Skip to content

feat: yield bearing bridge#177

Open
waelsy123 wants to merge 142 commits intomainfrom
feat/yield-bearing-bridge-full
Open

feat: yield bearing bridge#177
waelsy123 wants to merge 142 commits intomainfrom
feat/yield-bearing-bridge-full

Conversation

@waelsy123
Copy link
Copy Markdown
Contributor

@waelsy123 waelsy123 commented Feb 6, 2026

  • add master vault
  • add YBB gateways and integrate that with the bridge
  • happy path e2e test for deposit
  • cover master vault with tests

@waelsy123 waelsy123 requested review from godzillaba and gzeoneth and removed request for gzeoneth February 6, 2026 16:59
Copy link
Copy Markdown
Member

@gzeoneth gzeoneth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

still think the fee toggle just add complexity without good usecase

Comment on lines +229 to +230
address masterVaultRoles,
address masterVaultBeaconProxyFactory
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

breaks CREATE2-like deterministic deployment behavior as these new param are not part of _getL1Salt and _getL2Salt; we should consider to deploy these contract in the factory instead of taking untrusted input

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @title Layer 1 Gateway contract for bridging standard ERC20s with YBB enabled
* @notice Escrows funds into MasterVaults for yield bearing bridging.
*/
contract L1YbbERC20Gateway is L1ERC20Gateway {
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

L2 token created with underlying token decimals, but MV share have +6 decimals and L2 token represent MV share instead of underlying so we need to adjust somewhere

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/// - Set the rebalance cooldown
bytes32 public constant GENERAL_MANAGER_ROLE = keccak256("GENERAL_MANAGER_ROLE");
/// @notice The fee manager can:
/// - Toggle performance fees on/off
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider to take this away from FEE_MANAGER_ROLE because the current implementation allow reseting the high water mark by toggling the fee off and on. If the fee manager can temporally manipulate sub-vault price it can drain the vault too.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

.mulDiv(1e18, totalSupply(), MathUpgradeable.Rounding.Up)
);
} else {
_distributePerformanceFee();
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this can revert (if subvault.withdraw revert), preventing disabling fee when subvault have withdrawal paused

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.


__ReentrancyGuard_init();
__Pausable_init();
__MasterVaultRoles_init();
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

local roles are not initialized and no one have local default admin role to grant roles

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @title Layer 1 Gateway contract for bridging Custom ERC20s with YBB enabled
* @notice Escrows funds into MasterVaults for yield bearing bridging.
*/
contract L1YbbCustomGateway is L1CustomGateway {
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lack fee token (Orbit) variant, same for the L1YbbERC20Gateway

Comment on lines +297 to +303
uint256 totalAssetsUp = _totalAssetsLessProfit(MathUpgradeable.Rounding.Up);
uint256 totalAssetsDown = _totalAssetsLessProfit(MathUpgradeable.Rounding.Down);
uint256 idleTargetUp =
totalAssetsUp.mulDiv(1e18 - targetAllocationWad, 1e18, MathUpgradeable.Rounding.Up);
uint256 idleTargetDown =
totalAssetsDown.mulDiv(1e18 - targetAllocationWad, 1e18, MathUpgradeable.Rounding.Down);
uint256 idleBalance = asset.balanceOf(address(this));
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

inconsistent use of _totalAssetsLessProfit and asset.balanceOf(address(this))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you explain more what you mean? i'm not sure i follow

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we're changing rebalancing to include profit assets too fwiw

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if (idleAssets < assets) {
uint256 assetsToWithdraw = assets - idleAssets;
// slither-disable-next-line unused-return
subVault.withdraw(assetsToWithdraw, address(this), address(this));
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

also lack subvault slippage check tho idk what is a good fix

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

one of the assumption we have here is subvault should be erc4626 compliant, which require subvault.withdraw() to transfer exactly the requested assets a nd if a subVault misbehaves safeTransfer method on the next line would revert anyway

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fact that it return EXACT mean rounding error are lost, while the user withdrawing will get full value. This should be fine bcz most vault have share value much lower than 1 wei, but using redeem can be safer (so the master vault get the rounding assets).

E.g. if 1 share = 100 wei, withdraw(1) burn 1 share and receive 1 wei, losing 99 wei

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think we should leave this alone. as you say most vaults have low share values.

even if the value of the shares is high it's still an expensive thing to exploit to any meaningful degree because you'd have to initiate a separate withdrawal tx for every single subVault share you want to get rounded off.

there's not really a good way to profit from exploiting this unless you hold a non negligible share of the subvault or something like that

losing 1 subVault share's worth of assets on a rebalance, redeem, or fee distribution is acceptable imo

/// @notice Set the target allocation of assets to keep in the subvault
/// @dev Target allocation must be between 0 and 1e18 (100%).
/// @param _targetAllocationWad The target allocation in wad (1e18 = 100%)
function setTargetAllocationWad(uint64 _targetAllocationWad)
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lack event

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

onlyGateway
returns (uint256 shares)
{
shares = _convertToSharesRoundDown(assets);
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should check shares != 0

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

imo we should implement an optional slippage check in the gateways

we could pass it by repurposing extraData which would leave the existing function signature unchanged. we could also introduce a new function which is probably a bit better

* deposit side of ybb happy case e2e tests

* check mastervaultfactory set on custom gateway

* ybb withdrawal e2e test

* slippage path e2e tests

* dry out ybb e2e tests

* optimize absYbbNonReentrant

* Revert "optimize absYbbNonReentrant"

This reverts commit 692bdd7.
Copy link
Copy Markdown
Member

@gzeoneth gzeoneth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking pretty good, some minor comments

Comment thread contracts/tokenbridge/ethereum/L1AtomicTokenBridgeCreator.sol Outdated
if (idleAssets < assets) {
uint256 assetsToWithdraw = assets - idleAssets;
// slither-disable-next-line unused-return
subVault.withdraw(assetsToWithdraw, address(this), address(this));
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fact that it return EXACT mean rounding error are lost, while the user withdrawing will get full value. This should be fine bcz most vault have share value much lower than 1 wei, but using redeem can be safer (so the master vault get the rounding assets).

E.g. if 1 share = 100 wei, withdraw(1) burn 1 share and receive 1 wei, losing 99 wei

Copy link
Copy Markdown
Contributor

@godzillaba godzillaba left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we need to confirm whether we need token name+symbol prefix+suffix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants