Skip to content

Eliminate persistent Set allowances and residual balances - #74

Merged
stxphxn merged 2 commits into
mainfrom
agent/issue-14-zero-residual-balances
Jul 23, 2026
Merged

stxphxn merged 2 commits into
mainfrom
agent/issue-14-zero-residual-balances

Conversation

@stxphxn

@stxphxn stxphxn commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • force-approve exact Set pool allowances for zero-first tokens and clear them immediately after successful pool calls
  • enforce call-scoped ERC-20 input balance snapshots so fee-on-transfer assets and pools that under-consume input revert atomically
  • prevent token and pool reentrancy across Set execution while preserving sequential multicall legs
  • add unit and stateful invariant coverage for success, revert, reentrancy, malicious pools, false returns, native modes, and arbitrary multicall sequences
  • document the hardened Set execution safety model while retaining internal pool / poolId terminology

Why

The existing direct execution path cleared allowances on the normal path, but it did not handle USDT-style zero-first approvals or explicitly prove that the router input balance returned to its pre-call snapshot. A malicious pool could under-consume an approved input, and taxed assets were rejected only incidentally. The execution entry point also lacked an explicit reentrancy guard.

Impact

Successful direct swaps leave no call-scoped token or native residue and no Set pool allowance. Pre-existing router balances are excluded from settlement accounting. Unsupported fee-on-transfer and false-returning behavior reverts atomically.

Validation

  • npm run check
    • root tests: 116 passed, 1 skipped
    • quote service tests: 205 passed
    • app tests: 59 passed
    • upstream zFi Foundry tests: 95 passed
    • local contract tests: 156 passed
    • invariant suite: 256 runs / 128,000 calls per invariant
    • lint, type-check, formatting, deployment verification, and bytecode-size gates passed
  • npm run build
  • focused Set execution suite: 49 passed

Closes #14

@stxphxn
stxphxn marked this pull request as ready for review July 23, 2026 17:18
@stxphxn
stxphxn merged commit f220a55 into main Jul 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Eliminate persistent Setwise allowances and residual router balances

1 participant