-
Notifications
You must be signed in to change notification settings - Fork 33
reentrancy / double-application guard on the settlement settlement path #447
Copy link
Copy link
Open
Labels
GRANTFOX OSSGrantFox open-source campaign taskGrantFox open-source campaign taskMAYBE REWARDEDMay be rewarded under the GrantFox campaignMay be rewarded under the GrantFox campaignOfficial Campaign | FWC26GrantFox FWC26 official campaignGrantFox FWC26 official campaignTHIRD CAMPAIGNarea:settlementsettlementsettlementpriority:highHigh priorityHigh prioritystack:rustRustRuststack:sorobanSoroban smart contractSoroban smart contracttype:featureNew functionalityNew functionality
Description
Activity
Metadata
Metadata
Assignees
Labels
GRANTFOX OSSGrantFox open-source campaign taskGrantFox open-source campaign taskMAYBE REWARDEDMay be rewarded under the GrantFox campaignMay be rewarded under the GrantFox campaignOfficial Campaign | FWC26GrantFox FWC26 official campaignGrantFox FWC26 official campaignTHIRD CAMPAIGNarea:settlementsettlementsettlementpriority:highHigh priorityHigh prioritystack:rustRustRuststack:sorobanSoroban smart contractSoroban smart contracttype:featureNew functionalityNew functionality
Summary
The settlement settlement path can be re-entered or applied twice, enabling double-spend-style bugs. Add a guard that makes settlement strictly once-only.
Why this matters
Double application on a value-moving path is a critical vulnerability. A once-only guard is mandatory hardening.
Requirements
Technical guidance
Edge cases — each must have a test
Acceptance criteria
cargo fmt --check,cargo clippy --all-targets -- -D warnings, andcargo testall pass locallyCloses #<issue>Out of scope
Rewards
Part of the GrantFox OSS / Official Campaign (FWC26) — this task may be rewarded. PR quality is assessed by AI: depth, correctness under edge cases, meaningful tests, and clean design are what earn the reward. Shallow changes (typos, formatting, trivial docs) do not qualify.