What this is
A fixture set of three distinct deployed Musechain contract records used to test the
preflight risk checker (charter_risk_checks.py, built for task 239) against real on-chain
metadata. Every expected finding is asserted by test_preflight_fixtures.py —
not eyeballed. Platform-wide claims (no payable entries, no unverified records, no missing sources) are
asserted against a snapshot of all 14 published contract records (platform-scan-2026-10-02.json).
Reproduce: python3 test_preflight_fixtures.py · single fixture:
python3 charter_risk_checks.py --abi fixtures/<name>/abi.json --source fixtures/<name>/source.sol --verified
Fixtures
| Fixture | Address | Role in set |
|---|---|---|
community-needs-board |
0x295b52211d83fc2b6e985d0c895542a84cfcd8c9 | Dynamic-input writes — submitRequest(string,string), setLinkedWork, resolveRequest |
outreach-trial-board-v2 |
0xa1ed5eb9a443457e28e20184bd7887dd749c6fe8 | Safe zero-value writes — string inputs with source-enforced length caps (MAX_ROUTE / MAX_INVITATION / MAX_DATE) |
muse-contract-review |
0x90c495851da1e56916f756477003b2b7e2edd719 | Review-workflow contract (muse 10) — one dynamic input, otherwise clean control fixture |
Findings (asserted)
| Check | Result | Detail |
|---|---|---|
| R3 unbounded_input | 4 warns | community-needs-board: submitRequest(string,string) ×2, resolveRequest(uint256,string), setLinkedWork(uint256,string) |
| R3 unbounded_input | 5 warns | outreach-trial-board-v2: createTrial(string×4) ×4, updateNextAction(uint256,string) — ABI-level only; source enforces explicit length caps (asserted, documented mitigation) |
| R3 unbounded_input | 1 warn | muse-contract-review: submitReview(address,bool,string) (the note field) |
| R1 payable_entry | 0 findings | Zero payable entries across all 14 published contract ABIs — a payable fixture is not available on-platform (platform screens payable) |
| R2 value_bearing_src | 0 findings | No msg.value / .call{value:} / .transfer / .send in fixture sources |
| R4 restricted_access | no on-platform target | No access-control modifiers in any fixture source — restricted writes don't exist on-platform; R4 rule covered by the checker's own unit fixtures (task 239) |
| R5 missing_verify | silent when verified | All 14 records are verified=true with source present — the unverified/unavailable-source case doesn't exist on-platform; firing demonstrated synthetically (--verified omitted ⇒ finding present) |
| R6 selfdestruct/delegatecall | 0 findings | None in any fixture source |
Files
- charter_risk_checks.py — the checker (R1–R6)
- test_preflight_fixtures.py — 25 assertions
- run-output.txt — full test log
- fixture-meta.json — addresses, muse ids, verification, tx refs
- platform-scan-2026-10-02.json — all 14 records snapshot
- fixtures: cnb abi · cnb src · otbv2 abi · otbv2 src · mcr abi · mcr src
- findings: cnb · otbv2 · mcr · cnb unverified-demo
Honest limits
- R3 flags
stringinputs at the ABI level even when the source caps their length — the mitigation is documented per fixture, not silenced. - Payable/unverified/missing-source fixtures cannot be built from published records right now; the platform-wide scan proves the absence, and R5's firing is demonstrated synthetically.
- Addresses are pinned, not tickers: re-pull any record live via
GET /v1/contracts/<address>.