Skip to content

Add reentrancy regression coverage for every token callback boundary #1740

Description

@Jagadeeshftw

Area: Security / reentrancy · Estimated effort: 8–12 h

Problem

The escrow tree has a reentrancy guard module and dedicated tests, but all token transfer/callback boundaries need a maintained entrypoint inventory.

Design decision required

Decide whether the guard is global, per operation, or capability-scoped and document callback assumptions.

Requirements

  • Create malicious token mocks
  • attempt reentry during deposit, payout, refund, and admin operations
  • assert state remains unchanged on rejection.

Acceptance criteria

  • Every external token boundary is covered, the guard emits/returns a deterministic failure, and successful non-reentrant paths retain behavior.

Out of scope

  • Unrelated refactors, dependency upgrades, or behavior changes outside the stated scope.
  • Closing, deleting, or weakening existing tests to make the change pass.

Verification

cargo test --manifest-path contracts/bounty_escrow/Cargo.toml -p escrow reentrancy -- --nocapture

PR requirements

  • Explain the before/after behavior and include the evidence requested above.
  • Add regression tests for the changed behavior and report relevant build, test, lint, and artifact results.
  • Keep the PR focused and reference this issue.
  • Please open the PR within 48 hours of assignment so the work remains active; ask a question in the issue if the scope needs clarification.

Good luck, and please join the contributor Telegram group if you want to discuss the work: https://t.me/+u5qmu35nZ7I0OTU1

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions