Conversation
…wals partiallyLiquidateCreditAccount always withdraws fee + seized collateral, but passed useSafePrices: false into the final fullCollateralCheck. Multicall's withdrawCollateral path unconditionally ORs USE_SAFE_PRICES_FLAG after any withdrawal (including when a phantom adapter returns false). Honour the same post-withdrawal rule here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
partiallyLiquidateCreditAccountalways withdraws collateral (fee in underlying to treasury, seized token to the liquidator), then runs_fullCollateralCheckwith a hardcodeduseSafePrices: false.The multicall path treats any
withdrawCollateralas requiring safe prices: after the withdraw (and after any phantom-token adapter call) it unconditionally ORsUSE_SAFE_PRICES_FLAGinto the flags used for the final check (CreditFacadeV3._withdrawCollateral, returnflags | REVERT_ON_FORBIDDEN_TOKENS_FLAG | USE_SAFE_PRICES_FLAG). That includes the case where a phantom withdrawer's adapter returnsfalseforuseSafePrices.So the partial-liquidation path could leave an account that passed on a manipulated main feed after collateral left the account, while the equivalent multicall withdraw would have forced the stricter
min(main, reserve)check (and zero for tokens with no reserve feed).Related: #313 only forwards
flags & USE_SAFE_PRICES_FLAGfrom the phantom/external call. That is incomplete for ordinary (non-phantom) seizes, and also incomplete when a phantom adapter returnsfalse(the in-repoPhantomTokenWithdrawerMockdoes exactly that). This PR supersedes that approach.Fix
Pass
useSafePrices: trueon the partial-liquidation collateral check. Withdrawals always happen on this path, so this matches multicall withdraw semantics.Verification
Both pass. Unit expectations updated from
falsetotrueon thefullCollateralCheckcall.Made with Cursor