MixinReserve.claimableReserve() mid-round accounting mismatch when transcoder pool size and current-round active set diverge
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 20/100
- Tipo di issue
- Bug
- Chiarezza
- Da chiarire
- Stato di attività
- Tranquilla
- Stack tecnologico
- solidity
- Ambito
- blockchain, security
Direzione di ricerca
Inizia con contracts/pm/mixins/MixinReserve.sol, quindi segui MixinTicketBrokerCore.redeemWinningTicket() e BondingManager.resignTranscoder() o tryToJoinActiveSet(). L’issue descrive una discrepanza contabile documentata e fuori ambito e non specifica alcuna modifica al codice né alcun test di accettazione, quindi non viene fornita alcuna condizione concreta di completamento.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
MixinReserve.claimableReserve() reads two data structures that can fall out of sync within one round. Claimant eligibility is gated on bondingManager().isActiveTranscoder(_claimant) (a current-round snapshot), while the reserve allocation is divided by bondingManager().getTranscoderPoolSize() (the live pending transcoder pool counter). When the pending pool shrinks or grows mid-round (e.g. via resignTranscoder() or tryToJoinActiveSet()), the eligible active set and the divisor diverge, causing the per-claimant reserve cap to deviate from the fair R / N allocation in either direction.
Root cause
isActiveTranscoder() is gated on activationRound <= currentRound < deactivationRound, which is a round-level snapshot. getTranscoderPoolSize() returns the live size of the transcoderPool linked list, which is mutated immediately by bonds, unbonds, evictions, and resignations.
When an active transcoder fully unbonds in round r:
resignTranscoder()removes them fromtranscoderPoolimmediately, sogetTranscoderPoolSize()returnsN - 1.- It sets
deactivationRound = currentRound + 1, soisActiveTranscoder()still returnstruefor the remainder of roundr.
The set of eligible claimants has size N, but the divisor is N - 1. Every eligible share is inflated by N / (N - 1). The symmetric case (new transcoder joining via tryToJoinActiveSet() when a slot is free) deflates the cap in the same way.
Why it's not an issue
- No theft. The redeemed amount is bounded by the ticket's
faceValueand can never exceed the face value the broadcaster explicitly signed. No funds are created beyond what the broadcaster committed. - Grief is temporary.
claimFromReserveis explicitly designed to paymin(shortfall, claimableReserve), not the full face value. Partial reserve payment for a valid ticket is normal protocol behavior. After a revert,usedTickets[hash]remains false and the ticket can be retried in a later round (subject toticketValidityPeriod). - Restrictive preconditions. The attack requires (1) a valid pre-signed winning ticket where
faceValue - deposit > R / N, (2) the attacker accepting the opportunity cost of fully unbonding (or coordinating with a separate pool-shrinker), and (3) no other transcoder bonding into the freed slot between the pool shrink and the redeem call. Splitting the pool-shrinker and the overclaimer into separate accounts reintroduces a race: the pool shrink and the redemption can no longer be bundled into one transaction, so any transcoder bonding into the free slot between the two steps restores the pool size and cancels the inflation. - Protocol spec acknowledges the behavior. The Livepeer technical spec documents a scenario where an orchestrator sets their ticket's face value to
R / N, but by the time they redeem, the active set has grown toN + 1, dropping the cap toR / (N + 1). This is treated as a known limitation of the reserve mechanism. The invariantclaimableReserve == R / active_set_size at all timesis not guaranteed by the spec.
Out of scope for bug bounty
Reports targeting the claimableReserve accounting mismatch in MixinReserve.sol, and the associated griefing/payment-disruption paths through MixinTicketBrokerCore.redeemWinningTicket(), BondingManager.resignTranscoder(), or BondingManager.tryToJoinActiveSet(), are closed as known issues and not eligible for rewards under the Livepeer Immunefi bug bounty program.
References
- Source:
contracts/pm/mixins/MixinReserve.sol - Related:
contracts/pm/mixins/MixinTicketBrokerCore.sol,contracts/bonding/BondingManager.sol - Deployed TicketBroker (Arbitrum):
0xa8bB618B1520E284046F3dFc448851A1Ff26e41B
- Lingua principale
- JavaScript
- Stelle
- 155
- Fork
- 50
- Merge medio
- 9g 22h
- PR unite (30g)
- 1
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di livepeer/protocol
-
known-issue
Difficoltà 4/5 3-5 giorni Idoneità per principianti 30/100
-
Winning tickets can settle for less than their face value once the recipient’s reserve is exhaustedApertaknown-issue
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
-
blockchain enhancement pm
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
known-issue
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
enhancement
Difficoltà 4/5 3-5 giorni Idoneità per principianti 42/100
Tutte le issue di livepeer/protocol
Issue simili
-
documentation
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 91/100
githubnext/gh-aw-workshop#4458 ·
I maintainer di solito rispondono entro 1 giorno
-
Add: CartoonitoApertacheck:failed feeds:add
Difficoltà 2/5 1-3 ore Idoneità per principianti 63/100
iptv-org/database#37390 · 1 commento ·
I maintainer di solito rispondono entro 9 giorni
-
bug: directory index route root priority is overwritten when wildcard is falseForse già presa @TalhaHunter101 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
fastify/fastify-static#617 ·
-
agent/sec-check hive/hosted-available-lke648397-260827-5n31 security
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Tool errors containing cycles or BigInt crash getErrorMessage and replace the original failureApertafactory-active factory-automatic task-bug-reproduction-success task-identify-harness-labels-done task-identify-issue-type-done
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
vercel/ai#22796 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno