fix(blend-adapter): authorize the pool transfer immediately before submit() - #651
Open
collinsezedike wants to merge 1 commit into
Open
fix(blend-adapter): authorize the pool transfer immediately before submit()#651collinsezedike wants to merge 1 commit into
collinsezedike wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
blend-usdc-fixedcurrently fails in production withHostError: Error(Auth, InvalidAction)BlendAdapter::deposit()calledenv.authorize_as_current_contract(...)beforeget_reserve()/get_positions(), and those intervening cross-contract calls silently expire the authorization tracker beforesubmit()ever gets to consume itauthorize_as_current_contract()call to immediately precedeclient.submit(), with no cross-contract call in betweendeposit_authorization_tree_matches_the_real_pool_call_shape, a test that runs under real, enforcing Soroban auth verification (mock_auths) instead ofmock_all_auths_allowing_non_root_auth, so this class of bug is caught going forwardTest plan
cargo testinpackages/contracts/blend-adapter— all 18 tests pass, including the new strict auth test, which fails against the pre-fix ordering and passes against the fixvercel logs) that the failing call shape and error match this bug exactlyblend-adapterdeploy +migrate_adapterto move the live vault onto the corrected contract (tracked in [Bug] blend-adapter deposit() authorization tracker expires before submit() consumes it #650; the position currently holds zero assets, so this carries no fund-safety risk)