Skip to content

[High] Define and enforce fail-open vs fail-closed policy for every cross-contract dependency #421

Description

@james2177

Description:
Settlement calls the proof registry, the solver registry, and token contracts, and will soon call an oracle, a policy contract, and hooks. When one of them traps or is paused, is that failure swallowed (fail-open) or propagated (fail-closed)? Nothing currently defines this. Write a policy table and implement it consistently, using try_ invocations where fail-open is chosen.

Problem Statement & Context:
An inconsistent failure policy creates both DoS vectors (a paused registry blocks all fills) and safety holes (a trapping oracle skips the check). Auditors will ask for this table.

Scope & Acceptance Criteria:

  • A policy table in docs/ listing each call site, its dependency, the chosen policy, and the rationale.
  • Implementation, using env.try_invoke_contract for fail-open sites with event emission.
  • Tests that make each dependency trap or pause and assert the chosen behaviour.
  • Out of scope: new dependencies.

Implementation Guidelines:

  1. Key Files/Modules: intent_settlement/src/lib.rs, a new docs/dependency-failure-policy.md.
  2. Design/Architecture: Make slashing fail-open with respect to the registry, so a registry failure can't prevent a slash. Make proof verification fail-closed.
  3. Edge Cases/Constraints: A try_ call still consumes budget, and a trapping token transfer can't be made fail-open safely.
  4. Testing: A trap-injection mock for each dependency.

Definition of "Done":

  • Doc plus implementation plus tests.
  • Reviewed and approved.

Resources:

Complexity: High (200 points)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Stellar WaveIssues in the Stellar wave programhigh (200 pts)Drips Wave complexity: high, 200 pointssecuritySecurity hardening or audit finding

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions