Skip to main content

Testing

Contracts​

SuitePathCovers
Corecontracts/test/core/Launch, fees (25/75 split for buys and sells, gross-input buys, execution-value sells with rebates), collection and conversion, MEV decay, router, invariants (locked liquidity, 25/75 split, conversion bounds, conservation). Review regressions: ZkPadAuditFixes.t.sol, ZkPadOvershootSell.t.sol (zero-liquidity, thin-band and tiny-band overshoots), ZkPadConversionGuard.t.sol (same-block guard, protocol top-up)
Vaultcontracts/test/vault/Deposits, claims, EIP-712 digests, owner actions, binds, fallback, admin, reentrancy, invariants; FeeVaultAuditFixes.t.sol (veto sweep delay, template discard, idempotent registration)
Adapterscontracts/test/adapters/Railgun shield via a faithful mock, fees, blocklist, refund + recredit, proxy prediction, reentrancy, FeeVault integration, invariants, submitter sanctions screening, BSC fork test
Consolidationcontracts/test/consolidation/QuoteRegistry (Tier 1, Tier-2 admission checks), Infinity and V3 route executors, signed and creator consolidation (oracle bounds, sandwich attempts, caps), single-use templates through the real RailgunShieldAdapter, invariants (credits always backed), BSC fork tests. Review regressions per round: ConsolidationAuditFixes*.t.sol, ConsolidationRound2Fixes.t.sol (pro-rata launch credit, rotation discards templates), ConsolidationRound3Fixes.t.sol (full-balance sentinels, creator minimum, template pinning), ConsolidationRound4Fixes.t.sol (quoted whole-balance consolidate after a creator front-run)
End-to-endcontracts/test/e2e/Full journeys on the real stack: WBNB, 6-decimal and Tier-2 launches; stealth and handle beneficiaries; anti-snipe window; 25/75; relayed multicall(register, consolidate, claim) to Railgun; creator consolidate-and-shield; 2-of-3 bind with veto and finalize; fallback sweep; refunds. Also the deploy script: config parsing, full wiring and Ownable2Step hand-over, and a BSC-fork deploy of the mainnet config with live feed checks

Rules from docs/BUILD_SPEC.md:

  • Every contract has unit, fuzz and invariant tests.
  • Tests run against a locally deployed, real Infinity stack, not mocks.
  • Fee tests must show protocol : beneficiary ≈ 25 : 75 within rounding for buys and sells.

The whole suite passes; the BSC fork tests are skipped without BSC_RPC_URL. Per-suite counts are in the track reports (docs/tracks/*.REPORT.md). scripts/preflight.sh runs forge build --sizes, forge test, the TypeScript checks and the Docker image checks locally (there is no GitHub Actions CI); run it before merging to main.

cd contracts
forge test -vv
forge test --match-path 'test/vault/**'
FOUNDRY_PROFILE=ci forge test # 1,000 fuzz runs

Fork tests​

Fork tests against BSC mainnet are skipped unless BSC_RPC_URL is set:

BSC_RPC_URL=https://… forge test --match-path 'test/**/*Fork*'

They confirm what the research could not check from a sandbox: quote-token properties, Railgun's shieldFee() and tokenBlocklist, a real shield from a contract, Infinity addresses, and that the mainnet config (contracts/config/56.json) deploys: every V3 route exists with liquidity and every Chainlink feed answers, has 8 decimals and is fresher than the registry's 1-hour MAX_ORACLE_AGE (test/e2e/DeployScript.t.sol).

TypeScript​

  • SDK (vitest): id derivations and EIP-712 digests must match Solidity (hard-coded vectors from cast or anvil), ECIES hint round-trips, claim-link round-trips, tick math, pool ids.
  • Services: unit and HTTP tests with Hono's app.request; on-chain paths against anvil (they need forge build src/vault/FeeVault.sol lib/openzeppelin-contracts/contracts/mocks/token/ERC20Mock.sol into contracts/out-services, or ZKPAD_CONTRACTS_OUT).
  • Full stack: scripts/dev.sh --ci deploys everything on anvil and drives a claim through the real relayer with the SDK.
  • Indexer: vitest over the pure core (trade derivation, fees, candles, rankings, reorg-aware stream) and an anvil end-to-end replay (pnpm -C services/indexer test:e2e) that compares every beneficiary balance with FeeVault.balanceOf.
  • Web app: vitest/RTL (claim links, fee previews, privacy guards such as the search secret guard and the RPC-free consolidation pricing); Playwright tests (pnpm -C apps/web e2e; Chromium preinstalled at /opt/pw-browsers in CI sandboxes); and pnpm -C apps/web e2e:local, which drives discover, token, buy, launch, collect and claim on a real local stack.
  • Docs: pnpm -C apps/docs build fails on broken links or anchors.