> For the complete documentation index, see [llms.txt](https://harena.gitbook.io/harena-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://harena.gitbook.io/harena-docs/hrn-market-v2-deployment.md).

# HRN Market V2 Deployment

Status: **not deployed**. No command in this repository broadcasts the Market V2 contract automatically.

## Fixed production roles

The BNB Smart Chain deployment must use exactly:

| Constructor input | Value                                                                                   |
| ----------------- | --------------------------------------------------------------------------------------- |
| Token             | `0x707887d153B6373A763FbeAc9D0A91E000c86758`                                            |
| Admin             | `0x273dA3D91dd967e73E2Cf6869ffedE2A2b5fD73E`                                            |
| Runner            | `0x559850B3Ff3D078d590044a92e0Dd7F0bA76a5dC` (generated locally; disabled and unfunded) |
| Protocol treasury | `0x273dA3D91dd967e73E2Cf6869ffedE2A2b5fD73E`                                            |
| Arena reserve     | `0x273dA3D91dd967e73E2Cf6869ffedE2A2b5fD73E`                                            |

The contract deploys paused. Skill creators may register immutable skill terms while paused, but purchases and run consumption remain disabled until the Safe executes `unpause()` with the required owner approvals.

The only purchase entrypoint is `buyLicenseChecked`. The signed calldata fixes the skill ID, purchase reference, price, creator, protocol recipient, arena recipient and a short deadline. Any payout-role or price drift before mining reverts the entire transaction before HRN moves. The backend issues a one-shot signing lease, records the canonical-block blacklist/balance/allowance evidence, and accepts an attached transaction only with that lease.

The runner must differ from the Safe, every Safe owner, the HRN token and the deployed market. It holds no treasury authority. Its only intended contract permission is replay-safe `consumeRuns` or `consumeRunsBatch`, capped at 50 consumption records per batch.

The candidate runner private key exists only in the ignored host `secrets/` directory with mode `0600`. It is not available to the API, web, worker or Safe portal containers. The runner currently has no BNB, no contract role and no broadcast service; key generation did not submit a transaction.

The dedicated `hrn-runner` Compose profile is not started by the normal stack. Network submission requires both `HRN_RUNNER_ENABLED=true` and `HRN_RUNNER_BROADCAST_ENABLED=true`, a separate HTTPS `HRN_RUNNER_RPC_URL`, the read-only key mount, explicit gas caps and a deployed verified Market. With either switch false, the command exits before loading the signer or sending RPC writes.

The reversible runner pipeline now reserves one deterministic credit per agent decision epoch, binds up to 50 exact rows to one serialized nonce and calldata digest, persists signed raw bytes before submission, verifies every `RunsConsumed` event and only unlocks local execution after finality. Every consumption carries an immutable delivery deadline that the Market enforces with `block.timestamp`; the runner also rechecks it before signing and submission. Nonce drift, deterministic RPC rejection, unresolved submission ambiguity, event mismatch and post-finality canonical drift quarantine the runner instead of releasing ambiguous claims.

## Local verification

Run the pinned Foundry test image:

```bash
make contracts-test
```

The suite includes a true stateful invariant handler. It targets checked purchases, single and batched run consumption, pause transitions and recipient rotation for 256 runs at depth 64, while continuously checking run-limit conservation, nonzero controls, unchanged supply and zero Market token custody.

Generate the reproducible Standard JSON input, ABI, creation/runtime bytecode and a hash manifest without broadcasting:

```bash
make hrn-market-release-artifacts
```

The ignored output is written to `dist/hrn-market-v2-release/`. Freeze from a clean Git revision so `manifest.json` reports `gitDirty=false`; the unlinked runtime hash is not the final deployed hash because the immutable HRN token address is patched during construction.

Simulate the exact constructor against current BSC state with a candidate runner address:

```bash
make hrn-market-simulate \
  HRN_MARKET_RUNNER_ADDRESS=0xCandidateRunnerAddress
```

For reproducibility at an explicit block, provide an archive-capable RPC and block number:

```bash
make hrn-market-simulate \
  HRN_MARKET_RUNNER_ADDRESS=0xCandidateRunnerAddress \
  BSC_RPC_URL=https://your-bsc-archive-rpc.example \
  BSC_FORK_BLOCK=123456789
```

The standard public BSC endpoint may prune historical state, so a fixed-block simulation can require an archive provider. A latest-block simulation is useful for current compatibility but is not a substitute for recording the final release block and hash.

## Signing boundary

The deployment script reads only public constructor addresses. It contains no private key and the Make target never adds `--broadcast`.

After the build and runner address are frozen, deployment must be signed by a separately controlled BSC deployment wallet through a reviewed MetaMask-connected or hardware-wallet workflow. Send zero native value. The deployer receives no contract role because the constructor assigns all governance and custody roles directly to the Harena Online Safe.

Do not paste a MetaMask private key, seed phrase, Safe owner key or runner key into source, Compose environment variables, command history or support chat.

## Post-deployment checks

Before configuring the backend, independently read the deployed contract:

```bash
cast code 0xMarket --rpc-url "$BSC_RPC_URL" | cast keccak
cast call 0xMarket "TOKEN()(address)" --rpc-url "$BSC_RPC_URL"
cast call 0xMarket "admin()(address)" --rpc-url "$BSC_RPC_URL"
cast call 0xMarket "runner()(address)" --rpc-url "$BSC_RPC_URL"
cast call 0xMarket "protocolTreasury()(address)" --rpc-url "$BSC_RPC_URL"
cast call 0xMarket "arenaReserve()(address)" --rpc-url "$BSC_RPC_URL"
cast call 0xMarket "paused()(bool)" --rpc-url "$BSC_RPC_URL"
cast call 0xMarket "nextSkillId()(uint256)" --rpc-url "$BSC_RPC_URL"
```

The required initial values are the canonical HRN token, unified Safe for all three roles, approved separate runner, `paused=true`, and `nextSkillId=1`. Record the deployment transaction, block number/hash, runtime code hash, compiler input, source revision and role values in `contracts/deployments/bsc-mainnet.json`. Verify the source on BscScan before any canary.

## Staging and activation

1. Keep `HRN_PURCHASE_PROJECTION_ENABLED=false` and HRN launch mode `DISABLED`.
2. Configure `HRN_MARKET_ADDRESS`, `HRN_MARKET_CODE_HASH` and the managed runner public address.
3. Run the read-only market and multisig governance checks at one canonical block snapshot.
4. Register a canary skill from the exact creator wallet while the market remains paused.
5. Bind the finalized registration event to a fresh HRN skill version with the read-only binding command.
6. Configure the Safe API key, smallest transfer allowlist and per-transaction cap for the localhost operations portal.
7. Complete the isolated runner dispatch claim, network submission, finality and reconciliation path around the existing outbox, file-only signer and batch policy core.
8. Enter staff-only SHADOW mode and execute a capped `approve` plus `buyLicenseChecked` canary.
9. Reconcile the license event and all three transfers before any Safe proposal to unpause production access.

The official Safe Transaction Service requires a server-side production API key. Generate it in the [Safe Developer Dashboard](https://developer.safe.global), store it only in the protected runtime environment, and keep the portal read-only until authenticated service checks succeed.

If any code hash, role, owner, threshold, module, guard, runner, blacklist, balance, allowance, event or transfer check differs, leave the market paused and HRN projection disabled.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://harena.gitbook.io/harena-docs/hrn-market-v2-deployment.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
