Skip to content

fix: scope fee profiles to their measured chain - #3

Merged
MuncleUscles merged 1 commit into
v0.1-devfrom
fix/fee-profile-chain-guard
Sep 3, 2026
Merged

MuncleUscles merged 1 commit into
v0.1-devfrom
fix/fee-profile-chain-guard

Conversation

@MuncleUscles

Copy link
Copy Markdown
Member

Summary

  • require exact chainId provenance before applying developer fee suggestions
  • safely fall back for unscoped, malformed, wrong-chain, or below-floor profiles
  • re-estimate unsafe profiles through SDK network defaults so distribution and fee value remain coherent
  • clarify the boundary of live policy verification

Root cause

Profile selection used only deploy/method name. The human-readable network label was not a security boundary, so allocations measured for one chain could be reused on another while live price-cap verification still passed.

Validation

  • core: 21 tests
  • React: 16 tests
  • Vue: 13 tests
  • release policy: 6 tests
  • full typecheck and build
  • 3 package tarballs validated

Downstream

The testing-suite profile generator must emit numeric chainId. Legacy profiles deliberately fall back to network defaults, and the Boilerplate RC no longer loads its stale profile.

Require explicit chain-id provenance before developer allocations can seed a quote. If a matched profile falls below the live execution-budget floor, discard it and re-estimate with SDK defaults so the returned distribution and fee value remain coherent.

Validated with core profile-selection regressions, full workspace tests, typecheck, build, and package dry-run.
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: 2b5d30ae-b117-4707-a39b-ffaf4f677fd2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@MuncleUscles
MuncleUscles merged commit 5c177fd into v0.1-dev Sep 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant