Sorphera - contract review, executable testing and operations
Select CONTRACTS and continue the latest Sorphera project.
Repo: Sorphera
Reviewed PR: #2, merged.
Reviewed commit: 6a6b3e57adcbfac8063aaa0d734c055c4fcff940
Latest completed job: 76506bc8-6d8a-4fe0-95cb-6384a0801040
Name: Sorphera
Tagline: Weekly ETH & NFT lottery ball jackpots. Powered by FWA.
Use the current project head. Implement fixes, tests and contract execution tools in this repo. Supporting docs belong with the code; this is not a website or standalone report assignment.
Mainnet is the production target. Do not broadcast mainnet transactions, spend real funds, open a new paid launch or enable public sales. Complete local/fork work despite missing external access.
PRESERVE THE BASELINE
Read the existing test evidence, deployment docs and interfaces before editing. Preserve the passing mainnet integration and separate NFT tie-break VRF.
Keep two weekly games, uncapped total ticket sales, bounded transactions, three distinct unordered main numbers 1-20 plus bonus 1-5, default 0.005 ETH tickets and fixed 10% operator fee / 90% acquisition allocation. ETH matches split equally; no matches roll over. NFT no-match inventory rolls; one matching ticket wins all; multiple matches use a separate VRF request to select one ticket for all inventory. Separate company builder rewards from purchaser prizes/rewards/refunds.
ADVERSARIAL CONTRACT REVIEW AND FIXES
Review the latest code, especially tie states, callbacks, accounting and external dependencies. Use a separate reviewer if supported and disclose reviewer roles. Automated review is not a professional audit.
For reproducible bugs, add a failing regression test and a minimal fix. Cover:
Round isolation, immutable sold terms, fee release, rounding, rollovers and late recoveries.
Draw/tie request binding, replay/out-of-order callbacks, subscription changes, funding depletion and callback gas.
FWA settlement deadlines, forced outcomes, stuck NFTs, helper permissions and reward delivery.
Unauthorized withdrawals, reentrancy and bounded processing at large ticket/inventory counts.
Preserve economics and safeguards; avoid unrelated rewrites.
HANDLE ORACLE FAILURE WITHOUT COMPROMISING FAIRNESS
Current draw/tie VRF failure can lock funds indefinitely. Review against Chainlink security guidance.
Test underfunding followed by top-up, delayed callbacks, insufficient gas, legitimate callback completion without external payouts and permanent nonfulfillment. Distinguish a reverted request transaction from an accepted request awaiting fulfillment.
Implement compatible reserve checks, monitoring and safeguards where justified. Do not silently add cancellation, new randomness, fallback seeds, winner replacement or operator-selected results after a successful request. A timeout must not let anyone discard unfavorable randomness.
If a remedy changes refund/payout rights or trust assumptions, leave it out of the production candidate and present the exact proposed rule, attack analysis and decision required. Do not mark the lockup resolved merely because it is documented.
DELIVER AN EXECUTABLE LIVE SEPOLIA VRF WORKFLOW
SepoliaCanary.s.sol currently simulates deployment. Add a resumable CLI/script with explicit dry-run and live-Sepolia modes, controlled FWA test dependencies, the real coordinator and production lottery callbacks.
Support deployment, factory/router binding, company subscription creation or supplied ID, consumer registration, funding/configuration checks, test tickets, both draws, independent NFT tie-break, finalization and claims. Persist addresses/receipts for restart. Clearly label mock dependencies.
Use a small pre-sale test ticket price and coverage of all 5,700 combinations when needed to guarantee winners/ties. Never assume the random result or impersonate the coordinator in a live test.
Execute live transactions only with company test-wallet authorization/access and test funds supplied for this task. Use secure signers; never request, print or commit secrets. Otherwise finish/test the workflow locally and mark live execution NOT RUN with exact missing inputs. Prank-only simulation is not an executable live workflow.
Live evidence must include actual coordinator request/fulfillment receipts, callback success, billing, distinct draw/tie request IDs and claims. Keep it separate from simulated evidence.
BUILD A RUNNABLE CONTRACT KEEPER
Operations.s.sol only returns unsigned calldata. Add a minimal restart-safe keeper CLI/worker, defaulting to dry-run with live submission explicitly gated.
Support opening rounds, bounded purchases, FWA processing, urgent settlement, reconciliation/refunds, closing, draw/tie requests and finalization. Prioritize settlement deadlines. Enforce frozen budgets/slippage bounds and never replace accepted VRF requests.
Reconcile chain state before retries; persist cursors/checkpoints; prevent unsafe duplicate-worker/nonce behavior. Handle RPC outages, pending/replaced/reverted transactions and chain reorganizations. Add gas/spend ceilings, funding alerts, structured logs and a supervisor/container configuration.
Separate permissionless maintenance from owner-only treasury/configuration actions; do not give the keeper unrestricted ownership. Test both game lifecycles on a local fork, including restart and delayed callbacks. Supply start/dry-run/stop/recovery commands. Hosting and real operating funds remain external prerequisites.
ADDRESS THE IMD GATE WITH AVAILABLE ACCESS
Launch 961 remains parked on the original code. Empty-chain constructor rejection and genuine-fork success are already documented in docs/REHEARSAL.md.
If the private runner is accessible, rerun against the latest source and correct chain/manifest. Capture resolved arguments, dependency order/code, chain/block and inner revert. Fix demonstrated application faults while preserving dependency checks.
If unavailable, retain the public reproduction and provide one concise support-request draft listing the necessary evidence. Do not repeatedly probe inaccessible endpoints or claim local tests cleared the private gate. Do not contact support on my behalf.
Keep the historical Sepolia manifest separate from mainnet preparation. A continuation must not silently deploy or retarget the old launch.
VERIFY AND HAND OFF THE CONTRACT VERSION
Run build/format checks, regression/invariant tests, relevant mainnet/Sepolia fork tests and new tooling tests. Record exact commands, source commit, toolchain, fork blocks and pass/fail/skip counts. Distinguish live oracle results from simulation.
Update ABIs, events/status mappings, configuration schemas and deployment/setup commands after fixes. Leave undeployed addresses null. Identify interface/policy decisions affecting future website integration.
Publish through IMD's supported artifact mechanism to the existing repo/PR. Respect worker git restrictions; distinguish those from the platform's final publication status.
Finish with a concise summary of code changes, actual test results, unresolved findings, private-gate status, live-VRF status and one external-action checklist naming who must supply each item. State whether interfaces are ready for website integration. Complete all unblocked implementation; do not stop at recommendations or claim public-launch readiness.