Skip to content

Coordinate independent Setwise Router system audits and remediation #45

Description

@stxphxn

Summary

Coordinate independent review of the Setwise Router release while keeping RFQ API and pool-contract audit work in their owning repositories.

Scope

  • Audit the ZFi fork, Setwise adapter, registry, router authorization, transient accounting, route service, dapp execution flow, and deployment scripts.
  • Prepare commit hashes, architecture, threat model, documentation, test instructions, and release-candidate deployments.
  • Coordinate and consume the separate RFQ API audit (cenodev/setwise-rfq-api#9) and Setwise pool audit (cenodev/setwise-contracts#2).
  • Triage findings by component, assign remediation owners, add regression tests, and request auditor verification.
  • Publish the final reports and accepted-risk statement.

Acceptance criteria

  • No open critical or high-severity finding remains in the router, RFQ API, or pool contracts.
  • Every remediation links to owning-repository code and a regression test.
  • Auditors verify security-sensitive fixes.
  • Final release commits match the audited source and configuration.
  • Cross-repository accepted risks have explicit owners and controls.

Dependencies

  • Router threat model and adversarial test suites.
  • Release-candidate testnet and fork deployments.
  • Pre-audit router and component documentation.
  • RFQ API security audit (cenodev/setwise-rfq-api#9).
  • Setwise pool-contract audit (cenodev/setwise-contracts#2).

Difficulty

Expert — specialized external coordination and remediation spans three security-critical repositories.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: governanceOwnership, registries, timelocks, and emergency controlsarea: securitySecurity design, review, and remediationdifficulty: expertSecurity-critical or highly specialized workenhancementNew feature or requestphase: rolloutTestnet, security, and production rolloutpriority: p0Release blocker or critical path

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions