Repository navigation
Conversation
saturating_sub silently clamps total_supply to zero when an underflow occurs (e.g. due to storage corruption or an invariant violation). This makes a critical accounting error invisible at the call site. Replace saturating_sub with checked_sub so that any underflow is surfaced immediately as a hard revert with ERR_OVERFLOW, consistent with how mint already guards against overflow. The invariant (total_supply >= individual balance) is maintained by construction, so this change has no effect on correct execution. Also add two regression tests: - burn_decrements_total_supply_correctly: verifies the happy-path decrement is exact. - burn_reverts_on_total_supply_underflow_instead_of_saturating: verifies that a corrupted/zeroed total_supply triggers ERR_OVERFLOW instead of silently writing zero.
forumevi
requested review from
ZhiyuCircle,
ancazamfir,
romac and
sergio-mena
as code owners
October 5, 2026 16:47
Contributor
|
Hi @forumevi, Thank you for your interest in contributing to Arc Node. This PR has been automatically closed because it does not reference a GitHub issue. All PRs must reference an existing issue using the format To contribute properly:
Please see our CONTRIBUTING.md for more details. |
Contributor
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
## Summary
In
native_coin_authority.rs, theburnhandler reads the currenttotal_supplyfrom storage and then subtracts the burned amount using
saturating_sub:The inline comment says "Underflow cannot happen due to the balance check", but
saturating_subsilently clamps to zero when an underflow does occur instead ofsurfacing it as an error. This means that any bug or storage corruption that violates
the invariant (
total_supply >= individual balance) would causetotal_supplytobe written as
0without any revert or observable signal — permanently corruptingthe global supply accounting.
## Fix
Replace
saturating_subwithchecked_suband propagate a hard revert withERR_OVERFLOWon underflow, consistent with howmintalready guards theopposite direction:
If the invariant holds (it always should on a correct chain), behaviour is
identical. If it ever does not hold, the transaction reverts loudly instead of
corrupting the supply silently.
## Tests
Two regression tests are added to
native_coin_authority.rs:burn_decrements_total_supply_correctly— verifies the happy-path decrement is exact.burn_reverts_on_total_supply_underflow_instead_of_saturating— verifies that whentotal_supplyis artificially set below the burn amount (simulating storage corruption), the call reverts withERR_OVERFLOWrather than writing zero.