Skip to content

fix(capacitors): validate maxPacketLength_ input instead of stale state - #438

Open
HusseinAdeiza wants to merge 1 commit into
SocketDotTech:masterfrom
HusseinAdeiza:fix/hashchain-capacitor-packet-length
Open

HusseinAdeiza wants to merge 1 commit into
SocketDotTech:masterfrom
HusseinAdeiza:fix/hashchain-capacitor-packet-length

Conversation

@HusseinAdeiza

Copy link
Copy Markdown

Summary

HashChainCapacitor validates the stale maxPacketLength state variable instead of its own input maxPacketLength_ in both the constructor and updateMaxPacketLength, so the MAX_LEN (10) guard never rejects anything: the constructor checks the default 0, and the update path re-checks the already-set value. Oversized packet lengths install silently. Swapping the two checks to the input fixes it.

Fixes #436

Test plan

Three regression tests added to test/capacitors/HashChainCapacitor.t.sol: oversized constructor input and oversized update input must revert with InvalidPacketLength (both fail on current master), and the boundary value 10 stays accepted.

forge test --match-path test/capacitors/*
# 28 passed, 0 failed

Both changed files pass prettier@2.8.8 --check with prettier-plugin-solidity at the repo-pinned version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate the new HashChainCapacitor packet length instead of the old state value

1 participant