Enable batch proposal using a Ledger device - #142
Conversation
WalkthroughAdds Ledger sign-only and signature-based submission support across ops batch scripts and core BatchScriptV2, updates CLI tooling and shell scripts to accept --signonly/--signature and Ledger derivation handling, updates dependencies and remappings, removes a nested safe-utils install step, and documents the new workflow. Changes
Sequence Diagram(s)sequenceDiagram
autonumber
participant U as User
participant SH as safeBatchV2.sh
participant FS as forge script
participant BS as BatchScriptV2 (Sol)
participant MS as Multisig Safe
rect rgb(245,250,255)
note right of U: Sign-only flow (derive signature via Ledger)
U->>SH: run --multisig true --ledger <path> --signonly true
SH->>FS: invoke forge with --sig (...bool,bool,string,string,bytes)() and signOnly=true, derivPath, signature=0x
FS->>BS: setUp(useDaoMS, signOnly, argsFile, derivPath, signature=0x)
BS->>BS: build batch, simulate, derive signature (Ledger)
BS-->>SH: return derived signature (bytes)
end
rect rgb(245,255,245)
note right of U: Submit-with-signature flow (broadcast or propose)
U->>SH: run --signature 0xSIG --broadcast true
SH->>FS: invoke forge with signOnly=false, derivPath="", signature=0xSIG
FS->>BS: setUp(useDaoMS, signOnly=false, argsFile, "", signature=0xSIG)
BS->>MS: propose/execute batch using provided signature
MS-->>BS: tx hash / result
end
Estimated code review effort🎯 4 (Complex) | ⏱️ ~60 minutes Possibly related PRs
Poem
Pre-merge checks and finishing touches✅ Passed checks (3 passed)
✨ Finishing touches
🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (10)
💤 Files with no reviewable changes (1)
✅ Files skipped from review due to trivial changes (1)
🚧 Files skipped from review as they are similar to previous changes (2)
🧰 Additional context used🧠 Learnings (1)📓 Common learnings🧬 Code graph analysis (1)shell/safeBatchV2.sh (3)
🪛 Shellcheck (0.11.0)shell/safeBatchV2.sh[warning] 82-82: ledger is referenced but not assigned. (SC2154) [warning] 91-91: account is referenced but not assigned. (SC2154) ⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
🔇 Additional comments (10)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
📜 Review details
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
⛔ Files ignored due to path filters (1)
soldeer.lockis excluded by!**/*.lock
📒 Files selected for processing (10)
foundry.toml(1 hunks)remappings.txt(1 hunks)shell/full_install.sh(0 hunks)shell/lib/forge.sh(2 hunks)shell/safeBatchV2.sh(5 hunks)src/scripts/ops/README.md(1 hunks)src/scripts/ops/batches/ConvertibleDepositInstall.sol(15 hunks)src/scripts/ops/batches/HeartPeriodicTasksConfig.sol(3 hunks)src/scripts/ops/batches/MockPriceFeedConfig.sol(3 hunks)src/scripts/ops/lib/BatchScriptV2.sol(7 hunks)
💤 Files with no reviewable changes (1)
- shell/full_install.sh
🧰 Additional context used
🧠 Learnings (1)
📓 Common learnings
Learnt from: 0xJem
PR: OlympusDAO/olympus-v3#29
File: src/modules/TRSRY/TRSRY.v1.sol:2-2
Timestamp: 2025-07-18T00:21:49.138Z
Learning: 0xJem prefers to avoid changing historical/already-deployed contracts to minimize risk and maintain stability, even when it would improve consistency across the codebase.
🧬 Code graph analysis (1)
shell/safeBatchV2.sh (3)
shell/lib/arguments.sh (2)
validate_boolean(118-130)validate_text(60-65)shell/lib/error.sh (1)
display_error(5-7)shell/lib/forge.sh (2)
set_account_address_ledger(84-89)validate_and_set_account(95-121)
🪛 Shellcheck (0.11.0)
shell/safeBatchV2.sh
[warning] 82-82: ledger is referenced but not assigned.
(SC2154)
[warning] 91-91: account is referenced but not assigned.
(SC2154)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (7)
- GitHub Check: run-ci
- GitHub Check: run-ci
- GitHub Check: run-ci
- GitHub Check: run-ci
- GitHub Check: run-ci
- GitHub Check: run-ci
- GitHub Check: run-ci
# Conflicts: # remappings.txt
…tep process for submitting a batch to a Safe multi-sig using a Ledger device
800887f to
a336954
Compare
Utilises the changes from Recon-Fuzz/safe-utils#17 to enable a two-step process for signing and proposing a batch to a Safe multi-sig
Summary by CodeRabbit
New Features
Documentation
Chores
Style