Skip to content

feat: execute multi-token funding with durable mint recovery - #52

Merged
ameya-deshmukh merged 1 commit into
seismicfrom
codex/token-funding-runtime
Sep 28, 2026
Merged

ameya-deshmukh merged 1 commit into
seismicfrom
codex/token-funding-runtime

Conversation

@ameya-deshmukh

Copy link
Copy Markdown
Collaborator

The token catalog can describe additional contracts, but funding currently always uses the default contract. This change connects configured Base tokens to transfers and executes bounded reserve replenishment before payout, while preserving default-token requests and response shapes.

Closes https://linear.app/seismic-systems/issue/SEI-665

  • Accept optional token_address on the existing Base token-transfer endpoint and the generic /api/internal/base/erc20/transfers alias. Omission selects the existing default; unknown contracts return unsupported_token.
  • Resolve transfer limits, budgets, and idempotency scopes per contract. All Base tokens and gas requests retain one queue and nonce lock per signer.
  • Persist every signed mint and the signed payout atomically before broadcasting. Save each confirmed mint's progress; retries recover the same signed bytes. A failed mint never sends the payout.
  • Use inventory directly when sufficient. Manual-inventory shortages return manual_funding_required; the caller must fund the recipient manually. These terminal requests retain their idempotency result and quota reservation and leave the queue free for other requests.
  • Validate configured token bytecode/decimals and require an exact Transfer event for additional-token payouts. Check existing receipts before rebroadcast, including transactions whose original execution depleted the gas balance.
  • Allow token_address on /api/internal/base/settlement to retrieve the selected token's reserve identity. Existing readiness diagnostics remain scoped to the default token and native reserve.

Before

flowchart TD
  A[Funding request] --> B[Default token only]
  B --> C[Persist signed transfer]
  C --> D[Broadcast and confirm]
  E[Additional JSON catalog entries] --> F[No runtime execution]
Loading

After

flowchart TD
  A[Funding request with optional token address] --> B[Resolve exact allowed contract and limits]
  B --> C[Reserve token budget and acquire shared signer queue]
  C --> D{Inventory sufficient?}
  D -->|Yes| G[Persist signed payout]
  D -->|No, manual inventory| E[Return manual funding required]
  D -->|No, reviewed mint strategy| F[Persist signed mint batch and payout]
  F --> H[Confirm each mint and save progress]
  H --> G
  G --> I[Confirm payout and verify transfer event]
Loading

Validation and rollout

Workspace fmt, clippy with warnings denied, locked tests, and release build run locally. Tests cover HTTP selection/auth/limits/default replay, independent token budgets, shared signer queues, interrupted persistence at each mint boundary, restart recovery, mint failure, signed calldata/nonces, and exact transfer receipts. Tests use local Redis and simulated JSON-RPC; no testnet funding transactions were sent.

Deploy after review, then enable reviewed additional contracts in the JSON catalog and restart. Existing configuration without additional tokens preserves default funding behavior. Mint batches use a new persisted record state: do not mix older workers or downgrade while replenishment records remain pending; resolve those records first. Contract behavior beyond the supported reviewed mint strategy, swaps, and customer-funded treasury attribution are outside this change.

@linear-code

linear-code Bot commented Sep 28, 2026

Copy link
Copy Markdown

SEI-665

@ameya-deshmukh
ameya-deshmukh marked this pull request as ready for review September 28, 2026 14:09
@ameya-deshmukh
ameya-deshmukh merged commit 133d7ee into seismic Sep 28, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant