Skip to content

SelectorCondition

SelectorCondition narrows a permission so it may only be used to call a specific set of functions. It holds an allow-list of function selectors and, when consulted, permits the call only if the function being invoked is on that list. It's part of the condition library.

When to use it

A single permission often gates several auth-protected functions on a contract. When a given holder should be able to reach only some of them, attach a SelectorCondition allow-listing just those selectors. "You hold this permission, but only for functions X and Y."

What it checks

Its isGranted is essentially one lookup:

solidity
return allowedSelectors[getSelector(_data)];

It inspects the selector of the call being authorized (the first 4 bytes of that call's calldata) and returns whether it's allow-listed. Two things follow:

  • It gates the direct call's own function. If you instead want to constrain the actions inside a DAO execute(), that's the sibling ExecuteSelectorCondition.
  • It ignores who is calling. The where/who/permissionId are unused; only the selector matters. So granting to ANY_ADDR with this condition means anyone may call the allow-listed functions, the gate is on what is called, not who.

The allow-list is global (a plain mapping(bytes4 => bool), no per-target dimension), so an allowed selector is allowed wherever this condition applies.

Configuration

Constructor(IDAO _dao, bytes4[] _initialSelectors) — the DAO it reads permissions from, and an initial allow-list
ManageallowSelector(bytes4) / disallowSelector(bytes4)
Managed byMANAGE_SELECTORS_PERMISSION_ID (grant it to the DAO so changes go through governance)
EventsSelectorAllowed(selector) / SelectorDisallowed(selector)

Keep in mind

  • Redundant updates revert. allowSelector on an already-allowed selector reverts AlreadyAllowed (and the mirror for disallow). This differs from ExecuteSelectorCondition, whose updates are idempotent, mind it when scripting list changes.
  • A selector is not its arguments. This allow-lists which function, not with what arguments; for argument-level rules use a bespoke condition or RuledCondition.

See also