Web3 & DApp Development Fundamentals · 강의

타임락과 실행

안전한 업그레이드

레슨 4/413개 단계

타임락과 실행은(는) CoddyKit의 무료 Web3 & DApp Development Fundamentals 강의입니다. 이것은 4개 중 4번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Web3 & DApp Development Fundamentals 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Web3 & DApp Development Fundamentals 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Why Timelocks Exist

A timelock is a mandatory delay between when a proposal passes and when it executes.

It protects users by giving them time to react to changes they disagree with — for example, withdrawing funds before a risky upgrade.

The TimelockController

OpenZeppelin's TimelockController is a contract that schedules, delays, and then executes operations.

The Governor proposes and queues actions into the timelock, which actually owns the protocol's admin rights.

contract Timelock is TimelockController {
    constructor(uint minDelay, address[] proposers, address[] executors)
        TimelockController(minDelay, proposers, executors, msg.sender) {}
}

Schedule, Wait, Execute

Operations flow through three steps:

  • schedule — queue the action with a delay
  • wait — the minDelay must elapse
  • execute — run the action after the delay
timelock.schedule(target, value, data, predecessor, salt, delay);
// ... wait minDelay ...
timelock.execute(target, value, data, predecessor, salt);

The minDelay Parameter

The minDelay sets how long every scheduled operation must wait. Common values range from 1 to 7 days.

Longer delays mean more safety but slower governance — a deliberate trade-off each DAO must tune.

Roles in the Timelock

The timelock uses access roles:

  • PROPOSER — can schedule operations (the Governor)
  • EXECUTOR — can run them after the delay
  • ADMIN — manages roles (often renounced)

Timelock Owns the Protocol

For governance to be meaningful, the timelock contract should hold the protocol's admin and ownership rights — not any individual.

This ensures every privileged change must pass through the full govern-then-delay pipeline.

protocol.transferOwnership(
    address(timelock)
);

Defense Against Malicious Proposals

If an attacker sneaks a harmful proposal through voting, the timelock delay is the last line of defense.

The community can spot the queued action and exit or coordinate a response before it executes.

Predecessor and Salt

Each scheduled operation can specify a predecessor (an operation that must run first) and a salt to make its identifier unique.

These let DAOs order dependent operations and avoid hash collisions between similar actions.

Cancelling Operations

A scheduled operation can be cancelled before execution by an address with the canceller role.

This provides an emergency brake if a queued action is found to be dangerous during the delay window.

timelock.cancel(operationId);

Upgrades Done Safely

Combining Governor + Timelock + a proxy pattern lets DAOs upgrade contracts safely: vote, queue, delay, then execute the upgrade.

Every step is transparent and reversible up until execution, balancing flexibility with security.

Putting It Together

The timelock enforces a delay between approval and execution, owns the protocol's privileges, and uses roles plus cancellation to keep upgrades safe.

It is the crucial buffer that makes on-chain governance trustworthy.

Quick Check

Test your timelock understanding.

Recap: Timelocks and Execution

You learned that:

  • A timelock delays execution after a proposal passes
  • TimelockController schedules, waits, then executes
  • minDelay tunes the safety vs speed trade-off
  • The timelock should own the protocol; roles control access
  • Operations can be cancelled during the delay

Course complete! Next course: Layer 2 and Scaling.

무료로 시작

AI 튜터와 함께 Web3 & DApp Development Fundamentals을(를) 배우세요 — 무료

브라우저에서 실제 코드를 작성하고 실행하며, 24/7 AI 튜터로부터 즉각적인 도움을 받고, 웹이나 앱에서 중단한 부분부터 계속 학습하세요.

코스
29
레슨
105

자주 묻는 질문

“타임락과 실행” 강의는 무료인가요?

네 — “타임락과 실행” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Web3 & DApp Development Fundamentals 강의 전체를 잠금 해제할 수 있습니다. Web3 & DApp Development Fundamentals 강의에는 총 4개의 강의가 포함되어 있습니다.

“타임락과 실행”에서 뭘 배우나요?

안전한 업그레이드 브라우저에서 직접 실행하는 실습 코드로 Web3 & DApp Development Fundamentals을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Web3 & DApp Development Fundamentals을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Web3 & DApp Development Fundamentals은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 4번째 강의입니다.

“타임락과 실행” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Web3 & DApp Development Fundamentals 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Web3 & DApp Development Fundamentals 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. DAO란 무엇인가
  2. 거버넌스 토큰
  3. 제안과 투표
  4. 타임락과 실행
← Web3 & DApp Development Fundamentals(으)로 돌아가기