Overview
ETH Balance
0 ETH
ETH Value
$0.00More Info
Private Name Tags
Transaction Hash |
Method
|
Block
|
From
|
To
|
|||||
---|---|---|---|---|---|---|---|---|---|
Latest 1 internal transaction
Parent Transaction Hash | Block | From | To | |||
---|---|---|---|---|---|---|
5886777 | 11 days ago | Contract Creation | 0 ETH |
Loading...
Loading
This contract may be a proxy contract. Click on More Options and select Is this a proxy? to confirm and enable the "Read as Proxy" & "Write as Proxy" tabs.
Contract Source Code Verified (Exact Match)
Contract Name:
ZKSyncLST
Compiler Version
v0.8.25+commit.b61c2a91
ZkSolc Version
v1.5.12
Optimization Enabled:
Yes with Mode 3
Other Settings:
paris EvmVersion
Contract Source Code (Solidity Standard Json-Input format)
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; import {LiquidStakingTokenCompose} from "./LiquidStakingTokenCompose.sol"; import {IL2BaseToken} from "./interfaces/IL2BaseToken.sol"; import {IL1Receiver} from "./vendor/layerzero/syncpools/interfaces/IL1Receiver.sol"; /** * @title ZKSyncLST * @notice An implementation of the LiquidStakingToken contract on ZkSync Era that sends slow sync messages to the L2 system. * @dev This contract facilitates interactions between mainnet PirexEth contracts and the ZKSync. * @author Dinero Protocol */ contract ZKSyncLST is LiquidStakingTokenCompose { /** * @notice Contract constructor to initialize LiquidStakingTokenVault with necessary parameters and configurations. * @dev This constructor sets up the LiquidStakingTokenVault contract, configuring key parameters and initializing state variables. * @param _endpoint address The address of the LOCAL LayerZero endpoint. * @param _srcEid uint32 The source endpoint ID. */ /// @custom:oz-upgrades-unsafe-allow constructor constructor( address _endpoint, uint32 _srcEid ) LiquidStakingTokenCompose(_endpoint, _srcEid) {} /** * @dev Internal function to send a slow sync message * @param _value Amount of ETH to send * @param _data Data to send */ function _sendSlowSyncMessage( address, uint256 _value, uint256, bytes memory _data ) internal override { bytes memory message = abi.encodeCall( IL1Receiver.onMessageReceived, _data ); IL2BaseToken(getMessenger()).withdrawWithMessage{value: _value}( getReceiver(), message ); } }
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; import {LiquidStakingToken} from "./LiquidStakingToken.sol"; import {Origin} from "./vendor/layerzero-upgradeable/oapp/interfaces/IOAppReceiver.sol"; import {OFTComposeMsgCodec} from "./vendor/layerzero/oft/libs/OFTComposeMsgCodec.sol"; import {MsgCodec} from "./libraries/MsgCodec.sol"; /** * @title LiquidStakingTokenCompose * @notice An DineroERC20Rebase OApp contract for handling LST operations between L2 and mainnet. * @dev This contract facilitates interactions between mainnet PirexEth contracts and the L2 system. * @author redactedcartel.finance */ abstract contract LiquidStakingTokenCompose is LiquidStakingToken { /** * @dev Library: MsgCodec - Provides encoding and decoding of messages. */ using MsgCodec for bytes; /** * @notice Contract constructor to initialize LiquidStakingToken with necessary parameters and configurations. * @dev This constructor sets up the LiquidStakingToken contract, configuring key parameters and initializing state variables. * @param _endpoint address The address of the LOCAL LayerZero endpoint. * @param _srcEid uint32 The source endpoint ID. */ /// @custom:oz-upgrades-unsafe-allow constructor constructor( address _endpoint, uint32 _srcEid ) LiquidStakingToken(_endpoint, _srcEid) {} /** * @notice Handler for processing layerzero messages from L2. * @dev Only accept and handle the deposit and rebase messages from mainnet, which mints and stakes LiquidStakingToken. * @dev _origin Origin The origin information containing the source endpoint and sender address. * @dev _guid bytes32 The unique identifier for the received LayerZero message. * @param _message bytes The payload of the received message. * @dev address The address of the executor for the received message. * @dev bytes Additional arbitrary data provided by the corresponding executor. */ function _lzReceive( Origin calldata _origin, bytes32 _guid, bytes calldata _message, address, bytes calldata ) internal virtual override nonReentrant { _acceptNonce(_origin.srcEid, _origin.sender, _origin.nonce); uint256 amountReceived = _handleMessageReceived(_guid, _message); (bool isComposed, ) = _message.isComposed(); if (isComposed) { _sendCompose( _origin.srcEid, _origin.nonce, _guid, amountReceived, _message ); } } /** * @dev Decode the received message. * @param _message bytes The message to decode. * @return messageType uint256 The message type. * @return amount uint256 The amount. * @return assetsPerShare uint256 The assets per share. * @return receiver address The receiver address. * @return syncedIds bytes32[] The synced IDs. */ function _decodeReceivedMessage( bytes calldata _message ) internal pure override returns ( uint256 messageType, uint256 amount, uint256 assetsPerShare, address receiver, bytes32[] memory syncedIds ) { return _message.decodeL1Msg(); } /** * @dev Send compose message to the destination endpoint. * @param _srcEid endpoint ID of the source. * @param _nonce nonce of the message. * @param _guid GUID of the message. * @param _amountReceived amount received. * @param _message message to compose. */ function _sendCompose( uint32 _srcEid, uint64 _nonce, bytes32 _guid, uint256 _amountReceived, bytes calldata _message ) internal virtual { // @dev composeMsg format for the OFT. bytes memory composeMsg = OFTComposeMsgCodec.encode( _nonce, _srcEid, _amountReceived, abi.encodePacked( OFTComposeMsgCodec.addressToBytes32(address(this)), _message.composeMsg() ) ); endpoint.sendCompose( _message.composeTo(), _guid, 0 /* the index of the composed message*/, composeMsg ); } }
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; interface IL2BaseToken { function withdrawWithMessage( address _l1Receiver, bytes calldata _additionalData ) external payable; }
// SPDX-License-Identifier: LZBL-1.2 pragma solidity ^0.8.20; interface IL1Receiver { function onMessageReceived(bytes calldata message) external payable; }
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; import {DineroERC20RebaseUpgradeable} from "./DineroERC20RebaseUpgradeable.sol"; import {ReentrancyGuardUpgradeable} from "@openzeppelin/contracts-upgradeable/utils/ReentrancyGuardUpgradeable.sol"; import {PausableUpgradeable} from "@openzeppelin/contracts-upgradeable/utils/PausableUpgradeable.sol"; import {OAppUpgradeable} from "contracts/vendor/layerzero-upgradeable/oapp/OAppUpgradeable.sol"; import {MessagingFee, MessagingReceipt} from "contracts/vendor/layerzero-upgradeable/oapp/OAppSenderUpgradeable.sol"; import {OAppOptionsType3Upgradeable} from "contracts/vendor/layerzero-upgradeable/oapp/libs/OAppOptionsType3Upgradeable.sol"; import {Origin} from "contracts/vendor/layerzero-upgradeable/oapp/interfaces/IOAppReceiver.sol"; import {FixedPointMathLib} from "solmate/src/utils/FixedPointMathLib.sol"; import {Constants} from "./libraries/Constants.sol"; import {Errors} from "./libraries/Errors.sol"; import {L2SyncPool} from "./L2SyncPool.sol"; import {BaseMessengerUpgradeable} from "contracts/vendor/layerzero/syncpools/utils/BaseMessengerUpgradeable.sol"; import {BaseReceiverUpgradeable} from "contracts/vendor/layerzero/syncpools/utils/BaseReceiverUpgradeable.sol"; import {IRateProvider} from "./interfaces/IRateProvider.sol"; import {IRateLimiter} from "contracts/vendor/layerzero/syncpools/interfaces/IRateLimiter.sol"; import {IWrappedLiquidStakedToken} from "./interfaces/IWrappedLiquidStakedToken.sol"; /** * @title LiquidStakingToken * @notice An DineroERC20Rebase OApp contract for handling LST operations between L2 and mainnet. * @dev This contract facilitates interactions between mainnet PirexEth contracts and the L2 system. * @author redactedcartel.finance */ abstract contract LiquidStakingToken is DineroERC20RebaseUpgradeable, L2SyncPool, BaseMessengerUpgradeable, BaseReceiverUpgradeable, OAppUpgradeable, OAppOptionsType3Upgradeable, ReentrancyGuardUpgradeable, PausableUpgradeable { /** * @dev Library: FixedPointMathLib - Provides fixed-point arithmetic for uint256. */ using FixedPointMathLib for uint256; /** * @notice The endpoint ID for L1. * @dev This constant defines the source endpoint ID for the L1. */ uint32 internal immutable L1_EID; /// @custom:storage-location erc7201:redacted.storage.LiquidStakingToken struct L2TokenStorage { /** * @notice Total assets actively staked in the vault. * @dev This variable holds the total assets actively staked, follows totalAssets in the mainnet lockbox. */ uint256 totalStaked; /** * @notice The last assets per share value. * @dev This variable holds the last assets per share value received form deposit or rebase. */ uint256 lastAssetsPerShare; /** * @notice The unsynced pending deposit amount. * @dev This variable holds the pending deposit amount that has not been synced and is not staked in the mainnet vault and will not be rebased. */ uint256 unsyncedPendingDeposit; /** * @notice The synced pending deposit amount. * @dev This variable holds the pending deposit amount that has been synced and is not staked in the mainnet vault and will not be rebased. */ uint256 syncedPendingDeposit; /** * @notice The total unsynced shares. * @dev This variable holds the total unsynced shares. */ uint256 unsyncedShares; /** * @notice The rebase fee that is charged on each rebase. * @dev This variable holds the rebase fee that is charged on each rebase. */ uint256 rebaseFee; /** * @notice The sync deposit fee that is charged on each sync pool L2 deposit. * @dev This variable holds the sync deposit fee that is charged on each sync pool L2 deposit. */ uint256 syncDepositFee; /** * @notice The treasury address that receives the treasury fee. * @dev This variable holds the address of the treasury, which receives the treasury fee when a rebase occurs. */ address treasury; /** * @notice Last pending sync index. * @dev This variable holds the last pending sync index. */ uint256 lastPendingSyncIndex; /** * @notice Last completed sync index. * @dev This variable holds the last completed sync index. */ uint256 lastCompletedSyncIndex; /** * @notice Sync index to pending amount mapping. * @dev This mapping holds the sync index to pending amount mapping. */ mapping(uint256 => uint256) syncIndexPendingAmount; /** * @notice Sync ID to index mapping. * @dev This mapping holds the sync ID to index mapping. */ mapping(bytes32 => uint256) syncIdIndex; /** * @notice The nonce for the received messages. * @dev Mapping to track the maximum received nonce for each source endpoint and sender */ mapping(uint32 eid => mapping(bytes32 sender => uint64 nonce)) receivedNonce; /** * @notice Mapping to track the accounts that can pause the contract. * @dev This mapping holds the accounts that can pause the contract. */ mapping(address => bool) canPause; /** * @dev The address of the Wrapped Liquid Staked Token contract. * @dev This variable holds the address of the Wrapped Liquid Staked Token contract. */ address wLST; } // keccak256(abi.encode(uint256(keccak256(redacted.storage.LiquidStakingToken)) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant LiquidStakingTokenStorageLocation = 0xdd932cf12f0dd29482349e8f041f211cd1a01e556f17b4835472bd462fb09100; function _getLiquidStakingTokenStorage() internal pure returns (L2TokenStorage storage $) { assembly { $.slot := LiquidStakingTokenStorageLocation } } // Events /** * @notice Emitted on sending withdrawal message. * @param guid bytes32 GUID of the OFT message. * @param fromAddress address Address of the sender on the src chain. * @param toAddress address Address of the recipient on the src chain. * @param amount uint256 Withdrawal amount (in LiquidStakingToken). */ event Withdrawal( bytes32 indexed guid, address indexed fromAddress, address indexed toAddress, uint256 amount ); /** * @notice Emitted on receiving the deposit message. * @param guid bytes32 GUID of the OFT message. * @param toAddress address Address of the recipient on L2. * @param shares uint256 Deposit amount (in shares). * @param amount uint256 Deposit amount (in LiquidStakingToken). */ event Deposit( bytes32 indexed guid, address indexed toAddress, uint256 shares, uint256 amount ); /** * @notice Emitted on minting tokens from SyncPool. * @param toAddress address Address of the recipient on L2. * @param shares uint256 Deposit amount (in shares). * @param amount uint256 Deposit amount (in LiquidStakingToken). */ event Mint(address indexed toAddress, uint256 shares, uint256 amount); /** * @notice Emitted on receiving rebase message. * @param guid bytes32 GUID of the OFT message. * @param treasury address Address of the treasury. * @param assetsPerShare uint256 The current assets per share. * @param amount uint256 Deposit amount (in LiquidStakingToken). * @param fee uint256 Fee amount (in LiquidStakingToken). * @param feeShares uint256 Fee amount (in shares). */ event Rebase( bytes32 indexed guid, address indexed treasury, uint256 assetsPerShare, uint256 amount, uint256 fee, uint256 feeShares ); /** * @notice Emitted when the pause is set. * @param account address The account that can pause the contract. * @param allowed bool The allowed status. */ event canPauseSet(address indexed account, bool allowed); /** * @notice Contract constructor to initialize LiquidStakingTokenVault with necessary parameters and configurations. * @dev This constructor sets up the LiquidStakingTokenVault contract, configuring key parameters and initializing state variables. * @param _endpoint address The address of the LOCAL LayerZero endpoint. * @param _srcEid uint32 The source endpoint ID. */ /// @custom:oz-upgrades-unsafe-allow constructor constructor(address _endpoint, uint32 _srcEid) OAppUpgradeable(_endpoint) { L1_EID = _srcEid; _disableInitializers(); } /** * @dev modifier to allow only the owner or the canPause address to pause the contract */ modifier onlyCanPause() { if (!_canPause(_msgSender())) revert Errors.NotAllowed(); _; } /** * @notice Initialize the LiquidStakingToken contract. * @param _delegate address The delegate capable of making OApp configurations inside of the endpoint. * @param _owner address The owner of the contract. * @param _treasury address The treasury address. * @param _l2ExchangeRateProvider Address of the exchange rate provider * @param _rateLimiter address The rate limiter address. * @param _messenger Address of the messenger contract (most of the time, the L2 native bridge address) * @param _receiver Address of the receiver contract (most of the time, the L1 receiver contract) * @param _bridgeQuoter Address of the bridge quoter contract * @param _name string The name of the token. * @param _symbol string The symbol of the token. */ function initialize( address _delegate, address _owner, address _treasury, address _l2ExchangeRateProvider, address _rateLimiter, address _messenger, address _receiver, address _bridgeQuoter, string memory _name, string memory _symbol ) external initializer { __LiquidStakingToken_init(_delegate, _owner, _treasury, _name, _symbol); __L2BaseSyncPool_init( _l2ExchangeRateProvider, _rateLimiter, _bridgeQuoter ); __BaseMessenger_init(_messenger); __BaseReceiver_init(_receiver); } function __LiquidStakingToken_init( address _delegate, address _owner, address _treasury, string memory _name, string memory _symbol ) internal onlyInitializing { __ReentrancyGuard_init(); __Pausable_init(); __Ownable_init(_owner); __OAppCore_init(_delegate); __DineroERC20Rebase_init(_name, _symbol); _setTreasury(_treasury); } /** * @notice Handler for processing layerzero messages from L2. * @dev Only accept and handle the deposit and rebase messages from mainnet, which mints and stakes LiquidStakingToken. * @dev _origin Origin The origin information containing the source endpoint and sender address. * @dev _guid bytes32 The unique identifier for the received LayerZero message. * @param _message bytes The payload of the received message. * @dev address The address of the executor for the received message. * @dev bytes Additional arbitrary data provided by the corresponding executor. */ function _lzReceive( Origin calldata _origin, bytes32 _guid, bytes calldata _message, address, bytes calldata ) internal virtual override nonReentrant { _acceptNonce(_origin.srcEid, _origin.sender, _origin.nonce); _handleMessageReceived(_guid, _message); } /** * @notice Handler for processing layerzero messages. * @dev Only accept and handle the deposit and rebase messages from mainnet, which mints and stakes LiquidStakingToken. * @dev _guid bytes32 The unique identifier for the received LayerZero message. * @param _message bytes The payload of the received message. * @dev address The address of the executor for the received message. * @dev bytes Additional arbitrary data provided by the corresponding executor. */ function _handleMessageReceived( bytes32 _guid, bytes calldata _message ) internal virtual returns (uint256 amountReceived) { ( uint256 _messageType, uint256 _amount, uint256 _assetsPerShare, address _receiver, bytes32[] memory _syncedIds ) = _decodeReceivedMessage(_message); L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); if ( _messageType == Constants.MESSAGE_TYPE_DEPOSIT || _messageType == Constants.MESSAGE_TYPE_DEPOSIT_WRAP ) { _updateTotalStaked(_assetsPerShare); uint256 shares = getTotalShares() == 0 ? _amount : convertToShares(_amount); if (_messageType == Constants.MESSAGE_TYPE_DEPOSIT_WRAP) { _mintShares(address(this), shares); $.totalStaked += _amount; uint256 amount = convertToAssets(shares, true); _approve(address(this), $.wLST, amount, false); uint256 wAmount = IWrappedLiquidStakedToken($.wLST).wrap( amount ); IWrappedLiquidStakedToken($.wLST).transfer(_receiver, wAmount); } else { _mintShares(_receiver, shares); $.totalStaked += _amount; } IRateLimiter(getRateLimiter()).updateRateLimit( address(this), address(this), shares, 0 ); emit Deposit(_guid, _receiver, shares, _amount); } else if (_messageType == Constants.MESSAGE_TYPE_REBASE) { _updateTotalStaked(_assetsPerShare); uint256 fee = _amount.mulDivDown( $.rebaseFee, Constants.FEE_DENOMINATOR ); uint256 shares; if (fee > 0 && _totalAssets() > fee) { shares = fee.mulDivDown(getTotalShares(), _totalAssets() - fee); _mintShares($.treasury, shares); IRateLimiter(getRateLimiter()).updateRateLimit( address(this), address(this), shares, 0 ); } else { fee = 0; } emit Rebase( _guid, $.treasury, _assetsPerShare, _amount, fee, shares ); } else { revert Errors.NotAllowed(); } if (_syncedIds.length > 0) { uint256 staked = _updateSyncQueue(_syncedIds); if (staked > 0) { $.totalStaked += staked; $.syncedPendingDeposit -= staked; } } return _amount; } /** * @dev Decode the received message. * @param _message bytes The message to decode. * @return messageType uint256 The message type. * @return amount uint256 The amount. * @return assetsPerShare uint256 The assets per share. * @return receiver address The receiver address. * @return syncedIds bytes32[] The synced IDs. */ function _decodeReceivedMessage( bytes calldata _message ) internal pure virtual returns ( uint256 messageType, uint256 amount, uint256 assetsPerShare, address receiver, bytes32[] memory syncedIds ) { return abi.decode( _message, (uint256, uint256, uint256, address, bytes32[]) ); } /** * @notice Mint LiquidStakingToken tokens to the recipient. * @dev Only the Sync Pool contract can mint LiquidStakingToken tokens. * @param _to address The recipient of the minted tokens. * @param _assetsPerShare uint256 The assets per share value. * @param _amount uint256 The amount of assets to mint. */ function _mint( address _to, uint256 _assetsPerShare, uint256 _amount ) internal { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); if ($.lastAssetsPerShare < _assetsPerShare) _updateTotalStaked(_assetsPerShare); uint256 _totalShares = getTotalShares(); uint256 shares = _totalShares == 0 ? _amount : convertToShares(_amount); uint256 depositFee = $.syncDepositFee; if (depositFee > 0) { uint256 feeShares = shares.mulDivDown( depositFee, Constants.FEE_DENOMINATOR ); _mintShares($.treasury, feeShares); $.unsyncedShares += feeShares; shares -= feeShares; } _mintShares(_to, shares); $.unsyncedShares += shares; $.unsyncedPendingDeposit += _amount; emit Mint(_to, shares, _amount); } /** * @dev Add msg id to sync queue. * @param _msgReceipt bytes32 The unique identifier for the message. * @param _amount uint256 Sync amount */ function _addToSyncQueue( MessagingReceipt memory _msgReceipt, uint256 _amount ) internal { // add to sync queue L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); $.lastPendingSyncIndex += 1; uint256 id = $.lastPendingSyncIndex; $.syncIdIndex[_msgReceipt.guid] = id; $.syncIndexPendingAmount[id] = _amount; $.syncedPendingDeposit += _amount; $.unsyncedPendingDeposit -= _amount; } /** * @notice Perform withdraw and burn of LiquidStakingToken tokens relaying the withdrawal message to Mainnet. * @param _receiver address The recipient of the withdrawal on Mainnet. * @param _refundAddress The address to receive any excess funds sent to layer zero. * @param _amount uint256 Withdrawal amount (in assets). * @param _options bytes Additional options for the message. */ function withdraw( address _receiver, address _refundAddress, uint256 _amount, bytes calldata _options ) external payable virtual nonReentrant whenNotPaused { if (_receiver == address(0)) revert Errors.ZeroAddress(); // revert if the receiver is a smart contract on the source chain if (_receiver.code.length > 0) revert Errors.InvalidReceiver(); if (_amount == 0) revert Errors.ZeroAmount(); L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); uint256 shares = previewWithdraw(_amount); IRateLimiter(getRateLimiter()).updateRateLimit( address(this), address(this), 0, shares ); _burnShares(msg.sender, shares); bytes memory payload = abi.encode( Constants.MESSAGE_TYPE_WITHDRAW, _amount, _receiver ); bytes memory combinedOptions = combineOptions(L1_EID, 0, _options); uint256 synced = $.syncedPendingDeposit; if (synced > 0) { uint256 remaining = _withdrawPendingDeposit(_amount); if (remaining > 0) { $.totalStaked -= remaining; } } else { $.totalStaked -= _amount; } MessagingReceipt memory msgReceipt = _lzSend( L1_EID, payload, combinedOptions, MessagingFee(msg.value, 0), payable(_refundAddress) ); emit Withdrawal(msgReceipt.guid, msg.sender, _receiver, _amount); } /** * @notice Deposit tokens on Layer 2 * This will mint tokenOut on Layer 2 using the exchange rate for tokenIn to tokenOut. * The amount deposited and minted will be stored in the token data which can be synced to Layer 1. * Will revert if: * - The amountIn is zero * - The token is unauthorized (that is, the l1Address is address(0)) * - The amountOut is less than the minAmountOut * @param tokenIn Address of the token * @param amountIn Amount of tokens to deposit * @param minAmountOut Minimum amount of tokens to mint on Layer 2 * @param shouldWrap Whether to wrap the tokenIn before depositing * @return amountOut Amount of tokens minted on Layer 2 */ function deposit( address tokenIn, uint256 amountIn, uint256 minAmountOut, bool shouldWrap ) public payable virtual override nonReentrant whenNotPaused returns (uint256) { return super.deposit(tokenIn, amountIn, minAmountOut, shouldWrap); } /** * @notice Quote gas cost for withdrawal messages * @param _receiver address The recipient of the withdrawal on Mainnet. * @param _amount uint256 The withdrawal amount. * @param _options bytes Additional options for the message. */ function quoteWithdraw( address _receiver, uint256 _amount, bytes calldata _options ) external view virtual returns (MessagingFee memory msgFee) { bytes memory _payload = abi.encode( Constants.MESSAGE_TYPE_WITHDRAW, _amount, _receiver ); bytes memory _combinedOptions = combineOptions(L1_EID, 0, _options); return _quote(L1_EID, _payload, _combinedOptions, false); } /** * @dev Quote the messaging fee for a sync * @param _tokenIn address Address of the input token * @param _options bytes Additional options for the message. */ function quoteSync( address _tokenIn, bytes calldata _options ) external view virtual returns (MessagingFee memory msgFee) { Token storage token = _getL2SyncPoolStorage().tokens[_tokenIn]; bytes memory _payload = abi.encode( Constants.MESSAGE_TYPE_SYNC, _tokenIn, token.unsyncedAmountIn, token.unsyncedAmountOut ); bytes memory _combinedOptions = combineOptions(L1_EID, 0, _options); return _quote(L1_EID, _payload, _combinedOptions, false); } /** * @notice Internal function to set the canPause address. * @param _address the address to check if it can pause the contract. */ function _canPause(address _address) internal view returns (bool) { return _getLiquidStakingTokenStorage().canPause[_address] || _address == owner(); } /** * @notice Function to set the canPause address. * @param _address the address to check if it can pause the contract. */ function setCanPause(address _address, bool _allowed) external onlyOwner { _getLiquidStakingTokenStorage().canPause[_address] = _allowed; } /** * @notice Check if an address can pause the contract. * @param _address the address to check if it can pause the contract. */ function canPause(address _address) external view returns (bool) { return _canPause(_address); } /** * @notice Pause SyncPool deposits and withdrawals. */ function pause() external onlyCanPause { _pause(); } /** * @notice Unpause SyncPool deposits and withdrawals. */ function unpause() external onlyCanPause { _unpause(); } /** * @notice Set the rebase fee. * @param _rebaseFee uint256 Rebase fee. */ function setRebaseFee(uint256 _rebaseFee) external onlyOwner { if (_rebaseFee > Constants.MAX_REBASE_FEE) revert Errors.InvalidFee(); _getLiquidStakingTokenStorage().rebaseFee = _rebaseFee; } /** * @notice Set the rebase fee. * @param _syncDepositFee uint256 Rebase fee. */ function setSyncDepositFee(uint256 _syncDepositFee) external onlyOwner { if (_syncDepositFee > Constants.MAX_DEPOSIT_FEE) revert Errors.InvalidFee(); _getLiquidStakingTokenStorage().syncDepositFee = _syncDepositFee; } /** * @notice Set the treasury address. * @param _treasury address Treasury address. */ function setTreasury(address _treasury) external onlyOwner { _setTreasury(_treasury); } /** * @notice Set the Wrapped Liquid Staked Token address. * @param _wLST address Wrapped Liquid Staked Token address. */ function setWrappedLST(address _wLST) external onlyOwner { if (_wLST == address(0)) revert Errors.ZeroAddress(); _getLiquidStakingTokenStorage().wLST = _wLST; } /** * @return the total amount (in wei) of Pirex Ether controlled by the protocol. */ function totalAssets() public view returns (uint256) { return _totalAssets(); } /** * @return The treasury address that receives the treasury fee. */ function treasury() public view returns (address) { return _getLiquidStakingTokenStorage().treasury; } /** * @return The rebase fee that is charged on each rebase. */ function rebaseFee() public view returns (uint256) { return _getLiquidStakingTokenStorage().rebaseFee; } /** * @return The sync deposit fee that is charged on each sync pool L2 deposit. */ function syncDepositFee() public view returns (uint256) { return _getLiquidStakingTokenStorage().syncDepositFee; } /** * @return The last assets per share value. */ function lastAssetsPerShare() public view returns (uint256) { return _getLiquidStakingTokenStorage().lastAssetsPerShare; } /** * @param idx uint256 Sync index * @return Pending amount. */ function syncIndexPendingAmount( uint256 idx ) external view returns (uint256) { return _getLiquidStakingTokenStorage().syncIndexPendingAmount[idx]; } /** * @notice Returns the current sync indexes. * @return lastPendingSyncIndex The last pending sync index. * @return lastCompletedSyncIndex The last completed sync index. */ function syncIndexes() external view returns (uint256 lastPendingSyncIndex, uint256 lastCompletedSyncIndex) { return ( _getLiquidStakingTokenStorage().lastPendingSyncIndex, _getLiquidStakingTokenStorage().lastCompletedSyncIndex ); } /** * @return The total staked amount. */ function totalStaked() external view returns (uint256) { return _getLiquidStakingTokenStorage().totalStaked; } /** * @param includeUnsynced bool Include unsynced pending deposit. * @return The total amount (in wei) of pending deposit. */ function pendingDeposit( bool includeUnsynced ) public view returns (uint256) { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); return $.syncedPendingDeposit + (includeUnsynced ? $.unsyncedPendingDeposit : 0); } /** * @return the total amount (in wei) of Pirex Ether controlled by the protocol. */ function _totalAssets() internal view override returns (uint256) { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); return $.totalStaked + $.unsyncedPendingDeposit + $.syncedPendingDeposit; } /** * @notice Set the treasury address. * @param _treasury address Treasury address. */ function _setTreasury(address _treasury) internal { if (_treasury == address(0)) revert Errors.ZeroAddress(); _getLiquidStakingTokenStorage().treasury = _treasury; } /** * @notice Update the total staked amount. * @param _assetsPerShare uint256 The assets per share value. */ function _updateTotalStaked(uint256 _assetsPerShare) internal { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); uint256 _lastAssetsPerShare = $.lastAssetsPerShare; uint256 _totalStaked = $.totalStaked; if (_lastAssetsPerShare > 0) _totalStaked.mulDivDown(_assetsPerShare, _lastAssetsPerShare); $.lastAssetsPerShare = _assetsPerShare; } /** * @notice Withdraw from the pending deposit. * @param _withdrawAmount uint256 The amount to withdraw. * @return The remaining amount to withdraw from total staked. */ function _withdrawPendingDeposit( uint256 _withdrawAmount ) internal returns (uint256) { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); uint256 lastPendingIndex = $.lastPendingSyncIndex; uint256 lastCompletedIndex = $.lastCompletedSyncIndex; uint256 remaining = _withdrawAmount; for (uint256 i = lastCompletedIndex + 1; i <= lastPendingIndex; i++) { uint256 pendingAmount = $.syncIndexPendingAmount[i]; if (pendingAmount > remaining) { $.syncIndexPendingAmount[i] -= remaining; remaining = 0; break; } remaining -= pendingAmount; $.syncIndexPendingAmount[i] = 0; $.lastCompletedSyncIndex++; } $.syncedPendingDeposit -= (_withdrawAmount - remaining); return remaining; } /** * @notice Update the sync queue. * @param _syncedIds bytes The last synced ids. * @return The staked amount. */ function _updateSyncQueue( bytes32[] memory _syncedIds ) internal returns (uint256) { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); uint256 staked; uint256 index; uint256 pendingAmount; uint256 syncIdsLen = _syncedIds.length; uint256 lastPendingIndex = $.lastPendingSyncIndex; uint256 lastCompletedIndex = $.lastCompletedSyncIndex; for (uint256 i; i < syncIdsLen; i++) { index = $.syncIdIndex[_syncedIds[i]]; pendingAmount = $.syncIndexPendingAmount[index]; if (pendingAmount > 0) { $.syncIndexPendingAmount[index] = 0; staked += pendingAmount; } } // update last completed index uint256 startIndex = lastCompletedIndex + 1; uint256 maxSyncIndex = syncIdsLen + lastCompletedIndex > lastPendingIndex ? lastPendingIndex : syncIdsLen + lastCompletedIndex; for (uint256 i = startIndex; i <= maxSyncIndex; i++) { if ($.syncIndexPendingAmount[i] > 0) { $.lastCompletedSyncIndex = i - 1; break; } if (i == maxSyncIndex && $.syncIndexPendingAmount[i] == 0) { $.lastCompletedSyncIndex = i; } } return staked; } /** * @dev Internal function to sync tokens to L1 * This will send an additional message to the messenger contract after the LZ message * This message will contain the ETH that the LZ message anticipates to receive * @param _l2TokenIn Address of the token on Layer 2 * @param _l1TokenIn Address of the token on Layer 1 * @param _amountIn Amount of tokens deposited on Layer 2 * @param _amountOut Amount of tokens minted on Layer 2 * @param _totalAmountIn Total amount of tokens deposited on Layer 2 * @param _extraOptions Extra options for the messaging protocol * @param _fee Messaging fee * @return receipt Messaging receipt */ function _sync( address _l2TokenIn, address _l1TokenIn, uint256 _amountIn, uint256 _amountOut, uint256 _totalAmountIn, bytes calldata _extraOptions, MessagingFee calldata _fee ) internal virtual override nonReentrant whenNotPaused returns (MessagingReceipt memory) { // send fast sync message MessagingReceipt memory receipt = _lzSend( L1_EID, abi.encode( Constants.MESSAGE_TYPE_SYNC, _l1TokenIn, _amountIn, _amountOut ), combineOptions(L1_EID, 0, _extraOptions), MessagingFee(_fee.nativeFee, 0), payable(msg.sender) ); _addToSyncQueue(receipt, _amountOut); bytes memory data = abi.encode( endpoint.eid(), receipt.guid, _l1TokenIn, _amountIn, _amountOut ); // send slow sync message _sendSlowSyncMessage(_l2TokenIn, _amountIn, _fee.nativeFee, data); L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); uint256 unsyncedShares = $.unsyncedShares; uint256 syncedShares = _totalAmountIn == _amountIn ? unsyncedShares : unsyncedShares.mulDivDown(_amountIn, _totalAmountIn); IRateLimiter(getRateLimiter()).updateRateLimit( address(this), Constants.ETH_ADDRESS, syncedShares, 0 ); $.unsyncedShares -= syncedShares; return receipt; } /** * @dev Internal function to send tokenOut to an account * @param _account Address of the account * @param _amount Amount of tokens to send * @param shouldWrap bool Whether to wrap the tokens before sending */ function _sendTokenOut( address _account, uint256 _amount, bool shouldWrap ) internal override { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); uint256 assetsPerShare = IRateProvider(getL2ExchangeRateProvider()) .getAssetsPerShare(); if (shouldWrap) { _mint(address(this), assetsPerShare, _amount); _approve(address(this), $.wLST, _amount, false); uint256 wAmount = IWrappedLiquidStakedToken($.wLST).wrap(_amount); IWrappedLiquidStakedToken($.wLST).transfer(_account, wAmount); } else { _mint(_account, assetsPerShare, _amount); } } /** * @dev Internal function to send a slow sync message * This function should be overridden to send a slow sync message to the L1 receiver contract * @param _l2TokenIn Address of the token on Layer 2 * @param _amountIn Amount of tokens deposited on Layer 2 * @param _fastSyncNativeFee The amount of ETH already used as native fee in the fast sync * @param _message Message to send */ function _sendSlowSyncMessage( address _l2TokenIn, uint256 _amountIn, uint256 _fastSyncNativeFee, bytes memory _message ) internal virtual; /** * @dev Internal function to get the minimum gas limit * This function should be overridden to set a minimum gas limit to forward during the execution of the message * by the L1 receiver contract. This is mostly needed if the underlying contract have some try/catch mechanism * as this could be abused by gas-griefing attacks. * @return minGasLimit Minimum gas limit */ function _minGasLimit() internal view virtual returns (uint32) { return 0; } /** * @notice Set the last received nonce for the specified source endpoint and sender. * @dev this should be used to fix the nonce if there's a problem in the execution of a particular message. * @param _srcEid Source endpoint ID. * @param _sender Sender's address in bytes32 format. * @param _nonce The nonce to be set. */ function setNonce( uint32 _srcEid, bytes32 _sender, uint64 _nonce ) external onlyOwner { _getLiquidStakingTokenStorage().receivedNonce[_srcEid][ _sender ] = _nonce; } /** * @dev Public function to get the next expected nonce for a given source endpoint and sender. * @param _srcEid Source endpoint ID. * @param _sender Sender's address in bytes32 format. * @return uint64 Next expected nonce. */ function nextNonce( uint32 _srcEid, bytes32 _sender ) public view override returns (uint64) { return _getLiquidStakingTokenStorage().receivedNonce[_srcEid][_sender] + 1; } /** * @dev Internal function to accept nonce from the specified source endpoint and sender. * @param _srcEid Source endpoint ID. * @param _sender Sender's address in bytes32 format. * @param _nonce The nonce to be accepted. */ function _acceptNonce( uint32 _srcEid, bytes32 _sender, uint64 _nonce ) internal { L2TokenStorage storage $ = _getLiquidStakingTokenStorage(); if (_nonce != $.receivedNonce[_srcEid][_sender] + 1) revert Errors.InvalidNonce(); $.receivedNonce[_srcEid][_sender] += 1; } }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; library MsgCodec { // Offset constants for decoding messages uint256 private constant MESSAGE_TYPE_OFFSET = 32; uint256 private constant COMPOSE_TYPE_OFFSET = 64; uint256 private constant COMPOSE_RECEIVER_OFFSET = 32; /** * @dev Retrieves the message type from the message. * @param _msg The message. * @return The message type. */ function messageType(bytes calldata _msg) internal pure returns (uint8) { return abi.decode(_msg[:MESSAGE_TYPE_OFFSET], (uint8)); } /** * @dev Retrieve the relavant parameters from the message. * @param _msg The message. * @return msgType The message type. * @return amount The amount. * @return assetsPerShare The assets per share. * @return receiver The token receiver. * @return syncedIds The synced IDs. */ function decodeL1Msg( bytes calldata _msg ) internal pure returns ( uint8 msgType, uint256 amount, uint256 assetsPerShare, address receiver, bytes32[] memory syncedIds ) { (, uint256 composeMsgLen) = isComposed(_msg); (msgType, amount, assetsPerShare, receiver, syncedIds) = abi.decode( _msg[COMPOSE_TYPE_OFFSET:_msg.length - composeMsgLen], (uint8, uint256, uint256, address, bytes32[]) ); } /** * @dev Retrieve the relavant parameters from the sync message. * @param _msg The message. * @return token The deposited token. * @return amountIn The amount in. * @return amountOut The amount out. */ function decodeSync( bytes calldata _msg ) internal pure returns (address token, uint256 amountIn, uint256 amountOut) { (token, amountIn, amountOut) = abi.decode( _msg[MESSAGE_TYPE_OFFSET:], (address, uint256, uint256) ); } /** * @dev Retrieve the relavant parameters from the withdraw message. * @param _msg The message. * @return amount The amount. * @return receiver The receiver address. */ function decodeWithdraw( bytes calldata _msg ) internal pure returns (uint256 amount, address receiver) { (amount, receiver) = abi.decode( _msg[MESSAGE_TYPE_OFFSET:], (uint256, address) ); } /** * @dev Retrieve the compose message. * @param _payload The LayerZero msg payload. * @return The compose message. */ function composeMsg( bytes calldata _payload ) internal pure returns (bytes memory) { (bool composed, uint256 composeMsgLen) = isComposed(_payload); uint256 payloadLen = _payload.length; return composed ? _payload[COMPOSE_RECEIVER_OFFSET + payloadLen - composeMsgLen:] : new bytes(0); } /** * @dev Check if the message is composed. * @param _payload The LayerZero msg payload. * @return Boolean if paylaod is composed and the length of the compose message. */ function isComposed( bytes calldata _payload ) internal pure returns (bool, uint256) { (bool isCompose, uint256 composeMsgLen) = abi.decode( _payload[:COMPOSE_TYPE_OFFSET], (bool, uint256) ); return (isCompose, composeMsgLen); } /** * @dev Encode the message. * @param _msg The message. * @param _composeMsg The compose message. * @return The encoded message. */ function encode( bytes memory _msg, bytes memory _composeMsg ) internal pure returns (bytes memory) { uint256 composeMsgLen = _composeMsg.length; bool isCompose = composeMsgLen != 0; return abi.encodePacked( abi.encode(isCompose, composeMsgLen), _msg, _composeMsg ); } /** * @dev Encode the compose message receiver. * The compose message must reserve its first 32 bytes for the receiver. * @param _payload The LayerZero msg payload. * @return The receiver address. */ function composeTo( bytes calldata _payload ) internal pure returns (address) { (, uint256 composeMsgLen) = isComposed(_payload); uint256 payloadLen = _payload.length; uint256 start = payloadLen - composeMsgLen; uint256 end = start + 32; return address(uint160(uint256(bytes32(_payload[start:end])))); } }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import { ILayerZeroReceiver, Origin } from "contracts/vendor/layerzero/protocol/interfaces/ILayerZeroReceiver.sol"; interface IOAppReceiver is ILayerZeroReceiver { /** * @notice Retrieves the address responsible for 'sending' composeMsg's to the Endpoint. * @return sender The address responsible for 'sending' composeMsg's to the Endpoint. * * @dev Applications can optionally choose to implement a separate composeMsg sender that is NOT the bridging layer. * @dev The default sender IS the OApp implementer. */ function composeMsgSender() external view returns (address sender); }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; library OFTComposeMsgCodec { // Offset constants for decoding composed messages uint8 private constant NONCE_OFFSET = 8; uint8 private constant SRC_EID_OFFSET = 12; uint8 private constant AMOUNT_LD_OFFSET = 44; uint8 private constant COMPOSE_FROM_OFFSET = 76; /** * @dev Encodes a OFT composed message. * @param _nonce The nonce value. * @param _srcEid The source endpoint ID. * @param _amountLD The amount in local decimals. * @param _composeMsg The composed message. * @return _msg The encoded Composed message. */ function encode( uint64 _nonce, uint32 _srcEid, uint256 _amountLD, bytes memory _composeMsg // 0x[composeFrom][composeMsg] ) internal pure returns (bytes memory _msg) { _msg = abi.encodePacked(_nonce, _srcEid, _amountLD, _composeMsg); } /** * @dev Retrieves the nonce from the composed message. * @param _msg The message. * @return The nonce value. */ function nonce(bytes calldata _msg) internal pure returns (uint64) { return uint64(bytes8(_msg[:NONCE_OFFSET])); } /** * @dev Retrieves the source endpoint ID from the composed message. * @param _msg The message. * @return The source endpoint ID. */ function srcEid(bytes calldata _msg) internal pure returns (uint32) { return uint32(bytes4(_msg[NONCE_OFFSET:SRC_EID_OFFSET])); } /** * @dev Retrieves the amount in local decimals from the composed message. * @param _msg The message. * @return The amount in local decimals. */ function amountLD(bytes calldata _msg) internal pure returns (uint256) { return uint256(bytes32(_msg[SRC_EID_OFFSET:AMOUNT_LD_OFFSET])); } /** * @dev Retrieves the composeFrom value from the composed message. * @param _msg The message. * @return The composeFrom value. */ function composeFrom(bytes calldata _msg) internal pure returns (bytes32) { return bytes32(_msg[AMOUNT_LD_OFFSET:COMPOSE_FROM_OFFSET]); } /** * @dev Retrieves the composed message. * @param _msg The message. * @return The composed message. */ function composeMsg(bytes calldata _msg) internal pure returns (bytes memory) { return _msg[COMPOSE_FROM_OFFSET:]; } /** * @dev Converts an address to bytes32. * @param _addr The address to convert. * @return The bytes32 representation of the address. */ function addressToBytes32(address _addr) internal pure returns (bytes32) { return bytes32(uint256(uint160(_addr))); } /** * @dev Converts bytes32 to an address. * @param _b The bytes32 value to convert. * @return The address representation of bytes32. */ function bytes32ToAddress(bytes32 _b) internal pure returns (address) { return address(uint160(uint256(_b))); } }
// SPDX-License-Identifier: LZBL-1.2 pragma solidity ^0.8.20; import {SafeERC20, IERC20} from "@openzeppelin/contracts/token/ERC20/utils/SafeERC20.sol"; import {MessagingFee, MessagingReceipt} from "./vendor/layerzero/protocol/interfaces/ILayerZeroEndpointV2.sol"; import {OwnableUpgradeable} from "@openzeppelin/contracts-upgradeable/access/OwnableUpgradeable.sol"; import {IL2ExchangeRateProvider} from "./vendor/layerzero/syncpools/interfaces/IL2ExchangeRateProvider.sol"; import {IRateLimiter} from "./vendor/layerzero/syncpools/interfaces/IRateLimiter.sol"; import {IBridgeQuoter} from "./interfaces/IBridgeQuoter.sol"; import {Constants} from "./libraries/Constants.sol"; import {Errors} from "./libraries/Errors.sol"; /** * @title L2 Base Sync Pool * @dev Base contract for Layer 2 sync pools * A sync pool is an OApp that allows users to deposit tokens on Layer 2, and then sync them to Layer 1 * The L2 sync pool takes care of deposits on the L2 and syncing to the L1 using the L1 sync pool. * Once enough tokens have been deposited, anyone can trigger a sync to Layer 1. */ abstract contract L2SyncPool is OwnableUpgradeable { struct L2SyncPoolStorage { /** * @notice The address of the exchange rate provider contract. * @dev This variable holds the address of the exchange rate provider contract, which is used to get the conversion rate. */ IL2ExchangeRateProvider l2ExchangeRateProvider; /** * @notice The address of the rate limiter contract. * @dev This variable holds the address of the rate limiter contract, which is used to limit mint and withdrawal. */ IRateLimiter rateLimiter; /** * @notice The address of the bridge quoter contract. * @dev This variable holds the address of the bridge quoter contract, which is used to get the min amount receive when bridging to L1. */ IBridgeQuoter bridgeQuoter; /** * @notice The token data. * @dev This mapping holds the token data, which includes the amount of tokens deposited and minted, and the minimum amount required to sync. */ mapping(address => Token) tokens; /** * @notice The sync keeper. * @dev This mapping holds the sync keepers, which are allowed to trigger a sync to Layer 1. */ mapping(address => bool) syncKeeper; } /** * @dev Token data * @param unsyncedAmountIn Amount of tokens deposited on Layer 2 * @param unsyncedAmountOut Amount of tokens minted on Layer 2 * @param minSyncAmount Minimum amount of tokens required to sync * @param maxSyncAmount Maximum amount of tokens required to sync * @param l1Address Address of the token on Layer 1, address(0) is unauthorized */ struct Token { uint256 unsyncedAmountIn; uint256 unsyncedAmountOut; uint256 minSyncAmount; uint256 maxSyncAmount; address l1Address; } // keccak256(abi.encode(uint256(keccak256(syncpools.storage.l2syncpool)) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant L2SyncPoolStorageLocation = 0xc064a301e926254981c9bd3b3225923d097271573deb3cc61ae7f6a144f10a00; function _getL2SyncPoolStorage() internal pure returns (L2SyncPoolStorage storage $) { assembly { $.slot := L2SyncPoolStorageLocation } } event L2ExchangeRateProviderSet(address l2ExchangeRateProvider); event RateLimiterSet(address rateLimiter); event MinSyncAmountSet(address tokenIn, uint256 minSyncAmount); event MaxSyncAmountSet(address tokenIn, uint256 maxSyncAmount); event L1TokenInSet(address tokenIn, address l1TokenIn); event Deposit(address indexed tokenIn, uint256 amountIn, uint256 amountOut); event Sync(address indexed tokenIn, uint256 amountIn, uint256 amountOut); event SyncKeeperSet(address syncKeeper, bool status); event BridgeQuoterSet(address bridgeQuoter); /** * @dev Modifier to allow only the sync keeper to call the function */ modifier onlySyncKeeper() { if (!_getL2SyncPoolStorage().syncKeeper[msg.sender]) { revert Errors.UnauthorizedCaller(); } _; } /** * @dev Initialize the L2 Base Sync Pool * @param l2ExchangeRateProvider Address of the exchange rate provider * @param rateLimiter Address of the rate limiter * @param bridgeQuoter Address of the bridge quoter */ function __L2BaseSyncPool_init( address l2ExchangeRateProvider, address rateLimiter, address bridgeQuoter ) internal { __L2BaseSyncPool_init_unchained( l2ExchangeRateProvider, rateLimiter, bridgeQuoter ); } function __L2BaseSyncPool_init_unchained( address l2ExchangeRateProvider, address rateLimiter, address bridgeQuoter ) internal { _setL2ExchangeRateProvider(l2ExchangeRateProvider); _setRateLimiter(rateLimiter); _setBridgeQuoter(bridgeQuoter); } /** * @dev Get the exchange rate provider * @return l2ExchangeRateProvider Address of the exchange rate provider */ function getL2ExchangeRateProvider() public view virtual returns (address) { L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); return address($.l2ExchangeRateProvider); } /** * @dev Get the rate limiter * @return rateLimiter Address of the rate limiter */ function getRateLimiter() public view virtual returns (address) { L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); return address($.rateLimiter); } /** * @dev Get token data * If the l1Address is address(0), the token is unauthorized * @param tokenIn Address of the token * @return token Token data */ function getTokenData( address tokenIn ) public view virtual returns (Token memory) { L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); return $.tokens[tokenIn]; } /** * @dev Check if the address is a sync keeper * @param syncKeeper Address of the sync keeper * @return status True if the address is a sync keeper */ function isSyncKeeper( address syncKeeper ) public view virtual returns (bool) { return _getL2SyncPoolStorage().syncKeeper[syncKeeper]; } /** * @notice Deposit tokens on Layer 2 * This will mint tokenOut on Layer 2 using the exchange rate for tokenIn to tokenOut. * The amount deposited and minted will be stored in the token data which can be synced to Layer 1. * @param tokenIn Address of the token * @param amountIn Amount of tokens to deposit * @param minAmountOut Minimum amount of tokens to mint on Layer 2 * @param shouldWrap True if the token should be wrapped * @return amountOut Amount of tokens minted on Layer 2 */ function deposit( address tokenIn, uint256 amountIn, uint256 minAmountOut, bool shouldWrap ) public payable virtual returns (uint256 amountOut) { amountOut = _deposit(tokenIn, amountIn, minAmountOut); _sendTokenOut(msg.sender, amountOut, shouldWrap); } /** * @dev Deposit tokens on Layer 2 * This will mint tokenOut on Layer 2 using the exchange rate for tokenIn to tokenOut. * The amount deposited and minted will be stored in the token data which can be synced to Layer 1. * Will revert if: * - The amountIn is zero * - The token is unauthorized (that is, the l1Address is address(0)) * - The amountOut is less than the minAmountOut * @param tokenIn Address of the token * @param amountIn Amount of tokens to deposit * @param minAmountOut Minimum amount of tokens to mint on Layer 2 * @return amountOut Amount of tokens minted on Layer 2 */ function _deposit( address tokenIn, uint256 amountIn, uint256 minAmountOut ) internal virtual returns (uint256 amountOut) { if (amountIn == 0) revert Errors.ZeroAmount(); L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); Token storage token = $.tokens[tokenIn]; if (token.l1Address == address(0)) revert Errors.UnauthorizedToken(); uint256 amountReceived = amountIn; if (tokenIn != Constants.ETH_ADDRESS) { // get the actual amount sent and the expected amount received after bridging (amountIn, amountReceived) = $.bridgeQuoter.getAmountOut( tokenIn, amountIn ); // as only WETH deposits are allowed, the amount received should be greater than the amount sent // otherwise, therer might be some temporary pool imbalance if (amountReceived > amountIn) revert Errors.InvalidRate(); } amountOut = $.l2ExchangeRateProvider.getPostFeeAmount( tokenIn, amountReceived ); if (amountOut < minAmountOut) revert Errors.InsufficientAmountOut(); emit Deposit(tokenIn, amountIn, minAmountOut); _receiveTokenIn(tokenIn, amountIn); token.unsyncedAmountIn += amountIn; if ( token.maxSyncAmount != 0 && token.unsyncedAmountIn > token.maxSyncAmount ) { revert Errors.MaxSyncAmountExceeded(); } token.unsyncedAmountOut += amountOut; } /** * @dev Sync tokens to Layer 1 * This will send a message to the destination endpoint with the token data to * sync the tokens minted on Layer 2 to Layer 1. * Will revert if: * - The token is unauthorized (that is, the l1Address is address(0)) * - The amount to sync is zero or less than the minSyncAmount * @dev It is very important to listen for the Sync event to know when and how much tokens were synced * especially if an action is required on another chain (for example, executing the message). If an action * was required but was not executed, the tokens won't be sent to the L1. * @param tokenIn Address of the token * @param extraOptions Extra options for the messaging protocol * @param fee Fast sync messaging fee, does not consider token bridge fees * @return unsyncedAmountIn Amount of tokens deposited on Layer 2 * @return unsyncedAmountOut Amount of tokens minted on Layer 2 */ function sync( address tokenIn, bytes calldata extraOptions, MessagingFee calldata fee ) public payable virtual onlySyncKeeper returns (uint256 unsyncedAmountIn, uint256 unsyncedAmountOut) { L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); Token storage token = $.tokens[tokenIn]; address l1TokenIn = token.l1Address; if (l1TokenIn == address(0)) revert Errors.UnauthorizedToken(); unsyncedAmountIn = token.unsyncedAmountIn; unsyncedAmountOut = token.unsyncedAmountOut; if (unsyncedAmountIn == 0 || unsyncedAmountIn < token.minSyncAmount) { revert Errors.InsufficientAmountToSync(); } token.unsyncedAmountIn = 0; token.unsyncedAmountOut = 0; emit Sync(tokenIn, unsyncedAmountIn, unsyncedAmountOut); _sync( tokenIn, l1TokenIn, unsyncedAmountIn, unsyncedAmountOut, unsyncedAmountIn, extraOptions, fee ); return (unsyncedAmountIn, unsyncedAmountOut); } /** * @dev Sync tokens to Layer 1 * This will send a message to the destination endpoint with the token data to * sync the tokens minted on Layer 2 to Layer 1. * Will revert if: * - The token is unauthorized (that is, the l1Address is address(0)) * - The amount to sync is zero or less than the minSyncAmount * @dev It is very important to listen for the Sync event to know when and how much tokens were synced * especially if an action is required on another chain (for example, executing the message). If an action * was required but was not executed, the tokens won't be sent to the L1. * @param tokenIn Address of the token * @param amount Amount of tokens to sync * @param extraOptions Extra options for the messaging protocol * @param fee Fast sync messaging fee, does not consider token bridge fees * @return syncedAmountIn Amount of synced tokens deposited on Layer 2 * @return syncedAmountOut Amount of synced tokens minted on Layer 2 */ function sync( address tokenIn, uint256 amount, bytes calldata extraOptions, MessagingFee calldata fee ) public payable virtual onlySyncKeeper returns (uint256, uint256) { L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); Token storage token = $.tokens[tokenIn]; if (token.l1Address == address(0)) revert Errors.UnauthorizedToken(); uint256 unsyncedAmountIn = token.unsyncedAmountIn; if ( unsyncedAmountIn == 0 || unsyncedAmountIn < token.minSyncAmount || amount > unsyncedAmountIn ) { revert Errors.InsufficientAmountToSync(); } // Reduce unsyncedAmountOut proportionally to unsyncedAmountIn uint256 amountOut = (token.unsyncedAmountOut * amount) / unsyncedAmountIn; token.unsyncedAmountIn -= amount; token.unsyncedAmountOut -= amountOut; emit Sync(tokenIn, amount, amountOut); _sync( tokenIn, token.l1Address, amount, amountOut, unsyncedAmountIn, extraOptions, fee ); return (amount, amountOut); } /** * @dev Set the exchange rate provider * @param l2ExchangeRateProvider Address of the exchange rate provider */ function setL2ExchangeRateProvider( address l2ExchangeRateProvider ) public virtual onlyOwner { _setL2ExchangeRateProvider(l2ExchangeRateProvider); } /** * @dev Set the rate limiter * @param rateLimiter Address of the rate limiter */ function setRateLimiter(address rateLimiter) public virtual onlyOwner { _setRateLimiter(rateLimiter); } /** * @dev Set the minimum amount of tokens required to sync * @param tokenIn Address of the token * @param minSyncAmount Minimum amount of tokens required to sync */ function setMinSyncAmount( address tokenIn, uint256 minSyncAmount ) public virtual onlyOwner { if (minSyncAmount == 0) revert Errors.ZeroAmount(); L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); $.tokens[tokenIn].minSyncAmount = minSyncAmount; emit MinSyncAmountSet(tokenIn, minSyncAmount); } /** * @dev Set the maximum amount of tokens to sync * @param tokenIn Address of the token * @param maxSyncAmount Maximum amount of tokens to sync */ function setMaxSyncAmount( address tokenIn, uint256 maxSyncAmount ) public virtual onlyOwner { L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); $.tokens[tokenIn].maxSyncAmount = maxSyncAmount; emit MaxSyncAmountSet(tokenIn, maxSyncAmount); } /** * @dev Set the Layer 1 address of the token * @param l2TokenIn Address of the token on Layer 2 * @param l1TokenIn Address of the token on Layer 1 */ function setL1TokenIn( address l2TokenIn, address l1TokenIn ) public virtual onlyOwner { if (l1TokenIn == address(0)) revert Errors.ZeroAddress(); L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); $.tokens[l2TokenIn].l1Address = l1TokenIn; emit L1TokenInSet(l2TokenIn, l1TokenIn); } /** * @dev Set the sync keeper * @param syncKeeper Address of the sync keeper * @param status True to set as a sync keeper */ function setSyncKeeper( address syncKeeper, bool status ) public virtual onlyOwner { _getL2SyncPoolStorage().syncKeeper[syncKeeper] = status; emit SyncKeeperSet(syncKeeper, status); } /** * @dev Set bridge quoter * @param bridgeQuoter Bridge quoter contract to get the min amount receive when bridging to L1 */ function setBridgeQuoter(address bridgeQuoter) public virtual onlyOwner { _setBridgeQuoter(bridgeQuoter); } /** * @dev Internal function to set bridge quoter * @param bridgeQuoter Bridge quoter contract */ function _setBridgeQuoter(address bridgeQuoter) internal { _getL2SyncPoolStorage().bridgeQuoter = IBridgeQuoter(bridgeQuoter); emit BridgeQuoterSet(bridgeQuoter); } /** * @dev Internal function to set the exchange rate provider * @param l2ExchangeRateProvider Address of the exchange rate provider */ function _setL2ExchangeRateProvider( address l2ExchangeRateProvider ) internal virtual { if (l2ExchangeRateProvider == address(0)) revert Errors.ZeroAddress(); L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); $.l2ExchangeRateProvider = IL2ExchangeRateProvider( l2ExchangeRateProvider ); emit L2ExchangeRateProviderSet(l2ExchangeRateProvider); } /** * @dev Internal function to set the rate limiter * @param rateLimiter Address of the rate limiter */ function _setRateLimiter(address rateLimiter) internal virtual { if (rateLimiter == address(0)) revert Errors.ZeroAddress(); L2SyncPoolStorage storage $ = _getL2SyncPoolStorage(); $.rateLimiter = IRateLimiter(rateLimiter); emit RateLimiterSet(rateLimiter); } /** * @dev Internal function to receive tokens on Layer 2 * @param tokenIn Address of the token * @param amountIn Amount of tokens to receive */ function _receiveTokenIn( address tokenIn, uint256 amountIn ) internal virtual { if (tokenIn == Constants.ETH_ADDRESS) { if (amountIn != msg.value) revert Errors.InvalidAmountIn(); } else { if (msg.value != 0) revert Errors.InvalidAmountIn(); // warning: not safe with transfer tax tokens SafeERC20.safeTransferFrom( IERC20(tokenIn), msg.sender, address(this), amountIn ); } } /** * @dev Internal function to sync tokens to Layer 1 * @param l2TokenIn Address of the token on Layer 2 * @param l1TokenIn Address of the token on Layer 1 * @param amountIn Amount of tokens deposited on Layer 2 * @param amountOut Amount of tokens minted on Layer 2 * @param totalAmountIn Total amount of tokens deposited on Layer 2 * @param extraOptions Extra options for the messaging protocol * @param fee Messaging fee * @return receipt Messaging receipt */ function _sync( address l2TokenIn, address l1TokenIn, uint256 amountIn, uint256 amountOut, uint256 totalAmountIn, bytes calldata extraOptions, MessagingFee calldata fee ) internal virtual returns (MessagingReceipt memory); /** * @dev Internal function to send tokenOut to an account * @param account Address of the account * @param amount Amount of tokens to send * @param shouldWrap True if the token should be wrapped */ function _sendTokenOut( address account, uint256 amount, bool shouldWrap ) internal virtual; }
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; import {ERC20PermitUpgradeable, Initializable} from "@openzeppelin/contracts-upgradeable/token/ERC20/extensions/ERC20PermitUpgradeable.sol"; import {FixedPointMathLib} from "solmate/src/utils/FixedPointMathLib.sol"; import {Errors} from "./libraries/Errors.sol"; /** * @title Interest-bearing ERC20-like token for L2LiquidStakingToken assets. * * This contract is abstract. To make the contract deployable override the * `_totalAssets` function. `L2LiquidStakingToken.sol` contract inherits DineroERC20Rebase and defines * the `_totalAssets` function. * * DineroERC20Rebase balances are dynamic and represent the holder's share in the total amount * of Pirex assets controlled by the protocol. Account shares aren't normalized, so the * contract also stores the sum of all shares to calculate each account's token balance * which equals to: * * shares[account] * _totalAssets() / totalShares * * For example, assume that we have: * * _totalAssets() -> 10 ETH * sharesOf(user1) -> 100 * sharesOf(user2) -> 400 * * Therefore: * * balanceOf(user1) -> 2 tokens which corresponds 2 ETH * balanceOf(user2) -> 8 tokens which corresponds 8 ETH * * Since balances of all token holders change when the amount of total pooled assets * changes, this token cannot fully implement ERC20 standard: it only emits `Transfer` * events upon explicit transfer between holders. In contrast, when total amount of * pooled assets increases, no `Transfer` events are generated: doing so would require * emitting an event for each token holder and thus running an unbounded loop. */ abstract contract DineroERC20RebaseUpgradeable is Initializable, ERC20PermitUpgradeable { /** * @dev Library: FixedPointMathLib - Provides fixed-point arithmetic for uint256. */ using FixedPointMathLib for uint256; /*////////////////////////////////////////////////////////////// EVENTS //////////////////////////////////////////////////////////////*/ /** * @notice An executed shares transfer from `sender` to `recipient`. * * @dev emitted in pair with an ERC20-defined `Transfer` event. */ event TransferShares( address indexed from, address indexed to, uint256 sharesValue ); /** * @notice An executed `burnShares` request * * @dev Reports simultaneously burnt shares amount * and corresponding DineroERC20Rebase amount. * The DineroERC20Rebase amount is calculated twice: before and after the burning incurred rebase. * * @param account holder of the burnt shares * @param preRebaseTokenAmount amount of DineroERC20Rebase the burnt shares corresponded to before the burn * @param postRebaseTokenAmount amount of DineroERC20Rebase the burnt shares corresponded to after the burn * @param sharesAmount amount of burnt shares */ event SharesBurnt( address indexed account, uint256 preRebaseTokenAmount, uint256 postRebaseTokenAmount, uint256 sharesAmount ); /*////////////////////////////////////////////////////////////// ERC20 REBASE STORAGE //////////////////////////////////////////////////////////////*/ /// @custom:storage-location erc7201:redacted.storage.DineroERC20Rebase struct DineroERC20RebaseStorage { /** * @notice Total amount of shares in existence. * * @dev The sum of all accounts' shares can be an arbitrary number, therefore * it is necessary to store it in order to calculate each account's relative share. */ uint256 totalShares; /** * @dev DineroERC20Rebase balances are dynamic and are calculated based on the accounts' shares * and the total amount of assets controlled by the protocol. Account shares aren't * normalized, so the contract also stores the sum of all shares to calculate * each account's token balance which equals to: * * shares[account] * _totalAssets() / totalShares() */ mapping(address => uint256) shares; } // keccak256(abi.encode(uint256(keccak256(redacted.storage.DineroERC20Rebase)) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant DineroERC20RebaseStorageLocation = 0xddf967707f52bbdea6c202114c491d81e6de0cb9ded430e88a276a6f8d3e3800; function _getDineroERC20RebaseStorage() private pure returns (DineroERC20RebaseStorage storage $) { assembly { $.slot := DineroERC20RebaseStorageLocation } } /*////////////////////////////////////////////////////////////// INITIALIZER //////////////////////////////////////////////////////////////*/ function __DineroERC20Rebase_init( string memory name_, string memory symbol_ ) internal onlyInitializing { // Set decoded values for name and symbol. __ERC20_init_unchained(name_, symbol_); // Set the name for EIP-712 signature. __ERC20Permit_init(name_); } /*////////////////////////////////////////////////////////////// ERC20 OVERRIDES //////////////////////////////////////////////////////////////*/ /** * @return the amount of tokens in existence. * * @dev Always equals to `_totalAssets()` since token amount * is pegged to the total amount of assets controlled by the protocol. */ function totalSupply() public view override returns (uint256) { return _totalAssets(); } /** * @return the amount of tokens owned by the `_account`. * * @dev Balances are dynamic and equal the `_account`'s share in the amount of the * total assets controlled by the protocol. See `sharesOf`. */ function balanceOf( address _account ) public view override returns (uint256) { return convertToAssets(_sharesOf(_account), true); } /** * @notice Moves `_amount` tokens from `_sender` to `_recipient`. * Emits a `Transfer` event. * Emits a `TransferShares` event. */ function _update( address _sender, address _recipient, uint256 _amount ) internal override { uint256 sharesToTransfer = convertToShares(_amount); if (sharesToTransfer == 0) revert Errors.InvalidAmount(); _transferShares(_sender, _recipient, sharesToTransfer); _emitTransferEvents(_sender, _recipient, _amount, sharesToTransfer); } /*////////////////////////////////////////////////////////////// ERC20 REBASE FUNCTIONS //////////////////////////////////////////////////////////////*/ /** * @notice Moves `_shares` token shares from the caller's account to the `_recipient` account. * * @return amount of transferred tokens. * Emits a `TransferShares` event. * Emits a `Transfer` event. * * Requirements: * * - `_recipient` cannot be the zero address. * - the caller must have at least `_shares` shares. * - the contract must not be paused. * * @dev The `_shares` argument is the amount of shares, not tokens. */ function transferShares( address _recipient, uint256 _shares ) external returns (uint256) { _transferShares(msg.sender, _recipient, _shares); uint256 assets = convertToAssets(_shares, true); _emitTransferEvents(msg.sender, _recipient, assets, _shares); return assets; } /** * @notice Moves `_shares` token shares from the `_sender` account to the `_recipient` account. * * @return amount of transferred tokens. * Emits a `TransferShares` event. * Emits a `Transfer` event. * * Requirements: * * - `_sender` and `_recipient` cannot be the zero addresses. * - `_sender` must have at least `_shares` shares. * - the caller must have allowance for `_sender`'s tokens of at least `getPooledPxEthByShares(_shares)`. * - the contract must not be paused. * * @dev The `_shares` argument is the amount of shares, not tokens. */ function transferSharesFrom( address _sender, address _recipient, uint256 _shares ) external returns (uint256) { uint256 assets = convertToAssets(_shares, false); _spendAllowance(_sender, msg.sender, assets); _transferShares(_sender, _recipient, _shares); _emitTransferEvents(_sender, _recipient, assets, _shares); return assets; } /** * @return the amount of shares owned by `_account`. */ function getTotalShares() public view returns (uint256) { return _getDineroERC20RebaseStorage().totalShares; } /** * @return the amount of shares owned by `_account`. */ function sharesOf(address _account) external view returns (uint256) { return _sharesOf(_account); } /** * @return the amount of assets that corresponds to `_shares` token shares. * @param floor if true, the result is rounded down, otherwise it's rounded up. */ function convertToAssets( uint256 _shares, bool floor ) public view returns (uint256) { uint256 totalShares = _getDineroERC20RebaseStorage().totalShares; return totalShares == 0 ? 0 : floor ? _shares.mulDivDown(_totalAssets(), totalShares) : _shares.mulDivUp(_totalAssets(), totalShares); } /** * @return the amount of shares that corresponds to `_assets` (pxEth). */ function convertToShares(uint256 _assets) public view returns (uint256) { return _convertToShares(_assets, true); } /** * @return the amount of shares that corresponds to `_assets` (pxEth) rounding up. */ function previewWithdraw(uint256 _assets) public view returns (uint256) { return _convertToShares(_assets, false); } /*////////////////////////////////////////////////////////////// INTERNAL LOGIC //////////////////////////////////////////////////////////////*/ /** * @return the total amount (in wei) of Pirex assets controlled by the protocol. * @dev This is used for calculating tokens from shares and vice versa. * @dev This function is required to be implemented in a derived contract. */ function _totalAssets() internal view virtual returns (uint256); /** * @return the amount of shares owned by `_account`. */ function _sharesOf(address _account) internal view returns (uint256) { return _getDineroERC20RebaseStorage().shares[_account]; } /** * @notice Moves `_shares` shares from `_sender` to `_recipient`. * * Requirements: * * - `_sender` cannot be the zero address. * - `_recipient` cannot be the zero address or the `DineroERC20Rebase` token contract itself * - `_sender` must hold at least `_shares` shares. * - the contract must not be paused. */ function _transferShares( address _sender, address _recipient, uint256 _shares ) internal { if (_sender == address(0) || _recipient == address(0)) revert Errors.ZeroAddress(); if (_recipient == address(this) || _sender == _recipient) revert Errors.NotAllowed(); DineroERC20RebaseStorage storage $ = _getDineroERC20RebaseStorage(); uint256 currentSenderShares = $.shares[_sender]; if (_shares > currentSenderShares) revert Errors.InvalidAmount(); $.shares[_sender] = currentSenderShares - _shares; $.shares[_recipient] += _shares; } /** * @notice Creates `_shares` shares and assigns them to `_recipient`, increasing the total amount of shares. * @dev This doesn't increase the token total supply. * * NB: The method doesn't check protocol pause relying on the external enforcement. * * Requirements: * * - `_recipient` cannot be the zero address. * - the contract must not be paused. */ function _mintShares( address _recipient, uint256 _shares ) internal returns (uint256) { if (_recipient == address(0)) revert Errors.ZeroAddress(); DineroERC20RebaseStorage storage $ = _getDineroERC20RebaseStorage(); $.totalShares += _shares; $.shares[_recipient] = $.shares[_recipient] + _shares; return $.totalShares; // Notice: we're not emitting a Transfer event from the zero address here since shares mint // works by taking the amount of tokens corresponding to the minted shares from all other // token holders, proportionally to their share. The total supply of the token doesn't change // as the result. This is equivalent to performing a send from each other token holder's // address to `address`, but we cannot reflect this as it would require sending an unbounded // number of events. } /** * @notice Destroys `_shares` shares from `_account`'s holdings, decreasing the total amount of shares. * @dev This doesn't decrease the token total supply. * * Requirements: * * - `_account` cannot be the zero address. * - `_account` must hold at least `_shares` shares. * - the contract must not be paused. */ function _burnShares( address _account, uint256 _shares ) internal returns (uint256) { if (_account == address(0)) revert Errors.ZeroAddress(); DineroERC20RebaseStorage storage $ = _getDineroERC20RebaseStorage(); uint256 accountShares = $.shares[_account]; if (_shares > accountShares) revert Errors.InvalidAmount(); uint256 preRebaseTokenAmount = convertToAssets(_shares, true); $.totalShares -= _shares; $.shares[_account] = accountShares - _shares; uint256 postRebaseTokenAmount = convertToAssets(_shares, true); emit SharesBurnt( _account, preRebaseTokenAmount, postRebaseTokenAmount, _shares ); return $.totalShares; // Notice: we're not emitting a Transfer event to the zero address here since shares burn // works by redistributing the amount of tokens corresponding to the burned shares between // all other token holders. The total supply of the token doesn't change as the result. // This is equivalent to performing a send from `address` to each other token holder address, // but we cannot reflect this as it would require sending an unbounded number of events. // We're emitting `SharesBurnt` event to provide an explicit rebase log record nonetheless. } /** * @dev Emits {Transfer} and {TransferShares} events */ function _emitTransferEvents( address _from, address _to, uint256 _assets, uint256 _shares ) internal { emit Transfer(_from, _to, _assets); emit TransferShares(_from, _to, _shares); } /** * @dev Converts `_assets` (pxEth) to shares. * * @param _assets amount of assets to convert to shares. * @param floor if true, the result is rounded down, otherwise it's rounded up. */ function _convertToShares( uint256 _assets, bool floor ) internal view returns (uint256) { uint256 totalShares = _getDineroERC20RebaseStorage().totalShares; uint256 totalPooledPxEth = _totalAssets(); if (totalPooledPxEth == 0) return 0; return floor ? _assets.mulDivDown(totalShares, totalPooledPxEth) : _assets.mulDivUp(totalShares, totalPooledPxEth); } }
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; /** * @title Constants * @notice Library containing various constants for the L2LiquidStakingToken system. * @author redactedcartel.finance */ library Constants { /** * @notice Message type constant for deposit. * @dev This constant defines the message type for deposit operations. */ uint8 constant MESSAGE_TYPE_DEPOSIT = 1; /** * @notice Message type constant for deposit. * @dev This constant defines the message type for deposit operations. */ uint8 constant MESSAGE_TYPE_DEPOSIT_WRAP = 2; /** * @notice Message type constant for withdrawal. * @dev This constant defines the message type for withdrawal operations. */ uint8 constant MESSAGE_TYPE_WITHDRAW = 3; /** * @notice Message type constant for rebase. * @dev This constant defines the message type for rebase operations. */ uint8 constant MESSAGE_TYPE_REBASE = 4; /** * @notice Message type constant for sync. * @dev This constant defines the message type for sync operations. */ uint8 constant MESSAGE_TYPE_SYNC = 5; /** * @notice The destination endpoint ID for Mainnet. * @dev This constant holds the destination endpoint ID for Mainnet. */ uint32 constant MAINNET_EID = 30101; /** * @notice Fee denominator for precise fee calculations. * @dev This constant holds the fee denominator for precise fee calculations. */ uint256 constant FEE_DENOMINATOR = 1_000_000; /** * @notice Max rebase fee. * @dev This constant holds the maximum rebase fee that can be set. */ uint256 constant MAX_REBASE_FEE = 200_000; /** * @notice Max deposit fee. * @dev This constant holds the maximum sync deposit fee that can be set. */ uint256 constant MAX_DEPOSIT_FEE = 200_000; /** * @dev The address of the ETH token. */ address constant ETH_ADDRESS = 0xEeeeeEeeeEeEeeEeEeEeeEEEeeeeEeeeeeeeEEeE; }
// SPDX-License-Identifier: MIT pragma solidity 0.8.25; library Errors { /** * @dev Zero address specified */ error ZeroAddress(); /** * @dev Zero amount specified */ error ZeroAmount(); /** * @dev Invalid fee specified */ error InvalidFee(); /** * @dev not same as deposit size */ error InvalidAmount(); /** * @dev Invalid nonce */ error InvalidNonce(); /** * @dev not allowed */ error NotAllowed(); /** * @dev Only ETH allowed */ error OnlyETH(); /** * @dev Invalid rate */ error InvalidRate(); /** * @dev Withdraw limit exceeded */ error WithdrawLimitExceeded(); /** * @dev Unauthorized caller on SyncPool */ error UnauthorizedCaller(); /** * @dev Native transfer failed on SyncPool */ error NativeTransferFailed(); /** * @dev Insufficient amount out */ error InsufficientAmountOut(); /** * @dev Insufficient amount to sync */ error InsufficientAmountToSync(); /** * @dev Unauthorized token */ error UnauthorizedToken(); /** * @dev Invalid amount in */ error InvalidAmountIn(); /** * @dev Max sync amount exceeded, to prevent going over the bridge limit */ error MaxSyncAmountExceeded(); /** * @dev Unsupported destination chain */ error UnsupportedEid(); /** * @dev Multichain eposits can't be wrapped */ error MultichainDepositsCannotBeWrapped(); /** * @dev OFT lockbox not set for multichain deposit */ error OFTLockboxNotSet(); /** * @dev Invalid receiver address */ error InvalidReceiver(); }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import {IL2ExchangeRateProvider} from "contracts/vendor/layerzero/syncpools/interfaces/IL2ExchangeRateProvider.sol"; interface IRateProvider is IL2ExchangeRateProvider { function getConversionAmount( address tokenIn, uint256 amountIn ) external returns (uint256 amountOut); function getAssetsPerShare() external returns (uint256 assetsPerShare); }
//SPDX-License-Identifier: MIT pragma solidity ^0.8.0; interface IWrappedLiquidStakedToken { function wrap(uint256 _amount) external returns (uint256); function unwrap(uint256 _amount) external returns (uint256); function getLSTAddress() external view returns (address); function transfer(address recipient, uint256 amount) external returns (bool); }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import { SafeERC20, IERC20 } from "@openzeppelin/contracts/token/ERC20/utils/SafeERC20.sol"; import { MessagingParams, MessagingFee, MessagingReceipt } from "contracts/vendor/layerzero/protocol/interfaces/ILayerZeroEndpointV2.sol"; import { OAppCoreUpgradeable } from "./OAppCoreUpgradeable.sol"; /** * @title OAppSender * @dev Abstract contract implementing the OAppSender functionality for sending messages to a LayerZero endpoint. */ abstract contract OAppSenderUpgradeable is OAppCoreUpgradeable { using SafeERC20 for IERC20; // Custom error messages error NotEnoughNative(uint256 msgValue); error LzTokenUnavailable(); // @dev The version of the OAppSender implementation. // @dev Version is bumped when changes are made to this contract. uint64 internal constant SENDER_VERSION = 1; /** * @dev Ownable is not initialized here on purpose. It should be initialized in the child contract to * accommodate the different version of Ownable. */ function __OAppSender_init() internal onlyInitializing {} function __OAppSender_init_unchained() internal onlyInitializing {} /** * @notice Retrieves the OApp version information. * @return senderVersion The version of the OAppSender.sol contract. * @return receiverVersion The version of the OAppReceiver.sol contract. * * @dev Providing 0 as the default for OAppReceiver version. Indicates that the OAppReceiver is not implemented. * ie. this is a SEND only OApp. * @dev If the OApp uses both OAppSender and OAppReceiver, then this needs to be override returning the correct versions */ function oAppVersion() public view virtual returns (uint64 senderVersion, uint64 receiverVersion) { return (SENDER_VERSION, 0); } /** * @dev Internal function to interact with the LayerZero EndpointV2.quote() for fee calculation. * @param _dstEid The destination endpoint ID. * @param _message The message payload. * @param _options Additional options for the message. * @param _payInLzToken Flag indicating whether to pay the fee in LZ tokens. * @return fee The calculated MessagingFee for the message. * - nativeFee: The native fee for the message. * - lzTokenFee: The LZ token fee for the message. */ function _quote( uint32 _dstEid, bytes memory _message, bytes memory _options, bool _payInLzToken ) internal view virtual returns (MessagingFee memory fee) { return endpoint.quote( MessagingParams(_dstEid, _getPeerOrRevert(_dstEid), _message, _options, _payInLzToken), address(this) ); } /** * @dev Internal function to interact with the LayerZero EndpointV2.send() for sending a message. * @param _dstEid The destination endpoint ID. * @param _message The message payload. * @param _options Additional options for the message. * @param _fee The calculated LayerZero fee for the message. * - nativeFee: The native fee. * - lzTokenFee: The lzToken fee. * @param _refundAddress The address to receive any excess fee values sent to the endpoint. * @return receipt The receipt for the sent message. * - guid: The unique identifier for the sent message. * - nonce: The nonce of the sent message. * - fee: The LayerZero fee incurred for the message. */ function _lzSend( uint32 _dstEid, bytes memory _message, bytes memory _options, MessagingFee memory _fee, address _refundAddress ) internal virtual returns (MessagingReceipt memory receipt) { // @dev Push corresponding fees to the endpoint, any excess is sent back to the _refundAddress from the endpoint. uint256 messageValue = _payNative(_fee.nativeFee); if (_fee.lzTokenFee > 0) _payLzToken(_fee.lzTokenFee); return endpoint.send{ value: messageValue }( // solhint-disable-next-line check-send-result MessagingParams(_dstEid, _getPeerOrRevert(_dstEid), _message, _options, _fee.lzTokenFee > 0), _refundAddress ); } /** * @dev Internal function to pay the native fee associated with the message. * @param _nativeFee The native fee to be paid. * @return nativeFee The amount of native currency paid. * * @dev If the OApp needs to initiate MULTIPLE LayerZero messages in a single transaction, * this will need to be overridden because msg.value would contain multiple lzFees. * @dev Should be overridden in the event the LayerZero endpoint requires a different native currency. * @dev Some EVMs use an ERC20 as a method for paying transactions/gasFees. * @dev The endpoint is EITHER/OR, ie. it will NOT support both types of native payment at a time. */ function _payNative(uint256 _nativeFee) internal virtual returns (uint256 nativeFee) { if (msg.value != _nativeFee) revert NotEnoughNative(msg.value); return _nativeFee; } /** * @dev Internal function to pay the LZ token fee associated with the message. * @param _lzTokenFee The LZ token fee to be paid. * * @dev If the caller is trying to pay in the specified lzToken, then the lzTokenFee is passed to the endpoint. * @dev Any excess sent, is passed back to the specified _refundAddress in the _lzSend(). */ function _payLzToken(uint256 _lzTokenFee) internal virtual { // @dev Cannot cache the token because it is not immutable in the endpoint. address lzToken = endpoint.lzToken(); if (lzToken == address(0)) revert LzTokenUnavailable(); // Pay LZ token fee by sending tokens to the endpoint. IERC20(lzToken).safeTransferFrom(msg.sender, address(endpoint), _lzTokenFee); } }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; // @dev Import the 'MessagingFee' and 'MessagingReceipt' so it's exposed to OApp implementers // solhint-disable-next-line no-unused-import import { OAppSenderUpgradeable, MessagingFee, MessagingReceipt } from "./OAppSenderUpgradeable.sol"; // @dev Import the 'Origin' so it's exposed to OApp implementers // solhint-disable-next-line no-unused-import import { OAppReceiverUpgradeable, Origin } from "./OAppReceiverUpgradeable.sol"; import { OAppCoreUpgradeable } from "./OAppCoreUpgradeable.sol"; /** * @title OApp * @dev Abstract contract serving as the base for OApp implementation, combining OAppSender and OAppReceiver functionality. */ abstract contract OAppUpgradeable is OAppSenderUpgradeable, OAppReceiverUpgradeable { /** * @dev Constructor to initialize the OApp with the provided endpoint and owner. * @param _endpoint The address of the LOCAL LayerZero endpoint. */ /// @custom:oz-upgrades-unsafe-allow constructor constructor(address _endpoint) OAppCoreUpgradeable(_endpoint) {} /** * @dev Initializes the OApp with the provided delegate. * @param _delegate The delegate capable of making OApp configurations inside of the endpoint. * * @dev The delegate typically should be set as the owner of the contract. * @dev Ownable is not initialized here on purpose. It should be initialized in the child contract to * accommodate the different version of Ownable. */ function __OApp_init(address _delegate) internal onlyInitializing { __OAppCore_init(_delegate); } function __OApp_init_unchained() internal onlyInitializing {} /** * @notice Retrieves the OApp version information. * @return senderVersion The version of the OAppSender.sol implementation. * @return receiverVersion The version of the OAppReceiver.sol implementation. */ function oAppVersion() public pure virtual override(OAppSenderUpgradeable, OAppReceiverUpgradeable) returns (uint64 senderVersion, uint64 receiverVersion) { return (SENDER_VERSION, RECEIVER_VERSION); } }
// SPDX-License-Identifier: LZBL-1.2 pragma solidity ^0.8.20; interface IRateLimiter { function updateRateLimit(address sender, address tokenIn, uint256 amountIn, uint256 amountOut) external; }
// SPDX-License-Identifier: LZBL-1.2 pragma solidity ^0.8.20; import {OwnableUpgradeable} from "@openzeppelin/contracts-upgradeable/access/OwnableUpgradeable.sol"; /** * @title Base Messenger * @dev Base contract for setting the messenger contract */ abstract contract BaseMessengerUpgradeable is OwnableUpgradeable { struct BaseMessengerStorage { address messenger; } // keccak256(abi.encode(uint256(keccak256(syncpools.storage.basemessenger)) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant BaseMessengerStorageLocation = 0x2d365d82646798ae645c4baa2dc2ee228626f61d8b5395bf298ba125a3c6b100; function _getBaseMessengerStorage() internal pure returns (BaseMessengerStorage storage $) { assembly { $.slot := BaseMessengerStorageLocation } } event MessengerSet(address messenger); function __BaseMessenger_init(address messenger) internal onlyInitializing { __BaseMessenger_init_unchained(messenger); } function __BaseMessenger_init_unchained(address messenger) internal onlyInitializing { _setMessenger(messenger); } /** * @dev Get the messenger address * @return The messenger address */ function getMessenger() public view virtual returns (address) { BaseMessengerStorage storage $ = _getBaseMessengerStorage(); return $.messenger; } /** * @dev Set the messenger address * @param messenger The messenger address */ function setMessenger(address messenger) public virtual onlyOwner { _setMessenger(messenger); } /** * @dev Internal function to set the messenger address * @param messenger The messenger address */ function _setMessenger(address messenger) internal { BaseMessengerStorage storage $ = _getBaseMessengerStorage(); $.messenger = messenger; emit MessengerSet(messenger); } }
// SPDX-License-Identifier: LZBL-1.2 pragma solidity ^0.8.20; import {OwnableUpgradeable} from "@openzeppelin/contracts-upgradeable/access/OwnableUpgradeable.sol"; /** * @title Base Receiver * @dev Base contract for setting the receiver contract */ abstract contract BaseReceiverUpgradeable is OwnableUpgradeable { struct BaseReceiverStorage { address receiver; } // keccak256(abi.encode(uint256(keccak256(syncpools.storage.basereceiver)) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant BaseReceiverStorageLocation = 0x487698e326934c06370ca3c28e3bca79fe27d578048e9d42af7fa98f2e481e00; function _getBaseReceiverStorage() internal pure returns (BaseReceiverStorage storage $) { assembly { $.slot := BaseReceiverStorageLocation } } event ReceiverSet(address receiver); function __BaseReceiver_init(address receiver) internal onlyInitializing { __BaseReceiver_init_unchained(receiver); } function __BaseReceiver_init_unchained(address receiver) internal onlyInitializing { _setReceiver(receiver); } /** * @dev Get the receiver address * @return The receiver address */ function getReceiver() public view virtual returns (address) { BaseReceiverStorage storage $ = _getBaseReceiverStorage(); return $.receiver; } /** * @dev Set the receiver address * @param receiver The receiver address */ function setReceiver(address receiver) public virtual onlyOwner { _setReceiver(receiver); } /** * @dev Internal function to set the receiver address * @param receiver The receiver address */ function _setReceiver(address receiver) internal { BaseReceiverStorage storage $ = _getBaseReceiverStorage(); $.receiver = receiver; emit ReceiverSet(receiver); } }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import { OwnableUpgradeable } from "@openzeppelin/contracts-upgradeable/access/OwnableUpgradeable.sol"; import { IOAppOptionsType3, EnforcedOptionParam } from "../interfaces/IOAppOptionsType3.sol"; /** * @title OAppOptionsType3 * @dev Abstract contract implementing the IOAppOptionsType3 interface with type 3 options. */ abstract contract OAppOptionsType3Upgradeable is IOAppOptionsType3, OwnableUpgradeable { struct OAppOptionsType3Storage { // @dev The "msgType" should be defined in the child contract. mapping(uint32 => mapping(uint16 => bytes)) enforcedOptions; } // keccak256(abi.encode(uint256(keccak256("layerzerov2.storage.oappoptionstype3")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant OAppOptionsType3StorageLocation = 0x8d2bda5d9f6ffb5796910376005392955773acee5548d0fcdb10e7c264ea0000; uint16 internal constant OPTION_TYPE_3 = 3; function _getOAppOptionsType3Storage() internal pure returns (OAppOptionsType3Storage storage $) { assembly { $.slot := OAppOptionsType3StorageLocation } } /** * @dev Ownable is not initialized here on purpose. It should be initialized in the child contract to * accommodate the different version of Ownable. */ function __OAppOptionsType3_init() internal onlyInitializing {} function __OAppOptionsType3_init_unchained() internal onlyInitializing {} function enforcedOptions(uint32 _eid, uint16 _msgType) public view returns (bytes memory) { OAppOptionsType3Storage storage $ = _getOAppOptionsType3Storage(); return $.enforcedOptions[_eid][_msgType]; } /** * @dev Sets the enforced options for specific endpoint and message type combinations. * @param _enforcedOptions An array of EnforcedOptionParam structures specifying enforced options. * * @dev Only the owner/admin of the OApp can call this function. * @dev Provides a way for the OApp to enforce things like paying for PreCrime, AND/OR minimum dst lzReceive gas amounts etc. * @dev These enforced options can vary as the potential options/execution on the remote may differ as per the msgType. * eg. Amount of lzReceive() gas necessary to deliver a lzCompose() message adds overhead you dont want to pay * if you are only making a standard LayerZero message ie. lzReceive() WITHOUT sendCompose(). */ function setEnforcedOptions(EnforcedOptionParam[] calldata _enforcedOptions) public virtual onlyOwner { OAppOptionsType3Storage storage $ = _getOAppOptionsType3Storage(); for (uint256 i = 0; i < _enforcedOptions.length; i++) { // @dev Enforced options are only available for optionType 3, as type 1 and 2 dont support combining. _assertOptionsType3(_enforcedOptions[i].options); $.enforcedOptions[_enforcedOptions[i].eid][_enforcedOptions[i].msgType] = _enforcedOptions[i].options; } emit EnforcedOptionSet(_enforcedOptions); } /** * @notice Combines options for a given endpoint and message type. * @param _eid The endpoint ID. * @param _msgType The OAPP message type. * @param _extraOptions Additional options passed by the caller. * @return options The combination of caller specified options AND enforced options. * * @dev If there is an enforced lzReceive option: * - {gasLimit: 200k, msg.value: 1 ether} AND a caller supplies a lzReceive option: {gasLimit: 100k, msg.value: 0.5 ether} * - The resulting options will be {gasLimit: 300k, msg.value: 1.5 ether} when the message is executed on the remote lzReceive() function. * @dev This presence of duplicated options is handled off-chain in the verifier/executor. */ function combineOptions( uint32 _eid, uint16 _msgType, bytes calldata _extraOptions ) public view virtual returns (bytes memory) { OAppOptionsType3Storage storage $ = _getOAppOptionsType3Storage(); bytes memory enforced = $.enforcedOptions[_eid][_msgType]; // No enforced options, pass whatever the caller supplied, even if it's empty or legacy type 1/2 options. if (enforced.length == 0) return _extraOptions; // No caller options, return enforced if (_extraOptions.length == 0) return enforced; // @dev If caller provided _extraOptions, must be type 3 as its the ONLY type that can be combined. if (_extraOptions.length >= 2) { _assertOptionsType3(_extraOptions); // @dev Remove the first 2 bytes containing the type from the _extraOptions and combine with enforced. return bytes.concat(enforced, _extraOptions[2:]); } // No valid set of options was found. revert InvalidOptions(_extraOptions); } /** * @dev Internal function to assert that options are of type 3. * @param _options The options to be checked. */ function _assertOptionsType3(bytes calldata _options) internal pure virtual { uint16 optionsType = uint16(bytes2(_options[0:2])); if (optionsType != OPTION_TYPE_3) revert InvalidOptions(_options); } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/Pausable.sol) pragma solidity ^0.8.20; import {ContextUpgradeable} from "../utils/ContextUpgradeable.sol"; import {Initializable} from "../proxy/utils/Initializable.sol"; /** * @dev Contract module which allows children to implement an emergency stop * mechanism that can be triggered by an authorized account. * * This module is used through inheritance. It will make available the * modifiers `whenNotPaused` and `whenPaused`, which can be applied to * the functions of your contract. Note that they will not be pausable by * simply including this module, only once the modifiers are put in place. */ abstract contract PausableUpgradeable is Initializable, ContextUpgradeable { /// @custom:storage-location erc7201:openzeppelin.storage.Pausable struct PausableStorage { bool _paused; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.Pausable")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant PausableStorageLocation = 0xcd5ed15c6e187e77e9aee88184c21f4f2182ab5827cb3b7e07fbedcd63f03300; function _getPausableStorage() private pure returns (PausableStorage storage $) { assembly { $.slot := PausableStorageLocation } } /** * @dev Emitted when the pause is triggered by `account`. */ event Paused(address account); /** * @dev Emitted when the pause is lifted by `account`. */ event Unpaused(address account); /** * @dev The operation failed because the contract is paused. */ error EnforcedPause(); /** * @dev The operation failed because the contract is not paused. */ error ExpectedPause(); /** * @dev Initializes the contract in unpaused state. */ function __Pausable_init() internal onlyInitializing { __Pausable_init_unchained(); } function __Pausable_init_unchained() internal onlyInitializing { PausableStorage storage $ = _getPausableStorage(); $._paused = false; } /** * @dev Modifier to make a function callable only when the contract is not paused. * * Requirements: * * - The contract must not be paused. */ modifier whenNotPaused() { _requireNotPaused(); _; } /** * @dev Modifier to make a function callable only when the contract is paused. * * Requirements: * * - The contract must be paused. */ modifier whenPaused() { _requirePaused(); _; } /** * @dev Returns true if the contract is paused, and false otherwise. */ function paused() public view virtual returns (bool) { PausableStorage storage $ = _getPausableStorage(); return $._paused; } /** * @dev Throws if the contract is paused. */ function _requireNotPaused() internal view virtual { if (paused()) { revert EnforcedPause(); } } /** * @dev Throws if the contract is not paused. */ function _requirePaused() internal view virtual { if (!paused()) { revert ExpectedPause(); } } /** * @dev Triggers stopped state. * * Requirements: * * - The contract must not be paused. */ function _pause() internal virtual whenNotPaused { PausableStorage storage $ = _getPausableStorage(); $._paused = true; emit Paused(_msgSender()); } /** * @dev Returns to normal state. * * Requirements: * * - The contract must be paused. */ function _unpause() internal virtual whenPaused { PausableStorage storage $ = _getPausableStorage(); $._paused = false; emit Unpaused(_msgSender()); } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.1.0) (utils/ReentrancyGuard.sol) pragma solidity ^0.8.20; import {Initializable} from "../proxy/utils/Initializable.sol"; /** * @dev Contract module that helps prevent reentrant calls to a function. * * Inheriting from `ReentrancyGuard` will make the {nonReentrant} modifier * available, which can be applied to functions to make sure there are no nested * (reentrant) calls to them. * * Note that because there is a single `nonReentrant` guard, functions marked as * `nonReentrant` may not call one another. This can be worked around by making * those functions `private`, and then adding `external` `nonReentrant` entry * points to them. * * TIP: If EIP-1153 (transient storage) is available on the chain you're deploying at, * consider using {ReentrancyGuardTransient} instead. * * TIP: If you would like to learn more about reentrancy and alternative ways * to protect against it, check out our blog post * https://blog.openzeppelin.com/reentrancy-after-istanbul/[Reentrancy After Istanbul]. */ abstract contract ReentrancyGuardUpgradeable is Initializable { // Booleans are more expensive than uint256 or any type that takes up a full // word because each write operation emits an extra SLOAD to first read the // slot's contents, replace the bits taken up by the boolean, and then write // back. This is the compiler's defense against contract upgrades and // pointer aliasing, and it cannot be disabled. // The values being non-zero value makes deployment a bit more expensive, // but in exchange the refund on every call to nonReentrant will be lower in // amount. Since refunds are capped to a percentage of the total // transaction's gas, it is best to keep them low in cases like this one, to // increase the likelihood of the full refund coming into effect. uint256 private constant NOT_ENTERED = 1; uint256 private constant ENTERED = 2; /// @custom:storage-location erc7201:openzeppelin.storage.ReentrancyGuard struct ReentrancyGuardStorage { uint256 _status; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.ReentrancyGuard")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant ReentrancyGuardStorageLocation = 0x9b779b17422d0df92223018b32b4d1fa46e071723d6817e2486d003becc55f00; function _getReentrancyGuardStorage() private pure returns (ReentrancyGuardStorage storage $) { assembly { $.slot := ReentrancyGuardStorageLocation } } /** * @dev Unauthorized reentrant call. */ error ReentrancyGuardReentrantCall(); function __ReentrancyGuard_init() internal onlyInitializing { __ReentrancyGuard_init_unchained(); } function __ReentrancyGuard_init_unchained() internal onlyInitializing { ReentrancyGuardStorage storage $ = _getReentrancyGuardStorage(); $._status = NOT_ENTERED; } /** * @dev Prevents a contract from calling itself, directly or indirectly. * Calling a `nonReentrant` function from another `nonReentrant` * function is not supported. It is possible to prevent this from happening * by making the `nonReentrant` function external, and making it call a * `private` function that does the actual work. */ modifier nonReentrant() { _nonReentrantBefore(); _; _nonReentrantAfter(); } function _nonReentrantBefore() private { ReentrancyGuardStorage storage $ = _getReentrancyGuardStorage(); // On the first call to nonReentrant, _status will be NOT_ENTERED if ($._status == ENTERED) { revert ReentrancyGuardReentrantCall(); } // Any calls to nonReentrant after this point will fail $._status = ENTERED; } function _nonReentrantAfter() private { ReentrancyGuardStorage storage $ = _getReentrancyGuardStorage(); // By storing the original value once again, a refund is triggered (see // https://eips.ethereum.org/EIPS/eip-2200) $._status = NOT_ENTERED; } /** * @dev Returns true if the reentrancy guard is currently set to "entered", which indicates there is a * `nonReentrant` function in the call stack. */ function _reentrancyGuardEntered() internal view returns (bool) { ReentrancyGuardStorage storage $ = _getReentrancyGuardStorage(); return $._status == ENTERED; } }
// SPDX-License-Identifier: AGPL-3.0-only pragma solidity >=0.8.0; /// @notice Arithmetic library with operations for fixed-point numbers. /// @author Solmate (https://github.com/transmissions11/solmate/blob/main/src/utils/FixedPointMathLib.sol) /// @author Inspired by USM (https://github.com/usmfum/USM/blob/master/contracts/WadMath.sol) library FixedPointMathLib { /*////////////////////////////////////////////////////////////// SIMPLIFIED FIXED POINT OPERATIONS //////////////////////////////////////////////////////////////*/ uint256 internal constant MAX_UINT256 = 2**256 - 1; uint256 internal constant WAD = 1e18; // The scalar of ETH and most ERC20s. function mulWadDown(uint256 x, uint256 y) internal pure returns (uint256) { return mulDivDown(x, y, WAD); // Equivalent to (x * y) / WAD rounded down. } function mulWadUp(uint256 x, uint256 y) internal pure returns (uint256) { return mulDivUp(x, y, WAD); // Equivalent to (x * y) / WAD rounded up. } function divWadDown(uint256 x, uint256 y) internal pure returns (uint256) { return mulDivDown(x, WAD, y); // Equivalent to (x * WAD) / y rounded down. } function divWadUp(uint256 x, uint256 y) internal pure returns (uint256) { return mulDivUp(x, WAD, y); // Equivalent to (x * WAD) / y rounded up. } /*////////////////////////////////////////////////////////////// LOW LEVEL FIXED POINT OPERATIONS //////////////////////////////////////////////////////////////*/ function mulDivDown( uint256 x, uint256 y, uint256 denominator ) internal pure returns (uint256 z) { /// @solidity memory-safe-assembly assembly { // Equivalent to require(denominator != 0 && (y == 0 || x <= type(uint256).max / y)) if iszero(mul(denominator, iszero(mul(y, gt(x, div(MAX_UINT256, y)))))) { revert(0, 0) } // Divide x * y by the denominator. z := div(mul(x, y), denominator) } } function mulDivUp( uint256 x, uint256 y, uint256 denominator ) internal pure returns (uint256 z) { /// @solidity memory-safe-assembly assembly { // Equivalent to require(denominator != 0 && (y == 0 || x <= type(uint256).max / y)) if iszero(mul(denominator, iszero(mul(y, gt(x, div(MAX_UINT256, y)))))) { revert(0, 0) } // If x * y modulo the denominator is strictly greater than 0, // 1 is added to round up the division of x * y by the denominator. z := add(gt(mod(mul(x, y), denominator), 0), div(mul(x, y), denominator)) } } function rpow( uint256 x, uint256 n, uint256 scalar ) internal pure returns (uint256 z) { /// @solidity memory-safe-assembly assembly { switch x case 0 { switch n case 0 { // 0 ** 0 = 1 z := scalar } default { // 0 ** n = 0 z := 0 } } default { switch mod(n, 2) case 0 { // If n is even, store scalar in z for now. z := scalar } default { // If n is odd, store x in z for now. z := x } // Shifting right by 1 is like dividing by 2. let half := shr(1, scalar) for { // Shift n right by 1 before looping to halve it. n := shr(1, n) } n { // Shift n right by 1 each iteration to halve it. n := shr(1, n) } { // Revert immediately if x ** 2 would overflow. // Equivalent to iszero(eq(div(xx, x), x)) here. if shr(128, x) { revert(0, 0) } // Store x squared. let xx := mul(x, x) // Round to the nearest number. let xxRound := add(xx, half) // Revert if xx + half overflowed. if lt(xxRound, xx) { revert(0, 0) } // Set x to scaled xxRound. x := div(xxRound, scalar) // If n is even: if mod(n, 2) { // Compute z * x. let zx := mul(z, x) // If z * x overflowed: if iszero(eq(div(zx, x), z)) { // Revert if x is non-zero. if iszero(iszero(x)) { revert(0, 0) } } // Round to the nearest number. let zxRound := add(zx, half) // Revert if zx + half overflowed. if lt(zxRound, zx) { revert(0, 0) } // Return properly scaled zxRound. z := div(zxRound, scalar) } } } } } /*////////////////////////////////////////////////////////////// GENERAL NUMBER UTILITIES //////////////////////////////////////////////////////////////*/ function sqrt(uint256 x) internal pure returns (uint256 z) { /// @solidity memory-safe-assembly assembly { let y := x // We start y at x, which will help us make our initial estimate. z := 181 // The "correct" value is 1, but this saves a multiplication later. // This segment is to get a reasonable initial estimate for the Babylonian method. With a bad // start, the correct # of bits increases ~linearly each iteration instead of ~quadratically. // We check y >= 2^(k + 8) but shift right by k bits // each branch to ensure that if x >= 256, then y >= 256. if iszero(lt(y, 0x10000000000000000000000000000000000)) { y := shr(128, y) z := shl(64, z) } if iszero(lt(y, 0x1000000000000000000)) { y := shr(64, y) z := shl(32, z) } if iszero(lt(y, 0x10000000000)) { y := shr(32, y) z := shl(16, z) } if iszero(lt(y, 0x1000000)) { y := shr(16, y) z := shl(8, z) } // Goal was to get z*z*y within a small factor of x. More iterations could // get y in a tighter range. Currently, we will have y in [256, 256*2^16). // We ensured y >= 256 so that the relative difference between y and y+1 is small. // That's not possible if x < 256 but we can just verify those cases exhaustively. // Now, z*z*y <= x < z*z*(y+1), and y <= 2^(16+8), and either y >= 256, or x < 256. // Correctness can be checked exhaustively for x < 256, so we assume y >= 256. // Then z*sqrt(y) is within sqrt(257)/sqrt(256) of sqrt(x), or about 20bps. // For s in the range [1/256, 256], the estimate f(s) = (181/1024) * (s+1) is in the range // (1/2.84 * sqrt(s), 2.84 * sqrt(s)), with largest error when s = 1 and when s = 256 or 1/256. // Since y is in [256, 256*2^16), let a = y/65536, so that a is in [1/256, 256). Then we can estimate // sqrt(y) using sqrt(65536) * 181/1024 * (a + 1) = 181/4 * (y + 65536)/65536 = 181 * (y + 65536)/2^18. // There is no overflow risk here since y < 2^136 after the first branch above. z := shr(18, mul(z, add(y, 65536))) // A mul() is saved from starting z at 181. // Given the worst case multiplicative error of 2.84 above, 7 iterations should be enough. z := shr(1, add(z, div(x, z))) z := shr(1, add(z, div(x, z))) z := shr(1, add(z, div(x, z))) z := shr(1, add(z, div(x, z))) z := shr(1, add(z, div(x, z))) z := shr(1, add(z, div(x, z))) z := shr(1, add(z, div(x, z))) // If x+1 is a perfect square, the Babylonian method cycles between // floor(sqrt(x)) and ceil(sqrt(x)). This statement ensures we return floor. // See: https://en.wikipedia.org/wiki/Integer_square_root#Using_only_integer_division // Since the ceil is rare, we save gas on the assignment and repeat division in the rare case. // If you don't care whether the floor or ceil square root is returned, you can remove this statement. z := sub(z, lt(div(x, z), z)) } } function unsafeMod(uint256 x, uint256 y) internal pure returns (uint256 z) { /// @solidity memory-safe-assembly assembly { // Mod x by y. Note this will return // 0 instead of reverting if y is zero. z := mod(x, y) } } function unsafeDiv(uint256 x, uint256 y) internal pure returns (uint256 r) { /// @solidity memory-safe-assembly assembly { // Divide x by y. Note this will return // 0 instead of reverting if y is zero. r := div(x, y) } } function unsafeDivUp(uint256 x, uint256 y) internal pure returns (uint256 z) { /// @solidity memory-safe-assembly assembly { // Add 1 to x * y if x % y > 0. Note this will // return 0 instead of reverting if y is zero. z := add(gt(mod(x, y), 0), div(x, y)) } } }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; interface IBridgeQuoter { function getAmountOut( address token, uint256 amountIn ) external view returns (uint256 amountSent, uint256 amountReceived); }
// SPDX-License-Identifier: MIT pragma solidity >=0.8.0; import { Origin } from "./ILayerZeroEndpointV2.sol"; interface ILayerZeroReceiver { function allowInitializePath(Origin calldata _origin) external view returns (bool); function nextNonce(uint32 _eid, bytes32 _sender) external view returns (uint64); function lzReceive( Origin calldata _origin, bytes32 _guid, bytes calldata _message, address _executor, bytes calldata _extraData ) external payable; }
// SPDX-License-Identifier: MIT pragma solidity >=0.8.0; import { IMessageLibManager } from "./IMessageLibManager.sol"; import { IMessagingComposer } from "./IMessagingComposer.sol"; import { IMessagingChannel } from "./IMessagingChannel.sol"; import { IMessagingContext } from "./IMessagingContext.sol"; struct MessagingParams { uint32 dstEid; bytes32 receiver; bytes message; bytes options; bool payInLzToken; } struct MessagingReceipt { bytes32 guid; uint64 nonce; MessagingFee fee; } struct MessagingFee { uint256 nativeFee; uint256 lzTokenFee; } struct Origin { uint32 srcEid; bytes32 sender; uint64 nonce; } interface ILayerZeroEndpointV2 is IMessageLibManager, IMessagingComposer, IMessagingChannel, IMessagingContext { event PacketSent(bytes encodedPayload, bytes options, address sendLibrary); event PacketVerified(Origin origin, address receiver, bytes32 payloadHash); event PacketDelivered(Origin origin, address receiver); event LzReceiveAlert( address indexed receiver, address indexed executor, Origin origin, bytes32 guid, uint256 gas, uint256 value, bytes message, bytes extraData, bytes reason ); event LzTokenSet(address token); event DelegateSet(address sender, address delegate); function quote(MessagingParams calldata _params, address _sender) external view returns (MessagingFee memory); function send( MessagingParams calldata _params, address _refundAddress ) external payable returns (MessagingReceipt memory); function verify(Origin calldata _origin, address _receiver, bytes32 _payloadHash) external; function verifiable(Origin calldata _origin, address _receiver) external view returns (bool); function initializable(Origin calldata _origin, address _receiver) external view returns (bool); function lzReceive( Origin calldata _origin, address _receiver, bytes32 _guid, bytes calldata _message, bytes calldata _extraData ) external payable; // oapp can burn messages partially by calling this function with its own business logic if messages are verified in order function clear(address _oapp, Origin calldata _origin, bytes32 _guid, bytes calldata _message) external; function setLzToken(address _lzToken) external; function lzToken() external view returns (address); function nativeToken() external view returns (address); function setDelegate(address _delegate) external; }
// SPDX-License-Identifier: LZBL-1.2 pragma solidity ^0.8.20; interface IL2ExchangeRateProvider { function getConversionAmount(address tokenIn, uint256 amountIn) external returns (uint256 amountOut); function getPostFeeAmount(address tokenIn, uint256 amountIn) external view returns (uint256); }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; /** * @dev Struct representing enforced option parameters. */ struct EnforcedOptionParam { uint32 eid; // Endpoint ID uint16 msgType; // Message Type bytes options; // Additional options } /** * @title IOAppOptionsType3 * @dev Interface for the OApp with Type 3 Options, allowing the setting and combining of enforced options. */ interface IOAppOptionsType3 { // Custom error message for invalid options error InvalidOptions(bytes options); // Event emitted when enforced options are set event EnforcedOptionSet(EnforcedOptionParam[] _enforcedOptions); /** * @notice Sets enforced options for specific endpoint and message type combinations. * @param _enforcedOptions An array of EnforcedOptionParam structures specifying enforced options. */ function setEnforcedOptions(EnforcedOptionParam[] calldata _enforcedOptions) external; /** * @notice Combines options for a given endpoint and message type. * @param _eid The endpoint ID. * @param _msgType The OApp message type. * @param _extraOptions Additional options passed by the caller. * @return options The combination of caller specified options AND enforced options. */ function combineOptions( uint32 _eid, uint16 _msgType, bytes calldata _extraOptions ) external view returns (bytes memory options); }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import { OwnableUpgradeable } from "@openzeppelin/contracts-upgradeable/access/OwnableUpgradeable.sol"; import { IOAppCore, ILayerZeroEndpointV2 } from "./interfaces/IOAppCore.sol"; /** * @title OAppCore * @dev Abstract contract implementing the IOAppCore interface with basic OApp configurations. */ abstract contract OAppCoreUpgradeable is IOAppCore, OwnableUpgradeable { struct OAppCoreStorage { mapping(uint32 => bytes32) peers; } // keccak256(abi.encode(uint256(keccak256("layerzerov2.storage.oappcore")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant OAppCoreStorageLocation = 0x72ab1bc1039b79dc4724ffca13de82c96834302d3c7e0d4252232d4b2dd8f900; function _getOAppCoreStorage() internal pure returns (OAppCoreStorage storage $) { assembly { $.slot := OAppCoreStorageLocation } } // The LayerZero endpoint associated with the given OApp /// @custom:oz-upgrades-unsafe-allow state-variable-immutable ILayerZeroEndpointV2 public immutable endpoint; /** * @dev Constructor to initialize the OAppCore with the provided endpoint and delegate. * @param _endpoint The address of the LOCAL Layer Zero endpoint. */ /// @custom:oz-upgrades-unsafe-allow constructor constructor(address _endpoint) { endpoint = ILayerZeroEndpointV2(_endpoint); } /** * @dev Initializes the OAppCore with the provided delegate. * @param _delegate The delegate capable of making OApp configurations inside of the endpoint. * * @dev The delegate typically should be set as the owner of the contract. * @dev Ownable is not initialized here on purpose. It should be initialized in the child contract to * accommodate the different version of Ownable. */ function __OAppCore_init(address _delegate) internal onlyInitializing { __OAppCore_init_unchained(_delegate); } function __OAppCore_init_unchained(address _delegate) internal onlyInitializing { if (_delegate == address(0)) revert InvalidDelegate(); endpoint.setDelegate(_delegate); } /** * @notice Returns the peer address (OApp instance) associated with a specific endpoint. * @param _eid The endpoint ID. * @return peer The address of the peer associated with the specified endpoint. */ function peers(uint32 _eid) public view override returns (bytes32) { OAppCoreStorage storage $ = _getOAppCoreStorage(); return $.peers[_eid]; } /** * @notice Sets the peer address (OApp instance) for a corresponding endpoint. * @param _eid The endpoint ID. * @param _peer The address of the peer to be associated with the corresponding endpoint. * * @dev Only the owner/admin of the OApp can call this function. * @dev Indicates that the peer is trusted to send LayerZero messages to this OApp. * @dev Set this to bytes32(0) to remove the peer address. * @dev Peer is a bytes32 to accommodate non-evm chains. */ function setPeer(uint32 _eid, bytes32 _peer) public virtual onlyOwner { OAppCoreStorage storage $ = _getOAppCoreStorage(); $.peers[_eid] = _peer; emit PeerSet(_eid, _peer); } /** * @notice Internal function to get the peer address associated with a specific endpoint; reverts if NOT set. * ie. the peer is set to bytes32(0). * @param _eid The endpoint ID. * @return peer The address of the peer associated with the specified endpoint. */ function _getPeerOrRevert(uint32 _eid) internal view virtual returns (bytes32) { OAppCoreStorage storage $ = _getOAppCoreStorage(); bytes32 peer = $.peers[_eid]; if (peer == bytes32(0)) revert NoPeer(_eid); return peer; } /** * @notice Sets the delegate address for the OApp. * @param _delegate The address of the delegate to be set. * * @dev Only the owner/admin of the OApp can call this function. * @dev Provides the ability for a delegate to set configs, on behalf of the OApp, directly on the Endpoint contract. */ function setDelegate(address _delegate) public onlyOwner { endpoint.setDelegate(_delegate); } }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import { IOAppReceiver, Origin } from "./interfaces/IOAppReceiver.sol"; import { OAppCoreUpgradeable } from "./OAppCoreUpgradeable.sol"; /** * @title OAppReceiver * @dev Abstract contract implementing the ILayerZeroReceiver interface and extending OAppCore for OApp receivers. */ abstract contract OAppReceiverUpgradeable is IOAppReceiver, OAppCoreUpgradeable { // Custom error message for when the caller is not the registered endpoint/ error OnlyEndpoint(address addr); // @dev The version of the OAppReceiver implementation. // @dev Version is bumped when changes are made to this contract. uint64 internal constant RECEIVER_VERSION = 1; /** * @dev Ownable is not initialized here on purpose. It should be initialized in the child contract to * accommodate the different version of Ownable. */ function __OAppReceiver_init() internal onlyInitializing {} function __OAppReceiver_init_unchained() internal onlyInitializing {} /** * @notice Retrieves the OApp version information. * @return senderVersion The version of the OAppSender.sol contract. * @return receiverVersion The version of the OAppReceiver.sol contract. * * @dev Providing 0 as the default for OAppSender version. Indicates that the OAppSender is not implemented. * ie. this is a RECEIVE only OApp. * @dev If the OApp uses both OAppSender and OAppReceiver, then this needs to be override returning the correct versions. */ function oAppVersion() public view virtual returns (uint64 senderVersion, uint64 receiverVersion) { return (0, RECEIVER_VERSION); } /** * @notice Retrieves the address responsible for 'sending' composeMsg's to the Endpoint. * @return sender The address responsible for 'sending' composeMsg's to the Endpoint. * * @dev Applications can optionally choose to implement a separate composeMsg sender that is NOT the bridging layer. * @dev The default sender IS the OApp implementer. */ function composeMsgSender() public view virtual returns (address sender) { return address(this); } /** * @notice Checks if the path initialization is allowed based on the provided origin. * @param origin The origin information containing the source endpoint and sender address. * @return Whether the path has been initialized. * * @dev This indicates to the endpoint that the OApp has enabled msgs for this particular path to be received. * @dev This defaults to assuming if a peer has been set, its initialized. * Can be overridden by the OApp if there is other logic to determine this. */ function allowInitializePath(Origin calldata origin) public view virtual returns (bool) { return peers(origin.srcEid) == origin.sender; } /** * @notice Retrieves the next nonce for a given source endpoint and sender address. * @dev _srcEid The source endpoint ID. * @dev _sender The sender address. * @return nonce The next nonce. * * @dev The path nonce starts from 1. If 0 is returned it means that there is NO nonce ordered enforcement. * @dev Is required by the off-chain executor to determine the OApp expects msg execution is ordered. * @dev This is also enforced by the OApp. * @dev By default this is NOT enabled. ie. nextNonce is hardcoded to return 0. */ function nextNonce(uint32, /*_srcEid*/ bytes32 /*_sender*/) public view virtual returns (uint64 nonce) { return 0; } /** * @dev Entry point for receiving messages or packets from the endpoint. * @param _origin The origin information containing the source endpoint and sender address. * - srcEid: The source chain endpoint ID. * - sender: The sender address on the src chain. * - nonce: The nonce of the message. * @param _guid The unique identifier for the received LayerZero message. * @param _message The payload of the received message. * @param _executor The address of the executor for the received message. * @param _extraData Additional arbitrary data provided by the corresponding executor. * * @dev Entry point for receiving msg/packet from the LayerZero endpoint. */ function lzReceive( Origin calldata _origin, bytes32 _guid, bytes calldata _message, address _executor, bytes calldata _extraData ) public payable virtual { // Ensures that only the endpoint can attempt to lzReceive() messages to this OApp. if (address(endpoint) != msg.sender) revert OnlyEndpoint(msg.sender); // Ensure that the sender matches the expected peer for the source endpoint. if (_getPeerOrRevert(_origin.srcEid) != _origin.sender) revert OnlyPeer(_origin.srcEid, _origin.sender); // Call the internal OApp implementation of lzReceive. _lzReceive(_origin, _guid, _message, _executor, _extraData); } /** * @dev Internal function to implement lzReceive logic without needing to copy the basic parameter validation. */ function _lzReceive( Origin calldata _origin, bytes32 _guid, bytes calldata _message, address _executor, bytes calldata _extraData ) internal virtual; }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (access/Ownable.sol) pragma solidity ^0.8.20; import {ContextUpgradeable} from "../utils/ContextUpgradeable.sol"; import {Initializable} from "../proxy/utils/Initializable.sol"; /** * @dev Contract module which provides a basic access control mechanism, where * there is an account (an owner) that can be granted exclusive access to * specific functions. * * The initial owner is set to the address provided by the deployer. This can * later be changed with {transferOwnership}. * * This module is used through inheritance. It will make available the modifier * `onlyOwner`, which can be applied to your functions to restrict their use to * the owner. */ abstract contract OwnableUpgradeable is Initializable, ContextUpgradeable { /// @custom:storage-location erc7201:openzeppelin.storage.Ownable struct OwnableStorage { address _owner; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.Ownable")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant OwnableStorageLocation = 0x9016d09d72d40fdae2fd8ceac6b6234c7706214fd39c1cd1e609a0528c199300; function _getOwnableStorage() private pure returns (OwnableStorage storage $) { assembly { $.slot := OwnableStorageLocation } } /** * @dev The caller account is not authorized to perform an operation. */ error OwnableUnauthorizedAccount(address account); /** * @dev The owner is not a valid owner account. (eg. `address(0)`) */ error OwnableInvalidOwner(address owner); event OwnershipTransferred(address indexed previousOwner, address indexed newOwner); /** * @dev Initializes the contract setting the address provided by the deployer as the initial owner. */ function __Ownable_init(address initialOwner) internal onlyInitializing { __Ownable_init_unchained(initialOwner); } function __Ownable_init_unchained(address initialOwner) internal onlyInitializing { if (initialOwner == address(0)) { revert OwnableInvalidOwner(address(0)); } _transferOwnership(initialOwner); } /** * @dev Throws if called by any account other than the owner. */ modifier onlyOwner() { _checkOwner(); _; } /** * @dev Returns the address of the current owner. */ function owner() public view virtual returns (address) { OwnableStorage storage $ = _getOwnableStorage(); return $._owner; } /** * @dev Throws if the sender is not the owner. */ function _checkOwner() internal view virtual { if (owner() != _msgSender()) { revert OwnableUnauthorizedAccount(_msgSender()); } } /** * @dev Leaves the contract without owner. It will not be possible to call * `onlyOwner` functions. Can only be called by the current owner. * * NOTE: Renouncing ownership will leave the contract without an owner, * thereby disabling any functionality that is only available to the owner. */ function renounceOwnership() public virtual onlyOwner { _transferOwnership(address(0)); } /** * @dev Transfers ownership of the contract to a new account (`newOwner`). * Can only be called by the current owner. */ function transferOwnership(address newOwner) public virtual onlyOwner { if (newOwner == address(0)) { revert OwnableInvalidOwner(address(0)); } _transferOwnership(newOwner); } /** * @dev Transfers ownership of the contract to a new account (`newOwner`). * Internal function without access restriction. */ function _transferOwnership(address newOwner) internal virtual { OwnableStorage storage $ = _getOwnableStorage(); address oldOwner = $._owner; $._owner = newOwner; emit OwnershipTransferred(oldOwner, newOwner); } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.1.0) (token/ERC20/extensions/ERC20Permit.sol) pragma solidity ^0.8.20; import {IERC20Permit} from "@openzeppelin/contracts/token/ERC20/extensions/IERC20Permit.sol"; import {ERC20Upgradeable} from "../ERC20Upgradeable.sol"; import {ECDSA} from "@openzeppelin/contracts/utils/cryptography/ECDSA.sol"; import {EIP712Upgradeable} from "../../../utils/cryptography/EIP712Upgradeable.sol"; import {NoncesUpgradeable} from "../../../utils/NoncesUpgradeable.sol"; import {Initializable} from "../../../proxy/utils/Initializable.sol"; /** * @dev Implementation of the ERC-20 Permit extension allowing approvals to be made via signatures, as defined in * https://eips.ethereum.org/EIPS/eip-2612[ERC-2612]. * * Adds the {permit} method, which can be used to change an account's ERC-20 allowance (see {IERC20-allowance}) by * presenting a message signed by the account. By not relying on `{IERC20-approve}`, the token holder account doesn't * need to send a transaction, and thus is not required to hold Ether at all. */ abstract contract ERC20PermitUpgradeable is Initializable, ERC20Upgradeable, IERC20Permit, EIP712Upgradeable, NoncesUpgradeable { bytes32 private constant PERMIT_TYPEHASH = keccak256("Permit(address owner,address spender,uint256 value,uint256 nonce,uint256 deadline)"); /** * @dev Permit deadline has expired. */ error ERC2612ExpiredSignature(uint256 deadline); /** * @dev Mismatched signature. */ error ERC2612InvalidSigner(address signer, address owner); /** * @dev Initializes the {EIP712} domain separator using the `name` parameter, and setting `version` to `"1"`. * * It's a good idea to use the same `name` that is defined as the ERC-20 token name. */ function __ERC20Permit_init(string memory name) internal onlyInitializing { __EIP712_init_unchained(name, "1"); } function __ERC20Permit_init_unchained(string memory) internal onlyInitializing {} /** * @inheritdoc IERC20Permit */ function permit( address owner, address spender, uint256 value, uint256 deadline, uint8 v, bytes32 r, bytes32 s ) public virtual { if (block.timestamp > deadline) { revert ERC2612ExpiredSignature(deadline); } bytes32 structHash = keccak256(abi.encode(PERMIT_TYPEHASH, owner, spender, value, _useNonce(owner), deadline)); bytes32 hash = _hashTypedDataV4(structHash); address signer = ECDSA.recover(hash, v, r, s); if (signer != owner) { revert ERC2612InvalidSigner(signer, owner); } _approve(owner, spender, value); } /** * @inheritdoc IERC20Permit */ function nonces(address owner) public view virtual override(IERC20Permit, NoncesUpgradeable) returns (uint256) { return super.nonces(owner); } /** * @inheritdoc IERC20Permit */ // solhint-disable-next-line func-name-mixedcase function DOMAIN_SEPARATOR() external view virtual returns (bytes32) { return _domainSeparatorV4(); } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (token/ERC20/utils/SafeERC20.sol) pragma solidity ^0.8.20; import {IERC20} from "../IERC20.sol"; import {IERC20Permit} from "../extensions/IERC20Permit.sol"; import {Address} from "../../../utils/Address.sol"; /** * @title SafeERC20 * @dev Wrappers around ERC20 operations that throw on failure (when the token * contract returns false). Tokens that return no value (and instead revert or * throw on failure) are also supported, non-reverting calls are assumed to be * successful. * To use this library you can add a `using SafeERC20 for IERC20;` statement to your contract, * which allows you to call the safe operations as `token.safeTransfer(...)`, etc. */ library SafeERC20 { using Address for address; /** * @dev An operation with an ERC20 token failed. */ error SafeERC20FailedOperation(address token); /** * @dev Indicates a failed `decreaseAllowance` request. */ error SafeERC20FailedDecreaseAllowance(address spender, uint256 currentAllowance, uint256 requestedDecrease); /** * @dev Transfer `value` amount of `token` from the calling contract to `to`. If `token` returns no value, * non-reverting calls are assumed to be successful. */ function safeTransfer(IERC20 token, address to, uint256 value) internal { _callOptionalReturn(token, abi.encodeCall(token.transfer, (to, value))); } /** * @dev Transfer `value` amount of `token` from `from` to `to`, spending the approval given by `from` to the * calling contract. If `token` returns no value, non-reverting calls are assumed to be successful. */ function safeTransferFrom(IERC20 token, address from, address to, uint256 value) internal { _callOptionalReturn(token, abi.encodeCall(token.transferFrom, (from, to, value))); } /** * @dev Increase the calling contract's allowance toward `spender` by `value`. If `token` returns no value, * non-reverting calls are assumed to be successful. */ function safeIncreaseAllowance(IERC20 token, address spender, uint256 value) internal { uint256 oldAllowance = token.allowance(address(this), spender); forceApprove(token, spender, oldAllowance + value); } /** * @dev Decrease the calling contract's allowance toward `spender` by `requestedDecrease`. If `token` returns no * value, non-reverting calls are assumed to be successful. */ function safeDecreaseAllowance(IERC20 token, address spender, uint256 requestedDecrease) internal { unchecked { uint256 currentAllowance = token.allowance(address(this), spender); if (currentAllowance < requestedDecrease) { revert SafeERC20FailedDecreaseAllowance(spender, currentAllowance, requestedDecrease); } forceApprove(token, spender, currentAllowance - requestedDecrease); } } /** * @dev Set the calling contract's allowance toward `spender` to `value`. If `token` returns no value, * non-reverting calls are assumed to be successful. Meant to be used with tokens that require the approval * to be set to zero before setting it to a non-zero value, such as USDT. */ function forceApprove(IERC20 token, address spender, uint256 value) internal { bytes memory approvalCall = abi.encodeCall(token.approve, (spender, value)); if (!_callOptionalReturnBool(token, approvalCall)) { _callOptionalReturn(token, abi.encodeCall(token.approve, (spender, 0))); _callOptionalReturn(token, approvalCall); } } /** * @dev Imitates a Solidity high-level call (i.e. a regular function call to a contract), relaxing the requirement * on the return value: the return value is optional (but if data is returned, it must not be false). * @param token The token targeted by the call. * @param data The call data (encoded using abi.encode or one of its variants). */ function _callOptionalReturn(IERC20 token, bytes memory data) private { // We need to perform a low level call here, to bypass Solidity's return data size checking mechanism, since // we're implementing it ourselves. We use {Address-functionCall} to perform this call, which verifies that // the target address contains contract code and also asserts for success in the low-level call. bytes memory returndata = address(token).functionCall(data); if (returndata.length != 0 && !abi.decode(returndata, (bool))) { revert SafeERC20FailedOperation(address(token)); } } /** * @dev Imitates a Solidity high-level call (i.e. a regular function call to a contract), relaxing the requirement * on the return value: the return value is optional (but if data is returned, it must not be false). * @param token The token targeted by the call. * @param data The call data (encoded using abi.encode or one of its variants). * * This is a variant of {_callOptionalReturn} that silents catches all reverts and returns a bool instead. */ function _callOptionalReturnBool(IERC20 token, bytes memory data) private returns (bool) { // We need to perform a low level call here, to bypass Solidity's return data size checking mechanism, since // we're implementing it ourselves. We cannot use {Address-functionCall} here since this should return false // and not revert is the subcall reverts. (bool success, bytes memory returndata) = address(token).call(data); return success && (returndata.length == 0 || abi.decode(returndata, (bool))) && address(token).code.length > 0; } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.1) (utils/Context.sol) pragma solidity ^0.8.20; import {Initializable} from "../proxy/utils/Initializable.sol"; /** * @dev Provides information about the current execution context, including the * sender of the transaction and its data. While these are generally available * via msg.sender and msg.data, they should not be accessed in such a direct * manner, since when dealing with meta-transactions the account sending and * paying for execution may not be the actual sender (as far as an application * is concerned). * * This contract is only required for intermediate, library-like contracts. */ abstract contract ContextUpgradeable is Initializable { function __Context_init() internal onlyInitializing { } function __Context_init_unchained() internal onlyInitializing { } function _msgSender() internal view virtual returns (address) { return msg.sender; } function _msgData() internal view virtual returns (bytes calldata) { return msg.data; } function _contextSuffixLength() internal view virtual returns (uint256) { return 0; } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (proxy/utils/Initializable.sol) pragma solidity ^0.8.20; /** * @dev This is a base contract to aid in writing upgradeable contracts, or any kind of contract that will be deployed * behind a proxy. Since proxied contracts do not make use of a constructor, it's common to move constructor logic to an * external initializer function, usually called `initialize`. It then becomes necessary to protect this initializer * function so it can only be called once. The {initializer} modifier provided by this contract will have this effect. * * The initialization functions use a version number. Once a version number is used, it is consumed and cannot be * reused. This mechanism prevents re-execution of each "step" but allows the creation of new initialization steps in * case an upgrade adds a module that needs to be initialized. * * For example: * * [.hljs-theme-light.nopadding] * ```solidity * contract MyToken is ERC20Upgradeable { * function initialize() initializer public { * __ERC20_init("MyToken", "MTK"); * } * } * * contract MyTokenV2 is MyToken, ERC20PermitUpgradeable { * function initializeV2() reinitializer(2) public { * __ERC20Permit_init("MyToken"); * } * } * ``` * * TIP: To avoid leaving the proxy in an uninitialized state, the initializer function should be called as early as * possible by providing the encoded function call as the `_data` argument to {ERC1967Proxy-constructor}. * * CAUTION: When used with inheritance, manual care must be taken to not invoke a parent initializer twice, or to ensure * that all initializers are idempotent. This is not verified automatically as constructors are by Solidity. * * [CAUTION] * ==== * Avoid leaving a contract uninitialized. * * An uninitialized contract can be taken over by an attacker. This applies to both a proxy and its implementation * contract, which may impact the proxy. To prevent the implementation contract from being used, you should invoke * the {_disableInitializers} function in the constructor to automatically lock it when it is deployed: * * [.hljs-theme-light.nopadding] * ``` * /// @custom:oz-upgrades-unsafe-allow constructor * constructor() { * _disableInitializers(); * } * ``` * ==== */ abstract contract Initializable { /** * @dev Storage of the initializable contract. * * It's implemented on a custom ERC-7201 namespace to reduce the risk of storage collisions * when using with upgradeable contracts. * * @custom:storage-location erc7201:openzeppelin.storage.Initializable */ struct InitializableStorage { /** * @dev Indicates that the contract has been initialized. */ uint64 _initialized; /** * @dev Indicates that the contract is in the process of being initialized. */ bool _initializing; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.Initializable")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant INITIALIZABLE_STORAGE = 0xf0c57e16840df040f15088dc2f81fe391c3923bec73e23a9662efc9c229c6a00; /** * @dev The contract is already initialized. */ error InvalidInitialization(); /** * @dev The contract is not initializing. */ error NotInitializing(); /** * @dev Triggered when the contract has been initialized or reinitialized. */ event Initialized(uint64 version); /** * @dev A modifier that defines a protected initializer function that can be invoked at most once. In its scope, * `onlyInitializing` functions can be used to initialize parent contracts. * * Similar to `reinitializer(1)`, except that in the context of a constructor an `initializer` may be invoked any * number of times. This behavior in the constructor can be useful during testing and is not expected to be used in * production. * * Emits an {Initialized} event. */ modifier initializer() { // solhint-disable-next-line var-name-mixedcase InitializableStorage storage $ = _getInitializableStorage(); // Cache values to avoid duplicated sloads bool isTopLevelCall = !$._initializing; uint64 initialized = $._initialized; // Allowed calls: // - initialSetup: the contract is not in the initializing state and no previous version was // initialized // - construction: the contract is initialized at version 1 (no reininitialization) and the // current contract is just being deployed bool initialSetup = initialized == 0 && isTopLevelCall; bool construction = initialized == 1 && address(this).code.length == 0; if (!initialSetup && !construction) { revert InvalidInitialization(); } $._initialized = 1; if (isTopLevelCall) { $._initializing = true; } _; if (isTopLevelCall) { $._initializing = false; emit Initialized(1); } } /** * @dev A modifier that defines a protected reinitializer function that can be invoked at most once, and only if the * contract hasn't been initialized to a greater version before. In its scope, `onlyInitializing` functions can be * used to initialize parent contracts. * * A reinitializer may be used after the original initialization step. This is essential to configure modules that * are added through upgrades and that require initialization. * * When `version` is 1, this modifier is similar to `initializer`, except that functions marked with `reinitializer` * cannot be nested. If one is invoked in the context of another, execution will revert. * * Note that versions can jump in increments greater than 1; this implies that if multiple reinitializers coexist in * a contract, executing them in the right order is up to the developer or operator. * * WARNING: Setting the version to 2**64 - 1 will prevent any future reinitialization. * * Emits an {Initialized} event. */ modifier reinitializer(uint64 version) { // solhint-disable-next-line var-name-mixedcase InitializableStorage storage $ = _getInitializableStorage(); if ($._initializing || $._initialized >= version) { revert InvalidInitialization(); } $._initialized = version; $._initializing = true; _; $._initializing = false; emit Initialized(version); } /** * @dev Modifier to protect an initialization function so that it can only be invoked by functions with the * {initializer} and {reinitializer} modifiers, directly or indirectly. */ modifier onlyInitializing() { _checkInitializing(); _; } /** * @dev Reverts if the contract is not in an initializing state. See {onlyInitializing}. */ function _checkInitializing() internal view virtual { if (!_isInitializing()) { revert NotInitializing(); } } /** * @dev Locks the contract, preventing any future reinitialization. This cannot be part of an initializer call. * Calling this in the constructor of a contract will prevent that contract from being initialized or reinitialized * to any version. It is recommended to use this to lock implementation contracts that are designed to be called * through proxies. * * Emits an {Initialized} event the first time it is successfully executed. */ function _disableInitializers() internal virtual { // solhint-disable-next-line var-name-mixedcase InitializableStorage storage $ = _getInitializableStorage(); if ($._initializing) { revert InvalidInitialization(); } if ($._initialized != type(uint64).max) { $._initialized = type(uint64).max; emit Initialized(type(uint64).max); } } /** * @dev Returns the highest version that has been initialized. See {reinitializer}. */ function _getInitializedVersion() internal view returns (uint64) { return _getInitializableStorage()._initialized; } /** * @dev Returns `true` if the contract is currently initializing. See {onlyInitializing}. */ function _isInitializing() internal view returns (bool) { return _getInitializableStorage()._initializing; } /** * @dev Returns a pointer to the storage namespace. */ // solhint-disable-next-line var-name-mixedcase function _getInitializableStorage() private pure returns (InitializableStorage storage $) { assembly { $.slot := INITIALIZABLE_STORAGE } } }
// SPDX-License-Identifier: MIT pragma solidity >=0.8.0; struct SetConfigParam { uint32 eid; uint32 configType; bytes config; } interface IMessageLibManager { struct Timeout { address lib; uint256 expiry; } event LibraryRegistered(address newLib); event DefaultSendLibrarySet(uint32 eid, address newLib); event DefaultReceiveLibrarySet(uint32 eid, address newLib); event DefaultReceiveLibraryTimeoutSet(uint32 eid, address oldLib, uint256 expiry); event SendLibrarySet(address sender, uint32 eid, address newLib); event ReceiveLibrarySet(address receiver, uint32 eid, address newLib); event ReceiveLibraryTimeoutSet(address receiver, uint32 eid, address oldLib, uint256 timeout); function registerLibrary(address _lib) external; function isRegisteredLibrary(address _lib) external view returns (bool); function getRegisteredLibraries() external view returns (address[] memory); function setDefaultSendLibrary(uint32 _eid, address _newLib) external; function defaultSendLibrary(uint32 _eid) external view returns (address); function setDefaultReceiveLibrary(uint32 _eid, address _newLib, uint256 _timeout) external; function defaultReceiveLibrary(uint32 _eid) external view returns (address); function setDefaultReceiveLibraryTimeout(uint32 _eid, address _lib, uint256 _expiry) external; function defaultReceiveLibraryTimeout(uint32 _eid) external view returns (address lib, uint256 expiry); function isSupportedEid(uint32 _eid) external view returns (bool); function isValidReceiveLibrary(address _receiver, uint32 _eid, address _lib) external view returns (bool); /// ------------------- OApp interfaces ------------------- function setSendLibrary(address _oapp, uint32 _eid, address _newLib) external; function getSendLibrary(address _sender, uint32 _eid) external view returns (address lib); function isDefaultSendLibrary(address _sender, uint32 _eid) external view returns (bool); function setReceiveLibrary(address _oapp, uint32 _eid, address _newLib, uint256 _gracePeriod) external; function getReceiveLibrary(address _receiver, uint32 _eid) external view returns (address lib, bool isDefault); function setReceiveLibraryTimeout(address _oapp, uint32 _eid, address _lib, uint256 _gracePeriod) external; function receiveLibraryTimeout(address _receiver, uint32 _eid) external view returns (address lib, uint256 expiry); function setConfig(address _oapp, address _lib, SetConfigParam[] calldata _params) external; function getConfig( address _oapp, address _lib, uint32 _eid, uint32 _configType ) external view returns (bytes memory config); }
// SPDX-License-Identifier: MIT pragma solidity >=0.8.0; interface IMessagingComposer { event ComposeSent(address from, address to, bytes32 guid, uint16 index, bytes message); event ComposeDelivered(address from, address to, bytes32 guid, uint16 index); event LzComposeAlert( address indexed from, address indexed to, address indexed executor, bytes32 guid, uint16 index, uint256 gas, uint256 value, bytes message, bytes extraData, bytes reason ); function composeQueue( address _from, address _to, bytes32 _guid, uint16 _index ) external view returns (bytes32 messageHash); function sendCompose(address _to, bytes32 _guid, uint16 _index, bytes calldata _message) external; function lzCompose( address _from, address _to, bytes32 _guid, uint16 _index, bytes calldata _message, bytes calldata _extraData ) external payable; }
// SPDX-License-Identifier: MIT pragma solidity >=0.8.0; interface IMessagingContext { function isSendingMessage() external view returns (bool); function getSendContext() external view returns (uint32 dstEid, address sender); }
// SPDX-License-Identifier: MIT pragma solidity >=0.8.0; interface IMessagingChannel { event InboundNonceSkipped(uint32 srcEid, bytes32 sender, address receiver, uint64 nonce); event PacketNilified(uint32 srcEid, bytes32 sender, address receiver, uint64 nonce, bytes32 payloadHash); event PacketBurnt(uint32 srcEid, bytes32 sender, address receiver, uint64 nonce, bytes32 payloadHash); function eid() external view returns (uint32); // this is an emergency function if a message cannot be verified for some reasons // required to provide _nextNonce to avoid race condition function skip(address _oapp, uint32 _srcEid, bytes32 _sender, uint64 _nonce) external; function nilify(address _oapp, uint32 _srcEid, bytes32 _sender, uint64 _nonce, bytes32 _payloadHash) external; function burn(address _oapp, uint32 _srcEid, bytes32 _sender, uint64 _nonce, bytes32 _payloadHash) external; function nextGuid(address _sender, uint32 _dstEid, bytes32 _receiver) external view returns (bytes32); function inboundNonce(address _receiver, uint32 _srcEid, bytes32 _sender) external view returns (uint64); function outboundNonce(address _sender, uint32 _dstEid, bytes32 _receiver) external view returns (uint64); function inboundPayloadHash( address _receiver, uint32 _srcEid, bytes32 _sender, uint64 _nonce ) external view returns (bytes32); function lazyInboundNonce(address _receiver, uint32 _srcEid, bytes32 _sender) external view returns (uint64); }
// SPDX-License-Identifier: MIT pragma solidity ^0.8.20; import { ILayerZeroEndpointV2 } from "contracts/vendor/layerzero/protocol/interfaces/ILayerZeroEndpointV2.sol"; /** * @title IOAppCore */ interface IOAppCore { // Custom error messages error OnlyPeer(uint32 eid, bytes32 sender); error NoPeer(uint32 eid); error InvalidEndpointCall(); error InvalidDelegate(); // Event emitted when a peer (OApp) is set for a corresponding endpoint event PeerSet(uint32 eid, bytes32 peer); /** * @notice Retrieves the OApp version information. * @return senderVersion The version of the OAppSender.sol contract. * @return receiverVersion The version of the OAppReceiver.sol contract. */ function oAppVersion() external view returns (uint64 senderVersion, uint64 receiverVersion); /** * @notice Retrieves the LayerZero endpoint associated with the OApp. * @return iEndpoint The LayerZero endpoint as an interface. */ function endpoint() external view returns (ILayerZeroEndpointV2 iEndpoint); /** * @notice Retrieves the peer (OApp) associated with a corresponding endpoint. * @param _eid The endpoint ID. * @return peer The peer address (OApp instance) associated with the corresponding endpoint. */ function peers(uint32 _eid) external view returns (bytes32 peer); /** * @notice Sets the peer address (OApp instance) for a corresponding endpoint. * @param _eid The endpoint ID. * @param _peer The address of the peer to be associated with the corresponding endpoint. */ function setPeer(uint32 _eid, bytes32 _peer) external; /** * @notice Sets the delegate address for the OApp Core. * @param _delegate The address of the delegate to be set. */ function setDelegate(address _delegate) external; }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/Nonces.sol) pragma solidity ^0.8.20; import {Initializable} from "../proxy/utils/Initializable.sol"; /** * @dev Provides tracking nonces for addresses. Nonces will only increment. */ abstract contract NoncesUpgradeable is Initializable { /** * @dev The nonce used for an `account` is not the expected current nonce. */ error InvalidAccountNonce(address account, uint256 currentNonce); /// @custom:storage-location erc7201:openzeppelin.storage.Nonces struct NoncesStorage { mapping(address account => uint256) _nonces; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.Nonces")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant NoncesStorageLocation = 0x5ab42ced628888259c08ac98db1eb0cf702fc1501344311d8b100cd1bfe4bb00; function _getNoncesStorage() private pure returns (NoncesStorage storage $) { assembly { $.slot := NoncesStorageLocation } } function __Nonces_init() internal onlyInitializing { } function __Nonces_init_unchained() internal onlyInitializing { } /** * @dev Returns the next unused nonce for an address. */ function nonces(address owner) public view virtual returns (uint256) { NoncesStorage storage $ = _getNoncesStorage(); return $._nonces[owner]; } /** * @dev Consumes a nonce. * * Returns the current value and increments nonce. */ function _useNonce(address owner) internal virtual returns (uint256) { NoncesStorage storage $ = _getNoncesStorage(); // For each account, the nonce has an initial value of 0, can only be incremented by one, and cannot be // decremented or reset. This guarantees that the nonce never overflows. unchecked { // It is important to do x++ and not ++x here. return $._nonces[owner]++; } } /** * @dev Same as {_useNonce} but checking that `nonce` is the next valid for `owner`. */ function _useCheckedNonce(address owner, uint256 nonce) internal virtual { uint256 current = _useNonce(owner); if (nonce != current) { revert InvalidAccountNonce(owner, current); } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.1.0) (token/ERC20/ERC20.sol) pragma solidity ^0.8.20; import {IERC20} from "@openzeppelin/contracts/token/ERC20/IERC20.sol"; import {IERC20Metadata} from "@openzeppelin/contracts/token/ERC20/extensions/IERC20Metadata.sol"; import {ContextUpgradeable} from "../../utils/ContextUpgradeable.sol"; import {IERC20Errors} from "@openzeppelin/contracts/interfaces/draft-IERC6093.sol"; import {Initializable} from "../../proxy/utils/Initializable.sol"; /** * @dev Implementation of the {IERC20} interface. * * This implementation is agnostic to the way tokens are created. This means * that a supply mechanism has to be added in a derived contract using {_mint}. * * TIP: For a detailed writeup see our guide * https://forum.openzeppelin.com/t/how-to-implement-erc20-supply-mechanisms/226[How * to implement supply mechanisms]. * * The default value of {decimals} is 18. To change this, you should override * this function so it returns a different value. * * We have followed general OpenZeppelin Contracts guidelines: functions revert * instead returning `false` on failure. This behavior is nonetheless * conventional and does not conflict with the expectations of ERC-20 * applications. */ abstract contract ERC20Upgradeable is Initializable, ContextUpgradeable, IERC20, IERC20Metadata, IERC20Errors { /// @custom:storage-location erc7201:openzeppelin.storage.ERC20 struct ERC20Storage { mapping(address account => uint256) _balances; mapping(address account => mapping(address spender => uint256)) _allowances; uint256 _totalSupply; string _name; string _symbol; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.ERC20")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant ERC20StorageLocation = 0x52c63247e1f47db19d5ce0460030c497f067ca4cebf71ba98eeadabe20bace00; function _getERC20Storage() private pure returns (ERC20Storage storage $) { assembly { $.slot := ERC20StorageLocation } } /** * @dev Sets the values for {name} and {symbol}. * * All two of these values are immutable: they can only be set once during * construction. */ function __ERC20_init(string memory name_, string memory symbol_) internal onlyInitializing { __ERC20_init_unchained(name_, symbol_); } function __ERC20_init_unchained(string memory name_, string memory symbol_) internal onlyInitializing { ERC20Storage storage $ = _getERC20Storage(); $._name = name_; $._symbol = symbol_; } /** * @dev Returns the name of the token. */ function name() public view virtual returns (string memory) { ERC20Storage storage $ = _getERC20Storage(); return $._name; } /** * @dev Returns the symbol of the token, usually a shorter version of the * name. */ function symbol() public view virtual returns (string memory) { ERC20Storage storage $ = _getERC20Storage(); return $._symbol; } /** * @dev Returns the number of decimals used to get its user representation. * For example, if `decimals` equals `2`, a balance of `505` tokens should * be displayed to a user as `5.05` (`505 / 10 ** 2`). * * Tokens usually opt for a value of 18, imitating the relationship between * Ether and Wei. This is the default value returned by this function, unless * it's overridden. * * NOTE: This information is only used for _display_ purposes: it in * no way affects any of the arithmetic of the contract, including * {IERC20-balanceOf} and {IERC20-transfer}. */ function decimals() public view virtual returns (uint8) { return 18; } /** * @dev See {IERC20-totalSupply}. */ function totalSupply() public view virtual returns (uint256) { ERC20Storage storage $ = _getERC20Storage(); return $._totalSupply; } /** * @dev See {IERC20-balanceOf}. */ function balanceOf(address account) public view virtual returns (uint256) { ERC20Storage storage $ = _getERC20Storage(); return $._balances[account]; } /** * @dev See {IERC20-transfer}. * * Requirements: * * - `to` cannot be the zero address. * - the caller must have a balance of at least `value`. */ function transfer(address to, uint256 value) public virtual returns (bool) { address owner = _msgSender(); _transfer(owner, to, value); return true; } /** * @dev See {IERC20-allowance}. */ function allowance(address owner, address spender) public view virtual returns (uint256) { ERC20Storage storage $ = _getERC20Storage(); return $._allowances[owner][spender]; } /** * @dev See {IERC20-approve}. * * NOTE: If `value` is the maximum `uint256`, the allowance is not updated on * `transferFrom`. This is semantically equivalent to an infinite approval. * * Requirements: * * - `spender` cannot be the zero address. */ function approve(address spender, uint256 value) public virtual returns (bool) { address owner = _msgSender(); _approve(owner, spender, value); return true; } /** * @dev See {IERC20-transferFrom}. * * Skips emitting an {Approval} event indicating an allowance update. This is not * required by the ERC. See {xref-ERC20-_approve-address-address-uint256-bool-}[_approve]. * * NOTE: Does not update the allowance if the current allowance * is the maximum `uint256`. * * Requirements: * * - `from` and `to` cannot be the zero address. * - `from` must have a balance of at least `value`. * - the caller must have allowance for ``from``'s tokens of at least * `value`. */ function transferFrom(address from, address to, uint256 value) public virtual returns (bool) { address spender = _msgSender(); _spendAllowance(from, spender, value); _transfer(from, to, value); return true; } /** * @dev Moves a `value` amount of tokens from `from` to `to`. * * This internal function is equivalent to {transfer}, and can be used to * e.g. implement automatic token fees, slashing mechanisms, etc. * * Emits a {Transfer} event. * * NOTE: This function is not virtual, {_update} should be overridden instead. */ function _transfer(address from, address to, uint256 value) internal { if (from == address(0)) { revert ERC20InvalidSender(address(0)); } if (to == address(0)) { revert ERC20InvalidReceiver(address(0)); } _update(from, to, value); } /** * @dev Transfers a `value` amount of tokens from `from` to `to`, or alternatively mints (or burns) if `from` * (or `to`) is the zero address. All customizations to transfers, mints, and burns should be done by overriding * this function. * * Emits a {Transfer} event. */ function _update(address from, address to, uint256 value) internal virtual { ERC20Storage storage $ = _getERC20Storage(); if (from == address(0)) { // Overflow check required: The rest of the code assumes that totalSupply never overflows $._totalSupply += value; } else { uint256 fromBalance = $._balances[from]; if (fromBalance < value) { revert ERC20InsufficientBalance(from, fromBalance, value); } unchecked { // Overflow not possible: value <= fromBalance <= totalSupply. $._balances[from] = fromBalance - value; } } if (to == address(0)) { unchecked { // Overflow not possible: value <= totalSupply or value <= fromBalance <= totalSupply. $._totalSupply -= value; } } else { unchecked { // Overflow not possible: balance + value is at most totalSupply, which we know fits into a uint256. $._balances[to] += value; } } emit Transfer(from, to, value); } /** * @dev Creates a `value` amount of tokens and assigns them to `account`, by transferring it from address(0). * Relies on the `_update` mechanism * * Emits a {Transfer} event with `from` set to the zero address. * * NOTE: This function is not virtual, {_update} should be overridden instead. */ function _mint(address account, uint256 value) internal { if (account == address(0)) { revert ERC20InvalidReceiver(address(0)); } _update(address(0), account, value); } /** * @dev Destroys a `value` amount of tokens from `account`, lowering the total supply. * Relies on the `_update` mechanism. * * Emits a {Transfer} event with `to` set to the zero address. * * NOTE: This function is not virtual, {_update} should be overridden instead */ function _burn(address account, uint256 value) internal { if (account == address(0)) { revert ERC20InvalidSender(address(0)); } _update(account, address(0), value); } /** * @dev Sets `value` as the allowance of `spender` over the `owner` s tokens. * * This internal function is equivalent to `approve`, and can be used to * e.g. set automatic allowances for certain subsystems, etc. * * Emits an {Approval} event. * * Requirements: * * - `owner` cannot be the zero address. * - `spender` cannot be the zero address. * * Overrides to this logic should be done to the variant with an additional `bool emitEvent` argument. */ function _approve(address owner, address spender, uint256 value) internal { _approve(owner, spender, value, true); } /** * @dev Variant of {_approve} with an optional flag to enable or disable the {Approval} event. * * By default (when calling {_approve}) the flag is set to true. On the other hand, approval changes made by * `_spendAllowance` during the `transferFrom` operation set the flag to false. This saves gas by not emitting any * `Approval` event during `transferFrom` operations. * * Anyone who wishes to continue emitting `Approval` events on the`transferFrom` operation can force the flag to * true using the following override: * * ```solidity * function _approve(address owner, address spender, uint256 value, bool) internal virtual override { * super._approve(owner, spender, value, true); * } * ``` * * Requirements are the same as {_approve}. */ function _approve(address owner, address spender, uint256 value, bool emitEvent) internal virtual { ERC20Storage storage $ = _getERC20Storage(); if (owner == address(0)) { revert ERC20InvalidApprover(address(0)); } if (spender == address(0)) { revert ERC20InvalidSpender(address(0)); } $._allowances[owner][spender] = value; if (emitEvent) { emit Approval(owner, spender, value); } } /** * @dev Updates `owner` s allowance for `spender` based on spent `value`. * * Does not update the allowance value in case of infinite allowance. * Revert if not enough allowance is available. * * Does not emit an {Approval} event. */ function _spendAllowance(address owner, address spender, uint256 value) internal virtual { uint256 currentAllowance = allowance(owner, spender); if (currentAllowance != type(uint256).max) { if (currentAllowance < value) { revert ERC20InsufficientAllowance(spender, currentAllowance, value); } unchecked { _approve(owner, spender, currentAllowance - value, false); } } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/Address.sol) pragma solidity ^0.8.20; /** * @dev Collection of functions related to the address type */ library Address { /** * @dev The ETH balance of the account is not enough to perform the operation. */ error AddressInsufficientBalance(address account); /** * @dev There's no code at `target` (it is not a contract). */ error AddressEmptyCode(address target); /** * @dev A call to an address target failed. The target may have reverted. */ error FailedInnerCall(); /** * @dev Replacement for Solidity's `transfer`: sends `amount` wei to * `recipient`, forwarding all available gas and reverting on errors. * * https://eips.ethereum.org/EIPS/eip-1884[EIP1884] increases the gas cost * of certain opcodes, possibly making contracts go over the 2300 gas limit * imposed by `transfer`, making them unable to receive funds via * `transfer`. {sendValue} removes this limitation. * * https://consensys.net/diligence/blog/2019/09/stop-using-soliditys-transfer-now/[Learn more]. * * IMPORTANT: because control is transferred to `recipient`, care must be * taken to not create reentrancy vulnerabilities. Consider using * {ReentrancyGuard} or the * https://solidity.readthedocs.io/en/v0.8.20/security-considerations.html#use-the-checks-effects-interactions-pattern[checks-effects-interactions pattern]. */ function sendValue(address payable recipient, uint256 amount) internal { if (address(this).balance < amount) { revert AddressInsufficientBalance(address(this)); } (bool success, ) = recipient.call{value: amount}(""); if (!success) { revert FailedInnerCall(); } } /** * @dev Performs a Solidity function call using a low level `call`. A * plain `call` is an unsafe replacement for a function call: use this * function instead. * * If `target` reverts with a revert reason or custom error, it is bubbled * up by this function (like regular Solidity function calls). However, if * the call reverted with no returned reason, this function reverts with a * {FailedInnerCall} error. * * Returns the raw returned data. To convert to the expected return value, * use https://solidity.readthedocs.io/en/latest/units-and-global-variables.html?highlight=abi.decode#abi-encoding-and-decoding-functions[`abi.decode`]. * * Requirements: * * - `target` must be a contract. * - calling `target` with `data` must not revert. */ function functionCall(address target, bytes memory data) internal returns (bytes memory) { return functionCallWithValue(target, data, 0); } /** * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], * but also transferring `value` wei to `target`. * * Requirements: * * - the calling contract must have an ETH balance of at least `value`. * - the called Solidity function must be `payable`. */ function functionCallWithValue(address target, bytes memory data, uint256 value) internal returns (bytes memory) { if (address(this).balance < value) { revert AddressInsufficientBalance(address(this)); } (bool success, bytes memory returndata) = target.call{value: value}(data); return verifyCallResultFromTarget(target, success, returndata); } /** * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], * but performing a static call. */ function functionStaticCall(address target, bytes memory data) internal view returns (bytes memory) { (bool success, bytes memory returndata) = target.staticcall(data); return verifyCallResultFromTarget(target, success, returndata); } /** * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], * but performing a delegate call. */ function functionDelegateCall(address target, bytes memory data) internal returns (bytes memory) { (bool success, bytes memory returndata) = target.delegatecall(data); return verifyCallResultFromTarget(target, success, returndata); } /** * @dev Tool to verify that a low level call to smart-contract was successful, and reverts if the target * was not a contract or bubbling up the revert reason (falling back to {FailedInnerCall}) in case of an * unsuccessful call. */ function verifyCallResultFromTarget( address target, bool success, bytes memory returndata ) internal view returns (bytes memory) { if (!success) { _revert(returndata); } else { // only check if target is a contract if the call was successful and the return data is empty // otherwise we already know that it was a contract if (returndata.length == 0 && target.code.length == 0) { revert AddressEmptyCode(target); } return returndata; } } /** * @dev Tool to verify that a low level call was successful, and reverts if it wasn't, either by bubbling the * revert reason or with a default {FailedInnerCall} error. */ function verifyCallResult(bool success, bytes memory returndata) internal pure returns (bytes memory) { if (!success) { _revert(returndata); } else { return returndata; } } /** * @dev Reverts with returndata if present. Otherwise reverts with {FailedInnerCall}. */ function _revert(bytes memory returndata) private pure { // Look for revert reason and bubble it up if present if (returndata.length > 0) { // The easiest way to bubble the revert reason is using memory via assembly /// @solidity memory-safe-assembly assembly { let returndata_size := mload(returndata) revert(add(32, returndata), returndata_size) } } else { revert FailedInnerCall(); } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (token/ERC20/IERC20.sol) pragma solidity ^0.8.20; /** * @dev Interface of the ERC20 standard as defined in the EIP. */ interface IERC20 { /** * @dev Emitted when `value` tokens are moved from one account (`from`) to * another (`to`). * * Note that `value` may be zero. */ event Transfer(address indexed from, address indexed to, uint256 value); /** * @dev Emitted when the allowance of a `spender` for an `owner` is set by * a call to {approve}. `value` is the new allowance. */ event Approval(address indexed owner, address indexed spender, uint256 value); /** * @dev Returns the value of tokens in existence. */ function totalSupply() external view returns (uint256); /** * @dev Returns the value of tokens owned by `account`. */ function balanceOf(address account) external view returns (uint256); /** * @dev Moves a `value` amount of tokens from the caller's account to `to`. * * Returns a boolean value indicating whether the operation succeeded. * * Emits a {Transfer} event. */ function transfer(address to, uint256 value) external returns (bool); /** * @dev Returns the remaining number of tokens that `spender` will be * allowed to spend on behalf of `owner` through {transferFrom}. This is * zero by default. * * This value changes when {approve} or {transferFrom} are called. */ function allowance(address owner, address spender) external view returns (uint256); /** * @dev Sets a `value` amount of tokens as the allowance of `spender` over the * caller's tokens. * * Returns a boolean value indicating whether the operation succeeded. * * IMPORTANT: Beware that changing an allowance with this method brings the risk * that someone may use both the old and the new allowance by unfortunate * transaction ordering. One possible solution to mitigate this race * condition is to first reduce the spender's allowance to 0 and set the * desired value afterwards: * https://github.com/ethereum/EIPs/issues/20#issuecomment-263524729 * * Emits an {Approval} event. */ function approve(address spender, uint256 value) external returns (bool); /** * @dev Moves a `value` amount of tokens from `from` to `to` using the * allowance mechanism. `value` is then deducted from the caller's * allowance. * * Returns a boolean value indicating whether the operation succeeded. * * Emits a {Transfer} event. */ function transferFrom(address from, address to, uint256 value) external returns (bool); }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.1.0) (utils/cryptography/EIP712.sol) pragma solidity ^0.8.20; import {MessageHashUtils} from "@openzeppelin/contracts/utils/cryptography/MessageHashUtils.sol"; import {IERC5267} from "@openzeppelin/contracts/interfaces/IERC5267.sol"; import {Initializable} from "../../proxy/utils/Initializable.sol"; /** * @dev https://eips.ethereum.org/EIPS/eip-712[EIP-712] is a standard for hashing and signing of typed structured data. * * The encoding scheme specified in the EIP requires a domain separator and a hash of the typed structured data, whose * encoding is very generic and therefore its implementation in Solidity is not feasible, thus this contract * does not implement the encoding itself. Protocols need to implement the type-specific encoding they need in order to * produce the hash of their typed data using a combination of `abi.encode` and `keccak256`. * * This contract implements the EIP-712 domain separator ({_domainSeparatorV4}) that is used as part of the encoding * scheme, and the final step of the encoding to obtain the message digest that is then signed via ECDSA * ({_hashTypedDataV4}). * * The implementation of the domain separator was designed to be as efficient as possible while still properly updating * the chain id to protect against replay attacks on an eventual fork of the chain. * * NOTE: This contract implements the version of the encoding known as "v4", as implemented by the JSON RPC method * https://docs.metamask.io/guide/signing-data.html[`eth_signTypedDataV4` in MetaMask]. * * NOTE: In the upgradeable version of this contract, the cached values will correspond to the address, and the domain * separator of the implementation contract. This will cause the {_domainSeparatorV4} function to always rebuild the * separator from the immutable values, which is cheaper than accessing a cached version in cold storage. */ abstract contract EIP712Upgradeable is Initializable, IERC5267 { bytes32 private constant TYPE_HASH = keccak256("EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)"); /// @custom:storage-location erc7201:openzeppelin.storage.EIP712 struct EIP712Storage { /// @custom:oz-renamed-from _HASHED_NAME bytes32 _hashedName; /// @custom:oz-renamed-from _HASHED_VERSION bytes32 _hashedVersion; string _name; string _version; } // keccak256(abi.encode(uint256(keccak256("openzeppelin.storage.EIP712")) - 1)) & ~bytes32(uint256(0xff)) bytes32 private constant EIP712StorageLocation = 0xa16a46d94261c7517cc8ff89f61c0ce93598e3c849801011dee649a6a557d100; function _getEIP712Storage() private pure returns (EIP712Storage storage $) { assembly { $.slot := EIP712StorageLocation } } /** * @dev Initializes the domain separator and parameter caches. * * The meaning of `name` and `version` is specified in * https://eips.ethereum.org/EIPS/eip-712#definition-of-domainseparator[EIP-712]: * * - `name`: the user readable name of the signing domain, i.e. the name of the DApp or the protocol. * - `version`: the current major version of the signing domain. * * NOTE: These parameters cannot be changed except through a xref:learn::upgrading-smart-contracts.adoc[smart * contract upgrade]. */ function __EIP712_init(string memory name, string memory version) internal onlyInitializing { __EIP712_init_unchained(name, version); } function __EIP712_init_unchained(string memory name, string memory version) internal onlyInitializing { EIP712Storage storage $ = _getEIP712Storage(); $._name = name; $._version = version; // Reset prior values in storage if upgrading $._hashedName = 0; $._hashedVersion = 0; } /** * @dev Returns the domain separator for the current chain. */ function _domainSeparatorV4() internal view returns (bytes32) { return _buildDomainSeparator(); } function _buildDomainSeparator() private view returns (bytes32) { return keccak256(abi.encode(TYPE_HASH, _EIP712NameHash(), _EIP712VersionHash(), block.chainid, address(this))); } /** * @dev Given an already https://eips.ethereum.org/EIPS/eip-712#definition-of-hashstruct[hashed struct], this * function returns the hash of the fully encoded EIP712 message for this domain. * * This hash can be used together with {ECDSA-recover} to obtain the signer of a message. For example: * * ```solidity * bytes32 digest = _hashTypedDataV4(keccak256(abi.encode( * keccak256("Mail(address to,string contents)"), * mailTo, * keccak256(bytes(mailContents)) * ))); * address signer = ECDSA.recover(digest, signature); * ``` */ function _hashTypedDataV4(bytes32 structHash) internal view virtual returns (bytes32) { return MessageHashUtils.toTypedDataHash(_domainSeparatorV4(), structHash); } /** * @dev See {IERC-5267}. */ function eip712Domain() public view virtual returns ( bytes1 fields, string memory name, string memory version, uint256 chainId, address verifyingContract, bytes32 salt, uint256[] memory extensions ) { EIP712Storage storage $ = _getEIP712Storage(); // If the hashed name and version in storage are non-zero, the contract hasn't been properly initialized // and the EIP712 domain is not reliable, as it will be missing name and version. require($._hashedName == 0 && $._hashedVersion == 0, "EIP712: Uninitialized"); return ( hex"0f", // 01111 _EIP712Name(), _EIP712Version(), block.chainid, address(this), bytes32(0), new uint256[](0) ); } /** * @dev The name parameter for the EIP712 domain. * * NOTE: This function reads from storage by default, but can be redefined to return a constant value if gas costs * are a concern. */ function _EIP712Name() internal view virtual returns (string memory) { EIP712Storage storage $ = _getEIP712Storage(); return $._name; } /** * @dev The version parameter for the EIP712 domain. * * NOTE: This function reads from storage by default, but can be redefined to return a constant value if gas costs * are a concern. */ function _EIP712Version() internal view virtual returns (string memory) { EIP712Storage storage $ = _getEIP712Storage(); return $._version; } /** * @dev The hash of the name parameter for the EIP712 domain. * * NOTE: In previous versions this function was virtual. In this version you should override `_EIP712Name` instead. */ function _EIP712NameHash() internal view returns (bytes32) { EIP712Storage storage $ = _getEIP712Storage(); string memory name = _EIP712Name(); if (bytes(name).length > 0) { return keccak256(bytes(name)); } else { // If the name is empty, the contract may have been upgraded without initializing the new storage. // We return the name hash in storage if non-zero, otherwise we assume the name is empty by design. bytes32 hashedName = $._hashedName; if (hashedName != 0) { return hashedName; } else { return keccak256(""); } } } /** * @dev The hash of the version parameter for the EIP712 domain. * * NOTE: In previous versions this function was virtual. In this version you should override `_EIP712Version` instead. */ function _EIP712VersionHash() internal view returns (bytes32) { EIP712Storage storage $ = _getEIP712Storage(); string memory version = _EIP712Version(); if (bytes(version).length > 0) { return keccak256(bytes(version)); } else { // If the version is empty, the contract may have been upgraded without initializing the new storage. // We return the version hash in storage if non-zero, otherwise we assume the version is empty by design. bytes32 hashedVersion = $._hashedVersion; if (hashedVersion != 0) { return hashedVersion; } else { return keccak256(""); } } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (token/ERC20/extensions/IERC20Permit.sol) pragma solidity ^0.8.20; /** * @dev Interface of the ERC20 Permit extension allowing approvals to be made via signatures, as defined in * https://eips.ethereum.org/EIPS/eip-2612[EIP-2612]. * * Adds the {permit} method, which can be used to change an account's ERC20 allowance (see {IERC20-allowance}) by * presenting a message signed by the account. By not relying on {IERC20-approve}, the token holder account doesn't * need to send a transaction, and thus is not required to hold Ether at all. * * ==== Security Considerations * * There are two important considerations concerning the use of `permit`. The first is that a valid permit signature * expresses an allowance, and it should not be assumed to convey additional meaning. In particular, it should not be * considered as an intention to spend the allowance in any specific way. The second is that because permits have * built-in replay protection and can be submitted by anyone, they can be frontrun. A protocol that uses permits should * take this into consideration and allow a `permit` call to fail. Combining these two aspects, a pattern that may be * generally recommended is: * * ```solidity * function doThingWithPermit(..., uint256 value, uint256 deadline, uint8 v, bytes32 r, bytes32 s) public { * try token.permit(msg.sender, address(this), value, deadline, v, r, s) {} catch {} * doThing(..., value); * } * * function doThing(..., uint256 value) public { * token.safeTransferFrom(msg.sender, address(this), value); * ... * } * ``` * * Observe that: 1) `msg.sender` is used as the owner, leaving no ambiguity as to the signer intent, and 2) the use of * `try/catch` allows the permit to fail and makes the code tolerant to frontrunning. (See also * {SafeERC20-safeTransferFrom}). * * Additionally, note that smart contract wallets (such as Argent or Safe) are not able to produce permit signatures, so * contracts should have entry points that don't rely on permit. */ interface IERC20Permit { /** * @dev Sets `value` as the allowance of `spender` over ``owner``'s tokens, * given ``owner``'s signed approval. * * IMPORTANT: The same issues {IERC20-approve} has related to transaction * ordering also apply here. * * Emits an {Approval} event. * * Requirements: * * - `spender` cannot be the zero address. * - `deadline` must be a timestamp in the future. * - `v`, `r` and `s` must be a valid `secp256k1` signature from `owner` * over the EIP712-formatted function arguments. * - the signature must use ``owner``'s current nonce (see {nonces}). * * For more information on the signature format, see the * https://eips.ethereum.org/EIPS/eip-2612#specification[relevant EIP * section]. * * CAUTION: See Security Considerations above. */ function permit( address owner, address spender, uint256 value, uint256 deadline, uint8 v, bytes32 r, bytes32 s ) external; /** * @dev Returns the current nonce for `owner`. This value must be * included whenever a signature is generated for {permit}. * * Every successful call to {permit} increases ``owner``'s nonce by one. This * prevents a signature from being used multiple times. */ function nonces(address owner) external view returns (uint256); /** * @dev Returns the domain separator used in the encoding of the signature for {permit}, as defined by {EIP712}. */ // solhint-disable-next-line func-name-mixedcase function DOMAIN_SEPARATOR() external view returns (bytes32); }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/cryptography/ECDSA.sol) pragma solidity ^0.8.20; /** * @dev Elliptic Curve Digital Signature Algorithm (ECDSA) operations. * * These functions can be used to verify that a message was signed by the holder * of the private keys of a given address. */ library ECDSA { enum RecoverError { NoError, InvalidSignature, InvalidSignatureLength, InvalidSignatureS } /** * @dev The signature derives the `address(0)`. */ error ECDSAInvalidSignature(); /** * @dev The signature has an invalid length. */ error ECDSAInvalidSignatureLength(uint256 length); /** * @dev The signature has an S value that is in the upper half order. */ error ECDSAInvalidSignatureS(bytes32 s); /** * @dev Returns the address that signed a hashed message (`hash`) with `signature` or an error. This will not * return address(0) without also returning an error description. Errors are documented using an enum (error type) * and a bytes32 providing additional information about the error. * * If no error is returned, then the address can be used for verification purposes. * * The `ecrecover` EVM precompile allows for malleable (non-unique) signatures: * this function rejects them by requiring the `s` value to be in the lower * half order, and the `v` value to be either 27 or 28. * * IMPORTANT: `hash` _must_ be the result of a hash operation for the * verification to be secure: it is possible to craft signatures that * recover to arbitrary addresses for non-hashed data. A safe way to ensure * this is by receiving a hash of the original message (which may otherwise * be too long), and then calling {MessageHashUtils-toEthSignedMessageHash} on it. * * Documentation for signature generation: * - with https://web3js.readthedocs.io/en/v1.3.4/web3-eth-accounts.html#sign[Web3.js] * - with https://docs.ethers.io/v5/api/signer/#Signer-signMessage[ethers] */ function tryRecover(bytes32 hash, bytes memory signature) internal pure returns (address, RecoverError, bytes32) { if (signature.length == 65) { bytes32 r; bytes32 s; uint8 v; // ecrecover takes the signature parameters, and the only way to get them // currently is to use assembly. /// @solidity memory-safe-assembly assembly { r := mload(add(signature, 0x20)) s := mload(add(signature, 0x40)) v := byte(0, mload(add(signature, 0x60))) } return tryRecover(hash, v, r, s); } else { return (address(0), RecoverError.InvalidSignatureLength, bytes32(signature.length)); } } /** * @dev Returns the address that signed a hashed message (`hash`) with * `signature`. This address can then be used for verification purposes. * * The `ecrecover` EVM precompile allows for malleable (non-unique) signatures: * this function rejects them by requiring the `s` value to be in the lower * half order, and the `v` value to be either 27 or 28. * * IMPORTANT: `hash` _must_ be the result of a hash operation for the * verification to be secure: it is possible to craft signatures that * recover to arbitrary addresses for non-hashed data. A safe way to ensure * this is by receiving a hash of the original message (which may otherwise * be too long), and then calling {MessageHashUtils-toEthSignedMessageHash} on it. */ function recover(bytes32 hash, bytes memory signature) internal pure returns (address) { (address recovered, RecoverError error, bytes32 errorArg) = tryRecover(hash, signature); _throwError(error, errorArg); return recovered; } /** * @dev Overload of {ECDSA-tryRecover} that receives the `r` and `vs` short-signature fields separately. * * See https://eips.ethereum.org/EIPS/eip-2098[EIP-2098 short signatures] */ function tryRecover(bytes32 hash, bytes32 r, bytes32 vs) internal pure returns (address, RecoverError, bytes32) { unchecked { bytes32 s = vs & bytes32(0x7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff); // We do not check for an overflow here since the shift operation results in 0 or 1. uint8 v = uint8((uint256(vs) >> 255) + 27); return tryRecover(hash, v, r, s); } } /** * @dev Overload of {ECDSA-recover} that receives the `r and `vs` short-signature fields separately. */ function recover(bytes32 hash, bytes32 r, bytes32 vs) internal pure returns (address) { (address recovered, RecoverError error, bytes32 errorArg) = tryRecover(hash, r, vs); _throwError(error, errorArg); return recovered; } /** * @dev Overload of {ECDSA-tryRecover} that receives the `v`, * `r` and `s` signature fields separately. */ function tryRecover( bytes32 hash, uint8 v, bytes32 r, bytes32 s ) internal pure returns (address, RecoverError, bytes32) { // EIP-2 still allows signature malleability for ecrecover(). Remove this possibility and make the signature // unique. Appendix F in the Ethereum Yellow paper (https://ethereum.github.io/yellowpaper/paper.pdf), defines // the valid range for s in (301): 0 < s < secp256k1n ÷ 2 + 1, and for v in (302): v ∈ {27, 28}. Most // signatures from current libraries generate a unique signature with an s-value in the lower half order. // // If your library generates malleable signatures, such as s-values in the upper range, calculate a new s-value // with 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141 - s1 and flip v from 27 to 28 or // vice versa. If your library also generates signatures with 0/1 for v instead 27/28, add 27 to v to accept // these malleable signatures as well. if (uint256(s) > 0x7FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF5D576E7357A4501DDFE92F46681B20A0) { return (address(0), RecoverError.InvalidSignatureS, s); } // If the signature is valid (and not malleable), return the signer address address signer = ecrecover(hash, v, r, s); if (signer == address(0)) { return (address(0), RecoverError.InvalidSignature, bytes32(0)); } return (signer, RecoverError.NoError, bytes32(0)); } /** * @dev Overload of {ECDSA-recover} that receives the `v`, * `r` and `s` signature fields separately. */ function recover(bytes32 hash, uint8 v, bytes32 r, bytes32 s) internal pure returns (address) { (address recovered, RecoverError error, bytes32 errorArg) = tryRecover(hash, v, r, s); _throwError(error, errorArg); return recovered; } /** * @dev Optionally reverts with the corresponding custom error according to the `error` argument provided. */ function _throwError(RecoverError error, bytes32 errorArg) private pure { if (error == RecoverError.NoError) { return; // no error: do nothing } else if (error == RecoverError.InvalidSignature) { revert ECDSAInvalidSignature(); } else if (error == RecoverError.InvalidSignatureLength) { revert ECDSAInvalidSignatureLength(uint256(errorArg)); } else if (error == RecoverError.InvalidSignatureS) { revert ECDSAInvalidSignatureS(errorArg); } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/cryptography/MessageHashUtils.sol) pragma solidity ^0.8.20; import {Strings} from "../Strings.sol"; /** * @dev Signature message hash utilities for producing digests to be consumed by {ECDSA} recovery or signing. * * The library provides methods for generating a hash of a message that conforms to the * https://eips.ethereum.org/EIPS/eip-191[EIP 191] and https://eips.ethereum.org/EIPS/eip-712[EIP 712] * specifications. */ library MessageHashUtils { /** * @dev Returns the keccak256 digest of an EIP-191 signed data with version * `0x45` (`personal_sign` messages). * * The digest is calculated by prefixing a bytes32 `messageHash` with * `"\x19Ethereum Signed Message:\n32"` and hashing the result. It corresponds with the * hash signed when using the https://eth.wiki/json-rpc/API#eth_sign[`eth_sign`] JSON-RPC method. * * NOTE: The `messageHash` parameter is intended to be the result of hashing a raw message with * keccak256, although any bytes32 value can be safely used because the final digest will * be re-hashed. * * See {ECDSA-recover}. */ function toEthSignedMessageHash(bytes32 messageHash) internal pure returns (bytes32 digest) { /// @solidity memory-safe-assembly assembly { mstore(0x00, "\x19Ethereum Signed Message:\n32") // 32 is the bytes-length of messageHash mstore(0x1c, messageHash) // 0x1c (28) is the length of the prefix digest := keccak256(0x00, 0x3c) // 0x3c is the length of the prefix (0x1c) + messageHash (0x20) } } /** * @dev Returns the keccak256 digest of an EIP-191 signed data with version * `0x45` (`personal_sign` messages). * * The digest is calculated by prefixing an arbitrary `message` with * `"\x19Ethereum Signed Message:\n" + len(message)` and hashing the result. It corresponds with the * hash signed when using the https://eth.wiki/json-rpc/API#eth_sign[`eth_sign`] JSON-RPC method. * * See {ECDSA-recover}. */ function toEthSignedMessageHash(bytes memory message) internal pure returns (bytes32) { return keccak256(bytes.concat("\x19Ethereum Signed Message:\n", bytes(Strings.toString(message.length)), message)); } /** * @dev Returns the keccak256 digest of an EIP-191 signed data with version * `0x00` (data with intended validator). * * The digest is calculated by prefixing an arbitrary `data` with `"\x19\x00"` and the intended * `validator` address. Then hashing the result. * * See {ECDSA-recover}. */ function toDataWithIntendedValidatorHash(address validator, bytes memory data) internal pure returns (bytes32) { return keccak256(abi.encodePacked(hex"19_00", validator, data)); } /** * @dev Returns the keccak256 digest of an EIP-712 typed data (EIP-191 version `0x01`). * * The digest is calculated from a `domainSeparator` and a `structHash`, by prefixing them with * `\x19\x01` and hashing the result. It corresponds to the hash signed by the * https://eips.ethereum.org/EIPS/eip-712[`eth_signTypedData`] JSON-RPC method as part of EIP-712. * * See {ECDSA-recover}. */ function toTypedDataHash(bytes32 domainSeparator, bytes32 structHash) internal pure returns (bytes32 digest) { /// @solidity memory-safe-assembly assembly { let ptr := mload(0x40) mstore(ptr, hex"19_01") mstore(add(ptr, 0x02), domainSeparator) mstore(add(ptr, 0x22), structHash) digest := keccak256(ptr, 0x42) } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (token/ERC20/extensions/IERC20Metadata.sol) pragma solidity ^0.8.20; import {IERC20} from "../IERC20.sol"; /** * @dev Interface for the optional metadata functions from the ERC20 standard. */ interface IERC20Metadata is IERC20 { /** * @dev Returns the name of the token. */ function name() external view returns (string memory); /** * @dev Returns the symbol of the token. */ function symbol() external view returns (string memory); /** * @dev Returns the decimals places of the token. */ function decimals() external view returns (uint8); }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (interfaces/IERC5267.sol) pragma solidity ^0.8.20; interface IERC5267 { /** * @dev MAY be emitted to signal that the domain could have changed. */ event EIP712DomainChanged(); /** * @dev returns the fields and values that describe the domain separator used by this contract for EIP-712 * signature. */ function eip712Domain() external view returns ( bytes1 fields, string memory name, string memory version, uint256 chainId, address verifyingContract, bytes32 salt, uint256[] memory extensions ); }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (interfaces/draft-IERC6093.sol) pragma solidity ^0.8.20; /** * @dev Standard ERC20 Errors * Interface of the https://eips.ethereum.org/EIPS/eip-6093[ERC-6093] custom errors for ERC20 tokens. */ interface IERC20Errors { /** * @dev Indicates an error related to the current `balance` of a `sender`. Used in transfers. * @param sender Address whose tokens are being transferred. * @param balance Current balance for the interacting account. * @param needed Minimum amount required to perform a transfer. */ error ERC20InsufficientBalance(address sender, uint256 balance, uint256 needed); /** * @dev Indicates a failure with the token `sender`. Used in transfers. * @param sender Address whose tokens are being transferred. */ error ERC20InvalidSender(address sender); /** * @dev Indicates a failure with the token `receiver`. Used in transfers. * @param receiver Address to which tokens are being transferred. */ error ERC20InvalidReceiver(address receiver); /** * @dev Indicates a failure with the `spender`’s `allowance`. Used in transfers. * @param spender Address that may be allowed to operate on tokens without being their owner. * @param allowance Amount of tokens a `spender` is allowed to operate with. * @param needed Minimum amount required to perform a transfer. */ error ERC20InsufficientAllowance(address spender, uint256 allowance, uint256 needed); /** * @dev Indicates a failure with the `approver` of a token to be approved. Used in approvals. * @param approver Address initiating an approval operation. */ error ERC20InvalidApprover(address approver); /** * @dev Indicates a failure with the `spender` to be approved. Used in approvals. * @param spender Address that may be allowed to operate on tokens without being their owner. */ error ERC20InvalidSpender(address spender); } /** * @dev Standard ERC721 Errors * Interface of the https://eips.ethereum.org/EIPS/eip-6093[ERC-6093] custom errors for ERC721 tokens. */ interface IERC721Errors { /** * @dev Indicates that an address can't be an owner. For example, `address(0)` is a forbidden owner in EIP-20. * Used in balance queries. * @param owner Address of the current owner of a token. */ error ERC721InvalidOwner(address owner); /** * @dev Indicates a `tokenId` whose `owner` is the zero address. * @param tokenId Identifier number of a token. */ error ERC721NonexistentToken(uint256 tokenId); /** * @dev Indicates an error related to the ownership over a particular token. Used in transfers. * @param sender Address whose tokens are being transferred. * @param tokenId Identifier number of a token. * @param owner Address of the current owner of a token. */ error ERC721IncorrectOwner(address sender, uint256 tokenId, address owner); /** * @dev Indicates a failure with the token `sender`. Used in transfers. * @param sender Address whose tokens are being transferred. */ error ERC721InvalidSender(address sender); /** * @dev Indicates a failure with the token `receiver`. Used in transfers. * @param receiver Address to which tokens are being transferred. */ error ERC721InvalidReceiver(address receiver); /** * @dev Indicates a failure with the `operator`’s approval. Used in transfers. * @param operator Address that may be allowed to operate on tokens without being their owner. * @param tokenId Identifier number of a token. */ error ERC721InsufficientApproval(address operator, uint256 tokenId); /** * @dev Indicates a failure with the `approver` of a token to be approved. Used in approvals. * @param approver Address initiating an approval operation. */ error ERC721InvalidApprover(address approver); /** * @dev Indicates a failure with the `operator` to be approved. Used in approvals. * @param operator Address that may be allowed to operate on tokens without being their owner. */ error ERC721InvalidOperator(address operator); } /** * @dev Standard ERC1155 Errors * Interface of the https://eips.ethereum.org/EIPS/eip-6093[ERC-6093] custom errors for ERC1155 tokens. */ interface IERC1155Errors { /** * @dev Indicates an error related to the current `balance` of a `sender`. Used in transfers. * @param sender Address whose tokens are being transferred. * @param balance Current balance for the interacting account. * @param needed Minimum amount required to perform a transfer. * @param tokenId Identifier number of a token. */ error ERC1155InsufficientBalance(address sender, uint256 balance, uint256 needed, uint256 tokenId); /** * @dev Indicates a failure with the token `sender`. Used in transfers. * @param sender Address whose tokens are being transferred. */ error ERC1155InvalidSender(address sender); /** * @dev Indicates a failure with the token `receiver`. Used in transfers. * @param receiver Address to which tokens are being transferred. */ error ERC1155InvalidReceiver(address receiver); /** * @dev Indicates a failure with the `operator`’s approval. Used in transfers. * @param operator Address that may be allowed to operate on tokens without being their owner. * @param owner Address of the current owner of a token. */ error ERC1155MissingApprovalForAll(address operator, address owner); /** * @dev Indicates a failure with the `approver` of a token to be approved. Used in approvals. * @param approver Address initiating an approval operation. */ error ERC1155InvalidApprover(address approver); /** * @dev Indicates a failure with the `operator` to be approved. Used in approvals. * @param operator Address that may be allowed to operate on tokens without being their owner. */ error ERC1155InvalidOperator(address operator); /** * @dev Indicates an array length mismatch between ids and values in a safeBatchTransferFrom operation. * Used in batch transfers. * @param idsLength Length of the array of token identifiers * @param valuesLength Length of the array of token amounts */ error ERC1155InvalidArrayLength(uint256 idsLength, uint256 valuesLength); }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/Strings.sol) pragma solidity ^0.8.20; import {Math} from "./math/Math.sol"; import {SignedMath} from "./math/SignedMath.sol"; /** * @dev String operations. */ library Strings { bytes16 private constant HEX_DIGITS = "0123456789abcdef"; uint8 private constant ADDRESS_LENGTH = 20; /** * @dev The `value` string doesn't fit in the specified `length`. */ error StringsInsufficientHexLength(uint256 value, uint256 length); /** * @dev Converts a `uint256` to its ASCII `string` decimal representation. */ function toString(uint256 value) internal pure returns (string memory) { unchecked { uint256 length = Math.log10(value) + 1; string memory buffer = new string(length); uint256 ptr; /// @solidity memory-safe-assembly assembly { ptr := add(buffer, add(32, length)) } while (true) { ptr--; /// @solidity memory-safe-assembly assembly { mstore8(ptr, byte(mod(value, 10), HEX_DIGITS)) } value /= 10; if (value == 0) break; } return buffer; } } /** * @dev Converts a `int256` to its ASCII `string` decimal representation. */ function toStringSigned(int256 value) internal pure returns (string memory) { return string.concat(value < 0 ? "-" : "", toString(SignedMath.abs(value))); } /** * @dev Converts a `uint256` to its ASCII `string` hexadecimal representation. */ function toHexString(uint256 value) internal pure returns (string memory) { unchecked { return toHexString(value, Math.log256(value) + 1); } } /** * @dev Converts a `uint256` to its ASCII `string` hexadecimal representation with fixed length. */ function toHexString(uint256 value, uint256 length) internal pure returns (string memory) { uint256 localValue = value; bytes memory buffer = new bytes(2 * length + 2); buffer[0] = "0"; buffer[1] = "x"; for (uint256 i = 2 * length + 1; i > 1; --i) { buffer[i] = HEX_DIGITS[localValue & 0xf]; localValue >>= 4; } if (localValue != 0) { revert StringsInsufficientHexLength(value, length); } return string(buffer); } /** * @dev Converts an `address` with fixed length of 20 bytes to its not checksummed ASCII `string` hexadecimal * representation. */ function toHexString(address addr) internal pure returns (string memory) { return toHexString(uint256(uint160(addr)), ADDRESS_LENGTH); } /** * @dev Returns true if the two strings are equal. */ function equal(string memory a, string memory b) internal pure returns (bool) { return bytes(a).length == bytes(b).length && keccak256(bytes(a)) == keccak256(bytes(b)); } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/math/SignedMath.sol) pragma solidity ^0.8.20; /** * @dev Standard signed math utilities missing in the Solidity language. */ library SignedMath { /** * @dev Returns the largest of two signed numbers. */ function max(int256 a, int256 b) internal pure returns (int256) { return a > b ? a : b; } /** * @dev Returns the smallest of two signed numbers. */ function min(int256 a, int256 b) internal pure returns (int256) { return a < b ? a : b; } /** * @dev Returns the average of two signed numbers without overflow. * The result is rounded towards zero. */ function average(int256 a, int256 b) internal pure returns (int256) { // Formula from the book "Hacker's Delight" int256 x = (a & b) + ((a ^ b) >> 1); return x + (int256(uint256(x) >> 255) & (a ^ b)); } /** * @dev Returns the absolute unsigned value of a signed value. */ function abs(int256 n) internal pure returns (uint256) { unchecked { // must be unchecked in order to support `n = type(int256).min` return uint256(n >= 0 ? n : -n); } } }
// SPDX-License-Identifier: MIT // OpenZeppelin Contracts (last updated v5.0.0) (utils/math/Math.sol) pragma solidity ^0.8.20; /** * @dev Standard math utilities missing in the Solidity language. */ library Math { /** * @dev Muldiv operation overflow. */ error MathOverflowedMulDiv(); enum Rounding { Floor, // Toward negative infinity Ceil, // Toward positive infinity Trunc, // Toward zero Expand // Away from zero } /** * @dev Returns the addition of two unsigned integers, with an overflow flag. */ function tryAdd(uint256 a, uint256 b) internal pure returns (bool, uint256) { unchecked { uint256 c = a + b; if (c < a) return (false, 0); return (true, c); } } /** * @dev Returns the subtraction of two unsigned integers, with an overflow flag. */ function trySub(uint256 a, uint256 b) internal pure returns (bool, uint256) { unchecked { if (b > a) return (false, 0); return (true, a - b); } } /** * @dev Returns the multiplication of two unsigned integers, with an overflow flag. */ function tryMul(uint256 a, uint256 b) internal pure returns (bool, uint256) { unchecked { // Gas optimization: this is cheaper than requiring 'a' not being zero, but the // benefit is lost if 'b' is also tested. // See: https://github.com/OpenZeppelin/openzeppelin-contracts/pull/522 if (a == 0) return (true, 0); uint256 c = a * b; if (c / a != b) return (false, 0); return (true, c); } } /** * @dev Returns the division of two unsigned integers, with a division by zero flag. */ function tryDiv(uint256 a, uint256 b) internal pure returns (bool, uint256) { unchecked { if (b == 0) return (false, 0); return (true, a / b); } } /** * @dev Returns the remainder of dividing two unsigned integers, with a division by zero flag. */ function tryMod(uint256 a, uint256 b) internal pure returns (bool, uint256) { unchecked { if (b == 0) return (false, 0); return (true, a % b); } } /** * @dev Returns the largest of two numbers. */ function max(uint256 a, uint256 b) internal pure returns (uint256) { return a > b ? a : b; } /** * @dev Returns the smallest of two numbers. */ function min(uint256 a, uint256 b) internal pure returns (uint256) { return a < b ? a : b; } /** * @dev Returns the average of two numbers. The result is rounded towards * zero. */ function average(uint256 a, uint256 b) internal pure returns (uint256) { // (a + b) / 2 can overflow. return (a & b) + (a ^ b) / 2; } /** * @dev Returns the ceiling of the division of two numbers. * * This differs from standard division with `/` in that it rounds towards infinity instead * of rounding towards zero. */ function ceilDiv(uint256 a, uint256 b) internal pure returns (uint256) { if (b == 0) { // Guarantee the same behavior as in a regular Solidity division. return a / b; } // (a + b - 1) / b can overflow on addition, so we distribute. return a == 0 ? 0 : (a - 1) / b + 1; } /** * @notice Calculates floor(x * y / denominator) with full precision. Throws if result overflows a uint256 or * denominator == 0. * @dev Original credit to Remco Bloemen under MIT license (https://xn--2-umb.com/21/muldiv) with further edits by * Uniswap Labs also under MIT license. */ function mulDiv(uint256 x, uint256 y, uint256 denominator) internal pure returns (uint256 result) { unchecked { // 512-bit multiply [prod1 prod0] = x * y. Compute the product mod 2^256 and mod 2^256 - 1, then use // use the Chinese Remainder Theorem to reconstruct the 512 bit result. The result is stored in two 256 // variables such that product = prod1 * 2^256 + prod0. uint256 prod0 = x * y; // Least significant 256 bits of the product uint256 prod1; // Most significant 256 bits of the product assembly { let mm := mulmod(x, y, not(0)) prod1 := sub(sub(mm, prod0), lt(mm, prod0)) } // Handle non-overflow cases, 256 by 256 division. if (prod1 == 0) { // Solidity will revert if denominator == 0, unlike the div opcode on its own. // The surrounding unchecked block does not change this fact. // See https://docs.soliditylang.org/en/latest/control-structures.html#checked-or-unchecked-arithmetic. return prod0 / denominator; } // Make sure the result is less than 2^256. Also prevents denominator == 0. if (denominator <= prod1) { revert MathOverflowedMulDiv(); } /////////////////////////////////////////////// // 512 by 256 division. /////////////////////////////////////////////// // Make division exact by subtracting the remainder from [prod1 prod0]. uint256 remainder; assembly { // Compute remainder using mulmod. remainder := mulmod(x, y, denominator) // Subtract 256 bit number from 512 bit number. prod1 := sub(prod1, gt(remainder, prod0)) prod0 := sub(prod0, remainder) } // Factor powers of two out of denominator and compute largest power of two divisor of denominator. // Always >= 1. See https://cs.stackexchange.com/q/138556/92363. uint256 twos = denominator & (0 - denominator); assembly { // Divide denominator by twos. denominator := div(denominator, twos) // Divide [prod1 prod0] by twos. prod0 := div(prod0, twos) // Flip twos such that it is 2^256 / twos. If twos is zero, then it becomes one. twos := add(div(sub(0, twos), twos), 1) } // Shift in bits from prod1 into prod0. prod0 |= prod1 * twos; // Invert denominator mod 2^256. Now that denominator is an odd number, it has an inverse modulo 2^256 such // that denominator * inv = 1 mod 2^256. Compute the inverse by starting with a seed that is correct for // four bits. That is, denominator * inv = 1 mod 2^4. uint256 inverse = (3 * denominator) ^ 2; // Use the Newton-Raphson iteration to improve the precision. Thanks to Hensel's lifting lemma, this also // works in modular arithmetic, doubling the correct bits in each step. inverse *= 2 - denominator * inverse; // inverse mod 2^8 inverse *= 2 - denominator * inverse; // inverse mod 2^16 inverse *= 2 - denominator * inverse; // inverse mod 2^32 inverse *= 2 - denominator * inverse; // inverse mod 2^64 inverse *= 2 - denominator * inverse; // inverse mod 2^128 inverse *= 2 - denominator * inverse; // inverse mod 2^256 // Because the division is now exact we can divide by multiplying with the modular inverse of denominator. // This will give us the correct result modulo 2^256. Since the preconditions guarantee that the outcome is // less than 2^256, this is the final result. We don't need to compute the high bits of the result and prod1 // is no longer required. result = prod0 * inverse; return result; } } /** * @notice Calculates x * y / denominator with full precision, following the selected rounding direction. */ function mulDiv(uint256 x, uint256 y, uint256 denominator, Rounding rounding) internal pure returns (uint256) { uint256 result = mulDiv(x, y, denominator); if (unsignedRoundsUp(rounding) && mulmod(x, y, denominator) > 0) { result += 1; } return result; } /** * @dev Returns the square root of a number. If the number is not a perfect square, the value is rounded * towards zero. * * Inspired by Henry S. Warren, Jr.'s "Hacker's Delight" (Chapter 11). */ function sqrt(uint256 a) internal pure returns (uint256) { if (a == 0) { return 0; } // For our first guess, we get the biggest power of 2 which is smaller than the square root of the target. // // We know that the "msb" (most significant bit) of our target number `a` is a power of 2 such that we have // `msb(a) <= a < 2*msb(a)`. This value can be written `msb(a)=2**k` with `k=log2(a)`. // // This can be rewritten `2**log2(a) <= a < 2**(log2(a) + 1)` // → `sqrt(2**k) <= sqrt(a) < sqrt(2**(k+1))` // → `2**(k/2) <= sqrt(a) < 2**((k+1)/2) <= 2**(k/2 + 1)` // // Consequently, `2**(log2(a) / 2)` is a good first approximation of `sqrt(a)` with at least 1 correct bit. uint256 result = 1 << (log2(a) >> 1); // At this point `result` is an estimation with one bit of precision. We know the true value is a uint128, // since it is the square root of a uint256. Newton's method converges quadratically (precision doubles at // every iteration). We thus need at most 7 iteration to turn our partial result with one bit of precision // into the expected uint128 result. unchecked { result = (result + a / result) >> 1; result = (result + a / result) >> 1; result = (result + a / result) >> 1; result = (result + a / result) >> 1; result = (result + a / result) >> 1; result = (result + a / result) >> 1; result = (result + a / result) >> 1; return min(result, a / result); } } /** * @notice Calculates sqrt(a), following the selected rounding direction. */ function sqrt(uint256 a, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = sqrt(a); return result + (unsignedRoundsUp(rounding) && result * result < a ? 1 : 0); } } /** * @dev Return the log in base 2 of a positive value rounded towards zero. * Returns 0 if given 0. */ function log2(uint256 value) internal pure returns (uint256) { uint256 result = 0; unchecked { if (value >> 128 > 0) { value >>= 128; result += 128; } if (value >> 64 > 0) { value >>= 64; result += 64; } if (value >> 32 > 0) { value >>= 32; result += 32; } if (value >> 16 > 0) { value >>= 16; result += 16; } if (value >> 8 > 0) { value >>= 8; result += 8; } if (value >> 4 > 0) { value >>= 4; result += 4; } if (value >> 2 > 0) { value >>= 2; result += 2; } if (value >> 1 > 0) { result += 1; } } return result; } /** * @dev Return the log in base 2, following the selected rounding direction, of a positive value. * Returns 0 if given 0. */ function log2(uint256 value, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = log2(value); return result + (unsignedRoundsUp(rounding) && 1 << result < value ? 1 : 0); } } /** * @dev Return the log in base 10 of a positive value rounded towards zero. * Returns 0 if given 0. */ function log10(uint256 value) internal pure returns (uint256) { uint256 result = 0; unchecked { if (value >= 10 ** 64) { value /= 10 ** 64; result += 64; } if (value >= 10 ** 32) { value /= 10 ** 32; result += 32; } if (value >= 10 ** 16) { value /= 10 ** 16; result += 16; } if (value >= 10 ** 8) { value /= 10 ** 8; result += 8; } if (value >= 10 ** 4) { value /= 10 ** 4; result += 4; } if (value >= 10 ** 2) { value /= 10 ** 2; result += 2; } if (value >= 10 ** 1) { result += 1; } } return result; } /** * @dev Return the log in base 10, following the selected rounding direction, of a positive value. * Returns 0 if given 0. */ function log10(uint256 value, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = log10(value); return result + (unsignedRoundsUp(rounding) && 10 ** result < value ? 1 : 0); } } /** * @dev Return the log in base 256 of a positive value rounded towards zero. * Returns 0 if given 0. * * Adding one to the result gives the number of pairs of hex symbols needed to represent `value` as a hex string. */ function log256(uint256 value) internal pure returns (uint256) { uint256 result = 0; unchecked { if (value >> 128 > 0) { value >>= 128; result += 16; } if (value >> 64 > 0) { value >>= 64; result += 8; } if (value >> 32 > 0) { value >>= 32; result += 4; } if (value >> 16 > 0) { value >>= 16; result += 2; } if (value >> 8 > 0) { result += 1; } } return result; } /** * @dev Return the log in base 256, following the selected rounding direction, of a positive value. * Returns 0 if given 0. */ function log256(uint256 value, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = log256(value); return result + (unsignedRoundsUp(rounding) && 1 << (result << 3) < value ? 1 : 0); } } /** * @dev Returns whether a provided rounding mode is considered rounding up for unsigned integers. */ function unsignedRoundsUp(Rounding rounding) internal pure returns (bool) { return uint8(rounding) % 2 == 1; } }
{ "evmVersion": "paris", "optimizer": { "enabled": true, "mode": "3" }, "outputSelection": { "*": { "*": [ "abi" ] } }, "detectMissingLibraries": false, "forceEVMLA": false, "enableEraVMExtensions": true, "libraries": {} }
Contract Security Audit
- No Contract Security Audit Submitted- Submit Audit Here
Contract ABI
API[{"inputs":[{"internalType":"address","name":"_endpoint","type":"address"},{"internalType":"uint32","name":"_srcEid","type":"uint32"}],"stateMutability":"nonpayable","type":"constructor"},{"inputs":[{"internalType":"address","name":"target","type":"address"}],"name":"AddressEmptyCode","type":"error"},{"inputs":[{"internalType":"address","name":"account","type":"address"}],"name":"AddressInsufficientBalance","type":"error"},{"inputs":[],"name":"ECDSAInvalidSignature","type":"error"},{"inputs":[{"internalType":"uint256","name":"length","type":"uint256"}],"name":"ECDSAInvalidSignatureLength","type":"error"},{"inputs":[{"internalType":"bytes32","name":"s","type":"bytes32"}],"name":"ECDSAInvalidSignatureS","type":"error"},{"inputs":[{"internalType":"address","name":"spender","type":"address"},{"internalType":"uint256","name":"allowance","type":"uint256"},{"internalType":"uint256","name":"needed","type":"uint256"}],"name":"ERC20InsufficientAllowance","type":"error"},{"inputs":[{"internalType":"address","name":"sender","type":"address"},{"internalType":"uint256","name":"balance","type":"uint256"},{"internalType":"uint256","name":"needed","type":"uint256"}],"name":"ERC20InsufficientBalance","type":"error"},{"inputs":[{"internalType":"address","name":"approver","type":"address"}],"name":"ERC20InvalidApprover","type":"error"},{"inputs":[{"internalType":"address","name":"receiver","type":"address"}],"name":"ERC20InvalidReceiver","type":"error"},{"inputs":[{"internalType":"address","name":"sender","type":"address"}],"name":"ERC20InvalidSender","type":"error"},{"inputs":[{"internalType":"address","name":"spender","type":"address"}],"name":"ERC20InvalidSpender","type":"error"},{"inputs":[{"internalType":"uint256","name":"deadline","type":"uint256"}],"name":"ERC2612ExpiredSignature","type":"error"},{"inputs":[{"internalType":"address","name":"signer","type":"address"},{"internalType":"address","name":"owner","type":"address"}],"name":"ERC2612InvalidSigner","type":"error"},{"inputs":[],"name":"EnforcedPause","type":"error"},{"inputs":[],"name":"ExpectedPause","type":"error"},{"inputs":[],"name":"FailedInnerCall","type":"error"},{"inputs":[],"name":"InsufficientAmountOut","type":"error"},{"inputs":[],"name":"InsufficientAmountToSync","type":"error"},{"inputs":[{"internalType":"address","name":"account","type":"address"},{"internalType":"uint256","name":"currentNonce","type":"uint256"}],"name":"InvalidAccountNonce","type":"error"},{"inputs":[],"name":"InvalidAmount","type":"error"},{"inputs":[],"name":"InvalidAmountIn","type":"error"},{"inputs":[],"name":"InvalidDelegate","type":"error"},{"inputs":[],"name":"InvalidEndpointCall","type":"error"},{"inputs":[],"name":"InvalidFee","type":"error"},{"inputs":[],"name":"InvalidInitialization","type":"error"},{"inputs":[],"name":"InvalidNonce","type":"error"},{"inputs":[{"internalType":"bytes","name":"options","type":"bytes"}],"name":"InvalidOptions","type":"error"},{"inputs":[],"name":"InvalidRate","type":"error"},{"inputs":[],"name":"InvalidReceiver","type":"error"},{"inputs":[],"name":"LzTokenUnavailable","type":"error"},{"inputs":[],"name":"MaxSyncAmountExceeded","type":"error"},{"inputs":[{"internalType":"uint32","name":"eid","type":"uint32"}],"name":"NoPeer","type":"error"},{"inputs":[],"name":"NotAllowed","type":"error"},{"inputs":[{"internalType":"uint256","name":"msgValue","type":"uint256"}],"name":"NotEnoughNative","type":"error"},{"inputs":[],"name":"NotInitializing","type":"error"},{"inputs":[{"internalType":"address","name":"addr","type":"address"}],"name":"OnlyEndpoint","type":"error"},{"inputs":[{"internalType":"uint32","name":"eid","type":"uint32"},{"internalType":"bytes32","name":"sender","type":"bytes32"}],"name":"OnlyPeer","type":"error"},{"inputs":[{"internalType":"address","name":"owner","type":"address"}],"name":"OwnableInvalidOwner","type":"error"},{"inputs":[{"internalType":"address","name":"account","type":"address"}],"name":"OwnableUnauthorizedAccount","type":"error"},{"inputs":[],"name":"ReentrancyGuardReentrantCall","type":"error"},{"inputs":[{"internalType":"address","name":"token","type":"address"}],"name":"SafeERC20FailedOperation","type":"error"},{"inputs":[],"name":"UnauthorizedCaller","type":"error"},{"inputs":[],"name":"UnauthorizedToken","type":"error"},{"inputs":[],"name":"ZeroAddress","type":"error"},{"inputs":[],"name":"ZeroAmount","type":"error"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"owner","type":"address"},{"indexed":true,"internalType":"address","name":"spender","type":"address"},{"indexed":false,"internalType":"uint256","name":"value","type":"uint256"}],"name":"Approval","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"bridgeQuoter","type":"address"}],"name":"BridgeQuoterSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"tokenIn","type":"address"},{"indexed":false,"internalType":"uint256","name":"amountIn","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"amountOut","type":"uint256"}],"name":"Deposit","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"bytes32","name":"guid","type":"bytes32"},{"indexed":true,"internalType":"address","name":"toAddress","type":"address"},{"indexed":false,"internalType":"uint256","name":"shares","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"amount","type":"uint256"}],"name":"Deposit","type":"event"},{"anonymous":false,"inputs":[],"name":"EIP712DomainChanged","type":"event"},{"anonymous":false,"inputs":[{"components":[{"internalType":"uint32","name":"eid","type":"uint32"},{"internalType":"uint16","name":"msgType","type":"uint16"},{"internalType":"bytes","name":"options","type":"bytes"}],"indexed":false,"internalType":"struct EnforcedOptionParam[]","name":"_enforcedOptions","type":"tuple[]"}],"name":"EnforcedOptionSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"uint64","name":"version","type":"uint64"}],"name":"Initialized","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"tokenIn","type":"address"},{"indexed":false,"internalType":"address","name":"l1TokenIn","type":"address"}],"name":"L1TokenInSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"l2ExchangeRateProvider","type":"address"}],"name":"L2ExchangeRateProviderSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"tokenIn","type":"address"},{"indexed":false,"internalType":"uint256","name":"maxSyncAmount","type":"uint256"}],"name":"MaxSyncAmountSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"messenger","type":"address"}],"name":"MessengerSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"tokenIn","type":"address"},{"indexed":false,"internalType":"uint256","name":"minSyncAmount","type":"uint256"}],"name":"MinSyncAmountSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"toAddress","type":"address"},{"indexed":false,"internalType":"uint256","name":"shares","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"amount","type":"uint256"}],"name":"Mint","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"previousOwner","type":"address"},{"indexed":true,"internalType":"address","name":"newOwner","type":"address"}],"name":"OwnershipTransferred","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"account","type":"address"}],"name":"Paused","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"uint32","name":"eid","type":"uint32"},{"indexed":false,"internalType":"bytes32","name":"peer","type":"bytes32"}],"name":"PeerSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"rateLimiter","type":"address"}],"name":"RateLimiterSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"bytes32","name":"guid","type":"bytes32"},{"indexed":true,"internalType":"address","name":"treasury","type":"address"},{"indexed":false,"internalType":"uint256","name":"assetsPerShare","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"amount","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"fee","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"feeShares","type":"uint256"}],"name":"Rebase","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"receiver","type":"address"}],"name":"ReceiverSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"account","type":"address"},{"indexed":false,"internalType":"uint256","name":"preRebaseTokenAmount","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"postRebaseTokenAmount","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"sharesAmount","type":"uint256"}],"name":"SharesBurnt","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"tokenIn","type":"address"},{"indexed":false,"internalType":"uint256","name":"amountIn","type":"uint256"},{"indexed":false,"internalType":"uint256","name":"amountOut","type":"uint256"}],"name":"Sync","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"syncKeeper","type":"address"},{"indexed":false,"internalType":"bool","name":"status","type":"bool"}],"name":"SyncKeeperSet","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"from","type":"address"},{"indexed":true,"internalType":"address","name":"to","type":"address"},{"indexed":false,"internalType":"uint256","name":"value","type":"uint256"}],"name":"Transfer","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"from","type":"address"},{"indexed":true,"internalType":"address","name":"to","type":"address"},{"indexed":false,"internalType":"uint256","name":"sharesValue","type":"uint256"}],"name":"TransferShares","type":"event"},{"anonymous":false,"inputs":[{"indexed":false,"internalType":"address","name":"account","type":"address"}],"name":"Unpaused","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"bytes32","name":"guid","type":"bytes32"},{"indexed":true,"internalType":"address","name":"fromAddress","type":"address"},{"indexed":true,"internalType":"address","name":"toAddress","type":"address"},{"indexed":false,"internalType":"uint256","name":"amount","type":"uint256"}],"name":"Withdrawal","type":"event"},{"anonymous":false,"inputs":[{"indexed":true,"internalType":"address","name":"account","type":"address"},{"indexed":false,"internalType":"bool","name":"allowed","type":"bool"}],"name":"canPauseSet","type":"event"},{"inputs":[],"name":"DOMAIN_SEPARATOR","outputs":[{"internalType":"bytes32","name":"","type":"bytes32"}],"stateMutability":"view","type":"function"},{"inputs":[{"components":[{"internalType":"uint32","name":"srcEid","type":"uint32"},{"internalType":"bytes32","name":"sender","type":"bytes32"},{"internalType":"uint64","name":"nonce","type":"uint64"}],"internalType":"struct Origin","name":"origin","type":"tuple"}],"name":"allowInitializePath","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"owner","type":"address"},{"internalType":"address","name":"spender","type":"address"}],"name":"allowance","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"spender","type":"address"},{"internalType":"uint256","name":"value","type":"uint256"}],"name":"approve","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_account","type":"address"}],"name":"balanceOf","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"_address","type":"address"}],"name":"canPause","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint32","name":"_eid","type":"uint32"},{"internalType":"uint16","name":"_msgType","type":"uint16"},{"internalType":"bytes","name":"_extraOptions","type":"bytes"}],"name":"combineOptions","outputs":[{"internalType":"bytes","name":"","type":"bytes"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"composeMsgSender","outputs":[{"internalType":"address","name":"sender","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint256","name":"_shares","type":"uint256"},{"internalType":"bool","name":"floor","type":"bool"}],"name":"convertToAssets","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint256","name":"_assets","type":"uint256"}],"name":"convertToShares","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"decimals","outputs":[{"internalType":"uint8","name":"","type":"uint8"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"tokenIn","type":"address"},{"internalType":"uint256","name":"amountIn","type":"uint256"},{"internalType":"uint256","name":"minAmountOut","type":"uint256"},{"internalType":"bool","name":"shouldWrap","type":"bool"}],"name":"deposit","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"payable","type":"function"},{"inputs":[],"name":"eip712Domain","outputs":[{"internalType":"bytes1","name":"fields","type":"bytes1"},{"internalType":"string","name":"name","type":"string"},{"internalType":"string","name":"version","type":"string"},{"internalType":"uint256","name":"chainId","type":"uint256"},{"internalType":"address","name":"verifyingContract","type":"address"},{"internalType":"bytes32","name":"salt","type":"bytes32"},{"internalType":"uint256[]","name":"extensions","type":"uint256[]"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"endpoint","outputs":[{"internalType":"contract ILayerZeroEndpointV2","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint32","name":"_eid","type":"uint32"},{"internalType":"uint16","name":"_msgType","type":"uint16"}],"name":"enforcedOptions","outputs":[{"internalType":"bytes","name":"","type":"bytes"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"getL2ExchangeRateProvider","outputs":[{"internalType":"address","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"getMessenger","outputs":[{"internalType":"address","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"getRateLimiter","outputs":[{"internalType":"address","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"getReceiver","outputs":[{"internalType":"address","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"tokenIn","type":"address"}],"name":"getTokenData","outputs":[{"components":[{"internalType":"uint256","name":"unsyncedAmountIn","type":"uint256"},{"internalType":"uint256","name":"unsyncedAmountOut","type":"uint256"},{"internalType":"uint256","name":"minSyncAmount","type":"uint256"},{"internalType":"uint256","name":"maxSyncAmount","type":"uint256"},{"internalType":"address","name":"l1Address","type":"address"}],"internalType":"struct L2SyncPool.Token","name":"","type":"tuple"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"getTotalShares","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"_delegate","type":"address"},{"internalType":"address","name":"_owner","type":"address"},{"internalType":"address","name":"_treasury","type":"address"},{"internalType":"address","name":"_l2ExchangeRateProvider","type":"address"},{"internalType":"address","name":"_rateLimiter","type":"address"},{"internalType":"address","name":"_messenger","type":"address"},{"internalType":"address","name":"_receiver","type":"address"},{"internalType":"address","name":"_bridgeQuoter","type":"address"},{"internalType":"string","name":"_name","type":"string"},{"internalType":"string","name":"_symbol","type":"string"}],"name":"initialize","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"syncKeeper","type":"address"}],"name":"isSyncKeeper","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"lastAssetsPerShare","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"components":[{"internalType":"uint32","name":"srcEid","type":"uint32"},{"internalType":"bytes32","name":"sender","type":"bytes32"},{"internalType":"uint64","name":"nonce","type":"uint64"}],"internalType":"struct Origin","name":"_origin","type":"tuple"},{"internalType":"bytes32","name":"_guid","type":"bytes32"},{"internalType":"bytes","name":"_message","type":"bytes"},{"internalType":"address","name":"_executor","type":"address"},{"internalType":"bytes","name":"_extraData","type":"bytes"}],"name":"lzReceive","outputs":[],"stateMutability":"payable","type":"function"},{"inputs":[],"name":"name","outputs":[{"internalType":"string","name":"","type":"string"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint32","name":"_srcEid","type":"uint32"},{"internalType":"bytes32","name":"_sender","type":"bytes32"}],"name":"nextNonce","outputs":[{"internalType":"uint64","name":"","type":"uint64"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"owner","type":"address"}],"name":"nonces","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"oAppVersion","outputs":[{"internalType":"uint64","name":"senderVersion","type":"uint64"},{"internalType":"uint64","name":"receiverVersion","type":"uint64"}],"stateMutability":"pure","type":"function"},{"inputs":[],"name":"owner","outputs":[{"internalType":"address","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"pause","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[],"name":"paused","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint32","name":"_eid","type":"uint32"}],"name":"peers","outputs":[{"internalType":"bytes32","name":"","type":"bytes32"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"bool","name":"includeUnsynced","type":"bool"}],"name":"pendingDeposit","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"owner","type":"address"},{"internalType":"address","name":"spender","type":"address"},{"internalType":"uint256","name":"value","type":"uint256"},{"internalType":"uint256","name":"deadline","type":"uint256"},{"internalType":"uint8","name":"v","type":"uint8"},{"internalType":"bytes32","name":"r","type":"bytes32"},{"internalType":"bytes32","name":"s","type":"bytes32"}],"name":"permit","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"uint256","name":"_assets","type":"uint256"}],"name":"previewWithdraw","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"_tokenIn","type":"address"},{"internalType":"bytes","name":"_options","type":"bytes"}],"name":"quoteSync","outputs":[{"components":[{"internalType":"uint256","name":"nativeFee","type":"uint256"},{"internalType":"uint256","name":"lzTokenFee","type":"uint256"}],"internalType":"struct MessagingFee","name":"msgFee","type":"tuple"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"_receiver","type":"address"},{"internalType":"uint256","name":"_amount","type":"uint256"},{"internalType":"bytes","name":"_options","type":"bytes"}],"name":"quoteWithdraw","outputs":[{"components":[{"internalType":"uint256","name":"nativeFee","type":"uint256"},{"internalType":"uint256","name":"lzTokenFee","type":"uint256"}],"internalType":"struct MessagingFee","name":"msgFee","type":"tuple"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"rebaseFee","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"renounceOwnership","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"bridgeQuoter","type":"address"}],"name":"setBridgeQuoter","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_address","type":"address"},{"internalType":"bool","name":"_allowed","type":"bool"}],"name":"setCanPause","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_delegate","type":"address"}],"name":"setDelegate","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"components":[{"internalType":"uint32","name":"eid","type":"uint32"},{"internalType":"uint16","name":"msgType","type":"uint16"},{"internalType":"bytes","name":"options","type":"bytes"}],"internalType":"struct EnforcedOptionParam[]","name":"_enforcedOptions","type":"tuple[]"}],"name":"setEnforcedOptions","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"l2TokenIn","type":"address"},{"internalType":"address","name":"l1TokenIn","type":"address"}],"name":"setL1TokenIn","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"l2ExchangeRateProvider","type":"address"}],"name":"setL2ExchangeRateProvider","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"tokenIn","type":"address"},{"internalType":"uint256","name":"maxSyncAmount","type":"uint256"}],"name":"setMaxSyncAmount","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"messenger","type":"address"}],"name":"setMessenger","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"tokenIn","type":"address"},{"internalType":"uint256","name":"minSyncAmount","type":"uint256"}],"name":"setMinSyncAmount","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"uint32","name":"_srcEid","type":"uint32"},{"internalType":"bytes32","name":"_sender","type":"bytes32"},{"internalType":"uint64","name":"_nonce","type":"uint64"}],"name":"setNonce","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"uint32","name":"_eid","type":"uint32"},{"internalType":"bytes32","name":"_peer","type":"bytes32"}],"name":"setPeer","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"rateLimiter","type":"address"}],"name":"setRateLimiter","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"uint256","name":"_rebaseFee","type":"uint256"}],"name":"setRebaseFee","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"receiver","type":"address"}],"name":"setReceiver","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"uint256","name":"_syncDepositFee","type":"uint256"}],"name":"setSyncDepositFee","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"syncKeeper","type":"address"},{"internalType":"bool","name":"status","type":"bool"}],"name":"setSyncKeeper","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_treasury","type":"address"}],"name":"setTreasury","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_wLST","type":"address"}],"name":"setWrappedLST","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_account","type":"address"}],"name":"sharesOf","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"symbol","outputs":[{"internalType":"string","name":"","type":"string"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"tokenIn","type":"address"},{"internalType":"bytes","name":"extraOptions","type":"bytes"},{"components":[{"internalType":"uint256","name":"nativeFee","type":"uint256"},{"internalType":"uint256","name":"lzTokenFee","type":"uint256"}],"internalType":"struct MessagingFee","name":"fee","type":"tuple"}],"name":"sync","outputs":[{"internalType":"uint256","name":"unsyncedAmountIn","type":"uint256"},{"internalType":"uint256","name":"unsyncedAmountOut","type":"uint256"}],"stateMutability":"payable","type":"function"},{"inputs":[{"internalType":"address","name":"tokenIn","type":"address"},{"internalType":"uint256","name":"amount","type":"uint256"},{"internalType":"bytes","name":"extraOptions","type":"bytes"},{"components":[{"internalType":"uint256","name":"nativeFee","type":"uint256"},{"internalType":"uint256","name":"lzTokenFee","type":"uint256"}],"internalType":"struct MessagingFee","name":"fee","type":"tuple"}],"name":"sync","outputs":[{"internalType":"uint256","name":"","type":"uint256"},{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"payable","type":"function"},{"inputs":[],"name":"syncDepositFee","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"uint256","name":"idx","type":"uint256"}],"name":"syncIndexPendingAmount","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"syncIndexes","outputs":[{"internalType":"uint256","name":"lastPendingSyncIndex","type":"uint256"},{"internalType":"uint256","name":"lastCompletedSyncIndex","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"totalAssets","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"totalStaked","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"totalSupply","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"view","type":"function"},{"inputs":[{"internalType":"address","name":"to","type":"address"},{"internalType":"uint256","name":"value","type":"uint256"}],"name":"transfer","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"from","type":"address"},{"internalType":"address","name":"to","type":"address"},{"internalType":"uint256","name":"value","type":"uint256"}],"name":"transferFrom","outputs":[{"internalType":"bool","name":"","type":"bool"}],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"newOwner","type":"address"}],"name":"transferOwnership","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_recipient","type":"address"},{"internalType":"uint256","name":"_shares","type":"uint256"}],"name":"transferShares","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_sender","type":"address"},{"internalType":"address","name":"_recipient","type":"address"},{"internalType":"uint256","name":"_shares","type":"uint256"}],"name":"transferSharesFrom","outputs":[{"internalType":"uint256","name":"","type":"uint256"}],"stateMutability":"nonpayable","type":"function"},{"inputs":[],"name":"treasury","outputs":[{"internalType":"address","name":"","type":"address"}],"stateMutability":"view","type":"function"},{"inputs":[],"name":"unpause","outputs":[],"stateMutability":"nonpayable","type":"function"},{"inputs":[{"internalType":"address","name":"_receiver","type":"address"},{"internalType":"address","name":"_refundAddress","type":"address"},{"internalType":"uint256","name":"_amount","type":"uint256"},{"internalType":"bytes","name":"_options","type":"bytes"}],"name":"withdraw","outputs":[],"stateMutability":"payable","type":"function"}]
Contract Creation Code
9c4d535b000000000000000000000000000000000000000000000000000000000000000001000b7dd690c72c7c839a760ef97505f037b722cbac3c96143a05c98d8f21c9000000000000000000000000000000000000000000000000000000000000006000000000000000000000000000000000000000000000000000000000000000400000000000000000000000005c6cff4b7c49805f8295ff73c204ac83f3bc4ae70000000000000000000000000000000000000000000000000000000000007595
Deployed Bytecode

Constructor Arguments (ABI-Encoded and is the last bytes of the Contract Creation Code above)
0000000000000000000000005c6cff4b7c49805f8295ff73c204ac83f3bc4ae70000000000000000000000000000000000000000000000000000000000007595
-----Decoded View---------------
Arg [0] : _endpoint (address): 0x5c6cfF4b7C49805F8295Ff73C204ac83f3bC4AE7
Arg [1] : _srcEid (uint32): 30101
-----Encoded View---------------
2 Constructor Arguments found :
Arg [0] : 0000000000000000000000005c6cff4b7c49805f8295ff73c204ac83f3bc4ae7
Arg [1] : 0000000000000000000000000000000000000000000000000000000000007595
Loading...
Loading
Loading...
Loading
Multichain Portfolio | 34 Chains
Chain | Token | Portfolio % | Price | Amount | Value |
---|
Loading...
Loading
Loading...
Loading
[ Download: CSV Export ]
A contract address hosts a smart contract, which is a set of code stored on the blockchain that runs when predetermined conditions are met. Learn more about addresses in our Knowledge Base.