Skip to content

chore: add code complexity checks to CI - #711

Merged
GitGuru7 merged 7 commits into
developfrom
feat/code-complexity-gates
Sep 22, 2026
Merged

GitGuru7 merged 7 commits into
developfrom
feat/code-complexity-gates

Conversation

@GitGuru7

@GitGuru7 GitGuru7 commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Two CI gates, both enforced through existing scripts. No contract code changes.

Code complexity

ESLint now caps per-function complexity at 15 for TypeScript:

  • complexity: ["error", 15] — cyclomatic
  • sonarjs/cognitive-complexity: ["error", 15] — cognitive, via eslint-plugin-sonarjs@^1.0.4

Solhint's code-complexity was already at ["error", 14] and is untouched. 15 is a
ceiling, not a target, so a threshold that is already stricter stays where it is.

These run inside yarn lint, which CI already blocks on, so no workflow change was needed.

What the gate found

Four functions were over the limit. One is fixed, three carry an inline
eslint-disable-next-line with a reason:

Function File Cyclomatic Cognitive Action
generateCutParams script/deploy/comptroller/facet-cut-params-generator.ts 33 → 4 56 → 3 Fixed
atomicLiquidate scripts/bstock/atomic-liquidate.ts 49 58 Suppressed
buildSafeFallbackBatch scripts/bstock/safe-fallback.ts 22 24 Suppressed
sweepOne tests/hardhat/Fork/BStockLiquidatorFork.ts 29 30 Suppressed

generateCutParams was split into named pipeline stages — resolveNewFacetAddresses,
resolveNewSelectors, identifyOldFacets, buildCutEntries, collectRemovals. Pure
refactor: every statement is unchanged and runs in the same order.

The two bStock scripts are liquidation tooling and too important to reshape alongside a
lint rollout. They are suppressed here and get their own PR.

The fork test is low priority and does not need fixing.

Storage layout and upgrade safety

New Upgrade safety workflow, pull requests only, running two checks:

moved to : #712

Slither: tried and reverted

Added in a964902, reverted in e242e08, kept in history so the next person does not repeat it.

It works, but the signal is not there. 382 findings out of the box. Filtering the vendored
0x fixed-point math library, the legacy contract directories and the known false-positive
detectors got it to 192 — still ~190 unreviewed items, and the high-impact ones were
dominated by patterns that are the architecture rather than bugs: every
controlled-delegatecall hit is a proxy doing delegatecall.

A Security tab nobody opens is worse than no Security tab. With AI-assisted development and
review in the loop, generic pattern matching of this kind adds little.

Follow-ups

Compares every proxied mainnet implementation against the layout recorded in its
deployment artifact, read from the PR base branch so a deploy PR cannot pass by
overwriting its own reference. vTokens and Diamond facets are covered explicitly.
@greptile-apps

greptile-apps Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 3/5

The PR is not yet safe to merge because the storage-layout gate can skip deployed implementations or suppress genuine incompatibility reports.

Findings

  1. P1 Allowlist Hides Incompatible Layouts ▶
  2. P1 Deleted Targets Escape Validation ▶
  3. P2 Security Checksums Are Accepted Unverified ▶

Summary

This PR adds TypeScript complexity enforcement, refactors the comptroller facet-cut generator to satisfy it, and introduces CI checks for OpenZeppelin upgrade safety and deployed storage-layout compatibility.

  • Adds cyclomatic and cognitive-complexity ESLint gates.
  • Splits generateCutParams into behavior-preserving pipeline stages.
  • Adds a pull-request workflow that compiles contracts and runs upgrade/storage checks.
  • Adds base-branch storage-layout comparison and an exception allowlist.
  • The storage gate currently has two paths that can omit or suppress incompatible deployed layouts.

Reviews (1) · Last reviewed commit: "feat: check storage layout against deplo..."

Comment thread scripts/checkStorageLayout.ts Outdated
Comment thread scripts/checkStorageLayout.ts Outdated
Comment thread .github/workflows/upgrade-safety.yml Outdated
An entry now excuses only a target whose artifact records no layout to compare
against; one that compares badly fails whether or not it is listed. Also corrects
the header claim that renaming a variable shifts every slot after it -- it does not.
@github-actions

Copy link
Copy Markdown

Code Coverage

Package Line Rate Branch Rate Health
contracts 100% 100% ✔
contracts.Admin 88% 41% ✔
contracts.BStock 100% 97% ✔
contracts.Comptroller 100% 90% ✔
contracts.Comptroller.Diamond 95% 68% ✔
contracts.Comptroller.Diamond.facets 88% 74% ✔
contracts.Comptroller.Diamond.interfaces 100% 100% ✔
contracts.Comptroller.Types 100% 100% ✔
contracts.Comptroller.legacy 100% 100% ✔
contracts.Comptroller.legacy.Diamond 0% 0% ❌
contracts.Comptroller.legacy.Diamond.facets 0% 0% ❌
contracts.Comptroller.legacy.Diamond.interfaces 100% 100% ✔
contracts.DelegateBorrowers 100% 89% ✔
contracts.FlashLoan.interfaces 100% 100% ✔
contracts.Governance 68% 45% ➖
contracts.InterestRateModels 74% 59% ➖
contracts.Lens 44% 47% ❌
contracts.Liquidator 83% 60% ✔
contracts.Oracle 100% 100% ✔
contracts.PegStability 88% 84% ✔
contracts.Swap 87% 57% ✔
contracts.Swap.interfaces 100% 100% ✔
contracts.Swap.lib 81% 53% ✔
contracts.Tokens 100% 100% ✔
contracts.Tokens.Prime 97% 81% ✔
contracts.Tokens.Prime.Interfaces 100% 100% ✔
contracts.Tokens.Prime.libs 90% 77% ✔
contracts.Tokens.VAI 82% 52% ✔
contracts.Tokens.VRT 20% 9% ❌
contracts.Tokens.VTokens 71% 53% ➖
contracts.Tokens.VTokens.legacy 0% 0% ❌
contracts.Tokens.VTokens.legacy.Utils 0% 0% ❌
contracts.Tokens.XVS 19% 8% ❌
contracts.Tokens.test 100% 100% ✔
contracts.Utils 52% 31% ➖
contracts.VAIVault 50% 45% ➖
contracts.VRTVault 49% 36% ❌
contracts.XVSVault 63% 50% ➖
contracts.external 100% 100% ✔
contracts.lib 89% 71% ✔
Summary 62% (4516 / 7315) 48% (1752 / 3646) ➖

Comment thread script/deploy/comptroller/facet-cut-params-generator.ts
Comment thread package.json
@GitGuru7 GitGuru7 changed the title chore: add code complexity and storage layout gates to CI chore: add code complexity to CI Sep 18, 2026
@GitGuru7 GitGuru7 changed the title chore: add code complexity to CI chore: add code complexity checks to CI Sep 18, 2026
@GitGuru7
GitGuru7 merged commit 33f3933 into develop Sep 22, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants