Repository navigation
Conversation
…acts - Select the contract type with Compose<(...)> and document the valid combinations for fungible and non-fungible tokens - Document minting through Self::ContractType (fungible mint, NFT mint, mint_with_id and mint_range) instead of calling Base primitives - Add the opt-in Total Supply extension and rework Capped as a contract type exposing FungibleCapped - Route NFT royalty setters through the contract type - Fix the consecutive source link
…ellar-contracts - Votes: select FungibleVotes through Compose and note that minting must go through the contract type. - Access Control: mint through ContractType::mint_with_id and make both examples complete contracts. - RWA: use Compose<(RWA, TotalSupply)> with FungibleTotalSupply, implement Pausable and the required RWAToken functions, mint through the contract type, drop the operator argument from the RWA helpers, describe the snapshot-based compliance hooks (no more can_transfer/can_create), and fix the moved identity verification source links. - Vault: use Compose<(Vault, TotalSupply)> with FungibleTotalSupply, rely on the default FungibleVault functions (which already require operator auth), and mention the capped variant.
…racts - RWA: describe forced transfers accurately (only `to` is verified, pause and freezing are bypassed), document custodial (muxed) destinations and how to refuse them, batch operations and their sizing, per-token recovery including frozen zero-balance accounts, burn behaviour with frozen and locked tokens, and the identity registry removal and tombstoning rules. List the ready-made compliance modules with the hooks they need and their preset phase, replace the non-existent investor count module in the diagram, fix the verify_identity signature and the token binder capacity (100 tokens in a single entry). - Vault: deposits that would mint zero shares now revert with VaultZeroShares and redemptions that would return zero assets with VaultZeroAssets; rewrite the inflation attack section after the upstream analysis, which no longer claims the offset makes the attack infeasible. - SAC Admin Generic: import CustomAccountInterface from soroban_sdk::auth, add the missing stellar_tokens import and the ensure_minting_limit helper. - Overview: fix the Vault description copied from the fungible token.
…h latest stellar-contracts - Timelock Controller: add the missing auth_contexts/context_meta length check to the __check_auth example (without it, anyone could authorize arbitrary calls as the timelock), and rewrite the example around the Timelock trait and TimelockClient. - Governor: implement Governor with #[contractimpl(contracttrait)] so the default methods are exported, add a constructor, document the non-zero voting period (InvalidVotingPeriod), the derived vs stored states and that the governor does not enforce the queue eta. - Ownable: implement the Ownable trait in the examples, remove the duplicate owner auth in finalize_and_lock, fix the missing BytesN import and replace the deprecated update_current_contract_wasm. - Pausable and Upgradeable: complete the examples (imports, access control on migrate, owner-gated Upgrader) and link the upstream examples. Use #[...] headings for the macros, also in Access Control. - WAD: rename pow to powi, document ln, exp and powf, the operator overflow bounds and InvalidBase, and use the checked methods in the examples, which panicked on realistic inputs. - Add a Fixed-Point Math page for the i128/I256 mul_div functions, Rounding and phantom overflow handling. - Crypto and Merkle Distributor: fix the crate path, the broken source link and the non-compiling leaf clone, set the root in the constructor, and document Grumpkin, verify_with_index, verify_with_index_and_set_claimed, errors and events. - Fee Abstraction: fix collect_fee_and_invoke, describe the current Eager (pull max, pay fee, refund) and Lazy (inline approval) flows and the balance-conserving token requirement, the allowlist behaviour, and point the relayer links to 1.5.x. - Overview: list the WAD, Fixed-Point Math and Merkle Distributor pages.
- List the governance blocks (Timelock 40XX, Votes 41XX, Governor 42XX), now that GovernorError moved from 5000-5023 to 4200-4223 (#928). - Drop Upgradeable 11XX: the Upgradeable module has no error enum. - Mention the reserved 39XX block and that codes below 100 are left to contract-specific errors.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adapts the Stellar docs to the changes on
stellar-contractsmain(checked atd075db5), mainly #821, #795, #879, #881, #885, #911 and #913 (plus #748 for the RWA compliance hooks and #928 for the error codes).Stacked on #244. Retarget to
mainonce that PR is merged.Commits:
Breaking changes covered
Both token modules
ContractTypeis now selected uniformly withCompose<(...)>, e.g.Compose<(Base,)>orCompose<(AllowList, TotalSupply)>. Combinations are only reachable through it. The docs list the valid combinations, which are checked at compile time.<Self as XToken>::ContractType::mint*, instead ofBase::mint/Enumerable::.../Consecutive::.... A callout explains why calling a primitive directly is unsafe.Fungible
total_supplyis no longer part ofFungibleToken. It is now the opt-inTotalSupplycontract type plus theFungibleTotalSupplytrait (new section).Compose<(Capped, TotalSupply)>) with aFungibleCappedtrait exposingcap(). It used to be helper functions only.TotalSupply/Capped.Non-Fungible
sequential_mint(to)→mint(to), the oldmint(to, id)→mint_with_id(to, id), andbatch_mint→mint_range. A table shows which contract types support each one.sequential_burnis removed. The Enumerable and Consecutive examples now useNonFungibleBurnable.Self::ContractType::set_token_royalty/remove_token_royalty, which makes them work withConsecutive. Added an example.NonFungibleVotescan be combined withEnumerableorConsecutive.non-fungible→non_fungible).Votes (
governance/votes.mdx)Compose<(FungibleVotes,)>and notes that minting must go through the contract type for voting units to be tracked. The bareFungibleVotesstill compiled, so this aligns the page with the documented form rather than fixing a compile error.Access Control (
access/access-control.mdx)Base::mint(e, &to, token_id)no longer exists with that signature. The example now usesContractType::mint_with_idwithCompose<(Base,)>.NonFungibleTokenimpl, and the role-hierarchy example importedAccessControlwithout implementing it.RWA (
tokens/rwa/rwa.mdx)RWATokennow requiresFungibleTotalSupply. The example usesCompose<(RWA, TotalSupply)>, implementsFungibleTotalSupply, and mints through the contract type. It also mentionsCompose<(RWA, Capped, TotalSupply)>.can_transfer/can_createare gone (#748).transferred/created/destroyednow run after the operation, reject by panicking, and receiveAccountSnapshots plus aTransferKind. I updated the interface list, the hook descriptions, theComplianceModuletrait, both diagrams and the security callout.Pausableor the 15RWATokenfunctions that have no default body. It now does, with#[only_role(operator, "manager")].RWA::*helper snippets passed anoperatorargument these helpers don't take.is_verified; it's nowverify_identity.rwa/identity_verification/. Also replaced 2 stale#Lline anchors with plain file links.Vault (
tokens/vault/vault.mdx)FungibleVaultnow requiresFungibleTotalSupply. The example usesCompose<(Vault, TotalSupply)>and implementsFungibleTotalSupply. It also mentionsCompose<(Vault, Capped, TotalSupply)>.deposit/withdrawoverrides calledoperator.require_auth()beforeVault::deposit/Vault::withdraw, which already require it. The example now uses the defaultFungibleVaultfunctions. The custom-authorization snippet drops the duplicate auth and goes throughSelf::ContractType::deposit, so a capped vault still checks the cap.Error codes (
index.mdx)GovernorErrorfrom 5000–5023 (which collided with Fee Abstraction) to 4200–4223, andComplianceModuleErrorfrom 401–407 (which collided with Vault) to 383–389. No page cites any of those codes, and the overview already placed Governance in4XXX, so the code now matches the docs.40XX, Votes41XX, Governor42XX). It drops Upgradeable11XX, since the Upgradeable module has no error enum (removed in #585). It also mentions the reserved39XXblock and that codes below100are left to contract-specific errors.mainatd075db5.Verification
stellar-contractsworkspace (onmainatd075db5) and passedcargo checkwith no errors or warnings. The partial snippets were checked as combined contracts: the Total Supply section, the Votes callout and the vault custom-authorization override. Synthetic capped RWA and capped vault variants were checked the same way.main.