farming icon indicating copy to clipboard operation
farming copied to clipboard

Fix farming balance inflation bug

Open zZoMROT opened this issue 6 months ago • 2 comments

What Was Wrong

In FarmAccounting.startFarming(...), when starting a new farming period before the previous one ends, the leftover from the previous reward is added to amount. Then, the full amount (which now includes the leftover) is added to info.balance:

The Problem

info.balance should reflect only the actual tokens transferred to the contract via safeTransferFrom in startFarming.
However, leftover was already on the contract and previously accounted for in the last reward.

As a result:

  • info.balance becomes inflated, it includes both the newly transferred amount and already existing leftover
  • an inconsistency arises between internal accounting (info.balance) and the actual token balance of the contract

Why It Matters

  • rescueFunds() may allow withdrawal of “excess” tokens that are still needed for payouts
  • claim() may unexpectedly revert if the inflated balance doesn’t match the actual token balance

What Was Fixed

Now, info.balance is increased only by the amount passed to startFarming, which matches the actual safeTransferFrom.
The leftover is still used to increase reward, but it’s no longer double-counted in the internal balance

zZoMROT avatar Jul 04 '25 18:07 zZoMROT

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 92.40%. Comparing base (4579b9b) to head (e347f13). Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master      #94      +/-   ##
==========================================
+ Coverage   92.36%   92.40%   +0.03%     
==========================================
  Files           7        7              
  Lines         249      250       +1     
  Branches       60       60              
==========================================
+ Hits          230      231       +1     
  Misses         19       19              

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

:rocket: New features to boost your workflow:
  • :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

codecov[bot] avatar Jul 04 '25 18:07 codecov[bot]

But this was desired behavior, why do you think it should be fixed?

This balance is being used exclusively in rescueFunds() which lets distributor to withdraw some rewards - that's bad.

k06a avatar Sep 11 '25 16:09 k06a