assertEq(balanceAfter, balanceBefore + tokenAmount, "balance must be correct");
+ }
+
+ function test_ccipReceive_happyPath() public {
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](1);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: keccak256(abi.encode("ccip send")),
+ sourceChainSelector: 424242,
+ sender: abi.encode(XCHAIN_SENDER),
+ data: abi.encode(OWNER),
+ destTokenAmounts: destTokenAmounts
+ });
+
+ // simulate a cross-chain token transfer, just transfer the weth to s_etherSenderReceiver.
+ s_weth.transfer(address(s_etherSenderReceiver), amount);
+
+ uint256 balanceBefore = OWNER.balance;
+ s_etherSenderReceiver.publicCcipReceive(message);
+ uint256 balanceAfter = OWNER.balance;
+ assertEq(balanceAfter, balanceBefore + amount, "balance must be correct");
+ }
+
+ function test_ccipReceive_fallbackToWethTransfer() public {
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](1);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: keccak256(abi.encode("ccip send")),
+ sourceChainSelector: 424242,
+ sender: abi.encode(XCHAIN_SENDER),
+ data: abi.encode(address(s_linkToken)), // ERC20 cannot receive() ether.
+ destTokenAmounts: destTokenAmounts
+ });
+
+ // simulate a cross-chain token transfer, just transfer the weth to s_etherSenderReceiver.
+ s_weth.transfer(address(s_etherSenderReceiver), amount);
+
+ uint256 balanceBefore = address(s_linkToken).balance;
+ s_etherSenderReceiver.publicCcipReceive(message);
+ uint256 balanceAfter = address(s_linkToken).balance;
+ assertEq(balanceAfter, balanceBefore, "balance must be unchanged");
+ uint256 wethBalance = s_weth.balanceOf(address(s_linkToken));
+ assertEq(wethBalance, amount, "weth balance must be correct");
+ }
+
+ function test_ccipReceive_wrongTokenAmount() public {
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](2);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ destTokenAmounts[1] = Client.EVMTokenAmount({token: address(s_weth), amount: amount});
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: keccak256(abi.encode("ccip send")),
+ sourceChainSelector: 424242,
+ sender: abi.encode(XCHAIN_SENDER),
+ data: abi.encode(OWNER),
+ destTokenAmounts: destTokenAmounts
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(InvalidTokenAmounts.selector, uint256(2)));
+ s_etherSenderReceiver.publicCcipReceive(message);
+ }
+
+ function test_ccipReceive_wrongToken() public {
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](1);
+ destTokenAmounts[0] = Client.EVMTokenAmount({token: address(s_someOtherWeth), amount: amount});
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: keccak256(abi.encode("ccip send")),
+ sourceChainSelector: 424242,
+ sender: abi.encode(XCHAIN_SENDER),
+ data: abi.encode(OWNER),
+ destTokenAmounts: destTokenAmounts
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(InvalidToken.selector, address(s_someOtherWeth), address(s_weth)));
+ s_etherSenderReceiver.publicCcipReceive(message);
+ }
+}
+
+contract EtherSenderReceiverTest_ccipSend is EtherSenderReceiverTest {
+ error InsufficientFee(uint256 gotFee, uint256 fee);
+
+ uint256 internal constant amount = 100;
+ uint64 internal constant destinationChainSelector = 424242;
+ uint256 internal constant feeWei = 121212;
+ uint256 internal constant feeJuels = 232323;
+
+ function test_Fuzz_ccipSend(uint256 feeFromRouter, uint256 feeSupplied) public {
+ // cap the fuzzer because OWNER only has a million ether.
+ vm.assume(feeSupplied < 1_000_000 ether - amount);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeFromRouter)
+ );
+
+ if (feeSupplied < feeFromRouter) {
+ vm.expectRevert();
+ s_etherSenderReceiver.ccipSend{value: amount + feeSupplied}(destinationChainSelector, message);
+ } else {
+ bytes32 expectedMsgId = keccak256(abi.encode("ccip send"));
+ vm.mockCall(
+ ROUTER,
+ feeSupplied,
+ abi.encodeWithSelector(IRouterClient.ccipSend.selector, destinationChainSelector, validatedMessage),
+ abi.encode(expectedMsgId)
+ );
+
+ bytes32 actualMsgId =
+ s_etherSenderReceiver.ccipSend{value: amount + feeSupplied}(destinationChainSelector, message);
+ assertEq(actualMsgId, expectedMsgId, "message id must be correct");
+ }
+ }
+
+ function test_Fuzz_ccipSend_feeToken(uint256 feeFromRouter, uint256 feeSupplied) public {
+ // cap the fuzzer because OWNER only has a million LINK.
+ vm.assume(feeSupplied < 1_000_000 ether - amount);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(s_linkToken),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeFromRouter)
+ );
+
+ s_linkToken.approve(address(s_etherSenderReceiver), feeSupplied);
+
+ if (feeSupplied < feeFromRouter) {
+ vm.expectRevert();
+ s_etherSenderReceiver.ccipSend{value: amount}(destinationChainSelector, message);
+ } else {
+ bytes32 expectedMsgId = keccak256(abi.encode("ccip send"));
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.ccipSend.selector, destinationChainSelector, validatedMessage),
+ abi.encode(expectedMsgId)
+ );
+
+ bytes32 actualMsgId = s_etherSenderReceiver.ccipSend{value: amount}(destinationChainSelector, message);
+ assertEq(actualMsgId, expectedMsgId, "message id must be correct");
+ }
+ }
+
+ function test_ccipSend_reverts_insufficientFee_weth() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(s_weth),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeWei)
+ );
+
+ s_weth.approve(address(s_etherSenderReceiver), feeWei - 1);
+
+ vm.expectRevert("SafeERC20: low-level call failed");
+ s_etherSenderReceiver.ccipSend{value: amount}(destinationChainSelector, message);
+ }
+
+ function test_ccipSend_reverts_insufficientFee_feeToken() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(s_linkToken),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeJuels)
+ );
+
+ s_linkToken.approve(address(s_etherSenderReceiver), feeJuels - 1);
+
+ vm.expectRevert("ERC20: insufficient allowance");
+ s_etherSenderReceiver.ccipSend{value: amount}(destinationChainSelector, message);
+ }
+
+ function test_ccipSend_reverts_insufficientFee_native() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeWei)
+ );
+
+ vm.expectRevert();
+ s_etherSenderReceiver.ccipSend{value: amount + feeWei - 1}(destinationChainSelector, message);
+ }
+
+ function test_ccipSend_success_nativeExcess() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ bytes32 expectedMsgId = keccak256(abi.encode("ccip send"));
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeWei)
+ );
+
+ // we assert that the correct value is sent to the router call, which should be
+ // the msg.value - feeWei.
+ vm.mockCall(
+ ROUTER,
+ feeWei + 1,
+ abi.encodeWithSelector(IRouterClient.ccipSend.selector, destinationChainSelector, validatedMessage),
+ abi.encode(expectedMsgId)
+ );
+
+ bytes32 actualMsgId = s_etherSenderReceiver.ccipSend{value: amount + feeWei + 1}(destinationChainSelector, message);
+ assertEq(actualMsgId, expectedMsgId, "message id must be correct");
+ }
+
+ function test_ccipSend_success_native() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(0),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ bytes32 expectedMsgId = keccak256(abi.encode("ccip send"));
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeWei)
+ );
+ vm.mockCall(
+ ROUTER,
+ feeWei,
+ abi.encodeWithSelector(IRouterClient.ccipSend.selector, destinationChainSelector, validatedMessage),
+ abi.encode(expectedMsgId)
+ );
+
+ bytes32 actualMsgId = s_etherSenderReceiver.ccipSend{value: amount + feeWei}(destinationChainSelector, message);
+ assertEq(actualMsgId, expectedMsgId, "message id must be correct");
+ }
+
+ function test_ccipSend_success_feeToken() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(s_linkToken),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ bytes32 expectedMsgId = keccak256(abi.encode("ccip send"));
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeJuels)
+ );
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.ccipSend.selector, destinationChainSelector, validatedMessage),
+ abi.encode(expectedMsgId)
+ );
+
+ s_linkToken.approve(address(s_etherSenderReceiver), feeJuels);
+
+ bytes32 actualMsgId = s_etherSenderReceiver.ccipSend{value: amount}(destinationChainSelector, message);
+ assertEq(actualMsgId, expectedMsgId, "message id must be correct");
+ uint256 routerAllowance = s_linkToken.allowance(address(s_etherSenderReceiver), ROUTER);
+ assertEq(routerAllowance, feeJuels, "router allowance must be feeJuels");
+ }
+
+ function test_ccipSend_success_weth() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({
+ token: address(0), // callers may not specify this.
+ amount: amount
+ });
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(XCHAIN_RECEIVER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: address(s_weth),
+ extraArgs: ""
+ });
+
+ Client.EVM2AnyMessage memory validatedMessage = s_etherSenderReceiver.validatedMessage(message);
+
+ bytes32 expectedMsgId = keccak256(abi.encode("ccip send"));
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.getFee.selector, destinationChainSelector, validatedMessage),
+ abi.encode(feeWei)
+ );
+ vm.mockCall(
+ ROUTER,
+ abi.encodeWithSelector(IRouterClient.ccipSend.selector, destinationChainSelector, validatedMessage),
+ abi.encode(expectedMsgId)
+ );
+
+ s_weth.approve(address(s_etherSenderReceiver), feeWei);
+
+ bytes32 actualMsgId = s_etherSenderReceiver.ccipSend{value: amount}(destinationChainSelector, message);
+ assertEq(actualMsgId, expectedMsgId, "message id must be correct");
+ uint256 routerAllowance = s_weth.allowance(address(s_etherSenderReceiver), ROUTER);
+ assertEq(routerAllowance, type(uint256).max, "router allowance must be max for weth");
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/applications/ImmutableExample.t.sol b/contracts/src/v0.8/ccip/test/applications/ImmutableExample.t.sol
new file mode 100644
index 00000000000..eb12e6205a4
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/applications/ImmutableExample.t.sol
@@ -0,0 +1,61 @@
+pragma solidity ^0.8.0;
+
+import {IAny2EVMMessageReceiver} from "../../interfaces/IAny2EVMMessageReceiver.sol";
+
+import {CCIPClientExample} from "../../applications/CCIPClientExample.sol";
+import {Client} from "../../libraries/Client.sol";
+import {EVM2EVMOnRampSetup} from "../onRamp/EVM2EVMOnRampSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {ERC165Checker} from
+ "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol";
+
+contract CCIPClientExample_sanity is EVM2EVMOnRampSetup {
+ function test_ImmutableExamples_Success() public {
+ CCIPClientExample exampleContract = new CCIPClientExample(s_sourceRouter, IERC20(s_sourceFeeToken));
+ deal(address(exampleContract), 100 ether);
+ deal(s_sourceFeeToken, address(exampleContract), 100 ether);
+
+ // feeToken approval works
+ assertEq(IERC20(s_sourceFeeToken).allowance(address(exampleContract), address(s_sourceRouter)), 2 ** 256 - 1);
+
+ // Can set chain
+ Client.EVMExtraArgsV1 memory extraArgs = Client.EVMExtraArgsV1({gasLimit: 300_000});
+ bytes memory encodedExtraArgs = Client._argsToBytes(extraArgs);
+ exampleContract.enableChain(DEST_CHAIN_SELECTOR, encodedExtraArgs);
+ assertEq(exampleContract.s_chains(DEST_CHAIN_SELECTOR), encodedExtraArgs);
+
+ address toAddress = makeAddr("toAddress");
+
+ // Can send data pay native
+ exampleContract.sendDataPayNative(DEST_CHAIN_SELECTOR, abi.encode(toAddress), bytes("hello"));
+
+ // Can send data pay feeToken
+ exampleContract.sendDataPayFeeToken(DEST_CHAIN_SELECTOR, abi.encode(toAddress), bytes("hello"));
+
+ // Can send data tokens
+ address sourceToken = s_sourceTokens[1];
+ assertEq(
+ address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(sourceToken))),
+ address(s_sourcePoolByToken[sourceToken])
+ );
+ deal(sourceToken, OWNER, 100 ether);
+ IERC20(sourceToken).approve(address(exampleContract), 1 ether);
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: sourceToken, amount: 1 ether});
+ exampleContract.sendDataAndTokens(DEST_CHAIN_SELECTOR, abi.encode(toAddress), bytes("hello"), tokenAmounts);
+ // Tokens transferred from owner to router then burned in pool.
+ assertEq(IERC20(sourceToken).balanceOf(OWNER), 99 ether);
+ assertEq(IERC20(sourceToken).balanceOf(address(s_sourceRouter)), 0);
+
+ // Can send just tokens
+ IERC20(sourceToken).approve(address(exampleContract), 1 ether);
+ exampleContract.sendTokens(DEST_CHAIN_SELECTOR, abi.encode(toAddress), tokenAmounts);
+
+ // Can receive
+ assertTrue(ERC165Checker.supportsInterface(address(exampleContract), type(IAny2EVMMessageReceiver).interfaceId));
+
+ // Can disable chain
+ exampleContract.disableChain(DEST_CHAIN_SELECTOR);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/applications/PingPongDemo.t.sol b/contracts/src/v0.8/ccip/test/applications/PingPongDemo.t.sol
new file mode 100644
index 00000000000..3297e1f4fbc
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/applications/PingPongDemo.t.sol
@@ -0,0 +1,121 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {PingPongDemo} from "../../applications/PingPongDemo.sol";
+import {Client} from "../../libraries/Client.sol";
+import "../onRamp/EVM2EVMOnRampSetup.t.sol";
+
+// setup
+contract PingPongDappSetup is EVM2EVMOnRampSetup {
+ PingPongDemo internal s_pingPong;
+ IERC20 internal s_feeToken;
+
+ address internal immutable i_pongContract = makeAddr("ping_pong_counterpart");
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ s_feeToken = IERC20(s_sourceTokens[0]);
+ s_pingPong = new PingPongDemo(address(s_sourceRouter), s_feeToken);
+ s_pingPong.setCounterpart(DEST_CHAIN_SELECTOR, i_pongContract);
+
+ uint256 fundingAmount = 1e18;
+
+ // Fund the contract with LINK tokens
+ s_feeToken.transfer(address(s_pingPong), fundingAmount);
+ }
+}
+
+contract PingPong_startPingPong is PingPongDappSetup {
+ function test_StartPingPong_Success() public {
+ uint256 pingPongNumber = 1;
+ bytes memory data = abi.encode(pingPongNumber);
+
+ Client.EVM2AnyMessage memory sentMessage = Client.EVM2AnyMessage({
+ receiver: abi.encode(i_pongContract),
+ data: data,
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 2e5}))
+ });
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, sentMessage);
+
+ Internal.EVM2EVMMessage memory message = Internal.EVM2EVMMessage({
+ sequenceNumber: 1,
+ feeTokenAmount: expectedFee,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ sender: address(s_pingPong),
+ receiver: i_pongContract,
+ nonce: 1,
+ data: data,
+ tokenAmounts: sentMessage.tokenAmounts,
+ sourceTokenData: new bytes[](sentMessage.tokenAmounts.length),
+ gasLimit: 2e5,
+ feeToken: sentMessage.feeToken,
+ strict: false,
+ messageId: ""
+ });
+ message.messageId = Internal._hash(message, s_metadataHash);
+
+ vm.expectEmit();
+ emit PingPongDemo.Ping(pingPongNumber);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(message);
+
+ s_pingPong.startPingPong();
+ }
+}
+
+contract PingPong_ccipReceive is PingPongDappSetup {
+ function test_CcipReceive_Success() public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](0);
+
+ uint256 pingPongNumber = 5;
+
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: bytes32("a"),
+ sourceChainSelector: DEST_CHAIN_SELECTOR,
+ sender: abi.encode(i_pongContract),
+ data: abi.encode(pingPongNumber),
+ destTokenAmounts: tokenAmounts
+ });
+
+ vm.startPrank(address(s_sourceRouter));
+
+ vm.expectEmit();
+ emit PingPongDemo.Pong(pingPongNumber + 1);
+
+ s_pingPong.ccipReceive(message);
+ }
+}
+
+contract PingPong_plumbing is PingPongDappSetup {
+ function test_Fuzz_CounterPartChainSelector_Success(uint64 chainSelector) public {
+ s_pingPong.setCounterpartChainSelector(chainSelector);
+
+ assertEq(s_pingPong.getCounterpartChainSelector(), chainSelector);
+ }
+
+ function test_Fuzz_CounterPartAddress_Success(address counterpartAddress) public {
+ s_pingPong.setCounterpartAddress(counterpartAddress);
+
+ assertEq(s_pingPong.getCounterpartAddress(), counterpartAddress);
+ }
+
+ function test_Fuzz_CounterPartAddress_Success(uint64 chainSelector, address counterpartAddress) public {
+ s_pingPong.setCounterpart(chainSelector, counterpartAddress);
+
+ assertEq(s_pingPong.getCounterpartAddress(), counterpartAddress);
+ assertEq(s_pingPong.getCounterpartChainSelector(), chainSelector);
+ }
+
+ function test_Pausing_Success() public {
+ assertFalse(s_pingPong.isPaused());
+
+ s_pingPong.setPaused(true);
+
+ assertTrue(s_pingPong.isPaused());
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/applications/SelfFundedPingPong.t.sol b/contracts/src/v0.8/ccip/test/applications/SelfFundedPingPong.t.sol
new file mode 100644
index 00000000000..d5db9d1f9d0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/applications/SelfFundedPingPong.t.sol
@@ -0,0 +1,99 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {SelfFundedPingPong} from "../../applications/SelfFundedPingPong.sol";
+import {Client} from "../../libraries/Client.sol";
+import {EVM2EVMOnRamp} from "../../onRamp/EVM2EVMOnRamp.sol";
+import {EVM2EVMOnRampSetup} from "../onRamp/EVM2EVMOnRampSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract SelfFundedPingPongDappSetup is EVM2EVMOnRampSetup {
+ SelfFundedPingPong internal s_pingPong;
+ IERC20 internal s_feeToken;
+ uint8 internal constant s_roundTripsBeforeFunding = 0;
+
+ address internal immutable i_pongContract = makeAddr("ping_pong_counterpart");
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ s_feeToken = IERC20(s_sourceTokens[0]);
+ s_pingPong = new SelfFundedPingPong(address(s_sourceRouter), s_feeToken, s_roundTripsBeforeFunding);
+ s_pingPong.setCounterpart(DEST_CHAIN_SELECTOR, i_pongContract);
+
+ uint256 fundingAmount = 5e18;
+
+ // set ping pong as an onRamp nop to make sure that funding runs
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](1);
+ nopsAndWeights[0] = EVM2EVMOnRamp.NopAndWeight({nop: address(s_pingPong), weight: 1});
+ s_onRamp.setNops(nopsAndWeights);
+
+ // Fund the contract with LINK tokens
+ s_feeToken.transfer(address(s_pingPong), fundingAmount);
+ }
+}
+
+contract SelfFundedPingPong_ccipReceive is SelfFundedPingPongDappSetup {
+ function test_Funding_Success() public {
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: keccak256("msg id"),
+ sourceChainSelector: DEST_CHAIN_SELECTOR,
+ sender: abi.encode(i_pongContract),
+ data: "",
+ destTokenAmounts: new Client.EVMTokenAmount[](0)
+ });
+
+ uint8 countIncrBeforeFunding = 5;
+
+ vm.expectEmit();
+ emit SelfFundedPingPong.CountIncrBeforeFundingSet(countIncrBeforeFunding);
+
+ s_pingPong.setCountIncrBeforeFunding(countIncrBeforeFunding);
+
+ vm.startPrank(address(s_sourceRouter));
+ for (uint256 pingPongNumber = 0; pingPongNumber <= countIncrBeforeFunding; ++pingPongNumber) {
+ message.data = abi.encode(pingPongNumber);
+ if (pingPongNumber == countIncrBeforeFunding - 1) {
+ vm.expectEmit();
+ emit SelfFundedPingPong.Funded();
+ vm.expectCall(address(s_onRamp), "");
+ }
+ s_pingPong.ccipReceive(message);
+ }
+ }
+
+ function test_FundingIfNotANop_Revert() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](0);
+ s_onRamp.setNops(nopsAndWeights);
+
+ uint8 countIncrBeforeFunding = 3;
+ s_pingPong.setCountIncrBeforeFunding(countIncrBeforeFunding);
+
+ vm.startPrank(address(s_sourceRouter));
+ Client.Any2EVMMessage memory message = Client.Any2EVMMessage({
+ messageId: bytes32("a"),
+ sourceChainSelector: DEST_CHAIN_SELECTOR,
+ sender: abi.encode(i_pongContract),
+ data: abi.encode(countIncrBeforeFunding),
+ destTokenAmounts: new Client.EVMTokenAmount[](0)
+ });
+
+ // because pingPong is not set as a nop
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdminOrNop.selector);
+ s_pingPong.ccipReceive(message);
+ }
+}
+
+contract SelfFundedPingPong_setCountIncrBeforeFunding is SelfFundedPingPongDappSetup {
+ function test_setCountIncrBeforeFunding() public {
+ uint8 c = s_pingPong.getCountIncrBeforeFunding();
+
+ vm.expectEmit();
+ emit SelfFundedPingPong.CountIncrBeforeFundingSet(c + 1);
+
+ s_pingPong.setCountIncrBeforeFunding(c + 1);
+ uint8 c2 = s_pingPong.getCountIncrBeforeFunding();
+ assertEq(c2, c + 1);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/applications/TokenProxy.t.sol b/contracts/src/v0.8/ccip/test/applications/TokenProxy.t.sol
new file mode 100644
index 00000000000..9e78f6e369f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/applications/TokenProxy.t.sol
@@ -0,0 +1,211 @@
+// SPDX-License-Identifier: MIT
+pragma solidity 0.8.24;
+
+import {TokenProxy} from "../../applications/TokenProxy.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {EVM2EVMOnRamp} from "../../onRamp/EVM2EVMOnRamp.sol";
+import {EVM2EVMOnRampSetup} from "../onRamp/EVM2EVMOnRampSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract TokenProxySetup is EVM2EVMOnRampSetup {
+ TokenProxy internal s_tokenProxy;
+ IERC20 internal s_feeToken;
+ IERC20 internal s_transferToken;
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ s_feeToken = IERC20(s_sourceTokens[0]);
+ s_transferToken = IERC20(s_sourceTokens[1]);
+ s_tokenProxy = new TokenProxy(address(s_sourceRouter), address(s_transferToken));
+
+ s_transferToken.approve(address(s_tokenProxy), type(uint256).max);
+ s_feeToken.approve(address(s_tokenProxy), type(uint256).max);
+ }
+}
+
+contract TokenProxy_constructor is TokenProxySetup {
+ function test_Constructor() public view {
+ assertEq(address(s_tokenProxy.getRouter()), address(s_sourceRouter));
+ assertEq(address(s_tokenProxy.getToken()), address(s_transferToken));
+ }
+}
+
+contract TokenProxy_getFee is TokenProxySetup {
+ function test_GetFee_Success() public view {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(s_tokenProxy),
+ data: "",
+ tokenAmounts: tokens,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}))
+ });
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ uint256 actualFee = s_tokenProxy.getFee(DEST_CHAIN_SELECTOR, message);
+ assertEq(expectedFee, actualFee);
+ }
+
+ // Reverts
+
+ function test_GetFeeInvalidToken_Revert() public {
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(s_tokenProxy),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}))
+ });
+
+ vm.expectRevert(TokenProxy.InvalidToken.selector);
+
+ s_tokenProxy.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_GetFeeNoDataAllowed_Revert() public {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(s_tokenProxy),
+ data: "not empty",
+ tokenAmounts: tokens,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}))
+ });
+
+ vm.expectRevert(TokenProxy.NoDataAllowed.selector);
+
+ s_tokenProxy.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_GetFeeGasShouldBeZero_Revert() public {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(s_tokenProxy),
+ data: "",
+ tokenAmounts: tokens,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 10}))
+ });
+
+ vm.expectRevert(TokenProxy.GasShouldBeZero.selector);
+
+ s_tokenProxy.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+}
+
+contract TokenProxy_ccipSend is TokenProxySetup {
+ function test_CcipSend_Success() public {
+ vm.pauseGasMetering();
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = tokens;
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}));
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+
+ s_feeToken.approve(address(s_tokenProxy), expectedFee);
+
+ Internal.EVM2EVMMessage memory msgEvent = _messageToEvent(message, 1, 1, expectedFee, OWNER);
+ msgEvent.sender = address(s_tokenProxy);
+ msgEvent.messageId = Internal._hash(msgEvent, s_metadataHash);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ s_tokenProxy.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_CcipSendNative_Success() public {
+ vm.pauseGasMetering();
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = tokens;
+ message.feeToken = address(0);
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}));
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+
+ Internal.EVM2EVMMessage memory msgEvent = _messageToEvent(message, 1, 1, expectedFee, OWNER);
+ msgEvent.sender = address(s_tokenProxy);
+ msgEvent.feeToken = s_sourceRouter.getWrappedNative();
+ msgEvent.messageId = Internal._hash(msgEvent, s_metadataHash);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ s_tokenProxy.ccipSend{value: expectedFee}(DEST_CHAIN_SELECTOR, message);
+ }
+
+ // Reverts
+
+ function test_CcipSendInsufficientAllowance_Revert() public {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = tokens;
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}));
+
+ // Revoke allowance
+ s_transferToken.approve(address(s_tokenProxy), 0);
+
+ vm.expectRevert("ERC20: insufficient allowance");
+
+ s_tokenProxy.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_CcipSendInvalidToken_Revert() public {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_feeToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = tokens;
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}));
+
+ vm.expectRevert(TokenProxy.InvalidToken.selector);
+
+ s_tokenProxy.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_CcipSendNoDataAllowed_Revert() public {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = tokens;
+ message.data = "not empty";
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 0}));
+
+ vm.expectRevert(TokenProxy.NoDataAllowed.selector);
+
+ s_tokenProxy.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_CcipSendGasShouldBeZero_Revert() public {
+ Client.EVMTokenAmount[] memory tokens = new Client.EVMTokenAmount[](1);
+ tokens[0] = Client.EVMTokenAmount({token: address(s_transferToken), amount: 1e18});
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = tokens;
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 1}));
+
+ vm.expectRevert(TokenProxy.GasShouldBeZero.selector);
+
+ s_tokenProxy.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/arm/ARMProxy.t.sol b/contracts/src/v0.8/ccip/test/arm/ARMProxy.t.sol
new file mode 100644
index 00000000000..24b617c82a0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/arm/ARMProxy.t.sol
@@ -0,0 +1,43 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IRMN} from "../../interfaces/IRMN.sol";
+
+import {ARMProxy} from "../../ARMProxy.sol";
+import {RMN} from "../../RMN.sol";
+import {MockRMN} from "../mocks/MockRMN.sol";
+import {RMNSetup, makeSubjects} from "./RMNSetup.t.sol";
+
+contract ARMProxyTest is RMNSetup {
+ MockRMN internal s_mockRMN;
+ ARMProxy internal s_armProxy;
+
+ function setUp() public virtual override {
+ RMNSetup.setUp();
+ s_mockRMN = new MockRMN();
+ s_armProxy = new ARMProxy(address(s_rmn));
+ }
+
+ function test_ARMIsCursed_Success() public {
+ s_armProxy.setARM(address(s_mockRMN));
+ assertFalse(IRMN(address(s_armProxy)).isCursed());
+ s_mockRMN.setGlobalCursed(true);
+ assertTrue(IRMN(address(s_armProxy)).isCursed());
+ }
+
+ function test_ARMIsBlessed_Success() public {
+ s_armProxy.setARM(address(s_mockRMN));
+ s_mockRMN.setTaggedRootBlessed(IRMN.TaggedRoot({commitStore: address(0), root: bytes32(0)}), true);
+ assertTrue(IRMN(address(s_armProxy)).isBlessed(IRMN.TaggedRoot({commitStore: address(0), root: bytes32(0)})));
+ s_mockRMN.setTaggedRootBlessed(IRMN.TaggedRoot({commitStore: address(0), root: bytes32(0)}), false);
+ assertFalse(IRMN(address(s_armProxy)).isBlessed(IRMN.TaggedRoot({commitStore: address(0), root: bytes32(0)})));
+ }
+
+ function test_ARMCallRevertReasonForwarded() public {
+ bytes memory err = bytes("revert");
+ s_mockRMN.setIsCursedRevert(err);
+ s_armProxy.setARM(address(s_mockRMN));
+ vm.expectRevert(abi.encodeWithSelector(MockRMN.CustomError.selector, err));
+ IRMN(address(s_armProxy)).isCursed();
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/arm/ARMProxy_standalone.t.sol b/contracts/src/v0.8/ccip/test/arm/ARMProxy_standalone.t.sol
new file mode 100644
index 00000000000..4f3e96fafa2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/arm/ARMProxy_standalone.t.sol
@@ -0,0 +1,78 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ARMProxy} from "../../ARMProxy.sol";
+import {Test} from "forge-std/Test.sol";
+
+contract ARMProxyStandaloneTest is Test {
+ address internal constant EMPTY_ADDRESS = address(0x1);
+ address internal constant OWNER_ADDRESS = 0xC0ffeeEeC0fFeeeEc0ffeEeEc0ffEEEEC0FfEEee;
+ address internal constant MOCK_RMN_ADDRESS = 0x1337133713371337133713371337133713371337;
+
+ ARMProxy internal s_armProxy;
+
+ function setUp() public virtual {
+ // needed so that the extcodesize check in ARMProxy.fallback doesn't revert
+ vm.etch(MOCK_RMN_ADDRESS, bytes("fake bytecode"));
+
+ vm.prank(OWNER_ADDRESS);
+ s_armProxy = new ARMProxy(MOCK_RMN_ADDRESS);
+ }
+
+ function test_Constructor() public {
+ vm.expectEmit();
+ emit ARMProxy.ARMSet(MOCK_RMN_ADDRESS);
+ ARMProxy proxy = new ARMProxy(MOCK_RMN_ADDRESS);
+ assertEq(proxy.getARM(), MOCK_RMN_ADDRESS);
+ }
+
+ function test_SetARM() public {
+ vm.expectEmit();
+ emit ARMProxy.ARMSet(MOCK_RMN_ADDRESS);
+ vm.prank(OWNER_ADDRESS);
+ s_armProxy.setARM(MOCK_RMN_ADDRESS);
+ assertEq(s_armProxy.getARM(), MOCK_RMN_ADDRESS);
+ }
+
+ function test_SetARMzero() public {
+ vm.expectRevert(abi.encodeWithSelector(ARMProxy.ZeroAddressNotAllowed.selector));
+ vm.prank(OWNER_ADDRESS);
+ s_armProxy.setARM(address(0x0));
+ }
+
+ /*
+ function test_Fuzz_ARMCall(bool expectedSuccess, bytes memory call, bytes memory ret) public {
+ // filter out calls to functions that will be handled on the ARMProxy instead
+ // of the underlying ARM contract
+ vm.assume(
+ call.length < 4 ||
+ (bytes4(call) != s_armProxy.getARM.selector &&
+ bytes4(call) != s_armProxy.setARM.selector &&
+ bytes4(call) != s_armProxy.owner.selector &&
+ bytes4(call) != s_armProxy.acceptOwnership.selector &&
+ bytes4(call) != s_armProxy.transferOwnership.selector &&
+ bytes4(call) != s_armProxy.typeAndVersion.selector)
+ );
+
+ if (expectedSuccess) {
+ vm.mockCall(MOCK_RMN_ADDRESS, 0, call, ret);
+ } else {
+ vm.mockCallRevert(MOCK_RMN_ADDRESS, 0, call, ret);
+ }
+ (bool actualSuccess, bytes memory result) = address(s_armProxy).call(call);
+ vm.clearMockedCalls();
+
+ assertEq(result, ret);
+ assertEq(expectedSuccess, actualSuccess);
+ }
+ */
+
+ function test_ARMCallEmptyContractRevert() public {
+ vm.prank(OWNER_ADDRESS);
+ s_armProxy.setARM(EMPTY_ADDRESS); // No code at address 1, should revert.
+ vm.expectRevert();
+ bytes memory b = new bytes(0);
+ (bool success,) = address(s_armProxy).call(b);
+ success;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/arm/RMN.t.sol b/contracts/src/v0.8/ccip/test/arm/RMN.t.sol
new file mode 100644
index 00000000000..d3237592f29
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/arm/RMN.t.sol
@@ -0,0 +1,1068 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IRMN} from "../../interfaces/IRMN.sol";
+
+import {GLOBAL_CURSE_SUBJECT, LIFT_CURSE_VOTE_ADDR, OWNER_CURSE_VOTE_ADDR, RMN} from "../../RMN.sol";
+import {RMNSetup, makeCursesHash, makeSubjects} from "./RMNSetup.t.sol";
+
+import {Test} from "forge-std/Test.sol";
+
+bytes28 constant GARBAGE_CURSES_HASH = bytes28(keccak256("GARBAGE_CURSES_HASH"));
+
+contract ConfigCompare is Test {
+ function assertConfigEq(RMN.Config memory actualConfig, RMN.Config memory expectedConfig) public pure {
+ assertEq(actualConfig.voters.length, expectedConfig.voters.length);
+ for (uint256 i = 0; i < expectedConfig.voters.length; ++i) {
+ RMN.Voter memory expectedVoter = expectedConfig.voters[i];
+ RMN.Voter memory actualVoter = actualConfig.voters[i];
+ assertEq(actualVoter.blessVoteAddr, expectedVoter.blessVoteAddr);
+ assertEq(actualVoter.curseVoteAddr, expectedVoter.curseVoteAddr);
+ assertEq(actualVoter.blessWeight, expectedVoter.blessWeight);
+ assertEq(actualVoter.curseWeight, expectedVoter.curseWeight);
+ }
+ assertEq(actualConfig.blessWeightThreshold, expectedConfig.blessWeightThreshold);
+ assertEq(actualConfig.curseWeightThreshold, expectedConfig.curseWeightThreshold);
+ }
+}
+
+contract RMN_constructor is ConfigCompare, RMNSetup {
+ function test_Constructor_Success() public view {
+ RMN.Config memory expectedConfig = rmnConstructorArgs();
+ (uint32 actualVersion,, RMN.Config memory actualConfig) = s_rmn.getConfigDetails();
+ assertEq(actualVersion, 1);
+ assertConfigEq(actualConfig, expectedConfig);
+ }
+}
+
+contract RMN_voteToBless is RMNSetup {
+ function _getFirstBlessVoterAndWeight() internal pure returns (address, uint8) {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ return (cfg.voters[0].blessVoteAddr, cfg.voters[0].blessWeight);
+ }
+
+ // Success
+
+ function test_RootSuccess() public {
+ uint256 numRoots = 10;
+
+ (address voter, uint8 voterWeight) = _getFirstBlessVoterAndWeight();
+
+ for (uint256 i = 1; i <= numRoots; ++i) {
+ vm.expectEmit();
+ emit RMN.VotedToBless(1, voter, makeTaggedRoot(i), voterWeight);
+ }
+
+ vm.prank(voter);
+ s_rmn.voteToBless(makeTaggedRootsInclusive(1, numRoots));
+
+ for (uint256 i = 1; i <= numRoots; ++i) {
+ assertFalse(s_rmn.isBlessed(makeTaggedRoot(i)));
+ assertEq(voterWeight, getWeightOfVotesToBlessRoot(makeTaggedRoot(i)));
+ assertTrue(hasVotedToBlessRoot(voter, makeTaggedRoot(1)));
+ }
+ }
+
+ // Reverts
+
+ function test_SenderAlreadyVoted_Revert() public {
+ (address voter,) = _getFirstBlessVoterAndWeight();
+
+ vm.startPrank(voter);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ assertTrue(hasVotedToBlessRoot(voter, makeTaggedRoot(1)));
+
+ uint256 votesToBlessBefore = getWeightOfVotesToBlessRoot(makeTaggedRoot(1));
+ vm.expectRevert(RMN.VoteToBlessNoop.selector);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ assertEq(votesToBlessBefore, getWeightOfVotesToBlessRoot(makeTaggedRoot(1)));
+ }
+
+ function test_IsAlreadyBlessed_Revert() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+
+ // Bless voters 2,3,4 vote to bless
+ for (uint256 i = 1; i < cfg.voters.length; i++) {
+ vm.startPrank(cfg.voters[i].blessVoteAddr);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ }
+
+ uint256 votesToBlessBefore = getWeightOfVotesToBlessRoot(makeTaggedRoot(1));
+ vm.startPrank(cfg.voters[0].blessVoteAddr);
+ vm.expectRevert(RMN.VoteToBlessNoop.selector);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ assertEq(votesToBlessBefore, getWeightOfVotesToBlessRoot(makeTaggedRoot(1)));
+ }
+
+ function test_Curse_Revert() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+
+ for (uint256 i = 0; i < cfg.voters.length; i++) {
+ vm.startPrank(cfg.voters[i].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(i), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+
+ vm.startPrank(cfg.voters[0].blessVoteAddr);
+ vm.expectRevert(RMN.VoteToBlessForbiddenDuringActiveGlobalCurse.selector);
+ s_rmn.voteToBless(makeTaggedRootSingleton(12903));
+ }
+
+ function test_UnauthorizedVoter_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(RMN.UnauthorizedVoter.selector, STRANGER));
+ s_rmn.voteToBless(makeTaggedRootSingleton(12321));
+ }
+}
+
+contract RMN_ownerUnbless is RMNSetup {
+ function test_Unbless_Success() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ vm.startPrank(cfg.voters[i].blessVoteAddr);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ }
+ assertTrue(s_rmn.isBlessed(makeTaggedRoot(1)));
+
+ vm.startPrank(OWNER);
+ s_rmn.ownerResetBlessVotes(makeTaggedRootSingleton(1));
+ assertFalse(s_rmn.isBlessed(makeTaggedRoot(1)));
+ }
+}
+
+contract RMN_unvoteToCurse is RMNSetup {
+ uint256 internal s_curser;
+ bytes28 internal s_cursesHash;
+
+ function setUp() public override {
+ RMNSetup.setUp();
+ RMN.Config memory cfg = rmnConstructorArgs();
+
+ s_curser = 0;
+ vm.startPrank(cfg.voters[s_curser].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ bytes28 expectedCursesHash = makeCursesHash(makeCurseId(1));
+ assertFalse(s_rmn.isCursed());
+ (address[] memory cursers, bytes28[] memory cursesHashes, uint16 weight, bool cursed) = s_rmn.getCurseProgress(0);
+ assertEq(1, cursers.length);
+ assertEq(cfg.voters[s_curser].curseVoteAddr, cursers[0]);
+ assertEq(cfg.voters[s_curser].curseWeight, weight);
+ assertEq(1, cursesHashes.length);
+ assertEq(expectedCursesHash, cursesHashes[0]);
+ assertFalse(cursed);
+
+ s_cursesHash = expectedCursesHash;
+ }
+
+ function test_UnauthorizedVoter() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ // Someone else cannot unvote to curse on the curser's behalf.
+ address[] memory unauthorized = new address[](3);
+ unauthorized[0] = cfg.voters[s_curser].blessVoteAddr;
+ unauthorized[1] = cfg.voters[s_curser ^ 1].blessVoteAddr;
+ unauthorized[2] = OWNER;
+
+ for (uint256 i = 0; i < unauthorized.length; ++i) {
+ bytes memory expectedRevert = abi.encodeWithSelector(RMN.UnauthorizedVoter.selector, unauthorized[i]);
+ vm.startPrank(unauthorized[i]);
+ {
+ // should fail when using the correct curses hash
+ RMN.UnvoteToCurseRequest[] memory reqs = new RMN.UnvoteToCurseRequest[](1);
+ reqs[0] = RMN.UnvoteToCurseRequest({subject: 0, cursesHash: s_cursesHash});
+ vm.expectRevert(expectedRevert);
+ s_rmn.unvoteToCurse(reqs);
+ }
+ {
+ // should fail when using garbage curses hash
+ RMN.UnvoteToCurseRequest[] memory reqs = new RMN.UnvoteToCurseRequest[](1);
+ reqs[0] = RMN.UnvoteToCurseRequest({subject: 0, cursesHash: GARBAGE_CURSES_HASH});
+ vm.expectRevert(expectedRevert);
+ s_rmn.unvoteToCurse(reqs);
+ }
+ }
+ }
+
+ function test_InvalidCursesHash() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ vm.startPrank(cfg.voters[s_curser].curseVoteAddr);
+ RMN.UnvoteToCurseRequest[] memory reqs = new RMN.UnvoteToCurseRequest[](1);
+ reqs[0] = RMN.UnvoteToCurseRequest({subject: 0, cursesHash: GARBAGE_CURSES_HASH});
+ vm.expectRevert(RMN.UnvoteToCurseNoop.selector);
+ s_rmn.unvoteToCurse(reqs);
+ }
+
+ function test_ValidCursesHash() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ vm.startPrank(cfg.voters[s_curser].curseVoteAddr);
+ RMN.UnvoteToCurseRequest[] memory reqs = new RMN.UnvoteToCurseRequest[](1);
+ reqs[0] = RMN.UnvoteToCurseRequest({subject: 0, cursesHash: s_cursesHash});
+ s_rmn.unvoteToCurse(reqs); // succeeds
+ }
+
+ function test_OwnerSucceeds() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ vm.startPrank(OWNER);
+ RMN.OwnerUnvoteToCurseRequest[] memory reqs = new RMN.OwnerUnvoteToCurseRequest[](1);
+ reqs[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: cfg.voters[s_curser].curseVoteAddr,
+ unit: RMN.UnvoteToCurseRequest({subject: 0, cursesHash: s_cursesHash}),
+ forceUnvote: false
+ });
+ s_rmn.ownerUnvoteToCurse(reqs);
+ }
+
+ function test_OwnerSkips() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ vm.startPrank(OWNER);
+ RMN.OwnerUnvoteToCurseRequest[] memory reqs = new RMN.OwnerUnvoteToCurseRequest[](1);
+ reqs[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: cfg.voters[s_curser].curseVoteAddr,
+ unit: RMN.UnvoteToCurseRequest({subject: 0, cursesHash: GARBAGE_CURSES_HASH}),
+ forceUnvote: false
+ });
+
+ vm.expectEmit();
+ emit RMN.SkippedUnvoteToCurse(cfg.voters[s_curser].curseVoteAddr, 0, s_cursesHash, GARBAGE_CURSES_HASH);
+ vm.expectRevert(RMN.UnvoteToCurseNoop.selector);
+ s_rmn.ownerUnvoteToCurse(reqs);
+ }
+
+ function test_VotersCantLiftCurseButOwnerCan() public {
+ vm.stopPrank();
+ RMN.Config memory cfg = rmnConstructorArgs();
+ // s_curser has voted to curse during setUp
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(accWeight, cfg.voters[s_curser].curseWeight);
+ assertFalse(cursed);
+ assertEq(voters.length, 1);
+ assertEq(cursesHashes.length, 1);
+ assertEq(voters[0], cfg.voters[s_curser].curseVoteAddr);
+ assertEq(cursesHashes[0], makeCursesHash(makeCurseId(1)));
+ }
+ // everyone else votes now, same curse id, same subject
+ {
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ if (i == s_curser) continue; // already voted to curse
+ vm.prank(cfg.voters[i].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+ }
+ // subject must be cursed now
+ {
+ assertTrue(s_rmn.isCursed(0));
+ }
+ // curse progress should be as full as it can get
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ uint256 allWeights;
+ for (uint256 i = 0; i < cfg.voters.length; i++) {
+ allWeights += cfg.voters[i].curseWeight;
+ }
+ assertEq(accWeight, allWeights);
+ assertTrue(cursed);
+ assertEq(voters.length, cfg.voters.length);
+ assertEq(cursesHashes.length, cfg.voters.length);
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ assertEq(voters[i], cfg.voters[i].curseVoteAddr);
+ assertEq(cursesHashes[i], makeCursesHash(makeCurseId(1)));
+ }
+ }
+ // everyone unvotes to curse, successfully
+ {
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ vm.prank(cfg.voters[i].curseVoteAddr);
+ RMN.UnvoteToCurseRequest[] memory reqs = new RMN.UnvoteToCurseRequest[](1);
+ reqs[0] = RMN.UnvoteToCurseRequest({subject: 0, cursesHash: makeCursesHash(makeCurseId(1))});
+ s_rmn.unvoteToCurse(reqs);
+ }
+ }
+ // curse should still be in place as only the owner can lift it
+ {
+ assertTrue(s_rmn.isCursed(0));
+ }
+ // curse progress should be empty, expect for the cursed flag
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(accWeight, 0);
+ assertTrue(cursed);
+ assertEq(voters.length, 0);
+ assertEq(cursesHashes.length, 0);
+ }
+ // owner lifts curse
+ {
+ RMN.OwnerUnvoteToCurseRequest[] memory ownerReq = new RMN.OwnerUnvoteToCurseRequest[](1);
+ ownerReq[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: LIFT_CURSE_VOTE_ADDR,
+ unit: RMN.UnvoteToCurseRequest({subject: 0, cursesHash: 0}),
+ forceUnvote: false
+ });
+ vm.prank(OWNER);
+ s_rmn.ownerUnvoteToCurse(ownerReq);
+ }
+ // curse should now be lifted
+ {
+ assertFalse(s_rmn.isCursed(0));
+ }
+ }
+}
+
+contract RMN_voteToCurse_2 is RMNSetup {
+ function initialConfig() internal pure returns (RMN.Config memory) {
+ RMN.Config memory cfg = RMN.Config({voters: new RMN.Voter[](3), blessWeightThreshold: 1, curseWeightThreshold: 3});
+ cfg.voters[0] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_1, curseVoteAddr: CURSE_VOTER_1, blessWeight: 1, curseWeight: 1});
+ cfg.voters[1] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_2, curseVoteAddr: CURSE_VOTER_2, blessWeight: 1, curseWeight: 1});
+ cfg.voters[2] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_3, curseVoteAddr: CURSE_VOTER_3, blessWeight: 1, curseWeight: 1});
+ return cfg;
+ }
+
+ function setUp() public override {
+ vm.prank(OWNER);
+ s_rmn = new RMN(initialConfig());
+ }
+
+ function test_VotesAreDroppedIfSubjectIsNotCursedDuringConfigChange() public {
+ // vote to curse the subject from an insufficient number of voters, one voter
+ {
+ RMN.Config memory cfg = initialConfig();
+ vm.prank(cfg.voters[0].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+ // vote must be in place
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, 1);
+ assertEq(cursesHashes.length, 1);
+ assertEq(accWeight, 1);
+ assertFalse(cursed);
+ }
+ // change config to include only the first voter, i.e., initialConfig().voters[0]
+ {
+ RMN.Config memory cfg = initialConfig();
+ RMN.Voter[] memory voters = cfg.voters;
+ assembly {
+ mstore(voters, 1)
+ }
+ cfg.curseWeightThreshold = 1;
+ vm.prank(OWNER);
+ s_rmn.setConfig(cfg);
+ }
+ // vote must be dropped
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, 0);
+ assertEq(cursesHashes.length, 0);
+ assertEq(accWeight, 0);
+ assertFalse(cursed);
+ }
+ // cause an owner curse now
+ {
+ vm.prank(OWNER);
+ s_rmn.ownerCurse(makeCurseId(1), makeSubjects(0));
+ }
+ // only the owner curse must be visible
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, 1);
+ assertEq(voters[0], OWNER_CURSE_VOTE_ADDR);
+ assertEq(cursesHashes.length, 1);
+ assertEq(cursesHashes[0], makeCursesHash(makeCurseId(1)));
+ assertEq(accWeight, 0);
+ assertTrue(cursed);
+ }
+ }
+
+ function test_VotesAreRetainedIfSubjectIsCursedDuringConfigChange() public {
+ uint256 numVotersInitially = initialConfig().voters.length;
+ // curse the subject with votes from all voters
+ {
+ RMN.Config memory cfg = initialConfig();
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ vm.prank(cfg.voters[i].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+ }
+ // subject is now cursed
+ {
+ assertTrue(s_rmn.isCursed(0));
+ }
+ // throw in an owner curse
+ {
+ vm.prank(OWNER);
+ s_rmn.ownerCurse(makeCurseId(1), makeSubjects(0));
+ }
+
+ uint256 snapshot = vm.snapshot();
+
+ for (uint256 keepVoters = 1; keepVoters <= numVotersInitially; ++keepVoters) {
+ vm.revertTo(snapshot);
+
+ // change config to include only the first #keepVoters voters, i.e., initialConfig().voters[0..keepVoters]
+ {
+ RMN.Config memory cfg = initialConfig();
+ RMN.Voter[] memory voters = cfg.voters;
+ assembly {
+ mstore(voters, keepVoters)
+ }
+ cfg.curseWeightThreshold = uint16(keepVoters);
+ vm.prank(OWNER);
+ s_rmn.setConfig(cfg);
+ }
+ // subject is still cursed
+ {
+ assertTrue(s_rmn.isCursed(0));
+ }
+ // all votes from the first keepVoters & owner must be present
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint16 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, keepVoters + 1 /* owner */ );
+ assertEq(cursesHashes.length, keepVoters + 1 /* owner */ );
+ assertEq(accWeight, keepVoters /* 1 per voter */ );
+ assertTrue(cursed);
+ for (uint256 i = 0; i < keepVoters; ++i) {
+ assertEq(voters[i], initialConfig().voters[i].curseVoteAddr);
+ assertEq(cursesHashes[i], makeCursesHash(makeCurseId(1)));
+ }
+ assertEq(voters[voters.length - 1], OWNER_CURSE_VOTE_ADDR);
+ assertEq(cursesHashes[cursesHashes.length - 1], makeCursesHash(makeCurseId(1)));
+ }
+ // the owner unvoting for all is not enough to lift the curse, because remember that the owner has an active vote
+ // also
+ {
+ for (uint256 i = 0; i < keepVoters; ++i) {
+ RMN.OwnerUnvoteToCurseRequest[] memory ownerReq = new RMN.OwnerUnvoteToCurseRequest[](1);
+ ownerReq[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: initialConfig().voters[i].curseVoteAddr,
+ unit: RMN.UnvoteToCurseRequest({subject: 0, cursesHash: makeCursesHash(makeCurseId(1))}),
+ forceUnvote: false
+ });
+ vm.prank(OWNER);
+ s_rmn.ownerUnvoteToCurse(ownerReq);
+
+ assertTrue(s_rmn.isCursed(0));
+ }
+ }
+ // after owner unvotes for themselves, finally, the curse will be lifted
+ {
+ RMN.OwnerUnvoteToCurseRequest[] memory ownerReq = new RMN.OwnerUnvoteToCurseRequest[](1);
+ ownerReq[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: OWNER_CURSE_VOTE_ADDR,
+ unit: RMN.UnvoteToCurseRequest({subject: 0, cursesHash: makeCursesHash(makeCurseId(1))}),
+ forceUnvote: false
+ });
+ vm.prank(OWNER);
+ s_rmn.ownerUnvoteToCurse(ownerReq);
+
+ assertFalse(s_rmn.isCursed(0));
+ }
+ }
+ }
+}
+
+contract RMN_voteToCurse is RMNSetup {
+ function _getFirstCurseVoterAndWeight() internal pure returns (address, uint8) {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ return (cfg.voters[0].curseVoteAddr, cfg.voters[0].curseWeight);
+ }
+
+ // Success
+
+ function test_CurseOnlyWhenThresholdReached_Success() public {
+ uint256 numSubjects = 3;
+ uint256 maxNumRevotes = 2;
+
+ RMN.Config memory cfg = rmnConstructorArgs();
+ bytes16[] memory subjects = new bytes16[](numSubjects);
+ for (uint256 i = 0; i < numSubjects; ++i) {
+ subjects[i] = bytes16(uint128(i));
+ }
+ for (uint256 numRevotes = 1; numRevotes <= maxNumRevotes; ++numRevotes) {
+ // all voters but the last vote, but can't surpass the curse weight threshold
+ for (uint256 i = 0; i < cfg.voters.length - 1; ++i) {
+ vm.prank(cfg.voters[i].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(numRevotes), subjects);
+ }
+ // no curse is yet active, last voter also needs to vote for any curse to be active
+ {
+ // ensure every subject is not cursed
+ for (uint256 i = 0; i < numSubjects; ++i) {
+ assertFalse(s_rmn.isCursed(subjects[i]));
+ }
+ // ensure every vote has been recorded
+ assertEq(
+ s_rmn.getRecordedCurseRelatedOpsCount(),
+ 1 /* setConfig */ + (cfg.voters.length - 1) * numRevotes * numSubjects
+ );
+ }
+ }
+
+ // last voter now votes
+ vm.prank(cfg.voters[cfg.voters.length - 1].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(0), subjects);
+ // curses should be now active
+ {
+ // ensure every subject is now cursed
+ for (uint256 i = 0; i < numSubjects; ++i) {
+ assertTrue(s_rmn.isCursed(subjects[i]));
+ }
+ // ensure every vote has been recorded
+ assertEq(
+ s_rmn.getRecordedCurseRelatedOpsCount(),
+ 1 /* setConfig */ + ((cfg.voters.length - 1) * maxNumRevotes + 1) * numSubjects
+ );
+ }
+ }
+
+ function test_VoteToCurse_NoCurse_Success() public {
+ (address voter, uint8 weight) = _getFirstCurseVoterAndWeight();
+ vm.startPrank(voter);
+ vm.expectEmit();
+ emit RMN.VotedToCurse(
+ 1, // configVersion
+ voter,
+ GLOBAL_CURSE_SUBJECT,
+ makeCurseId(123),
+ weight,
+ 1234567890, // blockTimestamp
+ makeCursesHash(makeCurseId(123)), // cursesHash
+ weight
+ );
+
+ s_rmn.voteToCurse(makeCurseId(123), makeSubjects(GLOBAL_CURSE_SUBJECT));
+
+ (address[] memory voters,, uint16 votes, bool cursed) = s_rmn.getCurseProgress(GLOBAL_CURSE_SUBJECT);
+ assertEq(1, voters.length);
+ assertEq(voter, voters[0]);
+ assertEq(weight, votes);
+ assertFalse(cursed);
+ }
+
+ function test_VoteToCurse_YesCurse_Success() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ for (uint256 i = 0; i < cfg.voters.length - 1; ++i) {
+ vm.startPrank(cfg.voters[i].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+
+ vm.expectEmit();
+ emit RMN.Cursed(1, 0, uint64(block.timestamp));
+
+ vm.startPrank(cfg.voters[cfg.voters.length - 1].curseVoteAddr);
+ vm.resumeGasMetering();
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+
+ function test_EvenIfAlreadyCursed_Success() public {
+ RMN.Config memory cfg = rmnConstructorArgs();
+ uint16 weightSum = 0;
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ vm.startPrank(cfg.voters[i].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(i), makeSubjects(0));
+ weightSum += cfg.voters[i].curseWeight;
+ }
+
+ // Not part of the assertion of this test but good to have as a sanity
+ // check. We want a curse to be active in order for the ultimate assertion
+ // to make sense.
+ assert(s_rmn.isCursed(0));
+
+ vm.expectEmit();
+ emit RMN.VotedToCurse(
+ 1, // configVersion
+ cfg.voters[cfg.voters.length - 1].curseVoteAddr,
+ 0, // subject
+ makeCurseId(cfg.voters.length + 1), // this curse id
+ cfg.voters[cfg.voters.length - 1].curseWeight,
+ uint64(block.timestamp), // blockTimestamp
+ makeCursesHash(makeCurseId(cfg.voters.length - 1), makeCurseId(cfg.voters.length + 1)), // cursesHash
+ weightSum // accumulatedWeight
+ );
+ // Asserts that this call to vote with a new curse id goes through with no
+ // reverts even when the RMN contract is cursed.
+ s_rmn.voteToCurse(makeCurseId(cfg.voters.length + 1), makeSubjects(0));
+ }
+
+ function test_OwnerCanCurseAndUncurse() public {
+ vm.startPrank(OWNER);
+ bytes28 expectedCursesHash = makeCursesHash(makeCurseId(0));
+ vm.expectEmit();
+ emit RMN.VotedToCurse(
+ 1, // configVersion
+ OWNER_CURSE_VOTE_ADDR, // owner
+ 0, // subject
+ makeCurseId(0), // curse id
+ 0, // weight
+ uint64(block.timestamp), // blockTimestamp
+ expectedCursesHash, // cursesHash
+ 0 // accumulatedWeight
+ );
+ vm.expectEmit();
+ emit RMN.Cursed(
+ 1, // configVersion
+ 0, // subject
+ uint64(block.timestamp) // blockTimestamp
+ );
+ s_rmn.ownerCurse(makeCurseId(0), makeSubjects(0));
+
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint24 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, 1);
+ assertEq(voters[0], OWNER_CURSE_VOTE_ADDR /* owner */ );
+ assertEq(cursesHashes.length, 1);
+ assertEq(cursesHashes[0], expectedCursesHash);
+ assertEq(accWeight, 0);
+ assertTrue(cursed);
+ }
+
+ // ownerCurse again, should cause a vote to appear and a change in curses hash
+ expectedCursesHash = makeCursesHash(makeCurseId(0), makeCurseId(1));
+ vm.expectEmit();
+ emit RMN.VotedToCurse(
+ 1, // configVersion
+ OWNER_CURSE_VOTE_ADDR, // owner
+ 0, // subject
+ makeCurseId(1), // curse id
+ 0, // weight
+ uint64(block.timestamp), // blockTimestamp
+ expectedCursesHash, // cursesHash
+ 0 // accumulatedWeight
+ );
+ s_rmn.ownerCurse(makeCurseId(1), makeSubjects(0));
+
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint24 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, 1);
+ assertEq(voters[0], OWNER_CURSE_VOTE_ADDR /* owner */ );
+ assertEq(cursesHashes.length, 1);
+ assertEq(cursesHashes[0], expectedCursesHash);
+ assertEq(accWeight, 0);
+ assertTrue(cursed);
+ }
+
+ RMN.OwnerUnvoteToCurseRequest[] memory unvoteReqs = new RMN.OwnerUnvoteToCurseRequest[](1);
+ unvoteReqs[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: OWNER_CURSE_VOTE_ADDR,
+ unit: RMN.UnvoteToCurseRequest({subject: 0, cursesHash: 0}),
+ forceUnvote: true // TODO: test with forceUnvote false also
+ });
+ vm.expectEmit();
+ emit RMN.CurseLifted(0);
+ s_rmn.ownerUnvoteToCurse(unvoteReqs);
+ {
+ (address[] memory voters, bytes28[] memory cursesHashes, uint24 accWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(voters.length, 0);
+ assertEq(cursesHashes.length, 0);
+ assertEq(accWeight, 0);
+ assertFalse(cursed);
+ }
+ }
+
+ // Reverts
+
+ function test_UnauthorizedVoter_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(abi.encodeWithSelector(RMN.UnauthorizedVoter.selector, STRANGER));
+ s_rmn.voteToCurse(makeCurseId(12312), makeSubjects(0));
+ }
+
+ function test_ReusedCurseId_Revert() public {
+ (address voter,) = _getFirstCurseVoterAndWeight();
+ vm.startPrank(voter);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+
+ vm.expectRevert(abi.encodeWithSelector(RMN.ReusedCurseId.selector, voter, makeCurseId(1)));
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+
+ function test_RepeatedSubject_Revert() public {
+ (address voter,) = _getFirstCurseVoterAndWeight();
+ vm.prank(voter);
+
+ bytes16 subject = bytes16(uint128(1));
+
+ vm.expectRevert(RMN.SubjectsMustBeStrictlyIncreasing.selector);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(subject, subject));
+ }
+
+ function test_EmptySubjects_Revert() public {
+ (address voter,) = _getFirstCurseVoterAndWeight();
+ vm.prank(voter);
+
+ vm.expectRevert(RMN.VoteToCurseNoop.selector);
+ s_rmn.voteToCurse(makeCurseId(1), new bytes16[](0));
+ }
+}
+
+contract RMN_ownerUnvoteToCurse is RMNSetup {
+ // These cursers are going to curse in setUp curseCount times.
+ function getCursersAndCurseCounts() internal pure returns (address[] memory cursers, uint32[] memory curseCounts) {
+ // NOTE: Change this when changing setUp or rmnConstructorArgs.
+ // This is a bit ugly and error prone but if we read from storage we would
+ // not get an accurate gas reading for ownerUnvoteToCurse when we need it.
+ cursers = new address[](4);
+ cursers[0] = CURSE_VOTER_1;
+ cursers[1] = CURSE_VOTER_2;
+ cursers[2] = CURSE_VOTER_3;
+ cursers[3] = CURSE_VOTER_4;
+ curseCounts = new uint32[](cursers.length);
+ for (uint256 i = 0; i < cursers.length; ++i) {
+ curseCounts[i] = 1;
+ }
+ }
+
+ function setUp() public virtual override {
+ RMNSetup.setUp();
+ (address[] memory cursers, uint32[] memory curseCounts) = getCursersAndCurseCounts();
+ for (uint256 i = 0; i < cursers.length; ++i) {
+ vm.startPrank(cursers[i]);
+ for (uint256 j = 0; j < curseCounts[i]; ++j) {
+ s_rmn.voteToCurse(makeCurseId(j), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+ }
+ }
+
+ function ownerUnvoteToCurse() internal {
+ s_rmn.ownerUnvoteToCurse(makeOwnerUnvoteToCurseRequests());
+ }
+
+ function makeOwnerUnvoteToCurseRequests() internal pure returns (RMN.OwnerUnvoteToCurseRequest[] memory) {
+ (address[] memory cursers,) = getCursersAndCurseCounts();
+ RMN.OwnerUnvoteToCurseRequest[] memory reqs = new RMN.OwnerUnvoteToCurseRequest[](cursers.length);
+ for (uint256 i = 0; i < cursers.length; ++i) {
+ reqs[i] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: cursers[i],
+ unit: RMN.UnvoteToCurseRequest({subject: GLOBAL_CURSE_SUBJECT, cursesHash: bytes28(0)}),
+ forceUnvote: true
+ });
+ }
+ return reqs;
+ }
+
+ // Success
+
+ function test_OwnerUnvoteToCurseSuccess_gas() public {
+ vm.pauseGasMetering();
+ vm.startPrank(OWNER);
+
+ vm.expectEmit();
+ emit RMN.CurseLifted(GLOBAL_CURSE_SUBJECT);
+
+ vm.resumeGasMetering();
+ ownerUnvoteToCurse();
+ vm.pauseGasMetering();
+
+ assertFalse(s_rmn.isCursed());
+ (address[] memory voters, bytes28[] memory cursesHashes, uint256 weight, bool cursed) =
+ s_rmn.getCurseProgress(GLOBAL_CURSE_SUBJECT);
+ assertEq(voters.length, 0);
+ assertEq(cursesHashes.length, 0);
+ assertEq(weight, 0);
+ assertFalse(cursed);
+ vm.resumeGasMetering();
+ }
+
+ function test_IsIdempotent() public {
+ vm.startPrank(OWNER);
+ ownerUnvoteToCurse();
+ vm.expectRevert(RMN.UnvoteToCurseNoop.selector);
+ ownerUnvoteToCurse();
+
+ assertFalse(s_rmn.isCursed());
+ (address[] memory voters, bytes28[] memory cursesHashes, uint256 weight, bool cursed) =
+ s_rmn.getCurseProgress(GLOBAL_CURSE_SUBJECT);
+ assertEq(voters.length, 0);
+ assertEq(cursesHashes.length, 0);
+ assertEq(weight, 0);
+ assertFalse(cursed);
+ }
+
+ function test_CanBlessAndCurseAfterGlobalCurseIsLifted() public {
+ // Contract is already cursed due to setUp.
+
+ // Owner unvotes to curse.
+ vm.startPrank(OWNER);
+ vm.expectEmit();
+ emit RMN.CurseLifted(GLOBAL_CURSE_SUBJECT);
+ ownerUnvoteToCurse();
+
+ // Contract is now uncursed.
+ assertFalse(s_rmn.isCursed());
+
+ // Vote to bless should go through.
+ vm.startPrank(BLESS_VOTER_1);
+ s_rmn.voteToBless(makeTaggedRootSingleton(2387489729));
+
+ // Vote to curse should go through.
+ vm.startPrank(CURSE_VOTER_1);
+ s_rmn.voteToCurse(makeCurseId(73894728973), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+
+ // Reverts
+
+ function test_NonOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ ownerUnvoteToCurse();
+ }
+
+ function test_UnknownVoter_Revert() public {
+ vm.stopPrank();
+ RMN.OwnerUnvoteToCurseRequest[] memory reqs = new RMN.OwnerUnvoteToCurseRequest[](1);
+ reqs[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: STRANGER,
+ unit: RMN.UnvoteToCurseRequest({subject: GLOBAL_CURSE_SUBJECT, cursesHash: bytes28(0)}),
+ forceUnvote: true
+ });
+
+ vm.prank(OWNER);
+ vm.expectEmit();
+ emit RMN.SkippedUnvoteToCurse(STRANGER, GLOBAL_CURSE_SUBJECT, bytes28(0), bytes28(0));
+ vm.expectRevert(RMN.UnvoteToCurseNoop.selector);
+ s_rmn.ownerUnvoteToCurse(reqs);
+
+ // no effect on cursedness
+ assertTrue(s_rmn.isCursed(GLOBAL_CURSE_SUBJECT));
+ }
+}
+
+contract RMN_setConfig is ConfigCompare, RMNSetup {
+ /// @notice Test-specific function to use only in setConfig tests
+ function getDifferentConfigArgs() private pure returns (RMN.Config memory) {
+ RMN.Voter[] memory voters = new RMN.Voter[](2);
+ voters[0] = RMN.Voter({
+ blessVoteAddr: BLESS_VOTER_1,
+ curseVoteAddr: CURSE_VOTER_1,
+ blessWeight: WEIGHT_1,
+ curseWeight: WEIGHT_1
+ });
+ voters[1] = RMN.Voter({
+ blessVoteAddr: BLESS_VOTER_2,
+ curseVoteAddr: CURSE_VOTER_2,
+ blessWeight: WEIGHT_10,
+ curseWeight: WEIGHT_10
+ });
+ return RMN.Config({
+ voters: voters,
+ blessWeightThreshold: WEIGHT_1 + WEIGHT_10,
+ curseWeightThreshold: WEIGHT_1 + WEIGHT_10
+ });
+ }
+
+ function setUp() public virtual override {
+ RMNSetup.setUp();
+ RMN.Config memory cfg = rmnConstructorArgs();
+
+ // Setup some partial state
+ vm.startPrank(cfg.voters[0].blessVoteAddr);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ vm.startPrank(cfg.voters[1].blessVoteAddr);
+ s_rmn.voteToBless(makeTaggedRootSingleton(1));
+ vm.startPrank(cfg.voters[1].curseVoteAddr);
+ s_rmn.voteToCurse(makeCurseId(1), makeSubjects(0));
+ }
+
+ // Success
+
+ event ConfigSet(uint32 indexed configVersion, RMN.Config config);
+
+ function test_VoteToBlessByEjectedVoter_Revert() public {
+ // Previous config included BLESS_VOTER_4. Change to new config that doesn't.
+ RMN.Config memory cfg = getDifferentConfigArgs();
+ vm.startPrank(OWNER);
+ s_rmn.setConfig(cfg);
+
+ // BLESS_VOTER_4 is not part of cfg anymore, vote to bless should revert.
+ vm.startPrank(BLESS_VOTER_4);
+ vm.expectRevert(abi.encodeWithSelector(RMN.UnauthorizedVoter.selector, BLESS_VOTER_4));
+ s_rmn.voteToBless(makeTaggedRootSingleton(2));
+ }
+
+ function test_SetConfigSuccess_gas() public {
+ vm.pauseGasMetering();
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(OWNER);
+ vm.expectEmit();
+ emit ConfigSet(2, cfg);
+
+ (uint32 configVersionBefore,,) = s_rmn.getConfigDetails();
+ vm.resumeGasMetering();
+ s_rmn.setConfig(cfg);
+ vm.pauseGasMetering();
+ // Assert VersionedConfig has changed correctly
+ (uint32 configVersionAfter,, RMN.Config memory configAfter) = s_rmn.getConfigDetails();
+ assertEq(configVersionBefore + 1, configVersionAfter);
+ assertConfigEq(configAfter, cfg);
+
+ // Assert that curse votes have been cleared
+
+ (address[] memory curseVoters, bytes28[] memory cursesHashes, uint256 curseWeight, bool cursed) =
+ s_rmn.getCurseProgress(0);
+ assertEq(0, curseVoters.length);
+ assertEq(0, cursesHashes.length);
+ assertEq(0, curseWeight);
+ assertFalse(cursed);
+
+ // Assert that good votes have been cleared
+ uint256 votesToBlessRoot = getWeightOfVotesToBlessRoot(makeTaggedRoot(1));
+ assertEq(ZERO, votesToBlessRoot);
+ assertFalse(hasVotedToBlessRoot(cfg.voters[0].blessVoteAddr, makeTaggedRoot(1)));
+ assertFalse(hasVotedToBlessRoot(cfg.voters[1].blessVoteAddr, makeTaggedRoot(1)));
+ vm.resumeGasMetering();
+ }
+
+ // Reverts
+
+ function test_NonOwner_Revert() public {
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_rmn.setConfig(cfg);
+ }
+
+ function test_VotersLengthIsZero_Revert() public {
+ vm.startPrank(OWNER);
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(RMN.Config({voters: new RMN.Voter[](0), blessWeightThreshold: 1, curseWeightThreshold: 1}));
+ }
+
+ function test_EitherThresholdIsZero_Revert() public {
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(OWNER);
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(
+ RMN.Config({voters: cfg.voters, blessWeightThreshold: ZERO, curseWeightThreshold: cfg.curseWeightThreshold})
+ );
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(
+ RMN.Config({voters: cfg.voters, blessWeightThreshold: cfg.blessWeightThreshold, curseWeightThreshold: ZERO})
+ );
+ }
+
+ function test_BlessVoterIsZeroAddress_Revert() public {
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(OWNER);
+ cfg.voters[0].blessVoteAddr = ZERO_ADDRESS;
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(cfg);
+ }
+
+ function test_WeightIsZeroAddress_Revert() public {
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(OWNER);
+ cfg.voters[0].blessWeight = ZERO;
+ cfg.voters[0].curseWeight = ZERO;
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(cfg);
+ }
+
+ function test_TotalWeightsSmallerThanEachThreshold_Revert() public {
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(OWNER);
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(
+ RMN.Config({voters: cfg.voters, blessWeightThreshold: WEIGHT_40, curseWeightThreshold: cfg.curseWeightThreshold})
+ );
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(
+ RMN.Config({voters: cfg.voters, blessWeightThreshold: cfg.blessWeightThreshold, curseWeightThreshold: WEIGHT_40})
+ );
+ }
+
+ function test_RepeatedAddress_Revert() public {
+ RMN.Config memory cfg = getDifferentConfigArgs();
+
+ vm.startPrank(OWNER);
+ cfg.voters[0].blessVoteAddr = cfg.voters[1].curseVoteAddr;
+ vm.expectRevert(RMN.InvalidConfig.selector);
+ s_rmn.setConfig(cfg);
+ }
+}
+
+contract RMN_permaBlessing is RMNSetup {
+ function addresses() private pure returns (address[] memory) {
+ return new address[](0);
+ }
+
+ function addresses(address a) private pure returns (address[] memory) {
+ address[] memory arr = new address[](1);
+ arr[0] = a;
+ return arr;
+ }
+
+ function addresses(address a, address b) private pure returns (address[] memory) {
+ address[] memory arr = new address[](2);
+ arr[0] = a;
+ arr[1] = b;
+ return arr;
+ }
+
+ function test_PermaBlessing() public {
+ bytes32 SOME_ROOT = bytes32(~uint256(0));
+ address COMMIT_STORE_1 = makeAddr("COMMIT_STORE_1");
+ address COMMIT_STORE_2 = makeAddr("COMMIT_STORE_2");
+ IRMN.TaggedRoot memory taggedRootCommitStore1 = IRMN.TaggedRoot({root: SOME_ROOT, commitStore: COMMIT_STORE_1});
+ IRMN.TaggedRoot memory taggedRootCommitStore2 = IRMN.TaggedRoot({root: SOME_ROOT, commitStore: COMMIT_STORE_2});
+
+ assertFalse(s_rmn.isBlessed(taggedRootCommitStore1));
+ assertFalse(s_rmn.isBlessed(taggedRootCommitStore2));
+ assertEq(s_rmn.getPermaBlessedCommitStores(), addresses());
+
+ // only owner can mutate permaBlessedCommitStores
+ vm.prank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_rmn.ownerRemoveThenAddPermaBlessedCommitStores(addresses(), addresses(COMMIT_STORE_1));
+
+ vm.prank(OWNER);
+ s_rmn.ownerRemoveThenAddPermaBlessedCommitStores(addresses(), addresses(COMMIT_STORE_1));
+ assertTrue(s_rmn.isBlessed(taggedRootCommitStore1));
+ assertFalse(s_rmn.isBlessed(taggedRootCommitStore2));
+ assertEq(s_rmn.getPermaBlessedCommitStores(), addresses(COMMIT_STORE_1));
+
+ vm.prank(OWNER);
+ s_rmn.ownerRemoveThenAddPermaBlessedCommitStores(addresses(COMMIT_STORE_1), addresses(COMMIT_STORE_2));
+ assertFalse(s_rmn.isBlessed(taggedRootCommitStore1));
+ assertTrue(s_rmn.isBlessed(taggedRootCommitStore2));
+ assertEq(s_rmn.getPermaBlessedCommitStores(), addresses(COMMIT_STORE_2));
+
+ vm.prank(OWNER);
+ s_rmn.ownerRemoveThenAddPermaBlessedCommitStores(addresses(), addresses(COMMIT_STORE_1));
+ assertTrue(s_rmn.isBlessed(taggedRootCommitStore1));
+ assertTrue(s_rmn.isBlessed(taggedRootCommitStore2));
+ assertEq(s_rmn.getPermaBlessedCommitStores(), addresses(COMMIT_STORE_2, COMMIT_STORE_1));
+
+ vm.prank(OWNER);
+ s_rmn.ownerRemoveThenAddPermaBlessedCommitStores(addresses(COMMIT_STORE_1, COMMIT_STORE_2), addresses());
+ assertFalse(s_rmn.isBlessed(taggedRootCommitStore1));
+ assertFalse(s_rmn.isBlessed(taggedRootCommitStore2));
+ assertEq(s_rmn.getPermaBlessedCommitStores(), addresses());
+ }
+}
+
+contract RMN_getRecordedCurseRelatedOps is RMNSetup {
+ function test_OpsPostDeployment() public {
+ // The constructor call includes a setConfig, so that's the only thing we should expect to find.
+ assertEq(s_rmn.getRecordedCurseRelatedOpsCount(), 1);
+ RMN.RecordedCurseRelatedOp[] memory recordedCurseRelatedOps = s_rmn.getRecordedCurseRelatedOps(0, type(uint256).max);
+ assertEq(recordedCurseRelatedOps.length, 1);
+ assertEq(uint8(recordedCurseRelatedOps[0].tag), uint8(RMN.RecordedCurseRelatedOpTag.SetConfig));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/arm/RMNSetup.t.sol b/contracts/src/v0.8/ccip/test/arm/RMNSetup.t.sol
new file mode 100644
index 00000000000..8feacb95f45
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/arm/RMNSetup.t.sol
@@ -0,0 +1,144 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {RMN} from "../../RMN.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+
+import {Test} from "forge-std/Test.sol";
+
+function makeSubjects(bytes16 a) pure returns (bytes16[] memory) {
+ bytes16[] memory subjects = new bytes16[](1);
+ subjects[0] = a;
+ return subjects;
+}
+
+function makeSubjects(bytes16 a, bytes16 b) pure returns (bytes16[] memory) {
+ bytes16[] memory subjects = new bytes16[](2);
+ subjects[0] = a;
+ subjects[1] = b;
+ return subjects;
+}
+
+// in order from earliest to latest curse ids
+function makeCursesHashFromList(bytes32[] memory curseIds) pure returns (bytes28 cursesHash) {
+ for (uint256 i = 0; i < curseIds.length; ++i) {
+ cursesHash = bytes28(keccak256(abi.encode(cursesHash, curseIds[i])));
+ }
+}
+
+// hides the ugliness from tests
+function makeCursesHash(bytes32 a) pure returns (bytes28) {
+ bytes32[] memory curseIds = new bytes32[](1);
+ curseIds[0] = a;
+ return makeCursesHashFromList(curseIds);
+}
+
+function makeCursesHash(bytes32 a, bytes32 b) pure returns (bytes28) {
+ bytes32[] memory curseIds = new bytes32[](2);
+ curseIds[0] = a;
+ curseIds[1] = b;
+ return makeCursesHashFromList(curseIds);
+}
+
+contract RMNSetup is Test {
+ // Addresses
+ address internal constant OWNER = 0x00007e64E1fB0C487F25dd6D3601ff6aF8d32e4e;
+ address internal constant STRANGER = address(999999);
+ address internal constant ZERO_ADDRESS = address(0);
+ address internal constant BLESS_VOTER_1 = address(1);
+ address internal constant CURSE_VOTER_1 = address(10);
+ address internal constant BLESS_VOTER_2 = address(2);
+ address internal constant CURSE_VOTER_2 = address(12);
+ address internal constant BLESS_VOTER_3 = address(3);
+ address internal constant CURSE_VOTER_3 = address(13);
+ address internal constant BLESS_VOTER_4 = address(4);
+ address internal constant CURSE_VOTER_4 = address(14);
+
+ // Arm
+ function rmnConstructorArgs() internal pure returns (RMN.Config memory) {
+ RMN.Voter[] memory voters = new RMN.Voter[](4);
+ voters[0] = RMN.Voter({
+ blessVoteAddr: BLESS_VOTER_1,
+ curseVoteAddr: CURSE_VOTER_1,
+ blessWeight: WEIGHT_1,
+ curseWeight: WEIGHT_1
+ });
+ voters[1] = RMN.Voter({
+ blessVoteAddr: BLESS_VOTER_2,
+ curseVoteAddr: CURSE_VOTER_2,
+ blessWeight: WEIGHT_10,
+ curseWeight: WEIGHT_10
+ });
+ voters[2] = RMN.Voter({
+ blessVoteAddr: BLESS_VOTER_3,
+ curseVoteAddr: CURSE_VOTER_3,
+ blessWeight: WEIGHT_20,
+ curseWeight: WEIGHT_20
+ });
+ voters[3] = RMN.Voter({
+ blessVoteAddr: BLESS_VOTER_4,
+ curseVoteAddr: CURSE_VOTER_4,
+ blessWeight: WEIGHT_40,
+ curseWeight: WEIGHT_40
+ });
+ return RMN.Config({
+ voters: voters,
+ blessWeightThreshold: WEIGHT_10 + WEIGHT_20 + WEIGHT_40,
+ curseWeightThreshold: WEIGHT_1 + WEIGHT_10 + WEIGHT_20 + WEIGHT_40
+ });
+ }
+
+ uint8 internal constant ZERO = 0;
+ uint8 internal constant WEIGHT_1 = 1;
+ uint8 internal constant WEIGHT_10 = 10;
+ uint8 internal constant WEIGHT_20 = 20;
+ uint8 internal constant WEIGHT_40 = 40;
+
+ function makeTaggedRootsInclusive(uint256 from, uint256 to) internal pure returns (IRMN.TaggedRoot[] memory) {
+ IRMN.TaggedRoot[] memory votes = new IRMN.TaggedRoot[](to - from + 1);
+ for (uint256 i = from; i <= to; ++i) {
+ votes[i - from] = IRMN.TaggedRoot({commitStore: address(1), root: bytes32(uint256(i))});
+ }
+ return votes;
+ }
+
+ function makeTaggedRootSingleton(uint256 index) internal pure returns (IRMN.TaggedRoot[] memory) {
+ return makeTaggedRootsInclusive(index, index);
+ }
+
+ function makeTaggedRoot(uint256 index) internal pure returns (IRMN.TaggedRoot memory) {
+ return makeTaggedRootSingleton(index)[0];
+ }
+
+ function makeTaggedRootHash(uint256 index) internal pure returns (bytes32) {
+ IRMN.TaggedRoot memory taggedRoot = makeTaggedRootSingleton(index)[0];
+ return keccak256(abi.encode(taggedRoot.commitStore, taggedRoot.root));
+ }
+
+ function makeCurseId(uint256 index) internal pure returns (bytes16) {
+ return bytes16(uint128(index));
+ }
+
+ RMN internal s_rmn;
+
+ function setUp() public virtual {
+ vm.startPrank(OWNER);
+ s_rmn = new RMN(rmnConstructorArgs());
+ vm.stopPrank();
+ }
+
+ function hasVotedToBlessRoot(address voter, IRMN.TaggedRoot memory taggedRoot_) internal view returns (bool) {
+ (address[] memory voters,,) = s_rmn.getBlessProgress(taggedRoot_);
+ for (uint256 i = 0; i < voters.length; ++i) {
+ if (voters[i] == voter) {
+ return true;
+ }
+ }
+ return false;
+ }
+
+ function getWeightOfVotesToBlessRoot(IRMN.TaggedRoot memory taggedRoot_) internal view returns (uint16) {
+ (, uint16 weight,) = s_rmn.getBlessProgress(taggedRoot_);
+ return weight;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/arm/RMN_benchmark.t.sol b/contracts/src/v0.8/ccip/test/arm/RMN_benchmark.t.sol
new file mode 100644
index 00000000000..8564614a748
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/arm/RMN_benchmark.t.sol
@@ -0,0 +1,217 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {GLOBAL_CURSE_SUBJECT, OWNER_CURSE_VOTE_ADDR, RMN} from "../../RMN.sol";
+import {RMNSetup, makeCursesHash, makeSubjects} from "./RMNSetup.t.sol";
+
+contract RMN_voteToBless_Benchmark is RMNSetup {
+ function test_RootSuccess_gas(uint256 n) internal {
+ vm.prank(BLESS_VOTER_1);
+ s_rmn.voteToBless(makeTaggedRootsInclusive(1, n));
+ }
+
+ function test_1RootSuccess_gas() public {
+ test_RootSuccess_gas(1);
+ }
+
+ function test_3RootSuccess_gas() public {
+ test_RootSuccess_gas(3);
+ }
+
+ function test_5RootSuccess_gas() public {
+ test_RootSuccess_gas(5);
+ }
+}
+
+contract RMN_voteToBless_Blessed_Benchmark is RMN_voteToBless_Benchmark {
+ function setUp() public virtual override {
+ RMNSetup.setUp();
+ vm.prank(BLESS_VOTER_2);
+ s_rmn.voteToBless(makeTaggedRootsInclusive(1, 1));
+ vm.prank(BLESS_VOTER_3);
+ s_rmn.voteToBless(makeTaggedRootsInclusive(1, 1));
+ }
+
+ function test_1RootSuccessBecameBlessed_gas() public {
+ vm.prank(BLESS_VOTER_4);
+ s_rmn.voteToBless(makeTaggedRootsInclusive(1, 1));
+ }
+}
+
+abstract contract RMN_voteToCurse_Benchmark is RMNSetup {
+ struct PreVote {
+ address voter;
+ bytes16 subject;
+ }
+
+ PreVote[] internal s_preVotes;
+
+ function setUp() public virtual override {
+ // Intentionally does not inherit RMNSetup setUp(), because we set up a simpler config here.
+ // The only way to ensure that storage slots are cold for the actual functions to be benchmarked is to perform the
+ // setup in setUp().
+
+ RMN.Config memory cfg = RMN.Config({voters: new RMN.Voter[](3), blessWeightThreshold: 3, curseWeightThreshold: 3});
+ cfg.voters[0] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_1, curseVoteAddr: CURSE_VOTER_1, blessWeight: 1, curseWeight: 1});
+ cfg.voters[1] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_2, curseVoteAddr: CURSE_VOTER_2, blessWeight: 1, curseWeight: 1});
+ cfg.voters[2] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_3, curseVoteAddr: CURSE_VOTER_3, blessWeight: 1, curseWeight: 1});
+ vm.prank(OWNER);
+ s_rmn = new RMN(cfg);
+
+ for (uint256 i = 0; i < s_preVotes.length; ++i) {
+ vm.prank(s_preVotes[i].voter);
+ s_rmn.voteToCurse(makeCurseId(i), makeSubjects(s_preVotes[i].subject));
+ }
+ }
+}
+
+contract RMN_voteToCurse_Benchmark_1 is RMN_voteToCurse_Benchmark {
+ constructor() {
+ // some irrelevant subject & voter so that we don't pay for the nonzero->zero SSTORE of
+ // s_recordedVotesToCurse.length in the benchmark below
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_3, subject: bytes16(~uint128(0))}));
+ }
+
+ function test_VoteToCurse_NewSubject_NewVoter_NoCurse_gas() public {
+ vm.prank(CURSE_VOTER_1);
+ s_rmn.voteToCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+
+ function test_VoteToCurse_NewSubject_NewVoter_YesCurse_gas() public {
+ vm.prank(OWNER);
+ s_rmn.ownerCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+}
+
+contract RMN_voteToCurse_Benchmark_2 is RMN_voteToCurse_Benchmark {
+ constructor() {
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_1, subject: GLOBAL_CURSE_SUBJECT}));
+ }
+
+ function test_VoteToCurse_OldSubject_OldVoter_NoCurse_gas() public {
+ vm.prank(CURSE_VOTER_1);
+ s_rmn.voteToCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+
+ function test_VoteToCurse_OldSubject_NewVoter_NoCurse_gas() public {
+ vm.prank(CURSE_VOTER_2);
+ s_rmn.voteToCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+}
+
+contract RMN_voteToCurse_Benchmark_3 is RMN_voteToCurse_Benchmark {
+ constructor() {
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_1, subject: GLOBAL_CURSE_SUBJECT}));
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_2, subject: GLOBAL_CURSE_SUBJECT}));
+ }
+
+ function test_VoteToCurse_OldSubject_NewVoter_YesCurse_gas() public {
+ vm.prank(CURSE_VOTER_3);
+ s_rmn.voteToCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+}
+
+contract RMN_lazyVoteToCurseUpdate_Benchmark is RMN_voteToCurse_Benchmark {
+ constructor() {
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_1, subject: GLOBAL_CURSE_SUBJECT}));
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_2, subject: GLOBAL_CURSE_SUBJECT}));
+ s_preVotes.push(PreVote({voter: CURSE_VOTER_3, subject: GLOBAL_CURSE_SUBJECT}));
+ }
+
+ function setUp() public override {
+ RMN_voteToCurse_Benchmark.setUp(); // sends the prevotes
+ // initial config includes voters CURSE_VOTER_1, CURSE_VOTER_2, CURSE_VOTER_3
+ // include a new voter in the config
+ {
+ (,, RMN.Config memory cfg) = s_rmn.getConfigDetails();
+ RMN.Voter[] memory newVoters = new RMN.Voter[](cfg.voters.length + 1);
+ for (uint256 i = 0; i < cfg.voters.length; ++i) {
+ newVoters[i] = cfg.voters[i];
+ }
+ newVoters[newVoters.length - 1] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTER_4, curseVoteAddr: CURSE_VOTER_4, blessWeight: 1, curseWeight: 1});
+ cfg.voters = newVoters;
+
+ vm.prank(OWNER);
+ s_rmn.setConfig(cfg);
+ }
+ }
+
+ function test_VoteToCurseLazilyRetain3VotersUponConfigChange_gas() public {
+ // send a vote as the new voter, should cause a lazy update and votes from CURSE_VOTER_1, CURSE_VOTER_2,
+ // CURSE_VOTER_3 to be retained, which is the worst case for the prior config
+ vm.prank(CURSE_VOTER_4);
+ s_rmn.voteToCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+}
+
+contract RMN_setConfig_Benchmark is RMNSetup {
+ uint256 s_numVoters;
+
+ function configWithVoters(uint256 numVoters) internal pure returns (RMN.Config memory) {
+ RMN.Config memory cfg =
+ RMN.Config({voters: new RMN.Voter[](numVoters), blessWeightThreshold: 1, curseWeightThreshold: 1});
+ for (uint256 i = 1; i <= numVoters; ++i) {
+ cfg.voters[i - 1] = RMN.Voter({
+ blessVoteAddr: address(uint160(2 * i)),
+ curseVoteAddr: address(uint160(2 * i + 1)),
+ blessWeight: 1,
+ curseWeight: 1
+ });
+ }
+ return cfg;
+ }
+
+ function setUp() public virtual override {
+ vm.prank(OWNER);
+ s_rmn = new RMN(configWithVoters(s_numVoters));
+ }
+}
+
+contract RMN_setConfig_Benchmark_1 is RMN_setConfig_Benchmark {
+ constructor() {
+ s_numVoters = 1;
+ }
+
+ function test_SetConfig_7Voters_gas() public {
+ vm.prank(OWNER);
+ s_rmn.setConfig(configWithVoters(7));
+ }
+}
+
+contract RMN_setConfig_Benchmark_2 is RMN_setConfig_Benchmark {
+ constructor() {
+ s_numVoters = 7;
+ }
+
+ function test_ResetConfig_7Voters_gas() public {
+ vm.prank(OWNER);
+ s_rmn.setConfig(configWithVoters(7));
+ }
+}
+
+contract RMN_ownerUnvoteToCurse_Benchmark is RMN_setConfig_Benchmark {
+ constructor() {
+ s_numVoters = 7;
+ }
+
+ function setUp() public override {
+ RMN_setConfig_Benchmark.setUp();
+ vm.prank(OWNER);
+ s_rmn.ownerCurse(makeCurseId(0xffff), makeSubjects(GLOBAL_CURSE_SUBJECT));
+ }
+
+ function test_OwnerUnvoteToCurse_1Voter_LiftsCurse_gas() public {
+ RMN.OwnerUnvoteToCurseRequest[] memory reqs = new RMN.OwnerUnvoteToCurseRequest[](1);
+ reqs[0] = RMN.OwnerUnvoteToCurseRequest({
+ curseVoteAddr: OWNER_CURSE_VOTE_ADDR,
+ unit: RMN.UnvoteToCurseRequest({cursesHash: makeCursesHash(makeCurseId(0xffff)), subject: GLOBAL_CURSE_SUBJECT}),
+ forceUnvote: false
+ });
+ vm.prank(OWNER);
+ s_rmn.ownerUnvoteToCurse(reqs);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/attacks/onRamp/FacadeClient.sol b/contracts/src/v0.8/ccip/test/attacks/onRamp/FacadeClient.sol
new file mode 100644
index 00000000000..ad549e6ccc2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/attacks/onRamp/FacadeClient.sol
@@ -0,0 +1,54 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IRouterClient} from "../../../interfaces/IRouterClient.sol";
+
+import {Client} from "../../../libraries/Client.sol";
+
+import {IERC20} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+/// @title FacadeClient - A simple proxy for calling Router
+contract FacadeClient {
+ address private immutable i_router;
+ uint64 private immutable i_destChainSelector;
+ IERC20 private immutable i_sourceToken;
+ IERC20 private immutable i_feeToken;
+ address private immutable i_receiver;
+
+ uint256 private s_msg_sequence = 1;
+
+ constructor(address router, uint64 destChainSelector, IERC20 sourceToken, IERC20 feeToken, address receiver) {
+ i_router = router;
+ i_destChainSelector = destChainSelector;
+ i_sourceToken = sourceToken;
+ i_feeToken = feeToken;
+ i_receiver = receiver;
+
+ sourceToken.approve(address(router), 2 ** 256 - 1);
+ feeToken.approve(address(router), 2 ** 256 - 1);
+ }
+
+ /// @dev Calls Router to initiate CCIP send.
+ /// The expectation is that s_msg_sequence will always match the sequence in emitted CCIP messages.
+ function send(uint256 amount) public {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0].token = address(i_sourceToken);
+ tokenAmounts[0].amount = amount;
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(i_receiver),
+ data: abi.encodePacked(s_msg_sequence),
+ tokenAmounts: tokenAmounts,
+ extraArgs: "",
+ feeToken: address(i_feeToken)
+ });
+
+ s_msg_sequence++;
+
+ IRouterClient(i_router).ccipSend(i_destChainSelector, message);
+ }
+
+ function getSequence() public view returns (uint256) {
+ return s_msg_sequence;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/attacks/onRamp/MultiOnRampTokenPoolReentrancy.t.sol b/contracts/src/v0.8/ccip/test/attacks/onRamp/MultiOnRampTokenPoolReentrancy.t.sol
new file mode 100644
index 00000000000..5deeda64063
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/attacks/onRamp/MultiOnRampTokenPoolReentrancy.t.sol
@@ -0,0 +1,118 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Client} from "../../../libraries/Client.sol";
+import {Internal} from "../../../libraries/Internal.sol";
+import {EVM2EVMMultiOnRamp} from "../../../onRamp/EVM2EVMMultiOnRamp.sol";
+import {TokenPool} from "../../../pools/TokenPool.sol";
+import {EVM2EVMMultiOnRampSetup} from "../../onRamp/EVM2EVMMultiOnRampSetup.t.sol";
+import {FacadeClient} from "./FacadeClient.sol";
+import {ReentrantMaliciousTokenPool} from "./ReentrantMaliciousTokenPool.sol";
+
+import {IERC20} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+import {console} from "forge-std/console.sol";
+
+/// @title MultiOnRampTokenPoolReentrancy
+/// Attempts to perform a reentrancy exploit on Onramp with a malicious TokenPool
+contract MultiOnRampTokenPoolReentrancy is EVM2EVMMultiOnRampSetup {
+ FacadeClient internal s_facadeClient;
+ ReentrantMaliciousTokenPool internal s_maliciousTokenPool;
+ IERC20 internal s_sourceToken;
+ IERC20 internal s_feeToken;
+ address internal immutable i_receiver = makeAddr("receiver");
+
+ function setUp() public virtual override {
+ EVM2EVMMultiOnRampSetup.setUp();
+
+ s_sourceToken = IERC20(s_sourceTokens[0]);
+ s_feeToken = IERC20(s_sourceTokens[0]);
+
+ s_facadeClient =
+ new FacadeClient(address(s_sourceRouter), DEST_CHAIN_SELECTOR, s_sourceToken, s_feeToken, i_receiver);
+
+ s_maliciousTokenPool = new ReentrantMaliciousTokenPool(
+ address(s_facadeClient), s_sourceToken, address(s_mockRMN), address(s_sourceRouter)
+ );
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destPoolBySourceToken[s_sourceTokens[0]]),
+ remoteTokenAddress: abi.encode(s_destTokens[0]),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_maliciousTokenPool.applyChainUpdates(chainUpdates);
+ s_sourcePoolByToken[address(s_sourceToken)] = address(s_maliciousTokenPool);
+
+ Internal.PoolUpdate[] memory removes = new Internal.PoolUpdate[](1);
+ removes[0].token = address(s_sourceToken);
+ removes[0].pool = address(s_sourcePoolByToken[address(s_sourceToken)]);
+ Internal.PoolUpdate[] memory adds = new Internal.PoolUpdate[](1);
+ adds[0].token = address(s_sourceToken);
+ adds[0].pool = address(s_maliciousTokenPool);
+
+ s_tokenAdminRegistry.setPool(address(s_sourceToken), address(s_maliciousTokenPool));
+
+ s_sourceToken.transfer(address(s_facadeClient), 1e18);
+ s_feeToken.transfer(address(s_facadeClient), 1e18);
+ }
+
+ /// @dev This test was used to showcase a reentrancy exploit on OnRamp with malicious TokenPool.
+ /// How it worked: OnRamp used to construct EVM2Any messages after calling TokenPool's lockOrBurn.
+ /// This allowed the malicious TokenPool to break message sequencing expectations as follows:
+ /// Any user -> Facade -> 1st call to ccipSend -> pool’s lockOrBurn —>
+ /// (reenter)-> Facade -> 2nd call to ccipSend
+ /// In this case, Facade's second call would produce an EVM2Any msg with a lower sequence number.
+ /// The issue was fixed by moving state updates and event construction to before TokenPool calls.
+ /// This test is kept to verify message sequence expectations are not broken.
+ function test_OnRampTokenPoolReentrancy_Success() public {
+ uint256 amount = 1;
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0].token = address(s_sourceToken);
+ tokenAmounts[0].amount = amount;
+
+ Client.EVM2AnyMessage memory message1 = Client.EVM2AnyMessage({
+ receiver: abi.encode(i_receiver),
+ data: abi.encodePacked(uint256(1)), // message 1 contains data 1
+ tokenAmounts: tokenAmounts,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 200_000})),
+ feeToken: address(s_feeToken)
+ });
+
+ Client.EVM2AnyMessage memory message2 = Client.EVM2AnyMessage({
+ receiver: abi.encode(i_receiver),
+ data: abi.encodePacked(uint256(2)), // message 2 contains data 2
+ tokenAmounts: tokenAmounts,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 200_000})),
+ feeToken: address(s_feeToken)
+ });
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message1);
+ assertGt(expectedFee, 0);
+
+ // Outcome of a successful exploit:
+ // Message 1 event from OnRamp contains sequence/nonce 2, message 2 contains sequence/nonce 1
+ // Internal.EVM2EVMMessage memory msgEvent1 = _messageToEvent(message1, 2, 2, expectedFee, address(s_facadeClient));
+ // Internal.EVM2EVMMessage memory msgEvent2 = _messageToEvent(message2, 1, 1, expectedFee, address(s_facadeClient));
+
+ // vm.expectEmit();
+ // emit CCIPSendRequested(msgEvent2);
+ // vm.expectEmit();
+ // emit CCIPSendRequested(msgEvent1);
+
+ // After issue is fixed, sequence now increments as expected
+ Internal.EVM2AnyRampMessage memory msgEvent1 = _messageToEvent(message1, 1, 1, expectedFee, address(s_facadeClient));
+ Internal.EVM2AnyRampMessage memory msgEvent2 = _messageToEvent(message2, 2, 2, expectedFee, address(s_facadeClient));
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, msgEvent2);
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, msgEvent1);
+
+ s_facadeClient.send(amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/attacks/onRamp/OnRampTokenPoolReentrancy.t.sol b/contracts/src/v0.8/ccip/test/attacks/onRamp/OnRampTokenPoolReentrancy.t.sol
new file mode 100644
index 00000000000..8fc71be8573
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/attacks/onRamp/OnRampTokenPoolReentrancy.t.sol
@@ -0,0 +1,116 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Client} from "../../../libraries/Client.sol";
+import {Internal} from "../../../libraries/Internal.sol";
+import {EVM2EVMOnRamp} from "../../../onRamp/EVM2EVMOnRamp.sol";
+import {TokenPool} from "../../../pools/TokenPool.sol";
+import {EVM2EVMOnRampSetup} from "../../onRamp/EVM2EVMOnRampSetup.t.sol";
+import {FacadeClient} from "./FacadeClient.sol";
+import {ReentrantMaliciousTokenPool} from "./ReentrantMaliciousTokenPool.sol";
+
+import {IERC20} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+/// @title OnRampTokenPoolReentrancy
+/// Attempts to perform a reentrancy exploit on Onramp with a malicious TokenPool
+contract OnRampTokenPoolReentrancy is EVM2EVMOnRampSetup {
+ FacadeClient internal s_facadeClient;
+ ReentrantMaliciousTokenPool internal s_maliciousTokenPool;
+ IERC20 internal s_sourceToken;
+ IERC20 internal s_feeToken;
+ address internal immutable i_receiver = makeAddr("receiver");
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ s_sourceToken = IERC20(s_sourceTokens[0]);
+ s_feeToken = IERC20(s_sourceTokens[0]);
+
+ s_facadeClient =
+ new FacadeClient(address(s_sourceRouter), DEST_CHAIN_SELECTOR, s_sourceToken, s_feeToken, i_receiver);
+
+ s_maliciousTokenPool = new ReentrantMaliciousTokenPool(
+ address(s_facadeClient), s_sourceToken, address(s_mockRMN), address(s_sourceRouter)
+ );
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destPoolBySourceToken[s_sourceTokens[0]]),
+ remoteTokenAddress: abi.encode(s_destTokens[0]),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_maliciousTokenPool.applyChainUpdates(chainUpdates);
+ s_sourcePoolByToken[address(s_sourceToken)] = address(s_maliciousTokenPool);
+
+ Internal.PoolUpdate[] memory removes = new Internal.PoolUpdate[](1);
+ removes[0].token = address(s_sourceToken);
+ removes[0].pool = address(s_sourcePoolByToken[address(s_sourceToken)]);
+ Internal.PoolUpdate[] memory adds = new Internal.PoolUpdate[](1);
+ adds[0].token = address(s_sourceToken);
+ adds[0].pool = address(s_maliciousTokenPool);
+
+ s_tokenAdminRegistry.setPool(address(s_sourceToken), address(s_maliciousTokenPool));
+
+ s_sourceToken.transfer(address(s_facadeClient), 1e18);
+ s_feeToken.transfer(address(s_facadeClient), 1e18);
+ }
+
+ /// @dev This test was used to showcase a reentrancy exploit on OnRamp with malicious TokenPool.
+ /// How it worked: OnRamp used to construct EVM2EVM messages after calling TokenPool's lockOrBurn.
+ /// This allowed the malicious TokenPool to break message sequencing expectations as follows:
+ /// Any user -> Facade -> 1st call to ccipSend -> pool’s lockOrBurn —>
+ /// (reenter)-> Facade -> 2nd call to ccipSend
+ /// In this case, Facade's second call would produce an EVM2EVM msg with a lower sequence number.
+ /// The issue was fixed by moving state updates and event construction to before TokenPool calls.
+ /// This test is kept to verify message sequence expectations are not broken.
+ function test_OnRampTokenPoolReentrancy_Success() public {
+ uint256 amount = 1;
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0].token = address(s_sourceToken);
+ tokenAmounts[0].amount = amount;
+
+ Client.EVM2AnyMessage memory message1 = Client.EVM2AnyMessage({
+ receiver: abi.encode(i_receiver),
+ data: abi.encodePacked(uint256(1)), // message 1 contains data 1
+ tokenAmounts: tokenAmounts,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 200_000})),
+ feeToken: address(s_feeToken)
+ });
+
+ Client.EVM2AnyMessage memory message2 = Client.EVM2AnyMessage({
+ receiver: abi.encode(i_receiver),
+ data: abi.encodePacked(uint256(2)), // message 2 contains data 2
+ tokenAmounts: tokenAmounts,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 200_000})),
+ feeToken: address(s_feeToken)
+ });
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message1);
+ assertGt(expectedFee, 0);
+
+ // Outcome of a successful exploit:
+ // Message 1 event from OnRamp contains sequence/nonce 2, message 2 contains sequence/nonce 1
+ // Internal.EVM2EVMMessage memory msgEvent1 = _messageToEvent(message1, 2, 2, expectedFee, address(s_facadeClient));
+ // Internal.EVM2EVMMessage memory msgEvent2 = _messageToEvent(message2, 1, 1, expectedFee, address(s_facadeClient));
+
+ // vm.expectEmit();
+ // emit CCIPSendRequested(msgEvent2);
+ // vm.expectEmit();
+ // emit CCIPSendRequested(msgEvent1);
+
+ // After issue is fixed, sequence now increments as expected
+ Internal.EVM2EVMMessage memory msgEvent1 = _messageToEvent(message1, 1, 1, expectedFee, address(s_facadeClient));
+ Internal.EVM2EVMMessage memory msgEvent2 = _messageToEvent(message2, 2, 2, expectedFee, address(s_facadeClient));
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent2);
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent1);
+
+ s_facadeClient.send(amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/attacks/onRamp/ReentrantMaliciousTokenPool.sol b/contracts/src/v0.8/ccip/test/attacks/onRamp/ReentrantMaliciousTokenPool.sol
new file mode 100644
index 00000000000..17c13a8148e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/attacks/onRamp/ReentrantMaliciousTokenPool.sol
@@ -0,0 +1,50 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Pool} from "../../../libraries/Pool.sol";
+import {TokenPool} from "../../../pools/TokenPool.sol";
+import {FacadeClient} from "./FacadeClient.sol";
+
+import {IERC20} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract ReentrantMaliciousTokenPool is TokenPool {
+ address private i_facade;
+
+ bool private s_attacked;
+
+ constructor(
+ address facade,
+ IERC20 token,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, new address[](0), rmnProxy, router) {
+ i_facade = facade;
+ }
+
+ /// @dev Calls into Facade to reenter Router exactly 1 time
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ if (s_attacked) {
+ return
+ Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ s_attacked = true;
+
+ FacadeClient(i_facade).send(lockOrBurnIn.amount);
+ emit Burned(msg.sender, lockOrBurnIn.amount);
+ return Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ pure
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/capability/CCIPConfig.t.sol b/contracts/src/v0.8/ccip/test/capability/CCIPConfig.t.sol
new file mode 100644
index 00000000000..0c3108d279f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/capability/CCIPConfig.t.sol
@@ -0,0 +1,1681 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.24;
+
+import {Test} from "forge-std/Test.sol";
+
+import {SortedSetValidationUtil} from "../../../shared/util/SortedSetValidationUtil.sol";
+import {CCIPConfig} from "../../capability/CCIPConfig.sol";
+import {ICapabilitiesRegistry} from "../../capability/interfaces/ICapabilitiesRegistry.sol";
+import {CCIPConfigTypes} from "../../capability/libraries/CCIPConfigTypes.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {CCIPConfigHelper} from "../helpers/CCIPConfigHelper.sol";
+
+contract CCIPConfigSetup is Test {
+ address public constant OWNER = 0x82ae2B4F57CA5C1CBF8f744ADbD3697aD1a35AFe;
+ address public constant CAPABILITIES_REGISTRY = 0x272aF4BF7FBFc4944Ed59F914Cd864DfD912D55e;
+
+ CCIPConfigHelper public s_ccipCC;
+
+ function setUp() public {
+ changePrank(OWNER);
+ s_ccipCC = new CCIPConfigHelper(CAPABILITIES_REGISTRY);
+ }
+
+ function _makeBytes32Array(uint256 length, uint256 seed) internal pure returns (bytes32[] memory arr) {
+ arr = new bytes32[](length);
+ for (uint256 i = 0; i < length; i++) {
+ arr[i] = keccak256(abi.encode(i, 1, seed));
+ }
+ return arr;
+ }
+
+ function _makeBytesArray(uint256 length, uint256 seed) internal pure returns (bytes[] memory arr) {
+ arr = new bytes[](length);
+ for (uint256 i = 0; i < length; i++) {
+ arr[i] = abi.encodePacked(keccak256(abi.encode(i, 1, seed)));
+ }
+ return arr;
+ }
+
+ function _subset(bytes32[] memory arr, uint256 start, uint256 end) internal pure returns (bytes32[] memory) {
+ bytes32[] memory subset = new bytes32[](end - start);
+ for (uint256 i = start; i < end; i++) {
+ subset[i - start] = arr[i];
+ }
+ return subset;
+ }
+
+ //TODO: Use OZ's Arrays.sort when we upgrade to OZ v5
+ function _sort(bytes32[] memory arr, int256 left, int256 right) private pure {
+ int256 i = left;
+ int256 j = right;
+ if (i == j) return;
+ bytes32 pivot = arr[uint256(left + (right - left) / 2)];
+ while (i <= j) {
+ while (arr[uint256(i)] < pivot) i++;
+ while (pivot < arr[uint256(j)]) j--;
+ if (i <= j) {
+ (arr[uint256(i)], arr[uint256(j)]) = (arr[uint256(j)], arr[uint256(i)]);
+ i++;
+ j--;
+ }
+ }
+ if (left < j) _sort(arr, left, j);
+ if (i < right) _sort(arr, i, right);
+ }
+
+ function _addChainConfig(uint256 numNodes)
+ internal
+ returns (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters)
+ {
+ p2pIds = _makeBytes32Array(numNodes, 0);
+ _sort(p2pIds, 0, int256(numNodes - 1));
+ signers = _makeBytesArray(numNodes, 10);
+ transmitters = _makeBytesArray(numNodes, 20);
+ for (uint256 i = 0; i < numNodes; i++) {
+ vm.mockCall(
+ CAPABILITIES_REGISTRY,
+ abi.encodeWithSelector(ICapabilitiesRegistry.getNode.selector, p2pIds[i]),
+ abi.encode(
+ ICapabilitiesRegistry.NodeInfo({
+ nodeOperatorId: 1,
+ signer: bytes32(signers[i]),
+ p2pId: p2pIds[i],
+ hashedCapabilityIds: new bytes32[](0),
+ configCount: uint32(1),
+ workflowDONId: uint32(1),
+ capabilitiesDONIds: new uint256[](0)
+ })
+ )
+ );
+ }
+ // Add chain selector for chain 1.
+ CCIPConfigTypes.ChainConfigInfo[] memory adds = new CCIPConfigTypes.ChainConfigInfo[](1);
+ adds[0] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 1,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: p2pIds, fChain: 1, config: bytes("config1")})
+ });
+
+ vm.expectEmit();
+ emit CCIPConfig.ChainConfigSet(1, adds[0].chainConfig);
+ s_ccipCC.applyChainConfigUpdates(new uint64[](0), adds);
+
+ return (p2pIds, signers, transmitters);
+ }
+
+ function test_getCapabilityConfiguration_Success() public {
+ bytes memory capConfig = s_ccipCC.getCapabilityConfiguration(42 /* doesn't matter, not used */ );
+ assertEq(capConfig.length, 0, "capability config length must be 0");
+ }
+}
+
+contract CCIPConfig_chainConfig is CCIPConfigSetup {
+ // Successes.
+
+ function test_applyChainConfigUpdates_addChainConfigs_Success() public {
+ bytes32[] memory chainReaders = new bytes32[](1);
+ chainReaders[0] = keccak256(abi.encode(1));
+ CCIPConfigTypes.ChainConfigInfo[] memory adds = new CCIPConfigTypes.ChainConfigInfo[](2);
+ adds[0] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 1,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 1, config: bytes("config1")})
+ });
+ adds[1] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 2,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 1, config: bytes("config2")})
+ });
+
+ vm.mockCall(
+ CAPABILITIES_REGISTRY,
+ abi.encodeWithSelector(ICapabilitiesRegistry.getNode.selector, chainReaders[0]),
+ abi.encode(
+ ICapabilitiesRegistry.NodeInfo({
+ nodeOperatorId: 1,
+ signer: bytes32(uint256(1)),
+ p2pId: chainReaders[0],
+ hashedCapabilityIds: new bytes32[](0),
+ configCount: uint32(1),
+ workflowDONId: uint32(1),
+ capabilitiesDONIds: new uint256[](0)
+ })
+ )
+ );
+
+ vm.expectEmit();
+ emit CCIPConfig.ChainConfigSet(1, adds[0].chainConfig);
+ vm.expectEmit();
+ emit CCIPConfig.ChainConfigSet(2, adds[1].chainConfig);
+ s_ccipCC.applyChainConfigUpdates(new uint64[](0), adds);
+
+ CCIPConfigTypes.ChainConfigInfo[] memory configs = s_ccipCC.getAllChainConfigs();
+ assertEq(configs.length, 2, "chain configs length must be 2");
+ assertEq(configs[0].chainSelector, 1, "chain selector must match");
+ assertEq(configs[1].chainSelector, 2, "chain selector must match");
+ }
+
+ function test_applyChainConfigUpdates_removeChainConfigs_Success() public {
+ bytes32[] memory chainReaders = new bytes32[](1);
+ chainReaders[0] = keccak256(abi.encode(1));
+ CCIPConfigTypes.ChainConfigInfo[] memory adds = new CCIPConfigTypes.ChainConfigInfo[](2);
+ adds[0] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 1,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 1, config: bytes("config1")})
+ });
+ adds[1] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 2,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 1, config: bytes("config2")})
+ });
+
+ vm.mockCall(
+ CAPABILITIES_REGISTRY,
+ abi.encodeWithSelector(ICapabilitiesRegistry.getNode.selector, chainReaders[0]),
+ abi.encode(
+ ICapabilitiesRegistry.NodeInfo({
+ nodeOperatorId: 1,
+ signer: bytes32(uint256(1)),
+ p2pId: chainReaders[0],
+ hashedCapabilityIds: new bytes32[](0),
+ configCount: uint32(1),
+ workflowDONId: uint32(1),
+ capabilitiesDONIds: new uint256[](0)
+ })
+ )
+ );
+
+ vm.expectEmit();
+ emit CCIPConfig.ChainConfigSet(1, adds[0].chainConfig);
+ vm.expectEmit();
+ emit CCIPConfig.ChainConfigSet(2, adds[1].chainConfig);
+ s_ccipCC.applyChainConfigUpdates(new uint64[](0), adds);
+
+ uint64[] memory removes = new uint64[](1);
+ removes[0] = uint64(1);
+
+ vm.expectEmit();
+ emit CCIPConfig.ChainConfigRemoved(1);
+ s_ccipCC.applyChainConfigUpdates(removes, new CCIPConfigTypes.ChainConfigInfo[](0));
+ }
+
+ // Reverts.
+
+ function test_applyChainConfigUpdates_selectorNotFound_Reverts() public {
+ uint64[] memory removes = new uint64[](1);
+ removes[0] = uint64(1);
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.ChainSelectorNotFound.selector, 1));
+ s_ccipCC.applyChainConfigUpdates(removes, new CCIPConfigTypes.ChainConfigInfo[](0));
+ }
+
+ function test_applyChainConfigUpdates_nodeNotInRegistry_Reverts() public {
+ bytes32[] memory chainReaders = new bytes32[](1);
+ chainReaders[0] = keccak256(abi.encode(1));
+ CCIPConfigTypes.ChainConfigInfo[] memory adds = new CCIPConfigTypes.ChainConfigInfo[](1);
+ adds[0] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 1,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 1, config: abi.encode(1, 2, 3)})
+ });
+
+ vm.mockCall(
+ CAPABILITIES_REGISTRY,
+ abi.encodeWithSelector(ICapabilitiesRegistry.getNode.selector, chainReaders[0]),
+ abi.encode(
+ ICapabilitiesRegistry.NodeInfo({
+ nodeOperatorId: 0,
+ signer: bytes32(0),
+ p2pId: bytes32(uint256(0)),
+ hashedCapabilityIds: new bytes32[](0),
+ configCount: uint32(1),
+ workflowDONId: uint32(1),
+ capabilitiesDONIds: new uint256[](0)
+ })
+ )
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.NodeNotInRegistry.selector, chainReaders[0]));
+ s_ccipCC.applyChainConfigUpdates(new uint64[](0), adds);
+ }
+
+ function test__applyChainConfigUpdates_FChainNotPositive_Reverts() public {
+ bytes32[] memory chainReaders = new bytes32[](1);
+ chainReaders[0] = keccak256(abi.encode(1));
+ CCIPConfigTypes.ChainConfigInfo[] memory adds = new CCIPConfigTypes.ChainConfigInfo[](2);
+ adds[0] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 1,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 1, config: bytes("config1")})
+ });
+ adds[1] = CCIPConfigTypes.ChainConfigInfo({
+ chainSelector: 2,
+ chainConfig: CCIPConfigTypes.ChainConfig({readers: chainReaders, fChain: 0, config: bytes("config2")}) // bad fChain
+ });
+
+ vm.mockCall(
+ CAPABILITIES_REGISTRY,
+ abi.encodeWithSelector(ICapabilitiesRegistry.getNode.selector, chainReaders[0]),
+ abi.encode(
+ ICapabilitiesRegistry.NodeInfo({
+ nodeOperatorId: 1,
+ signer: bytes32(uint256(1)),
+ p2pId: chainReaders[0],
+ hashedCapabilityIds: new bytes32[](0),
+ configCount: uint32(1),
+ workflowDONId: uint32(1),
+ capabilitiesDONIds: new uint256[](0)
+ })
+ )
+ );
+
+ vm.expectRevert(CCIPConfig.FChainMustBePositive.selector);
+ s_ccipCC.applyChainConfigUpdates(new uint64[](0), adds);
+ }
+}
+
+contract CCIPConfig_validateConfig is CCIPConfigSetup {
+ // Successes.
+
+ function test__validateConfig_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+ s_ccipCC.validateConfig(config);
+ }
+
+ // Reverts.
+
+ function test__validateConfig_ChainSelectorNotSet_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 0, // invalid
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.ChainSelectorNotSet.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_OfframpAddressCannotBeZero_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: bytes(""), // invalid
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.OfframpAddressCannotBeZero.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_ChainSelectorNotFound_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 2, // not set
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.ChainSelectorNotFound.selector, 2));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_TooManySigners_Reverts() public {
+ // 32 > 31 (max num oracles)
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(32);
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.TooManySigners.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_TooManyTransmitters_Reverts() public {
+ // 32 > 31 (max num oracles)
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(32);
+
+ // truncate signers but keep transmitters > 31
+ assembly {
+ mstore(signers, 30)
+ }
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.TooManyTransmitters.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_NotEnoughTransmitters_Reverts() public {
+ // 32 > 31 (max num oracles)
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(31);
+
+ // truncate transmitters to < 3 * fChain + 1
+ // since fChain is 1 in this case, we need to truncate to 3 transmitters.
+ assembly {
+ mstore(transmitters, 3)
+ }
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.NotEnoughTransmitters.selector, 3, 4));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_FMustBePositive_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 0,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.FMustBePositive.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_FTooHigh_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 2,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.FTooHigh.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_P2PIdsLengthNotMatching_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // truncate the p2pIds length
+ assembly {
+ mstore(p2pIds, 3)
+ }
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(CCIPConfig.P2PIdsLengthNotMatching.selector, uint256(3), uint256(4), uint256(4))
+ );
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_TooManyBootstrapP2PIds_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _makeBytes32Array(5, 0), // too many bootstrap p2pIds, 5 > 4
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(CCIPConfig.TooManyBootstrapP2PIds.selector);
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_NodeNotInRegistry_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ bytes32 nonExistentP2PId = keccak256("notInRegistry");
+ p2pIds[0] = nonExistentP2PId;
+
+ vm.mockCall(
+ CAPABILITIES_REGISTRY,
+ abi.encodeWithSelector(ICapabilitiesRegistry.getNode.selector, nonExistentP2PId),
+ abi.encode(
+ ICapabilitiesRegistry.NodeInfo({
+ nodeOperatorId: 0,
+ signer: bytes32(0),
+ p2pId: bytes32(uint256(0)),
+ hashedCapabilityIds: new bytes32[](0),
+ configCount: uint32(1),
+ workflowDONId: uint32(1),
+ capabilitiesDONIds: new uint256[](0)
+ })
+ )
+ );
+
+ // Config is for 4 nodes, so f == 1.
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.NodeNotInRegistry.selector, nonExistentP2PId));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_P2PIdsNotSorted_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // Config is for 4 nodes, so f == 1.
+
+ //swapping two adjacent p2pIds to make it unsorted
+ (p2pIds[2], p2pIds[3]) = (p2pIds[3], p2pIds[2]);
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(SortedSetValidationUtil.NotASortedSet.selector, p2pIds));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_BootstrapP2PIdsNotSorted_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // Config is for 4 nodes, so f == 1.
+
+ bytes32[] memory bootstrapP2PIds = _subset(p2pIds, 0, 2);
+
+ //swapping bootstrapP2PIds to make it unsorted
+ (bootstrapP2PIds[0], bootstrapP2PIds[1]) = (bootstrapP2PIds[1], bootstrapP2PIds[0]);
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: bootstrapP2PIds,
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(SortedSetValidationUtil.NotASortedSet.selector, bootstrapP2PIds));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_P2PIdsHasDuplicates_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // Config is for 4 nodes, so f == 1.
+
+ //forcing duplicate p2pIds
+ p2pIds[1] = p2pIds[2];
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 2),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(SortedSetValidationUtil.NotASortedSet.selector, p2pIds));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_BootstrapP2PIdsHasDuplicates_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // Config is for 4 nodes, so f == 1.
+
+ bytes32[] memory bootstrapP2PIds = _subset(p2pIds, 0, 2);
+ //forcing duplicate bootstrapP2PIds
+ bootstrapP2PIds[1] = bootstrapP2PIds[0];
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: bootstrapP2PIds,
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(SortedSetValidationUtil.NotASortedSet.selector, bootstrapP2PIds));
+ s_ccipCC.validateConfig(config);
+ }
+
+ function test__validateConfig_BootstrapP2PIdsNotASubsetOfP2PIds_Reverts() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // Config is for 4 nodes, so f == 1.
+
+ //forcing invalid bootstrapP2PIds where the bootstrapP2PIds is sorted, but one of the element is not in the p2pIdsSet
+ bytes32[] memory bootstrapP2PIds = _subset(p2pIds, 0, 2);
+ p2pIds[1] = bytes32(uint256(p2pIds[0]) + 100);
+
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: bootstrapP2PIds,
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(SortedSetValidationUtil.NotASubset.selector, bootstrapP2PIds, p2pIds));
+ s_ccipCC.validateConfig(config);
+ }
+}
+
+contract CCIPConfig_ConfigStateMachine is CCIPConfigSetup {
+ // Successful cases.
+
+ function test__stateFromConfigLength_Success() public {
+ uint256 configLen = 0;
+ CCIPConfigTypes.ConfigState state = s_ccipCC.stateFromConfigLength(configLen);
+ assertEq(uint256(state), uint256(CCIPConfigTypes.ConfigState.Init));
+
+ configLen = 1;
+ state = s_ccipCC.stateFromConfigLength(configLen);
+ assertEq(uint256(state), uint256(CCIPConfigTypes.ConfigState.Running));
+
+ configLen = 2;
+ state = s_ccipCC.stateFromConfigLength(configLen);
+ assertEq(uint256(state), uint256(CCIPConfigTypes.ConfigState.Staging));
+ }
+
+ function test__validateConfigStateTransition_Success() public {
+ s_ccipCC.validateConfigStateTransition(CCIPConfigTypes.ConfigState.Init, CCIPConfigTypes.ConfigState.Running);
+
+ s_ccipCC.validateConfigStateTransition(CCIPConfigTypes.ConfigState.Running, CCIPConfigTypes.ConfigState.Staging);
+
+ s_ccipCC.validateConfigStateTransition(CCIPConfigTypes.ConfigState.Staging, CCIPConfigTypes.ConfigState.Running);
+ }
+
+ function test__computeConfigDigest_Success() public {
+ // config digest must change upon:
+ // - ocr config change (e.g plugin type, chain selector, etc.)
+ // - don id change
+ // - config count change
+ bytes32[] memory p2pIds = _makeBytes32Array(4, 0);
+ bytes[] memory signers = _makeBytesArray(2, 10);
+ bytes[] memory transmitters = _makeBytesArray(2, 20);
+ CCIPConfigTypes.OCR3Config memory config = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("offchainConfig")
+ });
+ uint32 donId = 1;
+ uint32 configCount = 1;
+
+ bytes32 configDigest1 = s_ccipCC.computeConfigDigest(donId, configCount, config);
+
+ donId = 2;
+ bytes32 configDigest2 = s_ccipCC.computeConfigDigest(donId, configCount, config);
+
+ donId = 1;
+ configCount = 2;
+ bytes32 configDigest3 = s_ccipCC.computeConfigDigest(donId, configCount, config);
+
+ configCount = 1;
+ config.pluginType = Internal.OCRPluginType.Execution;
+ bytes32 configDigest4 = s_ccipCC.computeConfigDigest(donId, configCount, config);
+
+ assertNotEq(configDigest1, configDigest2, "config digests 1 and 2 must not match");
+ assertNotEq(configDigest1, configDigest3, "config digests 1 and 3 must not match");
+ assertNotEq(configDigest1, configDigest4, "config digests 1 and 4 must not match");
+
+ assertNotEq(configDigest2, configDigest3, "config digests 2 and 3 must not match");
+ assertNotEq(configDigest2, configDigest4, "config digests 2 and 4 must not match");
+ }
+
+ function test_Fuzz__groupByPluginType_Success(uint256 numCommitCfgs, uint256 numExecCfgs) public {
+ numCommitCfgs = bound(numCommitCfgs, 0, 2);
+ numExecCfgs = bound(numExecCfgs, 0, 2);
+
+ bytes32[] memory p2pIds = _makeBytes32Array(4, 0);
+ bytes[] memory signers = _makeBytesArray(4, 10);
+ bytes[] memory transmitters = _makeBytesArray(4, 20);
+ CCIPConfigTypes.OCR3Config[] memory cfgs = new CCIPConfigTypes.OCR3Config[](numCommitCfgs + numExecCfgs);
+ for (uint256 i = 0; i < numCommitCfgs; i++) {
+ cfgs[i] = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: abi.encode("commit", i)
+ });
+ }
+ for (uint256 i = 0; i < numExecCfgs; i++) {
+ cfgs[numCommitCfgs + i] = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Execution,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: abi.encode("exec", numCommitCfgs + i)
+ });
+ }
+ (CCIPConfigTypes.OCR3Config[] memory commitCfgs, CCIPConfigTypes.OCR3Config[] memory execCfgs) =
+ s_ccipCC.groupByPluginType(cfgs);
+
+ assertEq(commitCfgs.length, numCommitCfgs, "commitCfgs length must match");
+ assertEq(execCfgs.length, numExecCfgs, "execCfgs length must match");
+ for (uint256 i = 0; i < commitCfgs.length; i++) {
+ assertEq(uint8(commitCfgs[i].pluginType), uint8(Internal.OCRPluginType.Commit), "plugin type must be commit");
+ assertEq(commitCfgs[i].offchainConfig, abi.encode("commit", i), "offchain config must match");
+ }
+ for (uint256 i = 0; i < execCfgs.length; i++) {
+ assertEq(uint8(execCfgs[i].pluginType), uint8(Internal.OCRPluginType.Execution), "plugin type must be execution");
+ assertEq(execCfgs[i].offchainConfig, abi.encode("exec", numCommitCfgs + i), "offchain config must match");
+ }
+ }
+
+ function test__computeNewConfigWithMeta_InitToRunning_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](0);
+ CCIPConfigTypes.OCR3Config[] memory newConfig = new CCIPConfigTypes.OCR3Config[](1);
+ newConfig[0] = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.ConfigState currentState = CCIPConfigTypes.ConfigState.Init;
+ CCIPConfigTypes.ConfigState newState = CCIPConfigTypes.ConfigState.Running;
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta =
+ s_ccipCC.computeNewConfigWithMeta(donId, currentConfig, newConfig, currentState, newState);
+ assertEq(newConfigWithMeta.length, 1, "new config with meta length must be 1");
+ assertEq(newConfigWithMeta[0].configCount, uint64(1), "config count must be 1");
+ assertEq(uint8(newConfigWithMeta[0].config.pluginType), uint8(newConfig[0].pluginType), "plugin type must match");
+ assertEq(newConfigWithMeta[0].config.offchainConfig, newConfig[0].offchainConfig, "offchain config must match");
+ assertEq(
+ newConfigWithMeta[0].configDigest,
+ s_ccipCC.computeConfigDigest(donId, 1, newConfig[0]),
+ "config digest must match"
+ );
+
+ // This ensures that the test case is using correct inputs.
+ s_ccipCC.validateConfigTransition(currentConfig, newConfigWithMeta);
+ }
+
+ function test__computeNewConfigWithMeta_RunningToStaging_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+
+ CCIPConfigTypes.OCR3Config[] memory newConfig = new CCIPConfigTypes.OCR3Config[](2);
+ // existing blue config first.
+ newConfig[0] = blueConfig;
+ // green config next.
+ newConfig[1] = greenConfig;
+
+ CCIPConfigTypes.ConfigState currentState = CCIPConfigTypes.ConfigState.Running;
+ CCIPConfigTypes.ConfigState newState = CCIPConfigTypes.ConfigState.Staging;
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta =
+ s_ccipCC.computeNewConfigWithMeta(donId, currentConfig, newConfig, currentState, newState);
+ assertEq(newConfigWithMeta.length, 2, "new config with meta length must be 2");
+
+ assertEq(newConfigWithMeta[0].configCount, uint64(1), "config count of blue must be 1");
+ assertEq(
+ uint8(newConfigWithMeta[0].config.pluginType), uint8(blueConfig.pluginType), "plugin type of blue must match"
+ );
+ assertEq(
+ newConfigWithMeta[0].config.offchainConfig, blueConfig.offchainConfig, "offchain config of blue must match"
+ );
+ assertEq(
+ newConfigWithMeta[0].configDigest,
+ s_ccipCC.computeConfigDigest(donId, 1, blueConfig),
+ "config digest of blue must match"
+ );
+
+ assertEq(newConfigWithMeta[1].configCount, uint64(2), "config count of green must be 2");
+ assertEq(
+ uint8(newConfigWithMeta[1].config.pluginType), uint8(greenConfig.pluginType), "plugin type of green must match"
+ );
+ assertEq(
+ newConfigWithMeta[1].config.offchainConfig, greenConfig.offchainConfig, "offchain config of green must match"
+ );
+ assertEq(
+ newConfigWithMeta[1].configDigest,
+ s_ccipCC.computeConfigDigest(donId, 2, greenConfig),
+ "config digest of green must match"
+ );
+
+ // This ensures that the test case is using correct inputs.
+ s_ccipCC.validateConfigTransition(currentConfig, newConfigWithMeta);
+ }
+
+ function test__computeNewConfigWithMeta_StagingToRunning_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](2);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ currentConfig[1] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ });
+ CCIPConfigTypes.OCR3Config[] memory newConfig = new CCIPConfigTypes.OCR3Config[](1);
+ newConfig[0] = greenConfig;
+
+ CCIPConfigTypes.ConfigState currentState = CCIPConfigTypes.ConfigState.Staging;
+ CCIPConfigTypes.ConfigState newState = CCIPConfigTypes.ConfigState.Running;
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta =
+ s_ccipCC.computeNewConfigWithMeta(donId, currentConfig, newConfig, currentState, newState);
+
+ assertEq(newConfigWithMeta.length, 1, "new config with meta length must be 1");
+ assertEq(newConfigWithMeta[0].configCount, uint64(2), "config count must be 2");
+ assertEq(uint8(newConfigWithMeta[0].config.pluginType), uint8(greenConfig.pluginType), "plugin type must match");
+ assertEq(newConfigWithMeta[0].config.offchainConfig, greenConfig.offchainConfig, "offchain config must match");
+ assertEq(
+ newConfigWithMeta[0].configDigest, s_ccipCC.computeConfigDigest(donId, 2, greenConfig), "config digest must match"
+ );
+
+ // This ensures that the test case is using correct inputs.
+ s_ccipCC.validateConfigTransition(currentConfig, newConfigWithMeta);
+ }
+
+ function test__validateConfigTransition_InitToRunning_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](0);
+
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ function test__validateConfigTransition_RunningToStaging_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](2);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ newConfig[1] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ function test__validateConfigTransition_StagingToRunning_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](2);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ currentConfig[1] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ });
+
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ // Reverts.
+
+ function test_Fuzz__stateFromConfigLength_Reverts(uint256 configLen) public {
+ vm.assume(configLen > 2);
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.InvalidConfigLength.selector, configLen));
+ s_ccipCC.stateFromConfigLength(configLen);
+ }
+
+ function test__groupByPluginType_threeCommitConfigs_Reverts() public {
+ bytes32[] memory p2pIds = _makeBytes32Array(4, 0);
+ bytes[] memory signers = _makeBytesArray(4, 10);
+ bytes[] memory transmitters = _makeBytesArray(4, 20);
+ CCIPConfigTypes.OCR3Config[] memory cfgs = new CCIPConfigTypes.OCR3Config[](3);
+ for (uint256 i = 0; i < 3; i++) {
+ cfgs[i] = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: abi.encode("commit", i)
+ });
+ }
+ vm.expectRevert();
+ s_ccipCC.groupByPluginType(cfgs);
+ }
+
+ function test__groupByPluginType_threeExecutionConfigs_Reverts() public {
+ bytes32[] memory p2pIds = _makeBytes32Array(4, 0);
+ bytes[] memory signers = _makeBytesArray(4, 10);
+ bytes[] memory transmitters = _makeBytesArray(4, 20);
+ CCIPConfigTypes.OCR3Config[] memory cfgs = new CCIPConfigTypes.OCR3Config[](3);
+ for (uint256 i = 0; i < 3; i++) {
+ cfgs[i] = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Execution,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: abi.encode("exec", i)
+ });
+ }
+ vm.expectRevert();
+ s_ccipCC.groupByPluginType(cfgs);
+ }
+
+ function test__groupByPluginType_TooManyOCR3Configs_Reverts() public {
+ CCIPConfigTypes.OCR3Config[] memory cfgs = new CCIPConfigTypes.OCR3Config[](5);
+ vm.expectRevert(CCIPConfig.TooManyOCR3Configs.selector);
+ s_ccipCC.groupByPluginType(cfgs);
+ }
+
+ function test__validateConfigTransition_InitToRunning_WrongConfigCount_Reverts() public {
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 0,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](0);
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.WrongConfigCount.selector, 0, 1));
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ function test__validateConfigTransition_RunningToStaging_WrongConfigDigestBlueGreen_Reverts() public {
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](2);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 3, blueConfig) // wrong config digest (due to diff config count)
+ });
+ newConfig[1] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ CCIPConfig.WrongConfigDigestBlueGreen.selector,
+ s_ccipCC.computeConfigDigest(donId, 3, blueConfig),
+ s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ )
+ );
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ function test__validateConfigTransition_RunningToStaging_WrongConfigCount_Reverts() public {
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](2);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ newConfig[1] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 3, // wrong config count
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 3, greenConfig)
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.WrongConfigCount.selector, 3, 2));
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ function test__validateConfigTransition_StagingToRunning_WrongConfigDigest_Reverts() public {
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(_makeBytes32Array(4, 0), 0, 1),
+ p2pIds: _makeBytes32Array(4, 0),
+ signers: _makeBytesArray(4, 10),
+ transmitters: _makeBytesArray(4, 20),
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](2);
+ currentConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 1,
+ config: blueConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 1, blueConfig)
+ });
+ currentConfig[1] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ });
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ newConfig[0] = CCIPConfigTypes.OCR3ConfigWithMeta({
+ configCount: 2,
+ config: greenConfig,
+ configDigest: s_ccipCC.computeConfigDigest(donId, 3, greenConfig) // wrong config digest
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ CCIPConfig.WrongConfigDigest.selector,
+ s_ccipCC.computeConfigDigest(donId, 3, greenConfig),
+ s_ccipCC.computeConfigDigest(donId, 2, greenConfig)
+ )
+ );
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+
+ function test__validateConfigTransition_NonExistentConfigTransition_Reverts() public {
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](3);
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfig = new CCIPConfigTypes.OCR3ConfigWithMeta[](1);
+ vm.expectRevert(CCIPConfig.NonExistentConfigTransition.selector);
+ s_ccipCC.validateConfigTransition(currentConfig, newConfig);
+ }
+}
+
+contract CCIPConfig__updatePluginConfig is CCIPConfigSetup {
+ // Successes.
+
+ function test__updatePluginConfig_InitToRunning_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config[] memory configs = new CCIPConfigTypes.OCR3Config[](1);
+ configs[0] = blueConfig;
+
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, configs);
+
+ // should see the updated config in the contract state.
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedConfig =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Commit);
+ assertEq(storedConfig.length, 1, "don config length must be 1");
+ assertEq(storedConfig[0].configCount, uint64(1), "config count must be 1");
+ assertEq(uint256(storedConfig[0].config.pluginType), uint256(blueConfig.pluginType), "plugin type must match");
+ }
+
+ function test__updatePluginConfig_RunningToStaging_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // add blue config.
+ uint32 donId = 1;
+ Internal.OCRPluginType pluginType = Internal.OCRPluginType.Commit;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config[] memory startConfigs = new CCIPConfigTypes.OCR3Config[](1);
+ startConfigs[0] = blueConfig;
+
+ // add blue AND green config to indicate an update.
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, startConfigs);
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+ CCIPConfigTypes.OCR3Config[] memory blueAndGreen = new CCIPConfigTypes.OCR3Config[](2);
+ blueAndGreen[0] = blueConfig;
+ blueAndGreen[1] = greenConfig;
+
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, blueAndGreen);
+
+ // should see the updated config in the contract state.
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedConfig =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Commit);
+ assertEq(storedConfig.length, 2, "don config length must be 2");
+ // 0 index is blue config, 1 index is green config.
+ assertEq(storedConfig[1].configCount, uint64(2), "config count must be 2");
+ assertEq(
+ uint256(storedConfig[0].config.pluginType), uint256(Internal.OCRPluginType.Commit), "plugin type must match"
+ );
+ assertEq(
+ uint256(storedConfig[1].config.pluginType), uint256(Internal.OCRPluginType.Commit), "plugin type must match"
+ );
+ assertEq(storedConfig[0].config.offchainConfig, bytes("commit"), "blue offchain config must match");
+ assertEq(storedConfig[1].config.offchainConfig, bytes("commit-new"), "green offchain config must match");
+ }
+
+ function test__updatePluginConfig_StagingToRunning_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ // add blue config.
+ uint32 donId = 1;
+ Internal.OCRPluginType pluginType = Internal.OCRPluginType.Commit;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config[] memory startConfigs = new CCIPConfigTypes.OCR3Config[](1);
+ startConfigs[0] = blueConfig;
+
+ // add blue AND green config to indicate an update.
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, startConfigs);
+ CCIPConfigTypes.OCR3Config memory greenConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit-new")
+ });
+ CCIPConfigTypes.OCR3Config[] memory blueAndGreen = new CCIPConfigTypes.OCR3Config[](2);
+ blueAndGreen[0] = blueConfig;
+ blueAndGreen[1] = greenConfig;
+
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, blueAndGreen);
+
+ // should see the updated config in the contract state.
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedConfig =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Commit);
+ assertEq(storedConfig.length, 2, "don config length must be 2");
+ // 0 index is blue config, 1 index is green config.
+ assertEq(storedConfig[1].configCount, uint64(2), "config count must be 2");
+ assertEq(
+ uint256(storedConfig[0].config.pluginType), uint256(Internal.OCRPluginType.Commit), "plugin type must match"
+ );
+ assertEq(
+ uint256(storedConfig[1].config.pluginType), uint256(Internal.OCRPluginType.Commit), "plugin type must match"
+ );
+ assertEq(storedConfig[0].config.offchainConfig, bytes("commit"), "blue offchain config must match");
+ assertEq(storedConfig[1].config.offchainConfig, bytes("commit-new"), "green offchain config must match");
+
+ // promote green to blue.
+ CCIPConfigTypes.OCR3Config[] memory promote = new CCIPConfigTypes.OCR3Config[](1);
+ promote[0] = greenConfig;
+
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, promote);
+
+ // should see the updated config in the contract state.
+ storedConfig = s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Commit);
+ assertEq(storedConfig.length, 1, "don config length must be 1");
+ assertEq(storedConfig[0].configCount, uint64(2), "config count must be 2");
+ assertEq(
+ uint256(storedConfig[0].config.pluginType), uint256(Internal.OCRPluginType.Commit), "plugin type must match"
+ );
+ assertEq(storedConfig[0].config.offchainConfig, bytes("commit-new"), "green offchain config must match");
+ }
+
+ // Reverts.
+ function test__updatePluginConfig_InvalidConfigLength_Reverts() public {
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config[] memory newConfig = new CCIPConfigTypes.OCR3Config[](3);
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.InvalidConfigLength.selector, uint256(3)));
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, newConfig);
+ }
+
+ function test__updatePluginConfig_InvalidConfigStateTransition_Reverts() public {
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config[] memory newConfig = new CCIPConfigTypes.OCR3Config[](2);
+ // 0 -> 2 is an invalid state transition.
+ vm.expectRevert(abi.encodeWithSelector(CCIPConfig.InvalidConfigStateTransition.selector, 0, 2));
+ s_ccipCC.updatePluginConfig(donId, Internal.OCRPluginType.Commit, newConfig);
+ }
+}
+
+contract CCIPConfig_beforeCapabilityConfigSet is CCIPConfigSetup {
+ // Successes.
+ function test_beforeCapabilityConfigSet_ZeroLengthConfig_Success() public {
+ changePrank(CAPABILITIES_REGISTRY);
+
+ CCIPConfigTypes.OCR3Config[] memory configs = new CCIPConfigTypes.OCR3Config[](0);
+ bytes memory encodedConfigs = abi.encode(configs);
+ s_ccipCC.beforeCapabilityConfigSet(new bytes32[](0), encodedConfigs, 1, 1);
+ }
+
+ function test_beforeCapabilityConfigSet_CommitConfigOnly_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ changePrank(CAPABILITIES_REGISTRY);
+
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config[] memory configs = new CCIPConfigTypes.OCR3Config[](1);
+ configs[0] = blueConfig;
+
+ bytes memory encoded = abi.encode(configs);
+ s_ccipCC.beforeCapabilityConfigSet(new bytes32[](0), encoded, 1, donId);
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedConfigs =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Commit);
+ assertEq(storedConfigs.length, 1, "config length must be 1");
+ assertEq(storedConfigs[0].configCount, uint64(1), "config count must be 1");
+ assertEq(
+ uint256(storedConfigs[0].config.pluginType), uint256(Internal.OCRPluginType.Commit), "plugin type must be commit"
+ );
+ }
+
+ function test_beforeCapabilityConfigSet_ExecConfigOnly_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ changePrank(CAPABILITIES_REGISTRY);
+
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Execution,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("exec")
+ });
+ CCIPConfigTypes.OCR3Config[] memory configs = new CCIPConfigTypes.OCR3Config[](1);
+ configs[0] = blueConfig;
+
+ bytes memory encoded = abi.encode(configs);
+ s_ccipCC.beforeCapabilityConfigSet(new bytes32[](0), encoded, 1, donId);
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedConfigs =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Execution);
+ assertEq(storedConfigs.length, 1, "config length must be 1");
+ assertEq(storedConfigs[0].configCount, uint64(1), "config count must be 1");
+ assertEq(
+ uint256(storedConfigs[0].config.pluginType),
+ uint256(Internal.OCRPluginType.Execution),
+ "plugin type must be execution"
+ );
+ }
+
+ function test_beforeCapabilityConfigSet_CommitAndExecConfig_Success() public {
+ (bytes32[] memory p2pIds, bytes[] memory signers, bytes[] memory transmitters) = _addChainConfig(4);
+ changePrank(CAPABILITIES_REGISTRY);
+
+ uint32 donId = 1;
+ CCIPConfigTypes.OCR3Config memory blueCommitConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Commit,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("commit")
+ });
+ CCIPConfigTypes.OCR3Config memory blueExecConfig = CCIPConfigTypes.OCR3Config({
+ pluginType: Internal.OCRPluginType.Execution,
+ offrampAddress: abi.encodePacked(keccak256(abi.encode("offramp"))),
+ chainSelector: 1,
+ bootstrapP2PIds: _subset(p2pIds, 0, 1),
+ p2pIds: p2pIds,
+ signers: signers,
+ transmitters: transmitters,
+ F: 1,
+ offchainConfigVersion: 30,
+ offchainConfig: bytes("exec")
+ });
+ CCIPConfigTypes.OCR3Config[] memory configs = new CCIPConfigTypes.OCR3Config[](2);
+ configs[0] = blueExecConfig;
+ configs[1] = blueCommitConfig;
+
+ bytes memory encoded = abi.encode(configs);
+ s_ccipCC.beforeCapabilityConfigSet(new bytes32[](0), encoded, 1, donId);
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedExecConfigs =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Execution);
+ assertEq(storedExecConfigs.length, 1, "config length must be 1");
+ assertEq(storedExecConfigs[0].configCount, uint64(1), "config count must be 1");
+ assertEq(
+ uint256(storedExecConfigs[0].config.pluginType),
+ uint256(Internal.OCRPluginType.Execution),
+ "plugin type must be execution"
+ );
+
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory storedCommitConfigs =
+ s_ccipCC.getOCRConfig(donId, Internal.OCRPluginType.Commit);
+ assertEq(storedCommitConfigs.length, 1, "config length must be 1");
+ assertEq(storedCommitConfigs[0].configCount, uint64(1), "config count must be 1");
+ assertEq(
+ uint256(storedCommitConfigs[0].config.pluginType),
+ uint256(Internal.OCRPluginType.Commit),
+ "plugin type must be commit"
+ );
+ }
+
+ // Reverts.
+
+ function test_beforeCapabilityConfigSet_OnlyCapabilitiesRegistryCanCall_Reverts() public {
+ bytes32[] memory nodes = new bytes32[](0);
+ bytes memory config = bytes("");
+ uint64 configCount = 1;
+ uint32 donId = 1;
+ vm.expectRevert(CCIPConfig.OnlyCapabilitiesRegistryCanCall.selector);
+ s_ccipCC.beforeCapabilityConfigSet(nodes, config, configCount, donId);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/commitStore/CommitStore.t.sol b/contracts/src/v0.8/ccip/test/commitStore/CommitStore.t.sol
new file mode 100644
index 00000000000..7598f9ccb69
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/commitStore/CommitStore.t.sol
@@ -0,0 +1,618 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPriceRegistry} from "../../interfaces/IPriceRegistry.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+
+import {AuthorizedCallers} from "../../../shared/access/AuthorizedCallers.sol";
+import {CommitStore} from "../../CommitStore.sol";
+import {PriceRegistry} from "../../PriceRegistry.sol";
+import {RMN} from "../../RMN.sol";
+import {MerkleMultiProof} from "../../libraries/MerkleMultiProof.sol";
+import {OCR2Abstract} from "../../ocr/OCR2Abstract.sol";
+import {CommitStoreHelper} from "../helpers/CommitStoreHelper.sol";
+import {OCR2BaseSetup} from "../ocr/OCR2Base.t.sol";
+import {PriceRegistrySetup} from "../priceRegistry/PriceRegistry.t.sol";
+
+contract CommitStoreSetup is PriceRegistrySetup, OCR2BaseSetup {
+ CommitStoreHelper internal s_commitStore;
+
+ function setUp() public virtual override(PriceRegistrySetup, OCR2BaseSetup) {
+ PriceRegistrySetup.setUp();
+ OCR2BaseSetup.setUp();
+
+ s_commitStore = new CommitStoreHelper(
+ CommitStore.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: ON_RAMP_ADDRESS,
+ rmnProxy: address(s_mockRMN)
+ })
+ );
+ CommitStore.DynamicConfig memory dynamicConfig =
+ CommitStore.DynamicConfig({priceRegistry: address(s_priceRegistry)});
+ s_commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+
+ address[] memory priceUpdaters = new address[](1);
+ priceUpdaters[0] = address(s_commitStore);
+ s_priceRegistry.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: priceUpdaters, removedCallers: new address[](0)})
+ );
+ }
+}
+
+contract CommitStoreRealRMNSetup is PriceRegistrySetup, OCR2BaseSetup {
+ CommitStoreHelper internal s_commitStore;
+
+ RMN internal s_rmn;
+
+ address internal constant BLESS_VOTE_ADDR = address(8888);
+
+ function setUp() public virtual override(PriceRegistrySetup, OCR2BaseSetup) {
+ PriceRegistrySetup.setUp();
+ OCR2BaseSetup.setUp();
+
+ RMN.Voter[] memory voters = new RMN.Voter[](1);
+ voters[0] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTE_ADDR, curseVoteAddr: address(9999), blessWeight: 1, curseWeight: 1});
+ // Overwrite base mock rmn with real.
+ s_rmn = new RMN(RMN.Config({voters: voters, blessWeightThreshold: 1, curseWeightThreshold: 1}));
+ s_commitStore = new CommitStoreHelper(
+ CommitStore.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: ON_RAMP_ADDRESS,
+ rmnProxy: address(s_rmn)
+ })
+ );
+ CommitStore.DynamicConfig memory dynamicConfig =
+ CommitStore.DynamicConfig({priceRegistry: address(s_priceRegistry)});
+ s_commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+ }
+}
+
+contract CommitStore_constructor is PriceRegistrySetup, OCR2BaseSetup {
+ function setUp() public virtual override(PriceRegistrySetup, OCR2BaseSetup) {
+ PriceRegistrySetup.setUp();
+ OCR2BaseSetup.setUp();
+ }
+
+ function test_Constructor_Success() public {
+ CommitStore.StaticConfig memory staticConfig = CommitStore.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: 0x2C44CDDdB6a900Fa2B585dd299E03D12Fa4293Bc,
+ rmnProxy: address(s_mockRMN)
+ });
+ CommitStore.DynamicConfig memory dynamicConfig =
+ CommitStore.DynamicConfig({priceRegistry: address(s_priceRegistry)});
+
+ vm.expectEmit();
+ emit CommitStore.ConfigSet(staticConfig, dynamicConfig);
+
+ CommitStore commitStore = new CommitStore(staticConfig);
+ commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+
+ CommitStore.StaticConfig memory gotStaticConfig = commitStore.getStaticConfig();
+
+ assertEq(staticConfig.chainSelector, gotStaticConfig.chainSelector);
+ assertEq(staticConfig.sourceChainSelector, gotStaticConfig.sourceChainSelector);
+ assertEq(staticConfig.onRamp, gotStaticConfig.onRamp);
+ assertEq(staticConfig.rmnProxy, gotStaticConfig.rmnProxy);
+
+ CommitStore.DynamicConfig memory gotDynamicConfig = commitStore.getDynamicConfig();
+
+ assertEq(dynamicConfig.priceRegistry, gotDynamicConfig.priceRegistry);
+
+ // CommitStore initial values
+ assertEq(0, commitStore.getLatestPriceEpochAndRound());
+ assertEq(1, commitStore.getExpectedNextSequenceNumber());
+ assertEq(commitStore.typeAndVersion(), "CommitStore 1.5.0-dev");
+ assertEq(OWNER, commitStore.owner());
+ assertTrue(commitStore.isUnpausedAndNotCursed());
+ }
+}
+
+contract CommitStore_setMinSeqNr is CommitStoreSetup {
+ function test_Fuzz_SetMinSeqNr_Success(uint64 minSeqNr) public {
+ vm.expectEmit();
+ emit CommitStore.SequenceNumberSet(s_commitStore.getExpectedNextSequenceNumber(), minSeqNr);
+
+ s_commitStore.setMinSeqNr(minSeqNr);
+
+ assertEq(s_commitStore.getExpectedNextSequenceNumber(), minSeqNr);
+ }
+
+ // Reverts
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ s_commitStore.setMinSeqNr(6723);
+ }
+}
+
+contract CommitStore_setDynamicConfig is CommitStoreSetup {
+ function test_Fuzz_SetDynamicConfig_Success(address priceRegistry) public {
+ vm.assume(priceRegistry != address(0));
+ CommitStore.StaticConfig memory staticConfig = s_commitStore.getStaticConfig();
+ CommitStore.DynamicConfig memory dynamicConfig = CommitStore.DynamicConfig({priceRegistry: priceRegistry});
+ bytes memory onchainConfig = abi.encode(dynamicConfig);
+
+ vm.expectEmit();
+ emit CommitStore.ConfigSet(staticConfig, dynamicConfig);
+
+ uint32 configCount = 1;
+
+ vm.expectEmit();
+ emit OCR2Abstract.ConfigSet(
+ uint32(block.number),
+ getBasicConfigDigest(address(s_commitStore), s_f, configCount, onchainConfig),
+ configCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ onchainConfig,
+ s_offchainConfigVersion,
+ abi.encode("")
+ );
+
+ s_commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, onchainConfig, s_offchainConfigVersion, abi.encode("")
+ );
+
+ CommitStore.DynamicConfig memory gotDynamicConfig = s_commitStore.getDynamicConfig();
+ assertEq(gotDynamicConfig.priceRegistry, dynamicConfig.priceRegistry);
+ }
+
+ function test_PriceEpochCleared_Success() public {
+ // Set latest price epoch and round to non-zero.
+ uint40 latestEpochAndRound = 1782155;
+ s_commitStore.setLatestPriceEpochAndRound(latestEpochAndRound);
+ assertEq(latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+
+ CommitStore.DynamicConfig memory dynamicConfig = CommitStore.DynamicConfig({priceRegistry: address(1)});
+ // New config should clear it.
+ s_commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+ // Assert cleared.
+ assertEq(0, s_commitStore.getLatestPriceEpochAndRound());
+ }
+
+ // Reverts
+ function test_OnlyOwner_Revert() public {
+ CommitStore.DynamicConfig memory dynamicConfig = CommitStore.DynamicConfig({priceRegistry: address(23784264)});
+
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ s_commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+ }
+
+ function test_InvalidCommitStoreConfig_Revert() public {
+ CommitStore.DynamicConfig memory dynamicConfig = CommitStore.DynamicConfig({priceRegistry: address(0)});
+
+ vm.expectRevert(CommitStore.InvalidCommitStoreConfig.selector);
+ s_commitStore.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+ }
+}
+
+contract CommitStore_resetUnblessedRoots is CommitStoreRealRMNSetup {
+ function test_ResetUnblessedRoots_Success() public {
+ bytes32[] memory rootsToReset = new bytes32[](3);
+ rootsToReset[0] = "1";
+ rootsToReset[1] = "2";
+ rootsToReset[2] = "3";
+
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(1, 2),
+ merkleRoot: rootsToReset[0]
+ });
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+
+ report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(3, 4),
+ merkleRoot: rootsToReset[1]
+ });
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+
+ report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(5, 5),
+ merkleRoot: rootsToReset[2]
+ });
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+
+ IRMN.TaggedRoot[] memory blessedTaggedRoots = new IRMN.TaggedRoot[](1);
+ blessedTaggedRoots[0] = IRMN.TaggedRoot({commitStore: address(s_commitStore), root: rootsToReset[1]});
+
+ vm.startPrank(BLESS_VOTE_ADDR);
+ s_rmn.voteToBless(blessedTaggedRoots);
+
+ vm.expectEmit(false, false, false, true);
+ emit CommitStore.RootRemoved(rootsToReset[0]);
+
+ vm.expectEmit(false, false, false, true);
+ emit CommitStore.RootRemoved(rootsToReset[2]);
+
+ vm.startPrank(OWNER);
+ s_commitStore.resetUnblessedRoots(rootsToReset);
+
+ assertEq(0, s_commitStore.getMerkleRoot(rootsToReset[0]));
+ assertEq(BLOCK_TIME, s_commitStore.getMerkleRoot(rootsToReset[1]));
+ assertEq(0, s_commitStore.getMerkleRoot(rootsToReset[2]));
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ bytes32[] memory rootToReset;
+ s_commitStore.resetUnblessedRoots(rootToReset);
+ }
+}
+
+contract CommitStore_report is CommitStoreSetup {
+ function test_ReportOnlyRootSuccess_gas() public {
+ vm.pauseGasMetering();
+ uint64 max1 = 931;
+ bytes32 root = "Only a single root";
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(1, max1),
+ merkleRoot: root
+ });
+
+ vm.expectEmit();
+ emit CommitStore.ReportAccepted(report);
+
+ bytes memory encodedReport = abi.encode(report);
+
+ vm.resumeGasMetering();
+ s_commitStore.report(encodedReport, ++s_latestEpochAndRound);
+ vm.pauseGasMetering();
+
+ assertEq(max1 + 1, s_commitStore.getExpectedNextSequenceNumber());
+ assertEq(block.timestamp, s_commitStore.getMerkleRoot(root));
+ vm.resumeGasMetering();
+ }
+
+ function test_ReportAndPriceUpdate_Success() public {
+ uint64 max1 = 12;
+
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ interval: CommitStore.Interval(1, max1),
+ merkleRoot: "test #2"
+ });
+
+ vm.expectEmit();
+ emit CommitStore.ReportAccepted(report);
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+
+ assertEq(max1 + 1, s_commitStore.getExpectedNextSequenceNumber());
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+ }
+
+ function test_StaleReportWithRoot_Success() public {
+ uint64 maxSeq = 12;
+ uint224 tokenStartPrice =
+ IPriceRegistry(s_commitStore.getDynamicConfig().priceRegistry).getTokenPrice(s_sourceFeeToken).value;
+
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ interval: CommitStore.Interval(1, maxSeq),
+ merkleRoot: "stale report 1"
+ });
+
+ vm.expectEmit();
+ emit CommitStore.ReportAccepted(report);
+
+ s_commitStore.report(abi.encode(report), s_latestEpochAndRound);
+ assertEq(maxSeq + 1, s_commitStore.getExpectedNextSequenceNumber());
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+
+ report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(maxSeq + 1, maxSeq * 2),
+ merkleRoot: "stale report 2"
+ });
+
+ vm.expectEmit();
+ emit CommitStore.ReportAccepted(report);
+
+ s_commitStore.report(abi.encode(report), s_latestEpochAndRound);
+ assertEq(maxSeq * 2 + 1, s_commitStore.getExpectedNextSequenceNumber());
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+ assertEq(
+ tokenStartPrice,
+ IPriceRegistry(s_commitStore.getDynamicConfig().priceRegistry).getTokenPrice(s_sourceFeeToken).value
+ );
+ }
+
+ function test_OnlyTokenPriceUpdates_Success() public {
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ interval: CommitStore.Interval(0, 0),
+ merkleRoot: ""
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+ }
+
+ function test_OnlyGasPriceUpdates_Success() public {
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ interval: CommitStore.Interval(0, 0),
+ merkleRoot: ""
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+ }
+
+ function test_ValidPriceUpdateThenStaleReportWithRoot_Success() public {
+ uint64 maxSeq = 12;
+ uint224 tokenPrice1 = 4e18;
+ uint224 tokenPrice2 = 5e18;
+
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, tokenPrice1),
+ interval: CommitStore.Interval(0, 0),
+ merkleRoot: ""
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, tokenPrice1, block.timestamp);
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+
+ report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, tokenPrice2),
+ interval: CommitStore.Interval(1, maxSeq),
+ merkleRoot: "stale report"
+ });
+
+ vm.expectEmit();
+ emit CommitStore.ReportAccepted(report);
+
+ s_commitStore.report(abi.encode(report), s_latestEpochAndRound);
+
+ assertEq(maxSeq + 1, s_commitStore.getExpectedNextSequenceNumber());
+ assertEq(
+ tokenPrice1, IPriceRegistry(s_commitStore.getDynamicConfig().priceRegistry).getTokenPrice(s_sourceFeeToken).value
+ );
+ assertEq(s_latestEpochAndRound, s_commitStore.getLatestPriceEpochAndRound());
+ }
+
+ // Reverts
+
+ function test_Paused_Revert() public {
+ s_commitStore.pause();
+ bytes memory report;
+ vm.expectRevert(CommitStore.PausedError.selector);
+ s_commitStore.report(report, ++s_latestEpochAndRound);
+ }
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(CommitStore.CursedByRMN.selector);
+ bytes memory report;
+ s_commitStore.report(report, ++s_latestEpochAndRound);
+ }
+
+ function test_InvalidRootRevert() public {
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(1, 4),
+ merkleRoot: bytes32(0)
+ });
+
+ vm.expectRevert(CommitStore.InvalidRoot.selector);
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ }
+
+ function test_InvalidInterval_Revert() public {
+ CommitStore.Interval memory interval = CommitStore.Interval(2, 2);
+ CommitStore.CommitReport memory report =
+ CommitStore.CommitReport({priceUpdates: getEmptyPriceUpdates(), interval: interval, merkleRoot: bytes32(0)});
+
+ vm.expectRevert(abi.encodeWithSelector(CommitStore.InvalidInterval.selector, interval));
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ }
+
+ function test_InvalidIntervalMinLargerThanMax_Revert() public {
+ CommitStore.Interval memory interval = CommitStore.Interval(1, 0);
+ CommitStore.CommitReport memory report =
+ CommitStore.CommitReport({priceUpdates: getEmptyPriceUpdates(), interval: interval, merkleRoot: bytes32(0)});
+
+ vm.expectRevert(abi.encodeWithSelector(CommitStore.InvalidInterval.selector, interval));
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ }
+
+ function test_ZeroEpochAndRound_Revert() public {
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ interval: CommitStore.Interval(0, 0),
+ merkleRoot: bytes32(0)
+ });
+
+ vm.expectRevert(CommitStore.StaleReport.selector);
+
+ s_commitStore.report(abi.encode(report), 0);
+ }
+
+ function test_OnlyPriceUpdateStaleReport_Revert() public {
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ interval: CommitStore.Interval(0, 0),
+ merkleRoot: bytes32(0)
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+
+ vm.expectRevert(CommitStore.StaleReport.selector);
+ s_commitStore.report(abi.encode(report), s_latestEpochAndRound);
+ }
+
+ function test_RootAlreadyCommitted_Revert() public {
+ CommitStore.CommitReport memory report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(1, 2),
+ merkleRoot: "Only a single root"
+ });
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+
+ report = CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(3, 3),
+ merkleRoot: "Only a single root"
+ });
+
+ vm.expectRevert(CommitStore.RootAlreadyCommitted.selector);
+
+ s_commitStore.report(abi.encode(report), ++s_latestEpochAndRound);
+ }
+}
+
+contract CommitStore_verify is CommitStoreRealRMNSetup {
+ function test_NotBlessed_Success() public {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = "root";
+ s_commitStore.report(
+ abi.encode(
+ CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(1, 2),
+ merkleRoot: leaves[0]
+ })
+ ),
+ ++s_latestEpochAndRound
+ );
+ bytes32[] memory proofs = new bytes32[](0);
+ // We have not blessed this root, should return 0.
+ uint256 timestamp = s_commitStore.verify(leaves, proofs, 0);
+ assertEq(uint256(0), timestamp);
+ }
+
+ function test_Blessed_Success() public {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = "root";
+ s_commitStore.report(
+ abi.encode(
+ CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(1, 2),
+ merkleRoot: leaves[0]
+ })
+ ),
+ ++s_latestEpochAndRound
+ );
+ // Bless that root.
+ IRMN.TaggedRoot[] memory taggedRoots = new IRMN.TaggedRoot[](1);
+ taggedRoots[0] = IRMN.TaggedRoot({commitStore: address(s_commitStore), root: leaves[0]});
+ vm.startPrank(BLESS_VOTE_ADDR);
+ s_rmn.voteToBless(taggedRoots);
+ bytes32[] memory proofs = new bytes32[](0);
+ uint256 timestamp = s_commitStore.verify(leaves, proofs, 0);
+ assertEq(BLOCK_TIME, timestamp);
+ }
+
+ // Reverts
+
+ function test_Paused_Revert() public {
+ s_commitStore.pause();
+
+ bytes32[] memory hashedLeaves = new bytes32[](0);
+ bytes32[] memory proofs = new bytes32[](0);
+ uint256 proofFlagBits = 0;
+
+ vm.expectRevert(CommitStore.PausedError.selector);
+ s_commitStore.verify(hashedLeaves, proofs, proofFlagBits);
+ }
+
+ function test_TooManyLeaves_Revert() public {
+ bytes32[] memory leaves = new bytes32[](258);
+ bytes32[] memory proofs = new bytes32[](0);
+
+ vm.expectRevert(MerkleMultiProof.InvalidProof.selector);
+
+ s_commitStore.verify(leaves, proofs, 0);
+ }
+}
+
+contract CommitStore_isUnpausedAndRMNHealthy is CommitStoreSetup {
+ function test_RMN_Success() public {
+ // Test pausing
+ assertFalse(s_commitStore.paused());
+ assertTrue(s_commitStore.isUnpausedAndNotCursed());
+ s_commitStore.pause();
+ assertTrue(s_commitStore.paused());
+ assertFalse(s_commitStore.isUnpausedAndNotCursed());
+ s_commitStore.unpause();
+ assertFalse(s_commitStore.paused());
+ assertTrue(s_commitStore.isUnpausedAndNotCursed());
+
+ // Test rmn
+ s_mockRMN.setGlobalCursed(true);
+ assertFalse(s_commitStore.isUnpausedAndNotCursed());
+ s_mockRMN.setGlobalCursed(false);
+ // TODO: also test with s_mockRMN.setChainCursed(sourceChainSelector),
+ // also for other similar tests (e.g., OffRamp, OnRamp)
+ assertTrue(s_commitStore.isUnpausedAndNotCursed());
+
+ s_mockRMN.setGlobalCursed(true);
+ s_commitStore.pause();
+ assertFalse(s_commitStore.isUnpausedAndNotCursed());
+ }
+}
+
+contract CommitStore_setLatestPriceEpochAndRound is CommitStoreSetup {
+ function test_SetLatestPriceEpochAndRound_Success() public {
+ uint40 latestRoundAndEpoch = 1782155;
+
+ vm.expectEmit();
+ emit CommitStore.LatestPriceEpochAndRoundSet(
+ uint40(s_commitStore.getLatestPriceEpochAndRound()), latestRoundAndEpoch
+ );
+
+ s_commitStore.setLatestPriceEpochAndRound(latestRoundAndEpoch);
+
+ assertEq(uint40(s_commitStore.getLatestPriceEpochAndRound()), latestRoundAndEpoch);
+ }
+
+ // Reverts
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ s_commitStore.setLatestPriceEpochAndRound(6723);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/e2e/End2End.t.sol b/contracts/src/v0.8/ccip/test/e2e/End2End.t.sol
new file mode 100644
index 00000000000..816862cbdfc
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/e2e/End2End.t.sol
@@ -0,0 +1,116 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../commitStore/CommitStore.t.sol";
+import "../helpers/MerkleHelper.sol";
+import "../offRamp/EVM2EVMOffRampSetup.t.sol";
+import "../onRamp/EVM2EVMOnRampSetup.t.sol";
+
+contract E2E is EVM2EVMOnRampSetup, CommitStoreSetup, EVM2EVMOffRampSetup {
+ using Internal for Internal.EVM2EVMMessage;
+
+ function setUp() public virtual override(EVM2EVMOnRampSetup, CommitStoreSetup, EVM2EVMOffRampSetup) {
+ EVM2EVMOnRampSetup.setUp();
+ CommitStoreSetup.setUp();
+ EVM2EVMOffRampSetup.setUp();
+
+ deployOffRamp(s_commitStore, s_destRouter, address(0));
+ }
+
+ function test_E2E_3MessagesSuccess_gas() public {
+ vm.pauseGasMetering();
+ IERC20 token0 = IERC20(s_sourceTokens[0]);
+ IERC20 token1 = IERC20(s_sourceTokens[1]);
+ uint256 balance0Pre = token0.balanceOf(OWNER);
+ uint256 balance1Pre = token1.balanceOf(OWNER);
+
+ Internal.EVM2EVMMessage[] memory messages = new Internal.EVM2EVMMessage[](3);
+ messages[0] = sendRequest(1);
+ messages[1] = sendRequest(2);
+ messages[2] = sendRequest(3);
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, _generateTokenMessage());
+ // Asserts that the tokens have been sent and the fee has been paid.
+ assertEq(balance0Pre - messages.length * (i_tokenAmount0 + expectedFee), token0.balanceOf(OWNER));
+ assertEq(balance1Pre - messages.length * i_tokenAmount1, token1.balanceOf(OWNER));
+
+ bytes32 metaDataHash = s_offRamp.metadataHash();
+
+ bytes32[] memory hashedMessages = new bytes32[](3);
+ hashedMessages[0] = messages[0]._hash(metaDataHash);
+ messages[0].messageId = hashedMessages[0];
+ hashedMessages[1] = messages[1]._hash(metaDataHash);
+ messages[1].messageId = hashedMessages[1];
+ hashedMessages[2] = messages[2]._hash(metaDataHash);
+ messages[2].messageId = hashedMessages[2];
+
+ bytes32[] memory merkleRoots = new bytes32[](1);
+ merkleRoots[0] = MerkleHelper.getMerkleRoot(hashedMessages);
+
+ address[] memory onRamps = new address[](1);
+ onRamps[0] = ON_RAMP_ADDRESS;
+
+ bytes memory commitReport = abi.encode(
+ CommitStore.CommitReport({
+ priceUpdates: getEmptyPriceUpdates(),
+ interval: CommitStore.Interval(messages[0].sequenceNumber, messages[2].sequenceNumber),
+ merkleRoot: merkleRoots[0]
+ })
+ );
+
+ vm.resumeGasMetering();
+ s_commitStore.report(commitReport, ++s_latestEpochAndRound);
+ vm.pauseGasMetering();
+
+ s_mockRMN.setTaggedRootBlessed(IRMN.TaggedRoot({commitStore: address(s_commitStore), root: merkleRoots[0]}), true);
+
+ bytes32[] memory proofs = new bytes32[](0);
+ uint256 timestamp = s_commitStore.verify(merkleRoots, proofs, 2 ** 2 - 1);
+ assertEq(BLOCK_TIME, timestamp);
+
+ // We change the block time so when execute would e.g. use the current
+ // block time instead of the committed block time the value would be
+ // incorrect in the checks below.
+ vm.warp(BLOCK_TIME + 2000);
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[1].sequenceNumber, messages[1].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[2].sequenceNumber, messages[2].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ Internal.ExecutionReport memory execReport = _generateReportFromMessages(messages);
+ vm.resumeGasMetering();
+ s_offRamp.execute(execReport, new uint256[](0));
+ }
+
+ function sendRequest(uint64 expectedSeqNum) public returns (Internal.EVM2EVMMessage memory) {
+ Client.EVM2AnyMessage memory message = _generateTokenMessage();
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+
+ IERC20(s_sourceTokens[0]).approve(address(s_sourceRouter), i_tokenAmount0 + expectedFee);
+ IERC20(s_sourceTokens[1]).approve(address(s_sourceRouter), i_tokenAmount1);
+
+ message.receiver = abi.encode(address(s_receiver));
+ Internal.EVM2EVMMessage memory msgEvent =
+ _messageToEvent(message, expectedSeqNum, expectedSeqNum, expectedFee, OWNER);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ vm.pauseGasMetering();
+
+ return msgEvent;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/e2e/MultiRampsEnd2End.sol b/contracts/src/v0.8/ccip/test/e2e/MultiRampsEnd2End.sol
new file mode 100644
index 00000000000..cbe8a35dce5
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/e2e/MultiRampsEnd2End.sol
@@ -0,0 +1,260 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {AuthorizedCallers} from "../../../shared/access/AuthorizedCallers.sol";
+import {NonceManager} from "../../NonceManager.sol";
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+import "../helpers/MerkleHelper.sol";
+import "../offRamp/EVM2EVMMultiOffRampSetup.t.sol";
+import "../onRamp/EVM2EVMMultiOnRampSetup.t.sol";
+
+/// @notice This E2E test implements the following scenario:
+/// 1. Send multiple messages from multiple source chains to a single destination chain (2 messages from source chain 1 and 1 from
+/// source chain 2).
+/// 2. Commit multiple merkle roots (1 for each source chain).
+/// 3. Batch execute all the committed messages.
+contract MultiRampsE2E is EVM2EVMMultiOnRampSetup, EVM2EVMMultiOffRampSetup {
+ using Internal for Internal.Any2EVMRampMessage;
+
+ Router internal s_sourceRouter2;
+ EVM2EVMMultiOnRampHelper internal s_onRamp2;
+ TokenAdminRegistry internal s_tokenAdminRegistry2;
+ NonceManager internal s_nonceManager2;
+
+ bytes32 internal s_metadataHash2;
+
+ mapping(address destPool => address sourcePool) internal s_sourcePoolByDestPool;
+
+ function setUp() public virtual override(EVM2EVMMultiOnRampSetup, EVM2EVMMultiOffRampSetup) {
+ EVM2EVMMultiOnRampSetup.setUp();
+ EVM2EVMMultiOffRampSetup.setUp();
+
+ // Deploy new source router for the new source chain
+ s_sourceRouter2 = new Router(s_sourceRouter.getWrappedNative(), address(s_mockRMN));
+
+ // Deploy new TokenAdminRegistry for the new source chain
+ s_tokenAdminRegistry2 = new TokenAdminRegistry();
+
+ // Deploy new token pools and set them on the new TokenAdminRegistry
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ address token = s_sourceTokens[i];
+ address pool = address(
+ new LockReleaseTokenPool(IERC20(token), new address[](0), address(s_mockRMN), true, address(s_sourceRouter2))
+ );
+
+ s_sourcePoolByDestPool[s_destPoolBySourceToken[token]] = pool;
+
+ _setPool(
+ s_tokenAdminRegistry2, token, pool, DEST_CHAIN_SELECTOR, s_destPoolByToken[s_destTokens[i]], s_destTokens[i]
+ );
+ }
+
+ for (uint256 i = 0; i < s_destTokens.length; ++i) {
+ address token = s_destTokens[i];
+ address pool = s_destPoolByToken[token];
+
+ _setPool(
+ s_tokenAdminRegistry2, token, pool, SOURCE_CHAIN_SELECTOR + 1, s_sourcePoolByDestPool[pool], s_sourceTokens[i]
+ );
+ }
+
+ s_nonceManager2 = new NonceManager(new address[](0));
+
+ (
+ // Deploy the new source chain onramp
+ // Outsource to shared helper function with EVM2EVMMultiOnRampSetup
+ s_onRamp2,
+ s_metadataHash2
+ ) = _deployOnRamp(
+ SOURCE_CHAIN_SELECTOR + 1, address(s_sourceRouter2), address(s_nonceManager2), address(s_tokenAdminRegistry2)
+ );
+
+ address[] memory authorizedCallers = new address[](1);
+ authorizedCallers[0] = address(s_onRamp2);
+ s_nonceManager2.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: authorizedCallers, removedCallers: new address[](0)})
+ );
+
+ // Enable destination chain on new source chain router
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: address(s_onRamp2)});
+ s_sourceRouter2.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), new Router.OffRamp[](0));
+
+ // Deploy offramp
+ _deployOffRamp(s_destRouter, s_mockRMN, s_inboundNonceManager);
+
+ // Enable source chains on offramp
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](2);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ isEnabled: true,
+ // Must match OnRamp address
+ onRamp: abi.encode(address(s_onRamp))
+ });
+ sourceChainConfigs[1] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR + 1,
+ isEnabled: true,
+ onRamp: abi.encode(address(s_onRamp2))
+ });
+
+ _setupMultipleOffRampsFromConfigs(sourceChainConfigs);
+ }
+
+ function test_E2E_3MessagesSuccess_gas() public {
+ vm.pauseGasMetering();
+ IERC20 token0 = IERC20(s_sourceTokens[0]);
+ IERC20 token1 = IERC20(s_sourceTokens[1]);
+ uint256 balance0Pre = token0.balanceOf(OWNER);
+ uint256 balance1Pre = token1.balanceOf(OWNER);
+
+ // Send messages
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ messages1[0] = _sendRequest(1, SOURCE_CHAIN_SELECTOR, 1, s_metadataHash, s_sourceRouter, s_tokenAdminRegistry);
+ messages1[1] = _sendRequest(2, SOURCE_CHAIN_SELECTOR, 2, s_metadataHash, s_sourceRouter, s_tokenAdminRegistry);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+ messages2[0] =
+ _sendRequest(1, SOURCE_CHAIN_SELECTOR + 1, 1, s_metadataHash2, s_sourceRouter2, s_tokenAdminRegistry2);
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, _generateTokenMessage());
+ // Asserts that the tokens have been sent and the fee has been paid.
+ assertEq(
+ balance0Pre - (messages1.length + messages2.length) * (i_tokenAmount0 + expectedFee), token0.balanceOf(OWNER)
+ );
+ assertEq(balance1Pre - (messages1.length + messages2.length) * i_tokenAmount1, token1.balanceOf(OWNER));
+
+ // Commit
+ bytes32[] memory hashedMessages1 = new bytes32[](2);
+ hashedMessages1[0] = messages1[0]._hash(abi.encode(address(s_onRamp)));
+ hashedMessages1[1] = messages1[1]._hash(abi.encode(address(s_onRamp)));
+ bytes32[] memory hashedMessages2 = new bytes32[](1);
+ hashedMessages2[0] = messages2[0]._hash(abi.encode(address(s_onRamp2)));
+
+ bytes32[] memory merkleRoots = new bytes32[](2);
+ merkleRoots[0] = MerkleHelper.getMerkleRoot(hashedMessages1);
+ merkleRoots[1] = MerkleHelper.getMerkleRoot(hashedMessages2);
+
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](2);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(messages1[0].header.sequenceNumber, messages1[1].header.sequenceNumber),
+ merkleRoot: merkleRoots[0]
+ });
+ roots[1] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR + 1,
+ interval: EVM2EVMMultiOffRamp.Interval(messages2[0].header.sequenceNumber, messages2[0].header.sequenceNumber),
+ merkleRoot: merkleRoots[1]
+ });
+
+ EVM2EVMMultiOffRamp.CommitReport memory report =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.resumeGasMetering();
+ _commit(report, ++s_latestSequenceNumber);
+ vm.pauseGasMetering();
+
+ s_mockRMN.setTaggedRootBlessed(IRMN.TaggedRoot({commitStore: address(s_offRamp), root: merkleRoots[0]}), true);
+ s_mockRMN.setTaggedRootBlessed(IRMN.TaggedRoot({commitStore: address(s_offRamp), root: merkleRoots[1]}), true);
+
+ bytes32[] memory proofs = new bytes32[](0);
+ bytes32[] memory hashedLeaves = new bytes32[](1);
+ hashedLeaves[0] = merkleRoots[0];
+ uint256 timestamp = s_offRamp.verify(SOURCE_CHAIN_SELECTOR, hashedLeaves, proofs, 2 ** 2 - 1);
+ assertEq(BLOCK_TIME, timestamp);
+ hashedLeaves[0] = merkleRoots[1];
+ timestamp = s_offRamp.verify(SOURCE_CHAIN_SELECTOR + 1, hashedLeaves, proofs, 2 ** 2 - 1);
+ assertEq(BLOCK_TIME, timestamp);
+
+ // We change the block time so when execute would e.g. use the current
+ // block time instead of the committed block time the value would be
+ // incorrect in the checks below.
+ vm.warp(BLOCK_TIME + 2000);
+
+ // Execute
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR,
+ messages1[0].header.sequenceNumber,
+ messages1[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR,
+ messages1[1].header.sequenceNumber,
+ messages1[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR + 1,
+ messages2[0].header.sequenceNumber,
+ messages2[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR + 1, messages2);
+
+ vm.resumeGasMetering();
+ _execute(reports);
+ }
+
+ function _sendRequest(
+ uint64 expectedSeqNum,
+ uint64 sourceChainSelector,
+ uint64 nonce,
+ bytes32 metadataHash,
+ Router router,
+ TokenAdminRegistry tokenAdminRegistry
+ ) public returns (Internal.Any2EVMRampMessage memory) {
+ Client.EVM2AnyMessage memory message = _generateTokenMessage();
+ uint256 expectedFee = router.getFee(DEST_CHAIN_SELECTOR, message);
+
+ IERC20(s_sourceTokens[0]).approve(address(router), i_tokenAmount0 + expectedFee);
+ IERC20(s_sourceTokens[1]).approve(address(router), i_tokenAmount1);
+
+ message.receiver = abi.encode(address(s_receiver));
+ Internal.EVM2AnyRampMessage memory msgEvent = _messageToEvent(
+ message,
+ sourceChainSelector,
+ DEST_CHAIN_SELECTOR,
+ expectedSeqNum,
+ nonce,
+ expectedFee,
+ OWNER,
+ metadataHash,
+ tokenAdminRegistry
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, msgEvent);
+
+ vm.resumeGasMetering();
+ router.ccipSend(DEST_CHAIN_SELECTOR, message);
+ vm.pauseGasMetering();
+
+ uint256 gasLimit = s_priceRegistry.parseEVMExtraArgsFromBytes(msgEvent.extraArgs, DEST_CHAIN_SELECTOR).gasLimit;
+
+ return Internal.Any2EVMRampMessage({
+ header: Internal.RampMessageHeader({
+ messageId: msgEvent.header.messageId,
+ sourceChainSelector: sourceChainSelector,
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ sequenceNumber: msgEvent.header.sequenceNumber,
+ nonce: msgEvent.header.nonce
+ }),
+ sender: abi.encode(msgEvent.sender),
+ data: msgEvent.data,
+ receiver: abi.decode(msgEvent.receiver, (address)),
+ gasLimit: gasLimit,
+ tokenAmounts: msgEvent.tokenAmounts
+ });
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/AggregateRateLimiterHelper.sol b/contracts/src/v0.8/ccip/test/helpers/AggregateRateLimiterHelper.sol
new file mode 100644
index 00000000000..ced605a7524
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/AggregateRateLimiterHelper.sol
@@ -0,0 +1,19 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../../AggregateRateLimiter.sol";
+
+contract AggregateRateLimiterHelper is AggregateRateLimiter {
+ constructor(RateLimiter.Config memory config) AggregateRateLimiter(config) {}
+
+ function rateLimitValue(uint256 value) public {
+ _rateLimitValue(value);
+ }
+
+ function getTokenValue(
+ Client.EVMTokenAmount memory tokenAmount,
+ IPriceRegistry priceRegistry
+ ) public view returns (uint256) {
+ return _getTokenValue(tokenAmount, priceRegistry);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/BurnMintERC677Helper.sol b/contracts/src/v0.8/ccip/test/helpers/BurnMintERC677Helper.sol
new file mode 100644
index 00000000000..9d2346996ae
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/BurnMintERC677Helper.sol
@@ -0,0 +1,18 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {IGetCCIPAdmin} from "../../interfaces/IGetCCIPAdmin.sol";
+
+contract BurnMintERC677Helper is BurnMintERC677, IGetCCIPAdmin {
+ constructor(string memory name, string memory symbol) BurnMintERC677(name, symbol, 18, 0) {}
+
+ // Gives one full token to any given address.
+ function drip(address to) external {
+ _mint(to, 1e18);
+ }
+
+ function getCCIPAdmin() external view override returns (address) {
+ return owner();
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/BurnMintMultiTokenPool.sol b/contracts/src/v0.8/ccip/test/helpers/BurnMintMultiTokenPool.sol
new file mode 100644
index 00000000000..a21fcde8357
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/BurnMintMultiTokenPool.sol
@@ -0,0 +1,56 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {Pool} from "../../libraries/Pool.sol";
+import {MultiTokenPool} from "./MultiTokenPool.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract BurnMintMultiTokenPool is MultiTokenPool {
+ constructor(
+ IERC20[] memory tokens,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) MultiTokenPool(tokens, allowlist, rmnProxy, router) {}
+
+ /// @notice Burn the token in the pool
+ /// @dev The _validateLockOrBurn check is an essential security check
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ IBurnMintERC20(lockOrBurnIn.localToken).burn(lockOrBurnIn.amount);
+
+ emit Burned(msg.sender, lockOrBurnIn.amount);
+
+ return Pool.LockOrBurnOutV1({
+ destTokenAddress: getRemoteToken(lockOrBurnIn.localToken, lockOrBurnIn.remoteChainSelector),
+ destPoolData: ""
+ });
+ }
+
+ /// @notice Mint tokens from the pool to the recipient
+ /// @dev The _validateReleaseOrMint check is an essential security check
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ virtual
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+
+ // Mint to the offRamp, which forwards it to the recipient
+ IBurnMintERC20(releaseOrMintIn.localToken).mint(msg.sender, releaseOrMintIn.amount);
+
+ emit Minted(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/CCIPConfigHelper.sol b/contracts/src/v0.8/ccip/test/helpers/CCIPConfigHelper.sol
new file mode 100644
index 00000000000..74f03890d3b
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/CCIPConfigHelper.sol
@@ -0,0 +1,66 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.24;
+
+import {CCIPConfig} from "../../capability/CCIPConfig.sol";
+import {CCIPConfigTypes} from "../../capability/libraries/CCIPConfigTypes.sol";
+import {Internal} from "../../libraries/Internal.sol";
+
+contract CCIPConfigHelper is CCIPConfig {
+ constructor(address capabilitiesRegistry) CCIPConfig(capabilitiesRegistry) {}
+
+ function stateFromConfigLength(uint256 configLength) public pure returns (CCIPConfigTypes.ConfigState) {
+ return _stateFromConfigLength(configLength);
+ }
+
+ function validateConfigStateTransition(
+ CCIPConfigTypes.ConfigState currentState,
+ CCIPConfigTypes.ConfigState newState
+ ) public pure {
+ _validateConfigStateTransition(currentState, newState);
+ }
+
+ function validateConfigTransition(
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig,
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory newConfigWithMeta
+ ) public pure {
+ _validateConfigTransition(currentConfig, newConfigWithMeta);
+ }
+
+ function computeNewConfigWithMeta(
+ uint32 donId,
+ CCIPConfigTypes.OCR3ConfigWithMeta[] memory currentConfig,
+ CCIPConfigTypes.OCR3Config[] memory newConfig,
+ CCIPConfigTypes.ConfigState currentState,
+ CCIPConfigTypes.ConfigState newState
+ ) public view returns (CCIPConfigTypes.OCR3ConfigWithMeta[] memory) {
+ return _computeNewConfigWithMeta(donId, currentConfig, newConfig, currentState, newState);
+ }
+
+ function groupByPluginType(CCIPConfigTypes.OCR3Config[] memory ocr3Configs)
+ public
+ pure
+ returns (CCIPConfigTypes.OCR3Config[] memory commitConfigs, CCIPConfigTypes.OCR3Config[] memory execConfigs)
+ {
+ return _groupByPluginType(ocr3Configs);
+ }
+
+ function computeConfigDigest(
+ uint32 donId,
+ uint64 configCount,
+ CCIPConfigTypes.OCR3Config memory ocr3Config
+ ) public pure returns (bytes32) {
+ return _computeConfigDigest(donId, configCount, ocr3Config);
+ }
+
+ function validateConfig(CCIPConfigTypes.OCR3Config memory cfg) public view {
+ _validateConfig(cfg);
+ }
+
+ function updatePluginConfig(
+ uint32 donId,
+ Internal.OCRPluginType pluginType,
+ CCIPConfigTypes.OCR3Config[] memory newConfig
+ ) public {
+ _updatePluginConfig(donId, pluginType, newConfig);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/CommitStoreHelper.sol b/contracts/src/v0.8/ccip/test/helpers/CommitStoreHelper.sol
new file mode 100644
index 00000000000..c8d66b8d72f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/CommitStoreHelper.sol
@@ -0,0 +1,13 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../../CommitStore.sol";
+
+contract CommitStoreHelper is CommitStore {
+ constructor(StaticConfig memory staticConfig) CommitStore(staticConfig) {}
+
+ /// @dev Expose _report for tests
+ function report(bytes calldata commitReport, uint40 epochAndRound) external {
+ _report(commitReport, epochAndRound);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/EVM2EVMMultiOffRampHelper.sol b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMMultiOffRampHelper.sol
new file mode 100644
index 00000000000..581d9bd7051
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMMultiOffRampHelper.sol
@@ -0,0 +1,103 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {EVM2EVMMultiOffRamp} from "../../offRamp/EVM2EVMMultiOffRamp.sol";
+import {IgnoreContractSize} from "./IgnoreContractSize.sol";
+
+contract EVM2EVMMultiOffRampHelper is EVM2EVMMultiOffRamp, IgnoreContractSize {
+ mapping(uint64 sourceChainSelector => uint256 overrideTimestamp) private s_sourceChainVerificationOverride;
+
+ constructor(
+ StaticConfig memory staticConfig,
+ DynamicConfig memory dynamicConfig,
+ SourceChainConfigArgs[] memory sourceChainConfigs
+ ) EVM2EVMMultiOffRamp(staticConfig, dynamicConfig, sourceChainConfigs) {}
+
+ function setExecutionStateHelper(
+ uint64 sourceChainSelector,
+ uint64 sequenceNumber,
+ Internal.MessageExecutionState state
+ ) public {
+ _setExecutionState(sourceChainSelector, sequenceNumber, state);
+ }
+
+ function getExecutionStateBitMap(uint64 sourceChainSelector, uint64 bitmapIndex) public view returns (uint256) {
+ return s_executionStates[sourceChainSelector][bitmapIndex];
+ }
+
+ function releaseOrMintSingleToken(
+ Internal.RampTokenAmount memory sourceTokenAmount,
+ bytes calldata originalSender,
+ address receiver,
+ uint64 sourceChainSelector,
+ bytes calldata offchainTokenData
+ ) external returns (Client.EVMTokenAmount memory) {
+ return
+ _releaseOrMintSingleToken(sourceTokenAmount, originalSender, receiver, sourceChainSelector, offchainTokenData);
+ }
+
+ function releaseOrMintTokens(
+ Internal.RampTokenAmount[] memory sourceTokenAmounts,
+ bytes memory originalSender,
+ address receiver,
+ uint64 sourceChainSelector,
+ bytes[] calldata offchainTokenData
+ ) external returns (Client.EVMTokenAmount[] memory) {
+ return _releaseOrMintTokens(sourceTokenAmounts, originalSender, receiver, sourceChainSelector, offchainTokenData);
+ }
+
+ function trialExecute(
+ Internal.Any2EVMRampMessage memory message,
+ bytes[] memory offchainTokenData
+ ) external returns (Internal.MessageExecutionState, bytes memory) {
+ return _trialExecute(message, offchainTokenData);
+ }
+
+ function executeSingleReport(
+ Internal.ExecutionReportSingleChain memory rep,
+ uint256[] memory manualExecGasLimits
+ ) external {
+ _executeSingleReport(rep, manualExecGasLimits);
+ }
+
+ function batchExecute(
+ Internal.ExecutionReportSingleChain[] memory reports,
+ uint256[][] memory manualExecGasLimits
+ ) external {
+ _batchExecute(reports, manualExecGasLimits);
+ }
+
+ function verify(
+ uint64 sourceChainSelector,
+ bytes32[] memory hashedLeaves,
+ bytes32[] memory proofs,
+ uint256 proofFlagBits
+ ) external view returns (uint256 timestamp) {
+ return super._verify(sourceChainSelector, hashedLeaves, proofs, proofFlagBits);
+ }
+
+ function _verify(
+ uint64 sourceChainSelector,
+ bytes32[] memory hashedLeaves,
+ bytes32[] memory proofs,
+ uint256 proofFlagBits
+ ) internal view override returns (uint256 timestamp) {
+ uint256 overrideTimestamp = s_sourceChainVerificationOverride[sourceChainSelector];
+
+ return overrideTimestamp == 0
+ ? super._verify(sourceChainSelector, hashedLeaves, proofs, proofFlagBits)
+ : overrideTimestamp;
+ }
+
+ /// @dev Test helper to override _verify result for easier exec testing
+ function setVerifyOverrideResult(uint64 sourceChainSelector, uint256 overrideTimestamp) external {
+ s_sourceChainVerificationOverride[sourceChainSelector] = overrideTimestamp;
+ }
+
+ /// @dev Test helper to directly set a root's timestamp
+ function setRootTimestamp(uint64 sourceChainSelector, bytes32 root, uint256 timestamp) external {
+ s_roots[sourceChainSelector][root] = timestamp;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/EVM2EVMMultiOnRampHelper.sol b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMMultiOnRampHelper.sol
new file mode 100644
index 00000000000..0532697d649
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMMultiOnRampHelper.sol
@@ -0,0 +1,12 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../../onRamp/EVM2EVMMultiOnRamp.sol";
+import {IgnoreContractSize} from "./IgnoreContractSize.sol";
+
+contract EVM2EVMMultiOnRampHelper is EVM2EVMMultiOnRamp, IgnoreContractSize {
+ constructor(
+ StaticConfig memory staticConfig,
+ DynamicConfig memory dynamicConfig
+ ) EVM2EVMMultiOnRamp(staticConfig, dynamicConfig) {}
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/EVM2EVMOffRampHelper.sol b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMOffRampHelper.sol
new file mode 100644
index 00000000000..e328f0ade29
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMOffRampHelper.sol
@@ -0,0 +1,59 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../../offRamp/EVM2EVMOffRamp.sol";
+import {IgnoreContractSize} from "./IgnoreContractSize.sol";
+
+contract EVM2EVMOffRampHelper is EVM2EVMOffRamp, IgnoreContractSize {
+ constructor(
+ StaticConfig memory staticConfig,
+ RateLimiter.Config memory rateLimiterConfig
+ ) EVM2EVMOffRamp(staticConfig, rateLimiterConfig) {}
+
+ function setExecutionStateHelper(uint64 sequenceNumber, Internal.MessageExecutionState state) public {
+ _setExecutionState(sequenceNumber, state);
+ }
+
+ function getExecutionStateBitMap(uint64 bitmapIndex) public view returns (uint256) {
+ return s_executionStates[bitmapIndex];
+ }
+
+ function releaseOrMintToken(
+ uint256 sourceTokenAmount,
+ bytes calldata originalSender,
+ address receiver,
+ Internal.SourceTokenData calldata sourceTokenData,
+ bytes calldata offchainTokenData
+ ) external returns (Client.EVMTokenAmount memory) {
+ return _releaseOrMintToken(sourceTokenAmount, originalSender, receiver, sourceTokenData, offchainTokenData);
+ }
+
+ function releaseOrMintTokens(
+ Client.EVMTokenAmount[] memory sourceTokenAmounts,
+ bytes calldata originalSender,
+ address receiver,
+ bytes[] calldata sourceTokenData,
+ bytes[] calldata offchainTokenData
+ ) external returns (Client.EVMTokenAmount[] memory) {
+ return _releaseOrMintTokens(sourceTokenAmounts, originalSender, receiver, sourceTokenData, offchainTokenData);
+ }
+
+ function trialExecute(
+ Internal.EVM2EVMMessage memory message,
+ bytes[] memory offchainTokenData
+ ) external returns (Internal.MessageExecutionState, bytes memory) {
+ return _trialExecute(message, offchainTokenData);
+ }
+
+ function report(bytes calldata executableMessages) external {
+ _report(executableMessages);
+ }
+
+ function execute(Internal.ExecutionReport memory rep, uint256[] memory manualExecGasLimits) external {
+ _execute(rep, manualExecGasLimits);
+ }
+
+ function metadataHash() external view returns (bytes32) {
+ return _metadataHash(Internal.EVM_2_EVM_MESSAGE_HASH);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/EVM2EVMOnRampHelper.sol b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMOnRampHelper.sol
new file mode 100644
index 00000000000..5cce6aaa445
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/EVM2EVMOnRampHelper.sol
@@ -0,0 +1,47 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../../onRamp/EVM2EVMOnRamp.sol";
+import {IgnoreContractSize} from "./IgnoreContractSize.sol";
+
+contract EVM2EVMOnRampHelper is EVM2EVMOnRamp, IgnoreContractSize {
+ constructor(
+ StaticConfig memory staticConfig,
+ DynamicConfig memory dynamicConfig,
+ RateLimiter.Config memory rateLimiterConfig,
+ FeeTokenConfigArgs[] memory feeTokenConfigs,
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ NopAndWeight[] memory nopsAndWeights
+ )
+ EVM2EVMOnRamp(
+ staticConfig,
+ dynamicConfig,
+ rateLimiterConfig,
+ feeTokenConfigs,
+ tokenTransferFeeConfigArgs,
+ nopsAndWeights
+ )
+ {}
+
+ function getDataAvailabilityCost(
+ uint112 dataAvailabilityGasPrice,
+ uint256 messageDataLength,
+ uint256 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) external view returns (uint256) {
+ return
+ _getDataAvailabilityCost(dataAvailabilityGasPrice, messageDataLength, numberOfTokens, tokenTransferBytesOverhead);
+ }
+
+ function getTokenTransferCost(
+ address feeToken,
+ uint224 feeTokenPrice,
+ Client.EVMTokenAmount[] calldata tokenAmounts
+ ) external view returns (uint256, uint32, uint32) {
+ return _getTokenTransferCost(feeToken, feeTokenPrice, tokenAmounts);
+ }
+
+ function getSequenceNumber() external view returns (uint64) {
+ return s_sequenceNumber;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/EtherSenderReceiverHelper.sol b/contracts/src/v0.8/ccip/test/helpers/EtherSenderReceiverHelper.sol
new file mode 100644
index 00000000000..71a5cdc7ab6
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/EtherSenderReceiverHelper.sol
@@ -0,0 +1,21 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {EtherSenderReceiver} from "../../applications/EtherSenderReceiver.sol";
+import {Client} from "../../libraries/Client.sol";
+
+contract EtherSenderReceiverHelper is EtherSenderReceiver {
+ constructor(address router) EtherSenderReceiver(router) {}
+
+ function validatedMessage(Client.EVM2AnyMessage calldata message) public view returns (Client.EVM2AnyMessage memory) {
+ return _validatedMessage(message);
+ }
+
+ function validateFeeToken(Client.EVM2AnyMessage calldata message) public payable {
+ _validateFeeToken(message);
+ }
+
+ function publicCcipReceive(Client.Any2EVMMessage memory message) public {
+ _ccipReceive(message);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/IgnoreContractSize.sol b/contracts/src/v0.8/ccip/test/helpers/IgnoreContractSize.sol
new file mode 100644
index 00000000000..b30124069f2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/IgnoreContractSize.sol
@@ -0,0 +1,10 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+contract IgnoreContractSize {
+ // test contracts are excluded from forge build --sizes by default
+ // --sizes exits with code 1 if any contract is over limit, which fails CI
+ // for helper contracts that are not explicit test contracts
+ // use this flag to exclude from --sizes
+ bool public IS_SCRIPT = true;
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MaybeRevertingBurnMintTokenPool.sol b/contracts/src/v0.8/ccip/test/helpers/MaybeRevertingBurnMintTokenPool.sol
new file mode 100644
index 00000000000..e572f798ad9
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MaybeRevertingBurnMintTokenPool.sol
@@ -0,0 +1,70 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {Pool} from "../../libraries/Pool.sol";
+import {BurnMintTokenPool} from "../../pools/BurnMintTokenPool.sol";
+
+contract MaybeRevertingBurnMintTokenPool is BurnMintTokenPool {
+ bytes public s_revertReason = "";
+ bytes public s_sourceTokenData = "";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) BurnMintTokenPool(token, allowlist, rmnProxy, router) {}
+
+ function setShouldRevert(bytes calldata revertReason) external {
+ s_revertReason = revertReason;
+ }
+
+ function setSourceTokenData(bytes calldata sourceTokenData) external {
+ s_sourceTokenData = sourceTokenData;
+ }
+
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ virtual
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ _validateLockOrBurn(lockOrBurnIn);
+
+ bytes memory revertReason = s_revertReason;
+ if (revertReason.length != 0) {
+ assembly {
+ revert(add(32, revertReason), mload(revertReason))
+ }
+ }
+
+ IBurnMintERC20(address(i_token)).burn(lockOrBurnIn.amount);
+ emit Burned(msg.sender, lockOrBurnIn.amount);
+ return Pool.LockOrBurnOutV1({
+ destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector),
+ destPoolData: s_sourceTokenData
+ });
+ }
+
+ /// @notice Reverts depending on the value of `s_revertReason`
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ virtual
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ _validateReleaseOrMint(releaseOrMintIn);
+
+ bytes memory revertReason = s_revertReason;
+ if (revertReason.length != 0) {
+ assembly {
+ revert(add(32, revertReason), mload(revertReason))
+ }
+ }
+ IBurnMintERC20(address(i_token)).mint(msg.sender, releaseOrMintIn.amount);
+ emit Minted(msg.sender, releaseOrMintIn.receiver, releaseOrMintIn.amount);
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MerkleHelper.sol b/contracts/src/v0.8/ccip/test/helpers/MerkleHelper.sol
new file mode 100644
index 00000000000..ccb05681f1c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MerkleHelper.sol
@@ -0,0 +1,52 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {MerkleMultiProof} from "../../libraries/MerkleMultiProof.sol";
+
+library MerkleHelper {
+ /// @notice Generate a Merkle Root from a full set of leaves. When a tree is unbalanced
+ /// the value is brought up in the tree. For example consider (a,b,c) as leaves. This would
+ /// result in the following tree with d being computed from hash(a,c) and the root r from
+ /// hash(d,c). Notice c is not being rehashed when it is brought up in the tree, so the
+ /// root is NOT hash(d,hash(c)) but instead hash(d,c) == hash(hash(a,b),c).
+ /// r
+ /// / \
+ /// d c
+ /// / \
+ /// a b
+ function getMerkleRoot(bytes32[] memory hashedLeaves) public pure returns (bytes32) {
+ require(hashedLeaves.length <= 256);
+ while (hashedLeaves.length > 1) {
+ hashedLeaves = computeNextLayer(hashedLeaves);
+ }
+ return hashedLeaves[0];
+ }
+
+ /// @notice Computes a single layer of a merkle proof by hashing each pair (i, i+1) for
+ /// each i, i+2, i+4.. n. When an uneven number of leaves is supplied the last item
+ /// is simply included as the last element in the result set and not hashed.
+ function computeNextLayer(bytes32[] memory layer) public pure returns (bytes32[] memory) {
+ uint256 leavesLen = layer.length;
+ if (leavesLen == 1) return layer;
+
+ unchecked {
+ bytes32[] memory nextLayer = new bytes32[]((leavesLen + 1) / 2);
+ for (uint256 i = 0; i < leavesLen; i += 2) {
+ if (i == leavesLen - 1) {
+ nextLayer[i / 2] = layer[i];
+ } else {
+ nextLayer[i / 2] = hashPair(layer[i], layer[i + 1]);
+ }
+ }
+ return nextLayer;
+ }
+ }
+
+ function hashPair(bytes32 a, bytes32 b) public pure returns (bytes32) {
+ return a < b ? hashInternalNode(a, b) : hashInternalNode(b, a);
+ }
+
+ function hashInternalNode(bytes32 left, bytes32 right) public pure returns (bytes32 hash) {
+ return keccak256(abi.encode(MerkleMultiProof.INTERNAL_DOMAIN_SEPARATOR, left, right));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MessageHasher.sol b/contracts/src/v0.8/ccip/test/helpers/MessageHasher.sol
new file mode 100644
index 00000000000..19f35df7969
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MessageHasher.sol
@@ -0,0 +1,71 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+
+/// @notice MessageHasher is a contract that utility functions to hash an Any2EVMRampMessage
+/// and encode various preimages for the final hash of the message.
+/// @dev This is only deployed in tests and is not part of the production contracts.
+contract MessageHasher {
+ function hash(Internal.Any2EVMRampMessage memory message, bytes memory onRamp) public pure returns (bytes32) {
+ return Internal._hash(message, onRamp);
+ }
+
+ function encodeTokenAmountsHashPreimage(Internal.RampTokenAmount[] memory rampTokenAmounts)
+ public
+ pure
+ returns (bytes memory)
+ {
+ return abi.encode(rampTokenAmounts);
+ }
+
+ function encodeMetadataHashPreimage(
+ bytes32 any2EVMMessageHash,
+ uint64 sourceChainSelector,
+ uint64 destChainSelector,
+ bytes memory onRamp
+ ) public pure returns (bytes memory) {
+ return abi.encode(any2EVMMessageHash, sourceChainSelector, destChainSelector, onRamp);
+ }
+
+ function encodeFixedSizeFieldsHashPreimage(
+ bytes32 messageId,
+ bytes memory sender,
+ address receiver,
+ uint64 sequenceNumber,
+ uint256 gasLimit,
+ uint64 nonce
+ ) public pure returns (bytes memory) {
+ return abi.encode(messageId, sender, receiver, sequenceNumber, gasLimit, nonce);
+ }
+
+ function encodeFinalHashPreimage(
+ bytes32 leafDomainSeparator,
+ bytes32 implicitMetadataHash,
+ bytes32 fixedSizeFieldsHash,
+ bytes32 dataHash,
+ bytes32 tokenAmountsHash
+ ) public pure returns (bytes memory) {
+ return abi.encode(leafDomainSeparator, implicitMetadataHash, fixedSizeFieldsHash, dataHash, tokenAmountsHash);
+ }
+
+ function encodeEVMExtraArgsV1(Client.EVMExtraArgsV1 memory extraArgs) public pure returns (bytes memory) {
+ return Client._argsToBytes(extraArgs);
+ }
+
+ function encodeEVMExtraArgsV2(Client.EVMExtraArgsV2 memory extraArgs) public pure returns (bytes memory) {
+ return Client._argsToBytes(extraArgs);
+ }
+
+ function decodeEVMExtraArgsV1(uint256 gasLimit) public pure returns (Client.EVMExtraArgsV1 memory) {
+ return Client.EVMExtraArgsV1(gasLimit);
+ }
+
+ function decodeEVMExtraArgsV2(
+ uint256 gasLimit,
+ bool allowOutOfOrderExecution
+ ) public pure returns (Client.EVMExtraArgsV2 memory) {
+ return Client.EVMExtraArgsV2(gasLimit, allowOutOfOrderExecution);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MessageInterceptorHelper.sol b/contracts/src/v0.8/ccip/test/helpers/MessageInterceptorHelper.sol
new file mode 100644
index 00000000000..a54145da84e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MessageInterceptorHelper.sol
@@ -0,0 +1,30 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IMessageInterceptor} from "../../interfaces/IMessageInterceptor.sol";
+import {Client} from "../../libraries/Client.sol";
+
+contract MessageInterceptorHelper is IMessageInterceptor {
+ mapping(bytes32 messageId => bool isInvalid) internal s_invalidMessageIds;
+
+ constructor() {}
+
+ function setMessageIdValidationState(bytes32 messageId, bool isInvalid) external {
+ s_invalidMessageIds[messageId] = isInvalid;
+ }
+
+ /// @inheritdoc IMessageInterceptor
+ function onInboundMessage(Client.Any2EVMMessage memory message) external view {
+ if (s_invalidMessageIds[message.messageId]) {
+ revert MessageValidationError(bytes("Invalid message"));
+ }
+ }
+
+ /// @inheritdoc IMessageInterceptor
+ function onOutboundMessage(uint64, Client.EVM2AnyMessage calldata message) external view {
+ if (s_invalidMessageIds[keccak256(abi.encode(message))]) {
+ revert MessageValidationError(bytes("Invalid message"));
+ }
+ return;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MultiAggregateRateLimiterHelper.sol b/contracts/src/v0.8/ccip/test/helpers/MultiAggregateRateLimiterHelper.sol
new file mode 100644
index 00000000000..d9386ca7db0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MultiAggregateRateLimiterHelper.sol
@@ -0,0 +1,17 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {MultiAggregateRateLimiter} from "../../MultiAggregateRateLimiter.sol";
+import {IPriceRegistry} from "../../interfaces/IPriceRegistry.sol";
+import {Client} from "../../libraries/Client.sol";
+
+contract MultiAggregateRateLimiterHelper is MultiAggregateRateLimiter {
+ constructor(
+ address priceRegistry,
+ address[] memory authorizedCallers
+ ) MultiAggregateRateLimiter(priceRegistry, authorizedCallers) {}
+
+ function getTokenValue(Client.EVMTokenAmount memory tokenAmount) public view returns (uint256) {
+ return _getTokenValue(tokenAmount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MultiOCR3Helper.sol b/contracts/src/v0.8/ccip/test/helpers/MultiOCR3Helper.sol
new file mode 100644
index 00000000000..003a5326b89
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MultiOCR3Helper.sol
@@ -0,0 +1,45 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {MultiOCR3Base} from "../../ocr/MultiOCR3Base.sol";
+
+contract MultiOCR3Helper is MultiOCR3Base {
+ event AfterConfigSet(uint8 ocrPluginType);
+
+ /// @dev OCR plugin type used for transmit.
+ /// Defined in storage since it cannot be passed as calldata due to strict transmit checks
+ uint8 internal s_transmitOcrPluginType;
+
+ function setTransmitOcrPluginType(uint8 ocrPluginType) external {
+ s_transmitOcrPluginType = ocrPluginType;
+ }
+
+ /// @dev transmit function with signatures
+ function transmitWithSignatures(
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 rawVs
+ ) external {
+ _transmit(s_transmitOcrPluginType, reportContext, report, rs, ss, rawVs);
+ }
+
+ /// @dev transmit function with no signatures
+ function transmitWithoutSignatures(bytes32[3] calldata reportContext, bytes calldata report) external {
+ bytes32[] memory emptySigs = new bytes32[](0);
+ _transmit(s_transmitOcrPluginType, reportContext, report, emptySigs, emptySigs, bytes32(""));
+ }
+
+ function getOracle(uint8 ocrPluginType, address oracleAddress) external view returns (Oracle memory) {
+ return s_oracles[ocrPluginType][oracleAddress];
+ }
+
+ function typeAndVersion() public pure override returns (string memory) {
+ return "MultiOCR3BaseHelper 1.0.0";
+ }
+
+ function _afterOCR3ConfigSet(uint8 ocrPluginType) internal virtual override {
+ emit AfterConfigSet(ocrPluginType);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/MultiTokenPool.sol b/contracts/src/v0.8/ccip/test/helpers/MultiTokenPool.sol
new file mode 100644
index 00000000000..0f7c312f713
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/MultiTokenPool.sol
@@ -0,0 +1,420 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+import {IRouter} from "../../interfaces/IRouter.sol";
+
+import {OwnerIsCreator} from "../../../shared/access/OwnerIsCreator.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {IERC165} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+import {EnumerableSet} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice This contract is a proof of concept and should NOT be used in production.
+abstract contract MultiTokenPool is IPoolV1, OwnerIsCreator {
+ using EnumerableSet for EnumerableSet.AddressSet;
+ using EnumerableSet for EnumerableSet.UintSet;
+ using RateLimiter for RateLimiter.TokenBucket;
+
+ error CallerIsNotARampOnRouter(address caller);
+ error ZeroAddressNotAllowed();
+ error SenderNotAllowed(address sender);
+ error AllowListNotEnabled();
+ error NonExistentChain(uint64 remoteChainSelector);
+ error ChainNotAllowed(uint64 remoteChainSelector);
+ error CursedByRMN();
+ error ChainAlreadyExists(uint64 chainSelector);
+ error InvalidSourcePoolAddress(bytes sourcePoolAddress);
+ error InvalidToken(address token);
+
+ event Locked(address indexed sender, uint256 amount);
+ event Burned(address indexed sender, uint256 amount);
+ event Released(address indexed sender, address indexed recipient, uint256 amount);
+ event Minted(address indexed sender, address indexed recipient, uint256 amount);
+ event ChainAdded(
+ uint64 remoteChainSelector,
+ bytes remoteToken,
+ RateLimiter.Config outboundRateLimiterConfig,
+ RateLimiter.Config inboundRateLimiterConfig
+ );
+ event ChainConfigured(
+ uint64 remoteChainSelector,
+ RateLimiter.Config outboundRateLimiterConfig,
+ RateLimiter.Config inboundRateLimiterConfig
+ );
+ event ChainRemoved(uint64 remoteChainSelector);
+ event RemotePoolSet(uint64 indexed remoteChainSelector, bytes previousPoolAddress, bytes remotePoolAddress);
+ event AllowListAdd(address sender);
+ event AllowListRemove(address sender);
+ event RouterUpdated(address oldRouter, address newRouter);
+
+ struct ChainUpdate {
+ uint64 remoteChainSelector; // ──╮ Remote chain selector
+ bool allowed; // ────────────────╯ Whether the chain is allowed
+ bytes remotePoolAddress; // Address of the remote pool, ABI encoded in the case of a remove EVM chain.
+ bytes remoteTokenAddress; // Address of the remote token, ABI encoded in the case of a remote EVM chain.
+ RateLimiter.Config outboundRateLimiterConfig; // Outbound rate limited config, meaning the rate limits for all of the onRamps for the given chain
+ RateLimiter.Config inboundRateLimiterConfig; // Inbound rate limited config, meaning the rate limits for all of the offRamps for the given chain
+ }
+
+ struct RemoteChainConfig {
+ RateLimiter.TokenBucket outboundRateLimiterConfig; // Outbound rate limited config, meaning the rate limits for all of the onRamps for the given chain
+ RateLimiter.TokenBucket inboundRateLimiterConfig; // Inbound rate limited config, meaning the rate limits for all of the offRamps for the given chain
+ bytes remotePoolAddress; // Address of the remote pool, ABI encoded in the case of a remote EVM chain.
+ bytes remoteTokenAddress; // Address of the remote token, ABI encoded in the case of a remote EVM chain.
+ }
+
+ /// @dev The IERC20 token that this pool supports
+ EnumerableSet.AddressSet internal s_tokens;
+ /// @dev The address of the RMN proxy
+ address internal immutable i_rmnProxy;
+ /// @dev The immutable flag that indicates if the pool is access-controlled.
+ bool internal immutable i_allowlistEnabled;
+ /// @dev A set of addresses allowed to trigger lockOrBurn as original senders.
+ /// Only takes effect if i_allowlistEnabled is true.
+ /// This can be used to ensure only token-issuer specified addresses can
+ /// move tokens.
+ EnumerableSet.AddressSet internal s_allowList;
+ /// @dev The address of the router
+ IRouter internal s_router;
+ /// @dev A set of allowed chain selectors. We want the allowlist to be enumerable to
+ /// be able to quickly determine (without parsing logs) who can access the pool.
+ /// @dev The chain selectors are in uin256 format because of the EnumerableSet implementation.
+ EnumerableSet.UintSet internal s_remoteChainSelectors;
+ mapping(address token => mapping(uint64 remoteChainSelector => RemoteChainConfig)) internal s_remoteChainConfigs;
+
+ constructor(IERC20[] memory token, address[] memory allowlist, address rmnProxy, address router) {
+ if (router == address(0) || rmnProxy == address(0)) revert ZeroAddressNotAllowed();
+ for (uint256 i = 0; i < token.length; ++i) {
+ s_tokens.add(address(token[i]));
+ }
+ i_rmnProxy = rmnProxy;
+ s_router = IRouter(router);
+
+ // Pool can be set as permissioned or permissionless at deployment time only to save hot-path gas.
+ i_allowlistEnabled = allowlist.length > 0;
+ if (i_allowlistEnabled) {
+ _applyAllowListUpdates(new address[](0), allowlist);
+ }
+ }
+
+ /// @notice Get RMN proxy address
+ /// @return rmnProxy Address of RMN proxy
+ function getRmnProxy() public view returns (address rmnProxy) {
+ return i_rmnProxy;
+ }
+
+ /// @inheritdoc IPoolV1
+ function isSupportedToken(address token) public view virtual returns (bool) {
+ return s_tokens.contains(token);
+ }
+
+ /// @notice Gets the IERC20 token that this pool can lock or burn.
+ /// @return tokens The IERC20 token representation.
+ function getTokens() public view returns (IERC20[] memory tokens) {
+ tokens = new IERC20[](s_tokens.length());
+ for (uint256 i = 0; i < s_tokens.length(); ++i) {
+ tokens[i] = IERC20(s_tokens.at(i));
+ }
+ return tokens;
+ }
+
+ /// @notice Gets the pool's Router
+ /// @return router The pool's Router
+ function getRouter() public view returns (address router) {
+ return address(s_router);
+ }
+
+ /// @notice Sets the pool's Router
+ /// @param newRouter The new Router
+ function setRouter(address newRouter) public onlyOwner {
+ if (newRouter == address(0)) revert ZeroAddressNotAllowed();
+ address oldRouter = address(s_router);
+ s_router = IRouter(newRouter);
+
+ emit RouterUpdated(oldRouter, newRouter);
+ }
+
+ /// @notice Signals which version of the pool interface is supported
+ function supportsInterface(bytes4 interfaceId) public pure virtual override returns (bool) {
+ return interfaceId == Pool.CCIP_POOL_V1 || interfaceId == type(IPoolV1).interfaceId
+ || interfaceId == type(IERC165).interfaceId;
+ }
+
+ // ================================================================
+ // │ Validation │
+ // ================================================================
+
+ /// @notice Validates the lock or burn input for correctness on
+ /// - token to be locked or burned
+ /// - RMN curse status
+ /// - allowlist status
+ /// - if the sender is a valid onRamp
+ /// - rate limit status
+ /// @param lockOrBurnIn The input to validate.
+ /// @dev This function should always be called before executing a lock or burn. Not doing so would allow
+ /// for various exploits.
+ function _validateLockOrBurn(Pool.LockOrBurnInV1 memory lockOrBurnIn) internal {
+ if (!isSupportedToken(lockOrBurnIn.localToken)) revert InvalidToken(lockOrBurnIn.localToken);
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(lockOrBurnIn.remoteChainSelector)))) revert CursedByRMN();
+ _checkAllowList(lockOrBurnIn.originalSender);
+
+ _onlyOnRamp(lockOrBurnIn.remoteChainSelector);
+ _consumeOutboundRateLimit(lockOrBurnIn.localToken, lockOrBurnIn.remoteChainSelector, lockOrBurnIn.amount);
+ }
+
+ /// @notice Validates the release or mint input for correctness on
+ /// - token to be released or minted
+ /// - RMN curse status
+ /// - if the sender is a valid offRamp
+ /// - if the source pool is valid
+ /// - rate limit status
+ /// @param releaseOrMintIn The input to validate.
+ /// @dev This function should always be called before executing a lock or burn. Not doing so would allow
+ /// for various exploits.
+ function _validateReleaseOrMint(Pool.ReleaseOrMintInV1 memory releaseOrMintIn) internal {
+ if (!isSupportedToken(releaseOrMintIn.localToken)) revert InvalidToken(releaseOrMintIn.localToken);
+ if (IRMN(i_rmnProxy).isCursed(bytes16(uint128(releaseOrMintIn.remoteChainSelector)))) revert CursedByRMN();
+ _onlyOffRamp(releaseOrMintIn.remoteChainSelector);
+
+ // Validates that the source pool address is configured on this pool.
+ bytes memory configuredRemotePool = getRemotePool(releaseOrMintIn.localToken, releaseOrMintIn.remoteChainSelector);
+ if (
+ configuredRemotePool.length == 0
+ || keccak256(releaseOrMintIn.sourcePoolAddress) != keccak256(configuredRemotePool)
+ ) {
+ revert InvalidSourcePoolAddress(releaseOrMintIn.sourcePoolAddress);
+ }
+ _consumeInboundRateLimit(releaseOrMintIn.localToken, releaseOrMintIn.remoteChainSelector, releaseOrMintIn.amount);
+ }
+
+ // ================================================================
+ // │ Chain permissions │
+ // ================================================================
+
+ /// @notice Gets the pool address on the remote chain.
+ /// @param remoteChainSelector Remote chain selector.
+ /// @dev To support non-evm chains, this value is encoded into bytes
+ function getRemotePool(address token, uint64 remoteChainSelector) public view returns (bytes memory) {
+ return s_remoteChainConfigs[token][remoteChainSelector].remotePoolAddress;
+ }
+
+ /// @notice Gets the token address on the remote chain.
+ /// @param remoteChainSelector Remote chain selector.
+ /// @dev To support non-evm chains, this value is encoded into bytes
+ function getRemoteToken(address token, uint64 remoteChainSelector) public view returns (bytes memory) {
+ return s_remoteChainConfigs[token][remoteChainSelector].remoteTokenAddress;
+ }
+
+ /// @notice Sets the remote pool address for a given chain selector.
+ /// @param remoteChainSelector The remote chain selector for which the remote pool address is being set.
+ /// @param remotePoolAddress The address of the remote pool.
+ function setRemotePool(
+ address token,
+ uint64 remoteChainSelector,
+ bytes calldata remotePoolAddress
+ ) external onlyOwner {
+ if (!isSupportedChain(remoteChainSelector)) revert NonExistentChain(remoteChainSelector);
+
+ bytes memory prevAddress = s_remoteChainConfigs[token][remoteChainSelector].remotePoolAddress;
+ s_remoteChainConfigs[token][remoteChainSelector].remotePoolAddress = remotePoolAddress;
+
+ emit RemotePoolSet(remoteChainSelector, prevAddress, remotePoolAddress);
+ }
+
+ /// @inheritdoc IPoolV1
+ function isSupportedChain(uint64 remoteChainSelector) public view returns (bool) {
+ return s_remoteChainSelectors.contains(remoteChainSelector);
+ }
+
+ /// @notice Get list of allowed chains
+ /// @return list of chains.
+ function getSupportedChains() public view returns (uint64[] memory) {
+ uint256[] memory uint256ChainSelectors = s_remoteChainSelectors.values();
+ uint64[] memory chainSelectors = new uint64[](uint256ChainSelectors.length);
+ for (uint256 i = 0; i < uint256ChainSelectors.length; ++i) {
+ chainSelectors[i] = uint64(uint256ChainSelectors[i]);
+ }
+
+ return chainSelectors;
+ }
+
+ /// @notice Sets the permissions for a list of chains selectors. Actual senders for these chains
+ /// need to be allowed on the Router to interact with this pool.
+ /// @dev Only callable by the owner
+ /// @param chains A list of chains and their new permission status & rate limits. Rate limits
+ /// are only used when the chain is being added through `allowed` being true.
+ function applyChainUpdates(address token, ChainUpdate[] calldata chains) external virtual onlyOwner {
+ for (uint256 i = 0; i < chains.length; ++i) {
+ ChainUpdate memory update = chains[i];
+ RateLimiter._validateTokenBucketConfig(update.outboundRateLimiterConfig, !update.allowed);
+ RateLimiter._validateTokenBucketConfig(update.inboundRateLimiterConfig, !update.allowed);
+
+ if (update.allowed) {
+ // If the chain already exists, revert
+ if (!s_remoteChainSelectors.add(update.remoteChainSelector)) {
+ revert ChainAlreadyExists(update.remoteChainSelector);
+ }
+
+ if (update.remotePoolAddress.length == 0 || update.remoteTokenAddress.length == 0) {
+ revert ZeroAddressNotAllowed();
+ }
+
+ s_remoteChainConfigs[token][update.remoteChainSelector] = RemoteChainConfig({
+ outboundRateLimiterConfig: RateLimiter.TokenBucket({
+ rate: update.outboundRateLimiterConfig.rate,
+ capacity: update.outboundRateLimiterConfig.capacity,
+ tokens: update.outboundRateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.outboundRateLimiterConfig.isEnabled
+ }),
+ inboundRateLimiterConfig: RateLimiter.TokenBucket({
+ rate: update.inboundRateLimiterConfig.rate,
+ capacity: update.inboundRateLimiterConfig.capacity,
+ tokens: update.inboundRateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.inboundRateLimiterConfig.isEnabled
+ }),
+ remotePoolAddress: update.remotePoolAddress,
+ remoteTokenAddress: update.remoteTokenAddress
+ });
+
+ emit ChainAdded(
+ update.remoteChainSelector,
+ update.remoteTokenAddress,
+ update.outboundRateLimiterConfig,
+ update.inboundRateLimiterConfig
+ );
+ } else {
+ // If the chain doesn't exist, revert
+ if (!s_remoteChainSelectors.remove(update.remoteChainSelector)) {
+ revert NonExistentChain(update.remoteChainSelector);
+ }
+
+ delete s_remoteChainConfigs[token][update.remoteChainSelector];
+
+ emit ChainRemoved(update.remoteChainSelector);
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Rate limiting │
+ // ================================================================
+
+ /// @notice Consumes outbound rate limiting capacity in this pool
+ function _consumeOutboundRateLimit(address token, uint64 remoteChainSelector, uint256 amount) internal {
+ s_remoteChainConfigs[token][remoteChainSelector].outboundRateLimiterConfig._consume(amount, token);
+ }
+
+ /// @notice Consumes inbound rate limiting capacity in this pool
+ function _consumeInboundRateLimit(address token, uint64 remoteChainSelector, uint256 amount) internal {
+ s_remoteChainConfigs[token][remoteChainSelector].inboundRateLimiterConfig._consume(amount, token);
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function getCurrentOutboundRateLimiterState(
+ address token,
+ uint64 remoteChainSelector
+ ) external view returns (RateLimiter.TokenBucket memory) {
+ return s_remoteChainConfigs[token][remoteChainSelector].outboundRateLimiterConfig._currentTokenBucketState();
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function getCurrentInboundRateLimiterState(
+ address token,
+ uint64 remoteChainSelector
+ ) external view returns (RateLimiter.TokenBucket memory) {
+ return s_remoteChainConfigs[token][remoteChainSelector].inboundRateLimiterConfig._currentTokenBucketState();
+ }
+
+ /// @notice Sets the chain rate limiter config.
+ /// @param remoteChainSelector The remote chain selector for which the rate limits apply.
+ /// @param outboundConfig The new outbound rate limiter config, meaning the onRamp rate limits for the given chain.
+ /// @param inboundConfig The new inbound rate limiter config, meaning the offRamp rate limits for the given chain.
+ function setChainRateLimiterConfig(
+ address token,
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) internal {
+ if (!isSupportedChain(remoteChainSelector)) revert NonExistentChain(remoteChainSelector);
+ RateLimiter._validateTokenBucketConfig(outboundConfig, false);
+ s_remoteChainConfigs[token][remoteChainSelector].outboundRateLimiterConfig._setTokenBucketConfig(outboundConfig);
+ RateLimiter._validateTokenBucketConfig(inboundConfig, false);
+ s_remoteChainConfigs[token][remoteChainSelector].inboundRateLimiterConfig._setTokenBucketConfig(inboundConfig);
+ emit ChainConfigured(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Checks whether remote chain selector is configured on this contract, and if the msg.sender
+ /// is a permissioned onRamp for the given chain on the Router.
+ function _onlyOnRamp(uint64 remoteChainSelector) internal view {
+ if (!isSupportedChain(remoteChainSelector)) revert ChainNotAllowed(remoteChainSelector);
+ if (!(msg.sender == s_router.getOnRamp(remoteChainSelector))) revert CallerIsNotARampOnRouter(msg.sender);
+ }
+
+ /// @notice Checks whether remote chain selector is configured on this contract, and if the msg.sender
+ /// is a permissioned offRamp for the given chain on the Router.
+ function _onlyOffRamp(uint64 remoteChainSelector) internal view {
+ if (!isSupportedChain(remoteChainSelector)) revert ChainNotAllowed(remoteChainSelector);
+ if (!s_router.isOffRamp(remoteChainSelector, msg.sender)) revert CallerIsNotARampOnRouter(msg.sender);
+ }
+
+ // ================================================================
+ // │ Allowlist │
+ // ================================================================
+
+ function _checkAllowList(address sender) internal view {
+ if (i_allowlistEnabled && !s_allowList.contains(sender)) revert SenderNotAllowed(sender);
+ }
+
+ /// @notice Gets whether the allowList functionality is enabled.
+ /// @return true is enabled, false if not.
+ function getAllowListEnabled() external view returns (bool) {
+ return i_allowlistEnabled;
+ }
+
+ /// @notice Gets the allowed addresses.
+ /// @return The allowed addresses.
+ function getAllowList() external view returns (address[] memory) {
+ return s_allowList.values();
+ }
+
+ /// @notice Apply updates to the allow list.
+ /// @param removes The addresses to be removed.
+ /// @param adds The addresses to be added.
+ /// @dev allowListing will be removed before public launch
+ function applyAllowListUpdates(address[] calldata removes, address[] calldata adds) external onlyOwner {
+ _applyAllowListUpdates(removes, adds);
+ }
+
+ /// @notice Internal version of applyAllowListUpdates to allow for reuse in the constructor.
+ function _applyAllowListUpdates(address[] memory removes, address[] memory adds) internal {
+ if (!i_allowlistEnabled) revert AllowListNotEnabled();
+
+ for (uint256 i = 0; i < removes.length; ++i) {
+ address toRemove = removes[i];
+ if (s_allowList.remove(toRemove)) {
+ emit AllowListRemove(toRemove);
+ }
+ }
+ for (uint256 i = 0; i < adds.length; ++i) {
+ address toAdd = adds[i];
+ if (toAdd == address(0)) {
+ continue;
+ }
+ if (s_allowList.add(toAdd)) {
+ emit AllowListAdd(toAdd);
+ }
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/OCR2Helper.sol b/contracts/src/v0.8/ccip/test/helpers/OCR2Helper.sol
new file mode 100644
index 00000000000..cb66352ff65
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/OCR2Helper.sol
@@ -0,0 +1,38 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OCR2Base} from "../../ocr/OCR2Base.sol";
+
+contract OCR2Helper is OCR2Base(false) {
+ function configDigestFromConfigData(
+ uint256 chainSelector,
+ address contractAddress,
+ uint64 configCount,
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) public pure returns (bytes32) {
+ return _configDigestFromConfigData(
+ chainSelector,
+ contractAddress,
+ configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+ }
+
+ function _report(bytes calldata report, uint40 epochAndRound) internal override {}
+
+ function typeAndVersion() public pure override returns (string memory) {
+ return "OCR2BaseHelper 1.0.0";
+ }
+
+ function _beforeSetConfig(bytes memory _onchainConfig) internal override {}
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/OCR2NoChecksHelper.sol b/contracts/src/v0.8/ccip/test/helpers/OCR2NoChecksHelper.sol
new file mode 100644
index 00000000000..a1ececa326f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/OCR2NoChecksHelper.sol
@@ -0,0 +1,38 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OCR2BaseNoChecks} from "../../ocr/OCR2BaseNoChecks.sol";
+
+contract OCR2NoChecksHelper is OCR2BaseNoChecks {
+ function configDigestFromConfigData(
+ uint256 chainSelector,
+ address contractAddress,
+ uint64 configCount,
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) public pure returns (bytes32) {
+ return _configDigestFromConfigData(
+ chainSelector,
+ contractAddress,
+ configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+ }
+
+ function _report(bytes calldata report) internal override {}
+
+ function typeAndVersion() public pure override returns (string memory) {
+ return "OCR2BaseHelper 1.0.0";
+ }
+
+ function _beforeSetConfig(bytes memory _onchainConfig) internal override {}
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/PriceRegistryHelper.sol b/contracts/src/v0.8/ccip/test/helpers/PriceRegistryHelper.sol
new file mode 100644
index 00000000000..8524df12ccf
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/PriceRegistryHelper.sol
@@ -0,0 +1,72 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {PriceRegistry} from "../../PriceRegistry.sol";
+import {Client} from "../../libraries/Client.sol";
+
+contract PriceRegistryHelper is PriceRegistry {
+ constructor(
+ StaticConfig memory staticConfig,
+ address[] memory priceUpdaters,
+ address[] memory feeTokens,
+ TokenPriceFeedUpdate[] memory tokenPriceFeeds,
+ TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs,
+ PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs,
+ DestChainConfigArgs[] memory destChainConfigArgs
+ )
+ PriceRegistry(
+ staticConfig,
+ priceUpdaters,
+ feeTokens,
+ tokenPriceFeeds,
+ tokenTransferFeeConfigArgs,
+ premiumMultiplierWeiPerEthArgs,
+ destChainConfigArgs
+ )
+ {}
+
+ function getDataAvailabilityCost(
+ uint64 destChainSelector,
+ uint112 dataAvailabilityGasPrice,
+ uint256 messageDataLength,
+ uint256 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) external view returns (uint256) {
+ return _getDataAvailabilityCost(
+ s_destChainConfigs[destChainSelector],
+ dataAvailabilityGasPrice,
+ messageDataLength,
+ numberOfTokens,
+ tokenTransferBytesOverhead
+ );
+ }
+
+ function getTokenTransferCost(
+ uint64 destChainSelector,
+ address feeToken,
+ uint224 feeTokenPrice,
+ Client.EVMTokenAmount[] calldata tokenAmounts
+ ) external view returns (uint256, uint32, uint32) {
+ return _getTokenTransferCost(
+ s_destChainConfigs[destChainSelector], destChainSelector, feeToken, feeTokenPrice, tokenAmounts
+ );
+ }
+
+ function parseEVMExtraArgsFromBytes(
+ bytes calldata extraArgs,
+ uint64 destChainSelector
+ ) external view returns (Client.EVMExtraArgsV2 memory) {
+ return _parseEVMExtraArgsFromBytes(extraArgs, s_destChainConfigs[destChainSelector]);
+ }
+
+ function parseEVMExtraArgsFromBytes(
+ bytes calldata extraArgs,
+ DestChainConfig memory destChainConfig
+ ) external pure returns (Client.EVMExtraArgsV2 memory) {
+ return _parseEVMExtraArgsFromBytes(extraArgs, destChainConfig);
+ }
+
+ function validateDestFamilyAddress(bytes4 chainFamilySelector, bytes memory destAddress) external pure {
+ _validateDestFamilyAddress(chainFamilySelector, destAddress);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/RateLimiterHelper.sol b/contracts/src/v0.8/ccip/test/helpers/RateLimiterHelper.sol
new file mode 100644
index 00000000000..8fb96a0c1c3
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/RateLimiterHelper.sol
@@ -0,0 +1,36 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+
+contract RateLimiterHelper {
+ using RateLimiter for RateLimiter.TokenBucket;
+
+ RateLimiter.TokenBucket internal s_rateLimiter;
+
+ constructor(RateLimiter.Config memory config) {
+ s_rateLimiter = RateLimiter.TokenBucket({
+ rate: config.rate,
+ capacity: config.capacity,
+ tokens: config.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: config.isEnabled
+ });
+ }
+
+ function consume(uint256 requestTokens, address tokenAddress) external {
+ s_rateLimiter._consume(requestTokens, tokenAddress);
+ }
+
+ function currentTokenBucketState() external view returns (RateLimiter.TokenBucket memory) {
+ return s_rateLimiter._currentTokenBucketState();
+ }
+
+ function setTokenBucketConfig(RateLimiter.Config memory config) external {
+ s_rateLimiter._setTokenBucketConfig(config);
+ }
+
+ function getRateLimiter() external view returns (RateLimiter.TokenBucket memory) {
+ return s_rateLimiter;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/ReportCodec.sol b/contracts/src/v0.8/ccip/test/helpers/ReportCodec.sol
new file mode 100644
index 00000000000..ca53d512c0d
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/ReportCodec.sol
@@ -0,0 +1,18 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {Internal} from "../../libraries/Internal.sol";
+import {EVM2EVMMultiOffRamp} from "../../offRamp/EVM2EVMMultiOffRamp.sol";
+
+contract ReportCodec {
+ event ExecuteReportDecoded(Internal.ExecutionReportSingleChain[] report);
+ event CommitReportDecoded(EVM2EVMMultiOffRamp.CommitReport report);
+
+ function decodeExecuteReport(bytes memory report) public pure returns (Internal.ExecutionReportSingleChain[] memory) {
+ return abi.decode(report, (Internal.ExecutionReportSingleChain[]));
+ }
+
+ function decodeCommitReport(bytes memory report) public pure returns (EVM2EVMMultiOffRamp.CommitReport memory) {
+ return abi.decode(report, (EVM2EVMMultiOffRamp.CommitReport));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/TokenPoolHelper.sol b/contracts/src/v0.8/ccip/test/helpers/TokenPoolHelper.sol
new file mode 100644
index 00000000000..c57bfa33119
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/TokenPoolHelper.sol
@@ -0,0 +1,42 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Pool} from "../../libraries/Pool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract TokenPoolHelper is TokenPool {
+ constructor(
+ IERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) TokenPool(token, allowlist, rmnProxy, router) {}
+
+ function lockOrBurn(Pool.LockOrBurnInV1 calldata lockOrBurnIn)
+ external
+ view
+ override
+ returns (Pool.LockOrBurnOutV1 memory)
+ {
+ return Pool.LockOrBurnOutV1({destTokenAddress: getRemoteToken(lockOrBurnIn.remoteChainSelector), destPoolData: ""});
+ }
+
+ function releaseOrMint(Pool.ReleaseOrMintInV1 calldata releaseOrMintIn)
+ external
+ pure
+ override
+ returns (Pool.ReleaseOrMintOutV1 memory)
+ {
+ return Pool.ReleaseOrMintOutV1({destinationAmount: releaseOrMintIn.amount});
+ }
+
+ function onlyOnRampModifier(uint64 remoteChainSelector) external view {
+ _onlyOnRamp(remoteChainSelector);
+ }
+
+ function onlyOffRampModifier(uint64 remoteChainSelector) external view {
+ _onlyOffRamp(remoteChainSelector);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/USDCTokenPoolHelper.sol b/contracts/src/v0.8/ccip/test/helpers/USDCTokenPoolHelper.sol
new file mode 100644
index 00000000000..7a3400588a8
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/USDCTokenPoolHelper.sol
@@ -0,0 +1,21 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+
+import {ITokenMessenger} from "../../pools/USDC/ITokenMessenger.sol";
+import {USDCTokenPool} from "../../pools/USDC/USDCTokenPool.sol";
+
+contract USDCTokenPoolHelper is USDCTokenPool {
+ constructor(
+ ITokenMessenger tokenMessenger,
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address rmnProxy,
+ address router
+ ) USDCTokenPool(tokenMessenger, token, allowlist, rmnProxy, router) {}
+
+ function validateMessage(bytes memory usdcMessage, SourceTokenDataPayload memory sourceTokenData) external view {
+ return _validateMessage(usdcMessage, sourceTokenData);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/receivers/ConformingReceiver.sol b/contracts/src/v0.8/ccip/test/helpers/receivers/ConformingReceiver.sol
new file mode 100644
index 00000000000..159cd7a8514
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/receivers/ConformingReceiver.sol
@@ -0,0 +1,15 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {CCIPReceiver} from "../../../applications/CCIPReceiver.sol";
+import {Client} from "../../../libraries/Client.sol";
+
+contract ConformingReceiver is CCIPReceiver {
+ event MessageReceived();
+
+ constructor(address router, address feeToken) CCIPReceiver(router) {}
+
+ function _ccipReceive(Client.Any2EVMMessage memory) internal virtual override {
+ emit MessageReceived();
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/receivers/MaybeRevertMessageReceiver.sol b/contracts/src/v0.8/ccip/test/helpers/receivers/MaybeRevertMessageReceiver.sol
new file mode 100644
index 00000000000..dd65f202dfe
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/receivers/MaybeRevertMessageReceiver.sol
@@ -0,0 +1,54 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IAny2EVMMessageReceiver} from "../../../interfaces/IAny2EVMMessageReceiver.sol";
+import {Client} from "../../../libraries/Client.sol";
+
+import {IERC165} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+
+contract MaybeRevertMessageReceiver is IAny2EVMMessageReceiver, IERC165 {
+ error ReceiveRevert();
+ error CustomError(bytes err);
+
+ event ValueReceived(uint256 amount);
+ event MessageReceived();
+
+ address private s_manager;
+ bool public s_toRevert;
+ bytes private s_err;
+
+ constructor(bool toRevert) {
+ s_manager = msg.sender;
+ s_toRevert = toRevert;
+ }
+
+ function setRevert(bool toRevert) external {
+ s_toRevert = toRevert;
+ }
+
+ function setErr(bytes memory err) external {
+ s_err = err;
+ }
+
+ /// @notice IERC165 supports an interfaceId
+ /// @param interfaceId The interfaceId to check
+ /// @return true if the interfaceId is supported
+ function supportsInterface(bytes4 interfaceId) public pure override returns (bool) {
+ return interfaceId == type(IAny2EVMMessageReceiver).interfaceId || interfaceId == type(IERC165).interfaceId;
+ }
+
+ function ccipReceive(Client.Any2EVMMessage calldata) external override {
+ if (s_toRevert) {
+ revert CustomError(s_err);
+ }
+ emit MessageReceived();
+ }
+
+ receive() external payable {
+ if (s_toRevert) {
+ revert ReceiveRevert();
+ }
+
+ emit ValueReceived(msg.value);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/receivers/MaybeRevertMessageReceiverNo165.sol b/contracts/src/v0.8/ccip/test/helpers/receivers/MaybeRevertMessageReceiverNo165.sol
new file mode 100644
index 00000000000..4f56394c4e5
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/receivers/MaybeRevertMessageReceiverNo165.sol
@@ -0,0 +1,27 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "../../../interfaces/IAny2EVMMessageReceiver.sol";
+
+contract MaybeRevertMessageReceiverNo165 is IAny2EVMMessageReceiver {
+ address private s_manager;
+ bool public s_toRevert;
+
+ event MessageReceived();
+
+ constructor(bool toRevert) {
+ s_manager = msg.sender;
+ s_toRevert = toRevert;
+ }
+
+ function setRevert(bool toRevert) external {
+ s_toRevert = toRevert;
+ }
+
+ function ccipReceive(Client.Any2EVMMessage calldata) external override {
+ if (s_toRevert) {
+ revert();
+ }
+ emit MessageReceived();
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/receivers/ReentrancyAbuser.sol b/contracts/src/v0.8/ccip/test/helpers/receivers/ReentrancyAbuser.sol
new file mode 100644
index 00000000000..ae8759099cd
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/receivers/ReentrancyAbuser.sol
@@ -0,0 +1,40 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {CCIPReceiver} from "../../../applications/CCIPReceiver.sol";
+import {Client} from "../../../libraries/Client.sol";
+import {Internal} from "../../../libraries/Internal.sol";
+import {EVM2EVMOffRamp} from "../../../offRamp/EVM2EVMOffRamp.sol";
+
+contract ReentrancyAbuser is CCIPReceiver {
+ event ReentrancySucceeded();
+
+ bool internal s_ReentrancyDone = false;
+ Internal.ExecutionReport internal s_payload;
+ EVM2EVMOffRamp internal s_offRamp;
+
+ constructor(address router, EVM2EVMOffRamp offRamp) CCIPReceiver(router) {
+ s_offRamp = offRamp;
+ }
+
+ function setPayload(Internal.ExecutionReport calldata payload) public {
+ s_payload = payload;
+ }
+
+ function _ccipReceive(Client.Any2EVMMessage memory) internal override {
+ // Use original message gas limits in manual execution
+ uint256 numMsgs = s_payload.messages.length;
+ uint256[] memory gasOverrides = new uint256[](numMsgs);
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ gasOverrides[i] = 0;
+ }
+
+ if (!s_ReentrancyDone) {
+ // Could do more rounds but a PoC one is enough
+ s_ReentrancyDone = true;
+ s_offRamp.manuallyExecute(s_payload, gasOverrides);
+ } else {
+ emit ReentrancySucceeded();
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/helpers/receivers/ReentrancyAbuserMultiRamp.sol b/contracts/src/v0.8/ccip/test/helpers/receivers/ReentrancyAbuserMultiRamp.sol
new file mode 100644
index 00000000000..c9e7d7e8ad6
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/helpers/receivers/ReentrancyAbuserMultiRamp.sol
@@ -0,0 +1,44 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.19;
+
+import {CCIPReceiver} from "../../../applications/CCIPReceiver.sol";
+import {Client} from "../../../libraries/Client.sol";
+import {Internal} from "../../../libraries/Internal.sol";
+import {EVM2EVMMultiOffRamp} from "../../../offRamp/EVM2EVMMultiOffRamp.sol";
+
+contract ReentrancyAbuserMultiRamp is CCIPReceiver {
+ event ReentrancySucceeded();
+
+ bool internal s_ReentrancyDone = false;
+ Internal.ExecutionReportSingleChain internal s_payload;
+ EVM2EVMMultiOffRamp internal s_offRamp;
+
+ constructor(address router, EVM2EVMMultiOffRamp offRamp) CCIPReceiver(router) {
+ s_offRamp = offRamp;
+ }
+
+ function setPayload(Internal.ExecutionReportSingleChain calldata payload) public {
+ s_payload = payload;
+ }
+
+ function _ccipReceive(Client.Any2EVMMessage memory) internal override {
+ // Use original message gas limits in manual execution
+ uint256 numMsgs = s_payload.messages.length;
+ uint256[][] memory gasOverrides = new uint256[][](1);
+ gasOverrides[0] = new uint256[](numMsgs);
+ for (uint256 i = 0; i < numMsgs; ++i) {
+ gasOverrides[0][i] = 0;
+ }
+
+ Internal.ExecutionReportSingleChain[] memory batchPayload = new Internal.ExecutionReportSingleChain[](1);
+ batchPayload[0] = s_payload;
+
+ if (!s_ReentrancyDone) {
+ // Could do more rounds but a PoC one is enough
+ s_ReentrancyDone = true;
+ s_offRamp.manuallyExecute(batchPayload, gasOverrides);
+ } else {
+ emit ReentrancySucceeded();
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/legacy/BurnMintTokenPool1_2.sol b/contracts/src/v0.8/ccip/test/legacy/BurnMintTokenPool1_2.sol
new file mode 100644
index 00000000000..2e7878730ea
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/legacy/BurnMintTokenPool1_2.sol
@@ -0,0 +1,353 @@
+// SPDX-License-Identifier: UNLICENSED
+pragma solidity ^0.8.0;
+
+import {ITypeAndVersion} from "../../../shared/interfaces/ITypeAndVersion.sol";
+import {IPoolPriorTo1_5} from "../../interfaces/IPoolPriorTo1_5.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+
+import {OwnerIsCreator} from "../../../shared/access/OwnerIsCreator.sol";
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {IERC165} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+import {EnumerableSet} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice Base abstract class with common functions for all token pools.
+/// A token pool serves as isolated place for holding tokens and token specific logic
+/// that may execute as tokens move across the bridge.
+abstract contract TokenPool1_2 is IPoolPriorTo1_5, OwnerIsCreator, IERC165 {
+ using EnumerableSet for EnumerableSet.AddressSet;
+ using RateLimiter for RateLimiter.TokenBucket;
+
+ error PermissionsError();
+ error ZeroAddressNotAllowed();
+ error SenderNotAllowed(address sender);
+ error AllowListNotEnabled();
+ error NonExistentRamp(address ramp);
+ error BadARMSignal();
+ error RampAlreadyExists(address ramp);
+
+ event Locked(address indexed sender, uint256 amount);
+ event Burned(address indexed sender, uint256 amount);
+ event Released(address indexed sender, address indexed recipient, uint256 amount);
+ event Minted(address indexed sender, address indexed recipient, uint256 amount);
+ event OnRampAdded(address onRamp, RateLimiter.Config rateLimiterConfig);
+ event OnRampConfigured(address onRamp, RateLimiter.Config rateLimiterConfig);
+ event OnRampRemoved(address onRamp);
+ event OffRampAdded(address offRamp, RateLimiter.Config rateLimiterConfig);
+ event OffRampConfigured(address offRamp, RateLimiter.Config rateLimiterConfig);
+ event OffRampRemoved(address offRamp);
+ event AllowListAdd(address sender);
+ event AllowListRemove(address sender);
+
+ struct RampUpdate {
+ address ramp;
+ bool allowed;
+ RateLimiter.Config rateLimiterConfig;
+ }
+
+ /// @dev The bridgeable token that is managed by this pool.
+ IERC20 internal immutable i_token;
+ /// @dev The address of the arm proxy
+ address internal immutable i_armProxy;
+ /// @dev The immutable flag that indicates if the pool is access-controlled.
+ bool internal immutable i_allowlistEnabled;
+ /// @dev A set of addresses allowed to trigger lockOrBurn as original senders.
+ /// Only takes effect if i_allowlistEnabled is true.
+ /// This can be used to ensure only token-issuer specified addresses can
+ /// move tokens.
+ EnumerableSet.AddressSet internal s_allowList;
+
+ /// @dev A set of allowed onRamps. We want the whitelist to be enumerable to
+ /// be able to quickly determine (without parsing logs) who can access the pool.
+ EnumerableSet.AddressSet internal s_onRamps;
+ /// @dev Inbound rate limits. This allows per destination chain
+ /// token issuer specified rate limiting (e.g. issuers may trust chains to varying
+ /// degrees and prefer different limits)
+ mapping(address => RateLimiter.TokenBucket) internal s_onRampRateLimits;
+ /// @dev A set of allowed offRamps.
+ EnumerableSet.AddressSet internal s_offRamps;
+ /// @dev Outbound rate limits. Corresponds to the inbound rate limit for the pool
+ /// on the remote chain.
+ mapping(address => RateLimiter.TokenBucket) internal s_offRampRateLimits;
+
+ constructor(IERC20 token, address[] memory allowlist, address armProxy) {
+ if (address(token) == address(0)) revert ZeroAddressNotAllowed();
+ i_token = token;
+ i_armProxy = armProxy;
+
+ // Pool can be set as permissioned or permissionless at deployment time only to save hot-path gas.
+ i_allowlistEnabled = allowlist.length > 0;
+ if (i_allowlistEnabled) {
+ _applyAllowListUpdates(new address[](0), allowlist);
+ }
+ }
+
+ /// @notice Get ARM proxy address
+ /// @return armProxy Address of arm proxy
+ function getArmProxy() public view returns (address armProxy) {
+ return i_armProxy;
+ }
+
+ /// @inheritdoc IPoolPriorTo1_5
+ function getToken() public view override returns (IERC20 token) {
+ return i_token;
+ }
+
+ /// @inheritdoc IERC165
+ function supportsInterface(bytes4 interfaceId) public pure virtual override returns (bool) {
+ return interfaceId == type(IPoolPriorTo1_5).interfaceId || interfaceId == type(IERC165).interfaceId;
+ }
+
+ // ================================================================
+ // │ Ramp permissions │
+ // ================================================================
+
+ /// @notice Checks whether something is a permissioned onRamp on this contract.
+ /// @return true if the given address is a permissioned onRamp.
+ function isOnRamp(address onRamp) public view returns (bool) {
+ return s_onRamps.contains(onRamp);
+ }
+
+ /// @notice Checks whether something is a permissioned offRamp on this contract.
+ /// @return true if the given address is a permissioned offRamp.
+ function isOffRamp(address offRamp) public view returns (bool) {
+ return s_offRamps.contains(offRamp);
+ }
+
+ /// @notice Get onRamp whitelist
+ /// @return list of onRamps.
+ function getOnRamps() public view returns (address[] memory) {
+ return s_onRamps.values();
+ }
+
+ /// @notice Get offRamp whitelist
+ /// @return list of offramps
+ function getOffRamps() public view returns (address[] memory) {
+ return s_offRamps.values();
+ }
+
+ /// @notice Sets permissions for all on and offRamps.
+ /// @dev Only callable by the owner
+ /// @param onRamps A list of onRamps and their new permission status/rate limits
+ /// @param offRamps A list of offRamps and their new permission status/rate limits
+ function applyRampUpdates(RampUpdate[] calldata onRamps, RampUpdate[] calldata offRamps) external virtual onlyOwner {
+ _applyRampUpdates(onRamps, offRamps);
+ }
+
+ function _applyRampUpdates(RampUpdate[] calldata onRamps, RampUpdate[] calldata offRamps) internal onlyOwner {
+ for (uint256 i = 0; i < onRamps.length; ++i) {
+ RampUpdate memory update = onRamps[i];
+ if (update.allowed) {
+ if (s_onRamps.add(update.ramp)) {
+ s_onRampRateLimits[update.ramp] = RateLimiter.TokenBucket({
+ rate: update.rateLimiterConfig.rate,
+ capacity: update.rateLimiterConfig.capacity,
+ tokens: update.rateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.rateLimiterConfig.isEnabled
+ });
+ emit OnRampAdded(update.ramp, update.rateLimiterConfig);
+ } else {
+ revert RampAlreadyExists(update.ramp);
+ }
+ } else {
+ if (s_onRamps.remove(update.ramp)) {
+ delete s_onRampRateLimits[update.ramp];
+ emit OnRampRemoved(update.ramp);
+ } else {
+ // Cannot remove a non-existent onRamp.
+ revert NonExistentRamp(update.ramp);
+ }
+ }
+ }
+
+ for (uint256 i = 0; i < offRamps.length; ++i) {
+ RampUpdate memory update = offRamps[i];
+ if (update.allowed) {
+ if (s_offRamps.add(update.ramp)) {
+ s_offRampRateLimits[update.ramp] = RateLimiter.TokenBucket({
+ rate: update.rateLimiterConfig.rate,
+ capacity: update.rateLimiterConfig.capacity,
+ tokens: update.rateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.rateLimiterConfig.isEnabled
+ });
+ emit OffRampAdded(update.ramp, update.rateLimiterConfig);
+ } else {
+ revert RampAlreadyExists(update.ramp);
+ }
+ } else {
+ if (s_offRamps.remove(update.ramp)) {
+ delete s_offRampRateLimits[update.ramp];
+ emit OffRampRemoved(update.ramp);
+ } else {
+ // Cannot remove a non-existent offRamp.
+ revert NonExistentRamp(update.ramp);
+ }
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Rate limiting │
+ // ================================================================
+
+ /// @notice Consumes outbound rate limiting capacity in this pool
+ function _consumeOnRampRateLimit(uint256 amount) internal {
+ s_onRampRateLimits[msg.sender]._consume(amount, address(i_token));
+ }
+
+ /// @notice Consumes inbound rate limiting capacity in this pool
+ function _consumeOffRampRateLimit(uint256 amount) internal {
+ s_offRampRateLimits[msg.sender]._consume(amount, address(i_token));
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function currentOnRampRateLimiterState(address onRamp) external view returns (RateLimiter.TokenBucket memory) {
+ return s_onRampRateLimits[onRamp]._currentTokenBucketState();
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function currentOffRampRateLimiterState(address offRamp) external view returns (RateLimiter.TokenBucket memory) {
+ return s_offRampRateLimits[offRamp]._currentTokenBucketState();
+ }
+
+ /// @notice Sets the onramp rate limited config.
+ /// @param config The new rate limiter config.
+ function setOnRampRateLimiterConfig(address onRamp, RateLimiter.Config memory config) external onlyOwner {
+ if (!isOnRamp(onRamp)) revert NonExistentRamp(onRamp);
+ s_onRampRateLimits[onRamp]._setTokenBucketConfig(config);
+ emit OnRampConfigured(onRamp, config);
+ }
+
+ /// @notice Sets the offramp rate limited config.
+ /// @param config The new rate limiter config.
+ function setOffRampRateLimiterConfig(address offRamp, RateLimiter.Config memory config) external onlyOwner {
+ if (!isOffRamp(offRamp)) revert NonExistentRamp(offRamp);
+ s_offRampRateLimits[offRamp]._setTokenBucketConfig(config);
+ emit OffRampConfigured(offRamp, config);
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Checks whether the msg.sender is a permissioned onRamp on this contract
+ /// @dev Reverts with a PermissionsError if check fails
+ modifier onlyOnRamp() {
+ if (!isOnRamp(msg.sender)) revert PermissionsError();
+ _;
+ }
+
+ /// @notice Checks whether the msg.sender is a permissioned offRamp on this contract
+ /// @dev Reverts with a PermissionsError if check fails
+ modifier onlyOffRamp() {
+ if (!isOffRamp(msg.sender)) revert PermissionsError();
+ _;
+ }
+
+ // ================================================================
+ // │ Allowlist │
+ // ================================================================
+
+ modifier checkAllowList(address sender) {
+ if (i_allowlistEnabled && !s_allowList.contains(sender)) revert SenderNotAllowed(sender);
+ _;
+ }
+
+ /// @notice Gets whether the allowList functionality is enabled.
+ /// @return true is enabled, false if not.
+ function getAllowListEnabled() external view returns (bool) {
+ return i_allowlistEnabled;
+ }
+
+ /// @notice Gets the allowed addresses.
+ /// @return The allowed addresses.
+ function getAllowList() external view returns (address[] memory) {
+ return s_allowList.values();
+ }
+
+ /// @notice Apply updates to the allow list.
+ /// @param removes The addresses to be removed.
+ /// @param adds The addresses to be added.
+ /// @dev allowListing will be removed before public launch
+ function applyAllowListUpdates(address[] calldata removes, address[] calldata adds) external onlyOwner {
+ _applyAllowListUpdates(removes, adds);
+ }
+
+ /// @notice Internal version of applyAllowListUpdates to allow for reuse in the constructor.
+ function _applyAllowListUpdates(address[] memory removes, address[] memory adds) internal {
+ if (!i_allowlistEnabled) revert AllowListNotEnabled();
+
+ for (uint256 i = 0; i < removes.length; ++i) {
+ address toRemove = removes[i];
+ if (s_allowList.remove(toRemove)) {
+ emit AllowListRemove(toRemove);
+ }
+ }
+ for (uint256 i = 0; i < adds.length; ++i) {
+ address toAdd = adds[i];
+ if (toAdd == address(0)) {
+ continue;
+ }
+ if (s_allowList.add(toAdd)) {
+ emit AllowListAdd(toAdd);
+ }
+ }
+ }
+
+ /// @notice Ensure that there is no active curse.
+ modifier whenHealthy() {
+ if (IRMN(i_armProxy).isCursed()) revert BadARMSignal();
+ _;
+ }
+}
+
+contract BurnMintTokenPool1_2 is ITypeAndVersion, TokenPool1_2 {
+ // solhint-disable-next-line chainlink-solidity/all-caps-constant-storage-variables
+ string public constant override typeAndVersion = "BurnMintTokenPool 1.2.0";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address armProxy
+ ) TokenPool1_2(token, allowlist, armProxy) {}
+
+ /// @notice Burn the token in the pool
+ /// @param amount Amount to burn
+ /// @dev The whenHealthy check is important to ensure that even if a ramp is compromised
+ /// we're able to stop token movement via ARM.
+ function lockOrBurn(
+ address originalSender,
+ bytes calldata,
+ uint256 amount,
+ uint64,
+ bytes calldata
+ ) external virtual override onlyOnRamp checkAllowList(originalSender) whenHealthy returns (bytes memory) {
+ _consumeOnRampRateLimit(amount);
+ IBurnMintERC20(address(i_token)).burn(amount);
+ emit Burned(msg.sender, amount);
+ return "";
+ }
+
+ /// @notice Mint tokens from the pool to the recipient
+ /// @param receiver Recipient address
+ /// @param amount Amount to mint
+ /// @dev The whenHealthy check is important to ensure that even if a ramp is compromised
+ /// we're able to stop token movement via ARM.
+ function releaseOrMint(
+ bytes memory,
+ address receiver,
+ uint256 amount,
+ uint64,
+ bytes memory
+ ) external virtual override whenHealthy onlyOffRamp {
+ _consumeOffRampRateLimit(amount);
+ IBurnMintERC20(address(i_token)).mint(receiver, amount);
+ emit Minted(msg.sender, receiver, amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/legacy/BurnMintTokenPool1_4.sol b/contracts/src/v0.8/ccip/test/legacy/BurnMintTokenPool1_4.sol
new file mode 100644
index 00000000000..9ac5d66b1cf
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/legacy/BurnMintTokenPool1_4.sol
@@ -0,0 +1,402 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../../shared/interfaces/ITypeAndVersion.sol";
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+import {IPoolPriorTo1_5} from "../../interfaces/IPoolPriorTo1_5.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+import {IRouter} from "../../interfaces/IRouter.sol";
+
+import {OwnerIsCreator} from "../../../shared/access/OwnerIsCreator.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {IERC165} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+import {EnumerableSet} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice Base abstract class with common functions for all token pools.
+/// A token pool serves as isolated place for holding tokens and token specific logic
+/// that may execute as tokens move across the bridge.
+abstract contract TokenPool1_4 is IPoolPriorTo1_5, OwnerIsCreator, IERC165 {
+ using EnumerableSet for EnumerableSet.AddressSet;
+ using EnumerableSet for EnumerableSet.UintSet;
+ using RateLimiter for RateLimiter.TokenBucket;
+
+ error CallerIsNotARampOnRouter(address caller);
+ error ZeroAddressNotAllowed();
+ error SenderNotAllowed(address sender);
+ error AllowListNotEnabled();
+ error NonExistentChain(uint64 remoteChainSelector);
+ error ChainNotAllowed(uint64 remoteChainSelector);
+ error BadARMSignal();
+ error ChainAlreadyExists(uint64 chainSelector);
+
+ event Locked(address indexed sender, uint256 amount);
+ event Burned(address indexed sender, uint256 amount);
+ event Released(address indexed sender, address indexed recipient, uint256 amount);
+ event Minted(address indexed sender, address indexed recipient, uint256 amount);
+ event ChainAdded(
+ uint64 remoteChainSelector,
+ RateLimiter.Config outboundRateLimiterConfig,
+ RateLimiter.Config inboundRateLimiterConfig
+ );
+ event ChainConfigured(
+ uint64 remoteChainSelector,
+ RateLimiter.Config outboundRateLimiterConfig,
+ RateLimiter.Config inboundRateLimiterConfig
+ );
+ event ChainRemoved(uint64 remoteChainSelector);
+ event AllowListAdd(address sender);
+ event AllowListRemove(address sender);
+ event RouterUpdated(address oldRouter, address newRouter);
+
+ struct ChainUpdate {
+ uint64 remoteChainSelector; // ──╮ Remote chain selector
+ bool allowed; // ────────────────╯ Whether the chain is allowed
+ RateLimiter.Config outboundRateLimiterConfig; // Outbound rate limited config, meaning the rate limits for all of the onRamps for the given chain
+ RateLimiter.Config inboundRateLimiterConfig; // Inbound rate limited config, meaning the rate limits for all of the offRamps for the given chain
+ }
+
+ /// @dev The bridgeable token that is managed by this pool.
+ IERC20 internal immutable i_token;
+ /// @dev The address of the arm proxy
+ address internal immutable i_armProxy;
+ /// @dev The immutable flag that indicates if the pool is access-controlled.
+ bool internal immutable i_allowlistEnabled;
+ /// @dev A set of addresses allowed to trigger lockOrBurn as original senders.
+ /// Only takes effect if i_allowlistEnabled is true.
+ /// This can be used to ensure only token-issuer specified addresses can
+ /// move tokens.
+ EnumerableSet.AddressSet internal s_allowList;
+ /// @dev The address of the router
+ IRouter internal s_router;
+ /// @dev A set of allowed chain selectors. We want the allowlist to be enumerable to
+ /// be able to quickly determine (without parsing logs) who can access the pool.
+ /// @dev The chain selectors are in uin256 format because of the EnumerableSet implementation.
+ EnumerableSet.UintSet internal s_remoteChainSelectors;
+ /// @dev Outbound rate limits. Corresponds to the inbound rate limit for the pool
+ /// on the remote chain.
+ mapping(uint64 remoteChainSelector => RateLimiter.TokenBucket) internal s_outboundRateLimits;
+ /// @dev Inbound rate limits. This allows per destination chain
+ /// token issuer specified rate limiting (e.g. issuers may trust chains to varying
+ /// degrees and prefer different limits)
+ mapping(uint64 remoteChainSelector => RateLimiter.TokenBucket) internal s_inboundRateLimits;
+
+ constructor(IERC20 token, address[] memory allowlist, address armProxy, address router) {
+ if (address(token) == address(0) || router == address(0)) revert ZeroAddressNotAllowed();
+ i_token = token;
+ i_armProxy = armProxy;
+ s_router = IRouter(router);
+
+ // Pool can be set as permissioned or permissionless at deployment time only to save hot-path gas.
+ i_allowlistEnabled = allowlist.length > 0;
+ if (i_allowlistEnabled) {
+ _applyAllowListUpdates(new address[](0), allowlist);
+ }
+ }
+
+ /// @notice Get ARM proxy address
+ /// @return armProxy Address of arm proxy
+ function getArmProxy() public view returns (address armProxy) {
+ return i_armProxy;
+ }
+
+ /// @inheritdoc IPoolPriorTo1_5
+ function getToken() public view override returns (IERC20 token) {
+ return i_token;
+ }
+
+ /// @notice Gets the pool's Router
+ /// @return router The pool's Router
+ function getRouter() public view returns (address router) {
+ return address(s_router);
+ }
+
+ /// @notice Sets the pool's Router
+ /// @param newRouter The new Router
+ function setRouter(address newRouter) public onlyOwner {
+ if (newRouter == address(0)) revert ZeroAddressNotAllowed();
+ address oldRouter = address(s_router);
+ s_router = IRouter(newRouter);
+
+ emit RouterUpdated(oldRouter, newRouter);
+ }
+
+ /// @inheritdoc IERC165
+ function supportsInterface(bytes4 interfaceId) public pure virtual override returns (bool) {
+ return interfaceId == type(IPoolPriorTo1_5).interfaceId || interfaceId == type(IERC165).interfaceId;
+ }
+
+ // ================================================================
+ // │ Chain permissions │
+ // ================================================================
+
+ /// @notice Checks whether a chain selector is permissioned on this contract.
+ /// @return true if the given chain selector is a permissioned remote chain.
+ function isSupportedChain(uint64 remoteChainSelector) public view returns (bool) {
+ return s_remoteChainSelectors.contains(remoteChainSelector);
+ }
+
+ /// @notice Get list of allowed chains
+ /// @return list of chains.
+ function getSupportedChains() public view returns (uint64[] memory) {
+ uint256[] memory uint256ChainSelectors = s_remoteChainSelectors.values();
+ uint64[] memory chainSelectors = new uint64[](uint256ChainSelectors.length);
+ for (uint256 i = 0; i < uint256ChainSelectors.length; ++i) {
+ chainSelectors[i] = uint64(uint256ChainSelectors[i]);
+ }
+
+ return chainSelectors;
+ }
+
+ /// @notice Sets the permissions for a list of chains selectors. Actual senders for these chains
+ /// need to be allowed on the Router to interact with this pool.
+ /// @dev Only callable by the owner
+ /// @param chains A list of chains and their new permission status & rate limits. Rate limits
+ /// are only used when the chain is being added through `allowed` being true.
+ function applyChainUpdates(ChainUpdate[] calldata chains) external virtual onlyOwner {
+ for (uint256 i = 0; i < chains.length; ++i) {
+ ChainUpdate memory update = chains[i];
+ RateLimiter._validateTokenBucketConfig(update.outboundRateLimiterConfig, !update.allowed);
+ RateLimiter._validateTokenBucketConfig(update.inboundRateLimiterConfig, !update.allowed);
+
+ if (update.allowed) {
+ // If the chain already exists, revert
+ if (!s_remoteChainSelectors.add(update.remoteChainSelector)) {
+ revert ChainAlreadyExists(update.remoteChainSelector);
+ }
+
+ s_outboundRateLimits[update.remoteChainSelector] = RateLimiter.TokenBucket({
+ rate: update.outboundRateLimiterConfig.rate,
+ capacity: update.outboundRateLimiterConfig.capacity,
+ tokens: update.outboundRateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.outboundRateLimiterConfig.isEnabled
+ });
+
+ s_inboundRateLimits[update.remoteChainSelector] = RateLimiter.TokenBucket({
+ rate: update.inboundRateLimiterConfig.rate,
+ capacity: update.inboundRateLimiterConfig.capacity,
+ tokens: update.inboundRateLimiterConfig.capacity,
+ lastUpdated: uint32(block.timestamp),
+ isEnabled: update.inboundRateLimiterConfig.isEnabled
+ });
+ emit ChainAdded(update.remoteChainSelector, update.outboundRateLimiterConfig, update.inboundRateLimiterConfig);
+ } else {
+ // If the chain doesn't exist, revert
+ if (!s_remoteChainSelectors.remove(update.remoteChainSelector)) {
+ revert NonExistentChain(update.remoteChainSelector);
+ }
+
+ delete s_inboundRateLimits[update.remoteChainSelector];
+ delete s_outboundRateLimits[update.remoteChainSelector];
+ emit ChainRemoved(update.remoteChainSelector);
+ }
+ }
+ }
+
+ // ================================================================
+ // │ Rate limiting │
+ // ================================================================
+
+ /// @notice Consumes outbound rate limiting capacity in this pool
+ function _consumeOutboundRateLimit(uint64 remoteChainSelector, uint256 amount) internal {
+ s_outboundRateLimits[remoteChainSelector]._consume(amount, address(i_token));
+ }
+
+ /// @notice Consumes inbound rate limiting capacity in this pool
+ function _consumeInboundRateLimit(uint64 remoteChainSelector, uint256 amount) internal {
+ s_inboundRateLimits[remoteChainSelector]._consume(amount, address(i_token));
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function getCurrentOutboundRateLimiterState(uint64 remoteChainSelector)
+ external
+ view
+ returns (RateLimiter.TokenBucket memory)
+ {
+ return s_outboundRateLimits[remoteChainSelector]._currentTokenBucketState();
+ }
+
+ /// @notice Gets the token bucket with its values for the block it was requested at.
+ /// @return The token bucket.
+ function getCurrentInboundRateLimiterState(uint64 remoteChainSelector)
+ external
+ view
+ returns (RateLimiter.TokenBucket memory)
+ {
+ return s_inboundRateLimits[remoteChainSelector]._currentTokenBucketState();
+ }
+
+ /// @notice Sets the chain rate limiter config.
+ /// @param remoteChainSelector The remote chain selector for which the rate limits apply.
+ /// @param outboundConfig The new outbound rate limiter config, meaning the onRamp rate limits for the given chain.
+ /// @param inboundConfig The new inbound rate limiter config, meaning the offRamp rate limits for the given chain.
+ function setChainRateLimiterConfig(
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) external virtual onlyOwner {
+ _setRateLimitConfig(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+
+ function _setRateLimitConfig(
+ uint64 remoteChainSelector,
+ RateLimiter.Config memory outboundConfig,
+ RateLimiter.Config memory inboundConfig
+ ) internal {
+ if (!isSupportedChain(remoteChainSelector)) revert NonExistentChain(remoteChainSelector);
+ RateLimiter._validateTokenBucketConfig(outboundConfig, false);
+ s_outboundRateLimits[remoteChainSelector]._setTokenBucketConfig(outboundConfig);
+ RateLimiter._validateTokenBucketConfig(inboundConfig, false);
+ s_inboundRateLimits[remoteChainSelector]._setTokenBucketConfig(inboundConfig);
+ emit ChainConfigured(remoteChainSelector, outboundConfig, inboundConfig);
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Checks whether remote chain selector is configured on this contract, and if the msg.sender
+ /// is a permissioned onRamp for the given chain on the Router.
+ modifier onlyOnRamp(uint64 remoteChainSelector) {
+ if (!isSupportedChain(remoteChainSelector)) revert ChainNotAllowed(remoteChainSelector);
+ if (!(msg.sender == s_router.getOnRamp(remoteChainSelector))) revert CallerIsNotARampOnRouter(msg.sender);
+ _;
+ }
+
+ /// @notice Checks whether remote chain selector is configured on this contract, and if the msg.sender
+ /// is a permissioned offRamp for the given chain on the Router.
+ modifier onlyOffRamp(uint64 remoteChainSelector) {
+ if (!isSupportedChain(remoteChainSelector)) revert ChainNotAllowed(remoteChainSelector);
+ if (!s_router.isOffRamp(remoteChainSelector, msg.sender)) revert CallerIsNotARampOnRouter(msg.sender);
+ _;
+ }
+
+ // ================================================================
+ // │ Allowlist │
+ // ================================================================
+
+ modifier checkAllowList(address sender) {
+ if (i_allowlistEnabled && !s_allowList.contains(sender)) revert SenderNotAllowed(sender);
+ _;
+ }
+
+ /// @notice Gets whether the allowList functionality is enabled.
+ /// @return true is enabled, false if not.
+ function getAllowListEnabled() external view returns (bool) {
+ return i_allowlistEnabled;
+ }
+
+ /// @notice Gets the allowed addresses.
+ /// @return The allowed addresses.
+ function getAllowList() external view returns (address[] memory) {
+ return s_allowList.values();
+ }
+
+ /// @notice Apply updates to the allow list.
+ /// @param removes The addresses to be removed.
+ /// @param adds The addresses to be added.
+ /// @dev allowListing will be removed before public launch
+ function applyAllowListUpdates(address[] calldata removes, address[] calldata adds) external onlyOwner {
+ _applyAllowListUpdates(removes, adds);
+ }
+
+ /// @notice Internal version of applyAllowListUpdates to allow for reuse in the constructor.
+ function _applyAllowListUpdates(address[] memory removes, address[] memory adds) internal {
+ if (!i_allowlistEnabled) revert AllowListNotEnabled();
+
+ for (uint256 i = 0; i < removes.length; ++i) {
+ address toRemove = removes[i];
+ if (s_allowList.remove(toRemove)) {
+ emit AllowListRemove(toRemove);
+ }
+ }
+ for (uint256 i = 0; i < adds.length; ++i) {
+ address toAdd = adds[i];
+ if (toAdd == address(0)) {
+ continue;
+ }
+ if (s_allowList.add(toAdd)) {
+ emit AllowListAdd(toAdd);
+ }
+ }
+ }
+
+ /// @notice Ensure that there is no active curse.
+ modifier whenHealthy() {
+ if (IRMN(i_armProxy).isCursed()) revert BadARMSignal();
+ _;
+ }
+}
+
+abstract contract BurnMintTokenPoolAbstract is TokenPool1_4 {
+ /// @notice Contains the specific burn call for a pool.
+ /// @dev overriding this method allows us to create pools with different burn signatures
+ /// without duplicating the underlying logic.
+ function _burn(uint256 amount) internal virtual;
+
+ /// @notice Burn the token in the pool
+ /// @param amount Amount to burn
+ /// @dev The whenHealthy check is important to ensure that even if a ramp is compromised
+ /// we're able to stop token movement via ARM.
+ function lockOrBurn(
+ address originalSender,
+ bytes calldata,
+ uint256 amount,
+ uint64 remoteChainSelector,
+ bytes calldata
+ )
+ external
+ virtual
+ override
+ onlyOnRamp(remoteChainSelector)
+ checkAllowList(originalSender)
+ whenHealthy
+ returns (bytes memory)
+ {
+ _consumeOutboundRateLimit(remoteChainSelector, amount);
+ _burn(amount);
+ emit Burned(msg.sender, amount);
+ return "";
+ }
+
+ /// @notice Mint tokens from the pool to the recipient
+ /// @param receiver Recipient address
+ /// @param amount Amount to mint
+ /// @dev The whenHealthy check is important to ensure that even if a ramp is compromised
+ /// we're able to stop token movement via ARM.
+ function releaseOrMint(
+ bytes memory,
+ address receiver,
+ uint256 amount,
+ uint64 remoteChainSelector,
+ bytes memory
+ ) external virtual override whenHealthy onlyOffRamp(remoteChainSelector) {
+ _consumeInboundRateLimit(remoteChainSelector, amount);
+ IBurnMintERC20(address(i_token)).mint(receiver, amount);
+ emit Minted(msg.sender, receiver, amount);
+ }
+}
+
+/// @notice This pool mints and burns a 3rd-party token.
+/// @dev Pool whitelisting mode is set in the constructor and cannot be modified later.
+/// It either accepts any address as originalSender, or only accepts whitelisted originalSender.
+/// The only way to change whitelisting mode is to deploy a new pool.
+/// If that is expected, please make sure the token's burner/minter roles are adjustable.
+contract BurnMintTokenPool1_4 is BurnMintTokenPoolAbstract, ITypeAndVersion {
+ string public constant override typeAndVersion = "BurnMintTokenPool 1.4.0";
+
+ constructor(
+ IBurnMintERC20 token,
+ address[] memory allowlist,
+ address armProxy,
+ address router
+ ) TokenPool1_4(token, allowlist, armProxy, router) {}
+
+ /// @inheritdoc BurnMintTokenPoolAbstract
+ function _burn(uint256 amount) internal virtual override {
+ IBurnMintERC20(address(i_token)).burn(amount);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/legacy/TokenPoolAndProxy.t.sol b/contracts/src/v0.8/ccip/test/legacy/TokenPoolAndProxy.t.sol
new file mode 100644
index 00000000000..292ac9a3bfd
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/legacy/TokenPoolAndProxy.t.sol
@@ -0,0 +1,771 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+import {IPoolPriorTo1_5} from "../../interfaces/IPoolPriorTo1_5.sol";
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {PriceRegistry} from "../../PriceRegistry.sol";
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {BurnMintTokenPoolAndProxy} from "../../pools/BurnMintTokenPoolAndProxy.sol";
+import {LockReleaseTokenPoolAndProxy} from "../../pools/LockReleaseTokenPoolAndProxy.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {TokenSetup} from "../TokenSetup.t.sol";
+import {EVM2EVMOnRampHelper} from "../helpers/EVM2EVMOnRampHelper.sol";
+import {EVM2EVMOnRampSetup} from "../onRamp/EVM2EVMOnRampSetup.t.sol";
+import {RouterSetup} from "../router/RouterSetup.t.sol";
+import {BurnMintTokenPool1_2, TokenPool1_2} from "./BurnMintTokenPool1_2.sol";
+import {BurnMintTokenPool1_4, TokenPool1_4} from "./BurnMintTokenPool1_4.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {IERC165} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+
+contract TokenPoolAndProxyMigration is EVM2EVMOnRampSetup {
+ BurnMintTokenPoolAndProxy internal s_newPool;
+ IPoolPriorTo1_5 internal s_legacyPool;
+ BurnMintERC677 internal s_token;
+
+ address internal s_offRamp;
+ address internal s_sourcePool = makeAddr("source_pool");
+ address internal s_sourceToken = makeAddr("source_token");
+ uint256 internal constant AMOUNT = 1;
+
+ function setUp() public virtual override {
+ super.setUp();
+ // Create a system with a token and a legacy pool
+ s_token = new BurnMintERC677("Test", "TEST", 18, type(uint256).max);
+ // dealing doesn't update the total supply, meaning the first time we burn a token we underflow, which isn't
+ // guarded against. Then, when we mint a token, we overflow, which is guarded against and will revert.
+ s_token.grantMintAndBurnRoles(OWNER);
+ s_token.mint(OWNER, 1e18);
+
+ s_offRamp = s_offRamps[0];
+ // Approve enough for a few calls
+ s_token.approve(address(s_sourceRouter), AMOUNT * 100);
+
+ // Approve infinite fee tokens
+ IERC20(s_sourceFeeToken).approve(address(s_sourceRouter), type(uint256).max);
+ }
+
+ /// @notice This test covers the entire migration plan for 1.0-1.2 pools to 1.5 pools. For simplicity
+ /// we will refer to the 1.0/1.2 pools as 1.2 pools, as they are functionally the same.
+ function test_tokenPoolMigration_Success_1_2() public {
+ // ================================================================
+ // | 1 1.2 prior to upgrade |
+ // ================================================================
+ _deployPool1_2();
+
+ // Ensure everything works on the 1.2 pool
+ _ccipSend_OLD();
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // ================================================================
+ // | 2 Deploy self serve |
+ // ================================================================
+ _deploySelfServe();
+
+ // This doesn't impact the 1.2 pool, so it should still be functional
+ _ccipSend_OLD();
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // ================================================================
+ // | 3 Configure new pool on old pool |
+ // ================================================================
+ // In the 1.2 case, everything keeps working on both the 1.2 and 1.5 pools. This config can be
+ // done in advance of the actual swap to 1.5 lanes.
+ vm.startPrank(OWNER);
+ TokenPool1_2.RampUpdate[] memory rampUpdates = new TokenPool1_2.RampUpdate[](1);
+ rampUpdates[0] = TokenPool1_2.RampUpdate({
+ ramp: address(s_newPool),
+ allowed: true,
+ // The rate limits should be turned off for this fake ramp, as the 1.5 pool will handle all the
+ // rate limiting for us.
+ rateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0})
+ });
+ // Since this call doesn't impact the usability of the old pool, we can do it whenever we want
+ BurnMintTokenPool1_2(address(s_legacyPool)).applyRampUpdates(rampUpdates, rampUpdates);
+
+ // Assert the 1.2 lanes still work
+ _ccipSend_OLD();
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // ================================================================
+ // | 4 Update the router with to 1.5 |
+ // ================================================================
+
+ // This will stop any new messages entering the old lanes, and will direct all traffic to the
+ // new 1.5 lanes, and therefore to the 1.5 pools. Note that the old pools will still receive
+ // inflight messages, and will need to continue functioning until all of those are processed.
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // Everything is configured, we can now send a ccip tx to the new pool
+ _ccipSend1_5();
+ _fakeReleaseOrMintFromOffRamp1_5();
+
+ // ================================================================
+ // | 5 Migrate to using 1.5 the pool |
+ // ================================================================
+ // Turn off the legacy pool, this enabled the 1.5 pool logic. This should be done AFTER the new pool
+ // has gotten permissions to mint/burn. We see the case where that isn't done below.
+ vm.startPrank(OWNER);
+ s_newPool.setPreviousPool(IPoolPriorTo1_5(address(0)));
+
+ // The new pool is now active, but is has not been given permissions to burn/mint yet
+ vm.expectRevert(abi.encodeWithSelector(BurnMintERC677.SenderNotBurner.selector, address(s_newPool)));
+ _ccipSend1_5();
+ vm.expectRevert(abi.encodeWithSelector(BurnMintERC677.SenderNotMinter.selector, address(s_newPool)));
+ _fakeReleaseOrMintFromOffRamp1_5();
+
+ // When we do give burn/mint, the new pool is fully active
+ vm.startPrank(OWNER);
+ s_token.grantMintAndBurnRoles(address(s_newPool));
+ _ccipSend1_5();
+ _fakeReleaseOrMintFromOffRamp1_5();
+
+ // Even after the pool has taken over as primary, the old pool can still process messages from the old lane
+ _fakeReleaseOrMintFromOffRamp_OLD();
+ }
+
+ function test_tokenPoolMigration_Success_1_4() public {
+ // ================================================================
+ // | 1 1.4 prior to upgrade |
+ // ================================================================
+ _deployPool1_4();
+
+ // Ensure everything works on the 1.4 pool
+ _ccipSend_OLD();
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // ================================================================
+ // | 2 Deploy self serve |
+ // ================================================================
+ _deploySelfServe();
+
+ // This doesn't impact the 1.4 pool, so it should still be functional
+ _ccipSend_OLD();
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // ================================================================
+ // | 3 Configure new pool on old pool |
+ // | AND |
+ // | Update the router with to 1.5 |
+ // ================================================================
+ // NOTE: when this call is made, the SENDING SIDE of old lanes stop working.
+ vm.startPrank(OWNER);
+ BurnMintTokenPool1_4(address(s_legacyPool)).setRouter(address(s_newPool));
+
+ // This will stop any new messages entering the old lanes, and will direct all traffic to the
+ // new 1.5 lanes, and therefore to the 1.5 pools. Note that the old pools will still receive
+ // inflight messages, and will need to continue functioning until all of those are processed.
+ _fakeReleaseOrMintFromOffRamp_OLD();
+
+ // Sending to the old 1.4 pool no longer works
+ _ccipSend_OLD_Reverts();
+
+ // Everything is configured, we can now send a ccip tx
+ _ccipSend1_5();
+ _fakeReleaseOrMintFromOffRamp1_5();
+
+ // ================================================================
+ // | 4 Migrate to using 1.5 the pool |
+ // ================================================================
+ // Turn off the legacy pool, this enabled the 1.5 pool logic. This should be done AFTER the new pool
+ // has gotten permissions to mint/burn. We see the case where that isn't done below.
+ vm.startPrank(OWNER);
+ s_newPool.setPreviousPool(IPoolPriorTo1_5(address(0)));
+
+ // The new pool is now active, but is has not been given permissions to burn/mint yet
+ vm.expectRevert(abi.encodeWithSelector(BurnMintERC677.SenderNotBurner.selector, address(s_newPool)));
+ _ccipSend1_5();
+ vm.expectRevert(abi.encodeWithSelector(BurnMintERC677.SenderNotMinter.selector, address(s_newPool)));
+ _fakeReleaseOrMintFromOffRamp1_5();
+
+ // When we do give burn/mint, the new pool is fully active
+ vm.startPrank(OWNER);
+ s_token.grantMintAndBurnRoles(address(s_newPool));
+ _ccipSend1_5();
+ _fakeReleaseOrMintFromOffRamp1_5();
+
+ // Even after the pool has taken over as primary, the old pool can still process messages from the old lane
+ _fakeReleaseOrMintFromOffRamp_OLD();
+ }
+
+ function _ccipSend_OLD() internal {
+ // We send the funds to the pool manually, as the ramp normally does that
+ deal(address(s_token), address(s_legacyPool), AMOUNT);
+ vm.startPrank(address(s_onRamp));
+ s_legacyPool.lockOrBurn(OWNER, abi.encode(OWNER), AMOUNT, DEST_CHAIN_SELECTOR, "");
+ }
+
+ function _ccipSend_OLD_Reverts() internal {
+ // We send the funds to the pool manually, as the ramp normally does that
+ deal(address(s_token), address(s_legacyPool), AMOUNT);
+ vm.startPrank(address(s_onRamp));
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool1_4.CallerIsNotARampOnRouter.selector, address(s_onRamp)));
+
+ s_legacyPool.lockOrBurn(OWNER, abi.encode(OWNER), AMOUNT, DEST_CHAIN_SELECTOR, "");
+ }
+
+ function _ccipSend1_5() internal {
+ vm.startPrank(address(OWNER));
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: address(s_token), amount: AMOUNT});
+
+ s_sourceRouter.ccipSend(
+ DEST_CHAIN_SELECTOR,
+ Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: s_sourceFeeToken,
+ extraArgs: ""
+ })
+ );
+ }
+
+ function _fakeReleaseOrMintFromOffRamp1_5() internal {
+ // This is a fake call to simulate the release or mint from the "offRamp"
+ vm.startPrank(s_offRamp);
+ s_newPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ receiver: OWNER,
+ amount: AMOUNT,
+ localToken: address(s_token),
+ sourcePoolAddress: abi.encode(s_sourcePool),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+ }
+
+ function _fakeReleaseOrMintFromOffRamp_OLD() internal {
+ // This is a fake call to simulate the release or mint from the "offRamp"
+ vm.startPrank(s_offRamp);
+ s_legacyPool.releaseOrMint(abi.encode(OWNER), OWNER, AMOUNT, SOURCE_CHAIN_SELECTOR, "");
+ }
+
+ function _deployPool1_2() internal {
+ vm.startPrank(OWNER);
+ s_legacyPool = new BurnMintTokenPool1_2(s_token, new address[](0), address(s_mockRMN));
+ s_token.grantMintAndBurnRoles(address(s_legacyPool));
+
+ TokenPool1_2.RampUpdate[] memory onRampUpdates = new TokenPool1_2.RampUpdate[](1);
+ onRampUpdates[0] = TokenPool1_2.RampUpdate({
+ ramp: address(s_onRamp),
+ allowed: true,
+ rateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ TokenPool1_2.RampUpdate[] memory offRampUpdates = new TokenPool1_2.RampUpdate[](1);
+ offRampUpdates[0] = TokenPool1_2.RampUpdate({
+ ramp: address(s_offRamp),
+ allowed: true,
+ rateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ BurnMintTokenPool1_2(address(s_legacyPool)).applyRampUpdates(onRampUpdates, offRampUpdates);
+ }
+
+ function _deployPool1_4() internal {
+ vm.startPrank(OWNER);
+ s_legacyPool = new BurnMintTokenPool1_4(s_token, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ s_token.grantMintAndBurnRoles(address(s_legacyPool));
+
+ TokenPool1_4.ChainUpdate[] memory legacyChainUpdates = new TokenPool1_4.ChainUpdate[](2);
+ legacyChainUpdates[0] = TokenPool1_4.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ legacyChainUpdates[1] = TokenPool1_4.ChainUpdate({
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ BurnMintTokenPool1_4(address(s_legacyPool)).applyChainUpdates(legacyChainUpdates);
+ }
+
+ function _deploySelfServe() internal {
+ vm.startPrank(OWNER);
+ // Deploy the new pool
+ s_newPool = new BurnMintTokenPoolAndProxy(s_token, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ // Set the previous pool on the new pool
+ s_newPool.setPreviousPool(s_legacyPool);
+
+ // Configure the lanes just like the legacy pool
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](2);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destTokenPool),
+ remoteTokenAddress: abi.encode(s_destToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ chainUpdates[1] = TokenPool.ChainUpdate({
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_sourcePool),
+ remoteTokenAddress: abi.encode(s_sourceToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_newPool.applyChainUpdates(chainUpdates);
+
+ // Register the token on the token admin registry
+ s_tokenAdminRegistry.proposeAdministrator(address(s_token), OWNER);
+ // Accept ownership of the token
+ s_tokenAdminRegistry.acceptAdminRole(address(s_token));
+ // Set the pool on the admin registry
+ s_tokenAdminRegistry.setPool(address(s_token), address(s_newPool));
+ }
+}
+
+contract TokenPoolAndProxy is EVM2EVMOnRampSetup {
+ event Burned(address indexed sender, uint256 amount);
+ event Minted(address indexed sender, address indexed recipient, uint256 amount);
+
+ IPoolV1 internal s_pool;
+ BurnMintERC677 internal s_token;
+ IPoolPriorTo1_5 internal s_legacyPool;
+ address internal s_fakeOffRamp = makeAddr("off_ramp");
+
+ address internal s_destPool = makeAddr("dest_pool");
+
+ function setUp() public virtual override {
+ super.setUp();
+ s_token = BurnMintERC677(s_sourceFeeToken);
+
+ Router.OffRamp[] memory fakeOffRamps = new Router.OffRamp[](1);
+ fakeOffRamps[0] = Router.OffRamp({sourceChainSelector: DEST_CHAIN_SELECTOR, offRamp: s_fakeOffRamp});
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), new Router.OffRamp[](0), fakeOffRamps);
+
+ s_token.grantMintAndBurnRoles(OWNER);
+ s_token.mint(OWNER, 1e18);
+ }
+
+ function test_lockOrBurn_burnMint_Success() public {
+ s_pool = new BurnMintTokenPoolAndProxy(s_token, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ _configurePool();
+ _deployOldPool();
+ _assertLockOrBurnCorrect();
+
+ vm.startPrank(OWNER);
+ BurnMintTokenPoolAndProxy(address(s_pool)).setPreviousPool(IPoolPriorTo1_5(address(0)));
+
+ _assertReleaseOrMintCorrect();
+ }
+
+ function test_lockOrBurn_lockRelease_Success() public {
+ s_pool =
+ new LockReleaseTokenPoolAndProxy(s_token, new address[](0), address(s_mockRMN), false, address(s_sourceRouter));
+ _configurePool();
+ _deployOldPool();
+ _assertLockOrBurnCorrect();
+
+ vm.startPrank(OWNER);
+ BurnMintTokenPoolAndProxy(address(s_pool)).setPreviousPool(IPoolPriorTo1_5(address(0)));
+
+ _assertReleaseOrMintCorrect();
+ }
+
+ function _deployOldPool() internal {
+ s_legacyPool = new BurnMintTokenPool1_2(s_token, new address[](0), address(s_mockRMN));
+ s_token.grantMintAndBurnRoles(address(s_legacyPool));
+
+ TokenPool1_2.RampUpdate[] memory onRampUpdates = new TokenPool1_2.RampUpdate[](1);
+ onRampUpdates[0] =
+ TokenPool1_2.RampUpdate({ramp: address(s_pool), allowed: true, rateLimiterConfig: getInboundRateLimiterConfig()});
+ TokenPool1_2.RampUpdate[] memory offRampUpdates = new TokenPool1_2.RampUpdate[](1);
+ offRampUpdates[0] =
+ TokenPool1_2.RampUpdate({ramp: address(s_pool), allowed: true, rateLimiterConfig: getInboundRateLimiterConfig()});
+ BurnMintTokenPool1_2(address(s_legacyPool)).applyRampUpdates(onRampUpdates, offRampUpdates);
+ }
+
+ function _configurePool() internal {
+ TokenPool.ChainUpdate[] memory chains = new TokenPool.ChainUpdate[](1);
+ chains[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destPool),
+ remoteTokenAddress: abi.encode(s_destToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ BurnMintTokenPoolAndProxy(address(s_pool)).applyChainUpdates(chains);
+
+ // CCIP Token Admin has already been registered from TokenSetup
+ s_tokenAdminRegistry.setPool(address(s_token), address(s_pool));
+
+ s_token.grantMintAndBurnRoles(address(s_pool));
+ }
+
+ function _assertLockOrBurnCorrect() internal {
+ uint256 amount = 1234;
+ vm.startPrank(address(s_onRamp));
+
+ // lockOrBurn, assert normal path is taken
+ deal(address(s_token), address(s_pool), amount);
+
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ receiver: abi.encode(OWNER),
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ originalSender: OWNER,
+ amount: amount,
+ localToken: address(s_token)
+ })
+ );
+
+ // set legacy pool
+
+ vm.startPrank(OWNER);
+ BurnMintTokenPoolAndProxy(address(s_pool)).setPreviousPool(s_legacyPool);
+
+ // lockOrBurn, assert legacy pool is called
+
+ vm.startPrank(address(s_onRamp));
+ deal(address(s_token), address(s_pool), amount);
+
+ vm.expectEmit(address(s_legacyPool));
+ emit Burned(address(s_pool), amount);
+
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ receiver: abi.encode(OWNER),
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ originalSender: OWNER,
+ amount: amount,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function _assertReleaseOrMintCorrect() internal {
+ uint256 amount = 1234;
+ vm.startPrank(s_fakeOffRamp);
+
+ // releaseOrMint, assert normal path is taken
+ deal(address(s_token), address(s_pool), amount);
+
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ receiver: OWNER,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ originalSender: abi.encode(OWNER),
+ amount: amount,
+ localToken: address(s_token),
+ sourcePoolAddress: abi.encode(s_destPool),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+
+ // set legacy pool
+
+ vm.startPrank(OWNER);
+ BurnMintTokenPoolAndProxy(address(s_pool)).setPreviousPool(s_legacyPool);
+
+ // releaseOrMint, assert legacy pool is called
+
+ vm.startPrank(address(s_fakeOffRamp));
+
+ vm.expectEmit(address(s_legacyPool));
+ emit Minted(address(s_pool), s_fakeOffRamp, amount);
+
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ receiver: OWNER,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ originalSender: abi.encode(OWNER),
+ amount: amount,
+ localToken: address(s_token),
+ sourcePoolAddress: abi.encode(s_destPool),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+ }
+}
+
+////
+/// Duplicated tests from LockReleaseTokenPool.t.sol
+///
+
+contract LockReleaseTokenPoolAndProxySetup is RouterSetup {
+ IERC20 internal s_token;
+ LockReleaseTokenPoolAndProxy internal s_lockReleaseTokenPoolAndProxy;
+ LockReleaseTokenPoolAndProxy internal s_lockReleaseTokenPoolAndProxyWithAllowList;
+ address[] internal s_allowedList;
+
+ address internal s_allowedOnRamp = address(123);
+ address internal s_allowedOffRamp = address(234);
+
+ address internal s_destPoolAddress = address(2736782345);
+ address internal s_sourcePoolAddress = address(53852352095);
+
+ function setUp() public virtual override {
+ RouterSetup.setUp();
+ s_token = new BurnMintERC677("LINK", "LNK", 18, 0);
+ deal(address(s_token), OWNER, type(uint256).max);
+ s_lockReleaseTokenPoolAndProxy =
+ new LockReleaseTokenPoolAndProxy(s_token, new address[](0), address(s_mockRMN), true, address(s_sourceRouter));
+
+ s_allowedList.push(USER_1);
+ s_allowedList.push(DUMMY_CONTRACT_ADDRESS);
+ s_lockReleaseTokenPoolAndProxyWithAllowList =
+ new LockReleaseTokenPoolAndProxy(s_token, s_allowedList, address(s_mockRMN), true, address(s_sourceRouter));
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destPoolAddress),
+ remoteTokenAddress: abi.encode(address(s_token)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ s_lockReleaseTokenPoolAndProxy.applyChainUpdates(chainUpdate);
+ s_lockReleaseTokenPoolAndProxyWithAllowList.applyChainUpdates(chainUpdate);
+ s_lockReleaseTokenPoolAndProxy.setRebalancer(OWNER);
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: s_allowedOnRamp});
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: s_allowedOffRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ }
+}
+
+contract LockReleaseTokenPoolAndProxy_setRebalancer is LockReleaseTokenPoolAndProxySetup {
+ function test_SetRebalancer_Success() public {
+ assertEq(address(s_lockReleaseTokenPoolAndProxy.getRebalancer()), OWNER);
+ s_lockReleaseTokenPoolAndProxy.setRebalancer(STRANGER);
+ assertEq(address(s_lockReleaseTokenPoolAndProxy.getRebalancer()), STRANGER);
+ }
+
+ function test_SetRebalancer_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+ s_lockReleaseTokenPoolAndProxy.setRebalancer(STRANGER);
+ }
+}
+
+contract LockReleaseTokenPoolPoolAndProxy_canAcceptLiquidity is LockReleaseTokenPoolAndProxySetup {
+ function test_CanAcceptLiquidity_Success() public {
+ assertEq(true, s_lockReleaseTokenPoolAndProxy.canAcceptLiquidity());
+
+ s_lockReleaseTokenPoolAndProxy =
+ new LockReleaseTokenPoolAndProxy(s_token, new address[](0), address(s_mockRMN), false, address(s_sourceRouter));
+ assertEq(false, s_lockReleaseTokenPoolAndProxy.canAcceptLiquidity());
+ }
+}
+
+contract LockReleaseTokenPoolPoolAndProxy_provideLiquidity is LockReleaseTokenPoolAndProxySetup {
+ function test_Fuzz_ProvideLiquidity_Success(uint256 amount) public {
+ uint256 balancePre = s_token.balanceOf(OWNER);
+ s_token.approve(address(s_lockReleaseTokenPoolAndProxy), amount);
+
+ s_lockReleaseTokenPoolAndProxy.provideLiquidity(amount);
+
+ assertEq(s_token.balanceOf(OWNER), balancePre - amount);
+ assertEq(s_token.balanceOf(address(s_lockReleaseTokenPoolAndProxy)), amount);
+ }
+
+ // Reverts
+
+ function test_Unauthorized_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(LockReleaseTokenPoolAndProxy.Unauthorized.selector, STRANGER));
+
+ s_lockReleaseTokenPoolAndProxy.provideLiquidity(1);
+ }
+
+ function test_Fuzz_ExceedsAllowance(uint256 amount) public {
+ vm.assume(amount > 0);
+ vm.expectRevert("ERC20: insufficient allowance");
+ s_lockReleaseTokenPoolAndProxy.provideLiquidity(amount);
+ }
+
+ function test_LiquidityNotAccepted_Revert() public {
+ s_lockReleaseTokenPoolAndProxy =
+ new LockReleaseTokenPoolAndProxy(s_token, new address[](0), address(s_mockRMN), false, address(s_sourceRouter));
+
+ vm.expectRevert(LockReleaseTokenPoolAndProxy.LiquidityNotAccepted.selector);
+ s_lockReleaseTokenPoolAndProxy.provideLiquidity(1);
+ }
+}
+
+contract LockReleaseTokenPoolPoolAndProxy_withdrawalLiquidity is LockReleaseTokenPoolAndProxySetup {
+ function test_Fuzz_WithdrawalLiquidity_Success(uint256 amount) public {
+ uint256 balancePre = s_token.balanceOf(OWNER);
+ s_token.approve(address(s_lockReleaseTokenPoolAndProxy), amount);
+ s_lockReleaseTokenPoolAndProxy.provideLiquidity(amount);
+
+ s_lockReleaseTokenPoolAndProxy.withdrawLiquidity(amount);
+
+ assertEq(s_token.balanceOf(OWNER), balancePre);
+ }
+
+ // Reverts
+
+ function test_Unauthorized_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(LockReleaseTokenPoolAndProxy.Unauthorized.selector, STRANGER));
+
+ s_lockReleaseTokenPoolAndProxy.withdrawLiquidity(1);
+ }
+
+ function test_InsufficientLiquidity_Revert() public {
+ uint256 maxUint256 = 2 ** 256 - 1;
+ s_token.approve(address(s_lockReleaseTokenPoolAndProxy), maxUint256);
+ s_lockReleaseTokenPoolAndProxy.provideLiquidity(maxUint256);
+
+ vm.startPrank(address(s_lockReleaseTokenPoolAndProxy));
+ s_token.transfer(OWNER, maxUint256);
+ vm.startPrank(OWNER);
+
+ vm.expectRevert(LockReleaseTokenPoolAndProxy.InsufficientLiquidity.selector);
+ s_lockReleaseTokenPoolAndProxy.withdrawLiquidity(1);
+ }
+}
+
+contract LockReleaseTokenPoolPoolAndProxy_supportsInterface is LockReleaseTokenPoolAndProxySetup {
+ function test_SupportsInterface_Success() public view {
+ assertTrue(s_lockReleaseTokenPoolAndProxy.supportsInterface(type(IPoolV1).interfaceId));
+ assertTrue(s_lockReleaseTokenPoolAndProxy.supportsInterface(type(IERC165).interfaceId));
+ }
+}
+
+contract LockReleaseTokenPoolPoolAndProxy_setChainRateLimiterConfig is LockReleaseTokenPoolAndProxySetup {
+ event ConfigChanged(RateLimiter.Config);
+ event ChainConfigured(
+ uint64 chainSelector, RateLimiter.Config outboundRateLimiterConfig, RateLimiter.Config inboundRateLimiterConfig
+ );
+
+ uint64 internal s_remoteChainSelector;
+
+ function setUp() public virtual override {
+ LockReleaseTokenPoolAndProxySetup.setUp();
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ s_remoteChainSelector = 123124;
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: s_remoteChainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_lockReleaseTokenPoolAndProxy.applyChainUpdates(chainUpdates);
+ }
+
+ function test_Fuzz_SetChainRateLimiterConfig_Success(uint128 capacity, uint128 rate, uint32 newTime) public {
+ // Cap the lower bound to 4 so 4/2 is still >= 2
+ vm.assume(capacity >= 4);
+ // Cap the lower bound to 2 so 2/2 is still >= 1
+ rate = uint128(bound(rate, 2, capacity - 2));
+ // Bucket updates only work on increasing time
+ newTime = uint32(bound(newTime, block.timestamp + 1, type(uint32).max));
+ vm.warp(newTime);
+
+ uint256 oldOutboundTokens =
+ s_lockReleaseTokenPoolAndProxy.getCurrentOutboundRateLimiterState(s_remoteChainSelector).tokens;
+ uint256 oldInboundTokens =
+ s_lockReleaseTokenPoolAndProxy.getCurrentInboundRateLimiterState(s_remoteChainSelector).tokens;
+
+ RateLimiter.Config memory newOutboundConfig = RateLimiter.Config({isEnabled: true, capacity: capacity, rate: rate});
+ RateLimiter.Config memory newInboundConfig =
+ RateLimiter.Config({isEnabled: true, capacity: capacity / 2, rate: rate / 2});
+
+ vm.expectEmit();
+ emit ConfigChanged(newOutboundConfig);
+ vm.expectEmit();
+ emit ConfigChanged(newInboundConfig);
+ vm.expectEmit();
+ emit ChainConfigured(s_remoteChainSelector, newOutboundConfig, newInboundConfig);
+
+ s_lockReleaseTokenPoolAndProxy.setChainRateLimiterConfig(s_remoteChainSelector, newOutboundConfig, newInboundConfig);
+
+ uint256 expectedTokens = RateLimiter._min(newOutboundConfig.capacity, oldOutboundTokens);
+
+ RateLimiter.TokenBucket memory bucket =
+ s_lockReleaseTokenPoolAndProxy.getCurrentOutboundRateLimiterState(s_remoteChainSelector);
+ assertEq(bucket.capacity, newOutboundConfig.capacity);
+ assertEq(bucket.rate, newOutboundConfig.rate);
+ assertEq(bucket.tokens, expectedTokens);
+ assertEq(bucket.lastUpdated, newTime);
+
+ expectedTokens = RateLimiter._min(newInboundConfig.capacity, oldInboundTokens);
+
+ bucket = s_lockReleaseTokenPoolAndProxy.getCurrentInboundRateLimiterState(s_remoteChainSelector);
+ assertEq(bucket.capacity, newInboundConfig.capacity);
+ assertEq(bucket.rate, newInboundConfig.rate);
+ assertEq(bucket.tokens, expectedTokens);
+ assertEq(bucket.lastUpdated, newTime);
+ }
+
+ function test_OnlyOwnerOrRateLimitAdmin_Revert() public {
+ address rateLimiterAdmin = address(28973509103597907);
+
+ s_lockReleaseTokenPoolAndProxy.setRateLimitAdmin(rateLimiterAdmin);
+
+ vm.startPrank(rateLimiterAdmin);
+
+ s_lockReleaseTokenPoolAndProxy.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+
+ vm.startPrank(OWNER);
+
+ s_lockReleaseTokenPoolAndProxy.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(abi.encodeWithSelector(LockReleaseTokenPoolAndProxy.Unauthorized.selector, STRANGER));
+ s_lockReleaseTokenPoolAndProxy.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+
+ function test_NonExistentChain_Revert() public {
+ uint64 wrongChainSelector = 9084102894;
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.NonExistentChain.selector, wrongChainSelector));
+ s_lockReleaseTokenPoolAndProxy.setChainRateLimiterConfig(
+ wrongChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+}
+
+contract LockReleaseTokenPoolAndProxy_setRateLimitAdmin is LockReleaseTokenPoolAndProxySetup {
+ function test_SetRateLimitAdmin_Success() public {
+ assertEq(address(0), s_lockReleaseTokenPoolAndProxy.getRateLimitAdmin());
+ s_lockReleaseTokenPoolAndProxy.setRateLimitAdmin(OWNER);
+ assertEq(OWNER, s_lockReleaseTokenPoolAndProxy.getRateLimitAdmin());
+ }
+
+ // Reverts
+
+ function test_SetRateLimitAdmin_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+ s_lockReleaseTokenPoolAndProxy.setRateLimitAdmin(STRANGER);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/libraries/MerkleMultiProof.t.sol b/contracts/src/v0.8/ccip/test/libraries/MerkleMultiProof.t.sol
new file mode 100644
index 00000000000..e2fc9814d07
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/libraries/MerkleMultiProof.t.sol
@@ -0,0 +1,196 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {MerkleMultiProof} from "../../libraries/MerkleMultiProof.sol";
+import {MerkleHelper} from "../helpers/MerkleHelper.sol";
+import {Test} from "forge-std/Test.sol";
+
+contract MerkleMultiProofTest is Test {
+ // This must match the spec
+ function test_SpecSync_gas() public pure {
+ bytes32 expectedRoot = 0xd4f0f3c40a4d583d98c17d89e550b1143fe4d3d759f25ccc63131c90b183928e;
+
+ bytes32[] memory leaves = new bytes32[](10);
+ leaves[0] = 0xa20c0244af79697a4ef4e2378c9d5d14cbd49ddab3427b12594c7cfa67a7f240;
+ leaves[1] = 0x3de96afb24ce2ac45a5595aa13d1a5163ae0b3c94cef6b2dc306b5966f32dfa5;
+ leaves[2] = 0xacadf7b4d13cd57c5d25f1d27be39b656347fe8f8e0de8db9c76d979dff57736;
+ leaves[3] = 0xc21c26a709802fe1ae52a9cd8ad94d15bf142ded26314339cd87a13e5b468165;
+ leaves[4] = 0x55f6df03562738c9a6437cd9ad221c52b76906a175ae96188cff60e0a2a59933;
+ leaves[5] = 0x2dbbe66452e43fec839dc65d5945aad6433d410c65863eaf1d876e1e0b06343c;
+ leaves[6] = 0x8beab00297b94bf079fcd5893b0a33ebf6b0ce862cd06be07c87d3c63e1c4acf;
+ leaves[7] = 0xcabdd3ad25daeb1e0541042f2ea4cd177f54e67aa4a2c697acd4bb682e94de59;
+ leaves[8] = 0x7e01d497203685e99e34df33d55465c66b2253fa1630ee2fe5c4997968e4a6fa;
+ leaves[9] = 0x1a03d013f1e2fa9cc04f89c7528ac3216e3e096a1185d7247304e97c59f9661f;
+
+ bytes32[] memory proofs = new bytes32[](33);
+ proofs[0] = 0xde96f24fcf9ddd20c803dc9c5fba7c478a5598a08a0faa5f032c65823b8e26a3;
+ proofs[1] = 0xe1303cffc3958a6b93e2dc04caf21f200ff5aa5be090c5013f37804b91488bc2;
+ proofs[2] = 0x90d80c76bccb44a91f4e16604976163aaa39e9a1588b0b24b33a61f1d4ba7bb5;
+ proofs[3] = 0x012a299b25539d513c8677ecf37968774e9e4b045e79737f48defd350224cdfd;
+ proofs[4] = 0x420a36c5a73f87d8fb98e70c48d0d6f9dd83f50b7b91416a6f5f91fac4db800f;
+ proofs[5] = 0x5857d8d1b56abcd7f863cedd3c3f8677256f54d675be61f05efa45d6495fc30a;
+ proofs[6] = 0xbf176d20166fdeb72593ff97efec1ce6244af41ca46cf0bc902d19d50c446f7b;
+ proofs[7] = 0xa9221608e4380250a1815fb308632bce99f611a673d2e17fc617123fdc6afcd2;
+ proofs[8] = 0xbd14f3366c73186314f182027217d0f70eba55817561de9e9a1f2c78bf5cbead;
+ proofs[9] = 0x2f9aa48c0c9f82aaac65d7a9374a52d9dc138ed100a5809ede57e70697f48b56;
+ proofs[10] = 0x2ae60afa54271cb421c12e4441c2dac0a25f25c9433a6d07cb32419e993fe344;
+ proofs[11] = 0xc765c091680f0434b74c44507b932e5c80f6e995a975a275e5b130af1de1064c;
+ proofs[12] = 0x59d2d6e0c4a5d07b169dbcdfa39dad7aea7b7783a814399f4f44c4a36b6336d3;
+ proofs[13] = 0xdd14d1387d10740187d71ad9500475399559c0922dbe2576882e61f1edd84692;
+ proofs[14] = 0x5412b8395509935406811ab3da43ab80be7acd8ffb5f398ab70f056ff3740f46;
+ proofs[15] = 0xeadab258ae7d779ce5f10fbb1bb0273116b8eccbf738ed878db570de78bed1e4;
+ proofs[16] = 0x6133aa40e6db75373b7cfc79e6f8b8ce80e441e6c1f98b85a593464dda3cf9c0;
+ proofs[17] = 0x5418948467112660639b932af9b1b212e40d71b24326b4606679d168a765af4f;
+ proofs[18] = 0x44f618505355c7e4e7c0f81d6bb15d2ec9cf9b366f9e1dc37db52745486e6b0f;
+ proofs[19] = 0xa410ee174a66a4d64f3c000b93efe15b5b1f3e39e962af2580fcd30bce07d039;
+ proofs[20] = 0x09c3eb05ac9552022a45c00d01a47cd56f95f94afdd4402299dba1291a17f976;
+ proofs[21] = 0x0e780f6acd081b07320a55208fa3e1d884e2e95cb13d1c98c74b7e853372c813;
+ proofs[22] = 0x2b60e8c21f78ef22fa4297f28f1d8c747181edfc465121b39c16be97d4fb8a04;
+ proofs[23] = 0xf24da95060a8598c06e9dfb3926e1a8c8bd8ec2c65be10e69323442840724888;
+ proofs[24] = 0x7e220fc095bcd2b0f5ef134d9620d89f6d7a1e8719ce8893bb9aff15e847578f;
+ proofs[25] = 0xcfe9e475c4bd32f1e36b2cc65a959c403c59979ff914fb629a64385b0c680a71;
+ proofs[26] = 0x25237fb8d1bfdc01ca5363ec3166a2b40789e38d5adcc8627801da683d2e1d76;
+ proofs[27] = 0x42647949fed0250139c01212d739d8c83d2852589ebc892d3490ae52e411432c;
+ proofs[28] = 0x34397a30930e6dd4fb5af48084afc5cfbe02c18dd9544b3faff4e2e90bf00cb9;
+ proofs[29] = 0xa028f33226adc3d1cb72b19eb6808dab9190b25066a45cacb5dfe5d640e57cf2;
+ proofs[30] = 0x7cff66ba47a05f932d06d168c294266dcb0d3943a4f2a4a75c860b9fd6e53092;
+ proofs[31] = 0x5ca1b32f1dbfadd83205882be5eb76f34c49e834726f5239905a0e70d0a5e0eb;
+ proofs[32] = 0x1b4b087a89e4eca6cdd237210932559dc8fd167d5f4f2d9acb13264e1e305479;
+
+ uint256 flagsUint256 = 0x2f3c0000000;
+
+ bytes32 root = MerkleMultiProof.merkleRoot(leaves, proofs, flagsUint256);
+
+ assertEq(expectedRoot, root);
+ }
+
+ function test_Fuzz_MerkleRoot2(bytes32 left, bytes32 right) public pure {
+ bytes32[] memory leaves = new bytes32[](2);
+ leaves[0] = left;
+ leaves[1] = right;
+ bytes32[] memory proofs = new bytes32[](0);
+
+ bytes32 expectedRoot = MerkleHelper.hashPair(left, right);
+
+ bytes32 root = MerkleMultiProof.merkleRoot(leaves, proofs, 2 ** 2 - 1);
+
+ assertEq(root, expectedRoot);
+ }
+
+ function test_MerkleRoot256() public pure {
+ bytes32[] memory leaves = new bytes32[](256);
+ for (uint256 i = 0; i < leaves.length; ++i) {
+ leaves[i] = keccak256("a");
+ }
+ bytes32[] memory proofs = new bytes32[](0);
+
+ bytes32 expectedRoot = MerkleHelper.getMerkleRoot(leaves);
+
+ bytes32 root = MerkleMultiProof.merkleRoot(leaves, proofs, 2 ** 256 - 1);
+
+ assertEq(root, expectedRoot);
+ }
+
+ function test_Fuzz_MerkleMulti1of4(bytes32 leaf1, bytes32 proof1, bytes32 proof2) public pure {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = leaf1;
+ bytes32[] memory proofs = new bytes32[](2);
+ proofs[0] = proof1;
+ proofs[1] = proof2;
+
+ // Proof flag = false
+ bytes32 result = MerkleHelper.hashPair(leaves[0], proofs[0]);
+ // Proof flag = false
+ result = MerkleHelper.hashPair(result, proofs[1]);
+
+ assertEq(MerkleMultiProof.merkleRoot(leaves, proofs, 0), result);
+ }
+
+ function test_Fuzz_MerkleMulti2of4(bytes32 leaf1, bytes32 leaf2, bytes32 proof1, bytes32 proof2) public pure {
+ bytes32[] memory leaves = new bytes32[](2);
+ leaves[0] = leaf1;
+ leaves[1] = leaf2;
+ bytes32[] memory proofs = new bytes32[](2);
+ proofs[0] = proof1;
+ proofs[1] = proof2;
+
+ // Proof flag = false
+ bytes32 result1 = MerkleHelper.hashPair(leaves[0], proofs[0]);
+ // Proof flag = false
+ bytes32 result2 = MerkleHelper.hashPair(leaves[1], proofs[1]);
+ // Proof flag = true
+ bytes32 finalResult = MerkleHelper.hashPair(result1, result2);
+
+ assertEq(MerkleMultiProof.merkleRoot(leaves, proofs, 4), finalResult);
+ }
+
+ function test_Fuzz_MerkleMulti3of4(bytes32 leaf1, bytes32 leaf2, bytes32 leaf3, bytes32 proof) public pure {
+ bytes32[] memory leaves = new bytes32[](3);
+ leaves[0] = leaf1;
+ leaves[1] = leaf2;
+ leaves[2] = leaf3;
+ bytes32[] memory proofs = new bytes32[](1);
+ proofs[0] = proof;
+
+ // Proof flag = true
+ bytes32 result1 = MerkleHelper.hashPair(leaves[0], leaves[1]);
+ // Proof flag = false
+ bytes32 result2 = MerkleHelper.hashPair(leaves[2], proofs[0]);
+ // Proof flag = true
+ bytes32 finalResult = MerkleHelper.hashPair(result1, result2);
+
+ assertEq(MerkleMultiProof.merkleRoot(leaves, proofs, 5), finalResult);
+ }
+
+ function test_Fuzz_MerkleMulti4of4(bytes32 leaf1, bytes32 leaf2, bytes32 leaf3, bytes32 leaf4) public pure {
+ bytes32[] memory leaves = new bytes32[](4);
+ leaves[0] = leaf1;
+ leaves[1] = leaf2;
+ leaves[2] = leaf3;
+ leaves[3] = leaf4;
+ bytes32[] memory proofs = new bytes32[](0);
+
+ // Proof flag = true
+ bytes32 result1 = MerkleHelper.hashPair(leaves[0], leaves[1]);
+ // Proof flag = true
+ bytes32 result2 = MerkleHelper.hashPair(leaves[2], leaves[3]);
+ // Proof flag = true
+ bytes32 finalResult = MerkleHelper.hashPair(result1, result2);
+
+ assertEq(MerkleMultiProof.merkleRoot(leaves, proofs, 7), finalResult);
+ }
+
+ function test_MerkleRootSingleLeaf_Success() public pure {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = "root";
+ bytes32[] memory proofs = new bytes32[](0);
+ assertEq(MerkleMultiProof.merkleRoot(leaves, proofs, 0), leaves[0]);
+ }
+
+ function test_EmptyLeaf_Revert() public {
+ bytes32[] memory leaves = new bytes32[](0);
+ bytes32[] memory proofs = new bytes32[](0);
+
+ vm.expectRevert(abi.encodeWithSelector(MerkleMultiProof.LeavesCannotBeEmpty.selector));
+ MerkleMultiProof.merkleRoot(leaves, proofs, 0);
+ }
+
+ function test_CVE_2023_34459() public {
+ bytes32[] memory leaves = new bytes32[](2);
+ // leaves[0] stays uninitialized, i.e., 0x000...0
+ leaves[1] = "leaf";
+
+ bytes32[] memory proof = new bytes32[](2);
+ proof[0] = leaves[1];
+ proof[1] = "will never be used";
+
+ bytes32[] memory malicious = new bytes32[](2);
+ malicious[0] = "malicious leaf";
+ malicious[1] = "another malicious leaf";
+
+ vm.expectRevert(abi.encodeWithSelector(MerkleMultiProof.InvalidProof.selector));
+ MerkleMultiProof.merkleRoot(malicious, proof, 3);
+ // Note, that without the revert the above computed root
+ // would equal MerkleHelper.hashPair(leaves[0], leaves[1]).
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/libraries/RateLimiter.t.sol b/contracts/src/v0.8/ccip/test/libraries/RateLimiter.t.sol
new file mode 100644
index 00000000000..da6a6f9ada7
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/libraries/RateLimiter.t.sol
@@ -0,0 +1,297 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {RateLimiterHelper} from "../helpers/RateLimiterHelper.sol";
+import {Test} from "forge-std/Test.sol";
+
+contract RateLimiterSetup is Test {
+ RateLimiterHelper internal s_helper;
+ RateLimiter.Config internal s_config;
+
+ uint256 internal constant BLOCK_TIME = 1234567890;
+
+ function setUp() public virtual {
+ s_config = RateLimiter.Config({isEnabled: true, rate: 5, capacity: 100});
+ s_helper = new RateLimiterHelper(s_config);
+ }
+}
+
+contract RateLimiter_constructor is RateLimiterSetup {
+ function test_Constructor_Success() public view {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(s_config.capacity, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ assertEq(BLOCK_TIME, rateLimiter.lastUpdated);
+ }
+}
+
+contract RateLimiter_setTokenBucketConfig is RateLimiterSetup {
+ function test_SetRateLimiterConfig_Success() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+
+ s_config =
+ RateLimiter.Config({isEnabled: true, rate: uint128(rateLimiter.rate * 2), capacity: rateLimiter.capacity * 8});
+
+ vm.expectEmit();
+ emit RateLimiter.ConfigChanged(s_config);
+
+ s_helper.setTokenBucketConfig(s_config);
+
+ rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(s_config.capacity / 8, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ assertEq(BLOCK_TIME, rateLimiter.lastUpdated);
+ }
+}
+
+contract RateLimiter_currentTokenBucketState is RateLimiterSetup {
+ function test_CurrentTokenBucketState_Success() public {
+ RateLimiter.TokenBucket memory bucket = s_helper.currentTokenBucketState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity, bucket.tokens);
+ assertEq(s_config.isEnabled, bucket.isEnabled);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+
+ s_config = RateLimiter.Config({isEnabled: true, rate: uint128(bucket.rate * 2), capacity: bucket.capacity * 8});
+
+ s_helper.setTokenBucketConfig(s_config);
+
+ bucket = s_helper.currentTokenBucketState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity / 8, bucket.tokens);
+ assertEq(s_config.isEnabled, bucket.isEnabled);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+ }
+
+ function test_Refill_Success() public {
+ RateLimiter.TokenBucket memory bucket = s_helper.currentTokenBucketState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity, bucket.tokens);
+ assertEq(s_config.isEnabled, bucket.isEnabled);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+
+ s_config = RateLimiter.Config({isEnabled: true, rate: uint128(bucket.rate * 2), capacity: bucket.capacity * 8});
+
+ s_helper.setTokenBucketConfig(s_config);
+
+ bucket = s_helper.currentTokenBucketState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity / 8, bucket.tokens);
+ assertEq(s_config.isEnabled, bucket.isEnabled);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+
+ uint256 warpTime = 4;
+ vm.warp(BLOCK_TIME + warpTime);
+
+ bucket = s_helper.currentTokenBucketState();
+
+ assertEq(s_config.capacity / 8 + warpTime * s_config.rate, bucket.tokens);
+
+ vm.warp(BLOCK_TIME + warpTime * 100);
+
+ // Bucket overflow
+ bucket = s_helper.currentTokenBucketState();
+ assertEq(s_config.capacity, bucket.tokens);
+ }
+}
+
+contract RateLimiter_consume is RateLimiterSetup {
+ address internal s_token = address(100);
+
+ function test_ConsumeAggregateValue_Success() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(s_config.capacity, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ assertEq(BLOCK_TIME, rateLimiter.lastUpdated);
+
+ uint256 requestTokens = 50;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(requestTokens);
+
+ s_helper.consume(requestTokens, address(0));
+
+ rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(s_config.capacity - requestTokens, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ assertEq(BLOCK_TIME, rateLimiter.lastUpdated);
+ }
+
+ function test_ConsumeTokens_Success() public {
+ uint256 requestTokens = 50;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(requestTokens);
+
+ s_helper.consume(requestTokens, s_token);
+ }
+
+ function test_Refill_Success() public {
+ uint256 requestTokens = 50;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(requestTokens);
+
+ s_helper.consume(requestTokens, address(0));
+
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(s_config.capacity - requestTokens, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ assertEq(BLOCK_TIME, rateLimiter.lastUpdated);
+
+ uint256 warpTime = 4;
+ vm.warp(BLOCK_TIME + warpTime);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(requestTokens);
+
+ s_helper.consume(requestTokens, address(0));
+
+ rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(s_config.capacity - requestTokens * 2 + warpTime * s_config.rate, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ assertEq(BLOCK_TIME + warpTime, rateLimiter.lastUpdated);
+ }
+
+ function test_ConsumeUnlimited_Success() public {
+ s_helper.consume(0, address(0));
+
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.capacity, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+
+ RateLimiter.Config memory disableConfig = RateLimiter.Config({isEnabled: false, rate: 0, capacity: 0});
+
+ s_helper.setTokenBucketConfig(disableConfig);
+
+ uint256 requestTokens = 50;
+ s_helper.consume(requestTokens, address(0));
+
+ rateLimiter = s_helper.getRateLimiter();
+ assertEq(disableConfig.capacity, rateLimiter.tokens);
+ assertEq(disableConfig.isEnabled, rateLimiter.isEnabled);
+
+ s_helper.setTokenBucketConfig(s_config);
+
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, 10, 0));
+ s_helper.consume(requestTokens, address(0));
+
+ rateLimiter = s_helper.getRateLimiter();
+ assertEq(s_config.rate, rateLimiter.rate);
+ assertEq(s_config.capacity, rateLimiter.capacity);
+ assertEq(0, rateLimiter.tokens);
+ assertEq(s_config.isEnabled, rateLimiter.isEnabled);
+ }
+
+ // Reverts
+
+ function test_AggregateValueMaxCapacityExceeded_Revert() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.AggregateValueMaxCapacityExceeded.selector, rateLimiter.capacity, rateLimiter.capacity + 1
+ )
+ );
+ s_helper.consume(rateLimiter.capacity + 1, address(0));
+ }
+
+ function test_TokenMaxCapacityExceeded_Revert() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.TokenMaxCapacityExceeded.selector, rateLimiter.capacity, rateLimiter.capacity + 1, s_token
+ )
+ );
+ s_helper.consume(rateLimiter.capacity + 1, s_token);
+ }
+
+ function test_ConsumingMoreThanUint128_Revert() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+
+ uint256 request = uint256(type(uint128).max) + 1;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.AggregateValueMaxCapacityExceeded.selector, rateLimiter.capacity, request)
+ );
+ s_helper.consume(request, address(0));
+ }
+
+ function test_AggregateValueRateLimitReached_Revert() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+
+ uint256 overLimit = 20;
+ uint256 requestTokens1 = rateLimiter.capacity / 2;
+ uint256 requestTokens2 = rateLimiter.capacity / 2 + overLimit;
+
+ uint256 waitInSeconds = overLimit / rateLimiter.rate;
+
+ s_helper.consume(requestTokens1, address(0));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.AggregateValueRateLimitReached.selector, waitInSeconds, rateLimiter.capacity - requestTokens1
+ )
+ );
+ s_helper.consume(requestTokens2, address(0));
+ }
+
+ function test_TokenRateLimitReached_Revert() public {
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+
+ uint256 overLimit = 20;
+ uint256 requestTokens1 = rateLimiter.capacity / 2;
+ uint256 requestTokens2 = rateLimiter.capacity / 2 + overLimit;
+
+ uint256 waitInSeconds = overLimit / rateLimiter.rate;
+
+ s_helper.consume(requestTokens1, s_token);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.TokenRateLimitReached.selector, waitInSeconds, rateLimiter.capacity - requestTokens1, s_token
+ )
+ );
+ s_helper.consume(requestTokens2, s_token);
+ }
+
+ function test_RateLimitReachedOverConsecutiveBlocks_Revert() public {
+ uint256 initBlockTime = BLOCK_TIME + 10000;
+ vm.warp(initBlockTime);
+
+ RateLimiter.TokenBucket memory rateLimiter = s_helper.getRateLimiter();
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(rateLimiter.capacity);
+
+ s_helper.consume(rateLimiter.capacity, address(0));
+
+ vm.warp(initBlockTime + 1);
+
+ // Over rate limit by 1, force 1 second wait
+ uint256 overLimit = 1;
+
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, 1, rateLimiter.rate));
+ s_helper.consume(rateLimiter.rate + overLimit, address(0));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockCommitStore.sol b/contracts/src/v0.8/ccip/test/mocks/MockCommitStore.sol
new file mode 100644
index 00000000000..aff06016fa5
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockCommitStore.sol
@@ -0,0 +1,42 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ICommitStore} from "../../interfaces/ICommitStore.sol";
+
+contract MockCommitStore is ICommitStore {
+ error PausedError();
+
+ uint64 private s_expectedNextSequenceNumber = 1;
+
+ bool private s_paused = false;
+
+ /// @inheritdoc ICommitStore
+ function verify(
+ bytes32[] calldata,
+ bytes32[] calldata,
+ uint256
+ ) external view whenNotPaused returns (uint256 timestamp) {
+ return 1;
+ }
+
+ function getExpectedNextSequenceNumber() external view returns (uint64) {
+ return s_expectedNextSequenceNumber;
+ }
+
+ function setExpectedNextSequenceNumber(uint64 nextSeqNum) external {
+ s_expectedNextSequenceNumber = nextSeqNum;
+ }
+
+ modifier whenNotPaused() {
+ if (paused()) revert PausedError();
+ _;
+ }
+
+ function paused() public view returns (bool) {
+ return s_paused;
+ }
+
+ function pause() external {
+ s_paused = true;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockE2EUSDCTokenMessenger.sol b/contracts/src/v0.8/ccip/test/mocks/MockE2EUSDCTokenMessenger.sol
new file mode 100644
index 00000000000..9fa5cd1a66d
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockE2EUSDCTokenMessenger.sol
@@ -0,0 +1,103 @@
+/*
+ * Copyright (c) 2022, Circle Internet Financial Limited.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+pragma solidity 0.8.24;
+
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+import {ITokenMessenger} from "../../pools/USDC/ITokenMessenger.sol";
+import {IMessageTransmitterWithRelay} from "./interfaces/IMessageTransmitterWithRelay.sol";
+
+// This contract mocks both the ITokenMessenger and IMessageTransmitter
+// contracts involved with the Cross Chain Token Protocol.
+contract MockE2EUSDCTokenMessenger is ITokenMessenger {
+ uint32 private immutable i_messageBodyVersion;
+ address private immutable i_transmitter;
+
+ bytes32 public constant DESTINATION_TOKEN_MESSENGER = keccak256("i_destinationTokenMessenger");
+
+ uint64 public s_nonce;
+
+ // Local Message Transmitter responsible for sending and receiving messages to/from remote domains
+ IMessageTransmitterWithRelay public immutable localMessageTransmitterWithRelay;
+
+ constructor(uint32 version, address transmitter) {
+ i_messageBodyVersion = version;
+ s_nonce = 1;
+ i_transmitter = transmitter;
+ localMessageTransmitterWithRelay = IMessageTransmitterWithRelay(transmitter);
+ }
+
+ // The mock function is based on the same function in https://github.com/circlefin/evm-cctp-contracts/blob/master/src/TokenMessenger.sol
+ function depositForBurnWithCaller(
+ uint256 amount,
+ uint32 destinationDomain,
+ bytes32 mintRecipient,
+ address burnToken,
+ bytes32 destinationCaller
+ ) external returns (uint64) {
+ IBurnMintERC20(burnToken).transferFrom(msg.sender, address(this), amount);
+ IBurnMintERC20(burnToken).burn(amount);
+ // Format message body
+ bytes memory _burnMessage =
+ abi.encodePacked(i_messageBodyVersion, burnToken, mintRecipient, amount, bytes32(uint256(uint160((msg.sender)))));
+ s_nonce =
+ _sendDepositForBurnMessage(destinationDomain, DESTINATION_TOKEN_MESSENGER, destinationCaller, _burnMessage);
+ emit DepositForBurn(
+ s_nonce,
+ burnToken,
+ amount,
+ msg.sender,
+ mintRecipient,
+ destinationDomain,
+ DESTINATION_TOKEN_MESSENGER,
+ destinationCaller
+ );
+ return s_nonce;
+ }
+
+ function messageBodyVersion() external view returns (uint32) {
+ return i_messageBodyVersion;
+ }
+
+ function localMessageTransmitter() external view returns (address) {
+ return i_transmitter;
+ }
+
+ /**
+ * @notice Sends a BurnMessage through the local message transmitter
+ * @dev calls local message transmitter's sendMessage() function if `_destinationCaller` == bytes32(0),
+ * or else calls sendMessageWithCaller().
+ * @param _destinationDomain destination domain
+ * @param _destinationTokenMessenger address of registered TokenMessenger contract on destination domain, as bytes32
+ * @param _destinationCaller caller on the destination domain, as bytes32. If `_destinationCaller` == bytes32(0),
+ * any address can call receiveMessage() on destination domain.
+ * @param _burnMessage formatted BurnMessage bytes (message body)
+ * @return nonce unique nonce reserved by message
+ */
+ function _sendDepositForBurnMessage(
+ uint32 _destinationDomain,
+ bytes32 _destinationTokenMessenger,
+ bytes32 _destinationCaller,
+ bytes memory _burnMessage
+ ) internal returns (uint64 nonce) {
+ if (_destinationCaller == bytes32(0)) {
+ return localMessageTransmitterWithRelay.sendMessage(_destinationDomain, _destinationTokenMessenger, _burnMessage);
+ } else {
+ return localMessageTransmitterWithRelay.sendMessageWithCaller(
+ _destinationDomain, _destinationTokenMessenger, _destinationCaller, _burnMessage
+ );
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockE2EUSDCTransmitter.sol b/contracts/src/v0.8/ccip/test/mocks/MockE2EUSDCTransmitter.sol
new file mode 100644
index 00000000000..8e50bedea99
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockE2EUSDCTransmitter.sol
@@ -0,0 +1,168 @@
+/*
+ * Copyright (c) 2022, Circle Internet Financial Limited.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+pragma solidity ^0.8.0;
+
+import {IMessageTransmitterWithRelay} from "./interfaces/IMessageTransmitterWithRelay.sol";
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+
+contract MockE2EUSDCTransmitter is IMessageTransmitterWithRelay {
+ // Indicated whether the receiveMessage() call should succeed.
+ bool public s_shouldSucceed;
+ uint32 private immutable i_version;
+ uint32 private immutable i_localDomain;
+ // Next available nonce from this source domain
+ uint64 public nextAvailableNonce;
+
+ BurnMintERC677 internal immutable i_token;
+
+ /**
+ * @notice Emitted when a new message is dispatched
+ * @param message Raw bytes of message
+ */
+ event MessageSent(bytes message);
+
+ constructor(uint32 _version, uint32 _localDomain, address token) {
+ i_version = _version;
+ i_localDomain = _localDomain;
+ s_shouldSucceed = true;
+
+ i_token = BurnMintERC677(token);
+ }
+
+ /// @param message The original message on the source chain
+ /// * Message format:
+ /// * Field Bytes Type Index
+ /// * version 4 uint32 0
+ /// * sourceDomain 4 uint32 4
+ /// * destinationDomain 4 uint32 8
+ /// * nonce 8 uint64 12
+ /// * sender 32 bytes32 20
+ /// * recipient 32 bytes32 52
+ /// * destinationCaller 32 bytes32 84
+ /// * messageBody dynamic bytes 116
+ function receiveMessage(bytes calldata message, bytes calldata) external returns (bool success) {
+ address recipient = address(bytes20(message[64:84]));
+
+ // We always mint 1000e18 tokens to not complicate the test.
+ i_token.mint(recipient, 1000e18);
+
+ return s_shouldSucceed;
+ }
+
+ function setShouldSucceed(bool shouldSucceed) external {
+ s_shouldSucceed = shouldSucceed;
+ }
+
+ function version() external view returns (uint32) {
+ return i_version;
+ }
+
+ function localDomain() external view returns (uint32) {
+ return i_localDomain;
+ }
+
+ /**
+ * This is based on similar function in https://github.com/circlefin/evm-cctp-contracts/blob/master/src/MessageTransmitter.sol
+ * @notice Send the message to the destination domain and recipient
+ * @dev Increment nonce, format the message, and emit `MessageSent` event with message information.
+ * @param destinationDomain Domain of destination chain
+ * @param recipient Address of message recipient on destination chain as bytes32
+ * @param messageBody Raw bytes content of message
+ * @return nonce reserved by message
+ */
+ function sendMessage(
+ uint32 destinationDomain,
+ bytes32 recipient,
+ bytes calldata messageBody
+ ) external returns (uint64) {
+ bytes32 _emptyDestinationCaller = bytes32(0);
+ uint64 _nonce = _reserveAndIncrementNonce();
+ bytes32 _messageSender = bytes32(uint256(uint160((msg.sender))));
+
+ _sendMessage(destinationDomain, recipient, _emptyDestinationCaller, _messageSender, _nonce, messageBody);
+
+ return _nonce;
+ }
+
+ /**
+ * @notice Send the message to the destination domain and recipient, for a specified `destinationCaller` on the
+ * destination domain.
+ * @dev Increment nonce, format the message, and emit `MessageSent` event with message information.
+ * WARNING: if the `destinationCaller` does not represent a valid address, then it will not be possible
+ * to broadcast the message on the destination domain. This is an advanced feature, and the standard
+ * sendMessage() should be preferred for use cases where a specific destination caller is not required.
+ * @param destinationDomain Domain of destination chain
+ * @param recipient Address of message recipient on destination domain as bytes32
+ * @param destinationCaller caller on the destination domain, as bytes32
+ * @param messageBody Raw bytes content of message
+ * @return nonce reserved by message
+ */
+ function sendMessageWithCaller(
+ uint32 destinationDomain,
+ bytes32 recipient,
+ bytes32 destinationCaller,
+ bytes calldata messageBody
+ ) external returns (uint64) {
+ require(destinationCaller != bytes32(0), "Destination caller must be nonzero");
+
+ uint64 _nonce = _reserveAndIncrementNonce();
+ bytes32 _messageSender = bytes32(uint256(uint160((msg.sender))));
+
+ _sendMessage(destinationDomain, recipient, destinationCaller, _messageSender, _nonce, messageBody);
+
+ return _nonce;
+ }
+
+ /**
+ * Reserve and increment next available nonce
+ * @return nonce reserved
+ */
+ function _reserveAndIncrementNonce() internal returns (uint64) {
+ uint64 _nonceReserved = nextAvailableNonce;
+ nextAvailableNonce = nextAvailableNonce + 1;
+ return _nonceReserved;
+ }
+
+ /**
+ * @notice Send the message to the destination domain and recipient. If `_destinationCaller` is not equal to bytes32(0),
+ * the message can only be received on the destination chain when called by `_destinationCaller`.
+ * @dev Format the message and emit `MessageSent` event with message information.
+ * @param _destinationDomain Domain of destination chain
+ * @param _recipient Address of message recipient on destination domain as bytes32
+ * @param _destinationCaller caller on the destination domain, as bytes32
+ * @param _sender message sender, as bytes32
+ * @param _nonce nonce reserved for message
+ * @param _messageBody Raw bytes content of message
+ */
+ function _sendMessage(
+ uint32 _destinationDomain,
+ bytes32 _recipient,
+ bytes32 _destinationCaller,
+ bytes32 _sender,
+ uint64 _nonce,
+ bytes calldata _messageBody
+ ) internal {
+ require(_recipient != bytes32(0), "Recipient must be nonzero");
+ // serialize message
+ bytes memory _message = abi.encodePacked(
+ i_version, i_localDomain, _destinationDomain, _nonce, _sender, _recipient, _destinationCaller, _messageBody
+ );
+
+ // Emit MessageSent event
+ emit MessageSent(_message);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockRMN.sol b/contracts/src/v0.8/ccip/test/mocks/MockRMN.sol
new file mode 100644
index 00000000000..3f7b0200e6f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockRMN.sol
@@ -0,0 +1,55 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {RMN} from "../../RMN.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+import {OwnerIsCreator} from "./../../../shared/access/OwnerIsCreator.sol";
+
+/// @notice WARNING: This contract is to be only used for testing, all methods are unprotected.
+contract MockRMN is IRMN {
+ error CustomError(bytes err);
+
+ bytes private s_isCursedRevert;
+
+ bool private s_globalCursed;
+ mapping(bytes16 subject => bool cursed) private s_cursedBySubject;
+ mapping(address commitStore => mapping(bytes32 root => bool blessed)) private s_blessedByRoot;
+
+ function setTaggedRootBlessed(IRMN.TaggedRoot calldata taggedRoot, bool blessed) external {
+ s_blessedByRoot[taggedRoot.commitStore][taggedRoot.root] = blessed;
+ }
+
+ function setGlobalCursed(bool cursed) external {
+ s_globalCursed = cursed;
+ }
+
+ function setChainCursed(uint64 chainSelector, bool cursed) external {
+ s_cursedBySubject[bytes16(uint128(chainSelector))] = cursed;
+ }
+
+ /// @notice Setting a revert error with length of 0 will disable reverts
+ /// @dev Useful to test revert handling of ARMProxy
+ function setIsCursedRevert(bytes calldata revertErr) external {
+ s_isCursedRevert = revertErr;
+ }
+
+ // IRMN implementation follows
+
+ function isCursed() external view returns (bool) {
+ if (s_isCursedRevert.length > 0) {
+ revert CustomError(s_isCursedRevert);
+ }
+ return s_globalCursed;
+ }
+
+ function isCursed(bytes16 subject) external view returns (bool) {
+ if (s_isCursedRevert.length > 0) {
+ revert CustomError(s_isCursedRevert);
+ }
+ return s_globalCursed || s_cursedBySubject[subject];
+ }
+
+ function isBlessed(IRMN.TaggedRoot calldata taggedRoot) external view returns (bool) {
+ return s_blessedByRoot[taggedRoot.commitStore][taggedRoot.root];
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockRMN1_0.sol b/contracts/src/v0.8/ccip/test/mocks/MockRMN1_0.sol
new file mode 100644
index 00000000000..44ffc23b78f
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockRMN1_0.sol
@@ -0,0 +1,91 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IRMN} from "../../interfaces/IRMN.sol";
+import {OwnerIsCreator} from "./../../../shared/access/OwnerIsCreator.sol";
+
+// Inlined from RMN 1.0 contract.
+// solhint-disable gas-struct-packing
+contract RMN {
+ struct Voter {
+ address blessVoteAddr;
+ address curseVoteAddr;
+ address curseUnvoteAddr;
+ uint8 blessWeight;
+ uint8 curseWeight;
+ }
+
+ struct Config {
+ Voter[] voters;
+ uint16 blessWeightThreshold;
+ uint16 curseWeightThreshold;
+ }
+
+ struct VersionedConfig {
+ Config config;
+ uint32 configVersion;
+ uint32 blockNumber;
+ }
+
+ struct UnvoteToCurseRecord {
+ address curseVoteAddr;
+ bytes32 cursesHash;
+ bool forceUnvote;
+ }
+}
+
+/// @dev Retained almost as-is from commit 88f285b94c23d0c684d337064758a5edde380fe2 for compatibility with offchain
+/// tests and scripts. Internal structs of the RMN 1.0 contract that were depended on have been inlined.
+/// @dev This contract should no longer be used for any new tests or scripts.
+/// @notice WARNING: This contract is to be only used for testing, all methods are unprotected.
+// TODO: remove this contract when tests and scripts are updated
+contract MockRMN is IRMN, OwnerIsCreator {
+ error CustomError(bytes err);
+
+ bool private s_curse;
+ bytes private s_err;
+ RMN.VersionedConfig private s_versionedConfig;
+ mapping(bytes16 subject => bool cursed) private s_curseBySubject;
+
+ function isCursed() external view override returns (bool) {
+ if (s_err.length != 0) {
+ revert CustomError(s_err);
+ }
+ return s_curse;
+ }
+
+ function isCursed(bytes16 subject) external view override returns (bool) {
+ if (s_err.length != 0) {
+ revert CustomError(s_err);
+ }
+ return s_curse || s_curseBySubject[subject];
+ }
+
+ function voteToCurse(bytes32) external {
+ s_curse = true;
+ }
+
+ function voteToCurse(bytes32, bytes16 subject) external {
+ s_curseBySubject[subject] = true;
+ }
+
+ function ownerUnvoteToCurse(RMN.UnvoteToCurseRecord[] memory) external {
+ s_curse = false;
+ }
+
+ function ownerUnvoteToCurse(RMN.UnvoteToCurseRecord[] memory, bytes16 subject) external {
+ s_curseBySubject[subject] = false;
+ }
+
+ function setRevert(bytes memory err) external {
+ s_err = err;
+ }
+
+ function isBlessed(IRMN.TaggedRoot calldata) external view override returns (bool) {
+ return !s_curse;
+ }
+
+ function getConfigDetails() external view returns (uint32 version, uint32 blockNumber, RMN.Config memory config) {
+ return (s_versionedConfig.configVersion, s_versionedConfig.blockNumber, s_versionedConfig.config);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockRouter.sol b/contracts/src/v0.8/ccip/test/mocks/MockRouter.sol
new file mode 100644
index 00000000000..87db0319514
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockRouter.sol
@@ -0,0 +1,148 @@
+// SPDX-License-Identifier: MIT
+pragma solidity ^0.8.0;
+
+import {IAny2EVMMessageReceiver} from "../../interfaces/IAny2EVMMessageReceiver.sol";
+import {IRouter} from "../../interfaces/IRouter.sol";
+import {IRouterClient} from "../../interfaces/IRouterClient.sol";
+
+import {CallWithExactGas} from "../../../shared/call/CallWithExactGas.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+import {ERC165Checker} from
+ "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol";
+
+contract MockCCIPRouter is IRouter, IRouterClient {
+ using SafeERC20 for IERC20;
+ using ERC165Checker for address;
+
+ error InvalidAddress(bytes encodedAddress);
+ error InvalidExtraArgsTag();
+ error ReceiverError(bytes err);
+
+ event MessageExecuted(bytes32 messageId, uint64 sourceChainSelector, address offRamp, bytes32 calldataHash);
+ event MsgExecuted(bool success, bytes retData, uint256 gasUsed);
+
+ uint16 public constant GAS_FOR_CALL_EXACT_CHECK = 5_000;
+ uint32 public constant DEFAULT_GAS_LIMIT = 200_000;
+
+ uint256 internal s_mockFeeTokenAmount; //use setFee() to change to non-zero to test fees
+
+ function routeMessage(
+ Client.Any2EVMMessage calldata message,
+ uint16 gasForCallExactCheck,
+ uint256 gasLimit,
+ address receiver
+ ) external returns (bool success, bytes memory retData, uint256 gasUsed) {
+ return _routeMessage(message, gasForCallExactCheck, gasLimit, receiver);
+ }
+
+ function _routeMessage(
+ Client.Any2EVMMessage memory message,
+ uint16 gasForCallExactCheck,
+ uint256 gasLimit,
+ address receiver
+ ) internal returns (bool success, bytes memory retData, uint256 gasUsed) {
+ // Only send through the router if the receiver is a contract and implements the IAny2EVMMessageReceiver interface.
+ if (receiver.code.length == 0 || !receiver.supportsInterface(type(IAny2EVMMessageReceiver).interfaceId)) {
+ return (true, "", 0);
+ }
+
+ bytes memory data = abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message);
+
+ (success, retData, gasUsed) = CallWithExactGas._callWithExactGasSafeReturnData(
+ data, receiver, gasLimit, gasForCallExactCheck, Internal.MAX_RET_BYTES
+ );
+
+ // Event to assist testing, does not exist on real deployments
+ emit MsgExecuted(success, retData, gasUsed);
+
+ // Real router event
+ emit MessageExecuted(message.messageId, message.sourceChainSelector, msg.sender, keccak256(data));
+ return (success, retData, gasUsed);
+ }
+
+ /// @notice Sends the tx locally to the receiver instead of on the destination chain.
+ /// @dev Ignores destinationChainSelector
+ /// @dev Returns a mock message ID, which is not calculated from the message contents in the
+ /// same way as the real message ID.
+ function ccipSend(
+ uint64 destinationChainSelector,
+ Client.EVM2AnyMessage calldata message
+ ) external payable returns (bytes32) {
+ if (message.receiver.length != 32) revert InvalidAddress(message.receiver);
+ uint256 decodedReceiver = abi.decode(message.receiver, (uint256));
+ // We want to disallow sending to address(0) and to precompiles, which exist on address(1) through address(9).
+ if (decodedReceiver > type(uint160).max || decodedReceiver < 10) revert InvalidAddress(message.receiver);
+
+ uint256 feeTokenAmount = getFee(destinationChainSelector, message);
+ if (message.feeToken == address(0)) {
+ if (msg.value < feeTokenAmount) revert InsufficientFeeTokenAmount();
+ } else {
+ if (msg.value > 0) revert InvalidMsgValue();
+ IERC20(message.feeToken).safeTransferFrom(msg.sender, address(this), feeTokenAmount);
+ }
+
+ address receiver = address(uint160(decodedReceiver));
+ uint256 gasLimit = _fromBytes(message.extraArgs).gasLimit;
+ bytes32 mockMsgId = keccak256(abi.encode(message));
+
+ Client.Any2EVMMessage memory executableMsg = Client.Any2EVMMessage({
+ messageId: mockMsgId,
+ sourceChainSelector: 16015286601757825753, // Sepolia
+ sender: abi.encode(msg.sender),
+ data: message.data,
+ destTokenAmounts: message.tokenAmounts
+ });
+
+ for (uint256 i = 0; i < message.tokenAmounts.length; ++i) {
+ IERC20(message.tokenAmounts[i].token).safeTransferFrom(msg.sender, receiver, message.tokenAmounts[i].amount);
+ }
+
+ (bool success, bytes memory retData,) = _routeMessage(executableMsg, GAS_FOR_CALL_EXACT_CHECK, gasLimit, receiver);
+
+ if (!success) revert ReceiverError(retData);
+
+ return mockMsgId;
+ }
+
+ function _fromBytes(bytes calldata extraArgs) internal pure returns (Client.EVMExtraArgsV1 memory) {
+ if (extraArgs.length == 0) {
+ return Client.EVMExtraArgsV1({gasLimit: DEFAULT_GAS_LIMIT});
+ }
+ if (bytes4(extraArgs) != Client.EVM_EXTRA_ARGS_V1_TAG) revert InvalidExtraArgsTag();
+ return abi.decode(extraArgs[4:], (Client.EVMExtraArgsV1));
+ }
+
+ /// @notice Always returns true to make sure this check can be performed on any chain.
+ function isChainSupported(uint64) external pure returns (bool supported) {
+ return true;
+ }
+
+ /// @notice Returns an empty array.
+ function getSupportedTokens(uint64) external pure returns (address[] memory tokens) {
+ return new address[](0);
+ }
+
+ /// @notice Returns 0 as the fee is not supported in this mock contract.
+ function getFee(uint64, Client.EVM2AnyMessage memory) public view returns (uint256) {
+ return s_mockFeeTokenAmount;
+ }
+
+ /// @notice Sets the fees returned by getFee but is only checked when using native fee tokens
+ function setFee(uint256 feeAmount) external {
+ s_mockFeeTokenAmount = feeAmount;
+ }
+
+ /// @notice Always returns address(1234567890)
+ function getOnRamp(uint64 /* destChainSelector */ ) external pure returns (address onRampAddress) {
+ return address(1234567890);
+ }
+
+ /// @notice Always returns true
+ function isOffRamp(uint64, /* sourceChainSelector */ address /* offRamp */ ) external pure returns (bool) {
+ return true;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/MockUSDCTokenMessenger.sol b/contracts/src/v0.8/ccip/test/mocks/MockUSDCTokenMessenger.sol
new file mode 100644
index 00000000000..562a9f467ff
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/MockUSDCTokenMessenger.sol
@@ -0,0 +1,52 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+import {ITokenMessenger} from "../../pools/USDC/ITokenMessenger.sol";
+
+// This contract mocks both the ITokenMessenger and IMessageTransmitter
+// contracts involved with the Cross Chain Token Protocol.
+contract MockUSDCTokenMessenger is ITokenMessenger {
+ uint32 private immutable i_messageBodyVersion;
+ address private immutable i_transmitter;
+
+ bytes32 public constant DESTINATION_TOKEN_MESSENGER = keccak256("i_destinationTokenMessenger");
+
+ uint64 public s_nonce;
+
+ constructor(uint32 version, address transmitter) {
+ i_messageBodyVersion = version;
+ s_nonce = 1;
+ i_transmitter = transmitter;
+ }
+
+ function depositForBurnWithCaller(
+ uint256 amount,
+ uint32 destinationDomain,
+ bytes32 mintRecipient,
+ address burnToken,
+ bytes32 destinationCaller
+ ) external returns (uint64) {
+ IBurnMintERC20(burnToken).transferFrom(msg.sender, address(this), amount);
+ IBurnMintERC20(burnToken).burn(amount);
+ emit DepositForBurn(
+ s_nonce,
+ burnToken,
+ amount,
+ msg.sender,
+ mintRecipient,
+ destinationDomain,
+ DESTINATION_TOKEN_MESSENGER,
+ destinationCaller
+ );
+ return s_nonce++;
+ }
+
+ function messageBodyVersion() external view returns (uint32) {
+ return i_messageBodyVersion;
+ }
+
+ function localMessageTransmitter() external view returns (address) {
+ return i_transmitter;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/interfaces/IMessageTransmitterWithRelay.sol b/contracts/src/v0.8/ccip/test/mocks/interfaces/IMessageTransmitterWithRelay.sol
new file mode 100644
index 00000000000..dc9c644e07a
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/interfaces/IMessageTransmitterWithRelay.sol
@@ -0,0 +1,55 @@
+/*
+ * Copyright (c) 2022, Circle Internet Financial Limited.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+pragma solidity ^0.8.0;
+
+import {IMessageTransmitter} from "../../../pools/USDC/IMessageTransmitter.sol";
+
+// This follows https://github.com/circlefin/evm-cctp-contracts/blob/master/src/interfaces/IMessageTransmitter.sol
+interface IMessageTransmitterWithRelay is IMessageTransmitter {
+ /**
+ * @notice Sends an outgoing message from the source domain.
+ * @dev Increment nonce, format the message, and emit `MessageSent` event with message information.
+ * @param destinationDomain Domain of destination chain
+ * @param recipient Address of message recipient on destination domain as bytes32
+ * @param messageBody Raw bytes content of message
+ * @return nonce reserved by message
+ */
+ function sendMessage(
+ uint32 destinationDomain,
+ bytes32 recipient,
+ bytes calldata messageBody
+ ) external returns (uint64);
+
+ /**
+ * @notice Sends an outgoing message from the source domain, with a specified caller on the
+ * destination domain.
+ * @dev Increment nonce, format the message, and emit `MessageSent` event with message information.
+ * WARNING: if the `destinationCaller` does not represent a valid address as bytes32, then it will not be possible
+ * to broadcast the message on the destination domain. This is an advanced feature, and the standard
+ * sendMessage() should be preferred for use cases where a specific destination caller is not required.
+ * @param destinationDomain Domain of destination chain
+ * @param recipient Address of message recipient on destination domain as bytes32
+ * @param destinationCaller caller on the destination domain, as bytes32
+ * @param messageBody Raw bytes content of message
+ * @return nonce reserved by message
+ */
+ function sendMessageWithCaller(
+ uint32 destinationDomain,
+ bytes32 recipient,
+ bytes32 destinationCaller,
+ bytes calldata messageBody
+ ) external returns (uint64);
+}
diff --git a/contracts/src/v0.8/ccip/test/mocks/test/MockRouterTest.t.sol b/contracts/src/v0.8/ccip/test/mocks/test/MockRouterTest.t.sol
new file mode 100644
index 00000000000..91798b494df
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/mocks/test/MockRouterTest.t.sol
@@ -0,0 +1,68 @@
+pragma solidity ^0.8.0;
+
+import {Client} from "../../../libraries/Client.sol";
+
+import {TokenSetup} from "../../TokenSetup.t.sol";
+import {IRouter, IRouterClient, MockCCIPRouter} from "../MockRouter.sol";
+
+import {IERC20} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+contract MockRouterTest is TokenSetup {
+ using SafeERC20 for IERC20;
+
+ MockCCIPRouter public mockRouter;
+
+ uint64 public constant mockChainSelector = 123456;
+
+ Client.EVM2AnyMessage public message;
+
+ function setUp() public override {
+ mockRouter = new MockCCIPRouter();
+
+ //Configure the Fee to 0.1 ether for native token fees
+ mockRouter.setFee(0.1 ether);
+
+ deal(address(this), 100 ether);
+
+ message.receiver = abi.encode(address(0x12345));
+ message.data = abi.encode("Hello World");
+
+ s_sourceFeeToken = _deploySourceToken("sLINK", type(uint256).max, 18);
+ }
+
+ function test_ccipSendWithInsufficientNativeTokens_Revert() public {
+ //Should revert because did not include sufficient eth to pay for fees
+ vm.expectRevert(IRouterClient.InsufficientFeeTokenAmount.selector);
+ mockRouter.ccipSend(mockChainSelector, message);
+ }
+
+ function test_ccipSendWithSufficientNativeFeeTokens_Success() public {
+ //ccipSend with sufficient native tokens for fees
+ mockRouter.ccipSend{value: 0.1 ether}(mockChainSelector, message);
+ }
+
+ function test_ccipSendWithInvalidMsgValue_Revert() public {
+ message.feeToken = address(1); //Set to non native-token fees
+
+ vm.expectRevert(IRouterClient.InvalidMsgValue.selector);
+ mockRouter.ccipSend{value: 0.1 ether}(mockChainSelector, message);
+ }
+
+ function test_ccipSendWithLinkFeeTokenbutInsufficientAllowance_Revert() public {
+ message.feeToken = s_sourceFeeToken;
+
+ vm.expectRevert(bytes("ERC20: insufficient allowance"));
+ mockRouter.ccipSend(mockChainSelector, message);
+ }
+
+ function test_ccipSendWithLinkFeeTokenAndValidMsgValue_Success() public {
+ message.feeToken = s_sourceFeeToken;
+
+ vm.startPrank(OWNER, OWNER);
+
+ IERC20(s_sourceFeeToken).safeApprove(address(mockRouter), type(uint256).max);
+
+ mockRouter.ccipSend(mockChainSelector, message);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/ocr/MultiOCR3Base.t.sol b/contracts/src/v0.8/ccip/test/ocr/MultiOCR3Base.t.sol
new file mode 100644
index 00000000000..5b784bf7219
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/ocr/MultiOCR3Base.t.sol
@@ -0,0 +1,921 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {MultiOCR3Base} from "../../ocr/MultiOCR3Base.sol";
+import {MultiOCR3Helper} from "../helpers/MultiOCR3Helper.sol";
+import {MultiOCR3BaseSetup} from "./MultiOCR3BaseSetup.t.sol";
+
+import {Vm} from "forge-std/Vm.sol";
+
+contract MultiOCR3Base_transmit is MultiOCR3BaseSetup {
+ bytes32 internal s_configDigest1;
+ bytes32 internal s_configDigest2;
+ bytes32 internal s_configDigest3;
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ s_configDigest1 = _getBasicConfigDigest(1, s_validSigners, s_validTransmitters);
+ s_configDigest2 = _getBasicConfigDigest(1, s_validSigners, s_validTransmitters);
+ s_configDigest3 = _getBasicConfigDigest(2, s_emptySigners, s_validTransmitters);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](3);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: s_configDigest1,
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ ocrConfigs[1] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 1,
+ configDigest: s_configDigest2,
+ F: 2,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ ocrConfigs[2] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 2,
+ configDigest: s_configDigest3,
+ F: 1,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_TransmitSigners_gas_Success() public {
+ vm.pauseGasMetering();
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ // F = 2, need 2 signatures
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 2);
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(0, s_configDigest1, uint64(uint256(s_configDigest1)));
+
+ vm.startPrank(s_validTransmitters[1]);
+ vm.resumeGasMetering();
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_TransmitWithoutSignatureVerification_gas_Success() public {
+ vm.pauseGasMetering();
+ bytes32[3] memory reportContext = [s_configDigest3, s_configDigest3, s_configDigest3];
+
+ s_multiOCR3.setTransmitOcrPluginType(2);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(2, s_configDigest3, uint64(uint256(s_configDigest3)));
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.resumeGasMetering();
+ s_multiOCR3.transmitWithoutSignatures(reportContext, REPORT);
+ }
+
+ function test_Fuzz_TransmitSignersWithSignatures_Success(uint8 F, uint64 randomAddressOffset) public {
+ vm.pauseGasMetering();
+
+ F = uint8(bound(F, 1, 3));
+
+ // condition: signers.length > 3F
+ uint8 signersLength = 3 * F + 1;
+ address[] memory signers = new address[](signersLength);
+ address[] memory transmitters = new address[](signersLength);
+ uint256[] memory signerKeys = new uint256[](signersLength);
+
+ // Force addresses to be unique (with a random offset for broader testing)
+ for (uint160 i = 0; i < signersLength; ++i) {
+ transmitters[i] = vm.addr(PRIVATE0 + randomAddressOffset + i);
+ // condition: non-zero oracle address
+ vm.assume(transmitters[i] != address(0));
+
+ // condition: non-repeating addresses (no clashes with transmitters)
+ signerKeys[i] = PRIVATE0 + randomAddressOffset + i + signersLength;
+ signers[i] = vm.addr(signerKeys[i]);
+ vm.assume(signers[i] != address(0));
+ }
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 3,
+ configDigest: s_configDigest1,
+ F: F,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: transmitters
+ });
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ s_multiOCR3.setTransmitOcrPluginType(3);
+
+ // Randomise picked transmitter with random offset
+ vm.startPrank(transmitters[randomAddressOffset % signersLength]);
+
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ // condition: matches signature expectation for transmit
+ uint8 numSignatures = F + 1;
+ uint256[] memory pickedSignerKeys = new uint256[](numSignatures);
+
+ // Randomise picked signers with random offset
+ for (uint256 i; i < numSignatures; ++i) {
+ pickedSignerKeys[i] = signerKeys[(i + randomAddressOffset) % numSignatures];
+ }
+
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(pickedSignerKeys, REPORT, reportContext, numSignatures);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(3, s_configDigest1, uint64(uint256(s_configDigest1)));
+
+ vm.resumeGasMetering();
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ // Reverts
+ function test_ForkedChain_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 2);
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ uint256 chain1 = block.chainid;
+ uint256 chain2 = chain1 + 1;
+ vm.chainId(chain2);
+ vm.expectRevert(abi.encodeWithSelector(MultiOCR3Base.ForkedChain.selector, chain1, chain2));
+
+ vm.startPrank(s_validTransmitters[0]);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_ZeroSignatures_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.WrongNumberOfSignatures.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, new bytes32[](0), new bytes32[](0), bytes32(""));
+ }
+
+ function test_TooManySignatures_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ // 1 signature too many
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 6);
+
+ s_multiOCR3.setTransmitOcrPluginType(1);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.WrongNumberOfSignatures.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_InsufficientSignatures_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ // Missing 1 signature for unique report
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 4);
+
+ s_multiOCR3.setTransmitOcrPluginType(1);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.WrongNumberOfSignatures.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_ConfigDigestMismatch_Revert() public {
+ bytes32 configDigest;
+ bytes32[3] memory reportContext = [configDigest, configDigest, configDigest];
+
+ (,,, bytes32 rawVs) = _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 2);
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.expectRevert(abi.encodeWithSelector(MultiOCR3Base.ConfigDigestMismatch.selector, s_configDigest1, configDigest));
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, new bytes32[](0), new bytes32[](0), rawVs);
+ }
+
+ function test_SignatureOutOfRegistration_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](1);
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.SignaturesOutOfRegistration.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, bytes32(""));
+ }
+
+ function test_UnAuthorizedTransmitter_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](2);
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.expectRevert(MultiOCR3Base.UnauthorizedTransmitter.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, bytes32(""));
+ }
+
+ function test_NonUniqueSignature_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ (bytes32[] memory rs, bytes32[] memory ss, uint8[] memory vs, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 2);
+
+ rs[1] = rs[0];
+ ss[1] = ss[0];
+ // Need to reset the rawVs to be valid
+ rawVs = bytes32(bytes1(vs[0] - 27)) | (bytes32(bytes1(vs[0] - 27)) >> 8);
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.NonUniqueSignatures.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_UnauthorizedSigner_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, REPORT, reportContext, 2);
+
+ rs[0] = s_configDigest1;
+ ss = rs;
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.UnauthorizedSigner.selector);
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_UnconfiguredPlugin_Revert() public {
+ bytes32 configDigest;
+ bytes32[3] memory reportContext = [configDigest, configDigest, configDigest];
+
+ s_multiOCR3.setTransmitOcrPluginType(42);
+
+ vm.expectRevert(MultiOCR3Base.UnauthorizedTransmitter.selector);
+ s_multiOCR3.transmitWithoutSignatures(reportContext, REPORT);
+ }
+
+ function test_TransmitWithLessCalldataArgs_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+
+ s_multiOCR3.setTransmitOcrPluginType(0);
+
+ // The transmit should fail, since we are trying to transmit without signatures when signatures are enabled
+ vm.startPrank(s_validTransmitters[1]);
+
+ // report length + function selector + report length + abiencoded location of report value + report context words
+ uint256 receivedLength = REPORT.length + 4 + 5 * 32;
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.WrongMessageLength.selector,
+ // Expecting inclusion of signature constant length components
+ receivedLength + 5 * 32,
+ receivedLength
+ )
+ );
+ s_multiOCR3.transmitWithoutSignatures(reportContext, REPORT);
+ }
+
+ function test_TransmitWithExtraCalldataArgs_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest1, s_configDigest1, s_configDigest1];
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](2);
+
+ s_multiOCR3.setTransmitOcrPluginType(2);
+
+ // The transmit should fail, since we are trying to transmit with signatures when signatures are disabled
+ vm.startPrank(s_validTransmitters[1]);
+
+ // dynamic length + function selector + report length + abiencoded location of report value + report context words
+ // rawVs value, lengths of rs, ss, and start locations of rs & ss -> 5 words
+ uint256 receivedLength = REPORT.length + 4 + (5 * 32) + (5 * 32) + (2 * 32) + (2 * 32);
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.WrongMessageLength.selector,
+ // Expecting exclusion of signature constant length components and rs, ss words
+ receivedLength - (5 * 32) - (4 * 32),
+ receivedLength
+ )
+ );
+ s_multiOCR3.transmitWithSignatures(reportContext, REPORT, rs, ss, bytes32(""));
+ }
+}
+
+contract MultiOCR3Base_setOCR3Configs is MultiOCR3BaseSetup {
+ function test_SetConfigsZeroInput_Success() public {
+ vm.recordLogs();
+ s_multiOCR3.setOCR3Configs(new MultiOCR3Base.OCRConfigArgs[](0));
+
+ // No logs emitted
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 0);
+ }
+
+ function test_SetConfigWithSigners_Success() public {
+ uint8 F = 2;
+
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(F, s_validSigners, s_validTransmitters),
+ F: F,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfigs[0].ocrPluginType,
+ ocrConfigs[0].configDigest,
+ ocrConfigs[0].signers,
+ ocrConfigs[0].transmitters,
+ ocrConfigs[0].F
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfigs[0].ocrPluginType);
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[0].configDigest,
+ F: ocrConfigs[0].F,
+ n: uint8(ocrConfigs[0].signers.length),
+ isSignatureVerificationEnabled: ocrConfigs[0].isSignatureVerificationEnabled
+ }),
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(0), expectedConfig);
+ }
+
+ function test_SetConfigWithoutSigners_Success() public {
+ uint8 F = 1;
+ address[] memory signers = new address[](0);
+
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(F, signers, s_validTransmitters),
+ F: F,
+ isSignatureVerificationEnabled: false,
+ signers: signers,
+ transmitters: s_validTransmitters
+ });
+
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfigs[0].ocrPluginType,
+ ocrConfigs[0].configDigest,
+ ocrConfigs[0].signers,
+ ocrConfigs[0].transmitters,
+ ocrConfigs[0].F
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfigs[0].ocrPluginType);
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[0].configDigest,
+ F: ocrConfigs[0].F,
+ n: uint8(ocrConfigs[0].signers.length),
+ isSignatureVerificationEnabled: ocrConfigs[0].isSignatureVerificationEnabled
+ }),
+ signers: signers,
+ transmitters: s_validTransmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(0), expectedConfig);
+ }
+
+ function test_SetConfigIgnoreSigners_Success() public {
+ uint8 F = 1;
+
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(F, new address[](0), s_validTransmitters),
+ F: F,
+ isSignatureVerificationEnabled: false,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfigs[0].ocrPluginType,
+ ocrConfigs[0].configDigest,
+ s_emptySigners,
+ ocrConfigs[0].transmitters,
+ ocrConfigs[0].F
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfigs[0].ocrPluginType);
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[0].configDigest,
+ F: ocrConfigs[0].F,
+ n: 0,
+ isSignatureVerificationEnabled: ocrConfigs[0].isSignatureVerificationEnabled
+ }),
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(0), expectedConfig);
+
+ // Verify no signer role is set
+ for (uint256 i = 0; i < s_validSigners.length; ++i) {
+ MultiOCR3Base.Oracle memory signerOracle = s_multiOCR3.getOracle(0, s_validSigners[i]);
+ assertEq(uint8(signerOracle.role), uint8(MultiOCR3Base.Role.Unset));
+ }
+ }
+
+ function test_SetMultipleConfigs_Success() public {
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(1));
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(2));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](3);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(2, s_validSigners, s_validTransmitters),
+ F: 2,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ ocrConfigs[1] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 1,
+ configDigest: _getBasicConfigDigest(1, s_validSigners, s_validTransmitters),
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ ocrConfigs[2] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 2,
+ configDigest: _getBasicConfigDigest(1, s_partialSigners, s_partialTransmitters),
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: s_partialSigners,
+ transmitters: s_partialTransmitters
+ });
+
+ for (uint256 i; i < ocrConfigs.length; ++i) {
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfigs[i].ocrPluginType,
+ ocrConfigs[i].configDigest,
+ ocrConfigs[i].signers,
+ ocrConfigs[i].transmitters,
+ ocrConfigs[i].F
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfigs[i].ocrPluginType);
+ }
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ for (uint256 i; i < ocrConfigs.length; ++i) {
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[i].configDigest,
+ F: ocrConfigs[i].F,
+ n: uint8(ocrConfigs[i].signers.length),
+ isSignatureVerificationEnabled: ocrConfigs[i].isSignatureVerificationEnabled
+ }),
+ signers: ocrConfigs[i].signers,
+ transmitters: ocrConfigs[i].transmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(ocrConfigs[i].ocrPluginType), expectedConfig);
+ }
+
+ // pluginType 3 remains unconfigured
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(3));
+ }
+
+ function test_Fuzz_SetConfig_Success(MultiOCR3Base.OCRConfigArgs memory ocrConfig, uint64 randomAddressOffset) public {
+ // condition: cannot assume max oracle count
+ vm.assume(ocrConfig.transmitters.length <= 31);
+ vm.assume(ocrConfig.signers.length <= 31);
+
+ // condition: F > 0
+ ocrConfig.F = uint8(bound(ocrConfig.F, 1, 3));
+
+ uint256 transmittersLength = ocrConfig.transmitters.length;
+
+ // Force addresses to be unique (with a random offset for broader testing)
+ for (uint160 i = 0; i < transmittersLength; ++i) {
+ ocrConfig.transmitters[i] = vm.addr(PRIVATE0 + randomAddressOffset + i);
+ // condition: non-zero oracle address
+ vm.assume(ocrConfig.transmitters[i] != address(0));
+ }
+
+ if (ocrConfig.signers.length == 0) {
+ ocrConfig.isSignatureVerificationEnabled = false;
+ } else {
+ ocrConfig.isSignatureVerificationEnabled = true;
+
+ // condition: number of signers > 3F
+ vm.assume(ocrConfig.signers.length > 3 * ocrConfig.F);
+
+ uint256 signersLength = ocrConfig.signers.length;
+
+ // Force addresses to be unique - continuing generation with an offset after the transmitter addresses
+ for (uint160 i = 0; i < signersLength; ++i) {
+ ocrConfig.signers[i] = vm.addr(PRIVATE0 + randomAddressOffset + i + transmittersLength);
+ // condition: non-zero oracle address
+ vm.assume(ocrConfig.signers[i] != address(0));
+ }
+ }
+
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(ocrConfig.ocrPluginType));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = ocrConfig;
+
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfig.ocrPluginType, ocrConfig.configDigest, ocrConfig.signers, ocrConfig.transmitters, ocrConfig.F
+ );
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfig.ocrPluginType);
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfig.configDigest,
+ F: ocrConfig.F,
+ n: ocrConfig.isSignatureVerificationEnabled ? uint8(ocrConfig.signers.length) : 0,
+ isSignatureVerificationEnabled: ocrConfig.isSignatureVerificationEnabled
+ }),
+ signers: ocrConfig.signers,
+ transmitters: ocrConfig.transmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(ocrConfig.ocrPluginType), expectedConfig);
+ }
+
+ function test_UpdateConfigTransmittersWithoutSigners_Success() public {
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(1, s_emptySigners, s_validTransmitters),
+ F: 1,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ address[] memory newTransmitters = s_partialSigners;
+
+ ocrConfigs[0].F = 2;
+ ocrConfigs[0].configDigest = _getBasicConfigDigest(2, s_emptySigners, newTransmitters);
+ ocrConfigs[0].transmitters = newTransmitters;
+
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfigs[0].ocrPluginType,
+ ocrConfigs[0].configDigest,
+ ocrConfigs[0].signers,
+ ocrConfigs[0].transmitters,
+ ocrConfigs[0].F
+ );
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfigs[0].ocrPluginType);
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[0].configDigest,
+ F: ocrConfigs[0].F,
+ n: uint8(ocrConfigs[0].signers.length),
+ isSignatureVerificationEnabled: ocrConfigs[0].isSignatureVerificationEnabled
+ }),
+ signers: s_emptySigners,
+ transmitters: newTransmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(0), expectedConfig);
+
+ // Verify oracle roles get correctly re-assigned
+ for (uint256 i; i < newTransmitters.length; ++i) {
+ MultiOCR3Base.Oracle memory transmitterOracle = s_multiOCR3.getOracle(0, newTransmitters[i]);
+ assertEq(transmitterOracle.index, i);
+ assertEq(uint8(transmitterOracle.role), uint8(MultiOCR3Base.Role.Transmitter));
+ }
+
+ // Verify old transmitters get correctly unset
+ for (uint256 i = newTransmitters.length; i < s_validTransmitters.length; ++i) {
+ MultiOCR3Base.Oracle memory transmitterOracle = s_multiOCR3.getOracle(0, s_validTransmitters[i]);
+ assertEq(uint8(transmitterOracle.role), uint8(MultiOCR3Base.Role.Unset));
+ }
+ }
+
+ function test_UpdateConfigSigners_Success() public {
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(2, s_validSigners, s_validTransmitters),
+ F: 2,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ address[] memory newSigners = s_partialTransmitters;
+ address[] memory newTransmitters = s_partialSigners;
+
+ ocrConfigs[0].F = 1;
+ ocrConfigs[0].configDigest = _getBasicConfigDigest(1, newSigners, newTransmitters);
+ ocrConfigs[0].signers = newSigners;
+ ocrConfigs[0].transmitters = newTransmitters;
+
+ vm.expectEmit();
+ emit MultiOCR3Base.ConfigSet(
+ ocrConfigs[0].ocrPluginType,
+ ocrConfigs[0].configDigest,
+ ocrConfigs[0].signers,
+ ocrConfigs[0].transmitters,
+ ocrConfigs[0].F
+ );
+ vm.expectEmit();
+ emit MultiOCR3Helper.AfterConfigSet(ocrConfigs[0].ocrPluginType);
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ MultiOCR3Base.OCRConfig memory expectedConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[0].configDigest,
+ F: ocrConfigs[0].F,
+ n: uint8(ocrConfigs[0].signers.length),
+ isSignatureVerificationEnabled: ocrConfigs[0].isSignatureVerificationEnabled
+ }),
+ signers: newSigners,
+ transmitters: newTransmitters
+ });
+ _assertOCRConfigEquality(s_multiOCR3.latestConfigDetails(0), expectedConfig);
+
+ // Verify oracle roles get correctly re-assigned
+ for (uint256 i; i < newSigners.length; ++i) {
+ MultiOCR3Base.Oracle memory signerOracle = s_multiOCR3.getOracle(0, newSigners[i]);
+ assertEq(signerOracle.index, i);
+ assertEq(uint8(signerOracle.role), uint8(MultiOCR3Base.Role.Signer));
+
+ MultiOCR3Base.Oracle memory transmitterOracle = s_multiOCR3.getOracle(0, newTransmitters[i]);
+ assertEq(transmitterOracle.index, i);
+ assertEq(uint8(transmitterOracle.role), uint8(MultiOCR3Base.Role.Transmitter));
+ }
+
+ // Verify old signers / transmitters get correctly unset
+ for (uint256 i = newSigners.length; i < s_validSigners.length; ++i) {
+ MultiOCR3Base.Oracle memory signerOracle = s_multiOCR3.getOracle(0, s_validSigners[i]);
+ assertEq(uint8(signerOracle.role), uint8(MultiOCR3Base.Role.Unset));
+
+ MultiOCR3Base.Oracle memory transmitterOracle = s_multiOCR3.getOracle(0, s_validTransmitters[i]);
+ assertEq(uint8(transmitterOracle.role), uint8(MultiOCR3Base.Role.Unset));
+ }
+ }
+
+ // Reverts
+
+ function test_RepeatTransmitterAddress_Revert() public {
+ address[] memory signers = s_validSigners;
+ address[] memory transmitters = s_validTransmitters;
+ transmitters[0] = signers[0];
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(1, signers, transmitters),
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: transmitters
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.InvalidConfig.selector, MultiOCR3Base.InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS
+ )
+ );
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_RepeatSignerAddress_Revert() public {
+ address[] memory signers = s_validSigners;
+ address[] memory transmitters = s_validTransmitters;
+ signers[1] = signers[0];
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(1, signers, transmitters),
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: transmitters
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.InvalidConfig.selector, MultiOCR3Base.InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS
+ )
+ );
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_SignerCannotBeZeroAddress_Revert() public {
+ uint8 F = 1;
+ address[] memory signers = new address[](3 * F + 1);
+ address[] memory transmitters = new address[](3 * F + 1);
+ for (uint160 i = 0; i < 3 * F + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ signers[0] = address(0);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(F, signers, transmitters),
+ F: F,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: transmitters
+ });
+
+ vm.expectRevert(MultiOCR3Base.OracleCannotBeZeroAddress.selector);
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_TransmitterCannotBeZeroAddress_Revert() public {
+ uint8 F = 1;
+ address[] memory signers = new address[](3 * F + 1);
+ address[] memory transmitters = new address[](3 * F + 1);
+ for (uint160 i = 0; i < 3 * F + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ transmitters[0] = address(0);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(F, signers, transmitters),
+ F: F,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: transmitters
+ });
+
+ vm.expectRevert(MultiOCR3Base.OracleCannotBeZeroAddress.selector);
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_StaticConfigChange_Revert() public {
+ uint8 F = 1;
+
+ _assertOCRConfigUnconfigured(s_multiOCR3.latestConfigDetails(0));
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(F, s_validSigners, s_validTransmitters),
+ F: F,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+
+ // signature verification cannot change
+ ocrConfigs[0].isSignatureVerificationEnabled = false;
+ vm.expectRevert(abi.encodeWithSelector(MultiOCR3Base.StaticConfigCannotBeChanged.selector, 0));
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_FTooHigh_Revert() public {
+ address[] memory signers = new address[](0);
+ address[] memory transmitters = new address[](0);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(1, signers, transmitters),
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: transmitters
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(MultiOCR3Base.InvalidConfig.selector, MultiOCR3Base.InvalidConfigErrorType.F_TOO_HIGH)
+ );
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_FMustBePositive_Revert() public {
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(0, s_validSigners, s_validTransmitters),
+ F: 0,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.InvalidConfig.selector, MultiOCR3Base.InvalidConfigErrorType.F_MUST_BE_POSITIVE
+ )
+ );
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_TooManyTransmitters_Revert() public {
+ address[] memory signers = new address[](0);
+ address[] memory transmitters = new address[](32);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(10, signers, transmitters),
+ F: 10,
+ isSignatureVerificationEnabled: false,
+ signers: signers,
+ transmitters: transmitters
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.InvalidConfig.selector, MultiOCR3Base.InvalidConfigErrorType.TOO_MANY_TRANSMITTERS
+ )
+ );
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+
+ function test_TooManySigners_Revert() public {
+ address[] memory signers = new address[](32);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: 0,
+ configDigest: _getBasicConfigDigest(1, signers, s_validTransmitters),
+ F: 1,
+ isSignatureVerificationEnabled: true,
+ signers: signers,
+ transmitters: s_validTransmitters
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ MultiOCR3Base.InvalidConfig.selector, MultiOCR3Base.InvalidConfigErrorType.TOO_MANY_SIGNERS
+ )
+ );
+ s_multiOCR3.setOCR3Configs(ocrConfigs);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/ocr/MultiOCR3BaseSetup.t.sol b/contracts/src/v0.8/ccip/test/ocr/MultiOCR3BaseSetup.t.sol
new file mode 100644
index 00000000000..6f6219bc9b0
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/ocr/MultiOCR3BaseSetup.t.sol
@@ -0,0 +1,113 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {MultiOCR3Base} from "../../ocr/MultiOCR3Base.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {MultiOCR3Helper} from "../helpers/MultiOCR3Helper.sol";
+
+contract MultiOCR3BaseSetup is BaseTest {
+ // Signer private keys used for these test
+ uint256 internal constant PRIVATE0 = 0x7b2e97fe057e6de99d6872a2ef2abf52c9b4469bc848c2465ac3fcd8d336e81d;
+
+ address[] internal s_validSigners;
+ address[] internal s_validTransmitters;
+ uint256[] internal s_validSignerKeys;
+
+ address[] internal s_partialSigners;
+ address[] internal s_partialTransmitters;
+ uint256[] internal s_partialSignerKeys;
+
+ address[] internal s_emptySigners;
+
+ bytes internal constant REPORT = abi.encode("testReport");
+ MultiOCR3Helper internal s_multiOCR3;
+
+ function setUp() public virtual override {
+ BaseTest.setUp();
+
+ uint160 numSigners = 7;
+ s_validSignerKeys = new uint256[](numSigners);
+ s_validSigners = new address[](numSigners);
+ s_validTransmitters = new address[](numSigners);
+
+ for (uint160 i; i < numSigners; ++i) {
+ s_validTransmitters[i] = address(4 + i);
+ s_validSignerKeys[i] = PRIVATE0 + i;
+ s_validSigners[i] = vm.addr(s_validSignerKeys[i]);
+ }
+
+ s_partialSigners = new address[](4);
+ s_partialSignerKeys = new uint256[](4);
+ s_partialTransmitters = new address[](4);
+ for (uint256 i; i < s_partialSigners.length; ++i) {
+ s_partialSigners[i] = s_validSigners[i];
+ s_partialSignerKeys[i] = s_validSignerKeys[i];
+ s_partialTransmitters[i] = s_validTransmitters[i];
+ }
+
+ s_emptySigners = new address[](0);
+
+ s_multiOCR3 = new MultiOCR3Helper();
+ }
+
+ /// @dev returns a mock config digest with config digest computation logic similar to OCR2Base
+ function _getBasicConfigDigest(
+ uint8 F,
+ address[] memory signers,
+ address[] memory transmitters
+ ) internal view returns (bytes32) {
+ bytes memory configBytes = abi.encode("");
+ uint256 configVersion = 1;
+
+ uint256 h = uint256(
+ keccak256(
+ abi.encode(
+ block.chainid, address(s_multiOCR3), signers, transmitters, F, configBytes, configVersion, configBytes
+ )
+ )
+ );
+ uint256 prefixMask = type(uint256).max << (256 - 16); // 0xFFFF00..00
+ uint256 prefix = 0x0001 << (256 - 16); // 0x000100..00
+ return bytes32((prefix & prefixMask) | (h & ~prefixMask));
+ }
+
+ function _assertOCRConfigEquality(
+ MultiOCR3Base.OCRConfig memory configA,
+ MultiOCR3Base.OCRConfig memory configB
+ ) internal pure {
+ vm.assertEq(configA.configInfo.configDigest, configB.configInfo.configDigest);
+ vm.assertEq(configA.configInfo.F, configB.configInfo.F);
+ vm.assertEq(configA.configInfo.n, configB.configInfo.n);
+ vm.assertEq(configA.configInfo.isSignatureVerificationEnabled, configB.configInfo.isSignatureVerificationEnabled);
+
+ vm.assertEq(configA.signers, configB.signers);
+ vm.assertEq(configA.transmitters, configB.transmitters);
+ }
+
+ function _assertOCRConfigUnconfigured(MultiOCR3Base.OCRConfig memory config) internal pure {
+ assertEq(config.configInfo.configDigest, bytes32(""));
+ assertEq(config.signers.length, 0);
+ assertEq(config.transmitters.length, 0);
+ }
+
+ function _getSignaturesForDigest(
+ uint256[] memory signerPrivateKeys,
+ bytes memory report,
+ bytes32[3] memory reportContext,
+ uint8 signatureCount
+ ) internal pure returns (bytes32[] memory rs, bytes32[] memory ss, uint8[] memory vs, bytes32 rawVs) {
+ rs = new bytes32[](signatureCount);
+ ss = new bytes32[](signatureCount);
+ vs = new uint8[](signatureCount);
+
+ bytes32 reportDigest = keccak256(abi.encodePacked(keccak256(report), reportContext));
+
+ // Calculate signatures
+ for (uint256 i; i < signatureCount; ++i) {
+ (vs[i], rs[i], ss[i]) = vm.sign(signerPrivateKeys[i], reportDigest);
+ rawVs = rawVs | (bytes32(bytes1(vs[i] - 27)) >> (8 * i));
+ }
+
+ return (rs, ss, vs, rawVs);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/ocr/OCR2Base.t.sol b/contracts/src/v0.8/ccip/test/ocr/OCR2Base.t.sol
new file mode 100644
index 00000000000..7511ebdffae
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/ocr/OCR2Base.t.sol
@@ -0,0 +1,305 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OCR2Abstract} from "../../ocr/OCR2Abstract.sol";
+import {OCR2Base} from "../../ocr/OCR2Base.sol";
+import {OCR2Helper} from "../helpers/OCR2Helper.sol";
+import {OCR2Setup} from "./OCR2Setup.t.sol";
+
+contract OCR2BaseSetup is OCR2Setup {
+ OCR2Helper internal s_OCR2Base;
+
+ bytes32[] internal s_rs;
+ bytes32[] internal s_ss;
+ bytes32 internal s_rawVs;
+
+ uint40 internal s_latestEpochAndRound;
+
+ function setUp() public virtual override {
+ OCR2Setup.setUp();
+ s_OCR2Base = new OCR2Helper();
+
+ bytes32 testReportDigest = getTestReportDigest();
+
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](2);
+ uint8[] memory vs = new uint8[](2);
+
+ // Calculate signatures
+ (vs[0], rs[0], ss[0]) = vm.sign(PRIVATE0, testReportDigest);
+ (vs[1], rs[1], ss[1]) = vm.sign(PRIVATE1, testReportDigest);
+
+ s_rs = rs;
+ s_ss = ss;
+ s_rawVs = bytes32(bytes1(vs[0] - 27)) | (bytes32(bytes1(vs[1] - 27)) >> 8);
+ }
+
+ function getBasicConfigDigest(uint8 f, uint64 currentConfigCount) internal view returns (bytes32) {
+ bytes memory configBytes = abi.encode("");
+ return s_OCR2Base.configDigestFromConfigData(
+ block.chainid,
+ address(s_OCR2Base),
+ currentConfigCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ }
+
+ function getTestReportDigest() internal view returns (bytes32) {
+ bytes32 configDigest = getBasicConfigDigest(s_f, 0);
+ bytes32[3] memory reportContext = [configDigest, configDigest, configDigest];
+ return keccak256(abi.encodePacked(keccak256(REPORT), reportContext));
+ }
+
+ function getBasicConfigDigest(
+ address contractAddress,
+ uint8 f,
+ uint64 currentConfigCount,
+ bytes memory onchainConfig
+ ) internal view returns (bytes32) {
+ return s_OCR2Base.configDigestFromConfigData(
+ block.chainid,
+ contractAddress,
+ currentConfigCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ f,
+ onchainConfig,
+ s_offchainConfigVersion,
+ abi.encode("")
+ );
+ }
+}
+
+contract OCR2Base_transmit is OCR2BaseSetup {
+ bytes32 internal s_configDigest;
+
+ function setUp() public virtual override {
+ OCR2BaseSetup.setUp();
+ bytes memory configBytes = abi.encode("");
+
+ s_configDigest = getBasicConfigDigest(s_f, 0);
+ s_OCR2Base.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, configBytes, s_offchainConfigVersion, configBytes
+ );
+ }
+
+ function test_Transmit2SignersSuccess_gas() public {
+ vm.pauseGasMetering();
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.resumeGasMetering();
+ s_OCR2Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ // Reverts
+
+ function test_ForkedChain_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ uint256 chain1 = block.chainid;
+ uint256 chain2 = chain1 + 1;
+ vm.chainId(chain2);
+ vm.expectRevert(abi.encodeWithSelector(OCR2Base.ForkedChain.selector, chain1, chain2));
+ vm.startPrank(s_valid_transmitters[0]);
+ s_OCR2Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ function test_WrongNumberOfSignatures_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ vm.expectRevert(OCR2Base.WrongNumberOfSignatures.selector);
+ s_OCR2Base.transmit(reportContext, REPORT, new bytes32[](0), new bytes32[](0), s_rawVs);
+ }
+
+ function test_ConfigDigestMismatch_Revert() public {
+ bytes32 configDigest;
+ bytes32[3] memory reportContext = [configDigest, configDigest, configDigest];
+
+ vm.expectRevert(abi.encodeWithSelector(OCR2Base.ConfigDigestMismatch.selector, s_configDigest, configDigest));
+ s_OCR2Base.transmit(reportContext, REPORT, new bytes32[](0), new bytes32[](0), s_rawVs);
+ }
+
+ function test_SignatureOutOfRegistration_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](1);
+
+ vm.expectRevert(OCR2Base.SignaturesOutOfRegistration.selector);
+ s_OCR2Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+
+ function test_UnAuthorizedTransmitter_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](2);
+
+ vm.expectRevert(OCR2Base.UnauthorizedTransmitter.selector);
+ s_OCR2Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+
+ function test_NonUniqueSignature_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = s_rs;
+ bytes32[] memory ss = s_ss;
+
+ rs[1] = rs[0];
+ ss[1] = ss[0];
+ // Need to reset the rawVs to be valid
+ bytes32 rawVs = bytes32(bytes1(uint8(28) - 27)) | (bytes32(bytes1(uint8(28) - 27)) >> 8);
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.expectRevert(OCR2Base.NonUniqueSignatures.selector);
+ s_OCR2Base.transmit(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function test_UnauthorizedSigner_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = new bytes32[](2);
+ rs[0] = s_configDigest;
+ bytes32[] memory ss = rs;
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.expectRevert(OCR2Base.UnauthorizedSigner.selector);
+ s_OCR2Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+}
+
+contract OCR2Base_setOCR2Config is OCR2BaseSetup {
+ function test_SetConfigSuccess_gas() public {
+ vm.pauseGasMetering();
+ bytes memory configBytes = abi.encode("");
+ uint32 configCount = 0;
+
+ bytes32 configDigest = getBasicConfigDigest(s_f, configCount++);
+
+ address[] memory transmitters = s_OCR2Base.getTransmitters();
+ assertEq(0, transmitters.length);
+
+ vm.expectEmit();
+ emit OCR2Abstract.ConfigSet(
+ 0,
+ configDigest,
+ configCount,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+
+ s_OCR2Base.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, configBytes, s_offchainConfigVersion, configBytes
+ );
+
+ transmitters = s_OCR2Base.getTransmitters();
+ assertEq(s_valid_transmitters, transmitters);
+
+ configDigest = getBasicConfigDigest(s_f, configCount++);
+
+ vm.expectEmit();
+ emit OCR2Abstract.ConfigSet(
+ uint32(block.number),
+ configDigest,
+ configCount,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ vm.resumeGasMetering();
+ s_OCR2Base.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, configBytes, s_offchainConfigVersion, configBytes
+ );
+ }
+
+ // Reverts
+ function test_RepeatAddress_Revert() public {
+ address[] memory signers = new address[](10);
+ signers[0] = address(1245678);
+ address[] memory transmitters = new address[](10);
+ transmitters[0] = signers[0];
+
+ vm.expectRevert(
+ abi.encodeWithSelector(OCR2Base.InvalidConfig.selector, OCR2Base.InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS)
+ );
+ s_OCR2Base.setOCR2Config(signers, transmitters, 2, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_SingerCannotBeZeroAddress_Revert() public {
+ uint256 f = 1;
+ address[] memory signers = new address[](3 * f + 1);
+ address[] memory transmitters = new address[](3 * f + 1);
+ for (uint160 i = 0; i < 3 * f + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ signers[0] = address(0);
+
+ vm.expectRevert(OCR2Base.OracleCannotBeZeroAddress.selector);
+ s_OCR2Base.setOCR2Config(signers, transmitters, uint8(f), abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_TransmitterCannotBeZeroAddress_Revert() public {
+ uint256 f = 1;
+ address[] memory signers = new address[](3 * f + 1);
+ address[] memory transmitters = new address[](3 * f + 1);
+ for (uint160 i = 0; i < 3 * f + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ transmitters[0] = address(0);
+
+ vm.expectRevert(OCR2Base.OracleCannotBeZeroAddress.selector);
+ s_OCR2Base.setOCR2Config(signers, transmitters, uint8(f), abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_OracleOutOfRegister_Revert() public {
+ address[] memory signers = new address[](10);
+ address[] memory transmitters = new address[](0);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ OCR2Base.InvalidConfig.selector, OCR2Base.InvalidConfigErrorType.NUM_SIGNERS_NOT_NUM_TRANSMITTERS
+ )
+ );
+ s_OCR2Base.setOCR2Config(signers, transmitters, 2, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_FTooHigh_Revert() public {
+ address[] memory signers = new address[](0);
+ uint8 f = 1;
+
+ vm.expectRevert(abi.encodeWithSelector(OCR2Base.InvalidConfig.selector, OCR2Base.InvalidConfigErrorType.F_TOO_HIGH));
+ s_OCR2Base.setOCR2Config(signers, new address[](0), f, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_FMustBePositive_Revert() public {
+ uint8 f = 0;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(OCR2Base.InvalidConfig.selector, OCR2Base.InvalidConfigErrorType.F_MUST_BE_POSITIVE)
+ );
+ s_OCR2Base.setOCR2Config(new address[](0), new address[](0), f, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_TooManySigners_Revert() public {
+ address[] memory signers = new address[](32);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(OCR2Base.InvalidConfig.selector, OCR2Base.InvalidConfigErrorType.TOO_MANY_SIGNERS)
+ );
+ s_OCR2Base.setOCR2Config(signers, new address[](0), 0, abi.encode(""), 100, abi.encode(""));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/ocr/OCR2BaseNoChecks.t.sol b/contracts/src/v0.8/ccip/test/ocr/OCR2BaseNoChecks.t.sol
new file mode 100644
index 00000000000..fd4cf3fc9e7
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/ocr/OCR2BaseNoChecks.t.sol
@@ -0,0 +1,208 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OCR2BaseNoChecks} from "../../ocr/OCR2BaseNoChecks.sol";
+import {OCR2NoChecksHelper} from "../helpers/OCR2NoChecksHelper.sol";
+import {OCR2Setup} from "./OCR2Setup.t.sol";
+
+contract OCR2BaseNoChecksSetup is OCR2Setup {
+ OCR2NoChecksHelper internal s_OCR2Base;
+
+ bytes32[] internal s_rs;
+ bytes32[] internal s_ss;
+ bytes32 internal s_rawVs;
+
+ function setUp() public virtual override {
+ OCR2Setup.setUp();
+ s_OCR2Base = new OCR2NoChecksHelper();
+ }
+
+ function getBasicConfigDigest(uint8 f, uint64 currentConfigCount) internal view returns (bytes32) {
+ bytes memory configBytes = abi.encode("");
+ return s_OCR2Base.configDigestFromConfigData(
+ block.chainid,
+ address(s_OCR2Base),
+ currentConfigCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ }
+}
+
+contract OCR2BaseNoChecks_transmit is OCR2BaseNoChecksSetup {
+ bytes32 internal s_configDigest;
+
+ function setUp() public virtual override {
+ OCR2BaseNoChecksSetup.setUp();
+ bytes memory configBytes = abi.encode("");
+
+ s_configDigest = getBasicConfigDigest(s_f, 0);
+ s_OCR2Base.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, configBytes, s_offchainConfigVersion, configBytes
+ );
+ }
+
+ function test_TransmitSuccess_gas() public {
+ vm.pauseGasMetering();
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.resumeGasMetering();
+ s_OCR2Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ // Reverts
+
+ function test_ForkedChain_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ uint256 chain1 = block.chainid;
+ uint256 chain2 = chain1 + 1;
+ vm.chainId(chain2);
+ vm.expectRevert(abi.encodeWithSelector(OCR2BaseNoChecks.ForkedChain.selector, chain1, chain2));
+ vm.startPrank(s_valid_transmitters[0]);
+ s_OCR2Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ function test_ConfigDigestMismatch_Revert() public {
+ bytes32 configDigest;
+
+ bytes32[3] memory reportContext = [configDigest, configDigest, configDigest];
+
+ vm.expectRevert(
+ abi.encodeWithSelector(OCR2BaseNoChecks.ConfigDigestMismatch.selector, s_configDigest, configDigest)
+ );
+ s_OCR2Base.transmit(reportContext, REPORT, new bytes32[](0), new bytes32[](0), s_rawVs);
+ }
+
+ function test_UnAuthorizedTransmitter_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = new bytes32[](3);
+ bytes32[] memory ss = new bytes32[](3);
+
+ vm.expectRevert(OCR2BaseNoChecks.UnauthorizedTransmitter.selector);
+ s_OCR2Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+}
+
+contract OCR2BaseNoChecks_setOCR2Config is OCR2BaseNoChecksSetup {
+ event ConfigSet(
+ uint32 previousConfigBlockNumber,
+ bytes32 configDigest,
+ uint64 configCount,
+ address[] signers,
+ address[] transmitters,
+ uint8 f,
+ bytes onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes offchainConfig
+ );
+
+ function test_SetConfigSuccess_gas() public {
+ vm.pauseGasMetering();
+ bytes memory configBytes = abi.encode("");
+ uint32 configCount = 0;
+
+ bytes32 configDigest = getBasicConfigDigest(s_f, configCount++);
+
+ address[] memory transmitters = s_OCR2Base.getTransmitters();
+ assertEq(0, transmitters.length);
+
+ vm.expectEmit();
+ emit ConfigSet(
+ 0,
+ configDigest,
+ configCount,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+
+ s_OCR2Base.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, configBytes, s_offchainConfigVersion, configBytes
+ );
+
+ transmitters = s_OCR2Base.getTransmitters();
+ assertEq(s_valid_transmitters, transmitters);
+
+ configDigest = getBasicConfigDigest(s_f, configCount++);
+
+ vm.expectEmit();
+ emit ConfigSet(
+ uint32(block.number),
+ configDigest,
+ configCount,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ vm.resumeGasMetering();
+ s_OCR2Base.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, configBytes, s_offchainConfigVersion, configBytes
+ );
+ }
+
+ // Reverts
+ function test_RepeatAddress_Revert() public {
+ address[] memory signers = new address[](4);
+ address[] memory transmitters = new address[](4);
+ transmitters[0] = address(1245678);
+ transmitters[1] = address(1245678);
+ transmitters[2] = address(1245678);
+ transmitters[3] = address(1245678);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ OCR2BaseNoChecks.InvalidConfig.selector, OCR2BaseNoChecks.InvalidConfigErrorType.REPEATED_ORACLE_ADDRESS
+ )
+ );
+ s_OCR2Base.setOCR2Config(signers, transmitters, 1, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_FMustBePositive_Revert() public {
+ uint8 f = 0;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ OCR2BaseNoChecks.InvalidConfig.selector, OCR2BaseNoChecks.InvalidConfigErrorType.F_MUST_BE_POSITIVE
+ )
+ );
+ s_OCR2Base.setOCR2Config(new address[](0), new address[](0), f, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_TransmitterCannotBeZeroAddress_Revert() public {
+ uint256 f = 1;
+ address[] memory signers = new address[](3 * f + 1);
+ address[] memory transmitters = new address[](3 * f + 1);
+ for (uint160 i = 0; i < 3 * f + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ transmitters[0] = address(0);
+
+ vm.expectRevert(OCR2BaseNoChecks.OracleCannotBeZeroAddress.selector);
+ s_OCR2Base.setOCR2Config(signers, transmitters, uint8(f), abi.encode(""), 100, abi.encode(""));
+ }
+
+ function test_TooManyTransmitter_Revert() public {
+ address[] memory transmitters = new address[](100);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ OCR2BaseNoChecks.InvalidConfig.selector, OCR2BaseNoChecks.InvalidConfigErrorType.TOO_MANY_TRANSMITTERS
+ )
+ );
+ s_OCR2Base.setOCR2Config(new address[](0), transmitters, 0, abi.encode(""), 100, abi.encode(""));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/ocr/OCR2Setup.t.sol b/contracts/src/v0.8/ccip/test/ocr/OCR2Setup.t.sol
new file mode 100644
index 00000000000..e4be8ffa29b
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/ocr/OCR2Setup.t.sol
@@ -0,0 +1,31 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Test} from "forge-std/Test.sol";
+
+contract OCR2Setup is Test {
+ uint256 internal constant PRIVATE0 = 0x7b2e97fe057e6de99d6872a2ef2abf52c9b4469bc848c2465ac3fcd8d336e81d;
+ uint256 internal constant PRIVATE1 = 0xab56160806b05ef1796789248e1d7f34a6465c5280899159d645218cd216cee6;
+ uint256 internal constant PRIVATE2 = 0x6ec7caa8406a49b76736602810e0a2871959fbbb675e23a8590839e4717f1f7f;
+ uint256 internal constant PRIVATE3 = 0x80f14b11da94ae7f29d9a7713ea13dc838e31960a5c0f2baf45ed458947b730a;
+
+ address[] internal s_valid_signers;
+ address[] internal s_valid_transmitters;
+
+ uint64 internal constant s_offchainConfigVersion = 3;
+ uint8 internal constant s_f = 1;
+ bytes internal constant REPORT = abi.encode("testReport");
+
+ function setUp() public virtual {
+ s_valid_transmitters = new address[](4);
+ for (uint160 i = 0; i < 4; ++i) {
+ s_valid_transmitters[i] = address(4 + i);
+ }
+
+ s_valid_signers = new address[](4);
+ s_valid_signers[0] = vm.addr(PRIVATE0); //0xc110458BE52CaA6bB68E66969C3218A4D9Db0211
+ s_valid_signers[1] = vm.addr(PRIVATE1); //0xc110a19c08f1da7F5FfB281dc93630923F8E3719
+ s_valid_signers[2] = vm.addr(PRIVATE2); //0xc110fdF6e8fD679C7Cc11602d1cd829211A18e9b
+ s_valid_signers[3] = vm.addr(PRIVATE3); //0xc11028017c9b445B6bF8aE7da951B5cC28B326C0
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMMultiOffRamp.t.sol b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMMultiOffRamp.t.sol
new file mode 100644
index 00000000000..43899cbfd69
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMMultiOffRamp.t.sol
@@ -0,0 +1,3429 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ICommitStore} from "../../interfaces/ICommitStore.sol";
+import {IMessageInterceptor} from "../../interfaces/IMessageInterceptor.sol";
+import {IPriceRegistry} from "../../interfaces/IPriceRegistry.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+import {ITokenAdminRegistry} from "../../interfaces/ITokenAdminRegistry.sol";
+
+import {CallWithExactGas} from "../../../shared/call/CallWithExactGas.sol";
+import {NonceManager} from "../../NonceManager.sol";
+import {PriceRegistry} from "../../PriceRegistry.sol";
+import {RMN} from "../../RMN.sol";
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {MerkleMultiProof} from "../../libraries/MerkleMultiProof.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {MultiOCR3Base} from "../../ocr/MultiOCR3Base.sol";
+import {EVM2EVMMultiOffRamp} from "../../offRamp/EVM2EVMMultiOffRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {EVM2EVMMultiOffRampHelper} from "../helpers/EVM2EVMMultiOffRampHelper.sol";
+import {EVM2EVMOffRampHelper} from "../helpers/EVM2EVMOffRampHelper.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {MessageInterceptorHelper} from "../helpers/MessageInterceptorHelper.sol";
+import {ConformingReceiver} from "../helpers/receivers/ConformingReceiver.sol";
+import {MaybeRevertMessageReceiver} from "../helpers/receivers/MaybeRevertMessageReceiver.sol";
+import {MaybeRevertMessageReceiverNo165} from "../helpers/receivers/MaybeRevertMessageReceiverNo165.sol";
+import {ReentrancyAbuserMultiRamp} from "../helpers/receivers/ReentrancyAbuserMultiRamp.sol";
+import {EVM2EVMMultiOffRampSetup} from "./EVM2EVMMultiOffRampSetup.t.sol";
+import {Vm} from "forge-std/Vm.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract EVM2EVMMultiOffRamp_constructor is EVM2EVMMultiOffRampSetup {
+ function test_Constructor_Success() public {
+ EVM2EVMMultiOffRamp.StaticConfig memory staticConfig = EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(s_inboundNonceManager)
+ });
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig =
+ _generateDynamicMultiOffRampConfig(address(s_destRouter), address(s_priceRegistry));
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](2);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: ON_RAMP_ADDRESS_1,
+ isEnabled: true
+ });
+ sourceChainConfigs[1] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1 + 1,
+ onRamp: ON_RAMP_ADDRESS_2,
+ isEnabled: true
+ });
+
+ EVM2EVMMultiOffRamp.SourceChainConfig memory expectedSourceChainConfig1 =
+ EVM2EVMMultiOffRamp.SourceChainConfig({isEnabled: true, minSeqNr: 1, onRamp: sourceChainConfigs[0].onRamp});
+
+ EVM2EVMMultiOffRamp.SourceChainConfig memory expectedSourceChainConfig2 =
+ EVM2EVMMultiOffRamp.SourceChainConfig({isEnabled: true, minSeqNr: 1, onRamp: sourceChainConfigs[1].onRamp});
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.StaticConfigSet(staticConfig);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.DynamicConfigSet(dynamicConfig);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainSelectorAdded(SOURCE_CHAIN_SELECTOR_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainConfigSet(SOURCE_CHAIN_SELECTOR_1, expectedSourceChainConfig1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainSelectorAdded(SOURCE_CHAIN_SELECTOR_1 + 1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainConfigSet(SOURCE_CHAIN_SELECTOR_1 + 1, expectedSourceChainConfig2);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(staticConfig, dynamicConfig, sourceChainConfigs);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Execution),
+ configDigest: s_configDigestExec,
+ F: s_F,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ // Static config
+ EVM2EVMMultiOffRamp.StaticConfig memory gotStaticConfig = s_offRamp.getStaticConfig();
+ assertEq(staticConfig.chainSelector, gotStaticConfig.chainSelector);
+ assertEq(staticConfig.rmnProxy, gotStaticConfig.rmnProxy);
+ assertEq(staticConfig.tokenAdminRegistry, gotStaticConfig.tokenAdminRegistry);
+
+ // Dynamic config
+ EVM2EVMMultiOffRamp.DynamicConfig memory gotDynamicConfig = s_offRamp.getDynamicConfig();
+ _assertSameConfig(dynamicConfig, gotDynamicConfig);
+
+ // OCR Config
+ MultiOCR3Base.OCRConfig memory expectedOCRConfig = MultiOCR3Base.OCRConfig({
+ configInfo: MultiOCR3Base.ConfigInfo({
+ configDigest: ocrConfigs[0].configDigest,
+ F: ocrConfigs[0].F,
+ n: 0,
+ isSignatureVerificationEnabled: ocrConfigs[0].isSignatureVerificationEnabled
+ }),
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ MultiOCR3Base.OCRConfig memory gotOCRConfig = s_offRamp.latestConfigDetails(uint8(Internal.OCRPluginType.Execution));
+ _assertOCRConfigEquality(expectedOCRConfig, gotOCRConfig);
+
+ _assertSourceChainConfigEquality(
+ s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR_1), expectedSourceChainConfig1
+ );
+ _assertSourceChainConfigEquality(
+ s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR_1 + 1), expectedSourceChainConfig2
+ );
+
+ // OffRamp initial values
+ assertEq("EVM2EVMMultiOffRamp 1.6.0-dev", s_offRamp.typeAndVersion());
+ assertEq(OWNER, s_offRamp.owner());
+ assertEq(0, s_offRamp.getLatestPriceSequenceNumber());
+ }
+
+ // Revert
+ function test_ZeroOnRampAddress_Revert() public {
+ uint64[] memory sourceChainSelectors = new uint64[](1);
+ sourceChainSelectors[0] = SOURCE_CHAIN_SELECTOR_1;
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: new bytes(0),
+ isEnabled: true
+ });
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(s_inboundNonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+ }
+
+ function test_SourceChainSelector_Revert() public {
+ uint64[] memory sourceChainSelectors = new uint64[](1);
+ sourceChainSelectors[0] = SOURCE_CHAIN_SELECTOR_1;
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] =
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs({sourceChainSelector: 0, onRamp: ON_RAMP_ADDRESS_1, isEnabled: true});
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroChainSelectorNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(s_inboundNonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+ }
+
+ function test_ZeroRMNProxy_Revert() public {
+ uint64[] memory sourceChainSelectors = new uint64[](1);
+ sourceChainSelectors[0] = SOURCE_CHAIN_SELECTOR_1;
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: ZERO_ADDRESS,
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(s_inboundNonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+ }
+
+ function test_ZeroChainSelector_Revert() public {
+ uint64[] memory sourceChainSelectors = new uint64[](1);
+ sourceChainSelectors[0] = SOURCE_CHAIN_SELECTOR_1;
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroChainSelectorNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: 0,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(s_inboundNonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+ }
+
+ function test_ZeroTokenAdminRegistry_Revert() public {
+ uint64[] memory sourceChainSelectors = new uint64[](1);
+ sourceChainSelectors[0] = SOURCE_CHAIN_SELECTOR_1;
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: ZERO_ADDRESS,
+ nonceManager: address(s_inboundNonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+ }
+
+ function test_ZeroNonceManager_Revert() public {
+ uint64[] memory sourceChainSelectors = new uint64[](1);
+ sourceChainSelectors[0] = SOURCE_CHAIN_SELECTOR_1;
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: ZERO_ADDRESS
+ }),
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+ }
+}
+
+contract EVM2EVMMultiOffRamp_setDynamicConfig is EVM2EVMMultiOffRampSetup {
+ function test_SetDynamicConfig_Success() public {
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig =
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry));
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.DynamicConfigSet(dynamicConfig);
+
+ s_offRamp.setDynamicConfig(dynamicConfig);
+
+ EVM2EVMMultiOffRamp.DynamicConfig memory newConfig = s_offRamp.getDynamicConfig();
+ _assertSameConfig(dynamicConfig, newConfig);
+ }
+
+ function test_SetDynamicConfigWithValidator_Success() public {
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig =
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry));
+ dynamicConfig.messageValidator = address(s_inboundMessageValidator);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.DynamicConfigSet(dynamicConfig);
+
+ s_offRamp.setDynamicConfig(dynamicConfig);
+
+ EVM2EVMMultiOffRamp.DynamicConfig memory newConfig = s_offRamp.getDynamicConfig();
+ _assertSameConfig(dynamicConfig, newConfig);
+ }
+
+ // Reverts
+
+ function test_NonOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig =
+ _generateDynamicMultiOffRampConfig(USER_3, address(s_priceRegistry));
+
+ vm.expectRevert("Only callable by owner");
+
+ s_offRamp.setDynamicConfig(dynamicConfig);
+ }
+
+ function test_RouterZeroAddress_Revert() public {
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig =
+ _generateDynamicMultiOffRampConfig(ZERO_ADDRESS, address(s_priceRegistry));
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp.setDynamicConfig(dynamicConfig);
+ }
+
+ function test_PriceRegistryZeroAddress_Revert() public {
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig = _generateDynamicMultiOffRampConfig(USER_3, ZERO_ADDRESS);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp.setDynamicConfig(dynamicConfig);
+ }
+}
+
+contract EVM2EVMMultiOffRamp_ccipReceive is EVM2EVMMultiOffRampSetup {
+ // Reverts
+
+ function test_Reverts() public {
+ Client.Any2EVMMessage memory message =
+ _convertToGeneralMessage(_generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1));
+ vm.expectRevert();
+ s_offRamp.ccipReceive(message);
+ }
+}
+
+contract EVM2EVMMultiOffRamp_executeSingleReport is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_3, 1);
+ }
+
+ function test_SingleMessageNoTokens_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+
+ messages[0].header.nonce++;
+ messages[0].header.sequenceNumber++;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ uint64 nonceBefore = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender);
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ assertGt(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender), nonceBefore);
+ }
+
+ function test_SingleMessageNoTokensUnordered_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].header.nonce = 0;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ // Nonce never increments on unordered messages.
+ uint64 nonceBefore = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender);
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ assertEq(
+ s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender),
+ nonceBefore,
+ "nonce must remain unchanged on unordered messages"
+ );
+
+ messages[0].header.sequenceNumber++;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ // Nonce never increments on unordered messages.
+ nonceBefore = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender);
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ assertEq(
+ s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender),
+ nonceBefore,
+ "nonce must remain unchanged on unordered messages"
+ );
+ }
+
+ function test_SingleMessageNoTokensOtherChain_Success() public {
+ Internal.Any2EVMRampMessage[] memory messagesChain1 =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messagesChain1), new uint256[](0)
+ );
+
+ uint64 nonceChain1 = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messagesChain1[0].sender);
+ assertGt(nonceChain1, 0);
+
+ Internal.Any2EVMRampMessage[] memory messagesChain2 =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_3, ON_RAMP_ADDRESS_3);
+ assertEq(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_3, messagesChain2[0].sender), 0);
+
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_3, messagesChain2), new uint256[](0)
+ );
+ assertGt(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_3, messagesChain2[0].sender), 0);
+
+ // Other chain's nonce is unaffected
+ assertEq(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messagesChain1[0].sender), nonceChain1);
+ }
+
+ function test_ReceiverError_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ bytes memory realError1 = new bytes(2);
+ realError1[0] = 0xbe;
+ realError1[1] = 0xef;
+ s_reverting_receiver.setErr(realError1);
+
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, realError1)
+ )
+ );
+ // Nonce should increment on non-strict
+ assertEq(uint64(0), s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(OWNER)));
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ assertEq(uint64(1), s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(OWNER)));
+ }
+
+ function test_SkippedIncorrectNonce_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ messages[0].header.nonce++;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit NonceManager.SkippedIncorrectNonce(
+ messages[0].header.sourceChainSelector, messages[0].header.nonce, messages[0].sender
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function test_SkippedIncorrectNonceStillExecutes_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ messages[1].header.nonce++;
+ messages[1].header.messageId = Internal._hash(messages[1], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit NonceManager.SkippedIncorrectNonce(SOURCE_CHAIN_SELECTOR_1, messages[1].header.nonce, messages[1].sender);
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function test__execute_SkippedAlreadyExecutedMessage_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SkippedAlreadyExecutedMessage(SOURCE_CHAIN_SELECTOR_1, messages[0].header.sequenceNumber);
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function test__execute_SkippedAlreadyExecutedMessageUnordered_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].header.nonce = 0;
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SkippedAlreadyExecutedMessage(SOURCE_CHAIN_SELECTOR_1, messages[0].header.sequenceNumber);
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ // Send a message to a contract that does not implement the CCIPReceiver interface
+ // This should execute successfully.
+ function test_SingleMessageToNonCCIPReceiver_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ MaybeRevertMessageReceiverNo165 newReceiver = new MaybeRevertMessageReceiverNo165(true);
+ messages[0].receiver = address(newReceiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function test_SingleMessagesNoTokensSuccess_gas() public {
+ vm.pauseGasMetering();
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ Internal.ExecutionReportSingleChain memory report = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.resumeGasMetering();
+ s_offRamp.executeSingleReport(report, new uint256[](0));
+ }
+
+ function test_TwoMessagesWithTokensSuccess_gas() public {
+ vm.pauseGasMetering();
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ // Set message 1 to use another receiver to simulate more fair gas costs
+ messages[1].receiver = address(s_secondary_receiver);
+ messages[1].header.messageId = Internal._hash(messages[1], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[1].header.sequenceNumber,
+ messages[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ Internal.ExecutionReportSingleChain memory report = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.resumeGasMetering();
+ s_offRamp.executeSingleReport(report, new uint256[](0));
+ }
+
+ function test_TwoMessagesWithTokensAndGE_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ // Set message 1 to use another receiver to simulate more fair gas costs
+ messages[1].receiver = address(s_secondary_receiver);
+ messages[1].header.messageId = Internal._hash(messages[1], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[1].header.sequenceNumber,
+ messages[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ assertEq(uint64(0), s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(OWNER)));
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), _getGasLimitsFromMessages(messages)
+ );
+ assertEq(uint64(2), s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(OWNER)));
+ }
+
+ function test_Fuzz_InterleavingOrderedAndUnorderedMessages_Success(bool[7] memory orderings) public {
+ Internal.Any2EVMRampMessage[] memory messages = new Internal.Any2EVMRampMessage[](orderings.length);
+ // number of tokens needs to be capped otherwise we hit UnsupportedNumberOfTokens.
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](3);
+ for (uint256 i = 0; i < 3; ++i) {
+ tokenAmounts[i].token = s_sourceTokens[i % s_sourceTokens.length];
+ tokenAmounts[i].amount = 1e18;
+ }
+ uint64 expectedNonce = 0;
+ for (uint256 i = 0; i < orderings.length; ++i) {
+ messages[i] =
+ _generateAny2EVMMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, uint64(i + 1), tokenAmounts, !orderings[i]);
+ if (orderings[i]) {
+ messages[i].header.nonce = ++expectedNonce;
+ }
+ messages[i].header.messageId = Internal._hash(messages[i], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[i].header.sequenceNumber,
+ messages[i].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+ }
+
+ uint64 nonceBefore = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(OWNER));
+ assertEq(uint64(0), nonceBefore, "nonce before exec should be 0");
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), _getGasLimitsFromMessages(messages)
+ );
+ // all executions should succeed.
+ for (uint256 i = 0; i < orderings.length; ++i) {
+ assertEq(
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, messages[i].header.sequenceNumber)),
+ uint256(Internal.MessageExecutionState.SUCCESS)
+ );
+ }
+ assertEq(
+ nonceBefore + expectedNonce, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, abi.encode(OWNER))
+ );
+ }
+
+ function test_InvalidSourcePoolAddress_Success() public {
+ address fakePoolAddress = address(0x0000000000333333);
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].tokenAmounts[0].sourcePoolAddress = abi.encode(fakePoolAddress);
+
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+ messages[1].header.messageId = Internal._hash(messages[1], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.TokenHandlingError.selector,
+ abi.encodeWithSelector(TokenPool.InvalidSourcePoolAddress.selector, abi.encode(fakePoolAddress))
+ )
+ );
+
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function test_WithCurseOnAnotherSourceChain_Success() public {
+ s_mockRMN.setChainCursed(SOURCE_CHAIN_SELECTOR_2, true);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[](0)
+ );
+ }
+
+ // Reverts
+
+ function test_MismatchingDestChainSelector_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_3, ON_RAMP_ADDRESS_3);
+ messages[0].header.destChainSelector = DEST_CHAIN_SELECTOR + 1;
+
+ Internal.ExecutionReportSingleChain memory executionReport =
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.InvalidMessageDestChainSelector.selector, messages[0].header.destChainSelector
+ )
+ );
+ s_offRamp.executeSingleReport(executionReport, new uint256[](0));
+ }
+
+ function test_MismatchingOnRampRoot_Revert() public {
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 0);
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = _constructCommitReport(
+ // Root against mismatching on ramp
+ Internal._hash(messages[0], ON_RAMP_ADDRESS_3)
+ );
+ _commit(commitReport, s_latestSequenceNumber);
+
+ Internal.ExecutionReportSingleChain memory executionReport =
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.RootNotCommitted.selector, SOURCE_CHAIN_SELECTOR_1));
+ s_offRamp.executeSingleReport(executionReport, new uint256[](0));
+ }
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.CursedByRMN.selector, SOURCE_CHAIN_SELECTOR_1));
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[](0)
+ );
+ // Uncurse should succeed
+ s_mockRMN.setGlobalCursed(false);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[](0)
+ );
+ }
+
+ function test_UnhealthySingleChainCurse_Revert() public {
+ s_mockRMN.setChainCursed(SOURCE_CHAIN_SELECTOR_1, true);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.CursedByRMN.selector, SOURCE_CHAIN_SELECTOR_1));
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[](0)
+ );
+ // Uncurse should succeed
+ s_mockRMN.setChainCursed(SOURCE_CHAIN_SELECTOR_1, false);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[](0)
+ );
+ }
+
+ function test_UnexpectedTokenData_Revert() public {
+ Internal.ExecutionReportSingleChain memory report = _generateReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ );
+ report.offchainTokenData = new bytes[][](report.messages.length + 1);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.UnexpectedTokenData.selector);
+
+ s_offRamp.executeSingleReport(report, new uint256[](0));
+ }
+
+ function test_EmptyReport_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOffRamp.EmptyReport.selector);
+ s_offRamp.executeSingleReport(
+ Internal.ExecutionReportSingleChain({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ proofs: new bytes32[](0),
+ proofFlagBits: 0,
+ messages: new Internal.Any2EVMRampMessage[](0),
+ offchainTokenData: new bytes[][](0)
+ }),
+ new uint256[](0)
+ );
+ }
+
+ function test_RootNotCommitted_Revert() public {
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 0);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.RootNotCommitted.selector, SOURCE_CHAIN_SELECTOR_1));
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), _getGasLimitsFromMessages(messages)
+ );
+ }
+
+ function test_ManualExecutionNotYetEnabled_Revert() public {
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, BLOCK_TIME);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMMultiOffRamp.ManualExecutionNotYetEnabled.selector, SOURCE_CHAIN_SELECTOR_1)
+ );
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ s_offRamp.executeSingleReport(
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), _getGasLimitsFromMessages(messages)
+ );
+ }
+
+ function test_NonExistingSourceChain_Revert() public {
+ uint64 newSourceChainSelector = SOURCE_CHAIN_SELECTOR_1 + 1;
+ bytes memory newOnRamp = abi.encode(ON_RAMP_ADDRESS, 1);
+
+ Internal.Any2EVMRampMessage[] memory messages = _generateSingleBasicMessage(newSourceChainSelector, newOnRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.SourceChainNotEnabled.selector, newSourceChainSelector));
+ s_offRamp.executeSingleReport(_generateReportFromMessages(newSourceChainSelector, messages), new uint256[](0));
+ }
+
+ function test_DisabledSourceChain_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_2, ON_RAMP_ADDRESS_2);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.SourceChainNotEnabled.selector, SOURCE_CHAIN_SELECTOR_2));
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_2, messages), new uint256[](0));
+ }
+
+ function test_TokenDataMismatch_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain memory report = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ report.offchainTokenData[0] = new bytes[](messages[0].tokenAmounts.length + 1);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.TokenDataMismatch.selector, SOURCE_CHAIN_SELECTOR_1, messages[0].header.sequenceNumber
+ )
+ );
+ s_offRamp.executeSingleReport(report, new uint256[](0));
+ }
+
+ function test_RouterYULCall_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ // gas limit too high, Router's external call should revert
+ messages[0].gasLimit = 1e36;
+ messages[0].receiver = address(new ConformingReceiver(address(s_destRouter), s_destFeeToken));
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ Internal.ExecutionReportSingleChain memory executionReport =
+ _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(CallWithExactGas.NotEnoughGasForCall.selector)
+ );
+ s_offRamp.executeSingleReport(executionReport, new uint256[](0));
+ }
+
+ function test_RetryFailedMessageWithoutManualExecution_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ bytes memory realError1 = new bytes(2);
+ realError1[0] = 0xbe;
+ realError1[1] = 0xef;
+ s_reverting_receiver.setErr(realError1);
+
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, realError1)
+ )
+ );
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.AlreadyAttempted.selector, SOURCE_CHAIN_SELECTOR_1, messages[0].header.sequenceNumber
+ )
+ );
+ s_offRamp.executeSingleReport(_generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[](0));
+ }
+
+ function _constructCommitReport(bytes32 merkleRoot) internal view returns (EVM2EVMMultiOffRamp.CommitReport memory) {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: merkleRoot
+ });
+
+ return EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+ }
+}
+
+contract EVM2EVMMultiOffRamp_executeSingleMessage is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ vm.startPrank(address(s_offRamp));
+ }
+
+ function test_executeSingleMessage_NoTokens_Success() public {
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_executeSingleMessage_WithTokens_Success() public {
+ Internal.Any2EVMRampMessage memory message =
+ _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)[0];
+ bytes[] memory offchainTokenData = new bytes[](message.tokenAmounts.length);
+
+ vm.expectCall(
+ s_destPoolByToken[s_destTokens[0]],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: message.sender,
+ receiver: message.receiver,
+ amount: message.tokenAmounts[0].amount,
+ localToken: abi.decode(message.tokenAmounts[0].destTokenAddress, (address)),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ sourcePoolAddress: message.tokenAmounts[0].sourcePoolAddress,
+ sourcePoolData: message.tokenAmounts[0].extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ )
+ );
+
+ s_offRamp.executeSingleMessage(message, offchainTokenData);
+ }
+
+ function test_executeSingleMessage_WithValidation_Success() public {
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ _enableInboundMessageValidator();
+ vm.startPrank(address(s_offRamp));
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_NonContract_Success() public {
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ message.receiver = STRANGER;
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_NonContractWithTokens_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+ vm.expectEmit();
+ emit TokenPool.Released(address(s_offRamp), STRANGER, amounts[0]);
+ vm.expectEmit();
+ emit TokenPool.Minted(address(s_offRamp), STRANGER, amounts[1]);
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1, amounts);
+ message.receiver = STRANGER;
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ // Reverts
+
+ function test_TokenHandlingError_Revert() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ bytes memory errorMessage = "Random token pool issue";
+
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1, amounts);
+ s_maybeRevertingPool.setShouldRevert(errorMessage);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.TokenHandlingError.selector, errorMessage));
+
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_ZeroGasDONExecution_Revert() public {
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ message.gasLimit = 0;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.ReceiverError.selector, ""));
+
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_MessageSender_Revert() public {
+ vm.stopPrank();
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ vm.expectRevert(EVM2EVMMultiOffRamp.CanOnlySelfCall.selector);
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_executeSingleMessage_WithFailingValidation_Revert() public {
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ _enableInboundMessageValidator();
+ vm.startPrank(address(s_offRamp));
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ s_inboundMessageValidator.setMessageIdValidationState(message.header.messageId, true);
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ IMessageInterceptor.MessageValidationError.selector,
+ abi.encodeWithSelector(IMessageInterceptor.MessageValidationError.selector, bytes("Invalid message"))
+ )
+ );
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_executeSingleMessage_WithFailingValidationNoRouterCall_Revert() public {
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ _enableInboundMessageValidator();
+ vm.startPrank(address(s_offRamp));
+
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+
+ // Setup the receiver to a non-CCIP Receiver, which will skip the Router call (but should still perform the validation)
+ MaybeRevertMessageReceiverNo165 newReceiver = new MaybeRevertMessageReceiverNo165(true);
+ message.receiver = address(newReceiver);
+ message.header.messageId = Internal._hash(message, ON_RAMP_ADDRESS_1);
+
+ s_inboundMessageValidator.setMessageIdValidationState(message.header.messageId, true);
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ IMessageInterceptor.MessageValidationError.selector,
+ abi.encodeWithSelector(IMessageInterceptor.MessageValidationError.selector, bytes("Invalid message"))
+ )
+ );
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+}
+
+contract EVM2EVMMultiOffRamp_batchExecute is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_3, 1);
+ }
+
+ function test_SingleReport_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ uint64 nonceBefore = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender);
+ s_offRamp.batchExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[][](1));
+
+ assertGt(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender), nonceBefore);
+ }
+
+ function test_MultipleReportsSameChain_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+
+ messages1[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages1[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+ messages2[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 3);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages2);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[0].header.sourceChainSelector,
+ messages1[0].header.sequenceNumber,
+ messages1[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[1].header.sourceChainSelector,
+ messages1[1].header.sequenceNumber,
+ messages1[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages2[0].header.sourceChainSelector,
+ messages2[0].header.sequenceNumber,
+ messages2[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ uint64 nonceBefore = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages1[0].sender);
+ s_offRamp.batchExecute(reports, new uint256[][](2));
+ assertGt(s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages1[0].sender), nonceBefore);
+ }
+
+ function test_MultipleReportsDifferentChains_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+
+ messages1[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages1[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+ messages2[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_3, ON_RAMP_ADDRESS_3, 1);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_3, messages2);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[0].header.sourceChainSelector,
+ messages1[0].header.sequenceNumber,
+ messages1[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[1].header.sourceChainSelector,
+ messages1[1].header.sequenceNumber,
+ messages1[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages2[0].header.sourceChainSelector,
+ messages2[0].header.sequenceNumber,
+ messages2[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.batchExecute(reports, new uint256[][](2));
+
+ uint64 nonceChain1 = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages1[0].sender);
+ uint64 nonceChain3 = s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_3, messages2[0].sender);
+
+ assertTrue(nonceChain1 != nonceChain3);
+ assertGt(nonceChain1, 0);
+ assertGt(nonceChain3, 0);
+ }
+
+ function test_MultipleReportsSkipDuplicate_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SkippedAlreadyExecutedMessage(SOURCE_CHAIN_SELECTOR_1, messages[0].header.sequenceNumber);
+
+ s_offRamp.batchExecute(reports, new uint256[][](2));
+ }
+
+ // Reverts
+ function test_ZeroReports_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOffRamp.EmptyReport.selector);
+ s_offRamp.batchExecute(new Internal.ExecutionReportSingleChain[](0), new uint256[][](1));
+ }
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.CursedByRMN.selector, SOURCE_CHAIN_SELECTOR_1));
+ s_offRamp.batchExecute(
+ _generateBatchReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[][](1)
+ );
+ // Uncurse should succeed
+ s_mockRMN.setGlobalCursed(false);
+ s_offRamp.batchExecute(
+ _generateBatchReportFromMessages(
+ SOURCE_CHAIN_SELECTOR_1, _generateMessagesWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1)
+ ),
+ new uint256[][](1)
+ );
+ }
+
+ function test_OutOfBoundsGasLimitsAccess_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+
+ messages1[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages1[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+ messages2[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 3);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages2);
+
+ vm.expectRevert();
+ s_offRamp.batchExecute(reports, new uint256[][](1));
+ }
+}
+
+contract EVM2EVMMultiOffRamp_manuallyExecute is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_3, 1);
+ }
+
+ function test_manuallyExecute_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+ s_offRamp.batchExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[][](1));
+
+ s_reverting_receiver.setRevert(false);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = new uint256[](messages.length);
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_WithGasOverride_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+ s_offRamp.batchExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[][](1));
+
+ s_reverting_receiver.setRevert(false);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages);
+ gasLimitOverrides[0][0] += 1;
+
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_DoesNotRevertIfUntouched_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ assertEq(
+ messages[0].header.nonce - 1, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender)
+ );
+
+ s_reverting_receiver.setRevert(true);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, "")
+ )
+ );
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages);
+
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+
+ assertEq(
+ messages[0].header.nonce, s_inboundNonceManager.getInboundNonce(SOURCE_CHAIN_SELECTOR_1, messages[0].sender)
+ );
+ }
+
+ function test_manuallyExecute_WithMultiReportGasOverride_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](3);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](2);
+
+ for (uint64 i = 0; i < 3; ++i) {
+ messages1[i] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, i + 1);
+ messages1[i].receiver = address(s_reverting_receiver);
+ messages1[i].header.messageId = Internal._hash(messages1[i], ON_RAMP_ADDRESS_1);
+ }
+
+ for (uint64 i = 0; i < 2; ++i) {
+ messages2[i] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_3, ON_RAMP_ADDRESS_3, i + 1);
+ messages2[i].receiver = address(s_reverting_receiver);
+ messages2[i].header.messageId = Internal._hash(messages2[i], ON_RAMP_ADDRESS_3);
+ }
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_3, messages2);
+
+ s_offRamp.batchExecute(reports, new uint256[][](2));
+
+ s_reverting_receiver.setRevert(false);
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](2);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages1);
+ gasLimitOverrides[1] = _getGasLimitsFromMessages(messages2);
+
+ for (uint256 i = 0; i < 3; ++i) {
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages1[i].header.sequenceNumber,
+ messages1[i].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ gasLimitOverrides[0][i] += 1;
+ }
+
+ for (uint256 i = 0; i < 2; ++i) {
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_3,
+ messages2[i].header.sequenceNumber,
+ messages2[i].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ gasLimitOverrides[1][i] += 1;
+ }
+
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_WithPartialMessages_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages = new Internal.Any2EVMRampMessage[](3);
+
+ for (uint64 i = 0; i < 3; ++i) {
+ messages[i] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, i + 1);
+ }
+ messages[1].receiver = address(s_reverting_receiver);
+ messages[1].header.messageId = Internal._hash(messages[1], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[1].header.sequenceNumber,
+ messages[1].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, bytes(""))
+ )
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[2].header.sequenceNumber,
+ messages[2].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.batchExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[][](1));
+
+ s_reverting_receiver.setRevert(false);
+
+ // Only the 2nd message reverted
+ Internal.Any2EVMRampMessage[] memory newMessages = new Internal.Any2EVMRampMessage[](1);
+ newMessages[0] = messages[1];
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(newMessages);
+ gasLimitOverrides[0][0] += 1;
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ newMessages[0].header.sequenceNumber,
+ newMessages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, newMessages), gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_LowGasLimit_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].gasLimit = 1;
+ messages[0].receiver = address(new ConformingReceiver(address(s_destRouter), s_destFeeToken));
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(EVM2EVMMultiOffRamp.ReceiverError.selector, "")
+ );
+ s_offRamp.batchExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[][](1));
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = new uint256[](1);
+ gasLimitOverrides[0][0] = 100_000;
+
+ vm.expectEmit();
+ emit ConformingReceiver.MessageReceived();
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+ }
+
+ // Reverts
+
+ function test_manuallyExecute_ForkedChain_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+ uint256 chain1 = block.chainid;
+ uint256 chain2 = chain1 + 1;
+ vm.chainId(chain2);
+ vm.expectRevert(abi.encodeWithSelector(MultiOCR3Base.ForkedChain.selector, chain1, chain2));
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages);
+
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+ }
+
+ function test_ManualExecGasLimitMismatchSingleReport_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages = new Internal.Any2EVMRampMessage[](2);
+ messages[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ // No overrides for report
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, new uint256[][](0));
+
+ // No messages
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+
+ // 1 message missing
+ gasLimitOverrides[0] = new uint256[](1);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+
+ // 1 message in excess
+ gasLimitOverrides[0] = new uint256[](3);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_GasLimitMismatchMultipleReports_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+
+ messages1[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages1[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+ messages2[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_3, ON_RAMP_ADDRESS_3, 1);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_3, messages2);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, new uint256[][](0));
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, new uint256[][](1));
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](2);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+
+ // 2nd report empty
+ gasLimitOverrides[0] = new uint256[](2);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+
+ // 1st report empty
+ gasLimitOverrides[0] = new uint256[](0);
+ gasLimitOverrides[1] = new uint256[](1);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+
+ // 1st report oversized
+ gasLimitOverrides[0] = new uint256[](3);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(reports, gasLimitOverrides);
+ }
+
+ function test_ManualExecInvalidGasLimit_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages);
+ gasLimitOverrides[0][0]--;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.InvalidManualExecutionGasLimit.selector, SOURCE_CHAIN_SELECTOR_1, 0, gasLimitOverrides[0][0]
+ )
+ );
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_FailedTx_Revert() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ s_offRamp.batchExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), new uint256[][](1));
+
+ s_reverting_receiver.setRevert(true);
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ExecutionError.selector,
+ messages[0].header.messageId,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, bytes(""))
+ )
+ )
+ );
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+ }
+
+ function test_manuallyExecute_ReentrancyFails() public {
+ uint256 tokenAmount = 1e9;
+ IERC20 tokenToAbuse = IERC20(s_destFeeToken);
+
+ // This needs to be deployed before the source chain message is sent
+ // because we need the address for the receiver.
+ ReentrancyAbuserMultiRamp receiver = new ReentrancyAbuserMultiRamp(address(s_destRouter), s_offRamp);
+ uint256 balancePre = tokenToAbuse.balanceOf(address(receiver));
+
+ // For this test any message will be flagged as correct by the
+ // commitStore. In a real scenario the abuser would have to actually
+ // send the message that they want to replay.
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ messages[0].tokenAmounts = new Internal.RampTokenAmount[](1);
+ messages[0].tokenAmounts[0] = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[s_sourceFeeToken]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[s_sourceFeeToken]),
+ extraData: "",
+ amount: tokenAmount
+ });
+
+ messages[0].receiver = address(receiver);
+
+ messages[0].header.messageId = Internal._hash(messages[0], ON_RAMP_ADDRESS_1);
+
+ Internal.ExecutionReportSingleChain memory report = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ // sets the report to be repeated on the ReentrancyAbuser to be able to replay
+ receiver.setPayload(report);
+
+ uint256[][] memory gasLimitOverrides = new uint256[][](1);
+ gasLimitOverrides[0] = _getGasLimitsFromMessages(messages);
+
+ // The first entry should be fine and triggers the second entry. This one fails
+ // but since it's an inner tx of the first one it is caught in the try-catch.
+ // This means the first tx is marked `FAILURE` with the error message of the second tx.
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.AlreadyExecuted.selector,
+ messages[0].header.sourceChainSelector,
+ messages[0].header.sequenceNumber
+ )
+ )
+ );
+
+ s_offRamp.manuallyExecute(_generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages), gasLimitOverrides);
+
+ // Since the tx failed we don't release the tokens
+ assertEq(tokenToAbuse.balanceOf(address(receiver)), balancePre);
+ }
+}
+
+contract EVM2EVMMultiOffRamp_execute is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+ }
+
+ // Asserts that execute completes
+ function test_SingleReport_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ SOURCE_CHAIN_SELECTOR_1,
+ messages[0].header.sequenceNumber,
+ messages[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(
+ uint8(Internal.OCRPluginType.Execution), s_configDigestExec, uint64(uint256(s_configDigestExec))
+ );
+
+ _execute(reports);
+ }
+
+ function test_MultipleReports_Success() public {
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+
+ messages1[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages1[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+ messages2[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 3);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages2);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[0].header.sourceChainSelector,
+ messages1[0].header.sequenceNumber,
+ messages1[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[1].header.sourceChainSelector,
+ messages1[1].header.sequenceNumber,
+ messages1[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages2[0].header.sourceChainSelector,
+ messages2[0].header.sequenceNumber,
+ messages2[0].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(
+ uint8(Internal.OCRPluginType.Execution), s_configDigestExec, uint64(uint256(s_configDigestExec))
+ );
+
+ _execute(reports);
+ }
+
+ function test_LargeBatch_Success() public {
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](10);
+ for (uint64 i = 0; i < reports.length; ++i) {
+ Internal.Any2EVMRampMessage[] memory messages = new Internal.Any2EVMRampMessage[](3);
+ messages[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1 + i * 3);
+ messages[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2 + i * 3);
+ messages[2] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 3 + i * 3);
+
+ reports[i] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+ }
+
+ for (uint64 i = 0; i < reports.length; ++i) {
+ for (uint64 j = 0; j < reports[i].messages.length; ++j) {
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ reports[i].messages[j].header.sourceChainSelector,
+ reports[i].messages[j].header.sequenceNumber,
+ reports[i].messages[j].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+ }
+ }
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(
+ uint8(Internal.OCRPluginType.Execution), s_configDigestExec, uint64(uint256(s_configDigestExec))
+ );
+
+ _execute(reports);
+ }
+
+ function test_MultipleReportsWithPartialValidationFailures_Success() public {
+ _enableInboundMessageValidator();
+
+ Internal.Any2EVMRampMessage[] memory messages1 = new Internal.Any2EVMRampMessage[](2);
+ Internal.Any2EVMRampMessage[] memory messages2 = new Internal.Any2EVMRampMessage[](1);
+
+ messages1[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1);
+ messages1[1] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 2);
+ messages2[0] = _generateAny2EVMMessageNoTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 3);
+
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](2);
+ reports[0] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages1);
+ reports[1] = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages2);
+
+ s_inboundMessageValidator.setMessageIdValidationState(messages1[0].header.messageId, true);
+ s_inboundMessageValidator.setMessageIdValidationState(messages2[0].header.messageId, true);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[0].header.sourceChainSelector,
+ messages1[0].header.sequenceNumber,
+ messages1[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ IMessageInterceptor.MessageValidationError.selector,
+ abi.encodeWithSelector(IMessageInterceptor.MessageValidationError.selector, bytes("Invalid message"))
+ )
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages1[1].header.sourceChainSelector,
+ messages1[1].header.sequenceNumber,
+ messages1[1].header.messageId,
+ Internal.MessageExecutionState.SUCCESS,
+ ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.ExecutionStateChanged(
+ messages2[0].header.sourceChainSelector,
+ messages2[0].header.sequenceNumber,
+ messages2[0].header.messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ IMessageInterceptor.MessageValidationError.selector,
+ abi.encodeWithSelector(IMessageInterceptor.MessageValidationError.selector, bytes("Invalid message"))
+ )
+ );
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(
+ uint8(Internal.OCRPluginType.Execution), s_configDigestExec, uint64(uint256(s_configDigestExec))
+ );
+
+ _execute(reports);
+ }
+
+ // Reverts
+
+ function test_UnauthorizedTransmitter_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigestExec, s_configDigestExec, s_configDigestExec];
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.expectRevert(MultiOCR3Base.UnauthorizedTransmitter.selector);
+ s_offRamp.execute(reportContext, abi.encode(reports));
+ }
+
+ function test_NoConfig_Revert() public {
+ _redeployOffRampWithNoOCRConfigs();
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ bytes32[3] memory reportContext = [bytes32(""), s_configDigestExec, s_configDigestExec];
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.UnauthorizedTransmitter.selector);
+ s_offRamp.execute(reportContext, abi.encode(reports));
+ }
+
+ function test_NoConfigWithOtherConfigPresent_Revert() public {
+ _redeployOffRampWithNoOCRConfigs();
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Commit),
+ configDigest: s_configDigestCommit,
+ F: s_F,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ bytes32[3] memory reportContext = [bytes32(""), s_configDigestExec, s_configDigestExec];
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert(MultiOCR3Base.UnauthorizedTransmitter.selector);
+ s_offRamp.execute(reportContext, abi.encode(reports));
+ }
+
+ function test_WrongConfigWithSigners_Revert() public {
+ _redeployOffRampWithNoOCRConfigs();
+ s_offRamp.setVerifyOverrideResult(SOURCE_CHAIN_SELECTOR_1, 1);
+
+ s_configDigestExec = _getBasicConfigDigest(1, s_validSigners, s_validTransmitters);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Execution),
+ configDigest: s_configDigestExec,
+ F: s_F,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain[] memory reports =
+ _generateBatchReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.expectRevert();
+ _execute(reports);
+ }
+
+ function test_ZeroReports_Revert() public {
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](0);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.EmptyReport.selector);
+ _execute(reports);
+ }
+
+ function test_IncorrectArrayType_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigestExec, s_configDigestExec, s_configDigestExec];
+
+ uint256[] memory wrongData = new uint256[](1);
+ wrongData[0] = 1;
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert();
+ s_offRamp.execute(reportContext, abi.encode(wrongData));
+ }
+
+ function test_NonArray_Revert() public {
+ bytes32[3] memory reportContext = [s_configDigestExec, s_configDigestExec, s_configDigestExec];
+
+ Internal.Any2EVMRampMessage[] memory messages =
+ _generateSingleBasicMessage(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1);
+ Internal.ExecutionReportSingleChain memory report = _generateReportFromMessages(SOURCE_CHAIN_SELECTOR_1, messages);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert();
+ s_offRamp.execute(reportContext, abi.encode(report));
+ }
+}
+
+contract EVM2EVMMultiOffRamp_getExecutionState is EVM2EVMMultiOffRampSetup {
+ mapping(uint64 sourceChainSelector => mapping(uint64 seqNum => Internal.MessageExecutionState state)) internal
+ s_differentialExecutionState;
+
+ /// forge-config: default.fuzz.runs = 32
+ /// forge-config: ccip.fuzz.runs = 32
+ function test_Fuzz_Differential_Success(
+ uint64 sourceChainSelector,
+ uint16[500] memory seqNums,
+ uint8[500] memory values
+ ) public {
+ for (uint256 i = 0; i < seqNums.length; ++i) {
+ // Only use the first three slots. This makes sure existing slots get overwritten
+ // as the tests uses 500 sequence numbers.
+ uint16 seqNum = seqNums[i] % 386;
+ Internal.MessageExecutionState state = Internal.MessageExecutionState(values[i] % 4);
+ s_differentialExecutionState[sourceChainSelector][seqNum] = state;
+ s_offRamp.setExecutionStateHelper(sourceChainSelector, seqNum, state);
+ assertEq(uint256(state), uint256(s_offRamp.getExecutionState(sourceChainSelector, seqNum)));
+ }
+
+ for (uint256 i = 0; i < seqNums.length; ++i) {
+ uint16 seqNum = seqNums[i] % 386;
+ Internal.MessageExecutionState expectedState = s_differentialExecutionState[sourceChainSelector][seqNum];
+ assertEq(uint256(expectedState), uint256(s_offRamp.getExecutionState(sourceChainSelector, seqNum)));
+ }
+ }
+
+ function test_GetExecutionState_Success() public {
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 0, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3);
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 1, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (3 << 2));
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 1, Internal.MessageExecutionState.IN_PROGRESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 2));
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 2, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 2) + (3 << 4));
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 127, Internal.MessageExecutionState.IN_PROGRESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 2) + (3 << 4) + (1 << 254));
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 128, Internal.MessageExecutionState.SUCCESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 2) + (3 << 4) + (1 << 254));
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 1), 2);
+
+ assertEq(
+ uint256(Internal.MessageExecutionState.FAILURE), uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 0))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.IN_PROGRESS),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 1))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.FAILURE), uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 2))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.IN_PROGRESS),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 127))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.SUCCESS),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 128))
+ );
+ }
+
+ function test_GetDifferentChainExecutionState_Success() public {
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 0, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1 + 1, 0), 0);
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 127, Internal.MessageExecutionState.IN_PROGRESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 254));
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1 + 1, 0), 0);
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, 128, Internal.MessageExecutionState.SUCCESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 254));
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 1), 2);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1 + 1, 0), 0);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1 + 1, 1), 0);
+
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1 + 1, 127, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 0), 3 + (1 << 254));
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, 1), 2);
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1 + 1, 0), (3 << 254));
+ assertEq(s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1 + 1, 1), 0);
+
+ assertEq(
+ uint256(Internal.MessageExecutionState.FAILURE), uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 0))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.IN_PROGRESS),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 127))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.SUCCESS),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, 128))
+ );
+
+ assertEq(
+ uint256(Internal.MessageExecutionState.UNTOUCHED),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1 + 1, 0))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.FAILURE),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1 + 1, 127))
+ );
+ assertEq(
+ uint256(Internal.MessageExecutionState.UNTOUCHED),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1 + 1, 128))
+ );
+ }
+
+ function test_FillExecutionState_Success() public {
+ for (uint64 i = 0; i < 384; ++i) {
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, i, Internal.MessageExecutionState.FAILURE);
+ }
+
+ for (uint64 i = 0; i < 384; ++i) {
+ assertEq(
+ uint256(Internal.MessageExecutionState.FAILURE),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, i))
+ );
+ }
+
+ for (uint64 i = 0; i < 3; ++i) {
+ assertEq(type(uint256).max, s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, i));
+ }
+
+ for (uint64 i = 0; i < 384; ++i) {
+ s_offRamp.setExecutionStateHelper(SOURCE_CHAIN_SELECTOR_1, i, Internal.MessageExecutionState.IN_PROGRESS);
+ }
+
+ for (uint64 i = 0; i < 384; ++i) {
+ assertEq(
+ uint256(Internal.MessageExecutionState.IN_PROGRESS),
+ uint256(s_offRamp.getExecutionState(SOURCE_CHAIN_SELECTOR_1, i))
+ );
+ }
+
+ for (uint64 i = 0; i < 3; ++i) {
+ // 0x555... == 0b101010101010.....
+ assertEq(
+ 0x5555555555555555555555555555555555555555555555555555555555555555,
+ s_offRamp.getExecutionStateBitMap(SOURCE_CHAIN_SELECTOR_1, i)
+ );
+ }
+ }
+}
+
+contract EVM2EVMMultiOffRamp_trialExecute is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ }
+
+ function test_trialExecute_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1, amounts);
+ IERC20 dstToken0 = IERC20(s_destTokens[0]);
+ uint256 startingBalance = dstToken0.balanceOf(message.receiver);
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(newState));
+ assertEq("", err);
+
+ // Check that the tokens were transferred
+ assertEq(startingBalance + amounts[0], dstToken0.balanceOf(message.receiver));
+ }
+
+ function test_TokenHandlingErrorIsCaught_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ IERC20 dstToken0 = IERC20(s_destTokens[0]);
+ uint256 startingBalance = dstToken0.balanceOf(OWNER);
+
+ bytes memory errorMessage = "Random token pool issue";
+
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1, amounts);
+ s_maybeRevertingPool.setShouldRevert(errorMessage);
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(EVM2EVMMultiOffRamp.TokenHandlingError.selector, errorMessage), err);
+
+ // Expect the balance to remain the same
+ assertEq(startingBalance, dstToken0.balanceOf(OWNER));
+ }
+
+ function test_RateLimitError_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ bytes memory errorMessage = abi.encodeWithSelector(RateLimiter.BucketOverfilled.selector);
+
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1, amounts);
+ s_maybeRevertingPool.setShouldRevert(errorMessage);
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(EVM2EVMMultiOffRamp.TokenHandlingError.selector, errorMessage), err);
+ }
+
+ // TODO test actual pool exists but isn't compatible instead of just no pool
+ function test_TokenPoolIsNotAContract_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 10000;
+ Internal.Any2EVMRampMessage memory message =
+ _generateAny2EVMMessageWithTokens(SOURCE_CHAIN_SELECTOR_1, ON_RAMP_ADDRESS_1, 1, amounts);
+
+ // Happy path, pool is correct
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(newState));
+ assertEq("", err);
+
+ // address 0 has no contract
+ assertEq(address(0).code.length, 0);
+
+ message.tokenAmounts[0] = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(address(0)),
+ destTokenAddress: abi.encode(address(0)),
+ extraData: "",
+ amount: message.tokenAmounts[0].amount
+ });
+
+ message.header.messageId = Internal._hash(message, ON_RAMP_ADDRESS_1);
+
+ // Unhappy path, no revert but marked as failed.
+ (newState, err) = s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, abi.encode(address(0))), err);
+
+ address notAContract = makeAddr("not_a_contract");
+
+ message.tokenAmounts[0] = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(address(0)),
+ destTokenAddress: abi.encode(notAContract),
+ extraData: "",
+ amount: message.tokenAmounts[0].amount
+ });
+
+ message.header.messageId = Internal._hash(message, ON_RAMP_ADDRESS_1);
+
+ (newState, err) = s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(EVM2EVMMultiOffRamp.NotACompatiblePool.selector, address(0)), err);
+ }
+}
+
+contract EVM2EVMMultiOffRamp__releaseOrMintSingleToken is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ }
+
+ function test__releaseOrMintSingleToken_Success() public {
+ uint256 amount = 123123;
+ address token = s_sourceTokens[0];
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes memory offchainTokenData = abi.encode(keccak256("offchainTokenData"));
+
+ IERC20 dstToken1 = IERC20(s_destTokenBySourceToken[token]);
+ uint256 startingBalance = dstToken1.balanceOf(OWNER);
+
+ Internal.RampTokenAmount memory tokenAmount = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[token]),
+ extraData: "",
+ amount: amount
+ });
+
+ vm.expectCall(
+ s_destPoolBySourceToken[token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: OWNER,
+ amount: amount,
+ localToken: s_destTokenBySourceToken[token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ sourcePoolAddress: tokenAmount.sourcePoolAddress,
+ sourcePoolData: tokenAmount.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ )
+ );
+
+ s_offRamp.releaseOrMintSingleToken(tokenAmount, originalSender, OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData);
+
+ assertEq(startingBalance + amount, dstToken1.balanceOf(OWNER));
+ }
+
+ function test__releaseOrMintSingleToken_NotACompatiblePool_Revert() public {
+ uint256 amount = 123123;
+ address token = s_sourceTokens[0];
+ address destToken = s_destTokenBySourceToken[token];
+ vm.label(destToken, "destToken");
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes memory offchainTokenData = abi.encode(keccak256("offchainTokenData"));
+
+ Internal.RampTokenAmount memory tokenAmount = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[token]),
+ destTokenAddress: abi.encode(destToken),
+ extraData: "",
+ amount: amount
+ });
+
+ // Address(0) should always revert
+ address returnedPool = address(0);
+
+ vm.mockCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(ITokenAdminRegistry.getPool.selector, destToken),
+ abi.encode(returnedPool)
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.NotACompatiblePool.selector, returnedPool));
+
+ s_offRamp.releaseOrMintSingleToken(tokenAmount, originalSender, OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData);
+
+ // A contract that doesn't support the interface should also revert
+ returnedPool = address(s_offRamp);
+
+ vm.mockCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(ITokenAdminRegistry.getPool.selector, destToken),
+ abi.encode(returnedPool)
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.NotACompatiblePool.selector, returnedPool));
+
+ s_offRamp.releaseOrMintSingleToken(tokenAmount, originalSender, OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData);
+ }
+
+ function test__releaseOrMintSingleToken_TokenHandlingError_revert_Revert() public {
+ address receiver = makeAddr("receiver");
+ uint256 amount = 123123;
+ address token = s_sourceTokens[0];
+ address destToken = s_destTokenBySourceToken[token];
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes memory offchainTokenData = abi.encode(keccak256("offchainTokenData"));
+
+ Internal.RampTokenAmount memory tokenAmount = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[token]),
+ destTokenAddress: abi.encode(destToken),
+ extraData: "",
+ amount: amount
+ });
+
+ bytes memory revertData = "call reverted :o";
+
+ vm.mockCallRevert(destToken, abi.encodeWithSelector(IERC20.transfer.selector, receiver, amount), revertData);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.TokenHandlingError.selector, revertData));
+ s_offRamp.releaseOrMintSingleToken(
+ tokenAmount, originalSender, receiver, SOURCE_CHAIN_SELECTOR_1, offchainTokenData
+ );
+ }
+}
+
+contract EVM2EVMMultiOffRamp_releaseOrMintTokens is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+ }
+
+ function test_releaseOrMintTokens_Success() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ IERC20 dstToken1 = IERC20(s_destFeeToken);
+ uint256 startingBalance = dstToken1.balanceOf(OWNER);
+ uint256 amount1 = 100;
+ srcTokenAmounts[0].amount = amount1;
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ offchainTokenData[0] = abi.encode(0x12345678);
+
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = _getDefaultSourceTokenData(srcTokenAmounts);
+
+ vm.expectCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: OWNER,
+ amount: srcTokenAmounts[0].amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ sourcePoolAddress: sourceTokenAmounts[0].sourcePoolAddress,
+ sourcePoolData: sourceTokenAmounts[0].extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ )
+ );
+
+ s_offRamp.releaseOrMintTokens(
+ sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData
+ );
+
+ assertEq(startingBalance + amount1, dstToken1.balanceOf(OWNER));
+ }
+
+ function test_releaseOrMintTokens_destDenominatedDecimals_Success() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ address destToken = s_destFeeToken;
+ uint256 amount = 100;
+ uint256 destinationDenominationMultiplier = 1000;
+ srcTokenAmounts[0].amount = amount;
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = _getDefaultSourceTokenData(srcTokenAmounts);
+
+ // Since the pool call is mocked, we manually release funds to the offRamp
+ deal(destToken, address(s_offRamp), amount * destinationDenominationMultiplier);
+
+ vm.mockCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: OWNER,
+ amount: amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ sourcePoolAddress: sourceTokenAmounts[0].sourcePoolAddress,
+ sourcePoolData: sourceTokenAmounts[0].extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ ),
+ abi.encode(amount * destinationDenominationMultiplier)
+ );
+
+ Client.EVMTokenAmount[] memory destTokenAmounts = s_offRamp.releaseOrMintTokens(
+ sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData
+ );
+
+ assertEq(destTokenAmounts[0].amount, amount * destinationDenominationMultiplier);
+ assertEq(destTokenAmounts[0].token, destToken);
+ }
+
+ // Revert
+
+ function test_TokenHandlingError_Reverts() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+
+ bytes memory unknownError = bytes("unknown error");
+ s_maybeRevertingPool.setShouldRevert(unknownError);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.TokenHandlingError.selector, unknownError));
+
+ s_offRamp.releaseOrMintTokens(
+ _getDefaultSourceTokenData(srcTokenAmounts),
+ abi.encode(OWNER),
+ OWNER,
+ SOURCE_CHAIN_SELECTOR_1,
+ new bytes[](srcTokenAmounts.length)
+ );
+ }
+
+ function test_releaseOrMintTokens_InvalidDataLengthReturnData_Revert() public {
+ uint256 amount = 100;
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ srcTokenAmounts[0].amount = amount;
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = _getDefaultSourceTokenData(srcTokenAmounts);
+
+ vm.mockCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: OWNER,
+ amount: amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ sourcePoolAddress: sourceTokenAmounts[0].sourcePoolAddress,
+ sourcePoolData: sourceTokenAmounts[0].extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ ),
+ // Includes the amount twice, this will revert due to the return data being to long
+ abi.encode(amount, amount)
+ );
+
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMMultiOffRamp.InvalidDataLength.selector, Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, 64)
+ );
+
+ s_offRamp.releaseOrMintTokens(
+ sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData
+ );
+ }
+
+ function test_releaseOrMintTokens_InvalidEVMAddress_Revert() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = _getDefaultSourceTokenData(srcTokenAmounts);
+ bytes memory wrongAddress = abi.encode(address(1000), address(10000), address(10000));
+
+ sourceTokenAmounts[0].destTokenAddress = wrongAddress;
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, wrongAddress));
+
+ s_offRamp.releaseOrMintTokens(
+ sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_1, offchainTokenData
+ );
+ }
+
+ function test__releaseOrMintTokens_PoolIsNotAPool_Reverts() public {
+ // The offRamp is a contract, but not a pool
+ address fakePoolAddress = address(s_offRamp);
+
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = new Internal.RampTokenAmount[](1);
+ sourceTokenAmounts[0] = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(fakePoolAddress),
+ destTokenAddress: abi.encode(s_offRamp),
+ extraData: "",
+ amount: 1
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.NotACompatiblePool.selector, address(0)));
+ s_offRamp.releaseOrMintTokens(sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_1, new bytes[](1));
+ }
+
+ function test_releaseOrMintTokens_PoolDoesNotSupportDest_Reverts() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ uint256 amount1 = 100;
+ srcTokenAmounts[0].amount = amount1;
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ offchainTokenData[0] = abi.encode(0x12345678);
+
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = _getDefaultSourceTokenData(srcTokenAmounts);
+
+ vm.expectCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: OWNER,
+ amount: srcTokenAmounts[0].amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR_3,
+ sourcePoolAddress: sourceTokenAmounts[0].sourcePoolAddress,
+ sourcePoolData: sourceTokenAmounts[0].extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ )
+ );
+ vm.expectRevert();
+ s_offRamp.releaseOrMintTokens(
+ sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_3, offchainTokenData
+ );
+ }
+
+ /// forge-config: default.fuzz.runs = 32
+ /// forge-config: ccip.fuzz.runs = 1024
+ // Uint256 gives a good range of values to test, both inside and outside of the eth address space.
+ function test_Fuzz__releaseOrMintTokens_AnyRevertIsCaught_Success(uint256 destPool) public {
+ // Input 447301751254033913445893214690834296930546521452, which is 0x4E59B44847B379578588920CA78FBF26C0B4956C
+ // triggers some Create2Deployer and causes it to fail
+ vm.assume(destPool != 447301751254033913445893214690834296930546521452);
+ bytes memory unusedVar = abi.encode(makeAddr("unused"));
+ Internal.RampTokenAmount[] memory sourceTokenAmounts = new Internal.RampTokenAmount[](1);
+ sourceTokenAmounts[0] = Internal.RampTokenAmount({
+ sourcePoolAddress: unusedVar,
+ destTokenAddress: abi.encode(destPool),
+ extraData: unusedVar,
+ amount: 1
+ });
+
+ try s_offRamp.releaseOrMintTokens(
+ sourceTokenAmounts, abi.encode(OWNER), OWNER, SOURCE_CHAIN_SELECTOR_1, new bytes[](1)
+ ) {} catch (bytes memory reason) {
+ // Any revert should be a TokenHandlingError, InvalidEVMAddress, InvalidDataLength or NoContract as those are caught by the offramp
+ assertTrue(
+ bytes4(reason) == EVM2EVMMultiOffRamp.TokenHandlingError.selector
+ || bytes4(reason) == Internal.InvalidEVMAddress.selector
+ || bytes4(reason) == EVM2EVMMultiOffRamp.InvalidDataLength.selector
+ || bytes4(reason) == CallWithExactGas.NoContract.selector
+ || bytes4(reason) == EVM2EVMMultiOffRamp.NotACompatiblePool.selector,
+ "Expected TokenHandlingError or InvalidEVMAddress"
+ );
+
+ if (destPool > type(uint160).max) {
+ assertEq(reason, abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, abi.encode(destPool)));
+ }
+ }
+ }
+}
+
+contract EVM2EVMMultiOffRamp_applySourceChainConfigUpdates is EVM2EVMMultiOffRampSetup {
+ function test_ApplyZeroUpdates_Success() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0);
+
+ vm.recordLogs();
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ // No logs emitted
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 0);
+
+ // assertEq(s_offRamp.getSourceChainSelectors().length, 0);
+ }
+
+ function test_AddNewChain_Success() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: ON_RAMP_ADDRESS_1,
+ isEnabled: true
+ });
+
+ EVM2EVMMultiOffRamp.SourceChainConfig memory expectedSourceChainConfig =
+ EVM2EVMMultiOffRamp.SourceChainConfig({isEnabled: true, minSeqNr: 1, onRamp: ON_RAMP_ADDRESS_1});
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainSelectorAdded(SOURCE_CHAIN_SELECTOR_1);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainConfigSet(SOURCE_CHAIN_SELECTOR_1, expectedSourceChainConfig);
+
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ _assertSourceChainConfigEquality(s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR_1), expectedSourceChainConfig);
+ }
+
+ function test_ReplaceExistingChain_Success() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: ON_RAMP_ADDRESS_1,
+ isEnabled: true
+ });
+
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ sourceChainConfigs[0].isEnabled = false;
+ EVM2EVMMultiOffRamp.SourceChainConfig memory expectedSourceChainConfig =
+ EVM2EVMMultiOffRamp.SourceChainConfig({isEnabled: false, minSeqNr: 1, onRamp: ON_RAMP_ADDRESS_1});
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainConfigSet(SOURCE_CHAIN_SELECTOR_1, expectedSourceChainConfig);
+
+ vm.recordLogs();
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ // No log emitted for chain selector added (only for setting the config)
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 1);
+
+ _assertSourceChainConfigEquality(s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR_1), expectedSourceChainConfig);
+
+ // uint64[] memory resultSourceChainSelectors = s_offRamp.getSourceChainSelectors();
+ // assertEq(resultSourceChainSelectors.length, 1);
+ // assertEq(resultSourceChainSelectors[0], SOURCE_CHAIN_SELECTOR_1);
+ }
+
+ function test_AddMultipleChains_Success() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](3);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: abi.encode(ON_RAMP_ADDRESS_1, 0),
+ isEnabled: true
+ });
+ sourceChainConfigs[1] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1 + 1,
+ onRamp: abi.encode(ON_RAMP_ADDRESS_1, 1),
+ isEnabled: false
+ });
+ sourceChainConfigs[2] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1 + 2,
+ onRamp: abi.encode(ON_RAMP_ADDRESS_1, 2),
+ isEnabled: true
+ });
+
+ EVM2EVMMultiOffRamp.SourceChainConfig[] memory expectedSourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfig[](3);
+ for (uint256 i = 0; i < 3; ++i) {
+ expectedSourceChainConfigs[i] = EVM2EVMMultiOffRamp.SourceChainConfig({
+ isEnabled: sourceChainConfigs[i].isEnabled,
+ minSeqNr: 1,
+ onRamp: abi.encode(ON_RAMP_ADDRESS_1, i)
+ });
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainSelectorAdded(sourceChainConfigs[i].sourceChainSelector);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainConfigSet(
+ sourceChainConfigs[i].sourceChainSelector, expectedSourceChainConfigs[i]
+ );
+ }
+
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ for (uint256 i = 0; i < 3; ++i) {
+ _assertSourceChainConfigEquality(
+ s_offRamp.getSourceChainConfig(sourceChainConfigs[i].sourceChainSelector), expectedSourceChainConfigs[i]
+ );
+ }
+ }
+
+ function test_Fuzz_applySourceChainConfigUpdate_Success(
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs memory sourceChainConfigArgs
+ ) public {
+ // Skip invalid inputs
+ vm.assume(sourceChainConfigArgs.sourceChainSelector != 0);
+ vm.assume(sourceChainConfigArgs.onRamp.length != 0);
+
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](2);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: ON_RAMP_ADDRESS_1,
+ isEnabled: true
+ });
+ sourceChainConfigs[1] = sourceChainConfigArgs;
+
+ // Handle cases when an update occurs
+ bool isNewChain = sourceChainConfigs[1].sourceChainSelector != SOURCE_CHAIN_SELECTOR_1;
+ if (!isNewChain) {
+ sourceChainConfigs[1].onRamp = sourceChainConfigs[0].onRamp;
+ }
+
+ EVM2EVMMultiOffRamp.SourceChainConfig memory expectedSourceChainConfig = EVM2EVMMultiOffRamp.SourceChainConfig({
+ isEnabled: sourceChainConfigArgs.isEnabled,
+ minSeqNr: 1,
+ onRamp: sourceChainConfigArgs.onRamp
+ });
+
+ if (isNewChain) {
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainSelectorAdded(sourceChainConfigArgs.sourceChainSelector);
+ }
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.SourceChainConfigSet(sourceChainConfigArgs.sourceChainSelector, expectedSourceChainConfig);
+
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ _assertSourceChainConfigEquality(
+ s_offRamp.getSourceChainConfig(sourceChainConfigArgs.sourceChainSelector), expectedSourceChainConfig
+ );
+ }
+
+ // Reverts
+
+ function test_ZeroOnRampAddress_Revert() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: new bytes(0),
+ isEnabled: true
+ });
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroAddressNotAllowed.selector);
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+ }
+
+ function test_ZeroSourceChainSelector_Revert() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] =
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs({sourceChainSelector: 0, onRamp: ON_RAMP_ADDRESS_1, isEnabled: true});
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.ZeroChainSelectorNotAllowed.selector);
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+ }
+
+ function test_ReplaceExistingChainOnRamp_Revert() public {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](1);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: ON_RAMP_ADDRESS_1,
+ isEnabled: true
+ });
+
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ sourceChainConfigs[0].onRamp = ON_RAMP_ADDRESS_2;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.InvalidStaticConfig.selector, SOURCE_CHAIN_SELECTOR_1));
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+ }
+}
+
+contract EVM2EVMMultiOffRamp_commit is EVM2EVMMultiOffRampSetup {
+ uint64 internal s_maxInterval = 12;
+
+ function setUp() public virtual override {
+ super.setUp();
+ _setupMultipleOffRamps();
+
+ s_latestSequenceNumber = uint64(uint256(s_configDigestCommit));
+ }
+
+ function test_ReportAndPriceUpdate_Success() public {
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = _constructCommitReport();
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.CommitReportAccepted(commitReport);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(s_maxInterval + 1, s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR).minSeqNr);
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+ }
+
+ function test_ReportOnlyRootSuccess_gas() public {
+ uint64 max1 = 931;
+ bytes32 root = "Only a single root";
+
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, max1),
+ merkleRoot: root
+ });
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.CommitReportAccepted(commitReport);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(max1 + 1, s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR).minSeqNr);
+ assertEq(0, s_offRamp.getLatestPriceSequenceNumber());
+ assertEq(block.timestamp, s_offRamp.getMerkleRoot(SOURCE_CHAIN_SELECTOR_1, root));
+ }
+
+ function test_StaleReportWithRoot_Success() public {
+ uint64 maxSeq = 12;
+ uint224 tokenStartPrice =
+ IPriceRegistry(s_offRamp.getDynamicConfig().priceRegistry).getTokenPrice(s_sourceFeeToken).value;
+
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, maxSeq),
+ merkleRoot: "stale report 1"
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.CommitReportAccepted(commitReport);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(maxSeq + 1, s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR).minSeqNr);
+ assertEq(0, s_offRamp.getLatestPriceSequenceNumber());
+
+ commitReport.merkleRoots[0].interval = EVM2EVMMultiOffRamp.Interval(maxSeq + 1, maxSeq * 2);
+ commitReport.merkleRoots[0].merkleRoot = "stale report 2";
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.CommitReportAccepted(commitReport);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(maxSeq * 2 + 1, s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR).minSeqNr);
+ assertEq(0, s_offRamp.getLatestPriceSequenceNumber());
+ assertEq(
+ tokenStartPrice, IPriceRegistry(s_offRamp.getDynamicConfig().priceRegistry).getTokenPrice(s_sourceFeeToken).value
+ );
+ }
+
+ function test_OnlyTokenPriceUpdates_Success() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](0);
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+ }
+
+ function test_OnlyGasPriceUpdates_Success() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](0);
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+ }
+
+ function test_PriceSequenceNumberCleared_Success() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](0);
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+
+ vm.startPrank(OWNER);
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Execution),
+ configDigest: s_configDigestExec,
+ F: s_F,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ // Execution plugin OCR config should not clear latest epoch and round
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+
+ // Commit plugin config should clear latest epoch & round
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Commit),
+ configDigest: s_configDigestCommit,
+ F: s_F,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ assertEq(0, s_offRamp.getLatestPriceSequenceNumber());
+
+ // The same sequence number can be reported again
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_ValidPriceUpdateThenStaleReportWithRoot_Success() public {
+ uint64 maxSeq = 12;
+ uint224 tokenPrice1 = 4e18;
+ uint224 tokenPrice2 = 5e18;
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](0);
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, tokenPrice1),
+ merkleRoots: roots
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, tokenPrice1, block.timestamp);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+
+ roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, maxSeq),
+ merkleRoot: "stale report"
+ });
+ commitReport.priceUpdates = getSingleTokenPriceUpdateStruct(s_sourceFeeToken, tokenPrice2);
+ commitReport.merkleRoots = roots;
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOffRamp.CommitReportAccepted(commitReport);
+
+ vm.expectEmit();
+ emit MultiOCR3Base.Transmitted(uint8(Internal.OCRPluginType.Commit), s_configDigestCommit, s_latestSequenceNumber);
+
+ _commit(commitReport, s_latestSequenceNumber);
+
+ assertEq(maxSeq + 1, s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR).minSeqNr);
+ assertEq(
+ tokenPrice1, IPriceRegistry(s_offRamp.getDynamicConfig().priceRegistry).getTokenPrice(s_sourceFeeToken).value
+ );
+ assertEq(s_latestSequenceNumber, s_offRamp.getLatestPriceSequenceNumber());
+ }
+
+ // Reverts
+
+ function test_UnauthorizedTransmitter_Revert() public {
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = _constructCommitReport();
+
+ bytes32[3] memory reportContext =
+ [s_configDigestCommit, bytes32(uint256(s_latestSequenceNumber)), s_configDigestCommit];
+
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, abi.encode(commitReport), reportContext, s_F + 1);
+
+ vm.expectRevert(MultiOCR3Base.UnauthorizedTransmitter.selector);
+ s_offRamp.commit(reportContext, abi.encode(commitReport), rs, ss, rawVs);
+ }
+
+ function test_NoConfig_Revert() public {
+ _redeployOffRampWithNoOCRConfigs();
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = _constructCommitReport();
+
+ bytes32[3] memory reportContext = [bytes32(""), s_configDigestCommit, s_configDigestCommit];
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, abi.encode(commitReport), reportContext, s_F + 1);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert();
+ s_offRamp.commit(reportContext, abi.encode(commitReport), rs, ss, rawVs);
+ }
+
+ function test_NoConfigWithOtherConfigPresent_Revert() public {
+ _redeployOffRampWithNoOCRConfigs();
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Execution),
+ configDigest: s_configDigestExec,
+ F: s_F,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = _constructCommitReport();
+
+ bytes32[3] memory reportContext = [bytes32(""), s_configDigestCommit, s_configDigestCommit];
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, abi.encode(commitReport), reportContext, s_F + 1);
+
+ vm.startPrank(s_validTransmitters[0]);
+ vm.expectRevert();
+ s_offRamp.commit(reportContext, abi.encode(commitReport), rs, ss, rawVs);
+ }
+
+ function test_WrongConfigWithoutSigners_Revert() public {
+ _redeployOffRampWithNoOCRConfigs();
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = _constructCommitReport();
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](1);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Commit),
+ configDigest: s_configDigestCommit,
+ F: s_F,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ vm.expectRevert();
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: "Only a single root"
+ });
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.CursedByRMN.selector, roots[0].sourceChainSelector));
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_InvalidRootRevert() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 4),
+ merkleRoot: bytes32(0)
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.InvalidRoot.selector);
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_InvalidInterval_Revert() public {
+ EVM2EVMMultiOffRamp.Interval memory interval = EVM2EVMMultiOffRamp.Interval(2, 2);
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: interval,
+ merkleRoot: bytes32(0)
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMMultiOffRamp.InvalidInterval.selector, roots[0].sourceChainSelector, interval)
+ );
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_InvalidIntervalMinLargerThanMax_Revert() public {
+ s_offRamp.getSourceChainConfig(SOURCE_CHAIN_SELECTOR);
+ EVM2EVMMultiOffRamp.Interval memory interval = EVM2EVMMultiOffRamp.Interval(1, 0);
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: interval,
+ merkleRoot: bytes32(0)
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMMultiOffRamp.InvalidInterval.selector, roots[0].sourceChainSelector, interval)
+ );
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_ZeroEpochAndRound_Revert() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](0);
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.StaleCommitReport.selector);
+ _commit(commitReport, 0);
+ }
+
+ function test_OnlyPriceUpdateStaleReport_Revert() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](0);
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport = EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(s_sourceFeeToken, 4e18, block.timestamp);
+ _commit(commitReport, s_latestSequenceNumber);
+
+ vm.expectRevert(EVM2EVMMultiOffRamp.StaleCommitReport.selector);
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_SourceChainNotEnabled_Revert() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: 0,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: "Only a single root"
+ });
+
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOffRamp.SourceChainNotEnabled.selector, 0));
+ _commit(commitReport, s_latestSequenceNumber);
+ }
+
+ function test_RootAlreadyCommitted_Revert() public {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: "Only a single root"
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory commitReport =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ _commit(commitReport, s_latestSequenceNumber);
+ commitReport.merkleRoots[0].interval = EVM2EVMMultiOffRamp.Interval(3, 3);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMMultiOffRamp.RootAlreadyCommitted.selector, roots[0].sourceChainSelector, roots[0].merkleRoot
+ )
+ );
+ _commit(commitReport, ++s_latestSequenceNumber);
+ }
+
+ function _constructCommitReport() internal view returns (EVM2EVMMultiOffRamp.CommitReport memory) {
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ interval: EVM2EVMMultiOffRamp.Interval(1, s_maxInterval),
+ merkleRoot: "test #2"
+ });
+
+ return EVM2EVMMultiOffRamp.CommitReport({
+ priceUpdates: getSingleTokenPriceUpdateStruct(s_sourceFeeToken, 4e18),
+ merkleRoots: roots
+ });
+ }
+}
+
+contract EVM2EVMMultiOffRamp_resetUnblessedRoots is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupRealRMN();
+ _deployOffRamp(s_destRouter, s_realRMN, s_inboundNonceManager);
+ _setupMultipleOffRamps();
+ }
+
+ function test_ResetUnblessedRoots_Success() public {
+ EVM2EVMMultiOffRamp.UnblessedRoot[] memory rootsToReset = new EVM2EVMMultiOffRamp.UnblessedRoot[](3);
+ rootsToReset[0] = EVM2EVMMultiOffRamp.UnblessedRoot({sourceChainSelector: SOURCE_CHAIN_SELECTOR, merkleRoot: "1"});
+ rootsToReset[1] = EVM2EVMMultiOffRamp.UnblessedRoot({sourceChainSelector: SOURCE_CHAIN_SELECTOR, merkleRoot: "2"});
+ rootsToReset[2] = EVM2EVMMultiOffRamp.UnblessedRoot({sourceChainSelector: SOURCE_CHAIN_SELECTOR, merkleRoot: "3"});
+
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](3);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: rootsToReset[0].merkleRoot
+ });
+ roots[1] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(3, 4),
+ merkleRoot: rootsToReset[1].merkleRoot
+ });
+ roots[2] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(5, 5),
+ merkleRoot: rootsToReset[2].merkleRoot
+ });
+
+ EVM2EVMMultiOffRamp.CommitReport memory report =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+
+ _commit(report, ++s_latestSequenceNumber);
+
+ IRMN.TaggedRoot[] memory blessedTaggedRoots = new IRMN.TaggedRoot[](1);
+ blessedTaggedRoots[0] = IRMN.TaggedRoot({commitStore: address(s_offRamp), root: rootsToReset[1].merkleRoot});
+
+ vm.startPrank(BLESS_VOTE_ADDR);
+ s_realRMN.voteToBless(blessedTaggedRoots);
+
+ vm.expectEmit(false, false, false, true);
+ emit EVM2EVMMultiOffRamp.RootRemoved(rootsToReset[0].merkleRoot);
+
+ vm.expectEmit(false, false, false, true);
+ emit EVM2EVMMultiOffRamp.RootRemoved(rootsToReset[2].merkleRoot);
+
+ vm.startPrank(OWNER);
+ s_offRamp.resetUnblessedRoots(rootsToReset);
+
+ assertEq(0, s_offRamp.getMerkleRoot(SOURCE_CHAIN_SELECTOR, rootsToReset[0].merkleRoot));
+ assertEq(BLOCK_TIME, s_offRamp.getMerkleRoot(SOURCE_CHAIN_SELECTOR, rootsToReset[1].merkleRoot));
+ assertEq(0, s_offRamp.getMerkleRoot(SOURCE_CHAIN_SELECTOR, rootsToReset[2].merkleRoot));
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ EVM2EVMMultiOffRamp.UnblessedRoot[] memory rootsToReset = new EVM2EVMMultiOffRamp.UnblessedRoot[](0);
+ s_offRamp.resetUnblessedRoots(rootsToReset);
+ }
+}
+
+contract EVM2EVMMultiOffRamp_verify is EVM2EVMMultiOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ _setupRealRMN();
+ _deployOffRamp(s_destRouter, s_realRMN, s_inboundNonceManager);
+ _setupMultipleOffRamps();
+ }
+
+ function test_NotBlessed_Success() public {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = "root";
+
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: leaves[0]
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory report =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+ _commit(report, ++s_latestSequenceNumber);
+ bytes32[] memory proofs = new bytes32[](0);
+ // We have not blessed this root, should return 0.
+ uint256 timestamp = s_offRamp.verify(SOURCE_CHAIN_SELECTOR, leaves, proofs, 0);
+ assertEq(uint256(0), timestamp);
+ }
+
+ function test_Blessed_Success() public {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = "root";
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: leaves[0]
+ });
+ EVM2EVMMultiOffRamp.CommitReport memory report =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+ _commit(report, ++s_latestSequenceNumber);
+ // Bless that root.
+ IRMN.TaggedRoot[] memory taggedRoots = new IRMN.TaggedRoot[](1);
+ taggedRoots[0] = IRMN.TaggedRoot({commitStore: address(s_offRamp), root: leaves[0]});
+ vm.startPrank(BLESS_VOTE_ADDR);
+ s_realRMN.voteToBless(taggedRoots);
+ bytes32[] memory proofs = new bytes32[](0);
+ uint256 timestamp = s_offRamp.verify(SOURCE_CHAIN_SELECTOR, leaves, proofs, 0);
+ assertEq(BLOCK_TIME, timestamp);
+ }
+
+ function test_NotBlessedWrongChainSelector_Success() public {
+ bytes32[] memory leaves = new bytes32[](1);
+ leaves[0] = "root";
+ EVM2EVMMultiOffRamp.MerkleRoot[] memory roots = new EVM2EVMMultiOffRamp.MerkleRoot[](1);
+ roots[0] = EVM2EVMMultiOffRamp.MerkleRoot({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ interval: EVM2EVMMultiOffRamp.Interval(1, 2),
+ merkleRoot: leaves[0]
+ });
+
+ EVM2EVMMultiOffRamp.CommitReport memory report =
+ EVM2EVMMultiOffRamp.CommitReport({priceUpdates: getEmptyPriceUpdates(), merkleRoots: roots});
+ _commit(report, ++s_latestSequenceNumber);
+
+ // Bless that root.
+ IRMN.TaggedRoot[] memory taggedRoots = new IRMN.TaggedRoot[](1);
+ taggedRoots[0] = IRMN.TaggedRoot({commitStore: address(s_offRamp), root: leaves[0]});
+ vm.startPrank(BLESS_VOTE_ADDR);
+ s_realRMN.voteToBless(taggedRoots);
+
+ bytes32[] memory proofs = new bytes32[](0);
+ uint256 timestamp = s_offRamp.verify(SOURCE_CHAIN_SELECTOR + 1, leaves, proofs, 0);
+ assertEq(uint256(0), timestamp);
+ }
+
+ // Reverts
+
+ function test_TooManyLeaves_Revert() public {
+ bytes32[] memory leaves = new bytes32[](258);
+ bytes32[] memory proofs = new bytes32[](0);
+ vm.expectRevert(MerkleMultiProof.InvalidProof.selector);
+ s_offRamp.verify(SOURCE_CHAIN_SELECTOR, leaves, proofs, 0);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMMultiOffRampSetup.t.sol b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMMultiOffRampSetup.t.sol
new file mode 100644
index 00000000000..507e966a70a
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMMultiOffRampSetup.t.sol
@@ -0,0 +1,491 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IAny2EVMMessageReceiver} from "../../interfaces/IAny2EVMMessageReceiver.sol";
+
+import {IAny2EVMOffRamp} from "../../interfaces/IAny2EVMOffRamp.sol";
+import {ICommitStore} from "../../interfaces/ICommitStore.sol";
+import {IRMN} from "../../interfaces/IRMN.sol";
+
+import {AuthorizedCallers} from "../../../shared/access/AuthorizedCallers.sol";
+import {NonceManager} from "../../NonceManager.sol";
+import {RMN} from "../../RMN.sol";
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {MultiOCR3Base} from "../../ocr/MultiOCR3Base.sol";
+import {EVM2EVMMultiOffRamp} from "../../offRamp/EVM2EVMMultiOffRamp.sol";
+import {EVM2EVMOffRamp} from "../../offRamp/EVM2EVMOffRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {TokenSetup} from "../TokenSetup.t.sol";
+import {EVM2EVMMultiOffRampHelper} from "../helpers/EVM2EVMMultiOffRampHelper.sol";
+import {EVM2EVMOffRampHelper} from "../helpers/EVM2EVMOffRampHelper.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {MessageInterceptorHelper} from "../helpers/MessageInterceptorHelper.sol";
+import {MaybeRevertMessageReceiver} from "../helpers/receivers/MaybeRevertMessageReceiver.sol";
+import {MockCommitStore} from "../mocks/MockCommitStore.sol";
+import {MultiOCR3BaseSetup} from "../ocr/MultiOCR3BaseSetup.t.sol";
+import {PriceRegistrySetup} from "../priceRegistry/PriceRegistry.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract EVM2EVMMultiOffRampSetup is TokenSetup, PriceRegistrySetup, MultiOCR3BaseSetup {
+ uint64 internal constant SOURCE_CHAIN_SELECTOR_1 = SOURCE_CHAIN_SELECTOR;
+ uint64 internal constant SOURCE_CHAIN_SELECTOR_2 = 6433500567565415381;
+ uint64 internal constant SOURCE_CHAIN_SELECTOR_3 = 4051577828743386545;
+
+ bytes internal constant ON_RAMP_ADDRESS_1 = abi.encode(ON_RAMP_ADDRESS);
+ bytes internal constant ON_RAMP_ADDRESS_2 = abi.encode(0xaA3f843Cf8E33B1F02dd28303b6bD87B1aBF8AE4);
+ bytes internal constant ON_RAMP_ADDRESS_3 = abi.encode(0x71830C37Cb193e820de488Da111cfbFcC680a1b9);
+
+ address internal constant BLESS_VOTE_ADDR = address(8888);
+
+ IAny2EVMMessageReceiver internal s_receiver;
+ IAny2EVMMessageReceiver internal s_secondary_receiver;
+ MaybeRevertMessageReceiver internal s_reverting_receiver;
+
+ MaybeRevertingBurnMintTokenPool internal s_maybeRevertingPool;
+
+ EVM2EVMMultiOffRampHelper internal s_offRamp;
+ MessageInterceptorHelper internal s_inboundMessageValidator;
+ NonceManager internal s_inboundNonceManager;
+ RMN internal s_realRMN;
+ address internal s_sourceTokenPool = makeAddr("sourceTokenPool");
+
+ bytes32 internal s_configDigestExec;
+ bytes32 internal s_configDigestCommit;
+ uint64 internal constant s_offchainConfigVersion = 3;
+ uint8 internal constant s_F = 1;
+
+ uint64 internal s_latestSequenceNumber;
+
+ function setUp() public virtual override(TokenSetup, PriceRegistrySetup, MultiOCR3BaseSetup) {
+ TokenSetup.setUp();
+ PriceRegistrySetup.setUp();
+ MultiOCR3BaseSetup.setUp();
+
+ s_inboundMessageValidator = new MessageInterceptorHelper();
+ s_receiver = new MaybeRevertMessageReceiver(false);
+ s_secondary_receiver = new MaybeRevertMessageReceiver(false);
+ s_reverting_receiver = new MaybeRevertMessageReceiver(true);
+
+ s_maybeRevertingPool = MaybeRevertingBurnMintTokenPool(s_destPoolByToken[s_destTokens[1]]);
+ s_inboundNonceManager = new NonceManager(new address[](0));
+
+ _deployOffRamp(s_destRouter, s_mockRMN, s_inboundNonceManager);
+ }
+
+ function _deployOffRamp(Router router, IRMN rmnProxy, NonceManager nonceManager) internal {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0);
+
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(rmnProxy),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(nonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(address(router), address(s_priceRegistry)),
+ sourceChainConfigs
+ );
+
+ s_configDigestExec = _getBasicConfigDigest(s_F, s_emptySigners, s_validTransmitters);
+ s_configDigestCommit = _getBasicConfigDigest(s_F, s_validSigners, s_validTransmitters);
+
+ MultiOCR3Base.OCRConfigArgs[] memory ocrConfigs = new MultiOCR3Base.OCRConfigArgs[](2);
+ ocrConfigs[0] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Execution),
+ configDigest: s_configDigestExec,
+ F: s_F,
+ isSignatureVerificationEnabled: false,
+ signers: s_emptySigners,
+ transmitters: s_validTransmitters
+ });
+ ocrConfigs[1] = MultiOCR3Base.OCRConfigArgs({
+ ocrPluginType: uint8(Internal.OCRPluginType.Commit),
+ configDigest: s_configDigestCommit,
+ F: s_F,
+ isSignatureVerificationEnabled: true,
+ signers: s_validSigners,
+ transmitters: s_validTransmitters
+ });
+
+ s_offRamp.setDynamicConfig(_generateDynamicMultiOffRampConfig(address(router), address(s_priceRegistry)));
+ s_offRamp.setOCR3Configs(ocrConfigs);
+
+ address[] memory authorizedCallers = new address[](1);
+ authorizedCallers[0] = address(s_offRamp);
+ NonceManager(nonceManager).applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: authorizedCallers, removedCallers: new address[](0)})
+ );
+
+ address[] memory priceUpdaters = new address[](1);
+ priceUpdaters[0] = address(s_offRamp);
+ s_priceRegistry.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: priceUpdaters, removedCallers: new address[](0)})
+ );
+ }
+
+ // TODO: function can be made common across OffRampSetup and MultiOffRampSetup
+ function _deploySingleLaneOffRamp(
+ ICommitStore commitStore,
+ Router router,
+ address prevOffRamp,
+ uint64 sourceChainSelector,
+ address onRampAddress
+ ) internal returns (EVM2EVMOffRampHelper) {
+ EVM2EVMOffRampHelper offRamp = new EVM2EVMOffRampHelper(
+ EVM2EVMOffRamp.StaticConfig({
+ commitStore: address(commitStore),
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: sourceChainSelector,
+ onRamp: onRampAddress,
+ prevOffRamp: prevOffRamp,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ getInboundRateLimiterConfig()
+ );
+ offRamp.setOCR2Config(
+ s_validSigners,
+ s_validTransmitters,
+ s_F,
+ abi.encode(_generateDynamicOffRampConfig(address(router), address(s_priceRegistry))),
+ s_offchainConfigVersion,
+ abi.encode("")
+ );
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](0);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](2);
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: sourceChainSelector, offRamp: address(s_offRamp)});
+ offRampUpdates[1] = Router.OffRamp({sourceChainSelector: sourceChainSelector, offRamp: address(prevOffRamp)});
+ s_destRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ EVM2EVMOffRamp.RateLimitToken[] memory tokensToAdd = new EVM2EVMOffRamp.RateLimitToken[](s_sourceTokens.length);
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ tokensToAdd[i] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[i], destToken: s_destTokens[i]});
+ }
+ offRamp.updateRateLimitTokens(new EVM2EVMOffRamp.RateLimitToken[](0), tokensToAdd);
+
+ return offRamp;
+ }
+
+ function _setupMultipleOffRamps() internal {
+ EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs =
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](3);
+ sourceChainConfigs[0] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_1,
+ onRamp: ON_RAMP_ADDRESS_1,
+ isEnabled: true
+ });
+ sourceChainConfigs[1] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_2,
+ onRamp: ON_RAMP_ADDRESS_2,
+ isEnabled: false
+ });
+ sourceChainConfigs[2] = EVM2EVMMultiOffRamp.SourceChainConfigArgs({
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR_3,
+ onRamp: ON_RAMP_ADDRESS_3,
+ isEnabled: true
+ });
+ _setupMultipleOffRampsFromConfigs(sourceChainConfigs);
+ }
+
+ function _setupMultipleOffRampsFromConfigs(EVM2EVMMultiOffRamp.SourceChainConfigArgs[] memory sourceChainConfigs)
+ internal
+ {
+ s_offRamp.applySourceChainConfigUpdates(sourceChainConfigs);
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](0);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](2 * sourceChainConfigs.length);
+
+ for (uint256 i = 0; i < sourceChainConfigs.length; ++i) {
+ uint64 sourceChainSelector = sourceChainConfigs[i].sourceChainSelector;
+
+ offRampUpdates[2 * i] = Router.OffRamp({sourceChainSelector: sourceChainSelector, offRamp: address(s_offRamp)});
+ offRampUpdates[2 * i + 1] = Router.OffRamp({
+ sourceChainSelector: sourceChainSelector,
+ offRamp: s_inboundNonceManager.getPreviousRamps(sourceChainSelector).prevOffRamp
+ });
+ }
+
+ s_destRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ }
+
+ function _generateDynamicOffRampConfig(
+ address router,
+ address priceRegistry
+ ) internal pure returns (EVM2EVMOffRamp.DynamicConfig memory) {
+ return EVM2EVMOffRamp.DynamicConfig({
+ permissionLessExecutionThresholdSeconds: PERMISSION_LESS_EXECUTION_THRESHOLD_SECONDS,
+ router: router,
+ priceRegistry: priceRegistry,
+ maxNumberOfTokensPerMsg: MAX_TOKENS_LENGTH,
+ maxDataBytes: MAX_DATA_SIZE,
+ maxPoolReleaseOrMintGas: MAX_TOKEN_POOL_RELEASE_OR_MINT_GAS,
+ maxTokenTransferGas: MAX_TOKEN_POOL_TRANSFER_GAS
+ });
+ }
+
+ function _generateDynamicMultiOffRampConfig(
+ address router,
+ address priceRegistry
+ ) internal pure returns (EVM2EVMMultiOffRamp.DynamicConfig memory) {
+ return EVM2EVMMultiOffRamp.DynamicConfig({
+ permissionLessExecutionThresholdSeconds: PERMISSION_LESS_EXECUTION_THRESHOLD_SECONDS,
+ router: router,
+ priceRegistry: priceRegistry,
+ messageValidator: address(0),
+ maxPoolReleaseOrMintGas: MAX_TOKEN_POOL_RELEASE_OR_MINT_GAS,
+ maxTokenTransferGas: MAX_TOKEN_POOL_TRANSFER_GAS
+ });
+ }
+
+ function _convertToGeneralMessage(Internal.Any2EVMRampMessage memory original)
+ internal
+ view
+ returns (Client.Any2EVMMessage memory message)
+ {
+ uint256 numberOfTokens = original.tokenAmounts.length;
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](numberOfTokens);
+
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ Internal.RampTokenAmount memory tokenAmount = original.tokenAmounts[i];
+
+ address destPoolAddress = abi.decode(tokenAmount.destTokenAddress, (address));
+ TokenPool pool = TokenPool(destPoolAddress);
+ destTokenAmounts[i].token = address(pool.getToken());
+ destTokenAmounts[i].amount = tokenAmount.amount;
+ }
+
+ return Client.Any2EVMMessage({
+ messageId: original.header.messageId,
+ sourceChainSelector: original.header.sourceChainSelector,
+ sender: abi.encode(original.sender),
+ data: original.data,
+ destTokenAmounts: destTokenAmounts
+ });
+ }
+
+ function _generateAny2EVMMessageNoTokens(
+ uint64 sourceChainSelector,
+ bytes memory onRamp,
+ uint64 sequenceNumber
+ ) internal view returns (Internal.Any2EVMRampMessage memory) {
+ return _generateAny2EVMMessage(sourceChainSelector, onRamp, sequenceNumber, new Client.EVMTokenAmount[](0), false);
+ }
+
+ function _generateAny2EVMMessageWithTokens(
+ uint64 sourceChainSelector,
+ bytes memory onRamp,
+ uint64 sequenceNumber,
+ uint256[] memory amounts
+ ) internal view returns (Internal.Any2EVMRampMessage memory) {
+ Client.EVMTokenAmount[] memory tokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ tokenAmounts[i].amount = amounts[i];
+ }
+ return _generateAny2EVMMessage(sourceChainSelector, onRamp, sequenceNumber, tokenAmounts, false);
+ }
+
+ function _generateAny2EVMMessage(
+ uint64 sourceChainSelector,
+ bytes memory onRamp,
+ uint64 sequenceNumber,
+ Client.EVMTokenAmount[] memory tokenAmounts,
+ bool allowOutOfOrderExecution
+ ) internal view returns (Internal.Any2EVMRampMessage memory) {
+ bytes memory data = abi.encode(0);
+
+ Internal.RampTokenAmount[] memory rampTokenAmounts = new Internal.RampTokenAmount[](tokenAmounts.length);
+
+ // Correctly set the TokenDataPayload for each token. Tokens have to be set up in the TokenSetup.
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ rampTokenAmounts[i] = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[tokenAmounts[i].token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[tokenAmounts[i].token]),
+ extraData: "",
+ amount: tokenAmounts[i].amount
+ });
+ }
+
+ Internal.Any2EVMRampMessage memory message = Internal.Any2EVMRampMessage({
+ header: Internal.RampMessageHeader({
+ messageId: "",
+ sourceChainSelector: sourceChainSelector,
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ sequenceNumber: sequenceNumber,
+ nonce: allowOutOfOrderExecution ? 0 : sequenceNumber
+ }),
+ sender: abi.encode(OWNER),
+ data: data,
+ receiver: address(s_receiver),
+ tokenAmounts: rampTokenAmounts,
+ gasLimit: GAS_LIMIT
+ });
+
+ message.header.messageId = Internal._hash(message, onRamp);
+
+ return message;
+ }
+
+ function _generateSingleBasicMessage(
+ uint64 sourceChainSelector,
+ bytes memory onRamp
+ ) internal view returns (Internal.Any2EVMRampMessage[] memory) {
+ Internal.Any2EVMRampMessage[] memory messages = new Internal.Any2EVMRampMessage[](1);
+ messages[0] = _generateAny2EVMMessageNoTokens(sourceChainSelector, onRamp, 1);
+ return messages;
+ }
+
+ function _generateMessagesWithTokens(
+ uint64 sourceChainSelector,
+ bytes memory onRamp
+ ) internal view returns (Internal.Any2EVMRampMessage[] memory) {
+ Internal.Any2EVMRampMessage[] memory messages = new Internal.Any2EVMRampMessage[](2);
+ Client.EVMTokenAmount[] memory tokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ tokenAmounts[0].amount = 1e18;
+ tokenAmounts[1].amount = 5e18;
+ messages[0] = _generateAny2EVMMessage(sourceChainSelector, onRamp, 1, tokenAmounts, false);
+ messages[1] = _generateAny2EVMMessage(sourceChainSelector, onRamp, 2, tokenAmounts, false);
+
+ return messages;
+ }
+
+ function _generateReportFromMessages(
+ uint64 sourceChainSelector,
+ Internal.Any2EVMRampMessage[] memory messages
+ ) internal pure returns (Internal.ExecutionReportSingleChain memory) {
+ bytes[][] memory offchainTokenData = new bytes[][](messages.length);
+
+ for (uint256 i = 0; i < messages.length; ++i) {
+ offchainTokenData[i] = new bytes[](messages[i].tokenAmounts.length);
+ }
+
+ return Internal.ExecutionReportSingleChain({
+ sourceChainSelector: sourceChainSelector,
+ proofs: new bytes32[](0),
+ proofFlagBits: 2 ** 256 - 1,
+ messages: messages,
+ offchainTokenData: offchainTokenData
+ });
+ }
+
+ function _generateBatchReportFromMessages(
+ uint64 sourceChainSelector,
+ Internal.Any2EVMRampMessage[] memory messages
+ ) internal pure returns (Internal.ExecutionReportSingleChain[] memory) {
+ Internal.ExecutionReportSingleChain[] memory reports = new Internal.ExecutionReportSingleChain[](1);
+ reports[0] = _generateReportFromMessages(sourceChainSelector, messages);
+ return reports;
+ }
+
+ function _getGasLimitsFromMessages(Internal.Any2EVMRampMessage[] memory messages)
+ internal
+ pure
+ returns (uint256[] memory)
+ {
+ uint256[] memory gasLimits = new uint256[](messages.length);
+ for (uint256 i = 0; i < messages.length; ++i) {
+ gasLimits[i] = messages[i].gasLimit;
+ }
+
+ return gasLimits;
+ }
+
+ function _assertSameConfig(
+ EVM2EVMMultiOffRamp.DynamicConfig memory a,
+ EVM2EVMMultiOffRamp.DynamicConfig memory b
+ ) public pure {
+ assertEq(a.permissionLessExecutionThresholdSeconds, b.permissionLessExecutionThresholdSeconds);
+ assertEq(a.router, b.router);
+ assertEq(a.maxPoolReleaseOrMintGas, b.maxPoolReleaseOrMintGas);
+ assertEq(a.maxTokenTransferGas, b.maxTokenTransferGas);
+ assertEq(a.messageValidator, b.messageValidator);
+ assertEq(a.priceRegistry, b.priceRegistry);
+ }
+
+ function _assertSourceChainConfigEquality(
+ EVM2EVMMultiOffRamp.SourceChainConfig memory config1,
+ EVM2EVMMultiOffRamp.SourceChainConfig memory config2
+ ) internal pure {
+ assertEq(config1.isEnabled, config2.isEnabled);
+ assertEq(config1.minSeqNr, config2.minSeqNr);
+ assertEq(config1.onRamp, config2.onRamp);
+ }
+
+ function _getDefaultSourceTokenData(Client.EVMTokenAmount[] memory srcTokenAmounts)
+ internal
+ view
+ returns (Internal.RampTokenAmount[] memory)
+ {
+ Internal.RampTokenAmount[] memory sourceTokenData = new Internal.RampTokenAmount[](srcTokenAmounts.length);
+ for (uint256 i = 0; i < srcTokenAmounts.length; ++i) {
+ sourceTokenData[i] = Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[srcTokenAmounts[i].token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[srcTokenAmounts[i].token]),
+ extraData: "",
+ amount: srcTokenAmounts[i].amount
+ });
+ }
+ return sourceTokenData;
+ }
+
+ function _enableInboundMessageValidator() internal {
+ EVM2EVMMultiOffRamp.DynamicConfig memory dynamicConfig = s_offRamp.getDynamicConfig();
+ dynamicConfig.messageValidator = address(s_inboundMessageValidator);
+ s_offRamp.setDynamicConfig(dynamicConfig);
+ }
+
+ function _redeployOffRampWithNoOCRConfigs() internal {
+ s_offRamp = new EVM2EVMMultiOffRampHelper(
+ EVM2EVMMultiOffRamp.StaticConfig({
+ chainSelector: DEST_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry),
+ nonceManager: address(s_inboundNonceManager)
+ }),
+ _generateDynamicMultiOffRampConfig(address(s_destRouter), address(s_priceRegistry)),
+ new EVM2EVMMultiOffRamp.SourceChainConfigArgs[](0)
+ );
+
+ address[] memory authorizedCallers = new address[](1);
+ authorizedCallers[0] = address(s_offRamp);
+ s_inboundNonceManager.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: authorizedCallers, removedCallers: new address[](0)})
+ );
+ _setupMultipleOffRamps();
+
+ address[] memory priceUpdaters = new address[](1);
+ priceUpdaters[0] = address(s_offRamp);
+ s_priceRegistry.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: priceUpdaters, removedCallers: new address[](0)})
+ );
+ }
+
+ function _setupRealRMN() internal {
+ RMN.Voter[] memory voters = new RMN.Voter[](1);
+ voters[0] =
+ RMN.Voter({blessVoteAddr: BLESS_VOTE_ADDR, curseVoteAddr: address(9999), blessWeight: 1, curseWeight: 1});
+ // Overwrite base mock rmn with real.
+ s_realRMN = new RMN(RMN.Config({voters: voters, blessWeightThreshold: 1, curseWeightThreshold: 1}));
+ }
+
+ function _commit(EVM2EVMMultiOffRamp.CommitReport memory commitReport, uint64 sequenceNumber) internal {
+ bytes32[3] memory reportContext = [s_configDigestCommit, bytes32(uint256(sequenceNumber)), s_configDigestCommit];
+
+ (bytes32[] memory rs, bytes32[] memory ss,, bytes32 rawVs) =
+ _getSignaturesForDigest(s_validSignerKeys, abi.encode(commitReport), reportContext, s_F + 1);
+
+ vm.startPrank(s_validTransmitters[0]);
+ s_offRamp.commit(reportContext, abi.encode(commitReport), rs, ss, rawVs);
+ }
+
+ function _execute(Internal.ExecutionReportSingleChain[] memory reports) internal {
+ bytes32[3] memory reportContext = [s_configDigestExec, s_configDigestExec, s_configDigestExec];
+
+ vm.startPrank(s_validTransmitters[0]);
+ s_offRamp.execute(reportContext, abi.encode(reports));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMOffRamp.t.sol b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMOffRamp.t.sol
new file mode 100644
index 00000000000..e94184e3c5e
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMOffRamp.t.sol
@@ -0,0 +1,1986 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ICommitStore} from "../../interfaces/ICommitStore.sol";
+import {IPoolV1} from "../../interfaces/IPool.sol";
+import {ITokenAdminRegistry} from "../../interfaces/ITokenAdminRegistry.sol";
+
+import {CallWithExactGas} from "../../../shared/call/CallWithExactGas.sol";
+
+import {GenericReceiver} from "../../../shared/test/testhelpers/GenericReceiver.sol";
+import {AggregateRateLimiter} from "../../AggregateRateLimiter.sol";
+import {RMN} from "../../RMN.sol";
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {OCR2Abstract} from "../../ocr/OCR2Abstract.sol";
+import {EVM2EVMOffRamp} from "../../offRamp/EVM2EVMOffRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {EVM2EVMOffRampHelper} from "../helpers/EVM2EVMOffRampHelper.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {ConformingReceiver} from "../helpers/receivers/ConformingReceiver.sol";
+import {MaybeRevertMessageReceiver} from "../helpers/receivers/MaybeRevertMessageReceiver.sol";
+import {MaybeRevertMessageReceiverNo165} from "../helpers/receivers/MaybeRevertMessageReceiverNo165.sol";
+import {ReentrancyAbuser} from "../helpers/receivers/ReentrancyAbuser.sol";
+import {MockCommitStore} from "../mocks/MockCommitStore.sol";
+import {OCR2Base} from "../ocr/OCR2Base.t.sol";
+import {OCR2BaseNoChecks} from "../ocr/OCR2BaseNoChecks.t.sol";
+import {EVM2EVMOffRampSetup} from "./EVM2EVMOffRampSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract EVM2EVMOffRamp_constructor is EVM2EVMOffRampSetup {
+ function test_Constructor_Success() public {
+ EVM2EVMOffRamp.StaticConfig memory staticConfig = EVM2EVMOffRamp.StaticConfig({
+ commitStore: address(s_mockCommitStore),
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: ON_RAMP_ADDRESS,
+ prevOffRamp: address(0),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ });
+ EVM2EVMOffRamp.DynamicConfig memory dynamicConfig =
+ generateDynamicOffRampConfig(address(s_destRouter), address(s_priceRegistry));
+
+ s_offRamp = new EVM2EVMOffRampHelper(staticConfig, getInboundRateLimiterConfig());
+
+ s_offRamp.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+
+ // Static config
+ EVM2EVMOffRamp.StaticConfig memory gotStaticConfig = s_offRamp.getStaticConfig();
+ assertEq(staticConfig.commitStore, gotStaticConfig.commitStore);
+ assertEq(staticConfig.sourceChainSelector, gotStaticConfig.sourceChainSelector);
+ assertEq(staticConfig.chainSelector, gotStaticConfig.chainSelector);
+ assertEq(staticConfig.onRamp, gotStaticConfig.onRamp);
+ assertEq(staticConfig.prevOffRamp, gotStaticConfig.prevOffRamp);
+ assertEq(staticConfig.tokenAdminRegistry, gotStaticConfig.tokenAdminRegistry);
+
+ // Dynamic config
+ EVM2EVMOffRamp.DynamicConfig memory gotDynamicConfig = s_offRamp.getDynamicConfig();
+ _assertSameConfig(dynamicConfig, gotDynamicConfig);
+
+ (uint32 configCount, uint32 blockNumber,) = s_offRamp.latestConfigDetails();
+ assertEq(1, configCount);
+ assertEq(block.number, blockNumber);
+
+ // OffRamp initial values
+ assertEq("EVM2EVMOffRamp 1.5.0-dev", s_offRamp.typeAndVersion());
+ assertEq(OWNER, s_offRamp.owner());
+ }
+
+ // Revert
+ function test_ZeroOnRampAddress_Revert() public {
+ vm.expectRevert(EVM2EVMOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp = new EVM2EVMOffRampHelper(
+ EVM2EVMOffRamp.StaticConfig({
+ commitStore: address(s_mockCommitStore),
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: ZERO_ADDRESS,
+ prevOffRamp: address(0),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ RateLimiter.Config({isEnabled: true, rate: 1e20, capacity: 1e20})
+ );
+ }
+
+ function test_CommitStoreAlreadyInUse_Revert() public {
+ s_mockCommitStore.setExpectedNextSequenceNumber(2);
+
+ vm.expectRevert(EVM2EVMOffRamp.CommitStoreAlreadyInUse.selector);
+
+ s_offRamp = new EVM2EVMOffRampHelper(
+ EVM2EVMOffRamp.StaticConfig({
+ commitStore: address(s_mockCommitStore),
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: ON_RAMP_ADDRESS,
+ prevOffRamp: address(0),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ getInboundRateLimiterConfig()
+ );
+ }
+}
+
+contract EVM2EVMOffRamp_setDynamicConfig is EVM2EVMOffRampSetup {
+ function test_SetDynamicConfig_Success() public {
+ EVM2EVMOffRamp.StaticConfig memory staticConfig = s_offRamp.getStaticConfig();
+ EVM2EVMOffRamp.DynamicConfig memory dynamicConfig = generateDynamicOffRampConfig(USER_3, address(s_priceRegistry));
+ bytes memory onchainConfig = abi.encode(dynamicConfig);
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ConfigSet(staticConfig, dynamicConfig);
+
+ vm.expectEmit();
+ uint32 configCount = 1;
+ emit OCR2Abstract.ConfigSet(
+ uint32(block.number),
+ getBasicConfigDigest(address(s_offRamp), s_f, configCount, onchainConfig),
+ configCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ onchainConfig,
+ s_offchainConfigVersion,
+ abi.encode("")
+ );
+
+ s_offRamp.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, onchainConfig, s_offchainConfigVersion, abi.encode("")
+ );
+
+ EVM2EVMOffRamp.DynamicConfig memory newConfig = s_offRamp.getDynamicConfig();
+ _assertSameConfig(dynamicConfig, newConfig);
+ }
+
+ function test_NonOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ EVM2EVMOffRamp.DynamicConfig memory dynamicConfig = generateDynamicOffRampConfig(USER_3, address(s_priceRegistry));
+
+ vm.expectRevert("Only callable by owner");
+
+ s_offRamp.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+ }
+
+ function test_RouterZeroAddress_Revert() public {
+ EVM2EVMOffRamp.DynamicConfig memory dynamicConfig = generateDynamicOffRampConfig(ZERO_ADDRESS, ZERO_ADDRESS);
+
+ vm.expectRevert(EVM2EVMOffRamp.ZeroAddressNotAllowed.selector);
+
+ s_offRamp.setOCR2Config(
+ s_valid_signers, s_valid_transmitters, s_f, abi.encode(dynamicConfig), s_offchainConfigVersion, abi.encode("")
+ );
+ }
+}
+
+contract EVM2EVMOffRamp_metadataHash is EVM2EVMOffRampSetup {
+ function test_MetadataHash_Success() public view {
+ bytes32 h = s_offRamp.metadataHash();
+ assertEq(
+ h,
+ keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, ON_RAMP_ADDRESS)
+ )
+ );
+ }
+}
+
+contract EVM2EVMOffRamp_ccipReceive is EVM2EVMOffRampSetup {
+ // Reverts
+
+ function test_Reverts() public {
+ Client.Any2EVMMessage memory message = _convertToGeneralMessage(_generateAny2EVMMessageNoTokens(1));
+ vm.expectRevert();
+ s_offRamp.ccipReceive(message);
+ }
+}
+
+contract EVM2EVMOffRamp_execute is EVM2EVMOffRampSetup {
+ error PausedError();
+
+ function _generateMsgWithoutTokens(
+ uint256 gasLimit,
+ bytes memory messageData
+ ) internal view returns (Internal.EVM2EVMMessage memory) {
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageNoTokens(1);
+ message.gasLimit = gasLimit;
+ message.data = messageData;
+ message.messageId = Internal._hash(
+ message,
+ keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, ON_RAMP_ADDRESS)
+ )
+ );
+ return message;
+ }
+
+ function test_Fuzz_trialExecuteWithoutTokens_Success(bytes4 funcSelector, bytes memory messageData) public {
+ vm.assume(
+ funcSelector != GenericReceiver.setRevert.selector && funcSelector != GenericReceiver.setErr.selector
+ && funcSelector != 0x5100fc21 && funcSelector != 0x00000000 // s_toRevert(), which is public and therefore has a function selector
+ );
+
+ // Convert bytes4 into bytes memory to use in the message
+ Internal.EVM2EVMMessage memory message = _generateMsgWithoutTokens(GAS_LIMIT, messageData);
+
+ // Convert an Internal.EVM2EVMMessage into a Client.Any2EVMMessage digestable by the client
+ Client.Any2EVMMessage memory receivedMessage = _convertToGeneralMessage(message);
+ bytes memory expectedCallData =
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.ccipReceive.selector, receivedMessage);
+
+ vm.expectCall(address(s_receiver), expectedCallData);
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(newState));
+ assertEq("", err);
+ }
+
+ function test_Fuzz_trialExecuteWithTokens_Success(uint16 tokenAmount, bytes calldata messageData) public {
+ vm.assume(tokenAmount != 0);
+
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = uint256(tokenAmount);
+ amounts[1] = uint256(tokenAmount);
+
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+ // console.log(message.length);
+ message.data = messageData;
+
+ IERC20 dstToken0 = IERC20(s_destTokens[0]);
+ uint256 startingBalance = dstToken0.balanceOf(message.receiver);
+
+ vm.expectCall(s_destTokens[0], abi.encodeWithSelector(IERC20.transfer.selector, address(s_receiver), amounts[0]));
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(newState));
+ assertEq("", err);
+
+ // Check that the tokens were transferred
+ assertEq(startingBalance + amounts[0], dstToken0.balanceOf(message.receiver));
+ }
+
+ function test_Fuzz_getSenderNonce(uint8 trialExecutions) public {
+ vm.assume(trialExecutions > 1);
+
+ Internal.EVM2EVMMessage[] memory messages;
+
+ if (trialExecutions == 1) {
+ messages = new Internal.EVM2EVMMessage[](1);
+ messages[0] = _generateAny2EVMMessageNoTokens(0);
+ } else {
+ messages = _generateSingleBasicMessage();
+ }
+
+ // Fuzz the number of calls from the sender to ensure that getSenderNonce works
+ for (uint256 i = 1; i < trialExecutions; ++i) {
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ messages[0].nonce++;
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+ }
+
+ messages[0].nonce = 0;
+ messages[0].sequenceNumber = 0;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ uint64 nonceBefore = s_offRamp.getSenderNonce(messages[0].sender);
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(s_offRamp.getSenderNonce(messages[0].sender), nonceBefore, "sender nonce is not as expected");
+ }
+
+ function test_Fuzz_getSenderNonceWithPrevOffRamp_Success(uint8 trialExecutions) public {
+ vm.assume(trialExecutions > 1);
+ // Fuzz a random nonce for getSenderNonce
+ test_Fuzz_getSenderNonce(trialExecutions);
+
+ address prevOffRamp = address(s_offRamp);
+ deployOffRamp(s_mockCommitStore, s_destRouter, prevOffRamp);
+
+ // Make sure the off-ramp address has changed by querying the static config
+ assertNotEq(address(s_offRamp), prevOffRamp);
+ EVM2EVMOffRamp.StaticConfig memory staticConfig = s_offRamp.getStaticConfig();
+ assertEq(staticConfig.prevOffRamp, prevOffRamp, "Previous offRamp does not match expected address");
+
+ // Since i_prevOffRamp != address(0) and senderNonce == 0, there should be a call to the previous offRamp
+ vm.expectCall(prevOffRamp, abi.encodeWithSelector(s_offRamp.getSenderNonce.selector, OWNER));
+ uint256 currentSenderNonce = s_offRamp.getSenderNonce(OWNER);
+ assertNotEq(currentSenderNonce, 0, "Sender nonce should not be zero");
+ assertEq(currentSenderNonce, trialExecutions - 1, "Sender Nonce does not match expected trial executions");
+
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ currentSenderNonce = s_offRamp.getSenderNonce(OWNER);
+ assertEq(currentSenderNonce, trialExecutions - 1, "Sender Nonce on new offramp does not match expected executions");
+ }
+
+ function test_SingleMessageNoTokens_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ messages[0].nonce++;
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ uint64 nonceBefore = s_offRamp.getSenderNonce(messages[0].sender);
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertGt(s_offRamp.getSenderNonce(messages[0].sender), nonceBefore);
+ }
+
+ function test_SingleMessageNoTokensUnordered_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].nonce = 0;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ // Nonce never increments on unordered messages.
+ uint64 nonceBefore = s_offRamp.getSenderNonce(messages[0].sender);
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(
+ s_offRamp.getSenderNonce(messages[0].sender), nonceBefore, "nonce must remain unchanged on unordered messages"
+ );
+
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ // Nonce never increments on unordered messages.
+ nonceBefore = s_offRamp.getSenderNonce(messages[0].sender);
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(
+ s_offRamp.getSenderNonce(messages[0].sender), nonceBefore, "nonce must remain unchanged on unordered messages"
+ );
+ }
+
+ function test_ReceiverError_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ bytes memory realError1 = new bytes(2);
+ realError1[0] = 0xbe;
+ realError1[1] = 0xef;
+ s_reverting_receiver.setErr(realError1);
+
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber,
+ messages[0].messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, realError1)
+ )
+ );
+ // Nonce should increment on non-strict
+ assertEq(uint64(0), s_offRamp.getSenderNonce(address(OWNER)));
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(uint64(1), s_offRamp.getSenderNonce(address(OWNER)));
+ }
+
+ function test_StrictUntouchedToSuccess_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ messages[0].strict = true;
+ messages[0].receiver = address(s_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+ // Nonce should increment on a strict untouched -> success.
+ assertEq(uint64(0), s_offRamp.getSenderNonce(address(OWNER)));
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(uint64(1), s_offRamp.getSenderNonce(address(OWNER)));
+ }
+
+ function test_SkippedIncorrectNonce_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ messages[0].nonce++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.SkippedIncorrectNonce(messages[0].nonce, messages[0].sender);
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ function test_SkippedIncorrectNonceStillExecutes_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateMessagesWithTokens();
+
+ messages[1].nonce++;
+ messages[1].messageId = Internal._hash(messages[1], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.SkippedIncorrectNonce(messages[1].nonce, messages[1].sender);
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ function test__execute_SkippedAlreadyExecutedMessage_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.SkippedAlreadyExecutedMessage(messages[0].sequenceNumber);
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ function test__execute_SkippedAlreadyExecutedMessageUnordered_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].nonce = 0;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.SkippedAlreadyExecutedMessage(messages[0].sequenceNumber);
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ // Send a message to a contract that does not implement the CCIPReceiver interface
+ // This should execute successfully.
+ function test_SingleMessageToNonCCIPReceiver_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ MaybeRevertMessageReceiverNo165 newReceiver = new MaybeRevertMessageReceiverNo165(true);
+ messages[0].receiver = address(newReceiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ function test_SingleMessagesNoTokensSuccess_gas() public {
+ vm.pauseGasMetering();
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+
+ vm.resumeGasMetering();
+ s_offRamp.execute(report, new uint256[](0));
+ }
+
+ function test_TwoMessagesWithTokensSuccess_gas() public {
+ vm.pauseGasMetering();
+ Internal.EVM2EVMMessage[] memory messages = _generateMessagesWithTokens();
+ // Set message 1 to use another receiver to simulate more fair gas costs
+ messages[1].receiver = address(s_secondary_receiver);
+ messages[1].messageId = Internal._hash(messages[1], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[1].sequenceNumber, messages[1].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+
+ vm.resumeGasMetering();
+ s_offRamp.execute(report, new uint256[](0));
+ }
+
+ function test_TwoMessagesWithTokensAndGE_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateMessagesWithTokens();
+ // Set message 1 to use another receiver to simulate more fair gas costs
+ messages[1].receiver = address(s_secondary_receiver);
+ messages[1].messageId = Internal._hash(messages[1], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[1].sequenceNumber, messages[1].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ assertEq(uint64(0), s_offRamp.getSenderNonce(OWNER));
+ s_offRamp.execute(_generateReportFromMessages(messages), _getGasLimitsFromMessages(messages));
+ assertEq(uint64(2), s_offRamp.getSenderNonce(OWNER));
+ }
+
+ function test_Fuzz_InterleavingOrderedAndUnorderedMessages_Success(bool[7] memory orderings) public {
+ Internal.EVM2EVMMessage[] memory messages = new Internal.EVM2EVMMessage[](orderings.length);
+ // number of tokens needs to be capped otherwise we hit UnsupportedNumberOfTokens.
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](3);
+ for (uint256 i = 0; i < 3; ++i) {
+ tokenAmounts[i].token = s_sourceTokens[i % s_sourceTokens.length];
+ tokenAmounts[i].amount = 1e18;
+ }
+ uint64 expectedNonce = 0;
+ for (uint256 i = 0; i < orderings.length; ++i) {
+ messages[i] = _generateAny2EVMMessage(uint64(i + 1), tokenAmounts, !orderings[i]);
+ if (orderings[i]) {
+ messages[i].nonce = ++expectedNonce;
+ }
+ messages[i].messageId = Internal._hash(messages[i], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[i].sequenceNumber, messages[i].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+ }
+
+ uint64 nonceBefore = s_offRamp.getSenderNonce(OWNER);
+ assertEq(uint64(0), nonceBefore, "nonce before exec should be 0");
+ s_offRamp.execute(_generateReportFromMessages(messages), _getGasLimitsFromMessages(messages));
+ // all executions should succeed.
+ for (uint256 i = 0; i < orderings.length; ++i) {
+ assertEq(
+ uint256(s_offRamp.getExecutionState(messages[i].sequenceNumber)),
+ uint256(Internal.MessageExecutionState.SUCCESS)
+ );
+ }
+ assertEq(nonceBefore + expectedNonce, s_offRamp.getSenderNonce(OWNER));
+ }
+
+ function test_InvalidSourcePoolAddress_Success() public {
+ address fakePoolAddress = address(0x0000000000333333);
+
+ Internal.EVM2EVMMessage[] memory messages = _generateMessagesWithTokens();
+ messages[0].sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(fakePoolAddress),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[messages[0].tokenAmounts[0].token]),
+ extraData: ""
+ })
+ );
+
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+ messages[1].messageId = Internal._hash(messages[1], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber,
+ messages[0].messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.TokenHandlingError.selector,
+ abi.encodeWithSelector(TokenPool.InvalidSourcePoolAddress.selector, abi.encode(fakePoolAddress))
+ )
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ // Reverts
+
+ function test_InvalidMessageId_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].nonce++;
+ // MessageID no longer matches hash.
+ Internal.ExecutionReport memory executionReport = _generateReportFromMessages(messages);
+ vm.expectRevert(EVM2EVMOffRamp.InvalidMessageId.selector);
+ s_offRamp.execute(executionReport, new uint256[](0));
+ }
+
+ function test_Paused_Revert() public {
+ s_mockCommitStore.pause();
+ vm.expectRevert(PausedError.selector);
+ s_offRamp.execute(_generateReportFromMessages(_generateMessagesWithTokens()), new uint256[](0));
+ }
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(EVM2EVMOffRamp.CursedByRMN.selector);
+ s_offRamp.execute(_generateReportFromMessages(_generateMessagesWithTokens()), new uint256[](0));
+ // Uncurse should succeed
+ s_mockRMN.setGlobalCursed(false);
+ s_offRamp.execute(_generateReportFromMessages(_generateMessagesWithTokens()), new uint256[](0));
+ }
+
+ function test_UnexpectedTokenData_Revert() public {
+ Internal.ExecutionReport memory report = _generateReportFromMessages(_generateSingleBasicMessage());
+ report.offchainTokenData = new bytes[][](report.messages.length + 1);
+
+ vm.expectRevert(EVM2EVMOffRamp.UnexpectedTokenData.selector);
+
+ s_offRamp.execute(report, new uint256[](0));
+ }
+
+ function test_EmptyReport_Revert() public {
+ vm.expectRevert(EVM2EVMOffRamp.EmptyReport.selector);
+ s_offRamp.execute(
+ Internal.ExecutionReport({
+ proofs: new bytes32[](0),
+ proofFlagBits: 0,
+ messages: new Internal.EVM2EVMMessage[](0),
+ offchainTokenData: new bytes[][](0)
+ }),
+ new uint256[](0)
+ );
+ }
+
+ function test_RootNotCommitted_Revert() public {
+ vm.mockCall(address(s_mockCommitStore), abi.encodeWithSelector(ICommitStore.verify.selector), abi.encode(0));
+ vm.expectRevert(EVM2EVMOffRamp.RootNotCommitted.selector);
+
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ s_offRamp.execute(_generateReportFromMessages(messages), _getGasLimitsFromMessages(messages));
+ vm.clearMockedCalls();
+ }
+
+ function test_ManualExecutionNotYetEnabled_Revert() public {
+ vm.mockCall(
+ address(s_mockCommitStore), abi.encodeWithSelector(ICommitStore.verify.selector), abi.encode(BLOCK_TIME)
+ );
+ vm.expectRevert(EVM2EVMOffRamp.ManualExecutionNotYetEnabled.selector);
+
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ s_offRamp.execute(_generateReportFromMessages(messages), _getGasLimitsFromMessages(messages));
+ vm.clearMockedCalls();
+ }
+
+ function test_InvalidSourceChain_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].sourceChainSelector = SOURCE_CHAIN_SELECTOR + 1;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.InvalidSourceChain.selector, SOURCE_CHAIN_SELECTOR + 1));
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ function test_UnsupportedNumberOfTokens_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ Client.EVMTokenAmount[] memory newTokens = new Client.EVMTokenAmount[](MAX_TOKENS_LENGTH + 1);
+ messages[0].tokenAmounts = newTokens;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMOffRamp.UnsupportedNumberOfTokens.selector, messages[0].sequenceNumber)
+ );
+ s_offRamp.execute(report, new uint256[](0));
+ }
+
+ function test_TokenDataMismatch_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+
+ report.offchainTokenData[0] = new bytes[](messages[0].tokenAmounts.length + 1);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.TokenDataMismatch.selector, messages[0].sequenceNumber));
+ s_offRamp.execute(report, new uint256[](0));
+ }
+
+ function test_MessageTooLarge_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].data = new bytes(MAX_DATA_SIZE + 1);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ Internal.ExecutionReport memory executionReport = _generateReportFromMessages(messages);
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMOffRamp.MessageTooLarge.selector, MAX_DATA_SIZE, messages[0].data.length)
+ );
+ s_offRamp.execute(executionReport, new uint256[](0));
+ }
+
+ function test_RouterYULCall_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ // gas limit too high, Router's external call should revert
+ messages[0].gasLimit = 1e36;
+ messages[0].receiver = address(new ConformingReceiver(address(s_destRouter), s_destFeeToken));
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ Internal.ExecutionReport memory executionReport = _generateReportFromMessages(messages);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ExecutionError.selector, abi.encodeWithSelector(CallWithExactGas.NotEnoughGasForCall.selector)
+ )
+ );
+ s_offRamp.execute(executionReport, new uint256[](0));
+ }
+
+ function test_RetryFailedMessageWithoutManualExecution_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ bytes memory realError1 = new bytes(2);
+ realError1[0] = 0xbe;
+ realError1[1] = 0xef;
+ s_reverting_receiver.setErr(realError1);
+
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber,
+ messages[0].messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, realError1)
+ )
+ );
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.AlreadyAttempted.selector, messages[0].sequenceNumber));
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+}
+
+contract EVM2EVMOffRamp_execute_upgrade is EVM2EVMOffRampSetup {
+ EVM2EVMOffRampHelper internal s_prevOffRamp;
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ s_prevOffRamp = s_offRamp;
+
+ deployOffRamp(s_mockCommitStore, s_destRouter, address(s_prevOffRamp));
+ }
+
+ function test_V2_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ }
+
+ function test_V2SenderNoncesReadsPreviousRamp_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ uint64 startNonce = s_offRamp.getSenderNonce(messages[0].sender);
+
+ for (uint64 i = 1; i < 4; ++i) {
+ s_prevOffRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ messages[0].nonce++;
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ assertEq(startNonce + i, s_offRamp.getSenderNonce(messages[0].sender));
+ }
+ }
+
+ function test_V2NonceStartsAtV1Nonce_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ uint64 startNonce = s_offRamp.getSenderNonce(messages[0].sender);
+
+ s_prevOffRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ assertEq(startNonce + 1, s_offRamp.getSenderNonce(messages[0].sender));
+
+ messages[0].nonce++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(startNonce + 2, s_offRamp.getSenderNonce(messages[0].sender));
+
+ messages[0].nonce++;
+ messages[0].sequenceNumber++;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(startNonce + 3, s_offRamp.getSenderNonce(messages[0].sender));
+ }
+
+ function test_V2NonceNewSenderStartsAtZero_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_prevOffRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ address newSender = address(1234567);
+ messages[0].sender = newSender;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ // new sender nonce in new offramp should go from 0 -> 1
+ assertEq(s_offRamp.getSenderNonce(newSender), 0);
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(s_offRamp.getSenderNonce(newSender), 1);
+ }
+
+ function test_V2OffRampNonceSkipsIfMsgInFlight_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ address newSender = address(1234567);
+ messages[0].sender = newSender;
+ messages[0].nonce = 2;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ uint64 startNonce = s_offRamp.getSenderNonce(messages[0].sender);
+
+ // new offramp sees msg nonce higher than senderNonce
+ // it waits for previous offramp to execute
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.SkippedSenderWithPreviousRampMessageInflight(messages[0].nonce, newSender);
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(startNonce, s_offRamp.getSenderNonce(messages[0].sender));
+
+ messages[0].nonce = 1;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ // previous offramp executes msg and increases nonce
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+ s_prevOffRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(startNonce + 1, s_offRamp.getSenderNonce(messages[0].sender));
+
+ messages[0].nonce = 2;
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ // new offramp is able to execute
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+ assertEq(startNonce + 2, s_offRamp.getSenderNonce(messages[0].sender));
+ }
+}
+
+contract EVM2EVMOffRamp_executeSingleMessage is EVM2EVMOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ vm.startPrank(address(s_offRamp));
+ }
+
+ function test_executeSingleMessage_NoTokens_Success() public {
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageNoTokens(1);
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_executeSingleMessage_WithTokens_Success() public {
+ Internal.EVM2EVMMessage memory message = _generateMessagesWithTokens()[0];
+ bytes[] memory offchainTokenData = new bytes[](message.tokenAmounts.length);
+ Internal.SourceTokenData memory sourceTokenData = abi.decode(message.sourceTokenData[0], (Internal.SourceTokenData));
+
+ vm.expectCall(
+ s_destPoolByToken[s_destTokens[0]],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(message.sender),
+ receiver: message.receiver,
+ amount: message.tokenAmounts[0].amount,
+ localToken: s_destTokenBySourceToken[message.tokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: ""
+ })
+ )
+ );
+
+ s_offRamp.executeSingleMessage(message, offchainTokenData);
+ }
+
+ function test_executeSingleMessage_ZeroGasZeroData_Success() public {
+ uint256 gasLimit = 0;
+ Internal.EVM2EVMMessage memory message = _generateMsgWithoutTokens(gasLimit);
+ Client.Any2EVMMessage memory receiverMsg = _convertToGeneralMessage(message);
+
+ // expect 0 calls to be made as no gas is provided
+ vm.expectCall(
+ address(s_destRouter),
+ abi.encodeCall(Router.routeMessage, (receiverMsg, Internal.GAS_FOR_CALL_EXACT_CHECK, gasLimit, message.receiver)),
+ 0
+ );
+
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+
+ // Ensure we encoded it properly, and didn't simply expect the wrong call
+ gasLimit = 200_000;
+ message = _generateMsgWithoutTokens(gasLimit);
+ receiverMsg = _convertToGeneralMessage(message);
+
+ vm.expectCall(
+ address(s_destRouter),
+ abi.encodeCall(Router.routeMessage, (receiverMsg, Internal.GAS_FOR_CALL_EXACT_CHECK, gasLimit, message.receiver)),
+ 1
+ );
+
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function _generateMsgWithoutTokens(uint256 gasLimit) internal view returns (Internal.EVM2EVMMessage memory) {
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageNoTokens(1);
+ message.gasLimit = gasLimit;
+ message.data = "";
+ message.messageId = Internal._hash(
+ message,
+ keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, ON_RAMP_ADDRESS)
+ )
+ );
+ return message;
+ }
+
+ function test_NonContract_Success() public {
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageNoTokens(1);
+ message.receiver = STRANGER;
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_NonContractWithTokens_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+ vm.expectEmit();
+ emit TokenPool.Released(address(s_offRamp), STRANGER, amounts[0]);
+ vm.expectEmit();
+ emit TokenPool.Minted(address(s_offRamp), STRANGER, amounts[1]);
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+ message.receiver = STRANGER;
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ // Reverts
+
+ function test_TokenHandlingError_Revert() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ bytes memory errorMessage = "Random token pool issue";
+
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+ s_maybeRevertingPool.setShouldRevert(errorMessage);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.TokenHandlingError.selector, errorMessage));
+
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_ZeroGasDONExecution_Revert() public {
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageNoTokens(1);
+ message.gasLimit = 0;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.ReceiverError.selector, ""));
+
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+
+ function test_MessageSender_Revert() public {
+ vm.stopPrank();
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageNoTokens(1);
+ vm.expectRevert(EVM2EVMOffRamp.CanOnlySelfCall.selector);
+ s_offRamp.executeSingleMessage(message, new bytes[](message.tokenAmounts.length));
+ }
+}
+
+contract EVM2EVMOffRamp__report is EVM2EVMOffRampSetup {
+ // Asserts that execute completes
+ function test_Report_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+ s_offRamp.report(abi.encode(report));
+ }
+}
+
+contract EVM2EVMOffRamp_manuallyExecute is EVM2EVMOffRampSetup {
+ function test_ManualExec_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ s_reverting_receiver.setRevert(false);
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), new uint256[](messages.length));
+ }
+
+ function test_manuallyExecute_DoesNotRevertIfUntouched_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ assertEq(messages[0].nonce - 1, s_offRamp.getSenderNonce(messages[0].sender));
+
+ s_reverting_receiver.setRevert(true);
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber,
+ messages[0].messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, "")
+ )
+ );
+
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), new uint256[](1));
+
+ assertEq(messages[0].nonce, s_offRamp.getSenderNonce(messages[0].sender));
+ }
+
+ function test_ManualExecWithGasOverride_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ s_reverting_receiver.setRevert(false);
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+
+ uint256[] memory gasLimitOverrides = _getGasLimitsFromMessages(messages);
+ gasLimitOverrides[0] += 1;
+
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), gasLimitOverrides);
+ }
+
+ function test_LowGasLimitManualExec_Success() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].gasLimit = 1;
+ messages[0].receiver = address(new ConformingReceiver(address(s_destRouter), s_destFeeToken));
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber,
+ messages[0].messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(EVM2EVMOffRamp.ReceiverError.selector, "")
+ );
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ uint256[] memory gasLimitOverrides = new uint256[](1);
+ gasLimitOverrides[0] = 100_000;
+
+ vm.expectEmit();
+ emit MaybeRevertMessageReceiver.MessageReceived();
+
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber, messages[0].messageId, Internal.MessageExecutionState.SUCCESS, ""
+ );
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), gasLimitOverrides);
+ }
+
+ function test_ManualExecForkedChain_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+ uint256 chain1 = block.chainid;
+ uint256 chain2 = chain1 + 1;
+ vm.chainId(chain2);
+ vm.expectRevert(abi.encodeWithSelector(OCR2BaseNoChecks.ForkedChain.selector, chain1, chain2));
+
+ s_offRamp.manuallyExecute(report, _getGasLimitsFromMessages(messages));
+ }
+
+ function test_ManualExecGasLimitMismatch_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ vm.expectRevert(EVM2EVMOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), new uint256[](0));
+
+ vm.expectRevert(EVM2EVMOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), new uint256[](messages.length - 1));
+
+ vm.expectRevert(EVM2EVMOffRamp.ManualExecutionGasLimitMismatch.selector);
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), new uint256[](messages.length + 1));
+ }
+
+ function test_ManualExecInvalidGasLimit_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ uint256[] memory gasLimits = _getGasLimitsFromMessages(messages);
+ gasLimits[0]--;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.InvalidManualExecutionGasLimit.selector, 0, gasLimits[0]));
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), gasLimits);
+ }
+
+ function test_ManualExecFailedTx_Revert() public {
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+
+ messages[0].receiver = address(s_reverting_receiver);
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ s_offRamp.execute(_generateReportFromMessages(messages), new uint256[](0));
+
+ s_reverting_receiver.setRevert(true);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ExecutionError.selector,
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, bytes(""))
+ )
+ )
+ );
+ s_offRamp.manuallyExecute(_generateReportFromMessages(messages), _getGasLimitsFromMessages(messages));
+ }
+
+ function test_ReentrancyManualExecuteFails() public {
+ uint256 tokenAmount = 1e9;
+ IERC20 tokenToAbuse = IERC20(s_destFeeToken);
+
+ // This needs to be deployed before the source chain message is sent
+ // because we need the address for the receiver.
+ ReentrancyAbuser receiver = new ReentrancyAbuser(address(s_destRouter), s_offRamp);
+ uint256 balancePre = tokenToAbuse.balanceOf(address(receiver));
+
+ // For this test any message will be flagged as correct by the
+ // commitStore. In a real scenario the abuser would have to actually
+ // send the message that they want to replay.
+ Internal.EVM2EVMMessage[] memory messages = _generateSingleBasicMessage();
+ messages[0].tokenAmounts = new Client.EVMTokenAmount[](1);
+ messages[0].tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceFeeToken, amount: tokenAmount});
+ messages[0].receiver = address(receiver);
+ messages[0].sourceTokenData = new bytes[](1);
+ messages[0].sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[s_sourceFeeToken]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[s_sourceFeeToken]),
+ extraData: ""
+ })
+ );
+
+ messages[0].messageId = Internal._hash(messages[0], s_offRamp.metadataHash());
+
+ Internal.ExecutionReport memory report = _generateReportFromMessages(messages);
+
+ // sets the report to be repeated on the ReentrancyAbuser to be able to replay
+ receiver.setPayload(report);
+
+ // The first entry should be fine and triggers the second entry. This one fails
+ // but since it's an inner tx of the first one it is caught in the try-catch.
+ // This means the first tx is marked `FAILURE` with the error message of the second tx.
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.ExecutionStateChanged(
+ messages[0].sequenceNumber,
+ messages[0].messageId,
+ Internal.MessageExecutionState.FAILURE,
+ abi.encodeWithSelector(
+ EVM2EVMOffRamp.ReceiverError.selector,
+ abi.encodeWithSelector(EVM2EVMOffRamp.AlreadyExecuted.selector, messages[0].sequenceNumber)
+ )
+ );
+
+ s_offRamp.manuallyExecute(report, _getGasLimitsFromMessages(messages));
+
+ // Since the tx failed we don't release the tokens
+ assertEq(tokenToAbuse.balanceOf(address(receiver)), balancePre);
+ }
+}
+
+contract EVM2EVMOffRamp_getExecutionState is EVM2EVMOffRampSetup {
+ mapping(uint64 seqNum => Internal.MessageExecutionState state) internal s_differentialExecutionState;
+
+ /// forge-config: default.fuzz.runs = 32
+ /// forge-config: ccip.fuzz.runs = 32
+ function test_Fuzz_Differential_Success(uint16[500] memory seqNums, uint8[500] memory values) public {
+ for (uint256 i = 0; i < seqNums.length; ++i) {
+ // Only use the first three slots. This makes sure existing slots get overwritten
+ // as the tests uses 500 sequence numbers.
+ uint16 seqNum = seqNums[i] % 386;
+ Internal.MessageExecutionState state = Internal.MessageExecutionState(values[i] % 4);
+ s_differentialExecutionState[seqNum] = state;
+ s_offRamp.setExecutionStateHelper(seqNum, state);
+ assertEq(uint256(state), uint256(s_offRamp.getExecutionState(seqNum)));
+ }
+
+ for (uint256 i = 0; i < seqNums.length; ++i) {
+ uint16 seqNum = seqNums[i] % 386;
+ Internal.MessageExecutionState expectedState = s_differentialExecutionState[seqNum];
+ assertEq(uint256(expectedState), uint256(s_offRamp.getExecutionState(seqNum)));
+ }
+ }
+
+ function test_GetExecutionState_Success() public {
+ s_offRamp.setExecutionStateHelper(0, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(0), 3);
+
+ s_offRamp.setExecutionStateHelper(1, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(0), 3 + (3 << 2));
+
+ s_offRamp.setExecutionStateHelper(1, Internal.MessageExecutionState.IN_PROGRESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(0), 3 + (1 << 2));
+
+ s_offRamp.setExecutionStateHelper(2, Internal.MessageExecutionState.FAILURE);
+ assertEq(s_offRamp.getExecutionStateBitMap(0), 3 + (1 << 2) + (3 << 4));
+
+ s_offRamp.setExecutionStateHelper(127, Internal.MessageExecutionState.IN_PROGRESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(0), 3 + (1 << 2) + (3 << 4) + (1 << 254));
+
+ s_offRamp.setExecutionStateHelper(128, Internal.MessageExecutionState.SUCCESS);
+ assertEq(s_offRamp.getExecutionStateBitMap(0), 3 + (1 << 2) + (3 << 4) + (1 << 254));
+ assertEq(s_offRamp.getExecutionStateBitMap(1), 2);
+
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(s_offRamp.getExecutionState(0)));
+ assertEq(uint256(Internal.MessageExecutionState.IN_PROGRESS), uint256(s_offRamp.getExecutionState(1)));
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(s_offRamp.getExecutionState(2)));
+ assertEq(uint256(Internal.MessageExecutionState.IN_PROGRESS), uint256(s_offRamp.getExecutionState(127)));
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(s_offRamp.getExecutionState(128)));
+ }
+
+ function test_FillExecutionState_Success() public {
+ for (uint64 i = 0; i < 384; ++i) {
+ s_offRamp.setExecutionStateHelper(i, Internal.MessageExecutionState.FAILURE);
+ }
+
+ for (uint64 i = 0; i < 384; ++i) {
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(s_offRamp.getExecutionState(i)));
+ }
+
+ for (uint64 i = 0; i < 3; ++i) {
+ assertEq(type(uint256).max, s_offRamp.getExecutionStateBitMap(i));
+ }
+
+ for (uint64 i = 0; i < 384; ++i) {
+ s_offRamp.setExecutionStateHelper(i, Internal.MessageExecutionState.IN_PROGRESS);
+ }
+
+ for (uint64 i = 0; i < 384; ++i) {
+ assertEq(uint256(Internal.MessageExecutionState.IN_PROGRESS), uint256(s_offRamp.getExecutionState(i)));
+ }
+
+ for (uint64 i = 0; i < 3; ++i) {
+ // 0x555... == 0b101010101010.....
+ assertEq(0x5555555555555555555555555555555555555555555555555555555555555555, s_offRamp.getExecutionStateBitMap(i));
+ }
+ }
+}
+
+contract EVM2EVMOffRamp__trialExecute is EVM2EVMOffRampSetup {
+ function test_trialExecute_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+ IERC20 dstToken0 = IERC20(s_destTokens[0]);
+ uint256 startingBalance = dstToken0.balanceOf(message.receiver);
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(newState));
+ assertEq("", err);
+
+ // Check that the tokens were transferred
+ assertEq(startingBalance + amounts[0], dstToken0.balanceOf(message.receiver));
+ }
+
+ function test_TokenHandlingErrorIsCaught_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ IERC20 dstToken0 = IERC20(s_destTokens[0]);
+ uint256 startingBalance = dstToken0.balanceOf(OWNER);
+
+ bytes memory errorMessage = "Random token pool issue";
+
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+ s_maybeRevertingPool.setShouldRevert(errorMessage);
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(EVM2EVMOffRamp.TokenHandlingError.selector, errorMessage), err);
+
+ // Expect the balance to remain the same
+ assertEq(startingBalance, dstToken0.balanceOf(OWNER));
+ }
+
+ function test_RateLimitError_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 1000;
+ amounts[1] = 50;
+
+ bytes memory errorMessage = abi.encodeWithSelector(RateLimiter.BucketOverfilled.selector);
+
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+ s_maybeRevertingPool.setShouldRevert(errorMessage);
+
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(EVM2EVMOffRamp.TokenHandlingError.selector, errorMessage), err);
+ }
+
+ function test_TokenPoolIsNotAContract_Success() public {
+ uint256[] memory amounts = new uint256[](2);
+ amounts[0] = 10000;
+ Internal.EVM2EVMMessage memory message = _generateAny2EVMMessageWithTokens(1, amounts);
+
+ // Happy path, pool is correct
+ (Internal.MessageExecutionState newState, bytes memory err) =
+ s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+
+ assertEq(uint256(Internal.MessageExecutionState.SUCCESS), uint256(newState));
+ assertEq("", err);
+
+ // address 0 has no contract
+ assertEq(address(0).code.length, 0);
+ message.sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(address(0)),
+ destTokenAddress: abi.encode(address(0)),
+ extraData: ""
+ })
+ );
+
+ message.messageId = Internal._hash(
+ message,
+ keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, ON_RAMP_ADDRESS)
+ )
+ );
+
+ // Unhappy path, no revert but marked as failed.
+ (newState, err) = s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, abi.encode(address(0))), err);
+
+ address notAContract = makeAddr("not_a_contract");
+
+ message.sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(address(0)),
+ destTokenAddress: abi.encode(notAContract),
+ extraData: ""
+ })
+ );
+
+ message.messageId = Internal._hash(
+ message,
+ keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, ON_RAMP_ADDRESS)
+ )
+ );
+
+ (newState, err) = s_offRamp.trialExecute(message, new bytes[](message.tokenAmounts.length));
+
+ assertEq(uint256(Internal.MessageExecutionState.FAILURE), uint256(newState));
+ assertEq(abi.encodeWithSelector(EVM2EVMOffRamp.NotACompatiblePool.selector, address(0)), err);
+ }
+}
+
+contract EVM2EVMOffRamp__releaseOrMintToken is EVM2EVMOffRampSetup {
+ function test__releaseOrMintToken_Success() public {
+ uint256 amount = 123123;
+ address token = s_sourceTokens[0];
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes memory offchainTokenData = abi.encode(keccak256("offchainTokenData"));
+
+ IERC20 dstToken1 = IERC20(s_destTokenBySourceToken[token]);
+ uint256 startingBalance = dstToken1.balanceOf(OWNER);
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[token]),
+ extraData: ""
+ });
+
+ vm.expectCall(
+ s_destPoolBySourceToken[token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: OWNER,
+ amount: amount,
+ localToken: s_destTokenBySourceToken[token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ )
+ );
+
+ s_offRamp.releaseOrMintToken(amount, originalSender, OWNER, sourceTokenData, offchainTokenData);
+
+ assertEq(startingBalance + amount, dstToken1.balanceOf(OWNER));
+ }
+
+ function test__releaseOrMintToken_NotACompatiblePool_Revert() public {
+ uint256 amount = 123123;
+ address token = s_sourceTokens[0];
+ address destToken = s_destTokenBySourceToken[token];
+ vm.label(destToken, "destToken");
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes memory offchainTokenData = abi.encode(keccak256("offchainTokenData"));
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[token]),
+ destTokenAddress: abi.encode(destToken),
+ extraData: ""
+ });
+
+ // Address(0) should always revert
+ address returnedPool = address(0);
+
+ vm.mockCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(ITokenAdminRegistry.getPool.selector, destToken),
+ abi.encode(returnedPool)
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.NotACompatiblePool.selector, returnedPool));
+
+ s_offRamp.releaseOrMintToken(amount, originalSender, OWNER, sourceTokenData, offchainTokenData);
+
+ // A contract that doesn't support the interface should also revert
+ returnedPool = address(s_offRamp);
+
+ vm.mockCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(ITokenAdminRegistry.getPool.selector, destToken),
+ abi.encode(returnedPool)
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.NotACompatiblePool.selector, returnedPool));
+
+ s_offRamp.releaseOrMintToken(amount, originalSender, OWNER, sourceTokenData, offchainTokenData);
+ }
+
+ function test__releaseOrMintToken_TokenHandlingError_revert_Revert() public {
+ address receiver = makeAddr("receiver");
+ uint256 amount = 123123;
+ address token = s_sourceTokens[0];
+ address destToken = s_destTokenBySourceToken[token];
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes memory offchainTokenData = abi.encode(keccak256("offchainTokenData"));
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[token]),
+ destTokenAddress: abi.encode(destToken),
+ extraData: ""
+ });
+
+ bytes memory revertData = "call reverted :o";
+
+ vm.mockCallRevert(destToken, abi.encodeWithSelector(IERC20.transfer.selector, receiver, amount), revertData);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.TokenHandlingError.selector, revertData));
+ s_offRamp.releaseOrMintToken(amount, originalSender, receiver, sourceTokenData, offchainTokenData);
+ }
+}
+
+contract EVM2EVMOffRamp__releaseOrMintTokens is EVM2EVMOffRampSetup {
+ function test_releaseOrMintTokens_Success() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ IERC20 dstToken1 = IERC20(s_destFeeToken);
+ uint256 startingBalance = dstToken1.balanceOf(OWNER);
+ uint256 amount1 = 100;
+ srcTokenAmounts[0].amount = amount1;
+
+ bytes memory originalSender = abi.encode(OWNER);
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ offchainTokenData[0] = abi.encode(0x12345678);
+
+ bytes[] memory encodedSourceTokenData = _getDefaultSourceTokenData(srcTokenAmounts);
+ Internal.SourceTokenData memory sourceTokenData = abi.decode(encodedSourceTokenData[0], (Internal.SourceTokenData));
+
+ vm.expectCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: OWNER,
+ amount: srcTokenAmounts[0].amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ )
+ );
+
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, encodedSourceTokenData, offchainTokenData);
+
+ assertEq(startingBalance + amount1, dstToken1.balanceOf(OWNER));
+ }
+
+ function test_releaseOrMintTokens_destDenominatedDecimals_Success() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ address destToken = s_destFeeToken;
+ uint256 amount = 100;
+ uint256 destinationDenominationMultiplier = 1000;
+ srcTokenAmounts[0].amount = amount;
+
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ bytes[] memory encodedSourceTokenData = _getDefaultSourceTokenData(srcTokenAmounts);
+ Internal.SourceTokenData memory sourceTokenData = abi.decode(encodedSourceTokenData[0], (Internal.SourceTokenData));
+
+ // Since the pool call is mocked, we manually release funds to the offRamp
+ deal(destToken, address(s_offRamp), amount * destinationDenominationMultiplier);
+
+ vm.mockCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: OWNER,
+ amount: amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ ),
+ abi.encode(amount * destinationDenominationMultiplier)
+ );
+
+ Client.EVMTokenAmount[] memory destTokenAmounts =
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, encodedSourceTokenData, offchainTokenData);
+
+ assertEq(destTokenAmounts[0].amount, amount * destinationDenominationMultiplier);
+ assertEq(destTokenAmounts[0].token, destToken);
+ }
+
+ function test_OverValueWithARLOff_Success() public {
+ // Set a high price to trip the ARL
+ uint224 tokenPrice = 3 ** 128;
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(s_destFeeToken, tokenPrice);
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ uint256 amount1 = 100;
+ srcTokenAmounts[0].amount = amount1;
+
+ bytes memory originalSender = abi.encode(OWNER);
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ offchainTokenData[0] = abi.encode(0x12345678);
+
+ bytes[] memory sourceTokenData = _getDefaultSourceTokenData(srcTokenAmounts);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.AggregateValueMaxCapacityExceeded.selector,
+ getInboundRateLimiterConfig().capacity,
+ (amount1 * tokenPrice) / 1e18
+ )
+ );
+
+ // // Expect to fail from ARL
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, sourceTokenData, offchainTokenData);
+
+ // Configure ARL off for token
+ EVM2EVMOffRamp.RateLimitToken[] memory removes = new EVM2EVMOffRamp.RateLimitToken[](1);
+ removes[0] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceFeeToken, destToken: s_destFeeToken});
+ s_offRamp.updateRateLimitTokens(removes, new EVM2EVMOffRamp.RateLimitToken[](0));
+
+ // Expect the call now succeeds
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, sourceTokenData, offchainTokenData);
+ }
+
+ // Revert
+
+ function test_TokenHandlingError_Reverts() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+
+ bytes memory unknownError = bytes("unknown error");
+ s_maybeRevertingPool.setShouldRevert(unknownError);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.TokenHandlingError.selector, unknownError));
+
+ s_offRamp.releaseOrMintTokens(
+ srcTokenAmounts,
+ abi.encode(OWNER),
+ OWNER,
+ _getDefaultSourceTokenData(srcTokenAmounts),
+ new bytes[](srcTokenAmounts.length)
+ );
+ }
+
+ function test_releaseOrMintTokens_InvalidDataLengthReturnData_Revert() public {
+ uint256 amount = 100;
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ srcTokenAmounts[0].amount = amount;
+
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ bytes[] memory encodedSourceTokenData = _getDefaultSourceTokenData(srcTokenAmounts);
+ Internal.SourceTokenData memory sourceTokenData = abi.decode(encodedSourceTokenData[0], (Internal.SourceTokenData));
+
+ vm.mockCall(
+ s_destPoolBySourceToken[srcTokenAmounts[0].token],
+ abi.encodeWithSelector(
+ LockReleaseTokenPool.releaseOrMint.selector,
+ Pool.ReleaseOrMintInV1({
+ originalSender: originalSender,
+ receiver: OWNER,
+ amount: amount,
+ localToken: s_destTokenBySourceToken[srcTokenAmounts[0].token],
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData[0]
+ })
+ ),
+ // Includes the amount twice, this will revert due to the return data being to long
+ abi.encode(amount, amount)
+ );
+
+ vm.expectRevert(
+ abi.encodeWithSelector(EVM2EVMOffRamp.InvalidDataLength.selector, Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, 64)
+ );
+
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, encodedSourceTokenData, offchainTokenData);
+ }
+
+ function test_releaseOrMintTokens_InvalidEVMAddress_Revert() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+
+ bytes memory originalSender = abi.encode(OWNER);
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ bytes[] memory sourceTokenData = _getDefaultSourceTokenData(srcTokenAmounts);
+ bytes memory wrongAddress = abi.encode(address(1000), address(10000), address(10000));
+
+ sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[srcTokenAmounts[0].token]),
+ destTokenAddress: wrongAddress,
+ extraData: ""
+ })
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, wrongAddress));
+
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, sourceTokenData, offchainTokenData);
+ }
+
+ function test_RateLimitErrors_Reverts() public {
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+
+ bytes[] memory rateLimitErrors = new bytes[](5);
+ rateLimitErrors[0] = abi.encodeWithSelector(RateLimiter.BucketOverfilled.selector);
+ rateLimitErrors[1] =
+ abi.encodeWithSelector(RateLimiter.AggregateValueMaxCapacityExceeded.selector, uint256(100), uint256(1000));
+ rateLimitErrors[2] =
+ abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, uint256(42), 1, s_sourceTokens[0]);
+ rateLimitErrors[3] = abi.encodeWithSelector(
+ RateLimiter.TokenMaxCapacityExceeded.selector, uint256(100), uint256(1000), s_sourceTokens[0]
+ );
+ rateLimitErrors[4] =
+ abi.encodeWithSelector(RateLimiter.TokenRateLimitReached.selector, uint256(42), 1, s_sourceTokens[0]);
+
+ for (uint256 i = 0; i < rateLimitErrors.length; ++i) {
+ s_maybeRevertingPool.setShouldRevert(rateLimitErrors[i]);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.TokenHandlingError.selector, rateLimitErrors[i]));
+
+ s_offRamp.releaseOrMintTokens(
+ srcTokenAmounts,
+ abi.encode(OWNER),
+ OWNER,
+ _getDefaultSourceTokenData(srcTokenAmounts),
+ new bytes[](srcTokenAmounts.length)
+ );
+ }
+ }
+
+ function test__releaseOrMintTokens_NotACompatiblePool_Reverts() public {
+ address fakePoolAddress = makeAddr("Doesn't exist");
+
+ bytes[] memory sourceTokenData = new bytes[](1);
+ sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(fakePoolAddress),
+ destTokenAddress: abi.encode(fakePoolAddress),
+ extraData: ""
+ })
+ );
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOffRamp.NotACompatiblePool.selector, address(0)));
+ s_offRamp.releaseOrMintTokens(
+ new Client.EVMTokenAmount[](1), abi.encode(makeAddr("original_sender")), OWNER, sourceTokenData, new bytes[](1)
+ );
+ }
+
+ function test_PriceNotFoundForToken_Reverts() public {
+ // Set token price to 0
+ s_priceRegistry.updatePrices(getSingleTokenPriceUpdateStruct(s_destFeeToken, 0));
+
+ Client.EVMTokenAmount[] memory srcTokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ uint256 amount1 = 100;
+ srcTokenAmounts[0].amount = amount1;
+
+ bytes memory originalSender = abi.encode(OWNER);
+
+ bytes[] memory offchainTokenData = new bytes[](srcTokenAmounts.length);
+ offchainTokenData[0] = abi.encode(0x12345678);
+
+ bytes[] memory sourceTokenData = _getDefaultSourceTokenData(srcTokenAmounts);
+
+ vm.expectRevert(abi.encodeWithSelector(AggregateRateLimiter.PriceNotFoundForToken.selector, s_destFeeToken));
+
+ s_offRamp.releaseOrMintTokens(srcTokenAmounts, originalSender, OWNER, sourceTokenData, offchainTokenData);
+ }
+
+ /// forge-config: default.fuzz.runs = 32
+ /// forge-config: ccip.fuzz.runs = 1024
+ // Uint256 gives a good range of values to test, both inside and outside of the eth address space.
+ function test_Fuzz__releaseOrMintTokens_AnyRevertIsCaught_Success(uint256 destPool) public {
+ // Input 447301751254033913445893214690834296930546521452, which is 0x4E59B44847B379578588920CA78FBF26C0B4956C
+ // triggers some Create2Deployer and causes it to fail
+ vm.assume(destPool != 447301751254033913445893214690834296930546521452);
+ bytes memory unusedVar = abi.encode(makeAddr("unused"));
+ bytes[] memory sourceTokenData = new bytes[](1);
+ sourceTokenData[0] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: unusedVar,
+ destTokenAddress: abi.encode(destPool),
+ extraData: unusedVar
+ })
+ );
+
+ try s_offRamp.releaseOrMintTokens(new Client.EVMTokenAmount[](1), unusedVar, OWNER, sourceTokenData, new bytes[](1))
+ {} catch (bytes memory reason) {
+ // Any revert should be a TokenHandlingError, InvalidEVMAddress, InvalidDataLength or NoContract as those are caught by the offramp
+ assertTrue(
+ bytes4(reason) == EVM2EVMOffRamp.TokenHandlingError.selector
+ || bytes4(reason) == Internal.InvalidEVMAddress.selector
+ || bytes4(reason) == EVM2EVMOffRamp.InvalidDataLength.selector
+ || bytes4(reason) == CallWithExactGas.NoContract.selector
+ || bytes4(reason) == EVM2EVMOffRamp.NotACompatiblePool.selector,
+ "Expected TokenHandlingError or InvalidEVMAddress"
+ );
+
+ if (destPool > type(uint160).max) {
+ assertEq(reason, abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, abi.encode(destPool)));
+ }
+ }
+ }
+}
+
+contract EVM2EVMOffRamp_getAllRateLimitTokens is EVM2EVMOffRampSetup {
+ function test_GetAllRateLimitTokens_Success() public view {
+ (address[] memory sourceTokens, address[] memory destTokens) = s_offRamp.getAllRateLimitTokens();
+
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ assertEq(s_sourceTokens[i], sourceTokens[i]);
+ assertEq(s_destTokens[i], destTokens[i]);
+ }
+ }
+}
+
+contract EVM2EVMOffRamp_updateRateLimitTokens is EVM2EVMOffRampSetup {
+ function setUp() public virtual override {
+ super.setUp();
+ // Clear rate limit tokens state
+ EVM2EVMOffRamp.RateLimitToken[] memory remove = new EVM2EVMOffRamp.RateLimitToken[](s_sourceTokens.length);
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ remove[i] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[i], destToken: s_destTokens[i]});
+ }
+ s_offRamp.updateRateLimitTokens(remove, new EVM2EVMOffRamp.RateLimitToken[](0));
+ }
+
+ function test_updateRateLimitTokens_Success() public {
+ EVM2EVMOffRamp.RateLimitToken[] memory adds = new EVM2EVMOffRamp.RateLimitToken[](2);
+ adds[0] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[0], destToken: s_destTokens[0]});
+ adds[1] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[1], destToken: s_destTokens[1]});
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.TokenAggregateRateLimitAdded(adds[i].sourceToken, adds[i].destToken);
+ }
+
+ s_offRamp.updateRateLimitTokens(new EVM2EVMOffRamp.RateLimitToken[](0), adds);
+
+ (address[] memory sourceTokens, address[] memory destTokens) = s_offRamp.getAllRateLimitTokens();
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ assertEq(adds[i].sourceToken, sourceTokens[i]);
+ assertEq(adds[i].destToken, destTokens[i]);
+ }
+ }
+
+ function test_updateRateLimitTokens_AddsAndRemoves_Success() public {
+ EVM2EVMOffRamp.RateLimitToken[] memory adds = new EVM2EVMOffRamp.RateLimitToken[](3);
+ adds[0] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[0], destToken: s_destTokens[0]});
+ adds[1] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[1], destToken: s_destTokens[1]});
+ // Add a duplicate, this should not revert the tx
+ adds[2] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[1], destToken: s_destTokens[1]});
+
+ EVM2EVMOffRamp.RateLimitToken[] memory removes = new EVM2EVMOffRamp.RateLimitToken[](1);
+ removes[0] = adds[0];
+
+ for (uint256 i = 0; i < adds.length - 1; ++i) {
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.TokenAggregateRateLimitAdded(adds[i].sourceToken, adds[i].destToken);
+ }
+
+ s_offRamp.updateRateLimitTokens(removes, adds);
+
+ for (uint256 i = 0; i < removes.length; ++i) {
+ vm.expectEmit();
+ emit EVM2EVMOffRamp.TokenAggregateRateLimitRemoved(removes[i].sourceToken, removes[i].destToken);
+ }
+
+ s_offRamp.updateRateLimitTokens(removes, new EVM2EVMOffRamp.RateLimitToken[](0));
+
+ (address[] memory sourceTokens, address[] memory destTokens) = s_offRamp.getAllRateLimitTokens();
+
+ assertEq(1, sourceTokens.length);
+ assertEq(adds[1].sourceToken, sourceTokens[0]);
+
+ assertEq(1, destTokens.length);
+ assertEq(adds[1].destToken, destTokens[0]);
+ }
+
+ function test_Fuzz_UpdateRateLimitTokens(uint8 numTokens) public {
+ // Needs to be more than 1 so that the division doesn't round down and the even makes the comparisons simpler
+ vm.assume(numTokens > 1 && numTokens % 2 == 0);
+
+ // Clear the Rate limit tokens array so the test can start from a baseline
+ (address[] memory sourceTokens, address[] memory destTokens) = s_offRamp.getAllRateLimitTokens();
+ EVM2EVMOffRamp.RateLimitToken[] memory removes = new EVM2EVMOffRamp.RateLimitToken[](sourceTokens.length);
+ for (uint256 x = 0; x < removes.length; x++) {
+ removes[x] = EVM2EVMOffRamp.RateLimitToken({sourceToken: sourceTokens[x], destToken: destTokens[x]});
+ }
+ s_offRamp.updateRateLimitTokens(removes, new EVM2EVMOffRamp.RateLimitToken[](0));
+
+ // Sanity check that the rateLimitTokens were successfully cleared
+ (sourceTokens, destTokens) = s_offRamp.getAllRateLimitTokens();
+ assertEq(sourceTokens.length, 0, "sourceTokenLength should be zero");
+
+ EVM2EVMOffRamp.RateLimitToken[] memory adds = new EVM2EVMOffRamp.RateLimitToken[](numTokens);
+
+ for (uint256 x = 0; x < numTokens; x++) {
+ address tokenAddr = vm.addr(x + 1);
+
+ // Create an array of several fake tokens to add which are deployed on the same address on both chains for simplicity
+ adds[x] = EVM2EVMOffRamp.RateLimitToken({sourceToken: tokenAddr, destToken: tokenAddr});
+ }
+
+ // Attempt to add the tokens to the RateLimitToken Array
+ s_offRamp.updateRateLimitTokens(new EVM2EVMOffRamp.RateLimitToken[](0), adds);
+
+ // Retrieve them from storage and make sure that they all match the expected adds
+ (sourceTokens, destTokens) = s_offRamp.getAllRateLimitTokens();
+
+ for (uint256 x = 0; x < sourceTokens.length; x++) {
+ // Check that the tokens match the ones we generated earlier
+ assertEq(sourceTokens[x], adds[x].sourceToken, "Source token doesn't match add");
+ assertEq(destTokens[x], adds[x].sourceToken, "dest Token doesn't match add");
+ }
+
+ // Attempt to remove half of the numTokens by removing the second half of the list and copying it to a removes array
+ removes = new EVM2EVMOffRamp.RateLimitToken[](adds.length / 2);
+
+ for (uint256 x = 0; x < adds.length / 2; x++) {
+ removes[x] = adds[x + (adds.length / 2)];
+ }
+
+ // Attempt to update again, this time adding nothing and removing the second half of the tokens
+ s_offRamp.updateRateLimitTokens(removes, new EVM2EVMOffRamp.RateLimitToken[](0));
+
+ (sourceTokens, destTokens) = s_offRamp.getAllRateLimitTokens();
+ assertEq(sourceTokens.length, adds.length / 2, "Current Rate limit token length is not half of the original adds");
+ for (uint256 x = 0; x < sourceTokens.length; x++) {
+ // Check that the tokens match the ones we generated earlier and didn't remove in the previous step
+ assertEq(sourceTokens[x], adds[x].sourceToken, "Source token doesn't match add after removes");
+ assertEq(destTokens[x], adds[x].destToken, "dest Token doesn't match add after removes");
+ }
+ }
+
+ // Reverts
+
+ function test_updateRateLimitTokens_NonOwner_Revert() public {
+ EVM2EVMOffRamp.RateLimitToken[] memory addsAndRemoves = new EVM2EVMOffRamp.RateLimitToken[](4);
+
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+
+ s_offRamp.updateRateLimitTokens(addsAndRemoves, addsAndRemoves);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMOffRampSetup.t.sol b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMOffRampSetup.t.sol
new file mode 100644
index 00000000000..053869b88a6
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/offRamp/EVM2EVMOffRampSetup.t.sol
@@ -0,0 +1,264 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IAny2EVMMessageReceiver} from "../../interfaces/IAny2EVMMessageReceiver.sol";
+import {ICommitStore} from "../../interfaces/ICommitStore.sol";
+import {IPoolV1} from "../../interfaces/IPool.sol";
+
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {EVM2EVMOffRamp} from "../../offRamp/EVM2EVMOffRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {TokenSetup} from "../TokenSetup.t.sol";
+import {EVM2EVMOffRampHelper} from "../helpers/EVM2EVMOffRampHelper.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {MaybeRevertMessageReceiver} from "../helpers/receivers/MaybeRevertMessageReceiver.sol";
+import {MockCommitStore} from "../mocks/MockCommitStore.sol";
+import {OCR2BaseSetup} from "../ocr/OCR2Base.t.sol";
+import {PriceRegistrySetup} from "../priceRegistry/PriceRegistry.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract EVM2EVMOffRampSetup is TokenSetup, PriceRegistrySetup, OCR2BaseSetup {
+ MockCommitStore internal s_mockCommitStore;
+ IAny2EVMMessageReceiver internal s_receiver;
+ IAny2EVMMessageReceiver internal s_secondary_receiver;
+ MaybeRevertMessageReceiver internal s_reverting_receiver;
+
+ MaybeRevertingBurnMintTokenPool internal s_maybeRevertingPool;
+
+ EVM2EVMOffRampHelper internal s_offRamp;
+ address internal s_sourceTokenPool = makeAddr("sourceTokenPool");
+
+ function setUp() public virtual override(TokenSetup, PriceRegistrySetup, OCR2BaseSetup) {
+ TokenSetup.setUp();
+ PriceRegistrySetup.setUp();
+ OCR2BaseSetup.setUp();
+
+ s_mockCommitStore = new MockCommitStore();
+ s_receiver = new MaybeRevertMessageReceiver(false);
+ s_secondary_receiver = new MaybeRevertMessageReceiver(false);
+ s_reverting_receiver = new MaybeRevertMessageReceiver(true);
+
+ s_maybeRevertingPool = MaybeRevertingBurnMintTokenPool(s_destPoolByToken[s_destTokens[1]]);
+
+ deployOffRamp(s_mockCommitStore, s_destRouter, address(0));
+ }
+
+ function deployOffRamp(ICommitStore commitStore, Router router, address prevOffRamp) internal {
+ s_offRamp = new EVM2EVMOffRampHelper(
+ EVM2EVMOffRamp.StaticConfig({
+ commitStore: address(commitStore),
+ chainSelector: DEST_CHAIN_SELECTOR,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ onRamp: ON_RAMP_ADDRESS,
+ prevOffRamp: prevOffRamp,
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ getInboundRateLimiterConfig()
+ );
+ s_offRamp.setOCR2Config(
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ abi.encode(generateDynamicOffRampConfig(address(router), address(s_priceRegistry))),
+ s_offchainConfigVersion,
+ abi.encode("")
+ );
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](0);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](2);
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: address(s_offRamp)});
+ offRampUpdates[1] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: address(prevOffRamp)});
+ s_destRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ EVM2EVMOffRamp.RateLimitToken[] memory tokensToAdd = new EVM2EVMOffRamp.RateLimitToken[](s_sourceTokens.length);
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ tokensToAdd[i] = EVM2EVMOffRamp.RateLimitToken({sourceToken: s_sourceTokens[i], destToken: s_destTokens[i]});
+ }
+ s_offRamp.updateRateLimitTokens(new EVM2EVMOffRamp.RateLimitToken[](0), tokensToAdd);
+ }
+
+ function generateDynamicOffRampConfig(
+ address router,
+ address priceRegistry
+ ) internal pure returns (EVM2EVMOffRamp.DynamicConfig memory) {
+ return EVM2EVMOffRamp.DynamicConfig({
+ permissionLessExecutionThresholdSeconds: PERMISSION_LESS_EXECUTION_THRESHOLD_SECONDS,
+ router: router,
+ priceRegistry: priceRegistry,
+ maxNumberOfTokensPerMsg: MAX_TOKENS_LENGTH,
+ maxDataBytes: MAX_DATA_SIZE,
+ maxPoolReleaseOrMintGas: MAX_TOKEN_POOL_RELEASE_OR_MINT_GAS,
+ maxTokenTransferGas: MAX_TOKEN_POOL_TRANSFER_GAS
+ });
+ }
+
+ function _convertToGeneralMessage(Internal.EVM2EVMMessage memory original)
+ internal
+ view
+ returns (Client.Any2EVMMessage memory message)
+ {
+ uint256 numberOfTokens = original.tokenAmounts.length;
+ Client.EVMTokenAmount[] memory destTokenAmounts = new Client.EVMTokenAmount[](numberOfTokens);
+
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ Internal.SourceTokenData memory sourceTokenData =
+ abi.decode(original.sourceTokenData[i], (Internal.SourceTokenData));
+
+ address destPoolAddress = abi.decode(sourceTokenData.destTokenAddress, (address));
+ TokenPool pool = TokenPool(destPoolAddress);
+ destTokenAmounts[i].token = address(pool.getToken());
+ destTokenAmounts[i].amount = original.tokenAmounts[i].amount;
+ }
+
+ return Client.Any2EVMMessage({
+ messageId: original.messageId,
+ sourceChainSelector: original.sourceChainSelector,
+ sender: abi.encode(original.sender),
+ data: original.data,
+ destTokenAmounts: destTokenAmounts
+ });
+ }
+
+ function _generateAny2EVMMessageNoTokens(uint64 sequenceNumber)
+ internal
+ view
+ returns (Internal.EVM2EVMMessage memory)
+ {
+ return _generateAny2EVMMessage(sequenceNumber, new Client.EVMTokenAmount[](0), false);
+ }
+
+ function _generateAny2EVMMessageWithTokens(
+ uint64 sequenceNumber,
+ uint256[] memory amounts
+ ) internal view returns (Internal.EVM2EVMMessage memory) {
+ Client.EVMTokenAmount[] memory tokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ tokenAmounts[i].amount = amounts[i];
+ }
+ return _generateAny2EVMMessage(sequenceNumber, tokenAmounts, false);
+ }
+
+ function _generateAny2EVMMessage(
+ uint64 sequenceNumber,
+ Client.EVMTokenAmount[] memory tokenAmounts,
+ bool allowOutOfOrderExecution
+ ) internal view returns (Internal.EVM2EVMMessage memory) {
+ bytes memory data = abi.encode(0);
+ Internal.EVM2EVMMessage memory message = Internal.EVM2EVMMessage({
+ sequenceNumber: sequenceNumber,
+ sender: OWNER,
+ nonce: allowOutOfOrderExecution ? 0 : sequenceNumber,
+ gasLimit: GAS_LIMIT,
+ strict: false,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ receiver: address(s_receiver),
+ data: data,
+ tokenAmounts: tokenAmounts,
+ sourceTokenData: new bytes[](tokenAmounts.length),
+ feeToken: s_destFeeToken,
+ feeTokenAmount: uint256(0),
+ messageId: ""
+ });
+
+ // Correctly set the TokenDataPayload for each token. Tokens have to be set up in the TokenSetup.
+ for (uint256 i = 0; i < tokenAmounts.length; ++i) {
+ message.sourceTokenData[i] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[tokenAmounts[i].token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[tokenAmounts[i].token]),
+ extraData: ""
+ })
+ );
+ }
+
+ message.messageId = Internal._hash(
+ message,
+ keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, ON_RAMP_ADDRESS)
+ )
+ );
+
+ return message;
+ }
+
+ function _generateSingleBasicMessage() internal view returns (Internal.EVM2EVMMessage[] memory) {
+ Internal.EVM2EVMMessage[] memory messages = new Internal.EVM2EVMMessage[](1);
+ messages[0] = _generateAny2EVMMessageNoTokens(1);
+ return messages;
+ }
+
+ function _generateMessagesWithTokens() internal view returns (Internal.EVM2EVMMessage[] memory) {
+ Internal.EVM2EVMMessage[] memory messages = new Internal.EVM2EVMMessage[](2);
+ Client.EVMTokenAmount[] memory tokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ tokenAmounts[0].amount = 1e18;
+ tokenAmounts[1].amount = 5e18;
+ messages[0] = _generateAny2EVMMessage(1, tokenAmounts, false);
+ messages[1] = _generateAny2EVMMessage(2, tokenAmounts, false);
+
+ return messages;
+ }
+
+ function _generateReportFromMessages(Internal.EVM2EVMMessage[] memory messages)
+ internal
+ pure
+ returns (Internal.ExecutionReport memory)
+ {
+ bytes[][] memory offchainTokenData = new bytes[][](messages.length);
+
+ for (uint256 i = 0; i < messages.length; ++i) {
+ offchainTokenData[i] = new bytes[](messages[i].tokenAmounts.length);
+ }
+
+ return Internal.ExecutionReport({
+ proofs: new bytes32[](0),
+ proofFlagBits: 2 ** 256 - 1,
+ messages: messages,
+ offchainTokenData: offchainTokenData
+ });
+ }
+
+ function _getGasLimitsFromMessages(Internal.EVM2EVMMessage[] memory messages)
+ internal
+ pure
+ returns (uint256[] memory)
+ {
+ uint256[] memory gasLimits = new uint256[](messages.length);
+ for (uint256 i = 0; i < messages.length; ++i) {
+ gasLimits[i] = messages[i].gasLimit;
+ }
+
+ return gasLimits;
+ }
+
+ function _assertSameConfig(EVM2EVMOffRamp.DynamicConfig memory a, EVM2EVMOffRamp.DynamicConfig memory b) public pure {
+ assertEq(a.permissionLessExecutionThresholdSeconds, b.permissionLessExecutionThresholdSeconds);
+ assertEq(a.router, b.router);
+ assertEq(a.priceRegistry, b.priceRegistry);
+ assertEq(a.maxNumberOfTokensPerMsg, b.maxNumberOfTokensPerMsg);
+ assertEq(a.maxDataBytes, b.maxDataBytes);
+ assertEq(a.maxPoolReleaseOrMintGas, b.maxPoolReleaseOrMintGas);
+ assertEq(a.maxTokenTransferGas, b.maxTokenTransferGas);
+ }
+
+ function _getDefaultSourceTokenData(Client.EVMTokenAmount[] memory srcTokenAmounts)
+ internal
+ view
+ returns (bytes[] memory)
+ {
+ bytes[] memory sourceTokenData = new bytes[](srcTokenAmounts.length);
+ for (uint256 i = 0; i < srcTokenAmounts.length; ++i) {
+ sourceTokenData[i] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[srcTokenAmounts[i].token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[srcTokenAmounts[i].token]),
+ extraData: ""
+ })
+ );
+ }
+ return sourceTokenData;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMMultiOnRamp.t.sol b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMMultiOnRamp.t.sol
new file mode 100644
index 00000000000..bc7fac95be6
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMMultiOnRamp.t.sol
@@ -0,0 +1,720 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IMessageInterceptor} from "../../interfaces/IMessageInterceptor.sol";
+import {ITokenAdminRegistry} from "../../interfaces/ITokenAdminRegistry.sol";
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {MultiAggregateRateLimiter} from "../../MultiAggregateRateLimiter.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {USDPriceWith18Decimals} from "../../libraries/USDPriceWith18Decimals.sol";
+import {EVM2EVMMultiOnRamp} from "../../onRamp/EVM2EVMMultiOnRamp.sol";
+import {EVM2EVMOnRamp} from "../../onRamp/EVM2EVMOnRamp.sol";
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+import {EVM2EVMOnRampHelper} from "../helpers/EVM2EVMOnRampHelper.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {MessageInterceptorHelper} from "../helpers/MessageInterceptorHelper.sol";
+import "./EVM2EVMMultiOnRampSetup.t.sol";
+
+contract EVM2EVMMultiOnRamp_constructor is EVM2EVMMultiOnRampSetup {
+ function test_Constructor_Success() public {
+ EVM2EVMMultiOnRamp.StaticConfig memory staticConfig = EVM2EVMMultiOnRamp.StaticConfig({
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ nonceManager: address(s_outboundNonceManager),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ });
+ EVM2EVMMultiOnRamp.DynamicConfig memory dynamicConfig =
+ _generateDynamicMultiOnRampConfig(address(s_sourceRouter), address(s_priceRegistry));
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.ConfigSet(staticConfig, dynamicConfig);
+
+ _deployOnRamp(
+ SOURCE_CHAIN_SELECTOR, address(s_sourceRouter), address(s_outboundNonceManager), address(s_tokenAdminRegistry)
+ );
+
+ EVM2EVMMultiOnRamp.StaticConfig memory gotStaticConfig = s_onRamp.getStaticConfig();
+ _assertStaticConfigsEqual(staticConfig, gotStaticConfig);
+
+ EVM2EVMMultiOnRamp.DynamicConfig memory gotDynamicConfig = s_onRamp.getDynamicConfig();
+ _assertDynamicConfigsEqual(dynamicConfig, gotDynamicConfig);
+
+ // Initial values
+ assertEq("EVM2EVMMultiOnRamp 1.6.0-dev", s_onRamp.typeAndVersion());
+ assertEq(OWNER, s_onRamp.owner());
+ assertEq(1, s_onRamp.getExpectedNextSequenceNumber(DEST_CHAIN_SELECTOR));
+ }
+
+ function test_Constructor_InvalidConfigChainSelectorEqZero_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ new EVM2EVMMultiOnRampHelper(
+ EVM2EVMMultiOnRamp.StaticConfig({
+ chainSelector: 0,
+ rmnProxy: address(s_mockRMN),
+ nonceManager: address(s_outboundNonceManager),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ _generateDynamicMultiOnRampConfig(address(s_sourceRouter), address(s_priceRegistry))
+ );
+ }
+
+ function test_Constructor_InvalidConfigRMNProxyEqAddressZero_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ s_onRamp = new EVM2EVMMultiOnRampHelper(
+ EVM2EVMMultiOnRamp.StaticConfig({
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ rmnProxy: address(0),
+ nonceManager: address(s_outboundNonceManager),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ _generateDynamicMultiOnRampConfig(address(s_sourceRouter), address(s_priceRegistry))
+ );
+ }
+
+ function test_Constructor_InvalidConfigNonceManagerEqAddressZero_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ new EVM2EVMMultiOnRampHelper(
+ EVM2EVMMultiOnRamp.StaticConfig({
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ nonceManager: address(0),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ _generateDynamicMultiOnRampConfig(address(s_sourceRouter), address(s_priceRegistry))
+ );
+ }
+
+ function test_Constructor_InvalidConfigTokenAdminRegistryEqAddressZero_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ new EVM2EVMMultiOnRampHelper(
+ EVM2EVMMultiOnRamp.StaticConfig({
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ rmnProxy: address(s_mockRMN),
+ nonceManager: address(s_outboundNonceManager),
+ tokenAdminRegistry: address(0)
+ }),
+ _generateDynamicMultiOnRampConfig(address(s_sourceRouter), address(s_priceRegistry))
+ );
+ }
+}
+
+contract EVM2EVMMultiOnRamp_forwardFromRouter is EVM2EVMMultiOnRampSetup {
+ struct LegacyExtraArgs {
+ uint256 gasLimit;
+ bool strict;
+ }
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = s_sourceTokens[1];
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+
+ // Since we'll mostly be testing for valid calls from the router we'll
+ // mock all calls to be originating from the router and re-mock in
+ // tests that require failure.
+ vm.startPrank(address(s_sourceRouter));
+ }
+
+ function test_ForwardFromRouterSuccessCustomExtraArgs() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT * 2}));
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterSuccessLegacyExtraArgs() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs =
+ abi.encodeWithSelector(Client.EVM_EXTRA_ARGS_V1_TAG, LegacyExtraArgs({gasLimit: GAS_LIMIT * 2, strict: true}));
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ // We expect the message to be emitted with strict = false.
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterSuccessEmptyExtraArgs() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = "";
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ // We expect the message to be emitted with strict = false.
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouter_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterExtraArgsV2_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: false})
+ );
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterExtraArgsV2AllowOutOfOrderTrue_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: true})
+ );
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ShouldIncrementSeqNumAndNonce_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ for (uint64 i = 1; i < 4; ++i) {
+ uint64 nonceBefore = s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER);
+ uint64 sequenceNumberBefore = s_onRamp.getExpectedNextSequenceNumber(DEST_CHAIN_SELECTOR) - 1;
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, i, i, 0, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ uint64 nonceAfter = s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER);
+ uint64 sequenceNumberAfter = s_onRamp.getExpectedNextSequenceNumber(DEST_CHAIN_SELECTOR) - 1;
+ assertEq(nonceAfter, nonceBefore + 1);
+ assertEq(sequenceNumberAfter, sequenceNumberBefore + 1);
+ }
+ }
+
+ function test_ShouldIncrementNonceOnlyOnOrdered_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: true})
+ );
+
+ for (uint64 i = 1; i < 4; ++i) {
+ uint64 nonceBefore = s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER);
+ uint64 sequenceNumberBefore = s_onRamp.getExpectedNextSequenceNumber(DEST_CHAIN_SELECTOR) - 1;
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, i, i, 0, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ uint64 nonceAfter = s_outboundNonceManager.getOutboundNonce(DEST_CHAIN_SELECTOR, OWNER);
+ uint64 sequenceNumberAfter = s_onRamp.getExpectedNextSequenceNumber(DEST_CHAIN_SELECTOR) - 1;
+ assertEq(nonceAfter, nonceBefore);
+ assertEq(sequenceNumberAfter, sequenceNumberBefore + 1);
+ }
+ }
+
+ function test_ShouldStoreLinkFees() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.FeePaid(s_sourceFeeToken, feeAmount);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp)), feeAmount);
+ }
+
+ function test_ShouldStoreNonLinkFees() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = s_sourceTokens[1];
+
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceTokens[1]).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ // Calculate conversion done by prices contract
+ uint256 feeTokenPrice = s_priceRegistry.getTokenPrice(s_sourceTokens[1]).value;
+ uint256 linkTokenPrice = s_priceRegistry.getTokenPrice(s_sourceFeeToken).value;
+ uint256 conversionRate = (feeTokenPrice * 1e18) / linkTokenPrice;
+ uint256 expectedJuels = (feeAmount * conversionRate) / 1e18;
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.FeePaid(s_sourceTokens[1], expectedJuels);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+
+ assertEq(IERC20(s_sourceTokens[1]).balanceOf(address(s_onRamp)), feeAmount);
+ }
+
+ // Make sure any valid sender, receiver and feeAmount can be handled.
+ // @TODO Temporarily setting lower fuzz run as 256 triggers snapshot gas off by 1 error.
+ // https://github.com/foundry-rs/foundry/issues/5689
+ /// forge-dynamicConfig: default.fuzz.runs = 32
+ /// forge-dynamicConfig: ccip.fuzz.runs = 32
+ function test_Fuzz_ForwardFromRouter_Success(address originalSender, address receiver, uint96 feeTokenAmount) public {
+ // To avoid RouterMustSetOriginalSender
+ vm.assume(originalSender != address(0));
+ vm.assume(uint160(receiver) >= Internal.PRECOMPILE_SPACE);
+ feeTokenAmount = uint96(bound(feeTokenAmount, 0, MAX_MSG_FEES_JUELS));
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.receiver = abi.encode(receiver);
+
+ // Make sure the tokens are in the contract
+ deal(s_sourceFeeToken, address(s_onRamp), feeTokenAmount);
+
+ Internal.EVM2AnyRampMessage memory expectedEvent = _messageToEvent(message, 1, 1, feeTokenAmount, originalSender);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.FeePaid(s_sourceFeeToken, feeTokenAmount);
+ vm.expectEmit(false, false, false, true);
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, expectedEvent);
+
+ // Assert the message Id is correct
+ assertEq(
+ expectedEvent.header.messageId,
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeTokenAmount, originalSender)
+ );
+ }
+
+ function test_forwardFromRouter_WithValidation_Success() public {
+ _enableOutboundMessageValidator();
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT * 2}));
+ uint256 feeAmount = 1234567890;
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 1e18;
+ message.tokenAmounts[0].token = s_sourceTokens[0];
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+ s_outboundMessageValidator.setMessageIdValidationState(keccak256(abi.encode(message)), false);
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.CCIPSendRequested(DEST_CHAIN_SELECTOR, _messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ // Reverts
+
+ function test_Paused_Revert() public {
+ // We pause by disabling the whitelist
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ address router = address(0);
+ s_onRamp.setDynamicConfig(_generateDynamicMultiOnRampConfig(router, address(2)));
+ vm.expectRevert(EVM2EVMMultiOnRamp.MustBeCalledByRouter.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, OWNER);
+ }
+
+ function test_InvalidExtraArgsTag_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = bytes("bad args");
+
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidExtraArgsTag.selector);
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_Permissions_Revert() public {
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ vm.expectRevert(EVM2EVMMultiOnRamp.MustBeCalledByRouter.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, OWNER);
+ }
+
+ function test_OriginalSender_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOnRamp.RouterMustSetOriginalSender.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, address(0));
+ }
+
+ function test_MessageValidationError_Revert() public {
+ _enableOutboundMessageValidator();
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT * 2}));
+ uint256 feeAmount = 1234567890;
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 1e18;
+ message.tokenAmounts[0].token = s_sourceTokens[0];
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+ s_outboundMessageValidator.setMessageIdValidationState(keccak256(abi.encode(message)), true);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(IMessageInterceptor.MessageValidationError.selector, bytes("Invalid message"))
+ );
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_CannotSendZeroTokens_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 0;
+ message.tokenAmounts[0].token = s_sourceTokens[0];
+ vm.expectRevert(EVM2EVMMultiOnRamp.CannotSendZeroTokens.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, STRANGER);
+ }
+
+ function test_UnsupportedToken_Revert() public {
+ address wrongToken = address(1);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].token = wrongToken;
+ message.tokenAmounts[0].amount = 1;
+
+ // We need to set the price of this new token to be able to reach
+ // the proper revert point. This must be called by the owner.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(wrongToken, 1);
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ // Change back to the router
+ vm.startPrank(address(s_sourceRouter));
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOnRamp.UnsupportedToken.selector, wrongToken));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_forwardFromRouter_UnsupportedToken_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 1;
+ message.tokenAmounts[0].token = address(1);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOnRamp.UnsupportedToken.selector, message.tokenAmounts[0].token));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_MesssageFeeTooHigh_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.MessageFeeTooHigh.selector, MAX_MSG_FEES_JUELS + 1, MAX_MSG_FEES_JUELS)
+ );
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, MAX_MSG_FEES_JUELS + 1, OWNER);
+ }
+
+ function test_SourceTokenDataTooLarge_Revert() public {
+ address sourceETH = s_sourceTokens[1];
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ MaybeRevertingBurnMintTokenPool newPool = new MaybeRevertingBurnMintTokenPool(
+ BurnMintERC677(sourceETH), new address[](0), address(s_mockRMN), address(s_sourceRouter)
+ );
+ BurnMintERC677(sourceETH).grantMintAndBurnRoles(address(newPool));
+ deal(address(sourceETH), address(newPool), type(uint256).max);
+
+ // Add TokenPool to OnRamp
+ s_tokenAdminRegistry.setPool(sourceETH, address(newPool));
+
+ // Allow chain in TokenPool
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destTokenPool),
+ remoteTokenAddress: abi.encode(s_destToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ newPool.applyChainUpdates(chainUpdates);
+
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(address(sourceETH), 1000);
+
+ // No data set, should succeed
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set max data length, should succeed
+ vm.startPrank(OWNER);
+ newPool.setSourceTokenData(new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES));
+
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set data to max length +1, should revert
+ vm.startPrank(OWNER);
+ newPool.setSourceTokenData(new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES + 1));
+
+ vm.startPrank(address(s_sourceRouter));
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.SourceTokenDataTooLarge.selector, sourceETH));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set token config to allow larger data
+ vm.startPrank(OWNER);
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ _generateTokenTransferFeeConfigArgs(1, 1);
+ tokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token = sourceETH;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig = PriceRegistry
+ .TokenTransferFeeConfig({
+ minFeeUSDCents: 1,
+ maxFeeUSDCents: 0,
+ deciBps: 0,
+ destGasOverhead: 0,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) + 32,
+ isEnabled: true
+ });
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ tokenTransferFeeConfigArgs, new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set the token data larger than the configured token data, should revert
+ vm.startPrank(OWNER);
+ newPool.setSourceTokenData(new bytes(uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) + 32 + 1));
+
+ vm.startPrank(address(s_sourceRouter));
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.SourceTokenDataTooLarge.selector, sourceETH));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+}
+
+contract EVM2EVMMultiOnRamp_getSupportedTokens is EVM2EVMMultiOnRampSetup {
+ function test_GetSupportedTokens_Revert() public {
+ vm.expectRevert(EVM2EVMMultiOnRamp.GetSupportedTokensFunctionalityRemovedCheckAdminRegistry.selector);
+ s_onRamp.getSupportedTokens(DEST_CHAIN_SELECTOR);
+ }
+}
+
+contract EVM2EVMMultiOnRamp_getFee is EVM2EVMMultiOnRampSetup {
+ using USDPriceWith18Decimals for uint224;
+
+ function test_EmptyMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = testTokens[i];
+
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ uint256 expectedFeeAmount = s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+
+ assertEq(expectedFeeAmount, feeAmount);
+ }
+ }
+
+ function test_SingleTokenMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 tokenAmount = 10000e18;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, tokenAmount);
+ message.feeToken = testTokens[i];
+
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ uint256 expectedFeeAmount = s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+
+ assertEq(expectedFeeAmount, feeAmount);
+ }
+ }
+
+ // Reverts
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMMultiOnRamp.CursedByRMN.selector, DEST_CHAIN_SELECTOR));
+ s_onRamp.getFee(DEST_CHAIN_SELECTOR, _generateEmptyMessage());
+ }
+
+ function test_EnforceOutOfOrder_Revert() public {
+ // Update dynamic config to enforce allowOutOfOrderExecution = true.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ destChainConfigArgs[0].destChainConfig.enforceOutOfOrder = true;
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ vm.stopPrank();
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ // Empty extraArgs to should revert since it enforceOutOfOrder is true.
+ message.extraArgs = "";
+
+ vm.expectRevert(PriceRegistry.ExtraArgOutOfOrderExecutionMustBeTrue.selector);
+ s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+}
+
+contract EVM2EVMMultiOnRamp_setDynamicConfig is EVM2EVMMultiOnRampSetup {
+ function test_SetDynamicConfig_Success() public {
+ EVM2EVMMultiOnRamp.StaticConfig memory staticConfig = s_onRamp.getStaticConfig();
+ EVM2EVMMultiOnRamp.DynamicConfig memory newConfig = EVM2EVMMultiOnRamp.DynamicConfig({
+ router: address(2134),
+ priceRegistry: address(23423),
+ messageValidator: makeAddr("messageValidator"),
+ feeAggregator: FEE_AGGREGATOR
+ });
+
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.ConfigSet(staticConfig, newConfig);
+
+ s_onRamp.setDynamicConfig(newConfig);
+
+ EVM2EVMMultiOnRamp.DynamicConfig memory gotDynamicConfig = s_onRamp.getDynamicConfig();
+ assertEq(newConfig.router, gotDynamicConfig.router);
+ assertEq(newConfig.priceRegistry, gotDynamicConfig.priceRegistry);
+ }
+
+ // Reverts
+
+ function test_SetConfigInvalidConfigPriceRegistryEqAddressZero_Revert() public {
+ EVM2EVMMultiOnRamp.DynamicConfig memory newConfig = EVM2EVMMultiOnRamp.DynamicConfig({
+ router: address(2134),
+ priceRegistry: address(0),
+ feeAggregator: FEE_AGGREGATOR,
+ messageValidator: makeAddr("messageValidator")
+ });
+
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ s_onRamp.setDynamicConfig(newConfig);
+ }
+
+ function test_SetConfigInvalidConfig_Revert() public {
+ EVM2EVMMultiOnRamp.DynamicConfig memory newConfig = EVM2EVMMultiOnRamp.DynamicConfig({
+ router: address(1),
+ priceRegistry: address(23423),
+ messageValidator: address(0),
+ feeAggregator: FEE_AGGREGATOR
+ });
+
+ // Invalid price reg reverts.
+ newConfig.priceRegistry = address(0);
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ s_onRamp.setDynamicConfig(newConfig);
+ }
+
+ function test_SetConfigInvalidConfigFeeAggregatorEqAddressZero_Revert() public {
+ EVM2EVMMultiOnRamp.DynamicConfig memory newConfig = EVM2EVMMultiOnRamp.DynamicConfig({
+ router: address(2134),
+ priceRegistry: address(23423),
+ messageValidator: address(0),
+ feeAggregator: address(0)
+ });
+ vm.expectRevert(EVM2EVMMultiOnRamp.InvalidConfig.selector);
+ s_onRamp.setDynamicConfig(newConfig);
+ }
+
+ function test_SetConfigOnlyOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_onRamp.setDynamicConfig(_generateDynamicMultiOnRampConfig(address(1), address(2)));
+ vm.startPrank(ADMIN);
+ vm.expectRevert("Only callable by owner");
+ s_onRamp.setDynamicConfig(_generateDynamicMultiOnRampConfig(address(1), address(2)));
+ }
+}
+
+contract EVM2EVMMultiOnRamp_withdrawFeeTokens is EVM2EVMMultiOnRampSetup {
+ mapping(address => uint256) internal s_nopFees;
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ // Since we'll mostly be testing for valid calls from the router we'll
+ // mock all calls to be originating from the router and re-mock in
+ // tests that require failure.
+ vm.startPrank(address(s_sourceRouter));
+
+ uint256 feeAmount = 1234567890;
+
+ // Send a bunch of messages, increasing the juels in the contract
+ for (uint256 i = 0; i < s_sourceFeeTokens.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = s_sourceFeeTokens[i % s_sourceFeeTokens.length];
+ uint256 newFeeTokenBalance = IERC20(message.feeToken).balanceOf(address(s_onRamp)) + feeAmount;
+ deal(message.feeToken, address(s_onRamp), newFeeTokenBalance);
+ s_nopFees[message.feeToken] = newFeeTokenBalance;
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+ }
+
+ function test_Fuzz_WithdrawFeeTokens_Success(uint256[5] memory amounts) public {
+ vm.startPrank(OWNER);
+ address[] memory feeTokens = new address[](amounts.length);
+ for (uint256 i = 0; i < amounts.length; ++i) {
+ vm.assume(amounts[i] > 0);
+ feeTokens[i] = _deploySourceToken("", amounts[i], 18);
+ IERC20(feeTokens[i]).transfer(address(s_onRamp), amounts[i]);
+ }
+
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+
+ for (uint256 i = 0; i < feeTokens.length; ++i) {
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.FeeTokenWithdrawn(FEE_AGGREGATOR, feeTokens[i], amounts[i]);
+ }
+
+ s_onRamp.withdrawFeeTokens();
+
+ for (uint256 i = 0; i < feeTokens.length; ++i) {
+ assertEq(IERC20(feeTokens[i]).balanceOf(FEE_AGGREGATOR), amounts[i]);
+ assertEq(IERC20(feeTokens[i]).balanceOf(address(s_onRamp)), 0);
+ }
+ }
+
+ function test_WithdrawFeeTokens_Success() public {
+ vm.expectEmit();
+ emit EVM2EVMMultiOnRamp.FeeTokenWithdrawn(FEE_AGGREGATOR, s_sourceFeeToken, s_nopFees[s_sourceFeeToken]);
+
+ s_onRamp.withdrawFeeTokens();
+
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(FEE_AGGREGATOR), s_nopFees[s_sourceFeeToken]);
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp)), 0);
+ }
+}
+
+contract EVM2EVMMultiOnRamp_getTokenPool is EVM2EVMMultiOnRampSetup {
+ function test_GetTokenPool_Success() public view {
+ assertEq(
+ s_sourcePoolByToken[s_sourceTokens[0]],
+ address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(s_sourceTokens[0])))
+ );
+ assertEq(
+ s_sourcePoolByToken[s_sourceTokens[1]],
+ address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(s_sourceTokens[1])))
+ );
+
+ address wrongToken = address(123);
+ address nonExistentPool = address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(wrongToken)));
+
+ assertEq(address(0), nonExistentPool);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMMultiOnRampSetup.t.sol b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMMultiOnRampSetup.t.sol
new file mode 100644
index 00000000000..f085185753d
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMMultiOnRampSetup.t.sol
@@ -0,0 +1,180 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+
+import {AuthorizedCallers} from "../../../shared/access/AuthorizedCallers.sol";
+import {NonceManager} from "../../NonceManager.sol";
+import {PriceRegistry} from "../../PriceRegistry.sol";
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {EVM2EVMMultiOnRamp} from "../../onRamp/EVM2EVMMultiOnRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+import {TokenSetup} from "../TokenSetup.t.sol";
+import {EVM2EVMMultiOnRampHelper} from "../helpers/EVM2EVMMultiOnRampHelper.sol";
+import {MessageInterceptorHelper} from "../helpers/MessageInterceptorHelper.sol";
+import {PriceRegistryFeeSetup} from "../priceRegistry/PriceRegistry.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract EVM2EVMMultiOnRampSetup is TokenSetup, PriceRegistryFeeSetup {
+ uint256 internal immutable i_tokenAmount0 = 9;
+ uint256 internal immutable i_tokenAmount1 = 7;
+
+ bytes32 internal s_metadataHash;
+
+ EVM2EVMMultiOnRampHelper internal s_onRamp;
+ MessageInterceptorHelper internal s_outboundMessageValidator;
+ address[] internal s_offRamps;
+ NonceManager internal s_outboundNonceManager;
+
+ function setUp() public virtual override(TokenSetup, PriceRegistryFeeSetup) {
+ TokenSetup.setUp();
+ PriceRegistryFeeSetup.setUp();
+
+ s_outboundMessageValidator = new MessageInterceptorHelper();
+ s_outboundNonceManager = new NonceManager(new address[](0));
+ (s_onRamp, s_metadataHash) = _deployOnRamp(
+ SOURCE_CHAIN_SELECTOR, address(s_sourceRouter), address(s_outboundNonceManager), address(s_tokenAdminRegistry)
+ );
+
+ s_offRamps = new address[](2);
+ s_offRamps[0] = address(10);
+ s_offRamps[1] = address(11);
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](2);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: address(s_onRamp)});
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: s_offRamps[0]});
+ offRampUpdates[1] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: s_offRamps[1]});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+
+ // Pre approve the first token so the gas estimates of the tests
+ // only cover actual gas usage from the ramps
+ IERC20(s_sourceTokens[0]).approve(address(s_sourceRouter), 2 ** 128);
+ IERC20(s_sourceTokens[1]).approve(address(s_sourceRouter), 2 ** 128);
+ }
+
+ function _generateTokenMessage() public view returns (Client.EVM2AnyMessage memory) {
+ Client.EVMTokenAmount[] memory tokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ tokenAmounts[0].amount = i_tokenAmount0;
+ tokenAmounts[1].amount = i_tokenAmount1;
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _messageToEvent(
+ Client.EVM2AnyMessage memory message,
+ uint64 seqNum,
+ uint64 nonce,
+ uint256 feeTokenAmount,
+ address originalSender
+ ) public view returns (Internal.EVM2AnyRampMessage memory) {
+ return _messageToEvent(
+ message,
+ SOURCE_CHAIN_SELECTOR,
+ DEST_CHAIN_SELECTOR,
+ seqNum,
+ nonce,
+ feeTokenAmount,
+ originalSender,
+ s_metadataHash,
+ s_tokenAdminRegistry
+ );
+ }
+
+ function _generateDynamicMultiOnRampConfig(
+ address router,
+ address priceRegistry
+ ) internal pure returns (EVM2EVMMultiOnRamp.DynamicConfig memory) {
+ return EVM2EVMMultiOnRamp.DynamicConfig({
+ router: router,
+ priceRegistry: priceRegistry,
+ messageValidator: address(0),
+ feeAggregator: FEE_AGGREGATOR
+ });
+ }
+
+ // Slicing is only available for calldata. So we have to build a new bytes array.
+ function _removeFirst4Bytes(bytes memory data) internal pure returns (bytes memory) {
+ bytes memory result = new bytes(data.length - 4);
+ for (uint256 i = 4; i < data.length; ++i) {
+ result[i - 4] = data[i];
+ }
+ return result;
+ }
+
+ function _deployOnRamp(
+ uint64 sourceChainSelector,
+ address sourceRouter,
+ address nonceManager,
+ address tokenAdminRegistry
+ ) internal returns (EVM2EVMMultiOnRampHelper, bytes32 metadataHash) {
+ EVM2EVMMultiOnRampHelper onRamp = new EVM2EVMMultiOnRampHelper(
+ EVM2EVMMultiOnRamp.StaticConfig({
+ chainSelector: sourceChainSelector,
+ rmnProxy: address(s_mockRMN),
+ nonceManager: nonceManager,
+ tokenAdminRegistry: tokenAdminRegistry
+ }),
+ _generateDynamicMultiOnRampConfig(sourceRouter, address(s_priceRegistry))
+ );
+
+ address[] memory authorizedCallers = new address[](1);
+ authorizedCallers[0] = address(onRamp);
+
+ NonceManager(nonceManager).applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: authorizedCallers, removedCallers: new address[](0)})
+ );
+
+ return (
+ onRamp,
+ keccak256(abi.encode(Internal.EVM_2_ANY_MESSAGE_HASH, sourceChainSelector, DEST_CHAIN_SELECTOR, address(onRamp)))
+ );
+ }
+
+ function _enableOutboundMessageValidator() internal {
+ (, address msgSender,) = vm.readCallers();
+
+ bool resetPrank = false;
+
+ if (msgSender != OWNER) {
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ resetPrank = true;
+ }
+
+ EVM2EVMMultiOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+ dynamicConfig.messageValidator = address(s_outboundMessageValidator);
+ s_onRamp.setDynamicConfig(dynamicConfig);
+
+ if (resetPrank) {
+ vm.stopPrank();
+ vm.startPrank(msgSender);
+ }
+ }
+
+ function _assertStaticConfigsEqual(
+ EVM2EVMMultiOnRamp.StaticConfig memory a,
+ EVM2EVMMultiOnRamp.StaticConfig memory b
+ ) internal pure {
+ assertEq(a.chainSelector, b.chainSelector);
+ assertEq(a.rmnProxy, b.rmnProxy);
+ assertEq(a.tokenAdminRegistry, b.tokenAdminRegistry);
+ }
+
+ function _assertDynamicConfigsEqual(
+ EVM2EVMMultiOnRamp.DynamicConfig memory a,
+ EVM2EVMMultiOnRamp.DynamicConfig memory b
+ ) internal pure {
+ assertEq(a.router, b.router);
+ assertEq(a.priceRegistry, b.priceRegistry);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMOnRamp.t.sol b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMOnRamp.t.sol
new file mode 100644
index 00000000000..197a87b7081
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMOnRamp.t.sol
@@ -0,0 +1,1986 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITokenAdminRegistry} from "../../interfaces/ITokenAdminRegistry.sol";
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {AggregateRateLimiter} from "../../AggregateRateLimiter.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {USDPriceWith18Decimals} from "../../libraries/USDPriceWith18Decimals.sol";
+import {EVM2EVMOnRamp} from "../../onRamp/EVM2EVMOnRamp.sol";
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import "./EVM2EVMOnRampSetup.t.sol";
+
+contract EVM2EVMOnRamp_constructor is EVM2EVMOnRampSetup {
+ function test_Constructor_Success() public {
+ EVM2EVMOnRamp.StaticConfig memory staticConfig = EVM2EVMOnRamp.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ defaultTxGasLimit: GAS_LIMIT,
+ maxNopFeesJuels: MAX_NOP_FEES_JUELS,
+ prevOnRamp: address(0),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ });
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig =
+ generateDynamicOnRampConfig(address(s_sourceRouter), address(s_priceRegistry));
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.ConfigSet(staticConfig, dynamicConfig);
+
+ s_onRamp = new EVM2EVMOnRampHelper(
+ staticConfig,
+ dynamicConfig,
+ getOutboundRateLimiterConfig(),
+ s_feeTokenConfigArgs,
+ s_tokenTransferFeeConfigArgs,
+ getNopsAndWeights()
+ );
+
+ EVM2EVMOnRamp.StaticConfig memory gotStaticConfig = s_onRamp.getStaticConfig();
+ assertEq(staticConfig.linkToken, gotStaticConfig.linkToken);
+ assertEq(staticConfig.chainSelector, gotStaticConfig.chainSelector);
+ assertEq(staticConfig.destChainSelector, gotStaticConfig.destChainSelector);
+ assertEq(staticConfig.defaultTxGasLimit, gotStaticConfig.defaultTxGasLimit);
+ assertEq(staticConfig.maxNopFeesJuels, gotStaticConfig.maxNopFeesJuels);
+ assertEq(staticConfig.prevOnRamp, gotStaticConfig.prevOnRamp);
+ assertEq(staticConfig.rmnProxy, gotStaticConfig.rmnProxy);
+
+ EVM2EVMOnRamp.DynamicConfig memory gotDynamicConfig = s_onRamp.getDynamicConfig();
+ assertEq(dynamicConfig.router, gotDynamicConfig.router);
+ assertEq(dynamicConfig.maxNumberOfTokensPerMsg, gotDynamicConfig.maxNumberOfTokensPerMsg);
+ assertEq(dynamicConfig.destGasOverhead, gotDynamicConfig.destGasOverhead);
+ assertEq(dynamicConfig.destGasPerPayloadByte, gotDynamicConfig.destGasPerPayloadByte);
+ assertEq(dynamicConfig.priceRegistry, gotDynamicConfig.priceRegistry);
+ assertEq(dynamicConfig.maxDataBytes, gotDynamicConfig.maxDataBytes);
+ assertEq(dynamicConfig.maxPerMsgGasLimit, gotDynamicConfig.maxPerMsgGasLimit);
+
+ // Initial values
+ assertEq("EVM2EVMOnRamp 1.5.0-dev", s_onRamp.typeAndVersion());
+ assertEq(OWNER, s_onRamp.owner());
+ assertEq(1, s_onRamp.getExpectedNextSequenceNumber());
+ }
+}
+
+contract EVM2EVMOnRamp_payNops_fuzz is EVM2EVMOnRampSetup {
+ function test_Fuzz_NopPayNops_Success(uint96 nopFeesJuels) public {
+ (EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights, uint256 weightsTotal) = s_onRamp.getNops();
+ // To avoid NoFeesToPay
+ vm.assume(nopFeesJuels > weightsTotal);
+ vm.assume(nopFeesJuels < MAX_NOP_FEES_JUELS);
+
+ // Set Nop fee juels
+ deal(s_sourceFeeToken, address(s_onRamp), nopFeesJuels);
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), nopFeesJuels, OWNER);
+
+ vm.startPrank(OWNER);
+
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+ s_onRamp.payNops();
+ for (uint256 i = 0; i < nopsAndWeights.length; ++i) {
+ uint256 expectedPayout = (totalJuels * nopsAndWeights[i].weight) / weightsTotal;
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(nopsAndWeights[i].nop), expectedPayout);
+ }
+ }
+}
+
+contract EVM2EVMNopsFeeSetup is EVM2EVMOnRampSetup {
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ // Since we'll mostly be testing for valid calls from the router we'll
+ // mock all calls to be originating from the router and re-mock in
+ // tests that require failure.
+ vm.startPrank(address(s_sourceRouter));
+
+ uint256 feeAmount = 1234567890;
+ uint256 numberOfMessages = 5;
+
+ // Send a bunch of messages, increasing the juels in the contract
+ for (uint256 i = 0; i < numberOfMessages; ++i) {
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), feeAmount, OWNER);
+ }
+
+ assertEq(s_onRamp.getNopFeesJuels(), feeAmount * numberOfMessages);
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp)), feeAmount * numberOfMessages);
+ }
+}
+
+contract EVM2EVMOnRamp_payNops is EVM2EVMNopsFeeSetup {
+ function test_OwnerPayNops_Success() public {
+ vm.startPrank(OWNER);
+
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+ s_onRamp.payNops();
+ (EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights, uint256 weightsTotal) = s_onRamp.getNops();
+ for (uint256 i = 0; i < nopsAndWeights.length; ++i) {
+ uint256 expectedPayout = (nopsAndWeights[i].weight * totalJuels) / weightsTotal;
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(nopsAndWeights[i].nop), expectedPayout);
+ }
+ }
+
+ function test_AdminPayNops_Success() public {
+ vm.startPrank(ADMIN);
+
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+ s_onRamp.payNops();
+ (EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights, uint256 weightsTotal) = s_onRamp.getNops();
+ for (uint256 i = 0; i < nopsAndWeights.length; ++i) {
+ uint256 expectedPayout = (nopsAndWeights[i].weight * totalJuels) / weightsTotal;
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(nopsAndWeights[i].nop), expectedPayout);
+ }
+ }
+
+ function test_NopPayNops_Success() public {
+ vm.startPrank(getNopsAndWeights()[0].nop);
+
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+ s_onRamp.payNops();
+ (EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights, uint256 weightsTotal) = s_onRamp.getNops();
+ for (uint256 i = 0; i < nopsAndWeights.length; ++i) {
+ uint256 expectedPayout = (nopsAndWeights[i].weight * totalJuels) / weightsTotal;
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(nopsAndWeights[i].nop), expectedPayout);
+ }
+ }
+
+ function test_PayNopsSuccessAfterSetNops() public {
+ vm.startPrank(OWNER);
+
+ // set 2 nops, 1 from previous, 1 new
+ address prevNop = getNopsAndWeights()[0].nop;
+ address newNop = STRANGER;
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](2);
+ nopsAndWeights[0] = EVM2EVMOnRamp.NopAndWeight({nop: prevNop, weight: 1});
+ nopsAndWeights[1] = EVM2EVMOnRamp.NopAndWeight({nop: newNop, weight: 1});
+ s_onRamp.setNops(nopsAndWeights);
+
+ // refill OnRamp nops fees
+ vm.startPrank(address(s_sourceRouter));
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), feeAmount, OWNER);
+
+ vm.startPrank(newNop);
+ uint256 prevNopBalance = IERC20(s_sourceFeeToken).balanceOf(prevNop);
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+
+ s_onRamp.payNops();
+
+ assertEq(totalJuels / 2 + prevNopBalance, IERC20(s_sourceFeeToken).balanceOf(prevNop));
+ assertEq(totalJuels / 2, IERC20(s_sourceFeeToken).balanceOf(newNop));
+ }
+
+ // Reverts
+
+ function test_InsufficientBalance_Revert() public {
+ vm.startPrank(address(s_onRamp));
+ IERC20(s_sourceFeeToken).transfer(OWNER, IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp)));
+ vm.startPrank(OWNER);
+ vm.expectRevert(EVM2EVMOnRamp.InsufficientBalance.selector);
+ s_onRamp.payNops();
+ }
+
+ function test_WrongPermissions_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdminOrNop.selector);
+ s_onRamp.payNops();
+ }
+
+ function test_NoFeesToPay_Revert() public {
+ vm.startPrank(OWNER);
+ s_onRamp.payNops();
+ vm.expectRevert(EVM2EVMOnRamp.NoFeesToPay.selector);
+ s_onRamp.payNops();
+ }
+
+ function test_NoNopsToPay_Revert() public {
+ vm.startPrank(OWNER);
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](0);
+ s_onRamp.setNops(nopsAndWeights);
+ vm.expectRevert(EVM2EVMOnRamp.NoNopsToPay.selector);
+ s_onRamp.payNops();
+ }
+}
+
+contract EVM2EVMOnRamp_linkAvailableForPayment is EVM2EVMNopsFeeSetup {
+ function test_LinkAvailableForPayment_Success() public {
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+ uint256 linkBalance = IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp));
+
+ assertEq(int256(linkBalance - totalJuels), s_onRamp.linkAvailableForPayment());
+
+ vm.startPrank(OWNER);
+ s_onRamp.payNops();
+
+ assertEq(int256(linkBalance - totalJuels), s_onRamp.linkAvailableForPayment());
+ }
+
+ function test_InsufficientLinkBalance_Success() public {
+ uint256 totalJuels = s_onRamp.getNopFeesJuels();
+ uint256 linkBalance = IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp));
+
+ vm.startPrank(address(s_onRamp));
+
+ uint256 linkRemaining = 1;
+ IERC20(s_sourceFeeToken).transfer(OWNER, linkBalance - linkRemaining);
+
+ vm.startPrank(STRANGER);
+ assertEq(int256(linkRemaining) - int256(totalJuels), s_onRamp.linkAvailableForPayment());
+ }
+}
+
+contract EVM2EVMOnRamp_forwardFromRouter is EVM2EVMOnRampSetup {
+ struct LegacyExtraArgs {
+ uint256 gasLimit;
+ bool strict;
+ }
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = s_sourceTokens[1];
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+
+ // Since we'll mostly be testing for valid calls from the router we'll
+ // mock all calls to be originating from the router and re-mock in
+ // tests that require failure.
+ vm.startPrank(address(s_sourceRouter));
+ }
+
+ function test_ForwardFromRouterSuccessCustomExtraArgs() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT * 2}));
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterSuccessLegacyExtraArgs() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs =
+ abi.encodeWithSelector(Client.EVM_EXTRA_ARGS_V1_TAG, LegacyExtraArgs({gasLimit: GAS_LIMIT * 2, strict: true}));
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ // We expect the message to be emitted with strict = false.
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouter_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterExtraArgsV2_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: true})
+ );
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_ForwardFromRouterExtraArgsV2AllowOutOfOrderTrue_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: true})
+ );
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+
+ function test_Fuzz_EnforceOutOfOrder(bool enforce, bool allowOutOfOrderExecution) public {
+ // Update dynamic config to enforce allowOutOfOrderExecution = defaultVal.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+ s_onRamp.setDynamicConfig(
+ EVM2EVMOnRamp.DynamicConfig({
+ router: dynamicConfig.router,
+ maxNumberOfTokensPerMsg: dynamicConfig.maxNumberOfTokensPerMsg,
+ destGasOverhead: dynamicConfig.destGasOverhead,
+ destGasPerPayloadByte: dynamicConfig.destGasPerPayloadByte,
+ destDataAvailabilityOverheadGas: dynamicConfig.destDataAvailabilityOverheadGas,
+ destGasPerDataAvailabilityByte: dynamicConfig.destGasPerDataAvailabilityByte,
+ destDataAvailabilityMultiplierBps: dynamicConfig.destDataAvailabilityMultiplierBps,
+ priceRegistry: dynamicConfig.priceRegistry,
+ maxDataBytes: dynamicConfig.maxDataBytes,
+ maxPerMsgGasLimit: dynamicConfig.maxPerMsgGasLimit,
+ defaultTokenFeeUSDCents: dynamicConfig.defaultTokenFeeUSDCents,
+ defaultTokenDestGasOverhead: dynamicConfig.defaultTokenDestGasOverhead,
+ defaultTokenDestBytesOverhead: dynamicConfig.defaultTokenDestBytesOverhead,
+ enforceOutOfOrder: enforce
+ })
+ );
+ vm.stopPrank();
+
+ vm.startPrank(address(s_sourceRouter));
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG,
+ Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: allowOutOfOrderExecution})
+ );
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ if (enforce) {
+ // If enforcement is on, only true should be allowed.
+ if (allowOutOfOrderExecution) {
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ } else {
+ vm.expectRevert(EVM2EVMOnRamp.ExtraArgOutOfOrderExecutionMustBeTrue.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+ } else {
+ // no enforcement should allow any value.
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, feeAmount, OWNER));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+ }
+
+ function test_ShouldIncrementSeqNumAndNonce_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ for (uint64 i = 1; i < 4; ++i) {
+ uint64 nonceBefore = s_onRamp.getSenderNonce(OWNER);
+ uint64 sequenceNumberBefore = s_onRamp.getSequenceNumber();
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, i, i, 0, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ uint64 nonceAfter = s_onRamp.getSenderNonce(OWNER);
+ uint64 sequenceNumberAfter = s_onRamp.getSequenceNumber();
+ assertEq(nonceAfter, nonceBefore + 1);
+ assertEq(sequenceNumberAfter, sequenceNumberBefore + 1);
+ }
+ }
+
+ function test_ShouldIncrementNonceOnlyOnOrdered_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: true})
+ );
+
+ for (uint64 i = 1; i < 4; ++i) {
+ uint64 nonceBefore = s_onRamp.getSenderNonce(OWNER);
+ uint64 sequenceNumberBefore = s_onRamp.getSequenceNumber();
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, i, i, 0, OWNER));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ uint64 nonceAfter = s_onRamp.getSenderNonce(OWNER);
+ uint64 sequenceNumberAfter = s_onRamp.getSequenceNumber();
+ assertEq(nonceAfter, nonceBefore);
+ assertEq(sequenceNumberAfter, sequenceNumberBefore + 1);
+ }
+ }
+
+ function test_forwardFromRouter_ShouldStoreLinkFees_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+
+ assertEq(IERC20(s_sourceFeeToken).balanceOf(address(s_onRamp)), feeAmount);
+ assertEq(s_onRamp.getNopFeesJuels(), feeAmount);
+ }
+
+ function test_ShouldStoreNonLinkFees() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = s_sourceTokens[1];
+
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceTokens[1]).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+
+ assertEq(IERC20(s_sourceTokens[1]).balanceOf(address(s_onRamp)), feeAmount);
+
+ // Calculate conversion done by prices contract
+ uint256 feeTokenPrice = s_priceRegistry.getTokenPrice(s_sourceTokens[1]).value;
+ uint256 linkTokenPrice = s_priceRegistry.getTokenPrice(s_sourceFeeToken).value;
+ uint256 conversionRate = (feeTokenPrice * 1e18) / linkTokenPrice;
+ uint256 expectedJuels = (feeAmount * conversionRate) / 1e18;
+
+ assertEq(s_onRamp.getNopFeesJuels(), expectedJuels);
+ }
+
+ // Make sure any valid sender, receiver and feeAmount can be handled.
+ // @TODO Temporarily setting lower fuzz run as 256 triggers snapshot gas off by 1 error.
+ // https://github.com/foundry-rs/foundry/issues/5689
+ /// forge-config: default.fuzz.runs = 32
+ /// forge-config: ccip.fuzz.runs = 32
+ function test_Fuzz_ForwardFromRouter_Success(address originalSender, address receiver, uint96 feeTokenAmount) public {
+ // To avoid RouterMustSetOriginalSender
+ vm.assume(originalSender != address(0));
+ vm.assume(uint160(receiver) >= Internal.PRECOMPILE_SPACE);
+ vm.assume(feeTokenAmount <= MAX_NOP_FEES_JUELS);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.receiver = abi.encode(receiver);
+
+ // Make sure the tokens are in the contract
+ deal(s_sourceFeeToken, address(s_onRamp), feeTokenAmount);
+
+ Internal.EVM2EVMMessage memory expectedEvent = _messageToEvent(message, 1, 1, feeTokenAmount, originalSender);
+
+ vm.expectEmit(false, false, false, true);
+ emit EVM2EVMOnRamp.CCIPSendRequested(expectedEvent);
+
+ // Assert the message Id is correct
+ assertEq(
+ expectedEvent.messageId, s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeTokenAmount, originalSender)
+ );
+ // Assert the fee token amount is correctly assigned to the nop fee pool
+ assertEq(feeTokenAmount, s_onRamp.getNopFeesJuels());
+ }
+
+ function test_OverValueWithARLOff_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 10;
+ message.tokenAmounts[0].token = s_sourceTokens[0];
+
+ IERC20(s_sourceTokens[0]).approve(address(s_onRamp), 10);
+
+ vm.startPrank(OWNER);
+ // Set a high price to trip the ARL
+ uint224 tokenPrice = 3 ** 128;
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(s_sourceTokens[0], tokenPrice);
+ s_priceRegistry.updatePrices(priceUpdates);
+ vm.startPrank(address(s_sourceRouter));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.AggregateValueMaxCapacityExceeded.selector,
+ getOutboundRateLimiterConfig().capacity,
+ (message.tokenAmounts[0].amount * tokenPrice) / 1e18
+ )
+ );
+ // Expect to fail from ARL
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Configure ARL off for token
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory tokenTransferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(s_sourceTokens[0]);
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](1);
+ tokenTransferFeeConfigArgs[0] = EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: s_sourceTokens[0],
+ minFeeUSDCents: tokenTransferFeeConfig.minFeeUSDCents,
+ maxFeeUSDCents: tokenTransferFeeConfig.maxFeeUSDCents,
+ deciBps: tokenTransferFeeConfig.deciBps,
+ destGasOverhead: tokenTransferFeeConfig.destGasOverhead,
+ destBytesOverhead: tokenTransferFeeConfig.destBytesOverhead,
+ aggregateRateLimitEnabled: false
+ });
+ vm.startPrank(OWNER);
+ s_onRamp.setTokenTransferFeeConfig(tokenTransferFeeConfigArgs, new address[](0));
+
+ vm.startPrank(address(s_sourceRouter));
+ // Expect the call now succeeds
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ // Reverts
+
+ function test_Paused_Revert() public {
+ // We pause by disabling the whitelist
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ address router = address(0);
+ s_onRamp.setDynamicConfig(generateDynamicOnRampConfig(router, address(2)));
+ vm.expectRevert(EVM2EVMOnRamp.MustBeCalledByRouter.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, OWNER);
+ }
+
+ function test_InvalidExtraArgsTag_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = bytes("bad args");
+
+ vm.expectRevert(EVM2EVMOnRamp.InvalidExtraArgsTag.selector);
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_Unhealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(EVM2EVMOnRamp.CursedByRMN.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, OWNER);
+ }
+
+ function test_Permissions_Revert() public {
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ vm.expectRevert(EVM2EVMOnRamp.MustBeCalledByRouter.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, OWNER);
+ }
+
+ function test_OriginalSender_Revert() public {
+ vm.expectRevert(EVM2EVMOnRamp.RouterMustSetOriginalSender.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), 0, address(0));
+ }
+
+ function test_MessageTooLarge_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.data = new bytes(MAX_DATA_SIZE + 1);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.MessageTooLarge.selector, MAX_DATA_SIZE, message.data.length));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, STRANGER);
+ }
+
+ function test_TooManyTokens_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint256 tooMany = MAX_TOKENS_LENGTH + 1;
+ message.tokenAmounts = new Client.EVMTokenAmount[](tooMany);
+ vm.expectRevert(EVM2EVMOnRamp.UnsupportedNumberOfTokens.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, STRANGER);
+ }
+
+ function test_CannotSendZeroTokens_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 0;
+ message.tokenAmounts[0].token = s_sourceTokens[0];
+ vm.expectRevert(EVM2EVMOnRamp.CannotSendZeroTokens.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, STRANGER);
+ }
+
+ function test_UnsupportedToken_Revert() public {
+ address wrongToken = address(1);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].token = wrongToken;
+ message.tokenAmounts[0].amount = 1;
+
+ // We need to set the price of this new token to be able to reach
+ // the proper revert point. This must be called by the owner.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(wrongToken, 1);
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ // Change back to the router
+ vm.startPrank(address(s_sourceRouter));
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.UnsupportedToken.selector, wrongToken));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_MaxCapacityExceeded_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 2 ** 128;
+ message.tokenAmounts[0].token = s_sourceTokens[0];
+
+ IERC20(s_sourceTokens[0]).approve(address(s_onRamp), 2 ** 128);
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.AggregateValueMaxCapacityExceeded.selector,
+ getOutboundRateLimiterConfig().capacity,
+ (message.tokenAmounts[0].amount * s_sourceTokenPrices[0]) / 1e18
+ )
+ );
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_PriceNotFoundForToken_Revert() public {
+ // Set token price to 0
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ s_priceRegistry.updatePrices(getSingleTokenPriceUpdateStruct(CUSTOM_TOKEN, 0));
+
+ vm.startPrank(address(s_sourceRouter));
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].token = CUSTOM_TOKEN;
+ message.tokenAmounts[0].amount = 1;
+
+ vm.expectRevert(abi.encodeWithSelector(AggregateRateLimiter.PriceNotFoundForToken.selector, CUSTOM_TOKEN));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ // Asserts gasLimit must be <=maxGasLimit
+ function test_MessageGasLimitTooHigh_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: MAX_GAS_LIMIT + 1}));
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.MessageGasLimitTooHigh.selector));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_InvalidAddressEncodePacked_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.receiver = abi.encodePacked(address(234));
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, message.receiver));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 1, OWNER);
+ }
+
+ function test_InvalidAddress_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.receiver = abi.encode(type(uint208).max);
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, message.receiver));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 1, OWNER);
+ }
+
+ // We disallow sending to addresses 0-9.
+ function test_ZeroAddressReceiver_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ for (uint160 i = 0; i < 10; ++i) {
+ message.receiver = abi.encode(address(i));
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, message.receiver));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 1, OWNER);
+ }
+ }
+
+ function test_MaxFeeBalanceReached_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ vm.expectRevert(EVM2EVMOnRamp.MaxFeeBalanceReached.selector);
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, MAX_NOP_FEES_JUELS + 1, OWNER);
+ }
+
+ function test_InvalidChainSelector_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint64 wrongChainSelector = DEST_CHAIN_SELECTOR + 1;
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.InvalidChainSelector.selector, wrongChainSelector));
+
+ s_onRamp.forwardFromRouter(wrongChainSelector, message, 1, OWNER);
+ }
+
+ function test_SourceTokenDataTooLarge_Revert() public {
+ address sourceETH = s_sourceTokens[1];
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ MaybeRevertingBurnMintTokenPool newPool = new MaybeRevertingBurnMintTokenPool(
+ BurnMintERC677(sourceETH), new address[](0), address(s_mockRMN), address(s_sourceRouter)
+ );
+ BurnMintERC677(sourceETH).grantMintAndBurnRoles(address(newPool));
+ deal(address(sourceETH), address(newPool), type(uint256).max);
+
+ // Add TokenPool to OnRamp
+ s_tokenAdminRegistry.setPool(sourceETH, address(newPool));
+
+ // Allow chain in TokenPool
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destTokenPool),
+ remoteTokenAddress: abi.encode(s_destToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ newPool.applyChainUpdates(chainUpdates);
+
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(address(sourceETH), 1000);
+
+ // No data set, should succeed
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set max data length, should succeed
+ vm.startPrank(OWNER);
+ newPool.setSourceTokenData(new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES));
+
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set data to max length +1, should revert
+ vm.startPrank(OWNER);
+ newPool.setSourceTokenData(new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES + 1));
+
+ vm.startPrank(address(s_sourceRouter));
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.SourceTokenDataTooLarge.selector, sourceETH));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set token config to allow larger data
+ vm.startPrank(OWNER);
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](1);
+ tokenTransferFeeConfigArgs[0] = EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: sourceETH,
+ minFeeUSDCents: 1,
+ maxFeeUSDCents: 0,
+ deciBps: 0,
+ destGasOverhead: 0,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) + 32,
+ aggregateRateLimitEnabled: false
+ });
+ s_onRamp.setTokenTransferFeeConfig(tokenTransferFeeConfigArgs, new address[](0));
+
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ // Set the token data larger than the configured token data, should revert
+ vm.startPrank(OWNER);
+ newPool.setSourceTokenData(new bytes(uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) + 32 + 1));
+
+ vm.startPrank(address(s_sourceRouter));
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.SourceTokenDataTooLarge.selector, sourceETH));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_forwardFromRouter_UnsupportedToken_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 1;
+ message.tokenAmounts[0].token = address(1);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.UnsupportedToken.selector, message.tokenAmounts[0].token));
+
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+ }
+
+ function test_EnforceOutOfOrder_Revert() public {
+ // Update dynamic config to enforce allowOutOfOrderExecution = true.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+ s_onRamp.setDynamicConfig(
+ EVM2EVMOnRamp.DynamicConfig({
+ router: dynamicConfig.router,
+ maxNumberOfTokensPerMsg: dynamicConfig.maxNumberOfTokensPerMsg,
+ destGasOverhead: dynamicConfig.destGasOverhead,
+ destGasPerPayloadByte: dynamicConfig.destGasPerPayloadByte,
+ destDataAvailabilityOverheadGas: dynamicConfig.destDataAvailabilityOverheadGas,
+ destGasPerDataAvailabilityByte: dynamicConfig.destGasPerDataAvailabilityByte,
+ destDataAvailabilityMultiplierBps: dynamicConfig.destDataAvailabilityMultiplierBps,
+ priceRegistry: dynamicConfig.priceRegistry,
+ maxDataBytes: dynamicConfig.maxDataBytes,
+ maxPerMsgGasLimit: dynamicConfig.maxPerMsgGasLimit,
+ defaultTokenFeeUSDCents: dynamicConfig.defaultTokenFeeUSDCents,
+ defaultTokenDestGasOverhead: dynamicConfig.defaultTokenDestGasOverhead,
+ defaultTokenDestBytesOverhead: dynamicConfig.defaultTokenDestBytesOverhead,
+ enforceOutOfOrder: true
+ })
+ );
+ vm.stopPrank();
+
+ vm.startPrank(address(s_sourceRouter));
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ // Empty extraArgs to should revert since it enforceOutOfOrder is true.
+ message.extraArgs = "";
+ uint256 feeAmount = 1234567890;
+ IERC20(s_sourceFeeToken).transferFrom(OWNER, address(s_onRamp), feeAmount);
+
+ vm.expectRevert(EVM2EVMOnRamp.ExtraArgOutOfOrderExecutionMustBeTrue.selector);
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, feeAmount, OWNER);
+ }
+}
+
+contract EVM2EVMOnRamp_forwardFromRouter_upgrade is EVM2EVMOnRampSetup {
+ uint256 internal constant FEE_AMOUNT = 1234567890;
+ EVM2EVMOnRampHelper internal s_prevOnRamp;
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ s_prevOnRamp = s_onRamp;
+
+ s_onRamp = new EVM2EVMOnRampHelper(
+ EVM2EVMOnRamp.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ defaultTxGasLimit: GAS_LIMIT,
+ maxNopFeesJuels: MAX_NOP_FEES_JUELS,
+ prevOnRamp: address(s_prevOnRamp),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ generateDynamicOnRampConfig(address(s_sourceRouter), address(s_priceRegistry)),
+ getOutboundRateLimiterConfig(),
+ s_feeTokenConfigArgs,
+ s_tokenTransferFeeConfigArgs,
+ getNopsAndWeights()
+ );
+ s_onRamp.setAdmin(ADMIN);
+
+ s_metadataHash = keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, address(s_onRamp))
+ );
+
+ vm.startPrank(address(s_sourceRouter));
+ }
+
+ function test_V2_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, FEE_AMOUNT, OWNER));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+ }
+
+ function test_V2SenderNoncesReadsPreviousRamp_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint64 startNonce = s_onRamp.getSenderNonce(OWNER);
+
+ for (uint64 i = 1; i < 4; ++i) {
+ s_prevOnRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, 0, OWNER);
+
+ assertEq(startNonce + i, s_onRamp.getSenderNonce(OWNER));
+ }
+ }
+
+ function test_V2NonceStartsAtV1Nonce_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint64 startNonce = s_onRamp.getSenderNonce(OWNER);
+
+ // send 1 message from previous onramp
+ s_prevOnRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ assertEq(startNonce + 1, s_onRamp.getSenderNonce(OWNER));
+
+ // new onramp nonce should start from 2, while sequence number start from 1
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, startNonce + 2, FEE_AMOUNT, OWNER));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ assertEq(startNonce + 2, s_onRamp.getSenderNonce(OWNER));
+
+ // after another send, nonce should be 3, and sequence number be 2
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 2, startNonce + 3, FEE_AMOUNT, OWNER));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ assertEq(startNonce + 3, s_onRamp.getSenderNonce(OWNER));
+ }
+
+ function test_V2NonceNewSenderStartsAtZero_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ // send 1 message from previous onramp from OWNER
+ s_prevOnRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, OWNER);
+
+ address newSender = address(1234567);
+ // new onramp nonce should start from 1 for new sender
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(_messageToEvent(message, 1, 1, FEE_AMOUNT, newSender));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, message, FEE_AMOUNT, newSender);
+ }
+}
+
+contract EVM2EVMOnRamp_getFeeSetup is EVM2EVMOnRampSetup {
+ uint224 internal s_feeTokenPrice;
+ uint224 internal s_wrappedTokenPrice;
+ uint224 internal s_customTokenPrice;
+
+ address internal s_selfServeTokenDefaultPricing = makeAddr("self-serve-token-default-pricing");
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+
+ // Add additional pool addresses for test tokens to mark them as supported
+ s_tokenAdminRegistry.proposeAdministrator(s_sourceRouter.getWrappedNative(), OWNER);
+ s_tokenAdminRegistry.acceptAdminRole(s_sourceRouter.getWrappedNative());
+ s_tokenAdminRegistry.proposeAdministrator(CUSTOM_TOKEN, OWNER);
+ s_tokenAdminRegistry.acceptAdminRole(CUSTOM_TOKEN);
+
+ LockReleaseTokenPool wrappedNativePool = new LockReleaseTokenPool(
+ IERC20(s_sourceRouter.getWrappedNative()), new address[](0), address(s_mockRMN), true, address(s_sourceRouter)
+ );
+
+ TokenPool.ChainUpdate[] memory wrappedNativeChainUpdate = new TokenPool.ChainUpdate[](1);
+ wrappedNativeChainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(address(111111)),
+ remoteTokenAddress: abi.encode(s_destToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ wrappedNativePool.applyChainUpdates(wrappedNativeChainUpdate);
+ s_tokenAdminRegistry.setPool(s_sourceRouter.getWrappedNative(), address(wrappedNativePool));
+
+ LockReleaseTokenPool customPool = new LockReleaseTokenPool(
+ IERC20(CUSTOM_TOKEN), new address[](0), address(s_mockRMN), true, address(s_sourceRouter)
+ );
+ TokenPool.ChainUpdate[] memory customChainUpdate = new TokenPool.ChainUpdate[](1);
+ customChainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(makeAddr("random")),
+ remoteTokenAddress: abi.encode(s_destToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ customPool.applyChainUpdates(customChainUpdate);
+ s_tokenAdminRegistry.setPool(CUSTOM_TOKEN, address(customPool));
+
+ s_feeTokenPrice = s_sourceTokenPrices[0];
+ s_wrappedTokenPrice = s_sourceTokenPrices[2];
+ s_customTokenPrice = CUSTOM_TOKEN_PRICE;
+
+ // Ensure the self-serve token is set up on the admin registry
+ vm.mockCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(ITokenAdminRegistry.getPool.selector, s_selfServeTokenDefaultPricing),
+ abi.encode(makeAddr("self-serve-pool"))
+ );
+ }
+
+ function calcUSDValueFromTokenAmount(uint224 tokenPrice, uint256 tokenAmount) internal pure returns (uint256) {
+ return (tokenPrice * tokenAmount) / 1e18;
+ }
+
+ function applyBpsRatio(uint256 tokenAmount, uint16 ratio) internal pure returns (uint256) {
+ return (tokenAmount * ratio) / 1e5;
+ }
+
+ function configUSDCentToWei(uint256 usdCent) internal pure returns (uint256) {
+ return usdCent * 1e16;
+ }
+}
+
+contract EVM2EVMOnRamp_getDataAvailabilityCost is EVM2EVMOnRamp_getFeeSetup {
+ function test_EmptyMessageCalculatesDataAvailabilityCost_Success() public view {
+ uint256 dataAvailabilityCostUSD = s_onRamp.getDataAvailabilityCost(USD_PER_DATA_AVAILABILITY_GAS, 0, 0, 0);
+
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+
+ uint256 dataAvailabilityGas = dynamicConfig.destDataAvailabilityOverheadGas
+ + dynamicConfig.destGasPerDataAvailabilityByte * Internal.MESSAGE_FIXED_BYTES;
+ uint256 expectedDataAvailabilityCostUSD =
+ USD_PER_DATA_AVAILABILITY_GAS * dataAvailabilityGas * dynamicConfig.destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD);
+ }
+
+ function test_SimpleMessageCalculatesDataAvailabilityCost_Success() public view {
+ uint256 dataAvailabilityCostUSD = s_onRamp.getDataAvailabilityCost(USD_PER_DATA_AVAILABILITY_GAS, 100, 5, 50);
+
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+
+ uint256 dataAvailabilityLengthBytes =
+ Internal.MESSAGE_FIXED_BYTES + 100 + (5 * Internal.MESSAGE_FIXED_BYTES_PER_TOKEN) + 50;
+ uint256 dataAvailabilityGas = dynamicConfig.destDataAvailabilityOverheadGas
+ + dynamicConfig.destGasPerDataAvailabilityByte * dataAvailabilityLengthBytes;
+ uint256 expectedDataAvailabilityCostUSD =
+ USD_PER_DATA_AVAILABILITY_GAS * dataAvailabilityGas * dynamicConfig.destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD);
+ }
+
+ function test_Fuzz_ZeroDataAvailabilityGasPriceAlwaysCalculatesZeroDataAvailabilityCost_Success(
+ uint64 messageDataLength,
+ uint32 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) public view {
+ uint256 dataAvailabilityCostUSD =
+ s_onRamp.getDataAvailabilityCost(0, messageDataLength, numberOfTokens, tokenTransferBytesOverhead);
+
+ assertEq(0, dataAvailabilityCostUSD);
+ }
+
+ function test_Fuzz_CalculateDataAvailabilityCost_Success(
+ uint32 destDataAvailabilityOverheadGas,
+ uint16 destGasPerDataAvailabilityByte,
+ uint16 destDataAvailabilityMultiplierBps,
+ uint112 dataAvailabilityGasPrice,
+ uint64 messageDataLength,
+ uint32 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) public {
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+ dynamicConfig.destDataAvailabilityOverheadGas = destDataAvailabilityOverheadGas;
+ dynamicConfig.destGasPerDataAvailabilityByte = destGasPerDataAvailabilityByte;
+ dynamicConfig.destDataAvailabilityMultiplierBps = destDataAvailabilityMultiplierBps;
+ s_onRamp.setDynamicConfig(dynamicConfig);
+
+ uint256 dataAvailabilityCostUSD = s_onRamp.getDataAvailabilityCost(
+ dataAvailabilityGasPrice, messageDataLength, numberOfTokens, tokenTransferBytesOverhead
+ );
+
+ uint256 dataAvailabilityLengthBytes = Internal.MESSAGE_FIXED_BYTES + messageDataLength
+ + (numberOfTokens * Internal.MESSAGE_FIXED_BYTES_PER_TOKEN) + tokenTransferBytesOverhead;
+
+ uint256 dataAvailabilityGas =
+ destDataAvailabilityOverheadGas + destGasPerDataAvailabilityByte * dataAvailabilityLengthBytes;
+ uint256 expectedDataAvailabilityCostUSD =
+ dataAvailabilityGasPrice * dataAvailabilityGas * destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD);
+ }
+}
+
+contract EVM2EVMOnRamp_getSupportedTokens is EVM2EVMOnRampSetup {
+ function test_GetSupportedTokens_Revert() public {
+ vm.expectRevert(EVM2EVMOnRamp.GetSupportedTokensFunctionalityRemovedCheckAdminRegistry.selector);
+ s_onRamp.getSupportedTokens(DEST_CHAIN_SELECTOR);
+ }
+}
+
+contract EVM2EVMOnRamp_getTokenTransferCost is EVM2EVMOnRamp_getFeeSetup {
+ using USDPriceWith18Decimals for uint224;
+
+ function test_NoTokenTransferChargesZeroFee_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(0, feeUSDWei);
+ assertEq(0, destGasOverhead);
+ assertEq(0, destBytesOverhead);
+ }
+
+ function test__getTokenTransferCost_selfServeUsesDefaults_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_selfServeTokenDefaultPricing, 1000);
+
+ // Get config to assert it isn't set
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ assertFalse(transferFeeConfig.isEnabled);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ // Assert that the default values are used
+ assertEq(uint256(DEFAULT_TOKEN_FEE_USD_CENTS) * 1e16, feeUSDWei);
+ assertEq(DEFAULT_TOKEN_DEST_GAS_OVERHEAD, destGasOverhead);
+ assertEq(DEFAULT_TOKEN_BYTES_OVERHEAD, destBytesOverhead);
+ }
+
+ function test_SmallTokenTransferChargesMinFeeAndGas_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 1000);
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(configUSDCentToWei(transferFeeConfig.minFeeUSDCents), feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, destBytesOverhead);
+ }
+
+ function test_ZeroAmountTokenTransferChargesMinFeeAndGas_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 0);
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(configUSDCentToWei(transferFeeConfig.minFeeUSDCents), feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, destBytesOverhead);
+ }
+
+ function test_LargeTokenTransferChargesMaxFeeAndGas_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 1e36);
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(configUSDCentToWei(transferFeeConfig.maxFeeUSDCents), feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, destBytesOverhead);
+ }
+
+ function test_FeeTokenBpsFee_Success() public view {
+ uint256 tokenAmount = 10000e18;
+
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, tokenAmount);
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ uint256 usdWei = calcUSDValueFromTokenAmount(s_feeTokenPrice, tokenAmount);
+ uint256 bpsUSDWei = applyBpsRatio(usdWei, s_tokenTransferFeeConfigArgs[0].deciBps);
+
+ assertEq(bpsUSDWei, feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, destBytesOverhead);
+ }
+
+ function test_WETHTokenBpsFee_Success() public view {
+ uint256 tokenAmount = 100e18;
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](1),
+ feeToken: s_sourceRouter.getWrappedNative(),
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceRouter.getWrappedNative(), amount: tokenAmount});
+
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_wrappedTokenPrice, message.tokenAmounts);
+
+ uint256 usdWei = calcUSDValueFromTokenAmount(s_wrappedTokenPrice, tokenAmount);
+ uint256 bpsUSDWei = applyBpsRatio(usdWei, s_tokenTransferFeeConfigArgs[1].deciBps);
+
+ assertEq(bpsUSDWei, feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_CustomTokenBpsFee_Success() public view {
+ uint256 tokenAmount = 200000e18;
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](1),
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: CUSTOM_TOKEN, amount: tokenAmount});
+
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory transferFeeConfig =
+ s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ uint256 usdWei = calcUSDValueFromTokenAmount(s_customTokenPrice, tokenAmount);
+ uint256 bpsUSDWei = applyBpsRatio(usdWei, s_tokenTransferFeeConfigArgs[2].deciBps);
+
+ assertEq(bpsUSDWei, feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_ZeroFeeConfigChargesMinFee_Success() public {
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](1);
+ tokenTransferFeeConfigArgs[0] = EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: s_sourceFeeToken,
+ minFeeUSDCents: 1,
+ maxFeeUSDCents: 0,
+ deciBps: 0,
+ destGasOverhead: 0,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES),
+ aggregateRateLimitEnabled: true
+ });
+ s_onRamp.setTokenTransferFeeConfig(tokenTransferFeeConfigArgs, new address[](0));
+
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 1e36);
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ // if token charges 0 bps, it should cost minFee to transfer
+ assertEq(configUSDCentToWei(tokenTransferFeeConfigArgs[0].minFeeUSDCents), feeUSDWei);
+ assertEq(0, destGasOverhead);
+ assertEq(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, destBytesOverhead);
+ }
+
+ function test_Fuzz_TokenTransferFeeDuplicateTokens_Success(uint256 transfers, uint256 amount) public view {
+ // It shouldn't be possible to pay materially lower fees by splitting up the transfers.
+ // Note it is possible to pay higher fees since the minimum fees are added.
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+ transfers = bound(transfers, 1, dynamicConfig.maxNumberOfTokensPerMsg);
+ // Cap amount to avoid overflow
+ amount = bound(amount, 0, 1e36);
+ Client.EVMTokenAmount[] memory multiple = new Client.EVMTokenAmount[](transfers);
+ for (uint256 i = 0; i < transfers; ++i) {
+ multiple[i] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: amount});
+ }
+ Client.EVMTokenAmount[] memory single = new Client.EVMTokenAmount[](1);
+ single[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: amount * transfers});
+
+ address feeToken = s_sourceRouter.getWrappedNative();
+
+ (uint256 feeSingleUSDWei, uint32 gasOverheadSingle, uint32 bytesOverheadSingle) =
+ s_onRamp.getTokenTransferCost(feeToken, s_wrappedTokenPrice, single);
+ (uint256 feeMultipleUSDWei, uint32 gasOverheadMultiple, uint32 bytesOverheadMultiple) =
+ s_onRamp.getTokenTransferCost(feeToken, s_wrappedTokenPrice, multiple);
+
+ // Note that there can be a rounding error once per split.
+ assertTrue(feeMultipleUSDWei >= (feeSingleUSDWei - dynamicConfig.maxNumberOfTokensPerMsg));
+ assertEq(gasOverheadMultiple, gasOverheadSingle * transfers);
+ assertEq(bytesOverheadMultiple, bytesOverheadSingle * transfers);
+ }
+
+ function test_MixedTokenTransferFee_Success() public view {
+ address[3] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative(), CUSTOM_TOKEN];
+ uint224[3] memory tokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice, s_customTokenPrice];
+ EVM2EVMOnRamp.TokenTransferFeeConfig[3] memory tokenTransferFeeConfigs = [
+ s_onRamp.getTokenTransferFeeConfig(testTokens[0]),
+ s_onRamp.getTokenTransferFeeConfig(testTokens[1]),
+ s_onRamp.getTokenTransferFeeConfig(testTokens[2])
+ ];
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](3),
+ feeToken: s_sourceRouter.getWrappedNative(),
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ uint256 expectedTotalGas = 0;
+ uint256 expectedTotalBytes = 0;
+
+ // Start with small token transfers, total bps fee is lower than min token transfer fee
+ for (uint256 i = 0; i < testTokens.length; ++i) {
+ message.tokenAmounts[i] = Client.EVMTokenAmount({token: testTokens[i], amount: 1e14});
+ expectedTotalGas += s_onRamp.getTokenTransferFeeConfig(testTokens[i]).destGasOverhead;
+ uint32 dstBytesOverhead = s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[i].token).destBytesOverhead;
+ expectedTotalBytes += dstBytesOverhead == 0 ? uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) : dstBytesOverhead;
+ }
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_wrappedTokenPrice, message.tokenAmounts);
+
+ uint256 expectedFeeUSDWei = 0;
+ for (uint256 i = 0; i < testTokens.length; ++i) {
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[i].minFeeUSDCents);
+ }
+
+ assertEq(expectedFeeUSDWei, feeUSDWei);
+ assertEq(expectedTotalGas, destGasOverhead);
+ assertEq(expectedTotalBytes, destBytesOverhead);
+
+ // Set 1st token transfer to a meaningful amount so its bps fee is now between min and max fee
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: testTokens[0], amount: 10000e18});
+
+ (feeUSDWei, destGasOverhead, destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_wrappedTokenPrice, message.tokenAmounts);
+ expectedFeeUSDWei = applyBpsRatio(
+ calcUSDValueFromTokenAmount(tokenPrices[0], message.tokenAmounts[0].amount), tokenTransferFeeConfigs[0].deciBps
+ );
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[1].minFeeUSDCents);
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[2].minFeeUSDCents);
+
+ assertEq(expectedFeeUSDWei, feeUSDWei);
+ assertEq(expectedTotalGas, destGasOverhead);
+ assertEq(expectedTotalBytes, destBytesOverhead);
+
+ // Set 2nd token transfer to a large amount that is higher than maxFeeUSD
+ message.tokenAmounts[1] = Client.EVMTokenAmount({token: testTokens[1], amount: 1e36});
+
+ (feeUSDWei, destGasOverhead, destBytesOverhead) =
+ s_onRamp.getTokenTransferCost(message.feeToken, s_wrappedTokenPrice, message.tokenAmounts);
+ expectedFeeUSDWei = applyBpsRatio(
+ calcUSDValueFromTokenAmount(tokenPrices[0], message.tokenAmounts[0].amount), tokenTransferFeeConfigs[0].deciBps
+ );
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[1].maxFeeUSDCents);
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[2].minFeeUSDCents);
+
+ assertEq(expectedFeeUSDWei, feeUSDWei);
+ assertEq(expectedTotalGas, destGasOverhead);
+ assertEq(expectedTotalBytes, destBytesOverhead);
+ }
+
+ // reverts
+
+ function test_UnsupportedToken_Revert() public {
+ address NOT_SUPPORTED_TOKEN = address(123);
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(NOT_SUPPORTED_TOKEN, 200);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.UnsupportedToken.selector, NOT_SUPPORTED_TOKEN));
+
+ s_onRamp.getTokenTransferCost(message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+ }
+}
+
+contract EVM2EVMOnRamp_getFee is EVM2EVMOnRamp_getFeeSetup {
+ using USDPriceWith18Decimals for uint224;
+
+ function test_EmptyMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = testTokens[i];
+ EVM2EVMOnRamp.FeeTokenConfig memory feeTokenConfig = s_onRamp.getFeeTokenConfig(message.feeToken);
+
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = GAS_LIMIT + DEST_GAS_OVERHEAD;
+ uint256 gasFeeUSD = (gasUsed * feeTokenConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ uint256 messageFeeUSD =
+ (configUSDCentToWei(feeTokenConfig.networkFeeUSDCents) * feeTokenConfig.premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_onRamp.getDataAvailabilityCost(
+ USD_PER_DATA_AVAILABILITY_GAS, message.data.length, message.tokenAmounts.length, 0
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ function test_ZeroDataAvailabilityMultiplier_Success() public {
+ EVM2EVMOnRamp.DynamicConfig memory dynamicConfig = s_onRamp.getDynamicConfig();
+ dynamicConfig.destDataAvailabilityMultiplierBps = 0;
+ s_onRamp.setDynamicConfig(dynamicConfig);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ EVM2EVMOnRamp.FeeTokenConfig memory feeTokenConfig = s_onRamp.getFeeTokenConfig(message.feeToken);
+
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = GAS_LIMIT + DEST_GAS_OVERHEAD;
+ uint256 gasFeeUSD = (gasUsed * feeTokenConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ uint256 messageFeeUSD =
+ (configUSDCentToWei(feeTokenConfig.networkFeeUSDCents) * feeTokenConfig.premiumMultiplierWeiPerEth);
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD) / s_feeTokenPrice;
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+
+ function test_HighGasMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 customGasLimit = MAX_GAS_LIMIT;
+ uint256 customDataSize = MAX_DATA_SIZE;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: new bytes(customDataSize),
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ feeToken: testTokens[i],
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: customGasLimit}))
+ });
+
+ EVM2EVMOnRamp.FeeTokenConfig memory feeTokenConfig = s_onRamp.getFeeTokenConfig(message.feeToken);
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = customGasLimit + DEST_GAS_OVERHEAD + customDataSize * DEST_GAS_PER_PAYLOAD_BYTE;
+ uint256 gasFeeUSD = (gasUsed * feeTokenConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ uint256 messageFeeUSD =
+ (configUSDCentToWei(feeTokenConfig.networkFeeUSDCents) * feeTokenConfig.premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_onRamp.getDataAvailabilityCost(
+ USD_PER_DATA_AVAILABILITY_GAS, message.data.length, message.tokenAmounts.length, 0
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ function test_SingleTokenMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 tokenAmount = 10000e18;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, tokenAmount);
+ message.feeToken = testTokens[i];
+ EVM2EVMOnRamp.FeeTokenConfig memory feeTokenConfig = s_onRamp.getFeeTokenConfig(message.feeToken);
+ uint32 tokenGasOverhead = s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token).destGasOverhead;
+ uint32 destBytesOverhead = s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[0].token).destBytesOverhead;
+ uint32 tokenBytesOverhead =
+ destBytesOverhead == 0 ? uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) : destBytesOverhead;
+
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = GAS_LIMIT + DEST_GAS_OVERHEAD + tokenGasOverhead;
+ uint256 gasFeeUSD = (gasUsed * feeTokenConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ (uint256 transferFeeUSD,,) =
+ s_onRamp.getTokenTransferCost(message.feeToken, feeTokenPrices[i], message.tokenAmounts);
+ uint256 messageFeeUSD = (transferFeeUSD * feeTokenConfig.premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_onRamp.getDataAvailabilityCost(
+ USD_PER_DATA_AVAILABILITY_GAS, message.data.length, message.tokenAmounts.length, tokenBytesOverhead
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ function test_MessageWithDataAndTokenTransfer_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 customGasLimit = 1_000_000;
+ uint256 feeTokenAmount = 10000e18;
+ uint256 customTokenAmount = 200000e18;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](2),
+ feeToken: testTokens[i],
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: customGasLimit}))
+ });
+ EVM2EVMOnRamp.FeeTokenConfig memory feeTokenConfig = s_onRamp.getFeeTokenConfig(message.feeToken);
+
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceFeeToken, amount: feeTokenAmount});
+ message.tokenAmounts[1] = Client.EVMTokenAmount({token: CUSTOM_TOKEN, amount: customTokenAmount});
+ message.data = "random bits and bytes that should be factored into the cost of the message";
+
+ uint32 tokenGasOverhead = 0;
+ uint32 tokenBytesOverhead = 0;
+ for (uint256 j = 0; j < message.tokenAmounts.length; ++j) {
+ tokenGasOverhead += s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[j].token).destGasOverhead;
+ uint32 destBytesOverhead = s_onRamp.getTokenTransferFeeConfig(message.tokenAmounts[j].token).destBytesOverhead;
+ tokenBytesOverhead += destBytesOverhead == 0 ? uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) : destBytesOverhead;
+ }
+
+ uint256 feeAmount = s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed =
+ customGasLimit + DEST_GAS_OVERHEAD + message.data.length * DEST_GAS_PER_PAYLOAD_BYTE + tokenGasOverhead;
+ uint256 gasFeeUSD = (gasUsed * feeTokenConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ (uint256 transferFeeUSD,,) =
+ s_onRamp.getTokenTransferCost(message.feeToken, feeTokenPrices[i], message.tokenAmounts);
+ uint256 messageFeeUSD = (transferFeeUSD * feeTokenConfig.premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_onRamp.getDataAvailabilityCost(
+ USD_PER_DATA_AVAILABILITY_GAS, message.data.length, message.tokenAmounts.length, tokenBytesOverhead
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ // Reverts
+
+ function test_NotAFeeToken_Revert() public {
+ address notAFeeToken = address(0x111111);
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(notAFeeToken, 1);
+ message.feeToken = notAFeeToken;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.NotAFeeToken.selector, notAFeeToken));
+
+ s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_MessageTooLarge_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.data = new bytes(MAX_DATA_SIZE + 1);
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.MessageTooLarge.selector, MAX_DATA_SIZE, message.data.length));
+
+ s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_TooManyTokens_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint256 tooMany = MAX_TOKENS_LENGTH + 1;
+ message.tokenAmounts = new Client.EVMTokenAmount[](tooMany);
+ vm.expectRevert(EVM2EVMOnRamp.UnsupportedNumberOfTokens.selector);
+ s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ // Asserts gasLimit must be <=maxGasLimit
+ function test_MessageGasLimitTooHigh_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: MAX_GAS_LIMIT + 1}));
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.MessageGasLimitTooHigh.selector));
+ s_onRamp.getFee(DEST_CHAIN_SELECTOR, message);
+ }
+}
+
+contract EVM2EVMOnRamp_setNops is EVM2EVMOnRampSetup {
+ // Used because EnumerableMap doesn't guarantee order
+ mapping(address nop => uint256 weight) internal s_nopsToWeights;
+
+ function test_SetNops_Success() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = getNopsAndWeights();
+ nopsAndWeights[1].nop = USER_4;
+ nopsAndWeights[1].weight = 20;
+ for (uint256 i = 0; i < nopsAndWeights.length; ++i) {
+ s_nopsToWeights[nopsAndWeights[i].nop] = nopsAndWeights[i].weight;
+ }
+
+ s_onRamp.setNops(nopsAndWeights);
+
+ (EVM2EVMOnRamp.NopAndWeight[] memory actual,) = s_onRamp.getNops();
+ for (uint256 i = 0; i < actual.length; ++i) {
+ assertEq(actual[i].weight, s_nopsToWeights[actual[i].nop]);
+ }
+ }
+
+ function test_AdminCanSetNops_Success() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = getNopsAndWeights();
+ // Should not revert
+ vm.startPrank(ADMIN);
+ s_onRamp.setNops(nopsAndWeights);
+ }
+
+ function test_IncludesPayment_Success() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = getNopsAndWeights();
+ nopsAndWeights[1].nop = USER_4;
+ nopsAndWeights[1].weight = 20;
+ uint32 totalWeight;
+ for (uint256 i = 0; i < nopsAndWeights.length; ++i) {
+ totalWeight += nopsAndWeights[i].weight;
+ s_nopsToWeights[nopsAndWeights[i].nop] = nopsAndWeights[i].weight;
+ }
+
+ // Make sure a payout happens regardless of what the weights are set to
+ uint96 nopFeesJuels = totalWeight * 5;
+ // Set Nop fee juels
+ deal(s_sourceFeeToken, address(s_onRamp), nopFeesJuels);
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), nopFeesJuels, OWNER);
+ vm.startPrank(OWNER);
+
+ // We don't care about the fee calculation logic in this test
+ // so we don't verify the amounts. We do verify the addresses to
+ // make sure the existing nops get paid and not the new ones.
+ EVM2EVMOnRamp.NopAndWeight[] memory existingNopsAndWeights = getNopsAndWeights();
+ for (uint256 i = 0; i < existingNopsAndWeights.length; ++i) {
+ vm.expectEmit(true, false, false, false);
+ emit EVM2EVMOnRamp.NopPaid(existingNopsAndWeights[i].nop, 0);
+ }
+
+ s_onRamp.setNops(nopsAndWeights);
+
+ (EVM2EVMOnRamp.NopAndWeight[] memory actual,) = s_onRamp.getNops();
+ for (uint256 i = 0; i < actual.length; ++i) {
+ assertEq(actual[i].weight, s_nopsToWeights[actual[i].nop]);
+ }
+ }
+
+ function test_SetNopsRemovesOldNopsCompletely_Success() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](0);
+ s_onRamp.setNops(nopsAndWeights);
+ (EVM2EVMOnRamp.NopAndWeight[] memory actual, uint256 totalWeight) = s_onRamp.getNops();
+ assertEq(actual.length, 0);
+ assertEq(totalWeight, 0);
+
+ address prevNop = getNopsAndWeights()[0].nop;
+ vm.startPrank(prevNop);
+
+ // prev nop should not have permission to call payNops
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdminOrNop.selector);
+ s_onRamp.payNops();
+ }
+
+ // Reverts
+
+ function test_NotEnoughFundsForPayout_Revert() public {
+ uint96 nopFeesJuels = MAX_NOP_FEES_JUELS;
+ // Set Nop fee juels but don't transfer LINK. This can happen when users
+ // pay in non-link tokens.
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), nopFeesJuels, OWNER);
+ vm.startPrank(OWNER);
+
+ vm.expectRevert(EVM2EVMOnRamp.InsufficientBalance.selector);
+
+ s_onRamp.setNops(getNopsAndWeights());
+ }
+
+ function test_NonOwnerOrAdmin_Revert() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = getNopsAndWeights();
+ vm.startPrank(STRANGER);
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdmin.selector);
+ s_onRamp.setNops(nopsAndWeights);
+ }
+
+ function test_LinkTokenCannotBeNop_Revert() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = getNopsAndWeights();
+ nopsAndWeights[0].nop = address(s_sourceTokens[0]);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.InvalidNopAddress.selector, address(s_sourceTokens[0])));
+
+ s_onRamp.setNops(nopsAndWeights);
+ }
+
+ function test_ZeroAddressCannotBeNop_Revert() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = getNopsAndWeights();
+ nopsAndWeights[0].nop = address(0);
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.InvalidNopAddress.selector, address(0)));
+
+ s_onRamp.setNops(nopsAndWeights);
+ }
+
+ function test_TooManyNops_Revert() public {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](257);
+
+ vm.expectRevert(EVM2EVMOnRamp.TooManyNops.selector);
+
+ s_onRamp.setNops(nopsAndWeights);
+ }
+}
+
+contract EVM2EVMOnRamp_withdrawNonLinkFees is EVM2EVMOnRampSetup {
+ IERC20 internal s_token;
+
+ function setUp() public virtual override {
+ EVM2EVMOnRampSetup.setUp();
+ // Send some non-link tokens to the onRamp
+ s_token = IERC20(s_sourceTokens[1]);
+ deal(s_sourceTokens[1], address(s_onRamp), 100);
+ }
+
+ function test_WithdrawNonLinkFees_Success() public {
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(this));
+
+ assertEq(0, s_token.balanceOf(address(s_onRamp)));
+ assertEq(100, s_token.balanceOf(address(this)));
+ }
+
+ function test_SettlingBalance_Success() public {
+ // Set Nop fee juels
+ uint96 nopFeesJuels = 10000000;
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), nopFeesJuels, OWNER);
+ vm.startPrank(OWNER);
+
+ vm.expectRevert(EVM2EVMOnRamp.LinkBalanceNotSettled.selector);
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(this));
+
+ // It doesnt matter how the link tokens get to the onRamp
+ // In this case we simply deal them to the ramp to show
+ // anyone can settle the balance
+ deal(s_sourceTokens[0], address(s_onRamp), nopFeesJuels);
+
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(this));
+ }
+
+ function test_Fuzz_FuzzWithdrawalOnlyLeftoverLink_Success(uint96 nopFeeJuels, uint64 extraJuels) public {
+ nopFeeJuels = uint96(bound(nopFeeJuels, 1, MAX_NOP_FEES_JUELS));
+
+ // Set Nop fee juels
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), nopFeeJuels, OWNER);
+ vm.startPrank(OWNER);
+
+ vm.expectRevert(EVM2EVMOnRamp.LinkBalanceNotSettled.selector);
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(this));
+
+ address linkToken = s_sourceTokens[0];
+ // It doesnt matter how the link tokens get to the onRamp
+ // In this case we simply deal them to the ramp to show
+ // anyone can settle the balance
+ deal(linkToken, address(s_onRamp), nopFeeJuels + uint96(extraJuels));
+
+ // Now that we've sent nopFeesJuels + extraJuels, we should be able to withdraw extraJuels
+ address linkRecipient = address(0x123456789);
+ assertEq(0, IERC20(linkToken).balanceOf(linkRecipient));
+
+ s_onRamp.withdrawNonLinkFees(linkToken, linkRecipient);
+
+ assertEq(extraJuels, IERC20(linkToken).balanceOf(linkRecipient));
+ }
+
+ // Reverts
+
+ function test_LinkBalanceNotSettled_Revert() public {
+ // Set Nop fee juels
+ uint96 nopFeesJuels = 10000000;
+ vm.startPrank(address(s_sourceRouter));
+ s_onRamp.forwardFromRouter(DEST_CHAIN_SELECTOR, _generateEmptyMessage(), nopFeesJuels, OWNER);
+ vm.startPrank(OWNER);
+
+ vm.expectRevert(EVM2EVMOnRamp.LinkBalanceNotSettled.selector);
+
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(this));
+ }
+
+ function test_NonOwnerOrAdmin_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdmin.selector);
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(this));
+ }
+
+ function test_WithdrawToZeroAddress_Revert() public {
+ vm.expectRevert(EVM2EVMOnRamp.InvalidWithdrawParams.selector);
+ s_onRamp.withdrawNonLinkFees(address(s_token), address(0));
+ }
+}
+
+contract EVM2EVMOnRamp_setFeeTokenConfig is EVM2EVMOnRampSetup {
+ function test_SetFeeTokenConfig_Success() public {
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] memory feeConfig;
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.FeeConfigSet(feeConfig);
+
+ s_onRamp.setFeeTokenConfig(feeConfig);
+ }
+
+ function test_SetFeeTokenConfigByAdmin_Success() public {
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] memory feeConfig;
+
+ vm.startPrank(ADMIN);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.FeeConfigSet(feeConfig);
+
+ s_onRamp.setFeeTokenConfig(feeConfig);
+ }
+
+ // Reverts
+
+ function test_OnlyCallableByOwnerOrAdmin_Revert() public {
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] memory feeConfig;
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdmin.selector);
+
+ s_onRamp.setFeeTokenConfig(feeConfig);
+ }
+}
+
+contract EVM2EVMOnRamp_setTokenTransferFeeConfig is EVM2EVMOnRampSetup {
+ function test__setTokenTransferFeeConfig_Success() public {
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory tokenTransferFeeArgs =
+ new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](2);
+ tokenTransferFeeArgs[0] = EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: address(5),
+ minFeeUSDCents: 6,
+ maxFeeUSDCents: 7,
+ deciBps: 8,
+ destGasOverhead: 9,
+ destBytesOverhead: 312,
+ aggregateRateLimitEnabled: true
+ });
+ tokenTransferFeeArgs[1] = EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: address(11),
+ minFeeUSDCents: 12,
+ maxFeeUSDCents: 13,
+ deciBps: 14,
+ destGasOverhead: 15,
+ destBytesOverhead: 394,
+ aggregateRateLimitEnabled: false
+ });
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.TokenTransferFeeConfigSet(tokenTransferFeeArgs);
+
+ s_onRamp.setTokenTransferFeeConfig(tokenTransferFeeArgs, new address[](0));
+
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory config0 =
+ s_onRamp.getTokenTransferFeeConfig(tokenTransferFeeArgs[0].token);
+
+ assertEq(tokenTransferFeeArgs[0].minFeeUSDCents, config0.minFeeUSDCents);
+ assertEq(tokenTransferFeeArgs[0].maxFeeUSDCents, config0.maxFeeUSDCents);
+ assertEq(tokenTransferFeeArgs[0].deciBps, config0.deciBps);
+ assertEq(tokenTransferFeeArgs[0].destGasOverhead, config0.destGasOverhead);
+ assertEq(tokenTransferFeeArgs[0].destBytesOverhead, config0.destBytesOverhead);
+ assertEq(tokenTransferFeeArgs[0].aggregateRateLimitEnabled, config0.aggregateRateLimitEnabled);
+ assertTrue(config0.isEnabled);
+
+ EVM2EVMOnRamp.TokenTransferFeeConfig memory config1 =
+ s_onRamp.getTokenTransferFeeConfig(tokenTransferFeeArgs[1].token);
+
+ assertEq(tokenTransferFeeArgs[1].minFeeUSDCents, config1.minFeeUSDCents);
+ assertEq(tokenTransferFeeArgs[1].maxFeeUSDCents, config1.maxFeeUSDCents);
+ assertEq(tokenTransferFeeArgs[1].deciBps, config1.deciBps);
+ assertEq(tokenTransferFeeArgs[1].destGasOverhead, config1.destGasOverhead);
+ assertEq(tokenTransferFeeArgs[1].destBytesOverhead, config1.destBytesOverhead);
+ assertEq(tokenTransferFeeArgs[1].aggregateRateLimitEnabled, config1.aggregateRateLimitEnabled);
+ assertTrue(config0.isEnabled);
+
+ // Remove only the first token and validate only the first token is removed
+ address[] memory tokensToRemove = new address[](1);
+ tokensToRemove[0] = tokenTransferFeeArgs[0].token;
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.TokenTransferFeeConfigDeleted(tokensToRemove);
+
+ s_onRamp.setTokenTransferFeeConfig(new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](0), tokensToRemove);
+
+ config0 = s_onRamp.getTokenTransferFeeConfig(tokenTransferFeeArgs[0].token);
+
+ assertEq(0, config0.minFeeUSDCents);
+ assertEq(0, config0.maxFeeUSDCents);
+ assertEq(0, config0.deciBps);
+ assertEq(0, config0.destGasOverhead);
+ assertEq(0, config0.destBytesOverhead);
+ assertFalse(config0.aggregateRateLimitEnabled);
+ assertFalse(config0.isEnabled);
+
+ config1 = s_onRamp.getTokenTransferFeeConfig(tokenTransferFeeArgs[1].token);
+
+ assertEq(tokenTransferFeeArgs[1].minFeeUSDCents, config1.minFeeUSDCents);
+ assertEq(tokenTransferFeeArgs[1].maxFeeUSDCents, config1.maxFeeUSDCents);
+ assertEq(tokenTransferFeeArgs[1].deciBps, config1.deciBps);
+ assertEq(tokenTransferFeeArgs[1].destGasOverhead, config1.destGasOverhead);
+ assertEq(tokenTransferFeeArgs[1].destBytesOverhead, config1.destBytesOverhead);
+ assertEq(tokenTransferFeeArgs[1].aggregateRateLimitEnabled, config1.aggregateRateLimitEnabled);
+ assertTrue(config1.isEnabled);
+ }
+
+ function test__setTokenTransferFeeConfig_byAdmin_Success() public {
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory transferFeeConfig;
+ vm.startPrank(ADMIN);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.TokenTransferFeeConfigSet(transferFeeConfig);
+
+ s_onRamp.setTokenTransferFeeConfig(transferFeeConfig, new address[](0));
+ }
+
+ // Reverts
+
+ function test__setTokenTransferFeeConfig_InvalidDestBytesOverhead_Revert() public {
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory transferFeeConfig =
+ new EVM2EVMOnRamp.TokenTransferFeeConfigArgs[](1);
+ transferFeeConfig[0].destBytesOverhead = uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) - 1;
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ EVM2EVMOnRamp.InvalidDestBytesOverhead.selector,
+ transferFeeConfig[0].token,
+ transferFeeConfig[0].destBytesOverhead
+ )
+ );
+ s_onRamp.setTokenTransferFeeConfig(transferFeeConfig, new address[](0));
+ }
+
+ function test__setTokenTransferFeeConfig_OnlyCallableByOwnerOrAdmin_Revert() public {
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] memory transferFeeConfig;
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(EVM2EVMOnRamp.OnlyCallableByOwnerOrAdmin.selector);
+
+ s_onRamp.setTokenTransferFeeConfig(transferFeeConfig, new address[](0));
+ }
+}
+
+contract EVM2EVMOnRamp_getTokenPool is EVM2EVMOnRampSetup {
+ function test_GetTokenPool_Success() public view {
+ assertEq(
+ s_sourcePoolByToken[s_sourceTokens[0]],
+ address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(s_sourceTokens[0])))
+ );
+ assertEq(
+ s_sourcePoolByToken[s_sourceTokens[1]],
+ address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(s_sourceTokens[1])))
+ );
+
+ address wrongToken = address(123);
+ address nonExistentPool = address(s_onRamp.getPoolBySourceToken(DEST_CHAIN_SELECTOR, IERC20(wrongToken)));
+
+ assertEq(address(0), nonExistentPool);
+ }
+}
+
+contract EVM2EVMOnRamp_setDynamicConfig is EVM2EVMOnRampSetup {
+ function test_SetDynamicConfig_Success() public {
+ EVM2EVMOnRamp.StaticConfig memory staticConfig = s_onRamp.getStaticConfig();
+ EVM2EVMOnRamp.DynamicConfig memory newConfig = EVM2EVMOnRamp.DynamicConfig({
+ router: address(2134),
+ maxNumberOfTokensPerMsg: 14,
+ destGasOverhead: DEST_GAS_OVERHEAD / 2,
+ destGasPerPayloadByte: DEST_GAS_PER_PAYLOAD_BYTE / 2,
+ destDataAvailabilityOverheadGas: DEST_DATA_AVAILABILITY_OVERHEAD_GAS,
+ destGasPerDataAvailabilityByte: DEST_GAS_PER_DATA_AVAILABILITY_BYTE,
+ destDataAvailabilityMultiplierBps: DEST_GAS_DATA_AVAILABILITY_MULTIPLIER_BPS,
+ priceRegistry: address(23423),
+ maxDataBytes: 400,
+ maxPerMsgGasLimit: MAX_GAS_LIMIT / 2,
+ defaultTokenFeeUSDCents: DEFAULT_TOKEN_FEE_USD_CENTS,
+ defaultTokenDestGasOverhead: DEFAULT_TOKEN_DEST_GAS_OVERHEAD,
+ defaultTokenDestBytesOverhead: DEFAULT_TOKEN_BYTES_OVERHEAD,
+ enforceOutOfOrder: false
+ });
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.ConfigSet(staticConfig, newConfig);
+
+ s_onRamp.setDynamicConfig(newConfig);
+
+ EVM2EVMOnRamp.DynamicConfig memory gotDynamicConfig = s_onRamp.getDynamicConfig();
+ assertEq(newConfig.router, gotDynamicConfig.router);
+ assertEq(newConfig.maxNumberOfTokensPerMsg, gotDynamicConfig.maxNumberOfTokensPerMsg);
+ assertEq(newConfig.destGasOverhead, gotDynamicConfig.destGasOverhead);
+ assertEq(newConfig.destGasPerPayloadByte, gotDynamicConfig.destGasPerPayloadByte);
+ assertEq(newConfig.priceRegistry, gotDynamicConfig.priceRegistry);
+ assertEq(newConfig.maxDataBytes, gotDynamicConfig.maxDataBytes);
+ assertEq(newConfig.maxPerMsgGasLimit, gotDynamicConfig.maxPerMsgGasLimit);
+ }
+
+ // Reverts
+
+ function test_SetConfigInvalidConfig_Revert() public {
+ EVM2EVMOnRamp.DynamicConfig memory newConfig = EVM2EVMOnRamp.DynamicConfig({
+ router: address(1),
+ maxNumberOfTokensPerMsg: 14,
+ destGasOverhead: DEST_GAS_OVERHEAD / 2,
+ destGasPerPayloadByte: DEST_GAS_PER_PAYLOAD_BYTE / 2,
+ destDataAvailabilityOverheadGas: DEST_DATA_AVAILABILITY_OVERHEAD_GAS,
+ destGasPerDataAvailabilityByte: DEST_GAS_PER_DATA_AVAILABILITY_BYTE,
+ destDataAvailabilityMultiplierBps: DEST_GAS_DATA_AVAILABILITY_MULTIPLIER_BPS,
+ priceRegistry: address(23423),
+ maxDataBytes: 400,
+ maxPerMsgGasLimit: MAX_GAS_LIMIT / 2,
+ defaultTokenFeeUSDCents: DEFAULT_TOKEN_FEE_USD_CENTS,
+ defaultTokenDestGasOverhead: DEFAULT_TOKEN_DEST_GAS_OVERHEAD,
+ defaultTokenDestBytesOverhead: DEFAULT_TOKEN_BYTES_OVERHEAD,
+ enforceOutOfOrder: false
+ });
+
+ // Invalid price reg reverts.
+ newConfig.priceRegistry = address(0);
+ vm.expectRevert(EVM2EVMOnRamp.InvalidConfig.selector);
+ s_onRamp.setDynamicConfig(newConfig);
+
+ // Succeeds if valid
+ newConfig.priceRegistry = address(23423);
+ s_onRamp.setDynamicConfig(newConfig);
+ }
+
+ function test_SetConfigOnlyOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_onRamp.setDynamicConfig(generateDynamicOnRampConfig(address(1), address(2)));
+ vm.startPrank(ADMIN);
+ vm.expectRevert("Only callable by owner");
+ s_onRamp.setDynamicConfig(generateDynamicOnRampConfig(address(1), address(2)));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMOnRampSetup.t.sol b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMOnRampSetup.t.sol
new file mode 100644
index 00000000000..6659b1217fd
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/onRamp/EVM2EVMOnRampSetup.t.sol
@@ -0,0 +1,261 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+
+import {PriceRegistry} from "../../PriceRegistry.sol";
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {EVM2EVMOnRamp} from "../../onRamp/EVM2EVMOnRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {TokenSetup} from "../TokenSetup.t.sol";
+import {EVM2EVMOnRampHelper} from "../helpers/EVM2EVMOnRampHelper.sol";
+import {PriceRegistrySetup} from "../priceRegistry/PriceRegistry.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract EVM2EVMOnRampSetup is TokenSetup, PriceRegistrySetup {
+ uint256 internal immutable i_tokenAmount0 = 9;
+ uint256 internal immutable i_tokenAmount1 = 7;
+
+ bytes32 internal s_metadataHash;
+
+ EVM2EVMOnRampHelper internal s_onRamp;
+ address[] internal s_offRamps;
+
+ address internal s_destTokenPool = makeAddr("destTokenPool");
+ address internal s_destToken = makeAddr("destToken");
+
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] internal s_feeTokenConfigArgs;
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs[] internal s_tokenTransferFeeConfigArgs;
+
+ function setUp() public virtual override(TokenSetup, PriceRegistrySetup) {
+ TokenSetup.setUp();
+ PriceRegistrySetup.setUp();
+
+ s_priceRegistry.updatePrices(getSingleTokenPriceUpdateStruct(CUSTOM_TOKEN, CUSTOM_TOKEN_PRICE));
+
+ address WETH = s_sourceRouter.getWrappedNative();
+
+ s_feeTokenConfigArgs.push(
+ EVM2EVMOnRamp.FeeTokenConfigArgs({
+ token: s_sourceFeeToken,
+ networkFeeUSDCents: 1_00, // 1 USD
+ gasMultiplierWeiPerEth: 1e18, // 1x
+ premiumMultiplierWeiPerEth: 5e17, // 0.5x
+ enabled: true
+ })
+ );
+ s_feeTokenConfigArgs.push(
+ EVM2EVMOnRamp.FeeTokenConfigArgs({
+ token: WETH,
+ networkFeeUSDCents: 5_00, // 5 USD
+ gasMultiplierWeiPerEth: 2e18, // 2x
+ premiumMultiplierWeiPerEth: 2e18, // 2x
+ enabled: true
+ })
+ );
+
+ s_tokenTransferFeeConfigArgs.push(
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: s_sourceFeeToken,
+ minFeeUSDCents: 1_00, // 1 USD
+ maxFeeUSDCents: 1000_00, // 1,000 USD
+ deciBps: 2_5, // 2.5 bps, or 0.025%
+ destGasOverhead: 40_000,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES),
+ aggregateRateLimitEnabled: true
+ })
+ );
+ s_tokenTransferFeeConfigArgs.push(
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: s_sourceRouter.getWrappedNative(),
+ minFeeUSDCents: 50, // 0.5 USD
+ maxFeeUSDCents: 500_00, // 500 USD
+ deciBps: 5_0, // 5 bps, or 0.05%
+ destGasOverhead: 10_000,
+ destBytesOverhead: 100,
+ aggregateRateLimitEnabled: true
+ })
+ );
+ s_tokenTransferFeeConfigArgs.push(
+ EVM2EVMOnRamp.TokenTransferFeeConfigArgs({
+ token: CUSTOM_TOKEN,
+ minFeeUSDCents: 2_00, // 1 USD
+ maxFeeUSDCents: 2000_00, // 1,000 USD
+ deciBps: 10_0, // 10 bps, or 0.1%
+ destGasOverhead: 1,
+ destBytesOverhead: 200,
+ aggregateRateLimitEnabled: true
+ })
+ );
+
+ s_onRamp = new EVM2EVMOnRampHelper(
+ EVM2EVMOnRamp.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ chainSelector: SOURCE_CHAIN_SELECTOR,
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ defaultTxGasLimit: GAS_LIMIT,
+ maxNopFeesJuels: MAX_NOP_FEES_JUELS,
+ prevOnRamp: address(0),
+ rmnProxy: address(s_mockRMN),
+ tokenAdminRegistry: address(s_tokenAdminRegistry)
+ }),
+ generateDynamicOnRampConfig(address(s_sourceRouter), address(s_priceRegistry)),
+ getOutboundRateLimiterConfig(),
+ s_feeTokenConfigArgs,
+ s_tokenTransferFeeConfigArgs,
+ getNopsAndWeights()
+ );
+ s_onRamp.setAdmin(ADMIN);
+
+ s_metadataHash = keccak256(
+ abi.encode(Internal.EVM_2_EVM_MESSAGE_HASH, SOURCE_CHAIN_SELECTOR, DEST_CHAIN_SELECTOR, address(s_onRamp))
+ );
+
+ s_offRamps = new address[](2);
+ s_offRamps[0] = address(10);
+ s_offRamps[1] = address(11);
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](2);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: address(s_onRamp)});
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: s_offRamps[0]});
+ offRampUpdates[1] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: s_offRamps[1]});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+
+ // Pre approve the first token so the gas estimates of the tests
+ // only cover actual gas usage from the ramps
+ IERC20(s_sourceTokens[0]).approve(address(s_sourceRouter), 2 ** 128);
+ IERC20(s_sourceTokens[1]).approve(address(s_sourceRouter), 2 ** 128);
+ }
+
+ function getNopsAndWeights() internal pure returns (EVM2EVMOnRamp.NopAndWeight[] memory) {
+ EVM2EVMOnRamp.NopAndWeight[] memory nopsAndWeights = new EVM2EVMOnRamp.NopAndWeight[](3);
+ nopsAndWeights[0] = EVM2EVMOnRamp.NopAndWeight({nop: USER_1, weight: 19284});
+ nopsAndWeights[1] = EVM2EVMOnRamp.NopAndWeight({nop: USER_2, weight: 52935});
+ nopsAndWeights[2] = EVM2EVMOnRamp.NopAndWeight({nop: USER_3, weight: 8});
+ return nopsAndWeights;
+ }
+
+ function generateDynamicOnRampConfig(
+ address router,
+ address priceRegistry
+ ) internal pure returns (EVM2EVMOnRamp.DynamicConfig memory) {
+ return EVM2EVMOnRamp.DynamicConfig({
+ router: router,
+ maxNumberOfTokensPerMsg: MAX_TOKENS_LENGTH,
+ destGasOverhead: DEST_GAS_OVERHEAD,
+ destGasPerPayloadByte: DEST_GAS_PER_PAYLOAD_BYTE,
+ destDataAvailabilityOverheadGas: DEST_DATA_AVAILABILITY_OVERHEAD_GAS,
+ destGasPerDataAvailabilityByte: DEST_GAS_PER_DATA_AVAILABILITY_BYTE,
+ destDataAvailabilityMultiplierBps: DEST_GAS_DATA_AVAILABILITY_MULTIPLIER_BPS,
+ priceRegistry: priceRegistry,
+ maxDataBytes: MAX_DATA_SIZE,
+ maxPerMsgGasLimit: MAX_GAS_LIMIT,
+ defaultTokenFeeUSDCents: DEFAULT_TOKEN_FEE_USD_CENTS,
+ defaultTokenDestGasOverhead: DEFAULT_TOKEN_DEST_GAS_OVERHEAD,
+ defaultTokenDestBytesOverhead: DEFAULT_TOKEN_BYTES_OVERHEAD,
+ enforceOutOfOrder: false
+ });
+ }
+
+ function _generateTokenMessage() public view returns (Client.EVM2AnyMessage memory) {
+ Client.EVMTokenAmount[] memory tokenAmounts = getCastedSourceEVMTokenAmountsWithZeroAmounts();
+ tokenAmounts[0].amount = i_tokenAmount0;
+ tokenAmounts[1].amount = i_tokenAmount1;
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _generateSingleTokenMessage(
+ address token,
+ uint256 amount
+ ) public view returns (Client.EVM2AnyMessage memory) {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: token, amount: amount});
+
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _generateEmptyMessage() public view returns (Client.EVM2AnyMessage memory) {
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _messageToEvent(
+ Client.EVM2AnyMessage memory message,
+ uint64 seqNum,
+ uint64 nonce,
+ uint256 feeTokenAmount,
+ address originalSender
+ ) public view returns (Internal.EVM2EVMMessage memory) {
+ // Slicing is only available for calldata. So we have to build a new bytes array.
+ bytes memory args = new bytes(message.extraArgs.length - 4);
+ for (uint256 i = 4; i < message.extraArgs.length; ++i) {
+ args[i - 4] = message.extraArgs[i];
+ }
+ uint256 numberOfTokens = message.tokenAmounts.length;
+ Client.EVMExtraArgsV2 memory extraArgs = _extraArgsFromBytes(bytes4(message.extraArgs), args);
+ Internal.EVM2EVMMessage memory messageEvent = Internal.EVM2EVMMessage({
+ sequenceNumber: seqNum,
+ feeTokenAmount: feeTokenAmount,
+ sender: originalSender,
+ nonce: extraArgs.allowOutOfOrderExecution ? 0 : nonce,
+ gasLimit: extraArgs.gasLimit,
+ strict: false,
+ sourceChainSelector: SOURCE_CHAIN_SELECTOR,
+ receiver: abi.decode(message.receiver, (address)),
+ data: message.data,
+ tokenAmounts: message.tokenAmounts,
+ sourceTokenData: new bytes[](numberOfTokens),
+ feeToken: message.feeToken,
+ messageId: ""
+ });
+
+ for (uint256 i = 0; i < numberOfTokens; ++i) {
+ messageEvent.sourceTokenData[i] = abi.encode(
+ Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(s_sourcePoolByToken[message.tokenAmounts[i].token]),
+ destTokenAddress: abi.encode(s_destTokenBySourceToken[message.tokenAmounts[i].token]),
+ extraData: ""
+ })
+ );
+ }
+
+ messageEvent.messageId = Internal._hash(messageEvent, s_metadataHash);
+ return messageEvent;
+ }
+
+ function _extraArgsFromBytes(
+ bytes4 sig,
+ bytes memory extraArgData
+ ) public pure returns (Client.EVMExtraArgsV2 memory) {
+ if (sig == Client.EVM_EXTRA_ARGS_V1_TAG) {
+ Client.EVMExtraArgsV1 memory extraArgsV1 = abi.decode(extraArgData, (Client.EVMExtraArgsV1));
+ return Client.EVMExtraArgsV2({gasLimit: extraArgsV1.gasLimit, allowOutOfOrderExecution: false});
+ } else if (sig == Client.EVM_EXTRA_ARGS_V2_TAG) {
+ return abi.decode(extraArgData, (Client.EVMExtraArgsV2));
+ } else {
+ revert("Invalid extraArgs tag");
+ }
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/BurnFromMintTokenPool.t.sol b/contracts/src/v0.8/ccip/test/pools/BurnFromMintTokenPool.t.sol
new file mode 100644
index 00000000000..290c4ae1537
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/BurnFromMintTokenPool.t.sol
@@ -0,0 +1,104 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {BurnFromMintTokenPool} from "../../pools/BurnFromMintTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {BurnMintSetup} from "./BurnMintSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract BurnFromMintTokenPoolSetup is BurnMintSetup {
+ BurnFromMintTokenPool internal s_pool;
+
+ function setUp() public virtual override {
+ BurnMintSetup.setUp();
+
+ s_pool = new BurnFromMintTokenPool(s_burnMintERC677, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ s_burnMintERC677.grantMintAndBurnRoles(address(s_pool));
+
+ _applyChainUpdates(address(s_pool));
+ }
+}
+
+contract BurnFromMintTokenPool_lockOrBurn is BurnFromMintTokenPoolSetup {
+ function test_Setup_Success() public view {
+ assertEq(address(s_burnMintERC677), address(s_pool.getToken()));
+ assertEq(address(s_mockRMN), s_pool.getRmnProxy());
+ assertEq(false, s_pool.getAllowListEnabled());
+ assertEq(type(uint256).max, s_burnMintERC677.allowance(address(s_pool), address(s_pool)));
+ assertEq("BurnFromMintTokenPool 1.5.0-dev", s_pool.typeAndVersion());
+ }
+
+ function test_PoolBurn_Success() public {
+ uint256 burnAmount = 20_000e18;
+
+ deal(address(s_burnMintERC677), address(s_pool), burnAmount);
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), burnAmount);
+
+ vm.startPrank(s_burnMintOnRamp);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(burnAmount);
+
+ vm.expectEmit();
+ emit IERC20.Transfer(address(s_pool), address(0), burnAmount);
+
+ vm.expectEmit();
+ emit TokenPool.Burned(address(s_burnMintOnRamp), burnAmount);
+
+ bytes4 expectedSignature = bytes4(keccak256("burnFrom(address,uint256)"));
+ vm.expectCall(address(s_burnMintERC677), abi.encodeWithSelector(expectedSignature, address(s_pool), burnAmount));
+
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: burnAmount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), 0);
+ }
+
+ // Should not burn tokens if cursed.
+ function test_PoolBurnRevertNotHealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ uint256 before = s_burnMintERC677.balanceOf(address(s_pool));
+ vm.startPrank(s_burnMintOnRamp);
+
+ vm.expectRevert(TokenPool.CursedByRMN.selector);
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: 1e5,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), before);
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ uint64 wrongChainSelector = 8838833;
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, wrongChainSelector));
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: 1,
+ localToken: address(s_burnMintERC677),
+ remoteChainSelector: wrongChainSelector,
+ sourcePoolAddress: generateSourceTokenData().sourcePoolAddress,
+ sourcePoolData: generateSourceTokenData().extraData,
+ offchainTokenData: ""
+ })
+ );
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/BurnMintSetup.t.sol b/contracts/src/v0.8/ccip/test/pools/BurnMintSetup.t.sol
new file mode 100644
index 00000000000..a39fd1bb9fa
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/BurnMintSetup.t.sol
@@ -0,0 +1,43 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {Router} from "../../Router.sol";
+import {BurnMintTokenPool} from "../../pools/BurnMintTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {RouterSetup} from "../router/RouterSetup.t.sol";
+
+contract BurnMintSetup is RouterSetup {
+ BurnMintERC677 internal s_burnMintERC677;
+ address internal s_burnMintOffRamp = makeAddr("burn_mint_offRamp");
+ address internal s_burnMintOnRamp = makeAddr("burn_mint_onRamp");
+
+ address internal s_remoteBurnMintPool = makeAddr("remote_burn_mint_pool");
+ address internal s_remoteToken = makeAddr("remote_token");
+
+ function setUp() public virtual override {
+ RouterSetup.setUp();
+
+ s_burnMintERC677 = new BurnMintERC677("Chainlink Token", "LINK", 18, 0);
+ }
+
+ function _applyChainUpdates(address pool) internal {
+ TokenPool.ChainUpdate[] memory chains = new TokenPool.ChainUpdate[](1);
+ chains[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_remoteBurnMintPool),
+ remoteTokenAddress: abi.encode(s_remoteToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ BurnMintTokenPool(pool).applyChainUpdates(chains);
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: s_burnMintOnRamp});
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: DEST_CHAIN_SELECTOR, offRamp: s_burnMintOffRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/BurnMintTokenPool.t.sol b/contracts/src/v0.8/ccip/test/pools/BurnMintTokenPool.t.sol
new file mode 100644
index 00000000000..c628c510d43
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/BurnMintTokenPool.t.sol
@@ -0,0 +1,171 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+
+import {Internal} from "../../libraries/Internal.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {EVM2EVMOffRamp} from "../../offRamp/EVM2EVMOffRamp.sol";
+import {BurnMintTokenPool} from "../../pools/BurnMintTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {BurnMintSetup} from "./BurnMintSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract BurnMintTokenPoolSetup is BurnMintSetup {
+ BurnMintTokenPool internal s_pool;
+
+ function setUp() public virtual override {
+ BurnMintSetup.setUp();
+
+ s_pool = new BurnMintTokenPool(s_burnMintERC677, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ s_burnMintERC677.grantMintAndBurnRoles(address(s_pool));
+
+ _applyChainUpdates(address(s_pool));
+ }
+}
+
+contract BurnMintTokenPool_lockOrBurn is BurnMintTokenPoolSetup {
+ function test_Setup_Success() public view {
+ assertEq(address(s_burnMintERC677), address(s_pool.getToken()));
+ assertEq(address(s_mockRMN), s_pool.getRmnProxy());
+ assertEq(false, s_pool.getAllowListEnabled());
+ assertEq("BurnMintTokenPool 1.5.0-dev", s_pool.typeAndVersion());
+ }
+
+ function test_PoolBurn_Success() public {
+ uint256 burnAmount = 20_000e18;
+
+ deal(address(s_burnMintERC677), address(s_pool), burnAmount);
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), burnAmount);
+
+ vm.startPrank(s_burnMintOnRamp);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(burnAmount);
+
+ vm.expectEmit();
+ emit IERC20.Transfer(address(s_pool), address(0), burnAmount);
+
+ vm.expectEmit();
+ emit TokenPool.Burned(address(s_burnMintOnRamp), burnAmount);
+
+ bytes4 expectedSignature = bytes4(keccak256("burn(uint256)"));
+ vm.expectCall(address(s_burnMintERC677), abi.encodeWithSelector(expectedSignature, burnAmount));
+
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: burnAmount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), 0);
+ }
+
+ // Should not burn tokens if cursed.
+ function test_PoolBurnRevertNotHealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ uint256 before = s_burnMintERC677.balanceOf(address(s_pool));
+ vm.startPrank(s_burnMintOnRamp);
+
+ vm.expectRevert(TokenPool.CursedByRMN.selector);
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: 1e5,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), before);
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ uint64 wrongChainSelector = 8838833;
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, wrongChainSelector));
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: 1,
+ remoteChainSelector: wrongChainSelector,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+ }
+}
+
+contract BurnMintTokenPool_releaseOrMint is BurnMintTokenPoolSetup {
+ function test_PoolMint_Success() public {
+ uint256 amount = 1e19;
+
+ vm.startPrank(s_burnMintOffRamp);
+
+ vm.expectEmit();
+ emit IERC20.Transfer(address(0), address(s_burnMintOffRamp), amount);
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: amount,
+ localToken: address(s_burnMintERC677),
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ sourcePoolAddress: abi.encode(s_remoteBurnMintPool),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(s_burnMintOffRamp), amount);
+ }
+
+ function test_PoolMintNotHealthy_Revert() public {
+ // Should not mint tokens if cursed.
+ s_mockRMN.setGlobalCursed(true);
+ uint256 before = s_burnMintERC677.balanceOf(OWNER);
+ vm.startPrank(s_burnMintOffRamp);
+
+ vm.expectRevert(TokenPool.CursedByRMN.selector);
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: 1e5,
+ localToken: address(s_burnMintERC677),
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ sourcePoolAddress: generateSourceTokenData().sourcePoolAddress,
+ sourcePoolData: generateSourceTokenData().extraData,
+ offchainTokenData: ""
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(OWNER), before);
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ uint64 wrongChainSelector = 8838833;
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, wrongChainSelector));
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: 1,
+ localToken: address(s_burnMintERC677),
+ remoteChainSelector: wrongChainSelector,
+ sourcePoolAddress: generateSourceTokenData().sourcePoolAddress,
+ sourcePoolData: generateSourceTokenData().extraData,
+ offchainTokenData: ""
+ })
+ );
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/BurnWithFromMintTokenPool.t.sol b/contracts/src/v0.8/ccip/test/pools/BurnWithFromMintTokenPool.t.sol
new file mode 100644
index 00000000000..22362ee4a55
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/BurnWithFromMintTokenPool.t.sol
@@ -0,0 +1,105 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {BurnWithFromMintTokenPool} from "../../pools/BurnWithFromMintTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {BurnMintSetup} from "./BurnMintSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract BurnWithFromMintTokenPoolSetup is BurnMintSetup {
+ BurnWithFromMintTokenPool internal s_pool;
+
+ function setUp() public virtual override {
+ BurnMintSetup.setUp();
+
+ s_pool =
+ new BurnWithFromMintTokenPool(s_burnMintERC677, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ s_burnMintERC677.grantMintAndBurnRoles(address(s_pool));
+
+ _applyChainUpdates(address(s_pool));
+ }
+}
+
+contract BurnWithFromMintTokenPool_lockOrBurn is BurnWithFromMintTokenPoolSetup {
+ function test_Setup_Success() public view {
+ assertEq(address(s_burnMintERC677), address(s_pool.getToken()));
+ assertEq(address(s_mockRMN), s_pool.getRmnProxy());
+ assertEq(false, s_pool.getAllowListEnabled());
+ assertEq(type(uint256).max, s_burnMintERC677.allowance(address(s_pool), address(s_pool)));
+ assertEq("BurnWithFromMintTokenPool 1.5.0-dev", s_pool.typeAndVersion());
+ }
+
+ function test_PoolBurn_Success() public {
+ uint256 burnAmount = 20_000e18;
+
+ deal(address(s_burnMintERC677), address(s_pool), burnAmount);
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), burnAmount);
+
+ vm.startPrank(s_burnMintOnRamp);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(burnAmount);
+
+ vm.expectEmit();
+ emit IERC20.Transfer(address(s_pool), address(0), burnAmount);
+
+ vm.expectEmit();
+ emit TokenPool.Burned(address(s_burnMintOnRamp), burnAmount);
+
+ bytes4 expectedSignature = bytes4(keccak256("burn(address,uint256)"));
+ vm.expectCall(address(s_burnMintERC677), abi.encodeWithSelector(expectedSignature, address(s_pool), burnAmount));
+
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: burnAmount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), 0);
+ }
+
+ // Should not burn tokens if cursed.
+ function test_PoolBurnRevertNotHealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ uint256 before = s_burnMintERC677.balanceOf(address(s_pool));
+ vm.startPrank(s_burnMintOnRamp);
+
+ vm.expectRevert(TokenPool.CursedByRMN.selector);
+ s_pool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: bytes(""),
+ amount: 1e5,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_burnMintERC677)
+ })
+ );
+
+ assertEq(s_burnMintERC677.balanceOf(address(s_pool)), before);
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ uint64 wrongChainSelector = 8838833;
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, wrongChainSelector));
+ s_pool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: 1,
+ localToken: address(s_burnMintERC677),
+ remoteChainSelector: wrongChainSelector,
+ sourcePoolAddress: generateSourceTokenData().sourcePoolAddress,
+ sourcePoolData: generateSourceTokenData().extraData,
+ offchainTokenData: ""
+ })
+ );
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/LockReleaseTokenPool.t.sol b/contracts/src/v0.8/ccip/test/pools/LockReleaseTokenPool.t.sol
new file mode 100644
index 00000000000..97d0d4e8947
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/LockReleaseTokenPool.t.sol
@@ -0,0 +1,512 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {Router} from "../../Router.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {EVM2EVMOffRamp} from "../../offRamp/EVM2EVMOffRamp.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {IERC165} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+import {RouterSetup} from "../router/RouterSetup.t.sol";
+
+contract LockReleaseTokenPoolSetup is RouterSetup {
+ IERC20 internal s_token;
+ LockReleaseTokenPool internal s_lockReleaseTokenPool;
+ LockReleaseTokenPool internal s_lockReleaseTokenPoolWithAllowList;
+ address[] internal s_allowedList;
+
+ address internal s_allowedOnRamp = address(123);
+ address internal s_allowedOffRamp = address(234);
+
+ address internal s_destPoolAddress = address(2736782345);
+ address internal s_sourcePoolAddress = address(53852352095);
+
+ function setUp() public virtual override {
+ RouterSetup.setUp();
+ s_token = new BurnMintERC677("LINK", "LNK", 18, 0);
+ deal(address(s_token), OWNER, type(uint256).max);
+ s_lockReleaseTokenPool =
+ new LockReleaseTokenPool(s_token, new address[](0), address(s_mockRMN), true, address(s_sourceRouter));
+
+ s_allowedList.push(USER_1);
+ s_allowedList.push(DUMMY_CONTRACT_ADDRESS);
+ s_lockReleaseTokenPoolWithAllowList =
+ new LockReleaseTokenPool(s_token, s_allowedList, address(s_mockRMN), true, address(s_sourceRouter));
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_destPoolAddress),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ s_lockReleaseTokenPool.applyChainUpdates(chainUpdate);
+ s_lockReleaseTokenPoolWithAllowList.applyChainUpdates(chainUpdate);
+ s_lockReleaseTokenPool.setRebalancer(OWNER);
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: s_allowedOnRamp});
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: s_allowedOffRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ }
+}
+
+contract LockReleaseTokenPool_setRebalancer is LockReleaseTokenPoolSetup {
+ function test_SetRebalancer_Success() public {
+ assertEq(address(s_lockReleaseTokenPool.getRebalancer()), OWNER);
+ s_lockReleaseTokenPool.setRebalancer(STRANGER);
+ assertEq(address(s_lockReleaseTokenPool.getRebalancer()), STRANGER);
+ }
+
+ function test_SetRebalancer_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+ s_lockReleaseTokenPool.setRebalancer(STRANGER);
+ }
+}
+
+contract LockReleaseTokenPool_lockOrBurn is LockReleaseTokenPoolSetup {
+ function test_Fuzz_LockOrBurnNoAllowList_Success(uint256 amount) public {
+ amount = bound(amount, 1, getOutboundRateLimiterConfig().capacity);
+ vm.startPrank(s_allowedOnRamp);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+ vm.expectEmit();
+ emit TokenPool.Locked(s_allowedOnRamp, amount);
+
+ s_lockReleaseTokenPool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: STRANGER,
+ receiver: bytes(""),
+ amount: amount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function test_LockOrBurnWithAllowList_Success() public {
+ uint256 amount = 100;
+ vm.startPrank(s_allowedOnRamp);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+ vm.expectEmit();
+ emit TokenPool.Locked(s_allowedOnRamp, amount);
+
+ s_lockReleaseTokenPoolWithAllowList.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: s_allowedList[0],
+ receiver: bytes(""),
+ amount: amount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+
+ vm.expectEmit();
+ emit TokenPool.Locked(s_allowedOnRamp, amount);
+
+ s_lockReleaseTokenPoolWithAllowList.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: s_allowedList[1],
+ receiver: bytes(""),
+ amount: amount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function test_LockOrBurnWithAllowList_Revert() public {
+ vm.startPrank(s_allowedOnRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.SenderNotAllowed.selector, STRANGER));
+
+ s_lockReleaseTokenPoolWithAllowList.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: STRANGER,
+ receiver: bytes(""),
+ amount: 100,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function test_PoolBurnRevertNotHealthy_Revert() public {
+ // Should not burn tokens if cursed.
+ s_mockRMN.setGlobalCursed(true);
+ uint256 before = s_token.balanceOf(address(s_lockReleaseTokenPoolWithAllowList));
+
+ vm.startPrank(s_allowedOnRamp);
+ vm.expectRevert(TokenPool.CursedByRMN.selector);
+
+ s_lockReleaseTokenPoolWithAllowList.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: s_allowedList[0],
+ receiver: bytes(""),
+ amount: 1e5,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+
+ assertEq(s_token.balanceOf(address(s_lockReleaseTokenPoolWithAllowList)), before);
+ }
+}
+
+contract LockReleaseTokenPool_releaseOrMint is LockReleaseTokenPoolSetup {
+ function setUp() public virtual override {
+ LockReleaseTokenPoolSetup.setUp();
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(s_sourcePoolAddress),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ s_lockReleaseTokenPool.applyChainUpdates(chainUpdate);
+ s_lockReleaseTokenPoolWithAllowList.applyChainUpdates(chainUpdate);
+ }
+
+ function test_ReleaseOrMint_Success() public {
+ vm.startPrank(s_allowedOffRamp);
+
+ uint256 amount = 100;
+ deal(address(s_token), address(s_lockReleaseTokenPool), amount);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+ vm.expectEmit();
+ emit TokenPool.Released(s_allowedOffRamp, OWNER, amount);
+
+ s_lockReleaseTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: amount,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: abi.encode(s_sourcePoolAddress),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+ }
+
+ function test_Fuzz_ReleaseOrMint_Success(address recipient, uint256 amount) public {
+ // Since the owner already has tokens this would break the checks
+ vm.assume(recipient != OWNER);
+ vm.assume(recipient != address(0));
+ vm.assume(recipient != address(s_token));
+
+ // Makes sure the pool always has enough funds
+ deal(address(s_token), address(s_lockReleaseTokenPool), amount);
+ vm.startPrank(s_allowedOffRamp);
+
+ uint256 capacity = getInboundRateLimiterConfig().capacity;
+ // Determine if we hit the rate limit or the txs should succeed.
+ if (amount > capacity) {
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.TokenMaxCapacityExceeded.selector, capacity, amount, address(s_token))
+ );
+ } else {
+ // Only rate limit if the amount is >0
+ if (amount > 0) {
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+ }
+
+ vm.expectEmit();
+ emit TokenPool.Released(s_allowedOffRamp, recipient, amount);
+ }
+
+ s_lockReleaseTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: recipient,
+ amount: amount,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: abi.encode(s_sourcePoolAddress),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ address notAllowedRemotePoolAddress = address(1);
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(notAllowedRemotePoolAddress),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: false,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0})
+ });
+
+ s_lockReleaseTokenPool.applyChainUpdates(chainUpdate);
+
+ vm.startPrank(s_allowedOffRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, SOURCE_CHAIN_SELECTOR));
+ s_lockReleaseTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: 1e5,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: abi.encode(s_sourcePoolAddress),
+ sourcePoolData: "",
+ offchainTokenData: ""
+ })
+ );
+ }
+
+ function test_PoolMintNotHealthy_Revert() public {
+ // Should not mint tokens if cursed.
+ s_mockRMN.setGlobalCursed(true);
+ uint256 before = s_token.balanceOf(OWNER);
+ vm.startPrank(s_allowedOffRamp);
+ vm.expectRevert(TokenPool.CursedByRMN.selector);
+ s_lockReleaseTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: bytes(""),
+ receiver: OWNER,
+ amount: 1e5,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: generateSourceTokenData().sourcePoolAddress,
+ sourcePoolData: generateSourceTokenData().extraData,
+ offchainTokenData: ""
+ })
+ );
+
+ assertEq(s_token.balanceOf(OWNER), before);
+ }
+}
+
+contract LockReleaseTokenPool_canAcceptLiquidity is LockReleaseTokenPoolSetup {
+ function test_CanAcceptLiquidity_Success() public {
+ assertEq(true, s_lockReleaseTokenPool.canAcceptLiquidity());
+
+ s_lockReleaseTokenPool =
+ new LockReleaseTokenPool(s_token, new address[](0), address(s_mockRMN), false, address(s_sourceRouter));
+ assertEq(false, s_lockReleaseTokenPool.canAcceptLiquidity());
+ }
+}
+
+contract LockReleaseTokenPool_provideLiquidity is LockReleaseTokenPoolSetup {
+ function test_Fuzz_ProvideLiquidity_Success(uint256 amount) public {
+ uint256 balancePre = s_token.balanceOf(OWNER);
+ s_token.approve(address(s_lockReleaseTokenPool), amount);
+
+ s_lockReleaseTokenPool.provideLiquidity(amount);
+
+ assertEq(s_token.balanceOf(OWNER), balancePre - amount);
+ assertEq(s_token.balanceOf(address(s_lockReleaseTokenPool)), amount);
+ }
+
+ // Reverts
+
+ function test_Unauthorized_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(LockReleaseTokenPool.Unauthorized.selector, STRANGER));
+
+ s_lockReleaseTokenPool.provideLiquidity(1);
+ }
+
+ function test_Fuzz_ExceedsAllowance(uint256 amount) public {
+ vm.assume(amount > 0);
+ vm.expectRevert("ERC20: insufficient allowance");
+ s_lockReleaseTokenPool.provideLiquidity(amount);
+ }
+
+ function test_LiquidityNotAccepted_Revert() public {
+ s_lockReleaseTokenPool =
+ new LockReleaseTokenPool(s_token, new address[](0), address(s_mockRMN), false, address(s_sourceRouter));
+
+ vm.expectRevert(LockReleaseTokenPool.LiquidityNotAccepted.selector);
+ s_lockReleaseTokenPool.provideLiquidity(1);
+ }
+}
+
+contract LockReleaseTokenPool_withdrawalLiquidity is LockReleaseTokenPoolSetup {
+ function test_Fuzz_WithdrawalLiquidity_Success(uint256 amount) public {
+ uint256 balancePre = s_token.balanceOf(OWNER);
+ s_token.approve(address(s_lockReleaseTokenPool), amount);
+ s_lockReleaseTokenPool.provideLiquidity(amount);
+
+ s_lockReleaseTokenPool.withdrawLiquidity(amount);
+
+ assertEq(s_token.balanceOf(OWNER), balancePre);
+ }
+
+ // Reverts
+
+ function test_Unauthorized_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(LockReleaseTokenPool.Unauthorized.selector, STRANGER));
+
+ s_lockReleaseTokenPool.withdrawLiquidity(1);
+ }
+
+ function test_InsufficientLiquidity_Revert() public {
+ uint256 maxUint256 = 2 ** 256 - 1;
+ s_token.approve(address(s_lockReleaseTokenPool), maxUint256);
+ s_lockReleaseTokenPool.provideLiquidity(maxUint256);
+
+ vm.startPrank(address(s_lockReleaseTokenPool));
+ s_token.transfer(OWNER, maxUint256);
+ vm.startPrank(OWNER);
+
+ vm.expectRevert(LockReleaseTokenPool.InsufficientLiquidity.selector);
+ s_lockReleaseTokenPool.withdrawLiquidity(1);
+ }
+}
+
+contract LockReleaseTokenPool_supportsInterface is LockReleaseTokenPoolSetup {
+ function test_SupportsInterface_Success() public view {
+ assertTrue(s_lockReleaseTokenPool.supportsInterface(type(IPoolV1).interfaceId));
+ assertTrue(s_lockReleaseTokenPool.supportsInterface(type(IERC165).interfaceId));
+ }
+}
+
+contract LockReleaseTokenPool_setChainRateLimiterConfig is LockReleaseTokenPoolSetup {
+ uint64 internal s_remoteChainSelector;
+
+ function setUp() public virtual override {
+ LockReleaseTokenPoolSetup.setUp();
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ s_remoteChainSelector = 123124;
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: s_remoteChainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_lockReleaseTokenPool.applyChainUpdates(chainUpdates);
+ }
+
+ function test_Fuzz_SetChainRateLimiterConfig_Success(uint128 capacity, uint128 rate, uint32 newTime) public {
+ // Cap the lower bound to 4 so 4/2 is still >= 2
+ vm.assume(capacity >= 4);
+ // Cap the lower bound to 2 so 2/2 is still >= 1
+ rate = uint128(bound(rate, 2, capacity - 2));
+ // Bucket updates only work on increasing time
+ newTime = uint32(bound(newTime, block.timestamp + 1, type(uint32).max));
+ vm.warp(newTime);
+
+ uint256 oldOutboundTokens = s_lockReleaseTokenPool.getCurrentOutboundRateLimiterState(s_remoteChainSelector).tokens;
+ uint256 oldInboundTokens = s_lockReleaseTokenPool.getCurrentInboundRateLimiterState(s_remoteChainSelector).tokens;
+
+ RateLimiter.Config memory newOutboundConfig = RateLimiter.Config({isEnabled: true, capacity: capacity, rate: rate});
+ RateLimiter.Config memory newInboundConfig =
+ RateLimiter.Config({isEnabled: true, capacity: capacity / 2, rate: rate / 2});
+
+ vm.expectEmit();
+ emit RateLimiter.ConfigChanged(newOutboundConfig);
+ vm.expectEmit();
+ emit RateLimiter.ConfigChanged(newInboundConfig);
+ vm.expectEmit();
+ emit TokenPool.ChainConfigured(s_remoteChainSelector, newOutboundConfig, newInboundConfig);
+
+ s_lockReleaseTokenPool.setChainRateLimiterConfig(s_remoteChainSelector, newOutboundConfig, newInboundConfig);
+
+ uint256 expectedTokens = RateLimiter._min(newOutboundConfig.capacity, oldOutboundTokens);
+
+ RateLimiter.TokenBucket memory bucket =
+ s_lockReleaseTokenPool.getCurrentOutboundRateLimiterState(s_remoteChainSelector);
+ assertEq(bucket.capacity, newOutboundConfig.capacity);
+ assertEq(bucket.rate, newOutboundConfig.rate);
+ assertEq(bucket.tokens, expectedTokens);
+ assertEq(bucket.lastUpdated, newTime);
+
+ expectedTokens = RateLimiter._min(newInboundConfig.capacity, oldInboundTokens);
+
+ bucket = s_lockReleaseTokenPool.getCurrentInboundRateLimiterState(s_remoteChainSelector);
+ assertEq(bucket.capacity, newInboundConfig.capacity);
+ assertEq(bucket.rate, newInboundConfig.rate);
+ assertEq(bucket.tokens, expectedTokens);
+ assertEq(bucket.lastUpdated, newTime);
+ }
+
+ function test_OnlyOwnerOrRateLimitAdmin_Revert() public {
+ address rateLimiterAdmin = address(28973509103597907);
+
+ s_lockReleaseTokenPool.setRateLimitAdmin(rateLimiterAdmin);
+
+ vm.startPrank(rateLimiterAdmin);
+
+ s_lockReleaseTokenPool.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+
+ vm.startPrank(OWNER);
+
+ s_lockReleaseTokenPool.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(abi.encodeWithSelector(LockReleaseTokenPool.Unauthorized.selector, STRANGER));
+ s_lockReleaseTokenPool.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+
+ function test_NonExistentChain_Revert() public {
+ uint64 wrongChainSelector = 9084102894;
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.NonExistentChain.selector, wrongChainSelector));
+ s_lockReleaseTokenPool.setChainRateLimiterConfig(
+ wrongChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+}
+
+contract LockReleaseTokenPool_setRateLimitAdmin is LockReleaseTokenPoolSetup {
+ function test_SetRateLimitAdmin_Success() public {
+ assertEq(address(0), s_lockReleaseTokenPool.getRateLimitAdmin());
+ s_lockReleaseTokenPool.setRateLimitAdmin(OWNER);
+ assertEq(OWNER, s_lockReleaseTokenPool.getRateLimitAdmin());
+ }
+
+ // Reverts
+
+ function test_SetRateLimitAdmin_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+ s_lockReleaseTokenPool.setRateLimitAdmin(STRANGER);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/TokenPool.t.sol b/contracts/src/v0.8/ccip/test/pools/TokenPool.t.sol
new file mode 100644
index 00000000000..e5eb04b7413
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/TokenPool.t.sol
@@ -0,0 +1,767 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {Router} from "../../Router.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {TokenPoolHelper} from "../helpers/TokenPoolHelper.sol";
+import {RouterSetup} from "../router/RouterSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract TokenPoolSetup is RouterSetup {
+ IERC20 internal s_token;
+ TokenPoolHelper internal s_tokenPool;
+
+ function setUp() public virtual override {
+ RouterSetup.setUp();
+ s_token = new BurnMintERC677("LINK", "LNK", 18, 0);
+ deal(address(s_token), OWNER, type(uint256).max);
+
+ s_tokenPool = new TokenPoolHelper(s_token, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ }
+}
+
+contract TokenPool_constructor is TokenPoolSetup {
+ function test_immutableFields_Success() public view {
+ assertEq(address(s_token), address(s_tokenPool.getToken()));
+ assertEq(address(s_mockRMN), s_tokenPool.getRmnProxy());
+ assertEq(false, s_tokenPool.getAllowListEnabled());
+ assertEq(address(s_sourceRouter), s_tokenPool.getRouter());
+ }
+
+ // Reverts
+ function test_ZeroAddressNotAllowed_Revert() public {
+ vm.expectRevert(TokenPool.ZeroAddressNotAllowed.selector);
+
+ s_tokenPool = new TokenPoolHelper(IERC20(address(0)), new address[](0), address(s_mockRMN), address(s_sourceRouter));
+ }
+}
+
+contract TokenPool_getRemotePool is TokenPoolSetup {
+ function test_getRemotePool_Success() public {
+ uint64 chainSelector = 123124;
+ address remotePool = makeAddr("remotePool");
+ address remoteToken = makeAddr("remoteToken");
+
+ // Zero indicates nothing is set
+ assertEq(0, s_tokenPool.getRemotePool(chainSelector).length);
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(remotePool),
+ remoteTokenAddress: abi.encode(remoteToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ assertEq(remotePool, abi.decode(s_tokenPool.getRemotePool(chainSelector), (address)));
+ }
+}
+
+contract TokenPool_setRemotePool is TokenPoolSetup {
+ function test_setRemotePool_Success() public {
+ uint64 chainSelector = DEST_CHAIN_SELECTOR;
+ address initialPool = makeAddr("remotePool");
+ address remoteToken = makeAddr("remoteToken");
+ // The new pool is a non-evm pool, as it doesn't fit in the normal 160 bits
+ bytes memory newPool = abi.encode(type(uint256).max);
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(initialPool),
+ remoteTokenAddress: abi.encode(remoteToken),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ vm.expectEmit();
+ emit TokenPool.RemotePoolSet(chainSelector, abi.encode(initialPool), newPool);
+
+ s_tokenPool.setRemotePool(chainSelector, newPool);
+
+ assertEq(keccak256(newPool), keccak256(s_tokenPool.getRemotePool(chainSelector)));
+ }
+
+ // Reverts
+
+ function test_setRemotePool_NonExistentChain_Reverts() public {
+ uint64 chainSelector = 123124;
+ bytes memory remotePool = abi.encode(makeAddr("remotePool"));
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.NonExistentChain.selector, chainSelector));
+ s_tokenPool.setRemotePool(chainSelector, remotePool);
+ }
+
+ function test_setRemotePool_OnlyOwner_Reverts() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+ s_tokenPool.setRemotePool(123124, abi.encode(makeAddr("remotePool")));
+ }
+}
+
+contract TokenPool_applyChainUpdates is TokenPoolSetup {
+ function assertState(TokenPool.ChainUpdate[] memory chainUpdates) public view {
+ uint64[] memory chainSelectors = s_tokenPool.getSupportedChains();
+ for (uint256 i = 0; i < chainUpdates.length; i++) {
+ assertEq(chainUpdates[i].remoteChainSelector, chainSelectors[i]);
+ }
+
+ for (uint256 i = 0; i < chainUpdates.length; ++i) {
+ assertTrue(s_tokenPool.isSupportedChain(chainUpdates[i].remoteChainSelector));
+ RateLimiter.TokenBucket memory bkt =
+ s_tokenPool.getCurrentOutboundRateLimiterState(chainUpdates[i].remoteChainSelector);
+ assertEq(bkt.capacity, chainUpdates[i].outboundRateLimiterConfig.capacity);
+ assertEq(bkt.rate, chainUpdates[i].outboundRateLimiterConfig.rate);
+ assertEq(bkt.isEnabled, chainUpdates[i].outboundRateLimiterConfig.isEnabled);
+
+ bkt = s_tokenPool.getCurrentInboundRateLimiterState(chainUpdates[i].remoteChainSelector);
+ assertEq(bkt.capacity, chainUpdates[i].inboundRateLimiterConfig.capacity);
+ assertEq(bkt.rate, chainUpdates[i].inboundRateLimiterConfig.rate);
+ assertEq(bkt.isEnabled, chainUpdates[i].inboundRateLimiterConfig.isEnabled);
+ }
+ }
+
+ function test_applyChainUpdates_Success() public {
+ RateLimiter.Config memory outboundRateLimit1 = RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e18});
+ RateLimiter.Config memory inboundRateLimit1 = RateLimiter.Config({isEnabled: true, capacity: 100e29, rate: 1e19});
+ RateLimiter.Config memory outboundRateLimit2 = RateLimiter.Config({isEnabled: true, capacity: 100e26, rate: 1e16});
+ RateLimiter.Config memory inboundRateLimit2 = RateLimiter.Config({isEnabled: true, capacity: 100e27, rate: 1e17});
+
+ // EVM chain, which uses the 160 bit evm address space
+ uint64 evmChainSelector = 1;
+ bytes memory evmRemotePool = abi.encode(makeAddr("evm_remote_pool"));
+ bytes memory evmRemoteToken = abi.encode(makeAddr("evm_remote_token"));
+
+ // Non EVM chain, which uses the full 256 bits
+ uint64 nonEvmChainSelector = type(uint64).max;
+ bytes memory nonEvmRemotePool = abi.encode(keccak256("non_evm_remote_pool"));
+ bytes memory nonEvmRemoteToken = abi.encode(keccak256("non_evm_remote_token"));
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](2);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: evmChainSelector,
+ remotePoolAddress: evmRemotePool,
+ remoteTokenAddress: evmRemoteToken,
+ allowed: true,
+ outboundRateLimiterConfig: outboundRateLimit1,
+ inboundRateLimiterConfig: inboundRateLimit1
+ });
+ chainUpdates[1] = TokenPool.ChainUpdate({
+ remoteChainSelector: nonEvmChainSelector,
+ remotePoolAddress: nonEvmRemotePool,
+ remoteTokenAddress: nonEvmRemoteToken,
+ allowed: true,
+ outboundRateLimiterConfig: outboundRateLimit2,
+ inboundRateLimiterConfig: inboundRateLimit2
+ });
+
+ // Assert configuration is applied
+ vm.expectEmit();
+ emit TokenPool.ChainAdded(
+ chainUpdates[0].remoteChainSelector,
+ chainUpdates[0].remoteTokenAddress,
+ chainUpdates[0].outboundRateLimiterConfig,
+ chainUpdates[0].inboundRateLimiterConfig
+ );
+ vm.expectEmit();
+ emit TokenPool.ChainAdded(
+ chainUpdates[1].remoteChainSelector,
+ chainUpdates[1].remoteTokenAddress,
+ chainUpdates[1].outboundRateLimiterConfig,
+ chainUpdates[1].inboundRateLimiterConfig
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+ // on1: rateLimit1, on2: rateLimit2, off1: rateLimit1, off2: rateLimit3
+ assertState(chainUpdates);
+
+ // Removing an non-existent chain should revert
+ TokenPool.ChainUpdate[] memory chainRemoves = new TokenPool.ChainUpdate[](1);
+ uint64 strangerChainSelector = 120938;
+ chainRemoves[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: strangerChainSelector,
+ remotePoolAddress: evmRemotePool,
+ remoteTokenAddress: evmRemoteToken,
+ allowed: false,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0})
+ });
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.NonExistentChain.selector, strangerChainSelector));
+ s_tokenPool.applyChainUpdates(chainRemoves);
+ // State remains
+ assertState(chainUpdates);
+
+ // Can remove a chain
+ chainRemoves[0].remoteChainSelector = evmChainSelector;
+
+ vm.expectEmit();
+ emit TokenPool.ChainRemoved(chainRemoves[0].remoteChainSelector);
+
+ s_tokenPool.applyChainUpdates(chainRemoves);
+
+ // State updated, only chain 2 remains
+ TokenPool.ChainUpdate[] memory singleChainConfigured = new TokenPool.ChainUpdate[](1);
+ singleChainConfigured[0] = chainUpdates[1];
+ assertState(singleChainConfigured);
+
+ // Cannot reset already configured ramp
+ vm.expectRevert(
+ abi.encodeWithSelector(TokenPool.ChainAlreadyExists.selector, singleChainConfigured[0].remoteChainSelector)
+ );
+ s_tokenPool.applyChainUpdates(singleChainConfigured);
+ }
+
+ // Reverts
+
+ function test_applyChainUpdates_OnlyCallableByOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_tokenPool.applyChainUpdates(new TokenPool.ChainUpdate[](0));
+ }
+
+ function test_applyChainUpdates_ZeroAddressNotAllowed_Revert() public {
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: 1,
+ remotePoolAddress: "",
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e18}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e18})
+ });
+
+ vm.expectRevert(TokenPool.ZeroAddressNotAllowed.selector);
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: 1,
+ remotePoolAddress: abi.encode(address(2)),
+ remoteTokenAddress: "",
+ allowed: true,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e18}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e18})
+ });
+
+ vm.expectRevert(TokenPool.ZeroAddressNotAllowed.selector);
+ s_tokenPool.applyChainUpdates(chainUpdates);
+ }
+
+ function test_applyChainUpdates_DisabledNonZeroRateLimit_Revert() public {
+ RateLimiter.Config memory outboundRateLimit = RateLimiter.Config({isEnabled: true, capacity: 100e28, rate: 1e18});
+ RateLimiter.Config memory inboundRateLimit = RateLimiter.Config({isEnabled: true, capacity: 100e22, rate: 1e12});
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: 1,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: outboundRateLimit,
+ inboundRateLimiterConfig: inboundRateLimit
+ });
+
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].allowed = false;
+ chainUpdates[0].outboundRateLimiterConfig = RateLimiter.Config({isEnabled: false, capacity: 10, rate: 1});
+ chainUpdates[0].inboundRateLimiterConfig = RateLimiter.Config({isEnabled: false, capacity: 10, rate: 1});
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.DisabledNonZeroRateLimit.selector, chainUpdates[0].outboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+ }
+
+ function test_applyChainUpdates_NonExistentChain_Revert() public {
+ RateLimiter.Config memory outboundRateLimit = RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0});
+ RateLimiter.Config memory inboundRateLimit = RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0});
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: 1,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: false,
+ outboundRateLimiterConfig: outboundRateLimit,
+ inboundRateLimiterConfig: inboundRateLimit
+ });
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.NonExistentChain.selector, chainUpdates[0].remoteChainSelector));
+ s_tokenPool.applyChainUpdates(chainUpdates);
+ }
+
+ function test_applyChainUpdates_InvalidRateLimitRate_Revert() public {
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: 1,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: true, capacity: 0, rate: 0}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: true, capacity: 100e22, rate: 1e12})
+ });
+
+ // Outbound
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.InvalidRateLimitRate.selector, chainUpdates[0].outboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].outboundRateLimiterConfig.rate = 100;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.InvalidRateLimitRate.selector, chainUpdates[0].outboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].outboundRateLimiterConfig.capacity = 100;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.InvalidRateLimitRate.selector, chainUpdates[0].outboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].outboundRateLimiterConfig.capacity = 101;
+
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ // Change the chain selector as adding the same one would revert
+ chainUpdates[0].remoteChainSelector = 2;
+
+ // Inbound
+
+ chainUpdates[0].inboundRateLimiterConfig.capacity = 0;
+ chainUpdates[0].inboundRateLimiterConfig.rate = 0;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.InvalidRateLimitRate.selector, chainUpdates[0].inboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].inboundRateLimiterConfig.rate = 100;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.InvalidRateLimitRate.selector, chainUpdates[0].inboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].inboundRateLimiterConfig.capacity = 100;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.InvalidRateLimitRate.selector, chainUpdates[0].inboundRateLimiterConfig)
+ );
+ s_tokenPool.applyChainUpdates(chainUpdates);
+
+ chainUpdates[0].inboundRateLimiterConfig.capacity = 101;
+
+ s_tokenPool.applyChainUpdates(chainUpdates);
+ }
+}
+
+contract TokenPool_setChainRateLimiterConfig is TokenPoolSetup {
+ uint64 internal s_remoteChainSelector;
+
+ function setUp() public virtual override {
+ TokenPoolSetup.setUp();
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ s_remoteChainSelector = 123124;
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: s_remoteChainSelector,
+ remotePoolAddress: abi.encode(address(2)),
+ remoteTokenAddress: abi.encode(address(3)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdates);
+ }
+
+ function test_Fuzz_SetChainRateLimiterConfig_Success(uint128 capacity, uint128 rate, uint32 newTime) public {
+ // Cap the lower bound to 4 so 4/2 is still >= 2
+ vm.assume(capacity >= 4);
+ // Cap the lower bound to 2 so 2/2 is still >= 1
+ rate = uint128(bound(rate, 2, capacity - 2));
+ // Bucket updates only work on increasing time
+ newTime = uint32(bound(newTime, block.timestamp + 1, type(uint32).max));
+ vm.warp(newTime);
+
+ uint256 oldOutboundTokens = s_tokenPool.getCurrentOutboundRateLimiterState(s_remoteChainSelector).tokens;
+ uint256 oldInboundTokens = s_tokenPool.getCurrentInboundRateLimiterState(s_remoteChainSelector).tokens;
+
+ RateLimiter.Config memory newOutboundConfig = RateLimiter.Config({isEnabled: true, capacity: capacity, rate: rate});
+ RateLimiter.Config memory newInboundConfig =
+ RateLimiter.Config({isEnabled: true, capacity: capacity / 2, rate: rate / 2});
+
+ vm.expectEmit();
+ emit RateLimiter.ConfigChanged(newOutboundConfig);
+ vm.expectEmit();
+ emit RateLimiter.ConfigChanged(newInboundConfig);
+ vm.expectEmit();
+ emit TokenPool.ChainConfigured(s_remoteChainSelector, newOutboundConfig, newInboundConfig);
+
+ s_tokenPool.setChainRateLimiterConfig(s_remoteChainSelector, newOutboundConfig, newInboundConfig);
+
+ uint256 expectedTokens = RateLimiter._min(newOutboundConfig.capacity, oldOutboundTokens);
+
+ RateLimiter.TokenBucket memory bucket = s_tokenPool.getCurrentOutboundRateLimiterState(s_remoteChainSelector);
+ assertEq(bucket.capacity, newOutboundConfig.capacity);
+ assertEq(bucket.rate, newOutboundConfig.rate);
+ assertEq(bucket.tokens, expectedTokens);
+ assertEq(bucket.lastUpdated, newTime);
+
+ expectedTokens = RateLimiter._min(newInboundConfig.capacity, oldInboundTokens);
+
+ bucket = s_tokenPool.getCurrentInboundRateLimiterState(s_remoteChainSelector);
+ assertEq(bucket.capacity, newInboundConfig.capacity);
+ assertEq(bucket.rate, newInboundConfig.rate);
+ assertEq(bucket.tokens, expectedTokens);
+ assertEq(bucket.lastUpdated, newTime);
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+ s_tokenPool.setChainRateLimiterConfig(
+ s_remoteChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+
+ function test_NonExistentChain_Revert() public {
+ uint64 wrongChainSelector = 9084102894;
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.NonExistentChain.selector, wrongChainSelector));
+ s_tokenPool.setChainRateLimiterConfig(
+ wrongChainSelector, getOutboundRateLimiterConfig(), getInboundRateLimiterConfig()
+ );
+ }
+}
+
+contract TokenPool_onlyOnRamp is TokenPoolSetup {
+ function test_onlyOnRamp_Success() public {
+ uint64 chainSelector = 13377;
+ address onRamp = makeAddr("onRamp");
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: chainSelector, onRamp: onRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), new Router.OffRamp[](0));
+
+ vm.startPrank(onRamp);
+
+ s_tokenPool.onlyOnRampModifier(chainSelector);
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ uint64 chainSelector = 13377;
+ address onRamp = makeAddr("onRamp");
+
+ vm.startPrank(onRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, chainSelector));
+ s_tokenPool.onlyOnRampModifier(chainSelector);
+
+ vm.startPrank(OWNER);
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: chainSelector, onRamp: onRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), new Router.OffRamp[](0));
+
+ vm.startPrank(onRamp);
+ // Should succeed now that we've added the chain
+ s_tokenPool.onlyOnRampModifier(chainSelector);
+
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: false,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0})
+ });
+
+ vm.startPrank(OWNER);
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ vm.startPrank(onRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, chainSelector));
+ s_tokenPool.onlyOffRampModifier(chainSelector);
+ }
+
+ function test_CallerIsNotARampOnRouter_Revert() public {
+ uint64 chainSelector = 13377;
+ address onRamp = makeAddr("onRamp");
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ vm.startPrank(onRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.CallerIsNotARampOnRouter.selector, onRamp));
+
+ s_tokenPool.onlyOnRampModifier(chainSelector);
+ }
+}
+
+contract TokenPool_onlyOffRamp is TokenPoolSetup {
+ function test_onlyOffRamp_Success() public {
+ uint64 chainSelector = 13377;
+ address offRamp = makeAddr("onRamp");
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: chainSelector, offRamp: offRamp});
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), new Router.OffRamp[](0), offRampUpdates);
+
+ vm.startPrank(offRamp);
+
+ s_tokenPool.onlyOffRampModifier(chainSelector);
+ }
+
+ function test_ChainNotAllowed_Revert() public {
+ uint64 chainSelector = 13377;
+ address offRamp = makeAddr("onRamp");
+
+ vm.startPrank(offRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, chainSelector));
+ s_tokenPool.onlyOffRampModifier(chainSelector);
+
+ vm.startPrank(OWNER);
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: chainSelector, offRamp: offRamp});
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), new Router.OffRamp[](0), offRampUpdates);
+
+ vm.startPrank(offRamp);
+ // Should succeed now that we've added the chain
+ s_tokenPool.onlyOffRampModifier(chainSelector);
+
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: false,
+ outboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0}),
+ inboundRateLimiterConfig: RateLimiter.Config({isEnabled: false, capacity: 0, rate: 0})
+ });
+
+ vm.startPrank(OWNER);
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ vm.startPrank(offRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.ChainNotAllowed.selector, chainSelector));
+ s_tokenPool.onlyOffRampModifier(chainSelector);
+ }
+
+ function test_CallerIsNotARampOnRouter_Revert() public {
+ uint64 chainSelector = 13377;
+ address offRamp = makeAddr("offRamp");
+
+ TokenPool.ChainUpdate[] memory chainUpdate = new TokenPool.ChainUpdate[](1);
+ chainUpdate[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: chainSelector,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ s_tokenPool.applyChainUpdates(chainUpdate);
+
+ vm.startPrank(offRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.CallerIsNotARampOnRouter.selector, offRamp));
+
+ s_tokenPool.onlyOffRampModifier(chainSelector);
+ }
+}
+
+contract TokenPoolWithAllowListSetup is TokenPoolSetup {
+ address[] internal s_allowedSenders;
+
+ function setUp() public virtual override {
+ TokenPoolSetup.setUp();
+
+ s_allowedSenders.push(STRANGER);
+ s_allowedSenders.push(DUMMY_CONTRACT_ADDRESS);
+
+ s_tokenPool = new TokenPoolHelper(s_token, s_allowedSenders, address(s_mockRMN), address(s_sourceRouter));
+ }
+}
+
+contract TokenPoolWithAllowList_getAllowListEnabled is TokenPoolWithAllowListSetup {
+ function test_GetAllowListEnabled_Success() public view {
+ assertTrue(s_tokenPool.getAllowListEnabled());
+ }
+}
+
+contract TokenPoolWithAllowList_setRouter is TokenPoolWithAllowListSetup {
+ function test_SetRouter_Success() public {
+ assertEq(address(s_sourceRouter), s_tokenPool.getRouter());
+
+ address newRouter = makeAddr("newRouter");
+
+ vm.expectEmit();
+ emit TokenPool.RouterUpdated(address(s_sourceRouter), newRouter);
+
+ s_tokenPool.setRouter(newRouter);
+
+ assertEq(newRouter, s_tokenPool.getRouter());
+ }
+}
+
+contract TokenPoolWithAllowList_getAllowList is TokenPoolWithAllowListSetup {
+ function test_GetAllowList_Success() public view {
+ address[] memory setAddresses = s_tokenPool.getAllowList();
+ assertEq(2, setAddresses.length);
+ assertEq(s_allowedSenders[0], setAddresses[0]);
+ assertEq(s_allowedSenders[1], setAddresses[1]);
+ }
+}
+
+contract TokenPoolWithAllowList_applyAllowListUpdates is TokenPoolWithAllowListSetup {
+ function test_SetAllowList_Success() public {
+ address[] memory newAddresses = new address[](2);
+ newAddresses[0] = address(1);
+ newAddresses[1] = address(2);
+
+ for (uint256 i = 0; i < 2; ++i) {
+ vm.expectEmit();
+ emit TokenPool.AllowListAdd(newAddresses[i]);
+ }
+
+ s_tokenPool.applyAllowListUpdates(new address[](0), newAddresses);
+ address[] memory setAddresses = s_tokenPool.getAllowList();
+
+ assertEq(s_allowedSenders[0], setAddresses[0]);
+ assertEq(s_allowedSenders[1], setAddresses[1]);
+ assertEq(address(1), setAddresses[2]);
+ assertEq(address(2), setAddresses[3]);
+
+ // address(2) exists noop, add address(3), remove address(1)
+ newAddresses = new address[](2);
+ newAddresses[0] = address(2);
+ newAddresses[1] = address(3);
+
+ address[] memory removeAddresses = new address[](1);
+ removeAddresses[0] = address(1);
+
+ vm.expectEmit();
+ emit TokenPool.AllowListRemove(address(1));
+
+ vm.expectEmit();
+ emit TokenPool.AllowListAdd(address(3));
+
+ s_tokenPool.applyAllowListUpdates(removeAddresses, newAddresses);
+ setAddresses = s_tokenPool.getAllowList();
+
+ assertEq(s_allowedSenders[0], setAddresses[0]);
+ assertEq(s_allowedSenders[1], setAddresses[1]);
+ assertEq(address(2), setAddresses[2]);
+ assertEq(address(3), setAddresses[3]);
+
+ // remove all from allowList
+ for (uint256 i = 0; i < setAddresses.length; ++i) {
+ vm.expectEmit();
+ emit TokenPool.AllowListRemove(setAddresses[i]);
+ }
+
+ s_tokenPool.applyAllowListUpdates(setAddresses, new address[](0));
+ setAddresses = s_tokenPool.getAllowList();
+
+ assertEq(0, setAddresses.length);
+ }
+
+ function test_SetAllowListSkipsZero_Success() public {
+ uint256 setAddressesLength = s_tokenPool.getAllowList().length;
+
+ address[] memory newAddresses = new address[](1);
+ newAddresses[0] = address(0);
+
+ s_tokenPool.applyAllowListUpdates(new address[](0), newAddresses);
+ address[] memory setAddresses = s_tokenPool.getAllowList();
+
+ assertEq(setAddresses.length, setAddressesLength);
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ address[] memory newAddresses = new address[](2);
+ s_tokenPool.applyAllowListUpdates(new address[](0), newAddresses);
+ }
+
+ function test_AllowListNotEnabled_Revert() public {
+ s_tokenPool = new TokenPoolHelper(s_token, new address[](0), address(s_mockRMN), address(s_sourceRouter));
+
+ vm.expectRevert(TokenPool.AllowListNotEnabled.selector);
+
+ s_tokenPool.applyAllowListUpdates(new address[](0), new address[](2));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/pools/USDCTokenPool.t.sol b/contracts/src/v0.8/ccip/test/pools/USDCTokenPool.t.sol
new file mode 100644
index 00000000000..200ffb4f6d6
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/pools/USDCTokenPool.t.sol
@@ -0,0 +1,690 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBurnMintERC20} from "../../../shared/token/ERC20/IBurnMintERC20.sol";
+import {IPoolV1} from "../../interfaces/IPool.sol";
+import {ITokenMessenger} from "../../pools/USDC/ITokenMessenger.sol";
+
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {Router} from "../../Router.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {USDCTokenPool} from "../../pools/USDC/USDCTokenPool.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {USDCTokenPoolHelper} from "../helpers/USDCTokenPoolHelper.sol";
+import {MockE2EUSDCTransmitter} from "../mocks/MockE2EUSDCTransmitter.sol";
+import {MockUSDCTokenMessenger} from "../mocks/MockUSDCTokenMessenger.sol";
+
+import {IERC165} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/IERC165.sol";
+
+contract USDCTokenPoolSetup is BaseTest {
+ IBurnMintERC20 internal s_token;
+ MockUSDCTokenMessenger internal s_mockUSDC;
+ MockE2EUSDCTransmitter internal s_mockUSDCTransmitter;
+
+ struct USDCMessage {
+ uint32 version;
+ uint32 sourceDomain;
+ uint32 destinationDomain;
+ uint64 nonce;
+ bytes32 sender;
+ bytes32 recipient;
+ bytes32 destinationCaller;
+ bytes messageBody;
+ }
+
+ uint32 internal constant SOURCE_DOMAIN_IDENTIFIER = 0x02020202;
+ uint32 internal constant DEST_DOMAIN_IDENTIFIER = 0;
+
+ bytes32 internal constant SOURCE_CHAIN_TOKEN_SENDER = bytes32(uint256(uint160(0x01111111221)));
+ address internal constant SOURCE_CHAIN_USDC_POOL = address(0x23789765456789);
+ address internal constant DEST_CHAIN_USDC_POOL = address(0x987384873458734);
+ address internal constant DEST_CHAIN_USDC_TOKEN = address(0x23598918358198766);
+
+ address internal s_routerAllowedOnRamp = address(3456);
+ address internal s_routerAllowedOffRamp = address(234);
+ Router internal s_router;
+
+ USDCTokenPoolHelper internal s_usdcTokenPool;
+ USDCTokenPoolHelper internal s_usdcTokenPoolWithAllowList;
+ address[] internal s_allowedList;
+
+ function setUp() public virtual override {
+ BaseTest.setUp();
+ BurnMintERC677 usdcToken = new BurnMintERC677("LINK", "LNK", 18, 0);
+ s_token = usdcToken;
+ deal(address(s_token), OWNER, type(uint256).max);
+ setUpRamps();
+
+ s_mockUSDCTransmitter = new MockE2EUSDCTransmitter(0, DEST_DOMAIN_IDENTIFIER, address(s_token));
+ s_mockUSDC = new MockUSDCTokenMessenger(0, address(s_mockUSDCTransmitter));
+
+ usdcToken.grantMintAndBurnRoles(address(s_mockUSDCTransmitter));
+
+ s_usdcTokenPool =
+ new USDCTokenPoolHelper(s_mockUSDC, s_token, new address[](0), address(s_mockRMN), address(s_router));
+ usdcToken.grantMintAndBurnRoles(address(s_mockUSDC));
+
+ s_allowedList.push(USER_1);
+ s_usdcTokenPoolWithAllowList =
+ new USDCTokenPoolHelper(s_mockUSDC, s_token, s_allowedList, address(s_mockRMN), address(s_router));
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](2);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(SOURCE_CHAIN_USDC_POOL),
+ remoteTokenAddress: abi.encode(address(s_token)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+ chainUpdates[1] = TokenPool.ChainUpdate({
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ remotePoolAddress: abi.encode(DEST_CHAIN_USDC_POOL),
+ remoteTokenAddress: abi.encode(DEST_CHAIN_USDC_TOKEN),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ s_usdcTokenPool.applyChainUpdates(chainUpdates);
+ s_usdcTokenPoolWithAllowList.applyChainUpdates(chainUpdates);
+
+ USDCTokenPool.DomainUpdate[] memory domains = new USDCTokenPool.DomainUpdate[](1);
+ domains[0] = USDCTokenPool.DomainUpdate({
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ domainIdentifier: 9999,
+ allowedCaller: keccak256("allowedCaller"),
+ enabled: true
+ });
+
+ s_usdcTokenPool.setDomains(domains);
+ s_usdcTokenPoolWithAllowList.setDomains(domains);
+ }
+
+ function setUpRamps() internal {
+ s_router = new Router(address(s_token), address(s_mockRMN));
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: s_routerAllowedOnRamp});
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ address[] memory offRamps = new address[](1);
+ offRamps[0] = s_routerAllowedOffRamp;
+ offRampUpdates[0] = Router.OffRamp({sourceChainSelector: SOURCE_CHAIN_SELECTOR, offRamp: offRamps[0]});
+
+ s_router.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ }
+
+ function _generateUSDCMessage(USDCMessage memory usdcMessage) internal pure returns (bytes memory) {
+ return abi.encodePacked(
+ usdcMessage.version,
+ usdcMessage.sourceDomain,
+ usdcMessage.destinationDomain,
+ usdcMessage.nonce,
+ usdcMessage.sender,
+ usdcMessage.recipient,
+ usdcMessage.destinationCaller,
+ usdcMessage.messageBody
+ );
+ }
+}
+
+contract USDCTokenPool_lockOrBurn is USDCTokenPoolSetup {
+ // Base test case, included for PR gas comparisons as fuzz tests are excluded from forge snapshot due to being flaky.
+ function test_LockOrBurn_Success() public {
+ bytes32 receiver = bytes32(uint256(uint160(STRANGER)));
+ uint256 amount = 1;
+ s_token.transfer(address(s_usdcTokenPool), amount);
+ vm.startPrank(s_routerAllowedOnRamp);
+
+ USDCTokenPool.Domain memory expectedDomain = s_usdcTokenPool.getDomain(DEST_CHAIN_SELECTOR);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+
+ vm.expectEmit();
+ emit ITokenMessenger.DepositForBurn(
+ s_mockUSDC.s_nonce(),
+ address(s_token),
+ amount,
+ address(s_usdcTokenPool),
+ expectedDomain.allowedCaller,
+ expectedDomain.domainIdentifier,
+ s_mockUSDC.DESTINATION_TOKEN_MESSENGER(),
+ expectedDomain.allowedCaller
+ );
+
+ vm.expectEmit();
+ emit TokenPool.Burned(s_routerAllowedOnRamp, amount);
+
+ Pool.LockOrBurnOutV1 memory poolReturnDataV1 = s_usdcTokenPool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: abi.encodePacked(receiver),
+ amount: amount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+
+ uint64 nonce = abi.decode(poolReturnDataV1.destPoolData, (uint64));
+ assertEq(s_mockUSDC.s_nonce() - 1, nonce);
+ }
+
+ function test_Fuzz_LockOrBurn_Success(bytes32 destinationReceiver, uint256 amount) public {
+ vm.assume(destinationReceiver != bytes32(0));
+ amount = bound(amount, 1, getOutboundRateLimiterConfig().capacity);
+ s_token.transfer(address(s_usdcTokenPool), amount);
+ vm.startPrank(s_routerAllowedOnRamp);
+
+ USDCTokenPool.Domain memory expectedDomain = s_usdcTokenPool.getDomain(DEST_CHAIN_SELECTOR);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+
+ vm.expectEmit();
+ emit ITokenMessenger.DepositForBurn(
+ s_mockUSDC.s_nonce(),
+ address(s_token),
+ amount,
+ address(s_usdcTokenPool),
+ expectedDomain.allowedCaller,
+ expectedDomain.domainIdentifier,
+ s_mockUSDC.DESTINATION_TOKEN_MESSENGER(),
+ expectedDomain.allowedCaller
+ );
+
+ vm.expectEmit();
+ emit TokenPool.Burned(s_routerAllowedOnRamp, amount);
+
+ Pool.LockOrBurnOutV1 memory poolReturnDataV1 = s_usdcTokenPool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: abi.encodePacked(destinationReceiver),
+ amount: amount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+
+ uint64 nonce = abi.decode(poolReturnDataV1.destPoolData, (uint64));
+ assertEq(s_mockUSDC.s_nonce() - 1, nonce);
+ assertEq(poolReturnDataV1.destTokenAddress, abi.encode(DEST_CHAIN_USDC_TOKEN));
+ }
+
+ function test_Fuzz_LockOrBurnWithAllowList_Success(bytes32 destinationReceiver, uint256 amount) public {
+ vm.assume(destinationReceiver != bytes32(0));
+ amount = bound(amount, 1, getOutboundRateLimiterConfig().capacity);
+ s_token.transfer(address(s_usdcTokenPoolWithAllowList), amount);
+ vm.startPrank(s_routerAllowedOnRamp);
+
+ USDCTokenPool.Domain memory expectedDomain = s_usdcTokenPoolWithAllowList.getDomain(DEST_CHAIN_SELECTOR);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(amount);
+ vm.expectEmit();
+ emit ITokenMessenger.DepositForBurn(
+ s_mockUSDC.s_nonce(),
+ address(s_token),
+ amount,
+ address(s_usdcTokenPoolWithAllowList),
+ expectedDomain.allowedCaller,
+ expectedDomain.domainIdentifier,
+ s_mockUSDC.DESTINATION_TOKEN_MESSENGER(),
+ expectedDomain.allowedCaller
+ );
+ vm.expectEmit();
+ emit TokenPool.Burned(s_routerAllowedOnRamp, amount);
+
+ Pool.LockOrBurnOutV1 memory poolReturnDataV1 = s_usdcTokenPoolWithAllowList.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: s_allowedList[0],
+ receiver: abi.encodePacked(destinationReceiver),
+ amount: amount,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ uint64 nonce = abi.decode(poolReturnDataV1.destPoolData, (uint64));
+ assertEq(s_mockUSDC.s_nonce() - 1, nonce);
+ assertEq(poolReturnDataV1.destTokenAddress, abi.encode(DEST_CHAIN_USDC_TOKEN));
+ }
+
+ // Reverts
+ function test_UnknownDomain_Revert() public {
+ uint64 wrongDomain = DEST_CHAIN_SELECTOR + 1;
+ // We need to setup the wrong chainSelector so it reaches the domain check
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: wrongDomain, onRamp: s_routerAllowedOnRamp});
+ s_router.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), new Router.OffRamp[](0));
+
+ TokenPool.ChainUpdate[] memory chainUpdates = new TokenPool.ChainUpdate[](1);
+ chainUpdates[0] = TokenPool.ChainUpdate({
+ remoteChainSelector: wrongDomain,
+ remotePoolAddress: abi.encode(address(1)),
+ remoteTokenAddress: abi.encode(address(2)),
+ allowed: true,
+ outboundRateLimiterConfig: getOutboundRateLimiterConfig(),
+ inboundRateLimiterConfig: getInboundRateLimiterConfig()
+ });
+
+ s_usdcTokenPool.applyChainUpdates(chainUpdates);
+
+ uint256 amount = 1000;
+ vm.startPrank(s_routerAllowedOnRamp);
+ deal(address(s_token), s_routerAllowedOnRamp, amount);
+ s_token.approve(address(s_usdcTokenPool), amount);
+
+ vm.expectRevert(abi.encodeWithSelector(USDCTokenPool.UnknownDomain.selector, wrongDomain));
+
+ s_usdcTokenPool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: abi.encodePacked(address(0)),
+ amount: amount,
+ remoteChainSelector: wrongDomain,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function test_CallerIsNotARampOnRouter_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.CallerIsNotARampOnRouter.selector, OWNER));
+
+ s_usdcTokenPool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: abi.encodePacked(address(0)),
+ amount: 0,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function test_LockOrBurnWithAllowList_Revert() public {
+ vm.startPrank(s_routerAllowedOnRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenPool.SenderNotAllowed.selector, STRANGER));
+
+ s_usdcTokenPoolWithAllowList.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: STRANGER,
+ receiver: abi.encodePacked(address(0)),
+ amount: 1000,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ }
+
+ function test_lockOrBurn_InvalidReceiver_Revert() public {
+ vm.startPrank(s_routerAllowedOnRamp);
+
+ bytes memory receiver = abi.encodePacked(address(0), address(1));
+
+ vm.expectRevert(abi.encodeWithSelector(USDCTokenPool.InvalidReceiver.selector, receiver));
+
+ s_usdcTokenPool.lockOrBurn(
+ Pool.LockOrBurnInV1({
+ originalSender: OWNER,
+ receiver: receiver,
+ amount: 1,
+ remoteChainSelector: DEST_CHAIN_SELECTOR,
+ localToken: address(s_token)
+ })
+ );
+ }
+}
+
+contract USDCTokenPool_releaseOrMint is USDCTokenPoolSetup {
+ function test_Fuzz_ReleaseOrMint_Success(address recipient, uint256 amount) public {
+ vm.assume(recipient != address(0) && recipient != address(s_token));
+ amount = bound(amount, 0, getInboundRateLimiterConfig().capacity);
+
+ USDCMessage memory usdcMessage = USDCMessage({
+ version: 0,
+ sourceDomain: SOURCE_DOMAIN_IDENTIFIER,
+ destinationDomain: DEST_DOMAIN_IDENTIFIER,
+ nonce: 0x060606060606,
+ sender: SOURCE_CHAIN_TOKEN_SENDER,
+ recipient: bytes32(uint256(uint160(recipient))),
+ destinationCaller: bytes32(uint256(uint160(address(s_usdcTokenPool)))),
+ messageBody: bytes("")
+ });
+
+ bytes memory message = _generateUSDCMessage(usdcMessage);
+ bytes memory attestation = bytes("attestation bytes");
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(SOURCE_CHAIN_USDC_POOL),
+ destTokenAddress: abi.encode(address(s_usdcTokenPool)),
+ extraData: abi.encode(
+ USDCTokenPool.SourceTokenDataPayload({nonce: usdcMessage.nonce, sourceDomain: SOURCE_DOMAIN_IDENTIFIER})
+ )
+ });
+
+ bytes memory offchainTokenData =
+ abi.encode(USDCTokenPool.MessageAndAttestation({message: message, attestation: attestation}));
+
+ // The mocked receiver does not release the token to the pool, so we manually do it here
+ deal(address(s_token), address(s_usdcTokenPool), amount);
+
+ vm.expectEmit();
+ emit TokenPool.Minted(s_routerAllowedOffRamp, recipient, amount);
+
+ vm.expectCall(
+ address(s_mockUSDCTransmitter),
+ abi.encodeWithSelector(MockE2EUSDCTransmitter.receiveMessage.selector, message, attestation)
+ );
+
+ vm.startPrank(s_routerAllowedOffRamp);
+ s_usdcTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: recipient,
+ amount: amount,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ );
+ }
+
+ // https://etherscan.io/tx/0xac9f501fe0b76df1f07a22e1db30929fd12524bc7068d74012dff948632f0883
+ function test_ReleaseOrMintRealTx_Success() public {
+ bytes memory encodedUsdcMessage =
+ hex"000000000000000300000000000000000000127a00000000000000000000000019330d10d9cc8751218eaf51e8885d058642e08a000000000000000000000000bd3fa81b58ba92a82136038b25adec7066af3155000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000af88d065e77c8cc2239327c5edb3a432268e58310000000000000000000000004af08f56978be7dce2d1be3c65c005b41e79401c000000000000000000000000000000000000000000000000000000002057ff7a0000000000000000000000003a23f943181408eac424116af7b7790c94cb97a50000000000000000000000000000000000000000000000000000000000000000000000000000008274119237535fd659626b090f87e365ff89ebc7096bb32e8b0e85f155626b73ae7c4bb2485c184b7cc3cf7909045487890b104efb62ae74a73e32901bdcec91df1bb9ee08ccb014fcbcfe77b74d1263fd4e0b0e8de05d6c9a5913554364abfd5ea768b222f50c715908183905d74044bb2b97527c7e70ae7983c443a603557cac3b1c000000000000000000000000000000000000000000000000000000000000";
+ bytes memory attestation = bytes("attestation bytes");
+
+ uint32 nonce = 4730;
+ uint32 sourceDomain = 3;
+ uint256 amount = 100;
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(SOURCE_CHAIN_USDC_POOL),
+ destTokenAddress: abi.encode(address(s_usdcTokenPool)),
+ extraData: abi.encode(USDCTokenPool.SourceTokenDataPayload({nonce: nonce, sourceDomain: sourceDomain}))
+ });
+
+ // The mocked receiver does not release the token to the pool, so we manually do it here
+ deal(address(s_token), address(s_usdcTokenPool), amount);
+
+ bytes memory offchainTokenData =
+ abi.encode(USDCTokenPool.MessageAndAttestation({message: encodedUsdcMessage, attestation: attestation}));
+
+ vm.expectCall(
+ address(s_mockUSDCTransmitter),
+ abi.encodeWithSelector(MockE2EUSDCTransmitter.receiveMessage.selector, encodedUsdcMessage, attestation)
+ );
+
+ vm.startPrank(s_routerAllowedOffRamp);
+ s_usdcTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: OWNER,
+ amount: amount,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ );
+ }
+
+ // Reverts
+ function test_UnlockingUSDCFailed_Revert() public {
+ vm.startPrank(s_routerAllowedOffRamp);
+ s_mockUSDCTransmitter.setShouldSucceed(false);
+
+ uint256 amount = 13255235235;
+
+ USDCMessage memory usdcMessage = USDCMessage({
+ version: 0,
+ sourceDomain: SOURCE_DOMAIN_IDENTIFIER,
+ destinationDomain: DEST_DOMAIN_IDENTIFIER,
+ nonce: 0x060606060606,
+ sender: SOURCE_CHAIN_TOKEN_SENDER,
+ recipient: bytes32(uint256(uint160(address(s_mockUSDC)))),
+ destinationCaller: bytes32(uint256(uint160(address(s_usdcTokenPool)))),
+ messageBody: bytes("")
+ });
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(SOURCE_CHAIN_USDC_POOL),
+ destTokenAddress: abi.encode(address(s_usdcTokenPool)),
+ extraData: abi.encode(
+ USDCTokenPool.SourceTokenDataPayload({nonce: usdcMessage.nonce, sourceDomain: SOURCE_DOMAIN_IDENTIFIER})
+ )
+ });
+
+ bytes memory offchainTokenData = abi.encode(
+ USDCTokenPool.MessageAndAttestation({message: _generateUSDCMessage(usdcMessage), attestation: bytes("")})
+ );
+
+ vm.expectRevert(USDCTokenPool.UnlockingUSDCFailed.selector);
+
+ s_usdcTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: OWNER,
+ amount: amount,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ );
+ }
+
+ function test_TokenMaxCapacityExceeded_Revert() public {
+ uint256 capacity = getInboundRateLimiterConfig().capacity;
+ uint256 amount = 10 * capacity;
+ address recipient = address(1);
+ vm.startPrank(s_routerAllowedOffRamp);
+
+ Internal.SourceTokenData memory sourceTokenData = Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(SOURCE_CHAIN_USDC_POOL),
+ destTokenAddress: abi.encode(address(s_usdcTokenPool)),
+ extraData: abi.encode(USDCTokenPool.SourceTokenDataPayload({nonce: 1, sourceDomain: SOURCE_DOMAIN_IDENTIFIER}))
+ });
+
+ bytes memory offchainTokenData =
+ abi.encode(USDCTokenPool.MessageAndAttestation({message: bytes(""), attestation: bytes("")}));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.TokenMaxCapacityExceeded.selector, capacity, amount, address(s_token))
+ );
+
+ s_usdcTokenPool.releaseOrMint(
+ Pool.ReleaseOrMintInV1({
+ originalSender: abi.encode(OWNER),
+ receiver: recipient,
+ amount: amount,
+ localToken: address(s_token),
+ remoteChainSelector: SOURCE_CHAIN_SELECTOR,
+ sourcePoolAddress: sourceTokenData.sourcePoolAddress,
+ sourcePoolData: sourceTokenData.extraData,
+ offchainTokenData: offchainTokenData
+ })
+ );
+ }
+}
+
+contract USDCTokenPool_supportsInterface is USDCTokenPoolSetup {
+ function test_SupportsInterface_Success() public view {
+ assertTrue(s_usdcTokenPool.supportsInterface(type(IPoolV1).interfaceId));
+ assertTrue(s_usdcTokenPool.supportsInterface(type(IERC165).interfaceId));
+ }
+}
+
+contract USDCTokenPool_setDomains is USDCTokenPoolSetup {
+ mapping(uint64 destChainSelector => USDCTokenPool.Domain domain) private s_chainToDomain;
+
+ // Setting lower fuzz run as 256 runs was causing differing gas results in snapshot.
+ /// forge-config: default.fuzz.runs = 32
+ /// forge-config: ccip.fuzz.runs = 32
+ function test_Fuzz_SetDomains_Success(
+ bytes32[5] calldata allowedCallers,
+ uint32[5] calldata domainIdentifiers,
+ uint64[5] calldata destChainSelectors
+ ) public {
+ uint256 numberOfDomains = allowedCallers.length;
+ USDCTokenPool.DomainUpdate[] memory domainUpdates = new USDCTokenPool.DomainUpdate[](numberOfDomains);
+ for (uint256 i = 0; i < numberOfDomains; ++i) {
+ vm.assume(allowedCallers[i] != bytes32(0) && domainIdentifiers[i] != 0 && destChainSelectors[i] != 0);
+
+ domainUpdates[i] = USDCTokenPool.DomainUpdate({
+ allowedCaller: allowedCallers[i],
+ domainIdentifier: domainIdentifiers[i],
+ destChainSelector: destChainSelectors[i],
+ enabled: true
+ });
+
+ s_chainToDomain[destChainSelectors[i]] =
+ USDCTokenPool.Domain({domainIdentifier: domainIdentifiers[i], allowedCaller: allowedCallers[i], enabled: true});
+ }
+
+ vm.expectEmit();
+ emit USDCTokenPool.DomainsSet(domainUpdates);
+
+ s_usdcTokenPool.setDomains(domainUpdates);
+
+ for (uint256 i = 0; i < numberOfDomains; ++i) {
+ USDCTokenPool.Domain memory expected = s_chainToDomain[destChainSelectors[i]];
+ USDCTokenPool.Domain memory got = s_usdcTokenPool.getDomain(destChainSelectors[i]);
+ assertEq(got.allowedCaller, expected.allowedCaller);
+ assertEq(got.domainIdentifier, expected.domainIdentifier);
+ }
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ USDCTokenPool.DomainUpdate[] memory domainUpdates = new USDCTokenPool.DomainUpdate[](0);
+
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+
+ s_usdcTokenPool.setDomains(domainUpdates);
+ }
+
+ function test_InvalidDomain_Revert() public {
+ bytes32 validCaller = bytes32(uint256(25));
+ // Ensure valid domain works
+ USDCTokenPool.DomainUpdate[] memory domainUpdates = new USDCTokenPool.DomainUpdate[](1);
+ domainUpdates[0] = USDCTokenPool.DomainUpdate({
+ allowedCaller: validCaller,
+ domainIdentifier: 0, // ensures 0 is valid, as this is eth mainnet
+ destChainSelector: 45690,
+ enabled: true
+ });
+
+ s_usdcTokenPool.setDomains(domainUpdates);
+
+ // Make update invalid on allowedCaller
+ domainUpdates[0].allowedCaller = bytes32(0);
+ vm.expectRevert(abi.encodeWithSelector(USDCTokenPool.InvalidDomain.selector, domainUpdates[0]));
+
+ s_usdcTokenPool.setDomains(domainUpdates);
+
+ // Make valid again
+ domainUpdates[0].allowedCaller = validCaller;
+
+ // Make invalid on destChainSelector
+ domainUpdates[0].destChainSelector = 0;
+ vm.expectRevert(abi.encodeWithSelector(USDCTokenPool.InvalidDomain.selector, domainUpdates[0]));
+
+ s_usdcTokenPool.setDomains(domainUpdates);
+ }
+}
+
+contract USDCTokenPool__validateMessage is USDCTokenPoolSetup {
+ function test_Fuzz_ValidateMessage_Success(uint32 sourceDomain, uint64 nonce) public {
+ vm.pauseGasMetering();
+ USDCMessage memory usdcMessage = USDCMessage({
+ version: 0,
+ sourceDomain: sourceDomain,
+ destinationDomain: DEST_DOMAIN_IDENTIFIER,
+ nonce: nonce,
+ sender: SOURCE_CHAIN_TOKEN_SENDER,
+ recipient: bytes32(uint256(299999)),
+ destinationCaller: bytes32(uint256(uint160(address(s_usdcTokenPool)))),
+ messageBody: bytes("")
+ });
+
+ bytes memory encodedUsdcMessage = _generateUSDCMessage(usdcMessage);
+
+ vm.resumeGasMetering();
+ s_usdcTokenPool.validateMessage(
+ encodedUsdcMessage, USDCTokenPool.SourceTokenDataPayload({nonce: nonce, sourceDomain: sourceDomain})
+ );
+ }
+
+ // Reverts
+
+ function test_ValidateInvalidMessage_Revert() public {
+ USDCMessage memory usdcMessage = USDCMessage({
+ version: 0,
+ sourceDomain: 1553252,
+ destinationDomain: DEST_DOMAIN_IDENTIFIER,
+ nonce: 387289284924,
+ sender: SOURCE_CHAIN_TOKEN_SENDER,
+ recipient: bytes32(uint256(92398429395823)),
+ destinationCaller: bytes32(uint256(uint160(address(s_usdcTokenPool)))),
+ messageBody: bytes("")
+ });
+
+ USDCTokenPool.SourceTokenDataPayload memory sourceTokenData =
+ USDCTokenPool.SourceTokenDataPayload({nonce: usdcMessage.nonce, sourceDomain: usdcMessage.sourceDomain});
+
+ bytes memory encodedUsdcMessage = _generateUSDCMessage(usdcMessage);
+
+ s_usdcTokenPool.validateMessage(encodedUsdcMessage, sourceTokenData);
+
+ uint32 expectedSourceDomain = usdcMessage.sourceDomain + 1;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(USDCTokenPool.InvalidSourceDomain.selector, expectedSourceDomain, usdcMessage.sourceDomain)
+ );
+ s_usdcTokenPool.validateMessage(
+ encodedUsdcMessage,
+ USDCTokenPool.SourceTokenDataPayload({nonce: usdcMessage.nonce, sourceDomain: expectedSourceDomain})
+ );
+
+ uint64 expectedNonce = usdcMessage.nonce + 1;
+
+ vm.expectRevert(abi.encodeWithSelector(USDCTokenPool.InvalidNonce.selector, expectedNonce, usdcMessage.nonce));
+ s_usdcTokenPool.validateMessage(
+ encodedUsdcMessage,
+ USDCTokenPool.SourceTokenDataPayload({nonce: expectedNonce, sourceDomain: usdcMessage.sourceDomain})
+ );
+
+ usdcMessage.destinationDomain = DEST_DOMAIN_IDENTIFIER + 1;
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ USDCTokenPool.InvalidDestinationDomain.selector, DEST_DOMAIN_IDENTIFIER, usdcMessage.destinationDomain
+ )
+ );
+
+ s_usdcTokenPool.validateMessage(
+ _generateUSDCMessage(usdcMessage),
+ USDCTokenPool.SourceTokenDataPayload({nonce: usdcMessage.nonce, sourceDomain: usdcMessage.sourceDomain})
+ );
+ usdcMessage.destinationDomain = DEST_DOMAIN_IDENTIFIER;
+
+ uint32 wrongVersion = usdcMessage.version + 1;
+
+ usdcMessage.version = wrongVersion;
+ encodedUsdcMessage = _generateUSDCMessage(usdcMessage);
+
+ vm.expectRevert(abi.encodeWithSelector(USDCTokenPool.InvalidMessageVersion.selector, wrongVersion));
+ s_usdcTokenPool.validateMessage(encodedUsdcMessage, sourceTokenData);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/priceRegistry/PriceRegistry.t.sol b/contracts/src/v0.8/ccip/test/priceRegistry/PriceRegistry.t.sol
new file mode 100644
index 00000000000..c3c22ef2909
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/priceRegistry/PriceRegistry.t.sol
@@ -0,0 +1,2542 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IPriceRegistry} from "../../interfaces/IPriceRegistry.sol";
+import {ITokenAdminRegistry} from "../../interfaces/ITokenAdminRegistry.sol";
+
+import {AuthorizedCallers} from "../../../shared/access/AuthorizedCallers.sol";
+import {BurnMintERC677} from "../../../shared/token/ERC677/BurnMintERC677.sol";
+import {MockV3Aggregator} from "../../../tests/MockV3Aggregator.sol";
+import {PriceRegistry} from "../../PriceRegistry.sol";
+
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {Pool} from "../../libraries/Pool.sol";
+import {USDPriceWith18Decimals} from "../../libraries/USDPriceWith18Decimals.sol";
+import {LockReleaseTokenPool} from "../../pools/LockReleaseTokenPool.sol";
+import {TokenPool} from "../../pools/TokenPool.sol";
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+
+import {TokenSetup} from "../TokenSetup.t.sol";
+import {MaybeRevertingBurnMintTokenPool} from "../helpers/MaybeRevertingBurnMintTokenPool.sol";
+import {PriceRegistryHelper} from "../helpers/PriceRegistryHelper.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+import {Vm} from "forge-std/Vm.sol";
+import {console} from "forge-std/console.sol";
+
+contract PriceRegistrySetup is TokenSetup {
+ uint112 internal constant USD_PER_GAS = 1e6; // 0.001 gwei
+ uint112 internal constant USD_PER_DATA_AVAILABILITY_GAS = 1e9; // 1 gwei
+
+ address internal constant CUSTOM_TOKEN = address(12345);
+ uint224 internal constant CUSTOM_TOKEN_PRICE = 1e17; // $0.1 CUSTOM
+
+ // Encode L1 gas price and L2 gas price into a packed price.
+ // L1 gas price is left-shifted to the higher-order bits.
+ uint224 internal constant PACKED_USD_PER_GAS =
+ (uint224(USD_PER_DATA_AVAILABILITY_GAS) << Internal.GAS_PRICE_BITS) + USD_PER_GAS;
+
+ PriceRegistryHelper internal s_priceRegistry;
+ // Cheat to store the price updates in storage since struct arrays aren't supported.
+ bytes internal s_encodedInitialPriceUpdates;
+ address internal s_weth;
+
+ address[] internal s_sourceFeeTokens;
+ uint224[] internal s_sourceTokenPrices;
+ address[] internal s_destFeeTokens;
+ uint224[] internal s_destTokenPrices;
+
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs[] internal s_priceRegistryPremiumMultiplierWeiPerEthArgs;
+ PriceRegistry.TokenTransferFeeConfigArgs[] internal s_priceRegistryTokenTransferFeeConfigArgs;
+
+ mapping(address token => address dataFeedAddress) internal s_dataFeedByToken;
+
+ function setUp() public virtual override {
+ TokenSetup.setUp();
+
+ _deployTokenPriceDataFeed(s_sourceFeeToken, 8, 1e8);
+
+ s_weth = s_sourceRouter.getWrappedNative();
+ _deployTokenPriceDataFeed(s_weth, 8, 1e11);
+
+ address[] memory sourceFeeTokens = new address[](3);
+ sourceFeeTokens[0] = s_sourceTokens[0];
+ sourceFeeTokens[1] = s_sourceTokens[1];
+ sourceFeeTokens[2] = s_sourceRouter.getWrappedNative();
+ s_sourceFeeTokens = sourceFeeTokens;
+
+ uint224[] memory sourceTokenPrices = new uint224[](3);
+ sourceTokenPrices[0] = 5e18;
+ sourceTokenPrices[1] = 2000e18;
+ sourceTokenPrices[2] = 2000e18;
+ s_sourceTokenPrices = sourceTokenPrices;
+
+ address[] memory destFeeTokens = new address[](3);
+ destFeeTokens[0] = s_destTokens[0];
+ destFeeTokens[1] = s_destTokens[1];
+ destFeeTokens[2] = s_destRouter.getWrappedNative();
+ s_destFeeTokens = destFeeTokens;
+
+ uint224[] memory destTokenPrices = new uint224[](3);
+ destTokenPrices[0] = 5e18;
+ destTokenPrices[1] = 2000e18;
+ destTokenPrices[2] = 2000e18;
+ s_destTokenPrices = destTokenPrices;
+
+ uint256 sourceTokenCount = sourceFeeTokens.length;
+ uint256 destTokenCount = destFeeTokens.length;
+ address[] memory pricedTokens = new address[](sourceTokenCount + destTokenCount);
+ uint224[] memory tokenPrices = new uint224[](sourceTokenCount + destTokenCount);
+ for (uint256 i = 0; i < sourceTokenCount; ++i) {
+ pricedTokens[i] = sourceFeeTokens[i];
+ tokenPrices[i] = sourceTokenPrices[i];
+ }
+ for (uint256 i = 0; i < destTokenCount; ++i) {
+ pricedTokens[i + sourceTokenCount] = destFeeTokens[i];
+ tokenPrices[i + sourceTokenCount] = destTokenPrices[i];
+ }
+
+ Internal.PriceUpdates memory priceUpdates = getPriceUpdatesStruct(pricedTokens, tokenPrices);
+ priceUpdates.gasPriceUpdates =
+ getSingleGasPriceUpdateStruct(DEST_CHAIN_SELECTOR, PACKED_USD_PER_GAS).gasPriceUpdates;
+
+ s_encodedInitialPriceUpdates = abi.encode(priceUpdates);
+
+ address[] memory priceUpdaters = new address[](1);
+ priceUpdaters[0] = OWNER;
+ address[] memory feeTokens = new address[](2);
+ feeTokens[0] = s_sourceTokens[0];
+ feeTokens[1] = s_weth;
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](0);
+
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs.push(
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs({
+ token: s_sourceFeeToken,
+ premiumMultiplierWeiPerEth: 5e17 // 0.5x
+ })
+ );
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs.push(
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs({
+ token: s_sourceRouter.getWrappedNative(),
+ premiumMultiplierWeiPerEth: 2e18 // 2x
+ })
+ );
+
+ s_priceRegistryTokenTransferFeeConfigArgs.push();
+ s_priceRegistryTokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs.push(
+ PriceRegistry.TokenTransferFeeConfigSingleTokenArgs({
+ token: s_sourceFeeToken,
+ tokenTransferFeeConfig: PriceRegistry.TokenTransferFeeConfig({
+ minFeeUSDCents: 1_00, // 1 USD
+ maxFeeUSDCents: 1000_00, // 1,000 USD
+ deciBps: 2_5, // 2.5 bps, or 0.025%
+ destGasOverhead: 40_000,
+ destBytesOverhead: 32,
+ isEnabled: true
+ })
+ })
+ );
+ s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs.push(
+ PriceRegistry.TokenTransferFeeConfigSingleTokenArgs({
+ token: s_sourceRouter.getWrappedNative(),
+ tokenTransferFeeConfig: PriceRegistry.TokenTransferFeeConfig({
+ minFeeUSDCents: 50, // 0.5 USD
+ maxFeeUSDCents: 500_00, // 500 USD
+ deciBps: 5_0, // 5 bps, or 0.05%
+ destGasOverhead: 10_000,
+ destBytesOverhead: 100,
+ isEnabled: true
+ })
+ })
+ );
+ s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs.push(
+ PriceRegistry.TokenTransferFeeConfigSingleTokenArgs({
+ token: CUSTOM_TOKEN,
+ tokenTransferFeeConfig: PriceRegistry.TokenTransferFeeConfig({
+ minFeeUSDCents: 2_00, // 1 USD
+ maxFeeUSDCents: 2000_00, // 1,000 USD
+ deciBps: 10_0, // 10 bps, or 0.1%
+ destGasOverhead: 1,
+ destBytesOverhead: 200,
+ isEnabled: true
+ })
+ })
+ );
+
+ s_priceRegistry = new PriceRegistryHelper(
+ PriceRegistry.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ maxFeeJuelsPerMsg: MAX_MSG_FEES_JUELS,
+ stalenessThreshold: uint32(TWELVE_HOURS)
+ }),
+ priceUpdaters,
+ feeTokens,
+ tokenPriceFeedUpdates,
+ s_priceRegistryTokenTransferFeeConfigArgs,
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs,
+ _generatePriceRegistryDestChainConfigArgs()
+ );
+ s_priceRegistry.updatePrices(priceUpdates);
+ }
+
+ function _deployTokenPriceDataFeed(address token, uint8 decimals, int256 initialAnswer) internal returns (address) {
+ MockV3Aggregator dataFeed = new MockV3Aggregator(decimals, initialAnswer);
+ s_dataFeedByToken[token] = address(dataFeed);
+ return address(dataFeed);
+ }
+
+ function getPriceUpdatesStruct(
+ address[] memory tokens,
+ uint224[] memory prices
+ ) internal pure returns (Internal.PriceUpdates memory) {
+ uint256 length = tokens.length;
+
+ Internal.TokenPriceUpdate[] memory tokenPriceUpdates = new Internal.TokenPriceUpdate[](length);
+ for (uint256 i = 0; i < length; ++i) {
+ tokenPriceUpdates[i] = Internal.TokenPriceUpdate({sourceToken: tokens[i], usdPerToken: prices[i]});
+ }
+ Internal.PriceUpdates memory priceUpdates =
+ Internal.PriceUpdates({tokenPriceUpdates: tokenPriceUpdates, gasPriceUpdates: new Internal.GasPriceUpdate[](0)});
+
+ return priceUpdates;
+ }
+
+ function getEmptyPriceUpdates() internal pure returns (Internal.PriceUpdates memory priceUpdates) {
+ return Internal.PriceUpdates({
+ tokenPriceUpdates: new Internal.TokenPriceUpdate[](0),
+ gasPriceUpdates: new Internal.GasPriceUpdate[](0)
+ });
+ }
+
+ function getSingleTokenPriceFeedUpdateStruct(
+ address sourceToken,
+ address dataFeedAddress,
+ uint8 tokenDecimals
+ ) internal pure returns (PriceRegistry.TokenPriceFeedUpdate memory) {
+ return PriceRegistry.TokenPriceFeedUpdate({
+ sourceToken: sourceToken,
+ feedConfig: IPriceRegistry.TokenPriceFeedConfig({dataFeedAddress: dataFeedAddress, tokenDecimals: tokenDecimals})
+ });
+ }
+
+ function _initialiseSingleTokenPriceFeed() internal returns (address) {
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[0], s_dataFeedByToken[s_sourceTokens[0]], 18);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+ return s_sourceTokens[0];
+ }
+
+ function _generateTokenTransferFeeConfigArgs(
+ uint256 destChainSelectorLength,
+ uint256 tokenLength
+ ) internal pure returns (PriceRegistry.TokenTransferFeeConfigArgs[] memory) {
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ new PriceRegistry.TokenTransferFeeConfigArgs[](destChainSelectorLength);
+ for (uint256 i = 0; i < destChainSelectorLength; ++i) {
+ tokenTransferFeeConfigArgs[i].tokenTransferFeeConfigs =
+ new PriceRegistry.TokenTransferFeeConfigSingleTokenArgs[](tokenLength);
+ }
+ return tokenTransferFeeConfigArgs;
+ }
+
+ function _generatePriceRegistryDestChainConfigArgs()
+ internal
+ pure
+ returns (PriceRegistry.DestChainConfigArgs[] memory)
+ {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigs = new PriceRegistry.DestChainConfigArgs[](1);
+ destChainConfigs[0] = PriceRegistry.DestChainConfigArgs({
+ destChainSelector: DEST_CHAIN_SELECTOR,
+ destChainConfig: PriceRegistry.DestChainConfig({
+ isEnabled: true,
+ maxNumberOfTokensPerMsg: MAX_TOKENS_LENGTH,
+ destGasOverhead: DEST_GAS_OVERHEAD,
+ destGasPerPayloadByte: DEST_GAS_PER_PAYLOAD_BYTE,
+ destDataAvailabilityOverheadGas: DEST_DATA_AVAILABILITY_OVERHEAD_GAS,
+ destGasPerDataAvailabilityByte: DEST_GAS_PER_DATA_AVAILABILITY_BYTE,
+ destDataAvailabilityMultiplierBps: DEST_GAS_DATA_AVAILABILITY_MULTIPLIER_BPS,
+ maxDataBytes: MAX_DATA_SIZE,
+ maxPerMsgGasLimit: MAX_GAS_LIMIT,
+ defaultTokenFeeUSDCents: DEFAULT_TOKEN_FEE_USD_CENTS,
+ defaultTokenDestGasOverhead: DEFAULT_TOKEN_DEST_GAS_OVERHEAD,
+ defaultTokenDestBytesOverhead: DEFAULT_TOKEN_BYTES_OVERHEAD,
+ defaultTxGasLimit: GAS_LIMIT,
+ gasMultiplierWeiPerEth: 5e17,
+ networkFeeUSDCents: 1_00,
+ enforceOutOfOrder: false,
+ chainFamilySelector: Internal.CHAIN_FAMILY_SELECTOR_EVM
+ })
+ });
+ return destChainConfigs;
+ }
+
+ function _assertTokenPriceFeedConfigEquality(
+ IPriceRegistry.TokenPriceFeedConfig memory config1,
+ IPriceRegistry.TokenPriceFeedConfig memory config2
+ ) internal pure virtual {
+ assertEq(config1.dataFeedAddress, config2.dataFeedAddress);
+ assertEq(config1.tokenDecimals, config2.tokenDecimals);
+ }
+
+ function _assertTokenPriceFeedConfigUnconfigured(IPriceRegistry.TokenPriceFeedConfig memory config)
+ internal
+ pure
+ virtual
+ {
+ _assertTokenPriceFeedConfigEquality(
+ config, IPriceRegistry.TokenPriceFeedConfig({dataFeedAddress: address(0), tokenDecimals: 0})
+ );
+ }
+
+ function _assertTokenTransferFeeConfigEqual(
+ PriceRegistry.TokenTransferFeeConfig memory a,
+ PriceRegistry.TokenTransferFeeConfig memory b
+ ) internal pure {
+ assertEq(a.minFeeUSDCents, b.minFeeUSDCents);
+ assertEq(a.maxFeeUSDCents, b.maxFeeUSDCents);
+ assertEq(a.deciBps, b.deciBps);
+ assertEq(a.destGasOverhead, b.destGasOverhead);
+ assertEq(a.destBytesOverhead, b.destBytesOverhead);
+ assertEq(a.isEnabled, b.isEnabled);
+ }
+
+ function _assertPriceRegistryStaticConfigsEqual(
+ PriceRegistry.StaticConfig memory a,
+ PriceRegistry.StaticConfig memory b
+ ) internal pure {
+ assertEq(a.linkToken, b.linkToken);
+ assertEq(a.maxFeeJuelsPerMsg, b.maxFeeJuelsPerMsg);
+ }
+
+ function _assertPriceRegistryDestChainConfigsEqual(
+ PriceRegistry.DestChainConfig memory a,
+ PriceRegistry.DestChainConfig memory b
+ ) internal pure {
+ assertEq(a.isEnabled, b.isEnabled);
+ assertEq(a.maxNumberOfTokensPerMsg, b.maxNumberOfTokensPerMsg);
+ assertEq(a.maxDataBytes, b.maxDataBytes);
+ assertEq(a.maxPerMsgGasLimit, b.maxPerMsgGasLimit);
+ assertEq(a.destGasOverhead, b.destGasOverhead);
+ assertEq(a.destGasPerPayloadByte, b.destGasPerPayloadByte);
+ assertEq(a.destDataAvailabilityOverheadGas, b.destDataAvailabilityOverheadGas);
+ assertEq(a.destGasPerDataAvailabilityByte, b.destGasPerDataAvailabilityByte);
+ assertEq(a.destDataAvailabilityMultiplierBps, b.destDataAvailabilityMultiplierBps);
+ assertEq(a.defaultTokenFeeUSDCents, b.defaultTokenFeeUSDCents);
+ assertEq(a.defaultTokenDestGasOverhead, b.defaultTokenDestGasOverhead);
+ assertEq(a.defaultTokenDestBytesOverhead, b.defaultTokenDestBytesOverhead);
+ assertEq(a.defaultTxGasLimit, b.defaultTxGasLimit);
+ }
+}
+
+contract PriceRegistryFeeSetup is PriceRegistrySetup {
+ uint224 internal s_feeTokenPrice;
+ uint224 internal s_wrappedTokenPrice;
+ uint224 internal s_customTokenPrice;
+
+ address internal s_selfServeTokenDefaultPricing = makeAddr("self-serve-token-default-pricing");
+
+ address internal s_destTokenPool = makeAddr("destTokenPool");
+ address internal s_destToken = makeAddr("destToken");
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ s_feeTokenPrice = s_sourceTokenPrices[0];
+ s_wrappedTokenPrice = s_sourceTokenPrices[2];
+ s_customTokenPrice = CUSTOM_TOKEN_PRICE;
+
+ s_priceRegistry.updatePrices(getSingleTokenPriceUpdateStruct(CUSTOM_TOKEN, CUSTOM_TOKEN_PRICE));
+ }
+
+ function _generateEmptyMessage() public view returns (Client.EVM2AnyMessage memory) {
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _generateSingleTokenMessage(
+ address token,
+ uint256 amount
+ ) public view returns (Client.EVM2AnyMessage memory) {
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: token, amount: amount});
+
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _messageToEvent(
+ Client.EVM2AnyMessage memory message,
+ uint64 sourceChainSelector,
+ uint64 destChainSelector,
+ uint64 seqNum,
+ uint64 nonce,
+ uint256 feeTokenAmount,
+ address originalSender,
+ bytes32 metadataHash,
+ TokenAdminRegistry tokenAdminRegistry
+ ) internal view returns (Internal.EVM2AnyRampMessage memory) {
+ Client.EVMExtraArgsV2 memory extraArgs =
+ s_priceRegistry.parseEVMExtraArgsFromBytes(message.extraArgs, destChainSelector);
+
+ Internal.EVM2AnyRampMessage memory messageEvent = Internal.EVM2AnyRampMessage({
+ header: Internal.RampMessageHeader({
+ messageId: "",
+ sourceChainSelector: sourceChainSelector,
+ destChainSelector: destChainSelector,
+ sequenceNumber: seqNum,
+ nonce: extraArgs.allowOutOfOrderExecution ? 0 : nonce
+ }),
+ sender: originalSender,
+ data: message.data,
+ receiver: message.receiver,
+ extraArgs: Client._argsToBytes(extraArgs),
+ feeToken: message.feeToken,
+ feeTokenAmount: feeTokenAmount,
+ tokenAmounts: new Internal.RampTokenAmount[](message.tokenAmounts.length)
+ });
+
+ for (uint256 i = 0; i < message.tokenAmounts.length; ++i) {
+ messageEvent.tokenAmounts[i] = _getSourceTokenData(message.tokenAmounts[i], tokenAdminRegistry);
+ }
+
+ messageEvent.header.messageId = Internal._hash(messageEvent, metadataHash);
+ return messageEvent;
+ }
+
+ function _getSourceTokenData(
+ Client.EVMTokenAmount memory tokenAmount,
+ TokenAdminRegistry tokenAdminRegistry
+ ) internal view returns (Internal.RampTokenAmount memory) {
+ address destToken = s_destTokenBySourceToken[tokenAmount.token];
+
+ return Internal.RampTokenAmount({
+ sourcePoolAddress: abi.encode(tokenAdminRegistry.getTokenConfig(tokenAmount.token).tokenPool),
+ destTokenAddress: abi.encode(destToken),
+ extraData: "",
+ amount: tokenAmount.amount
+ });
+ }
+
+ function calcUSDValueFromTokenAmount(uint224 tokenPrice, uint256 tokenAmount) internal pure returns (uint256) {
+ return (tokenPrice * tokenAmount) / 1e18;
+ }
+
+ function applyBpsRatio(uint256 tokenAmount, uint16 ratio) internal pure returns (uint256) {
+ return (tokenAmount * ratio) / 1e5;
+ }
+
+ function configUSDCentToWei(uint256 usdCent) internal pure returns (uint256) {
+ return usdCent * 1e16;
+ }
+}
+
+contract PriceRegistry_constructor is PriceRegistrySetup {
+ function test_Setup_Success() public virtual {
+ address[] memory priceUpdaters = new address[](2);
+ priceUpdaters[0] = STRANGER;
+ priceUpdaters[1] = OWNER;
+ address[] memory feeTokens = new address[](2);
+ feeTokens[0] = s_sourceTokens[0];
+ feeTokens[1] = s_sourceTokens[1];
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](2);
+ tokenPriceFeedUpdates[0] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[0], s_dataFeedByToken[s_sourceTokens[0]], 18);
+ tokenPriceFeedUpdates[1] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[1], s_dataFeedByToken[s_sourceTokens[1]], 6);
+
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+
+ PriceRegistry.StaticConfig memory staticConfig = PriceRegistry.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ maxFeeJuelsPerMsg: MAX_MSG_FEES_JUELS,
+ stalenessThreshold: uint32(TWELVE_HOURS)
+ });
+ s_priceRegistry = new PriceRegistryHelper(
+ staticConfig,
+ priceUpdaters,
+ feeTokens,
+ tokenPriceFeedUpdates,
+ s_priceRegistryTokenTransferFeeConfigArgs,
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs,
+ destChainConfigArgs
+ );
+
+ _assertPriceRegistryStaticConfigsEqual(s_priceRegistry.getStaticConfig(), staticConfig);
+ assertEq(feeTokens, s_priceRegistry.getFeeTokens());
+ assertEq(priceUpdaters, s_priceRegistry.getAllAuthorizedCallers());
+ assertEq(s_priceRegistry.typeAndVersion(), "PriceRegistry 1.6.0-dev");
+
+ _assertTokenPriceFeedConfigEquality(
+ tokenPriceFeedUpdates[0].feedConfig, s_priceRegistry.getTokenPriceFeedConfig(s_sourceTokens[0])
+ );
+
+ _assertTokenPriceFeedConfigEquality(
+ tokenPriceFeedUpdates[1].feedConfig, s_priceRegistry.getTokenPriceFeedConfig(s_sourceTokens[1])
+ );
+
+ assertEq(
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs[0].premiumMultiplierWeiPerEth,
+ s_priceRegistry.getPremiumMultiplierWeiPerEth(s_priceRegistryPremiumMultiplierWeiPerEthArgs[0].token)
+ );
+
+ assertEq(
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs[1].premiumMultiplierWeiPerEth,
+ s_priceRegistry.getPremiumMultiplierWeiPerEth(s_priceRegistryPremiumMultiplierWeiPerEthArgs[1].token)
+ );
+
+ PriceRegistry.TokenTransferFeeConfigArgs memory tokenTransferFeeConfigArg =
+ s_priceRegistryTokenTransferFeeConfigArgs[0];
+ for (uint256 i = 0; i < tokenTransferFeeConfigArg.tokenTransferFeeConfigs.length; ++i) {
+ PriceRegistry.TokenTransferFeeConfigSingleTokenArgs memory tokenFeeArgs =
+ s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[i];
+
+ _assertTokenTransferFeeConfigEqual(
+ tokenFeeArgs.tokenTransferFeeConfig,
+ s_priceRegistry.getTokenTransferFeeConfig(tokenTransferFeeConfigArg.destChainSelector, tokenFeeArgs.token)
+ );
+ }
+
+ for (uint256 i = 0; i < destChainConfigArgs.length; ++i) {
+ PriceRegistry.DestChainConfig memory expectedConfig = destChainConfigArgs[i].destChainConfig;
+ uint64 destChainSelector = destChainConfigArgs[i].destChainSelector;
+
+ _assertPriceRegistryDestChainConfigsEqual(expectedConfig, s_priceRegistry.getDestChainConfig(destChainSelector));
+ }
+ }
+
+ function test_InvalidStalenessThreshold_Revert() public {
+ PriceRegistry.StaticConfig memory staticConfig = PriceRegistry.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ maxFeeJuelsPerMsg: MAX_MSG_FEES_JUELS,
+ stalenessThreshold: 0
+ });
+
+ vm.expectRevert(PriceRegistry.InvalidStaticConfig.selector);
+
+ s_priceRegistry = new PriceRegistryHelper(
+ staticConfig,
+ new address[](0),
+ new address[](0),
+ new PriceRegistry.TokenPriceFeedUpdate[](0),
+ s_priceRegistryTokenTransferFeeConfigArgs,
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs,
+ new PriceRegistry.DestChainConfigArgs[](0)
+ );
+ }
+
+ function test_InvalidLinkTokenEqZeroAddress_Revert() public {
+ PriceRegistry.StaticConfig memory staticConfig = PriceRegistry.StaticConfig({
+ linkToken: address(0),
+ maxFeeJuelsPerMsg: MAX_MSG_FEES_JUELS,
+ stalenessThreshold: uint32(TWELVE_HOURS)
+ });
+
+ vm.expectRevert(PriceRegistry.InvalidStaticConfig.selector);
+
+ s_priceRegistry = new PriceRegistryHelper(
+ staticConfig,
+ new address[](0),
+ new address[](0),
+ new PriceRegistry.TokenPriceFeedUpdate[](0),
+ s_priceRegistryTokenTransferFeeConfigArgs,
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs,
+ new PriceRegistry.DestChainConfigArgs[](0)
+ );
+ }
+
+ function test_InvalidMaxFeeJuelsPerMsg_Revert() public {
+ PriceRegistry.StaticConfig memory staticConfig = PriceRegistry.StaticConfig({
+ linkToken: s_sourceTokens[0],
+ maxFeeJuelsPerMsg: 0,
+ stalenessThreshold: uint32(TWELVE_HOURS)
+ });
+
+ vm.expectRevert(PriceRegistry.InvalidStaticConfig.selector);
+
+ s_priceRegistry = new PriceRegistryHelper(
+ staticConfig,
+ new address[](0),
+ new address[](0),
+ new PriceRegistry.TokenPriceFeedUpdate[](0),
+ s_priceRegistryTokenTransferFeeConfigArgs,
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs,
+ new PriceRegistry.DestChainConfigArgs[](0)
+ );
+ }
+}
+
+contract PriceRegistry_getTokenPrices is PriceRegistrySetup {
+ function test_GetTokenPrices_Success() public view {
+ Internal.PriceUpdates memory priceUpdates = abi.decode(s_encodedInitialPriceUpdates, (Internal.PriceUpdates));
+
+ address[] memory tokens = new address[](3);
+ tokens[0] = s_sourceTokens[0];
+ tokens[1] = s_sourceTokens[1];
+ tokens[2] = s_weth;
+
+ Internal.TimestampedPackedUint224[] memory tokenPrices = s_priceRegistry.getTokenPrices(tokens);
+
+ assertEq(tokenPrices.length, 3);
+ assertEq(tokenPrices[0].value, priceUpdates.tokenPriceUpdates[0].usdPerToken);
+ assertEq(tokenPrices[1].value, priceUpdates.tokenPriceUpdates[1].usdPerToken);
+ assertEq(tokenPrices[2].value, priceUpdates.tokenPriceUpdates[2].usdPerToken);
+ }
+}
+
+contract PriceRegistry_getTokenPrice is PriceRegistrySetup {
+ function test_GetTokenPriceFromFeed_Success() public {
+ uint256 originalTimestampValue = block.timestamp;
+
+ // Below staleness threshold
+ vm.warp(originalTimestampValue + 1 hours);
+
+ address sourceToken = _initialiseSingleTokenPriceFeed();
+ Internal.TimestampedPackedUint224 memory tokenPriceAnswer = s_priceRegistry.getTokenPrice(sourceToken);
+
+ // Price answer is 1e8 (18 decimal token) - unit is (1e18 * 1e18 / 1e18) -> expected 1e18
+ assertEq(tokenPriceAnswer.value, uint224(1e18));
+ assertEq(tokenPriceAnswer.timestamp, uint32(block.timestamp));
+ }
+}
+
+contract PriceRegistry_getValidatedTokenPrice is PriceRegistrySetup {
+ function test_GetValidatedTokenPrice_Success() public view {
+ Internal.PriceUpdates memory priceUpdates = abi.decode(s_encodedInitialPriceUpdates, (Internal.PriceUpdates));
+ address token = priceUpdates.tokenPriceUpdates[0].sourceToken;
+
+ uint224 tokenPrice = s_priceRegistry.getValidatedTokenPrice(token);
+
+ assertEq(priceUpdates.tokenPriceUpdates[0].usdPerToken, tokenPrice);
+ }
+
+ function test_GetValidatedTokenPriceFromFeed_Success() public {
+ uint256 originalTimestampValue = block.timestamp;
+
+ // Right below staleness threshold
+ vm.warp(originalTimestampValue + TWELVE_HOURS);
+
+ address sourceToken = _initialiseSingleTokenPriceFeed();
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(sourceToken);
+
+ // Price answer is 1e8 (18 decimal token) - unit is (1e18 * 1e18 / 1e18) -> expected 1e18
+ assertEq(tokenPriceAnswer, uint224(1e18));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedOverStalenessPeriod_Success() public {
+ uint256 originalTimestampValue = block.timestamp;
+
+ // Right above staleness threshold
+ vm.warp(originalTimestampValue + TWELVE_HOURS + 1);
+
+ address sourceToken = _initialiseSingleTokenPriceFeed();
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(sourceToken);
+
+ // Price answer is 1e8 (18 decimal token) - unit is (1e18 * 1e18 / 1e18) -> expected 1e18
+ assertEq(tokenPriceAnswer, uint224(1e18));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedMaxInt224Value_Success() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 18);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 18, int256(uint256(type(uint224).max)));
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 18);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+
+ // Price answer is: uint224.MAX_VALUE * (10 ** (36 - 18 - 18))
+ assertEq(tokenPriceAnswer, uint224(type(uint224).max));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedErc20Below18Decimals_Success() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 6);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 8, 1e8);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 6);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+
+ // Price answer is 1e8 (6 decimal token) - unit is (1e18 * 1e18 / 1e6) -> expected 1e30
+ assertEq(tokenPriceAnswer, uint224(1e30));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedErc20Above18Decimals_Success() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 24);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 8, 1e8);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 24);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+
+ // Price answer is 1e8 (6 decimal token) - unit is (1e18 * 1e18 / 1e24) -> expected 1e12
+ assertEq(tokenPriceAnswer, uint224(1e12));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedFeedAt18Decimals_Success() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 18);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 18, 1e18);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 18);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+
+ // Price answer is 1e8 (6 decimal token) - unit is (1e18 * 1e18 / 1e18) -> expected 1e18
+ assertEq(tokenPriceAnswer, uint224(1e18));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedFeedAt0Decimals_Success() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 0);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 0, 1e31);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 0);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+
+ // Price answer is 1e31 (0 decimal token) - unit is (1e18 * 1e18 / 1e0) -> expected 1e36
+ assertEq(tokenPriceAnswer, uint224(1e67));
+ }
+
+ function test_GetValidatedTokenPriceFromFeedFlippedDecimals_Success() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 20);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 20, 1e18);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 20);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ uint224 tokenPriceAnswer = s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+
+ // Price answer is 1e8 (6 decimal token) - unit is (1e18 * 1e18 / 1e20) -> expected 1e14
+ assertEq(tokenPriceAnswer, uint224(1e14));
+ }
+
+ function test_StaleFeeToken_Success() public {
+ vm.warp(block.timestamp + TWELVE_HOURS + 1);
+
+ Internal.PriceUpdates memory priceUpdates = abi.decode(s_encodedInitialPriceUpdates, (Internal.PriceUpdates));
+ address token = priceUpdates.tokenPriceUpdates[0].sourceToken;
+
+ uint224 tokenPrice = s_priceRegistry.getValidatedTokenPrice(token);
+
+ assertEq(priceUpdates.tokenPriceUpdates[0].usdPerToken, tokenPrice);
+ }
+
+ // Reverts
+
+ function test_OverflowFeedPrice_Revert() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 18);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 18, int256(uint256(type(uint224).max) + 1));
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 18);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ vm.expectRevert(PriceRegistry.DataFeedValueOutOfUint224Range.selector);
+ s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+ }
+
+ function test_UnderflowFeedPrice_Revert() public {
+ address tokenAddress = _deploySourceToken("testToken", 0, 18);
+ address feedAddress = _deployTokenPriceDataFeed(tokenAddress, 18, -1);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] = getSingleTokenPriceFeedUpdateStruct(tokenAddress, feedAddress, 18);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ vm.expectRevert(PriceRegistry.DataFeedValueOutOfUint224Range.selector);
+ s_priceRegistry.getValidatedTokenPrice(tokenAddress);
+ }
+
+ function test_TokenNotSupported_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.TokenNotSupported.selector, DUMMY_CONTRACT_ADDRESS));
+ s_priceRegistry.getValidatedTokenPrice(DUMMY_CONTRACT_ADDRESS);
+ }
+
+ function test_TokenNotSupportedFeed_Revert() public {
+ address sourceToken = _initialiseSingleTokenPriceFeed();
+ MockV3Aggregator(s_dataFeedByToken[sourceToken]).updateAnswer(0);
+
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.TokenNotSupported.selector, sourceToken));
+ s_priceRegistry.getValidatedTokenPrice(sourceToken);
+ }
+}
+
+contract PriceRegistry_applyFeeTokensUpdates is PriceRegistrySetup {
+ function test_ApplyFeeTokensUpdates_Success() public {
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = s_sourceTokens[1];
+
+ vm.expectEmit();
+ emit PriceRegistry.FeeTokenAdded(feeTokens[0]);
+
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+ assertEq(s_priceRegistry.getFeeTokens().length, 3);
+ assertEq(s_priceRegistry.getFeeTokens()[2], feeTokens[0]);
+
+ // add same feeToken is no-op
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+ assertEq(s_priceRegistry.getFeeTokens().length, 3);
+ assertEq(s_priceRegistry.getFeeTokens()[2], feeTokens[0]);
+
+ vm.expectEmit();
+ emit PriceRegistry.FeeTokenRemoved(feeTokens[0]);
+
+ s_priceRegistry.applyFeeTokensUpdates(new address[](0), feeTokens);
+ assertEq(s_priceRegistry.getFeeTokens().length, 2);
+
+ // removing already removed feeToken is no-op
+ s_priceRegistry.applyFeeTokensUpdates(new address[](0), feeTokens);
+ assertEq(s_priceRegistry.getFeeTokens().length, 2);
+ }
+
+ function test_OnlyCallableByOwner_Revert() public {
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = STRANGER;
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+ }
+}
+
+contract PriceRegistry_updatePrices is PriceRegistrySetup {
+ function test_OnlyTokenPrice_Success() public {
+ Internal.PriceUpdates memory update = Internal.PriceUpdates({
+ tokenPriceUpdates: new Internal.TokenPriceUpdate[](1),
+ gasPriceUpdates: new Internal.GasPriceUpdate[](0)
+ });
+ update.tokenPriceUpdates[0] = Internal.TokenPriceUpdate({sourceToken: s_sourceTokens[0], usdPerToken: 4e18});
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(
+ update.tokenPriceUpdates[0].sourceToken, update.tokenPriceUpdates[0].usdPerToken, block.timestamp
+ );
+
+ s_priceRegistry.updatePrices(update);
+
+ assertEq(s_priceRegistry.getTokenPrice(s_sourceTokens[0]).value, update.tokenPriceUpdates[0].usdPerToken);
+ }
+
+ function test_OnlyGasPrice_Success() public {
+ Internal.PriceUpdates memory update = Internal.PriceUpdates({
+ tokenPriceUpdates: new Internal.TokenPriceUpdate[](0),
+ gasPriceUpdates: new Internal.GasPriceUpdate[](1)
+ });
+ update.gasPriceUpdates[0] =
+ Internal.GasPriceUpdate({destChainSelector: DEST_CHAIN_SELECTOR, usdPerUnitGas: 2000e18});
+
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerUnitGasUpdated(
+ update.gasPriceUpdates[0].destChainSelector, update.gasPriceUpdates[0].usdPerUnitGas, block.timestamp
+ );
+
+ s_priceRegistry.updatePrices(update);
+
+ assertEq(
+ s_priceRegistry.getDestinationChainGasPrice(DEST_CHAIN_SELECTOR).value, update.gasPriceUpdates[0].usdPerUnitGas
+ );
+ }
+
+ function test_UpdateMultiplePrices_Success() public {
+ Internal.TokenPriceUpdate[] memory tokenPriceUpdates = new Internal.TokenPriceUpdate[](3);
+ tokenPriceUpdates[0] = Internal.TokenPriceUpdate({sourceToken: s_sourceTokens[0], usdPerToken: 4e18});
+ tokenPriceUpdates[1] = Internal.TokenPriceUpdate({sourceToken: s_sourceTokens[1], usdPerToken: 1800e18});
+ tokenPriceUpdates[2] = Internal.TokenPriceUpdate({sourceToken: address(12345), usdPerToken: 1e18});
+
+ Internal.GasPriceUpdate[] memory gasPriceUpdates = new Internal.GasPriceUpdate[](3);
+ gasPriceUpdates[0] = Internal.GasPriceUpdate({destChainSelector: DEST_CHAIN_SELECTOR, usdPerUnitGas: 2e6});
+ gasPriceUpdates[1] = Internal.GasPriceUpdate({destChainSelector: SOURCE_CHAIN_SELECTOR, usdPerUnitGas: 2000e18});
+ gasPriceUpdates[2] = Internal.GasPriceUpdate({destChainSelector: 12345, usdPerUnitGas: 1e18});
+
+ Internal.PriceUpdates memory update =
+ Internal.PriceUpdates({tokenPriceUpdates: tokenPriceUpdates, gasPriceUpdates: gasPriceUpdates});
+
+ for (uint256 i = 0; i < tokenPriceUpdates.length; ++i) {
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(
+ update.tokenPriceUpdates[i].sourceToken, update.tokenPriceUpdates[i].usdPerToken, block.timestamp
+ );
+ }
+ for (uint256 i = 0; i < gasPriceUpdates.length; ++i) {
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerUnitGasUpdated(
+ update.gasPriceUpdates[i].destChainSelector, update.gasPriceUpdates[i].usdPerUnitGas, block.timestamp
+ );
+ }
+
+ s_priceRegistry.updatePrices(update);
+
+ for (uint256 i = 0; i < tokenPriceUpdates.length; ++i) {
+ assertEq(
+ s_priceRegistry.getTokenPrice(update.tokenPriceUpdates[i].sourceToken).value, tokenPriceUpdates[i].usdPerToken
+ );
+ }
+ for (uint256 i = 0; i < gasPriceUpdates.length; ++i) {
+ assertEq(
+ s_priceRegistry.getDestinationChainGasPrice(update.gasPriceUpdates[i].destChainSelector).value,
+ gasPriceUpdates[i].usdPerUnitGas
+ );
+ }
+ }
+
+ function test_UpdatableByAuthorizedCaller_Success() public {
+ Internal.PriceUpdates memory priceUpdates = Internal.PriceUpdates({
+ tokenPriceUpdates: new Internal.TokenPriceUpdate[](1),
+ gasPriceUpdates: new Internal.GasPriceUpdate[](0)
+ });
+ priceUpdates.tokenPriceUpdates[0] = Internal.TokenPriceUpdate({sourceToken: s_sourceTokens[0], usdPerToken: 4e18});
+
+ // Revert when caller is not authorized
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(AuthorizedCallers.UnauthorizedCaller.selector, STRANGER));
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ address[] memory priceUpdaters = new address[](1);
+ priceUpdaters[0] = STRANGER;
+ vm.startPrank(OWNER);
+ s_priceRegistry.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: priceUpdaters, removedCallers: new address[](0)})
+ );
+
+ // Stranger is now an authorized caller to update prices
+ vm.expectEmit();
+ emit PriceRegistry.UsdPerTokenUpdated(
+ priceUpdates.tokenPriceUpdates[0].sourceToken, priceUpdates.tokenPriceUpdates[0].usdPerToken, block.timestamp
+ );
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ assertEq(s_priceRegistry.getTokenPrice(s_sourceTokens[0]).value, priceUpdates.tokenPriceUpdates[0].usdPerToken);
+
+ vm.startPrank(OWNER);
+ s_priceRegistry.applyAuthorizedCallerUpdates(
+ AuthorizedCallers.AuthorizedCallerArgs({addedCallers: new address[](0), removedCallers: priceUpdaters})
+ );
+
+ // Revert when authorized caller is removed
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(AuthorizedCallers.UnauthorizedCaller.selector, STRANGER));
+ s_priceRegistry.updatePrices(priceUpdates);
+ }
+
+ // Reverts
+
+ function test_OnlyCallableByUpdater_Revert() public {
+ Internal.PriceUpdates memory priceUpdates = Internal.PriceUpdates({
+ tokenPriceUpdates: new Internal.TokenPriceUpdate[](0),
+ gasPriceUpdates: new Internal.GasPriceUpdate[](0)
+ });
+
+ vm.startPrank(STRANGER);
+ vm.expectRevert(abi.encodeWithSelector(AuthorizedCallers.UnauthorizedCaller.selector, STRANGER));
+ s_priceRegistry.updatePrices(priceUpdates);
+ }
+}
+
+contract PriceRegistry_convertTokenAmount is PriceRegistrySetup {
+ function test_ConvertTokenAmount_Success() public view {
+ Internal.PriceUpdates memory initialPriceUpdates = abi.decode(s_encodedInitialPriceUpdates, (Internal.PriceUpdates));
+ uint256 amount = 3e16;
+ uint256 conversionRate = (uint256(initialPriceUpdates.tokenPriceUpdates[2].usdPerToken) * 1e18)
+ / uint256(initialPriceUpdates.tokenPriceUpdates[0].usdPerToken);
+ uint256 expected = (amount * conversionRate) / 1e18;
+ assertEq(s_priceRegistry.convertTokenAmount(s_weth, amount, s_sourceTokens[0]), expected);
+ }
+
+ function test_Fuzz_ConvertTokenAmount_Success(
+ uint256 feeTokenAmount,
+ uint224 usdPerFeeToken,
+ uint160 usdPerLinkToken,
+ uint224 usdPerUnitGas
+ ) public {
+ vm.assume(usdPerFeeToken > 0);
+ vm.assume(usdPerLinkToken > 0);
+ // We bound the max fees to be at most uint96.max link.
+ feeTokenAmount = bound(feeTokenAmount, 0, (uint256(type(uint96).max) * usdPerLinkToken) / usdPerFeeToken);
+
+ address feeToken = address(1);
+ address linkToken = address(2);
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = feeToken;
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+
+ Internal.TokenPriceUpdate[] memory tokenPriceUpdates = new Internal.TokenPriceUpdate[](2);
+ tokenPriceUpdates[0] = Internal.TokenPriceUpdate({sourceToken: feeToken, usdPerToken: usdPerFeeToken});
+ tokenPriceUpdates[1] = Internal.TokenPriceUpdate({sourceToken: linkToken, usdPerToken: usdPerLinkToken});
+
+ Internal.GasPriceUpdate[] memory gasPriceUpdates = new Internal.GasPriceUpdate[](1);
+ gasPriceUpdates[0] = Internal.GasPriceUpdate({destChainSelector: DEST_CHAIN_SELECTOR, usdPerUnitGas: usdPerUnitGas});
+
+ Internal.PriceUpdates memory priceUpdates =
+ Internal.PriceUpdates({tokenPriceUpdates: tokenPriceUpdates, gasPriceUpdates: gasPriceUpdates});
+
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ uint256 linkFee = s_priceRegistry.convertTokenAmount(feeToken, feeTokenAmount, linkToken);
+ assertEq(linkFee, (feeTokenAmount * usdPerFeeToken) / usdPerLinkToken);
+ }
+
+ // Reverts
+
+ function test_LinkTokenNotSupported_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.TokenNotSupported.selector, DUMMY_CONTRACT_ADDRESS));
+ s_priceRegistry.convertTokenAmount(DUMMY_CONTRACT_ADDRESS, 3e16, s_sourceTokens[0]);
+
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.TokenNotSupported.selector, DUMMY_CONTRACT_ADDRESS));
+ s_priceRegistry.convertTokenAmount(s_sourceTokens[0], 3e16, DUMMY_CONTRACT_ADDRESS);
+ }
+}
+
+contract PriceRegistry_getTokenAndGasPrices is PriceRegistrySetup {
+ function test_GetFeeTokenAndGasPrices_Success() public view {
+ (uint224 feeTokenPrice, uint224 gasPrice) =
+ s_priceRegistry.getTokenAndGasPrices(s_sourceFeeToken, DEST_CHAIN_SELECTOR);
+
+ Internal.PriceUpdates memory priceUpdates = abi.decode(s_encodedInitialPriceUpdates, (Internal.PriceUpdates));
+
+ assertEq(feeTokenPrice, s_sourceTokenPrices[0]);
+ assertEq(gasPrice, priceUpdates.gasPriceUpdates[0].usdPerUnitGas);
+ }
+
+ function test_ZeroGasPrice_Success() public {
+ uint64 zeroGasDestChainSelector = 345678;
+ Internal.GasPriceUpdate[] memory gasPriceUpdates = new Internal.GasPriceUpdate[](1);
+ gasPriceUpdates[0] = Internal.GasPriceUpdate({destChainSelector: zeroGasDestChainSelector, usdPerUnitGas: 0});
+
+ Internal.PriceUpdates memory priceUpdates =
+ Internal.PriceUpdates({tokenPriceUpdates: new Internal.TokenPriceUpdate[](0), gasPriceUpdates: gasPriceUpdates});
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ (, uint224 gasPrice) = s_priceRegistry.getTokenAndGasPrices(s_sourceFeeToken, zeroGasDestChainSelector);
+
+ assertEq(gasPrice, priceUpdates.gasPriceUpdates[0].usdPerUnitGas);
+ }
+
+ function test_UnsupportedChain_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.ChainNotSupported.selector, DEST_CHAIN_SELECTOR + 1));
+ s_priceRegistry.getTokenAndGasPrices(s_sourceTokens[0], DEST_CHAIN_SELECTOR + 1);
+ }
+
+ function test_StaleGasPrice_Revert() public {
+ uint256 diff = TWELVE_HOURS + 1;
+ vm.warp(block.timestamp + diff);
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.StaleGasPrice.selector, DEST_CHAIN_SELECTOR, TWELVE_HOURS, diff)
+ );
+ s_priceRegistry.getTokenAndGasPrices(s_sourceTokens[0], DEST_CHAIN_SELECTOR);
+ }
+}
+
+contract PriceRegistry_updateTokenPriceFeeds is PriceRegistrySetup {
+ function test_ZeroFeeds_Success() public {
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](0);
+ vm.recordLogs();
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ // Verify no log emissions
+ assertEq(logEntries.length, 0);
+ }
+
+ function test_SingleFeedUpdate_Success() public {
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[0], s_dataFeedByToken[s_sourceTokens[0]], 18);
+
+ _assertTokenPriceFeedConfigUnconfigured(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[0].sourceToken)
+ );
+
+ vm.expectEmit();
+ emit PriceRegistry.PriceFeedPerTokenUpdated(
+ tokenPriceFeedUpdates[0].sourceToken, tokenPriceFeedUpdates[0].feedConfig
+ );
+
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ _assertTokenPriceFeedConfigEquality(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[0].sourceToken), tokenPriceFeedUpdates[0].feedConfig
+ );
+ }
+
+ function test_MultipleFeedUpdate_Success() public {
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](2);
+
+ for (uint256 i = 0; i < 2; ++i) {
+ tokenPriceFeedUpdates[i] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[i], s_dataFeedByToken[s_sourceTokens[i]], 18);
+
+ _assertTokenPriceFeedConfigUnconfigured(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[i].sourceToken)
+ );
+
+ vm.expectEmit();
+ emit PriceRegistry.PriceFeedPerTokenUpdated(
+ tokenPriceFeedUpdates[i].sourceToken, tokenPriceFeedUpdates[i].feedConfig
+ );
+ }
+
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ _assertTokenPriceFeedConfigEquality(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[0].sourceToken), tokenPriceFeedUpdates[0].feedConfig
+ );
+ _assertTokenPriceFeedConfigEquality(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[1].sourceToken), tokenPriceFeedUpdates[1].feedConfig
+ );
+ }
+
+ function test_FeedUnset_Success() public {
+ Internal.TimestampedPackedUint224 memory priceQueryInitial = s_priceRegistry.getTokenPrice(s_sourceTokens[0]);
+ assertFalse(priceQueryInitial.value == 0);
+ assertFalse(priceQueryInitial.timestamp == 0);
+
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[0], s_dataFeedByToken[s_sourceTokens[0]], 18);
+
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+ _assertTokenPriceFeedConfigEquality(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[0].sourceToken), tokenPriceFeedUpdates[0].feedConfig
+ );
+
+ tokenPriceFeedUpdates[0].feedConfig.dataFeedAddress = address(0);
+ vm.expectEmit();
+ emit PriceRegistry.PriceFeedPerTokenUpdated(
+ tokenPriceFeedUpdates[0].sourceToken, tokenPriceFeedUpdates[0].feedConfig
+ );
+
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+ _assertTokenPriceFeedConfigEquality(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[0].sourceToken), tokenPriceFeedUpdates[0].feedConfig
+ );
+
+ // Price data should remain after a feed has been set->unset
+ Internal.TimestampedPackedUint224 memory priceQueryPostUnsetFeed = s_priceRegistry.getTokenPrice(s_sourceTokens[0]);
+ assertEq(priceQueryPostUnsetFeed.value, priceQueryInitial.value);
+ assertEq(priceQueryPostUnsetFeed.timestamp, priceQueryInitial.timestamp);
+ }
+
+ function test_FeedNotUpdated() public {
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[0], s_dataFeedByToken[s_sourceTokens[0]], 18);
+
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+
+ _assertTokenPriceFeedConfigEquality(
+ s_priceRegistry.getTokenPriceFeedConfig(tokenPriceFeedUpdates[0].sourceToken), tokenPriceFeedUpdates[0].feedConfig
+ );
+ }
+
+ // Reverts
+
+ function test_FeedUpdatedByNonOwner_Revert() public {
+ PriceRegistry.TokenPriceFeedUpdate[] memory tokenPriceFeedUpdates = new PriceRegistry.TokenPriceFeedUpdate[](1);
+ tokenPriceFeedUpdates[0] =
+ getSingleTokenPriceFeedUpdateStruct(s_sourceTokens[0], s_dataFeedByToken[s_sourceTokens[0]], 18);
+
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+
+ s_priceRegistry.updateTokenPriceFeeds(tokenPriceFeedUpdates);
+ }
+}
+
+contract PriceRegistry_applyDestChainConfigUpdates is PriceRegistrySetup {
+ function test_Fuzz_applyDestChainConfigUpdates_Success(PriceRegistry.DestChainConfigArgs memory destChainConfigArgs)
+ public
+ {
+ vm.assume(destChainConfigArgs.destChainSelector != 0);
+ vm.assume(destChainConfigArgs.destChainConfig.maxPerMsgGasLimit != 0);
+ destChainConfigArgs.destChainConfig.defaultTxGasLimit = uint32(
+ bound(
+ destChainConfigArgs.destChainConfig.defaultTxGasLimit, 1, destChainConfigArgs.destChainConfig.maxPerMsgGasLimit
+ )
+ );
+ destChainConfigArgs.destChainConfig.defaultTokenDestBytesOverhead = uint32(
+ bound(
+ destChainConfigArgs.destChainConfig.defaultTokenDestBytesOverhead,
+ Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES,
+ type(uint32).max
+ )
+ );
+ destChainConfigArgs.destChainConfig.chainFamilySelector = Internal.CHAIN_FAMILY_SELECTOR_EVM;
+
+ bool isNewChain = destChainConfigArgs.destChainSelector != DEST_CHAIN_SELECTOR;
+
+ PriceRegistry.DestChainConfigArgs[] memory newDestChainConfigArgs = new PriceRegistry.DestChainConfigArgs[](1);
+ newDestChainConfigArgs[0] = destChainConfigArgs;
+
+ if (isNewChain) {
+ vm.expectEmit();
+ emit PriceRegistry.DestChainAdded(destChainConfigArgs.destChainSelector, destChainConfigArgs.destChainConfig);
+ } else {
+ vm.expectEmit();
+ emit PriceRegistry.DestChainConfigUpdated(
+ destChainConfigArgs.destChainSelector, destChainConfigArgs.destChainConfig
+ );
+ }
+
+ s_priceRegistry.applyDestChainConfigUpdates(newDestChainConfigArgs);
+
+ _assertPriceRegistryDestChainConfigsEqual(
+ destChainConfigArgs.destChainConfig, s_priceRegistry.getDestChainConfig(destChainConfigArgs.destChainSelector)
+ );
+ }
+
+ function test_applyDestChainConfigUpdates_Success() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = new PriceRegistry.DestChainConfigArgs[](2);
+ destChainConfigArgs[0] = _generatePriceRegistryDestChainConfigArgs()[0];
+ destChainConfigArgs[0].destChainConfig.isEnabled = false;
+ destChainConfigArgs[1] = _generatePriceRegistryDestChainConfigArgs()[0];
+ destChainConfigArgs[1].destChainSelector = DEST_CHAIN_SELECTOR + 1;
+
+ vm.expectEmit();
+ emit PriceRegistry.DestChainConfigUpdated(DEST_CHAIN_SELECTOR, destChainConfigArgs[0].destChainConfig);
+ vm.expectEmit();
+ emit PriceRegistry.DestChainAdded(DEST_CHAIN_SELECTOR + 1, destChainConfigArgs[1].destChainConfig);
+
+ vm.recordLogs();
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ PriceRegistry.DestChainConfig memory gotDestChainConfig0 = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+ PriceRegistry.DestChainConfig memory gotDestChainConfig1 =
+ s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR + 1);
+
+ assertEq(vm.getRecordedLogs().length, 2);
+ _assertPriceRegistryDestChainConfigsEqual(destChainConfigArgs[0].destChainConfig, gotDestChainConfig0);
+ _assertPriceRegistryDestChainConfigsEqual(destChainConfigArgs[1].destChainConfig, gotDestChainConfig1);
+ }
+
+ function test_applyDestChainConfigUpdatesZeroIntput_Success() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = new PriceRegistry.DestChainConfigArgs[](0);
+
+ vm.recordLogs();
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ // Reverts
+
+ function test_applyDestChainConfigUpdatesDefaultTxGasLimitEqZero_Revert() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ PriceRegistry.DestChainConfigArgs memory destChainConfigArg = destChainConfigArgs[0];
+
+ destChainConfigArg.destChainConfig.defaultTxGasLimit = 0;
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.InvalidDestChainConfig.selector, destChainConfigArg.destChainSelector)
+ );
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ }
+
+ function test_applyDestChainConfigUpdatesDefaultTxGasLimitGtMaxPerMessageGasLimit_Revert() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ PriceRegistry.DestChainConfigArgs memory destChainConfigArg = destChainConfigArgs[0];
+
+ // Allow setting to the max value
+ destChainConfigArg.destChainConfig.defaultTxGasLimit = destChainConfigArg.destChainConfig.maxPerMsgGasLimit;
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ // Revert when exceeding max value
+ destChainConfigArg.destChainConfig.defaultTxGasLimit = destChainConfigArg.destChainConfig.maxPerMsgGasLimit + 1;
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.InvalidDestChainConfig.selector, destChainConfigArg.destChainSelector)
+ );
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ }
+
+ function test_InvalidDestChainConfigDestChainSelectorEqZero_Revert() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ PriceRegistry.DestChainConfigArgs memory destChainConfigArg = destChainConfigArgs[0];
+
+ destChainConfigArg.destChainSelector = 0;
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.InvalidDestChainConfig.selector, destChainConfigArg.destChainSelector)
+ );
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ }
+
+ function test_InvalidDestBytesOverhead_Revert() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ PriceRegistry.DestChainConfigArgs memory destChainConfigArg = destChainConfigArgs[0];
+
+ destChainConfigArg.destChainConfig.defaultTokenDestBytesOverhead = uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES - 1);
+
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.InvalidDestChainConfig.selector, DEST_CHAIN_SELECTOR));
+
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ }
+
+ function test_InvalidChainFamilySelector_Revert() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ PriceRegistry.DestChainConfigArgs memory destChainConfigArg = destChainConfigArgs[0];
+
+ destChainConfigArg.destChainConfig.chainFamilySelector = bytes4(uint32(1));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.InvalidDestChainConfig.selector, destChainConfigArg.destChainSelector)
+ );
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ }
+}
+
+contract PriceRegistry_getDataAvailabilityCost is PriceRegistrySetup {
+ function test_EmptyMessageCalculatesDataAvailabilityCost_Success() public {
+ uint256 dataAvailabilityCostUSD =
+ s_priceRegistry.getDataAvailabilityCost(DEST_CHAIN_SELECTOR, USD_PER_DATA_AVAILABILITY_GAS, 0, 0, 0);
+
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+
+ uint256 dataAvailabilityGas = destChainConfig.destDataAvailabilityOverheadGas
+ + destChainConfig.destGasPerDataAvailabilityByte * Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES;
+ uint256 expectedDataAvailabilityCostUSD =
+ USD_PER_DATA_AVAILABILITY_GAS * dataAvailabilityGas * destChainConfig.destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD);
+
+ // Test that the cost is destnation chain specific
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ destChainConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR + 1;
+ destChainConfigArgs[0].destChainConfig.destDataAvailabilityOverheadGas =
+ destChainConfig.destDataAvailabilityOverheadGas * 2;
+ destChainConfigArgs[0].destChainConfig.destGasPerDataAvailabilityByte =
+ destChainConfig.destGasPerDataAvailabilityByte * 2;
+ destChainConfigArgs[0].destChainConfig.destDataAvailabilityMultiplierBps =
+ destChainConfig.destDataAvailabilityMultiplierBps * 2;
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR + 1);
+ uint256 dataAvailabilityCostUSD2 =
+ s_priceRegistry.getDataAvailabilityCost(DEST_CHAIN_SELECTOR + 1, USD_PER_DATA_AVAILABILITY_GAS, 0, 0, 0);
+ dataAvailabilityGas = destChainConfig.destDataAvailabilityOverheadGas
+ + destChainConfig.destGasPerDataAvailabilityByte * Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES;
+ expectedDataAvailabilityCostUSD =
+ USD_PER_DATA_AVAILABILITY_GAS * dataAvailabilityGas * destChainConfig.destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD2);
+ assertFalse(dataAvailabilityCostUSD == dataAvailabilityCostUSD2);
+ }
+
+ function test_SimpleMessageCalculatesDataAvailabilityCost_Success() public view {
+ uint256 dataAvailabilityCostUSD =
+ s_priceRegistry.getDataAvailabilityCost(DEST_CHAIN_SELECTOR, USD_PER_DATA_AVAILABILITY_GAS, 100, 5, 50);
+
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+
+ uint256 dataAvailabilityLengthBytes =
+ Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES + 100 + (5 * Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES_PER_TOKEN) + 50;
+ uint256 dataAvailabilityGas = destChainConfig.destDataAvailabilityOverheadGas
+ + destChainConfig.destGasPerDataAvailabilityByte * dataAvailabilityLengthBytes;
+ uint256 expectedDataAvailabilityCostUSD =
+ USD_PER_DATA_AVAILABILITY_GAS * dataAvailabilityGas * destChainConfig.destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD);
+ }
+
+ function test_SimpleMessageCalculatesDataAvailabilityCostUnsupportedDestChainSelector_Success() public view {
+ uint256 dataAvailabilityCostUSD =
+ s_priceRegistry.getDataAvailabilityCost(0, USD_PER_DATA_AVAILABILITY_GAS, 100, 5, 50);
+
+ assertEq(dataAvailabilityCostUSD, 0);
+ }
+
+ function test_Fuzz_ZeroDataAvailabilityGasPriceAlwaysCalculatesZeroDataAvailabilityCost_Success(
+ uint64 messageDataLength,
+ uint32 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) public view {
+ uint256 dataAvailabilityCostUSD = s_priceRegistry.getDataAvailabilityCost(
+ DEST_CHAIN_SELECTOR, 0, messageDataLength, numberOfTokens, tokenTransferBytesOverhead
+ );
+
+ assertEq(0, dataAvailabilityCostUSD);
+ }
+
+ function test_Fuzz_CalculateDataAvailabilityCost_Success(
+ uint64 destChainSelector,
+ uint32 destDataAvailabilityOverheadGas,
+ uint16 destGasPerDataAvailabilityByte,
+ uint16 destDataAvailabilityMultiplierBps,
+ uint112 dataAvailabilityGasPrice,
+ uint64 messageDataLength,
+ uint32 numberOfTokens,
+ uint32 tokenTransferBytesOverhead
+ ) public {
+ vm.assume(destChainSelector != 0);
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = new PriceRegistry.DestChainConfigArgs[](1);
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(destChainSelector);
+ destChainConfigArgs[0] =
+ PriceRegistry.DestChainConfigArgs({destChainSelector: destChainSelector, destChainConfig: destChainConfig});
+ destChainConfigArgs[0].destChainConfig.destDataAvailabilityOverheadGas = destDataAvailabilityOverheadGas;
+ destChainConfigArgs[0].destChainConfig.destGasPerDataAvailabilityByte = destGasPerDataAvailabilityByte;
+ destChainConfigArgs[0].destChainConfig.destDataAvailabilityMultiplierBps = destDataAvailabilityMultiplierBps;
+ destChainConfigArgs[0].destChainConfig.defaultTxGasLimit = GAS_LIMIT;
+ destChainConfigArgs[0].destChainConfig.maxPerMsgGasLimit = GAS_LIMIT;
+ destChainConfigArgs[0].destChainConfig.chainFamilySelector = Internal.CHAIN_FAMILY_SELECTOR_EVM;
+ destChainConfigArgs[0].destChainConfig.defaultTokenDestBytesOverhead = DEFAULT_TOKEN_BYTES_OVERHEAD;
+
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ uint256 dataAvailabilityCostUSD = s_priceRegistry.getDataAvailabilityCost(
+ destChainConfigArgs[0].destChainSelector,
+ dataAvailabilityGasPrice,
+ messageDataLength,
+ numberOfTokens,
+ tokenTransferBytesOverhead
+ );
+
+ uint256 dataAvailabilityLengthBytes = Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES + messageDataLength
+ + (numberOfTokens * Internal.ANY_2_EVM_MESSAGE_FIXED_BYTES_PER_TOKEN) + tokenTransferBytesOverhead;
+
+ uint256 dataAvailabilityGas =
+ destDataAvailabilityOverheadGas + destGasPerDataAvailabilityByte * dataAvailabilityLengthBytes;
+ uint256 expectedDataAvailabilityCostUSD =
+ dataAvailabilityGasPrice * dataAvailabilityGas * destDataAvailabilityMultiplierBps * 1e14;
+
+ assertEq(expectedDataAvailabilityCostUSD, dataAvailabilityCostUSD);
+ }
+}
+
+contract PriceRegistry_applyPremiumMultiplierWeiPerEthUpdates is PriceRegistrySetup {
+ function test_Fuzz_applyPremiumMultiplierWeiPerEthUpdates_Success(
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs memory premiumMultiplierWeiPerEthArg
+ ) public {
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs =
+ new PriceRegistry.PremiumMultiplierWeiPerEthArgs[](1);
+ premiumMultiplierWeiPerEthArgs[0] = premiumMultiplierWeiPerEthArg;
+
+ vm.expectEmit();
+ emit PriceRegistry.PremiumMultiplierWeiPerEthUpdated(
+ premiumMultiplierWeiPerEthArg.token, premiumMultiplierWeiPerEthArg.premiumMultiplierWeiPerEth
+ );
+
+ s_priceRegistry.applyPremiumMultiplierWeiPerEthUpdates(premiumMultiplierWeiPerEthArgs);
+
+ assertEq(
+ premiumMultiplierWeiPerEthArg.premiumMultiplierWeiPerEth,
+ s_priceRegistry.getPremiumMultiplierWeiPerEth(premiumMultiplierWeiPerEthArg.token)
+ );
+ }
+
+ function test_applyPremiumMultiplierWeiPerEthUpdatesSingleToken_Success() public {
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs =
+ new PriceRegistry.PremiumMultiplierWeiPerEthArgs[](1);
+ premiumMultiplierWeiPerEthArgs[0] = s_priceRegistryPremiumMultiplierWeiPerEthArgs[0];
+ premiumMultiplierWeiPerEthArgs[0].token = vm.addr(1);
+
+ vm.expectEmit();
+ emit PriceRegistry.PremiumMultiplierWeiPerEthUpdated(
+ vm.addr(1), premiumMultiplierWeiPerEthArgs[0].premiumMultiplierWeiPerEth
+ );
+
+ s_priceRegistry.applyPremiumMultiplierWeiPerEthUpdates(premiumMultiplierWeiPerEthArgs);
+
+ assertEq(
+ s_priceRegistryPremiumMultiplierWeiPerEthArgs[0].premiumMultiplierWeiPerEth,
+ s_priceRegistry.getPremiumMultiplierWeiPerEth(vm.addr(1))
+ );
+ }
+
+ function test_applyPremiumMultiplierWeiPerEthUpdatesMultipleTokens_Success() public {
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs =
+ new PriceRegistry.PremiumMultiplierWeiPerEthArgs[](2);
+ premiumMultiplierWeiPerEthArgs[0] = s_priceRegistryPremiumMultiplierWeiPerEthArgs[0];
+ premiumMultiplierWeiPerEthArgs[0].token = vm.addr(1);
+ premiumMultiplierWeiPerEthArgs[1].token = vm.addr(2);
+
+ vm.expectEmit();
+ emit PriceRegistry.PremiumMultiplierWeiPerEthUpdated(
+ vm.addr(1), premiumMultiplierWeiPerEthArgs[0].premiumMultiplierWeiPerEth
+ );
+ vm.expectEmit();
+ emit PriceRegistry.PremiumMultiplierWeiPerEthUpdated(
+ vm.addr(2), premiumMultiplierWeiPerEthArgs[1].premiumMultiplierWeiPerEth
+ );
+
+ s_priceRegistry.applyPremiumMultiplierWeiPerEthUpdates(premiumMultiplierWeiPerEthArgs);
+
+ assertEq(
+ premiumMultiplierWeiPerEthArgs[0].premiumMultiplierWeiPerEth,
+ s_priceRegistry.getPremiumMultiplierWeiPerEth(vm.addr(1))
+ );
+ assertEq(
+ premiumMultiplierWeiPerEthArgs[1].premiumMultiplierWeiPerEth,
+ s_priceRegistry.getPremiumMultiplierWeiPerEth(vm.addr(2))
+ );
+ }
+
+ function test_applyPremiumMultiplierWeiPerEthUpdatesZeroInput() public {
+ vm.recordLogs();
+ s_priceRegistry.applyPremiumMultiplierWeiPerEthUpdates(new PriceRegistry.PremiumMultiplierWeiPerEthArgs[](0));
+
+ assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ // Reverts
+
+ function test_OnlyCallableByOwnerOrAdmin_Revert() public {
+ PriceRegistry.PremiumMultiplierWeiPerEthArgs[] memory premiumMultiplierWeiPerEthArgs;
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert("Only callable by owner");
+
+ s_priceRegistry.applyPremiumMultiplierWeiPerEthUpdates(premiumMultiplierWeiPerEthArgs);
+ }
+}
+
+contract PriceRegistry_applyTokenTransferFeeConfigUpdates is PriceRegistrySetup {
+ function test_Fuzz_ApplyTokenTransferFeeConfig_Success(
+ PriceRegistry.TokenTransferFeeConfig[2] memory tokenTransferFeeConfigs
+ ) public {
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ _generateTokenTransferFeeConfigArgs(2, 2);
+ tokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ tokenTransferFeeConfigArgs[1].destChainSelector = DEST_CHAIN_SELECTOR + 1;
+
+ for (uint256 i = 0; i < tokenTransferFeeConfigArgs.length; ++i) {
+ for (uint256 j = 0; j < tokenTransferFeeConfigs.length; ++j) {
+ tokenTransferFeeConfigs[j].destBytesOverhead = uint32(
+ bound(tokenTransferFeeConfigs[j].destBytesOverhead, Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, type(uint32).max)
+ );
+ address feeToken = s_sourceTokens[j];
+ tokenTransferFeeConfigArgs[i].tokenTransferFeeConfigs[j].token = feeToken;
+ tokenTransferFeeConfigArgs[i].tokenTransferFeeConfigs[j].tokenTransferFeeConfig = tokenTransferFeeConfigs[j];
+
+ vm.expectEmit();
+ emit PriceRegistry.TokenTransferFeeConfigUpdated(
+ tokenTransferFeeConfigArgs[i].destChainSelector, feeToken, tokenTransferFeeConfigs[j]
+ );
+ }
+ }
+
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ tokenTransferFeeConfigArgs, new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+
+ for (uint256 i = 0; i < tokenTransferFeeConfigs.length; ++i) {
+ _assertTokenTransferFeeConfigEqual(
+ tokenTransferFeeConfigs[i],
+ s_priceRegistry.getTokenTransferFeeConfig(
+ tokenTransferFeeConfigArgs[0].destChainSelector,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[i].token
+ )
+ );
+ }
+ }
+
+ function test_ApplyTokenTransferFeeConfig_Success() public {
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ _generateTokenTransferFeeConfigArgs(1, 2);
+ tokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token = address(5);
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig = PriceRegistry
+ .TokenTransferFeeConfig({
+ minFeeUSDCents: 6,
+ maxFeeUSDCents: 7,
+ deciBps: 8,
+ destGasOverhead: 9,
+ destBytesOverhead: 312,
+ isEnabled: true
+ });
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].token = address(11);
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].tokenTransferFeeConfig = PriceRegistry
+ .TokenTransferFeeConfig({
+ minFeeUSDCents: 12,
+ maxFeeUSDCents: 13,
+ deciBps: 14,
+ destGasOverhead: 15,
+ destBytesOverhead: 394,
+ isEnabled: true
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.TokenTransferFeeConfigUpdated(
+ tokenTransferFeeConfigArgs[0].destChainSelector,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig
+ );
+ vm.expectEmit();
+ emit PriceRegistry.TokenTransferFeeConfigUpdated(
+ tokenTransferFeeConfigArgs[0].destChainSelector,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].token,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].tokenTransferFeeConfig
+ );
+
+ PriceRegistry.TokenTransferFeeConfigRemoveArgs[] memory tokensToRemove =
+ new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0);
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(tokenTransferFeeConfigArgs, tokensToRemove);
+
+ PriceRegistry.TokenTransferFeeConfig memory config0 = s_priceRegistry.getTokenTransferFeeConfig(
+ tokenTransferFeeConfigArgs[0].destChainSelector, tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token
+ );
+ PriceRegistry.TokenTransferFeeConfig memory config1 = s_priceRegistry.getTokenTransferFeeConfig(
+ tokenTransferFeeConfigArgs[0].destChainSelector, tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].token
+ );
+
+ _assertTokenTransferFeeConfigEqual(
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig, config0
+ );
+ _assertTokenTransferFeeConfigEqual(
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].tokenTransferFeeConfig, config1
+ );
+
+ // Remove only the first token and validate only the first token is removed
+ tokensToRemove = new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](1);
+ tokensToRemove[0] = PriceRegistry.TokenTransferFeeConfigRemoveArgs({
+ destChainSelector: tokenTransferFeeConfigArgs[0].destChainSelector,
+ token: tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token
+ });
+
+ vm.expectEmit();
+ emit PriceRegistry.TokenTransferFeeConfigDeleted(
+ tokenTransferFeeConfigArgs[0].destChainSelector, tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token
+ );
+
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ new PriceRegistry.TokenTransferFeeConfigArgs[](0), tokensToRemove
+ );
+
+ config0 = s_priceRegistry.getTokenTransferFeeConfig(
+ tokenTransferFeeConfigArgs[0].destChainSelector, tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token
+ );
+ config1 = s_priceRegistry.getTokenTransferFeeConfig(
+ tokenTransferFeeConfigArgs[0].destChainSelector, tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].token
+ );
+
+ PriceRegistry.TokenTransferFeeConfig memory emptyConfig;
+
+ _assertTokenTransferFeeConfigEqual(emptyConfig, config0);
+ _assertTokenTransferFeeConfigEqual(
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].tokenTransferFeeConfig, config1
+ );
+ }
+
+ function test_ApplyTokenTransferFeeZeroInput() public {
+ vm.recordLogs();
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ new PriceRegistry.TokenTransferFeeConfigArgs[](0), new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+
+ assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ // Reverts
+
+ function test_OnlyCallableByOwnerOrAdmin_Revert() public {
+ vm.startPrank(STRANGER);
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs;
+
+ vm.expectRevert("Only callable by owner");
+
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ tokenTransferFeeConfigArgs, new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+ }
+
+ function test_InvalidDestBytesOverhead_Revert() public {
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ _generateTokenTransferFeeConfigArgs(1, 1);
+ tokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token = address(5);
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig = PriceRegistry
+ .TokenTransferFeeConfig({
+ minFeeUSDCents: 6,
+ maxFeeUSDCents: 7,
+ deciBps: 8,
+ destGasOverhead: 9,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES - 1),
+ isEnabled: true
+ });
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ PriceRegistry.InvalidDestBytesOverhead.selector,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token,
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig.destBytesOverhead
+ )
+ );
+
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ tokenTransferFeeConfigArgs, new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+ }
+}
+
+contract PriceRegistry_getTokenTransferCost is PriceRegistryFeeSetup {
+ using USDPriceWith18Decimals for uint224;
+
+ function test_NoTokenTransferChargesZeroFee_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(0, feeUSDWei);
+ assertEq(0, destGasOverhead);
+ assertEq(0, destBytesOverhead);
+ }
+
+ function test_getTokenTransferCost_selfServeUsesDefaults_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_selfServeTokenDefaultPricing, 1000);
+
+ // Get config to assert it isn't set
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ assertFalse(transferFeeConfig.isEnabled);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ // Assert that the default values are used
+ assertEq(uint256(DEFAULT_TOKEN_FEE_USD_CENTS) * 1e16, feeUSDWei);
+ assertEq(DEFAULT_TOKEN_DEST_GAS_OVERHEAD, destGasOverhead);
+ assertEq(DEFAULT_TOKEN_BYTES_OVERHEAD, destBytesOverhead);
+ }
+
+ function test_SmallTokenTransferChargesMinFeeAndGas_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 1000);
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(configUSDCentToWei(transferFeeConfig.minFeeUSDCents), feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_ZeroAmountTokenTransferChargesMinFeeAndGas_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 0);
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(configUSDCentToWei(transferFeeConfig.minFeeUSDCents), feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_LargeTokenTransferChargesMaxFeeAndGas_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 1e36);
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ assertEq(configUSDCentToWei(transferFeeConfig.maxFeeUSDCents), feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_FeeTokenBpsFee_Success() public view {
+ uint256 tokenAmount = 10000e18;
+
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, tokenAmount);
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ uint256 usdWei = calcUSDValueFromTokenAmount(s_feeTokenPrice, tokenAmount);
+ uint256 bpsUSDWei = applyBpsRatio(
+ usdWei, s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig.deciBps
+ );
+
+ assertEq(bpsUSDWei, feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_WETHTokenBpsFee_Success() public view {
+ uint256 tokenAmount = 100e18;
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](1),
+ feeToken: s_sourceRouter.getWrappedNative(),
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceRouter.getWrappedNative(), amount: tokenAmount});
+
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) = s_priceRegistry.getTokenTransferCost(
+ DEST_CHAIN_SELECTOR, message.feeToken, s_wrappedTokenPrice, message.tokenAmounts
+ );
+
+ uint256 usdWei = calcUSDValueFromTokenAmount(s_wrappedTokenPrice, tokenAmount);
+ uint256 bpsUSDWei = applyBpsRatio(
+ usdWei, s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[1].tokenTransferFeeConfig.deciBps
+ );
+
+ assertEq(bpsUSDWei, feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_CustomTokenBpsFee_Success() public view {
+ uint256 tokenAmount = 200000e18;
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](1),
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: CUSTOM_TOKEN, amount: tokenAmount});
+
+ PriceRegistry.TokenTransferFeeConfig memory transferFeeConfig =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token);
+
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ uint256 usdWei = calcUSDValueFromTokenAmount(s_customTokenPrice, tokenAmount);
+ uint256 bpsUSDWei = applyBpsRatio(
+ usdWei, s_priceRegistryTokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[2].tokenTransferFeeConfig.deciBps
+ );
+
+ assertEq(bpsUSDWei, feeUSDWei);
+ assertEq(transferFeeConfig.destGasOverhead, destGasOverhead);
+ assertEq(transferFeeConfig.destBytesOverhead, destBytesOverhead);
+ }
+
+ function test_ZeroFeeConfigChargesMinFee_Success() public {
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ _generateTokenTransferFeeConfigArgs(1, 1);
+ tokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token = s_sourceFeeToken;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig = PriceRegistry
+ .TokenTransferFeeConfig({
+ minFeeUSDCents: 1,
+ maxFeeUSDCents: 0,
+ deciBps: 0,
+ destGasOverhead: 0,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES),
+ isEnabled: true
+ });
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ tokenTransferFeeConfigArgs, new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, 1e36);
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, message.feeToken, s_feeTokenPrice, message.tokenAmounts);
+
+ // if token charges 0 bps, it should cost minFee to transfer
+ assertEq(
+ configUSDCentToWei(tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig.minFeeUSDCents),
+ feeUSDWei
+ );
+ assertEq(0, destGasOverhead);
+ assertEq(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES, destBytesOverhead);
+ }
+
+ function test_Fuzz_TokenTransferFeeDuplicateTokens_Success(uint256 transfers, uint256 amount) public view {
+ // It shouldn't be possible to pay materially lower fees by splitting up the transfers.
+ // Note it is possible to pay higher fees since the minimum fees are added.
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+ transfers = bound(transfers, 1, destChainConfig.maxNumberOfTokensPerMsg);
+ // Cap amount to avoid overflow
+ amount = bound(amount, 0, 1e36);
+ Client.EVMTokenAmount[] memory multiple = new Client.EVMTokenAmount[](transfers);
+ for (uint256 i = 0; i < transfers; ++i) {
+ multiple[i] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: amount});
+ }
+ Client.EVMTokenAmount[] memory single = new Client.EVMTokenAmount[](1);
+ single[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: amount * transfers});
+
+ address feeToken = s_sourceRouter.getWrappedNative();
+
+ (uint256 feeSingleUSDWei, uint32 gasOverheadSingle, uint32 bytesOverheadSingle) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, feeToken, s_wrappedTokenPrice, single);
+ (uint256 feeMultipleUSDWei, uint32 gasOverheadMultiple, uint32 bytesOverheadMultiple) =
+ s_priceRegistry.getTokenTransferCost(DEST_CHAIN_SELECTOR, feeToken, s_wrappedTokenPrice, multiple);
+
+ // Note that there can be a rounding error once per split.
+ assertGe(feeMultipleUSDWei, (feeSingleUSDWei - destChainConfig.maxNumberOfTokensPerMsg));
+ assertEq(gasOverheadMultiple, gasOverheadSingle * transfers);
+ assertEq(bytesOverheadMultiple, bytesOverheadSingle * transfers);
+ }
+
+ function test_MixedTokenTransferFee_Success() public view {
+ address[3] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative(), CUSTOM_TOKEN];
+ uint224[3] memory tokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice, s_customTokenPrice];
+ PriceRegistry.TokenTransferFeeConfig[3] memory tokenTransferFeeConfigs = [
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, testTokens[0]),
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, testTokens[1]),
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, testTokens[2])
+ ];
+
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](3),
+ feeToken: s_sourceRouter.getWrappedNative(),
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ uint256 expectedTotalGas = 0;
+ uint256 expectedTotalBytes = 0;
+
+ // Start with small token transfers, total bps fee is lower than min token transfer fee
+ for (uint256 i = 0; i < testTokens.length; ++i) {
+ message.tokenAmounts[i] = Client.EVMTokenAmount({token: testTokens[i], amount: 1e14});
+ expectedTotalGas += s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, testTokens[i]).destGasOverhead;
+ expectedTotalBytes +=
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, testTokens[i]).destBytesOverhead;
+ }
+ (uint256 feeUSDWei, uint32 destGasOverhead, uint32 destBytesOverhead) = s_priceRegistry.getTokenTransferCost(
+ DEST_CHAIN_SELECTOR, message.feeToken, s_wrappedTokenPrice, message.tokenAmounts
+ );
+
+ uint256 expectedFeeUSDWei = 0;
+ for (uint256 i = 0; i < testTokens.length; ++i) {
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[i].minFeeUSDCents);
+ }
+
+ assertEq(expectedFeeUSDWei, feeUSDWei);
+ assertEq(expectedTotalGas, destGasOverhead);
+ assertEq(expectedTotalBytes, destBytesOverhead);
+
+ // Set 1st token transfer to a meaningful amount so its bps fee is now between min and max fee
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: testTokens[0], amount: 10000e18});
+
+ (feeUSDWei, destGasOverhead, destBytesOverhead) = s_priceRegistry.getTokenTransferCost(
+ DEST_CHAIN_SELECTOR, message.feeToken, s_wrappedTokenPrice, message.tokenAmounts
+ );
+ expectedFeeUSDWei = applyBpsRatio(
+ calcUSDValueFromTokenAmount(tokenPrices[0], message.tokenAmounts[0].amount), tokenTransferFeeConfigs[0].deciBps
+ );
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[1].minFeeUSDCents);
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[2].minFeeUSDCents);
+
+ assertEq(expectedFeeUSDWei, feeUSDWei);
+ assertEq(expectedTotalGas, destGasOverhead);
+ assertEq(expectedTotalBytes, destBytesOverhead);
+
+ // Set 2nd token transfer to a large amount that is higher than maxFeeUSD
+ message.tokenAmounts[1] = Client.EVMTokenAmount({token: testTokens[1], amount: 1e36});
+
+ (feeUSDWei, destGasOverhead, destBytesOverhead) = s_priceRegistry.getTokenTransferCost(
+ DEST_CHAIN_SELECTOR, message.feeToken, s_wrappedTokenPrice, message.tokenAmounts
+ );
+ expectedFeeUSDWei = applyBpsRatio(
+ calcUSDValueFromTokenAmount(tokenPrices[0], message.tokenAmounts[0].amount), tokenTransferFeeConfigs[0].deciBps
+ );
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[1].maxFeeUSDCents);
+ expectedFeeUSDWei += configUSDCentToWei(tokenTransferFeeConfigs[2].minFeeUSDCents);
+
+ assertEq(expectedFeeUSDWei, feeUSDWei);
+ assertEq(expectedTotalGas, destGasOverhead);
+ assertEq(expectedTotalBytes, destBytesOverhead);
+ }
+}
+
+contract PriceRegistry_getValidatedFee is PriceRegistryFeeSetup {
+ using USDPriceWith18Decimals for uint224;
+
+ function test_EmptyMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = testTokens[i];
+ uint64 premiumMultiplierWeiPerEth = s_priceRegistry.getPremiumMultiplierWeiPerEth(message.feeToken);
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+
+ uint256 feeAmount = s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = GAS_LIMIT + DEST_GAS_OVERHEAD;
+ uint256 gasFeeUSD = (gasUsed * destChainConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ uint256 messageFeeUSD = (configUSDCentToWei(destChainConfig.networkFeeUSDCents) * premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_priceRegistry.getDataAvailabilityCost(
+ DEST_CHAIN_SELECTOR, USD_PER_DATA_AVAILABILITY_GAS, message.data.length, message.tokenAmounts.length, 0
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ function test_ZeroDataAvailabilityMultiplier_Success() public {
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = new PriceRegistry.DestChainConfigArgs[](1);
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+ destChainConfigArgs[0] =
+ PriceRegistry.DestChainConfigArgs({destChainSelector: DEST_CHAIN_SELECTOR, destChainConfig: destChainConfig});
+ destChainConfigArgs[0].destChainConfig.destDataAvailabilityMultiplierBps = 0;
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint64 premiumMultiplierWeiPerEth = s_priceRegistry.getPremiumMultiplierWeiPerEth(message.feeToken);
+
+ uint256 feeAmount = s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = GAS_LIMIT + DEST_GAS_OVERHEAD;
+ uint256 gasFeeUSD = (gasUsed * destChainConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ uint256 messageFeeUSD = (configUSDCentToWei(destChainConfig.networkFeeUSDCents) * premiumMultiplierWeiPerEth);
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD) / s_feeTokenPrice;
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+
+ function test_HighGasMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 customGasLimit = MAX_GAS_LIMIT;
+ uint256 customDataSize = MAX_DATA_SIZE;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: new bytes(customDataSize),
+ tokenAmounts: new Client.EVMTokenAmount[](0),
+ feeToken: testTokens[i],
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: customGasLimit}))
+ });
+
+ uint64 premiumMultiplierWeiPerEth = s_priceRegistry.getPremiumMultiplierWeiPerEth(message.feeToken);
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+
+ uint256 feeAmount = s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ uint256 gasUsed = customGasLimit + DEST_GAS_OVERHEAD + customDataSize * DEST_GAS_PER_PAYLOAD_BYTE;
+ uint256 gasFeeUSD = (gasUsed * destChainConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ uint256 messageFeeUSD = (configUSDCentToWei(destChainConfig.networkFeeUSDCents) * premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_priceRegistry.getDataAvailabilityCost(
+ DEST_CHAIN_SELECTOR, USD_PER_DATA_AVAILABILITY_GAS, message.data.length, message.tokenAmounts.length, 0
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ function test_SingleTokenMessage_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 tokenAmount = 10000e18;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(s_sourceFeeToken, tokenAmount);
+ message.feeToken = testTokens[i];
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+ uint32 destBytesOverhead =
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token).destBytesOverhead;
+ uint32 tokenBytesOverhead =
+ destBytesOverhead == 0 ? uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) : destBytesOverhead;
+
+ uint256 feeAmount = s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+
+ uint256 gasUsed = GAS_LIMIT + DEST_GAS_OVERHEAD
+ + s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[0].token).destGasOverhead;
+ uint256 gasFeeUSD = (gasUsed * destChainConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ (uint256 transferFeeUSD,,) = s_priceRegistry.getTokenTransferCost(
+ DEST_CHAIN_SELECTOR, message.feeToken, feeTokenPrices[i], message.tokenAmounts
+ );
+ uint256 messageFeeUSD = (transferFeeUSD * s_priceRegistry.getPremiumMultiplierWeiPerEth(message.feeToken));
+ uint256 dataAvailabilityFeeUSD = s_priceRegistry.getDataAvailabilityCost(
+ DEST_CHAIN_SELECTOR,
+ USD_PER_DATA_AVAILABILITY_GAS,
+ message.data.length,
+ message.tokenAmounts.length,
+ tokenBytesOverhead
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, feeAmount);
+ }
+ }
+
+ function test_MessageWithDataAndTokenTransfer_Success() public view {
+ address[2] memory testTokens = [s_sourceFeeToken, s_sourceRouter.getWrappedNative()];
+ uint224[2] memory feeTokenPrices = [s_feeTokenPrice, s_wrappedTokenPrice];
+
+ uint256 customGasLimit = 1_000_000;
+ for (uint256 i = 0; i < feeTokenPrices.length; ++i) {
+ Client.EVM2AnyMessage memory message = Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: new Client.EVMTokenAmount[](2),
+ feeToken: testTokens[i],
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: customGasLimit}))
+ });
+ uint64 premiumMultiplierWeiPerEth = s_priceRegistry.getPremiumMultiplierWeiPerEth(message.feeToken);
+ PriceRegistry.DestChainConfig memory destChainConfig = s_priceRegistry.getDestChainConfig(DEST_CHAIN_SELECTOR);
+
+ message.tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceFeeToken, amount: 10000e18}); // feeTokenAmount
+ message.tokenAmounts[1] = Client.EVMTokenAmount({token: CUSTOM_TOKEN, amount: 200000e18}); // customTokenAmount
+ message.data = "random bits and bytes that should be factored into the cost of the message";
+
+ uint32 tokenGasOverhead = 0;
+ uint32 tokenBytesOverhead = 0;
+ for (uint256 j = 0; j < message.tokenAmounts.length; ++j) {
+ tokenGasOverhead +=
+ s_priceRegistry.getTokenTransferFeeConfig(DEST_CHAIN_SELECTOR, message.tokenAmounts[j].token).destGasOverhead;
+ uint32 destBytesOverhead = s_priceRegistry.getTokenTransferFeeConfig(
+ DEST_CHAIN_SELECTOR, message.tokenAmounts[j].token
+ ).destBytesOverhead;
+ tokenBytesOverhead += destBytesOverhead == 0 ? uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) : destBytesOverhead;
+ }
+
+ uint256 gasUsed =
+ customGasLimit + DEST_GAS_OVERHEAD + message.data.length * DEST_GAS_PER_PAYLOAD_BYTE + tokenGasOverhead;
+ uint256 gasFeeUSD = (gasUsed * destChainConfig.gasMultiplierWeiPerEth * USD_PER_GAS);
+ (uint256 transferFeeUSD,,) = s_priceRegistry.getTokenTransferCost(
+ DEST_CHAIN_SELECTOR, message.feeToken, feeTokenPrices[i], message.tokenAmounts
+ );
+ uint256 messageFeeUSD = (transferFeeUSD * premiumMultiplierWeiPerEth);
+ uint256 dataAvailabilityFeeUSD = s_priceRegistry.getDataAvailabilityCost(
+ DEST_CHAIN_SELECTOR,
+ USD_PER_DATA_AVAILABILITY_GAS,
+ message.data.length,
+ message.tokenAmounts.length,
+ tokenBytesOverhead
+ );
+
+ uint256 totalPriceInFeeToken = (gasFeeUSD + messageFeeUSD + dataAvailabilityFeeUSD) / feeTokenPrices[i];
+ assertEq(totalPriceInFeeToken, s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message));
+ }
+ }
+
+ function test_Fuzz_EnforceOutOfOrder(bool enforce, bool allowOutOfOrderExecution) public {
+ // Update config to enforce allowOutOfOrderExecution = defaultVal.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ destChainConfigArgs[0].destChainConfig.enforceOutOfOrder = enforce;
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = abi.encodeWithSelector(
+ Client.EVM_EXTRA_ARGS_V2_TAG,
+ Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT * 2, allowOutOfOrderExecution: allowOutOfOrderExecution})
+ );
+
+ // If enforcement is on, only true should be allowed.
+ if (enforce && !allowOutOfOrderExecution) {
+ vm.expectRevert(PriceRegistry.ExtraArgOutOfOrderExecutionMustBeTrue.selector);
+ }
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ // Reverts
+
+ function test_DestinationChainNotEnabled_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.DestinationChainNotEnabled.selector, DEST_CHAIN_SELECTOR + 1));
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR + 1, _generateEmptyMessage());
+ }
+
+ function test_EnforceOutOfOrder_Revert() public {
+ // Update config to enforce allowOutOfOrderExecution = true.
+ vm.stopPrank();
+ vm.startPrank(OWNER);
+
+ PriceRegistry.DestChainConfigArgs[] memory destChainConfigArgs = _generatePriceRegistryDestChainConfigArgs();
+ destChainConfigArgs[0].destChainConfig.enforceOutOfOrder = true;
+ s_priceRegistry.applyDestChainConfigUpdates(destChainConfigArgs);
+ vm.stopPrank();
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ // Empty extraArgs to should revert since it enforceOutOfOrder is true.
+ message.extraArgs = "";
+
+ vm.expectRevert(PriceRegistry.ExtraArgOutOfOrderExecutionMustBeTrue.selector);
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_MessageTooLarge_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.data = new bytes(MAX_DATA_SIZE + 1);
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.MessageTooLarge.selector, MAX_DATA_SIZE, message.data.length));
+
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_TooManyTokens_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint256 tooMany = MAX_TOKENS_LENGTH + 1;
+ message.tokenAmounts = new Client.EVMTokenAmount[](tooMany);
+ vm.expectRevert(PriceRegistry.UnsupportedNumberOfTokens.selector);
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ // Asserts gasLimit must be <=maxGasLimit
+ function test_MessageGasLimitTooHigh_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: MAX_GAS_LIMIT + 1}));
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.MessageGasLimitTooHigh.selector));
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_NotAFeeToken_Revert() public {
+ address notAFeeToken = address(0x111111);
+ Client.EVM2AnyMessage memory message = _generateSingleTokenMessage(notAFeeToken, 1);
+ message.feeToken = notAFeeToken;
+
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.TokenNotSupported.selector, notAFeeToken));
+
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_InvalidEVMAddress_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.receiver = abi.encode(type(uint208).max);
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, message.receiver));
+
+ s_priceRegistry.getValidatedFee(DEST_CHAIN_SELECTOR, message);
+ }
+}
+
+contract PriceRegistry_processMessageArgs is PriceRegistryFeeSetup {
+ using USDPriceWith18Decimals for uint224;
+
+ function setUp() public virtual override {
+ super.setUp();
+ }
+
+ function test_WithLinkTokenAmount_Success() public view {
+ (
+ uint256 msgFeeJuels,
+ /* bool isOutOfOrderExecution */
+ ,
+ /* bytes memory convertedExtraArgs */
+ ) = s_priceRegistry.processMessageArgs(
+ DEST_CHAIN_SELECTOR,
+ // LINK
+ s_sourceTokens[0],
+ MAX_MSG_FEES_JUELS,
+ ""
+ );
+
+ assertEq(msgFeeJuels, MAX_MSG_FEES_JUELS);
+ }
+
+ function test_WithConvertedTokenAmount_Success() public view {
+ address feeToken = s_sourceTokens[1];
+ uint256 feeTokenAmount = 10_000 gwei;
+ uint256 expectedConvertedAmount = s_priceRegistry.convertTokenAmount(feeToken, feeTokenAmount, s_sourceTokens[0]);
+
+ (
+ uint256 msgFeeJuels,
+ /* bool isOutOfOrderExecution */
+ ,
+ /* bytes memory convertedExtraArgs */
+ ) = s_priceRegistry.processMessageArgs(DEST_CHAIN_SELECTOR, feeToken, feeTokenAmount, "");
+
+ assertEq(msgFeeJuels, expectedConvertedAmount);
+ }
+
+ function test_WithEmptyEVMExtraArgs_Success() public view {
+ (
+ /* uint256 msgFeeJuels */
+ ,
+ bool isOutOfOrderExecution,
+ bytes memory convertedExtraArgs
+ ) = s_priceRegistry.processMessageArgs(DEST_CHAIN_SELECTOR, s_sourceTokens[0], 0, "");
+
+ assertEq(isOutOfOrderExecution, false);
+ assertEq(
+ convertedExtraArgs, Client._argsToBytes(s_priceRegistry.parseEVMExtraArgsFromBytes("", DEST_CHAIN_SELECTOR))
+ );
+ }
+
+ function test_WithEVMExtraArgsV1_Success() public view {
+ bytes memory extraArgs = Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: 1000}));
+
+ (
+ /* uint256 msgFeeJuels */
+ ,
+ bool isOutOfOrderExecution,
+ bytes memory convertedExtraArgs
+ ) = s_priceRegistry.processMessageArgs(DEST_CHAIN_SELECTOR, s_sourceTokens[0], 0, extraArgs);
+
+ assertEq(isOutOfOrderExecution, false);
+ assertEq(
+ convertedExtraArgs,
+ Client._argsToBytes(s_priceRegistry.parseEVMExtraArgsFromBytes(extraArgs, DEST_CHAIN_SELECTOR))
+ );
+ }
+
+ function test_WitEVMExtraArgsV2_Success() public view {
+ bytes memory extraArgs = Client._argsToBytes(Client.EVMExtraArgsV2({gasLimit: 0, allowOutOfOrderExecution: true}));
+
+ (
+ /* uint256 msgFeeJuels */
+ ,
+ bool isOutOfOrderExecution,
+ bytes memory convertedExtraArgs
+ ) = s_priceRegistry.processMessageArgs(DEST_CHAIN_SELECTOR, s_sourceTokens[0], 0, extraArgs);
+
+ assertEq(isOutOfOrderExecution, true);
+ assertEq(
+ convertedExtraArgs,
+ Client._argsToBytes(s_priceRegistry.parseEVMExtraArgsFromBytes(extraArgs, DEST_CHAIN_SELECTOR))
+ );
+ }
+
+ // Reverts
+
+ function test_MessageFeeTooHigh_Revert() public {
+ vm.expectRevert(
+ abi.encodeWithSelector(PriceRegistry.MessageFeeTooHigh.selector, MAX_MSG_FEES_JUELS + 1, MAX_MSG_FEES_JUELS)
+ );
+
+ s_priceRegistry.processMessageArgs(DEST_CHAIN_SELECTOR, s_sourceTokens[0], MAX_MSG_FEES_JUELS + 1, "");
+ }
+
+ function test_InvalidExtraArgs_Revert() public {
+ vm.expectRevert(PriceRegistry.InvalidExtraArgsTag.selector);
+
+ s_priceRegistry.processMessageArgs(DEST_CHAIN_SELECTOR, s_sourceTokens[0], 0, "abcde");
+ }
+
+ function test_MalformedEVMExtraArgs_Revert() public {
+ // abi.decode error
+ vm.expectRevert();
+
+ s_priceRegistry.processMessageArgs(
+ DEST_CHAIN_SELECTOR,
+ s_sourceTokens[0],
+ 0,
+ abi.encodeWithSelector(Client.EVM_EXTRA_ARGS_V2_TAG, Client.EVMExtraArgsV1({gasLimit: 100}))
+ );
+ }
+}
+
+contract PriceRegistry_validatePoolReturnData is PriceRegistryFeeSetup {
+ function test_WithSingleToken_Success() public view {
+ Client.EVMTokenAmount[] memory sourceTokenAmounts = new Client.EVMTokenAmount[](1);
+ sourceTokenAmounts[0].amount = 1e18;
+ sourceTokenAmounts[0].token = s_sourceTokens[0];
+
+ Internal.RampTokenAmount[] memory rampTokenAmounts = new Internal.RampTokenAmount[](1);
+ rampTokenAmounts[0] = _getSourceTokenData(sourceTokenAmounts[0], s_tokenAdminRegistry);
+
+ // No revert - successful
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+ }
+
+ function test_TokenAmountArraysMismatching_Revert() public {
+ Client.EVMTokenAmount[] memory sourceTokenAmounts = new Client.EVMTokenAmount[](1);
+ sourceTokenAmounts[0].amount = 1e18;
+ sourceTokenAmounts[0].token = s_sourceTokens[0];
+
+ Internal.RampTokenAmount[] memory rampTokenAmounts = new Internal.RampTokenAmount[](1);
+ rampTokenAmounts[0] = _getSourceTokenData(sourceTokenAmounts[0], s_tokenAdminRegistry);
+
+ // Revert due to index out of bounds access
+ vm.expectRevert();
+
+ s_priceRegistry.validatePoolReturnData(
+ DEST_CHAIN_SELECTOR, new Internal.RampTokenAmount[](1), new Client.EVMTokenAmount[](0)
+ );
+ }
+
+ function test_SourceTokenDataTooLarge_Revert() public {
+ address sourceETH = s_sourceTokens[1];
+
+ Client.EVMTokenAmount[] memory sourceTokenAmounts = new Client.EVMTokenAmount[](1);
+ sourceTokenAmounts[0].amount = 1000;
+ sourceTokenAmounts[0].token = sourceETH;
+
+ Internal.RampTokenAmount[] memory rampTokenAmounts = new Internal.RampTokenAmount[](1);
+ rampTokenAmounts[0] = _getSourceTokenData(sourceTokenAmounts[0], s_tokenAdminRegistry);
+
+ // No data set, should succeed
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+
+ // Set max data length, should succeed
+ rampTokenAmounts[0].extraData = new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES);
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+
+ // Set data to max length +1, should revert
+ rampTokenAmounts[0].extraData = new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES + 1);
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.SourceTokenDataTooLarge.selector, sourceETH));
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+
+ // Set token config to allow larger data
+ PriceRegistry.TokenTransferFeeConfigArgs[] memory tokenTransferFeeConfigArgs =
+ _generateTokenTransferFeeConfigArgs(1, 1);
+ tokenTransferFeeConfigArgs[0].destChainSelector = DEST_CHAIN_SELECTOR;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].token = sourceETH;
+ tokenTransferFeeConfigArgs[0].tokenTransferFeeConfigs[0].tokenTransferFeeConfig = PriceRegistry
+ .TokenTransferFeeConfig({
+ minFeeUSDCents: 1,
+ maxFeeUSDCents: 0,
+ deciBps: 0,
+ destGasOverhead: 0,
+ destBytesOverhead: uint32(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES) + 32,
+ isEnabled: true
+ });
+ s_priceRegistry.applyTokenTransferFeeConfigUpdates(
+ tokenTransferFeeConfigArgs, new PriceRegistry.TokenTransferFeeConfigRemoveArgs[](0)
+ );
+
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+
+ // Set the token data larger than the configured token data, should revert
+ rampTokenAmounts[0].extraData = new bytes(Pool.CCIP_LOCK_OR_BURN_V1_RET_BYTES + 32 + 1);
+
+ vm.expectRevert(abi.encodeWithSelector(PriceRegistry.SourceTokenDataTooLarge.selector, sourceETH));
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+ }
+
+ function test_InvalidEVMAddressDestToken_Revert() public {
+ bytes memory nonEvmAddress = abi.encode(type(uint208).max);
+
+ Client.EVMTokenAmount[] memory sourceTokenAmounts = new Client.EVMTokenAmount[](1);
+ sourceTokenAmounts[0].amount = 1e18;
+ sourceTokenAmounts[0].token = s_sourceTokens[0];
+
+ Internal.RampTokenAmount[] memory rampTokenAmounts = new Internal.RampTokenAmount[](1);
+ rampTokenAmounts[0] = _getSourceTokenData(sourceTokenAmounts[0], s_tokenAdminRegistry);
+ rampTokenAmounts[0].destTokenAddress = nonEvmAddress;
+
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, nonEvmAddress));
+ s_priceRegistry.validatePoolReturnData(DEST_CHAIN_SELECTOR, rampTokenAmounts, sourceTokenAmounts);
+ }
+}
+
+contract PriceRegistry_validateDestFamilyAddress is PriceRegistrySetup {
+ function test_ValidEVMAddress_Success() public view {
+ bytes memory encodedAddress = abi.encode(address(10000));
+ s_priceRegistry.validateDestFamilyAddress(Internal.CHAIN_FAMILY_SELECTOR_EVM, encodedAddress);
+ }
+
+ function test_ValidNonEVMAddress_Success() public view {
+ s_priceRegistry.validateDestFamilyAddress(bytes4(uint32(1)), abi.encode(type(uint208).max));
+ }
+
+ // Reverts
+
+ function test_InvalidEVMAddress_Revert() public {
+ bytes memory invalidAddress = abi.encode(type(uint208).max);
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, invalidAddress));
+ s_priceRegistry.validateDestFamilyAddress(Internal.CHAIN_FAMILY_SELECTOR_EVM, invalidAddress);
+ }
+
+ function test_InvalidEVMAddressEncodePacked_Revert() public {
+ bytes memory invalidAddress = abi.encodePacked(address(234));
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, invalidAddress));
+ s_priceRegistry.validateDestFamilyAddress(Internal.CHAIN_FAMILY_SELECTOR_EVM, invalidAddress);
+ }
+
+ function test_InvalidEVMAddressPrecompiles_Revert() public {
+ for (uint160 i = 0; i < Internal.PRECOMPILE_SPACE; ++i) {
+ bytes memory invalidAddress = abi.encode(address(i));
+ vm.expectRevert(abi.encodeWithSelector(Internal.InvalidEVMAddress.selector, invalidAddress));
+ s_priceRegistry.validateDestFamilyAddress(Internal.CHAIN_FAMILY_SELECTOR_EVM, invalidAddress);
+ }
+
+ s_priceRegistry.validateDestFamilyAddress(
+ Internal.CHAIN_FAMILY_SELECTOR_EVM, abi.encode(address(uint160(Internal.PRECOMPILE_SPACE)))
+ );
+ }
+}
+
+contract PriceRegistry_parseEVMExtraArgsFromBytes is PriceRegistrySetup {
+ PriceRegistry.DestChainConfig private s_destChainConfig;
+
+ function setUp() public virtual override {
+ super.setUp();
+ s_destChainConfig = _generatePriceRegistryDestChainConfigArgs()[0].destChainConfig;
+ }
+
+ function test_EVMExtraArgsV1_Success() public view {
+ Client.EVMExtraArgsV1 memory inputArgs = Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT});
+ bytes memory inputExtraArgs = Client._argsToBytes(inputArgs);
+ Client.EVMExtraArgsV2 memory expectedOutputArgs =
+ Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT, allowOutOfOrderExecution: false});
+
+ vm.assertEq(
+ abi.encode(s_priceRegistry.parseEVMExtraArgsFromBytes(inputExtraArgs, s_destChainConfig)),
+ abi.encode(expectedOutputArgs)
+ );
+ }
+
+ function test_EVMExtraArgsV2_Success() public view {
+ Client.EVMExtraArgsV2 memory inputArgs =
+ Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT, allowOutOfOrderExecution: true});
+ bytes memory inputExtraArgs = Client._argsToBytes(inputArgs);
+
+ vm.assertEq(
+ abi.encode(s_priceRegistry.parseEVMExtraArgsFromBytes(inputExtraArgs, s_destChainConfig)), abi.encode(inputArgs)
+ );
+ }
+
+ function test_EVMExtraArgsDefault_Success() public view {
+ Client.EVMExtraArgsV2 memory expectedOutputArgs =
+ Client.EVMExtraArgsV2({gasLimit: s_destChainConfig.defaultTxGasLimit, allowOutOfOrderExecution: false});
+
+ vm.assertEq(
+ abi.encode(s_priceRegistry.parseEVMExtraArgsFromBytes("", s_destChainConfig)), abi.encode(expectedOutputArgs)
+ );
+ }
+
+ // Reverts
+
+ function test_EVMExtraArgsInvalidExtraArgsTag_Revert() public {
+ Client.EVMExtraArgsV2 memory inputArgs =
+ Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT, allowOutOfOrderExecution: true});
+ bytes memory inputExtraArgs = Client._argsToBytes(inputArgs);
+ // Invalidate selector
+ inputExtraArgs[0] = bytes1(uint8(0));
+
+ vm.expectRevert(PriceRegistry.InvalidExtraArgsTag.selector);
+ s_priceRegistry.parseEVMExtraArgsFromBytes(inputExtraArgs, s_destChainConfig);
+ }
+
+ function test_EVMExtraArgsEnforceOutOfOrder_Revert() public {
+ Client.EVMExtraArgsV2 memory inputArgs =
+ Client.EVMExtraArgsV2({gasLimit: GAS_LIMIT, allowOutOfOrderExecution: false});
+ bytes memory inputExtraArgs = Client._argsToBytes(inputArgs);
+ s_destChainConfig.enforceOutOfOrder = true;
+
+ vm.expectRevert(PriceRegistry.ExtraArgOutOfOrderExecutionMustBeTrue.selector);
+ s_priceRegistry.parseEVMExtraArgsFromBytes(inputExtraArgs, s_destChainConfig);
+ }
+
+ function test_EVMExtraArgsGasLimitTooHigh_Revert() public {
+ Client.EVMExtraArgsV2 memory inputArgs =
+ Client.EVMExtraArgsV2({gasLimit: s_destChainConfig.maxPerMsgGasLimit + 1, allowOutOfOrderExecution: true});
+ bytes memory inputExtraArgs = Client._argsToBytes(inputArgs);
+
+ vm.expectRevert(PriceRegistry.MessageGasLimitTooHigh.selector);
+ s_priceRegistry.parseEVMExtraArgsFromBytes(inputExtraArgs, s_destChainConfig);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/rateLimiter/AggregateRateLimiter.t.sol b/contracts/src/v0.8/ccip/test/rateLimiter/AggregateRateLimiter.t.sol
new file mode 100644
index 00000000000..d3a07ef11e9
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/rateLimiter/AggregateRateLimiter.t.sol
@@ -0,0 +1,234 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {AggregateRateLimiter} from "../../AggregateRateLimiter.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {AggregateRateLimiterHelper} from "../helpers/AggregateRateLimiterHelper.sol";
+import {PriceRegistrySetup} from "../priceRegistry/PriceRegistry.t.sol";
+
+import {stdError} from "forge-std/Test.sol";
+
+contract AggregateTokenLimiterSetup is PriceRegistrySetup {
+ AggregateRateLimiterHelper internal s_rateLimiter;
+ RateLimiter.Config internal s_config;
+
+ address internal immutable TOKEN = 0x21118E64E1fB0c487F25Dd6d3601FF6af8D32E4e;
+ uint224 internal constant TOKEN_PRICE = 4e18;
+
+ function setUp() public virtual override {
+ PriceRegistrySetup.setUp();
+
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(TOKEN, TOKEN_PRICE);
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ s_config = RateLimiter.Config({isEnabled: true, rate: 5, capacity: 100});
+ s_rateLimiter = new AggregateRateLimiterHelper(s_config);
+ s_rateLimiter.setAdmin(ADMIN);
+ }
+}
+
+contract AggregateTokenLimiter_constructor is AggregateTokenLimiterSetup {
+ function test_Constructor_Success() public view {
+ assertEq(ADMIN, s_rateLimiter.getTokenLimitAdmin());
+ assertEq(OWNER, s_rateLimiter.owner());
+
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity, bucket.tokens);
+ assertEq(s_config.isEnabled, bucket.isEnabled);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+ }
+}
+
+contract AggregateTokenLimiter_getTokenLimitAdmin is AggregateTokenLimiterSetup {
+ function test_GetTokenLimitAdmin_Success() public view {
+ assertEq(ADMIN, s_rateLimiter.getTokenLimitAdmin());
+ }
+}
+
+contract AggregateTokenLimiter_setAdmin is AggregateTokenLimiterSetup {
+ function test_Owner_Success() public {
+ vm.expectEmit();
+ emit AggregateRateLimiter.AdminSet(STRANGER);
+
+ s_rateLimiter.setAdmin(STRANGER);
+ assertEq(STRANGER, s_rateLimiter.getTokenLimitAdmin());
+ }
+
+ // Reverts
+
+ function test_OnlyOwnerOrAdmin_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(RateLimiter.OnlyCallableByAdminOrOwner.selector);
+
+ s_rateLimiter.setAdmin(STRANGER);
+ }
+}
+
+contract AggregateTokenLimiter_getTokenBucket is AggregateTokenLimiterSetup {
+ function test_GetTokenBucket_Success() public view {
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity, bucket.tokens);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+ }
+
+ function test_Refill_Success() public {
+ s_config.capacity = s_config.capacity * 2;
+ s_rateLimiter.setRateLimiterConfig(s_config);
+
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState();
+
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity / 2, bucket.tokens);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+
+ uint256 warpTime = 4;
+ vm.warp(BLOCK_TIME + warpTime);
+
+ bucket = s_rateLimiter.currentRateLimiterState();
+
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.capacity / 2 + warpTime * s_config.rate, bucket.tokens);
+ assertEq(BLOCK_TIME + warpTime, bucket.lastUpdated);
+
+ vm.warp(BLOCK_TIME + warpTime * 100);
+
+ // Bucket overflow
+ bucket = s_rateLimiter.currentRateLimiterState();
+ assertEq(s_config.capacity, bucket.tokens);
+ }
+
+ // Reverts
+
+ function test_TimeUnderflow_Revert() public {
+ vm.warp(BLOCK_TIME - 1);
+
+ vm.expectRevert(stdError.arithmeticError);
+ s_rateLimiter.currentRateLimiterState();
+ }
+}
+
+contract AggregateTokenLimiter_setRateLimiterConfig is AggregateTokenLimiterSetup {
+ function test_Owner_Success() public {
+ setConfig();
+ }
+
+ function test_TokenLimitAdmin_Success() public {
+ vm.startPrank(ADMIN);
+ setConfig();
+ }
+
+ function setConfig() private {
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+
+ if (bucket.isEnabled) {
+ s_config = RateLimiter.Config({isEnabled: false, rate: 0, capacity: 0});
+ } else {
+ s_config = RateLimiter.Config({isEnabled: true, rate: 100, capacity: 200});
+ }
+
+ vm.expectEmit();
+ emit RateLimiter.ConfigChanged(s_config);
+
+ s_rateLimiter.setRateLimiterConfig(s_config);
+
+ bucket = s_rateLimiter.currentRateLimiterState();
+ assertEq(s_config.rate, bucket.rate);
+ assertEq(s_config.capacity, bucket.capacity);
+ assertEq(s_config.isEnabled, bucket.isEnabled);
+ }
+
+ // Reverts
+
+ function test_OnlyOnlyCallableByAdminOrOwner_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(RateLimiter.OnlyCallableByAdminOrOwner.selector);
+
+ s_rateLimiter.setRateLimiterConfig(s_config);
+ }
+}
+
+contract AggregateTokenLimiter_rateLimitValue is AggregateTokenLimiterSetup {
+ function test_RateLimitValueSuccess_gas() public {
+ vm.pauseGasMetering();
+ // start from blocktime that does not equal rate limiter init timestamp
+ vm.warp(BLOCK_TIME + 1);
+
+ // 15 (tokens) * 4 (price) * 2 (number of times) > 100 (capacity)
+ uint256 numberOfTokens = 15;
+ uint256 value = (numberOfTokens * TOKEN_PRICE) / 1e18;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(value);
+
+ vm.resumeGasMetering();
+ s_rateLimiter.rateLimitValue(value);
+ vm.pauseGasMetering();
+
+ // Get the updated bucket status
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState();
+ // Assert the proper value has been taken out of the bucket
+ assertEq(bucket.capacity - value, bucket.tokens);
+
+ // Since value * 2 > bucket.capacity we cannot take it out twice.
+ // Expect a revert when we try, with a wait time.
+ uint256 waitTime = 4;
+ vm.expectRevert(
+ abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, waitTime, bucket.tokens)
+ );
+ s_rateLimiter.rateLimitValue(value);
+
+ // Move the block time forward by 10 so the bucket refills by 10 * rate
+ vm.warp(BLOCK_TIME + 1 + waitTime);
+
+ // The bucket has filled up enough so we can take out more tokens
+ s_rateLimiter.rateLimitValue(value);
+ bucket = s_rateLimiter.currentRateLimiterState();
+ assertEq(bucket.capacity - value + waitTime * s_config.rate - value, bucket.tokens);
+ vm.resumeGasMetering();
+ }
+
+ // Reverts
+
+ function test_AggregateValueMaxCapacityExceeded_Revert() public {
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState();
+
+ uint256 numberOfTokens = 100;
+ uint256 value = (numberOfTokens * TOKEN_PRICE) / 1e18;
+
+ vm.expectRevert(
+ abi.encodeWithSelector(
+ RateLimiter.AggregateValueMaxCapacityExceeded.selector, bucket.capacity, (numberOfTokens * TOKEN_PRICE) / 1e18
+ )
+ );
+ s_rateLimiter.rateLimitValue(value);
+ }
+}
+
+contract AggregateTokenLimiter_getTokenValue is AggregateTokenLimiterSetup {
+ function test_GetTokenValue_Success() public view {
+ uint256 numberOfTokens = 10;
+ Client.EVMTokenAmount memory tokenAmount = Client.EVMTokenAmount({token: TOKEN, amount: 10});
+ uint256 value = s_rateLimiter.getTokenValue(tokenAmount, s_priceRegistry);
+ assertEq(value, (numberOfTokens * TOKEN_PRICE) / 1e18);
+ }
+
+ // Reverts
+ function test_NoTokenPrice_Reverts() public {
+ address tokenWithNoPrice = makeAddr("Token with no price");
+ Client.EVMTokenAmount memory tokenAmount = Client.EVMTokenAmount({token: tokenWithNoPrice, amount: 10});
+
+ vm.expectRevert(abi.encodeWithSelector(AggregateRateLimiter.PriceNotFoundForToken.selector, tokenWithNoPrice));
+ s_rateLimiter.getTokenValue(tokenAmount, s_priceRegistry);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/rateLimiter/MultiAggregateRateLimiter.t.sol b/contracts/src/v0.8/ccip/test/rateLimiter/MultiAggregateRateLimiter.t.sol
new file mode 100644
index 00000000000..2bd31452f00
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/rateLimiter/MultiAggregateRateLimiter.t.sol
@@ -0,0 +1,1201 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {AuthorizedCallers} from "../../../shared/access/AuthorizedCallers.sol";
+import {MultiAggregateRateLimiter} from "../../MultiAggregateRateLimiter.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {RateLimiter} from "../../libraries/RateLimiter.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {MultiAggregateRateLimiterHelper} from "../helpers/MultiAggregateRateLimiterHelper.sol";
+import {PriceRegistrySetup} from "../priceRegistry/PriceRegistry.t.sol";
+import {stdError} from "forge-std/Test.sol";
+import {Vm} from "forge-std/Vm.sol";
+
+contract MultiAggregateRateLimiterSetup is BaseTest, PriceRegistrySetup {
+ MultiAggregateRateLimiterHelper internal s_rateLimiter;
+
+ address internal immutable TOKEN = 0x21118E64E1fB0c487F25Dd6d3601FF6af8D32E4e;
+ uint224 internal constant TOKEN_PRICE = 4e18;
+
+ uint64 internal constant CHAIN_SELECTOR_1 = 5009297550715157269;
+ uint64 internal constant CHAIN_SELECTOR_2 = 4949039107694359620;
+
+ RateLimiter.Config internal RATE_LIMITER_CONFIG_1 = RateLimiter.Config({isEnabled: true, rate: 5, capacity: 100});
+ RateLimiter.Config internal RATE_LIMITER_CONFIG_2 = RateLimiter.Config({isEnabled: true, rate: 10, capacity: 200});
+
+ address internal immutable MOCK_OFFRAMP = address(1111);
+ address internal immutable MOCK_ONRAMP = address(1112);
+
+ address[] internal s_authorizedCallers;
+
+ function setUp() public virtual override(BaseTest, PriceRegistrySetup) {
+ BaseTest.setUp();
+ PriceRegistrySetup.setUp();
+
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(TOKEN, TOKEN_PRICE);
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](4);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+ configUpdates[1] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_2
+ });
+ configUpdates[2] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: true,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+ configUpdates[3] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ isOutboundLane: true,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_2
+ });
+
+ s_authorizedCallers = new address[](2);
+ s_authorizedCallers[0] = MOCK_OFFRAMP;
+ s_authorizedCallers[1] = MOCK_ONRAMP;
+
+ s_rateLimiter = new MultiAggregateRateLimiterHelper(address(s_priceRegistry), s_authorizedCallers);
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+ }
+
+ function _assertConfigWithTokenBucketEquality(
+ RateLimiter.Config memory config,
+ RateLimiter.TokenBucket memory tokenBucket
+ ) internal pure {
+ assertEq(config.rate, tokenBucket.rate);
+ assertEq(config.capacity, tokenBucket.capacity);
+ assertEq(config.capacity, tokenBucket.tokens);
+ assertEq(config.isEnabled, tokenBucket.isEnabled);
+ }
+
+ function _assertTokenBucketEquality(
+ RateLimiter.TokenBucket memory tokenBucketA,
+ RateLimiter.TokenBucket memory tokenBucketB
+ ) internal pure {
+ assertEq(tokenBucketA.rate, tokenBucketB.rate);
+ assertEq(tokenBucketA.capacity, tokenBucketB.capacity);
+ assertEq(tokenBucketA.tokens, tokenBucketB.tokens);
+ assertEq(tokenBucketA.isEnabled, tokenBucketB.isEnabled);
+ }
+
+ function _generateAny2EVMMessage(
+ uint64 sourceChainSelector,
+ Client.EVMTokenAmount[] memory tokenAmounts
+ ) internal pure returns (Client.Any2EVMMessage memory) {
+ return Client.Any2EVMMessage({
+ messageId: keccak256(bytes("messageId")),
+ sourceChainSelector: sourceChainSelector,
+ sender: abi.encode(OWNER),
+ data: abi.encode(0),
+ destTokenAmounts: tokenAmounts
+ });
+ }
+
+ function _generateAny2EVMMessageNoTokens(uint64 sourceChainSelector)
+ internal
+ pure
+ returns (Client.Any2EVMMessage memory)
+ {
+ return _generateAny2EVMMessage(sourceChainSelector, new Client.EVMTokenAmount[](0));
+ }
+}
+
+contract MultiAggregateRateLimiter_constructor is MultiAggregateRateLimiterSetup {
+ function test_ConstructorNoAuthorizedCallers_Success() public {
+ address[] memory authorizedCallers = new address[](0);
+
+ vm.recordLogs();
+ s_rateLimiter = new MultiAggregateRateLimiterHelper(address(s_priceRegistry), authorizedCallers);
+
+ // PriceRegistrySet
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 1);
+
+ assertEq(OWNER, s_rateLimiter.owner());
+ assertEq(address(s_priceRegistry), s_rateLimiter.getPriceRegistry());
+ }
+
+ function test_Constructor_Success() public {
+ address[] memory authorizedCallers = new address[](2);
+ authorizedCallers[0] = MOCK_OFFRAMP;
+ authorizedCallers[1] = MOCK_ONRAMP;
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.PriceRegistrySet(address(s_priceRegistry));
+
+ s_rateLimiter = new MultiAggregateRateLimiterHelper(address(s_priceRegistry), authorizedCallers);
+
+ assertEq(OWNER, s_rateLimiter.owner());
+ assertEq(address(s_priceRegistry), s_rateLimiter.getPriceRegistry());
+ }
+}
+
+contract MultiAggregateRateLimiter_setPriceRegistry is MultiAggregateRateLimiterSetup {
+ function test_Owner_Success() public {
+ address newAddress = address(42);
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.PriceRegistrySet(newAddress);
+
+ s_rateLimiter.setPriceRegistry(newAddress);
+ assertEq(newAddress, s_rateLimiter.getPriceRegistry());
+ }
+
+ // Reverts
+
+ function test_OnlyOwner_Revert() public {
+ vm.startPrank(STRANGER);
+ vm.expectRevert(bytes("Only callable by owner"));
+
+ s_rateLimiter.setPriceRegistry(STRANGER);
+ }
+
+ function test_ZeroAddress_Revert() public {
+ vm.expectRevert(AuthorizedCallers.ZeroAddressNotAllowed.selector);
+ s_rateLimiter.setPriceRegistry(address(0));
+ }
+}
+
+contract MultiAggregateRateLimiter_getTokenBucket is MultiAggregateRateLimiterSetup {
+ function test_GetTokenBucket_Success() public view {
+ RateLimiter.TokenBucket memory bucketInbound = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ _assertConfigWithTokenBucketEquality(RATE_LIMITER_CONFIG_1, bucketInbound);
+ assertEq(BLOCK_TIME, bucketInbound.lastUpdated);
+
+ RateLimiter.TokenBucket memory bucketOutbound = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ _assertConfigWithTokenBucketEquality(RATE_LIMITER_CONFIG_1, bucketOutbound);
+ assertEq(BLOCK_TIME, bucketOutbound.lastUpdated);
+ }
+
+ function test_Refill_Success() public {
+ RATE_LIMITER_CONFIG_1.capacity = RATE_LIMITER_CONFIG_1.capacity * 2;
+
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ RateLimiter.TokenBucket memory bucket = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+
+ assertEq(RATE_LIMITER_CONFIG_1.rate, bucket.rate);
+ assertEq(RATE_LIMITER_CONFIG_1.capacity, bucket.capacity);
+ assertEq(RATE_LIMITER_CONFIG_1.capacity / 2, bucket.tokens);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+
+ uint256 warpTime = 4;
+ vm.warp(BLOCK_TIME + warpTime);
+
+ bucket = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+
+ assertEq(RATE_LIMITER_CONFIG_1.rate, bucket.rate);
+ assertEq(RATE_LIMITER_CONFIG_1.capacity, bucket.capacity);
+ assertEq(RATE_LIMITER_CONFIG_1.capacity / 2 + warpTime * RATE_LIMITER_CONFIG_1.rate, bucket.tokens);
+ assertEq(BLOCK_TIME + warpTime, bucket.lastUpdated);
+
+ vm.warp(BLOCK_TIME + warpTime * 100);
+
+ // Bucket overflow
+ bucket = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ assertEq(RATE_LIMITER_CONFIG_1.capacity, bucket.tokens);
+ }
+
+ // Reverts
+
+ function test_TimeUnderflow_Revert() public {
+ vm.warp(BLOCK_TIME - 1);
+
+ vm.expectRevert(stdError.arithmeticError);
+ s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ }
+}
+
+contract MultiAggregateRateLimiter_applyRateLimiterConfigUpdates is MultiAggregateRateLimiterSetup {
+ function test_ZeroConfigs_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](0);
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 0);
+ }
+
+ function test_SingleConfig_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1 + 1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.RateLimiterConfigUpdated(
+ configUpdates[0].remoteChainSelector, false, configUpdates[0].rateLimiterConfig
+ );
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 1);
+
+ RateLimiter.TokenBucket memory bucket1 =
+ s_rateLimiter.currentRateLimiterState(configUpdates[0].remoteChainSelector, false);
+ _assertConfigWithTokenBucketEquality(configUpdates[0].rateLimiterConfig, bucket1);
+ assertEq(BLOCK_TIME, bucket1.lastUpdated);
+ }
+
+ function test_SingleConfigOutbound_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1 + 1,
+ isOutboundLane: true,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_2
+ });
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.RateLimiterConfigUpdated(
+ configUpdates[0].remoteChainSelector, true, configUpdates[0].rateLimiterConfig
+ );
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 1);
+
+ RateLimiter.TokenBucket memory bucket1 =
+ s_rateLimiter.currentRateLimiterState(configUpdates[0].remoteChainSelector, true);
+ _assertConfigWithTokenBucketEquality(configUpdates[0].rateLimiterConfig, bucket1);
+ assertEq(BLOCK_TIME, bucket1.lastUpdated);
+ }
+
+ function test_MultipleConfigs_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](5);
+
+ for (uint64 i; i < configUpdates.length; ++i) {
+ configUpdates[i] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1 + i + 1,
+ isOutboundLane: i % 2 == 0 ? false : true,
+ rateLimiterConfig: RateLimiter.Config({isEnabled: true, rate: 5 + i, capacity: 100 + i})
+ });
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.RateLimiterConfigUpdated(
+ configUpdates[i].remoteChainSelector, configUpdates[i].isOutboundLane, configUpdates[i].rateLimiterConfig
+ );
+ }
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, configUpdates.length);
+
+ for (uint256 i; i < configUpdates.length; ++i) {
+ RateLimiter.TokenBucket memory bucket =
+ s_rateLimiter.currentRateLimiterState(configUpdates[i].remoteChainSelector, configUpdates[i].isOutboundLane);
+ _assertConfigWithTokenBucketEquality(configUpdates[i].rateLimiterConfig, bucket);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+ }
+ }
+
+ function test_MultipleConfigsBothLanes_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](2);
+
+ for (uint64 i; i < configUpdates.length; ++i) {
+ configUpdates[i] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1 + 1,
+ isOutboundLane: i % 2 == 0 ? false : true,
+ rateLimiterConfig: RateLimiter.Config({isEnabled: true, rate: 5 + i, capacity: 100 + i})
+ });
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.RateLimiterConfigUpdated(
+ configUpdates[i].remoteChainSelector, configUpdates[i].isOutboundLane, configUpdates[i].rateLimiterConfig
+ );
+ }
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, configUpdates.length);
+
+ for (uint256 i; i < configUpdates.length; ++i) {
+ RateLimiter.TokenBucket memory bucket =
+ s_rateLimiter.currentRateLimiterState(configUpdates[i].remoteChainSelector, configUpdates[i].isOutboundLane);
+ _assertConfigWithTokenBucketEquality(configUpdates[i].rateLimiterConfig, bucket);
+ assertEq(BLOCK_TIME, bucket.lastUpdated);
+ }
+ }
+
+ function test_UpdateExistingConfig_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_2
+ });
+
+ RateLimiter.TokenBucket memory bucket1 =
+ s_rateLimiter.currentRateLimiterState(configUpdates[0].remoteChainSelector, false);
+
+ // Capacity equals tokens
+ assertEq(bucket1.capacity, bucket1.tokens);
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.RateLimiterConfigUpdated(
+ configUpdates[0].remoteChainSelector, false, configUpdates[0].rateLimiterConfig
+ );
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ vm.warp(BLOCK_TIME + 1);
+ bucket1 = s_rateLimiter.currentRateLimiterState(configUpdates[0].remoteChainSelector, false);
+ assertEq(BLOCK_TIME + 1, bucket1.lastUpdated);
+
+ // Tokens < capacity since capacity doubled
+ assertTrue(bucket1.capacity != bucket1.tokens);
+
+ // Outbound lane config remains unchanged
+ _assertConfigWithTokenBucketEquality(
+ RATE_LIMITER_CONFIG_1, s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true)
+ );
+ }
+
+ function test_UpdateExistingConfigWithNoDifference_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+
+ RateLimiter.TokenBucket memory bucketPreUpdate =
+ s_rateLimiter.currentRateLimiterState(configUpdates[0].remoteChainSelector, false);
+
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.RateLimiterConfigUpdated(
+ configUpdates[0].remoteChainSelector, false, configUpdates[0].rateLimiterConfig
+ );
+
+ vm.recordLogs();
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ vm.warp(BLOCK_TIME + 1);
+ RateLimiter.TokenBucket memory bucketPostUpdate =
+ s_rateLimiter.currentRateLimiterState(configUpdates[0].remoteChainSelector, false);
+ _assertTokenBucketEquality(bucketPreUpdate, bucketPostUpdate);
+ assertEq(BLOCK_TIME + 1, bucketPostUpdate.lastUpdated);
+ }
+
+ // Reverts
+ function test_ZeroChainSelector_Revert() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: 0,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+
+ vm.expectRevert(MultiAggregateRateLimiter.ZeroChainSelectorNotAllowed.selector);
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+ }
+
+ function test_OnlyCallableByOwner_Revert() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1 + 1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(bytes("Only callable by owner"));
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+ }
+}
+
+contract MultiAggregateRateLimiter_getTokenValue is MultiAggregateRateLimiterSetup {
+ function test_GetTokenValue_Success() public view {
+ uint256 numberOfTokens = 10;
+ Client.EVMTokenAmount memory tokenAmount = Client.EVMTokenAmount({token: TOKEN, amount: 10});
+ uint256 value = s_rateLimiter.getTokenValue(tokenAmount);
+ assertEq(value, (numberOfTokens * TOKEN_PRICE) / 1e18);
+ }
+
+ // Reverts
+ function test_NoTokenPrice_Reverts() public {
+ address tokenWithNoPrice = makeAddr("Token with no price");
+ Client.EVMTokenAmount memory tokenAmount = Client.EVMTokenAmount({token: tokenWithNoPrice, amount: 10});
+
+ vm.expectRevert(abi.encodeWithSelector(MultiAggregateRateLimiter.PriceNotFoundForToken.selector, tokenWithNoPrice));
+ s_rateLimiter.getTokenValue(tokenAmount);
+ }
+}
+
+contract MultiAggregateRateLimiter_updateRateLimitTokens is MultiAggregateRateLimiterSetup {
+ function setUp() public virtual override {
+ super.setUp();
+
+ // Clear rate limit tokens state
+ MultiAggregateRateLimiter.LocalRateLimitToken[] memory removes =
+ new MultiAggregateRateLimiter.LocalRateLimitToken[](s_sourceTokens.length);
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ removes[i] = MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[i]
+ });
+ }
+ s_rateLimiter.updateRateLimitTokens(removes, new MultiAggregateRateLimiter.RateLimitTokenArgs[](0));
+ }
+
+ function test_UpdateRateLimitTokensSingleChain_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](2);
+ adds[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[0]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[0]))
+ });
+ adds[1] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[1]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[1]))
+ });
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.TokenAggregateRateLimitAdded(
+ CHAIN_SELECTOR_1, adds[i].remoteToken, adds[i].localTokenArgs.localToken
+ );
+ }
+
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), adds);
+
+ (address[] memory localTokens, bytes32[] memory remoteTokens) =
+ s_rateLimiter.getAllRateLimitTokens(CHAIN_SELECTOR_1);
+
+ assertEq(localTokens.length, adds.length);
+ assertEq(localTokens.length, remoteTokens.length);
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ assertEq(adds[i].remoteToken, remoteTokens[i]);
+ assertEq(adds[i].localTokenArgs.localToken, localTokens[i]);
+ }
+ }
+
+ function test_UpdateRateLimitTokensMultipleChains_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](2);
+ adds[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[0]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[0]))
+ });
+ adds[1] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ localToken: s_destTokens[1]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[1]))
+ });
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.TokenAggregateRateLimitAdded(
+ adds[i].localTokenArgs.remoteChainSelector, adds[i].remoteToken, adds[i].localTokenArgs.localToken
+ );
+ }
+
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), adds);
+
+ (address[] memory localTokensChain1, bytes32[] memory remoteTokensChain1) =
+ s_rateLimiter.getAllRateLimitTokens(CHAIN_SELECTOR_1);
+
+ assertEq(localTokensChain1.length, 1);
+ assertEq(localTokensChain1.length, remoteTokensChain1.length);
+ assertEq(localTokensChain1[0], adds[0].localTokenArgs.localToken);
+ assertEq(remoteTokensChain1[0], adds[0].remoteToken);
+
+ (address[] memory localTokensChain2, bytes32[] memory remoteTokensChain2) =
+ s_rateLimiter.getAllRateLimitTokens(CHAIN_SELECTOR_2);
+
+ assertEq(localTokensChain2.length, 1);
+ assertEq(localTokensChain2.length, remoteTokensChain2.length);
+ assertEq(localTokensChain2[0], adds[1].localTokenArgs.localToken);
+ assertEq(remoteTokensChain2[0], adds[1].remoteToken);
+ }
+
+ function test_UpdateRateLimitTokens_AddsAndRemoves_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](2);
+ adds[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[0]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[0]))
+ });
+ adds[1] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[1]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[1]))
+ });
+
+ MultiAggregateRateLimiter.LocalRateLimitToken[] memory removes =
+ new MultiAggregateRateLimiter.LocalRateLimitToken[](1);
+ removes[0] = adds[0].localTokenArgs;
+
+ for (uint256 i = 0; i < adds.length; ++i) {
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.TokenAggregateRateLimitAdded(
+ CHAIN_SELECTOR_1, adds[i].remoteToken, adds[i].localTokenArgs.localToken
+ );
+ }
+
+ s_rateLimiter.updateRateLimitTokens(removes, adds);
+
+ for (uint256 i = 0; i < removes.length; ++i) {
+ vm.expectEmit();
+ emit MultiAggregateRateLimiter.TokenAggregateRateLimitRemoved(CHAIN_SELECTOR_1, removes[i].localToken);
+ }
+
+ s_rateLimiter.updateRateLimitTokens(removes, new MultiAggregateRateLimiter.RateLimitTokenArgs[](0));
+
+ (address[] memory localTokens, bytes32[] memory remoteTokens) =
+ s_rateLimiter.getAllRateLimitTokens(CHAIN_SELECTOR_1);
+
+ assertEq(1, remoteTokens.length);
+ assertEq(adds[1].remoteToken, remoteTokens[0]);
+
+ assertEq(1, localTokens.length);
+ assertEq(adds[1].localTokenArgs.localToken, localTokens[0]);
+ }
+
+ function test_UpdateRateLimitTokens_RemoveNonExistentToken_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](0);
+
+ MultiAggregateRateLimiter.LocalRateLimitToken[] memory removes =
+ new MultiAggregateRateLimiter.LocalRateLimitToken[](1);
+ removes[0] = MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[0]
+ });
+
+ vm.recordLogs();
+ s_rateLimiter.updateRateLimitTokens(removes, adds);
+
+ // No event since no remove occurred
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 0);
+
+ (address[] memory localTokens, bytes32[] memory remoteTokens) =
+ s_rateLimiter.getAllRateLimitTokens(CHAIN_SELECTOR_1);
+
+ assertEq(localTokens.length, 0);
+ assertEq(localTokens.length, remoteTokens.length);
+ }
+
+ // Reverts
+
+ function test_ZeroSourceToken_Revert() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](1);
+ adds[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[0]
+ }),
+ remoteToken: bytes32(bytes20(address(0)))
+ });
+
+ vm.expectRevert(AuthorizedCallers.ZeroAddressNotAllowed.selector);
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), adds);
+ }
+
+ function test_ZeroDestToken_Revert() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](1);
+ adds[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: address(0)
+ }),
+ remoteToken: bytes32(bytes20(s_destTokens[0]))
+ });
+
+ vm.expectRevert(AuthorizedCallers.ZeroAddressNotAllowed.selector);
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), adds);
+ }
+
+ function test_NonOwner_Revert() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory adds = new MultiAggregateRateLimiter.RateLimitTokenArgs[](4);
+
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(bytes("Only callable by owner"));
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), adds);
+ }
+}
+
+contract MultiAggregateRateLimiter_onInboundMessage is MultiAggregateRateLimiterSetup {
+ address internal immutable MOCK_RECEIVER = address(1113);
+
+ function setUp() public virtual override {
+ super.setUp();
+
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory tokensToAdd =
+ new MultiAggregateRateLimiter.RateLimitTokenArgs[](s_sourceTokens.length);
+ for (uint224 i = 0; i < s_sourceTokens.length; ++i) {
+ tokensToAdd[i] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[i]
+ }),
+ remoteToken: bytes32(bytes20(s_sourceTokens[i]))
+ });
+
+ Internal.PriceUpdates memory priceUpdates =
+ getSingleTokenPriceUpdateStruct(s_destTokens[i], TOKEN_PRICE * (i + 1));
+ s_priceRegistry.updatePrices(priceUpdates);
+ }
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), tokensToAdd);
+ }
+
+ function test_ValidateMessageWithNoTokens_Success() public {
+ vm.startPrank(MOCK_OFFRAMP);
+
+ vm.recordLogs();
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessageNoTokens(CHAIN_SELECTOR_1));
+
+ // No consumed rate limit events
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 0);
+ }
+
+ function test_ValidateMessageWithTokens_Success() public {
+ vm.startPrank(MOCK_OFFRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 3});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_destTokens[1], amount: 1});
+
+ // 3 tokens * TOKEN_PRICE + 1 token * (2 * TOKEN_PRICE)
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed((5 * TOKEN_PRICE) / 1e18);
+
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+ }
+
+ function test_ValidateMessageWithDisabledRateLimitToken_Success() public {
+ MultiAggregateRateLimiter.LocalRateLimitToken[] memory removes =
+ new MultiAggregateRateLimiter.LocalRateLimitToken[](1);
+ removes[0] = MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_destTokens[1]
+ });
+ s_rateLimiter.updateRateLimitTokens(removes, new MultiAggregateRateLimiter.RateLimitTokenArgs[](0));
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 5});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_destTokens[1], amount: 1});
+
+ vm.startPrank(MOCK_OFFRAMP);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed((5 * TOKEN_PRICE) / 1e18);
+
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+ }
+
+ function test_ValidateMessageWithRateLimitDisabled_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: false,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+ configUpdates[0].rateLimiterConfig.isEnabled = false;
+
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 1000});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_destTokens[1], amount: 50});
+
+ vm.startPrank(MOCK_OFFRAMP);
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+
+ // No consumed rate limit events
+ Vm.Log[] memory logEntries = vm.getRecordedLogs();
+ assertEq(logEntries.length, 0);
+ }
+
+ function test_ValidateMessageWithTokensOnDifferentChains_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory tokensToAdd =
+ new MultiAggregateRateLimiter.RateLimitTokenArgs[](s_sourceTokens.length);
+ for (uint224 i = 0; i < s_sourceTokens.length; ++i) {
+ tokensToAdd[i] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ localToken: s_destTokens[i]
+ }),
+ // Create a remote token address that is different from CHAIN_SELECTOR_1
+ remoteToken: bytes32(uint256(uint160(s_sourceTokens[i])) + type(uint160).max + 1)
+ });
+ }
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), tokensToAdd);
+
+ vm.startPrank(MOCK_OFFRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 2});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_destTokens[1], amount: 1});
+
+ // 2 tokens * (TOKEN_PRICE) + 1 token * (2 * TOKEN_PRICE)
+ uint256 totalValue = (4 * TOKEN_PRICE) / 1e18;
+
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+
+ // Chain 1 changed
+ RateLimiter.TokenBucket memory bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 unchanged
+ RateLimiter.TokenBucket memory bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, false);
+ assertEq(bucketChain2.capacity, bucketChain2.tokens);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(totalValue);
+
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_2, tokenAmounts));
+
+ // Chain 1 unchanged
+ bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 changed
+ bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, false);
+ assertEq(bucketChain2.capacity - totalValue, bucketChain2.tokens);
+ }
+
+ function test_ValidateMessageWithDifferentTokensOnDifferentChains_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory tokensToAdd =
+ new MultiAggregateRateLimiter.RateLimitTokenArgs[](1);
+
+ // Only 1 rate limited token on different chain
+ tokensToAdd[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ localToken: s_destTokens[0]
+ }),
+ // Create a remote token address that is different from CHAIN_SELECTOR_1
+ remoteToken: bytes32(uint256(uint160(s_sourceTokens[0])) + type(uint160).max + 1)
+ });
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), tokensToAdd);
+
+ vm.startPrank(MOCK_OFFRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 3});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_destTokens[1], amount: 1});
+
+ // 3 tokens * (TOKEN_PRICE) + 1 token * (2 * TOKEN_PRICE)
+ uint256 totalValue = (5 * TOKEN_PRICE) / 1e18;
+
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+
+ // Chain 1 changed
+ RateLimiter.TokenBucket memory bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 unchanged
+ RateLimiter.TokenBucket memory bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, false);
+ assertEq(bucketChain2.capacity, bucketChain2.tokens);
+
+ // 3 tokens * (TOKEN_PRICE)
+ uint256 totalValue2 = (3 * TOKEN_PRICE) / 1e18;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(totalValue2);
+
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_2, tokenAmounts));
+
+ // Chain 1 unchanged
+ bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 changed
+ bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, false);
+ assertEq(bucketChain2.capacity - totalValue2, bucketChain2.tokens);
+ }
+
+ function test_ValidateMessageWithRateLimitReset_Success() public {
+ vm.startPrank(MOCK_OFFRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 20});
+
+ // Remaining capacity: 100 -> 20
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+
+ // Cannot fit 80 rate limit value (need to wait at least 12 blocks, current capacity is 20)
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, 12, 20));
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+
+ // Remaining capacity: 20 -> 35 (need to wait 9 more blocks)
+ vm.warp(BLOCK_TIME + 3);
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, 9, 35));
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+
+ // Remaining capacity: 35 -> 80 (can fit exactly 80)
+ vm.warp(BLOCK_TIME + 12);
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+ }
+
+ // Reverts
+
+ function test_ValidateMessageWithRateLimitExceeded_Revert() public {
+ vm.startPrank(MOCK_OFFRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_destTokens[0], amount: 80});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_destTokens[1], amount: 30});
+
+ uint256 totalValue = (80 * TOKEN_PRICE + 2 * (30 * TOKEN_PRICE)) / 1e18;
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueMaxCapacityExceeded.selector, 100, totalValue));
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+ }
+
+ function test_ValidateMessageFromUnauthorizedCaller_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(abi.encodeWithSelector(AuthorizedCallers.UnauthorizedCaller.selector, STRANGER));
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessageNoTokens(CHAIN_SELECTOR_1));
+ }
+}
+
+contract MultiAggregateRateLimiter_onOutboundMessage is MultiAggregateRateLimiterSetup {
+ function setUp() public virtual override {
+ super.setUp();
+
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory tokensToAdd =
+ new MultiAggregateRateLimiter.RateLimitTokenArgs[](s_sourceTokens.length);
+ for (uint224 i = 0; i < s_sourceTokens.length; ++i) {
+ tokensToAdd[i] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_sourceTokens[i]
+ }),
+ remoteToken: bytes32(bytes20(s_destTokenBySourceToken[s_sourceTokens[i]]))
+ });
+
+ Internal.PriceUpdates memory priceUpdates =
+ getSingleTokenPriceUpdateStruct(s_sourceTokens[i], TOKEN_PRICE * (i + 1));
+ s_priceRegistry.updatePrices(priceUpdates);
+ }
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), tokensToAdd);
+ }
+
+ function test_ValidateMessageWithNoTokens_Success() public {
+ vm.startPrank(MOCK_ONRAMP);
+
+ vm.recordLogs();
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessageNoTokens());
+
+ // No consumed rate limit events
+ assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ function test_onOutboundMessage_ValidateMessageWithTokens_Success() public {
+ vm.startPrank(MOCK_ONRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 3});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_sourceTokens[1], amount: 1});
+
+ // 3 tokens * TOKEN_PRICE + 1 token * (2 * TOKEN_PRICE)
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed((5 * TOKEN_PRICE) / 1e18);
+
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+ }
+
+ function test_onOutboundMessage_ValidateMessageWithDisabledRateLimitToken_Success() public {
+ MultiAggregateRateLimiter.LocalRateLimitToken[] memory removes =
+ new MultiAggregateRateLimiter.LocalRateLimitToken[](1);
+ removes[0] = MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ localToken: s_sourceTokens[1]
+ });
+ s_rateLimiter.updateRateLimitTokens(removes, new MultiAggregateRateLimiter.RateLimitTokenArgs[](0));
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 5});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_sourceTokens[1], amount: 1});
+
+ vm.startPrank(MOCK_ONRAMP);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed((5 * TOKEN_PRICE) / 1e18);
+
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+ }
+
+ function test_onOutboundMessage_ValidateMessageWithRateLimitDisabled_Success() public {
+ MultiAggregateRateLimiter.RateLimiterConfigArgs[] memory configUpdates =
+ new MultiAggregateRateLimiter.RateLimiterConfigArgs[](1);
+ configUpdates[0] = MultiAggregateRateLimiter.RateLimiterConfigArgs({
+ remoteChainSelector: CHAIN_SELECTOR_1,
+ isOutboundLane: true,
+ rateLimiterConfig: RATE_LIMITER_CONFIG_1
+ });
+ configUpdates[0].rateLimiterConfig.isEnabled = false;
+
+ s_rateLimiter.applyRateLimiterConfigUpdates(configUpdates);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 1000});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_sourceTokens[1], amount: 50});
+
+ vm.startPrank(MOCK_ONRAMP);
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+
+ // No consumed rate limit events
+ assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ function test_onOutboundMessage_ValidateMessageWithTokensOnDifferentChains_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory tokensToAdd =
+ new MultiAggregateRateLimiter.RateLimitTokenArgs[](s_sourceTokens.length);
+ for (uint224 i = 0; i < s_sourceTokens.length; ++i) {
+ tokensToAdd[i] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ localToken: s_sourceTokens[i]
+ }),
+ // Create a remote token address that is different from CHAIN_SELECTOR_1
+ remoteToken: bytes32(uint256(uint160(s_destTokenBySourceToken[s_sourceTokens[i]])) + type(uint160).max + 1)
+ });
+ }
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), tokensToAdd);
+
+ vm.startPrank(MOCK_ONRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 2});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_sourceTokens[1], amount: 1});
+
+ // 2 tokens * (TOKEN_PRICE) + 1 token * (2 * TOKEN_PRICE)
+ uint256 totalValue = (4 * TOKEN_PRICE) / 1e18;
+
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Chain 1 changed
+ RateLimiter.TokenBucket memory bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 unchanged
+ RateLimiter.TokenBucket memory bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, true);
+ assertEq(bucketChain2.capacity, bucketChain2.tokens);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(totalValue);
+
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_2, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Chain 1 unchanged
+ bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 changed
+ bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, true);
+ assertEq(bucketChain2.capacity - totalValue, bucketChain2.tokens);
+ }
+
+ function test_onOutboundMessage_ValidateMessageWithDifferentTokensOnDifferentChains_Success() public {
+ MultiAggregateRateLimiter.RateLimitTokenArgs[] memory tokensToAdd =
+ new MultiAggregateRateLimiter.RateLimitTokenArgs[](1);
+
+ // Only 1 rate limited token on different chain
+ tokensToAdd[0] = MultiAggregateRateLimiter.RateLimitTokenArgs({
+ localTokenArgs: MultiAggregateRateLimiter.LocalRateLimitToken({
+ remoteChainSelector: CHAIN_SELECTOR_2,
+ localToken: s_sourceTokens[0]
+ }),
+ // Create a remote token address that is different from CHAIN_SELECTOR_1
+ remoteToken: bytes32(uint256(uint160(s_destTokenBySourceToken[s_sourceTokens[0]])) + type(uint160).max + 1)
+ });
+ s_rateLimiter.updateRateLimitTokens(new MultiAggregateRateLimiter.LocalRateLimitToken[](0), tokensToAdd);
+
+ vm.startPrank(MOCK_ONRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 3});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_sourceTokens[1], amount: 1});
+
+ // 3 tokens * (TOKEN_PRICE) + 1 token * (2 * TOKEN_PRICE)
+ uint256 totalValue = (5 * TOKEN_PRICE) / 1e18;
+
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Chain 1 changed
+ RateLimiter.TokenBucket memory bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 unchanged
+ RateLimiter.TokenBucket memory bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, true);
+ assertEq(bucketChain2.capacity, bucketChain2.tokens);
+
+ // 3 tokens * (TOKEN_PRICE)
+ uint256 totalValue2 = (3 * TOKEN_PRICE) / 1e18;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(totalValue2);
+
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_2, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Chain 1 unchanged
+ bucketChain1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ assertEq(bucketChain1.capacity - totalValue, bucketChain1.tokens);
+
+ // Chain 2 changed
+ bucketChain2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_2, true);
+ assertEq(bucketChain2.capacity - totalValue2, bucketChain2.tokens);
+ }
+
+ function test_onOutboundMessage_ValidateMessageWithRateLimitReset_Success() public {
+ vm.startPrank(MOCK_ONRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 20});
+
+ // Remaining capacity: 100 -> 20
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Cannot fit 80 rate limit value (need to wait at least 12 blocks, current capacity is 20)
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, 12, 20));
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Remaining capacity: 20 -> 35 (need to wait 9 more blocks)
+ vm.warp(BLOCK_TIME + 3);
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueRateLimitReached.selector, 9, 35));
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+
+ // Remaining capacity: 35 -> 80 (can fit exactly 80)
+ vm.warp(BLOCK_TIME + 12);
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+ }
+
+ function test_RateLimitValueDifferentLanes_Success() public {
+ vm.pauseGasMetering();
+ // start from blocktime that does not equal rate limiter init timestamp
+ vm.warp(BLOCK_TIME + 1);
+
+ // 10 (tokens) * 4 (price) * 2 (number of times) = 80 < 100 (capacity)
+ uint256 numberOfTokens = 10;
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: numberOfTokens});
+ uint256 value = (numberOfTokens * TOKEN_PRICE) / 1e18;
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(value);
+
+ vm.resumeGasMetering();
+ vm.startPrank(MOCK_ONRAMP);
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+ vm.pauseGasMetering();
+
+ // Get the updated bucket status
+ RateLimiter.TokenBucket memory bucket1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ RateLimiter.TokenBucket memory bucket2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+
+ // Assert the proper value has been taken out of the bucket
+ assertEq(bucket1.capacity - value, bucket1.tokens);
+ // Inbound lane should remain unchanged
+ assertEq(bucket2.capacity, bucket2.tokens);
+
+ vm.expectEmit();
+ emit RateLimiter.TokensConsumed(value);
+
+ vm.resumeGasMetering();
+ s_rateLimiter.onInboundMessage(_generateAny2EVMMessage(CHAIN_SELECTOR_1, tokenAmounts));
+ vm.pauseGasMetering();
+
+ bucket1 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, true);
+ bucket2 = s_rateLimiter.currentRateLimiterState(CHAIN_SELECTOR_1, false);
+
+ // Inbound lane should remain unchanged
+ assertEq(bucket1.capacity - value, bucket1.tokens);
+ assertEq(bucket2.capacity - value, bucket2.tokens);
+ }
+
+ // Reverts
+
+ function test_onOutboundMessage_ValidateMessageWithRateLimitExceeded_Revert() public {
+ vm.startPrank(MOCK_OFFRAMP);
+
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](2);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: s_sourceTokens[0], amount: 80});
+ tokenAmounts[1] = Client.EVMTokenAmount({token: s_sourceTokens[1], amount: 30});
+
+ uint256 totalValue = (80 * TOKEN_PRICE + 2 * (30 * TOKEN_PRICE)) / 1e18;
+ vm.expectRevert(abi.encodeWithSelector(RateLimiter.AggregateValueMaxCapacityExceeded.selector, 100, totalValue));
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessage(tokenAmounts));
+ }
+
+ function test_onOutboundMessage_ValidateMessageFromUnauthorizedCaller_Revert() public {
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(abi.encodeWithSelector(AuthorizedCallers.UnauthorizedCaller.selector, STRANGER));
+ s_rateLimiter.onOutboundMessage(CHAIN_SELECTOR_1, _generateEVM2AnyMessageNoTokens());
+ }
+
+ function _generateEVM2AnyMessage(Client.EVMTokenAmount[] memory tokenAmounts)
+ public
+ view
+ returns (Client.EVM2AnyMessage memory)
+ {
+ return Client.EVM2AnyMessage({
+ receiver: abi.encode(OWNER),
+ data: "",
+ tokenAmounts: tokenAmounts,
+ feeToken: s_sourceFeeToken,
+ extraArgs: Client._argsToBytes(Client.EVMExtraArgsV1({gasLimit: GAS_LIMIT}))
+ });
+ }
+
+ function _generateEVM2AnyMessageNoTokens() internal view returns (Client.EVM2AnyMessage memory) {
+ return _generateEVM2AnyMessage(new Client.EVMTokenAmount[](0));
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/router/Router.t.sol b/contracts/src/v0.8/ccip/test/router/Router.t.sol
new file mode 100644
index 00000000000..cfe01e3c417
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/router/Router.t.sol
@@ -0,0 +1,889 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IAny2EVMMessageReceiver} from "../../interfaces/IAny2EVMMessageReceiver.sol";
+import {IRouter} from "../../interfaces/IRouter.sol";
+import {IRouterClient} from "../../interfaces/IRouterClient.sol";
+import {IWrappedNative} from "../../interfaces/IWrappedNative.sol";
+
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {EVM2EVMOnRamp} from "../../onRamp/EVM2EVMOnRamp.sol";
+import {MaybeRevertMessageReceiver} from "../helpers/receivers/MaybeRevertMessageReceiver.sol";
+import {EVM2EVMOffRampSetup} from "../offRamp/EVM2EVMOffRampSetup.t.sol";
+import {EVM2EVMOnRampSetup} from "../onRamp/EVM2EVMOnRampSetup.t.sol";
+import {RouterSetup} from "../router/RouterSetup.t.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract Router_constructor is EVM2EVMOnRampSetup {
+ function test_Constructor_Success() public view {
+ assertEq("Router 1.2.0", s_sourceRouter.typeAndVersion());
+ assertEq(OWNER, s_sourceRouter.owner());
+ }
+}
+
+contract Router_recoverTokens is EVM2EVMOnRampSetup {
+ function test_RecoverTokens_Success() public {
+ // Assert we can recover sourceToken
+ IERC20 token = IERC20(s_sourceTokens[0]);
+ uint256 balanceBefore = token.balanceOf(OWNER);
+ token.transfer(address(s_sourceRouter), 1);
+ assertEq(token.balanceOf(address(s_sourceRouter)), 1);
+ s_sourceRouter.recoverTokens(address(token), OWNER, 1);
+ assertEq(token.balanceOf(address(s_sourceRouter)), 0);
+ assertEq(token.balanceOf(OWNER), balanceBefore);
+
+ // Assert we can recover native
+ balanceBefore = OWNER.balance;
+ deal(address(s_sourceRouter), 10);
+ assertEq(address(s_sourceRouter).balance, 10);
+ s_sourceRouter.recoverTokens(address(0), OWNER, 10);
+ assertEq(OWNER.balance, balanceBefore + 10);
+ assertEq(address(s_sourceRouter).balance, 0);
+ }
+
+ function test_RecoverTokensNonOwner_Revert() public {
+ // Reverts if not owner
+ vm.startPrank(STRANGER);
+ vm.expectRevert("Only callable by owner");
+ s_sourceRouter.recoverTokens(address(0), STRANGER, 1);
+ }
+
+ function test_RecoverTokensInvalidRecipient_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(Router.InvalidRecipientAddress.selector, address(0)));
+ s_sourceRouter.recoverTokens(address(0), address(0), 1);
+ }
+
+ function test_RecoverTokensNoFunds_Revert() public {
+ // Reverts if no funds present
+ vm.expectRevert();
+ s_sourceRouter.recoverTokens(address(0), OWNER, 10);
+ }
+
+ function test_RecoverTokensValueReceiver_Revert() public {
+ MaybeRevertMessageReceiver revertingValueReceiver = new MaybeRevertMessageReceiver(true);
+ deal(address(s_sourceRouter), 10);
+
+ // Value receiver reverts
+ vm.expectRevert(Router.FailedToSendValue.selector);
+ s_sourceRouter.recoverTokens(address(0), address(revertingValueReceiver), 10);
+ }
+}
+
+contract Router_ccipSend is EVM2EVMOnRampSetup {
+ event Burned(address indexed sender, uint256 amount);
+
+ function test_CCIPSendLinkFeeOneTokenSuccess_gas() public {
+ vm.pauseGasMetering();
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ IERC20 sourceToken1 = IERC20(s_sourceTokens[1]);
+ sourceToken1.approve(address(s_sourceRouter), 2 ** 64);
+
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 2 ** 64;
+ message.tokenAmounts[0].token = s_sourceTokens[1];
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ assertGt(expectedFee, 0);
+
+ uint256 balanceBefore = sourceToken1.balanceOf(OWNER);
+
+ // Assert that the tokens are burned
+ vm.expectEmit();
+ emit Burned(address(s_onRamp), message.tokenAmounts[0].amount);
+
+ Internal.EVM2EVMMessage memory msgEvent = _messageToEvent(message, 1, 1, expectedFee, OWNER);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ bytes32 messageId = s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ vm.pauseGasMetering();
+
+ assertEq(msgEvent.messageId, messageId);
+ // Assert the user balance is lowered by the tokenAmounts sent and the fee amount
+ uint256 expectedBalance = balanceBefore - (message.tokenAmounts[0].amount);
+ assertEq(expectedBalance, sourceToken1.balanceOf(OWNER));
+ vm.resumeGasMetering();
+ }
+
+ function test_CCIPSendLinkFeeNoTokenSuccess_gas() public {
+ vm.pauseGasMetering();
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ assertGt(expectedFee, 0);
+
+ Internal.EVM2EVMMessage memory msgEvent = _messageToEvent(message, 1, 1, expectedFee, OWNER);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ bytes32 messageId = s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ vm.pauseGasMetering();
+
+ assertEq(msgEvent.messageId, messageId);
+ vm.resumeGasMetering();
+ }
+
+ function test_CCIPSendNativeFeeOneTokenSuccess_gas() public {
+ vm.pauseGasMetering();
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ IERC20 sourceToken1 = IERC20(s_sourceTokens[1]);
+ sourceToken1.approve(address(s_sourceRouter), 2 ** 64);
+
+ message.tokenAmounts = new Client.EVMTokenAmount[](1);
+ message.tokenAmounts[0].amount = 2 ** 64;
+ message.tokenAmounts[0].token = s_sourceTokens[1];
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ assertGt(expectedFee, 0);
+
+ uint256 balanceBefore = sourceToken1.balanceOf(OWNER);
+
+ // Assert that the tokens are burned
+ vm.expectEmit();
+ emit Burned(address(s_onRamp), message.tokenAmounts[0].amount);
+
+ // Native fees will be wrapped so we need to calculate the event with
+ // the wrapped native feeCoin address.
+ message.feeToken = s_sourceRouter.getWrappedNative();
+ Internal.EVM2EVMMessage memory msgEvent = _messageToEvent(message, 1, 1, expectedFee, OWNER);
+ // Set it to address(0) to indicate native
+ message.feeToken = address(0);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ bytes32 messageId = s_sourceRouter.ccipSend{value: expectedFee}(DEST_CHAIN_SELECTOR, message);
+ vm.pauseGasMetering();
+
+ assertEq(msgEvent.messageId, messageId);
+ // Assert the user balance is lowered by the tokenAmounts sent and the fee amount
+ uint256 expectedBalance = balanceBefore - (message.tokenAmounts[0].amount);
+ assertEq(expectedBalance, sourceToken1.balanceOf(OWNER));
+ vm.resumeGasMetering();
+ }
+
+ function test_CCIPSendNativeFeeNoTokenSuccess_gas() public {
+ vm.pauseGasMetering();
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ assertGt(expectedFee, 0);
+
+ // Native fees will be wrapped so we need to calculate the event with
+ // the wrapped native feeCoin address.
+ message.feeToken = s_sourceRouter.getWrappedNative();
+ Internal.EVM2EVMMessage memory msgEvent = _messageToEvent(message, 1, 1, expectedFee, OWNER);
+ // Set it to address(0) to indicate native
+ message.feeToken = address(0);
+
+ vm.expectEmit();
+ emit EVM2EVMOnRamp.CCIPSendRequested(msgEvent);
+
+ vm.resumeGasMetering();
+ bytes32 messageId = s_sourceRouter.ccipSend{value: expectedFee}(DEST_CHAIN_SELECTOR, message);
+ vm.pauseGasMetering();
+
+ assertEq(msgEvent.messageId, messageId);
+ // Assert the user balance is lowered by the tokenAmounts sent and the fee amount
+ vm.resumeGasMetering();
+ }
+
+ function test_NonLinkFeeToken_Success() public {
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] memory feeTokenConfigArgs = new EVM2EVMOnRamp.FeeTokenConfigArgs[](1);
+ feeTokenConfigArgs[0] = EVM2EVMOnRamp.FeeTokenConfigArgs({
+ token: s_sourceTokens[1],
+ networkFeeUSDCents: 1,
+ gasMultiplierWeiPerEth: 108e16,
+ premiumMultiplierWeiPerEth: 1e18,
+ enabled: true
+ });
+ s_onRamp.setFeeTokenConfig(feeTokenConfigArgs);
+
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = s_sourceTokens[1];
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = s_sourceTokens[1];
+ IERC20(s_sourceTokens[1]).approve(address(s_sourceRouter), 2 ** 64);
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_NativeFeeToken_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = address(0); // Raw native
+ uint256 nativeQuote = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ vm.stopPrank();
+ hoax(address(1), 100 ether);
+ s_sourceRouter.ccipSend{value: nativeQuote}(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_NativeFeeTokenOverpay_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = address(0); // Raw native
+ uint256 nativeQuote = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ vm.stopPrank();
+ hoax(address(1), 100 ether);
+ s_sourceRouter.ccipSend{value: nativeQuote + 1}(DEST_CHAIN_SELECTOR, message);
+ // We expect the overpayment to be taken in full.
+ assertEq(address(1).balance, 100 ether - (nativeQuote + 1));
+ assertEq(address(s_sourceRouter).balance, 0);
+ }
+
+ function test_WrappedNativeFeeToken_Success() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = s_sourceRouter.getWrappedNative();
+ uint256 nativeQuote = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ vm.stopPrank();
+ hoax(address(1), 100 ether);
+ // Now address(1) has nativeQuote wrapped.
+ IWrappedNative(s_sourceRouter.getWrappedNative()).deposit{value: nativeQuote}();
+ IWrappedNative(s_sourceRouter.getWrappedNative()).approve(address(s_sourceRouter), nativeQuote);
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ // Since sending with zero fees is a legitimate use case for some destination
+ // chains, e.g. private chains, we want to make sure that we can still send even
+ // when the configured fee is 0.
+ function test_ZeroFeeAndGasPrice_Success() public {
+ // Configure a new fee token that has zero gas and zero fees but is still
+ // enabled and valid to pay with.
+ address feeTokenWithZeroFeeAndGas = s_sourceTokens[1];
+
+ // Set the new token as feeToken
+ address[] memory feeTokens = new address[](1);
+ feeTokens[0] = feeTokenWithZeroFeeAndGas;
+ s_priceRegistry.applyFeeTokensUpdates(feeTokens, new address[](0));
+
+ // Update the price of the newly set feeToken
+ Internal.PriceUpdates memory priceUpdates = getSingleTokenPriceUpdateStruct(feeTokenWithZeroFeeAndGas, 2_000 ether);
+ priceUpdates.gasPriceUpdates = getSingleGasPriceUpdateStruct(DEST_CHAIN_SELECTOR, 0).gasPriceUpdates;
+ s_priceRegistry.updatePrices(priceUpdates);
+
+ // Set the feeToken args on the onRamp
+ EVM2EVMOnRamp.FeeTokenConfigArgs[] memory feeTokenConfigArgs = new EVM2EVMOnRamp.FeeTokenConfigArgs[](1);
+ feeTokenConfigArgs[0] = EVM2EVMOnRamp.FeeTokenConfigArgs({
+ token: s_sourceTokens[1],
+ networkFeeUSDCents: 0,
+ gasMultiplierWeiPerEth: 108e16,
+ premiumMultiplierWeiPerEth: 1e18,
+ enabled: true
+ });
+
+ s_onRamp.setFeeTokenConfig(feeTokenConfigArgs);
+
+ // Send a message with the new feeToken
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = feeTokenWithZeroFeeAndGas;
+
+ // Fee should be 0 and sending should not revert
+ uint256 fee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ assertEq(fee, 0);
+
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ // Reverts
+
+ function test_WhenNotHealthy_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(Router.BadARMSignal.selector);
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_UnsupportedDestinationChain_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint64 wrongChain = DEST_CHAIN_SELECTOR + 1;
+
+ vm.expectRevert(abi.encodeWithSelector(IRouterClient.UnsupportedDestinationChain.selector, wrongChain));
+
+ s_sourceRouter.ccipSend(wrongChain, message);
+ }
+
+ function test_Fuzz_UnsupportedFeeToken_Reverts(address wrongFeeToken) public {
+ // We have three fee tokens set, all others should revert.
+ vm.assume(address(s_sourceFeeToken) != wrongFeeToken);
+ vm.assume(address(s_sourceRouter.getWrappedNative()) != wrongFeeToken);
+ vm.assume(address(0) != wrongFeeToken);
+
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = wrongFeeToken;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.NotAFeeToken.selector, wrongFeeToken));
+
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_Fuzz_UnsupportedToken_Reverts(address wrongToken) public {
+ for (uint256 i = 0; i < s_sourceTokens.length; ++i) {
+ vm.assume(address(s_sourceTokens[i]) != wrongToken);
+ }
+
+ for (uint256 i = 0; i < s_destTokens.length; ++i) {
+ vm.assume(address(s_destTokens[i]) != wrongToken);
+ }
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ Client.EVMTokenAmount[] memory tokenAmounts = new Client.EVMTokenAmount[](1);
+ tokenAmounts[0] = Client.EVMTokenAmount({token: wrongToken, amount: 1});
+ message.tokenAmounts = tokenAmounts;
+
+ vm.expectRevert(abi.encodeWithSelector(EVM2EVMOnRamp.UnsupportedToken.selector, wrongToken));
+
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_FeeTokenAmountTooLow_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ IERC20(s_sourceTokens[0]).approve(address(s_sourceRouter), 0);
+
+ vm.expectRevert("ERC20: insufficient allowance");
+
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_InvalidMsgValue() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ // Non-empty feeToken but with msg.value should revert
+ vm.stopPrank();
+ hoax(address(1), 1);
+ vm.expectRevert(IRouterClient.InvalidMsgValue.selector);
+ s_sourceRouter.ccipSend{value: 1}(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_NativeFeeTokenZeroValue() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = address(0); // Raw native
+ // Include no value, should revert
+ vm.expectRevert();
+ s_sourceRouter.ccipSend(DEST_CHAIN_SELECTOR, message);
+ }
+
+ function test_NativeFeeTokenInsufficientValue() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ message.feeToken = address(0); // Raw native
+ // Include insufficient, should also revert
+ vm.stopPrank();
+
+ s_onRamp.getFeeTokenConfig(s_sourceRouter.getWrappedNative());
+
+ hoax(address(1), 1);
+ vm.expectRevert(IRouterClient.InsufficientFeeTokenAmount.selector);
+ s_sourceRouter.ccipSend{value: 1}(DEST_CHAIN_SELECTOR, message);
+ }
+}
+
+contract Router_getArmProxy is RouterSetup {
+ function test_getArmProxy() public view {
+ assertEq(s_sourceRouter.getArmProxy(), address(s_mockRMN));
+ }
+}
+
+contract Router_applyRampUpdates is RouterSetup {
+ MaybeRevertMessageReceiver internal s_receiver;
+
+ function setUp() public virtual override(RouterSetup) {
+ RouterSetup.setUp();
+ s_receiver = new MaybeRevertMessageReceiver(false);
+ }
+
+ function assertOffRampRouteSucceeds(Router.OffRamp memory offRamp) internal {
+ vm.startPrank(offRamp.offRamp);
+
+ Client.Any2EVMMessage memory message = generateReceiverMessage(offRamp.sourceChainSelector);
+ vm.expectCall(address(s_receiver), abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message));
+ s_sourceRouter.routeMessage(message, GAS_FOR_CALL_EXACT_CHECK, 100_000, address(s_receiver));
+ }
+
+ function assertOffRampRouteReverts(Router.OffRamp memory offRamp) internal {
+ vm.startPrank(offRamp.offRamp);
+
+ vm.expectRevert(IRouter.OnlyOffRamp.selector);
+ s_sourceRouter.routeMessage(
+ generateReceiverMessage(offRamp.sourceChainSelector), GAS_FOR_CALL_EXACT_CHECK, 100_000, address(s_receiver)
+ );
+ }
+
+ function test_Fuzz_OffRampUpdates(address[20] memory offRampsInput) public {
+ Router.OffRamp[] memory offRamps = new Router.OffRamp[](20);
+
+ for (uint256 i = 0; i < offRampsInput.length; ++i) {
+ offRamps[i] = Router.OffRamp({sourceChainSelector: uint64(i), offRamp: offRampsInput[i]});
+ }
+
+ // Test adding offRamps
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), new Router.OffRamp[](0), offRamps);
+
+ // There is no uniqueness guarantee on fuzz input, offRamps will not emit in case of a duplicate,
+ // hence cannot assert on number of offRamps event emissions, we need to use isOffRa
+ for (uint256 i = 0; i < offRamps.length; ++i) {
+ assertTrue(s_sourceRouter.isOffRamp(offRamps[i].sourceChainSelector, offRamps[i].offRamp));
+ }
+
+ // Test removing offRamps
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), s_sourceRouter.getOffRamps(), new Router.OffRamp[](0));
+
+ assertEq(0, s_sourceRouter.getOffRamps().length);
+ for (uint256 i = 0; i < offRamps.length; ++i) {
+ assertFalse(s_sourceRouter.isOffRamp(offRamps[i].sourceChainSelector, offRamps[i].offRamp));
+ }
+
+ // Testing removing and adding in same call
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), new Router.OffRamp[](0), offRamps);
+ s_sourceRouter.applyRampUpdates(new Router.OnRamp[](0), offRamps, offRamps);
+ for (uint256 i = 0; i < offRamps.length; ++i) {
+ assertTrue(s_sourceRouter.isOffRamp(offRamps[i].sourceChainSelector, offRamps[i].offRamp));
+ }
+ }
+
+ function test_OffRampUpdatesWithRouting() public {
+ // Explicitly construct chain selectors and ramp addresses so we have ramp uniqueness for the various test scenarios.
+ uint256 numberOfSelectors = 10;
+ uint64[] memory sourceChainSelectors = new uint64[](numberOfSelectors);
+ for (uint256 i = 0; i < numberOfSelectors; ++i) {
+ sourceChainSelectors[i] = uint64(i);
+ }
+
+ uint256 numberOfOffRamps = 5;
+ address[] memory offRamps = new address[](numberOfOffRamps);
+ for (uint256 i = 0; i < numberOfOffRamps; ++i) {
+ offRamps[i] = address(uint160(i * 10));
+ }
+
+ // 1st test scenario: add offramps.
+ // Check all the offramps are added correctly, and can route messages.
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](0);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](numberOfSelectors * numberOfOffRamps);
+
+ // Ensure there are multi-offramp source and multi-source offramps
+ for (uint256 i = 0; i < numberOfSelectors; ++i) {
+ for (uint256 j = 0; j < numberOfOffRamps; ++j) {
+ offRampUpdates[(i * numberOfOffRamps) + j] = Router.OffRamp(sourceChainSelectors[i], offRamps[j]);
+ }
+ }
+
+ for (uint256 i = 0; i < offRampUpdates.length; ++i) {
+ vm.expectEmit();
+ emit Router.OffRampAdded(offRampUpdates[i].sourceChainSelector, offRampUpdates[i].offRamp);
+ }
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+
+ Router.OffRamp[] memory gotOffRamps = s_sourceRouter.getOffRamps();
+ assertEq(offRampUpdates.length, gotOffRamps.length);
+
+ for (uint256 i = 0; i < offRampUpdates.length; ++i) {
+ assertEq(offRampUpdates[i].offRamp, gotOffRamps[i].offRamp);
+ assertTrue(s_sourceRouter.isOffRamp(offRampUpdates[i].sourceChainSelector, offRampUpdates[i].offRamp));
+ assertOffRampRouteSucceeds(offRampUpdates[i]);
+ }
+
+ vm.startPrank(OWNER);
+
+ // 2nd test scenario: partially remove existing offramps, add new offramps.
+ // Check offramps are removed correctly. Removed offramps cannot route messages.
+ // Check new offramps are added correctly. New offramps can route messages.
+ // Check unmodified offramps remain correct, and can still route messages.
+ uint256 numberOfPartialUpdates = offRampUpdates.length / 2;
+ Router.OffRamp[] memory partialOffRampRemoves = new Router.OffRamp[](numberOfPartialUpdates);
+ Router.OffRamp[] memory partialOffRampAdds = new Router.OffRamp[](numberOfPartialUpdates);
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ partialOffRampRemoves[i] = offRampUpdates[i];
+ partialOffRampAdds[i] = Router.OffRamp({
+ sourceChainSelector: offRampUpdates[i].sourceChainSelector,
+ offRamp: address(uint160(offRampUpdates[i].offRamp) + 1e18) // Ensure unique new offRamps addresses
+ });
+ }
+
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ vm.expectEmit();
+ emit Router.OffRampRemoved(partialOffRampRemoves[i].sourceChainSelector, partialOffRampRemoves[i].offRamp);
+ }
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ vm.expectEmit();
+ emit Router.OffRampAdded(partialOffRampAdds[i].sourceChainSelector, partialOffRampAdds[i].offRamp);
+ }
+ s_sourceRouter.applyRampUpdates(onRampUpdates, partialOffRampRemoves, partialOffRampAdds);
+
+ gotOffRamps = s_sourceRouter.getOffRamps();
+ assertEq(offRampUpdates.length, gotOffRamps.length);
+
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ assertFalse(
+ s_sourceRouter.isOffRamp(partialOffRampRemoves[i].sourceChainSelector, partialOffRampRemoves[i].offRamp)
+ );
+ assertOffRampRouteReverts(partialOffRampRemoves[i]);
+
+ assertTrue(s_sourceRouter.isOffRamp(partialOffRampAdds[i].sourceChainSelector, partialOffRampAdds[i].offRamp));
+ assertOffRampRouteSucceeds(partialOffRampAdds[i]);
+ }
+ for (uint256 i = numberOfPartialUpdates; i < offRampUpdates.length; ++i) {
+ assertTrue(s_sourceRouter.isOffRamp(offRampUpdates[i].sourceChainSelector, offRampUpdates[i].offRamp));
+ assertOffRampRouteSucceeds(offRampUpdates[i]);
+ }
+
+ vm.startPrank(OWNER);
+
+ // 3rd test scenario: remove all offRamps.
+ // Check all offramps have been removed, no offramp is able to route messages.
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ vm.expectEmit();
+ emit Router.OffRampRemoved(partialOffRampAdds[i].sourceChainSelector, partialOffRampAdds[i].offRamp);
+ }
+ s_sourceRouter.applyRampUpdates(onRampUpdates, partialOffRampAdds, new Router.OffRamp[](0));
+
+ uint256 numberOfRemainingOfframps = offRampUpdates.length - numberOfPartialUpdates;
+ Router.OffRamp[] memory remainingOffRampRemoves = new Router.OffRamp[](numberOfRemainingOfframps);
+ for (uint256 i = 0; i < numberOfRemainingOfframps; ++i) {
+ remainingOffRampRemoves[i] = offRampUpdates[i + numberOfPartialUpdates];
+ }
+
+ for (uint256 i = 0; i < numberOfRemainingOfframps; ++i) {
+ vm.expectEmit();
+ emit Router.OffRampRemoved(remainingOffRampRemoves[i].sourceChainSelector, remainingOffRampRemoves[i].offRamp);
+ }
+ s_sourceRouter.applyRampUpdates(onRampUpdates, remainingOffRampRemoves, new Router.OffRamp[](0));
+
+ // Check there are no offRamps.
+ assertEq(0, s_sourceRouter.getOffRamps().length);
+
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ assertFalse(s_sourceRouter.isOffRamp(partialOffRampAdds[i].sourceChainSelector, partialOffRampAdds[i].offRamp));
+ assertOffRampRouteReverts(partialOffRampAdds[i]);
+ }
+ for (uint256 i = 0; i < offRampUpdates.length; ++i) {
+ assertFalse(s_sourceRouter.isOffRamp(offRampUpdates[i].sourceChainSelector, offRampUpdates[i].offRamp));
+ assertOffRampRouteReverts(offRampUpdates[i]);
+ }
+
+ vm.startPrank(OWNER);
+
+ // 4th test scenario: add initial onRamps back.
+ // Check the offramps are added correctly, and can route messages.
+ // Check offramps that were not added back remain unset, and cannot route messages.
+ for (uint256 i = 0; i < offRampUpdates.length; ++i) {
+ vm.expectEmit();
+ emit Router.OffRampAdded(offRampUpdates[i].sourceChainSelector, offRampUpdates[i].offRamp);
+ }
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+
+ // Check initial offRamps are added back and can route to receiver.
+ gotOffRamps = s_sourceRouter.getOffRamps();
+ assertEq(offRampUpdates.length, gotOffRamps.length);
+
+ for (uint256 i = 0; i < offRampUpdates.length; ++i) {
+ assertEq(offRampUpdates[i].offRamp, gotOffRamps[i].offRamp);
+ assertTrue(s_sourceRouter.isOffRamp(offRampUpdates[i].sourceChainSelector, offRampUpdates[i].offRamp));
+ assertOffRampRouteSucceeds(offRampUpdates[i]);
+ }
+
+ // Check offramps that were not added back remain unset.
+ for (uint256 i = 0; i < numberOfPartialUpdates; ++i) {
+ assertFalse(s_sourceRouter.isOffRamp(partialOffRampAdds[i].sourceChainSelector, partialOffRampAdds[i].offRamp));
+ assertOffRampRouteReverts(partialOffRampAdds[i]);
+ }
+ }
+
+ function test_Fuzz_OnRampUpdates(Router.OnRamp[] memory onRamps) public {
+ // Test adding onRamps
+ for (uint256 i = 0; i < onRamps.length; ++i) {
+ vm.expectEmit();
+ emit Router.OnRampSet(onRamps[i].destChainSelector, onRamps[i].onRamp);
+ }
+
+ s_sourceRouter.applyRampUpdates(onRamps, new Router.OffRamp[](0), new Router.OffRamp[](0));
+
+ // Test setting onRamps to unsupported
+ for (uint256 i = 0; i < onRamps.length; ++i) {
+ onRamps[i].onRamp = address(0);
+
+ vm.expectEmit();
+ emit Router.OnRampSet(onRamps[i].destChainSelector, onRamps[i].onRamp);
+ }
+ s_sourceRouter.applyRampUpdates(onRamps, new Router.OffRamp[](0), new Router.OffRamp[](0));
+ for (uint256 i = 0; i < onRamps.length; ++i) {
+ assertEq(address(0), s_sourceRouter.getOnRamp(onRamps[i].destChainSelector));
+ assertFalse(s_sourceRouter.isChainSupported(onRamps[i].destChainSelector));
+ }
+ }
+
+ function test_OnRampDisable() public {
+ // Add onRamp
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](1);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](0);
+ address onRamp = address(uint160(2));
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: onRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+ assertEq(onRamp, s_sourceRouter.getOnRamp(DEST_CHAIN_SELECTOR));
+ assertTrue(s_sourceRouter.isChainSupported(DEST_CHAIN_SELECTOR));
+
+ // Disable onRamp
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: address(0)});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), new Router.OffRamp[](0));
+ assertEq(address(0), s_sourceRouter.getOnRamp(DEST_CHAIN_SELECTOR));
+ assertFalse(s_sourceRouter.isChainSupported(DEST_CHAIN_SELECTOR));
+
+ // Re-enable onRamp
+ onRampUpdates[0] = Router.OnRamp({destChainSelector: DEST_CHAIN_SELECTOR, onRamp: onRamp});
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), new Router.OffRamp[](0));
+ assertEq(onRamp, s_sourceRouter.getOnRamp(DEST_CHAIN_SELECTOR));
+ assertTrue(s_sourceRouter.isChainSupported(DEST_CHAIN_SELECTOR));
+ }
+
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](0);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](0);
+ s_sourceRouter.applyRampUpdates(onRampUpdates, offRampUpdates, offRampUpdates);
+ }
+
+ function test_OffRampMismatch_Revert() public {
+ address offRamp = address(uint160(2));
+
+ Router.OnRamp[] memory onRampUpdates = new Router.OnRamp[](0);
+ Router.OffRamp[] memory offRampUpdates = new Router.OffRamp[](1);
+ offRampUpdates[0] = Router.OffRamp(DEST_CHAIN_SELECTOR, offRamp);
+
+ vm.expectEmit();
+ emit Router.OffRampAdded(DEST_CHAIN_SELECTOR, offRamp);
+ s_sourceRouter.applyRampUpdates(onRampUpdates, new Router.OffRamp[](0), offRampUpdates);
+
+ offRampUpdates[0] = Router.OffRamp(SOURCE_CHAIN_SELECTOR, offRamp);
+
+ vm.expectRevert(abi.encodeWithSelector(Router.OffRampMismatch.selector, SOURCE_CHAIN_SELECTOR, offRamp));
+ s_sourceRouter.applyRampUpdates(onRampUpdates, offRampUpdates, offRampUpdates);
+ }
+}
+
+contract Router_setWrappedNative is EVM2EVMOnRampSetup {
+ function test_Fuzz_SetWrappedNative_Success(address wrappedNative) public {
+ s_sourceRouter.setWrappedNative(wrappedNative);
+ assertEq(wrappedNative, s_sourceRouter.getWrappedNative());
+ }
+
+ // Reverts
+ function test_OnlyOwner_Revert() public {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ s_sourceRouter.setWrappedNative(address(1));
+ }
+}
+
+contract Router_getSupportedTokens is EVM2EVMOnRampSetup {
+ function test_GetSupportedTokens_Revert() public {
+ vm.expectRevert(EVM2EVMOnRamp.GetSupportedTokensFunctionalityRemovedCheckAdminRegistry.selector);
+ s_onRamp.getSupportedTokens(DEST_CHAIN_SELECTOR);
+ }
+}
+
+contract Router_routeMessage is EVM2EVMOffRampSetup {
+ function setUp() public virtual override {
+ EVM2EVMOffRampSetup.setUp();
+ vm.startPrank(address(s_offRamp));
+ }
+
+ function generateManualGasLimit(uint256 callDataLength) internal view returns (uint256) {
+ return ((gasleft() - 2 * (16 * callDataLength + GAS_FOR_CALL_EXACT_CHECK)) * 62) / 64;
+ }
+
+ function test_ManualExec_Success() public {
+ Client.Any2EVMMessage memory message = generateReceiverMessage(SOURCE_CHAIN_SELECTOR);
+ // Manuel execution cannot run out of gas
+
+ (bool success, bytes memory retData, uint256 gasUsed) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR),
+ GAS_FOR_CALL_EXACT_CHECK,
+ generateManualGasLimit(message.data.length),
+ address(s_receiver)
+ );
+ assertTrue(success);
+ assertEq("", retData);
+ assertGt(gasUsed, 3_000);
+ }
+
+ function test_ExecutionEvent_Success() public {
+ Client.Any2EVMMessage memory message = generateReceiverMessage(SOURCE_CHAIN_SELECTOR);
+ // Should revert with reason
+ bytes memory realError1 = new bytes(2);
+ realError1[0] = 0xbe;
+ realError1[1] = 0xef;
+ s_reverting_receiver.setErr(realError1);
+
+ vm.expectEmit();
+ emit Router.MessageExecuted(
+ message.messageId,
+ message.sourceChainSelector,
+ address(s_offRamp),
+ keccak256(abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message))
+ );
+
+ (bool success, bytes memory retData, uint256 gasUsed) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR),
+ GAS_FOR_CALL_EXACT_CHECK,
+ generateManualGasLimit(message.data.length),
+ address(s_reverting_receiver)
+ );
+
+ assertFalse(success);
+ assertEq(abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, realError1), retData);
+ assertGt(gasUsed, 3_000);
+
+ // Reason is truncated
+ // Over the MAX_RET_BYTES limit (including offset and length word since we have a dynamic values), should be ignored
+ bytes memory realError2 = new bytes(32 * 2 + 1);
+ realError2[32 * 2 - 1] = 0xAA;
+ realError2[32 * 2] = 0xFF;
+ s_reverting_receiver.setErr(realError2);
+
+ vm.expectEmit();
+ emit Router.MessageExecuted(
+ message.messageId,
+ message.sourceChainSelector,
+ address(s_offRamp),
+ keccak256(abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message))
+ );
+
+ (success, retData, gasUsed) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR),
+ GAS_FOR_CALL_EXACT_CHECK,
+ generateManualGasLimit(message.data.length),
+ address(s_reverting_receiver)
+ );
+
+ assertFalse(success);
+ assertEq(
+ abi.encodeWithSelector(
+ MaybeRevertMessageReceiver.CustomError.selector,
+ uint256(32),
+ uint256(realError2.length),
+ uint256(0),
+ uint256(0xAA)
+ ),
+ retData
+ );
+ assertGt(gasUsed, 3_000);
+
+ // Should emit success
+ vm.expectEmit();
+ emit Router.MessageExecuted(
+ message.messageId,
+ message.sourceChainSelector,
+ address(s_offRamp),
+ keccak256(abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message))
+ );
+
+ (success, retData, gasUsed) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR),
+ GAS_FOR_CALL_EXACT_CHECK,
+ generateManualGasLimit(message.data.length),
+ address(s_receiver)
+ );
+
+ assertTrue(success);
+ assertEq("", retData);
+ assertGt(gasUsed, 3_000);
+ }
+
+ function test_Fuzz_ExecutionEvent_Success(bytes calldata error) public {
+ Client.Any2EVMMessage memory message = generateReceiverMessage(SOURCE_CHAIN_SELECTOR);
+ s_reverting_receiver.setErr(error);
+
+ bytes memory expectedRetData;
+
+ if (error.length >= 33) {
+ uint256 cutOff = error.length > 64 ? 64 : error.length;
+ vm.expectEmit();
+ emit Router.MessageExecuted(
+ message.messageId,
+ message.sourceChainSelector,
+ address(s_offRamp),
+ keccak256(abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message))
+ );
+ expectedRetData = abi.encodeWithSelector(
+ MaybeRevertMessageReceiver.CustomError.selector,
+ uint256(32),
+ uint256(error.length),
+ bytes32(error[:32]),
+ bytes32(error[32:cutOff])
+ );
+ } else {
+ vm.expectEmit();
+ emit Router.MessageExecuted(
+ message.messageId,
+ message.sourceChainSelector,
+ address(s_offRamp),
+ keccak256(abi.encodeWithSelector(IAny2EVMMessageReceiver.ccipReceive.selector, message))
+ );
+ expectedRetData = abi.encodeWithSelector(MaybeRevertMessageReceiver.CustomError.selector, error);
+ }
+
+ (bool success, bytes memory retData,) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR),
+ GAS_FOR_CALL_EXACT_CHECK,
+ generateManualGasLimit(message.data.length),
+ address(s_reverting_receiver)
+ );
+
+ assertFalse(success);
+ assertEq(expectedRetData, retData);
+ }
+
+ function test_AutoExec_Success() public {
+ (bool success,,) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR), GAS_FOR_CALL_EXACT_CHECK, 100_000, address(s_receiver)
+ );
+
+ assertTrue(success);
+
+ (success,,) = s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR), GAS_FOR_CALL_EXACT_CHECK, 1, address(s_receiver)
+ );
+
+ // Can run out of gas, should return false
+ assertFalse(success);
+ }
+
+ // Reverts
+ function test_OnlyOffRamp_Revert() public {
+ vm.stopPrank();
+ vm.startPrank(STRANGER);
+
+ vm.expectRevert(IRouter.OnlyOffRamp.selector);
+ s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR), GAS_FOR_CALL_EXACT_CHECK, 100_000, address(s_receiver)
+ );
+ }
+
+ function test_WhenNotHealthy_Revert() public {
+ s_mockRMN.setGlobalCursed(true);
+ vm.expectRevert(Router.BadARMSignal.selector);
+ s_destRouter.routeMessage(
+ generateReceiverMessage(SOURCE_CHAIN_SELECTOR), GAS_FOR_CALL_EXACT_CHECK, 100_000, address(s_receiver)
+ );
+ }
+}
+
+contract Router_getFee is EVM2EVMOnRampSetup {
+ function test_GetFeeSupportedChain_Success() public view {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+ uint256 expectedFee = s_sourceRouter.getFee(DEST_CHAIN_SELECTOR, message);
+ assertGt(expectedFee, 10e9);
+ }
+
+ // Reverts
+ function test_UnsupportedDestinationChain_Revert() public {
+ Client.EVM2AnyMessage memory message = _generateEmptyMessage();
+
+ vm.expectRevert(abi.encodeWithSelector(IRouterClient.UnsupportedDestinationChain.selector, 999));
+ s_sourceRouter.getFee(999, message);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/router/RouterSetup.t.sol b/contracts/src/v0.8/ccip/test/router/RouterSetup.t.sol
new file mode 100644
index 00000000000..de751617612
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/router/RouterSetup.t.sol
@@ -0,0 +1,47 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Router} from "../../Router.sol";
+import {Client} from "../../libraries/Client.sol";
+import {Internal} from "../../libraries/Internal.sol";
+import {BaseTest} from "../BaseTest.t.sol";
+import {WETH9} from "../WETH9.sol";
+
+contract RouterSetup is BaseTest {
+ Router internal s_sourceRouter;
+ Router internal s_destRouter;
+
+ function setUp() public virtual override {
+ BaseTest.setUp();
+
+ if (address(s_sourceRouter) == address(0)) {
+ WETH9 weth = new WETH9();
+ s_sourceRouter = new Router(address(weth), address(s_mockRMN));
+ vm.label(address(s_sourceRouter), "sourceRouter");
+ }
+ if (address(s_destRouter) == address(0)) {
+ WETH9 weth = new WETH9();
+ s_destRouter = new Router(address(weth), address(s_mockRMN));
+ vm.label(address(s_destRouter), "destRouter");
+ }
+ }
+
+ function generateReceiverMessage(uint64 chainSelector) internal pure returns (Client.Any2EVMMessage memory) {
+ Client.EVMTokenAmount[] memory ta = new Client.EVMTokenAmount[](0);
+ return Client.Any2EVMMessage({
+ messageId: bytes32("a"),
+ sourceChainSelector: chainSelector,
+ sender: bytes("a"),
+ data: bytes("a"),
+ destTokenAmounts: ta
+ });
+ }
+
+ function generateSourceTokenData() internal pure returns (Internal.SourceTokenData memory) {
+ return Internal.SourceTokenData({
+ sourcePoolAddress: abi.encode(address(12312412312)),
+ destTokenAddress: abi.encode(address(9809808909)),
+ extraData: ""
+ });
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/tokenAdminRegistry/RegistryModuleOwnerCustom.t.sol b/contracts/src/v0.8/ccip/test/tokenAdminRegistry/RegistryModuleOwnerCustom.t.sol
new file mode 100644
index 00000000000..dfb599bd307
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/tokenAdminRegistry/RegistryModuleOwnerCustom.t.sol
@@ -0,0 +1,104 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IGetCCIPAdmin} from "../../interfaces/IGetCCIPAdmin.sol";
+import {IOwner} from "../../interfaces/IOwner.sol";
+
+import {RegistryModuleOwnerCustom} from "../../tokenAdminRegistry/RegistryModuleOwnerCustom.sol";
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+import {BurnMintERC677Helper} from "../helpers/BurnMintERC677Helper.sol";
+
+import {Test} from "forge-std/Test.sol";
+
+contract RegistryModuleOwnerCustomSetup is Test {
+ address internal constant OWNER = 0x00007e64E1fB0C487F25dd6D3601ff6aF8d32e4e;
+
+ RegistryModuleOwnerCustom internal s_registryModuleOwnerCustom;
+ TokenAdminRegistry internal s_tokenAdminRegistry;
+ address internal s_token;
+
+ function setUp() public virtual {
+ vm.startPrank(OWNER);
+
+ s_tokenAdminRegistry = new TokenAdminRegistry();
+ s_token = address(new BurnMintERC677Helper("Test", "TST"));
+ s_registryModuleOwnerCustom = new RegistryModuleOwnerCustom(address(s_tokenAdminRegistry));
+ s_tokenAdminRegistry.addRegistryModule(address(s_registryModuleOwnerCustom));
+ }
+}
+
+contract RegistryModuleOwnerCustom_constructor is RegistryModuleOwnerCustomSetup {
+ function test_constructor_Revert() public {
+ vm.expectRevert(abi.encodeWithSelector(RegistryModuleOwnerCustom.AddressZero.selector));
+
+ new RegistryModuleOwnerCustom(address(0));
+ }
+}
+
+contract RegistryModuleOwnerCustom_registerAdminViaGetCCIPAdmin is RegistryModuleOwnerCustomSetup {
+ function test_registerAdminViaGetCCIPAdmin_Success() public {
+ assertEq(s_tokenAdminRegistry.getTokenConfig(s_token).administrator, address(0));
+
+ address expectedOwner = IGetCCIPAdmin(s_token).getCCIPAdmin();
+
+ vm.expectCall(s_token, abi.encodeWithSelector(IGetCCIPAdmin.getCCIPAdmin.selector), 1);
+ vm.expectCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(TokenAdminRegistry.proposeAdministrator.selector, s_token, expectedOwner),
+ 1
+ );
+
+ vm.expectEmit();
+ emit RegistryModuleOwnerCustom.AdministratorRegistered(s_token, expectedOwner);
+
+ s_registryModuleOwnerCustom.registerAdminViaGetCCIPAdmin(s_token);
+
+ assertEq(s_tokenAdminRegistry.getTokenConfig(s_token).pendingAdministrator, OWNER);
+ }
+
+ function test_registerAdminViaGetCCIPAdmin_Revert() public {
+ address expectedOwner = IGetCCIPAdmin(s_token).getCCIPAdmin();
+
+ vm.startPrank(makeAddr("Not_expected_owner"));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RegistryModuleOwnerCustom.CanOnlySelfRegister.selector, expectedOwner, s_token)
+ );
+
+ s_registryModuleOwnerCustom.registerAdminViaGetCCIPAdmin(s_token);
+ }
+}
+
+contract RegistryModuleOwnerCustom_registerAdminViaOwner is RegistryModuleOwnerCustomSetup {
+ function test_registerAdminViaOwner_Success() public {
+ assertEq(s_tokenAdminRegistry.getTokenConfig(s_token).administrator, address(0));
+
+ address expectedOwner = IOwner(s_token).owner();
+
+ vm.expectCall(s_token, abi.encodeWithSelector(IOwner.owner.selector), 1);
+ vm.expectCall(
+ address(s_tokenAdminRegistry),
+ abi.encodeWithSelector(TokenAdminRegistry.proposeAdministrator.selector, s_token, expectedOwner),
+ 1
+ );
+
+ vm.expectEmit();
+ emit RegistryModuleOwnerCustom.AdministratorRegistered(s_token, expectedOwner);
+
+ s_registryModuleOwnerCustom.registerAdminViaOwner(s_token);
+
+ assertEq(s_tokenAdminRegistry.getTokenConfig(s_token).pendingAdministrator, OWNER);
+ }
+
+ function test_registerAdminViaOwner_Revert() public {
+ address expectedOwner = IOwner(s_token).owner();
+
+ vm.startPrank(makeAddr("Not_expected_owner"));
+
+ vm.expectRevert(
+ abi.encodeWithSelector(RegistryModuleOwnerCustom.CanOnlySelfRegister.selector, expectedOwner, s_token)
+ );
+
+ s_registryModuleOwnerCustom.registerAdminViaOwner(s_token);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/test/tokenAdminRegistry/TokenAdminRegistry.t.sol b/contracts/src/v0.8/ccip/test/tokenAdminRegistry/TokenAdminRegistry.t.sol
new file mode 100644
index 00000000000..ada0369045c
--- /dev/null
+++ b/contracts/src/v0.8/ccip/test/tokenAdminRegistry/TokenAdminRegistry.t.sol
@@ -0,0 +1,393 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IPoolV1} from "../../interfaces/IPool.sol";
+
+import {TokenAdminRegistry} from "../../tokenAdminRegistry/TokenAdminRegistry.sol";
+import {TokenSetup} from "../TokenSetup.t.sol";
+
+contract TokenAdminRegistrySetup is TokenSetup {
+ address internal s_registryModule = makeAddr("registryModule");
+
+ function setUp() public virtual override {
+ TokenSetup.setUp();
+
+ s_tokenAdminRegistry.addRegistryModule(s_registryModule);
+ }
+}
+
+contract TokenAdminRegistry_getPools is TokenAdminRegistrySetup {
+ function test_getPools_Success() public {
+ address[] memory tokens = new address[](1);
+ tokens[0] = s_sourceTokens[0];
+
+ address[] memory got = s_tokenAdminRegistry.getPools(tokens);
+ assertEq(got.length, 1);
+ assertEq(got[0], s_sourcePoolByToken[tokens[0]]);
+
+ got = s_tokenAdminRegistry.getPools(s_sourceTokens);
+ assertEq(got.length, s_sourceTokens.length);
+ for (uint256 i = 0; i < s_sourceTokens.length; i++) {
+ assertEq(got[i], s_sourcePoolByToken[s_sourceTokens[i]]);
+ }
+
+ address doesNotExist = makeAddr("doesNotExist");
+ tokens[0] = doesNotExist;
+ got = s_tokenAdminRegistry.getPools(tokens);
+ assertEq(got.length, 1);
+ assertEq(got[0], address(0));
+ }
+}
+
+contract TokenAdminRegistry_getPool is TokenAdminRegistrySetup {
+ function test_getPool_Success() public view {
+ address got = s_tokenAdminRegistry.getPool(s_sourceTokens[0]);
+ assertEq(got, s_sourcePoolByToken[s_sourceTokens[0]]);
+ }
+}
+
+contract TokenAdminRegistry_setPool is TokenAdminRegistrySetup {
+ function test_setPool_Success() public {
+ address pool = makeAddr("pool");
+ vm.mockCall(pool, abi.encodeWithSelector(IPoolV1.isSupportedToken.selector), abi.encode(true));
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.PoolSet(s_sourceTokens[0], s_sourcePoolByToken[s_sourceTokens[0]], pool);
+
+ s_tokenAdminRegistry.setPool(s_sourceTokens[0], pool);
+
+ assertEq(s_tokenAdminRegistry.getPool(s_sourceTokens[0]), pool);
+
+ // Assert the event is not emitted if the pool is the same as the current pool.
+ vm.recordLogs();
+ s_tokenAdminRegistry.setPool(s_sourceTokens[0], pool);
+
+ vm.assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ function test_setPool_ZeroAddressRemovesPool_Success() public {
+ address pool = makeAddr("pool");
+ vm.mockCall(pool, abi.encodeWithSelector(IPoolV1.isSupportedToken.selector), abi.encode(true));
+ s_tokenAdminRegistry.setPool(s_sourceTokens[0], pool);
+
+ assertEq(s_tokenAdminRegistry.getPool(s_sourceTokens[0]), pool);
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.PoolSet(s_sourceTokens[0], pool, address(0));
+
+ s_tokenAdminRegistry.setPool(s_sourceTokens[0], address(0));
+
+ assertEq(s_tokenAdminRegistry.getPool(s_sourceTokens[0]), address(0));
+ }
+
+ function test_setPool_InvalidTokenPoolToken_Revert() public {
+ address pool = makeAddr("pool");
+ vm.mockCall(pool, abi.encodeWithSelector(IPoolV1.isSupportedToken.selector), abi.encode(false));
+
+ vm.expectRevert(abi.encodeWithSelector(TokenAdminRegistry.InvalidTokenPoolToken.selector, s_sourceTokens[0]));
+ s_tokenAdminRegistry.setPool(s_sourceTokens[0], pool);
+ }
+
+ function test_setPool_OnlyAdministrator_Revert() public {
+ vm.stopPrank();
+
+ vm.expectRevert(
+ abi.encodeWithSelector(TokenAdminRegistry.OnlyAdministrator.selector, address(this), s_sourceTokens[0])
+ );
+ s_tokenAdminRegistry.setPool(s_sourceTokens[0], makeAddr("pool"));
+ }
+}
+
+contract TokenAdminRegistry_getAllConfiguredTokens is TokenAdminRegistrySetup {
+ function test_Fuzz_getAllConfiguredTokens_Success(uint8 numberOfTokens) public {
+ TokenAdminRegistry cleanTokenAdminRegistry = new TokenAdminRegistry();
+ for (uint160 i = 0; i < numberOfTokens; ++i) {
+ cleanTokenAdminRegistry.proposeAdministrator(address(i), address(i + 1000));
+ }
+
+ uint160 count = 0;
+ for (uint160 start = 0; start < numberOfTokens; start += count++) {
+ address[] memory got = cleanTokenAdminRegistry.getAllConfiguredTokens(uint64(start), uint64(count));
+ if (start + count > numberOfTokens) {
+ assertEq(got.length, numberOfTokens - start);
+ } else {
+ assertEq(got.length, count);
+ }
+
+ for (uint160 j = 0; j < got.length; ++j) {
+ assertEq(got[j], address(j + start));
+ }
+ }
+ }
+
+ function test_getAllConfiguredTokens_outOfBounds_Success() public view {
+ address[] memory tokens = s_tokenAdminRegistry.getAllConfiguredTokens(type(uint64).max, 10);
+ assertEq(tokens.length, 0);
+ }
+}
+
+contract TokenAdminRegistry_transferAdminRole is TokenAdminRegistrySetup {
+ function test_transferAdminRole_Success() public {
+ address token = s_sourceTokens[0];
+
+ address currentAdmin = s_tokenAdminRegistry.getTokenConfig(token).administrator;
+ address newAdmin = makeAddr("newAdmin");
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferRequested(token, currentAdmin, newAdmin);
+
+ s_tokenAdminRegistry.transferAdminRole(token, newAdmin);
+
+ TokenAdminRegistry.TokenConfig memory config = s_tokenAdminRegistry.getTokenConfig(token);
+
+ // Assert only the pending admin updates, without affecting the pending admin.
+ assertEq(config.pendingAdministrator, newAdmin);
+ assertEq(config.administrator, currentAdmin);
+ }
+
+ function test_transferAdminRole_OnlyAdministrator_Revert() public {
+ vm.stopPrank();
+
+ vm.expectRevert(
+ abi.encodeWithSelector(TokenAdminRegistry.OnlyAdministrator.selector, address(this), s_sourceTokens[0])
+ );
+ s_tokenAdminRegistry.transferAdminRole(s_sourceTokens[0], makeAddr("newAdmin"));
+ }
+}
+
+contract TokenAdminRegistry_acceptAdminRole is TokenAdminRegistrySetup {
+ function test_acceptAdminRole_Success() public {
+ address token = s_sourceTokens[0];
+
+ address currentAdmin = s_tokenAdminRegistry.getTokenConfig(token).administrator;
+ address newAdmin = makeAddr("newAdmin");
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferRequested(token, currentAdmin, newAdmin);
+
+ s_tokenAdminRegistry.transferAdminRole(token, newAdmin);
+
+ TokenAdminRegistry.TokenConfig memory config = s_tokenAdminRegistry.getTokenConfig(token);
+
+ // Assert only the pending admin updates, without affecting the pending admin.
+ assertEq(config.pendingAdministrator, newAdmin);
+ assertEq(config.administrator, currentAdmin);
+
+ vm.startPrank(newAdmin);
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferred(token, newAdmin);
+
+ s_tokenAdminRegistry.acceptAdminRole(token);
+
+ config = s_tokenAdminRegistry.getTokenConfig(token);
+
+ // Assert only the pending admin updates, without affecting the pending admin.
+ assertEq(config.pendingAdministrator, address(0));
+ assertEq(config.administrator, newAdmin);
+ }
+
+ function test_acceptAdminRole_OnlyPendingAdministrator_Revert() public {
+ address token = s_sourceTokens[0];
+ address currentAdmin = s_tokenAdminRegistry.getTokenConfig(token).administrator;
+ address newAdmin = makeAddr("newAdmin");
+
+ s_tokenAdminRegistry.transferAdminRole(token, newAdmin);
+
+ TokenAdminRegistry.TokenConfig memory config = s_tokenAdminRegistry.getTokenConfig(token);
+
+ // Assert only the pending admin updates, without affecting the pending admin.
+ assertEq(config.pendingAdministrator, newAdmin);
+ assertEq(config.administrator, currentAdmin);
+
+ address notNewAdmin = makeAddr("notNewAdmin");
+ vm.startPrank(notNewAdmin);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenAdminRegistry.OnlyPendingAdministrator.selector, notNewAdmin, token));
+ s_tokenAdminRegistry.acceptAdminRole(token);
+ }
+}
+
+contract TokenAdminRegistry_isAdministrator is TokenAdminRegistrySetup {
+ function test_isAdministrator_Success() public {
+ address newAdmin = makeAddr("newAdmin");
+ address newToken = makeAddr("newToken");
+ assertFalse(s_tokenAdminRegistry.isAdministrator(newToken, newAdmin));
+ assertFalse(s_tokenAdminRegistry.isAdministrator(newToken, OWNER));
+
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+ changePrank(newAdmin);
+ s_tokenAdminRegistry.acceptAdminRole(newToken);
+
+ assertTrue(s_tokenAdminRegistry.isAdministrator(newToken, newAdmin));
+ assertFalse(s_tokenAdminRegistry.isAdministrator(newToken, OWNER));
+ }
+}
+
+contract TokenAdminRegistry_proposeAdministrator is TokenAdminRegistrySetup {
+ function test_proposeAdministrator_module_Success() public {
+ vm.startPrank(s_registryModule);
+ address newAdmin = makeAddr("newAdmin");
+ address newToken = makeAddr("newToken");
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferRequested(newToken, address(0), newAdmin);
+
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+
+ assertEq(s_tokenAdminRegistry.getTokenConfig(newToken).pendingAdministrator, newAdmin);
+ assertEq(s_tokenAdminRegistry.getTokenConfig(newToken).administrator, address(0));
+ assertEq(s_tokenAdminRegistry.getTokenConfig(newToken).tokenPool, address(0));
+
+ changePrank(newAdmin);
+ s_tokenAdminRegistry.acceptAdminRole(newToken);
+
+ assertTrue(s_tokenAdminRegistry.isAdministrator(newToken, newAdmin));
+ }
+
+ function test_proposeAdministrator_owner_Success() public {
+ address newAdmin = makeAddr("newAdmin");
+ address newToken = makeAddr("newToken");
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferRequested(newToken, address(0), newAdmin);
+
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+
+ assertEq(s_tokenAdminRegistry.getTokenConfig(newToken).pendingAdministrator, newAdmin);
+
+ changePrank(newAdmin);
+ s_tokenAdminRegistry.acceptAdminRole(newToken);
+
+ assertTrue(s_tokenAdminRegistry.isAdministrator(newToken, newAdmin));
+ }
+
+ function test_proposeAdministrator_reRegisterWhileUnclaimed_Success() public {
+ address newAdmin = makeAddr("wrongAddress");
+ address newToken = makeAddr("newToken");
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferRequested(newToken, address(0), newAdmin);
+
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+
+ assertEq(s_tokenAdminRegistry.getTokenConfig(newToken).pendingAdministrator, newAdmin);
+
+ newAdmin = makeAddr("correctAddress");
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.AdministratorTransferRequested(newToken, address(0), newAdmin);
+
+ // Ensure we can still register the correct admin while the previous admin is unclaimed.
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+
+ changePrank(newAdmin);
+ s_tokenAdminRegistry.acceptAdminRole(newToken);
+
+ assertTrue(s_tokenAdminRegistry.isAdministrator(newToken, newAdmin));
+ }
+
+ mapping(address token => address admin) internal s_AdminByToken;
+
+ function test_Fuzz_proposeAdministrator_Success(address[50] memory tokens, address[50] memory admins) public {
+ TokenAdminRegistry cleanTokenAdminRegistry = new TokenAdminRegistry();
+ for (uint256 i = 0; i < tokens.length; i++) {
+ if (admins[i] == address(0)) {
+ continue;
+ }
+ if (cleanTokenAdminRegistry.getTokenConfig(tokens[i]).administrator != address(0)) {
+ continue;
+ }
+ cleanTokenAdminRegistry.proposeAdministrator(tokens[i], admins[i]);
+ s_AdminByToken[tokens[i]] = admins[i];
+ }
+
+ for (uint256 i = 0; i < tokens.length; i++) {
+ assertEq(cleanTokenAdminRegistry.getTokenConfig(tokens[i]).pendingAdministrator, s_AdminByToken[tokens[i]]);
+ }
+ }
+
+ function test_proposeAdministrator_OnlyRegistryModule_Revert() public {
+ address newToken = makeAddr("newToken");
+ vm.stopPrank();
+
+ vm.expectRevert(abi.encodeWithSelector(TokenAdminRegistry.OnlyRegistryModuleOrOwner.selector, address(this)));
+ s_tokenAdminRegistry.proposeAdministrator(newToken, OWNER);
+ }
+
+ function test_proposeAdministrator_ZeroAddress_Revert() public {
+ address newToken = makeAddr("newToken");
+
+ vm.expectRevert(abi.encodeWithSelector(TokenAdminRegistry.ZeroAddress.selector));
+ s_tokenAdminRegistry.proposeAdministrator(newToken, address(0));
+ }
+
+ function test_proposeAdministrator_AlreadyRegistered_Revert() public {
+ address newAdmin = makeAddr("newAdmin");
+ address newToken = makeAddr("newToken");
+
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+ changePrank(newAdmin);
+ s_tokenAdminRegistry.acceptAdminRole(newToken);
+
+ changePrank(OWNER);
+
+ vm.expectRevert(abi.encodeWithSelector(TokenAdminRegistry.AlreadyRegistered.selector, newToken));
+ s_tokenAdminRegistry.proposeAdministrator(newToken, newAdmin);
+ }
+}
+
+contract TokenAdminRegistry_addRegistryModule is TokenAdminRegistrySetup {
+ function test_addRegistryModule_Success() public {
+ address newModule = makeAddr("newModule");
+
+ s_tokenAdminRegistry.addRegistryModule(newModule);
+
+ assertTrue(s_tokenAdminRegistry.isRegistryModule(newModule));
+
+ // Assert the event is not emitted if the module is already added.
+ vm.recordLogs();
+ s_tokenAdminRegistry.addRegistryModule(newModule);
+
+ vm.assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ function test_addRegistryModule_OnlyOwner_Revert() public {
+ address newModule = makeAddr("newModule");
+ vm.stopPrank();
+
+ vm.expectRevert("Only callable by owner");
+ s_tokenAdminRegistry.addRegistryModule(newModule);
+ }
+}
+
+contract TokenAdminRegistry_removeRegistryModule is TokenAdminRegistrySetup {
+ function test_removeRegistryModule_Success() public {
+ address newModule = makeAddr("newModule");
+
+ s_tokenAdminRegistry.addRegistryModule(newModule);
+
+ assertTrue(s_tokenAdminRegistry.isRegistryModule(newModule));
+
+ vm.expectEmit();
+ emit TokenAdminRegistry.RegistryModuleRemoved(newModule);
+
+ s_tokenAdminRegistry.removeRegistryModule(newModule);
+
+ assertFalse(s_tokenAdminRegistry.isRegistryModule(newModule));
+
+ // Assert the event is not emitted if the module is already removed.
+ vm.recordLogs();
+ s_tokenAdminRegistry.removeRegistryModule(newModule);
+
+ vm.assertEq(vm.getRecordedLogs().length, 0);
+ }
+
+ function test_removeRegistryModule_OnlyOwner_Revert() public {
+ address newModule = makeAddr("newModule");
+ vm.stopPrank();
+
+ vm.expectRevert("Only callable by owner");
+ s_tokenAdminRegistry.removeRegistryModule(newModule);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/tokenAdminRegistry/RegistryModuleOwnerCustom.sol b/contracts/src/v0.8/ccip/tokenAdminRegistry/RegistryModuleOwnerCustom.sol
new file mode 100644
index 00000000000..3cd17df05f2
--- /dev/null
+++ b/contracts/src/v0.8/ccip/tokenAdminRegistry/RegistryModuleOwnerCustom.sol
@@ -0,0 +1,54 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IGetCCIPAdmin} from "../interfaces/IGetCCIPAdmin.sol";
+import {IOwner} from "../interfaces/IOwner.sol";
+import {ITokenAdminRegistry} from "../interfaces/ITokenAdminRegistry.sol";
+
+contract RegistryModuleOwnerCustom is ITypeAndVersion {
+ error CanOnlySelfRegister(address admin, address token);
+ error AddressZero();
+
+ event AdministratorRegistered(address indexed token, address indexed administrator);
+
+ string public constant override typeAndVersion = "RegistryModuleOwnerCustom 1.5.0-dev";
+
+ // The TokenAdminRegistry contract
+ ITokenAdminRegistry internal immutable i_tokenAdminRegistry;
+
+ constructor(address tokenAdminRegistry) {
+ if (tokenAdminRegistry == address(0)) {
+ revert AddressZero();
+ }
+ i_tokenAdminRegistry = ITokenAdminRegistry(tokenAdminRegistry);
+ }
+
+ /// @notice Registers the admin of the token using the `getCCIPAdmin` method.
+ /// @param token The token to register the admin for.
+ /// @dev The caller must be the admin returned by the `getCCIPAdmin` method.
+ function registerAdminViaGetCCIPAdmin(address token) external {
+ _registerAdmin(token, IGetCCIPAdmin(token).getCCIPAdmin());
+ }
+
+ /// @notice Registers the admin of the token using the `owner` method.
+ /// @param token The token to register the admin for.
+ /// @dev The caller must be the admin returned by the `owner` method.
+ function registerAdminViaOwner(address token) external {
+ _registerAdmin(token, IOwner(token).owner());
+ }
+
+ /// @notice Registers the admin of the token to msg.sender given that the
+ /// admin is equal to msg.sender.
+ /// @param token The token to register the admin for.
+ /// @param admin The caller must be the admin.
+ function _registerAdmin(address token, address admin) internal {
+ if (admin != msg.sender) {
+ revert CanOnlySelfRegister(admin, token);
+ }
+
+ i_tokenAdminRegistry.proposeAdministrator(token, admin);
+
+ emit AdministratorRegistered(token, admin);
+ }
+}
diff --git a/contracts/src/v0.8/ccip/tokenAdminRegistry/TokenAdminRegistry.sol b/contracts/src/v0.8/ccip/tokenAdminRegistry/TokenAdminRegistry.sol
new file mode 100644
index 00000000000..32394a396ec
--- /dev/null
+++ b/contracts/src/v0.8/ccip/tokenAdminRegistry/TokenAdminRegistry.sol
@@ -0,0 +1,223 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+import {IPoolV1} from "../interfaces/IPool.sol";
+import {ITokenAdminRegistry} from "../interfaces/ITokenAdminRegistry.sol";
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+
+import {EnumerableSet} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/utils/structs/EnumerableSet.sol";
+
+/// @notice This contract stores the token pool configuration for all CCIP enabled tokens. It works
+/// on a self-serve basis, where tokens can be registered without intervention from the CCIP owner.
+/// @dev This contract is not considered upgradable, as it is a customer facing contract that will store
+/// significant amounts of data.
+contract TokenAdminRegistry is ITokenAdminRegistry, ITypeAndVersion, OwnerIsCreator {
+ using EnumerableSet for EnumerableSet.AddressSet;
+
+ error OnlyRegistryModuleOrOwner(address sender);
+ error OnlyAdministrator(address sender, address token);
+ error OnlyPendingAdministrator(address sender, address token);
+ error AlreadyRegistered(address token);
+ error ZeroAddress();
+ error InvalidTokenPoolToken(address token);
+
+ event PoolSet(address indexed token, address indexed previousPool, address indexed newPool);
+ event AdministratorTransferRequested(address indexed token, address indexed currentAdmin, address indexed newAdmin);
+ event AdministratorTransferred(address indexed token, address indexed newAdmin);
+ event DisableReRegistrationSet(address indexed token, bool disabled);
+ event RemovedAdministrator(address token);
+ event RegistryModuleAdded(address module);
+ event RegistryModuleRemoved(address indexed module);
+
+ // The struct is packed in a way that optimizes the attributes that are accessed together.
+ // solhint-disable-next-line gas-struct-packing
+ struct TokenConfig {
+ address administrator; // the current administrator of the token
+ address pendingAdministrator; // the address that is pending to become the new administrator
+ address tokenPool; // the token pool for this token. Can be address(0) if not deployed or not configured.
+ }
+
+ string public constant override typeAndVersion = "TokenAdminRegistry 1.5.0-dev";
+
+ // Mapping of token address to token configuration
+ mapping(address token => TokenConfig) internal s_tokenConfig;
+
+ // All tokens that have been configured
+ EnumerableSet.AddressSet internal s_tokens;
+
+ // Registry modules are allowed to register administrators for tokens
+ EnumerableSet.AddressSet internal s_registryModules;
+
+ /// @notice Returns all pools for the given tokens.
+ /// @dev Will return address(0) for tokens that do not have a pool.
+ function getPools(address[] calldata tokens) external view returns (address[] memory) {
+ address[] memory pools = new address[](tokens.length);
+ for (uint256 i = 0; i < tokens.length; ++i) {
+ pools[i] = s_tokenConfig[tokens[i]].tokenPool;
+ }
+ return pools;
+ }
+
+ /// @inheritdoc ITokenAdminRegistry
+ function getPool(address token) external view returns (address) {
+ return s_tokenConfig[token].tokenPool;
+ }
+
+ /// @notice Returns the configuration for a token.
+ /// @param token The token to get the configuration for.
+ /// @return config The configuration for the token.
+ function getTokenConfig(address token) external view returns (TokenConfig memory) {
+ return s_tokenConfig[token];
+ }
+
+ /// @notice Returns a list of tokens that are configured in the token admin registry.
+ /// @param startIndex Starting index in list, can be 0 if you want to start from the beginning.
+ /// @param maxCount Maximum number of tokens to retrieve. Since the list can be large,
+ /// it is recommended to use a paging mechanism to retrieve all tokens. If querying for very
+ /// large lists, RPCs can time out. If you want all tokens, use type(uint64).max.
+ /// @return tokens List of configured tokens.
+ /// @dev The function is paginated to avoid RPC timeouts.
+ /// @dev The ordering is guaranteed to remain the same as it is not possible to remove tokens
+ /// from s_tokens.
+ function getAllConfiguredTokens(uint64 startIndex, uint64 maxCount) external view returns (address[] memory tokens) {
+ uint256 numberOfTokens = s_tokens.length();
+ if (startIndex >= numberOfTokens) {
+ return tokens;
+ }
+ uint256 count = maxCount;
+ if (count + startIndex > numberOfTokens) {
+ count = numberOfTokens - startIndex;
+ }
+ tokens = new address[](count);
+ for (uint256 i = 0; i < count; ++i) {
+ tokens[i] = s_tokens.at(startIndex + i);
+ }
+
+ return tokens;
+ }
+
+ // ================================================================
+ // │ Administrator functions │
+ // ================================================================
+
+ /// @notice Sets the pool for a token. Setting the pool to address(0) effectively delists the token
+ /// from CCIP. Setting the pool to any other address enables the token on CCIP.
+ /// @param localToken The token to set the pool for.
+ /// @param pool The pool to set for the token.
+ function setPool(address localToken, address pool) external onlyTokenAdmin(localToken) {
+ // The pool has to support the token, but we want to allow removing the pool, so we only check
+ // if the pool supports the token if it is not address(0).
+ if (pool != address(0) && !IPoolV1(pool).isSupportedToken(localToken)) {
+ revert InvalidTokenPoolToken(localToken);
+ }
+
+ TokenConfig storage config = s_tokenConfig[localToken];
+
+ address previousPool = config.tokenPool;
+ config.tokenPool = pool;
+
+ if (previousPool != pool) {
+ emit PoolSet(localToken, previousPool, pool);
+ }
+ }
+
+ /// @notice Transfers the administrator role for a token to a new address with a 2-step process.
+ /// @param localToken The token to transfer the administrator role for.
+ /// @param newAdmin The address to transfer the administrator role to. Can be address(0) to cancel
+ /// a pending transfer.
+ /// @dev The new admin must call `acceptAdminRole` to accept the role.
+ function transferAdminRole(address localToken, address newAdmin) external onlyTokenAdmin(localToken) {
+ TokenConfig storage config = s_tokenConfig[localToken];
+ config.pendingAdministrator = newAdmin;
+
+ emit AdministratorTransferRequested(localToken, msg.sender, newAdmin);
+ }
+
+ /// @notice Accepts the administrator role for a token.
+ /// @param localToken The token to accept the administrator role for.
+ /// @dev This function can only be called by the pending administrator.
+ function acceptAdminRole(address localToken) external {
+ TokenConfig storage config = s_tokenConfig[localToken];
+ if (config.pendingAdministrator != msg.sender) {
+ revert OnlyPendingAdministrator(msg.sender, localToken);
+ }
+
+ config.administrator = msg.sender;
+ config.pendingAdministrator = address(0);
+
+ emit AdministratorTransferred(localToken, msg.sender);
+ }
+
+ // ================================================================
+ // │ Administrator config │
+ // ================================================================
+
+ /// @notice Public getter to check for permissions of an administrator
+ function isAdministrator(address localToken, address administrator) external view returns (bool) {
+ return s_tokenConfig[localToken].administrator == administrator;
+ }
+
+ /// @inheritdoc ITokenAdminRegistry
+ /// @dev Can only be called by a registry module.
+ function proposeAdministrator(address localToken, address administrator) external {
+ if (!isRegistryModule(msg.sender) && msg.sender != owner()) {
+ revert OnlyRegistryModuleOrOwner(msg.sender);
+ }
+ if (administrator == address(0)) {
+ revert ZeroAddress();
+ }
+ TokenConfig storage config = s_tokenConfig[localToken];
+
+ if (config.administrator != address(0)) {
+ revert AlreadyRegistered(localToken);
+ }
+
+ config.pendingAdministrator = administrator;
+
+ // We don't care if it's already in the set, as it's a no-op.
+ s_tokens.add(localToken);
+
+ emit AdministratorTransferRequested(localToken, address(0), administrator);
+ }
+
+ // ================================================================
+ // │ Registry Modules │
+ // ================================================================
+
+ /// @notice Checks if an address is a registry module.
+ /// @param module The address to check.
+ /// @return True if the address is a registry module, false otherwise.
+ function isRegistryModule(address module) public view returns (bool) {
+ return s_registryModules.contains(module);
+ }
+
+ /// @notice Adds a new registry module to the list of allowed modules.
+ /// @param module The module to add.
+ function addRegistryModule(address module) external onlyOwner {
+ if (s_registryModules.add(module)) {
+ emit RegistryModuleAdded(module);
+ }
+ }
+
+ /// @notice Removes a registry module from the list of allowed modules.
+ /// @param module The module to remove.
+ function removeRegistryModule(address module) external onlyOwner {
+ if (s_registryModules.remove(module)) {
+ emit RegistryModuleRemoved(module);
+ }
+ }
+
+ // ================================================================
+ // │ Access │
+ // ================================================================
+
+ /// @notice Checks if an address is the administrator of the given token.
+ modifier onlyTokenAdmin(address token) {
+ if (s_tokenConfig[token].administrator != msg.sender) {
+ revert OnlyAdministrator(msg.sender, token);
+ }
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/ccip/v1.4-CCIP-License-grants.md b/contracts/src/v0.8/ccip/v1.4-CCIP-License-grants.md
new file mode 100644
index 00000000000..f206b8adcc1
--- /dev/null
+++ b/contracts/src/v0.8/ccip/v1.4-CCIP-License-grants.md
@@ -0,0 +1,5 @@
+v1.4-CCIP-License-grants
+
+Additional Use Grant(s):
+
+You may make use of the Cross-Chain Interoperability Protocol v1.4 (which is available subject to the license here the “Licensed Work ”) solely for purposes of importing client-side libraries or example clients to facilitate the integration of the Licensed Work into your application.
\ No newline at end of file
diff --git a/contracts/src/v0.8/liquiditymanager/LiquidityManager.sol b/contracts/src/v0.8/liquiditymanager/LiquidityManager.sol
new file mode 100644
index 00000000000..070930b904a
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/LiquidityManager.sol
@@ -0,0 +1,575 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBridgeAdapter} from "./interfaces/IBridge.sol";
+import {ILiquidityManager} from "./interfaces/ILiquidityManager.sol";
+import {ILiquidityContainer} from "./interfaces/ILiquidityContainer.sol";
+import {IWrappedNative} from "../ccip/interfaces/IWrappedNative.sol";
+
+import {OCR3Base} from "./ocr/OCR3Base.sol";
+
+import {IERC20} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice LiquidityManager for a single token over multiple chains.
+/// @dev This contract is designed to be used with the LockReleaseTokenPool contract but
+/// isn't constrained to it. It can be used with any contract that implements the ILiquidityContainer
+/// interface.
+/// @dev The OCR3 DON should only be able to transfer funds to other pre-approved contracts
+/// on other chains. Under no circumstances should it be able to transfer funds to arbitrary
+/// addresses. The owner is therefore in full control of the funds in this contract, not the DON.
+/// This is a security feature. The worst that can happen is that the DON can lock up funds in
+/// bridges, but it can't steal them.
+/// @dev References to local mean logic on the same chain as this contract is deployed on.
+/// References to remote mean logic on other chains.
+contract LiquidityManager is ILiquidityManager, OCR3Base {
+ using SafeERC20 for IERC20;
+
+ error ZeroAddress();
+ error InvalidRemoteChain(uint64 chainSelector);
+ error ZeroChainSelector();
+ error InsufficientLiquidity(uint256 requested, uint256 available, uint256 reserve);
+ error EmptyReport();
+ error TransferFailed();
+ error OnlyFinanceRole();
+
+ /// @notice Emitted when a finalization step is completed without funds being available.
+ /// @param ocrSeqNum The OCR sequence number of the report.
+ /// @param remoteChainSelector The chain selector of the remote chain funds are coming from.
+ /// @param bridgeSpecificData The bridge specific data that was used to finalize the transfer.
+ event FinalizationStepCompleted(
+ uint64 indexed ocrSeqNum,
+ uint64 indexed remoteChainSelector,
+ bytes bridgeSpecificData
+ );
+
+ /// @notice Emitted when the CLL finance role is set.
+ /// @param financeRole The address of the new finance role.
+ event FinanceRoleSet(address financeRole);
+
+ /// @notice Emitted when liquidity is transferred to another chain, or received from another chain.
+ /// @param ocrSeqNum The OCR sequence number of the report.
+ /// @param fromChainSelector The chain selector of the chain the funds are coming from.
+ /// In the event fromChainSelector == i_localChainSelector, this is an outgoing transfer.
+ /// Otherwise, it is an incoming transfer.
+ /// @param toChainSelector The chain selector of the chain the funds are going to.
+ /// In the event toChainSelector == i_localChainSelector, this is an incoming transfer.
+ /// Otherwise, it is an outgoing transfer.
+ /// @param to The address the funds are going to.
+ /// If this is address(this), the funds are arriving in this contract.
+ /// @param amount The amount of tokens being transferred.
+ /// @param bridgeSpecificData The bridge specific data that was passed to the local bridge adapter
+ /// when transferring the funds.
+ /// @param bridgeReturnData The return data from the local bridge adapter when transferring the funds.
+ event LiquidityTransferred(
+ uint64 indexed ocrSeqNum,
+ uint64 indexed fromChainSelector,
+ uint64 indexed toChainSelector,
+ address to,
+ uint256 amount,
+ bytes bridgeSpecificData,
+ bytes bridgeReturnData
+ );
+
+ /// @notice Emitted when liquidity is added to the local liquidity container.
+ /// @param provider The address of the provider that added the liquidity.
+ /// @param amount The amount of liquidity that was added.
+ event LiquidityAddedToContainer(address indexed provider, uint256 indexed amount);
+
+ /// @notice Emitted when liquidity is removed from the local liquidity container.
+ /// @param remover The address of the remover that removed the liquidity.
+ /// @param amount The amount of liquidity that was removed.
+ event LiquidityRemovedFromContainer(address indexed remover, uint256 indexed amount);
+
+ /// @notice Emitted when the local liquidity container is set.
+ /// @param newLiquidityContainer The address of the new liquidity container.
+ event LiquidityContainerSet(address indexed newLiquidityContainer);
+
+ /// @notice Emitted when the minimum liquidity is set.
+ /// @param oldBalance The old minimum liquidity.
+ /// @param newBalance The new minimum liquidity.
+ event MinimumLiquiditySet(uint256 oldBalance, uint256 newBalance);
+
+ /// @notice Emitted when someone sends native to this contract
+ /// @param amount The amount of native deposited
+ /// @param depositor The address that deposited the native
+ event NativeDeposited(uint256 amount, address depositor);
+
+ /// @notice Emitted when native balance is withdrawn by contract owner
+ /// @param amount The amount of native withdrawn
+ /// @param destination The address the native is sent to
+ event NativeWithdrawn(uint256 amount, address destination);
+
+ /// @notice Emitted when a cross chain rebalancer is set.
+ /// @param remoteChainSelector The chain selector of the remote chain.
+ /// @param localBridge The local bridge adapter that will be used to transfer funds.
+ /// @param remoteToken The address of the token on the remote chain.
+ /// @param remoteRebalancer The address of the remote rebalancer contract.
+ /// @param enabled Whether the rebalancer is enabled.
+ event CrossChainRebalancerSet(
+ uint64 indexed remoteChainSelector,
+ IBridgeAdapter localBridge,
+ address remoteToken,
+ address remoteRebalancer,
+ bool enabled
+ );
+
+ /// @notice Emitted when a finalization step fails.
+ /// @param ocrSeqNum The OCR sequence number of the report.
+ /// @param remoteChainSelector The chain selector of the remote chain funds are coming from.
+ /// @param bridgeSpecificData The bridge specific data that was used to finalize the transfer.
+ /// @param reason The reason the finalization failed.
+ event FinalizationFailed(
+ uint64 indexed ocrSeqNum,
+ uint64 indexed remoteChainSelector,
+ bytes bridgeSpecificData,
+ bytes reason
+ );
+
+ struct CrossChainRebalancer {
+ address remoteRebalancer;
+ IBridgeAdapter localBridge;
+ address remoteToken;
+ bool enabled;
+ }
+
+ string public constant override typeAndVersion = "LiquidityManager 1.0.0-dev";
+
+ /// @notice The token that this pool manages liquidity for.
+ IERC20 public immutable i_localToken;
+
+ /// @notice The chain selector belonging to the chain this pool is deployed on.
+ uint64 internal immutable i_localChainSelector;
+
+ /// @notice The target balance defines the expected amount of tokens for this network.
+ /// Setting the balance to 0 will disable any automated rebalancing operations.
+ uint256 internal s_minimumLiquidity;
+
+ /// @notice Mapping of chain selector to liquidity container on other chains
+ mapping(uint64 chainSelector => CrossChainRebalancer) private s_crossChainRebalancer;
+
+ uint64[] private s_supportedDestChains;
+
+ /// @notice The liquidity container on the local chain
+ /// @dev In the case of CCIP, this would be the token pool.
+ ILiquidityContainer private s_localLiquidityContainer;
+
+ /// @notice The CLL finance team multisig
+ address private s_finance;
+
+ constructor(
+ IERC20 token,
+ uint64 localChainSelector,
+ ILiquidityContainer localLiquidityContainer,
+ uint256 minimumLiquidity,
+ address finance
+ ) OCR3Base() {
+ if (localChainSelector == 0) {
+ revert ZeroChainSelector();
+ }
+
+ if (address(token) == address(0) || address(localLiquidityContainer) == address(0)) {
+ revert ZeroAddress();
+ }
+ i_localToken = token;
+ i_localChainSelector = localChainSelector;
+ s_localLiquidityContainer = localLiquidityContainer;
+ s_minimumLiquidity = minimumLiquidity;
+ s_finance = finance;
+ }
+
+ // ================================================================
+ // │ Native Management │
+ // ================================================================
+
+ receive() external payable {
+ emit NativeDeposited(msg.value, msg.sender);
+ }
+
+ /// @notice withdraw native balance
+ function withdrawNative(uint256 amount, address payable destination) external onlyFinance {
+ (bool success, ) = destination.call{value: amount}("");
+ if (!success) revert TransferFailed();
+
+ emit NativeWithdrawn(amount, destination);
+ }
+
+ // ================================================================
+ // │ Liquidity Management │
+ // ================================================================
+
+ /// @inheritdoc ILiquidityManager
+ function getLiquidity() public view returns (uint256 currentLiquidity) {
+ return i_localToken.balanceOf(address(s_localLiquidityContainer));
+ }
+
+ /// @notice Adds liquidity to the multi-chain system.
+ /// @dev Anyone can call this function, but anyone other than the owner should regard
+ /// adding liquidity as a donation to the system, as there is no way to get it out.
+ /// This function is open to anyone to be able to quickly add funds to the system
+ /// without having to go through potentially complicated multisig schemes to do it from
+ /// the owner address.
+ function addLiquidity(uint256 amount) external {
+ i_localToken.safeTransferFrom(msg.sender, address(this), amount);
+
+ // Make sure this is tether compatible, as they have strange approval requirements
+ // Should be good since all approvals are always immediately used.
+ i_localToken.safeApprove(address(s_localLiquidityContainer), amount);
+ s_localLiquidityContainer.provideLiquidity(amount);
+
+ emit LiquidityAddedToContainer(msg.sender, amount);
+ }
+
+ /// @notice Removes liquidity from the system and sends it to the caller, so the owner.
+ /// @dev Only the owner can call this function.
+ function removeLiquidity(uint256 amount) external onlyFinance {
+ uint256 currentBalance = getLiquidity();
+ if (currentBalance < amount) {
+ revert InsufficientLiquidity(amount, currentBalance, 0);
+ }
+
+ s_localLiquidityContainer.withdrawLiquidity(amount);
+ i_localToken.safeTransfer(msg.sender, amount);
+
+ emit LiquidityRemovedFromContainer(msg.sender, amount);
+ }
+
+ /// @notice escape hatch to manually withdraw any ERC20 token from the LM contract
+ /// @param token The address of the token to withdraw
+ /// @param amount The amount of tokens to withdraw
+ /// @param destination The address to send the tokens to
+ function withdrawERC20(address token, uint256 amount, address destination) external onlyFinance {
+ IERC20(token).safeTransfer(destination, amount);
+ }
+
+ /// @notice Transfers liquidity to another chain.
+ /// @dev This function is a public version of the internal _rebalanceLiquidity function.
+ /// to allow the owner to also initiate a rebalancing when needed.
+ function rebalanceLiquidity(
+ uint64 chainSelector,
+ uint256 amount,
+ uint256 nativeBridgeFee,
+ bytes calldata bridgeSpecificPayload
+ ) external onlyFinance {
+ _rebalanceLiquidity(chainSelector, amount, nativeBridgeFee, type(uint64).max, bridgeSpecificPayload);
+ }
+
+ /// @notice Finalizes liquidity from another chain.
+ /// @dev This function is a public version of the internal _receiveLiquidity function.
+ /// to allow the owner to also initiate a finalization when needed.
+ function receiveLiquidity(
+ uint64 remoteChainSelector,
+ uint256 amount,
+ bool shouldWrapNative,
+ bytes calldata bridgeSpecificPayload
+ ) external onlyFinance {
+ _receiveLiquidity(remoteChainSelector, amount, bridgeSpecificPayload, shouldWrapNative, type(uint64).max);
+ }
+
+ /// @notice Transfers liquidity to another chain.
+ /// @dev Called by both the owner and the DON.
+ /// @param chainSelector The chain selector of the chain to transfer liquidity to.
+ /// @param tokenAmount The amount of tokens to transfer.
+ /// @param nativeBridgeFee The fee to pay to the bridge.
+ /// @param ocrSeqNum The OCR sequence number of the report.
+ /// @param bridgeSpecificPayload The bridge specific data to pass to the bridge adapter.
+ function _rebalanceLiquidity(
+ uint64 chainSelector,
+ uint256 tokenAmount,
+ uint256 nativeBridgeFee,
+ uint64 ocrSeqNum,
+ bytes memory bridgeSpecificPayload
+ ) internal {
+ uint256 currentBalance = getLiquidity();
+ uint256 minBalance = s_minimumLiquidity;
+ if (currentBalance < minBalance || currentBalance - minBalance < tokenAmount) {
+ revert InsufficientLiquidity(tokenAmount, currentBalance, minBalance);
+ }
+
+ CrossChainRebalancer memory remoteLiqManager = s_crossChainRebalancer[chainSelector];
+
+ if (!remoteLiqManager.enabled) {
+ revert InvalidRemoteChain(chainSelector);
+ }
+
+ // XXX: Could be optimized by withdrawing once and then sending to all destinations
+ s_localLiquidityContainer.withdrawLiquidity(tokenAmount);
+ i_localToken.safeApprove(address(remoteLiqManager.localBridge), tokenAmount);
+
+ bytes memory bridgeReturnData = remoteLiqManager.localBridge.sendERC20{value: nativeBridgeFee}(
+ address(i_localToken),
+ remoteLiqManager.remoteToken,
+ remoteLiqManager.remoteRebalancer,
+ tokenAmount,
+ bridgeSpecificPayload
+ );
+
+ emit LiquidityTransferred(
+ ocrSeqNum,
+ i_localChainSelector,
+ chainSelector,
+ remoteLiqManager.remoteRebalancer,
+ tokenAmount,
+ bridgeSpecificPayload,
+ bridgeReturnData
+ );
+ }
+
+ /// @notice Receives liquidity from another chain.
+ /// @dev Called by both the owner and the DON.
+ /// @param remoteChainSelector The chain selector of the chain to receive liquidity from.
+ /// @param amount The amount of tokens to receive.
+ /// @param bridgeSpecificPayload The bridge specific data to pass to the bridge adapter finalizeWithdrawERC20 call.
+ /// @param shouldWrapNative Whether the token should be wrapped before injecting it into the liquidity container.
+ /// This only applies to native tokens wrapper contracts, e.g WETH.
+ /// @param ocrSeqNum The OCR sequence number of the report.
+ function _receiveLiquidity(
+ uint64 remoteChainSelector,
+ uint256 amount,
+ bytes memory bridgeSpecificPayload,
+ bool shouldWrapNative,
+ uint64 ocrSeqNum
+ ) internal {
+ // check if the remote chain is supported
+ CrossChainRebalancer memory remoteRebalancer = s_crossChainRebalancer[remoteChainSelector];
+ if (!remoteRebalancer.enabled) {
+ revert InvalidRemoteChain(remoteChainSelector);
+ }
+
+ // finalize the withdrawal through the bridge adapter
+ try
+ remoteRebalancer.localBridge.finalizeWithdrawERC20(
+ remoteRebalancer.remoteRebalancer, // remoteSender: the remote rebalancer
+ address(this), // localReceiver: this contract
+ bridgeSpecificPayload
+ )
+ returns (bool fundsAvailable) {
+ if (fundsAvailable) {
+ // finalization was successful and we can inject the liquidity into the container.
+ // approve and liquidity container should transferFrom.
+ _injectLiquidity(amount, ocrSeqNum, remoteChainSelector, bridgeSpecificPayload, shouldWrapNative);
+ } else {
+ // a finalization step was completed, but funds are not available.
+ // hence, we cannot inject any liquidity yet.
+ emit FinalizationStepCompleted(ocrSeqNum, remoteChainSelector, bridgeSpecificPayload);
+ }
+
+ // return here on the happy path.
+ // sad path is when finalizeWithdrawERC20 reverts, which is handled after the catch block.
+ return;
+ } catch (bytes memory lowLevelData) {
+ // failed to finalize the withdrawal.
+ // this could mean that the withdrawal was already finalized
+ // or that the withdrawal failed.
+ // we assume the former and continue
+ emit FinalizationFailed(ocrSeqNum, remoteChainSelector, bridgeSpecificPayload, lowLevelData);
+ }
+
+ // if we reach this point, the finalization failed.
+ // since we don't have enough information to know why it failed,
+ // we assume that it failed because the withdrawal was already finalized,
+ // and that the funds are available.
+ _injectLiquidity(amount, ocrSeqNum, remoteChainSelector, bridgeSpecificPayload, shouldWrapNative);
+ }
+
+ /// @notice Injects liquidity into the local liquidity container.
+ /// @param amount The amount of tokens to inject.
+ /// @param ocrSeqNum The OCR sequence number of the report.
+ /// @param remoteChainSelector The chain selector of the remote chain.
+ /// @param bridgeSpecificPayload The bridge specific data passed to the bridge adapter finalizeWithdrawERC20 call.
+ /// @param shouldWrapNative Whether the token should be wrapped before injecting it into the liquidity container.
+ function _injectLiquidity(
+ uint256 amount,
+ uint64 ocrSeqNum,
+ uint64 remoteChainSelector,
+ bytes memory bridgeSpecificPayload,
+ bool shouldWrapNative
+ ) private {
+ // We trust the DON or the owner (the only two actors who can end up calling this function)
+ // to correctly set the shouldWrapNative flag.
+ // Some bridges only bridge native and not wrapped native.
+ // In such a case we need to re-wrap the native in order to inject it into the liquidity container.
+ // TODO: escape hatch in case of bug?
+ if (shouldWrapNative) {
+ IWrappedNative(address(i_localToken)).deposit{value: amount}();
+ }
+
+ i_localToken.safeIncreaseAllowance(address(s_localLiquidityContainer), amount);
+ s_localLiquidityContainer.provideLiquidity(amount);
+
+ emit LiquidityTransferred(
+ ocrSeqNum,
+ remoteChainSelector,
+ i_localChainSelector,
+ address(this),
+ amount,
+ bridgeSpecificPayload,
+ bytes("") // no bridge return data when receiving
+ );
+ }
+
+ /// @notice Process the OCR report.
+ /// @dev Called by OCR3Base's transmit() function.
+ function _report(bytes calldata report, uint64 ocrSeqNum) internal override {
+ ILiquidityManager.LiquidityInstructions memory instructions = abi.decode(
+ report,
+ (ILiquidityManager.LiquidityInstructions)
+ );
+
+ uint256 sendInstructions = instructions.sendLiquidityParams.length;
+ uint256 receiveInstructions = instructions.receiveLiquidityParams.length;
+
+ // There should always be instructions to send or receive, if not, the report is invalid
+ // and we revert to save the gas of the signature validation of OCR.
+ if (sendInstructions == 0 && receiveInstructions == 0) {
+ revert EmptyReport();
+ }
+
+ for (uint256 i = 0; i < sendInstructions; ++i) {
+ _rebalanceLiquidity(
+ instructions.sendLiquidityParams[i].remoteChainSelector,
+ instructions.sendLiquidityParams[i].amount,
+ instructions.sendLiquidityParams[i].nativeBridgeFee,
+ ocrSeqNum,
+ instructions.sendLiquidityParams[i].bridgeData
+ );
+ }
+
+ for (uint256 i = 0; i < receiveInstructions; ++i) {
+ _receiveLiquidity(
+ instructions.receiveLiquidityParams[i].remoteChainSelector,
+ instructions.receiveLiquidityParams[i].amount,
+ instructions.receiveLiquidityParams[i].bridgeData,
+ instructions.receiveLiquidityParams[i].shouldWrapNative,
+ ocrSeqNum
+ );
+ }
+ }
+
+ // ================================================================
+ // │ Config │
+ // ================================================================
+
+ function getSupportedDestChains() external view returns (uint64[] memory) {
+ return s_supportedDestChains;
+ }
+
+ /// @notice Gets the cross chain liquidity manager
+ function getCrossChainRebalancer(uint64 chainSelector) external view returns (CrossChainRebalancer memory) {
+ return s_crossChainRebalancer[chainSelector];
+ }
+
+ /// @notice Gets all cross chain liquidity managers
+ /// @dev We don't care too much about gas since this function is intended for offchain usage.
+ function getAllCrossChainRebalancers() external view returns (CrossChainRebalancerArgs[] memory) {
+ uint256 numChains = s_supportedDestChains.length;
+ CrossChainRebalancerArgs[] memory managers = new CrossChainRebalancerArgs[](numChains);
+ for (uint256 i = 0; i < numChains; ++i) {
+ uint64 chainSelector = s_supportedDestChains[i];
+ CrossChainRebalancer memory currentManager = s_crossChainRebalancer[chainSelector];
+ managers[i] = CrossChainRebalancerArgs({
+ remoteRebalancer: currentManager.remoteRebalancer,
+ localBridge: currentManager.localBridge,
+ remoteToken: currentManager.remoteToken,
+ remoteChainSelector: chainSelector,
+ enabled: currentManager.enabled
+ });
+ }
+
+ return managers;
+ }
+
+ /// @notice Sets a list of cross chain liquidity managers.
+ /// @dev Will update the list of supported dest chains if the chain is new.
+ function setCrossChainRebalancers(CrossChainRebalancerArgs[] calldata crossChainRebalancers) external onlyOwner {
+ for (uint256 i = 0; i < crossChainRebalancers.length; ++i) {
+ _setCrossChainRebalancer(crossChainRebalancers[i]);
+ }
+ }
+
+ function setCrossChainRebalancer(CrossChainRebalancerArgs calldata crossChainLiqManager) external onlyOwner {
+ _setCrossChainRebalancer(crossChainLiqManager);
+ }
+
+ /// @notice Sets a single cross chain liquidity manager.
+ /// @dev Will update the list of supported dest chains if the chain is new.
+ function _setCrossChainRebalancer(CrossChainRebalancerArgs calldata crossChainLiqManager) internal {
+ if (crossChainLiqManager.remoteChainSelector == 0) {
+ revert ZeroChainSelector();
+ }
+
+ if (
+ crossChainLiqManager.remoteRebalancer == address(0) ||
+ address(crossChainLiqManager.localBridge) == address(0) ||
+ crossChainLiqManager.remoteToken == address(0)
+ ) {
+ revert ZeroAddress();
+ }
+
+ // If the destination chain is new, add it to the list of supported chains
+ if (s_crossChainRebalancer[crossChainLiqManager.remoteChainSelector].remoteToken == address(0)) {
+ s_supportedDestChains.push(crossChainLiqManager.remoteChainSelector);
+ }
+
+ s_crossChainRebalancer[crossChainLiqManager.remoteChainSelector] = CrossChainRebalancer({
+ remoteRebalancer: crossChainLiqManager.remoteRebalancer,
+ localBridge: crossChainLiqManager.localBridge,
+ remoteToken: crossChainLiqManager.remoteToken,
+ enabled: crossChainLiqManager.enabled
+ });
+
+ emit CrossChainRebalancerSet(
+ crossChainLiqManager.remoteChainSelector,
+ crossChainLiqManager.localBridge,
+ crossChainLiqManager.remoteToken,
+ crossChainLiqManager.remoteRebalancer,
+ crossChainLiqManager.enabled
+ );
+ }
+
+ /// @notice Gets the local liquidity container.
+ function getLocalLiquidityContainer() external view returns (address) {
+ return address(s_localLiquidityContainer);
+ }
+
+ /// @notice Sets the local liquidity container.
+ /// @dev Only the owner can call this function.
+ function setLocalLiquidityContainer(ILiquidityContainer localLiquidityContainer) external onlyOwner {
+ if (address(localLiquidityContainer) == address(0)) {
+ revert ZeroAddress();
+ }
+ s_localLiquidityContainer = localLiquidityContainer;
+
+ emit LiquidityContainerSet(address(localLiquidityContainer));
+ }
+
+ /// @notice Gets the target tokens balance.
+ function getMinimumLiquidity() external view returns (uint256) {
+ return s_minimumLiquidity;
+ }
+
+ /// @notice Sets the target tokens balance.
+ /// @dev Only the owner can call this function.
+ function setMinimumLiquidity(uint256 minimumLiquidity) external onlyOwner {
+ uint256 oldLiquidity = s_minimumLiquidity;
+ s_minimumLiquidity = minimumLiquidity;
+ emit MinimumLiquiditySet(oldLiquidity, s_minimumLiquidity);
+ }
+
+ /// @notice Gets the CLL finance team multisig address
+ function getFinanceRole() external view returns (address) {
+ return s_finance;
+ }
+
+ /// @notice Sets the finance team multisig address
+ /// @dev Only the owner can call this function.
+ function setFinanceRole(address finance) external onlyOwner {
+ s_finance = finance;
+ emit FinanceRoleSet(finance);
+ }
+
+ modifier onlyFinance() {
+ if (msg.sender != s_finance) revert OnlyFinanceRole();
+ _;
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/bridge-adapters/ArbitrumL1BridgeAdapter.sol b/contracts/src/v0.8/liquiditymanager/bridge-adapters/ArbitrumL1BridgeAdapter.sol
new file mode 100644
index 00000000000..9ab7376c273
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/bridge-adapters/ArbitrumL1BridgeAdapter.sol
@@ -0,0 +1,175 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBridgeAdapter} from "../interfaces/IBridge.sol";
+
+import {IL1GatewayRouter} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/ethereum/gateway/IL1GatewayRouter.sol";
+import {IGatewayRouter} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/libraries/gateway/IGatewayRouter.sol";
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+interface IOutbox {
+ /**
+ * @notice Executes a messages in an Outbox entry.
+ * @dev Reverts if dispute period hasn't expired, since the outbox entry
+ * is only created once the rollup confirms the respective assertion.
+ * @dev it is not possible to execute any L2-to-L1 transaction which contains data
+ * to a contract address without any code (as enforced by the Bridge contract).
+ * @param proof Merkle proof of message inclusion in send root
+ * @param index Merkle path to message
+ * @param l2Sender sender if original message (i.e., caller of ArbSys.sendTxToL1)
+ * @param to destination address for L1 contract call
+ * @param l2Block l2 block number at which sendTxToL1 call was made
+ * @param l1Block l1 block number at which sendTxToL1 call was made
+ * @param l2Timestamp l2 Timestamp at which sendTxToL1 call was made
+ * @param value wei in L1 message
+ * @param data abi-encoded L1 message data
+ */
+ function executeTransaction(
+ bytes32[] calldata proof,
+ uint256 index,
+ address l2Sender,
+ address to,
+ uint256 l2Block,
+ uint256 l1Block,
+ uint256 l2Timestamp,
+ uint256 value,
+ bytes calldata data
+ ) external;
+}
+
+/// @notice Arbitrum L1 Bridge adapter
+/// @dev Auto unwraps and re-wraps wrapped eth in the bridge.
+contract ArbitrumL1BridgeAdapter is IBridgeAdapter {
+ using SafeERC20 for IERC20;
+
+ IL1GatewayRouter internal immutable i_l1GatewayRouter;
+ IOutbox internal immutable i_l1Outbox;
+
+ error NoGatewayForToken(address token);
+ error Unimplemented();
+
+ constructor(IL1GatewayRouter l1GatewayRouter, IOutbox l1Outbox) {
+ if (address(l1GatewayRouter) == address(0) || address(l1Outbox) == address(0)) {
+ revert BridgeAddressCannotBeZero();
+ }
+ i_l1GatewayRouter = l1GatewayRouter;
+ i_l1Outbox = l1Outbox;
+ }
+
+ /// @dev these are parameters provided by the caller of the sendERC20 function
+ /// and must be determined offchain.
+ struct SendERC20Params {
+ uint256 gasLimit;
+ uint256 maxSubmissionCost;
+ uint256 maxFeePerGas;
+ }
+
+ /// @inheritdoc IBridgeAdapter
+ function sendERC20(
+ address localToken,
+ address /* remoteToken */,
+ address recipient,
+ uint256 amount,
+ bytes calldata bridgeSpecificPayload
+ ) external payable override returns (bytes memory) {
+ // receive the token transfer from the msg.sender
+ IERC20(localToken).safeTransferFrom(msg.sender, address(this), amount);
+
+ // Note: the gateway router could return 0x0 for the gateway address
+ // if that token is not yet registered
+ address gateway = IGatewayRouter(address(i_l1GatewayRouter)).getGateway(localToken);
+ if (gateway == address(0)) {
+ revert NoGatewayForToken(localToken);
+ }
+
+ // approve the gateway to transfer the token amount sent to the adapter
+ IERC20(localToken).safeApprove(gateway, amount);
+
+ SendERC20Params memory params = abi.decode(bridgeSpecificPayload, (SendERC20Params));
+
+ uint256 expectedMsgValue = (params.gasLimit * params.maxFeePerGas) + params.maxSubmissionCost;
+ if (msg.value < expectedMsgValue) {
+ revert MsgValueDoesNotMatchAmount(msg.value, expectedMsgValue);
+ }
+
+ // The router will route the call to the gateway that we approved
+ // above. The gateway will then transfer the tokens to the L2.
+ // outboundTransferCustomRefund will return the abi encoded inbox sequence number
+ // which is 256 bits, so we can cap the return data to 256 bits.
+ bytes memory inboxSequenceNumber = i_l1GatewayRouter.outboundTransferCustomRefund{value: msg.value}(
+ localToken,
+ recipient,
+ recipient,
+ amount,
+ params.gasLimit,
+ params.maxFeePerGas,
+ abi.encode(params.maxSubmissionCost, bytes(""))
+ );
+
+ return inboxSequenceNumber;
+ }
+
+ /// @dev This function is so that we can easily abi-encode the arbitrum-specific payload for the sendERC20 function.
+ function exposeSendERC20Params(SendERC20Params memory params) public pure {}
+
+ /// @dev fees have to be determined offchain for arbitrum, therefore revert here to discourage usage.
+ function getBridgeFeeInNative() public pure override returns (uint256) {
+ revert Unimplemented();
+ }
+
+ /// @param proof Merkle proof of message inclusion in send root
+ /// @param index Merkle path to message
+ /// @param l2Sender sender if original message (i.e., caller of ArbSys.sendTxToL1)
+ /// @param to destination address for L1 contract call
+ /// @param l2Block l2 block number at which sendTxToL1 call was made
+ /// @param l1Block l1 block number at which sendTxToL1 call was made
+ /// @param l2Timestamp l2 Timestamp at which sendTxToL1 call was made
+ /// @param value wei in L1 message
+ /// @param data abi-encoded L1 message data
+ struct ArbitrumFinalizationPayload {
+ bytes32[] proof;
+ uint256 index;
+ address l2Sender;
+ address to;
+ uint256 l2Block;
+ uint256 l1Block;
+ uint256 l2Timestamp;
+ uint256 value;
+ bytes data;
+ }
+
+ /// @dev This function is so that we can easily abi-encode the arbitrum-specific payload for the finalizeWithdrawERC20 function.
+ function exposeArbitrumFinalizationPayload(ArbitrumFinalizationPayload memory payload) public pure {}
+
+ /// @notice Finalize an L2 -> L1 transfer.
+ /// Arbitrum finalizations are single-step, so we always return true.
+ /// Calls to this function will revert in two cases, 1) if the finalization payload is wrong,
+ /// i.e incorrect merkle proof, or index and 2) if the withdrawal was already finalized.
+ /// @return true iff the finalization does not revert.
+ function finalizeWithdrawERC20(
+ address /* remoteSender */,
+ address /* localReceiver */,
+ bytes calldata arbitrumFinalizationPayload
+ ) external override returns (bool) {
+ ArbitrumFinalizationPayload memory payload = abi.decode(arbitrumFinalizationPayload, (ArbitrumFinalizationPayload));
+ i_l1Outbox.executeTransaction(
+ payload.proof,
+ payload.index,
+ payload.l2Sender,
+ payload.to,
+ payload.l2Block,
+ payload.l1Block,
+ payload.l2Timestamp,
+ payload.value,
+ payload.data
+ );
+ return true;
+ }
+
+ /// @notice Convenience function to get the L2 token address from the L1 token address.
+ /// @return The L2 token address for the given L1 token address.
+ function getL2Token(address l1Token) external view returns (address) {
+ return i_l1GatewayRouter.calculateL2TokenAddress(l1Token);
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/bridge-adapters/ArbitrumL2BridgeAdapter.sol b/contracts/src/v0.8/liquiditymanager/bridge-adapters/ArbitrumL2BridgeAdapter.sol
new file mode 100644
index 00000000000..6ee97163f65
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/bridge-adapters/ArbitrumL2BridgeAdapter.sol
@@ -0,0 +1,78 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBridgeAdapter} from "../interfaces/IBridge.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+interface IArbSys {
+ function withdrawEth(address destination) external payable returns (uint256);
+}
+
+interface IL2GatewayRouter {
+ function outboundTransfer(
+ address l1Token,
+ address to,
+ uint256 amount,
+ bytes calldata data
+ ) external payable returns (bytes memory);
+}
+
+/// @notice Arbitrum L2 Bridge adapter
+/// @dev Auto unwraps and re-wraps wrapped eth in the bridge.
+contract ArbitrumL2BridgeAdapter is IBridgeAdapter {
+ using SafeERC20 for IERC20;
+
+ IL2GatewayRouter internal immutable i_l2GatewayRouter;
+ // address internal immutable i_l1ERC20Gateway;
+ IArbSys internal constant ARB_SYS = IArbSys(address(0x64));
+
+ constructor(IL2GatewayRouter l2GatewayRouter) {
+ if (address(l2GatewayRouter) == address(0)) {
+ revert BridgeAddressCannotBeZero();
+ }
+ i_l2GatewayRouter = l2GatewayRouter;
+ }
+
+ /// @inheritdoc IBridgeAdapter
+ function sendERC20(
+ address localToken,
+ address remoteToken,
+ address recipient,
+ uint256 amount,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external payable override returns (bytes memory) {
+ if (msg.value != 0) {
+ revert MsgShouldNotContainValue(msg.value);
+ }
+
+ IERC20(localToken).safeTransferFrom(msg.sender, address(this), amount);
+
+ // the data returned is the unique id of the L2 to L1 transfer
+ // see https://github.com/OffchainLabs/token-bridge-contracts/blob/bf9ad3d7f25c0eaf0a5f89eec7a0a370833cea16/contracts/tokenbridge/arbitrum/gateway/L2ArbitrumGateway.sol#L169-L191
+ // No approval needed, the bridge will burn the tokens from this contract.
+ bytes memory l2ToL1TxId = i_l2GatewayRouter.outboundTransfer(remoteToken, recipient, amount, bytes(""));
+
+ return l2ToL1TxId;
+ }
+
+ /// @notice No-op since L1 -> L2 transfers do not need finalization.
+ /// @return true always.
+ function finalizeWithdrawERC20(
+ address /* remoteSender */,
+ address /* localReceiver */,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external pure override returns (bool) {
+ return true;
+ }
+
+ /// @notice There are no fees to bridge back to L1
+ function getBridgeFeeInNative() external pure returns (uint256) {
+ return 0;
+ }
+
+ function depositNativeToL1(address recipient) external payable {
+ ARB_SYS.withdrawEth{value: msg.value}(recipient);
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/bridge-adapters/OptimismL1BridgeAdapter.sol b/contracts/src/v0.8/liquiditymanager/bridge-adapters/OptimismL1BridgeAdapter.sol
new file mode 100644
index 00000000000..6734c74bd8d
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/bridge-adapters/OptimismL1BridgeAdapter.sol
@@ -0,0 +1,196 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBridgeAdapter} from "../interfaces/IBridge.sol";
+import {IWrappedNative} from "../../ccip/interfaces/IWrappedNative.sol";
+import {Types} from "../interfaces/optimism/Types.sol";
+import {IOptimismPortal} from "../interfaces/optimism/IOptimismPortal.sol";
+
+import {IL1StandardBridge} from "@eth-optimism/contracts/L1/messaging/IL1StandardBridge.sol";
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice OptimismL1BridgeAdapter implements IBridgeAdapter for the Optimism L1<=>L2 bridge.
+/// @dev L1 -> L2 deposits are done via the depositERC20To and depositETHTo functions on the L1StandardBridge.
+/// The amount of gas provided for the transaction must be buffered - the Optimism SDK recommends a 20% buffer.
+/// The Optimism Bridge implements 2-step withdrawals from L2 to L1. Once a withdrawal transaction is included
+/// in the L2 chain, it must be proven on L1 before it can be finalized. There is a buffer between the transaction
+/// being posted on L2 before it can be proven, and similarly, there is a buffer in the time it takes to prove
+/// the transaction before it can be finalized.
+/// See https://blog.oplabs.co/two-step-withdrawals/ for more details on this mechanism.
+/// @dev We have to unwrap WETH into ether before depositing it to L2. Therefore this bridge adapter bridges
+/// WETH to ether. The receiver on L2 must wrap the ether back into WETH.
+contract OptimismL1BridgeAdapter is IBridgeAdapter {
+ using SafeERC20 for IERC20;
+
+ /// @notice used when the action in the payload is invalid.
+ error InvalidFinalizationAction();
+
+ /// @notice Payload for proving a withdrawal from L2 on L1 via finalizeWithdrawERC20.
+ /// @param withdrawalTransaction The withdrawal transaction, see its docstring for more details.
+ /// @param l2OutputIndex The index of the output in the L2 block, or the dispute game index post fault proof upgrade.
+ /// @param outputRootProof The inclusion proof of the L2ToL1MessagePasser contract's storage root.
+ /// @param withdrawalProof The Merkle proof of the withdrawal key presence in the L2ToL1MessagePasser contract's state trie.
+ struct OptimismProveWithdrawalPayload {
+ Types.WithdrawalTransaction withdrawalTransaction;
+ uint256 l2OutputIndex;
+ Types.OutputRootProof outputRootProof;
+ bytes[] withdrawalProof;
+ }
+
+ /// @notice Payload for finalizing a withdrawal from L2 on L1.
+ /// Note that the withdrawal must be proven first before it can be finalized.
+ /// @param withdrawalTransaction The withdrawal transaction, see its docstring for more details.
+ struct OptimismFinalizationPayload {
+ Types.WithdrawalTransaction withdrawalTransaction;
+ }
+
+ /// @notice The action to take when finalizing a withdrawal.
+ /// Optimism implements two-step withdrawals, so we need to specify the action to take
+ /// each time the finalizeWithdrawERC20 function is called.
+ enum FinalizationAction {
+ ProveWithdrawal,
+ FinalizeWithdrawal
+ }
+
+ /// @notice Payload for interacting with the finalizeWithdrawERC20 function.
+ /// Since Optimism has 2-step withdrawals, we cannot finalize and get the funds on L1 in the same transaction.
+ /// @param action The action to take; either ProveWithdrawal or FinalizeWithdrawal.
+ /// @param data The payload for the action. If ProveWithdrawal, it must be an abi-encoded OptimismProveWithdrawalPayload.
+ /// If FinalizeWithdrawal, it must be an abi-encoded OptimismFinalizationPayload.
+ struct FinalizeWithdrawERC20Payload {
+ FinalizationAction action;
+ bytes data;
+ }
+
+ /// @dev Reference to the L1StandardBridge contract. Deposits to L2 go through this contract.
+ IL1StandardBridge internal immutable i_L1Bridge;
+
+ /// @dev Reference to the WrappedNative contract. Optimism bridges ether directly rather than WETH,
+ /// so we need to unwrap WETH into ether before depositing it to L2.
+ IWrappedNative internal immutable i_wrappedNative;
+
+ /// @dev Reference to the OptimismPortal contract, which is used to prove and finalize withdrawals.
+ IOptimismPortal internal immutable i_optimismPortal;
+
+ /// @dev Nonce to use for L2 deposits to allow for better tracking offchain.
+ uint64 private s_nonce = 0;
+
+ constructor(IL1StandardBridge l1Bridge, IWrappedNative wrappedNative, IOptimismPortal optimismPortal) {
+ if (
+ address(l1Bridge) == address(0) || address(wrappedNative) == address(0) || address(optimismPortal) == address(0)
+ ) {
+ revert BridgeAddressCannotBeZero();
+ }
+ i_L1Bridge = l1Bridge;
+ i_wrappedNative = wrappedNative;
+ i_optimismPortal = optimismPortal;
+ }
+
+ /// @notice The WETH withdraw requires this be present otherwise withdraws will fail.
+ receive() external payable {}
+
+ /// @inheritdoc IBridgeAdapter
+ function sendERC20(
+ address localToken,
+ address remoteToken,
+ address recipient,
+ uint256 amount,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external payable override returns (bytes memory) {
+ IERC20(localToken).safeTransferFrom(msg.sender, address(this), amount);
+
+ if (msg.value != 0) {
+ revert MsgShouldNotContainValue(msg.value);
+ }
+
+ // Extra data for the L2 deposit.
+ // We encode the nonce in the extra data so that we can track the L2 deposit offchain.
+ bytes memory extraData = abi.encode(s_nonce++);
+
+ // If the token is the wrapped native, we unwrap it and deposit native
+ if (localToken == address(i_wrappedNative)) {
+ i_wrappedNative.withdraw(amount);
+ i_L1Bridge.depositETHTo{value: amount}(recipient, 0, extraData);
+ return extraData;
+ }
+
+ // Token is a normal ERC20.
+ IERC20(localToken).safeApprove(address(i_L1Bridge), amount);
+ i_L1Bridge.depositERC20To(localToken, remoteToken, recipient, amount, 0, extraData);
+
+ return extraData;
+ }
+
+ /// @notice Bridging to Optimism is paid for with gas
+ /// @dev Since the gas amount charged is dynamic, the gas burn can change from block to block.
+ /// You should always add a buffer of at least 20% to the gas limit for your L1 to L2 transaction
+ /// to avoid running out of gas.
+ function getBridgeFeeInNative() public pure returns (uint256) {
+ return 0;
+ }
+
+ /// @notice Prove or finalize an ERC20 withdrawal from L2.
+ /// The action to take is specified in the payload. See the docstring of FinalizeWithdrawERC20Payload for more details.
+ /// @param data The payload for the action. This is an abi.encode'd FinalizeWithdrawERC20Payload with the appropriate data.
+ /// @return true iff finalization is successful, and false for proving a withdrawal. If either of these fail,
+ /// the call to this function will revert.
+ function finalizeWithdrawERC20(
+ address /* remoteSender */,
+ address /* localReceiver */,
+ bytes calldata data
+ ) external override returns (bool) {
+ // decode the data into FinalizeWithdrawERC20Payload first and extract the action.
+ FinalizeWithdrawERC20Payload memory payload = abi.decode(data, (FinalizeWithdrawERC20Payload));
+ if (payload.action == FinalizationAction.ProveWithdrawal) {
+ // The action being ProveWithdrawal indicates that this is a withdrawal proof payload.
+ // Decode the data into OptimismProveWithdrawalPayload and call the proveWithdrawal function.
+ OptimismProveWithdrawalPayload memory provePayload = abi.decode(payload.data, (OptimismProveWithdrawalPayload));
+ _proveWithdrawal(provePayload);
+ return false;
+ } else if (payload.action == FinalizationAction.FinalizeWithdrawal) {
+ // decode the data into OptimismFinalizationPayload and call the finalizeWithdrawal function.
+ OptimismFinalizationPayload memory finalizePayload = abi.decode(payload.data, (OptimismFinalizationPayload));
+ // NOTE: finalizing ether withdrawals will currently send ether to the receiver address as indicated by the
+ // withdrawal tx. However, this is problematic because we need to re-wrap it into WETH.
+ // However, we can't do that from within this adapter because it doesn't actually have the ether.
+ // So its up to the caller to rectify this by re-wrapping the ether.
+ _finalizeWithdrawal(finalizePayload);
+ return true;
+ } else {
+ revert InvalidFinalizationAction();
+ }
+ }
+
+ function _proveWithdrawal(OptimismProveWithdrawalPayload memory payload) internal {
+ // will revert if the proof is invalid or the output index is not yet included on L1.
+ i_optimismPortal.proveWithdrawalTransaction(
+ payload.withdrawalTransaction,
+ payload.l2OutputIndex,
+ payload.outputRootProof,
+ payload.withdrawalProof
+ );
+ }
+
+ function _finalizeWithdrawal(OptimismFinalizationPayload memory payload) internal {
+ i_optimismPortal.finalizeWithdrawalTransaction(payload.withdrawalTransaction);
+ }
+
+ /// @notice returns the address of the WETH token used by this adapter.
+ /// @return the address of the WETH token used by this adapter.
+ function getWrappedNative() external view returns (address) {
+ return address(i_wrappedNative);
+ }
+
+ /// @notice returns the address of the Optimism portal contract.
+ /// @return the address of the Optimism portal contract.
+ function getOptimismPortal() external view returns (address) {
+ return address(i_optimismPortal);
+ }
+
+ /// @notice returns the address of the Optimism L1StandardBridge bridge contract.
+ /// @return the address of the Optimism L1StandardBridge bridge contract.
+ function getL1Bridge() external view returns (address) {
+ return address(i_L1Bridge);
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/bridge-adapters/OptimismL2BridgeAdapter.sol b/contracts/src/v0.8/liquiditymanager/bridge-adapters/OptimismL2BridgeAdapter.sol
new file mode 100644
index 00000000000..fd1218f6704
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/bridge-adapters/OptimismL2BridgeAdapter.sol
@@ -0,0 +1,119 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IBridgeAdapter} from "../interfaces/IBridge.sol";
+import {IWrappedNative} from "../../ccip/interfaces/IWrappedNative.sol";
+
+import {Lib_PredeployAddresses} from "@eth-optimism/contracts/libraries/constants/Lib_PredeployAddresses.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @dev copy/pasted from https://github.com/ethereum-optimism/optimism/blob/f707883038d527cbf1e9f8ea513fe33255deadbc/packages/contracts-bedrock/src/L2/L2StandardBridge.sol#L114-L122.
+/// We can't import it because of hard pin solidity version in the pragma (0.8.15).
+interface IL2StandardBridge {
+ /// @custom:legacy
+ /// @notice Initiates a withdrawal from L2 to L1 to a target account on L1.
+ /// Note that if ETH is sent to a contract on L1 and the call fails, then that ETH will
+ /// be locked in the L1StandardBridge. ETH may be recoverable if the call can be
+ /// successfully replayed by increasing the amount of gas supplied to the call. If the
+ /// call will fail for any amount of gas, then the ETH will be locked permanently.
+ /// This function only works with OptimismMintableERC20 tokens or ether. Use the
+ /// `bridgeERC20To` function to bridge native L2 tokens to L1.
+ /// @param _l2Token Address of the L2 token to withdraw.
+ /// @param _to Recipient account on L1.
+ /// @param _amount Amount of the L2 token to withdraw.
+ /// @param _minGasLimit Minimum gas limit to use for the transaction.
+ /// @param _extraData Extra data attached to the withdrawal.
+ function withdrawTo(
+ address _l2Token,
+ address _to,
+ uint256 _amount,
+ uint32 _minGasLimit,
+ bytes calldata _extraData
+ ) external payable;
+}
+
+/// @notice OptimismL2BridgeAdapter implements IBridgeAdapter for the Optimism L2<=>L1 bridge.
+/// @dev We have to unwrap WETH into ether before withdrawing it to L1. Therefore this bridge adapter bridges
+/// WETH to ether. The receiver on L1 must wrap the ether back into WETH.
+contract OptimismL2BridgeAdapter is IBridgeAdapter {
+ using SafeERC20 for IERC20;
+
+ IL2StandardBridge internal immutable i_L2Bridge = IL2StandardBridge(Lib_PredeployAddresses.L2_STANDARD_BRIDGE);
+ IWrappedNative internal immutable i_wrappedNative;
+
+ // Nonce to use for L1 withdrawals to allow for better tracking offchain.
+ uint64 private s_nonce = 0;
+
+ constructor(IWrappedNative wrappedNative) {
+ // Wrapped native can be address zero, this means that auto-wrapping is disabled.
+ i_wrappedNative = wrappedNative;
+ }
+
+ /// @notice The WETH withdraw requires this be present otherwise withdraws will fail.
+ receive() external payable {}
+
+ /// @inheritdoc IBridgeAdapter
+ function sendERC20(
+ address localToken,
+ address /* remoteToken */,
+ address recipient,
+ uint256 amount,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external payable override returns (bytes memory) {
+ if (msg.value != 0) {
+ revert MsgShouldNotContainValue(msg.value);
+ }
+
+ IERC20(localToken).safeTransferFrom(msg.sender, address(this), amount);
+
+ // Extra data for the L2 withdraw.
+ // We encode the nonce in the extra data so that we can track the L2 withdraw offchain.
+ bytes memory extraData = abi.encode(s_nonce++);
+
+ // If the token is the wrapped native, we unwrap it and withdraw native
+ if (localToken == address(i_wrappedNative)) {
+ i_wrappedNative.withdraw(amount);
+ // XXX: Lib_PredeployAddresses.OVM_ETH is actually 0xDeadDeAddeAddEAddeadDEaDDEAdDeaDDeAD0000.
+ // This code path still works because the L2 bridge is hardcoded to handle this specific address.
+ // The better approach might be to use the bridgeEthTo function, which is on the StandardBridge
+ // abstract contract, inherited by both L1StandardBridge and L2StandardBridge.
+ // This is also marked as legacy, so it might mean that this will be deprecated soon.
+ i_L2Bridge.withdrawTo{value: amount}(Lib_PredeployAddresses.OVM_ETH, recipient, amount, 0, extraData);
+ return extraData;
+ }
+
+ // Token is normal ERC20
+ IERC20(localToken).approve(address(i_L2Bridge), amount);
+ i_L2Bridge.withdrawTo(localToken, recipient, amount, 0, extraData);
+ return extraData;
+ }
+
+ /// @notice No-op since L1 -> L2 transfers do not need finalization.
+ /// @return true always.
+ function finalizeWithdrawERC20(
+ address /* remoteSender */,
+ address /* localReceiver */,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external pure override returns (bool) {
+ return true;
+ }
+
+ /// @notice There are no fees to bridge back to L1
+ function getBridgeFeeInNative() external pure returns (uint256) {
+ return 0;
+ }
+
+ /// @notice returns the address of the WETH token used by this adapter.
+ /// @return the address of the WETH token used by this adapter.
+ function getWrappedNative() external view returns (address) {
+ return address(i_wrappedNative);
+ }
+
+ /// @notice returns the address of the L2 bridge used by this adapter.
+ /// @return the address of the L2 bridge used by this adapter.
+ function getL2Bridge() external view returns (address) {
+ return address(i_L2Bridge);
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/encoders/OptimismL1BridgeAdapterEncoder.sol b/contracts/src/v0.8/liquiditymanager/encoders/OptimismL1BridgeAdapterEncoder.sol
new file mode 100644
index 00000000000..888b48732d7
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/encoders/OptimismL1BridgeAdapterEncoder.sol
@@ -0,0 +1,21 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OptimismL1BridgeAdapter} from "../bridge-adapters/OptimismL1BridgeAdapter.sol";
+
+/// @dev to generate abi's for the OptimismL1BridgeAdapter's various payload types.
+/// @dev for usage examples see core/scripts/ccip/liquiditymanager/opstack/prove_withdrawal.go
+/// @dev or core/scripts/ccip/liquiditymanager/opstack/finalize.go.
+abstract contract OptimismL1BridgeAdapterEncoder {
+ function encodeFinalizeWithdrawalERC20Payload(
+ OptimismL1BridgeAdapter.FinalizeWithdrawERC20Payload memory payload
+ ) public pure {}
+
+ function encodeOptimismProveWithdrawalPayload(
+ OptimismL1BridgeAdapter.OptimismProveWithdrawalPayload memory payload
+ ) public pure {}
+
+ function encodeOptimismFinalizationPayload(
+ OptimismL1BridgeAdapter.OptimismFinalizationPayload memory payload
+ ) public pure {}
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/IBridge.sol b/contracts/src/v0.8/liquiditymanager/interfaces/IBridge.sol
new file mode 100644
index 00000000000..83e64edce48
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/IBridge.sol
@@ -0,0 +1,49 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+/// @dev IBridgeAdapter provides a common interface to interact with the native bridge.
+interface IBridgeAdapter {
+ error BridgeAddressCannotBeZero();
+ error MsgValueDoesNotMatchAmount(uint256 msgValue, uint256 amount);
+ error InsufficientEthValue(uint256 wanted, uint256 got);
+ error MsgShouldNotContainValue(uint256 value);
+
+ /// @notice Send the specified amount of the local token cross-chain to the remote chain.
+ /// The tokens on the remote chain will then be sourced from the remoteToken address.
+ /// The amount to be sent must be approved by the caller beforehand on the localToken contract.
+ /// The caller must provide the bridging fee in native currency, i.e msg.value.
+ /// @param localToken The address of the local ERC-20 token.
+ /// @param remoteToken The address of the remote ERC-20 token.
+ /// @param recipient The address of the recipient on the remote chain.
+ /// @param amount The amount of the local token to send.
+ /// @param bridgeSpecificPayload The payload of the cross-chain transfer. Bridge-specific.
+ function sendERC20(
+ address localToken,
+ address remoteToken,
+ address recipient,
+ uint256 amount,
+ bytes calldata bridgeSpecificPayload
+ ) external payable returns (bytes memory);
+
+ /// @notice Get the bridging fee in native currency. This fee must be provided upon sending tokens via
+ /// the sendERC20 function.
+ /// @return The bridging fee in native currency.
+ function getBridgeFeeInNative() external view returns (uint256);
+
+ /// @notice Finalize the withdrawal of a cross-chain transfer.
+ /// Not all implementations will finalize a transfer in a single call to this function.
+ /// Optimism, for example, requires a two-step process to finalize a transfer. The first
+ /// step requires proving the withdrawal that occurred on L2 on L1. The second step is then
+ /// the finalization, whereby funds become available to the recipient. So, in that particular
+ /// scenario, `false` is returned from `finalizeWithdrawERC20` when the first step is completed,
+ /// and `true` is returned when the second step is completed.
+ /// @param remoteSender The address of the sender on the remote chain.
+ /// @param localReceiver The address of the receiver on the local chain.
+ /// @param bridgeSpecificPayload The payload of the cross-chain transfer, bridge-specific, i.e a proof of some kind.
+ /// @return true iff the funds are available, false otherwise.
+ function finalizeWithdrawERC20(
+ address remoteSender,
+ address localReceiver,
+ bytes calldata bridgeSpecificPayload
+ ) external returns (bool);
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/ILiquidityContainer.sol b/contracts/src/v0.8/liquiditymanager/interfaces/ILiquidityContainer.sol
new file mode 100644
index 00000000000..062325d9531
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/ILiquidityContainer.sol
@@ -0,0 +1,16 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+/// @notice Interface for a liquidity container, this can be a CCIP token pool.
+interface ILiquidityContainer {
+ event LiquidityAdded(address indexed provider, uint256 indexed amount);
+ event LiquidityRemoved(address indexed provider, uint256 indexed amount);
+
+ /// @notice Provide additional liquidity to the container.
+ /// @dev Should emit LiquidityAdded
+ function provideLiquidity(uint256 amount) external;
+
+ /// @notice Withdraws liquidity from the container to the msg sender
+ /// @dev Should emit LiquidityRemoved
+ function withdrawLiquidity(uint256 amount) external;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/ILiquidityManager.sol b/contracts/src/v0.8/liquiditymanager/interfaces/ILiquidityManager.sol
new file mode 100644
index 00000000000..19fd1014a4d
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/ILiquidityManager.sol
@@ -0,0 +1,62 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IBridgeAdapter} from "./IBridge.sol";
+
+interface ILiquidityManager {
+ /// @notice Parameters for sending liquidity to a remote chain.
+ /// @param amount The amount of tokens to be sent to the remote chain.
+ /// @param nativeBridgeFee The amount of native that should be sent by the liquiditymanager in the sendERC20 call.
+ /// Used to pay for the bridge fees.
+ /// @param remoteChainSelector The selector of the remote chain.
+ /// @param bridgeData The bridge data that should be passed to the sendERC20 call.
+ struct SendLiquidityParams {
+ uint256 amount;
+ uint256 nativeBridgeFee;
+ uint64 remoteChainSelector;
+ bytes bridgeData;
+ }
+
+ /// @notice Parameters for receiving liquidity from a remote chain.
+ /// @param amount The amount of tokens to be received from the remote chain.
+ /// @param remoteChainSelector The selector of the remote chain.
+ /// @param bridgeData The bridge data that should be passed to the finalizeWithdrawERC20 call.
+ /// @param shouldWrapNative Whether the received native token should be wrapped into wrapped native.
+ /// This is needed for when the bridge being used doesn't bridge wrapped native but native directly.
+ struct ReceiveLiquidityParams {
+ uint256 amount;
+ uint64 remoteChainSelector;
+ bool shouldWrapNative;
+ bytes bridgeData;
+ }
+
+ /// @notice Instructions for the rebalancer on what to do with the available liquidity.
+ /// @param sendLiquidityParams The parameters for sending liquidity to a remote chain.
+ /// @param receiveLiquidityParams The parameters for receiving liquidity from a remote chain.
+ struct LiquidityInstructions {
+ SendLiquidityParams[] sendLiquidityParams;
+ ReceiveLiquidityParams[] receiveLiquidityParams;
+ }
+
+ /// @notice Parameters for adding a cross-chain rebalancer.
+ /// @param remoteRebalancer The address of the remote rebalancer.
+ /// @param localBridge The local bridge adapter address.
+ /// @param remoteToken The address of the remote token.
+ /// @param remoteChainSelector The selector of the remote chain.
+ /// @param enabled Whether the rebalancer is enabled.
+ struct CrossChainRebalancerArgs {
+ address remoteRebalancer;
+ IBridgeAdapter localBridge;
+ address remoteToken;
+ uint64 remoteChainSelector;
+ bool enabled;
+ }
+
+ /// @notice Returns the current liquidity in the liquidity container.
+ /// @return currentLiquidity The current liquidity in the liquidity container.
+ function getLiquidity() external view returns (uint256 currentLiquidity);
+
+ /// @notice Returns all the cross-chain rebalancers.
+ /// @return All the cross-chain rebalancers.
+ function getAllCrossChainRebalancers() external view returns (CrossChainRebalancerArgs[] memory);
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IAbstractArbitrumTokenGateway.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IAbstractArbitrumTokenGateway.sol
new file mode 100644
index 00000000000..c695729fa93
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IAbstractArbitrumTokenGateway.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {TokenGateway} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/libraries/gateway/TokenGateway.sol";
+
+/// @dev to generate gethwrappers
+abstract contract IAbstractArbitrumTokenGateway is TokenGateway {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbRollupCore.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbRollupCore.sol
new file mode 100644
index 00000000000..a5d0e5e8e6a
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbRollupCore.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IRollupCore} from "@arbitrum/nitro-contracts/src/rollup/IRollupCore.sol";
+
+/// @dev to generate gethwrappers
+interface IArbRollupCore is IRollupCore {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbSys.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbSys.sol
new file mode 100644
index 00000000000..7d6afbc18e4
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbSys.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {ArbSys} from "../../../vendor/@arbitrum/nitro-contracts/src/precompiles/ArbSys.sol";
+
+/// @dev to generate gethwrappers
+interface IArbSys is ArbSys {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumGatewayRouter.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumGatewayRouter.sol
new file mode 100644
index 00000000000..81fc2cb1b5e
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumGatewayRouter.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IGatewayRouter} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/libraries/gateway/IGatewayRouter.sol";
+
+/// @dev to generate gethwrappers
+interface IArbitrumGatewayRouter is IGatewayRouter {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumInbox.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumInbox.sol
new file mode 100644
index 00000000000..a306ef21b1a
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumInbox.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IInboxBase} from "@arbitrum/nitro-contracts/src/bridge/IInboxBase.sol";
+
+/// @dev to generate gethwrappers
+interface IArbitrumInbox is IInboxBase {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumL1GatewayRouter.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumL1GatewayRouter.sol
new file mode 100644
index 00000000000..49e7e45dd7d
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumL1GatewayRouter.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {IL1GatewayRouter} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/ethereum/gateway/IL1GatewayRouter.sol";
+
+/// @dev to generate gethwrappers
+interface IArbitrumL1GatewayRouter is IL1GatewayRouter {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumTokenGateway.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumTokenGateway.sol
new file mode 100644
index 00000000000..0c1f2281890
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IArbitrumTokenGateway.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {ITokenGateway} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/libraries/gateway/ITokenGateway.sol";
+
+/// @dev to generate gethwrappers
+interface IArbitrumTokenGateway is ITokenGateway {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IL2ArbitrumGateway.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IL2ArbitrumGateway.sol
new file mode 100644
index 00000000000..96a63a0dcd0
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IL2ArbitrumGateway.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {L2ArbitrumGateway} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/arbitrum/gateway/L2ArbitrumGateway.sol";
+
+/// @dev to generate gethwrappers
+abstract contract IL2ArbitrumGateway is L2ArbitrumGateway {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IL2ArbitrumMessenger.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IL2ArbitrumMessenger.sol
new file mode 100644
index 00000000000..115882a2115
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/IL2ArbitrumMessenger.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {L2ArbitrumMessenger} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/arbitrum/L2ArbitrumMessenger.sol";
+
+/// @dev to generate gethwrappers
+abstract contract IL2ArbitrumMessenger is L2ArbitrumMessenger {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/INodeInterface.sol b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/INodeInterface.sol
new file mode 100644
index 00000000000..79475cdf5d1
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/arbitrum/INodeInterface.sol
@@ -0,0 +1,7 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {NodeInterface} from "@arbitrum/nitro-contracts/src/node-interface/NodeInterface.sol";
+
+/// @dev to generate gethwrappers
+interface INodeInterface is NodeInterface {}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/DisputeTypes.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/DisputeTypes.sol
new file mode 100644
index 00000000000..f0bd99fbcde
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/DisputeTypes.sol
@@ -0,0 +1,23 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/libraries/DisputeTypes.sol
+pragma solidity ^0.8.0;
+
+/// @notice A `GameType` represents the type of game being played.
+type GameType is uint32;
+
+/// @notice A `GameId` represents a packed 1 byte game ID, an 11 byte timestamp, and a 20 byte address.
+/// @dev The packed layout of this type is as follows:
+/// ┌───────────┬───────────┐
+/// │ Bits │ Value │
+/// ├───────────┼───────────┤
+/// │ [0, 8) │ Game Type │
+/// │ [8, 96) │ Timestamp │
+/// │ [96, 256) │ Address │
+/// └───────────┴───────────┘
+type GameId is bytes32;
+
+/// @notice A dedicated timestamp type.
+type Timestamp is uint64;
+
+/// @notice A claim represents an MPT root representing the state of the fault proof program.
+type Claim is bytes32;
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismCrossDomainMessenger.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismCrossDomainMessenger.sol
new file mode 100644
index 00000000000..2b5cc650724
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismCrossDomainMessenger.sol
@@ -0,0 +1,31 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/f707883038d527cbf1e9f8ea513fe33255deadbc/packages/contracts-bedrock/src/universal/CrossDomainMessenger.sol#L153
+pragma solidity ^0.8.0;
+
+interface IOptimismCrossDomainMessenger {
+ /// @notice Emitted whenever a message is sent to the other chain.
+ /// @param target Address of the recipient of the message.
+ /// @param sender Address of the sender of the message.
+ /// @param message Message to trigger the recipient address with.
+ /// @param messageNonce Unique nonce attached to the message.
+ /// @param gasLimit Minimum gas limit that the message can be executed with.
+ event SentMessage(address indexed target, address sender, bytes message, uint256 messageNonce, uint256 gasLimit);
+
+ /// @notice Relays a message that was sent by the other CrossDomainMessenger contract. Can only
+ /// be executed via cross-chain call from the other messenger OR if the message was
+ /// already received once and is currently being replayed.
+ /// @param _nonce Nonce of the message being relayed.
+ /// @param _sender Address of the user who sent the message.
+ /// @param _target Address that the message is targeted at.
+ /// @param _value ETH value to send with the message.
+ /// @param _minGasLimit Minimum amount of gas that the message can be executed with.
+ /// @param _message Message to send to the target.
+ function relayMessage(
+ uint256 _nonce,
+ address _sender,
+ address _target,
+ uint256 _value,
+ uint256 _minGasLimit,
+ bytes calldata _message
+ ) external payable;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismDisputeGameFactory.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismDisputeGameFactory.sol
new file mode 100644
index 00000000000..f72e6456d3f
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismDisputeGameFactory.sol
@@ -0,0 +1,31 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/dispute/DisputeGameFactory.sol
+pragma solidity ^0.8.0;
+
+import {GameType, GameId, Timestamp, Claim} from "./DisputeTypes.sol";
+
+interface IOptimismDisputeGameFactory {
+ /// @notice Information about a dispute game found in a `findLatestGames` search.
+ struct GameSearchResult {
+ uint256 index;
+ GameId metadata;
+ Timestamp timestamp;
+ Claim rootClaim;
+ bytes extraData;
+ }
+
+ /// @notice Finds the `_n` most recent `GameId`'s of type `_gameType` starting at `_start`. If there are less than
+ /// `_n` games of type `_gameType` starting at `_start`, then the returned array will be shorter than `_n`.
+ /// @param _gameType The type of game to find.
+ /// @param _start The index to start the reverse search from.
+ /// @param _n The number of games to find.
+ function findLatestGames(
+ GameType _gameType,
+ uint256 _start,
+ uint256 _n
+ ) external view returns (GameSearchResult[] memory games_);
+
+ /// @notice The total number of dispute games created by this factory.
+ /// @return gameCount_ The total number of dispute games created by this factory.
+ function gameCount() external view returns (uint256 gameCount_);
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL1StandardBridge.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL1StandardBridge.sol
new file mode 100644
index 00000000000..3a518fcf798
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL1StandardBridge.sol
@@ -0,0 +1,18 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/f707883038d527cbf1e9f8ea513fe33255deadbc/packages/contracts-bedrock/src/L1/L1StandardBridge.sol
+pragma solidity ^0.8.0;
+
+interface IOptimismL1StandardBridge {
+ /// @custom:legacy
+ /// @notice Deposits some amount of ETH into a target account on L2.
+ /// Note that if ETH is sent to a contract on L2 and the call fails, then that ETH will
+ /// be locked in the L2StandardBridge. ETH may be recoverable if the call can be
+ /// successfully replayed by increasing the amount of gas supplied to the call. If the
+ /// call will fail for any amount of gas, then the ETH will be locked permanently.
+ /// @param _to Address of the recipient on L2.
+ /// @param _minGasLimit Minimum gas limit for the deposit message on L2.
+ /// @param _extraData Optional data to forward to L2.
+ /// Data supplied here will not be used to execute any code on L2 and is
+ /// only emitted as extra data for the convenience of off-chain tooling.
+ function depositETHTo(address _to, uint32 _minGasLimit, bytes calldata _extraData) external payable;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL2OutputOracle.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL2OutputOracle.sol
new file mode 100644
index 00000000000..fa36863c5b7
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL2OutputOracle.sol
@@ -0,0 +1,19 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/L1/L2OutputOracle.sol
+pragma solidity ^0.8.0;
+
+import {Types} from "./Types.sol";
+
+interface IOptimismL2OutputOracle {
+ /// @notice Returns the index of the L2 output that checkpoints a given L2 block number.
+ /// Uses a binary search to find the first output greater than or equal to the given
+ /// block.
+ /// @param _l2BlockNumber L2 block number to find a checkpoint for.
+ /// @return Index of the first checkpoint that commits to the given L2 block number.
+ function getL2OutputIndexAfter(uint256 _l2BlockNumber) external view returns (uint256);
+
+ /// @notice Returns an output by index. Needed to return a struct instead of a tuple.
+ /// @param _l2OutputIndex Index of the output to return.
+ /// @return The output at the given index.
+ function getL2Output(uint256 _l2OutputIndex) external view returns (Types.OutputProposal memory);
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL2ToL1MessagePasser.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL2ToL1MessagePasser.sol
new file mode 100644
index 00000000000..9ac6aebfb28
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismL2ToL1MessagePasser.sol
@@ -0,0 +1,23 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/L2/L2ToL1MessagePasser.sol
+pragma solidity ^0.8.0;
+
+interface IOptimismL2ToL1MessagePasser {
+ /// @notice Emitted any time a withdrawal is initiated.
+ /// @param nonce Unique value corresponding to each withdrawal.
+ /// @param sender The L2 account address which initiated the withdrawal.
+ /// @param target The L1 account address the call will be send to.
+ /// @param value The ETH value submitted for withdrawal, to be forwarded to the target.
+ /// @param gasLimit The minimum amount of gas that must be provided when withdrawing.
+ /// @param data The data to be forwarded to the target on L1.
+ /// @param withdrawalHash The hash of the withdrawal.
+ event MessagePassed(
+ uint256 indexed nonce,
+ address indexed sender,
+ address indexed target,
+ uint256 value,
+ uint256 gasLimit,
+ bytes data,
+ bytes32 withdrawalHash
+ );
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismPortal.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismPortal.sol
new file mode 100644
index 00000000000..887025bac75
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismPortal.sol
@@ -0,0 +1,26 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/L1/OptimismPortal.sol
+pragma solidity ^0.8.0;
+
+import {Types} from "./Types.sol";
+
+interface IOptimismPortal {
+ /// @notice Semantic version.
+ function version() external view returns (string memory);
+
+ /// @notice Proves a withdrawal transaction.
+ /// @param _tx Withdrawal transaction to finalize.
+ /// @param _l2OutputIndex L2 output index to prove against.
+ /// @param _outputRootProof Inclusion proof of the L2ToL1MessagePasser contract's storage root.
+ /// @param _withdrawalProof Inclusion proof of the withdrawal in L2ToL1MessagePasser contract.
+ function proveWithdrawalTransaction(
+ Types.WithdrawalTransaction memory _tx,
+ uint256 _l2OutputIndex,
+ Types.OutputRootProof calldata _outputRootProof,
+ bytes[] calldata _withdrawalProof
+ ) external;
+
+ /// @notice Finalizes a withdrawal transaction.
+ /// @param _tx Withdrawal transaction to finalize.
+ function finalizeWithdrawalTransaction(Types.WithdrawalTransaction memory _tx) external;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismPortal2.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismPortal2.sol
new file mode 100644
index 00000000000..165922b5aae
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismPortal2.sol
@@ -0,0 +1,12 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/L1/OptimismPortal2.sol
+pragma solidity ^0.8.0;
+import {GameType} from "./DisputeTypes.sol";
+
+interface IOptimismPortal2 {
+ /// @notice The dispute game factory address.
+ /// @dev See https://github.com/ethereum-optimism/optimism/blob/f707883038d527cbf1e9f8ea513fe33255deadbc/packages/contracts-bedrock/src/L1/OptimismPortal2.sol#L79.
+ function disputeGameFactory() external view returns (address);
+ /// @notice The game type that the OptimismPortal consults for output proposals.
+ function respectedGameType() external view returns (GameType);
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismStandardBridge.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismStandardBridge.sol
new file mode 100644
index 00000000000..2f9ef91d7c4
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/IOptimismStandardBridge.sol
@@ -0,0 +1,40 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/f707883038d527cbf1e9f8ea513fe33255deadbc/packages/contracts-bedrock/src/universal/StandardBridge.sol#L88
+pragma solidity ^0.8.0;
+
+interface IOptimismStandardBridge {
+ /// @notice Emitted when an ERC20 bridge is finalized on this chain.
+ /// @param localToken Address of the ERC20 on this chain.
+ /// @param remoteToken Address of the ERC20 on the remote chain.
+ /// @param from Address of the sender.
+ /// @param to Address of the receiver.
+ /// @param amount Amount of the ERC20 sent.
+ /// @param extraData Extra data sent with the transaction.
+ event ERC20BridgeFinalized(
+ address indexed localToken,
+ address indexed remoteToken,
+ address indexed from,
+ address to,
+ uint256 amount,
+ bytes extraData
+ );
+
+ /// @notice Finalizes an ERC20 bridge on this chain. Can only be triggered by the other
+ /// StandardBridge contract on the remote chain.
+ /// @param _localToken Address of the ERC20 on this chain.
+ /// @param _remoteToken Address of the corresponding token on the remote chain.
+ /// @param _from Address of the sender.
+ /// @param _to Address of the receiver.
+ /// @param _amount Amount of the ERC20 being bridged.
+ /// @param _extraData Extra data to be sent with the transaction. Note that the recipient will
+ /// not be triggered with this data, but it will be emitted and can be used
+ /// to identify the transaction.
+ function finalizeBridgeERC20(
+ address _localToken,
+ address _remoteToken,
+ address _from,
+ address _to,
+ uint256 _amount,
+ bytes calldata _extraData
+ ) external;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/interfaces/optimism/Types.sol b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/Types.sol
new file mode 100644
index 00000000000..bd8d5d3b630
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/interfaces/optimism/Types.sol
@@ -0,0 +1,72 @@
+// SPDX-License-Identifier: MIT
+// Copied from https://github.com/ethereum-optimism/optimism/blob/v1.7.0/packages/contracts-bedrock/src/libraries/Types.sol
+pragma solidity ^0.8.0;
+
+/// @title Types
+/// @notice Contains various types used throughout the Optimism contract system.
+library Types {
+ /// @notice OutputProposal represents a commitment to the L2 state. The timestamp is the L1
+ /// timestamp that the output root is posted. This timestamp is used to verify that the
+ /// finalization period has passed since the output root was submitted.
+ /// @custom:field outputRoot Hash of the L2 output.
+ /// @custom:field timestamp Timestamp of the L1 block that the output root was submitted in.
+ /// @custom:field l2BlockNumber L2 block number that the output corresponds to.
+ struct OutputProposal {
+ bytes32 outputRoot;
+ uint128 timestamp;
+ uint128 l2BlockNumber;
+ }
+
+ /// @notice Struct representing the elements that are hashed together to generate an output root
+ /// which itself represents a snapshot of the L2 state.
+ /// @custom:field version Version of the output root.
+ /// @custom:field stateRoot Root of the state trie at the block of this output.
+ /// @custom:field messagePasserStorageRoot Root of the message passer storage trie.
+ /// @custom:field latestBlockhash Hash of the block this output was generated from.
+ struct OutputRootProof {
+ bytes32 version;
+ bytes32 stateRoot;
+ bytes32 messagePasserStorageRoot;
+ bytes32 latestBlockhash;
+ }
+
+ /// @notice Struct representing a deposit transaction (L1 => L2 transaction) created by an end
+ /// user (as opposed to a system deposit transaction generated by the system).
+ /// @custom:field from Address of the sender of the transaction.
+ /// @custom:field to Address of the recipient of the transaction.
+ /// @custom:field isCreation True if the transaction is a contract creation.
+ /// @custom:field value Value to send to the recipient.
+ /// @custom:field mint Amount of ETH to mint.
+ /// @custom:field gasLimit Gas limit of the transaction.
+ /// @custom:field data Data of the transaction.
+ /// @custom:field l1BlockHash Hash of the block the transaction was submitted in.
+ /// @custom:field logIndex Index of the log in the block the transaction was submitted in.
+ //solhint-disable gas-struct-packing
+ struct UserDepositTransaction {
+ address from;
+ address to;
+ bool isCreation;
+ uint256 value;
+ uint256 mint;
+ uint64 gasLimit;
+ bytes data;
+ bytes32 l1BlockHash;
+ uint256 logIndex;
+ }
+
+ /// @notice Struct representing a withdrawal transaction.
+ /// @custom:field nonce Nonce of the withdrawal transaction
+ /// @custom:field sender Address of the sender of the transaction.
+ /// @custom:field target Address of the recipient of the transaction.
+ /// @custom:field value Value to send to the recipient.
+ /// @custom:field gasLimit Gas limit of the transaction.
+ /// @custom:field data Data of the transaction.
+ struct WithdrawalTransaction {
+ uint256 nonce;
+ address sender;
+ address target;
+ uint256 value;
+ uint256 gasLimit;
+ bytes data;
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/ocr/OCR3Abstract.sol b/contracts/src/v0.8/liquiditymanager/ocr/OCR3Abstract.sol
new file mode 100644
index 00000000000..44e5d89f7fb
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/ocr/OCR3Abstract.sol
@@ -0,0 +1,108 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {ITypeAndVersion} from "../../shared/interfaces/ITypeAndVersion.sol";
+
+abstract contract OCR3Abstract is ITypeAndVersion {
+ // Maximum number of oracles the offchain reporting protocol is designed for
+ uint256 internal constant MAX_NUM_ORACLES = 31;
+
+ /// @notice triggers a new run of the offchain reporting protocol
+ /// @param previousConfigBlockNumber block in which the previous config was set, to simplify historic analysis
+ /// @param configDigest configDigest of this configuration
+ /// @param configCount ordinal number of this config setting among all config settings over the life of this contract
+ /// @param signers ith element is address ith oracle uses to sign a report
+ /// @param transmitters ith element is address ith oracle uses to transmit a report via the transmit method
+ /// @param f maximum number of faulty/dishonest oracles the protocol can tolerate while still working correctly
+ /// @param onchainConfig serialized configuration used by the contract (and possibly oracles)
+ /// @param offchainConfigVersion version of the serialization format used for "offchainConfig" parameter
+ /// @param offchainConfig serialized configuration used by the oracles exclusively and only passed through the contract
+ event ConfigSet(
+ uint32 previousConfigBlockNumber,
+ bytes32 configDigest,
+ uint64 configCount,
+ address[] signers,
+ address[] transmitters,
+ uint8 f,
+ bytes onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes offchainConfig
+ );
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles
+ /// @param signers addresses with which oracles sign the reports
+ /// @param transmitters addresses oracles use to transmit the reports
+ /// @param f number of faulty oracles the system can tolerate
+ /// @param onchainConfig serialized configuration used by the contract (and possibly oracles)
+ /// @param offchainConfigVersion version number for offchainEncoding schema
+ /// @param offchainConfig serialized configuration used by the oracles exclusively and only passed through the contract
+ function setOCR3Config(
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) external virtual;
+
+ /// @notice information about current offchain reporting protocol configuration
+ /// @return configCount ordinal number of current config, out of all configs applied to this contract so far
+ /// @return blockNumber block at which this config was set
+ /// @return configDigest domain-separation tag for current config (see _configDigestFromConfigData)
+ function latestConfigDetails()
+ external
+ view
+ virtual
+ returns (uint32 configCount, uint32 blockNumber, bytes32 configDigest);
+
+ function _configDigestFromConfigData(
+ uint256 chainId,
+ address contractAddress,
+ uint64 configCount,
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) internal pure returns (bytes32) {
+ uint256 h = uint256(
+ keccak256(
+ abi.encode(
+ chainId,
+ contractAddress,
+ configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ )
+ )
+ );
+ uint256 prefixMask = type(uint256).max << (256 - 16); // 0xFFFF00..00
+ uint256 prefix = 0x0001 << (256 - 16); // 0x000100..00
+ return bytes32((prefix & prefixMask) | (h & ~prefixMask));
+ }
+
+ /// @notice optionally emitted to indicate the latest configDigest and sequence number
+ /// for which a report was successfully transmitted. Alternatively, the contract may
+ /// use latestConfigDigestAndEpoch with scanLogs set to false.
+ event Transmitted(bytes32 configDigest, uint64 sequenceNumber);
+
+ /// @notice transmit is called to post a new report to the contract
+ /// @param report serialized report, which the signatures are signing.
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param rawVs ith element is the the V component of the ith signature
+ function transmit(
+ // NOTE: If these parameters are changed, expectedMsgDataLength and/or
+ // TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT need to be changed accordingly
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 rawVs // signatures
+ ) external virtual;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/ocr/OCR3Base.sol b/contracts/src/v0.8/liquiditymanager/ocr/OCR3Base.sol
new file mode 100644
index 00000000000..b856f734e7b
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/ocr/OCR3Base.sol
@@ -0,0 +1,284 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {OwnerIsCreator} from "../../shared/access/OwnerIsCreator.sol";
+import {OCR3Abstract} from "./OCR3Abstract.sol";
+
+/// @notice Onchain verification of reports from the offchain reporting protocol
+/// @dev For details on its operation, see the offchain reporting protocol design
+/// doc, which refers to this contract as simply the "contract".
+abstract contract OCR3Base is OwnerIsCreator, OCR3Abstract {
+ error InvalidConfig(string message);
+ error WrongMessageLength(uint256 expected, uint256 actual);
+ error ConfigDigestMismatch(bytes32 expected, bytes32 actual);
+ error ForkedChain(uint256 expected, uint256 actual);
+ error WrongNumberOfSignatures();
+ error SignaturesOutOfRegistration();
+ error UnauthorizedTransmitter();
+ error UnauthorizedSigner();
+ error NonUniqueSignatures();
+ error OracleCannotBeZeroAddress();
+ error NonIncreasingSequenceNumber(uint64 sequenceNumber, uint64 latestSequenceNumber);
+
+ // Packing these fields used on the hot path in a ConfigInfo variable reduces the
+ // retrieval of all of them to a minimum number of SLOADs.
+ struct ConfigInfo {
+ bytes32 latestConfigDigest;
+ uint8 f;
+ uint8 n;
+ }
+
+ // Used for s_oracles[a].role, where a is an address, to track the purpose
+ // of the address, or to indicate that the address is unset.
+ enum Role {
+ // No oracle role has been set for address a
+ Unset,
+ // Signing address for the s_oracles[a].index'th oracle. I.e., report
+ // signatures from this oracle should ecrecover back to address a.
+ Signer,
+ // Transmission address for the s_oracles[a].index'th oracle. I.e., if a
+ // report is received by OCR3Aggregator.transmit in which msg.sender is
+ // a, it is attributed to the s_oracles[a].index'th oracle.
+ Transmitter
+ }
+
+ struct Oracle {
+ uint8 index; // Index of oracle in s_signers/s_transmitters
+ Role role; // Role of the address which mapped to this struct
+ }
+
+ // The current config
+ ConfigInfo internal s_configInfo;
+
+ // incremented each time a new config is posted. This count is incorporated
+ // into the config digest, to prevent replay attacks.
+ uint32 internal s_configCount;
+ // makes it easier for offchain systems to extract config from logs.
+ uint32 internal s_latestConfigBlockNumber;
+
+ uint64 internal s_latestSequenceNumber;
+
+ // signer OR transmitter address
+ mapping(address signerOrTransmitter => Oracle oracle) internal s_oracles;
+
+ // s_signers contains the signing address of each oracle
+ address[] internal s_signers;
+
+ // s_transmitters contains the transmission address of each oracle,
+ // i.e. the address the oracle actually sends transactions to the contract from
+ address[] internal s_transmitters;
+
+ // The constant-length components of the msg.data sent to transmit.
+ // See the "If we wanted to call sam" example on for example reasoning
+ // https://solidity.readthedocs.io/en/v0.7.2/abi-spec.html
+ uint16 private constant TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT =
+ 4 + // function selector
+ 32 *
+ 3 + // 3 words containing reportContext
+ 32 + // word containing start location of abiencoded report value
+ 32 + // word containing location start of abiencoded rs value
+ 32 + // word containing start location of abiencoded ss value
+ 32 + // rawVs value
+ 32 + // word containing length of report
+ 32 + // word containing length rs
+ 32; // word containing length of ss
+
+ uint256 internal immutable i_chainID;
+
+ constructor() {
+ i_chainID = block.chainid;
+ }
+
+ // Reverts transaction if config args are invalid
+ modifier checkConfigValid(
+ uint256 numSigners,
+ uint256 numTransmitters,
+ uint256 f
+ ) {
+ if (numSigners > MAX_NUM_ORACLES) revert InvalidConfig("too many signers");
+ if (f == 0) revert InvalidConfig("f must be positive");
+ if (numSigners != numTransmitters) revert InvalidConfig("oracle addresses out of registration");
+ if (numSigners <= 3 * f) revert InvalidConfig("faulty-oracle f too high");
+ _;
+ }
+
+ /// @notice sets offchain reporting protocol configuration incl. participating oracles
+ /// @param signers addresses with which oracles sign the reports
+ /// @param transmitters addresses oracles use to transmit the reports
+ /// @param f number of faulty oracles the system can tolerate
+ /// @param onchainConfig encoded on-chain contract configuration
+ /// @param offchainConfigVersion version number for offchainEncoding schema
+ /// @param offchainConfig encoded off-chain oracle configuration
+ function setOCR3Config(
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) external override checkConfigValid(signers.length, transmitters.length, f) onlyOwner {
+ _beforeSetConfig(onchainConfig);
+ uint256 oldSignerLength = s_signers.length;
+ for (uint256 i = 0; i < oldSignerLength; ++i) {
+ delete s_oracles[s_signers[i]];
+ delete s_oracles[s_transmitters[i]];
+ }
+
+ uint256 newSignersLength = signers.length;
+ for (uint256 i = 0; i < newSignersLength; ++i) {
+ // add new signer/transmitter addresses
+ address signer = signers[i];
+ if (s_oracles[signer].role != Role.Unset) revert InvalidConfig("repeated signer address");
+ if (signer == address(0)) revert OracleCannotBeZeroAddress();
+ s_oracles[signer] = Oracle(uint8(i), Role.Signer);
+
+ address transmitter = transmitters[i];
+ if (s_oracles[transmitter].role != Role.Unset) revert InvalidConfig("repeated transmitter address");
+ if (transmitter == address(0)) revert OracleCannotBeZeroAddress();
+ s_oracles[transmitter] = Oracle(uint8(i), Role.Transmitter);
+ }
+
+ s_signers = signers;
+ s_transmitters = transmitters;
+
+ s_configInfo.f = f;
+ s_configInfo.n = uint8(newSignersLength);
+ s_configInfo.latestConfigDigest = _configDigestFromConfigData(
+ block.chainid,
+ address(this),
+ ++s_configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+
+ uint32 previousConfigBlockNumber = s_latestConfigBlockNumber;
+ s_latestConfigBlockNumber = uint32(block.number);
+ s_latestSequenceNumber = 0;
+
+ emit ConfigSet(
+ previousConfigBlockNumber,
+ s_configInfo.latestConfigDigest,
+ s_configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+ }
+
+ /// @dev Hook that is run from setOCR3Config() right after validating configuration.
+ /// Empty by default, please provide an implementation in a child contract if you need additional configuration processing
+ function _beforeSetConfig(bytes memory _onchainConfig) internal virtual {}
+
+ /// @return list of addresses permitted to transmit reports to this contract
+ /// @dev The list will match the order used to specify the transmitter during setConfig
+ function getTransmitters() external view returns (address[] memory) {
+ return s_transmitters;
+ }
+
+ /// @notice transmit is called to post a new report to the contract
+ /// @param report serialized report, which the signatures are signing.
+ /// @param rs ith element is the R components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param ss ith element is the S components of the ith signature on report. Must have at most MAX_NUM_ORACLES entries
+ /// @param rawVs ith element is the the V component of the ith signature
+ function transmit(
+ // NOTE: If these parameters are changed, expectedMsgDataLength and/or
+ // TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT need to be changed accordingly
+ bytes32[3] calldata reportContext,
+ bytes calldata report,
+ bytes32[] calldata rs,
+ bytes32[] calldata ss,
+ bytes32 rawVs // signatures
+ ) external override {
+ uint64 sequenceNumber = uint64(uint256(reportContext[1]));
+ if (sequenceNumber <= s_latestSequenceNumber) {
+ revert NonIncreasingSequenceNumber(sequenceNumber, s_latestSequenceNumber);
+ }
+
+ // Scoping this reduces stack pressure and gas usage
+ {
+ _report(report, sequenceNumber);
+ }
+
+ s_latestSequenceNumber = sequenceNumber;
+ // reportContext consists of:
+ // reportContext[0]: ConfigDigest
+ // reportContext[1]: 24 byte padding, 8 byte sequence number
+ bytes32 configDigest = reportContext[0];
+ ConfigInfo memory configInfo = s_configInfo;
+
+ if (configInfo.latestConfigDigest != configDigest) {
+ revert ConfigDigestMismatch(configInfo.latestConfigDigest, configDigest);
+ }
+ // If the cached chainID at time of deployment doesn't match the current chainID, we reject all signed reports.
+ // This avoids a (rare) scenario where chain A forks into chain A and A', A' still has configDigest
+ // calculated from chain A and so OCR reports will be valid on both forks.
+ if (i_chainID != block.chainid) revert ForkedChain(i_chainID, block.chainid);
+
+ emit Transmitted(configDigest, sequenceNumber);
+
+ if (rs.length != configInfo.f + 1) revert WrongNumberOfSignatures();
+ if (rs.length != ss.length) revert SignaturesOutOfRegistration();
+
+ // Scoping this reduces stack pressure and gas usage
+ {
+ Oracle memory transmitter = s_oracles[msg.sender];
+ // Check that sender is authorized to report
+ if (!(transmitter.role == Role.Transmitter && msg.sender == s_transmitters[transmitter.index]))
+ revert UnauthorizedTransmitter();
+ }
+ // Scoping this reduces stack pressure and gas usage
+ {
+ uint256 expectedDataLength = uint256(TRANSMIT_MSGDATA_CONSTANT_LENGTH_COMPONENT) +
+ report.length + // one byte pure entry in _report
+ rs.length *
+ 32 + // 32 bytes per entry in _rs
+ ss.length *
+ 32; // 32 bytes per entry in _ss)
+ if (msg.data.length != expectedDataLength) revert WrongMessageLength(expectedDataLength, msg.data.length);
+ }
+
+ // Verify signatures attached to report
+ bytes32 h = keccak256(abi.encodePacked(keccak256(report), reportContext));
+ bool[MAX_NUM_ORACLES] memory signed;
+
+ uint256 numberOfSignatures = rs.length;
+ for (uint256 i = 0; i < numberOfSignatures; ++i) {
+ // Safe from ECDSA malleability here since we check for duplicate signers.
+ address signer = ecrecover(h, uint8(rawVs[i]) + 27, rs[i], ss[i]);
+ // Since we disallow address(0) as a valid signer address, it can
+ // never have a signer role.
+ Oracle memory oracle = s_oracles[signer];
+ if (oracle.role != Role.Signer) revert UnauthorizedSigner();
+ if (signed[oracle.index]) revert NonUniqueSignatures();
+ signed[oracle.index] = true;
+ }
+ }
+
+ /// @notice information about current offchain reporting protocol configuration
+ /// @return configCount ordinal number of current config, out of all configs applied to this contract so far
+ /// @return blockNumber block at which this config was set
+ /// @return configDigest domain-separation tag for current config (see _configDigestFromConfigData)
+ function latestConfigDetails()
+ external
+ view
+ override
+ returns (uint32 configCount, uint32 blockNumber, bytes32 configDigest)
+ {
+ return (s_configCount, s_latestConfigBlockNumber, s_configInfo.latestConfigDigest);
+ }
+
+ /// @notice gets the latest sequence number accepted by the contract
+ /// @return sequenceNumber the monotomically incremenenting number associated with OCR reports
+ function latestSequenceNumber() external view virtual returns (uint64 sequenceNumber) {
+ return s_latestSequenceNumber;
+ }
+
+ function _report(bytes calldata report, uint64 sequenceNumber) internal virtual;
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/LiquidityManager.t.sol b/contracts/src/v0.8/liquiditymanager/test/LiquidityManager.t.sol
new file mode 100644
index 00000000000..73c9ba74455
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/LiquidityManager.t.sol
@@ -0,0 +1,945 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {ILiquidityManager} from "../interfaces/ILiquidityManager.sol";
+import {IBridgeAdapter} from "../interfaces/IBridge.sol";
+
+import {LockReleaseTokenPool} from "../../ccip/pools/LockReleaseTokenPool.sol";
+import {LiquidityManager} from "../LiquidityManager.sol";
+import {MockL1BridgeAdapter} from "./mocks/MockBridgeAdapter.sol";
+import {LiquidityManagerBaseTest} from "./LiquidityManagerBaseTest.t.sol";
+import {LiquidityManagerHelper} from "./helpers/LiquidityManagerHelper.sol";
+
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+// FOUNDRY_PROFILE=liquiditymanager forge test --match-path src/v0.8/liquiditymanager/test/LiquidityManager.t.sol
+
+contract LiquidityManagerSetup is LiquidityManagerBaseTest {
+ event FinalizationStepCompleted(
+ uint64 indexed ocrSeqNum,
+ uint64 indexed remoteChainSelector,
+ bytes bridgeSpecificData
+ );
+ event LiquidityTransferred(
+ uint64 indexed ocrSeqNum,
+ uint64 indexed fromChainSelector,
+ uint64 indexed toChainSelector,
+ address to,
+ uint256 amount,
+ bytes bridgeSpecificPayload,
+ bytes bridgeReturnData
+ );
+ event FinalizationFailed(
+ uint64 indexed ocrSeqNum,
+ uint64 indexed remoteChainSelector,
+ bytes bridgeSpecificData,
+ bytes reason
+ );
+ event FinanceRoleSet(address financeRole);
+ event LiquidityAddedToContainer(address indexed provider, uint256 indexed amount);
+ event LiquidityRemovedFromContainer(address indexed remover, uint256 indexed amount);
+ // Liquidity container event
+ event LiquidityAdded(address indexed provider, uint256 indexed amount);
+ event LiquidityRemoved(address indexed remover, uint256 indexed amount);
+
+ error NonceAlreadyUsed(uint256 nonce);
+
+ LiquidityManagerHelper internal s_liquidityManager;
+ LockReleaseTokenPool internal s_lockReleaseTokenPool;
+ MockL1BridgeAdapter internal s_bridgeAdapter;
+
+ // LiquidityManager that rebalances weth.
+ LiquidityManagerHelper internal s_wethRebalancer;
+ LockReleaseTokenPool internal s_wethLockReleaseTokenPool;
+ MockL1BridgeAdapter internal s_wethBridgeAdapter;
+
+ function setUp() public virtual override {
+ LiquidityManagerBaseTest.setUp();
+
+ s_bridgeAdapter = new MockL1BridgeAdapter(s_l1Token, false);
+ s_lockReleaseTokenPool = new LockReleaseTokenPool(s_l1Token, new address[](0), address(1), true, address(123));
+ s_liquidityManager = new LiquidityManagerHelper(
+ s_l1Token,
+ i_localChainSelector,
+ s_lockReleaseTokenPool,
+ 0,
+ FINANCE
+ );
+
+ s_lockReleaseTokenPool.setRebalancer(address(s_liquidityManager));
+
+ s_wethBridgeAdapter = new MockL1BridgeAdapter(IERC20(address(s_l1Weth)), true);
+ s_wethLockReleaseTokenPool = new LockReleaseTokenPool(
+ IERC20(address(s_l1Weth)),
+ new address[](0),
+ address(1),
+ true,
+ address(123)
+ );
+ s_wethRebalancer = new LiquidityManagerHelper(
+ IERC20(address(s_l1Weth)),
+ i_localChainSelector,
+ s_wethLockReleaseTokenPool,
+ 0,
+ FINANCE
+ );
+
+ s_wethLockReleaseTokenPool.setRebalancer(address(s_wethRebalancer));
+ }
+}
+
+contract LiquidityManager_addLiquidity is LiquidityManagerSetup {
+ function test_addLiquiditySuccess() external {
+ address caller = STRANGER;
+ vm.startPrank(caller);
+
+ uint256 amount = 12345679;
+ deal(address(s_l1Token), caller, amount);
+
+ s_l1Token.approve(address(s_liquidityManager), amount);
+
+ vm.expectEmit();
+ emit LiquidityAddedToContainer(caller, amount);
+
+ s_liquidityManager.addLiquidity(amount);
+
+ assertEq(s_l1Token.balanceOf(address(s_lockReleaseTokenPool)), amount);
+ }
+}
+
+contract LiquidityManager_removeLiquidity is LiquidityManagerSetup {
+ function test_removeLiquiditySuccess() external {
+ uint256 amount = 12345679;
+ deal(address(s_l1Token), address(s_lockReleaseTokenPool), amount);
+
+ vm.expectEmit();
+ emit LiquidityRemovedFromContainer(FINANCE, amount);
+
+ vm.startPrank(FINANCE);
+ s_liquidityManager.removeLiquidity(amount);
+
+ assertEq(s_l1Token.balanceOf(address(s_liquidityManager)), 0);
+ }
+
+ function test_InsufficientLiquidityReverts() external {
+ uint256 balance = 923;
+ uint256 requested = balance + 1;
+
+ deal(address(s_l1Token), address(s_lockReleaseTokenPool), balance);
+
+ vm.expectRevert(abi.encodeWithSelector(LiquidityManager.InsufficientLiquidity.selector, requested, balance, 0));
+
+ vm.startPrank(FINANCE);
+ s_liquidityManager.removeLiquidity(requested);
+ }
+
+ function test_OnlyFinanceRoleReverts() external {
+ vm.stopPrank();
+
+ vm.expectRevert(LiquidityManager.OnlyFinanceRole.selector);
+
+ s_liquidityManager.removeLiquidity(123);
+ }
+}
+
+contract LiquidityManager__report is LiquidityManagerSetup {
+ function test_EmptyReportReverts() external {
+ ILiquidityManager.LiquidityInstructions memory instructions = ILiquidityManager.LiquidityInstructions({
+ sendLiquidityParams: new ILiquidityManager.SendLiquidityParams[](0),
+ receiveLiquidityParams: new ILiquidityManager.ReceiveLiquidityParams[](0)
+ });
+
+ vm.expectRevert(LiquidityManager.EmptyReport.selector);
+
+ s_liquidityManager.report(abi.encode(instructions), 123);
+ }
+}
+
+contract LiquidityManager_rebalanceLiquidity is LiquidityManagerSetup {
+ uint256 internal constant AMOUNT = 12345679;
+
+ function test_rebalanceLiquiditySuccess() external {
+ deal(address(s_l1Token), address(s_lockReleaseTokenPool), AMOUNT);
+
+ LiquidityManager.CrossChainRebalancerArgs[] memory args = new LiquidityManager.CrossChainRebalancerArgs[](1);
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(s_liquidityManager),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(s_l2Token),
+ remoteChainSelector: i_remoteChainSelector,
+ enabled: true
+ });
+ s_liquidityManager.setCrossChainRebalancers(args);
+
+ vm.expectEmit();
+ emit Transfer(address(s_lockReleaseTokenPool), address(s_liquidityManager), AMOUNT);
+
+ vm.expectEmit();
+ emit Approval(address(s_liquidityManager), address(s_bridgeAdapter), AMOUNT);
+
+ vm.expectEmit();
+ emit Transfer(address(s_liquidityManager), address(s_bridgeAdapter), AMOUNT);
+
+ vm.expectEmit();
+ bytes memory encodedNonce = abi.encode(uint256(1));
+ emit LiquidityTransferred(
+ type(uint64).max,
+ i_localChainSelector,
+ i_remoteChainSelector,
+ address(s_liquidityManager),
+ AMOUNT,
+ bytes(""),
+ encodedNonce
+ );
+
+ vm.startPrank(FINANCE);
+ s_liquidityManager.rebalanceLiquidity(i_remoteChainSelector, AMOUNT, 0, bytes(""));
+
+ assertEq(s_l1Token.balanceOf(address(s_liquidityManager)), 0);
+ assertEq(s_l1Token.balanceOf(address(s_bridgeAdapter)), AMOUNT);
+ assertEq(s_l1Token.allowance(address(s_liquidityManager), address(s_bridgeAdapter)), 0);
+ }
+
+ /// @notice this test sets up a circular system where the liquidity container of
+ /// the local Liquidity manager is the bridge adapter of the remote liquidity manager
+ /// and the other way around for the remote liquidity manager. This allows us to
+ /// rebalance funds between the two liquidity managers on the same chain.
+ function test_rebalanceBetweenPoolsSuccess() external {
+ uint256 amount = 12345670;
+
+ s_liquidityManager = new LiquidityManagerHelper(s_l1Token, i_localChainSelector, s_bridgeAdapter, 0, FINANCE);
+
+ MockL1BridgeAdapter mockRemoteBridgeAdapter = new MockL1BridgeAdapter(s_l1Token, false);
+ LiquidityManager mockRemoteRebalancer = new LiquidityManager(
+ s_l1Token,
+ i_remoteChainSelector,
+ mockRemoteBridgeAdapter,
+ 0,
+ FINANCE
+ );
+
+ LiquidityManager.CrossChainRebalancerArgs[] memory args = new LiquidityManager.CrossChainRebalancerArgs[](1);
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(mockRemoteRebalancer),
+ localBridge: mockRemoteBridgeAdapter,
+ remoteToken: address(s_l1Token),
+ remoteChainSelector: i_remoteChainSelector,
+ enabled: true
+ });
+
+ s_liquidityManager.setCrossChainRebalancers(args);
+
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(s_liquidityManager),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(s_l1Token),
+ remoteChainSelector: i_localChainSelector,
+ enabled: true
+ });
+
+ mockRemoteRebalancer.setCrossChainRebalancers(args);
+
+ deal(address(s_l1Token), address(s_bridgeAdapter), amount);
+
+ vm.startPrank(FINANCE);
+ s_liquidityManager.rebalanceLiquidity(i_remoteChainSelector, amount, 0, bytes(""));
+
+ assertEq(s_l1Token.balanceOf(address(s_bridgeAdapter)), 0);
+ assertEq(s_l1Token.balanceOf(address(mockRemoteBridgeAdapter)), amount);
+ assertEq(s_l1Token.allowance(address(s_liquidityManager), address(s_bridgeAdapter)), 0);
+
+ // attach a bridge fee and see the relevant adapter's ether balance change.
+ // the bridge fee is sent along with the sendERC20 call.
+ uint256 bridgeFee = 123;
+ vm.deal(address(mockRemoteRebalancer), bridgeFee);
+ mockRemoteRebalancer.rebalanceLiquidity(i_localChainSelector, amount, bridgeFee, bytes(""));
+
+ assertEq(s_l1Token.balanceOf(address(s_bridgeAdapter)), amount);
+ assertEq(s_l1Token.balanceOf(address(mockRemoteBridgeAdapter)), 0);
+ assertEq(address(s_bridgeAdapter).balance, bridgeFee);
+
+ // Assert partial rebalancing works correctly
+ s_liquidityManager.rebalanceLiquidity(i_remoteChainSelector, amount / 2, 0, bytes(""));
+
+ assertEq(s_l1Token.balanceOf(address(s_bridgeAdapter)), amount / 2);
+ assertEq(s_l1Token.balanceOf(address(mockRemoteBridgeAdapter)), amount / 2);
+ }
+
+ function test_rebalanceBetweenPoolsSuccess_AlreadyFinalized() external {
+ // set up a rebalancer on another chain, an "L2".
+ // note we use the L1 bridge adapter because it has the reverting logic
+ // when finalization is already done.
+ MockL1BridgeAdapter remoteBridgeAdapter = new MockL1BridgeAdapter(s_l2Token, false);
+ LockReleaseTokenPool remotePool = new LockReleaseTokenPool(
+ s_l2Token,
+ new address[](0),
+ address(1),
+ true,
+ address(123)
+ );
+ LiquidityManager remoteRebalancer = new LiquidityManager(s_l2Token, i_remoteChainSelector, remotePool, 0, FINANCE);
+
+ // set rebalancer role on the pool.
+ remotePool.setRebalancer(address(remoteRebalancer));
+
+ // set up the cross chain rebalancer on "L1".
+ LiquidityManager.CrossChainRebalancerArgs[] memory args = new LiquidityManager.CrossChainRebalancerArgs[](1);
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(remoteRebalancer),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(s_l2Token),
+ remoteChainSelector: i_remoteChainSelector,
+ enabled: true
+ });
+
+ s_liquidityManager.setCrossChainRebalancers(args);
+
+ // set up the cross chain rebalancer on "L2".
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(s_liquidityManager),
+ localBridge: remoteBridgeAdapter,
+ remoteToken: address(s_l1Token),
+ remoteChainSelector: i_localChainSelector,
+ enabled: true
+ });
+
+ remoteRebalancer.setCrossChainRebalancers(args);
+
+ // deal some L1 tokens to the L1 bridge adapter so that it can send them to the rebalancer
+ // when the withdrawal gets finalized.
+ deal(address(s_l1Token), address(s_bridgeAdapter), AMOUNT);
+ // deal some L2 tokens to the remote token pool so that we can withdraw it when we rebalance.
+ deal(address(s_l2Token), address(remotePool), AMOUNT);
+
+ uint256 nonce = 1;
+ uint64 maxSeqNum = type(uint64).max;
+ bytes memory bridgeSendReturnData = abi.encode(nonce);
+ bytes memory bridgeSpecificPayload = bytes("");
+ vm.expectEmit();
+ emit LiquidityRemoved(address(remoteRebalancer), AMOUNT);
+ vm.expectEmit();
+ emit LiquidityTransferred(
+ maxSeqNum,
+ i_remoteChainSelector,
+ i_localChainSelector,
+ address(s_liquidityManager),
+ AMOUNT,
+ bridgeSpecificPayload,
+ bridgeSendReturnData
+ );
+ vm.startPrank(FINANCE);
+ remoteRebalancer.rebalanceLiquidity(i_localChainSelector, AMOUNT, 0, bridgeSpecificPayload);
+
+ // available liquidity has been moved to the remote bridge adapter from the token pool.
+ assertEq(s_l2Token.balanceOf(address(remoteBridgeAdapter)), AMOUNT, "remoteBridgeAdapter balance");
+ assertEq(s_l2Token.balanceOf(address(remotePool)), 0, "remotePool balance");
+
+ // prove and finalize manually on the L1 bridge adapter.
+ // this should transfer the funds to the rebalancer.
+ MockL1BridgeAdapter.ProvePayload memory provePayload = MockL1BridgeAdapter.ProvePayload({nonce: nonce});
+ MockL1BridgeAdapter.Payload memory payload = MockL1BridgeAdapter.Payload({
+ action: MockL1BridgeAdapter.FinalizationAction.ProveWithdrawal,
+ data: abi.encode(provePayload)
+ });
+ bool fundsAvailable = s_bridgeAdapter.finalizeWithdrawERC20(
+ address(0),
+ address(s_liquidityManager),
+ abi.encode(payload)
+ );
+ assertFalse(fundsAvailable, "fundsAvailable must be false");
+ MockL1BridgeAdapter.FinalizePayload memory finalizePayload = MockL1BridgeAdapter.FinalizePayload({
+ nonce: nonce,
+ amount: AMOUNT
+ });
+ payload = MockL1BridgeAdapter.Payload({
+ action: MockL1BridgeAdapter.FinalizationAction.FinalizeWithdrawal,
+ data: abi.encode(finalizePayload)
+ });
+ fundsAvailable = s_bridgeAdapter.finalizeWithdrawERC20(
+ address(0),
+ address(s_liquidityManager),
+ abi.encode(payload)
+ );
+ assertTrue(fundsAvailable, "fundsAvailable must be true");
+
+ // available balance on the L1 bridge adapter has been moved to the rebalancer.
+ assertEq(s_l1Token.balanceOf(address(s_liquidityManager)), AMOUNT, "rebalancer balance 1");
+ assertEq(s_l1Token.balanceOf(address(s_bridgeAdapter)), 0, "bridgeAdapter balance");
+
+ // try to finalize on L1 again
+ // bytes memory revertData = abi.encodeWithSelector(NonceAlreadyUsed.selector, nonce);
+ vm.expectEmit();
+ emit FinalizationFailed(
+ maxSeqNum,
+ i_remoteChainSelector,
+ abi.encode(payload),
+ abi.encodeWithSelector(NonceAlreadyUsed.selector, nonce)
+ );
+ vm.expectEmit();
+ emit LiquidityAdded(address(s_liquidityManager), AMOUNT);
+ vm.expectEmit();
+ emit LiquidityTransferred(
+ maxSeqNum,
+ i_remoteChainSelector,
+ i_localChainSelector,
+ address(s_liquidityManager),
+ AMOUNT,
+ abi.encode(payload),
+ bytes("")
+ );
+ s_liquidityManager.receiveLiquidity(i_remoteChainSelector, AMOUNT, false, abi.encode(payload));
+
+ // available balance on the rebalancer has been injected into the token pool.
+ assertEq(s_l1Token.balanceOf(address(s_liquidityManager)), 0, "rebalancer balance 2");
+ assertEq(s_l1Token.balanceOf(address(s_lockReleaseTokenPool)), AMOUNT, "lockReleaseTokenPool balance");
+ }
+
+ function test_rebalanceBetweenPools_MultiStageFinalization() external {
+ // set up a rebalancer on another chain, an "L2".
+ // note we use the L1 bridge adapter because it has the reverting logic
+ // when finalization is already done.
+ MockL1BridgeAdapter remoteBridgeAdapter = new MockL1BridgeAdapter(s_l2Token, false);
+ LockReleaseTokenPool remotePool = new LockReleaseTokenPool(
+ s_l2Token,
+ new address[](0),
+ address(1),
+ true,
+ address(123)
+ );
+ LiquidityManager remoteRebalancer = new LiquidityManager(s_l2Token, i_remoteChainSelector, remotePool, 0, FINANCE);
+
+ // set rebalancer role on the pool.
+ remotePool.setRebalancer(address(remoteRebalancer));
+
+ // set up the cross chain rebalancer on "L1".
+ LiquidityManager.CrossChainRebalancerArgs[] memory args = new LiquidityManager.CrossChainRebalancerArgs[](1);
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(remoteRebalancer),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(s_l2Token),
+ remoteChainSelector: i_remoteChainSelector,
+ enabled: true
+ });
+
+ s_liquidityManager.setCrossChainRebalancers(args);
+
+ // set up the cross chain rebalancer on "L2".
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(s_liquidityManager),
+ localBridge: remoteBridgeAdapter,
+ remoteToken: address(s_l1Token),
+ remoteChainSelector: i_localChainSelector,
+ enabled: true
+ });
+
+ remoteRebalancer.setCrossChainRebalancers(args);
+
+ // deal some L1 tokens to the L1 bridge adapter so that it can send them to the rebalancer
+ // when the withdrawal gets finalized.
+ deal(address(s_l1Token), address(s_bridgeAdapter), AMOUNT);
+ // deal some L2 tokens to the remote token pool so that we can withdraw it when we rebalance.
+ deal(address(s_l2Token), address(remotePool), AMOUNT);
+
+ // initiate a send from remote rebalancer to s_liquidityManager.
+ uint256 nonce = 1;
+ uint64 maxSeqNum = type(uint64).max;
+ bytes memory bridgeSendReturnData = abi.encode(nonce);
+ bytes memory bridgeSpecificPayload = bytes("");
+ vm.expectEmit();
+ emit LiquidityRemoved(address(remoteRebalancer), AMOUNT);
+ vm.expectEmit();
+ emit LiquidityTransferred(
+ maxSeqNum,
+ i_remoteChainSelector,
+ i_localChainSelector,
+ address(s_liquidityManager),
+ AMOUNT,
+ bridgeSpecificPayload,
+ bridgeSendReturnData
+ );
+ vm.startPrank(FINANCE);
+ remoteRebalancer.rebalanceLiquidity(i_localChainSelector, AMOUNT, 0, bridgeSpecificPayload);
+
+ // available liquidity has been moved to the remote bridge adapter from the token pool.
+ assertEq(s_l2Token.balanceOf(address(remoteBridgeAdapter)), AMOUNT, "remoteBridgeAdapter balance");
+ assertEq(s_l2Token.balanceOf(address(remotePool)), 0, "remotePool balance");
+
+ // prove withdrawal on the L1 bridge adapter, through the rebalancer.
+ uint256 balanceBeforeProve = s_l1Token.balanceOf(address(s_lockReleaseTokenPool));
+ MockL1BridgeAdapter.ProvePayload memory provePayload = MockL1BridgeAdapter.ProvePayload({nonce: nonce});
+ MockL1BridgeAdapter.Payload memory payload = MockL1BridgeAdapter.Payload({
+ action: MockL1BridgeAdapter.FinalizationAction.ProveWithdrawal,
+ data: abi.encode(provePayload)
+ });
+ vm.expectEmit();
+ emit FinalizationStepCompleted(maxSeqNum, i_remoteChainSelector, abi.encode(payload));
+ s_liquidityManager.receiveLiquidity(i_remoteChainSelector, AMOUNT, false, abi.encode(payload));
+
+ // s_liquidityManager should have no tokens.
+ assertEq(s_l1Token.balanceOf(address(s_liquidityManager)), 0, "rebalancer balance 1");
+ // balance of s_lockReleaseTokenPool should be unchanged since no liquidity got added yet.
+ assertEq(
+ s_l1Token.balanceOf(address(s_lockReleaseTokenPool)),
+ balanceBeforeProve,
+ "s_lockReleaseTokenPool balance should be unchanged"
+ );
+
+ // finalize withdrawal on the L1 bridge adapter, through the rebalancer.
+ MockL1BridgeAdapter.FinalizePayload memory finalizePayload = MockL1BridgeAdapter.FinalizePayload({
+ nonce: nonce,
+ amount: AMOUNT
+ });
+ payload = MockL1BridgeAdapter.Payload({
+ action: MockL1BridgeAdapter.FinalizationAction.FinalizeWithdrawal,
+ data: abi.encode(finalizePayload)
+ });
+ vm.expectEmit();
+ emit LiquidityAdded(address(s_liquidityManager), AMOUNT);
+ vm.expectEmit();
+ emit LiquidityTransferred(
+ maxSeqNum,
+ i_remoteChainSelector,
+ i_localChainSelector,
+ address(s_liquidityManager),
+ AMOUNT,
+ abi.encode(payload),
+ bytes("")
+ );
+ s_liquidityManager.receiveLiquidity(i_remoteChainSelector, AMOUNT, false, abi.encode(payload));
+
+ // s_liquidityManager should have no tokens.
+ assertEq(s_l1Token.balanceOf(address(s_liquidityManager)), 0, "rebalancer balance 2");
+ // balance of s_lockReleaseTokenPool should be updated
+ assertEq(
+ s_l1Token.balanceOf(address(s_lockReleaseTokenPool)),
+ balanceBeforeProve + AMOUNT,
+ "s_lockReleaseTokenPool balance should be updated"
+ );
+ }
+
+ function test_rebalanceBetweenPools_NativeRewrap() external {
+ // set up a rebalancer similar to the above on another chain, an "L2".
+ MockL1BridgeAdapter remoteBridgeAdapter = new MockL1BridgeAdapter(IERC20(address(s_l2Weth)), true);
+ LockReleaseTokenPool remotePool = new LockReleaseTokenPool(
+ IERC20(address(s_l2Weth)),
+ new address[](0),
+ address(1),
+ true,
+ address(123)
+ );
+ LiquidityManager remoteRebalancer = new LiquidityManager(
+ IERC20(address(s_l2Weth)),
+ i_remoteChainSelector,
+ remotePool,
+ 0,
+ FINANCE
+ );
+
+ // set rebalancer role on the pool.
+ remotePool.setRebalancer(address(remoteRebalancer));
+
+ // set up the cross chain rebalancer on "L1".
+ LiquidityManager.CrossChainRebalancerArgs[] memory args = new LiquidityManager.CrossChainRebalancerArgs[](1);
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(remoteRebalancer),
+ localBridge: s_wethBridgeAdapter,
+ remoteToken: address(s_l2Weth),
+ remoteChainSelector: i_remoteChainSelector,
+ enabled: true
+ });
+
+ s_wethRebalancer.setCrossChainRebalancers(args);
+
+ // set up the cross chain rebalancer on "L2".
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(s_wethRebalancer),
+ localBridge: remoteBridgeAdapter,
+ remoteToken: address(s_l1Weth),
+ remoteChainSelector: i_localChainSelector,
+ enabled: true
+ });
+
+ remoteRebalancer.setCrossChainRebalancers(args);
+
+ // deal some ether to the L1 bridge adapter so that it can send them to the rebalancer
+ // when the withdrawal gets finalized.
+ vm.deal(address(s_wethBridgeAdapter), AMOUNT);
+ // deal some L2 tokens to the remote token pool so that we can withdraw it when we rebalance.
+ deal(address(s_l2Weth), address(remotePool), AMOUNT);
+ // deposit some eth to the weth contract on L2 from the remote bridge adapter
+ // so that the withdraw() call succeeds.
+ vm.deal(address(remoteBridgeAdapter), AMOUNT);
+ vm.startPrank(address(remoteBridgeAdapter));
+ s_l2Weth.deposit{value: AMOUNT}();
+ vm.stopPrank();
+
+ // switch to finance for the rest of the test to avoid reverts.
+ vm.startPrank(FINANCE);
+
+ // initiate a send from remote rebalancer to s_wethRebalancer.
+ uint256 nonce = 1;
+ uint64 maxSeqNum = type(uint64).max;
+ bytes memory bridgeSendReturnData = abi.encode(nonce);
+ bytes memory bridgeSpecificPayload = bytes("");
+ vm.expectEmit();
+ emit LiquidityRemoved(address(remoteRebalancer), AMOUNT);
+ vm.expectEmit();
+ emit LiquidityTransferred(
+ maxSeqNum,
+ i_remoteChainSelector,
+ i_localChainSelector,
+ address(s_wethRebalancer),
+ AMOUNT,
+ bridgeSpecificPayload,
+ bridgeSendReturnData
+ );
+ remoteRebalancer.rebalanceLiquidity(i_localChainSelector, AMOUNT, 0, bridgeSpecificPayload);
+
+ // available liquidity has been moved to the remote bridge adapter from the token pool.
+ assertEq(s_l2Weth.balanceOf(address(remoteBridgeAdapter)), AMOUNT, "remoteBridgeAdapter balance");
+ assertEq(s_l2Weth.balanceOf(address(remotePool)), 0, "remotePool balance");
+
+ // prove withdrawal on the L1 bridge adapter, through the rebalancer.
+ uint256 balanceBeforeProve = s_l1Weth.balanceOf(address(s_wethLockReleaseTokenPool));
+ MockL1BridgeAdapter.ProvePayload memory provePayload = MockL1BridgeAdapter.ProvePayload({nonce: nonce});
+ MockL1BridgeAdapter.Payload memory payload = MockL1BridgeAdapter.Payload({
+ action: MockL1BridgeAdapter.FinalizationAction.ProveWithdrawal,
+ data: abi.encode(provePayload)
+ });
+ vm.expectEmit();
+ emit FinalizationStepCompleted(maxSeqNum, i_remoteChainSelector, abi.encode(payload));
+ s_wethRebalancer.receiveLiquidity(i_remoteChainSelector, AMOUNT, false, abi.encode(payload));
+
+ // s_wethRebalancer should have no tokens.
+ assertEq(s_l1Weth.balanceOf(address(s_wethRebalancer)), 0, "rebalancer balance 1");
+ // balance of s_wethLockReleaseTokenPool should be unchanged since no liquidity got added yet.
+ assertEq(
+ s_l1Weth.balanceOf(address(s_wethLockReleaseTokenPool)),
+ balanceBeforeProve,
+ "s_wethLockReleaseTokenPool balance should be unchanged"
+ );
+
+ // finalize withdrawal on the L1 bridge adapter, through the rebalancer.
+ MockL1BridgeAdapter.FinalizePayload memory finalizePayload = MockL1BridgeAdapter.FinalizePayload({
+ nonce: nonce,
+ amount: AMOUNT
+ });
+ payload = MockL1BridgeAdapter.Payload({
+ action: MockL1BridgeAdapter.FinalizationAction.FinalizeWithdrawal,
+ data: abi.encode(finalizePayload)
+ });
+ vm.expectEmit();
+ emit LiquidityAdded(address(s_wethRebalancer), AMOUNT);
+ vm.expectEmit();
+ emit LiquidityTransferred(
+ maxSeqNum,
+ i_remoteChainSelector,
+ i_localChainSelector,
+ address(s_wethRebalancer),
+ AMOUNT,
+ abi.encode(payload),
+ bytes("")
+ );
+ s_wethRebalancer.receiveLiquidity(i_remoteChainSelector, AMOUNT, true, abi.encode(payload));
+
+ // s_wethRebalancer should have no tokens.
+ assertEq(s_l1Weth.balanceOf(address(s_wethRebalancer)), 0, "rebalancer balance 2");
+ // s_wethRebalancer should have no native tokens.
+ assertEq(address(s_wethRebalancer).balance, 0, "rebalancer native balance should be zero");
+ // balance of s_wethLockReleaseTokenPool should be updated
+ assertEq(
+ s_l1Weth.balanceOf(address(s_wethLockReleaseTokenPool)),
+ balanceBeforeProve + AMOUNT,
+ "s_wethLockReleaseTokenPool balance should be updated"
+ );
+ }
+
+ // Reverts
+
+ function test_InsufficientLiquidityReverts() external {
+ s_liquidityManager.setMinimumLiquidity(3);
+ deal(address(s_l1Token), address(s_lockReleaseTokenPool), AMOUNT);
+ vm.expectRevert(abi.encodeWithSelector(LiquidityManager.InsufficientLiquidity.selector, AMOUNT, AMOUNT, 3));
+
+ vm.startPrank(FINANCE);
+ s_liquidityManager.rebalanceLiquidity(0, AMOUNT, 0, bytes(""));
+ }
+
+ function test_InvalidRemoteChainReverts() external {
+ deal(address(s_l1Token), address(s_lockReleaseTokenPool), AMOUNT);
+
+ vm.expectRevert(abi.encodeWithSelector(LiquidityManager.InvalidRemoteChain.selector, i_remoteChainSelector));
+
+ vm.startPrank(FINANCE);
+ s_liquidityManager.rebalanceLiquidity(i_remoteChainSelector, AMOUNT, 0, bytes(""));
+ }
+}
+
+contract LiquidityManager_setCrossChainRebalancer is LiquidityManagerSetup {
+ event CrossChainRebalancerSet(
+ uint64 indexed remoteChainSelector,
+ IBridgeAdapter localBridge,
+ address remoteToken,
+ address remoteRebalancer,
+ bool enabled
+ );
+
+ function test_setCrossChainRebalancerSuccess() external {
+ address newRebalancer = address(23892423);
+ uint64 remoteChainSelector = 12301293;
+
+ uint64[] memory supportedChains = s_liquidityManager.getSupportedDestChains();
+ assertEq(supportedChains.length, 0);
+
+ LiquidityManager.CrossChainRebalancerArgs[] memory args = new LiquidityManager.CrossChainRebalancerArgs[](1);
+ args[0] = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: newRebalancer,
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(190490124908),
+ remoteChainSelector: remoteChainSelector,
+ enabled: true
+ });
+
+ vm.expectEmit();
+ emit CrossChainRebalancerSet(
+ remoteChainSelector,
+ args[0].localBridge,
+ args[0].remoteToken,
+ newRebalancer,
+ args[0].enabled
+ );
+
+ s_liquidityManager.setCrossChainRebalancers(args);
+
+ assertEq(s_liquidityManager.getCrossChainRebalancer(remoteChainSelector).remoteRebalancer, newRebalancer);
+
+ LiquidityManager.CrossChainRebalancerArgs[] memory got = s_liquidityManager.getAllCrossChainRebalancers();
+ assertEq(got.length, 1);
+ assertEq(got[0].remoteRebalancer, args[0].remoteRebalancer);
+ assertEq(address(got[0].localBridge), address(args[0].localBridge));
+ assertEq(got[0].remoteToken, args[0].remoteToken);
+ assertEq(got[0].remoteChainSelector, args[0].remoteChainSelector);
+ assertEq(got[0].enabled, args[0].enabled);
+
+ supportedChains = s_liquidityManager.getSupportedDestChains();
+ assertEq(supportedChains.length, 1);
+ assertEq(supportedChains[0], remoteChainSelector);
+
+ address anotherRebalancer = address(123);
+ args[0].remoteRebalancer = anotherRebalancer;
+
+ vm.expectEmit();
+ emit CrossChainRebalancerSet(
+ remoteChainSelector,
+ args[0].localBridge,
+ args[0].remoteToken,
+ anotherRebalancer,
+ args[0].enabled
+ );
+
+ s_liquidityManager.setCrossChainRebalancer(args[0]);
+
+ assertEq(s_liquidityManager.getCrossChainRebalancer(remoteChainSelector).remoteRebalancer, anotherRebalancer);
+
+ supportedChains = s_liquidityManager.getSupportedDestChains();
+ assertEq(supportedChains.length, 1);
+ assertEq(supportedChains[0], remoteChainSelector);
+ }
+
+ function test_ZeroChainSelectorReverts() external {
+ LiquidityManager.CrossChainRebalancerArgs memory arg = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(9),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(190490124908),
+ remoteChainSelector: 0,
+ enabled: true
+ });
+
+ vm.expectRevert(LiquidityManager.ZeroChainSelector.selector);
+
+ s_liquidityManager.setCrossChainRebalancer(arg);
+ }
+
+ function test_ZeroAddressReverts() external {
+ LiquidityManager.CrossChainRebalancerArgs memory arg = ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(0),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(190490124908),
+ remoteChainSelector: 123,
+ enabled: true
+ });
+
+ vm.expectRevert(LiquidityManager.ZeroAddress.selector);
+
+ s_liquidityManager.setCrossChainRebalancer(arg);
+
+ arg.remoteRebalancer = address(9);
+ arg.localBridge = IBridgeAdapter(address(0));
+
+ vm.expectRevert(LiquidityManager.ZeroAddress.selector);
+
+ s_liquidityManager.setCrossChainRebalancer(arg);
+
+ arg.localBridge = s_bridgeAdapter;
+ arg.remoteToken = address(0);
+
+ vm.expectRevert(LiquidityManager.ZeroAddress.selector);
+
+ s_liquidityManager.setCrossChainRebalancer(arg);
+ }
+
+ function test_OnlyOwnerReverts() external {
+ vm.stopPrank();
+
+ vm.expectRevert("Only callable by owner");
+
+ // Test the entrypoint that takes a list
+ s_liquidityManager.setCrossChainRebalancers(new LiquidityManager.CrossChainRebalancerArgs[](0));
+
+ vm.expectRevert("Only callable by owner");
+
+ // Test the entrypoint that takes a single item
+ s_liquidityManager.setCrossChainRebalancer(
+ ILiquidityManager.CrossChainRebalancerArgs({
+ remoteRebalancer: address(9),
+ localBridge: s_bridgeAdapter,
+ remoteToken: address(190490124908),
+ remoteChainSelector: 124,
+ enabled: true
+ })
+ );
+ }
+}
+
+contract LiquidityManager_setLocalLiquidityContainer is LiquidityManagerSetup {
+ event LiquidityContainerSet(address indexed newLiquidityContainer);
+
+ function test_setLocalLiquidityContainerSuccess() external {
+ LockReleaseTokenPool newPool = new LockReleaseTokenPool(
+ s_l1Token,
+ new address[](0),
+ address(1),
+ true,
+ address(123)
+ );
+
+ vm.expectEmit();
+ emit LiquidityContainerSet(address(newPool));
+
+ s_liquidityManager.setLocalLiquidityContainer(newPool);
+
+ assertEq(s_liquidityManager.getLocalLiquidityContainer(), address(newPool));
+ }
+
+ function test_OnlyOwnerReverts() external {
+ vm.stopPrank();
+
+ vm.expectRevert("Only callable by owner");
+
+ s_liquidityManager.setLocalLiquidityContainer(LockReleaseTokenPool(address(1)));
+ }
+
+ function test_ReverstWhen_CalledWithTheZeroAddress() external {
+ vm.expectRevert(LiquidityManager.ZeroAddress.selector);
+ s_liquidityManager.setLocalLiquidityContainer(LockReleaseTokenPool(address(0)));
+ }
+}
+
+contract LiquidityManager_setMinimumLiquidity is LiquidityManagerSetup {
+ event MinimumLiquiditySet(uint256 oldBalance, uint256 newBalance);
+
+ function test_setMinimumLiquiditySuccess() external {
+ vm.expectEmit();
+ emit MinimumLiquiditySet(uint256(0), uint256(1000));
+ s_liquidityManager.setMinimumLiquidity(1000);
+ assertEq(s_liquidityManager.getMinimumLiquidity(), uint256(1000));
+ }
+
+ function test_OnlyOwnerReverts() external {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ s_liquidityManager.setMinimumLiquidity(uint256(1000));
+ }
+}
+
+contract LiquidityManager_setFinanceRole is LiquidityManagerSetup {
+ event MinimumLiquiditySet(uint256 oldBalance, uint256 newBalance);
+
+ function test_setFinanceRoleSuccess() external {
+ vm.expectEmit();
+ address newFinanceRole = makeAddr("newFinanceRole");
+ assertEq(s_liquidityManager.getFinanceRole(), FINANCE);
+ emit FinanceRoleSet(newFinanceRole);
+ s_liquidityManager.setFinanceRole(newFinanceRole);
+ assertEq(s_liquidityManager.getFinanceRole(), newFinanceRole);
+ }
+
+ function test_OnlyOwnerReverts() external {
+ vm.stopPrank();
+ vm.expectRevert("Only callable by owner");
+ s_liquidityManager.setFinanceRole(address(1));
+ }
+}
+
+contract LiquidityManager_withdrawNative is LiquidityManagerSetup {
+ event NativeWithdrawn(uint256 amount, address destination);
+
+ address private receiver = makeAddr("receiver");
+
+ function setUp() public override {
+ super.setUp();
+ vm.deal(address(s_liquidityManager), 1);
+ }
+
+ function test_withdrawNative_success() external {
+ assertEq(receiver.balance, 0);
+ vm.expectEmit();
+ emit NativeWithdrawn(1, receiver);
+ vm.startPrank(FINANCE);
+ s_liquidityManager.withdrawNative(1, payable(receiver));
+ assertEq(receiver.balance, 1);
+ }
+
+ function test_OnlyFinanceRoleReverts() external {
+ vm.stopPrank();
+ vm.expectRevert(LiquidityManager.OnlyFinanceRole.selector);
+ s_liquidityManager.withdrawNative(1, payable(receiver));
+ }
+}
+
+contract LiquidityManager_receive is LiquidityManagerSetup {
+ event NativeDeposited(uint256 amount, address depositor);
+
+ address private depositor = makeAddr("depositor");
+
+ function test_receive_success() external {
+ vm.deal(depositor, 100);
+ uint256 before = address(s_liquidityManager).balance;
+ vm.expectEmit();
+ emit NativeDeposited(100, depositor);
+ vm.startPrank(depositor);
+ payable(address(s_liquidityManager)).transfer(100);
+ assertEq(address(s_liquidityManager).balance, before + 100);
+ }
+}
+
+contract LiquidityManager_withdrawERC20 is LiquidityManagerSetup {
+ function test_withdrawERC20Success() external {
+ uint256 amount = 100;
+ deal(address(s_otherToken), address(s_liquidityManager), amount);
+ assertEq(s_otherToken.balanceOf(address(1)), 0);
+ assertEq(s_otherToken.balanceOf(address(s_liquidityManager)), amount);
+ vm.startPrank(FINANCE);
+ s_liquidityManager.withdrawERC20(address(s_otherToken), amount, address(1));
+ assertEq(s_otherToken.balanceOf(address(1)), amount);
+ assertEq(s_otherToken.balanceOf(address(s_liquidityManager)), 0);
+ }
+
+ function test_withdrawERC20Reverts() external {
+ uint256 amount = 100;
+ deal(address(s_otherToken), address(s_liquidityManager), amount);
+ vm.startPrank(STRANGER);
+ vm.expectRevert(LiquidityManager.OnlyFinanceRole.selector);
+ s_liquidityManager.withdrawERC20(address(s_otherToken), amount, address(1));
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/LiquidityManagerBaseTest.t.sol b/contracts/src/v0.8/liquiditymanager/test/LiquidityManagerBaseTest.t.sol
new file mode 100644
index 00000000000..128a03f255a
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/LiquidityManagerBaseTest.t.sol
@@ -0,0 +1,43 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {Test} from "forge-std/Test.sol";
+
+import {WETH9} from "../../ccip/test/WETH9.sol";
+
+import {ERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/ERC20.sol";
+import {IERC20} from "../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract LiquidityManagerBaseTest is Test {
+ // ERC20 events
+ event Transfer(address indexed from, address indexed to, uint256 value);
+ event Approval(address indexed owner, address indexed spender, uint256 value);
+
+ IERC20 internal s_l1Token;
+ IERC20 internal s_l2Token;
+ IERC20 internal s_otherToken;
+ WETH9 internal s_l1Weth;
+ WETH9 internal s_l2Weth;
+
+ uint64 internal immutable i_localChainSelector = 1234;
+ uint64 internal immutable i_remoteChainSelector = 9876;
+
+ address internal constant FINANCE = address(0x00000fffffffffffffffffffff);
+ address internal constant OWNER = address(0x00000078772732723782873283);
+ address internal constant STRANGER = address(0x00000999999911111111222222);
+
+ function setUp() public virtual {
+ s_l1Token = new ERC20("l1", "L1");
+ s_l2Token = new ERC20("l2", "L2");
+ s_otherToken = new ERC20("other", "OTHER");
+
+ s_l1Weth = new WETH9();
+ s_l2Weth = new WETH9();
+
+ vm.startPrank(OWNER);
+
+ vm.label(FINANCE, "FINANCE");
+ vm.label(OWNER, "OWNER");
+ vm.label(STRANGER, "STRANGER");
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/ArbitrumL1BridgeAdapter.t.sol b/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/ArbitrumL1BridgeAdapter.t.sol
new file mode 100644
index 00000000000..8afea2d680d
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/ArbitrumL1BridgeAdapter.t.sol
@@ -0,0 +1,98 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IWrappedNative} from "../../../ccip/interfaces/IWrappedNative.sol";
+
+import {ArbitrumL1BridgeAdapter, IOutbox} from "../../bridge-adapters/ArbitrumL1BridgeAdapter.sol";
+import "forge-std/Test.sol";
+
+import {IL1GatewayRouter} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/ethereum/gateway/IL1GatewayRouter.sol";
+import {IGatewayRouter} from "@arbitrum/token-bridge-contracts/contracts/tokenbridge/libraries/gateway/IGatewayRouter.sol";
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+//contract ArbitrumL1BridgeAdapterSetup is Test {
+// uint256 internal mainnetFork;
+// uint256 internal arbitrumFork;
+//
+// string internal constant MAINNET_RPC_URL = "";
+//
+// address internal constant L1_GATEWAY_ROUTER = 0x72Ce9c846789fdB6fC1f34aC4AD25Dd9ef7031ef;
+// address internal constant L1_ERC20_GATEWAY = 0xa3A7B6F88361F48403514059F1F16C8E78d60EeC;
+// address internal constant L1_INBOX = 0x4Dbd4fc535Ac27206064B68FfCf827b0A60BAB3f;
+// // inbox 0x5aED5f8A1e3607476F1f81c3d8fe126deB0aFE94?
+// address internal constant L1_OUTBOX = 0x0B9857ae2D4A3DBe74ffE1d7DF045bb7F96E4840;
+//
+// IERC20 internal constant L1_LINK = IERC20(0x514910771AF9Ca656af840dff83E8264EcF986CA);
+// IWrappedNative internal constant L1_WRAPPED_NATIVE = IWrappedNative(0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2);
+//
+// address internal constant L2_GATEWAY_ROUTER = 0x5288c571Fd7aD117beA99bF60FE0846C4E84F933;
+// address internal constant L2_ETH_WITHDRAWAL_PRECOMPILE = 0x0000000000000000000000000000000000000064;
+//
+// IERC20 internal constant L2_LINK = IERC20(0xf97f4df75117a78c1A5a0DBb814Af92458539FB4);
+// IWrappedNative internal constant L2_WRAPPED_NATIVE = IWrappedNative(0x82aF49447D8a07e3bd95BD0d56f35241523fBab1);
+//
+// ArbitrumL1BridgeAdapter internal s_l1BridgeAdapter;
+//
+// uint256 internal constant TOKEN_BALANCE = 10e18;
+// address internal constant OWNER = address(0xdead);
+//
+// function setUp() public {
+// vm.startPrank(OWNER);
+//
+// mainnetFork = vm.createFork(MAINNET_RPC_URL);
+// vm.selectFork(mainnetFork);
+//
+// s_l1BridgeAdapter = new ArbitrumL1BridgeAdapter(
+// IL1GatewayRouter(L1_GATEWAY_ROUTER),
+// IOutbox(L1_OUTBOX),
+// L1_ERC20_GATEWAY
+// );
+//
+// deal(address(L1_LINK), OWNER, TOKEN_BALANCE);
+// deal(address(L1_WRAPPED_NATIVE), OWNER, TOKEN_BALANCE);
+//
+// vm.label(OWNER, "Owner");
+// vm.label(L1_GATEWAY_ROUTER, "L1GatewayRouter");
+// vm.label(L1_ERC20_GATEWAY, "L1 ERC20 Gateway");
+// }
+//}
+//
+//contract ArbitrumL1BridgeAdapter_sendERC20 is ArbitrumL1BridgeAdapterSetup {
+// event TransferRouted(address indexed token, address indexed _userFrom, address indexed _userTo, address gateway);
+//
+// function test_sendERC20Success() public {
+// L1_LINK.approve(address(s_l1BridgeAdapter), TOKEN_BALANCE);
+//
+// vm.expectEmit();
+// emit TransferRouted(address(L1_LINK), address(s_l1BridgeAdapter), OWNER, L1_ERC20_GATEWAY);
+//
+// uint256 expectedCost = s_l1BridgeAdapter.MAX_GAS() *
+// s_l1BridgeAdapter.GAS_PRICE_BID() +
+// s_l1BridgeAdapter.MAX_SUBMISSION_COST();
+//
+// s_l1BridgeAdapter.sendERC20{value: expectedCost}(address(L1_LINK), OWNER, OWNER, TOKEN_BALANCE);
+// }
+//
+// function test_BridgeFeeTooLowReverts() public {
+// L1_LINK.approve(address(s_l1BridgeAdapter), TOKEN_BALANCE);
+// uint256 expectedCost = s_l1BridgeAdapter.MAX_GAS() *
+// s_l1BridgeAdapter.GAS_PRICE_BID() +
+// s_l1BridgeAdapter.MAX_SUBMISSION_COST();
+//
+// vm.expectRevert(
+// abi.encodeWithSelector(ArbitrumL1BridgeAdapter.InsufficientEthValue.selector, expectedCost, expectedCost - 1)
+// );
+//
+// s_l1BridgeAdapter.sendERC20{value: expectedCost - 1}(address(L1_LINK), OWNER, OWNER, TOKEN_BALANCE);
+// }
+//
+// function test_noApprovalReverts() public {
+// uint256 expectedCost = s_l1BridgeAdapter.MAX_GAS() *
+// s_l1BridgeAdapter.GAS_PRICE_BID() +
+// s_l1BridgeAdapter.MAX_SUBMISSION_COST();
+//
+// vm.expectRevert("SafeERC20: low-level call failed");
+//
+// s_l1BridgeAdapter.sendERC20{value: expectedCost}(address(L1_LINK), OWNER, OWNER, TOKEN_BALANCE);
+// }
+//}
diff --git a/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/ArbitrumL2BridgeAdapter.t.sol b/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/ArbitrumL2BridgeAdapter.t.sol
new file mode 100644
index 00000000000..e34ff0480c0
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/ArbitrumL2BridgeAdapter.t.sol
@@ -0,0 +1,51 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {IWrappedNative} from "../../../ccip/interfaces/IWrappedNative.sol";
+
+import {ArbitrumL2BridgeAdapter, IL2GatewayRouter} from "../../bridge-adapters/ArbitrumL2BridgeAdapter.sol";
+import "forge-std/Test.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+//contract ArbitrumL2BridgeAdapterSetup is Test {
+// uint256 internal arbitrumFork;
+//
+// string internal constant ARBITRUM_RPC_URL = "";
+//
+// address internal constant L2_GATEWAY_ROUTER = 0x5288c571Fd7aD117beA99bF60FE0846C4E84F933;
+// address internal constant L2_ETH_WITHDRAWAL_PRECOMPILE = 0x0000000000000000000000000000000000000064;
+//
+// IERC20 internal constant L1_LINK = IERC20(0x514910771AF9Ca656af840dff83E8264EcF986CA);
+// IERC20 internal constant L2_LINK = IERC20(0xf97f4df75117a78c1A5a0DBb814Af92458539FB4);
+// IWrappedNative internal constant L2_WRAPPED_NATIVE = IWrappedNative(0x82aF49447D8a07e3bd95BD0d56f35241523fBab1);
+//
+// uint256 internal constant TOKEN_BALANCE = 10e18;
+// address internal constant OWNER = address(0xdead);
+//
+// ArbitrumL2BridgeAdapter internal s_l2BridgeAdapter;
+//
+// function setUp() public {
+// vm.startPrank(OWNER);
+//
+// arbitrumFork = vm.createFork(ARBITRUM_RPC_URL);
+//
+// vm.selectFork(arbitrumFork);
+// s_l2BridgeAdapter = new ArbitrumL2BridgeAdapter(IL2GatewayRouter(L2_GATEWAY_ROUTER));
+// deal(address(L2_LINK), OWNER, TOKEN_BALANCE);
+// deal(address(L2_WRAPPED_NATIVE), OWNER, TOKEN_BALANCE);
+//
+// vm.label(OWNER, "Owner");
+// vm.label(L2_GATEWAY_ROUTER, "L2GatewayRouterProxy");
+// vm.label(0xe80eb0238029333e368e0bDDB7acDf1b9cb28278, "L2GatewayRouter");
+// vm.label(L2_ETH_WITHDRAWAL_PRECOMPILE, "Precompile: ArbSys");
+// }
+//}
+//
+//contract ArbitrumL2BridgeAdapter_sendERC20 is ArbitrumL2BridgeAdapterSetup {
+// function test_sendERC20Success() public {
+// L2_LINK.approve(address(s_l2BridgeAdapter), TOKEN_BALANCE);
+//
+// s_l2BridgeAdapter.sendERC20(address(L1_LINK), address(L2_LINK), OWNER, TOKEN_BALANCE);
+// }
+//}
diff --git a/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/OptimismL1BridgeAdapter.t.sol b/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/OptimismL1BridgeAdapter.t.sol
new file mode 100644
index 00000000000..cface1d5067
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/bridge-adapters/OptimismL1BridgeAdapter.t.sol
@@ -0,0 +1,129 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import "forge-std/Test.sol";
+
+import {IWrappedNative} from "../../../ccip/interfaces/IWrappedNative.sol";
+import {WETH9} from "../../../ccip/test/WETH9.sol";
+import {OptimismL1BridgeAdapter} from "../../bridge-adapters/OptimismL1BridgeAdapter.sol";
+import {Types} from "../../interfaces/optimism/Types.sol";
+import {IOptimismPortal} from "../../interfaces/optimism/IOptimismPortal.sol";
+
+import {IL1StandardBridge} from "@eth-optimism/contracts/L1/messaging/IL1StandardBridge.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract OptimismL1BridgeAdapterSetup is Test {
+ // addresses below are fake
+ address internal constant L1_STANDARD_BRIDGE = address(1234);
+ address internal constant OP_PORTAL = address(4567);
+ address internal constant OWNER = address(0xdead);
+
+ OptimismL1BridgeAdapter internal s_adapter;
+
+ function setUp() public {
+ vm.startPrank(OWNER);
+
+ // deploy wrapped native
+ WETH9 weth = new WETH9();
+
+ // deploy bridge adapter
+ s_adapter = new OptimismL1BridgeAdapter(
+ IL1StandardBridge(L1_STANDARD_BRIDGE),
+ IWrappedNative(address(weth)),
+ IOptimismPortal(OP_PORTAL)
+ );
+ }
+}
+
+contract OptimismL1BridgeAdapter_finalizeWithdrawERC20 is OptimismL1BridgeAdapterSetup {
+ function testfinalizeWithdrawERC20proveWithdrawalSuccess() public {
+ // prepare payload
+ OptimismL1BridgeAdapter.OptimismProveWithdrawalPayload memory provePayload = OptimismL1BridgeAdapter
+ .OptimismProveWithdrawalPayload({
+ withdrawalTransaction: Types.WithdrawalTransaction({
+ nonce: 1,
+ sender: address(0xdead),
+ target: address(0xbeef),
+ value: 1234,
+ gasLimit: 4567,
+ data: hex"deadbeef"
+ }),
+ l2OutputIndex: 1234,
+ outputRootProof: Types.OutputRootProof({
+ version: bytes32(0),
+ stateRoot: bytes32(uint256(500)),
+ messagePasserStorageRoot: bytes32(uint256(600)),
+ latestBlockhash: bytes32(uint256(700))
+ }),
+ withdrawalProof: new bytes[](0)
+ });
+ OptimismL1BridgeAdapter.FinalizeWithdrawERC20Payload memory payload;
+ payload.action = OptimismL1BridgeAdapter.FinalizationAction.ProveWithdrawal;
+ payload.data = abi.encode(provePayload);
+
+ bytes memory encodedPayload = abi.encode(payload);
+
+ // mock out call to optimism portal
+ vm.mockCall(
+ OP_PORTAL,
+ abi.encodeWithSelector(
+ IOptimismPortal.proveWithdrawalTransaction.selector,
+ provePayload.withdrawalTransaction,
+ provePayload.l2OutputIndex,
+ provePayload.outputRootProof,
+ provePayload.withdrawalProof
+ ),
+ ""
+ );
+
+ // call finalizeWithdrawERC20
+ s_adapter.finalizeWithdrawERC20(address(0), address(0), encodedPayload);
+ }
+
+ function testfinalizeWithdrawERC20FinalizeSuccess() public {
+ // prepare payload
+ OptimismL1BridgeAdapter.OptimismFinalizationPayload memory finalizePayload = OptimismL1BridgeAdapter
+ .OptimismFinalizationPayload({
+ withdrawalTransaction: Types.WithdrawalTransaction({
+ nonce: 1,
+ sender: address(0xdead),
+ target: address(0xbeef),
+ value: 1234,
+ gasLimit: 4567,
+ data: hex"deadbeef"
+ })
+ });
+ OptimismL1BridgeAdapter.FinalizeWithdrawERC20Payload memory payload;
+ payload.action = OptimismL1BridgeAdapter.FinalizationAction.FinalizeWithdrawal;
+ payload.data = abi.encode(finalizePayload);
+
+ bytes memory encodedPayload = abi.encode(payload);
+
+ // mock out call to optimism portal
+ vm.mockCall(
+ OP_PORTAL,
+ abi.encodeWithSelector(
+ IOptimismPortal.finalizeWithdrawalTransaction.selector,
+ finalizePayload.withdrawalTransaction
+ ),
+ ""
+ );
+
+ // call finalizeWithdrawERC20
+ s_adapter.finalizeWithdrawERC20(address(0), address(0), encodedPayload);
+ }
+
+ function testFinalizeWithdrawERC20Reverts() public {
+ // case 1: badly encoded payload
+ bytes memory payload = abi.encode(1, 2, 3);
+ vm.expectRevert();
+ s_adapter.finalizeWithdrawERC20(address(0), address(0), payload);
+
+ // case 2: invalid action
+ // can't prepare the payload in solidity
+ payload = hex"0000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000400000000000000000000000000000000000000000000000000000000000000004deadbeef00000000000000000000000000000000000000000000000000000000";
+ vm.expectRevert();
+ s_adapter.finalizeWithdrawERC20(address(0), address(0), payload);
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/helpers/LiquidityManagerHelper.sol b/contracts/src/v0.8/liquiditymanager/test/helpers/LiquidityManagerHelper.sol
new file mode 100644
index 00000000000..9b4654a07ff
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/helpers/LiquidityManagerHelper.sol
@@ -0,0 +1,22 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {ILiquidityContainer} from "../../interfaces/ILiquidityContainer.sol";
+
+import {LiquidityManager} from "../../LiquidityManager.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+
+contract LiquidityManagerHelper is LiquidityManager {
+ constructor(
+ IERC20 token,
+ uint64 localChainSelector,
+ ILiquidityContainer localLiquidityContainer,
+ uint256 targetTokens,
+ address finance
+ ) LiquidityManager(token, localChainSelector, localLiquidityContainer, targetTokens, finance) {}
+
+ function report(bytes calldata rep, uint64 ocrSeqNum) external {
+ _report(rep, ocrSeqNum);
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/helpers/OCR3Helper.sol b/contracts/src/v0.8/liquiditymanager/test/helpers/OCR3Helper.sol
new file mode 100644
index 00000000000..b2cd2ef3712
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/helpers/OCR3Helper.sol
@@ -0,0 +1,41 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OCR3Base} from "../../ocr/OCR3Base.sol";
+
+contract OCR3Helper is OCR3Base {
+ function configDigestFromConfigData(
+ uint256 chainSelector,
+ address contractAddress,
+ uint64 configCount,
+ address[] memory signers,
+ address[] memory transmitters,
+ uint8 f,
+ bytes memory onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes memory offchainConfig
+ ) public pure returns (bytes32) {
+ return
+ _configDigestFromConfigData(
+ chainSelector,
+ contractAddress,
+ configCount,
+ signers,
+ transmitters,
+ f,
+ onchainConfig,
+ offchainConfigVersion,
+ offchainConfig
+ );
+ }
+
+ function _report(bytes calldata report, uint64 sequenceNumber) internal override {}
+
+ function typeAndVersion() public pure override returns (string memory) {
+ return "OCR3BaseHelper 1.0.0";
+ }
+
+ function setLatestSeqNum(uint64 newSeqNum) external {
+ s_latestSequenceNumber = newSeqNum;
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/helpers/ReportEncoder.sol b/contracts/src/v0.8/liquiditymanager/test/helpers/ReportEncoder.sol
new file mode 100644
index 00000000000..ff5e21f2e14
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/helpers/ReportEncoder.sol
@@ -0,0 +1,10 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {ILiquidityManager} from "../../interfaces/ILiquidityManager.sol";
+
+/// @dev this is needed to generate the types to help encode the report offchain
+abstract contract ReportEncoder is ILiquidityManager {
+ /// @dev exposed so that we can encode the report for OCR offchain
+ function exposeForEncoding(ILiquidityManager.LiquidityInstructions memory instructions) public pure {}
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/mocks/MockBridgeAdapter.sol b/contracts/src/v0.8/liquiditymanager/test/mocks/MockBridgeAdapter.sol
new file mode 100644
index 00000000000..f51c60fcf3d
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/mocks/MockBridgeAdapter.sol
@@ -0,0 +1,191 @@
+// SPDX-License-Identifier: BUSL-1.1
+// solhint-disable one-contract-per-file
+pragma solidity ^0.8.0;
+
+import {IBridgeAdapter} from "../../interfaces/IBridge.sol";
+import {ILiquidityContainer} from "../../interfaces/ILiquidityContainer.sol";
+import {IWrappedNative} from "../../../ccip/interfaces/IWrappedNative.sol";
+
+import {IERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/IERC20.sol";
+import {SafeERC20} from "../../../vendor/openzeppelin-solidity/v4.8.3/contracts/token/ERC20/utils/SafeERC20.sol";
+
+/// @notice Mock multiple-stage finalization bridge adapter implementation.
+/// @dev Funds are only made available after both the prove and finalization steps are completed.
+/// Sends the L1 tokens from the msg sender to address(this).
+contract MockL1BridgeAdapter is IBridgeAdapter, ILiquidityContainer {
+ using SafeERC20 for IERC20;
+
+ error InsufficientLiquidity();
+ error NonceAlreadyUsed(uint256 nonce);
+ error InvalidFinalizationAction();
+ error NonceNotProven(uint256 nonce);
+ error NativeSendFailed();
+
+ /// @notice Payload to "prove" the withdrawal.
+ /// @dev This is just a mock setup, there's no real proving. This is so that
+ /// we can test the multi-step finalization code path.
+ /// @param nonce the nonce emitted on the remote chain.
+ struct ProvePayload {
+ uint256 nonce;
+ }
+
+ /// @notice Payload to "finalize" the withdrawal.
+ /// @dev This is just a mock setup, there's no real finalization. This is so that
+ /// we can test the multi-step finalization code path.
+ /// @param nonce the nonce emitted on the remote chain.
+ struct FinalizePayload {
+ uint256 nonce;
+ uint256 amount;
+ }
+
+ /// @notice The finalization action to take.
+ /// @dev This emulates Optimism's two-step withdrawal process.
+ enum FinalizationAction {
+ ProveWithdrawal,
+ FinalizeWithdrawal
+ }
+
+ /// @notice The payload to use for the bridgeSpecificPayload in the finalizeWithdrawERC20 function.
+ struct Payload {
+ FinalizationAction action;
+ bytes data;
+ }
+
+ IERC20 internal immutable i_token;
+ uint256 internal s_nonce = 1;
+ mapping(uint256 => bool) internal s_nonceProven;
+ mapping(uint256 => bool) internal s_nonceFinalized;
+
+ /// @dev For test cases where we want to send pure native upon finalizeWithdrawERC20 being called.
+ /// This is to emulate the behavior of bridges that do not bridge wrapped native.
+ bool internal immutable i_holdNative;
+
+ constructor(IERC20 token, bool holdNative) {
+ i_token = token;
+ i_holdNative = holdNative;
+ }
+
+ /// @dev The receive function is needed for IWrappedNative.withdraw() to work.
+ receive() external payable {}
+
+ /// @notice Simply transferFrom msg.sender the tokens that are to be bridged to address(this).
+ function sendERC20(
+ address localToken,
+ address /* remoteToken */,
+ address /* remoteReceiver */,
+ uint256 amount,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external payable override returns (bytes memory) {
+ IERC20(localToken).transferFrom(msg.sender, address(this), amount);
+
+ // If the flag to hold native is set we assume that i_token points to a WETH contract
+ // and withdraw native.
+ // This way we can transfer the raw native back to the sender upon finalization.
+ if (i_holdNative) {
+ IWrappedNative(address(i_token)).withdraw(amount);
+ }
+
+ bytes memory encodedNonce = abi.encode(s_nonce++);
+ return encodedNonce;
+ }
+
+ function getBridgeFeeInNative() external pure returns (uint256) {
+ return 0;
+ }
+
+ function provideLiquidity(uint256 amount) external {
+ i_token.safeTransferFrom(msg.sender, address(this), amount);
+ emit LiquidityAdded(msg.sender, amount);
+ }
+
+ function withdrawLiquidity(uint256 amount) external {
+ if (i_token.balanceOf(address(this)) < amount) revert InsufficientLiquidity();
+ i_token.safeTransfer(msg.sender, amount);
+ emit LiquidityRemoved(msg.sender, amount);
+ }
+
+ /// @dev for easy encoding offchain
+ function encodeProvePayload(ProvePayload memory payload) external pure {}
+
+ function encodeFinalizePayload(FinalizePayload memory payload) external pure {}
+
+ function encodePayload(Payload memory payload) external pure {}
+
+ /// @dev Test setup is trusted, so just transfer the tokens to the localReceiver,
+ /// which should be the local rebalancer. Infer the amount from the bridgeSpecificPayload.
+ /// Note that this means that this bridge adapter will need to have some tokens,
+ /// however this is ok in a test environment since we will have infinite tokens.
+ /// @param localReceiver the address to transfer the tokens to.
+ /// @param bridgeSpecificPayload the payload to use for the finalization or proving.
+ /// @return true if the transfer was successful, revert otherwise.
+ function finalizeWithdrawERC20(
+ address /* remoteSender */,
+ address localReceiver,
+ bytes calldata bridgeSpecificPayload
+ ) external override returns (bool) {
+ Payload memory payload = abi.decode(bridgeSpecificPayload, (Payload));
+ if (payload.action == FinalizationAction.ProveWithdrawal) {
+ return _proveWithdrawal(payload);
+ } else if (payload.action == FinalizationAction.FinalizeWithdrawal) {
+ return _finalizeWithdrawal(payload, localReceiver);
+ }
+ revert InvalidFinalizationAction();
+ }
+
+ function _proveWithdrawal(Payload memory payload) internal returns (bool) {
+ ProvePayload memory provePayload = abi.decode(payload.data, (ProvePayload));
+ if (s_nonceProven[provePayload.nonce]) revert NonceAlreadyUsed(provePayload.nonce);
+ s_nonceProven[provePayload.nonce] = true;
+ return false;
+ }
+
+ function _finalizeWithdrawal(Payload memory payload, address localReceiver) internal returns (bool) {
+ FinalizePayload memory finalizePayload = abi.decode(payload.data, (FinalizePayload));
+ if (!s_nonceProven[finalizePayload.nonce]) revert NonceNotProven(finalizePayload.nonce);
+ if (s_nonceFinalized[finalizePayload.nonce]) revert NonceAlreadyUsed(finalizePayload.nonce);
+ s_nonceFinalized[finalizePayload.nonce] = true;
+ // re-entrancy prevented by nonce checks above.
+ _transferTokens(finalizePayload.amount, localReceiver);
+ return true;
+ }
+
+ function _transferTokens(uint256 amount, address localReceiver) internal {
+ if (i_holdNative) {
+ (bool success, ) = payable(localReceiver).call{value: amount}("");
+ if (!success) {
+ revert NativeSendFailed();
+ }
+ } else {
+ i_token.safeTransfer(localReceiver, amount);
+ }
+ }
+}
+
+/// @notice Mock L2 Bridge adapter
+/// @dev Sends the L2 tokens from the msg sender to address(this)
+contract MockL2BridgeAdapter is IBridgeAdapter {
+ /// @notice Simply transferFrom msg.sender the tokens that are to be bridged.
+ function sendERC20(
+ address localToken,
+ address /* remoteToken */,
+ address /* recipient */,
+ uint256 amount,
+ bytes calldata /* bridgeSpecificPayload */
+ ) external payable override returns (bytes memory) {
+ IERC20(localToken).transferFrom(msg.sender, address(this), amount);
+ return "";
+ }
+
+ function getBridgeFeeInNative() external pure returns (uint256) {
+ return 0;
+ }
+
+ // No-op
+ function finalizeWithdrawERC20(
+ address /* remoteSender */,
+ address /* localReceiver */,
+ bytes calldata /* bridgeSpecificData */
+ ) external pure override returns (bool) {
+ return true;
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/mocks/NoOpOCR3.sol b/contracts/src/v0.8/liquiditymanager/test/mocks/NoOpOCR3.sol
new file mode 100644
index 00000000000..5e771f0ccd6
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/mocks/NoOpOCR3.sol
@@ -0,0 +1,18 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {OCR3Base} from "../../ocr/OCR3Base.sol";
+
+// NoOpOCR3 is a mock implementation of the OCR3Base contract that does nothing
+// This is so that we can generate gethwrappers for the contract and use the OCR3 ABI in
+// Go code.
+contract NoOpOCR3 is OCR3Base {
+ // solhint-disable-next-line chainlink-solidity/all-caps-constant-storage-variables
+ string public constant override typeAndVersion = "NoOpOCR3 1.0.0";
+
+ constructor() OCR3Base() {}
+
+ function _report(bytes calldata, uint64) internal override {
+ // do nothing
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/ocr/OCR3Base.t.sol b/contracts/src/v0.8/liquiditymanager/test/ocr/OCR3Base.t.sol
new file mode 100644
index 00000000000..840e90fb876
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/ocr/OCR3Base.t.sol
@@ -0,0 +1,337 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity 0.8.24;
+
+import {OCR3Setup} from "./OCR3Setup.t.sol";
+import {OCR3Base} from "../../ocr/OCR3Base.sol";
+import {OCR3Helper} from "../helpers/OCR3Helper.sol";
+
+contract OCR3BaseSetup is OCR3Setup {
+ event ConfigSet(
+ uint32 previousConfigBlockNumber,
+ bytes32 configDigest,
+ uint64 configCount,
+ address[] signers,
+ address[] transmitters,
+ uint8 f,
+ bytes onchainConfig,
+ uint64 offchainConfigVersion,
+ bytes offchainConfig
+ );
+
+ OCR3Helper internal s_OCR3Base;
+
+ bytes32[] internal s_rs;
+ bytes32[] internal s_ss;
+ bytes32 internal s_rawVs;
+
+ uint40 internal s_latestEpochAndRound;
+
+ function setUp() public virtual override {
+ OCR3Setup.setUp();
+ s_OCR3Base = new OCR3Helper();
+
+ bytes32 testReportDigest = getTestReportDigest();
+
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](2);
+ uint8[] memory vs = new uint8[](2);
+
+ // Calculate signatures
+ (vs[0], rs[0], ss[0]) = vm.sign(PRIVATE0, testReportDigest);
+ (vs[1], rs[1], ss[1]) = vm.sign(PRIVATE1, testReportDigest);
+
+ s_rs = rs;
+ s_ss = ss;
+ s_rawVs = bytes32(bytes1(vs[0] - 27)) | (bytes32(bytes1(vs[1] - 27)) >> 8);
+ }
+
+ function getBasicConfigDigest(uint8 f, uint64 currentConfigCount) internal view returns (bytes32) {
+ bytes memory configBytes = abi.encode("");
+ return
+ s_OCR3Base.configDigestFromConfigData(
+ block.chainid,
+ address(s_OCR3Base),
+ currentConfigCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ }
+
+ function getTestReportDigest() internal view returns (bytes32) {
+ bytes32 configDigest = getBasicConfigDigest(s_f, 0);
+ bytes32[3] memory reportContext = [configDigest, configDigest, configDigest];
+ return keccak256(abi.encodePacked(keccak256(REPORT), reportContext));
+ }
+
+ function getBasicConfigDigest(
+ address contractAddress,
+ uint8 f,
+ uint64 currentConfigCount,
+ bytes memory onchainConfig
+ ) internal view returns (bytes32) {
+ return
+ s_OCR3Base.configDigestFromConfigData(
+ block.chainid,
+ contractAddress,
+ currentConfigCount + 1,
+ s_valid_signers,
+ s_valid_transmitters,
+ f,
+ onchainConfig,
+ s_offchainConfigVersion,
+ abi.encode("")
+ );
+ }
+}
+
+contract OCR3Base_transmit is OCR3BaseSetup {
+ bytes32 internal s_configDigest;
+
+ function setUp() public virtual override {
+ OCR3BaseSetup.setUp();
+ bytes memory configBytes = abi.encode("");
+
+ s_configDigest = getBasicConfigDigest(s_f, 0);
+ s_OCR3Base.setOCR3Config(
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ }
+
+ function testTransmit2SignersSuccess_gas() public {
+ vm.pauseGasMetering();
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.resumeGasMetering();
+ s_OCR3Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ // Reverts
+
+ function testNonIncreasingSequenceNumberReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, bytes32(uint256(0)) /* sequence number */, s_configDigest];
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.NonIncreasingSequenceNumber.selector, 0, 0));
+ s_OCR3Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ function testForkedChainReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ uint256 chain1 = block.chainid;
+ uint256 chain2 = chain1 + 1;
+ vm.chainId(chain2);
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.ForkedChain.selector, chain1, chain2));
+ vm.startPrank(s_valid_transmitters[0]);
+ s_OCR3Base.transmit(reportContext, REPORT, s_rs, s_ss, s_rawVs);
+ }
+
+ function testWrongNumberOfSignaturesReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ vm.expectRevert(OCR3Base.WrongNumberOfSignatures.selector);
+ s_OCR3Base.transmit(reportContext, REPORT, new bytes32[](0), new bytes32[](0), s_rawVs);
+ }
+
+ function testConfigDigestMismatchReverts() public {
+ bytes32 configDigest;
+ bytes32[3] memory reportContext = [configDigest, bytes32(uint256(1)) /* sequence number */, configDigest];
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.ConfigDigestMismatch.selector, s_configDigest, configDigest));
+ s_OCR3Base.transmit(reportContext, REPORT, new bytes32[](0), new bytes32[](0), s_rawVs);
+ }
+
+ function testSignatureOutOfRegistrationReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](1);
+
+ vm.expectRevert(OCR3Base.SignaturesOutOfRegistration.selector);
+ s_OCR3Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+
+ function testUnAuthorizedTransmitterReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = new bytes32[](2);
+ bytes32[] memory ss = new bytes32[](2);
+
+ vm.expectRevert(OCR3Base.UnauthorizedTransmitter.selector);
+ s_OCR3Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+
+ function testNonUniqueSignatureReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = s_rs;
+ bytes32[] memory ss = s_ss;
+
+ rs[1] = rs[0];
+ ss[1] = ss[0];
+ // Need to reset the rawVs to be valid
+ bytes32 rawVs = bytes32(bytes1(uint8(28) - 27)) | (bytes32(bytes1(uint8(28) - 27)) >> 8);
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.expectRevert(OCR3Base.NonUniqueSignatures.selector);
+ s_OCR3Base.transmit(reportContext, REPORT, rs, ss, rawVs);
+ }
+
+ function testUnauthorizedSignerReverts() public {
+ bytes32[3] memory reportContext = [s_configDigest, s_configDigest, s_configDigest];
+ bytes32[] memory rs = new bytes32[](2);
+ rs[0] = s_configDigest;
+ bytes32[] memory ss = rs;
+
+ vm.startPrank(s_valid_transmitters[0]);
+ vm.expectRevert(OCR3Base.UnauthorizedSigner.selector);
+ s_OCR3Base.transmit(reportContext, REPORT, rs, ss, s_rawVs);
+ }
+}
+
+contract OCR3Base_setOCR3Config is OCR3BaseSetup {
+ function testSetConfigSuccess() public {
+ vm.pauseGasMetering();
+ bytes memory configBytes = abi.encode("");
+ uint32 configCount = 0;
+
+ bytes32 configDigest = getBasicConfigDigest(s_f, configCount++);
+
+ address[] memory transmitters = s_OCR3Base.getTransmitters();
+ assertEq(0, transmitters.length);
+
+ s_OCR3Base.setLatestSeqNum(3);
+ uint64 seqNum = s_OCR3Base.latestSequenceNumber();
+ assertEq(seqNum, 3);
+
+ vm.expectEmit();
+ emit ConfigSet(
+ 0,
+ configDigest,
+ configCount,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+
+ s_OCR3Base.setOCR3Config(
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+
+ transmitters = s_OCR3Base.getTransmitters();
+ assertEq(s_valid_transmitters, transmitters);
+
+ configDigest = getBasicConfigDigest(s_f, configCount++);
+
+ seqNum = s_OCR3Base.latestSequenceNumber();
+ assertEq(seqNum, 0);
+
+ vm.expectEmit();
+ emit ConfigSet(
+ uint32(block.number),
+ configDigest,
+ configCount,
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ vm.resumeGasMetering();
+ s_OCR3Base.setOCR3Config(
+ s_valid_signers,
+ s_valid_transmitters,
+ s_f,
+ configBytes,
+ s_offchainConfigVersion,
+ configBytes
+ );
+ }
+
+ // Reverts
+ function testRepeatAddressReverts() public {
+ address[] memory signers = new address[](10);
+ signers[0] = address(1245678);
+ address[] memory transmitters = new address[](10);
+ transmitters[0] = signers[0];
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.InvalidConfig.selector, "repeated transmitter address"));
+ s_OCR3Base.setOCR3Config(signers, transmitters, 2, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function testSignerCannotBeZeroAddressReverts() public {
+ uint256 f = 1;
+ address[] memory signers = new address[](3 * f + 1);
+ address[] memory transmitters = new address[](3 * f + 1);
+ for (uint160 i = 0; i < 3 * f + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ signers[0] = address(0);
+
+ vm.expectRevert(OCR3Base.OracleCannotBeZeroAddress.selector);
+ s_OCR3Base.setOCR3Config(signers, transmitters, uint8(f), abi.encode(""), 100, abi.encode(""));
+ }
+
+ function testTransmitterCannotBeZeroAddressReverts() public {
+ uint256 f = 1;
+ address[] memory signers = new address[](3 * f + 1);
+ address[] memory transmitters = new address[](3 * f + 1);
+ for (uint160 i = 0; i < 3 * f + 1; ++i) {
+ signers[i] = address(i + 1);
+ transmitters[i] = address(i + 1000);
+ }
+
+ transmitters[0] = address(0);
+
+ vm.expectRevert(OCR3Base.OracleCannotBeZeroAddress.selector);
+ s_OCR3Base.setOCR3Config(signers, transmitters, uint8(f), abi.encode(""), 100, abi.encode(""));
+ }
+
+ function testOracleOutOfRegisterReverts() public {
+ address[] memory signers = new address[](10);
+ address[] memory transmitters = new address[](0);
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.InvalidConfig.selector, "oracle addresses out of registration"));
+ s_OCR3Base.setOCR3Config(signers, transmitters, 2, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function testFTooHighReverts() public {
+ address[] memory signers = new address[](0);
+ uint8 f = 1;
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.InvalidConfig.selector, "faulty-oracle f too high"));
+ s_OCR3Base.setOCR3Config(signers, new address[](0), f, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function testFMustBePositiveReverts() public {
+ uint8 f = 0;
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.InvalidConfig.selector, "f must be positive"));
+ s_OCR3Base.setOCR3Config(new address[](0), new address[](0), f, abi.encode(""), 100, abi.encode(""));
+ }
+
+ function testTooManySignersReverts() public {
+ address[] memory signers = new address[](32);
+
+ vm.expectRevert(abi.encodeWithSelector(OCR3Base.InvalidConfig.selector, "too many signers"));
+ s_OCR3Base.setOCR3Config(signers, new address[](0), 0, abi.encode(""), 100, abi.encode(""));
+ }
+}
diff --git a/contracts/src/v0.8/liquiditymanager/test/ocr/OCR3Setup.t.sol b/contracts/src/v0.8/liquiditymanager/test/ocr/OCR3Setup.t.sol
new file mode 100644
index 00000000000..ee60c58dcc6
--- /dev/null
+++ b/contracts/src/v0.8/liquiditymanager/test/ocr/OCR3Setup.t.sol
@@ -0,0 +1,34 @@
+// SPDX-License-Identifier: BUSL-1.1
+pragma solidity ^0.8.0;
+
+import {LiquidityManagerBaseTest} from "../LiquidityManagerBaseTest.t.sol";
+
+contract OCR3Setup is LiquidityManagerBaseTest {
+ // Signer private keys used for these test
+ uint256 internal constant PRIVATE0 = 0x7b2e97fe057e6de99d6872a2ef2abf52c9b4469bc848c2465ac3fcd8d336e81d;
+ uint256 internal constant PRIVATE1 = 0xab56160806b05ef1796789248e1d7f34a6465c5280899159d645218cd216cee6;
+ uint256 internal constant PRIVATE2 = 0x6ec7caa8406a49b76736602810e0a2871959fbbb675e23a8590839e4717f1f7f;
+ uint256 internal constant PRIVATE3 = 0x80f14b11da94ae7f29d9a7713ea13dc838e31960a5c0f2baf45ed458947b730a;
+
+ address[] internal s_valid_signers;
+ address[] internal s_valid_transmitters;
+
+ uint64 internal constant s_offchainConfigVersion = 3;
+ uint8 internal constant s_f = 1;
+ bytes internal constant REPORT = abi.encode("testReport");
+
+ function setUp() public virtual override {
+ LiquidityManagerBaseTest.setUp();
+
+ s_valid_transmitters = new address[](4);
+ for (uint160 i = 0; i < 4; ++i) {
+ s_valid_transmitters[i] = address(4 + i);
+ }
+
+ s_valid_signers = new address[](4);
+ s_valid_signers[0] = vm.addr(PRIVATE0); //0xc110458BE52CaA6bB68E66969C3218A4D9Db0211
+ s_valid_signers[1] = vm.addr(PRIVATE1); //0xc110a19c08f1da7F5FfB281dc93630923F8E3719
+ s_valid_signers[2] = vm.addr(PRIVATE2); //0xc110fdF6e8fD679C7Cc11602d1cd829211A18e9b
+ s_valid_signers[3] = vm.addr(PRIVATE3); //0xc11028017c9b445B6bF8aE7da951B5cC28B326C0
+ }
+}
diff --git a/contracts/src/v0.8/vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol b/contracts/src/v0.8/vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol
new file mode 100644
index 00000000000..4daefc5d4f2
--- /dev/null
+++ b/contracts/src/v0.8/vendor/openzeppelin-solidity/v4.8.3/contracts/utils/introspection/ERC165Checker.sol
@@ -0,0 +1,127 @@
+// SPDX-License-Identifier: MIT
+// OpenZeppelin Contracts (last updated v4.8.2) (utils/introspection/ERC165Checker.sol)
+
+pragma solidity ^0.8.0;
+
+import "./IERC165.sol";
+
+/**
+ * @dev Library used to query support of an interface declared via {IERC165}.
+ *
+ * Note that these functions return the actual result of the query: they do not
+ * `revert` if an interface is not supported. It is up to the caller to decide
+ * what to do in these cases.
+ */
+library ERC165Checker {
+ // As per the EIP-165 spec, no interface should ever match 0xffffffff
+ bytes4 private constant _INTERFACE_ID_INVALID = 0xffffffff;
+
+ /**
+ * @dev Returns true if `account` supports the {IERC165} interface.
+ */
+ function supportsERC165(address account) internal view returns (bool) {
+ // Any contract that implements ERC165 must explicitly indicate support of
+ // InterfaceId_ERC165 and explicitly indicate non-support of InterfaceId_Invalid
+ return
+ supportsERC165InterfaceUnchecked(account, type(IERC165).interfaceId) &&
+ !supportsERC165InterfaceUnchecked(account, _INTERFACE_ID_INVALID);
+ }
+
+ /**
+ * @dev Returns true if `account` supports the interface defined by
+ * `interfaceId`. Support for {IERC165} itself is queried automatically.
+ *
+ * See {IERC165-supportsInterface}.
+ */
+ function supportsInterface(address account, bytes4 interfaceId) internal view returns (bool) {
+ // query support of both ERC165 as per the spec and support of _interfaceId
+ return supportsERC165(account) && supportsERC165InterfaceUnchecked(account, interfaceId);
+ }
+
+ /**
+ * @dev Returns a boolean array where each value corresponds to the
+ * interfaces passed in and whether they're supported or not. This allows
+ * you to batch check interfaces for a contract where your expectation
+ * is that some interfaces may not be supported.
+ *
+ * See {IERC165-supportsInterface}.
+ *
+ * _Available since v3.4._
+ */
+ function getSupportedInterfaces(address account, bytes4[] memory interfaceIds)
+ internal
+ view
+ returns (bool[] memory)
+ {
+ // an array of booleans corresponding to interfaceIds and whether they're supported or not
+ bool[] memory interfaceIdsSupported = new bool[](interfaceIds.length);
+
+ // query support of ERC165 itself
+ if (supportsERC165(account)) {
+ // query support of each interface in interfaceIds
+ for (uint256 i = 0; i < interfaceIds.length; i++) {
+ interfaceIdsSupported[i] = supportsERC165InterfaceUnchecked(account, interfaceIds[i]);
+ }
+ }
+
+ return interfaceIdsSupported;
+ }
+
+ /**
+ * @dev Returns true if `account` supports all the interfaces defined in
+ * `interfaceIds`. Support for {IERC165} itself is queried automatically.
+ *
+ * Batch-querying can lead to gas savings by skipping repeated checks for
+ * {IERC165} support.
+ *
+ * See {IERC165-supportsInterface}.
+ */
+ function supportsAllInterfaces(address account, bytes4[] memory interfaceIds) internal view returns (bool) {
+ // query support of ERC165 itself
+ if (!supportsERC165(account)) {
+ return false;
+ }
+
+ // query support of each interface in interfaceIds
+ for (uint256 i = 0; i < interfaceIds.length; i++) {
+ if (!supportsERC165InterfaceUnchecked(account, interfaceIds[i])) {
+ return false;
+ }
+ }
+
+ // all interfaces supported
+ return true;
+ }
+
+ /**
+ * @notice Query if a contract implements an interface, does not check ERC165 support
+ * @param account The address of the contract to query for support of an interface
+ * @param interfaceId The interface identifier, as specified in ERC-165
+ * @return true if the contract at account indicates support of the interface with
+ * identifier interfaceId, false otherwise
+ * @dev Assumes that account contains a contract that supports ERC165, otherwise
+ * the behavior of this method is undefined. This precondition can be checked
+ * with {supportsERC165}.
+ *
+ * Some precompiled contracts will falsely indicate support for a given interface, so caution
+ * should be exercised when using this function.
+ *
+ * Interface identification is specified in ERC-165.
+ */
+ function supportsERC165InterfaceUnchecked(address account, bytes4 interfaceId) internal view returns (bool) {
+ // prepare call
+ bytes memory encodedParams = abi.encodeWithSelector(IERC165.supportsInterface.selector, interfaceId);
+
+ // perform static call
+ bool success;
+ uint256 returnSize;
+ uint256 returnValue;
+ assembly {
+ success := staticcall(30000, account, add(encodedParams, 0x20), mload(encodedParams), 0x00, 0x20)
+ returnSize := returndatasize()
+ returnValue := mload(0x00)
+ }
+
+ return success && returnSize >= 0x20 && returnValue > 0;
+ }
+}