Skip to content

fix(vault): align simulate_deduct with deduct via shared validate_deduct - #1337

Open
Manta-Byte wants to merge 1 commit into
CalloraOrg:mainfrom
Manta-Byte:feat/vault-simulate-deduct-parity
Open

Manta-Byte wants to merge 1 commit into
CalloraOrg:mainfrom
Manta-Byte:feat/vault-simulate-deduct-parity

Conversation

@Manta-Byte

Copy link
Copy Markdown
Contributor

Closes #1115

Summary

simulate_deduct claimed parity with deduct but checked different things. Both now call one shared validate_deduct, so the preflight returns the same error the live call would for caller, pause state, amount bounds and balance.

Criteria → code and tests

Criterion Code Test
Simulator and deduct share one validation function validate_deduct in lib.rs, called by deduct and by simulate_deduct in views.rs parity proptest
Below-min amounts rejected by both with BelowMinDeposit require_valid_deduct_amount inside validate_deduct explicit simulate / try_deduct BelowMinDeposit test
Parity proptest compares simulate vs try_deduct error codes over 256 cases n/a test_simulate_parity.rs: random amount, caller, paused flag and balance; ProptestConfig::with_cases(256); asserts identical error codes or both succeed
Module docs describe the actual parameter list views.rs module docs rewritten n/a

Behavior changes

  • simulate_deduct signature is now (env, caller, amount, request_id: u64). It previously took Option<Symbol> plus max_fee_bps and developer.
  • Slippage removed from the simulator. deduct never implemented it, so the simulator produced false failures. Implementing it in deduct would change on-chain behavior, so I removed it from the simulator instead. Happy to go the other way if you prefer.
  • The simulator no longer checks duplicate request ids or rate limits, since deduct doesn't either.
  • The simulator now performs the authorized-caller check it was missing.
  • docs/interfaces/vault.json updated to the new simulate_deduct signature.

Design and failure modes

  • validate_deduct is read-only: no storage writes, no events, no auth. Check order and error values for deduct are unchanged (authorized caller, pause, amount bounds, balance).
  • validate_deduct takes (env, caller, amount). request_id is not validated by deduct, so it isn't passed in. simulate_deduct keeps the parameter for interface alignment.
  • caller.require_auth() stays in deduct only, so the simulator can be called without auth and never panics on it.
  • The shared validator covers caller, pause, amount bounds and balance. Checks deduct performs around token transfer (settlement / USDC configuration), if any, are outside it.

Compatibility

simulate_deduct is a view, so there are no storage or state changes and existing deployments are unaffected. Callers of the old signature must update; I found none in this repo outside the vault crate (older status reports in the repo root describe a previous signature and were left untouched). proptest is added as a dev-dependency only, using the same feature set as callora-settlement.

Validation

cargo test -p callora-vault simulate

…alloraOrg#1115)

Extract validate_deduct used by both paths (authorized caller, pause, min/max bounds, balance). Drop slippage/rate-limit/duplicate checks from the simulator, align request_id to u64, update module docs, add 256-case parity proptest.
@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Manta-Byte Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Align simulate_deduct checks with live deduct

2 participants