Skip to content

[Quality][High] Make liquidation accrual and closeout arithmetic overflow-safe #1263

Description

@Baskarayelu

Objective

Centralize checked accrual math and define exact boundary behavior for liquidation, repayment, and closeout.

Why this matters

Accrued value grows across time and rate parameters. Overflow, rounding direction, or stale timestamps can undercharge or overcharge a position.

This is a substantive production-quality improvement. It must change runtime behavior, security guarantees, correctness, reliability, or meaningful user functionality. It is not a documentation-only, formatting-only, or trivial dependency task.

Scope

Area: liquidation and interest math

Starting points: docs/liquidation.md, docs/COMPOUND_RATE.md, credence_bond and math crates

The contributor should verify the current implementation before changing it and keep the PR limited to this issue. Do not introduce unrelated refactors or weaken existing CI/security gates.

Acceptance criteria

  • All arithmetic is checked and returns stable contract errors on overflow.
  • Accrual uses a single timestamp/rate convention across preview and execution.
  • Rounding direction is deterministic and cannot create value.
  • Liquidation cannot occur before its eligibility boundary or twice after closeout.

Required validation

  • Add property tests for monotonicity and conservation across randomized rates/times.

  • Test exact boundary, maximum duration, zero rate, and overflow inputs.

  • Add repeated liquidation/repayment regression tests.

  • The PR explains the failure mode, the chosen design, backward-compatibility impact, and rollback or migration considerations.

  • The PR includes CI evidence and does not contain secrets, generated noise, unrelated cleanup, or disabled checks.

Contributor deliverables

  • Open a focused feature branch and do not begin implementation until assigned.
  • Reference this issue with Closes #<issue-number> or Fixes #<issue-number>.
  • Check off every acceptance criterion in the PR with links to the relevant code and tests.
  • Include a security/correctness note explaining why adversarial inputs cannot bypass the new guarantee.

Maintainer quality bar

The PR must be independently reviewable, preserve existing behavior outside this scope, exercise failure paths, and pass the repository's complete required CI/CD checks. Reward eligibility is not guaranteed by this issue or by merging.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions