Intermediate
Proxies & Upgradeable Contracts — Hands-on lab
Understand how upgrades work.
Developer Intermediate
4/6 — Proxies & Upgradeable Contracts — Hands-on lab
Practice the failure modes Intentionally reorder a variable in tests to see how storage breaks. Practice an unauthorized upgrade and make sure it fails. Rehearse your upgrade script on testnet and verify on an explorer.
Cryptography is about how to maintain control over information.
Observability Emit upgrade events, log implementation addresses, and keep a changelog. Verify proxiableUUID for UUPS to avoid proxy bricking.
Runbooks Write down the exact CLI steps to upgrade, who signs, and how to verify storage afterward. Include rollback steps and thresholds for pausing.
contract Box is Initializable, UUPSUpgradeable, OwnableUpgradeable {
uint256 public value;
function initialize(uint256 v) public initializer {
__Ownable_init();
__UUPSUpgradeable_init();
value = v;
}
function _authorizeUpgrade(address newImpl) internal override onlyOwner {}
function setValue(uint256 v) external onlyOwner { value = v; }
}
// test storage append-only:
// V2 adds: uint256 public extra;
// ensure reordering fails in tests.
Steps
- Deploy a Transparent or:UUPS proxy for a simple contract using OZ plugins; verify implementation + admin addresses.
- Create V1 with state;:Create V2 adding new variables (append-only). Write a test that reorders state and assert it fails (storage diff).
- Implement an initializer that:Sets roles/state; add an initializer modifier to block re-entry. Prove constructor is skipped behind proxy.
- Write an upgrade script:And tests that check proxiableUUID (UUPS), emit events, preserve storage, and verify new functions.
- Add upgrade authority via:Multisig/timelock; test unauthorized upgrade reverts. Add a pause/rollback plan and document steps.
- Run a rehearsal on:A testnet; verify implementation addresses in an explorer and confirm storage correctness after upgrade.