aere-docs/AERE-ERC7683-DESTINATION-SUMMARY.md
Aere Network dd1410c266 The unpublished line of work joins the sanitized public line
The published line and the local line of this repository had no common
ancestor: the public one carried the hygiene pass (no host names, no internal
paths), the local one carried a month of corrections that never shipped. This
commit ports the local work onto the public line, keeping the public hygiene
wording wherever the two touched the same sentence, and keeping the public
version of AERE-CROSS-CLIENT-DETERMINISM.md entirely.

Carried: LICENSE/LICENSING corrections, VERIFY-POLICY.md,
CITATIONS-UNRESOLVED.md remeasured 2026-08-11, the 'audited' adjective removed
from next to Bouncy Castle, citation paths rewritten to published form, AIP-8,
the QA consolidation report, the second EIP validation pass, fork-height
corrections, the AereSink / threshold-factory correction, the forge test
floor, and the architecture-map updates.
2026-08-15 13:54:42 +03:00

3.8 KiB

Spec 8 - ERC-7683 Destination Settler for Aere Network

What was built (all new files, deployed origin contracts untouched)

  1. aere-contracts/contracts/intents/AereDestinationSettler.sol

    • Implements ERC-7683 IDestinationSettler.fill(bytes32 orderId, bytes originData, bytes fillerData) from the existing aere-contracts/contracts/intents/IERC7683.sol (reused, not redefined).
    • A solver (msg.sender = filler) delivers the promised output straight to the recipient on Aere via OpenZeppelin SafeERC20 (no custody), records the fill, emits Filled.
    • originData = the origin's declared output leg, matching AereSpokePool _buildResolved: abi.encode(bytes32 orderId, address outputToken, uint256 outputAmount, bytes32 recipient).
    • fillerData = abi.encode(address deliveredToken, uint256 deliveredAmount, address deliveredRecipient, bytes32 repaymentAddress).
    • Fail-closed reverts: OrderIdMismatch, ZeroRecipient, ZeroAmount/ZeroAddress, AlreadyFilled (duplicate), OutputMismatch (wrong token/recipient or short amount).
    • Views: fills, getFill, isFilled, fillCount, and fillCommitment(orderId) (canonical repayment binder = keccak256 over AERE_CHAIN_ID=2800, settler, orderId, filler, outputToken, outputAmount, recipient, repaymentAddress).
    • nonReentrant; checks-effects-interactions.
  2. Finality / repayment wiring (real reference, not a live cross-chain claim):

    • Declares IAereQbftFinalityLightClient matching the deployed aere-contracts/contracts/interop/AereZkQbftLightClient.sol (0xCaDA54FA...6488): the SP1 Groth16 QBFT-finality prover (guest qbft-lightclient-guest, quorum ceil(2N/3) = 5-of-7).
    • FILLED_EVENT_SIG + Filled log + fillCommitment are the on-chain surface an origin-side AereOutboundVerifierV2-style verifier consumes: it proves the Filled log was included in a QBFT-final Aere block (validator-set anchored) and repays the solver, no trusted relayer.
    • The light client is deployed on the consuming/origin chain (Aere is native on Aere), so the settler does NOT call it on-chain; documented, not faked.
  3. aere-contracts/test/destination-settler.test.js - RAN, 4 passing:

    • valid fill: delivers output, records fill, emits Filled, fillCommitment matches
    • duplicate fill reverts (AlreadyFilled)
    • mismatched-output reverts (OutputMismatch) - tested short amount, wrong recipient, wrong token
    • zero-recipient reverts (ZeroRecipient)
    • Command: npx hardhat test test/destination-settler.test.js from aerenew/contracts.
  4. aerenew/docs/AERE-ERC7683-DESTINATION.md - origin+destination composition, solver flow (lock on origin, fill on destination, prove-and-repay), proof shape, honest status, and the point that solver liquidity removes the bridge-liquidity bootstrap.

REAL test result

Compiled 1 Solidity file successfully. 4 passing (~1s), 0 failing.

Flags

  • [MEASURE] End-to-end cross-chain repayment (off-chain SP1 prover over the qbft-lightclient-guest ELF + origin-chain verifier deploy on a 2nd chain) is NOT exercised on one chain in the unit test. No live cross-chain flow claimed.
  • [VERIFY] Exact receipt-trie inclusion encoding for the Filled log: confirm against the final AereOutboundVerifierV2 guest.
  • [VERIFY] ERC-7683 struct shapes taken from the repo's vendored IERC7683.sol (canonical Input/Output/ResolvedCrossChainOrder/IDestinationSettler); matches AereSpokePool origin side.

Scope / honesty

Settlement/interop only. Aere consensus stays classical secp256k1 ECDSA QBFT; the finality proof is ABOUT that QBFT finality, verified classically (falconVerified required false). Deployed origin contracts (AereSpokePool, settlement hub) not modified. No em-dashes; brand "Aere Network"/"Aere", ticker AERE; solc 0.8.23.