Conversation
…y branch
collect_fee and collect_fee_and_invoke document expiration_ledger with
identical prose ("the ledger sequence at which the approval expires"),
which reads correctly for the latter but is misleading for the former
when called on its own: in the Lazy branch, once an existing allowance
already covers max_fee_amount, the value is validated as a freshness
bound on the call itself (see validate_expiration_ledger), never read
from the token's actual on-chain allowance expiry. This ambiguity led
to a filed-and-withdrawn bug report (OpenZeppelin#840/OpenZeppelin#844); this note is the
follow-up promised in that thread's closing comment.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe ChangesFee collection documentation
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to This documentation clarification does not alter fee collection behavior and is safe to merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
A rabbit reads each line, Comment |
Summary
collect_feeandcollect_fee_and_invokedocumentexpiration_ledgerwith identical prose ("the ledger sequence at which the approval
expires"). That's accurate for
collect_fee_and_invoke, where the valueis threaded into
user_args_for_authas a freshness bound on the signedcall itself, but it reads as "the allowance's expiration" when
collect_feeis read (or called) in isolation, since it's the onlyplace that phrasing appears for a function with no
require_authofits own.
That ambiguity produced a real filed-and-withdrawn finding, #840 (fix
attempt at #844): a reproduction called
collect_feedirectly with agenuinely non-expired 100-unit allowance and still hit
InvalidExpirationLedger, read at the time as a bug. @brozorec'sclosing explanation on #840 was correct and is not being reopened here:
in the
Lazybranch, once an existing allowance already coversmax_fee_amount,expiration_ledgeris validated viavalidate_expiration_ledgeras a freshness bound on the call, whollyindependent of the token's own allowance expiry. This PR is the doc
clarification promised in that thread's closing comment, so the next
reader doesn't hit the same misreading.
Changes
Three lines added to
collect_fee's own# Argumentsdoc comment,nothing else touched.
Test plan
cargo doc -p stellar-fee-abstraction --no-depsbuilds clean locally.Disclosure: drafted with AI assistance under my direction and reviewed
by hand.
🤖 Generated with Claude Code