What
increase_allowance (learn-token lib.rs:1274) computes new_amount = current + additional_amount at line 1292 using plain i128 addition without overflow protection. If current + additional_amount > i128::MAX, the addition will panic (Soroban has overflow-checks enabled in release profile).
While the panic prevents actual overflow, the error is an uncontrolled host panic rather than a graceful ContractError return. More importantly, there is no upper-bound check on the resulting allowance -- a user could set an astronomically large allowance that, while not overflowing, is far beyond any reasonable token supply.
Note: #434 was previously filed and closed for this issue, but the code at line 1292 still uses plain +.
Why
Allowance overflow could be used in a griefing attack: set an allowance near i128::MAX, then call increase_allowance with any positive value to trigger a host panic. The error message would be opaque to the caller.
Scope
Use checked_add and return a typed error:
let new_amount = current.checked_add(additional_amount)
.ok_or(ContractError::MaxSupplyExceeded)?;
Or add a reasonable upper bound (e.g., max_supply).
Acceptance Criteria
increase_allowance with values that would overflow returns a typed error instead of host panic
- Test verifies the overflow case
Technical Context
contracts/learn-token/src/lib.rs:1274-1297 -- increase_allowance
contracts/learn-token/src/lib.rs:1292 -- let new_amount = current + additional_amount
What
increase_allowance(learn-token lib.rs:1274) computesnew_amount = current + additional_amountat line 1292 using plain i128 addition without overflow protection. Ifcurrent + additional_amount > i128::MAX, the addition will panic (Soroban has overflow-checks enabled in release profile).While the panic prevents actual overflow, the error is an uncontrolled host panic rather than a graceful
ContractErrorreturn. More importantly, there is no upper-bound check on the resulting allowance -- a user could set an astronomically large allowance that, while not overflowing, is far beyond any reasonable token supply.Note: #434 was previously filed and closed for this issue, but the code at line 1292 still uses plain
+.Why
Allowance overflow could be used in a griefing attack: set an allowance near i128::MAX, then call
increase_allowancewith any positive value to trigger a host panic. The error message would be opaque to the caller.Scope
Use
checked_addand return a typed error:Or add a reasonable upper bound (e.g., max_supply).
Acceptance Criteria
increase_allowancewith values that would overflow returns a typed error instead of host panicTechnical Context
contracts/learn-token/src/lib.rs:1274-1297--increase_allowancecontracts/learn-token/src/lib.rs:1292--let new_amount = current + additional_amount