Skip to content

[evm, pallet-intents-coprocessor]: bundler allowlist and EntryPoint v0.9 for SimplexPaymaster and SolverAccount - #1371

Merged
Wizdave97 merged 6 commits into
mainfrom
roy/paymaster-bundler-allowlist
Oct 9, 2026
Merged

Wizdave97 merged 6 commits into
mainfrom
roy/paymaster-bundler-allowlist

Conversation

@royvardhan

@royvardhan royvardhan commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #1364. Contract side of #1365 and #1366; their rollout steps stay open there.

Bundler allowlist

SimplexPaymaster only sponsors a user operation when tx.origin is a listed bundler wallet. An empty list turns the check off, and tx.origin is not read at all in that case, so bundlers that enforce ERC-7562 still accept the paymaster on chains that leave it off.

  • Contract: the SetBundlers governance request (kind 8, abi.encode(address[], bool)) adds or removes wallets. Adds getBundlers() and UnauthorizedBundler(origin). The list takes two slots from __gap, and the proxy layout is otherwise unchanged.
  • Pallet: set_paymaster_bundlers(state_machine, bundlers, allowed) dispatches the request.

EntryPoint v0.9

  • SimplexPaymaster answers only to EntryPoint v0.9, and VERSION is 3. Governance upgrades each proxy with upgrade_paymaster and init_data set to migrate(), the same calldata on every chain. migrate() moves the v0.8 deposit to v0.9 and unlocks the v0.8 stake. It does not stake on v0.9, since our bundler needs no paymaster stake. Once the v0.8 delay passes, anyone can call withdrawStakeV08(), which moves the v0.8 stake into the paymaster's v0.9 deposit.
  • SolverAccount answers only to EntryPoint v0.9. It is a new deployment, so solvers re-delegate. The Budgets slot is unchanged, so limit-order tallies carry over. Nonces restart and bids are signed for v0.9.
  • No pallet change for the upgrade, since init_data is opaque.

Rollout

  • The first set_paymaster_bundlers request on a chain must list every bundler signer plus rundler's simulation address 0x0643866dA50efE0b055Cd15aF95191968c8411b5, or the bundler rejects every sponsored operation. Remove a signer only after it stops bundling. Our rundler must run with --unsafe on chains where the list is set.
  • The SDK must pick the EntryPoint per bid and ship before any paymaster upgrade, because an SDK that hard-codes v0.8 cannot execute a v0.9 bid. That change is a separate PR.
  • Each chain's bundler must enable v0.9, and its signer wallets must be plain EOAs.
  • The paymaster is unstaked on v0.9, so bundlers that enforce ERC-7562 (Alchemy, Pimlico) reject its operations. Our rundler must serve a chain before that chain's paymaster upgrade.

Not included: an SDK encoder for SetBundlers. No paymaster governance request has one; the pallet builds the body.

Validated: Foundry unit tests, and fork tests on Ethereum, BSC and Base against the real v0.9 EntryPoint. The fork tests deliver the governance upgrade to the live proxies, move the v0.8 stake into the v0.9 deposit after the delay, and sponsor PERMIT and PERMIT2 operations through the upgraded proxies. Gas-grief margins hold on v0.9. Pallet tests pass. End-to-end runs of rundler against a BSC testnet fork covered the allowlist on EntryPoint v0.8 and v0.9.

@royvardhan royvardhan changed the title [evm, pallet-intents-coprocessor]: bundler allowlist in SimplexPaymaster [evm, pallet-intents-coprocessor]: bundler allowlist and EntryPoint v0.9 for SimplexPaymaster and SolverAccount Oct 6, 2026
@Wizdave97

Copy link
Copy Markdown
Member

it's not a good idea for migration to revert if it cannot stake, we can always stake manually

@royvardhan

royvardhan commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator Author

Agreed @Wizdave97 , changed it. If the withdrawn funds don't cover the stake, migrate now skips the v0.9 stake and deposits everything, and the treasury stakes afterwards with addStake. The v0.8 stake is still unlocked and swept to the treasury as before.

@Wizdave97

Wizdave97 commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

@royvardhan there's a build issue on the sdk CI workflow, rebase on main to clear the issue

@royvardhan
royvardhan force-pushed the roy/paymaster-bundler-allowlist branch from afcdae5 to 15033db Compare October 7, 2026 14:22
Comment thread evm/src/utils/SimplexPaymaster.sol Outdated
Comment thread evm/src/utils/SimplexPaymaster.sol Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[simplex] Bundler whitelists in paymaster

3 participants