Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1354
Summary
This PR fixes a critical race condition between
claim_auctionandsettle_default_liquidationthat could be exploited by a winning bidder to reclaim their bid while preventing the credit contract from receiving the settlement funds.The Issue
Under the previous implementation, if an auction closed and the winning bidder called
claim_auctionbefore the factory could callsettle_default_liquidation, two things happened:claim_auctionincorrectly refunded thehighest_bidback to the winning bidder.Claimed.When the factory subsequently attempted to call
settle_default_liquidation, the call would panic withNotClosedbecause it exclusively expected the status to beClosed. This failure left the credit contract without its rightful settlement payout.The Fix
To enforce the correct claim semantics safely:
src/lib.rs(claim_auction): Removed the token transfer logic that returned the bid to the winner. Thehighest_bidremains securely held for the credit contract.src/lib.rs(settle_default_liquidation): Updated the status validation to accept bothClosedandClaimedstates, allowing settlement to succeed even if the winner has already invokedclaim_auction.Testing & Acceptance Criteria Map
A new testing suite has been added to
tests/auth_settle.rsmocking a complete auction flow with the bid token.claim_then_settle_succeeds: Verifies that ifclaim_auctionis called first,settle_default_liquidationstill executes successfully afterward.settle_then_claim_succeeds_with_claim_reverting: Verifies that ifsettle_default_liquidationruns first, a subsequent call toclaim_auctioncorrectly reverts withAlreadySettled.highest_bidamount (420 stroops) and the winner's token balance does not increase after claiming.Security & Failure-Mode Handling
already_settledboolean flag ensures double-settlement is still impossible regardless of the ordering.