Skip to content

[Regression on closed #318] milestones::contribute's existing-sponsor lookup still calls unwrap() on Contribution records #418

Description

@chonilius

Problem

#318 reported the same unwrap-on-archived-record panic risk as #317, in milestones::contribute. It's closed as completed, but contracts/milestones/src/lib.rs on main still has two .unwrap() calls, at about lines 210 and 238:

for i in 0..milestone.contributor_count {
    let contribution_key = DataKey::Contribution(milestone_id, i);
    let contribution: Contribution =
        env.storage().persistent().get(&contribution_key).unwrap();
    ...
}
...
let mut contribution: Contribution =
    env.storage().persistent().get(&contribution_key).unwrap();

refund_remaining_budget in the same file (#103) already returns a typed error for a missing record, so contribute is the remaining gap.

Impact

On a long-lived milestone, which is exactly what milestones are designed for, a single archived early contribution makes every later contribute() call panic instead of returning Error::ContributionNotFound. Crowdfunding for that milestone is blocked until someone calls keep_alive, and callers don't get a typed error explaining why.

Suggested fix

Replace both calls with .ok_or(Error::ContributionNotFound)?, and add an archived-record test for contribute.

Related: #103, #318. The escrow counterpart is filed separately.

Activity

  1. added
    bugSomething isn't working
    securitySecurity-related issue
    Stellar WaveIssues in the Stellar wave program
    on Sep 27, 2026
  2. Wittig18 commented on Sep 27, 2026

    @Wittig18

    @Wittig18 has applied to work on this issue as part of the Stellar Wave Program's 9th wave.

    hey maintainer, i would love to work on this

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @Wittig18 to this issue.

  3. nasirudeenbadirudeen87-cloud commented on Sep 27, 2026

    @nasirudeenbadirudeen87-cloud

    @nasirudeenbadirudeen87-cloud has applied to work on this issue as part of the Stellar Wave Program's 9th wave.

    Hi maintainer, I'd very much appreciate the opportunity to work on this issue.
    Having reviewed the acceptance criteria, I'm confident that I'd be able to have a PR up shortly after being assigned.
    Kindly assign this issue to me.
    Thank you!

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @nasirudeenbadirudeen87-cloud to this issue.

  4. edehvictor commented on Sep 27, 2026

    @edehvictor
    Contributor

    @edehvictor has applied to work on this issue as part of the Stellar Wave Program's 9th wave.

    I’d love to help out with this issue. I’ve checked the current codebase/documentation and know exactly what needs to be updated to make this clearer. I will ensure everything aligns perfectly with your existing contribution guidelines.

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @edehvictor to this issue.

  5. drips-wave commented on Sep 27, 2026

    @drips-wave

    Congratulations, @edehvictor! 🎉 Your application was accepted by the repo's maintainers, and the issue is due on September 30, 2026.

    🧑‍💻 @edehvictor: Please resolve the issue such that the repo's maintainers have enough time to review your contribution before the due date. You'll earn Points for completing the issue on-time, which will make you eligible for a share of the Stellar Wave Program's reward pool.

    Warning

    When opening a PR, please link it to this issue to ensure it gets tracked accurately. Points are awarded when this issue is marked as completed by the maintainer.

    🤠 Repo maintainers: Please keep an eye on the contributor's progress and review their work before the due date. You can manage this issue, including adjusting its complexity and points, here.

    🌊 Happy Wave 🌊

  6. grantfox-oss commented on Sep 28, 2026

    @grantfox-oss

    🎉 This issue has been marked as completed on GrantFox!

    @edehvictor's PR #422 was approved and merged by @chonilius.

    🏆 @edehvictor: You earned 40 FoxPoints for this contribution! Your current tier: Builder (1,602 total points). Track your full progress on GrantFox.

    👏 Great work, @edehvictor! Keep contributing to MergeFi.

  7. drips-wave commented on Sep 28, 2026

    @drips-wave

    This issue has been completed by @edehvictor as part of the Stellar Wave Program's 9th Wave 🥳

    😎 @edehvictor: You earned 200 Points for completing this issue! After the current Wave ends, you'll be eligible for a percentage of the Wave's reward pool based on the percentage of total points you've earned. Learn more here. You can also Leave a review to share your experience working on this issue.

    🧑‍💻 Repo maintainers: How'd the contributor do? Leave a review to share your experience working with them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programbugSomething isn't workingsecuritySecurity-related issue

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions