Skip to content

Sync: v3.3.0-rc2 from protocol-internal - #832

Merged
hieronx merged 1 commit into
mainfrom
sync/v3.3-rc2
Sep 9, 2026
Merged

hieronx merged 1 commit into
mainfrom
sync/v3.3-rc2

Conversation

@hieronx

@hieronx hieronx commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Publishes the v3.3 protocol as of protocol-internal#382, the fixes and hardening that followed the v3.3 audits.

Everything in it is additive: 30 files, 1558 insertions, no file deleted and env/ untouched.

  • Callback authentication. Fulfillment callbacks are bound to the pool they were authenticated for, rather than resolved through the share token's ERC-7575 pointer. VaultRouter.getVault validates the vault it resolves against the full (poolId, scId, asset) tuple it was asked about.
  • Transfer hooks. FreelyTransferable no longer strands deposit claims. Claim eligibility is now documented per entry point in src/token/hooks/README.md, since which party the hook is asked about differs between the legs that hand out shares and the legs that pay out assets.
  • Comment corrections. ShareTokenRegistrar.burn no longer claims the caller's allowance survives the burn, and IBaseTransferHook no longer implies the maxRedeem / maxWithdraw / claimableCancelDepositRequest views are what gate a claim.
  • Tests. New pool-isolation invariant (test/invariant/vaults/, reached with FOUNDRY_PROFILE=invariant), a hook permissiveness lattice, and a hook claim lifecycle suite pinning all four settlement legs across all four shipped hooks.
  • Out-of-scope list. docs/audits/out-of-scope/v3.3.0.md extended with what the audits surfaced and this release accepts.

Synced from protocol-internal#382

@hieronx
hieronx requested a review from onnovisser September 9, 2026 19:21
@hieronx
hieronx enabled auto-merge (squash) September 9, 2026 19:22
@hieronx
hieronx disabled auto-merge September 9, 2026 19:23
@hieronx
hieronx merged commit 60d240f into main Sep 9, 2026
2 checks passed
@hieronx
hieronx deleted the sync/v3.3-rc2 branch September 9, 2026 19:24
@wischli wischli added sync:public Public-first, may need backport to internal version:v3.3.0 Scoped for v3.3.0 labels Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

sync:public Public-first, may need backport to internal version:v3.3.0 Scoped for v3.3.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants