Skip to content

fix(builders): run constitution guardrail script in propose() - #595

Merged
solidsnakedev merged 4 commits into
IntersectMBO:mainfrom
katomm:feat/propose-guardrail-redeemer
Oct 6, 2026
Merged

solidsnakedev merged 4 commits into
IntersectMBO:mainfrom
katomm:feat/propose-guardrail-redeemer

Conversation

@katomm

@katomm katomm commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
  • .propose() accepts a redeemer and label, so proposals checked by the constitution guardrail can be built and submitted
  • Treasury withdrawals and parameter changes now work on networks with a guardrail, such as mainnet, preview and preprod
  • The guardrail script can be attached, read from a reference input or carried by a spent input
  • Native scripts carried by a spent input are now recognized for voters, certificates and proposals, and their signers count toward the fee
  • Verified on preview: gov_action1rtr3p3lya3hg9f4shgmlrfzvrm5a5l9rnr3fmpvd9cra882q60dsqurjzc4

Closes #594

katomm added 4 commits October 6, 2026 16:34
ProposeParams takes an optional redeemer and label. The redeemer is tracked
under the propose purpose, keyed by the proposal's position in
proposalProcedures, and is indexed, evaluated and balanced like the other
script redeemers. The guardrail script is supplied with attachScript() or
readFrom().

The build fails early when a proposal with a Plutus policyHash has no
redeemer, or when a redeemer is supplied for a proposal that runs no
guardrail. Redeemers for native-script guardrails are dropped.

The devnet ConwayGenesis type accepts constitution.script, and a devnet test
submits TreasuryWithdrawals and ParameterChange proposals against an
always-succeeding guardrail, with the script attached and via a reference
input.

Closes IntersectMBO#594
… propose()

Review follow-ups:
- A self redeemer has no input to resolve against for a proposal, so
  propose() now fails with a clear message instead of a resolution error.
- A redeemer for a Plutus guardrail now requires the script to be attached
  or available from a reference or spent input, so a missing script fails at
  build time rather than at submission.
- Unit tests cover propose next to mint redeemers with distinct ExUnits, two
  guardrail proposals, compose(), reference input scripts, batch redeemers,
  an unexpected evaluator index and label enrichment on script failure.
- Docs note redeemer data and supported redeemer modes.

@solidsnakedev solidsnakedev left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, this is a clean fix. Checked against the ledger: the propose redeemer index and the spent-input scripts both match what the node expects, and the devnet tests pass locally. One small follow-up on the fee estimate is tracked in #596; it does not block this.

@solidsnakedev
solidsnakedev merged commit efb96b4 into IntersectMBO:main Oct 6, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

propose() cannot attach guardrail script and redeemer (TreasuryWithdrawals / ParameterChange on mainnet)

2 participants