Skip to content

feat(#1375): Scaffold OpNonce storage and batch validation logic - #1577

Open
T-kesh wants to merge 1 commit into
LabsCrypt:mainfrom
T-kesh:fix-issue-1375
Open

feat(#1375): Scaffold OpNonce storage and batch validation logic#1577
T-kesh wants to merge 1 commit into
LabsCrypt:mainfrom
T-kesh:fix-issue-1375

Conversation

@T-kesh

@T-kesh T-kesh commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Description: closes #1375 (Phase 1).

The current smart contract lacks application-level nonces, making it vulnerable to replay attacks on already-applied operations when a fresh authorization is re-signed by the backend retry loop.

This PR introduces Phase 1 of the cross-layer fix for the Smart Contract infrastructure:

Scaffolds contracts/loan_manager/src/nonce.rs.
Introduces persistent monotonic OpNonce storage tracking.
Implements consume_nonce guard which bumps the counter strictly on stored + 1, blocking all downstream replays.
Adds valid_until_ledger batch window expiration checks.
Defines robust BatchError::NonceReused and BatchError::BatchWindowExpired handling.

@ogazboiz ogazboiz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

same core problem as your #1579: nonce.rs is never declared in lib.rs, so this is dead code and the replay vulnerability from #1375 is untouched at runtime. the strict stored+1 bump and ledger window logic are a decent sketch though.

  1. declare the module in lib.rs.
  2. actually call consume_nonce and validate_batch_window from process_defaults_batch / approve_loans_batch, threading supplied_nonce and valid_until_ledger through their signatures.
  3. align error codes with the issue's contract (LoanError::NonceReused, LoanError::BatchWindowExpired) since the indexer and frontend consume them.
  4. add unit tests for reuse, gap, and expired-window cases.

if you want to keep contributing, join us on Telegram: https://t.me/+DOylgFv1jyJlNzM0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Cross-Layer] Non-Idempotent Batch Authorization Causing Cross-Layer Ledger State Desynchronization and Client State Corruption

2 participants