Overview
sweep (contracts/maintenance-pool/src/lib.rs:332-367) transfers any surplus balance to an admin-supplied recipient: Address with no check that recipient != env.current_contract_address(). This is the same category of gap already-open issue #44 flags for withdraw's recipient parameter, but #44's title and body are scoped specifically to withdraw — sweep is a distinct function (added later, for #39) that has the identical unvalidated-recipient shape and isn't covered by #44's scope.
If an admin (accidentally, or via a compromised/buggy off-chain tool) passes the contract's own address as recipient, the resulting transfer is a self-transfer: surplus is computed correctly, but no funds actually leave the contract, silently masking what should have been a successful sweep. Low severity (admin-gated, no fund loss), but a real, concrete correctness gap distinct from #44.
Requirements
Add a check in sweep rejecting recipient == env.current_contract_address(), following whatever pattern is chosen to fix #44 for withdraw, for consistency.
Acceptance Criteria
Additional Notes
Verified via direct inspection of contracts/maintenance-pool/src/lib.rs:332-367 (no recipient validation against the contract's own address). Cross-reference: #44 (open, same category, scoped to withdraw only).
Overview
sweep(contracts/maintenance-pool/src/lib.rs:332-367) transfers any surplus balance to an admin-suppliedrecipient: Addresswith no check thatrecipient != env.current_contract_address(). This is the same category of gap already-open issue #44 flags forwithdraw'srecipientparameter, but#44's title and body are scoped specifically towithdraw—sweepis a distinct function (added later, for #39) that has the identical unvalidated-recipient shape and isn't covered by #44's scope.If an admin (accidentally, or via a compromised/buggy off-chain tool) passes the contract's own address as
recipient, the resultingtransferis a self-transfer:surplusis computed correctly, but no funds actually leave the contract, silently masking what should have been a successful sweep. Low severity (admin-gated, no fund loss), but a real, concrete correctness gap distinct from #44.Requirements
Add a check in
sweeprejectingrecipient == env.current_contract_address(), following whatever pattern is chosen to fix #44 forwithdraw, for consistency.Acceptance Criteria
sweeprejects a self-referential recipientcargo test --workspacepassesAdditional Notes
Verified via direct inspection of
contracts/maintenance-pool/src/lib.rs:332-367(norecipientvalidation against the contract's own address). Cross-reference: #44 (open, same category, scoped towithdrawonly).