referrerpolicy=no-referrer-when-downgrade

pallet_society/
lib.rs

1// This file is part of Substrate.
2
3// Copyright (C) Parity Technologies (UK) Ltd.
4// SPDX-License-Identifier: Apache-2.0
5
6// Licensed under the Apache License, Version 2.0 (the "License");
7// you may not use this file except in compliance with the License.
8// You may obtain a copy of the License at
9//
10// 	http://www.apache.org/licenses/LICENSE-2.0
11//
12// Unless required by applicable law or agreed to in writing, software
13// distributed under the License is distributed on an "AS IS" BASIS,
14// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15// See the License for the specific language governing permissions and
16// limitations under the License.
17
18//! # Society Pallet
19//!
20//! - [`Config`]
21//! - [`Call`]
22//!
23//! ## Overview
24//!
25//! The Society pallet is an economic game which incentivizes users to participate
26//! and maintain a membership society.
27//!
28//! ### User Types
29//!
30//! At any point, a user in the society can be one of a:
31//! * Bidder - A user who has submitted intention of joining the society.
32//! * Candidate - A user who will be voted on to join the society.
33//! * Member - A user who is a member of the society.
34//! * Suspended Member - A member of the society who has accumulated too many strikes
35//! or failed their membership challenge.
36//!
37//! Of the non-suspended members, there is always a:
38//! * Head - A member who is exempt from suspension.
39//! * Defender - A member whose membership is under question and voted on again.
40//!
41//! Of the non-suspended members of the society, a random set of them are chosen as
42//! "skeptics". The mechanics of skeptics is explained in the
43//! [member phase](#member-phase) below.
44//!
45//! ### Mechanics
46//!
47//! #### Rewards
48//!
49//! Members are incentivized to participate in the society through rewards paid
50//! by the Society treasury. These payments have a maturity period that the user
51//! must wait before they are able to access the funds.
52//!
53//! #### Punishments
54//!
55//! Members can be punished by slashing the reward payouts that have not been
56//! collected. Additionally, members can accumulate "strikes", and when they
57//! reach a max strike limit, they become suspended.
58//!
59//! #### Skeptics
60//!
61//! During the voting period, a random set of members are selected as "skeptics".
62//! These skeptics are expected to vote on the current candidates. If they do not vote,
63//! their skeptic status is treated as a rejection vote, the member is deemed
64//! "lazy", and are given a strike per missing vote.
65//!
66//! #### Membership Challenges
67//!
68//! Every challenge rotation period, an existing member will be randomly selected
69//! to defend their membership into society. Then, other members can vote whether
70//! this defender should stay in society. A simple majority wins vote will determine
71//! the outcome of the user. Ties are treated as a failure of the challenge, but
72//! assuming no one else votes, the defender always get a free vote on their
73//! own challenge keeping them in the society. The Head member is exempt from the
74//! negative outcome of a membership challenge.
75//!
76//! #### Society Treasury
77//!
78//! The membership society is independently funded by a treasury managed by this
79//! pallet. Some subset of this treasury is placed in a Society Pot, which is used
80//! to determine the number of accepted bids.
81//!
82//! #### Rate of Growth
83//!
84//! The membership society can grow at a rate of 10 accepted candidates per rotation period up
85//! to the max membership threshold. Once this threshold is met, candidate selections
86//! are stalled until there is space for new members to join. This can be resolved by
87//! voting out existing members through the random challenges or by using governance
88//! to increase the maximum membership count.
89//!
90//! ### User Life Cycle
91//!
92//! A user can go through the following phases:
93//!
94//! ```ignore
95//!           +------->  User  <----------+
96//!           |           +               |
97//!           |           |               |
98//! +----------------------------------------------+
99//! |         |           |               |        |
100//! |         |           v               |        |
101//! |         |        Bidder <-----------+        |
102//! |         |           +               |        |
103//! |         |           |               +        |
104//! |         |           v            Suspended   |
105//! |         |       Candidate +----> Candidate   |
106//! |         |           +               +        |
107//! |         |           |               |        |
108//! |         +           |               |        |
109//! |   Suspended +------>|               |        |
110//! |      Member         |               |        |
111//! |         ^           |               |        |
112//! |         |           v               |        |
113//! |         +-------+ Member <----------+        |
114//! |                                              |
115//! |                                              |
116//! +------------------Society---------------------+
117//! ```
118//!
119//! #### Initialization
120//!
121//! The society is initialized with a single member who is automatically chosen as the Head.
122//!
123//! #### Bid Phase
124//!
125//! New users must have a bid to join the society.
126//!
127//! A user can make a bid by reserving a deposit. Alternatively, an already existing member
128//! can create a bid on a user's behalf by "vouching" for them.
129//!
130//! A bid includes reward information that the user would like to receive for joining
131//! the society. A vouching bid can additionally request some portion of that reward as a tip
132//! to the voucher for vouching for the prospective candidate.
133//!
134//! Every rotation period, Bids are ordered by reward amount, and the pallet
135//! selects as many bids the Society Pot can support for that period.
136//!
137//! These selected bids become candidates and move on to the Candidate phase.
138//! Bids that were not selected stay in the bidder pool until they are selected or
139//! a user chooses to "unbid".
140//!
141//! #### Candidate Phase
142//!
143//! Once a bidder becomes a candidate, members vote whether to approve or reject
144//! that candidate into society. This voting process also happens during a rotation period.
145//!
146//! The approval and rejection criteria for candidates are not set on chain,
147//! and may change for different societies.
148//!
149//! At the end of the rotation period, we collect the votes for a candidate
150//! and randomly select a vote as the final outcome.
151//!
152//! ```ignore
153//!  [ a-accept, r-reject, s-skeptic ]
154//! +----------------------------------+
155//! |                                  |
156//! |  Member   |0|1|2|3|4|5|6|7|8|9|  |
157//! |  -----------------------------   |
158//! |  Vote     |a|a|a|r|s|r|a|a|s|a|  |
159//! |  -----------------------------   |
160//! |  Selected | | | |x| | | | | | |  |
161//! |                                  |
162//! +----------------------------------+
163//!
164//! Result: Rejected
165//! ```
166//!
167//! Each member that voted opposite to this randomly selected vote is punished by
168//! slashing their unclaimed payouts and increasing the number of strikes they have.
169//!
170//! These slashed funds are given to a random user who voted the same as the
171//! selected vote as a reward for participating in the vote.
172//!
173//! If the candidate wins the vote, they receive their bid reward as a future payout.
174//! If the bid was placed by a voucher, they will receive their portion of the reward,
175//! before the rest is paid to the winning candidate.
176//!
177//! One winning candidate is selected as the Head of the members. This is randomly
178//! chosen, weighted by the number of approvals the winning candidates accumulated.
179//!
180//! If the candidate loses the vote, they are suspended and it is up to the Suspension
181//! Judgement origin to determine if the candidate should go through the bidding process
182//! again, should be accepted into the membership society, or rejected and their deposit
183//! slashed.
184//!
185//! #### Member Phase
186//!
187//! Once a candidate becomes a member, their role is to participate in society.
188//!
189//! Regular participation involves voting on candidates who want to join the membership
190//! society, and by voting in the right way, a member will accumulate future payouts.
191//! When a payout matures, members are able to claim those payouts.
192//!
193//! Members can also vouch for users to join the society, and request a "tip" from
194//! the fees the new member would collect by joining the society. This vouching
195//! process is useful in situations where a user may not have enough balance to
196//! satisfy the bid deposit. A member can only vouch one user at a time.
197//!
198//! During rotation periods, a random group of members are selected as "skeptics".
199//! These skeptics are expected to vote on the current candidates. If they do not vote,
200//! their skeptic status is treated as a rejection vote, the member is deemed
201//! "lazy", and are given a strike per missing vote.
202//!
203//! There is a challenge period in parallel to the rotation period. During a challenge period,
204//! a random member is selected to defend their membership to the society. Other members
205//! make a traditional majority-wins vote to determine if the member should stay in the society.
206//! Ties are treated as a failure of the challenge.
207//!
208//! If a member accumulates too many strikes or fails their membership challenge,
209//! they will become suspended. While a member is suspended, they are unable to
210//! claim matured payouts. It is up to the Suspension Judgement origin to determine
211//! if the member should re-enter society or be removed from society with all their
212//! future payouts slashed.
213//!
214//! ## Interface
215//!
216//! ### Dispatchable Functions
217//!
218//! #### For General Users
219//!
220//! * `bid` - A user can make a bid to join the membership society by reserving a deposit.
221//! * `unbid` - A user can withdraw their bid for entry, the deposit is returned.
222//!
223//! #### For Members
224//!
225//! * `vouch` - A member can place a bid on behalf of a user to join the membership society.
226//! * `unvouch` - A member can revoke their vouch for a user.
227//! * `vote` - A member can vote to approve or reject a candidate's request to join the society.
228//! * `defender_vote` - A member can vote to approve or reject a defender's continued membership
229//! to the society.
230//! * `payout` - A member can claim their first matured payment.
231//! * `unfound` - Allow the founder to unfound the society when they are the only member.
232//!
233//! #### For Super Users
234//!
235//! * `found` - The founder origin can initiate this society. Useful for bootstrapping the Society
236//! pallet on an already running chain.
237//! * `judge_suspended_member` - The suspension judgement origin is able to make
238//! judgement on a suspended member.
239//! * `judge_suspended_candidate` - The suspension judgement origin is able to
240//! make judgement on a suspended candidate.
241//! * `set_max_membership` - The ROOT origin can update the maximum member count for the society.
242//! The max membership count must be greater than 1.
243
244// Ensure we're `no_std` when compiling for Wasm.
245#![cfg_attr(not(feature = "std"), no_std)]
246
247#[cfg(test)]
248mod mock;
249
250#[cfg(test)]
251mod tests;
252
253#[cfg(feature = "runtime-benchmarks")]
254mod benchmarking;
255
256pub mod weights;
257
258pub mod migrations;
259
260extern crate alloc;
261
262use alloc::vec::Vec;
263use frame_support::{
264	impl_ensure_origin_with_arg_ignoring_arg,
265	pallet_prelude::*,
266	storage::KeyLenOf,
267	traits::{
268		BalanceStatus, Currency, EnsureOrigin, EnsureOriginWithArg,
269		ExistenceRequirement::AllowDeath, Imbalance, OnUnbalanced, Randomness, ReservableCurrency,
270		StorageVersion,
271	},
272	PalletId,
273};
274use frame_system::pallet_prelude::{
275	ensure_signed, BlockNumberFor as SystemBlockNumberFor, OriginFor,
276};
277use rand_chacha::{
278	rand_core::{RngCore, SeedableRng},
279	ChaChaRng,
280};
281use scale_info::TypeInfo;
282use sp_runtime::{
283	traits::{
284		AccountIdConversion, CheckedAdd, CheckedSub, Hash, Saturating, StaticLookup,
285		TrailingZeroInput, Zero,
286	},
287	ArithmeticError::Overflow,
288	Debug, Percent,
289};
290
291pub use weights::WeightInfo;
292
293pub use pallet::*;
294use sp_runtime::traits::BlockNumberProvider;
295
296pub type BlockNumberFor<T, I> =
297	<<T as Config<I>>::BlockNumberProvider as BlockNumberProvider>::BlockNumber;
298
299pub type BalanceOf<T, I> =
300	<<T as Config<I>>::Currency as Currency<<T as frame_system::Config>::AccountId>>::Balance;
301pub type NegativeImbalanceOf<T, I> = <<T as Config<I>>::Currency as Currency<
302	<T as frame_system::Config>::AccountId,
303>>::NegativeImbalance;
304pub type AccountIdLookupOf<T> = <<T as frame_system::Config>::Lookup as StaticLookup>::Source;
305
306#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
307pub struct Vote {
308	pub approve: bool,
309	pub weight: u32,
310}
311
312/// A judgement by the suspension judgement origin on a suspended candidate.
313#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
314pub enum Judgement {
315	/// The suspension judgement origin takes no direct judgment
316	/// and places the candidate back into the bid pool.
317	Rebid,
318	/// The suspension judgement origin has rejected the candidate's application.
319	Reject,
320	/// The suspension judgement origin approves of the candidate's application.
321	Approve,
322}
323
324/// Details of a payout given as a per-block linear "trickle".
325#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, Default, TypeInfo, MaxEncodedLen)]
326pub struct Payout<Balance, BlockNumber> {
327	/// Total value of the payout.
328	pub value: Balance,
329	/// Block number at which the payout begins.
330	pub begin: BlockNumber,
331	/// Total number of blocks over which the payout is spread.
332	pub duration: BlockNumber,
333	/// Total value paid out so far.
334	pub paid: Balance,
335}
336
337/// Status of a vouching member.
338#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
339pub enum VouchingStatus {
340	/// Member is currently vouching for a user.
341	Vouching,
342	/// Member is banned from vouching for other members.
343	Banned,
344}
345
346/// Number of strikes that a member has against them.
347pub type StrikeCount = u32;
348
349/// A bid for entry into society.
350#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
351pub struct Bid<AccountId, Balance> {
352	/// The bidder/candidate trying to enter society
353	pub who: AccountId,
354	/// The kind of bid placed for this bidder/candidate. See `BidKind`.
355	pub kind: BidKind<AccountId, Balance>,
356	/// The reward that the bidder has requested for successfully joining the society.
357	pub value: Balance,
358}
359
360/// The index of a round of candidates.
361pub type RoundIndex = u32;
362
363/// The rank of a member.
364pub type Rank = u32;
365
366/// The number of votes.
367pub type VoteCount = u32;
368
369/// Tally of votes.
370#[derive(Default, Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
371pub struct Tally {
372	/// The approval votes.
373	pub approvals: VoteCount,
374	/// The rejection votes.
375	pub rejections: VoteCount,
376}
377
378impl Tally {
379	fn more_approvals(&self) -> bool {
380		self.approvals > self.rejections
381	}
382
383	fn more_rejections(&self) -> bool {
384		self.rejections > self.approvals
385	}
386
387	fn clear_approval(&self) -> bool {
388		self.approvals >= (2 * self.rejections).max(1)
389	}
390
391	fn clear_rejection(&self) -> bool {
392		self.rejections >= (2 * self.approvals).max(1)
393	}
394}
395
396/// A bid for entry into society.
397#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
398pub struct Candidacy<AccountId, Balance> {
399	/// The index of the round where the candidacy began.
400	pub round: RoundIndex,
401	/// The kind of bid placed for this bidder/candidate. See `BidKind`.
402	pub kind: BidKind<AccountId, Balance>,
403	/// The reward that the bidder has requested for successfully joining the society.
404	pub bid: Balance,
405	/// The tally of votes so far.
406	pub tally: Tally,
407	/// True if the skeptic was already punished for note voting.
408	pub skeptic_struck: bool,
409}
410
411/// A vote by a member on a candidate application.
412#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
413pub enum BidKind<AccountId, Balance> {
414	/// The given deposit was paid for this bid.
415	Deposit(Balance),
416	/// A member vouched for this bid. The account should be reinstated into `Members` once the
417	/// bid is successful (or if it is rescinded prior to launch).
418	Vouch(AccountId, Balance),
419}
420
421impl<AccountId: PartialEq, Balance> BidKind<AccountId, Balance> {
422	fn is_vouch(&self, v: &AccountId) -> bool {
423		matches!(self, BidKind::Vouch(ref a, _) if a == v)
424	}
425}
426
427pub type PayoutsFor<T, I> =
428	BoundedVec<(BlockNumberFor<T, I>, BalanceOf<T, I>), <T as Config<I>>::MaxPayouts>;
429
430/// Information concerning a member.
431#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
432pub struct MemberRecord {
433	pub rank: Rank,
434	pub strikes: StrikeCount,
435	pub vouching: Option<VouchingStatus>,
436	pub index: u32,
437}
438
439/// Information concerning a member.
440#[derive(Encode, Decode, Clone, PartialEq, Eq, Debug, TypeInfo, Default, MaxEncodedLen)]
441pub struct PayoutRecord<Balance, PayoutsVec> {
442	pub paid: Balance,
443	pub payouts: PayoutsVec,
444}
445
446pub type PayoutRecordFor<T, I> = PayoutRecord<
447	BalanceOf<T, I>,
448	BoundedVec<(BlockNumberFor<T, I>, BalanceOf<T, I>), <T as Config<I>>::MaxPayouts>,
449>;
450
451/// Record for an individual new member who was elevated from a candidate recently.
452#[derive(Encode, Decode, Copy, Clone, PartialEq, Eq, Debug, TypeInfo, MaxEncodedLen)]
453pub struct IntakeRecord<AccountId, Balance> {
454	pub who: AccountId,
455	pub bid: Balance,
456	pub round: RoundIndex,
457}
458
459pub type IntakeRecordFor<T, I> =
460	IntakeRecord<<T as frame_system::Config>::AccountId, BalanceOf<T, I>>;
461
462#[derive(
463	Encode,
464	Decode,
465	DecodeWithMemTracking,
466	Copy,
467	Clone,
468	PartialEq,
469	Eq,
470	Debug,
471	TypeInfo,
472	MaxEncodedLen,
473)]
474pub struct GroupParams<Balance> {
475	pub max_members: u32,
476	pub max_intake: u32,
477	pub max_strikes: u32,
478	pub candidate_deposit: Balance,
479}
480
481pub type GroupParamsFor<T, I> = GroupParams<BalanceOf<T, I>>;
482
483pub(crate) const STORAGE_VERSION: StorageVersion = StorageVersion::new(2);
484
485#[frame_support::pallet]
486pub mod pallet {
487	use super::*;
488
489	#[pallet::pallet]
490	#[pallet::storage_version(STORAGE_VERSION)]
491	pub struct Pallet<T, I = ()>(_);
492
493	#[pallet::config]
494	pub trait Config<I: 'static = ()>: frame_system::Config {
495		/// The overarching event type.
496		#[allow(deprecated)]
497		type RuntimeEvent: From<Event<Self, I>>
498			+ IsType<<Self as frame_system::Config>::RuntimeEvent>;
499
500		/// The societies's pallet id
501		#[pallet::constant]
502		type PalletId: Get<PalletId>;
503
504		/// The currency type used for bidding.
505		type Currency: ReservableCurrency<Self::AccountId>;
506
507		/// Something that provides randomness in the runtime.
508		type Randomness: Randomness<Self::Hash, BlockNumberFor<Self, I>>;
509
510		/// The maximum number of strikes before a member gets funds slashed.
511		#[pallet::constant]
512		type GraceStrikes: Get<u32>;
513
514		/// The amount of incentive paid within each period. Doesn't include VoterTip.
515		#[pallet::constant]
516		type PeriodSpend: Get<BalanceOf<Self, I>>;
517
518		/// The number of [Config::BlockNumberProvider] blocks on which new candidates should be
519		/// voted on. Together with
520		/// `ClaimPeriod`, this sums to the number of blocks between candidate intake periods.
521		#[pallet::constant]
522		type VotingPeriod: Get<BlockNumberFor<Self, I>>;
523
524		/// The number of [Config::BlockNumberProvider] blocks on which new candidates can claim
525		/// their membership and be the named head.
526		#[pallet::constant]
527		type ClaimPeriod: Get<BlockNumberFor<Self, I>>;
528
529		/// The maximum duration of the payout lock.
530		#[pallet::constant]
531		type MaxLockDuration: Get<BlockNumberFor<Self, I>>;
532
533		/// The origin that is allowed to call `found`.
534		type FounderSetOrigin: EnsureOrigin<Self::RuntimeOrigin>;
535
536		/// The number of [Config::BlockNumberProvider] blocks between membership challenges.
537		#[pallet::constant]
538		type ChallengePeriod: Get<BlockNumberFor<Self, I>>;
539
540		/// The maximum number of payouts a member may have waiting unclaimed.
541		#[pallet::constant]
542		type MaxPayouts: Get<u32>;
543
544		/// The maximum number of bids at once.
545		#[pallet::constant]
546		type MaxBids: Get<u32>;
547
548		/// Weight information for extrinsics in this pallet.
549		type WeightInfo: WeightInfo;
550		/// Provider for the block number. Normally this is the `frame_system` pallet.
551		type BlockNumberProvider: BlockNumberProvider;
552	}
553
554	#[pallet::error]
555	pub enum Error<T, I = ()> {
556		/// User is not a member.
557		NotMember,
558		/// User is already a member.
559		AlreadyMember,
560		/// User is suspended.
561		Suspended,
562		/// User is not suspended.
563		NotSuspended,
564		/// Nothing to payout.
565		NoPayout,
566		/// Society already founded.
567		AlreadyFounded,
568		/// Not enough in pot to accept candidate.
569		InsufficientPot,
570		/// Member is already vouching or banned from vouching again.
571		AlreadyVouching,
572		/// Member is not vouching.
573		NotVouchingOnBidder,
574		/// Cannot remove the head of the chain.
575		Head,
576		/// Cannot remove the founder.
577		Founder,
578		/// User has already made a bid.
579		AlreadyBid,
580		/// User is already a candidate.
581		AlreadyCandidate,
582		/// User is not a candidate.
583		NotCandidate,
584		/// Too many members in the society.
585		MaxMembers,
586		/// The caller is not the founder.
587		NotFounder,
588		/// The caller is not the head.
589		NotHead,
590		/// The membership cannot be claimed as the candidate was not clearly approved.
591		NotApproved,
592		/// The candidate cannot be kicked as the candidate was not clearly rejected.
593		NotRejected,
594		/// The candidacy cannot be dropped as the candidate was clearly approved.
595		Approved,
596		/// The candidacy cannot be bestowed as the candidate was clearly rejected.
597		Rejected,
598		/// The candidacy cannot be concluded as the voting is still in progress.
599		InProgress,
600		/// The candidacy cannot be pruned until a full additional intake period has passed.
601		TooEarly,
602		/// The skeptic already voted.
603		Voted,
604		/// The skeptic need not vote on candidates from expired rounds.
605		Expired,
606		/// User is not a bidder.
607		NotBidder,
608		/// There is no defender currently.
609		NoDefender,
610		/// Group doesn't exist.
611		NotGroup,
612		/// The member is already elevated to this rank.
613		AlreadyElevated,
614		/// The skeptic has already been punished for this offence.
615		AlreadyPunished,
616		/// Funds are insufficient to pay off society debts.
617		InsufficientFunds,
618		/// The candidate/defender has no stale votes to remove.
619		NoVotes,
620		/// There is no deposit associated with a bid.
621		NoDeposit,
622	}
623
624	#[pallet::event]
625	#[pallet::generate_deposit(pub(super) fn deposit_event)]
626	pub enum Event<T: Config<I>, I: 'static = ()> {
627		/// The society is founded by the given identity.
628		Founded { founder: T::AccountId },
629		/// A membership bid just happened. The given account is the candidate's ID and their offer
630		/// is the second.
631		Bid { candidate_id: T::AccountId, offer: BalanceOf<T, I> },
632		/// A membership bid just happened by vouching. The given account is the candidate's ID and
633		/// their offer is the second. The vouching party is the third.
634		Vouch { candidate_id: T::AccountId, offer: BalanceOf<T, I>, vouching: T::AccountId },
635		/// A candidate was dropped (due to an excess of bids in the system).
636		AutoUnbid { candidate: T::AccountId },
637		/// A candidate was dropped (by their request).
638		Unbid { candidate: T::AccountId },
639		/// A candidate was dropped (by request of who vouched for them).
640		Unvouch { candidate: T::AccountId },
641		/// A group of candidates have been inducted. The batch's primary is the first value, the
642		/// batch in full is the second.
643		Inducted { primary: T::AccountId, candidates: Vec<T::AccountId> },
644		/// A suspended member has been judged.
645		SuspendedMemberJudgement { who: T::AccountId, judged: bool },
646		/// A candidate has been suspended
647		CandidateSuspended { candidate: T::AccountId },
648		/// A member has been suspended
649		MemberSuspended { member: T::AccountId },
650		/// A member has been challenged
651		Challenged { member: T::AccountId },
652		/// A vote has been placed
653		Vote { candidate: T::AccountId, voter: T::AccountId, vote: bool },
654		/// A vote has been placed for a defending member
655		DefenderVote { voter: T::AccountId, vote: bool },
656		/// A new set of \[params\] has been set for the group.
657		NewParams { params: GroupParamsFor<T, I> },
658		/// Society is unfounded.
659		Unfounded { founder: T::AccountId },
660		/// Some funds were deposited into the society account.
661		Deposit { value: BalanceOf<T, I> },
662		/// A \[member\] got elevated to \[rank\].
663		Elevated { member: T::AccountId, rank: Rank },
664		/// A deposit was poked / adjusted.
665		DepositPoked {
666			who: T::AccountId,
667			old_deposit: BalanceOf<T, I>,
668			new_deposit: BalanceOf<T, I>,
669		},
670		/// A member was kicked by the founder.
671		MemberKicked { member: T::AccountId },
672	}
673
674	/// The max number of members for the society at one time.
675	#[pallet::storage]
676	pub type Parameters<T: Config<I>, I: 'static = ()> =
677		StorageValue<_, GroupParamsFor<T, I>, OptionQuery>;
678
679	/// Amount of our account balance that is specifically for the next round's bid(s).
680	#[pallet::storage]
681	pub type Pot<T: Config<I>, I: 'static = ()> = StorageValue<_, BalanceOf<T, I>, ValueQuery>;
682
683	/// The first member.
684	#[pallet::storage]
685	pub type Founder<T: Config<I>, I: 'static = ()> = StorageValue<_, T::AccountId>;
686
687	/// The most primary from the most recently approved rank 0 members in the society.
688	#[pallet::storage]
689	pub type Head<T: Config<I>, I: 'static = ()> = StorageValue<_, T::AccountId>;
690
691	/// A hash of the rules of this society concerning membership. Can only be set once and
692	/// only by the founder.
693	#[pallet::storage]
694	pub type Rules<T: Config<I>, I: 'static = ()> = StorageValue<_, T::Hash>;
695
696	/// The current members and their rank. Doesn't include `SuspendedMembers`.
697	#[pallet::storage]
698	pub type Members<T: Config<I>, I: 'static = ()> =
699		StorageMap<_, Twox64Concat, T::AccountId, MemberRecord, OptionQuery>;
700
701	/// Information regarding rank-0 payouts, past and future.
702	#[pallet::storage]
703	pub type Payouts<T: Config<I>, I: 'static = ()> =
704		StorageMap<_, Twox64Concat, T::AccountId, PayoutRecordFor<T, I>, ValueQuery>;
705
706	/// The number of items in `Members` currently. (Doesn't include `SuspendedMembers`.)
707	#[pallet::storage]
708	pub type MemberCount<T: Config<I>, I: 'static = ()> = StorageValue<_, u32, ValueQuery>;
709
710	/// The current items in `Members` keyed by their unique index. Keys are densely populated
711	/// `0..MemberCount` (does not include `MemberCount`).
712	#[pallet::storage]
713	pub type MemberByIndex<T: Config<I>, I: 'static = ()> =
714		StorageMap<_, Twox64Concat, u32, T::AccountId, OptionQuery>;
715
716	/// The set of suspended members, with their old membership record.
717	#[pallet::storage]
718	pub type SuspendedMembers<T: Config<I>, I: 'static = ()> =
719		StorageMap<_, Twox64Concat, T::AccountId, MemberRecord, OptionQuery>;
720
721	/// The number of rounds which have passed.
722	#[pallet::storage]
723	pub type RoundCount<T: Config<I>, I: 'static = ()> = StorageValue<_, RoundIndex, ValueQuery>;
724
725	/// The current bids, stored ordered by the value of the bid.
726	#[pallet::storage]
727	pub type Bids<T: Config<I>, I: 'static = ()> =
728		StorageValue<_, BoundedVec<Bid<T::AccountId, BalanceOf<T, I>>, T::MaxBids>, ValueQuery>;
729
730	#[pallet::storage]
731	pub type Candidates<T: Config<I>, I: 'static = ()> = StorageMap<
732		_,
733		Blake2_128Concat,
734		T::AccountId,
735		Candidacy<T::AccountId, BalanceOf<T, I>>,
736		OptionQuery,
737	>;
738
739	/// The current skeptic.
740	#[pallet::storage]
741	pub type Skeptic<T: Config<I>, I: 'static = ()> = StorageValue<_, T::AccountId, OptionQuery>;
742
743	/// Double map from Candidate -> Voter -> (Maybe) Vote.
744	#[pallet::storage]
745	pub type Votes<T: Config<I>, I: 'static = ()> = StorageDoubleMap<
746		_,
747		Twox64Concat,
748		T::AccountId,
749		Twox64Concat,
750		T::AccountId,
751		Vote,
752		OptionQuery,
753	>;
754
755	/// Clear-cursor for Vote, map from Candidate -> (Maybe) Cursor.
756	#[pallet::storage]
757	pub type VoteClearCursor<T: Config<I>, I: 'static = ()> =
758		StorageMap<_, Twox64Concat, T::AccountId, BoundedVec<u8, KeyLenOf<Votes<T, I>>>>;
759
760	/// At the end of the claim period, this contains the most recently approved members (along with
761	/// their bid and round ID) who is from the most recent round with the lowest bid. They will
762	/// become the new `Head`.
763	#[pallet::storage]
764	pub type NextHead<T: Config<I>, I: 'static = ()> =
765		StorageValue<_, IntakeRecordFor<T, I>, OptionQuery>;
766
767	/// The number of challenge rounds there have been. Used to identify stale DefenderVotes.
768	#[pallet::storage]
769	pub type ChallengeRoundCount<T: Config<I>, I: 'static = ()> =
770		StorageValue<_, RoundIndex, ValueQuery>;
771
772	/// The defending member currently being challenged, along with a running tally of votes.
773	#[pallet::storage]
774	pub type Defending<T: Config<I>, I: 'static = ()> =
775		StorageValue<_, (T::AccountId, T::AccountId, Tally)>;
776
777	/// Votes for the defender, keyed by challenge round.
778	#[pallet::storage]
779	pub type DefenderVotes<T: Config<I>, I: 'static = ()> =
780		StorageDoubleMap<_, Twox64Concat, RoundIndex, Twox64Concat, T::AccountId, Vote>;
781
782	/// Next intake rotation scheduled with [Config::BlockNumberProvider].
783	#[pallet::storage]
784	pub type NextIntakeAt<T: Config<I>, I: 'static = ()> = StorageValue<_, BlockNumberFor<T, I>>;
785
786	/// Next challenge rotation scheduled with [Config::BlockNumberProvider].
787	#[pallet::storage]
788	pub type NextChallengeAt<T: Config<I>, I: 'static = ()> = StorageValue<_, BlockNumberFor<T, I>>;
789
790	#[pallet::hooks]
791	impl<T: Config<I>, I: 'static> Hooks<SystemBlockNumberFor<T>> for Pallet<T, I> {
792		fn on_initialize(_n: SystemBlockNumberFor<T>) -> Weight {
793			let mut weight = Weight::zero();
794			let weights = T::BlockWeights::get();
795			let now = T::BlockNumberProvider::current_block_number();
796
797			let phrase = b"society_rotation";
798			// we'll need a random seed here.
799			// TODO: deal with randomness freshness
800			// https://github.com/paritytech/substrate/issues/8312
801			let (seed, _) = T::Randomness::random(phrase);
802			// seed needs to be guaranteed to be 32 bytes.
803			let seed = <[u8; 32]>::decode(&mut TrailingZeroInput::new(seed.as_ref()))
804				.expect("input is padded with zeroes; qed");
805			let mut rng = ChaChaRng::from_seed(seed);
806
807			// Run a candidate/membership rotation
808			let is_intake_moment = match Self::period() {
809				Period::Intake { .. } => true,
810				_ => false,
811			};
812			if is_intake_moment {
813				Self::rotate_intake(&mut rng);
814				weight.saturating_accrue(weights.max_block / 20);
815				Self::set_next_intake_at();
816			}
817
818			// Run a challenge rotation
819			if now >= Self::next_challenge_at() {
820				Self::rotate_challenge(&mut rng);
821				weight.saturating_accrue(weights.max_block / 20);
822				Self::set_next_challenge_at();
823			}
824
825			weight
826		}
827
828		#[cfg(feature = "try-runtime")]
829		fn try_state(_: SystemBlockNumberFor<T>) -> Result<(), sp_runtime::TryRuntimeError> {
830			Self::do_try_state()
831		}
832	}
833
834	#[pallet::genesis_config]
835	#[derive(frame_support::DefaultNoBound)]
836	pub struct GenesisConfig<T: Config<I>, I: 'static = ()> {
837		pub pot: BalanceOf<T, I>,
838	}
839
840	#[pallet::genesis_build]
841	impl<T: Config<I>, I: 'static> BuildGenesisConfig for GenesisConfig<T, I> {
842		fn build(&self) {
843			Pot::<T, I>::put(self.pot);
844		}
845	}
846
847	#[pallet::call]
848	impl<T: Config<I>, I: 'static> Pallet<T, I> {
849		/// A user outside of the society can make a bid for entry.
850		///
851		/// Payment: The group's Candidate Deposit will be reserved for making a bid. It is returned
852		/// when the bid becomes a member, or if the bid calls `unbid`.
853		///
854		/// The dispatch origin for this call must be _Signed_.
855		///
856		/// Parameters:
857		/// - `value`: A one time payment the bid would like to receive when joining the society.
858		#[pallet::call_index(0)]
859		#[pallet::weight(T::WeightInfo::bid())]
860		pub fn bid(origin: OriginFor<T>, value: BalanceOf<T, I>) -> DispatchResult {
861			let who = ensure_signed(origin)?;
862
863			let mut bids = Bids::<T, I>::get();
864			ensure!(!Self::has_bid(&bids, &who), Error::<T, I>::AlreadyBid);
865			ensure!(!Candidates::<T, I>::contains_key(&who), Error::<T, I>::AlreadyCandidate);
866			ensure!(!Members::<T, I>::contains_key(&who), Error::<T, I>::AlreadyMember);
867			ensure!(!SuspendedMembers::<T, I>::contains_key(&who), Error::<T, I>::Suspended);
868
869			let params = Parameters::<T, I>::get().ok_or(Error::<T, I>::NotGroup)?;
870			let deposit = params.candidate_deposit;
871			// NOTE: Reserve must happen before `insert_bid` since that could end up unreserving.
872			T::Currency::reserve(&who, deposit)?;
873			Self::insert_bid(&mut bids, &who, value, BidKind::Deposit(deposit));
874
875			Bids::<T, I>::put(bids);
876			Self::deposit_event(Event::<T, I>::Bid { candidate_id: who, offer: value });
877			Ok(())
878		}
879
880		/// A bidder can remove their bid for entry into society.
881		/// By doing so, they will have their candidate deposit returned or
882		/// they will unvouch their voucher.
883		///
884		/// Payment: The bid deposit is unreserved if the user made a bid.
885		///
886		/// The dispatch origin for this call must be _Signed_ and a bidder.
887		#[pallet::call_index(1)]
888		#[pallet::weight(T::WeightInfo::unbid())]
889		pub fn unbid(origin: OriginFor<T>) -> DispatchResult {
890			let who = ensure_signed(origin)?;
891
892			let mut bids = Bids::<T, I>::get();
893			let pos = bids.iter().position(|bid| bid.who == who).ok_or(Error::<T, I>::NotBidder)?;
894			Self::clean_bid(&bids.remove(pos));
895			Bids::<T, I>::put(bids);
896			Self::deposit_event(Event::<T, I>::Unbid { candidate: who });
897			Ok(())
898		}
899
900		/// As a member, vouch for someone to join society by placing a bid on their behalf.
901		///
902		/// There is no deposit required to vouch for a new bid, but a member can only vouch for
903		/// one bid at a time. If the bid becomes a suspended candidate and ultimately rejected by
904		/// the suspension judgement origin, the member will be banned from vouching again.
905		///
906		/// As a vouching member, you can claim a tip if the candidate is accepted. This tip will
907		/// be paid as a portion of the reward the member will receive for joining the society.
908		///
909		/// The dispatch origin for this call must be _Signed_ and a member.
910		///
911		/// Parameters:
912		/// - `who`: The user who you would like to vouch for.
913		/// - `value`: The total reward to be paid between you and the candidate if they become
914		/// a member in the society.
915		/// - `tip`: Your cut of the total `value` payout when the candidate is inducted into
916		/// the society. Tips larger than `value` will be saturated upon payout.
917		#[pallet::call_index(2)]
918		#[pallet::weight(T::WeightInfo::vouch())]
919		pub fn vouch(
920			origin: OriginFor<T>,
921			who: AccountIdLookupOf<T>,
922			value: BalanceOf<T, I>,
923			tip: BalanceOf<T, I>,
924		) -> DispatchResult {
925			let voucher = ensure_signed(origin)?;
926			let who = T::Lookup::lookup(who)?;
927
928			// Get bids and check user is not bidding.
929			let mut bids = Bids::<T, I>::get();
930			ensure!(!Self::has_bid(&bids, &who), Error::<T, I>::AlreadyBid);
931
932			// Check user is not already a candidate, member or suspended member.
933			ensure!(!Candidates::<T, I>::contains_key(&who), Error::<T, I>::AlreadyCandidate);
934			ensure!(!Members::<T, I>::contains_key(&who), Error::<T, I>::AlreadyMember);
935			ensure!(!SuspendedMembers::<T, I>::contains_key(&who), Error::<T, I>::Suspended);
936
937			// Check sender can vouch.
938			let mut record = Members::<T, I>::get(&voucher).ok_or(Error::<T, I>::NotMember)?;
939			ensure!(record.vouching.is_none(), Error::<T, I>::AlreadyVouching);
940
941			// Update voucher record.
942			record.vouching = Some(VouchingStatus::Vouching);
943			// Update bids
944			Self::insert_bid(&mut bids, &who, value, BidKind::Vouch(voucher.clone(), tip));
945
946			// Write new state.
947			Members::<T, I>::insert(&voucher, &record);
948			Bids::<T, I>::put(bids);
949			Self::deposit_event(Event::<T, I>::Vouch {
950				candidate_id: who,
951				offer: value,
952				vouching: voucher,
953			});
954			Ok(())
955		}
956
957		/// As a vouching member, unvouch a bid. This only works while vouched user is
958		/// only a bidder (and not a candidate).
959		///
960		/// The dispatch origin for this call must be _Signed_ and a vouching member.
961		///
962		/// Parameters:
963		/// - `pos`: Position in the `Bids` vector of the bid who should be unvouched.
964		#[pallet::call_index(3)]
965		#[pallet::weight(T::WeightInfo::unvouch())]
966		pub fn unvouch(origin: OriginFor<T>) -> DispatchResult {
967			let voucher = ensure_signed(origin)?;
968
969			let mut bids = Bids::<T, I>::get();
970			let pos = bids
971				.iter()
972				.position(|bid| bid.kind.is_vouch(&voucher))
973				.ok_or(Error::<T, I>::NotVouchingOnBidder)?;
974			let bid = bids.remove(pos);
975			Self::clean_bid(&bid);
976
977			Bids::<T, I>::put(bids);
978			Self::deposit_event(Event::<T, I>::Unvouch { candidate: bid.who });
979			Ok(())
980		}
981
982		/// As a member, vote on a candidate.
983		///
984		/// The dispatch origin for this call must be _Signed_ and a member.
985		///
986		/// Parameters:
987		/// - `candidate`: The candidate that the member would like to bid on.
988		/// - `approve`: A boolean which says if the candidate should be approved (`true`) or
989		///   rejected (`false`).
990		#[pallet::call_index(4)]
991		#[pallet::weight(T::WeightInfo::vote())]
992		pub fn vote(
993			origin: OriginFor<T>,
994			candidate: AccountIdLookupOf<T>,
995			approve: bool,
996		) -> DispatchResultWithPostInfo {
997			let voter = ensure_signed(origin)?;
998			let candidate = T::Lookup::lookup(candidate)?;
999
1000			let mut candidacy =
1001				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1002			let record = Members::<T, I>::get(&voter).ok_or(Error::<T, I>::NotMember)?;
1003
1004			let first_time = Votes::<T, I>::mutate(&candidate, &voter, |v| {
1005				let first_time = v.is_none();
1006				*v = Some(Self::do_vote(*v, approve, record.rank, &mut candidacy.tally));
1007				first_time
1008			});
1009
1010			Candidates::<T, I>::insert(&candidate, &candidacy);
1011			Self::deposit_event(Event::<T, I>::Vote { candidate, voter, vote: approve });
1012			Ok(if first_time { Pays::No } else { Pays::Yes }.into())
1013		}
1014
1015		/// As a member, vote on the defender.
1016		///
1017		/// The dispatch origin for this call must be _Signed_ and a member.
1018		///
1019		/// Parameters:
1020		/// - `approve`: A boolean which says if the candidate should be
1021		/// approved (`true`) or rejected (`false`).
1022		#[pallet::call_index(5)]
1023		#[pallet::weight(T::WeightInfo::defender_vote())]
1024		pub fn defender_vote(origin: OriginFor<T>, approve: bool) -> DispatchResultWithPostInfo {
1025			let voter = ensure_signed(origin)?;
1026
1027			let mut defending = Defending::<T, I>::get().ok_or(Error::<T, I>::NoDefender)?;
1028			let record = Members::<T, I>::get(&voter).ok_or(Error::<T, I>::NotMember)?;
1029
1030			let round = ChallengeRoundCount::<T, I>::get();
1031			let first_time = DefenderVotes::<T, I>::mutate(round, &voter, |v| {
1032				let first_time = v.is_none();
1033				*v = Some(Self::do_vote(*v, approve, record.rank, &mut defending.2));
1034				first_time
1035			});
1036
1037			Defending::<T, I>::put(defending);
1038			Self::deposit_event(Event::<T, I>::DefenderVote { voter, vote: approve });
1039			Ok(if first_time { Pays::No } else { Pays::Yes }.into())
1040		}
1041
1042		/// Transfer the first matured payout for the sender and remove it from the records.
1043		///
1044		/// NOTE: This extrinsic needs to be called multiple times to claim multiple matured
1045		/// payouts.
1046		///
1047		/// Payment: The member will receive a payment equal to their first matured
1048		/// payout to their free balance.
1049		///
1050		/// The dispatch origin for this call must be _Signed_ and a member with
1051		/// payouts remaining.
1052		#[pallet::call_index(6)]
1053		#[pallet::weight(T::WeightInfo::payout())]
1054		pub fn payout(origin: OriginFor<T>) -> DispatchResult {
1055			let who = ensure_signed(origin)?;
1056			ensure!(
1057				Members::<T, I>::get(&who).ok_or(Error::<T, I>::NotMember)?.rank == 0,
1058				Error::<T, I>::NoPayout
1059			);
1060			let mut record = Payouts::<T, I>::get(&who);
1061			let block_number = T::BlockNumberProvider::current_block_number();
1062			if let Some((when, amount)) = record.payouts.first() {
1063				if when <= &block_number {
1064					record.paid = record.paid.checked_add(amount).ok_or(Overflow)?;
1065					T::Currency::transfer(&Self::payouts(), &who, *amount, AllowDeath)?;
1066					record.payouts.remove(0);
1067					Payouts::<T, I>::insert(&who, record);
1068					return Ok(());
1069				}
1070			}
1071			Err(Error::<T, I>::NoPayout)?
1072		}
1073
1074		/// Repay the payment previously given to the member with the signed origin, remove any
1075		/// pending payments, and elevate them from rank 0 to rank 1.
1076		///
1077		/// The funds reserved for the forfeited pending payments are returned to the society pot.
1078		#[pallet::call_index(7)]
1079		#[pallet::weight(T::WeightInfo::waive_repay())]
1080		pub fn waive_repay(origin: OriginFor<T>, amount: BalanceOf<T, I>) -> DispatchResult {
1081			let who = ensure_signed(origin)?;
1082			let mut record = Members::<T, I>::get(&who).ok_or(Error::<T, I>::NotMember)?;
1083			let mut payout_record = Payouts::<T, I>::get(&who);
1084			ensure!(record.rank == 0, Error::<T, I>::AlreadyElevated);
1085			ensure!(amount >= payout_record.paid, Error::<T, I>::InsufficientFunds);
1086
1087			T::Currency::transfer(&who, &Self::account_id(), payout_record.paid, AllowDeath)?;
1088			let total = payout_record
1089				.payouts
1090				.drain(..)
1091				.fold(Zero::zero(), |acc: BalanceOf<T, I>, x| acc.saturating_add(x.1));
1092			Self::unreserve_payout(total);
1093			payout_record.paid = Zero::zero();
1094			record.rank = 1;
1095			Members::<T, I>::insert(&who, record);
1096			Payouts::<T, I>::insert(&who, payout_record);
1097			Self::deposit_event(Event::<T, I>::Elevated { member: who, rank: 1 });
1098
1099			Ok(())
1100		}
1101
1102		/// Found the society.
1103		///
1104		/// This is done as a discrete action in order to allow for the
1105		/// pallet to be included into a running chain and can only be done once.
1106		///
1107		/// The dispatch origin for this call must be from the _FounderSetOrigin_.
1108		///
1109		/// Parameters:
1110		/// - `founder` - The first member and head of the newly founded society.
1111		/// - `max_members` - The initial max number of members for the society.
1112		/// - `max_intake` - The maximum number of candidates per intake period.
1113		/// - `max_strikes`: The maximum number of strikes a member may get before they become
1114		///   suspended and may only be reinstated by the founder.
1115		/// - `candidate_deposit`: The deposit required to make a bid for membership of the group.
1116		/// - `rules` - The rules of this society concerning membership.
1117		///
1118		/// Complexity: O(1)
1119		#[pallet::call_index(8)]
1120		#[pallet::weight(T::WeightInfo::found_society())]
1121		pub fn found_society(
1122			origin: OriginFor<T>,
1123			founder: AccountIdLookupOf<T>,
1124			max_members: u32,
1125			max_intake: u32,
1126			max_strikes: u32,
1127			candidate_deposit: BalanceOf<T, I>,
1128			rules: Vec<u8>,
1129		) -> DispatchResult {
1130			T::FounderSetOrigin::ensure_origin(origin)?;
1131			let founder = T::Lookup::lookup(founder)?;
1132			ensure!(!Head::<T, I>::exists(), Error::<T, I>::AlreadyFounded);
1133			ensure!(max_members > 1, Error::<T, I>::MaxMembers);
1134			// This should never fail in the context of this function...
1135			let params = GroupParams { max_members, max_intake, max_strikes, candidate_deposit };
1136			Parameters::<T, I>::put(params);
1137			Self::insert_member(&founder, 1)?;
1138			Head::<T, I>::put(&founder);
1139			Founder::<T, I>::put(&founder);
1140			Rules::<T, I>::put(T::Hashing::hash(&rules));
1141			Self::deposit_event(Event::<T, I>::Founded { founder });
1142			Ok(())
1143		}
1144
1145		/// Dissolve the society and remove all members.
1146		///
1147		/// The dispatch origin for this call must be Signed, and the signing account must be both
1148		/// the `Founder` and the `Head`. This implies that it may only be done when there is one
1149		/// member.
1150		#[pallet::call_index(9)]
1151		#[pallet::weight(T::WeightInfo::dissolve())]
1152		pub fn dissolve(origin: OriginFor<T>) -> DispatchResult {
1153			let founder = ensure_signed(origin)?;
1154			ensure!(Founder::<T, I>::get().as_ref() == Some(&founder), Error::<T, I>::NotFounder);
1155			ensure!(MemberCount::<T, I>::get() == 1, Error::<T, I>::NotHead);
1156
1157			let _ = Members::<T, I>::clear(u32::MAX, None);
1158			MemberCount::<T, I>::kill();
1159			let _ = MemberByIndex::<T, I>::clear(u32::MAX, None);
1160			let _ = SuspendedMembers::<T, I>::clear(u32::MAX, None);
1161			// Return the funds backing the discarded pending payouts to the society account. On
1162			// failure, abort the dissolution rather than stranding the funds in the payouts
1163			// account with no records left to claim them.
1164			let payouts_account = Self::payouts();
1165			T::Currency::transfer(
1166				&payouts_account,
1167				&Self::account_id(),
1168				T::Currency::free_balance(&payouts_account),
1169				AllowDeath,
1170			)?;
1171			let _ = Payouts::<T, I>::clear(u32::MAX, None);
1172			let _ = Votes::<T, I>::clear(u32::MAX, None);
1173			let _ = VoteClearCursor::<T, I>::clear(u32::MAX, None);
1174			Head::<T, I>::kill();
1175			NextHead::<T, I>::kill();
1176			Founder::<T, I>::kill();
1177			Rules::<T, I>::kill();
1178			Parameters::<T, I>::kill();
1179			Pot::<T, I>::kill();
1180			RoundCount::<T, I>::kill();
1181			Bids::<T, I>::kill();
1182			Skeptic::<T, I>::kill();
1183			ChallengeRoundCount::<T, I>::kill();
1184			Defending::<T, I>::kill();
1185			let _ = DefenderVotes::<T, I>::clear(u32::MAX, None);
1186			let _ = Candidates::<T, I>::clear(u32::MAX, None);
1187			Self::deposit_event(Event::<T, I>::Unfounded { founder });
1188			Ok(())
1189		}
1190
1191		/// Allow suspension judgement origin to make judgement on a suspended member.
1192		///
1193		/// If a suspended member is forgiven, we simply add them back as a member, not affecting
1194		/// any of the existing storage items for that member.
1195		///
1196		/// If a suspended member is rejected, remove all associated storage items, including
1197		/// their payouts, and remove any vouched bids they currently have.
1198		///
1199		/// The dispatch origin for this call must be Signed from the Founder.
1200		///
1201		/// Parameters:
1202		/// - `who` - The suspended member to be judged.
1203		/// - `forgive` - A boolean representing whether the suspension judgement origin forgives
1204		///   (`true`) or rejects (`false`) a suspended member.
1205		#[pallet::call_index(10)]
1206		#[pallet::weight(T::WeightInfo::judge_suspended_member())]
1207		pub fn judge_suspended_member(
1208			origin: OriginFor<T>,
1209			who: AccountIdLookupOf<T>,
1210			forgive: bool,
1211		) -> DispatchResultWithPostInfo {
1212			ensure!(
1213				Some(ensure_signed(origin)?) == Founder::<T, I>::get(),
1214				Error::<T, I>::NotFounder
1215			);
1216			let who = T::Lookup::lookup(who)?;
1217			let record = SuspendedMembers::<T, I>::get(&who).ok_or(Error::<T, I>::NotSuspended)?;
1218			if forgive {
1219				// Try to add member back to society. Can fail with `MaxMembers` limit.
1220				Self::reinstate_member(&who, record.rank)?;
1221			} else {
1222				let payout_record = Payouts::<T, I>::take(&who);
1223				let total = payout_record
1224					.payouts
1225					.into_iter()
1226					.map(|x| x.1)
1227					.fold(Zero::zero(), |acc: BalanceOf<T, I>, x| acc.saturating_add(x));
1228				Self::unreserve_payout(total);
1229			}
1230			SuspendedMembers::<T, I>::remove(&who);
1231			Self::deposit_event(Event::<T, I>::SuspendedMemberJudgement { who, judged: forgive });
1232			Ok(Pays::No.into())
1233		}
1234
1235		/// Change the maximum number of members in society and the maximum number of new candidates
1236		/// in a single intake period.
1237		///
1238		/// The dispatch origin for this call must be Signed by the Founder.
1239		///
1240		/// Parameters:
1241		/// - `max_members` - The maximum number of members for the society. This must be no less
1242		///   than the current number of members.
1243		/// - `max_intake` - The maximum number of candidates per intake period.
1244		/// - `max_strikes`: The maximum number of strikes a member may get before they become
1245		///   suspended and may only be reinstated by the founder.
1246		/// - `candidate_deposit`: The deposit required to make a bid for membership of the group.
1247		#[pallet::call_index(11)]
1248		#[pallet::weight(T::WeightInfo::set_parameters())]
1249		pub fn set_parameters(
1250			origin: OriginFor<T>,
1251			max_members: u32,
1252			max_intake: u32,
1253			max_strikes: u32,
1254			candidate_deposit: BalanceOf<T, I>,
1255		) -> DispatchResult {
1256			ensure!(
1257				Some(ensure_signed(origin)?) == Founder::<T, I>::get(),
1258				Error::<T, I>::NotFounder
1259			);
1260			ensure!(max_members >= MemberCount::<T, I>::get(), Error::<T, I>::MaxMembers);
1261			let params = GroupParams { max_members, max_intake, max_strikes, candidate_deposit };
1262			Parameters::<T, I>::put(&params);
1263			Self::deposit_event(Event::<T, I>::NewParams { params });
1264			Ok(())
1265		}
1266
1267		/// Punish the skeptic with a strike if they did not vote on a candidate. Callable by the
1268		/// candidate.
1269		#[pallet::call_index(12)]
1270		#[pallet::weight(T::WeightInfo::punish_skeptic())]
1271		pub fn punish_skeptic(origin: OriginFor<T>) -> DispatchResultWithPostInfo {
1272			let candidate = ensure_signed(origin)?;
1273			let mut candidacy =
1274				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1275			ensure!(!candidacy.skeptic_struck, Error::<T, I>::AlreadyPunished);
1276			ensure!(!Self::in_progress(candidacy.round), Error::<T, I>::InProgress);
1277			let punished = Self::check_skeptic(&candidate, &mut candidacy);
1278			Candidates::<T, I>::insert(&candidate, candidacy);
1279			Ok(if punished { Pays::No } else { Pays::Yes }.into())
1280		}
1281
1282		/// Transform an approved candidate into a member. Callable only by the
1283		/// the candidate, and only after the period for voting has ended.
1284		#[pallet::call_index(13)]
1285		#[pallet::weight(T::WeightInfo::claim_membership())]
1286		pub fn claim_membership(origin: OriginFor<T>) -> DispatchResultWithPostInfo {
1287			let candidate = ensure_signed(origin)?;
1288			let candidacy =
1289				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1290			ensure!(candidacy.tally.clear_approval(), Error::<T, I>::NotApproved);
1291			ensure!(!Self::in_progress(candidacy.round), Error::<T, I>::InProgress);
1292			Self::induct_member(candidate, candidacy, 0)?;
1293			Ok(Pays::No.into())
1294		}
1295
1296		/// Transform an approved candidate into a member. Callable only by the Signed origin of the
1297		/// Founder, only after the period for voting has ended and only when the candidate is not
1298		/// clearly rejected.
1299		#[pallet::call_index(14)]
1300		#[pallet::weight(T::WeightInfo::bestow_membership())]
1301		pub fn bestow_membership(
1302			origin: OriginFor<T>,
1303			candidate: T::AccountId,
1304		) -> DispatchResultWithPostInfo {
1305			ensure!(
1306				Some(ensure_signed(origin)?) == Founder::<T, I>::get(),
1307				Error::<T, I>::NotFounder
1308			);
1309			let candidacy =
1310				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1311			ensure!(!candidacy.tally.clear_rejection(), Error::<T, I>::Rejected);
1312			ensure!(!Self::in_progress(candidacy.round), Error::<T, I>::InProgress);
1313			Self::induct_member(candidate, candidacy, 0)?;
1314			Ok(Pays::No.into())
1315		}
1316
1317		/// Remove the candidate's application from the society. Callable only by the Signed origin
1318		/// of the Founder, only after the period for voting has ended, and only when they do not
1319		/// have a clear approval.
1320		///
1321		/// Any bid deposit is lost and voucher is banned.
1322		#[pallet::call_index(15)]
1323		#[pallet::weight(T::WeightInfo::kick_candidate())]
1324		pub fn kick_candidate(
1325			origin: OriginFor<T>,
1326			candidate: T::AccountId,
1327		) -> DispatchResultWithPostInfo {
1328			ensure!(
1329				Some(ensure_signed(origin)?) == Founder::<T, I>::get(),
1330				Error::<T, I>::NotFounder
1331			);
1332			let mut candidacy =
1333				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1334			ensure!(!Self::in_progress(candidacy.round), Error::<T, I>::InProgress);
1335			ensure!(!candidacy.tally.clear_approval(), Error::<T, I>::Approved);
1336			Self::check_skeptic(&candidate, &mut candidacy);
1337			Self::reject_candidate(&candidate, &candidacy.kind);
1338			Candidates::<T, I>::remove(&candidate);
1339			Ok(Pays::No.into())
1340		}
1341
1342		/// Remove the candidate's application from the society. Callable only by the candidate.
1343		///
1344		/// Any bid deposit is lost and voucher is banned.
1345		#[pallet::call_index(16)]
1346		#[pallet::weight(T::WeightInfo::resign_candidacy())]
1347		pub fn resign_candidacy(origin: OriginFor<T>) -> DispatchResultWithPostInfo {
1348			let candidate = ensure_signed(origin)?;
1349			let mut candidacy =
1350				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1351			if !Self::in_progress(candidacy.round) {
1352				Self::check_skeptic(&candidate, &mut candidacy);
1353			}
1354			Self::reject_candidate(&candidate, &candidacy.kind);
1355			Candidates::<T, I>::remove(&candidate);
1356			Ok(Pays::No.into())
1357		}
1358
1359		/// Remove a `candidate`'s failed application from the society. Callable by any
1360		/// signed origin but only at the end of the subsequent round and only for
1361		/// a candidate with more rejections than approvals.
1362		///
1363		/// The bid deposit is lost and the voucher is banned.
1364		#[pallet::call_index(17)]
1365		#[pallet::weight(T::WeightInfo::drop_candidate())]
1366		pub fn drop_candidate(
1367			origin: OriginFor<T>,
1368			candidate: T::AccountId,
1369		) -> DispatchResultWithPostInfo {
1370			ensure_signed(origin)?;
1371			let candidacy =
1372				Candidates::<T, I>::get(&candidate).ok_or(Error::<T, I>::NotCandidate)?;
1373			ensure!(candidacy.tally.clear_rejection(), Error::<T, I>::NotRejected);
1374			ensure!(RoundCount::<T, I>::get() > candidacy.round + 1, Error::<T, I>::TooEarly);
1375			Self::reject_candidate(&candidate, &candidacy.kind);
1376			Candidates::<T, I>::remove(&candidate);
1377			Ok(Pays::No.into())
1378		}
1379
1380		/// Remove up to `max` stale votes for the given `candidate`.
1381		///
1382		/// May be called by any Signed origin, but only after the candidate's candidacy is ended.
1383		#[pallet::call_index(18)]
1384		#[pallet::weight(T::WeightInfo::cleanup_candidacy())]
1385		pub fn cleanup_candidacy(
1386			origin: OriginFor<T>,
1387			candidate: T::AccountId,
1388			max: u32,
1389		) -> DispatchResultWithPostInfo {
1390			ensure_signed(origin)?;
1391			ensure!(!Candidates::<T, I>::contains_key(&candidate), Error::<T, I>::InProgress);
1392			let maybe_cursor = VoteClearCursor::<T, I>::get(&candidate);
1393			let r =
1394				Votes::<T, I>::clear_prefix(&candidate, max, maybe_cursor.as_ref().map(|x| &x[..]));
1395			if let Some(cursor) = r.maybe_cursor {
1396				VoteClearCursor::<T, I>::insert(&candidate, BoundedVec::truncate_from(cursor));
1397			}
1398			Ok(if r.loops == 0 { Pays::Yes } else { Pays::No }.into())
1399		}
1400
1401		/// Remove up to `max` stale votes for the defender in the given `challenge_round`.
1402		///
1403		/// May be called by any Signed origin, but only after the challenge round is ended.
1404		#[pallet::call_index(19)]
1405		#[pallet::weight(T::WeightInfo::cleanup_challenge())]
1406		pub fn cleanup_challenge(
1407			origin: OriginFor<T>,
1408			challenge_round: RoundIndex,
1409			max: u32,
1410		) -> DispatchResultWithPostInfo {
1411			ensure_signed(origin)?;
1412			ensure!(
1413				challenge_round < ChallengeRoundCount::<T, I>::get(),
1414				Error::<T, I>::InProgress
1415			);
1416			let _ = DefenderVotes::<T, I>::clear_prefix(challenge_round, max, None);
1417			// clear_prefix() v2 is always returning backend = 0, ignoring it till v3.
1418			// let (_, backend, _, _) = r.deconstruct();
1419			// if backend == 0 { return Err(Error::<T, I>::NoVotes.into()); };
1420			Ok(Pays::No.into())
1421		}
1422
1423		/// Poke the deposit reserved when bidding.
1424		///
1425		/// The dispatch origin for this call must be _Signed_ and must be the bidder.
1426		///
1427		/// The transaction fee is waived if the deposit is changed after poking/reconsideration.
1428		///
1429		/// Emits `DepositPoked` if successful.
1430		#[pallet::call_index(20)]
1431		#[pallet::weight(T::WeightInfo::poke_deposit())]
1432		pub fn poke_deposit(origin: OriginFor<T>) -> DispatchResultWithPostInfo {
1433			let who = ensure_signed(origin)?;
1434
1435			// Get current bids and find the bidder's bid
1436			let mut bids = Bids::<T, I>::get();
1437			let bid = bids.iter_mut().find(|bid| bid.who == who).ok_or(Error::<T, I>::NotBidder)?;
1438
1439			// Only handle deposit bids
1440			let old_deposit = match &bid.kind {
1441				BidKind::Deposit(amount) => *amount,
1442				_ => return Err(Error::<T, I>::NoDeposit.into()),
1443			};
1444
1445			let params = Parameters::<T, I>::get().ok_or(Error::<T, I>::NotGroup)?;
1446			let new_deposit = params.candidate_deposit;
1447
1448			if old_deposit == new_deposit {
1449				return Ok(Pays::Yes.into());
1450			}
1451
1452			if new_deposit > old_deposit {
1453				// Need to reserve more
1454				let extra = new_deposit.saturating_sub(old_deposit);
1455				T::Currency::reserve(&who, extra)?;
1456			} else {
1457				// Need to unreserve some
1458				let excess = old_deposit.saturating_sub(new_deposit);
1459				let remaining_unreserved = T::Currency::unreserve(&who, excess);
1460				if !remaining_unreserved.is_zero() {
1461					defensive!(
1462						"Failed to unreserve for full amount for bid (Requested, Actual)",
1463						(excess, excess.saturating_sub(remaining_unreserved))
1464					);
1465				}
1466			}
1467
1468			bid.kind = BidKind::Deposit(new_deposit);
1469			Bids::<T, I>::put(bids);
1470
1471			Self::deposit_event(Event::<T, I>::DepositPoked {
1472				who: who.clone(),
1473				old_deposit,
1474				new_deposit,
1475			});
1476
1477			Ok(Pays::No.into())
1478		}
1479
1480		/// Kick a member from the society. Callable only by the Signed origin of the Founder.
1481		///
1482		/// The member is fully removed (not suspended). All unclaimed payouts are slashed and
1483		/// returned to the society pot.
1484		///
1485		/// Parameters:
1486		/// - `who`: The member to be removed.
1487		#[pallet::call_index(21)]
1488		#[pallet::weight(T::WeightInfo::kick_member())]
1489		pub fn kick_member(origin: OriginFor<T>, who: AccountIdLookupOf<T>) -> DispatchResult {
1490			ensure!(
1491				Some(ensure_signed(origin)?) == Founder::<T, I>::get(),
1492				Error::<T, I>::NotFounder
1493			);
1494			let who = T::Lookup::lookup(who)?;
1495
1496			let _ = Self::remove_member(&who)?;
1497
1498			let payout_record = Payouts::<T, I>::take(&who);
1499			let total = payout_record
1500				.payouts
1501				.into_iter()
1502				.fold(Zero::zero(), |acc: BalanceOf<T, I>, x| acc.saturating_add(x.1));
1503			Self::unreserve_payout(total);
1504
1505			Self::deposit_event(Event::<T, I>::MemberKicked { member: who });
1506			Ok(())
1507		}
1508	}
1509}
1510
1511/// Simple ensure origin struct to filter for the founder account.
1512pub struct EnsureFounder<T>(core::marker::PhantomData<T>);
1513impl<T: Config> EnsureOrigin<<T as frame_system::Config>::RuntimeOrigin> for EnsureFounder<T> {
1514	type Success = T::AccountId;
1515	fn try_origin(o: T::RuntimeOrigin) -> Result<Self::Success, T::RuntimeOrigin> {
1516		match (o.as_signer(), Founder::<T>::get()) {
1517			(Some(who), Some(f)) if *who == f => Ok(f),
1518			_ => Err(o),
1519		}
1520	}
1521
1522	#[cfg(feature = "runtime-benchmarks")]
1523	fn try_successful_origin() -> Result<T::RuntimeOrigin, ()> {
1524		let founder = Founder::<T>::get().ok_or(())?;
1525		Ok(T::RuntimeOrigin::from(frame_system::RawOrigin::Signed(founder)))
1526	}
1527}
1528
1529impl_ensure_origin_with_arg_ignoring_arg! {
1530	impl<{ T: Config, A }>
1531		EnsureOriginWithArg<T::RuntimeOrigin, A> for EnsureFounder<T>
1532	{}
1533}
1534
1535#[derive(Debug, PartialEq, Eq)]
1536pub enum Period<BlockNumber> {
1537	Voting { elapsed: BlockNumber, more: BlockNumber },
1538	Claim { elapsed: BlockNumber, more: BlockNumber },
1539	Intake { elapsed: BlockNumber },
1540}
1541
1542impl<T: Config<I>, I: 'static> Pallet<T, I> {
1543	/// Get the period we are currently in.
1544	fn period() -> Period<BlockNumberFor<T, I>> {
1545		let claim_period = T::ClaimPeriod::get();
1546		let voting_period = T::VotingPeriod::get();
1547		let rotation_period = voting_period + claim_period;
1548		let now = T::BlockNumberProvider::current_block_number();
1549		let phase = now % rotation_period;
1550		if now >= Self::next_intake_at() {
1551			Period::Intake { elapsed: now - Self::next_intake_at() }
1552		} else if phase < voting_period {
1553			Period::Voting { elapsed: phase, more: voting_period - phase }
1554		} else {
1555			Period::Claim { elapsed: phase - voting_period, more: rotation_period - phase }
1556		}
1557	}
1558
1559	/// Next intake (candidate/membership) rotation scheduled with [Config::BlockNumberProvider].
1560	///
1561	/// Rounds the previous block number up to the next rotation period (voting + claim periods).
1562	pub fn next_intake_at() -> BlockNumberFor<T, I> {
1563		match NextIntakeAt::<T, I>::get() {
1564			Some(next) => next,
1565			None => {
1566				// executed once.
1567				let now = T::BlockNumberProvider::current_block_number();
1568				let prev_block = now.saturating_sub(BlockNumberFor::<T, I>::one());
1569				let rotation_period = T::VotingPeriod::get().saturating_add(T::ClaimPeriod::get());
1570				let elapsed = prev_block % rotation_period;
1571				let next_intake_at = prev_block + (rotation_period - elapsed);
1572				NextIntakeAt::<T, I>::put(next_intake_at);
1573				next_intake_at
1574			},
1575		}
1576	}
1577
1578	/// Set the next intake (candidate/membership) rotation.
1579	///
1580	/// This supposed to be called once the current intake is executed.
1581	fn set_next_intake_at() {
1582		let prev_next_intake_at = Self::next_intake_at();
1583		let next_intake_at = prev_next_intake_at
1584			.saturating_add(T::VotingPeriod::get().saturating_add(T::ClaimPeriod::get()));
1585		NextIntakeAt::<T, I>::put(next_intake_at);
1586	}
1587
1588	/// Returns the next challenge rotation scheduled with [Config::BlockNumberProvider].
1589	///
1590	/// Rounds the previous block number up to the next multiple of the challenge duration.
1591	pub fn next_challenge_at() -> BlockNumberFor<T, I> {
1592		match NextChallengeAt::<T, I>::get() {
1593			Some(next) => next,
1594			None => {
1595				// executed once.
1596				let now = T::BlockNumberProvider::current_block_number();
1597				let prev_block = now.saturating_sub(BlockNumberFor::<T, I>::one());
1598				let challenge_period = T::ChallengePeriod::get();
1599				let elapsed = prev_block % challenge_period;
1600				let next_challenge_at = prev_block + (challenge_period - elapsed);
1601				NextChallengeAt::<T, I>::put(next_challenge_at);
1602				next_challenge_at
1603			},
1604		}
1605	}
1606
1607	/// Set the next challenge rotation.
1608	///
1609	/// This supposed to be called once the current challenge is executed.
1610	fn set_next_challenge_at() {
1611		let prev_next_challenge_at = Self::next_challenge_at();
1612		let next_challenge_at = prev_next_challenge_at.saturating_add(T::ChallengePeriod::get());
1613		NextChallengeAt::<T, I>::put(next_challenge_at);
1614	}
1615
1616	/// Returns true if the given `target_round` is still in its initial voting phase.
1617	fn in_progress(target_round: RoundIndex) -> bool {
1618		let round = RoundCount::<T, I>::get();
1619		target_round == round && matches!(Self::period(), Period::Voting { .. })
1620	}
1621
1622	/// Returns the new vote.
1623	fn do_vote(maybe_old: Option<Vote>, approve: bool, rank: Rank, tally: &mut Tally) -> Vote {
1624		match maybe_old {
1625			Some(Vote { approve: true, weight }) => tally.approvals.saturating_reduce(weight),
1626			Some(Vote { approve: false, weight }) => tally.rejections.saturating_reduce(weight),
1627			_ => {},
1628		}
1629		let weight_root = rank + 1;
1630		let weight = weight_root * weight_root;
1631		match approve {
1632			true => tally.approvals.saturating_accrue(weight),
1633			false => tally.rejections.saturating_accrue(weight),
1634		}
1635		Vote { approve, weight }
1636	}
1637
1638	/// Returns `true` if a punishment was given.
1639	fn check_skeptic(
1640		candidate: &T::AccountId,
1641		candidacy: &mut Candidacy<T::AccountId, BalanceOf<T, I>>,
1642	) -> bool {
1643		if RoundCount::<T, I>::get() != candidacy.round || candidacy.skeptic_struck {
1644			return false;
1645		}
1646		// We expect the skeptic to have voted.
1647		let skeptic = match Skeptic::<T, I>::get() {
1648			Some(s) => s,
1649			None => return false,
1650		};
1651		let maybe_vote = Votes::<T, I>::get(&candidate, &skeptic);
1652		let approved = candidacy.tally.clear_approval();
1653		let rejected = candidacy.tally.clear_rejection();
1654		match (maybe_vote, approved, rejected) {
1655			(None, _, _) |
1656			(Some(Vote { approve: true, .. }), false, true) |
1657			(Some(Vote { approve: false, .. }), true, false) => {
1658				// Can't do much if the punishment doesn't work out.
1659				if Self::strike_member(&skeptic).is_ok() {
1660					candidacy.skeptic_struck = true;
1661					true
1662				} else {
1663					false
1664				}
1665			},
1666			_ => false,
1667		}
1668	}
1669
1670	/// End the current challenge period and start a new one.
1671	fn rotate_challenge(rng: &mut impl RngCore) {
1672		let mut next_defender = None;
1673		let mut round = ChallengeRoundCount::<T, I>::get();
1674
1675		// End current defender rotation
1676		if let Some((defender, skeptic, tally)) = Defending::<T, I>::get() {
1677			// We require strictly more approvals, since the member should be voting for themselves.
1678			if !tally.more_approvals() {
1679				// Member has failed the challenge: Suspend them. This will fail if they are Head
1680				// or Founder, in which case we ignore.
1681				let _ = Self::suspend_member(&defender);
1682			}
1683
1684			// Check defender skeptic voted and that their vote was with the majority.
1685			let skeptic_vote = DefenderVotes::<T, I>::get(round, &skeptic);
1686			match (skeptic_vote, tally.more_approvals(), tally.more_rejections()) {
1687				(None, _, _) |
1688				(Some(Vote { approve: true, .. }), false, true) |
1689				(Some(Vote { approve: false, .. }), true, false) => {
1690					// Punish skeptic and challenge them next.
1691					let _ = Self::strike_member(&skeptic);
1692					let founder = Founder::<T, I>::get();
1693					let head = Head::<T, I>::get();
1694					if Some(&skeptic) != founder.as_ref() && Some(&skeptic) != head.as_ref() {
1695						next_defender = Some(skeptic);
1696					}
1697				},
1698				_ => {},
1699			}
1700			round.saturating_inc();
1701			ChallengeRoundCount::<T, I>::put(round);
1702		}
1703
1704		// Avoid challenging if there's only two members since we never challenge the Head or
1705		// the Founder.
1706		if MemberCount::<T, I>::get() > 2 {
1707			let defender = next_defender
1708				.or_else(|| Self::pick_defendant(rng))
1709				.expect("exited if members empty; qed");
1710			let skeptic =
1711				Self::pick_member_except(rng, &defender).expect("exited if members empty; qed");
1712			Self::deposit_event(Event::<T, I>::Challenged { member: defender.clone() });
1713			Defending::<T, I>::put((defender, skeptic, Tally::default()));
1714		} else {
1715			Defending::<T, I>::kill();
1716		}
1717	}
1718
1719	/// End the current intake period and begin a new one.
1720	///
1721	/// ---------------------------------------------
1722	///  #10  || #11           _              || #12
1723	///       || Voting        | Claiming     ||
1724	/// ---------------------------------------------
1725	fn rotate_intake(rng: &mut impl RngCore) {
1726		// We assume there's at least one member or this logic won't work.
1727		let member_count = MemberCount::<T, I>::get();
1728		if member_count < 1 {
1729			return;
1730		}
1731		let maybe_head = NextHead::<T, I>::take();
1732		if let Some(head) = maybe_head {
1733			Head::<T, I>::put(&head.who);
1734		}
1735
1736		// Bump the pot by at most `PeriodSpend`, but less if there's not very much left in our
1737		// account.
1738		let mut pot = Pot::<T, I>::get();
1739		let unaccounted = T::Currency::free_balance(&Self::account_id()).saturating_sub(pot);
1740		pot.saturating_accrue(T::PeriodSpend::get().min(unaccounted / 2u8.into()));
1741		Pot::<T, I>::put(&pot);
1742
1743		// Bump round and create the new intake.
1744		let mut round_count = RoundCount::<T, I>::get();
1745		round_count.saturating_inc();
1746		let candidate_count = Self::select_new_candidates(round_count, member_count, pot);
1747		if candidate_count > 0 {
1748			// Select a member at random and make them the skeptic for this round.
1749			let skeptic = Self::pick_member(rng).expect("exited if members empty; qed");
1750			Skeptic::<T, I>::put(skeptic);
1751		}
1752		RoundCount::<T, I>::put(round_count);
1753	}
1754
1755	/// Remove a selection of bidding accounts such that the total bids is no greater than `Pot` and
1756	/// the number of bids would not surpass `MaxMembers` if all were accepted. At most one bid may
1757	/// be zero.
1758	///
1759	/// Candidates are inserted from each bidder.
1760	///
1761	/// The number of candidates inserted are returned.
1762	pub fn select_new_candidates(
1763		round: RoundIndex,
1764		member_count: u32,
1765		pot: BalanceOf<T, I>,
1766	) -> u32 {
1767		// Get the number of left-most bidders whose bids add up to less than `pot`.
1768		let mut bids = Bids::<T, I>::get();
1769		let params = match Parameters::<T, I>::get() {
1770			Some(params) => params,
1771			None => return 0,
1772		};
1773		let max_selections: u32 = params
1774			.max_intake
1775			.min(params.max_members.saturating_sub(member_count))
1776			.min(bids.len() as u32);
1777
1778		let mut selections = 0;
1779		// A running total of the cost to onboard these bids
1780		let mut total_cost: BalanceOf<T, I> = Zero::zero();
1781
1782		bids.retain(|bid| {
1783			// We only accept a zero bid as the first selection.
1784			total_cost.saturating_accrue(bid.value);
1785			let accept = selections < max_selections &&
1786				(!bid.value.is_zero() || selections == 0) &&
1787				total_cost <= pot;
1788			if accept {
1789				let candidacy = Candidacy {
1790					round,
1791					kind: bid.kind.clone(),
1792					bid: bid.value,
1793					tally: Default::default(),
1794					skeptic_struck: false,
1795				};
1796				Candidates::<T, I>::insert(&bid.who, candidacy);
1797				selections.saturating_inc();
1798			}
1799			!accept
1800		});
1801
1802		// No need to reset Bids if we're not taking anything.
1803		Bids::<T, I>::put(&bids);
1804		selections
1805	}
1806
1807	/// Puts a bid into storage ordered by smallest to largest value.
1808	/// Allows a maximum of 1000 bids in queue, removing largest value people first.
1809	fn insert_bid(
1810		bids: &mut BoundedVec<Bid<T::AccountId, BalanceOf<T, I>>, T::MaxBids>,
1811		who: &T::AccountId,
1812		value: BalanceOf<T, I>,
1813		bid_kind: BidKind<T::AccountId, BalanceOf<T, I>>,
1814	) {
1815		let pos = bids.iter().position(|bid| bid.value > value).unwrap_or(bids.len());
1816		let r = bids.force_insert_keep_left(pos, Bid { value, who: who.clone(), kind: bid_kind });
1817		let maybe_discarded = match r {
1818			Ok(x) => x,
1819			Err(x) => Some(x),
1820		};
1821		if let Some(discarded) = maybe_discarded {
1822			Self::clean_bid(&discarded);
1823			Self::deposit_event(Event::<T, I>::AutoUnbid { candidate: discarded.who });
1824		}
1825	}
1826
1827	/// Either unreserve the deposit or free up the vouching member.
1828	///
1829	/// In neither case can we do much if the action isn't completable, but there's
1830	/// no reason that either should fail.
1831	///
1832	/// WARNING: This alters the voucher item of `Members`. You must ensure that you do not
1833	/// accidentally overwrite it with an older value after calling this.
1834	fn clean_bid(bid: &Bid<T::AccountId, BalanceOf<T, I>>) {
1835		match &bid.kind {
1836			BidKind::Deposit(deposit) => {
1837				let err_amount = T::Currency::unreserve(&bid.who, *deposit);
1838				debug_assert!(err_amount.is_zero());
1839			},
1840			BidKind::Vouch(voucher, _) => {
1841				Members::<T, I>::mutate_extant(voucher, |record| record.vouching = None);
1842			},
1843		}
1844	}
1845
1846	/// Either repatriate the deposit into the Society account or ban the vouching member.
1847	///
1848	/// In neither case can we do much if the action isn't completable, but there's
1849	/// no reason that either should fail.
1850	///
1851	/// WARNING: This alters the voucher item of `Members`. You must ensure that you do not
1852	/// accidentally overwrite it with an older value after calling this.
1853	fn reject_candidate(who: &T::AccountId, kind: &BidKind<T::AccountId, BalanceOf<T, I>>) {
1854		match kind {
1855			BidKind::Deposit(deposit) => {
1856				let pot = Self::account_id();
1857				let free = BalanceStatus::Free;
1858				let r = T::Currency::repatriate_reserved(&who, &pot, *deposit, free);
1859				debug_assert!(r.is_ok());
1860			},
1861			BidKind::Vouch(voucher, _) => {
1862				Members::<T, I>::mutate_extant(voucher, |record| {
1863					record.vouching = Some(VouchingStatus::Banned)
1864				});
1865			},
1866		}
1867	}
1868
1869	/// Check a user has a bid.
1870	fn has_bid(bids: &Vec<Bid<T::AccountId, BalanceOf<T, I>>>, who: &T::AccountId) -> bool {
1871		// Bids are ordered by `value`, so we cannot binary search for a user.
1872		bids.iter().any(|bid| bid.who == *who)
1873	}
1874
1875	/// Add a member to the members list. If the user is already a member, do nothing. Can fail when
1876	/// `MaxMember` limit is reached, but in that case it has no side-effects.
1877	///
1878	/// Set the `payouts` for the member. NOTE: This *WILL NOT RESERVE THE FUNDS TO MAKE THE
1879	/// PAYOUT*. Only set this to be non-empty if you already have the funds reserved in the Payouts
1880	/// account.
1881	///
1882	/// NOTE: Generally you should not use this, and instead use `add_new_member` or
1883	/// `reinstate_member`, whose names clearly match the desired intention.
1884	fn insert_member(who: &T::AccountId, rank: Rank) -> DispatchResult {
1885		let params = Parameters::<T, I>::get().ok_or(Error::<T, I>::NotGroup)?;
1886		ensure!(MemberCount::<T, I>::get() < params.max_members, Error::<T, I>::MaxMembers);
1887		let index = MemberCount::<T, I>::mutate(|i| {
1888			i.saturating_accrue(1);
1889			*i - 1
1890		});
1891		let record = MemberRecord { rank, strikes: 0, vouching: None, index };
1892		Members::<T, I>::insert(who, record);
1893		MemberByIndex::<T, I>::insert(index, who);
1894		Ok(())
1895	}
1896
1897	/// Add a member back to the members list, setting their `rank` and `payouts`.
1898	///
1899	/// Can fail when `MaxMember` limit is reached, but in that case it has no side-effects.
1900	///
1901	/// The `payouts` value must be exactly as it was prior to suspension since no further funds
1902	/// will be reserved.
1903	fn reinstate_member(who: &T::AccountId, rank: Rank) -> DispatchResult {
1904		Self::insert_member(who, rank)
1905	}
1906
1907	/// Add a member to the members list. If the user is already a member, do nothing. Can fail when
1908	/// `MaxMember` limit is reached, but in that case it has no side-effects.
1909	fn add_new_member(who: &T::AccountId, rank: Rank) -> DispatchResult {
1910		Self::insert_member(who, rank)
1911	}
1912
1913	/// Induct a new member into the set.
1914	fn induct_member(
1915		candidate: T::AccountId,
1916		mut candidacy: Candidacy<T::AccountId, BalanceOf<T, I>>,
1917		rank: Rank,
1918	) -> DispatchResult {
1919		Self::add_new_member(&candidate, rank)?;
1920		Self::check_skeptic(&candidate, &mut candidacy);
1921
1922		let next_head = NextHead::<T, I>::get()
1923			.filter(|old| {
1924				old.round > candidacy.round ||
1925					old.round == candidacy.round && old.bid < candidacy.bid
1926			})
1927			.unwrap_or_else(|| IntakeRecord {
1928				who: candidate.clone(),
1929				bid: candidacy.bid,
1930				round: candidacy.round,
1931			});
1932		NextHead::<T, I>::put(next_head);
1933
1934		let now = T::BlockNumberProvider::current_block_number();
1935		let maturity = now + Self::lock_duration(MemberCount::<T, I>::get());
1936		Self::reward_bidder(&candidate, candidacy.bid, candidacy.kind, maturity);
1937
1938		Candidates::<T, I>::remove(&candidate);
1939		Ok(())
1940	}
1941
1942	fn strike_member(who: &T::AccountId) -> DispatchResult {
1943		let mut record = Members::<T, I>::get(who).ok_or(Error::<T, I>::NotMember)?;
1944		record.strikes.saturating_inc();
1945		Members::<T, I>::insert(who, &record);
1946		// ^^^ Keep the member record mutation self-contained as we might be suspending them later
1947		// in this function.
1948
1949		if record.strikes >= T::GraceStrikes::get() {
1950			// Too many strikes: slash the payout in half.
1951			let total_payout = Payouts::<T, I>::get(who)
1952				.payouts
1953				.iter()
1954				.fold(BalanceOf::<T, I>::zero(), |acc, x| acc.saturating_add(x.1));
1955			Self::slash_payout(who, total_payout / 2u32.into());
1956		}
1957
1958		let params = Parameters::<T, I>::get().ok_or(Error::<T, I>::NotGroup)?;
1959		if record.strikes >= params.max_strikes {
1960			// Way too many strikes: suspend.
1961			let _ = Self::suspend_member(who);
1962		}
1963		Ok(())
1964	}
1965
1966	/// Remove a member from the members list and return the candidacy.
1967	///
1968	/// If the member was vouching, then this will be reset. Any bidders that the member was
1969	/// vouching for will be cancelled unless they are already selected as candidates (in which case
1970	/// they will be able to stand).
1971	///
1972	/// If the member has existing payouts, they will be retained in the resultant `MemberRecord`
1973	/// and the funds will remain reserved.
1974	///
1975	/// The Head and the Founder may never be removed.
1976	pub fn remove_member(m: &T::AccountId) -> Result<MemberRecord, DispatchError> {
1977		ensure!(Head::<T, I>::get().as_ref() != Some(m), Error::<T, I>::Head);
1978		ensure!(Founder::<T, I>::get().as_ref() != Some(m), Error::<T, I>::Founder);
1979		if let Some(mut record) = Members::<T, I>::get(m) {
1980			let index = record.index;
1981			let last_index = MemberCount::<T, I>::mutate(|i| {
1982				i.saturating_reduce(1);
1983				*i
1984			});
1985			if index != last_index {
1986				// Move the member with the last index down to the index of the member to be
1987				// removed.
1988				if let Some(other) = MemberByIndex::<T, I>::get(last_index) {
1989					MemberByIndex::<T, I>::insert(index, &other);
1990					Members::<T, I>::mutate(other, |m_r| {
1991						if let Some(r) = m_r {
1992							r.index = index
1993						}
1994					});
1995				} else {
1996					debug_assert!(false, "ERROR: No member at the last index position?");
1997				}
1998			}
1999
2000			MemberByIndex::<T, I>::remove(last_index);
2001			Members::<T, I>::remove(m);
2002			// Remove their vouching status, potentially unbanning them in the future.
2003			if record.vouching.take() == Some(VouchingStatus::Vouching) {
2004				// Try to remove their bid if they are vouching.
2005				// If their vouch is already a candidate, do nothing.
2006				Bids::<T, I>::mutate(|bids|
2007					// Try to find the matching bid
2008					if let Some(pos) = bids.iter().position(|b| b.kind.is_vouch(&m)) {
2009						// Remove the bid, and emit an event
2010						let vouched = bids.remove(pos).who;
2011						Self::deposit_event(Event::<T, I>::Unvouch { candidate: vouched });
2012					}
2013				);
2014			}
2015			Ok(record)
2016		} else {
2017			Err(Error::<T, I>::NotMember.into())
2018		}
2019	}
2020
2021	/// Remove a member from the members set and add them to the suspended members.
2022	///
2023	/// If the member was vouching, then this will be reset. Any bidders that the member was
2024	/// vouching for will be cancelled unless they are already selected as candidates (in which case
2025	/// they will be able to stand).
2026	fn suspend_member(who: &T::AccountId) -> DispatchResult {
2027		let record = Self::remove_member(&who)?;
2028		SuspendedMembers::<T, I>::insert(who, record);
2029		Self::deposit_event(Event::<T, I>::MemberSuspended { member: who.clone() });
2030		Ok(())
2031	}
2032
2033	/// Select a member at random, given the RNG `rng`.
2034	///
2035	/// If no members exist (or the state is inconsistent), then `None` may be returned.
2036	fn pick_member(rng: &mut impl RngCore) -> Option<T::AccountId> {
2037		let member_count = MemberCount::<T, I>::get();
2038		if member_count == 0 {
2039			return None;
2040		}
2041		let random_index = rng.next_u32() % member_count;
2042		MemberByIndex::<T, I>::get(random_index)
2043	}
2044
2045	/// Select a member at random except `exception`, given the RNG `rng`.
2046	///
2047	/// If `exception` is the only member (or the state is inconsistent), then `None` may be
2048	/// returned.
2049	fn pick_member_except(
2050		rng: &mut impl RngCore,
2051		exception: &T::AccountId,
2052	) -> Option<T::AccountId> {
2053		let member_count = MemberCount::<T, I>::get();
2054		if member_count <= 1 {
2055			return None;
2056		}
2057		let random_index = rng.next_u32() % (member_count - 1);
2058		let pick = MemberByIndex::<T, I>::get(random_index);
2059		if pick.as_ref() == Some(exception) {
2060			MemberByIndex::<T, I>::get(member_count - 1)
2061		} else {
2062			pick
2063		}
2064	}
2065
2066	/// Select a member who is able to defend at random, given the RNG `rng`.
2067	///
2068	/// If only the Founder and Head members exist (or the state is inconsistent), then `None`
2069	/// may be returned.
2070	fn pick_defendant(rng: &mut impl RngCore) -> Option<T::AccountId> {
2071		let member_count = MemberCount::<T, I>::get();
2072		if member_count <= 2 {
2073			return None;
2074		}
2075		// Founder is always at index 0, so we should never pick that one.
2076		// Head will typically but not always be the highest index. We assume it is for now and
2077		// fix it up later if not.
2078		let head = Head::<T, I>::get();
2079		let pickable_count = member_count - if head.is_some() { 2 } else { 1 };
2080		let random_index = rng.next_u32() % pickable_count + 1;
2081		let pick = MemberByIndex::<T, I>::get(random_index);
2082		if pick == head && head.is_some() {
2083			// Turns out that head was not the last index since we managed to pick it. Exchange our
2084			// pick for the last index.
2085			MemberByIndex::<T, I>::get(member_count - 1)
2086		} else {
2087			pick
2088		}
2089	}
2090
2091	/// Pay an accepted candidate their bid value.
2092	fn reward_bidder(
2093		candidate: &T::AccountId,
2094		value: BalanceOf<T, I>,
2095		kind: BidKind<T::AccountId, BalanceOf<T, I>>,
2096		maturity: BlockNumberFor<T, I>,
2097	) {
2098		let value = match kind {
2099			BidKind::Deposit(deposit) => {
2100				// In the case that a normal deposit bid is accepted we unreserve
2101				// the deposit.
2102				let err_amount = T::Currency::unreserve(candidate, deposit);
2103				debug_assert!(err_amount.is_zero());
2104				value
2105			},
2106			BidKind::Vouch(voucher, tip) => {
2107				// Check that the voucher is still vouching, else some other logic may have removed
2108				// their status.
2109				if let Some(mut record) = Members::<T, I>::get(&voucher) {
2110					if let Some(VouchingStatus::Vouching) = record.vouching {
2111						// In the case that a vouched-for bid is accepted we unset the
2112						// vouching status and transfer the tip over to the voucher.
2113						record.vouching = None;
2114						Self::bump_payout(&voucher, maturity, tip.min(value));
2115						Members::<T, I>::insert(&voucher, record);
2116						value.saturating_sub(tip)
2117					} else {
2118						value
2119					}
2120				} else {
2121					value
2122				}
2123			},
2124		};
2125
2126		Self::bump_payout(candidate, maturity, value);
2127	}
2128
2129	/// Bump the payout amount of `who`, to be unlocked at the given block number.
2130	///
2131	/// It is the caller's duty to ensure that `who` is already a member. This does nothing if `who`
2132	/// is not a member, if `value` is zero or if the payment cannot be recorded because the member
2133	/// already has too many pending payouts.
2134	fn bump_payout(who: &T::AccountId, when: BlockNumberFor<T, I>, value: BalanceOf<T, I>) {
2135		if value.is_zero() {
2136			return;
2137		}
2138		if let Some(MemberRecord { rank: 0, .. }) = Members::<T, I>::get(who) {
2139			let recorded = Payouts::<T, I>::mutate(who, |record| {
2140				// Members of rank 1 never get payouts.
2141				match record.payouts.binary_search_by_key(&when, |x| x.0) {
2142					Ok(index) => {
2143						record.payouts[index].1.saturating_accrue(value);
2144						true
2145					},
2146					// A member with too many pending payouts forfeits the payment.
2147					Err(index) => record.payouts.try_insert(index, (when, value)).is_ok(),
2148				}
2149			});
2150			// Only reserve funds for payments which have been recorded.
2151			if recorded {
2152				Self::reserve_payout(value);
2153			}
2154		}
2155	}
2156
2157	/// Attempt to slash the payout of some member, returning the funds reserved for the deducted
2158	/// amount to the pot. Return the total amount that was deducted.
2159	fn slash_payout(who: &T::AccountId, value: BalanceOf<T, I>) -> BalanceOf<T, I> {
2160		let mut record = Payouts::<T, I>::get(who);
2161		let mut rest = value;
2162		while !record.payouts.is_empty() {
2163			if let Some(new_rest) = rest.checked_sub(&record.payouts[0].1) {
2164				// not yet totally slashed after this one; drop it completely.
2165				rest = new_rest;
2166				record.payouts.remove(0);
2167			} else {
2168				// whole slash is accounted for.
2169				record.payouts[0].1.saturating_reduce(rest);
2170				rest = Zero::zero();
2171				break;
2172			}
2173		}
2174		Payouts::<T, I>::insert(who, record);
2175		let slashed = value - rest;
2176		Self::unreserve_payout(slashed);
2177		slashed
2178	}
2179
2180	/// Transfer some `amount` from the main account into the payouts account and reduce the Pot
2181	/// by this amount.
2182	fn reserve_payout(amount: BalanceOf<T, I>) {
2183		// Transfer payout from the Pot into the payouts account.
2184		Pot::<T, I>::mutate(|pot| pot.saturating_reduce(amount));
2185
2186		// this should never fail since we ensure we can afford the payouts in a previous
2187		// block, but there's not much we can do to recover if it fails anyway.
2188		let res = T::Currency::transfer(&Self::account_id(), &Self::payouts(), amount, AllowDeath);
2189		debug_assert!(res.is_ok());
2190	}
2191
2192	/// Transfer some `amount` from the main account into the payouts account and increase the Pot
2193	/// by this amount.
2194	fn unreserve_payout(amount: BalanceOf<T, I>) {
2195		// Transfer payout from the Pot into the payouts account.
2196		Pot::<T, I>::mutate(|pot| pot.saturating_accrue(amount));
2197
2198		// this should never fail since we ensure we can afford the payouts in a previous
2199		// block, but there's not much we can do to recover if it fails anyway.
2200		let res = T::Currency::transfer(&Self::payouts(), &Self::account_id(), amount, AllowDeath);
2201		debug_assert!(res.is_ok());
2202	}
2203
2204	/// The account ID of the treasury pot.
2205	///
2206	/// This actually does computation. If you need to keep using it, then make sure you cache the
2207	/// value and only call this once.
2208	pub fn account_id() -> T::AccountId {
2209		T::PalletId::get().into_account_truncating()
2210	}
2211
2212	/// The account ID of the payouts pot. This is where payouts are made from.
2213	///
2214	/// This actually does computation. If you need to keep using it, then make sure you cache the
2215	/// value and only call this once.
2216	pub fn payouts() -> T::AccountId {
2217		T::PalletId::get().into_sub_account_truncating(b"payouts")
2218	}
2219
2220	/// The total of all pending payouts recorded in [`Payouts`].
2221	pub(crate) fn pending_payouts_total() -> BalanceOf<T, I> {
2222		Payouts::<T, I>::iter_values()
2223			.flat_map(|record| record.payouts.into_iter())
2224			.fold(Zero::zero(), |acc: BalanceOf<T, I>, x| acc.saturating_add(x.1))
2225	}
2226
2227	/// Ensure the correctness of the state of this pallet.
2228	///
2229	/// The balance of the payouts account must equal the total of all pending payouts recorded in
2230	/// `Payouts`, as funds are moved into the account when a payout is recorded and out of it when
2231	/// a payout is claimed or discarded.
2232	#[cfg(any(feature = "try-runtime", test))]
2233	pub fn do_try_state() -> Result<(), sp_runtime::TryRuntimeError> {
2234		frame_support::ensure!(
2235			T::Currency::free_balance(&Self::payouts()) == Self::pending_payouts_total(),
2236			"payouts account balance must equal the total of pending payouts",
2237		);
2238		Ok(())
2239	}
2240
2241	/// Return the duration of the lock, in blocks, with the given number of members.
2242	///
2243	/// This is a rather opaque calculation based on the formula here:
2244	/// https://www.desmos.com/calculator/9itkal1tce
2245	fn lock_duration(x: u32) -> BlockNumberFor<T, I> {
2246		let lock_pc = 100 - 50_000 / (x + 500);
2247		Percent::from_percent(lock_pc as u8) * T::MaxLockDuration::get()
2248	}
2249}
2250
2251impl<T: Config<I>, I: 'static> OnUnbalanced<NegativeImbalanceOf<T, I>> for Pallet<T, I> {
2252	fn on_nonzero_unbalanced(amount: NegativeImbalanceOf<T, I>) {
2253		let numeric_amount = amount.peek();
2254
2255		// Must resolve into existing but better to be safe.
2256		let _ = T::Currency::resolve_creating(&Self::account_id(), amount);
2257
2258		Self::deposit_event(Event::<T, I>::Deposit { value: numeric_amount });
2259	}
2260}