Skip to content

[High] Restrict rescue_tokens with a timelock and a complete protected-balance model #412

Description

@james2177

Description:
rescue_tokens lets the admin move any token that isn't "protected" immediately. Protection is currently an allowlist of token kinds, and doesn't subtract liabilities: escrow, backstop, dispute bonds, and non-default bond tokens. Replace the check with amount <= balance - liabilities(token) and put rescue behind a timelock.

Problem Statement & Context:
Rescue is the most direct admin-drain path in the contract. #265 hardened it for multi-bond tokens, but new liability types (escrow, backstop, submission deposits) have been added since.

Scope & Acceptance Criteria:

  • Rescue only the surplus above liabilities, for any token including bond tokens.
  • A propose_rescue / execute_rescue flow with a timelock, with events at each step.
  • Rescue can't target a token with a pending liability-changing operation in the same ledger.
  • Out of scope: auto-sweeping surplus.

Implementation Guidelines:

  1. Key Files/Modules: intent_settlement/src/lib.rs (rescue_tokens), and the liability counters from the solvency issue.
  2. Design/Architecture: Reuse check_solvency.
  3. Edge Cases/Constraints: Balance changing between propose and execute (re-check at execution time).
  4. Testing: Tests trying to rescue each liability type.

Definition of "Done":

  • CI green, and SECURITY.md updated.
  • Reviewed and approved.

Resources:

Complexity: High (200 points)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programhigh (200 pts)Drips Wave complexity: high, 200 pointssecuritySecurity hardening or audit finding

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions