Skip to content

feat: propose/execute rescue with surplus-only check and timelock - #455

Merged
james2177 merged 2 commits into
stellar-vortex-protocol:mainfrom
Keengfk:feat/rescue-tokens-timelock-surplus-check
Sep 30, 2026
Merged

james2177 merged 2 commits into
stellar-vortex-protocol:mainfrom
Keengfk:feat/rescue-tokens-timelock-surplus-check

Conversation

@Keengfk

@Keengfk Keengfk commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Branch: feat/rescue-tokens-timelock-surplus-check Fork:
Keengfk/vortex-contracts

What this branch is doing

Hardening rescue_tokens — currently the most direct admin-drain path in the
contract — by replacing its static token-kind allowlist with a surplus-only
check and putting the operation behind a propose/execute timelock.

Changes committed so far (eb596d8)

New storage keys (DataKey enum):

  • PendingRescue(Address) — stores a pending rescue proposal per token
  • TokenLiabilities(Address) — per-token counter of all outstanding liabilities
    (solver bonds + escrowed fill amounts), maintained incrementally

New error variants:

  • RescueTimelockNotElapsed = 36 — execution attempted before the 48h window
  • NoPendingRescue = 37 — no proposal exists for the given token
  • RescueLiabilityConflict = 38 — same-ledger proposal/execution guard
  • RescueAmountExceedsSurplus = 39 — balance minus liabilities is less than
    requested amount

New struct: PendingRescueRecord — holds token, to, amount, eta, and
proposed_ledger (for the same-ledger conflict guard)

New constant: RESCUE_TIMELOCK_DELAY = 48h (mirrors ADMIN_TIMELOCK_DELAY)

Instrumentation started: TokenLiabilities is now incremented when a solver
registers a bond (register_solver_inner) and decremented when a solver
deregisters (deregister_solver).

Still to do on this branch

  • Wire TokenLiabilities at remaining call sites: withdraw_bond, slash_solver,
    begin_fill, release_fill, resolve_dispute
  • Implement propose_rescue and execute_rescue entrypoints
  • Remove (or deprecate) old rescue_tokens
  • Tests covering all new error paths and the happy path
  • Update SECURITY.md

closes #412

- Add PendingRescue(Address) and TokenLiabilities(Address) DataKey variants
- Add RescueTimelockNotElapsed=36, NoPendingRescue=37, RescueLiabilityConflict=38,
  RescueAmountExceedsSurplus=39 error variants
- Add PendingRescueRecord contracttype struct (token, to, amount, eta, proposed_ledger)
- Add RESCUE_TIMELOCK_DELAY constant (48 h, mirrors ADMIN_TIMELOCK_DELAY)
- Instrument register_solver_inner to increment TokenLiabilities on bond deposit
- Instrument deregister_solver refund loop to decrement TokenLiabilities
- Partial: remaining call sites (withdraw_bond, slash_solver, begin_fill,
  release_fill, resolve_dispute) and propose/execute_rescue entrypoints still
  to be wired up

Relates to: stellar-vortex-protocol#265, stellar-vortex-protocol#35
@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Keengfk Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

…timelock-surplus-check

# Conflicts:
#	intent_settlement/src/lib.rs
@james2177
james2177 merged commit ec3002d into stellar-vortex-protocol:main Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[High] Restrict rescue_tokens with a timelock and a complete protected-balance model

2 participants