Skip to content

Introduce the Sovryn Perimeter Fee on Zero - #10

Open
tjcloa wants to merge 1 commit into
developmentfrom
sovryn-perimeter-fee
Open

Introduce the Sovryn Perimeter Fee on Zero#10
tjcloa wants to merge 1 commit into
developmentfrom
sovryn-perimeter-fee

Conversation

@tjcloa

@tjcloa tjcloa commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Phase 1 of the Sovryn security perimeter (SIP-0094): a minimal exit fee on
user-initiated withdrawal surfaces, funding continuous exit monitoring.
This change carries the Zero half of the system:

  • exit-fee hooks in BorrowerOperations on collateral withdrawal and trove
    closure, quoting through the shared ExitFeeController (Sovryn-perimeter
    repo) and paying the fee leg to the ExitFeeVault; every hook fails open —
    a fee fault forgoes the fee, never blocks a withdrawal;
  • the surplus-claim surface: CollSurplusPool.claimCollWithFee, a BO-only
    two-leg split that keeps claimColl byte-untouched, with the pool
    implementation upgrade ordered strictly before the BO upgrade inside
    SIP-0094 executable part 1;
  • impl-only deploy scripts for both contracts (the proxy swaps are
    governance actions), storage-layout zero-diff guards, and the ColFee
    test suite incl. reentrancy/fail-open matrices and Echidna invariants.

The fee system deploys disabled and enables only by governance after
post-deployment verification.

Phase 1 of the Sovryn security perimeter (SIP-0094): a minimal exit fee on
user-initiated withdrawal surfaces, funding continuous exit monitoring.
This change carries the Zero half of the system:

- exit-fee hooks in BorrowerOperations on collateral withdrawal and trove
  closure, quoting through the shared ExitFeeController (Sovryn-perimeter
  repo) and paying the fee leg to the ExitFeeVault; every hook fails open —
  a fee fault forgoes the fee, never blocks a withdrawal;
- the surplus-claim surface: CollSurplusPool.claimCollWithFee, a BO-only
  two-leg split that keeps claimColl byte-untouched, with the pool
  implementation upgrade ordered strictly before the BO upgrade inside
  SIP-0094 executable part 1;
- impl-only deploy scripts for both contracts (the proxy swaps are
  governance actions), storage-layout zero-diff guards, and the ColFee
  test suite incl. reentrancy/fail-open matrices and Echidna invariants.

The fee system deploys disabled and enables only by governance after
post-deployment verification.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant