Skip to main content

QA gate rules

Every automated rule a contract deploy must satisfy before it can be Allowed into a block. Source: protocol crate boing-qa as of 26 August 2026. List contents (hashes, patterns, terms) are governance-mutable; rule IDs and matching logic are code.

Pre-flight: QA check · Live queue: QA transparency · Design spec: QUALITY-ASSURANCE-NETWORK.md

QA gate rulesDownload PDFOpen

Loading QA gate rules

Live public testnet vs intended policy

On 26 August 2026, boing_getQaRegistry at the public testnet RPC returned empty blocklist, scam_patterns, always_review_categories, and content_blocklist, with max bytecode 32,768 bytes. The intended public-testnet policy merges 132 English terms into the content blocklist. Those terms do not reject until the live registry contains them. Always trust the RPC you submit to.

Outcomes

OutcomeRPCMeaning
Allowsubmit succeedsEligible for inclusion in a block.
Reject-32050Never enters a block. Response includes rule_id and message.
Unsure-32051Referred to the community QA pool. Not auto-included.

Evaluation order

First match wins in check_contract_deploy_full_with_metadata.

  1. METADATA_TOO_LONG — name > 256 or symbol > 32 UTF-8 bytes
  2. Empty bytecode → MALFORMED_BYTECODE
  3. Init marker 0xFD with no body → MALFORMED_BYTECODE
  4. MAX_BYTECODE_SIZE (default 32,768)
  5. INVALID_OPCODE or MALFORMED_BYTECODE on the stream after optional 0xFD
  6. BLOCKLIST_MATCH — BLAKE3 of the full payload
  7. PURPOSE_DECLARATION_INVALID — non-empty purpose not in the valid set
  8. SCAM_PATTERN_MATCH — contiguous byte sequence
  9. CONTENT_POLICY_VIOLATION — name/symbol vs content_blocklist
  10. Always-review category → Unsure
  11. other with description_hash shorter than 4 bytes → Unsure
  12. Allow

Hard rules (Reject)

Necessary for Allow, not always sufficient — Unsure can still fire after these pass.

IDrule_idRuleIf it fails
R1MALFORMED_BYTECODEBytecode must not be empty. bytecode.len() == 0 → “Bytecode must not be empty”.Reject
R2MALFORMED_BYTECODEInit-code prefix must have a body. Leading 0xFD (CONTRACT_DEPLOY_INIT_CODE_MARKER) with no following bytes is malformed. Opcode checks apply to bytes after the marker.Reject
R3MAX_BYTECODE_SIZEBytecode size cap. Full payload (including optional 0xFD) must be ≤ registry max. Default 32,768 bytes (32 KiB).Reject
R4INVALID_OPCODEOpcode whitelist. Every instruction byte must be in the Boing VM table. PUSH immediates are data, not opcodes.Reject
R5MALFORMED_BYTECODEWell-formed instruction stream. PUSH1–PUSH32 must consume exactly 1–32 following bytes; the scan must end at len. Jump-target alignment is not checked at QA time.Reject
R6BLOCKLIST_MATCHBytecode hash blocklist. BLAKE3-256 of the full payload must not match any registry.blocklist hash. Default list is empty.Reject
R7PURPOSE_DECLARATION_INVALIDPurpose category when provided. If purpose is present and non-empty, it must be a valid category (case-insensitive). Missing purpose is allowed.Reject
R8SCAM_PATTERN_MATCHScam byte patterns. Bytecode must not contain any registry.scam_patterns sequence as a contiguous window. Default list is empty.Reject
R9METADATA_TOO_LONGMetadata length. asset_name ≤ 256 UTF-8 bytes; asset_symbol ≤ 32 UTF-8 bytes (when those fields are sent).Reject
R10CONTENT_POLICY_VIOLATIONContent policy on name / symbol. asset_name or asset_symbol must not match a content_blocklist term (see matching rules). Inert when the live list is empty.Reject

Valid purpose categories

Matching is case-insensitive. Missing purpose is allowed. Meme, community, and entertainment are first-class — “no traditional utility” is not a reject.

  • dApp / dapp
  • token
  • NFT / nft
  • meme
  • community
  • entertainment
  • tooling
  • other

Allowed opcodes

Any other opcode byte is INVALID_OPCODE. PUSH immediates are not whitelist-checked.

ByteName
0x00STOP
0x01ADD
0x02SUB
0x03MUL
0x04DIV
0x06MOD
0x08ADDMOD
0x09MULMOD
0x10LT
0x11GT
0x14EQ
0x15ISZERO
0x16AND
0x17OR
0x18XOR
0x19NOT
0x1BSHL
0x1CSHR
0x1DSAR
0x30ADDRESS
0x33CALLER
0x40BLOCKHEIGHT
0x41TIMESTAMP
0x51MLOAD
0x52MSTORE
0x54SLOAD
0x55SSTORE
0x56JUMP
0x57JUMPI
0x60–0x7FPUSH1–PUSH32
0x80DUP1
0xA0–0xA4LOG0–LOG4
0xF1CALL
0xF3RETURN
0xF5CREATE2

Soft / policy rules (Unsure)

IDRuleOutcome
U1Always-review category. If the trimmed, lowercased purpose is in registry.always_review_categories, the deploy goes to the pool. Default list is empty.Unsure
U2other with almost no description. Purpose other plus description_hash shorter than 4 bytes (missing counts as 0) goes to the pool. other with ≥ 4-byte hash can Allow.Unsure

Content-policy matching

  1. Empty blocklist → skip. Names are trimmed and lowercased.
  2. Terms with spaces or punctuation: substring match (e.g. “kill yourself”).
  3. Alphanumeric terms of length ≥ 4: substring match (e.g. “shit” matches “ShitCoin”).
  4. Alphanumeric terms shorter than 4: whole-token match only (“ass” does not match “Classic”).

Content policy does not scan bytecode, purpose text, or off-chain URIs. It only sees deploy-time asset_name / asset_symbol.

Intended English content blocklist (132 terms)

a55hole, asshole, assholes, b1tch, badass, bastard, bastards, beaner, beaners, bestiality, bitch, bitches, bitchy, blowjob, bollocks, bukkake, bullshit, child porn, childporn, chink, chinks, clitoris, cocksucker, cocksuckers, cunt, cunts, dilf, dipshit, douche, douchebag, douchebags, dumbass, dyke, dykes, ejaculate, ejaculation, faggot, faggots, fagot, fck, fuck, fucked, fucker, fuckers, fuckface, fuckhead, fucking, fuckwit, fuk, fvck, gangbang, go die, gook, gooks, handjob, heil, hentai, hitler, jackass, kike, kikes, kill yourself, kys, masturbate, masturbation, mfucker, milf, motherfucker, motherfuckers, nazi, nazis, nigga, niggas, nigger, niggers, onlyfans, orgasm, paedophile, paedophilia, pedophile, pedophilia, penis, penises, phuck, porn, pornhub, porno, pornography, pussies, pussy, raghead, retard, retardation, retarded, rimjob, sandnigger, scrotum, sh1t, shit, shitbag, shitface, shithead, shits, shitshow, shitty, slut, sluts, slutty, spic, spics, swastika, testicle, testicles, towelhead, trannies, tranny, twat, twats, vagina, vaginas, vulva, wanker, wankers, wetback, wetbacks, whitepower, whore, whores, whoring, xvideos, xxx, zoophilia.

What is required for Allow

  • Every applicable hard rule R1–R10 passes.
  • Purpose is omitted, empty, or a valid category.
  • Purpose is not in the always-review set.
  • If purpose is other, description_hash is at least 4 bytes.

Not required: traditional utility, jump-target proofs, token/NFT ABI layout, off-chain websites, or vulgarity inside bytecode.

Community pool (Unsure)

Anyone with a 32-byte account may vote Allow, Reject, or Abstain (live public testnet has open voting). The deployer cannot vote on their own item. Counted votes are Allow+Reject; 2/3 of those decide after quorum. Default on the 7-day window expiry is reject. Pool voters should reject scams, phishing, rug-pulls, malware, impersonation, deceptive naming, Ponzi patterns, and spam — not memes or experimental work.

QA RPC error codes

CodeMeaning
-32050Rejected by protocol QA (rule_id + message).
-32051Unsure — referred to the governance QA pool (pending tx_hash).
-32052No pending pool item for that transaction hash.
-32053Voter ineligible (not a member, deployer conflict, or stake).
-32054QA pool disabled (no admins / zero capacity).
-32055Global pool capacity reached.
-32056Per-deployer pending cap reached.
-32057Operator RPC auth required (X-Boing-Operator).