Skip to content

Classify delegated spends and let a donor take part of a note back - #198

Merged
AdamSpitz merged 5 commits into
devfrom
feature/spend-classification
Sep 27, 2026
Merged

AdamSpitz merged 5 commits into
devfrom
feature/spend-classification

Conversation

@AdamSpitz

Copy link
Copy Markdown
Owner

Summary

  • A delegated spend against a fine-listed beneficiary is unsuspicious only while that beneficiary's payout registry still reports the current controller. Fixed-controller factories are pinned to the registry they were deployed with, so a delegate cannot point a market at a forged registry.
  • Donors set a standing delay, a shorter unsuspicious delay, strict mode, and flaggers. Pending spends keep the standing delay from when they were scheduled. The note and project screens show the live deadline, the class, and whether the spend can still be cancelled. Approve, cancel, and policy edits wait for a successful receipt.
  • The root can take part of a delegated note back without ending the rest of the delegation. A second delegation hop still reverts. The indexer watches fixed-controller markets created by the new factory.

Recurring-pledge fine-list and unsuspicious-delay controls, and donor notification delivery, stay on the to-do list. The contract already stores the pledge policy; the product controls still edit individual notes.

Validation

  • automated.test-full-integration: 106 passing, 1 pending (run 2026-09-27T00-36-42.212Z-b5d019cb), after the one-hop revoke test was updated to match DelegationHopLimit.
  • Pre-commit: docs links, lint, build, and automated.test-fast passed.
  • DelegatableNotes deployed bytecode is 23,931 bytes (EIP-170 limit 24,576).
  • Touched UI unit tests: 57 passing. No browser pass on the pending-spend screens.

Local indexer Compose now sets CHOKIDAR_USEPOLLING=true. This host's inotify instance cap is 128, and Ponder's file watcher otherwise dies with EMFILE before the integration suite can start. That matches the Render indexer workaround.

… beneficiary.

A donor names beneficiary ids and a shorter unsuspicious delay. Only a market whose payout registry reports that id as the current controller uses that shorter wait; every other spend keeps the standing delay. ADR 0017 records the decision, and recurring pledges copy the fine list onto each new note.
Note and project screens treat a scheduled spend as cancellable money, not raised funds. Donors can set the delay, strict mode, and flaggers, and a banner points at suspicious spends that are still pending.
…egation.

The slice is a new root-only note. The original note stays delegated, a pending spend blocks the call, and the notes pages expose the control.
…review gaps.

The factory only accepts its deployed payout registry. Pending deadlines keep the standing delay from schedule time, the indexer watches the new factory, and the one-hop revoke integration test matches the hop limit.

@AdamSpitz AdamSpitz left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review receipt.

Reviewed the branch against origin/dev, including the uncommitted review fixes now in 2a1f353. Fixed registry pinning, pending-deadline snapshots, indexer factory discovery, receipt waits, currency formatting, and the stale two-hop revoke integration test. No open findings. Deferred pledge fine-list UI and donor notification delivery, already on TODO.md. Integration 106 passing; no browser pass.

Reviewed-with: grok
Reviewed-files: 70
Reviewed-commit: 2a1f353

@AdamSpitz
AdamSpitz merged commit 3ddf175 into dev Sep 27, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant