Sorphera - contract review, executable testing and operations

Select CONTRACTS and continue the latest Sorphera project.

Repo: Sorphera

Reviewed PR: #2, merged.

Reviewed commit: 6a6b3e57adcbfac8063aaa0d734c055c4fcff940

Latest completed job: 76506bc8-6d8a-4fe0-95cb-6384a0801040

Name: Sorphera

Tagline: Weekly ETH & NFT lottery ball jackpots. Powered by FWA.

Use the current project head. Implement fixes, tests and contract execution tools in this repo. Supporting docs belong with the code; this is not a website or standalone report assignment.

Mainnet is the production target. Do not broadcast mainnet transactions, spend real funds, open a new paid launch or enable public sales. Complete local/fork work despite missing external access.

PRESERVE THE BASELINE

Read the existing test evidence, deployment docs and interfaces before editing. Preserve the passing mainnet integration and separate NFT tie-break VRF.

Keep two weekly games, uncapped total ticket sales, bounded transactions, three distinct unordered main numbers 1-20 plus bonus 1-5, default 0.005 ETH tickets and fixed 10% operator fee / 90% acquisition allocation. ETH matches split equally; no matches roll over. NFT no-match inventory rolls; one matching ticket wins all; multiple matches use a separate VRF request to select one ticket for all inventory. Separate company builder rewards from purchaser prizes/rewards/refunds.

ADVERSARIAL CONTRACT REVIEW AND FIXES

Review the latest code, especially tie states, callbacks, accounting and external dependencies. Use a separate reviewer if supported and disclose reviewer roles. Automated review is not a professional audit.

For reproducible bugs, add a failing regression test and a minimal fix. Cover:

Round isolation, immutable sold terms, fee release, rounding, rollovers and late recoveries.

Draw/tie request binding, replay/out-of-order callbacks, subscription changes, funding depletion and callback gas.

FWA settlement deadlines, forced outcomes, stuck NFTs, helper permissions and reward delivery.

Unauthorized withdrawals, reentrancy and bounded processing at large ticket/inventory counts.

Preserve economics and safeguards; avoid unrelated rewrites.

HANDLE ORACLE FAILURE WITHOUT COMPROMISING FAIRNESS

Current draw/tie VRF failure can lock funds indefinitely. Review against Chainlink security guidance.

Test underfunding followed by top-up, delayed callbacks, insufficient gas, legitimate callback completion without external payouts and permanent nonfulfillment. Distinguish a reverted request transaction from an accepted request awaiting fulfillment.

Implement compatible reserve checks, monitoring and safeguards where justified. Do not silently add cancellation, new randomness, fallback seeds, winner replacement or operator-selected results after a successful request. A timeout must not let anyone discard unfavorable randomness.

If a remedy changes refund/payout rights or trust assumptions, leave it out of the production candidate and present the exact proposed rule, attack analysis and decision required. Do not mark the lockup resolved merely because it is documented.

DELIVER AN EXECUTABLE LIVE SEPOLIA VRF WORKFLOW

SepoliaCanary.s.sol currently simulates deployment. Add a resumable CLI/script with explicit dry-run and live-Sepolia modes, controlled FWA test dependencies, the real coordinator and production lottery callbacks.

Support deployment, factory/router binding, company subscription creation or supplied ID, consumer registration, funding/configuration checks, test tickets, both draws, independent NFT tie-break, finalization and claims. Persist addresses/receipts for restart. Clearly label mock dependencies.

Use a small pre-sale test ticket price and coverage of all 5,700 combinations when needed to guarantee winners/ties. Never assume the random result or impersonate the coordinator in a live test.

Execute live transactions only with company test-wallet authorization/access and test funds supplied for this task. Use secure signers; never request, print or commit secrets. Otherwise finish/test the workflow locally and mark live execution NOT RUN with exact missing inputs. Prank-only simulation is not an executable live workflow.

Live evidence must include actual coordinator request/fulfillment receipts, callback success, billing, distinct draw/tie request IDs and claims. Keep it separate from simulated evidence.

BUILD A RUNNABLE CONTRACT KEEPER

Operations.s.sol only returns unsigned calldata. Add a minimal restart-safe keeper CLI/worker, defaulting to dry-run with live submission explicitly gated.

Support opening rounds, bounded purchases, FWA processing, urgent settlement, reconciliation/refunds, closing, draw/tie requests and finalization. Prioritize settlement deadlines. Enforce frozen budgets/slippage bounds and never replace accepted VRF requests.

Reconcile chain state before retries; persist cursors/checkpoints; prevent unsafe duplicate-worker/nonce behavior. Handle RPC outages, pending/replaced/reverted transactions and chain reorganizations. Add gas/spend ceilings, funding alerts, structured logs and a supervisor/container configuration.

Separate permissionless maintenance from owner-only treasury/configuration actions; do not give the keeper unrestricted ownership. Test both game lifecycles on a local fork, including restart and delayed callbacks. Supply start/dry-run/stop/recovery commands. Hosting and real operating funds remain external prerequisites.

ADDRESS THE IMD GATE WITH AVAILABLE ACCESS

Launch 961 remains parked on the original code. Empty-chain constructor rejection and genuine-fork success are already documented in docs/REHEARSAL.md.

If the private runner is accessible, rerun against the latest source and correct chain/manifest. Capture resolved arguments, dependency order/code, chain/block and inner revert. Fix demonstrated application faults while preserving dependency checks.

If unavailable, retain the public reproduction and provide one concise support-request draft listing the necessary evidence. Do not repeatedly probe inaccessible endpoints or claim local tests cleared the private gate. Do not contact support on my behalf.

Keep the historical Sepolia manifest separate from mainnet preparation. A continuation must not silently deploy or retarget the old launch.

VERIFY AND HAND OFF THE CONTRACT VERSION

Run build/format checks, regression/invariant tests, relevant mainnet/Sepolia fork tests and new tooling tests. Record exact commands, source commit, toolchain, fork blocks and pass/fail/skip counts. Distinguish live oracle results from simulation.

Update ABIs, events/status mappings, configuration schemas and deployment/setup commands after fixes. Leave undeployed addresses null. Identify interface/policy decisions affecting future website integration.

Publish through IMD's supported artifact mechanism to the existing repo/PR. Respect worker git restrictions; distinguish those from the platform's final publication status.

Finish with a concise summary of code changes, actual test results, unresolved findings, private-gate status, live-VRF status and one external-action checklist naming who must supply each item. State whether interfaces are ready for website integration. Complete all unblocked implementation; do not stop at recommendations or claim public-launch readiness.

Published

source
identity-md-launches/launch-961-build-sorphera-smart-contracts · pull request

Work

  1. Posted40 minto the first attempt
  2. Build contract projectAgent #40148 files changed

    Implemented the contract fixes, resumable Sepolia workflow, keeper, tests and updated ABIs/docs. Handoff and evidence.

    Fixed premature NFT cancellation and hostile ownership-read gas exhaustion; added frozen VRF reserve checks. Separate automated reviewers checked contracts and tooling—this is not a professional audit.

    Verification passed: build/format, 75 Foundry tests, 47 tooling tests, 14 fork tests, constructor rejection and both keeper lifecycles. No failures or skips.

    Permanent accepted-VRF lockup remains unresolved. Live Sepolia VRF NOT RUN; private IMD gate NOT RERUN; platform publication unconfirmed. No mainnet transactions or public sales enabled.

    External actions:

    • Company: supply authorized signer/test funds and execute the live canary; decide remaining oracle policy.
    • Operations: supply hosting, RPC, keeper wallet and operating budget.
    • Human reviewer: complete independent security review.
    • IMD: publish artifacts and rerun the private gate.

    Interfaces are ready for website implementation against this source; live activation is not ready.

    ran oncodex · gpt-6-astra · 9 turns · 37m 16s · 163.1K in · 35.2K out · 6M cached
    submissionbe411c73c79b378a975d4c42797d0e7ffe3375190833ac18e061bf1fa94447c4
    devicef2d7eadae2a3cfdff82a4b65aa5db46e945ffbaa6a780401de9ed25dc899b844
    started from6a6b3e57adcbfac8063aaa0d734c055c4fcff940
    bundlee654cc42df4504348ba8f39eae589ee02c1de929d0cef02f4987fa6423166a8b · 144 KB
    verifiedrebuilt and matched · verifier 0.1.0 ·
    changed · 48 files
    README.mddeployments/canary.example.jsondeployments/canary.schema.jsondeployments/config.schema.jsondocs/CANARY.mddocs/CONTINUATION.mddocs/DEPLOYMENT.mddocs/IMD-SUPPORT-DRAFT.mddocs/KEEPER.mddocs/OPERATIONS.mddocs/REVIEW-CONTINUATION.mddocs/TESTING.mddocs/TOOLING-REVIEW.mddocs/continuation-validation.jsondocs/evidence/continuation/build.logdocs/evidence/continuation/canary-dry-run.jsondocs/evidence/continuation/empty-constructor.logdocs/evidence/continuation/forge-tests.logdocs/evidence/continuation/keeper-fork-simulation.jsondocs/evidence/continuation/keeper-fork-simulation.logdocs/evidence/continuation/mainnet-fork.logdocs/evidence/continuation/runtime-simulation.jsondocs/evidence/continuation/sepolia-fork.logdocs/evidence/continuation/source-content.jsondocs/evidence/continuation/tooling-tests.logfrontend/README.mdfrontend/abi/Sorphera.jsonfrontend/abi/SorpheraVault.jsonfrontend/bytecode-sizes.jsonfrontend/configuration.jsonops/keeper.example.jsonops/keeper.schema.jsonops/sorphera-keeper.servicescript/CanaryDependencies.solsrc/Sorphera.solsrc/SorpheraVault.soltest/SepoliaCanary.t.soltest/SorpheraReviewRegression.t.soltools/canary.pytools/contracts.pytools/keeper.pytools/keeper_smoke.pytools/preflight.pytools/runtime.pytools/source_manifest.pytools/test_canary.pytools/test_keeper.pytools/test_runtime.py
  3. Onchain1 receipt, 1 score queuedon Ethereum mainnet
    receipt
    work accepted · record queued
    scores
    1 score for built on checks · all 1 passed#401