Area: Security / reentrancy · Estimated effort: 8–12 h
Problem
The escrow tree has a reentrancy guard module and dedicated tests, but all token transfer/callback boundaries need a maintained entrypoint inventory.
Design decision required
Decide whether the guard is global, per operation, or capability-scoped and document callback assumptions.
Requirements
- Create malicious token mocks
- attempt reentry during deposit, payout, refund, and admin operations
- assert state remains unchanged on rejection.
Acceptance criteria
Out of scope
- Unrelated refactors, dependency upgrades, or behavior changes outside the stated scope.
- Closing, deleting, or weakening existing tests to make the change pass.
Verification
cargo test --manifest-path contracts/bounty_escrow/Cargo.toml -p escrow reentrancy -- --nocapture
PR requirements
- Explain the before/after behavior and include the evidence requested above.
- Add regression tests for the changed behavior and report relevant build, test, lint, and artifact results.
- Keep the PR focused and reference this issue.
- Please open the PR within 48 hours of assignment so the work remains active; ask a question in the issue if the scope needs clarification.
Good luck, and please join the contributor Telegram group if you want to discuss the work: https://t.me/+u5qmu35nZ7I0OTU1
Area: Security / reentrancy · Estimated effort: 8–12 h
Problem
The escrow tree has a reentrancy guard module and dedicated tests, but all token transfer/callback boundaries need a maintained entrypoint inventory.
Design decision required
Decide whether the guard is global, per operation, or capability-scoped and document callback assumptions.
Requirements
Acceptance criteria
Out of scope
Verification
cargo test --manifest-path contracts/bounty_escrow/Cargo.toml -p escrow reentrancy -- --nocapturePR requirements
Good luck, and please join the contributor Telegram group if you want to discuss the work: https://t.me/+u5qmu35nZ7I0OTU1