Description:
rescue_tokens lets the admin move any token that isn't "protected" immediately. Protection is currently an allowlist of token kinds, and doesn't subtract liabilities: escrow, backstop, dispute bonds, and non-default bond tokens. Replace the check with amount <= balance - liabilities(token) and put rescue behind a timelock.
Problem Statement & Context:
Rescue is the most direct admin-drain path in the contract. #265 hardened it for multi-bond tokens, but new liability types (escrow, backstop, submission deposits) have been added since.
Scope & Acceptance Criteria:
- Rescue only the surplus above liabilities, for any token including bond tokens.
- A
propose_rescue / execute_rescue flow with a timelock, with events at each step.
- Rescue can't target a token with a pending liability-changing operation in the same ledger.
- Out of scope: auto-sweeping surplus.
Implementation Guidelines:
- Key Files/Modules:
intent_settlement/src/lib.rs (rescue_tokens), and the liability counters from the solvency issue.
- Design/Architecture: Reuse
check_solvency.
- Edge Cases/Constraints: Balance changing between propose and execute (re-check at execution time).
- Testing: Tests trying to rescue each liability type.
Definition of "Done":
- CI green, and SECURITY.md updated.
- Reviewed and approved.
Resources:
Complexity: High (200 points)
Description:
rescue_tokenslets the admin move any token that isn't "protected" immediately. Protection is currently an allowlist of token kinds, and doesn't subtract liabilities: escrow, backstop, dispute bonds, and non-default bond tokens. Replace the check withamount <= balance - liabilities(token)and put rescue behind a timelock.Problem Statement & Context:
Rescue is the most direct admin-drain path in the contract. #265 hardened it for multi-bond tokens, but new liability types (escrow, backstop, submission deposits) have been added since.
Scope & Acceptance Criteria:
propose_rescue/execute_rescueflow with a timelock, with events at each step.Implementation Guidelines:
intent_settlement/src/lib.rs(rescue_tokens), and the liability counters from the solvency issue.check_solvency.Definition of "Done":
Resources:
rescue_tokens' protected-token guard for forward-compatibility with multi-bond-token work #265Complexity: High (200 points)