Context
acquire_renewal_lock(env, sub_id, lock_timeout) can be called by anyone who can name a sub_id. An attacker can hold the lock for the maximum timeout, release it and immediately re-acquire, permanently preventing a legitimate renewal — a cheap denial of service against a specific user's subscription.
Scope
- Restrict lock acquisition to the subscription owner, a registered agent (via
agent-registry scope Renewals), or admin.
- Add a cooldown so the same caller cannot re-acquire immediately after releasing.
- Emit an event on rejected acquisition attempts so griefing is observable off-chain.
- Cover the attack in a regression test.
Acceptance criteria
Files / areas
contracts/contracts/subscription_renewal/src/lib.rs, contracts/contracts/agent-registry/src/lib.rs
Part of the SYNCRO v2 rewrite. Epic: B — Per-contract rewrites.
Context
acquire_renewal_lock(env, sub_id, lock_timeout)can be called by anyone who can name asub_id. An attacker can hold the lock for the maximum timeout, release it and immediately re-acquire, permanently preventing a legitimate renewal — a cheap denial of service against a specific user's subscription.Scope
agent-registryscopeRenewals), or admin.Acceptance criteria
sub_id.Files / areas
contracts/contracts/subscription_renewal/src/lib.rs,contracts/contracts/agent-registry/src/lib.rsPart of the SYNCRO v2 rewrite. Epic: B — Per-contract rewrites.