Repository navigation
Conversation
Documentation-only changes, no logic changes: - IDataServiceFees.releaseStake: claims released in creation order (FIND-047) - IssuanceAllocator: issuance upper bound excludes retroactive rate changes (FIND-033) - RecurringAgreementManager: containing a compromised collector (FIND-034) - SubgraphService.acceptProvisionPendingParameters: remove stale registration requirement (FIND-021) - Authorizable: revocation is permanent (FIND-045) - RecurringCollector._isAuthorized: override also governs onlyAuthorized (FIND-046) - ISubgraphService.setStakeToFeesRatio: ratio is a plain multiplier (FIND-029) - Allocation.isStale: threshold is in seconds (FIND-026) - IAgreementCollector.cancel / IDataServiceAgreements: active-scope cancel callback (FIND-044)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documentation-only follow-up to the Halborn 2026-08 assessment (#1366). No logic changes.
IDataServiceFees.releaseStake: claims are released in creation order; after a dispute period reduction an older unexpired claim can block newer expired onesIssuanceAllocatorheader: Issuance Upper Bound invariant excludes intentional retroactive rate application over an undistributed windowRecurringAgreementManagerescalation ladder: revokingCOLLECTOR_ROLEonly blocks discovery; contain a compromised collector by pausing and force-removing its agreementsSubgraphService.acceptProvisionPendingParameters: remove stale "indexer must be registered" requirement (removed in the OZ CR-02 fix)Authorizable: revocation is permanentRecurringCollector._isAuthorized: override also governs theonlyAuthorizedguard; self-trust branch must not depend on stored authorization stateISubgraphService.setStakeToFeesRatio: ratio is a plain multiplier, not PPMAllocation.isStale: threshold is in seconds, not blocksIAgreementCollector.cancel/IDataServiceAgreements.cancelIndexingAgreementByPayer: active-scope cancel forwards to the data service, which must call back to complete itNote: comment changes alter the Solidity metadata hash, so compiled bytecode for the affected contracts will differ from what's deployed even though behavior is unchanged.