Repository navigation
Conversation
saturating_sub silently clamps total_supply to zero when an underflow occurs (e.g. due to storage corruption or an invariant violation). This makes a critical accounting error invisible at the call site. Replace saturating_sub with checked_sub so that any underflow is surfaced immediately as a hard revert with ERR_OVERFLOW, consistent with how mint already guards against overflow. The invariant (total_supply >= individual balance) is maintained by construction, so this change has no effect on correct execution. Also add two regression tests: - burn_decrements_total_supply_correctly: verifies the happy-path decrement is exact. - burn_reverts_on_total_supply_underflow_instead_of_saturating: verifies that a corrupted/zeroed total_supply triggers ERR_OVERFLOW instead of silently writing zero.
forumevi
requested review from
ZhiyuCircle,
ancazamfir,
romac and
sergio-mena
as code owners
October 5, 2026 16:54
Contributor
|
Contributor
|
Hi @forumevi, Thank you for your interest in contributing to Arc Node. This PR has been automatically closed because you are not assigned to issue #481. We require contributors to be explicitly assigned to an issue before submitting a PR. To contribute properly:
Please see our CONTRIBUTING.md for more details. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
In
native_coin_authority.rs, theburnhandler updatestotal_supplyusingsaturating_sub. The inline comment says "Underflow cannot happen due to the balance check", butsaturating_subsilently clamps to zero on underflow instead of reverting. Any bug or storage corruption violating the invariant (total_supply >= individual balance) would writetotal_supply = 0with no error — permanently corrupting global supply accounting.Fix
Replace with
checked_subso underflow causes a hard revert withERR_OVERFLOW, consistent with howmintalready guards against overflow. On a correct chain behaviour is identical.Testing
Two regression tests added:
burn_decrements_total_supply_correctly— happy-path decrement is exactburn_reverts_on_total_supply_underflow_instead_of_saturating— corruptedtotal_supplytriggersERR_OVERFLOWinstead of writing zeroCloses #481