Skip to content

feat(#1375): Scaffold OpNonce storage and batch validation logic - #1577

Open
T-kesh wants to merge 1 commit into
LabsCrypt:mainfrom
T-kesh:fix-issue-1375
Open

feat(#1375): Scaffold OpNonce storage and batch validation logic#1577
T-kesh wants to merge 1 commit into
LabsCrypt:mainfrom
T-kesh:fix-issue-1375

Conversation

@T-kesh

@T-kesh T-kesh commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Description: closes #1375 (Phase 1).

The current smart contract lacks application-level nonces, making it vulnerable to replay attacks on already-applied operations when a fresh authorization is re-signed by the backend retry loop.

This PR introduces Phase 1 of the cross-layer fix for the Smart Contract infrastructure:

Scaffolds contracts/loan_manager/src/nonce.rs.
Introduces persistent monotonic OpNonce storage tracking.
Implements consume_nonce guard which bumps the counter strictly on stored + 1, blocking all downstream replays.
Adds valid_until_ledger batch window expiration checks.
Defines robust BatchError::NonceReused and BatchError::BatchWindowExpired handling.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Cross-Layer] Non-Idempotent Batch Authorization Causing Cross-Layer Ledger State Desynchronization and Client State Corruption

1 participant