-
Notifications
You must be signed in to change notification settings - Fork 50
Revenue pool: prove receive_payment cannot move tokens (docs + tests) #159
Copy link
Copy link
Open
Labels
Stellar WaveIssues in the Stellar wave programIssues in the Stellar wave programrevenue-poolsecuritysmart-contractssoroban
Description
Description
Add tests demonstrating receive_payment does not invoke token transfers; document the threat-model note for ops.
Requirements and context
- Prevents confusion with real settlement.
- Align with
SECURITY.mdexternal call checklist.
Suggested execution
- Fork the repo and create a branch:
git checkout -b test/revenue-pool-receive-payment-security - Implement changes in the Callora-Contracts Soroban workspace (
contracts/*/src/). - Run
cargo fmt,cargo clippy --all-targets --all-features -- -D warnings, andcargo testfrom the workspace root. - For WASM release builds:
cargo build --target wasm32-unknown-unknown --release -p callora-revenue-pool(adjust-pif the crate name differs).
Deliverables
test.rs+ rustdoc.
Test and commit
- Run tests and
./scripts/coverage.sh(orcargo tarpaulinpertarpaulin.toml). - Cover edge cases; include summarized test output and brief security notes in the PR description.
Example commit message
test(revenue-pool): receive_payment does not transfer tokens
Guidelines
- Minimum 95% line coverage for touched crates (workspace policy).
- Clear documentation (Rust
///on public items where applicable; repo markdown as needed). - Timeframe: 96 hours from assignment unless agreed otherwise.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Stellar WaveIssues in the Stellar wave programIssues in the Stellar wave programrevenue-poolsecuritysmart-contractssoroban