0xMiden / 0xMiden/protocol

`verify_u256_to_native_amount_conversion` accepts amounts up to 2^128, but only ~2^123 are claimable

Offen
#3,084 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
agglayer
Vorherrschende Sprache
Rust
Sterne
132
Forks
167
Ø Merge
1 T. 23 Std.
Gemergte PRs (30 T.)
110

Beschreibung

> Tracking issue for the Cantina finding linked below; confirmed against the current `next` code.

The bridge-in CLAIM amount gate `verify_u256_to_native_amount_conversion` ([`asset_conversion.masm:385-387`](https://github.com/0xMiden/protocol/blob/next/crates/miden-agglayer/asm/agglayer/common/asset_conversion.masm#L385-L387)) only rejects amounts ≥ 2^128 (it asserts the upper 128 bits are zero), but `y ≤ FUNGIBLE_ASSET_MAX_AMOUNT` and `scale ≤ 18` cap the largest scalable value at ~2^122.79, so any amount in `[~2^123, 2^128)` passes the gate and then always panics deep in `verify_u128_to_native_amount_conversion` with a misleading `ERR_UNDERFLOW` instead of a clear "amount too large". Severity: low (informational / spec-fidelity) — structurally unreachable for any realistic token, no double-spend, just a confusing failure path.

Cantina finding: https://cantina.xyz/code/b4ccbfb3-665e-4169-837d-3c7b2f0be458/findings?finding=12

PR status: no open PR. Fix is a one-line gate tightening (additionally assert `x3 < 2^27`).

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.