Skip to content

fix(math): bound pow_factor's integer-power loop - #702

Merged
IbrahimIjai merged 1 commit into
SO4-Markets:mainfrom
dev-debbie-umoh:fix/538-pow-factor-unbounded-exponent-loop
Aug 31, 2026
Merged

fix(math): bound pow_factor's integer-power loop#702
IbrahimIjai merged 1 commit into
SO4-Markets:mainfrom
dev-debbie-umoh:fix/538-pow-factor-unbounded-exponent-loop

Conversation

@dev-debbie-umoh

Copy link
Copy Markdown
Contributor

Summary

gmx_math::pow_factor's integer-power loop iterated exponent / FLOAT_PRECISION times with no upper bound. Funding/borrowing/price-impact exponent factors are read straight from data_store config with no validation, so a misconfigured value (admin typo, script bug, wrong-precision value) could drive a loop large enough to exhaust the CPU budget on every order execution, funding update, or price-impact calculation that touches the affected market — a self-inflicted denial of service.

Fix

  • Added MAX_POW_FACTOR_WHOLE_EXPONENT = 10 (GMX-style exponent factors are conventionally 1.0–3.0) and reject any exponent whose whole part exceeds it, before the loop runs.
  • Added regression tests: the bound rejects an oversized exponent, and the bound is inclusive (max value itself still succeeds).

Closes #538

Test plan

  • cargo test -p gmx-math — 30 passed, 0 failed
  • grep -n "TODO" n/a — this issue had no stub, straightforward bound addition

)

pow_factor's `whole` exponent came straight from data_store config with
no upper bound, so a misconfigured funding/borrowing/price-impact
exponent factor could drive an O(whole)-iteration loop large enough to
exhaust the CPU budget on every call that reaches it. Reject any whole
exponent above 10 (GMX-style factors are conventionally 1.0-3.0), and
add regression tests for both the rejection and the inclusive boundary.
@drips-wave

drips-wave Bot commented Aug 31, 2026

Copy link
Copy Markdown

@dev-debbie-umoh Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@IbrahimIjai
IbrahimIjai merged commit 569e482 into SO4-Markets:main Aug 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

math::pow_factor's integer-power loop is unbounded — a large exponent factor can exhaust the CPU budget on every call

2 participants