Skip to content

[v2][subscription_renewal] Anti-griefing limits on renewal lock acquisition #1240

Description

@Calebux

Context

acquire_renewal_lock(env, sub_id, lock_timeout) can be called by anyone who can name a sub_id. An attacker can hold the lock for the maximum timeout, release it and immediately re-acquire, permanently preventing a legitimate renewal — a cheap denial of service against a specific user's subscription.

Scope

  • Restrict lock acquisition to the subscription owner, a registered agent (via agent-registry scope Renewals), or admin.
  • Add a cooldown so the same caller cannot re-acquire immediately after releasing.
  • Emit an event on rejected acquisition attempts so griefing is observable off-chain.
  • Cover the attack in a regression test.

Acceptance criteria

  • Only the owner, a scoped agent, or admin can acquire a renewal lock.
  • A re-acquire within the cooldown window returns a typed error.
  • A test reproduces the lock-grief loop and asserts it now fails.
  • Rejected acquisitions emit an event carrying the caller and sub_id.

Files / areas

contracts/contracts/subscription_renewal/src/lib.rs, contracts/contracts/agent-registry/src/lib.rs


Part of the SYNCRO v2 rewrite. Epic: B — Per-contract rewrites.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programarea:blockchainContracts and blockchain integrationscontractsSoroban smart contractspriority:p1High prioritysecuritySecurity vulnerability or concernv2-rewriteSYNCRO v2 rewrite program

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions