Fix double-payouts for maintenance pools and overdue expiry race conditions - #473
Open
Ultra-Tech-code wants to merge 2 commits into
Open
Ultra-Tech-code wants to merge 2 commits into
Ultra-Tech-code wants to merge 2 commits into
Conversation
Replace read-then-save loop with an atomic bulk update so concurrently-advanced bounties are not overwritten to EXPIRED.
- Adds maintenanceIssueId to Payment with a unique index alongside escrowId - Updates MaintenancePoolService.assignReward to check payouts by issueId instead of recipientId - Passes issueId through EscrowService.poolWithdraw
|
@Ultra-Tech-code is attempting to deploy a commit to the chonilius' projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@Ultra-Tech-code Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description:
This PR resolves a couple of critical race conditions and validation bugs when expiring bounties and paying out maintenance pool rewards.
Fixes
1. Atomic Overdue Expiry (#460)
BountiesService.expireOverdue()was reading an overdue list into memory and looping through per-rowsave()s. If a bounty transitioned (e.g., IN_REVIEW or PAID) during this loop, it would get incorrectly overwritten toEXPIREDusing the stale in-memory copy.UPDATEquery via the query builder. This guarantees thatstatuschanges only apply to records that are still eligible at the exact moment of execution, completely avoiding the read-write gap.2. Guard against double-payouts by pool and issue (#458)
assignRewardincorrectly keyed its guard on(pool, recipient)rather than(pool, issue). This allowed paying out the same issue multiple times to different recipients, while unfairly blocking legitimate payouts when a maintainer completed two distinct issues.maintenanceIssuerelation andmaintenanceIssueIdcolumn to thePaymententity.(escrowId, maintenanceIssueId).MaintenancePoolService.assignReward()to check the payout guard againstissueIdinstead ofrecipientId.EscrowService.poolWithdraw()to correctly stamp the resulting payment with the correspondingmaintenanceIssueId.Closes #460
Closes #458