Repository navigation
feat: execute multi-token funding with durable mint recovery - #52
Merged
Merged
Conversation
ameya-deshmukh
marked this pull request as ready for review
September 28, 2026 14:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The token catalog can describe additional contracts, but funding currently always uses the default contract. This change connects configured Base tokens to transfers and executes bounded reserve replenishment before payout, while preserving default-token requests and response shapes.
Closes https://linear.app/seismic-systems/issue/SEI-665
token_addresson the existing Base token-transfer endpoint and the generic/api/internal/base/erc20/transfersalias. Omission selects the existing default; unknown contracts returnunsupported_token.manual_funding_required; the caller must fund the recipient manually. These terminal requests retain their idempotency result and quota reservation and leave the queue free for other requests.token_addresson/api/internal/base/settlementto retrieve the selected token's reserve identity. Existing readiness diagnostics remain scoped to the default token and native reserve.Before
After
flowchart TD A[Funding request with optional token address] --> B[Resolve exact allowed contract and limits] B --> C[Reserve token budget and acquire shared signer queue] C --> D{Inventory sufficient?} D -->|Yes| G[Persist signed payout] D -->|No, manual inventory| E[Return manual funding required] D -->|No, reviewed mint strategy| F[Persist signed mint batch and payout] F --> H[Confirm each mint and save progress] H --> G G --> I[Confirm payout and verify transfer event]Validation and rollout
Workspace fmt, clippy with warnings denied, locked tests, and release build run locally. Tests cover HTTP selection/auth/limits/default replay, independent token budgets, shared signer queues, interrupted persistence at each mint boundary, restart recovery, mint failure, signed calldata/nonces, and exact transfer receipts. Tests use local Redis and simulated JSON-RPC; no testnet funding transactions were sent.
Deploy after review, then enable reviewed additional contracts in the JSON catalog and restart. Existing configuration without additional tokens preserves default funding behavior. Mint batches use a new persisted record state: do not mix older workers or downgrade while replenishment records remain pending; resolve those records first. Contract behavior beyond the supported reviewed mint strategy, swaps, and customer-funded treasury attribution are outside this change.