Repository navigation
fix: validation guards for #621, #622, #623, #624 - #660
Merged
nonsobethel0-dev merged 2 commits intoSep 27, 2026
Merged
nonsobethel0-dev merged 2 commits into
nonsobethel0-dev merged 2 commits into
Conversation
…-Protocol#622, Parashield-Protocol#623, Parashield-Protocol#624 Parashield-Protocol#621 RiskPool share calculation underflow - transfer_position: add ZeroAmount guard after shares*deposited/shares calculation -- prevents burning shares without returning capital when deposited has been eroded by claim losses - withdraw_inner: annotate existing ZeroAmount guard with issue reference - deposit: annotate integer-truncation comment on second-branch share calc Parashield-Protocol#622 ClaimsProcessor payout delay not validated - set_payout_delay: add MAX_PAYOUT_DELAY (90 days) upper bound so an admin cannot lock payouts indefinitely; 0 (immediate) remains valid Parashield-Protocol#623 PolicyEngine duration exceeds max_duration_days not checked - buy_policy_inner: add explicit comment tying the duration_days > max_duration_days guard to this issue - buy_policy_inner: add post-calculation defense-in-depth check that (end_time - start_time) <= max_duration_days * 86400, catching any future code path that bypasses the parameter check Parashield-Protocol#624 OracleVerifier min_submit_interval allows zero - set_min_submit_interval: reject seconds == 0; a zero interval removes the per-oracle rate-limit entirely and allows oracle spam
|
@jajafwangshak86-ops Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #621
Closes #622
Closes #623
Closes #624
#621 — RiskPool share calculation underflow
transfer_position: Added aZeroAmountguard immediately after theshares * deposited / sharescalculation. When a pool has absorbed claim losses,from_pos.depositedcan be eroded whilefrom_pos.sharesstays constant, causing integer-truncation division to yield 0. Without this guard, an LP's shares would be burned without any capital being transferred.withdraw_inner: Annotated the existingZeroAmountguard with the issue reference.deposit: Annotated the second-branch share calculation with a truncation comment so the existingMIN_SHARESguard's purpose is clear.#622 — ClaimsProcessor payout delay not validated
set_payout_delay: Althoughdelay_secondsisu64and cannot be negative at the type level, no upper bound existed — an admin could set an arbitrarily large delay effectively locking payouts forever. AddedMAX_PAYOUT_DELAY = 90 days. The zero sentinel (immediate payout) remains valid.#623 — PolicyEngine duration not checked against max_duration_days
buy_policy_inner: The existingduration_days > max_duration_dayscheck is correct, but the issue asked for an explicit guard on the computed(end_time - start_time)span. Added a post-calculation defense-in-depth check:end_time.saturating_sub(start_time) > max_duration_days * 86_400→DurationTooLong. This is particularly important forbuy_policy_scheduledwherestart_time != now.#624 — OracleVerifier min_submit_interval allows zero
set_min_submit_interval: Added aseconds == 0rejection. A zero interval disables the per-oracle rate-limit entirely, allowing any registered oracle to flood the contract with unlimited submissions per block, exhausting storage and instruction budget.Testing
The three modified contracts (risk-pool, claims-processor, policy-engine) compile cleanly. The oracle-verifier has pre-existing build failures on
main(missingStaleThreshold/StaleCountStorageKeyvariants — unrelated to this PR).