Events and errors
Use logs from the configured hub proxy address. A matching event name emitted by another contract is not evidence of a RUFF request or delivery.
Requested
Section titled “Requested”event Requested( address indexed provider, address indexed caller, uint64 indexed sequenceNumber, bytes32 userContribution, uint32 gasLimit, bytes extraArgs);provider is the hub. caller is the consumer contract. gasLimit is the resolved callback budget. Decode extraArgs as:
abi.decode(extraArgs, (uint32, uint64)) // laneId, indexRevealed
Section titled “Revealed”event Revealed( address indexed provider, address indexed caller, uint64 indexed sequenceNumber, bytes32 randomNumber, bytes32 userContribution, bytes32 providerContribution, bool callbackFailed, bytes callbackReturnValue, uint32 callbackGasUsed, bytes extraArgs);providerContribution is the verified effective seed, including when the hub derived it from an existing anchor. callbackReturnValue is capped at 256 bytes. callbackFailed describes the consumer callback, not failure to store the result.
abi.decode(extraArgs, (uint32, uint64, bytes32))// laneId, index, requestBlockHashThe event is emitted after the callback attempt so it can report the outcome. Verify the complete history instead of trusting one isolated event.
Lifecycle and configuration events
Section titled “Lifecycle and configuration events”| Event | Meaning |
|---|---|
LanePublished(laneId, head, length) |
A new chain commitment was published. |
ActiveLaneSet(laneId) |
New requests use this lane. |
AnchorAdvanced(laneId, index, sequenceNumber) |
Recovery moved the anchor through an expired request. |
Expired(sequenceNumber, caller) |
The request was closed; caller is the account performing expiry. |
RelayerSet(relayer, allowed) |
Delivery authorization changed. |
DefaultTariffSet, ConsumerTariffSet, ConsumerTariffCleared |
Fee or per-consumer settings changed. |
LimitsSet |
Hub-wide intake or callback limits changed. |
FeesWithdrawn, AllWithdrawn, ERC20Rescued |
Administrative asset movements. |
Inherited pause and ownership events, proxy upgrade events, and timelock events belong to their respective contracts. Observe the correct address for each.
Request errors
Section titled “Request errors”| Error | Interpretation and response |
|---|---|
ConsumerNotContract(caller) |
Request through a deployed consumer, not directly from an EOA. |
UnknownProvider(provider) |
Use the hub as provider. |
InsufficientFee(required, paid) |
Obtain a fresh quote and send the exact required value. |
CallbackGasTooHigh(requested, allowed) |
Budget is above the allowed tariff/ceiling; optimize or change configuration. |
ConsumerLimitReached(consumer, pending) |
This consumer’s pending capacity is full. |
GlobalLimitReached(pendingTotal) |
Hub pending capacity is full. |
RateLimited(blockNumber) |
The optional per-block intake cap was reached. |
NoActiveLane() / LaneExhausted(laneId) |
Operator action is needed before new requests can be accepted. |
EnforcedPause() |
The relevant hub operation is paused. |
For capacity errors, wait for capacity to become available. Retrying immediately in a tight loop increases failed transaction costs.
Delivery and recovery errors
Section titled “Delivery and recovery errors”| Error | Meaning |
|---|---|
NotRelayer() |
Sender lacks delivery authorization. |
UnknownRequest(sequence) |
No request exists at the sequence. |
NotPending(sequence, status) |
Request already settled or has another status. |
TooEarly(requestBlock) |
Delivery is attempted in or before the request block. |
InvalidSeed() |
Link failed commitment validation. |
TooFarFromAnchor(steps) |
Required forward verification exceeds 4096 steps. |
BlockhashUnavailable(blockNumber) |
The needed request hash is not available. |
NotEnoughGas() |
Delivery lacks the callback forwarding reserve; the transaction reverts. |
NotExpired(sequence) |
Anchor recovery requires an Expired request. |
AlreadyAnchored(index, anchorIndex) |
The anchor has reached or passed this recovery point. |
NotExpirable(sequence, age) |
The request has not passed the 8191-block expiry boundary. |
OwnershipRenounceDisabled() is returned by renounceOwnership(): ownership can only move through a two-step transfer and acceptance.
Administrative validation errors include InvalidLane, LaneHeadUsed, InvalidConfig, InvalidAmount, ZeroAddress, NativeTransferFailed, and ForbiddenToken. The complete ABI includes their parameter types and inherited errors.
