Skip to content

[CRITICAL] No upgrade coordination between contracts — independent upgrades break cross-contract ABI #170

Description

@grantfox-oss

Summary

The four contracts (prediction_market, pulse_token, referral_registry, leaderboard) can each be upgraded independently via their upgrade() entry points. There is no cross-contract version check: a governor can upgrade one contract without upgrading the others, breaking the cross-contract ABI.

Impact

  • If the leaderboard adds a new storage key that prediction_market expects, but the market contract wasn't upgraded, the cross-contract call reverts or reads garbage.
  • If pulse_token changes its mint signature, the leaderboard's reward call breaks.
  • If referral_registry changes its register_referral return type, place_bet fails mid-flow.
  • ABI mismatches are silent on deployment — they only surface at runtime when a user triggers the affected call path.

Fix

  • Add an interface_version() or contract_version() entry point to every contract.
  • Have the governor set a coordinated "version bundle" via set_config that pins all four versions together.
  • Reject calls from contracts whose version does not match the expected set.
  • Add a migration path: store an interface compatibility matrix in instance storage.

Activity

  1. darkifyyy commented on Aug 23, 2026

    @darkifyyy

    Hello,
    I can work on this
    Could you please assign it to me
    Thank you

  2. Samaro1 commented on Aug 23, 2026

    @Samaro1

    Gm gm boss. I would like to take this one on. I can add a contract_version() entry point to each of the four contracts, wire the governor's set_config to pin a coordinated version bundle, reject cross-contract calls when the version pinning doesn't match, and build the interface compatibility matrix stored in instance storage as the migration path across upgrades. Please assign it to me.

  3. samjay8 commented on Aug 23, 2026

    @samjay8
    Contributor

    Hi team,

    I'd like to work on resolving this issue. Here is my proposed plan of approach to establish version coordination and prevent ABI mismatches across independent contract upgrades:

    Plan of Approach

    1. Implement Contract Version Entry Points:

      • Add a contract_version() -> u32 entry point to all four ecosystem contracts (prediction_market, pulse_token, referral_registry, and leaderboard).
    2. Governor Version Bundle Management:

      • Extend the governor configuration (set_config) to store a coordinated "version bundle" defining expected interface versions for each target contract.
      • Add validation logic during cross-contract interactions to verify that target contract versions match the pinned versions in the active version bundle.
    3. Cross-Contract Version Checks & Rejection:

      • Implement version assertions at the start of cross-contract call entry paths.
      • Reject execution with a descriptive error (e.g., Error::VersionMismatch) if an uncoordinated upgrade leads to an invalid contract version pair.
    4. Compatibility Matrix & Migration Path:

      • Store an interface compatibility matrix in instance storage to allow non-breaking, backward-compatible interface updates across version transitions.
    5. Testing & Validation:

      • Write unit and integration tests simulating independent contract upgrades.
      • Verify that matched version upgrades succeed smoothly while mismatched cross-contract calls fail explicitly at runtime before state modification.

    I can implement these version check mechanisms and tests promptly.

  4. grantfox-oss commented on Aug 23, 2026

    @grantfox-oss
    Author

    🦊 GrantFox — @samjay8 has been assigned to this issue as part of the Third Campaign campaign!

    Next steps:

    1. Open a Pull Request referencing this issue (e.g., Closes #170)
    2. Your PR will be reviewed by the SPulse-Org maintainers

    Good luck! Track your progress on GrantFox.

  5. grantfox-oss commented on Aug 30, 2026

    @grantfox-oss
    Author

    🎉 This issue has been marked as completed on GrantFox!

    @samjay8's PR #192 was approved and merged by @Muyideen-js.

    🏆 @samjay8: You earned 40 FoxPoints for this contribution! Your current tier: Builder (2,180 total points). Track your full progress on GrantFox.

    👏 Great work, @samjay8! Keep contributing to SPulse-Org.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSThird CampaignCampaign: Third CampaigncriticalCritical severity - funds at riskcross-contractCross-contract interactionupgradeabilityUpgrade / admin control

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions