Skip to content

feat: automate pyth router rotations - #24

Open
chalabi2 wants to merge 5 commits into
akash-network:mainfrom
chalabi2:chalabi/pyth-router-auto-rotation
Open

chalabi2 wants to merge 5 commits into
akash-network:mainfrom
chalabi2:chalabi/pyth-router-auto-rotation

Conversation

@chalabi2

@chalabi2 chalabi2 commented Sep 5, 2026 •

Copy link
Copy Markdown

Automatically handles InvalidRouterSetIndex by fetching Pyth's signed guardian-set upgrade VAA from the configured Hermes endpoint, validating it, submitting submit_v_a_a to pyth_vaa, and retrying the price update.

Uses the protocol governance emitter, separate from the price emitter, and preserves Pyth's original signed bytes. Includes the unchanged published production rotation fixture, tampering and replay checks, and continued price processing after a failed rotation transaction. Alpha releases no longer replace stable image tags.

Validation: 309 tests, build, lint. On a sandbox-snapshot local fork, Hermes automatically rotated set 0 to 1 using Pyth's authentic historical VAA and then committed a live AKT price. The historical VAA was served through a local HTTP endpoint because no live rotation is currently active.

Detects router-set index mismatches, fetches signed router-set upgrade VAAs from Pyth routers, submits them to pyth_vaa, and retries the price update.

Signed-off-by: Joseph Chalabi <chalabi.joseph@gmail.com>
@codecov-commenter

Copy link
Copy Markdown

Welcome to Codecov 🎉

Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests.

Thanks for integrating Codecov - We've got you covered ☂️

Normalize router-set upgrade signatures before assembling the VAA so the Rust pyth_vaa contract can recover the signer addresses consistently. This keeps router rotation automatic when Pyth emits a signed upgrade.

Signed-off-by: Joseph Chalabi <chalabi.joseph@gmail.com>
Fetch router-set upgrade VAAs from the documented Hermes aggregate route
instead of raw Douro router endpoints. This keeps price updates and router
rotation behind the same authenticated base URL and converts the returned hex
VAA to base64 before submitting submit_v_a_a.

Signed-off-by: Joseph Chalabi <chalabi.joseph@gmail.com>
Preserve Pyth's published rotation VAA bytes and validate their governance
emitter separately from price messages. Cover genuine production signatures,
tampering, replay, and price processing after a failed rotation transaction.

Signed-off-by: Joseph Chalabi <chalabi.joseph@gmail.com>
Mark prereleases automatically and publish only their explicit version tag.
Sandbox alpha builds must not replace latest or the stable minor tag.

Signed-off-by: Joseph Chalabi <chalabi.joseph@gmail.com>
@chalabi2

Copy link
Copy Markdown
Author

v0.0.3-a9 is published as a prerelease and deployed to both sandbox relayers. Each passed a rolling health observation period and committed successful price transactions after startup; the oracle and BME report healthy. Existing wallet, endpoint, contract, network, and container settings were preserved. Stable Docker tags were not changed.

Together with node PR 2082, the automatic local snapshot-fork test accepted Pyth's unchanged historical rotation VAA and retried a live AKT price successfully. The corrected verifier also accepted that VAA from a non-admin on sandbox and rejected tampering and replay. A future live upstream rotation remains unobserved; the automatic test served the authentic historical VAA through a local HTTP endpoint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants