Skip to content

maintenance-pool::sweep's recipient parameter is never validated against the contract's own address #329

Description

@abayomicornelius

Overview

sweep (contracts/maintenance-pool/src/lib.rs:332-367) transfers any surplus balance to an admin-supplied recipient: Address with no check that recipient != env.current_contract_address(). This is the same category of gap already-open issue #44 flags for withdraw's recipient parameter, but #44's title and body are scoped specifically to withdraw — sweep is a distinct function (added later, for #39) that has the identical unvalidated-recipient shape and isn't covered by #44's scope.

If an admin (accidentally, or via a compromised/buggy off-chain tool) passes the contract's own address as recipient, the resulting transfer is a self-transfer: surplus is computed correctly, but no funds actually leave the contract, silently masking what should have been a successful sweep. Low severity (admin-gated, no fund loss), but a real, concrete correctness gap distinct from #44.

Requirements

Add a check in sweep rejecting recipient == env.current_contract_address(), following whatever pattern is chosen to fix #44 for withdraw, for consistency.

Acceptance Criteria

  • sweep rejects a self-referential recipient
  • A regression test added
  • cargo test --workspace passes

Additional Notes

Verified via direct inspection of contracts/maintenance-pool/src/lib.rs:332-367 (no recipient validation against the contract's own address). Cross-reference: #44 (open, same category, scoped to withdraw only).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programsecuritySecurity-related issue

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions