Skip to content

platform_stats: address trust assumption, storage growth, 24h window semantics, and storage_ok invariant - #1196

Merged
martinzhames merged 4 commits into
dupdab:mainfrom
bytescape30:drips/1123-1124-1125-1126
Oct 7, 2026
Merged

martinzhames merged 4 commits into
dupdab:mainfrom
bytescape30:drips/1123-1124-1125-1126

Conversation

@bytescape30

Copy link
Copy Markdown
Contributor

Summary

platform_stats: address trust assumption, storage growth, 24h window semantics, and storage_ok invariant

What was solved

#1123 — platform_stats::record_payment accepts caller-supplied amount_usd and settled with no on-chain corroboration

The issue asks to address the trust assumption in platform_stats::record_payment, which accepts a caller-supplied amount_usd and settled flag and adds it to TotalSettledVolumeUsd without any on-chain corroboration against settlement_ledger. The suggested fix is either to document the trust assumption explicitly in code or to add a cross-contract call to settlement_ledger::get_settlement to verify the reported amount matches an actual recorded settlement before updating the running total.

Addressed:

  • Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs
  • Address the trust assumption in platform_stats::record_payment where caller-supplied amount_usd and settled are accepted without on-chain corroboration
  • Either document the trust assumption explicitly in the code OR add a cross-contract call to settlement_ledger::get_settlement to verify the reported amount matches an actual recorded settlement before adding to the running total
  • Stay within the scope of platform_stats::record_payment and its interaction with settlement_ledger; do not refactor unrelated contracts or off-chain code

#1124 — platform_stats: ActiveBucket entries accumulate forever in instance storage, one per 24h period, never pruned

Fix unbounded instance-storage growth in platform_stats by moving ActiveBucket entries out of instance() storage into persistent() storage with a short TTL that naturally expires once a bucket is no longer current, since stats() only reads the current bucket.

Addressed:

  • Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs
  • Change record_payment in dabdub_contracts/contracts/platform_stats/src/lib.rs so ActiveBucket entries are written to persistent() storage instead of instance() storage.
  • Apply a short TTL to ActiveBucket persistent entries so they naturally expire once the bucket is no longer current, rather than living forever in the shared instance footprint.
  • Keep stats() reading only the CURRENT bucket (bucket = ledger().sequence() / ACTIVE_WINDOW_LEDGERS) — do not add historical bucket reads.

#1125 — platform_stats: active_payments_24h is a fixed ledger-aligned bucket, not a true rolling 24-hour window

Fix the misleading active_payments_24h semantics in the platform_stats contract. The field is currently computed from a fixed ledger-sequence-aligned bucket (ledger().sequence() / ACTIVE_WINDOW_LEDGERS), which does not match its name or doc comment implying a rolling 24-hour window. Implement a genuine sliding window by summing the current and previous bucket so activity near a bucket boundary is not immediately dropped, and update the doc comment to accurately describe the semantics.

Addressed:

  • Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs
  • Address the contract/documentation mismatch for active_payments_24h in dabdub_contracts/contracts/platform_stats/src/lib.rs
  • Implement a genuine sliding window (sum current and previous bucket) OR rename/redocument the field to fixed-bucket semantics — the issue allows either; prefer the sliding-window fix since it preserves the field name and its documented intent
  • Update the doc comment on active_payments_24h so it accurately describes the implemented semantics

#1126 — platform_stats::health's storage_ok field is a tautology — it can never report false

Fix the tautological storage_ok field in platform_stats::health() so it reports a genuinely falsifiable storage invariant instead of the always-true has(&DataKey::Admin) check. The fix replaces the check with a verification that the contract's core storage state is internally consistent (e.g. Admin present AND the stats/config keys the contract relies on are present and coherent), so the field can actually report false when storage is corrupted or partially initialized.

Addressed:

  • Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs
  • Modify health() in dabdub_contracts/contracts/platform_stats/src/lib.rs so storage_ok is no longer an unconditional tautology.
  • storage_ok must be derived from a check that can plausibly evaluate to false (a real storage invariant), not merely has(&DataKey::Admin).
  • Keep the SystemHealth struct shape and the stats() response contract intact unless removal is explicitly required; prefer making the field meaningful over deleting it.

Changes

  • dabdub_contracts/contracts/platform_stats/src/lib.rs (modify)

Approach

  1. platform_stats::record_payment accepts caller-supplied amount_usd and settled with no on-chain corroboration #1123 — platform_stats::record_payment accepts caller-supplied amount_usd and settled with no on-chain corroboration (Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs)
  2. platform_stats: ActiveBucket entries accumulate forever in instance storage, one per 24h period, never pruned #1124 — platform_stats: ActiveBucket entries accumulate forever in instance storage, one per 24h period, never pruned (Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs)
  3. platform_stats: active_payments_24h is a fixed ledger-aligned bucket, not a true rolling 24-hour window #1125 — platform_stats: active_payments_24h is a fixed ledger-aligned bucket, not a true rolling 24-hour window (Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs)
  4. platform_stats::health's storage_ok field is a tautology — it can never report false #1126 — platform_stats::health's storage_ok field is a tautology — it can never report false (Changed: dabdub_contracts/contracts/platform_stats/src/lib.rs)

Issues

Closes #1123
Closes #1124
Closes #1125
Closes #1126

@martinzhames
martinzhames merged commit b0d24b6 into dupdab:main Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment