Skip to content

docs(tip-1088): unify quote/swap fill logic - #6700

Merged
max-digi merged 8 commits into
mainfrom
tip/1088
Sep 15, 2026
Merged

max-digi merged 8 commits into
mainfrom
tip/1088

Conversation

@grandizzy

@grandizzy grandizzy commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Description

Proposes TIP-1088 for T11.

  1. Quote/swap parity — quote() runs the same per-order fill engine as
    swap(), read-only: same traversal, rounding, and InsufficientLiquidity
    behavior. minAmountOut = quote no longer reverts.

  2. Tick liquidity on demand (docs(tip-1088): derive tick liquidity on demand #6942) — write paths stop maintaining the
    per-tick totalLiquidity aggregate; getTickLevel derives it as a checked
    sum over active orders. No O(N) scans in write paths; slots deprecated in
    place at T11.

@github-actions

Copy link
Copy Markdown
Contributor

This PR has been marked stale due to 7 days of inactivity.

@github-actions github-actions Bot added the stale label Jul 15, 2026
Comment thread tips/tip-1088.md Outdated
Comment thread tips/tip-1088.md Outdated
Comment thread tips/tip-1088.md Outdated
@github-actions github-actions Bot removed the stale label Jul 16, 2026
Co-authored-by: Jennifer <jenpaff0@gmail.com>
Comment thread tips/tip-1088.md Outdated
Comment thread tips/tip-1088.md Outdated
Co-authored-by: 0xrusowsky <90208954+0xrusowsky@users.noreply.github.com>
0xrusowsky
0xrusowsky previously approved these changes Jul 21, 2026
@tempo-voight-kampff

Copy link
Copy Markdown

Hi @0xrusowsky — your review approval was detected by Voight-Kampff, but this repository configures allow-self-reviews: false, so the current head commit author cannot approve their own changes. Your review did not trigger an approval prompt and is not counted toward this PR.

Ask another reviewer to +1 the PR (or submit an "Approve" review) to satisfy the gate.

jenpaff and others added 2 commits July 21, 2026 21:35
Updates TIP-1088 to include the remaining tick-liquidity changes
implemented by #6939.

- Stops maintaining stored per-tick `totalLiquidity` at T9.
- Derives `getTickLevel.totalLiquidity` on demand with checked
summation.
- Deprecates existing aggregate slots in place without migration.
- Explicitly forbids O(N) liquidity scans in placement, fill,
cancellation, and flip paths.
- Documents the read/write gas and complexity changes.

Validation: `git diff --check`

Prompted by: @jenpaff
danrobinson
danrobinson previously approved these changes Jul 23, 2026
@tempo-voight-kampff

Copy link
Copy Markdown

Hi @danrobinson — your review approval was detected by Voight-Kampff, but there is no email mapping for your GitHub account, so no approval prompt can be sent to your device. Your review did not trigger an approval prompt and is not counted toward this PR.

Because Voight-Kampff does not know which email address belongs to @danrobinson yet, it cannot route to the correct device for approval. See go/vk.

@github-actions

Copy link
Copy Markdown
Contributor

This PR has been marked stale due to 7 days of inactivity.

@github-actions github-actions Bot added the stale label Jul 31, 2026
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Closed due to inactivity. Reopen if still needed.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

This PR has been marked stale due to 7 days of inactivity.

@github-actions github-actions Bot added the stale label Sep 3, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Closed due to inactivity. Reopen if still needed.

@github-actions github-actions Bot closed this Sep 7, 2026
@DaniPopes
DaniPopes deleted the tip/1088 branch September 10, 2026 23:25
@0xalpharush
0xalpharush restored the tip/1088 branch September 11, 2026 13:34
@0xalpharush 0xalpharush reopened this Sep 11, 2026
@github-actions github-actions Bot removed the stale label Sep 12, 2026
@max-digi
max-digi added this pull request to the merge queue Sep 15, 2026
Merged via the queue into main with commit e074a29 Sep 15, 2026
48 of 49 checks passed
@max-digi
max-digi deleted the tip/1088 branch September 15, 2026 09:35
@max-digi

Copy link
Copy Markdown
Contributor

cyclops audit

@tempoxyz-bot tempoxyz-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👁️ Cyclops Review

PR #6700 adds TIP-1088 for StablecoinDEX quote/swap fill parity and T11 deprecation of the stored per-tick totalLiquidity aggregate. The remaining actionable issues are inline.

Reviewer Callouts
  • ⚡ Stale aggregate slots: tips/tip-1088.md:72 says stale TickLevel.totalLiquidity slots remain and need not be cleared. That can permanently strand pre-T11 slot occupancy and its TIP-1060 clearing credit; decide whether to clear slot 1 on first post-T11 write/delete or document the state bloat explicitly.
  • ⚡ Book-structure invariants become load-bearing: Once depth is derived from head -> next, the spec should state invariants for tail, bitmap bits, best_*_tick, and non-orphaned live orders. The stored aggregate currently acts as a redundancy/canary that T11 removes.
  • ⚡ Quote mutability must remain view: The external quote ABI is view; routing through a shared engine should not be implemented by dispatching quote entrypoints through a mutating helper that rejects STATICCALL.

Comment thread tips/tip-1088.md
- Traverse the same reachable ticks and the same individual orders within those ticks, in the same priority order as `Execute` mode. Traversal occurs at **order granularity**, not tick-aggregate granularity.
- Apply the same rounding direction at every conversion step.
- Produce the same fill amounts and price progression as `Execute` mode for an identical state snapshot.
- Avoid all writes and side effects:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ [ISSUE] Simulate write ban omits DEX storage credits and lacks fail-closed enforcement

Simulate is specified by an enumerated no-write list, but the list does not explicitly cover the persistent TIP-1060 DEX storage-credit ledger (StorageCreditDeltas, dex_storage_credits, order-slot reuse/allocation). Current view(...) dispatch and the storage provider do not fail closed on missed writes, so an implementation that leaves storage-credit accrual/flush in the shared engine could let quotes/staticcalls persist free DEX storage credits; analogous missed writes could mint internal balances.

Recommended Fix: Explicitly include DEX storage-credit accrual/spend, order-id allocation, deleted-slot reuse, and storage-credit preservation state in the no-write invariant, and require a fail-closed read-only guard that aborts on any sstore, tstore, event/log, or journaled write during Simulate.

Comment thread tips/tip-1088.md

5. Tick liquidity compatibility at T11:
- The `getTickLevel` function signature and return shape remain unchanged.
- `getTickLevel.totalLiquidity` MUST equal the checked sum of `remaining` across all active orders in the tick's linked list.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ [ISSUE] Removing the aggregate bound can make getTickLevel.totalLiquidity overflow

The current totalLiquidity maintenance also enforces the only per-tick Σ remaining <= u128::MAX bound via a write-path checked_add. T11 forbids maintaining that aggregate and also forbids write-path traversal to validate it, while this line requires a checked uint128 sum on read. Bid-side books at negative ticks can keep quote escrow within the TIP-20 cap while base-denominated resting remaining exceeds u128::MAX, moving the overflow from placement to getTickLevel and making the getter revert for that tick until orders are cancelled/filled.

Recommended Fix: Keep an explicit write-path bound, define saturating/clamped getter semantics, or document the revert as an intended failure mode and update consumers/tests that currently treat getTickLevel as infallible.

Comment thread tips/tip-1088.md
6. API compatibility:
- External quote and swap method signatures remain unchanged.
- Quote precision now matches swap precision exactly for the same state snapshot. Parity is scoped to the fill math (tick/order traversal, rounding, and fill amounts); caller-level and token-specific constraints (e.g., TIP-20 transfer fees) and execute-only side effects are outside this guarantee. In particular, `swap()` places flip orders and `quote()` does not: a flip-order placement that raises a system error reverts `swap()` (post-T1A) but not `quote()`. Business-logic flip failures are swallowed and do not change the taker fill, so fill-math parity still holds; only execute-only revert outcomes differ.
- Gas costs change: `quote()` and `getTickLevel()` become more expensive because they traverse individual orders, while swap and order-management paths avoid the storage operations previously used to maintain `totalLiquidity`. Callers SHOULD NOT depend on specific gas costs for these functions.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ [ISSUE] On-demand getTickLevel traversal is unbounded and attacker-controlled

The spec acknowledges higher gas but gives no maximum list length, pagination, cap, or fallback. A maker can park many minimum-sized orders at a chosen tick and later cancel them, so a third party controls how many storage records this public getter must read. That turns a formerly O(1) view into an unbounded call that can revert/OOG for on-chain consumers and invariant checks even when the sum fits.

Recommended Fix: Preserve an O(1) depth value, add a bounded/paginated depth API with continuation state, or define capped/best-effort semantics for totalLiquidity above a documented traversal limit.

@max-digi

Copy link
Copy Markdown
Contributor

Must update copy to reflect that this will be in T12, not T11

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants