Skip to content

execute_proposal succeeds with zero votes -- no quorum or minimum vote check #503

Description

@DeFiVC

What

execute_proposal (learn-token lib.rs:1701) does not check if any votes were cast. If no one votes on a proposal, all vote_totals are 0, and the function still marks the proposal as executed with winning_choice = 0 and winning_votes = 0.

Why

A proposal that received zero votes should not be executable. This allows an admin to create a proposal, wait for the voting period to end, and execute it with a "winner" that no one voted for. This undermines the governance mechanism.

Scope

Add a check after the tally loop (after line 1725):

if winning_votes == 0 {
    panic!("no votes cast");
}

Acceptance Criteria

  • execute_proposal panics if no votes were cast
  • Test verifies zero-vote proposals cannot be executed

Technical Context

  • contracts/learn-token/src/lib.rs:1701-1733 -- execute_proposal
  • contracts/learn-token/src/lib.rs:1716-1725 -- tally loop (no quorum check)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programbugSomething isn't workingmediumFunctionality impaired but workaround exists, edge case, partial featurerustRust language

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions