Repository navigation
feat: Add rollups cli withdraw / refund / foreclose - #545
Conversation
🦋 Changeset detectedLatest commit: 3cc85bd The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Coverage Report
📁 File Coverage (20 files)
|
|
First of all I appreciate the effort to bring the EW features to the Cartesi CLI, because IMHO the EW feature is very complex for the application developers to implement (and for the operator to operate, which is not a concern here). I posted a proposal some time ago on #516 for how emergency withdrawal should work in the Cartesi CLI, focused on the application developer: #516 (comment) In short:
I think it also affects the scope of this PR. I thought the rollups-node team was still planning to make changes to the EW feature, by adding an API for it, and potentially a simplification. And I don't think we have an urge right now for these commands. Providing a good developer experience is IMO more important than having the commands. In any case, about the implementation I was expecting that the There are also some design issues that I was trying to avoid, like for example using the node JSON-RPC from the host, mixing that with node CLI calls in the container. So my current suggestions are:
Please let me know if there are other motivations that I'm not aware of to add this now. |
Thanks @tuler, I've being following the issue and read the proposal. In a few places the PR is being read as doing more than it does, so here's a clarification point by point. These are already thin wrappers around the node's tools. The CLI doesn't replay or generate proofs itself. Every step runs the sequencing is the DX. I agree that a good developer experience matters more than having the commands, and here the automation of the sequencing is that experience. With alpha.13, which the CLI ships today, #516 is orthogonal to this PR. The commands read the withdrawal config from the deployed application, not from Foreclose signer. The default path is the devnet one: it signs with the node signer and finds the guardian's index in the node's mnemonic, so a devnet guardian needs no setup. A guardian outside the node signer is a real development case too. I don't use the devnet accounts myself, but my own dev accounts that I fund during development. Keeping the guardian separate from the node signer also tests the roles as they are in production, which is the point of your open question 4 on #516. Setting Node JSON-RPC from the host. I agree, done in 3cc85bd. The three reads (application, input, epoch) now go through cartesi-rollups-cli app list and read inside the container, which keeps the versions matched and drops @cartesi/client. The only reads left on the host are chain reads through anvil, the same way send and deposit work. Passthrough plus a docs recipe. A |
Summary
Adds
cartesi foreclose,cartesi refundandcartesi withdrawto recover funds from a foreclosed application in the local environment. They run rollups-node'scartesi-rollups-cliandcartesi-rollups-machine-toolinside therollups_nodecontainer, so no new images are needed.How it works
The replay is the slow step. It's cached in the node container's
/tmp, and the drive root is proven only once, so every withdrawal after the first one is just a proof and one transaction.Warning
The replay re-runs every accepted input of the application, so a long-running application with many inputs takes longer to replay. The cached snapshot is about the size of the machine RAM and lives in the node container's
/tmp, so it's limited by the container's memory and disk (seecartesi run --memory). It's lost when the environment is recreated, and the next withdrawal replays again.Features
cartesi foreclosesigns as the guardian of[withdrawal.config]. A guardian outside the node's signer is set for that one command withCARTESI_AUTH_MNEMONICorCARTESI_AUTH_PRIVATE_KEY, andCARTESI_AUTH_KINDwhen both are set. The values are forwarded by name, never in argv. A private key's address is checked against the guardian before anything is sent.cartesi refund <input-index>refunds a deposit that wasn't finalized before the foreclosure.cartesi withdrawwithdraws an account's finalized balance with--account, or with a proof generated elsewhere with--proof-file.--application,--project-name,--account-index,--yes,--json,--no-waitand--wait-timeout. The application is resolved from the running environment when--applicationisn't given.Refactoring
exec/rollups.tsis split intoexec/node-container.tsandexec/cartesi-rollups-machine-tool.ts. The existing node calls (getDeployments,deployAuthority,deployApplication,removeApplication,getAnvilNodeInfo) now go through the sameexecNodeCommandhelper, with no behavior change.cartesi-rollups-cli app listandreadinside the container, so the CLI never queries the node's JSON-RPC from the host and adds no new dependency.base.ts.DEVNET_MNEMONICis exported fromcompose/node.ts, andfindMnemonicAccountIndexis added towallet.ts.CI and tooling
cliworkflow sets up Node 24 (actions/setup-nodev7.0.0), because the integration tests run the CLI withnode.2.0.0-alpha.4.turbo.jsonsetsagentGuidance: false, which stops turbo from writingAGENTS.md.Verification
Full suite against the released
0.12.0-alpha.44images, on Node 24: 325 pass / 1 skip / 0 fail. 90 of the tests are new, and the skip is pre-existing.tscandbiome ciare clean.recovery.test.tsruns the whole flow on the devnet with an ERC-20 withdrawal application:--input-file.--proof-file.0before and as the full amount after.