A delay on an admin key looks like the upgrade is done. A page prints a timelock and treats the protocol as finished. The delay is the first story. Who can still cancel, skip, or point the proxy is not.
A timelock can give readers a window. It can also sit in front of an admin that still points the implementation. I read an upgrade path the way a door closer is read: the closer slows the slam. It does not remove the hand on the handle.
- A delay is the first reading
- A proxy still has a pointer
- Cancel, skip, and guardian
- Log I kept for a proxy called LATCH
- A delay that is actually a window
- Read the admin before you call the upgrade finished
A delay is the first reading
The problem is easy to name. Docs say “48-hour timelock.” The first reading treats that sentence as: no one can change the code in secret, and the current implementation is the last one. A delay is a clock. An admin key is still a key.
Is the first reading always false? No. Some systems have no admin left, or the admin can only execute what already passed a public vote. The first reading fails when the same key can cancel the queued item, when a guardian can skip the clock, or when the proxy admin is a hot wallet with no lock at all.
My claim is narrow. A timelock is a waiting room. A finished upgrade is a later fact: the pointer cannot move, or it can move only through a path that already ran. Mixing them turns a timer into a seal.
Opinion, not a law for every proxy: the hour count is a costume. The admin address is the room.
A proxy still has a pointer
Most upgradeable contracts keep a proxy in front. Users talk to the proxy. The proxy points at an implementation. Whoever can change that pointer can change what users call “the protocol” without touching the old address.
Question I keep on the page: which address may call the function that sets the implementation? If the answer is a single key, write that key. Do not stop at “there is a timelock.”
Exception: a proxy whose admin is a burned address, or a contract that cannot set a new implementation, is closer to finished. Confirm the burn on chain. A sentence in the docs is not the burn.
Cancel, skip, and guardian
Many lock contracts let a role cancel a queued upgrade. Some let a guardian execute early. Some let a pause key freeze the whole path. Those roles are part of the door.
Observation from public explorers: I have opened a timelock, listed proposers and executors, and found a cancel role on a separate address. That list is a fact on a page. It is not a biography of the team.
Condition: if the lock delay is two days and the cancel key is live, the window is a chance to notice, not a promise the change will land.
Log I kept for a proxy called LATCH
I keep a log for a made-up proxy I call LATCH. Docs: 48-hour timelock, “immutable core.” On chain: proxy admin is Address A. Timelock is Address B. A can still change the admin. B’s cancel role is Address C. A queued upgrade sat for 48 hours and C cancelled it. The page still printed finished.
Question in the margin: what was finished? Answer I could defend: the marketing sentence. Not the pointer. Not the cancel key.
Was I looking at a live book? No. LATCH is a page. The experience was lining admin, lock, and cancel. A reader can repeat that line on any public proxy without taking a position.
Exception I left beside the log: if A is burned and C is gone, the 48 hours are a leftover label. Until those keys are gone on chain, the label is ahead of the door.
A delay that is actually a window
The first reading works when the only path to a new implementation is a public queue, when cancel and skip keys are absent or themselves locked, and when the admin cannot replace the lock. It works for that window.
It fails when a printed delay is treated as a sealed protocol. It fails when “decentralized upgrade” is counted as done because the hours look long.
I do not treat a live admin as a command to leave. I treat it as a reason to keep the timer and the key on two lines.
Read the admin before you call the upgrade finished
The solution that holds under the conditions above is a short read, not a slogan.
Write the proxy address and the current implementation. Write who may set a new one. Write the lock delay, and who may cancel or skip it. If a page will not name the admin, the “finished upgrade” sentence is not ready to stand.
If the docs and the proxy disagree, say so and stop before the seal becomes certain.
The spare thought on the desk is small. A delay can be a real window. The hand on the pointer can still move. I read the admin first. I do not call the upgrade finished because the first reading stopped at the hours.
The articles on this site are not investment recommendations or financial advice. They are structural analysis based on on-chain data and project documents.
Comments
Post a Comment