v3.0.0-rc5
Changed
ERC3643ComplianceModule._bindToken/_unbindToken: rely on theEnumerableSetmutation return value instead of a precedingcontains()lookup, keeping theTokenAlreadyBound/TokenNotBounddiagnostics (269 gas measured)._bindToken,_unbindTokenandRuleEngineBase._supportsRuleEngineBaseInterfaceare nowvirtual, along with the remaining non-virtualinternals in the mock rules, per the project convention.RuleAddressList.addressIsListedBatch:memoryparameter changed tocalldata(587 gas measured for 10 addresses).- Deployment now emits
SetMaxRuleswith the initial cap, so the event log alone is sufficient to reconstructmaxRules. RulesManagementModule: the rule-cap write and its event moved into a newinternal virtual _setMaxRules(uint256), called bysetMaxRulesand by the deployable contracts' constructors._maxRulesis now written from a single place, so the invariant "every change to the cap emitsSetMaxRules" holds structurally rather than by convention, and the non-zero check guards every path including construction.RulesManagementModule: rule insertion moved into a newinternal virtual _addRule(IRule), called byaddRuleand by thesetRulesloop.AddRuleis now emitted from a single site. ThemaxRulescap is deliberately checked by the callers, sinceaddRulechecks per insertion whilesetRuleschecks the whole batch up front.
Added
-
Add
ERC3643TokenMock: a minimal ERC-3643 (T-REX) style token whose compliance interaction mirrorsToken.solfrom the reference implementation, used to test the RuleEngine through the ERC-3643 entry points (setComplianceself-binding,transferred,created,destroyed). -
Add
ERC3643TokenIntegration.t.sol(11 tests), including a regression guard for the H-1 mint pre-check fail-open and one pinning the requirement thataddress(0)be whitelisted for an ERC-3643 token to mint. -
Renamed the reference rules in
src/mocks/rules/with aMocksuffix, so a reader cannot mistake them for the production rules of the same name maintained in CMTA/Rules:RuleWhitelist->RuleWhitelistMock,RuleConditionalTransferLight->RuleConditionalTransferLightMock,RuleMintAllowance->RuleMintAllowanceMock,RuleOperationRevert->RuleOperationRevertMock. Files renamed to match. The abstract bases and invariant-storage contracts they build on are unchanged, as they are not themselves rules.
Removed
RuleEngine_ERC3643Compliance_OperationNotSuccessful: unreachable after the bind/unbind simplification and referenced nowhere else.
Documentation
- Document that the ERC-1404 3-argument
canTransfer/detectTransferRestrictionpath fails open for spender-dependent rules, and thatcanTransferFrom/detectTransferRestrictionFrommust be used to pre-check an operation that has an operator. - Add the code-quality review in doc/security/audits/tools/v3.0.0-rc5/CLAUDE_ANALYSIS.md.
- Add integration guides in
doc/technical: RuleEngine-with-CMTAT.md and RuleEngine-with-ERC3643.md, covering entry points, configuration, warnings, limitations and test coverage for each token standard. - Add the script review in doc/security/audits/tools/v3.0.0-rc5/CLAUDE_ANALYSIS_SCRIPT.md.
- Add the v3.0.0-rc5 Slither and Aderyn reports with their assessment feedback, each prefixed with a summary table of findings and dispositions.
- Add doc/security/audits/AUDIT_OVERVIEW.md indexing every analysis performed, the static-analysis results per tool, and the substantive findings that were fixed.
Fixed
RuleEngineScript.s.sol: the CMTAT token is now bound to the engine (passed to the constructor). Previously the script produced a deployment in which every transfer, mint and burn reverted withRuleEngine_ERC3643Compliance_UnauthorizedCaller, because the token was never bound.RuleEngineScript.s.sol:setRuleEngineis now called through the typed interface instead of a low-level.callguarded by a barerequire(success). The previous form returned success whenCMTAT_ADDRESSheld no code, silently producing an unconfigured deployment, and discarded the revert reason on failure.RuleEngineScript.s.sol: the demo whitelist is now seeded with the deployer andaddress(0), so the resulting deployment can transfer, mint and burn as-is.test/script/RuleEngineScript.t.sol: asserts the resulting deployment works (engine set, token bound, rule configured, a real mint) instead of only thatrun()does not revert.doc/script/script_surya_*.sh: fixed the shebang (#/bin/bash->#!/bin/bash), the undefined$dirloop variable,mkdirwithout-pin the report script, and the output-directory guard in the inheritance script; addedset -euo pipefailand null-delimitedfinditeration to all three. The loop iteratesfind .rather than an absolute path on purpose:surya mdreportembeds the path it is given, so an absolute one would write machine-specific paths into the committed reports underdoc/schema/surya/surya_report.package.json: thesurya:*anduml:*scripts now write beneathdocOut/(gitignored) instead of the repository root.doc/script/convert_links_for_pdf.sh: the default input is nowdoc/README.md(the full documentation) rather than the short root README.
Dependencies
- Update CMTAT submodule to v3.3.0-rc3.
- Update OpenZeppelin Contracts and OpenZeppelin Contracts Upgradeable submodules to v5.7.0.