Build & operate
Run a buyback keeper
The keeper pays gas to call a permissionless function. It cannot withdraw a pool’s queued quote or choose where tokens go.
Before enabling execution
The repository includes a one-pass worker and systemd timer templates. They are not active in the current deployment. Use them only after the contracts, matching ABI/API, audit, and Arc integration checks are complete.
Run the keeper under a separate non-login OS user with its own gas-paying wallet. Keep the key in a server-only regular file with mode 0600. Do not reuse the treasury, deployer, API, or a creator’s key.
The worker checks the deployment manifest, API support flag, chain ID, and factory/hook/PoolManager wiring before considering transactions. It discovers queued tokens through the API and simulates execution at latest state.
Start with a dry run
pnpm --filter @fiatex/contracts build:dist
pnpm --filter @fiatex/indexer buyback:onceDry run is the default and does not need a signing key. An inactive manifest stops before key access or execution. Live signing requires an explicit FIATEX_BUYBACK_EXECUTE=true and the dedicated key-file configuration.
Default limits allow at most 0.05 native USDC in worst-case gas per transaction and 0.10 per pass, with 20% padding on the gas estimate. These are not daily spending caps. Limit the wallet’s funding and monitor it.
The timer checks 60 seconds after a completed pass. Each pass examines up to 100 queued tokens and saves its place, so the next pass continues through the queue. Contract cooldowns and price checks still decide whether any batch can run.
Handle uncertain transactions without double-signing
The worker holds a Linux process lock and persists the signed transaction before broadcasting it. It waits for three confirmations before clearing the journal. A timeout or uncertain send leaves the journal intact.
On restart, it rebroadcasts the same signed bytes and hash. It does not silently create a new transaction, skip a nonce, or raise the fee. Unknown pending nonces and unexpected replacement receipts stop the pass.
If a transaction is stuck, stop the timer and reconcile the saved hash, nonce, and receipt. Do not delete an unresolved journal or use the same key from another keeper. An underpriced or replaced transaction requires operator recovery. Three confirmations do not eliminate every reorganization risk.
