fix(round): reject seals outside the committed Drand reveal window (#… - #464
Merged
karagozemin merged 3 commits intoOct 1, 2026
Merged
karagozemin merged 3 commits into
karagozemin merged 3 commits into
Conversation
…ub-Rosa-Issue#376) A bid seal is only meaningful for the Drand round the auction committed to open. The contract now stores that rule: `commit` takes the seal's round and rejects, before any escrow is locked, any value that differs from the stored `reveal_round` — with stable errors SealRoundTooEarly (40), SealRoundTooLate (41), and InvalidSealRoundZero (42), the last also covering zero/overflowing reveal rounds at `create_round` via the new checked_time_of_round. Off-chain, @sub-rosa/tlock enforces the same window in sealBid/sealPayload through assertSealRoundWindow (SealRoundError with matching stable reasons), so the TS helper and the contract reject the same fixture set built from the repo's quicknet chain parameters. The SDK forwards sealed.sealRound as seal_round, bindings are regenerated, drand-tools' timeOfRound rejects rounds the chain can never publish, and ERRORS.md plus all error registry guards stay in lock-step. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@CollinsKRO Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
4 tasks
Hustler490
pushed a commit
to Hustler490/sub-rosa-issue
that referenced
this pull request
Oct 4, 2026
…und-commit-window
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #376
Goal
Refuse a bid seal — both off-chain and in the round contract — when its Drand quicknet round is not the round the auction committed to open.
Contract (
contracts/round)commitgains aseal_round: u64argument. The allowed reveal round is always the storedRound::reveal_round, never a caller-supplied value. Mismatched seals are rejected before the escrow transfer, so a seal for a different round can never lock funds.SealRoundTooEarly = 40— seal round before the auction's roundSealRoundTooLate = 41— seal round after the auction's roundInvalidSealRoundZero = 42— zero/malformed rounds; also returned bycreate_roundfor zero or overflowing reveal rounds via the newdrand::checked_time_of_round(replaces the saturating placeholder that could map an absurd round into the far future and strand the round past the void window).ERRORS.md(new 40–42 section),DOCUMENTED_ERROR_CODES,variant_name,ERROR_PATH_REGISTRY(27→30),scripts/check-round-errorstest counts.errors:check/errors:testPASS; 63 contract call snapshots regenerated with the new argument.TypeScript (
packages/tlock,sdk, services)packages/tlock/src/window.ts:assertSealRoundWindow(sealRound, revealRound)throwsSealRoundErrorwith stable reasons (seal-round-too-early/seal-round-too-late/invalid-seal-round-zero) mirroring the contract codes. Wired intosealBidandsealPayloadbefore any encryption/network call.SealedBidnow carriessealRound; the SDK forwards it tocommitasseal_round(typed config error if missing). All e2e/smoke/agent call sites updated (lifecycle-e2e,keeper-e2e,live-smoke,mainnet-micro,sealed-auction, agent bidder).services/drand-toolstimeOfRoundnow throws on zero/unsafe/overflowing rounds instead of returning a garbage product.Acceptance criteria
error_path_seal_round_too_early/..._too_late, asserting no bid state / no escrow)VEC_ROUNDon-chain)error_path_invalid_seal_round_zero,create_round_rejects_overflowing_reveal_round)revealRoundargument)Validation
cargo test -p sub-rosa-round: 91 passed, 0 failedpnpm tlock:test: 79 passed (incl. newwindow.test.tsvectors)pnpm sdk:test211,keeper:test73,agent:test38,bindings:test17,drand-tools:test5 — all greentlock,sdk,round-bindings,keeper,agent,auction-template)