Skip to content

fix(governance): validate snapshot_ledger is strictly in the past (closes #504) - #520

Open
Ranjeet2063 wants to merge 2 commits into
ChainLearnOfficial:mainfrom
Ranjeet2063:fix/issue-504
Open

Ranjeet2063 wants to merge 2 commits into
ChainLearnOfficial:mainfrom
Ranjeet2063:fix/issue-504

Conversation

@Ranjeet2063

@Ranjeet2063 Ranjeet2063 commented Oct 2, 2026 •

Copy link
Copy Markdown

Summary

Enforces invariant validation in Soroban smart contract governance proposal creation ensuring that snapshot_ledger is strictly earlier than the current ledger sequence (snapshot_ledger < env.ledger().sequence()).

Key Fixes & Tests

  1. Contract Invariant:

    • In create_proposal(), panics with "snapshot_ledger must be earlier than the current ledger"" when snapshot_ledger >= env.ledger().sequence()`.
    • Prevents retroactive flash-loan/just-in-time token minting voting attacks by guaranteeing voting power strictly references a completed past ledger snapshot.
  2. Automated Unit Verification:

    • Added and fixed test_create_proposal_rejects_current_or_future_snapshot_ledger asserting rejection on current/future ledger sequences.
    • Updated pause boundary tests (test_create_proposal_fails_while_paused, test_vote_fails_while_paused, test_execute_proposal_fails_while_paused) with consistent historical ledger snapshots.
    • Verified 100% green with cargo test.

Closes #504

Copilot AI balanced review requested due to automatic review settings October 2, 2026 20:14

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Ranjeet2063 Ranjeet2063 changed the title docs: update README documentation and references fix(governance): validate snapshot_ledger is strictly in the past (closes #504) Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

create_proposal does not validate snapshot_ledger is in the past

2 participants