fix(math): add zero-check guard in convert_shares division - #196
Open
BABAT-CODE wants to merge 1 commit into
Open
fix(math): add zero-check guard in convert_shares division#196BABAT-CODE wants to merge 1 commit into
BABAT-CODE wants to merge 1 commit into
Conversation
Add convert_shares() to common/src/math.rs to safely convert a member's
proportional shares into a token payout from a pool.
The function explicitly returns MathError::DivisionByZero when total_shares
is zero, preventing an on-chain panic that would occur if a vault or pool
loses all share-holders due to a rounding edge case.
Also guards multiplication overflow via safe_mul() before the division step.
Tests added in common/src/test.rs:
- 7 deterministic unit tests covering: zero total_shares (guard), zero
pool, equal split, 100% to one member, zero member shares, single share
of many, and overflow on huge inputs.
- 1 property-based test (proptest) verifying no panic for any non-zero
total_shares across random inputs.
Fixes: HIGH security issue — unguarded division by user-supplied denominator
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add convert_shares() to common/src/math.rs to safely convert a member's proportional shares into a token payout from a pool.
The function explicitly returns MathError::DivisionByZero when total_shares is zero, preventing an on-chain panic that would occur if a vault or pool loses all share-holders due to a rounding edge case.
Also guards multiplication overflow via safe_mul() before the division step.
Tests added in common/src/test.rs:
Fixes: HIGH security issue — unguarded division by user-supplied denominator
closes #113