Skip to content

fix: address #38, #39, #40, #41 - #173

Merged
dultimateade merged 4 commits into
dultimateade:mainfrom
paulumanyi:drips/38-39-40-41
Sep 29, 2026
Merged

dultimateade merged 4 commits into
dultimateade:mainfrom
paulumanyi:drips/38-39-40-41

Conversation

@paulumanyi

Copy link
Copy Markdown
Contributor

Summary

fix: address #38, #39, #40, #41

What was solved

#38 — [#38][feat] Issue #38

Add a minimum confidence score parameter to market resolution so that oracle readings which are technically valid but low-confidence (common for high-volatility assets) cannot be used to finalize markets. The change introduces a configurable confidence threshold that resolution logic must enforce before finalizing.

Addressed:

  • Changed: contracts/betting/src/lib.rs
  • Introduce a minimum confidence score parameter used during market resolution
  • Reject/prevent finalizing markets when the oracle reading's confidence is below the configured minimum
  • Keep the change scoped to resolution logic and its configuration; do not alter unrelated oracle, fee, or market features

#39 — [#39][security] Issue #39

Issue #39 is a security report about the commit-reveal scheme in the disputes contract: the fuzz harness uses an 11-byte corpus prefix, implying the real preimage is short, which makes the commit-reveal vulnerable to offline preimage brute-force search before the apply window opens. The fix should harden the commit-reveal preimage requirements (e.g., enforce a minimum preimage length / entropy) and align the fuzz harness corpus with the corrected preimage size, without touching unrelated contracts or features.

Addressed:

  • Changed: contracts/disputes/src/lib.rs, contracts/disputes/FUZZ_TARGET.md
  • Address the short-preimage weakness in the commit-reveal scheme so offline preimage search before the apply window is infeasible.
  • Enforce or validate a minimum preimage length/entropy in the commit-reveal logic (commit and/or reveal paths).
  • Update the fuzz harness corpus/prefix so it reflects the corrected preimage size rather than the 11-byte short prefix.

#40 — [#40][bug] Issue #40

Fix the fee-config apply path so it enforces the timelock: validate that the current ledger time is at or past the stored apply_eta before allowing apply_fee_config (or equivalent) to take effect, rejecting early calls.

Addressed:

  • Changed: contracts/fees/src/errors.rs
  • Enforce the timelock on the apply path by validating apply_eta against the current ledger timestamp before applying the revealed fee config.
  • Reject apply calls made before apply_eta with an appropriate error (e.g., timelock-not-elapsed), rather than silently applying.
  • Keep the existing reveal_fee_config behavior and stored apply_eta semantics intact; only add the missing validation on apply.

#41 — [#41][bug] Issue #41

Enforce a lower bound on collection_threshold so a value of 0 cannot be configured, preventing collect_fees from draining any non-zero balance on every call (fee-drain griefing). The fix adds validation at the configuration/setter boundary and rejects zero (and likely sub-minimum) thresholds with an appropriate error.

Addressed:

  • Changed: contracts/analytics/src/errors.rs
  • Enforce a lower bound (> 0) on collection_threshold wherever it is set/configured.
  • Reject 0 (and any value below the minimum) with a clear error rather than silently accepting it.
  • Ensure collect_fees cannot drain arbitrary non-zero balances due to a zero threshold.

Changes

  • contracts/disputes/FUZZ_TARGET.md (modify)
  • contracts/disputes/src/lib.rs (modify)
  • contracts/analytics/src/errors.rs (modify)
  • contracts/betting/src/lib.rs (modify)
  • contracts/fees/src/errors.rs (modify)

Approach

  1. [#038][feat] Issue #038 #38 — [[#038][feat] Issue #038 #38][feat] Issue [#038][feat] Issue #038 #38 (Changed: contracts/betting/src/lib.rs)
  2. [#039][security] Issue #039 #39 — [[#039][security] Issue #039 #39][security] Issue [#039][security] Issue #039 #39 (Changed: contracts/disputes/src/lib.rs, contracts/disputes/FUZZ_TARGET.md)
  3. [#040][bug] Issue #040 #40 — [[#040][bug] Issue #040 #40][bug] Issue [#040][bug] Issue #040 #40 (Changed: contracts/fees/src/errors.rs)
  4. [#041][bug] Issue #041 #41 — [[#041][bug] Issue #041 #41][bug] Issue [#041][bug] Issue #041 #41 (Changed: contracts/analytics/src/errors.rs)

Issues

Closes #38
Closes #39
Closes #40
Closes #41

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@paulumanyi Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@dultimateade
dultimateade merged commit d898986 into dultimateade:main Sep 29, 2026
0 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[#041][bug] Issue #041 [#040][bug] Issue #040 [#039][security] Issue #039 [#038][feat] Issue #038

2 participants