Skip to content

fix(math): add zero-check guard in convert_shares division - #196

Open
BABAT-CODE wants to merge 1 commit into
cocor-tech:masterfrom
BABAT-CODE:fix/math-zero-division-guard
Open

fix(math): add zero-check guard in convert_shares division#196
BABAT-CODE wants to merge 1 commit into
cocor-tech:masterfrom
BABAT-CODE:fix/math-zero-division-guard

Conversation

@BABAT-CODE

Copy link
Copy Markdown
Contributor

Add convert_shares() to common/src/math.rs to safely convert a member's proportional shares into a token payout from a pool.

The function explicitly returns MathError::DivisionByZero when total_shares is zero, preventing an on-chain panic that would occur if a vault or pool loses all share-holders due to a rounding edge case.

Also guards multiplication overflow via safe_mul() before the division step.

Tests added in common/src/test.rs:

  • 7 deterministic unit tests covering: zero total_shares (guard), zero pool, equal split, 100% to one member, zero member shares, single share of many, and overflow on huge inputs.
  • 1 property-based test (proptest) verifying no panic for any non-zero total_shares across random inputs.

Fixes: HIGH security issue — unguarded division by user-supplied denominator

closes #113

Add convert_shares() to common/src/math.rs to safely convert a member's
proportional shares into a token payout from a pool.

The function explicitly returns MathError::DivisionByZero when total_shares
is zero, preventing an on-chain panic that would occur if a vault or pool
loses all share-holders due to a rounding edge case.

Also guards multiplication overflow via safe_mul() before the division step.

Tests added in common/src/test.rs:
  - 7 deterministic unit tests covering: zero total_shares (guard), zero
    pool, equal split, 100% to one member, zero member shares, single share
    of many, and overflow on huge inputs.
  - 1 property-based test (proptest) verifying no panic for any non-zero
    total_shares across random inputs.

Fixes: HIGH security issue — unguarded division by user-supplied denominator
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(contract): prevent division by zero in share conversion when total_shares is zero

1 participant