Skip to content

fix(precompiles): use checked_sub for total_supply in burn - #482

Closed
forumevi wants to merge 1 commit into
circlefin:mainfrom
forumevi:fix/burn-total-supply-checked-sub
Closed

forumevi wants to merge 1 commit into
circlefin:mainfrom
forumevi:fix/burn-total-supply-checked-sub

Conversation

@forumevi

@forumevi forumevi commented Oct 5, 2026

Copy link
Copy Markdown

Summary

In native_coin_authority.rs, the burn handler updates total_supply using saturating_sub. The inline comment says "Underflow cannot happen due to the balance check", but saturating_sub silently clamps to zero on underflow instead of reverting. Any bug or storage corruption violating the invariant (total_supply >= individual balance) would write total_supply = 0 with no error — permanently corrupting global supply accounting.

Fix

Replace with checked_sub so underflow causes a hard revert with ERR_OVERFLOW, consistent with how mint already guards against overflow. On a correct chain behaviour is identical.

Testing

Two regression tests added:

  • burn_decrements_total_supply_correctly — happy-path decrement is exact
  • burn_reverts_on_total_supply_underflow_instead_of_saturating — corrupted total_supply triggers ERR_OVERFLOW instead of writing zero

Closes #481

saturating_sub silently clamps total_supply to zero when an underflow
occurs (e.g. due to storage corruption or an invariant violation).
This makes a critical accounting error invisible at the call site.

Replace saturating_sub with checked_sub so that any underflow is
surfaced immediately as a hard revert with ERR_OVERFLOW, consistent
with how mint already guards against overflow.

The invariant (total_supply >= individual balance) is maintained by
construction, so this change has no effect on correct execution.

Also add two regression tests:
- burn_decrements_total_supply_correctly: verifies the happy-path
  decrement is exact.
- burn_reverts_on_total_supply_underflow_instead_of_saturating:
  verifies that a corrupted/zeroed total_supply triggers ERR_OVERFLOW
  instead of silently writing zero.
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

⚠️ Unsigned Commits Detected

The following commits are missing a verified signature:

  • c5a1ac0 by forumevi

How to fix: Sign your commits.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Hi @forumevi,

Thank you for your interest in contributing to Arc Node.

This PR has been automatically closed because you are not assigned to issue #481. We require contributors to be explicitly assigned to an issue before submitting a PR.

To contribute properly:

  1. Comment on issue bug(precompiles): saturating_sub in burn silently corrupts total_supply on underflow #481 requesting assignment
  2. Wait for maintainer approval
  3. Only submit a PR after you have been assigned

Please see our CONTRIBUTING.md for more details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(precompiles): saturating_sub in burn silently corrupts total_supply on underflow

1 participant