Repository navigation
feat(bridge): add Arc xReserve and CCTP support - #73
Conversation
iamalwaysuncomfortable
left a comment
There was a problem hiding this comment.
Review of the Arc xReserve + CCTP work. Ten inline comments, ranked most severe first.
Blocking, in my view:
cctp.py:417— delivered transfers can get stuck in DELIVERY_PENDING with no way to complete._evm_connections.py:53— testnet clients fail to construct when any mainnet EVM RPC var is exported.cctp.py:122— Circle 429/5xx are classified as non-transient, sowait()aborts on the first blip.cctp.py:151— the defaultmax_feepins the cap to the live fee, so execute can spend approval gas and then abort.
The remaining six are duplication and efficiency cleanups (double checkpoint writes, triple quoting, unbounded log scan on recovery, duplicated env parsing and fee reads, hardcoded xReserve domains) that could land as a follow-up.
| if not floor.isdigit(): | ||
| raise ConfigurationError("BRIDGE_MIN_PRIORITY_FEE_WEI must be a whole number of wei") | ||
| kwargs["min_priority_fee_wei"] = int(floor) | ||
| for chain, variable in RPC_VARIABLES.items(): |
There was a problem hiding this comment.
Breaks testnet clients with a shared .env. from_env unconditionally builds connections for ARC_RPC_URL, BASE_RPC_URL, ARBITRUM_RPC_URL (all mainnet-only), and normalize() then rejects them for a testnet client. Reproduced: ALEO_NETWORK=testnet + ARC_RPC_URL set → Bridge.from_env() raises ConfigurationError "EVM connection 'arc' must belong to testnet and the EVM family". Previously working testnet setups break on upgrade with no fix except unsetting mainnet variables. Suggest filtering by the client's network before building, or skipping incompatible chains in normalize.
Adds native Arc support to the Python bridge based on Veil #148, pinned to
3c3b457bd5f63620657321893a2487e489750d24.ethereum=,bridge.eth, existing calling forms, and compatible checkpoints for the 22 original routes.Review fixes preserve testnet construction when mainnet RPC variables are exported; retry Circle 429/5xx and truncated responses; backfill old destination receipts; quote 10% default fee headroom without increasing explicit or saved caps; return resumable approval-only progress when fees rise; reuse one xReserve execution fee estimate; and reconcile source history in bounded batches. Scan cursors stay in memory, check block-hash anchors (including while extending a scan), and safely restart after a process restart. Public calling signatures remain compatible.
Validation
885519a, including 23 added regression cases; project and strict new-module Pyright reported 0 errors, 0 warnings. Generated-context and diff checks passed. Independent review found a scan-extension reorg race; its regression failed before the fix and passed afterward, with no remaining reviewer findings.1152925, before the review fixes. No new funded transactions were submitted for885519a.1152925, including cross-platform tests, proving/network tests, lint, and bridge/package builds. Four release jobs were skipped for the PR. CI results.USDT was excluded at the account owner's request. Ten registry routes marked
metadata-requiredremain unavailable.Initial attempts encountered gas shortfalls, an expired Solana blockhash, RPC allowance propagation, changing fee quotes, finality timeouts, and concurrent-wallet interference with a WBTC assertion/approval. These were resolved through funding, serialized reruns, fresh quotes before any submission, or recovery of recorded transactions. Assertions were retained, submitted checkpoints retained their fee caps, and pending deposits were not repeated.
Outbound xReserve completion generally uses balance observation. The dedicated Arc withdrawal test additionally requires an exact successful destination receipt and balance delta. Both public integration journeys and the funded L2 CLI withdrawal were also independently audited against accepted Aleo burns and exact successful Arc transfer receipts.