Skip to content

maintenance-pool has no MAX_DEPOSITS bound on deposit_count, unlike MAX_SPONSORS in escrow/milestones #94

Description

@chonilius

Both contracts/escrow/src/lib.rs and contracts/milestones/src/lib.rs define pub const MAX_SPONSORS: u32 = 20 and enforce it (TooManySponsors) to bound per-contributor loops to a small, predictable constant. contracts/maintenance-pool/src/lib.rs has no equivalent constant or check on deposit_count at all — deposit() increments it unconditionally on every call, forever (see also the separate, already-filed #45 about the unchecked-increment overflow panic this enables).

Beyond the overflow-panic fix #45 tracks, this is a design inconsistency worth resolving deliberately: either give maintenance-pool the same kind of bounded-deposit-count model escrow/milestones use for contributors (with a documented reason a "recurring, open-ended" pool doesn't need one, if that's the intended design), or explicitly cap it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programarchitectureArchitecture/design issuebugSomething isn't workinghelp wantedExtra attention is neededvery hardVery difficult task, expert-level effort required

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions