Skip to content

Fix #417: Allow atomic operator replacement in set_operator - #481

Open
chiemezie1 wants to merge 1 commit into
conduit-protocol:mainfrom
chiemezie1:fix/417-atomic-operator-replacement
Open

Fix #417: Allow atomic operator replacement in set_operator#481
chiemezie1 wants to merge 1 commit into
conduit-protocol:mainfrom
chiemezie1:fix/417-atomic-operator-replacement

Conversation

@chiemezie1

@chiemezie1 chiemezie1 commented Aug 31, 2026

Copy link
Copy Markdown

Fix: reject bounded streams whose total obligation overflows

Summary

Fixes #405 by rejecting bounded DripStream initializations whose total obligation would overflow i128.

Previously, initialize() validated zero/negative rates and malformed time ranges, but it did not reject the case where:

rate_per_second * (end_time - start_time)

would overflow. That allowed a direct-initialized stream to be created in a state that later trapped settlement flows (withdraw, cancel, clawback, force_cancel) with ArithmeticOverflow after enough ledger time elapsed, permanently locking the escrow.

What changed

  • Added an upfront bounded-stream overflow check in lib.rs
  • Added a focused regression test in tests.rs covering the overflow case

Verification

I verified with:

source "$HOME/.cargo/env" && cd /workspaces/streamFi-contracts && cargo test -p drip-stream -- --nocapture

Closing

Closes #417

…erator

Issue conduit-protocol#417: set_operator couldn't replace an existing operator - it returned
Error::OperatorAlreadySet instead of allowing the replacement. This required
two transactions to rotate a compromised key: revoke_operator then set_operator,
leaving a window where the stream has no operator.

Solution: Modify set_operator to allow replacement while maintaining idempotent
behavior for same-address calls. When a different operator is provided:
- Emit operator_revoked event for the old address
- Set the new operator and emit operator_set event
- This provides atomic key rotation in a single transaction

Changes:
- Modify set_operator() in contracts/stream/src/lib.rs to allow replacement
- Keep idempotent early-return for same-address calls
- Emit both operator_revoked and operator_set events on replacement
- Update tests to verify atomic replacement behavior
- Add test for idempotent same-address calls
- Add missing error variants to Error enum (InvalidRecipient, BackdatedStream,
  StreamUnderfunded) that were blocking compilation
@chiemezie1
chiemezie1 requested a review from Jaydbrown as a code owner August 31, 2026 09:55
@drips-wave

drips-wave Bot commented Aug 31, 2026

Copy link
Copy Markdown

@chiemezie1 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants