Repository navigation
fix: address #38, #39, #40, #41 - #173
Merged
Merged
Conversation
|
@paulumanyi Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
fix: address #38, #39, #40, #41
What was solved
#38 — [#38][feat] Issue #38
Add a minimum confidence score parameter to market resolution so that oracle readings which are technically valid but low-confidence (common for high-volatility assets) cannot be used to finalize markets. The change introduces a configurable confidence threshold that resolution logic must enforce before finalizing.
Addressed:
#39 — [#39][security] Issue #39
Issue #39 is a security report about the commit-reveal scheme in the disputes contract: the fuzz harness uses an 11-byte corpus prefix, implying the real preimage is short, which makes the commit-reveal vulnerable to offline preimage brute-force search before the apply window opens. The fix should harden the commit-reveal preimage requirements (e.g., enforce a minimum preimage length / entropy) and align the fuzz harness corpus with the corrected preimage size, without touching unrelated contracts or features.
Addressed:
#40 — [#40][bug] Issue #40
Fix the fee-config apply path so it enforces the timelock: validate that the current ledger time is at or past the stored
apply_etabefore allowingapply_fee_config(or equivalent) to take effect, rejecting early calls.Addressed:
apply_etaagainst the current ledger timestamp before applying the revealed fee config.apply_etawith an appropriate error (e.g., timelock-not-elapsed), rather than silently applying.reveal_fee_configbehavior and storedapply_etasemantics intact; only add the missing validation on apply.#41 — [#41][bug] Issue #41
Enforce a lower bound on
collection_thresholdso a value of0cannot be configured, preventingcollect_feesfrom draining any non-zero balance on every call (fee-drain griefing). The fix adds validation at the configuration/setter boundary and rejects zero (and likely sub-minimum) thresholds with an appropriate error.Addressed:
collection_thresholdwherever it is set/configured.0(and any value below the minimum) with a clear error rather than silently accepting it.collect_feescannot drain arbitrary non-zero balances due to a zero threshold.Changes
contracts/disputes/FUZZ_TARGET.md(modify)contracts/disputes/src/lib.rs(modify)contracts/analytics/src/errors.rs(modify)contracts/betting/src/lib.rs(modify)contracts/fees/src/errors.rs(modify)Approach
Issues
Closes #38
Closes #39
Closes #40
Closes #41