Factories and proxiesLink to this section
TL;DRLink to this section
- Factories deploy and check new contracts in one transaction; they do not move Mining4 state into Mining5.
CoreandMininghave separate proxies, each upgraded through a dedicated timelock-ownedProxyAdmin.- Predicted addresses depend on the full deployment configuration and caller; prediction does not validate or approve a deployment.
ResponsibilityLink to this section
SqueekFactory deploys a fresh Core proxy using a reviewed implementation and existing governance. SqueekTokenFactory deploys Mining, Token and NFT, connects them, and removes its one-time bootstrap permission in the same transaction.
SqueekProxy and SqueekIssuanceProxy hold application state at stable addresses while their admins control implementation upgrades. Token, NFT, renderer and page deploy directly and cannot be upgraded.
Dependencies and authorityLink to this section
| Component | Identity and authority |
|---|---|
Core factory |
Checks implementation code/runtime/version/layout and supplied Timelock/proposer runtime/roles |
| Economic factory | Checks complete Core, Mining, governance, Token and NFT/renderer identity envelope |
Core ProxyAdmin |
Created by Core proxy constructor, owned by approved Operator Timelock |
Mining ProxyAdmin |
Created by guarded Mining proxy constructor, owned by Mining governance Timelock |
SqueekIssuanceProxy |
Rejects initializer that changes reviewed implementation; exposes nondelegated actual identity |
| Bootstrap caller | Economic factory during launch only; authority becomes zero after completion |
The deployment configuration includes an approval commitment, but the factory has no registry of approved code. The caller must independently verify that the committed configuration is approved and trustworthy.
State and viewsLink to this section
| View / struct | Meaning |
|---|---|
SqueekTokenFactory.predict(deployer, config, nftCreationCode) |
Predicted Mining, Token, NFT and Mining ProxyAdmin addresses |
SqueekIssuanceProxy.deploymentIdentity() |
Actual implementation slot and immutable transparent dispatch admin |
Core / Mining implementation metadata |
Executing code address/version/layout digest |
ProxyAdmin owner(), UPGRADE_INTERFACE_VERSION() |
Upgrade owner and inherited upgrade-interface version |
Timelock getMinDelay, hasRole, operation-state/hash views |
Delay, privilege and operation readback |
TokenDeploymentConfig carries chain ID, full Core identity/configuration, governance, Mining implementation and launch policy, cap, NFT/visual identity, deployment approval and salt. DeploymentImplementation carries implementation address, runtime hash, version and layout digest.
The CREATE2 root salt is keccak256(abi.encode(deployer, config)); separate child salts distinguish Mining, Token and collection. The predicted Mining ProxyAdmin address is the first CREATE child of the predicted Mining proxy.
ActionsLink to this section
| Action | Behavior |
|---|---|
Core factory deploy(config, initialImplementation, expectedRuntimeHash) |
Deploys and initializes a paused Core with zero state, checks its actors and configuration, returns its proxy |
Economic factory deploy(config, nftCreationCode) |
Checks the complete configuration and separately pinned NFT creation code, deploys and connects the contracts, then checks their final state |
| Proxy constructor | Creates standard ProxyAdmin and delegates initialization atomically |
ProxyAdmin upgradeAndCall(proxy, implementation, data) |
Owner-only transparent upgrade, normally executed by Timelock |
Timelock schedule/execute/cancel and role administration |
Inherited governance lifecycle; permissions depend on verified role configuration |
Neither factory migrates existing state, deploys a Controller, provides a permanent upgrade lock or offers Mining4 compatibility aliases. Initialization runs during proxy construction, not as a later public setup call.
Proxy code embeds the admin that handles upgrades. Verify that code before trusting deploymentIdentity(); a getter delegated to an implementation or a writable storage slot alone cannot prove the actual admin address.
Events and errorsLink to this section
| Event | Evidence |
|---|---|
SqueekDeploymentCreated |
Core proxy, implementation, Operator Timelock, ProxyAdmin, proposer, stream |
SqueekTokenDeploymentCreated |
Token, Mining, NFT, deployer, Mining implementation/admin, envelope hash and approval commitment |
Upgraded, AdminChanged, OwnershipTransferred |
Inherited proxy/admin identity changes |
CallScheduled, CallExecuted, Cancelled, role events |
Inherited timelock operation and authority history |
| Error group | Scope |
|---|---|
Core InvalidInitialImplementation, ImplementationRuntimeHashMismatch, ImplementationCodeAddressMismatch, ImplementationVersionMismatch, ImplementationLayoutMismatch |
Core implementation identity |
Core InvalidOperatorProposer, TimelockRuntimeHashMismatch, OperatorProposerRuntimeHashMismatch, InvalidTimelockDelay, InvalidTimelockRole |
Governance identity and privilege |
Both factories InvalidDeploymentConfiguration, DeploymentReadbackMismatch |
Invalid envelope, actor separation or postcreation identity |
Economic RuntimeHashMismatch(target), ImplementationIdentityMismatch(implementation) |
Dependency or implementation mismatch |
Economic InvalidTimelockRole, InvalidTimelockDelay, CoreNotFresh, CollectionArtifactMismatch |
Governance, fresh Core or separately pinned NFT artifact |
Guarded proxy InitializationChangedImplementation |
Initializer changed the reviewed implementation |
| Inherited proxy/admin/timelock and CREATE2 errors | Invalid admin dispatch, unauthorized upgrade, operation state or creation failure |
If any check fails, the entire deployment rolls back, including created contracts and bootstrap. Address prediction does not run all deployment checks.
LimitsLink to this section
Corefactory expects initialCoreversion 2 and its exact V2 aggregate layout digest;Coreduration 600 seconds and batch limit 16 are rechecked.- Approved minimum delay is positive;
Corefactory accepts actual delay at least that minimum. Economic factory requires the exact supplied governance delay, also at leastMining's positive minimum. - Expected proposer has proposer and canceller roles; execution is open through zero-address executor;
Timelockhas its own default-admin role. - Economic validation rejects factory/deployer default-admin privilege, but arbitrary unlisted role membership cannot be exhaustively enumerated by these getters. Reviewed runtime and role history remain necessary.
- Economic
Coremust be paused and exactly zero-state, including nonce/frontier/work; supply cap is1..2^128-1. Miningpolicy must satisfy the Mining limits, including Levels, weights, activation period and cooldowns.NFTcreation-code and runtime-template commitments match the independent build; caller-provided bytes are not arbitrary plug-ins.- Every deployment configuration field and the deployer affect predicted addresses; recompute them after changing either.
Mining's upgrade governance remains trusted even thoughToken's mint authority address cannot change.
SourceLink to this section
Mining5 source specification e0617449. First-party source is private; see source and release scope.
- Exhaustive transparent proxy interface
- Exhaustive ProxyAdmin interface
- Exhaustive Timelock interface